Methodology
Defensibility comes from the governance of the rating, not the complexity of the formula.
An AIGR™ AI Governance Rating is a governance opinion within a defined scope and date. This page sets out how one is produced. Weights, thresholds and calibration logic are controlled and not published.
Two layersAn analytical measure and a rating designation are not the same thing.
Separating them lets the analysis stay detailed while the published outcome stays stable and interpretable.
Analytical layer
AIGX Governance Score™
A 0–100 measure supporting assessment, diagnostics and trend analysis. Disclosure varies by product and scope; calculation logic remains controlled.
Rating layer
AIGR™ AI Governance Ratings
A categorical designation from AIGR-100 to AIGR-40 for executive interpretation and reporting. It is not a percentage, a probability or a credit score.
Rating architectureEight domains produce a balanced view of enterprise AI governance.
Sector and jurisdiction overlays change the emphasis and the evidence expected; the architecture stays constant.
Domain 01
Governance & oversight
Accountability, decision rights, policy and board-level visibility.
Domain 02
Organizational readiness
Skills, operating model, training and management capability.
Domain 03
Risk management
Classification, impact analysis, control design and remediation.
Domain 04
Responsible AI practices
Intended use, transparency, fairness and human oversight.
Domain 05
Enterprise architecture
System design, integration, data flows and control points.
Domain 06
Cybersecurity governance
Access, model and data security, and third-party controls.
Domain 07
Regulatory alignment
Mapping to applicable obligations and jurisdictional requirements.
Domain 08
Operational governance
Monitoring, change management and evidence continuity.
Rating lifecycleA governed decision process, not a one-time questionnaire.
01
Intake
Define organization, system, use case, sector and assessment scope.
02
Classify
Set risk context, evidence expectations and assessment pathway.
03
Assess
Review controls, evidence, findings and material deficiencies.
04
Review
Challenge evidence quality, judgment, conflicts and exceptions.
05
Rate
Determine rating outcome, rationale and benchmark context.
06
Monitor
Track validity, change triggers, incidents and re-review.
AIGR™ rating scaleSeven designations, plus Not Rated.
The designation summarizes an assessment opinion on governance maturity and evidence confidence within a defined scope.
| Designation | Meaning | Interpretation |
|---|---|---|
| AIGR-100 | Exemplary governance | Leading maturity |
| AIGR-90 | Advanced governance | High confidence |
| AIGR-80 | Established governance | Established |
| AIGR-70 | Developing governance | Improvement required |
| AIGR-60 | Emerging governance | Material remediation |
| AIGR-50 | Limited governance | High concern |
| AIGR-40 | Critical governance concern | Urgent review |
| AIGR-NR | Not rated | Insufficient scope, evidence or conditions |
How to read the scale
AIGR-100 through AIGR-40 are proprietary categorical designations. AIGR-100 does not mean 100%, 100 out of 100, or a probability. The AIGX Governance Score™ is a separate analytical measure and conversion logic remains proprietary. Any familiar letter-grade reference is a secondary, non-operative communication aid only; it is not a credit rating and does not claim equivalence to any external rating-agency methodology.
Scope definitionA rating is only meaningful if what it covers is explicit.
Every engagement fixes five scope parameters before assessment begins. They appear on the face of the rating report.
| Parameter | What is fixed | Why it matters |
|---|---|---|
| ENTITY | The legal entity and business unit accountable | Determines who owns remediation |
| SYSTEM | The named AI system, model version and intended use | A rating does not transfer to other systems |
| LIFECYCLE | The stage assessed, from development to production | Evidence expectations differ by stage |
| JURISDICTION | The regulatory context applied | Obligations are territorial |
| PERIOD | The evidence window and the as-at date | A rating is a point-in-time opinion |
Evidence standardFour tests decide whether evidence supports a conclusion.
A control is not credited because a policy exists. It is credited when an artifact passes all four tests and a reviewer records the decision.
Test 01
Relevance
The artifact addresses the control requirement as written, not an adjacent or general practice.
Test 02
Currency
The artifact reflects the system and period under assessment, and has not been superseded.
Test 03
Traceability
The artifact has a named owner, a date and a verifiable source within the client environment.
Test 04
Sufficiency
The artifact demonstrates the control operating, not only that it was designed or intended.
