TIER 3 · AI SECURITY MATURITY MODEL

OWASP AIMA to AITBM Mapping

Shows how maturity practices can support AITBM evidence without converting maturity levels directly into ERS.

How to use this crosswalk

External requirements, controls, threats, and practices identify evidence to collect or tests to run. Only measured evidence from the assessed deployment determines AITBM rubric placements, IVP, ORP, ACI, MVT findings, and ERS.

Mapping content last verified 2026-08-13. No endorsement by the external framework owner is implied.

AIMA

Maturity model

OWASP AI Maturity Assessment (AIMA) · OWASP Foundation

OWASP AIMA grades an organization's AI-program maturity qualitatively across eight lifecycle domains, while AITBM operationalizes that maturity quantitatively - turning the maturity grade into Tiered Assessment Pathway eligibility and, through the ACI components (Pc/Ec/Tf), into the confidence and freshness of a per-system ERS.

AIMA Domain Primary AITBM Sub-Metrics Evidence Use / Notes
Responsible AIFa-1Fa-2Fa-3Fa-4Tr-1Fairness/explainability artifacts; raises Ec
GovernanceTr-3Tr-4Pc and deployment-tier assignment
Data ManagementPr-1Pr-3Ro-4Data lineage is the canonical Pc source
PrivacyPr-1Pr-2Pr-3Pr-4Privacy-by-design; Ec and tier assignment
DesignCn-1Cn-2Ro-2Threat modeling sets containment boundaries
ImplementationCn-3Cn-4Cn-5Secure build provenance; agentic identity binding
VerificationRo-1Ro-3Cn-3Cn-5Red-team/eval reports; strongest Ec + Tf driver
OperationsTr-3Monitoring keeps Tf fresh; incident-response improves Rf

Key findings

  • AIMA maturity provides organizational-process context. It does not assign an AITBM pathway or ACI range; only the system's applicable provenance, evaluation, monitoring, and freshness evidence determines those values.
  • The two-organization example is a dated illustration. An AIMA level alone cannot justify its displayed ACI or ERS; a current assessment must score the underlying evidence independently.
  • AIMA practices may produce evaluation, monitoring, and provenance artifacts relevant to ACI. Practice maturity is contextual and never substitutes for AITBM admissibility, coverage, or freshness checks.
  • The frameworks operate at different levels: AIMA assesses organizational maturity and process, while AITBM assesses a deployed system. AIMA v1.0 and Toolkit 1.0.1 use eight lifecycle domains and do not define an ERS, IVP/ORP/ACI profile, or Cn-5 metric.

AIMA reference →