Methodology

Defensibility comes from the governance of the rating, not the complexity of the formula.

An AIGR™ rating is a governance opinion within a defined scope and date. This page sets out how one is produced. Weights, thresholds and calibration logic are controlled and not published.

Two layers

An analytical measure and a rating designation are not the same thing.

Separating them lets the analysis stay detailed while the published outcome stays stable and interpretable.

Analytical layer

AIGX Governance Score™

A 0–100 measure supporting assessment, diagnostics and trend analysis. Disclosure varies by product and scope; calculation logic remains controlled.

Rating layer

AIGR™ AI Governance Ratings

A categorical designation from AIGR-100 to AIGR-40 for executive interpretation and reporting. It is not a percentage, a probability or a credit score.

Rating architecture

Eight domains produce a balanced view of enterprise AI governance.

These are the same domains published on the AI Governance Index. Sector and jurisdiction overlays change the emphasis and the evidence expected; the architecture stays constant.

Domain 01
  • Governance & oversightAccountability, decision rights, policy and board-level visibility.
Domain 02
  • Organizational readinessSkills, operating model, training and management capability.
Domain 03
  • Risk managementClassification, impact analysis, control design and remediation.
Domain 04
  • Responsible AI practicesIntended use, transparency, fairness and human oversight.
Domain 05
  • Enterprise architectureSystem design, integration, data flows and control points.
Domain 06
  • Cybersecurity governanceAccess, model and data security, and third-party controls.
Domain 07
  • Regulatory alignmentMapping to applicable obligations and jurisdictional requirements.
Domain 08
  • Operational governanceMonitoring, change management and evidence continuity.
Rating lifecycle

A governed decision process, not a one-time questionnaire.

01

Intake

Define organization, system, use case, sector and assessment scope.

02

Classify

Set risk context, evidence expectations and assessment pathway.

03

Assess

Review controls, evidence, findings and material deficiencies.

04

Review

Challenge evidence quality, judgment, conflicts and exceptions.

05

Rate

Determine rating outcome, rationale and benchmark context.

06

Monitor

Track validity, change triggers, incidents and re-review.

What the process preserves

Five disciplines make a rating defensible.

Scope

Define the subject

Entity, systems, lifecycle, jurisdiction and evidence period are explicit before assessment begins.

Evidence

Anchor the opinion

Material conclusions are supported by relevant, current and traceable records.

Judgment

Control interpretation

Reviewer roles, exceptions and material decisions follow a consistent governance process.

Issuance

Separate authority

The framework is designed to separate final rating approval from commercial influence and routine assessment activity.

Monitoring

Keep it current

Material changes, incidents and new evidence can trigger reassessment or rating action.

Critical gates

No masking

Severe failures in safety, privacy, security, accountability or evidence integrity are not offset by strong performance elsewhere.

AIGR™ rating scale

Seven designations, plus Not Rated.

The designation summarizes an assessment opinion on governance maturity and evidence confidence within a defined scope.

DesignationMeaningInterpretation
AIGR-100Exemplary governanceLeading maturity
AIGR-90Advanced governanceHigh confidence
AIGR-80Established governanceEstablished
AIGR-70Developing governanceImprovement required
AIGR-60Emerging governanceMaterial remediation
AIGR-50Limited governanceHigh concern
AIGR-40Critical governance concernUrgent review
AIGR-NRNot ratedInsufficient scope, evidence or conditions

How to read the scale

AIGR-100 through AIGR-40 are proprietary categorical designations. AIGR-100 does not mean 100%, 100 out of 100, or a probability. The AIGX Governance Score™ is a separate analytical measure and conversion logic remains proprietary. Any familiar letter-grade reference is a secondary, non-operative communication aid only; it is not a credit rating and does not claim equivalence to any external rating-agency methodology.

Scope definition

A rating is only meaningful if what it covers is explicit.

Every engagement fixes five scope parameters before assessment begins. They appear on the face of the rating report.

ParameterWhat is fixedWhy it matters
ENTITYThe legal entity and business unit accountableDetermines who owns remediation
SYSTEMThe named AI system, model version and intended useA rating does not transfer to other systems
LIFECYCLEThe stage assessed, from development to productionEvidence expectations differ by stage
JURISDICTIONThe regulatory context appliedObligations are territorial
PERIODThe evidence window and the as-at dateA rating is a point-in-time opinion
Evidence standard

Four tests decide whether evidence supports a conclusion.

A control is not credited because a policy exists. It is credited when an artifact passes all four tests and a reviewer records the decision.

Test 01

Relevance

The artifact addresses the control requirement as written, not an adjacent or general practice.