Reviewer states
Each requirement resolves to Validated, In review, Not applicable with recorded justification, or Blocker. Blocker states are reserved for material failures in safety, privacy, security, accountability or evidence integrity, and are not offset by strength elsewhere.
Independence & conflictsSeparation of assessment, remediation support and issuance.
The framework is designed so that the people who help an organization improve are not the people who approve its rating.
Function 01
Assessment
Collects and tests evidence against the framework. Records findings and reviewer states. Does not determine the published designation.
Function 02
Remediation support
Advisory work helping an organization close gaps. Commercially separate from issuance, and disclosed on the rating record where engaged.
Function 03
Rating issuance
Reviews the assessment record, challenges judgment and exceptions, and approves or declines the designation.
Conflicts management
Conflicts of interest are identified at intake and recorded on the rating file. Where a conflict cannot be managed through separation of function, AIGX declines the engagement or issues AIGR-NR. Commercial terms are fixed before assessment begins and are not contingent on the rating outcome.
Rating actionsWhat is designed to happen to a rating once issuance begins.
A rating is intended to be a live opinion. Defined triggers move it, and every action is recorded against the rating file.
Action
Affirmation
Periodic review confirms the designation remains supported by current evidence.
Action
Upgrade or downgrade
Material change in governance capability, evidence quality or open conditions moves the designation.
Action
Conditional
An open critical gate holds the deployment decision regardless of the Governance Score.
Action
Suspension
Pending investigation of an incident, a material change, or a challenge to evidence integrity.
Action
Withdrawal
Where scope no longer applies, access to evidence ends, or a rating is misrepresented and not corrected.
Action
Not rated
AIGR-NR, where scope, evidence, independence or assessment conditions cannot support an opinion.
Challenge & appealA rated organization will be able to contest the outcome.
An appeal is heard by reviewers who were not part of the original decision, and the outcome is recorded whether or not the designation changes.
Grounds
Factual error, evidence not considered, misapplication of the framework, or scope misstatement.
Not grounds
Disagreement with the framework itself, or with commercial consequences of the designation.
Process
Written submission, independent review, recorded determination with rationale.
Effect
The original designation stands during the appeal unless suspended for cause.
Methodology governanceThe framework itself is version-controlled.
A rating states the methodology version used. Reproducibility depends on it.
Versioning
Every rating names its version
Framework releases are numbered and dated. A rating can be reconstructed from its methodology version, evidence set and decision record.
Change control
Revisions are documented
Material changes to criteria, gates or scale are published with rationale and an effective date, and do not apply retroactively to live ratings.
Calibration
Consistency is tested
Reviewer decisions are tested for consistency across assessments so that the same evidence produces the same state.
Confidentiality
Client evidence is segregated
Evidence is held per tenant and is not disclosed in a rating report, which carries the designation, rationale and conditions only.
Cohorts
Benchmarks are consented
Cohorts are constructed under consent and confidentiality rules and reported in aggregate, not in a form that identifies a participant.
Records
Decisions are retained
Assessment records, reviewer challenge and approval decisions are retained to support later review and appeal.
LimitationsWhat an AIGR™ rating is not.
Stating the boundary is part of the methodology. A rating that claims more than it can support is not defensible.
| A rating is | A rating is not |
|---|---|
| An opinion on governance maturity and evidence confidence | A certification, accreditation or attestation of compliance |
| Scoped to a named system, entity, period and jurisdiction | Transferable to other systems, entities or periods |
| A point-in-time view subject to defined rating actions | A permanent or guaranteed status |
| A decision-support signal for boards, buyers and risk teams | An audit opinion, legal opinion or regulatory approval |
| A categorical designation, AIGR-100 to AIGR-40 | A percentage, probability, credit rating or safety guarantee |
Full frameworkThe published market outlook and ratings framework.
Category thesis, rating architecture, lifecycle and scale in full. Proprietary formulas, weights, thresholds and calibration logic are not disclosed.
PDF · Market Outlook & Ratings Framework 2026 · v1.3
Disclaimer
AIGX™ assessments and ratings are independent governance evaluations and do not constitute certifications, regulatory approvals, legal opinions, or attestations of compliance. References to third-party standards, regulations, and frameworks are provided for alignment purposes only and do not imply affiliation, endorsement, sponsorship, or certification by their respective owners.