SDLC AI Capability Scorecard

A snapshot of how systematically and safely AI is embedded across each phase of the software development lifecycle — from fragmented, ungoverned experimentation today, to governed, team-wide capability. Each phase is scored on the same 1–5 maturity scale; the gap between baseline and target drives the phased engagement.

How the Scorecard Works

01. Score Each Phase

Rate each of the seven SDLC phases 1–5 for how systematically and safely AI is applied today. Use half-points (e.g. 2.5) where a phase sits between two levels.

02. Capture the Evidence

Every score is backed by a concrete observation, such as tool adoption, a workflow, or a policy, not a gut feel.

03. Set a Target

Typically one to two levels up, chosen deliberately rather than defaulting to "as high as possible."

04. Re-measure at Handover

Baselines are established in Phase 1, Assess & Quick Wins, and re-measured at handover so improvement is demonstrable against the Value Realisation Framework.

Five Levels of Maturity

Each level builds on the last, from ad-hoc individual use to an AI-native SDLC where agents and MCP are integral to delivery.

Level 1

Exploring

Ad-hoc individual use; no shared standards or visibility.

Level 2

Experimenting

Some developers trialling AI; inconsistent, ungoverned.

Level 3

Operationalising

AI in daily workflows with policies and quality gates.

Level 4

Scaling

Standardised, reusable patterns and playbooks across teams.

Level 5

Transforming

AI-native delivery; agents and MCP integral to the SDLC.

AI Capability by SDLC Phase

Each phase is scored on its own. Strong coding assistance doesn't offset an ungoverned review process or untested code reaching production.

design_services

Requirements & Design

AI-assisted requirements analysis, user-story generation, design review and critique.

code

Coding & Refactoring

AI pair programming, code generation from specs, intelligent refactoring.

rate_review

Code Review

Automated review workflows, AI-generated feedback, consistency and security scanning.

bug_report

Testing

AI-generated test cases, edge-case identification, coverage analysis, regression expansion.

description

Documentation

Automated API docs, inline comments, architecture decision records.

sync

CI/CD & Quality Gates

AI-integrated pipelines, automated quality checks, deployment risk assessment.

inventory_2

Developer Enablement

Curated prompt libraries, team playbooks, reusable templates for common tasks.

Target Outcomes

What closing the gap is actually meant to deliver, beyond a higher score.

check

Developer Productivity

Meaningful improvement in output per developer.

check

Cycle Time

Reduced feature delivery time.

check

Code Quality

Improved test coverage, fewer defects in production.

check

Developer Satisfaction

Reduced toil, more time on high-value work.

check

Governed Usage

Clear policies, quality gates and compliance controls in place.

check

Self-Sustaining Capability

Internal champions, prompt libraries and a community of practice.

Next step

Walk Through Your Results With Us

Share a few details below and we'll set up a time to go through your SDLC results together, what they mean, and what a phased engagement would actually involve for your team.

Stay up to date
*
*
*
*
*
Thank you! Your submission has been received.
Please try again. Ensure all required fields are completed.