IMIA — the instrument for measuring sociotechnical maturity
Measuring maturity before buying is the method’s rule number one. But a rule that cannot be measured is only advice. This chapter presents the instrument that makes it operable: the IMIA (AI Maturity Index), with which the bridge measures the sociotechnical maturity of an organization before touching the technology. It was born in the Mendoza FuturIA observatory.
If small business and the public sector say whom the bridge serves, IMIA says by what rule one decides where AI pays off and where it only destroys value.
Why it exists (the problem it attacks)
Most “AI maturity” diagnostics are marketing checklists. They return a single, optimistic, non-actionable number, and they treat governance as an optional appendix. In practice the opposite holds: governance is the variable that decides whether an organization moves from isolated pilots to value in production. What was needed was an instrument that met two conditions. It had to measure the actual organizational configuration, not declared intent, and it had to make governance a structural requirement rather than an ornament.
IMIA operationalizes two ideas from the method:
- Measure maturity first, before choosing any technology → The four links.
- Governance as a hard constraint. What separates the bridge from a policy consultant is that here governance is operationalized: it can be measured and audited, and it limits what the organization can claim.
The theoretical foundation comes from research on AI readiness, which shows that readiness is multidimensional: having technology is not enough; the organizational conditions to absorb it are required.1 The dimensions with which IMIA measures those conditions are defined below; the theoretical discussion is in Authors and currents.
The architecture of the model: 7 dimensions × 6 levels
An organization is assessed across 7 dimensions, each on a 0–100 scale, and from these a global level from 0 to 5 is derived.
The 7 dimensions
| # | Dimension | What it measures | Discipline of the method |
|---|---|---|---|
| D1 | Leadership | Explicit strategy, sponsorship, resource allocation, tolerance for learning | Sociology (power/incentives) |
| D2 | Data | Existence, quality, accessibility and contextual meaning of the data | Data engineering |
| D3 | Culture | Openness to change, literacy, relationship with error and evidence; values–assumptions coherence (Schein) | Sociology |
| D4 | Capabilities | Talent, technical and management skills, absorptive capacity | Software / data engineering |
| D5 | Processes | Real processes mapped, standardized and amenable to improvement | Sociology / software engineering |
| D6 | Governance | AI use policies, risk management (privacy, security, bias, compliance), clear and auditable rules | AI architecture and governance |
| D7 | Automation potential | Repeatable tasks automatable, distinguishing deterministic layer (fixed rules) from agentic (autonomous decision) | AI architecture and governance |
D1 to D6 measure configuration: what the organization is today. D7 measures opportunity: what it could gain if it were ready. That is why D7 informs but does not penalize the global level. An immature organization may have very high automation potential, and that is a priority signal, not a defect.
D7 also distinguishes two classes of opportunity, because each demands a different maturity. Automating a fixed-rule task (generating a report, loading a file, calculating a tax with a known formula) asks for little additional governance. Adding agents, that is, software that decides and executes on its own without a human reviewing each case, raises the bar for D6. Human judgment stops filtering each decision and shifts to the design and audit of the agent’s rules. That is why a high agentic component on top of low governance reads as risk before it reads as opportunity.
The 6 levels (0 → 5)
The name of each level follows the method’s arc from silo to architecture. The table is the adoption ladder expressed as measurement: levels 0 to 2 are the silo, level 3 is the first real but isolated value, and levels 4 and 5 are the governed architecture.