Test 02

Currency

The artifact reflects the system and period under assessment, and has not been superseded.

Test 03

Traceability

The artifact has a named owner, a date and a verifiable source within the client environment.

Test 04

Sufficiency

The artifact demonstrates the control operating, not only that it was designed or intended.

Reviewer states

Each requirement resolves to Validated, In review, Not applicable with recorded justification, or Blocker. Blocker states are reserved for material failures in safety, privacy, security, accountability or evidence integrity, and are not offset by strength elsewhere.

Independence & conflicts

Separation of assessment, remediation support and issuance.

The framework is designed so that the people who help an organization improve are not the people who approve its rating.

Function 01

Assessment

Collects and tests evidence against the framework. Records findings and reviewer states. Does not determine the published designation.

Function 02

Remediation support

Advisory work helping an organization close gaps. Commercially separate from issuance, and disclosed on the rating record where engaged.

Function 03

Rating issuance

Reviews the assessment record, challenges judgment and exceptions, and approves or declines the designation.

Conflicts management

Conflicts of interest are identified at intake and recorded on the rating file. Where a conflict cannot be managed through separation of function, AIGX declines the engagement or issues AIGR-NR. Commercial terms are fixed before assessment begins and are not contingent on the rating outcome.

Rating actions

What is designed to happen to a rating once issuance begins.

A rating is intended to be a live opinion. Defined triggers move it, and every action is recorded against the rating file.

ACTION

Affirmation

Periodic review confirms the designation remains supported by current evidence.

ACTION

Upgrade or downgrade

Material change in governance capability, evidence quality or open conditions moves the designation.

ACTION

Conditional

An open critical gate holds the deployment decision regardless of the Governance Score.

ACTION

Suspension

Pending investigation of an incident, a material change, or a challenge to evidence integrity.

ACTION

Withdrawal

Where scope no longer applies, access to evidence ends, or a rating is misrepresented and not corrected.

ACTION

Not rated

AIGR-NR, where scope, evidence, independence or assessment conditions cannot support an opinion.

Challenge & appeal

A rated organization will be able to contest the outcome.

An appeal is heard by reviewers who were not part of the original decision, and the outcome is recorded whether or not the designation changes.

Grounds

Factual error, evidence not considered, misapplication of the framework, or scope misstatement.

Not grounds

Disagreement with the framework itself, or with commercial consequences of the designation.

Process

Written submission, independent review, recorded determination with rationale.

Effect

The original designation stands during the appeal unless suspended for cause.

Methodology governance

The framework itself is version-controlled.

A rating states the methodology version used. Reproducibility depends on it.

Versioning

Every rating names its version

Framework releases are numbered and dated. A rating can be reconstructed from its methodology version, evidence set and decision record.

Change control

Revisions are documented

Material changes to criteria, gates or scale are published with rationale and an effective date, and do not apply retroactively to live ratings.

Calibration

Consistency is tested

Reviewer decisions are tested for consistency across assessments so that the same evidence produces the same state.

Confidentiality

Client evidence is segregated

Evidence is held per tenant and is not disclosed in a rating report, which carries the designation, rationale and conditions only.

Cohorts

Benchmarks are consented

Cohorts are constructed under consent and confidentiality rules and reported in aggregate, not in a form that identifies a participant.

Records

Decisions are retained

Assessment records, reviewer challenge and approval decisions are retained to support later review and appeal.

Limitations

What an AIGR™ rating is not.

Stating the boundary is part of the methodology. A rating that claims more than it can support is not defensible.

A rating isA rating is not
An opinion on governance maturity and evidence confidenceA certification, accreditation or attestation of compliance
Scoped to a named system, entity, period and jurisdictionTransferable to other systems, entities or periods
A point-in-time view subject to defined rating actionsA permanent or guaranteed status
A decision-support signal for boards, buyers and risk teamsAn audit opinion, legal opinion or regulatory approval
A categorical designation, AIGR-100 to AIGR-40A percentage, probability, credit rating or safety guarantee
Full framework

The published market outlook and ratings framework.

Category thesis, rating architecture, lifecycle and scale in full. Proprietary formulas, weights, thresholds and calibration logic are not disclosed.

Download the framework PDF · Market Outlook & Ratings Framework 2026 · v1.3

Disclaimer

AIGX™ assessments and ratings are independent governance evaluations and do not constitute certifications, regulatory approvals, legal opinions, or attestations of compliance. References to third-party standards, regulations, and frameworks are provided for alignment purposes only and do not imply affiliation, endorsement, sponsorship, or certification by their respective owners.