Maturity of ethical and responsible AI models
Your responsible AI practices, measured by theme and translated into a roadmap.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
Maturity of ethical and responsible AI models
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One Ethical and responsible AI framework (OECD and UNESCO principles, NIST AI RMF, with ISO/IEC 42001 as support) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
It is this mechanism (a level, a higher level, and the action linking the two) that turns a finding into a trajectory.
Are model biases tested and monitored throughout their lifecycle?
- N1
No bias testing is carried out. The topic is not addressed when a model goes into production.
- N2
Tests are carried out on an ad hoc basis, at the initiative of the team concerned, with no common metric and no record kept of results.
- N3
A test protocol is defined and applied before every go-live, with documented fairness metrics and archived results.
- N4
Tests are rerun periodically in production, drifts trigger a tracked action, and results are presented to the governance body.
- N5
The protocol and metrics are revised based on usage feedback and incidents, with a documented record of revisions and a comparison over time between models.
Action to move from L2 to L3
Define a common bias testing protocol, with the metrics and populations to be covered, make it a mandatory step in the go-live review, and archive results in the model’s record.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurement
What this framework covers
Ethical and responsible AI is not a standard but a framework of practices, built on principles that are now well established: fairness and non-discrimination, transparency and explainability, effective human oversight, robustness and security, respect for privacy, identified accountability, and consideration of environmental impact. These principles appear in the OECD and UNESCO recommendations, in the NIST AI Risk Management Framework and, as a management system, in ISO/IEC 42001. They describe expected behaviour from models and from the teams that design them, not a list of enforceable requirements.
This is what makes the topic hard to steer. The principles are widely agreed, but implementation varies from one team to another and from one model to another. Who decides that a model can go into production, and on what measured criteria? Are biases tested once before go-live, or monitored throughout the model’s lifetime? Does a business user know that a decision was assisted by a model, and who to contact to challenge it? Most organisations can answer for their flagship model, far fewer for the dozens of models and generative AI uses deployed off the radar.
The arrival of generative AI has shifted the topic. Responsible AI practices were originally designed for models built in-house, on controlled data, with an identified lifecycle. A growing share of usage today relies on third-party vendor models, embedded in business tools, sometimes activated without going through the IT department. The question is no longer just about designing models well, but knowing which ones are in use, by whom, for which decisions, and with what level of control. A confusion often recurs: responsible AI and regulatory compliance do not overlap. The latter sets a floor, the former structures the way of working.
The maturity assessment answers a different question from a yes or no check. It is not about whether a charter exists, but at what level practices are actually tooled, repeatable and monitored. Each theme gets a score, each gap against the target produces an action, and Datamensio’s AI groups these actions into a prioritised roadmap, with cost, timeframe and expected impact on the score.
The framework is ready to use and it belongs to you. You can adjust the themes, rephrase the questions, redefine the levels, or have the AI build a version tailored to your sector and your own internal documents, whether a charter, a model governance policy or an existing review checklist.
Reference standard: Ethical and responsible AI framework (OECD and UNESCO principles, NIST AI RMF, with ISO/IEC 42001 as support)
The themes assessed
Principles and responsible AI strategy
Existence of formalised principles, alignment with the data and AI strategy, senior leadership sponsorship, operational rollout within teams.
Governance and accountability
Use case review body, identified roles, go-live criteria, arbitration of sensitive uses, escalation of contentious cases.
Inventory and classification of uses
Inventory of models and generative AI uses, including those from third-party tools, classification by risk and criticality level.
Training data and quality
Data source and licensing, representativeness, personal data handling, processing documentation, version traceability.
Fairness and bias handling
Fairness metrics used, populations tested, pre-launch testing protocol, periodic re-assessment, documented corrective actions.
Transparency and explainability
Information provided to affected individuals, model documentation, ability to explain an individual decision, appeal and challenge routes.
Human oversight
Level of human intervention according to criticality, training of staff involved, actual ability to override a recommendation, traceability of overrides.
Model robustness and security
Stress testing, drift management, access control over models and data, handling of attacks on inputs and prompts.
Production monitoring and lifecycle
Indicators tracked after go-live, detection of performance drift, model decommissioning procedure, periodic review of active uses.
Culture, skills and environmental impact
Awareness raising across business functions, upskilling of technical teams, consideration of resource consumption, choice of models used.
A short version of the framework, with 32 questions, is available for the online self-assessment.
Frequently asked questions
Can ethical and responsible AI be certified?
No, it is a framework of practices rather than a certifiable standard. An organisation seeking a certifiable framework should turn to ISO/IEC 42001, which structures an artificial intelligence management system. This assessment measures the maturity of practices and provides a reusable foundation for that approach.
What is the difference with an assessment on the European AI regulation?
The regulatory framework sets obligations according to the risk level of systems. Responsible AI covers a broader scope: how models are designed, deployed and monitored, including for uses that fall under no obligation at all. The two assessments intersect in a cross-cutting roadmap, without duplicating actions.
How long does the assessment take?
The short version is completed in a single working session. The full version, run collaboratively with several contributors, takes one to two weeks: most of the time goes into gathering input from data teams, business functions and the IT department.
Do you need technical expertise to answer?
The questions cover governance and lifecycle management practices, not model architecture. An AI governance lead or a data project manager can answer them. Some questions require input from a data scientist: the collaborative mode allows them to be assigned directly to the right person.
Can the framework be adapted to our context?
Yes. Themes, questions and levels can be edited, and you can add your own areas. The AI can also build a version based on your charter, your model governance policy or your existing review checklists.
How can several business units be compared?
Each entity is assessed on the same framework, which makes scores comparable by theme. The benchmark positions an entity against others and against its own previous assessments. A cross-cutting roadmap then consolidates the action plans from several assessments.
Is the action plan costed?
Yes. Each gap against the target generates an action, and the services catalogue offers a solution against each of these actions, with cost, timeframe and expected impact on the score. The roadmap is prioritised by the AI, then managed through to completion.
Where is the data hosted?
In France, with OVH, with backup at Scaleway. No transfer outside the European Union. The AI models used within the platform can be selected, including from European solutions.





