The world's best AI frameworks were designed for the Fortune 500. What about everyone else?
The AI maturity frameworks from McKinsey, BCG, Accenture, Gartner and the cloud vendors are sound and they work — but they were designed for organisations with a multi-year horizon, dedicated teams per business domain, and the budget for a diagnostic phase lasting several months. The mid-sized Latin American company needs that same rigour delivered at a different scale: per process rather than per whole domain, and with an entry point of under an hour rather than several months.
This is what we found reviewing each framework one by one, and what we built to close that gap.
The figure that frames the conversation
Latin America adopted artificial intelligence faster than expected. What did not follow was the capture of value.
The World Economic Forum report produced with McKinsey is explicit: only 23% of organisations in the region generate measurable economic value from generative AI, and six out of ten SMEs capture none at all. At the same time, the regional AI market went from around USD 29.5 billion in 2025 to a projected USD 40.5 billion in 2026.
There is money and there is enthusiasm. What is missing is the result.
And the gap has a specific shape depending on company size. An analysis based on more than five thousand real subscriptions to AI platforms in Brazil, Mexico and Colombia found that SMEs record an adoption rate of 11.3%, while the mid-market and large corporates exceed 20%. In Colombia that asymmetry weighs especially heavily, because micro, small and medium-sized businesses account for more than 90% of the business fabric.
Another regional figure helps explain why: Latin America accounts for just 1.1% of global investment in artificial intelligence despite adoption rates comparable to or above the world average.
That combination —high adoption, low investment, little value captured— defines the real problem. And it is not solved with more technology.
The frameworks exist and they are good
It is worth saying so without ambiguity, because the easy argument would be the opposite: the global methodological offering is excellent. The major strategy firms published sophisticated frameworks backed by thousands of projects. The cloud vendors published detailed operational guides. Certifiable international standards exist.
None of that is wrong. We reviewed it carefully before building our own, and much of what we do comes from there.
Here is the tour, framework by framework: what each one proposes, what makes it valuable, and who it was designed for.
The strategy firms' frameworks
McKinsey · Rewired
What it proposes. Rewired is less a maturity model than a transformation manual. It organises the work around six capabilities that have to be developed together: a business roadmap tied to value, digital talent, an operating model capable of delivering quickly, distributed technology, data treated as a product, and adoption with managed scaling.
What makes it valuable. Three things.
The first is the unit of work. McKinsey does not organise transformation around isolated use cases but around business domains —a complete customer journey, an end-to-end process— and requires every domain to have an owner with authority over the outcome. It is a direct correction to the pattern of the organisation that accumulates twenty disconnected pilots.
The second is the economic link: the initiative is tied to a line of the income statement with a named owner. Not to an innovation objective, but to a number somebody has to defend.
The third is treating data as a product, with an owner, an internal customer, measured quality and a lifecycle. It is an idea that sounds bureaucratic and that solves the most common problem of all.
Its central finding is consistent with all the evidence that followed: the differentiators of successful transformations were organisational —workflow redesign, training people, sustained executive commitment— and not technology decisions. Its own measurement found that high-performing organisations redesigned processes thoroughly at close to three times the rate of the rest.
Who it was designed for. For the corporation that can sustain a multi-year transformation, dedicate whole teams to each domain, and absorb a diagnostic phase of several months before building anything.
BCG · AI@Scale and the 10-20-70 rule
What it proposes. BCG contributes the most cited principle in the whole literature and probably the most useful: 10% of the value of an AI initiative comes from the algorithms, 20% from technology and data, and 70% from people and processes. Its analysis of obstacles in real transformations follows the same proportion.
What makes it valuable. It reorders the entire conversation. If 70% of the outcome depends on people and processes, then "which model should we use?" is the least important question in the room — and yet it is the one that takes up 80% of the time in most meetings.
The framework also draws a precise distinction between three different ambitions that are routinely conflated: deploying individual productivity, redesigning whole functions, and reinventing the business model. These are projects with different economics, risk and horizon, and treating them alike is a frequent source of disappointment.
BCG also documented the state of the market honestly. Its review of the value gap found that most organisations generate no material value despite sustained investment, and that only a very small minority capture substantial value at scale.
Who it was designed for. For organisations able to reorganise whole functions. The 70% of effort on people and processes assumes a change-management function that exists and has its own budget.
Accenture · The Art of AI Maturity
What it proposes. A normalised index from 0 to 100 built on two layers: foundational capabilities —data, AI, cloud— and differentiating capabilities —organisational strategy, responsible AI, top-level sponsorship, talent and culture. The result places the organisation in one of four archetypes, from the one that experiments to the one that achieves sustained results.
What makes it valuable. It is the best communication instrument of the set. A number and a name travel through an organisation; a twelve-dimension radar does not. An executive remembers "we are at 42 and we are builders" and repeats it in the next meeting. That moves budget.
Its other contribution is treating responsible AI as a differentiating capability rather than a compliance requirement. In 2022, when it was published, that was an advanced position. Today it is self-evident.
Who it was designed for. For the segment Accenture serves: large organisations able to benchmark their performance against global peers and to act on that comparison.
Gartner · AI Maturity Model
What it proposes. Five levels —awareness, activity, operation, systematisation, transformation— assessed across seven pillars including strategy, product portfolio, governance, engineering, data, operating model, and people and culture.
What makes it valuable. It is the shared vocabulary. When an organisation says "we are at level 2 and we want to reach 3", the conversation is understood across departments without translation. That common language is more useful than it appears: much organisational paralysis comes from each area describing the same situation in different words.
Gartner also offers a piece of self-criticism worth more than many complete frameworks: an organisation does not have a single maturity level. The aggregate corporate score hides exactly what a leader needs to see —where there is excellence and where there is stagnation. And it points out that most of these models measure inputs, not outcomes.
