Ad hoc
Controls exist informally; documentation is incomplete; no consistent review.
Every HI-AAF control is graded on a five-level maturity ladder. An agent's overall maturity at certification is the lowest level achieved across all required controls in scope. This is deliberately conservative: a chain of trust is no stronger than its weakest link.
Controls exist informally; documentation is incomplete; no consistent review.
Controls are written down; ownership is assigned; review cadence is defined.
Controls are followed in practice; evidence is collected; deviations are tracked.
Control effectiveness is measured against documented thresholds; trends are reported.
Controls evolve based on incident learning; maturity gains are evidenced over time.
Controls exist informally; documentation is incomplete; no consistent review.
Controls are written down; ownership is assigned; review cadence is defined.
Controls are followed in practice; evidence is collected; deviations are tracked.
Control effectiveness is measured against documented thresholds; trends are reported.
Controls evolve based on incident learning; maturity gains are evidenced over time.