The Vivid Governance Maturity Index: Navigating the 5 Tiers of IT Oversight
Not all governance is created equal. We break down the 5 levels of the Vivid Governance Maturity Index and how to move from "Informal" to "Optimized" oversight.
The Maturity Problem
Most organisations measure IT success by uptime or project completion. However, from a governance and risk perspective, the most critical metric is Maturity—the degree to which your processes are defined, measured, and controlled.
Introducing the VGMI
The Vivid Governance Maturity Index (VGMI) is our proprietary framework for assessing how “defensible” an organisation’s technical operations truly are. It is based on a synthesis of COBIT 2019 principles and the CMMI (Capability Maturity Model Integration).
The Five Tiers of Maturity
Each tier is a band on your Vivid Maturity Index, and these are the actual
cut-offs the product uses — the same ones the report headline, the dashboard and
every domain row read from (MATURITY_TIERS in lib/scoring.ts):
| Tier | Name | VMI |
|---|---|---|
| 1 | Initial | 0–34 |
| 2 | Repeatable | 35–54 |
| 3 | Defined | 55–74 |
| 4 | Managed | 75–89 |
| 5 | Optimized | 90–100 |
Tier 5 starts at 90, exactly where the Certificate of Diligence's score condition does (90) — and that is not a coincidence. The certificate threshold is derived from this table rather than written down separately.
Tier 1: Initial (Hero-Based)
At this level, IT processes are undocumented and inconsistent. Success depends on the specific knowledge of individual team members. If a “Hero” leaves, the governance knowledge leaves with them. This is the highest risk tier.
Tier 2: Repeatable (Disciplined)
The organisation has established basic processes for specific projects or departments. While not yet consistent across the entire enterprise, there is a “muscle memory” forming around certain controls like backups or access requests.
Tier 3: Defined (Standardised)
This is the baseline for “Audit-Readiness.” Processes are formally documented, approved by management, and communicated to all staff. Evidence is collected centrally rather than living in individual email inboxes.
Tier 4: Managed (Quantitative)
At Tier 4, the organisation doesn’t just “do” things; it measures them. Controls are monitored with technical metadata (e.g., automated configuration scans, sign-in logs). Decisions are made based on data rather than intuition.
Tier 5: Optimized (Continuous Improvement)
This is the “Gold Standard.” The organisation uses a Governance Rhythm to continuously improve its posture. Feedback loops from incidents and audits are automatically fed back into policy refinement.
Why Maturity Matters for Your Board
Boards are increasingly held accountable for “Negligent Oversight.” Being at Tier 1 or 2 is a signal of management negligence should a major breach occur. Moving to Tier 3 and beyond provides the Board with a defensible narrative of professional diligence.
How to Progress
- Intake: Use the platform to identify your current Tier.
- Document: Move from Tier 2 to Tier 3 by formalizing your “informal” but repeating processes.
- Automate: Reach Tier 4 by logging references from your technical stack (M365, AWS) in the Evidence Registry as you answer each control (direct technical-stack integration is on our roadmap, not yet built).
- Govern: Achieve Tier 5 by maintaining a schedule of continuous review and metadata-driven monitoring.
Conclusion
Maturity is a journey, not a destination. By using the VGMI as your compass, you can rotate your IT function from a “cost center” into a “governed bridge”—one that builds trust with partners and regulators alike.