| Level | Name | State of the organization |
|---|---|---|
| 0 | Denial | The relevance of AI is not acknowledged; management in spreadsheets and silos, decisions without evidence. |
| 1 | Exploration | Individual, informal and scattered use (shadow AI), with no strategy or data behind it. |
| 2 | Experimentation | Isolated pilots and proofs of concept; enthusiasm without sustained value in production. |
| 3 | Functional adoption | Real cases in production that deliver value, but isolated by area and without cross-cutting governance. |
| 4 | Governed integration | AI integrated into key processes with verifiable governance; risk is managed, not ignored. |
| 5 | Augmented organization | AI is a systemic capability; the human-AI loop is part of how the organization operates and decides. |
The key architecture decision: governance as a gate, not as an average
The global level is not an average of the dimensions. The scoring applies three ceiling rules, or gates, that prevent inflating the level with good marks on the easy parts:
| Gate | Rule | Why |
|---|---|---|
| Production | No Level ≥ 3 is assigned without real cases in production | Without real value there is no “functional adoption”; it cuts through the smoke of eternal pilots. It is Moore’s chasm turned into a rule: the pilot that excites the early adopters dies as it tries to cross into the majority, and the jump from level 2 to 3 is that crossing. |
| Governance | No Level ≥ 4 is assigned if D6 (Governance) < 40/100 | Without verifiable rules there is no sustainable integration. It is the moat. v1.0 design hypothesis: the 40 threshold is not hard empirical data; it is grounded in NIST AI RMF (cross-cutting Govern) and EU AI Act for high risk, plus field judgment. Recalibration planned in scoring v2.0. |
| Data | Level ≥ 4 requires D2 (Data) ≥ 50/100 | Without usable raw material, integration does not scale: you automate the data that lies. |
The governance gate is the central piece. An organization with excellent leadership, data and culture, but with no AI use policies, no risk management and no clear rules, is capped at Level 3. Governance thus stops being discourse and becomes a hard constraint of the model.
In the field, D6 is verified with a minimum structure. It includes sponsorship and a committee (or cell) that keeps minutes; a use-case inventory with risk classification; operational policies, including generative AI use; checkpoints before scaling pilots (stage-gates); and leading indicators that alert before the audit, such as multi-factor authentication (MFA), up-to-date patches or equity in public procedures. ISO 42001 and ISO 27001 serve as control maps, not as ends in themselves.
No Level ≥ 3 without real cases in production. Cuts through the smoke of eternal pilots: Moore's chasm turned into a rule.
No Level ≥ 4 without verifiable rules. It is the moat: what separates isolated pilots from value in production.
Level ≥ 4 requires usable raw material. Without it, integration only automates the data that lies.
The double mechanism. Governance acts twice: it weighs in the index (D6 is weighted) and it functions as a gate (it caps the level). If it only weighed, it would be negotiable, because good marks on another dimension could offset it. If it only capped, it would be binary. Together, the two functions say that governance adds up when it is present and blocks when it is missing.
How it is computed (scoring v1.0)
-
Each dimension is the average of its items (0–4 scale per item), rescaled to 0–100.
-
Global index: weighted sum of D1–D6, with grounded, provisional v1.0 weights:
D2 Data D1 Leadership D6 Governance D4 Capabilities D5 Processes D3 Culture 22% 20% 18% 14% 14% 12% Data and Leadership weigh more because they are the strongest theoretical predictors of successful adoption. Governance weighs high because it is the condition the rest of the model protects. D7 (Potential) informs, but it does not enter the index.
-
Conversion to level 0–5: the gates are applied over the global index.
-
Leap potential = D2·0.5 + D1·0.3 + D4·0.2. It detects organizations that are immature but have an exploitable base: the “high potential return” case, where the bridge pays off fastest.
-
Agentic risk ratio = D7 ÷ D6 (when D6 > 0). It is a complementary signal: high D7 with low D6 indicates the temptation to automate or delegate to agents without proportional control. It does not replace the gates, but it guides the “destroys value” verdict of the diagnosis. Example: D7=80 and D6=32 give a ratio ≈ 2.5. D7 also reports two sub-scores, deterministic and agentic; the latter, high over a low D6, is a risk alert, not an immediate opportunity.
-
Weights and cutoffs provisional by design. The v1.0 ones will be recalibrated with data (per-dimension reliability, factor analysis, regression on “cases in production”) and will lead to a scoring v2.0. It is a discipline of versioning, not a fixed opinion.
The instrument behind the model. This chapter describes the model. Beneath it there is an operational instrument: a bank of items per dimension, with anchors that explain what each point of the 0–4 scale means, and a calibration plan to move from scoring v1.0 to a v2.0 validated with field data. It is not reproduced here because it is application material, not exposition. For the argument, three things matter: that it exists, that it is a v1.0 by design, and that its validation awaits the observatory’s first data. Said without makeup: today the number of organizations measured is zero.
The output: a profile that prioritizes
Distribuidora Norte (illustrative, synthetic data)
Profile rebuilt to show output format. It does not correspond to a real field measurement: the instrument still lacks empirical calibration (see honesty at the end of the chapter).
