Compliance maturity levels
1) Purpose and area
The Compliance Maturity Model provides a common language for assessing current status, prioritizing, and planning for next-level transitions. Outputs:- uniform criteria and metrics by function;
- scoring and maturity heat maps;
- road map linkage (initiatives → effects → evidence);
- "audit-ready" confirmation of progress.
2) Maturity model (M0-M4)
3) Evaluation domains and criteria
Score each domain on a scale of 0-4 (M0-M4).
1. Governance
M0: scattered documents without versions
M1: repository, RACI, revision calendar
M2: norm/jurisdiction mapping, changelog, read- & -attest
M3: policy-as-code, PR process
M4: auto-localization, advisory updates
2. Controls and CCM
M0: "paper" checks
M1: list of controls, manual tests
M2: metrics/pass-fail reports, ToD/ToE
M3: continuous control monitoring, CI/CD gates, auto artifacts
M4: predictive checks and self-healing gates
3. Privacy and data (DSAR, retention, Legal Hold, cross-border)
4. VRM/vendors (due diligence, audit right, mirror retention, vendor-evidence)
5. Licenses/certifications (ISO/SOC/PCI; PBC readiness)
6. AML/KYC/Payments (rules, monitoring, chargeback, anti-fraud)
7. Incidents/BCP/DR (playbooks, drills, post-mortem → CAPA, RTO/RPO)
8. Training and Ethics (Role/Country Curriculum, Recertification, Whistleblowing)
9. Tracking legal changes (radar, alerts, implementation)
10. Reporting and dashboards (KPI/KRI, risk heatmap, evidence completeness)
(Use the same gradation for each domain M0-M4.)
4) Maturity scoring technique
4. 1 Individual assessments
Scale: 0.. 4 (M0.. M4).
Evaluation attributes: processes, tools, proofs (40/30/30 weight).
4. 2 Summary score
MaturityScore_total = Σ (Weight_domain × Score_domain) / Σ Weight_domain
Recommended weights (example): Governance 12%, Controls/CCM 15%, Privacy 10%, VRM 10%, Licenses 8%, AML/KYC 10%, Incidents/BCP 10%, Training/Ethics 8%, Legal Updates 7%, Reporting 10%
4. 3 Readiness classes
1. 5–2. 5 - "Yellow": stabilization of processes and metrics.
5) Self-assessment process (SOP)
SOP-1: Preparation
Collect artifacts (policies, metrics, audit reports, evidence) → assign domain owners → agree on weights.
SOP-2: Evaluation
Interview + ToD/ToE samples → score 0.. 4 on attributes → fix sources (hash receipts).
SOP-3: Calibration
Cross-functional session → discrepancy resolution → finalization.
SOP-4: Publish and Plan
Maturity heat map → gap Top-5 → 2-3 quarter roadmap (epics, KPI, DoD).
SOP-5: Cycle repetition
Quarterly (or after significant incidents/regulatory changes) → progress reconciliation → Roadmap update.
6) Maturity dashboards
Maturity Heatmap: domains × levels (colors M0-M4).
Δ progress: changes for Q-Q, closed gaps, goals achieved.
Controls/Evidence Readiness: CCM pass-rate and completeness of packages.
Regulatory Clock: deadlines of norms against the current level of domains.
Vendor Mirror: compliance of critical providers with target levels.
Audit-Ready Index: time to collect "audit pack" (target - hours, not days).
7) Road map link
For each gap, create an epic with DoD: DoD example for M1 → M2 (Privacy) transition:- A repository of policies with versions and localizations;
- DSAR/retention - p95 metrics, alerts;
- WORM archive of evidence;
- Role training with read- & -attest ≥ 95%.
- Control statements в YAML;
- Rego/SQL CCM rules;
- CI/CD gates;
- Pass/fail reports and evidence autocollection.
8) Quick Wins (Quick Wins) by Level
From M0 to M1: policy inventory, owner assignment, basic RACIs and revision calendar.
From M1 to M2: metrics and KRI for key controls, WORM-evidence, planned revisions, VRM questionnaires.
From M2 to M3: policy-/assurance-as-code, CCM to IAM/retention/marketing, CI/CD-gates of releases.
From M3 to M4: predictive KRIs, scenario analysis, recommendatory inspection plan, automatic refresher courses.
9) Example checklist (fragment)
Governance (0..4):- Policy register with versions and localizations
- Relationship of policies to regulations (jurisdictions, standards)
- Clear RACI/DoA/SoD
- Committees and meeting calendar + minutes
- Policy-as-code (ID, controls mapping)
- Controls directory + ToD/ToE
- Metrics/KRI, target thresholds
- CCM rules and pass/fail reports
- CI/CD Gates
- "Audit pack" in the ≤ 4 hours
(Duplicate the structure for the remaining domains.)
10) Metrics and maturity thresholds
MaturityScore_total by domain.
Evidence Completeness (100% target for High-risk domains).
Controls Pass-rate (target ≥ 95%).
Regulatory On-time (≥ 95%).
On-time CAPA (≥ 90–95% по Critical/High).
Vendor Certificate Freshness (100% for critical).
Training Completion (≥ 98% of coverage, ≤ 5% of delays).
Time-to-Audit-Ready.
11) Roles and Responsibilities (High Level RACI)
12) Antipatterns
"Assessment by eye" without evidence and ToD/ToE.
Policies without controls/metrics (or vice versa).
One-time exercise without quarterly cycles.
Ignoring VRM and vendor mirror.
Waivers without term and compensatory measures.
Chasing "green pictures" instead of reducing residual risk.
13) Relationship with risks and audits
The heat risk map should refer to domain maturity levels (low maturity increases Likelihood).
External/internal audit plans use maturity levels for sampling focus.
Maturity progress is recorded in the audit-ready package: policy diffusions, CCM reports, metrics, committee protocols, training certificates, vendor confirmations.
14) Example of target model for 12 months (fragment)
15) Artifact patterns
15. 1 Domain Card (YAML)
yaml domain: "Privacy"
owner: "Head of Privacy"
level_current: 2 level_target: 3 evidence:
- "hash://policy/privacy-v2. 1. pdf"
- "hash://metrics/dsar_sla_q3. csv"
gaps: ["No CCM by retention," "No automatic Legal Hold"]
initiatives:
- id: EP-PRIV-CCM-01 name: "CCM Retention & Deletion"
due: "2025-04-30"
dod: ["Rego rules", "Pass-rate ≥95%", "WORM exports"]
kpi:
- key: "dsar_response_p95_days"
target: 20
15. 2 Maturity report (one-pager)
Summary score and trend
Top 5 gaps and roadmap
Risks and Impact on Licenses/PII/Finance
"What Management Needs" (Solutions/Resources)
16) Maturity model vs. investments
M0→M1: low costs, quick effect on penalty risks.
M1→M2: average investment, predictability and "visibility."
M2→M3: capital investments in automation → reduction of TCO audits/incidents.
M3→M4: analytics/ML/KRI → leading risk management.
17) Related wiki articles
Compliance Roadmap
Heat Risk Map/Risk Scoring and Prioritization
Continuous Compliance Monitoring (CCM)
Policy and compliance repository
Risk-Based Audit (RBA)
Regulatory Change Alerts/Legal Update Tracking
Partner Compliance Guide (VRM)
Remediation Plans (CAPAs) and Re-Audits
Total
Compliance maturity levels turn "somehow working" into a manageable improvement program: agreed criteria, measurable steps, and verifiable evidence. This speeds up decisions, reduces residual risk, and makes audit-ready on an ongoing basis.