EDIH, EEN, Interreg: the platform for European programmes.Find out more

Maturity of ethical and responsible AI models

Your responsible AI practices, measured by theme and translated into a roadmap.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Maturity of ethical and responsible AI models

Principles and responsible AI strategyN1 → N5
Governance and accountabilityN1 → N5
Inventory and classification of usesN1 → N5
Training data and qualityN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Principles and responsible AI strategy6484
Governance and accountability5379
Inventory and classification of uses6182
Training data and quality3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • ANITI
  • CNRS
  • LIRMM
  • CNES
  • Docaposte
  • KPMG

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Ethical and responsible AI framework (OECD and UNESCO principles, NIST AI RMF, with ISO/IEC 42001 as support) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism (a level, a higher level, and the action linking the two) that turns a finding into a trajectory.

Are model biases tested and monitored throughout their lifecycle?

  1. N1

    No bias testing is carried out. The topic is not addressed when a model goes into production.

  2. N2

    Tests are carried out on an ad hoc basis, at the initiative of the team concerned, with no common metric and no record kept of results.

  3. N3

    A test protocol is defined and applied before every go-live, with documented fairness metrics and archived results.

  4. N4

    Tests are rerun periodically in production, drifts trigger a tracked action, and results are presented to the governance body.

  5. N5

    The protocol and metrics are revised based on usage feedback and incidents, with a documented record of revisions and a comparison over time between models.

Action to move from L2 to L3

Define a common bias testing protocol, with the metrics and populations to be covered, make it a mandatory step in the go-live review, and archive results in the model’s record.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurement

What this framework covers

Ethical and responsible AI is not a standard but a framework of practices, built on principles that are now well established: fairness and non-discrimination, transparency and explainability, effective human oversight, robustness and security, respect for privacy, identified accountability, and consideration of environmental impact. These principles appear in the OECD and UNESCO recommendations, in the NIST AI Risk Management Framework and, as a management system, in ISO/IEC 42001. They describe expected behaviour from models and from the teams that design them, not a list of enforceable requirements.

This is what makes the topic hard to steer. The principles are widely agreed, but implementation varies from one team to another and from one model to another. Who decides that a model can go into production, and on what measured criteria? Are biases tested once before go-live, or monitored throughout the model’s lifetime? Does a business user know that a decision was assisted by a model, and who to contact to challenge it? Most organisations can answer for their flagship model, far fewer for the dozens of models and generative AI uses deployed off the radar.

The arrival of generative AI has shifted the topic. Responsible AI practices were originally designed for models built in-house, on controlled data, with an identified lifecycle. A growing share of usage today relies on third-party vendor models, embedded in business tools, sometimes activated without going through the IT department. The question is no longer just about designing models well, but knowing which ones are in use, by whom, for which decisions, and with what level of control. A confusion often recurs: responsible AI and regulatory compliance do not overlap. The latter sets a floor, the former structures the way of working.

The maturity assessment answers a different question from a yes or no check. It is not about whether a charter exists, but at what level practices are actually tooled, repeatable and monitored. Each theme gets a score, each gap against the target produces an action, and Datamensio’s AI groups these actions into a prioritised roadmap, with cost, timeframe and expected impact on the score.

The framework is ready to use and it belongs to you. You can adjust the themes, rephrase the questions, redefine the levels, or have the AI build a version tailored to your sector and your own internal documents, whether a charter, a model governance policy or an existing review checklist.

Reference standard: Ethical and responsible AI framework (OECD and UNESCO principles, NIST AI RMF, with ISO/IEC 42001 as support)

The themes assessed

  • Principles and responsible AI strategy

    Existence of formalised principles, alignment with the data and AI strategy, senior leadership sponsorship, operational rollout within teams.

  • Governance and accountability

    Use case review body, identified roles, go-live criteria, arbitration of sensitive uses, escalation of contentious cases.

  • Inventory and classification of uses

    Inventory of models and generative AI uses, including those from third-party tools, classification by risk and criticality level.

  • Training data and quality

    Data source and licensing, representativeness, personal data handling, processing documentation, version traceability.

  • Fairness and bias handling

    Fairness metrics used, populations tested, pre-launch testing protocol, periodic re-assessment, documented corrective actions.

  • Transparency and explainability

    Information provided to affected individuals, model documentation, ability to explain an individual decision, appeal and challenge routes.

  • Human oversight

    Level of human intervention according to criticality, training of staff involved, actual ability to override a recommendation, traceability of overrides.

  • Model robustness and security

    Stress testing, drift management, access control over models and data, handling of attacks on inputs and prompts.

  • Production monitoring and lifecycle

    Indicators tracked after go-live, detection of performance drift, model decommissioning procedure, periodic review of active uses.

  • Culture, skills and environmental impact

    Awareness raising across business functions, upskilling of technical teams, consideration of resource consumption, choice of models used.

A short version of the framework, with 32 questions, is available for the online self-assessment.

Frequently asked questions

Can ethical and responsible AI be certified?

No, it is a framework of practices rather than a certifiable standard. An organisation seeking a certifiable framework should turn to ISO/IEC 42001, which structures an artificial intelligence management system. This assessment measures the maturity of practices and provides a reusable foundation for that approach.

What is the difference with an assessment on the European AI regulation?

The regulatory framework sets obligations according to the risk level of systems. Responsible AI covers a broader scope: how models are designed, deployed and monitored, including for uses that fall under no obligation at all. The two assessments intersect in a cross-cutting roadmap, without duplicating actions.

How long does the assessment take?

The short version is completed in a single working session. The full version, run collaboratively with several contributors, takes one to two weeks: most of the time goes into gathering input from data teams, business functions and the IT department.

Do you need technical expertise to answer?

The questions cover governance and lifecycle management practices, not model architecture. An AI governance lead or a data project manager can answer them. Some questions require input from a data scientist: the collaborative mode allows them to be assigned directly to the right person.

Can the framework be adapted to our context?

Yes. Themes, questions and levels can be edited, and you can add your own areas. The AI can also build a version based on your charter, your model governance policy or your existing review checklists.

How can several business units be compared?

Each entity is assessed on the same framework, which makes scores comparable by theme. The benchmark positions an entity against others and against its own previous assessments. A cross-cutting roadmap then consolidates the action plans from several assessments.

Is the action plan costed?

Yes. Each gap against the target generates an action, and the services catalogue offers a solution against each of these actions, with cost, timeframe and expected impact on the score. The roadmap is prioritised by the AI, then managed through to completion.

Where is the data hosted?

In France, with OVH, with backup at Scaleway. No transfer outside the European Union. The AI models used within the platform can be selected, including from European solutions.

Take your first measurement