Let us return to Distribuidora Norte’s second pass, a year after the churn model. The company has already unified its delivery data and put a co-developed dashboard in production, but it has not yet scaled agentic route prediction. At that point, an IMIA profile might look like this:
Maturity profile — Distribuidora Norte (synthetic)
Leadership ██████░░░░ 58 committed owner; informal committee, no minutes
Data █████░░░░░ 52 delivery glossary aligned; still fragile at peaks
Culture █████░░░░░ 50 scar from earlier pilot; error punishment in stories
Capabilities ████░░░░░░ 42 one systems lead; little depth on the floor
Processes █████░░░░░ 54 formal/real map documented in delivery; sales better
Governance ███░░░░░░░ 35 no written AI policy or risk classification
Automation pot. ███████░░░ 74 (deterministic 78 / agentic 62)
IMIA global: 48/100 → Level 2–3 (experimentation / partial functional adoption)
Cap: governance gate blocks Level 4 (D6 = 35 < 40)
D7/D6 ratio: ≈ 2.1 → temptation to automate dispatch without proportional rules
Recommendation: AI use policy and stage-gate before agent in dispatch;
consolidate D2 in peak season; second operational lead (anti-champion).
The diagnostic verdict and this profile should say the same thing in different languages: the first with narrative and verdicts (pays off / not yet / destroys value), the second with numerical prioritization. If they contradict each other, there is a method error.
Generic format (another synthetic organization)
Fictional data, only to show the output format. It does not correspond to any real organization: what is published is the method, not field data.
Maturity profile — Org. example (synthetic)
Leadership ███████░░░ 72
Data █████░░░░░ 48
Culture ██████░░░░ 60
Capabilities ████░░░░░░ 40
Processes █████░░░░░ 52
Governance ███░░░░░░░ 32 ← bottleneck
Automation pot. ████████░░ 80 (deterministic 84 / agentic 70)
D7/D6 ratio: ≈ 2.5 ← agentic alert (low D6)
IMIA global: 51/100 → Level 3 (Functional adoption)
Cap applied: governance gate prevents Level 4 (Governance 32 < 40)
Diagnosis: high leap potential, held back by governance and data; agentic D7 component over
D6=32 is a risk signal, not immediate opportunity.
Recommendation: before scaling AI, establish use policies and risk
management (D6) and improve data accessibility/quality (D2).
The actionable reading is not “they are at Level 3”, but “their bottleneck is Governance and Data, not Leadership, and their value ceiling is high”. That is what a governed adoption roadmap needs in order to prioritize: not a number, but what to unblock first.
How it ties to the bridge thesis
IMIA is not a neutral instrument. It translates the thesis of the bridge into measurement, and that shows in three traits:
- It is the deliverable of link 1, the sociological reading: the sociotechnical diagnosis made into an instrument. It measures real organizational configuration, not intent.
- It embodies from silo to architecture. Besides placing the organization on a rung, it says which one comes next.
- It puts governance at the center. It turns it into a positioning bet that can be verified, not into discourse.
Empirical grounding (why this model and not another)
-
Why measuring the gap is the real problem. AI penetration in Latin America is below 4% (against more than 20% in Europe), and in Brazil 41% of large firms use it versus 11% of small businesses.2 Since the distance between large and small firms is as wide as the one between regions, measuring maturity serves to close it, not to certify those who already arrived.
-
Why the bottleneck is organizational, not technological. According to nadIA’s national survey of AI adoption in small businesses, 41.6% already use some AI, but concentrated in basic tools (text or code generation, 77.9%; ML and data, only 24.1%) and with very low governance and internal capability indicators.3 What is missing is not the technology but the organizational conditions, which is precisely what IMIA measures.
-
Why 7 dimensions and not a single score. AI readiness research identifies 18 factors across 5 categories: strategic alignment, resources, knowledge, culture and data. IMIA adapts them and adds Processes and Governance as explicit dimensions.1 It rests on academic scaffolding; it is not an invented model.
