Blog · AI Readiness / NLQ

Five Questions That Grade Your TBM Governance

Before Your CIO Does

Sometime this year, most Technology Business Management (TBM) and IT Finance leaders will field a version of the same question from their CIO: can we put AI on top of our data? The honest answer is rarely yes or no; it is a governance grade.

A governance gauge spanning Ramping, Maturing, and Innovating stages of AI readiness

Here are five questions that produce that grade in about ten minutes, followed by what each grade means you can responsibly do.

  1. Who owns reconciliation between the CMDB and the TBM model? A name is a good sign. "The team," or a pause, is not.
  2. What triggers a reconciliation, a calendar or a complaint? Programs where discrepancies surface because a stakeholder noticed one are running governance in reactive mode, whatever the org chart says.
  3. Can you trace any cost allocation to source data on demand, or does a trace require an analyst assembling it specially?
  4. Where do discrepancy resolutions live? In a documented workflow, or in the institutional memory of whoever fixed them?
  5. How would you know a Resource Tower count had drifted? Would a control catch it, or would a wrong number in a meeting catch it?

Three Profiles

Score the answers honestly and three profiles emerge. Mostly reactive answers put a program at Ramping: governance exists informally, reconciliation is manual and complaint-driven, and turning on NLQ would be an exposure event, because every latent discrepancy that used to surface occasionally in a report would surface instantly, on demand. Named owners and calendared cadences, but manual traces, put a program at Maturing, where most enterprise programs genuinely sit. That is a workable foundation for a scoped pilot on specifically validated towers and pools, though not for organization-wide access. Standing workflows, on-demand traceability, and automated drift detection describe Innovating, the only stage at which an NLQ answer can be trusted without someone quietly double-checking it.

A governance gauge spanning Ramping, Maturing, and Innovating stages of AI readiness

The value of the grade is the sentence it lets you say. "We are Maturing: our top five cost pools are validated and ready for a pilot, our long-tail towers still reconcile manually, and we are scoping access accordingly" is a defensible position that survives scrutiny. "We think we're ready" is not a position at all.

The data says governance, not technology, is where the gap actually lives. In TBM Council research, 80 percent of TBM practitioners report a clear plan for managing AI costs, against 33 percent of organizations without TBM. That is the same discipline gap that separates the Council's "Deep Diver" programs, which report three to seven times the impact of shallow adopters in the 2025 State of TBM. And with 76 percent of organizations planning to invest more in data quality management over the next one to three years, the honest question is not whether to fund the governance work, but whether it gets funded before or after the first bad AI answer.

FogLifter®'s role in this progression is to operationalize the stage transitions rather than merely audit them: the Count, Caliber, and Cost framework turns Ramping-stage manual reconciliation into a Maturing-stage cadence, and its standing validation workflow and drift detection supply the continuous controls that define Innovating. But the five questions come first, and they cost nothing. Ask them this week, before someone senior asks you.

The whitepaper behind this blog

For a deeper look at the validation framework and a step-by-step pre-launch checklist, read the full whitepaper: The AI Readiness Assessment for TBM Programs.

Read the Whitepaper

Frequently Asked Questions

Only after targeted validation of a very small scope, such as a single tower and its associated pools, effectively borrowing Maturing-stage discipline for one slice of the model. Broad access at Ramping converts every latent discrepancy into an instantly queryable wrong answer.

For data exposed to unsupervised querying, yes, but "everywhere" can arrive tower by tower. The practical path is expanding NLQ access as each tower and pool reaches continuously validated status, not holding the entire rollout for uniform maturity.

It grades the processes that keep quality intact (ownership, cadence, traceability, and drift detection) rather than sampling the data itself. Data quality describes today; governance maturity predicts whether today's quality survives the quarter.

Related Resources

Continue reading on connected topics from FogLifter®.

See FogLifter® in action

Book a 30-minute demo to see how validated IT data changes the cost-of-IT conversation.

Book a Demo More blog posts