-
Why IMIA declares what it has not calibrated. A systematic review of AI maturity models found the literature biased toward the technical, because it underrepresents the social, cultural and governance dimensions, and weakly validated: fewer than half the models report empirical validation.4
The gap IMIA admits (weights and gates that are grounded but not yet calibrated, and zero organizations measured) is therefore the gap of the whole field. The difference is that most models do not declare it. IMIA answers both biases: it makes the social, the cultural and governance half the model, and it versions its calibration rather than presenting a threshold as hard data. A recent responsible-AI maturity model, built with more than ninety specialists, points in the same direction: it treats maturity as a multidimensional configuration, not as a ladder toward a single end.5 Against a literature that tends to hide its lack of validation, declaring it is a methodological position, not a weakness.
-
Why the governance gate. D6 maps to recognized frameworks: the Govern function of the NIST AI RMF 1.0, cross-cutting by design,6 and the EU AI Act (Regulation (EU) 2024/1689, binding).7 Putting governance first follows the architecture of the global standards; it is not an opinion.
-
Why the production gate and the weight of Capabilities and Culture. Without human judgment to filter it, AI widens inequalities: in the Kenya experiment it helped high-performing entrepreneurs (around +15%) and harmed low performers (around −8%).8 Enthusiasm without capability destroys value.
The origin: Mendoza. The model is born from the Mendoza FuturIA observatory, in a province with a real and heterogeneous productive structure: winemaking (the bulk of national production), agribusiness and energy. It also has an emerging AI ecosystem, with Polo TIC Mendoza, the AI Micro-master’s and the “AI for governance” program of UNCuyo with the Province. There is no AI maturity measurement of the Mendoza small-business fabric. That void, treated as a hypothesis and not as a fact, is the reason for being of the observatory and of IMIA.
Honesty (guardrail)
What is published of IMIA is the model, the scoring and the methodology, design artifacts of one’s own and defensible. No field organization data appears: the example profiles are illustrative and synthetic, and are labeled as such. Where a weight is a design decision and not hard data, it is said. The instrument carries the same brand as the book: rigor, not hype.
See also: Concepts of our own · The bridge applied to small business · The bridge applied to the public sector · Authors and currents · Bibliography
Notes
-
Jöhnk, J., Weißert, M. & Wyrtki, K. (2021). “Ready or Not, AI Comes.” Business & Information Systems Engineering 63(1), 5–20. 18 factors of AI readiness across 5 categories —strategic alignment, resources, knowledge, culture and data—. ↩ ↩2
-
CEPAL (2024). AI penetration in Latin America below 4% versus more than 20% in Europe; in Brazil, 41% of large firms use AI versus 11% of small businesses (cf. Jung, J. & Katz, R., 2024/2025, “Impacto económico de la inteligencia artificial en América Latina”, CEPAL). ↩
-
nodo nadIA (CEPE-UTDT + Fundar) (2025). National survey of AI adoption in Argentine small businesses (n=402): 41.6% use at least one AI, mostly basic tools (text/code generation 77.9%; ML/data 24.1%), with very low governance and internal capability indicators. ↩
-
Sadiq, R. B., Safie, N., Abd Rahman, A. H. & Goudarzi, S. (2021). “Artificial intelligence maturity model: a systematic literature review.” PeerJ Computer Science 7, e661. AI maturity literature is biased toward the technical and fewer than half the models report empirical validation. ↩
-
Heger, A. K., Passi, S., Dhanorkar, S., Kahn, Z., Wang, R. & Vorvoreanu, M. (2025). “Towards a Responsible AI Organizational Maturity Model.” Proc. ACM Human-Computer Interaction 9(7), CSCW. 24 dimensions derived from more than ninety responsible-AI specialists. ↩
-
NIST (2023). AI Risk Management Framework (AI RMF 1.0). Four functions —Govern, Map, Measure, Manage—, with Govern cross-cutting by design. ↩
-
Regulation (EU) 2024/1689 (EU AI Act). In force since 1 August 2024, with staggered application; binding, with sanctions. ↩
-
Otis, N., Clarke, R., Delecourt, S., Holtz, D. & Koning, R. (2024). The Uneven Impact of Generative AI on Entrepreneurial Performance. Working paper, Harvard Business School / UC Berkeley Haas (SSRN 4671369). 640 entrepreneurs in Kenya: high performers around +15%, low performers around −8%. ↩