Who it was designed for. For Gartner's research client: organisations with an enterprise architecture function and formal planning cycles.
The vendors' frameworks
AWS · Cloud Adoption Framework for AI
What it proposes. Assessment across six perspectives: business, people, governance, platform, security and operations. Each breaks down into specific capabilities with maturity levels and associated actions.
What makes it valuable. It is the most exhaustive inventory in existence. It is explicitly designed to judge maturity and drive short-term improvements, with the stated aim of getting past the isolated proof of concept. If the purpose is to leave no capability unassessed, this is where you start.
Its treatment of the operations perspective is particularly useful, because it covers what almost nobody plans for: model observability in production, drift detection, inference cost management and incident response.
Who it was designed for. For architecture teams that have already decided to build and need a complete checklist. And, like every vendor framework, it assumes its own platform.
Microsoft · Cloud Adoption Framework, AI scenario
What it proposes. Six stages: strategy, plan, readiness, governance, security and management. Each with separate checklists for small organisations and for large enterprises.
What makes it valuable. It is the only framework that turns the diagnosis into an ordered path rather than a score. It knows what comes after what.
It also carries one structural decision that deserves to be singled out above the rest. Before choosing technology, it forces every use case to be classified on two axes: whether it improves individual work or automates a business function, and whether it requires a deterministic or a generative system. A process that must produce the same result from the same input is not solved with a generative system, however attractive that may be. Making that decision before choosing a tool avoids the most expensive and most frequent architecture error in the market.
Its limit. It presents the six stages as equivalent steps, which invites treating them as a list to be completed. They are not: governing, securing and managing never end. And it does not define exit criteria per stage, so in practice they overlap.
Anthropic · enterprise adoption guide
What it proposes. A four-stage model centred on aligning people, process and technology, with particular emphasis on data readiness.
What makes it valuable. It corrects a widespread belief: what matters is not the volume of data but its quality, its accessibility and its legal compliance. An organisation with inaccessible petabytes is in a worse position than one with a modest, clean set whose legal basis is settled.
It is a correction especially relevant to the mid-market, where "we do not have enough data" tends to be used as a reason not to start when the real problem is order, not quantity.
The standards: the floor that became a condition of sale
ISO/IEC 42001 defines a certifiable artificial intelligence management system under a continuous improvement cycle. Its relevance grew by an unexpected route: large corporations began requiring it of their suppliers as a purchasing requirement. For a mid-sized company selling to corporates, it stopped being a governance aspiration and became a commercial condition.
NIST AI RMF contributes the risk management methodology under four functions: govern, map, measure and manage. It does not compete with the former. They complement each other, and a published crosswalk exists between the two.
ISO/IEC 23894 develops AI-specific risk management, and ISO/IEC 38507 contributes the governance perspective for the board.
The dominant practice today is not to choose one but to operate with several: ethical principles as the base, the risk framework as the operating model, the certifiable standard as the management system, and European regulation for anyone with exposure to that market.
The comparison table
| Framework | Distinctive contribution | Unit of work | Designed for |
|---|---|---|---|
| McKinsey Rewired | Business domain as the unit; data as a product | Whole domain | Multi-year corporate transformation |
| BCG AI@Scale | The 10-20-70 rule; distinction between three ambitions | Business function | Organisations with established change management |
| Accenture | Normalised index and communicable archetypes | Organisation | Benchmarking against global peers |
| Gartner | Five-level vocabulary across seven pillars | Organisation | Enterprise architecture function |
| AWS CAF-AI | Exhaustive inventory of operational capabilities | Technical capability | Teams that have already decided to build |
| Microsoft CAF | Ordered sequence; deterministic/generative decision | Adoption stage | Planning on its own platform |
| Anthropic | Data quality and accessibility over volume | Use case | Data strategy |
| ISO/IEC 42001 | Certifiable, auditable management system | Organisation | Compliance and selling to corporates |
| NIST AI RMF | Operable risk taxonomy across four functions | AI system | Risk management |
The problem is not the framework. It is the fit.
Here is the observation that puts everything above in order.
None of these frameworks is wrong. They are correctly designed for a client that is not the majority of the Latin American business fabric.
They were built with and for organisations that have three things: the horizon to sustain a transformation lasting several years, the structure to dedicate whole teams to each domain, and the financial slack to absorb a long diagnostic phase before building anything.
A mid-sized Colombian or Mexican company with a process it wants to resolve this half-year lives a different reality:
The horizon is different. The question is not where the company will be in three years, but whether this process can be resolved before the budget, the sponsor or the priority changes.
The structure is different. There is no transformation office. The process owner also runs the operation, and the data lead also answers for the infrastructure.
And above all, the economic sensitivity is different. In a global corporation, a three-month diagnostic is a minor line in the programme budget. In a mid-sized company in the region, a diagnostic costing a significant fraction of the project simply does not get bought — and rightly so. The cost of finding out cannot approach the cost of doing.
That asymmetry explains the figure at the start better than any hypothesis about technological maturity. Six out of ten SMEs in the region capture no value at all from generative AI not because they are unaware of these frameworks, but because the available route in is calibrated for another scale.
The diagnostic gets cited, admired, and never executed.
A specialist from the Inter-American Development Bank put it precisely when analysing adoption among SMEs in the region: there is no successful AI adoption without a settled digital foundation, and institutional support proves crucial in reducing the risk of innovating for small companies. The same survey found something counter-intuitive: the lack of internal experience and qualified staff weighs even more heavily than concern about costs.
In other words: the mid-market does not need a different framework. It needs the same rigour, delivered differently.
What we built
That is the problem we set out to solve, and the proposition is deliberately modest: we did not invent a new theory. We compressed the existing one.
SUMāTO AI Ready takes from each framework what proved to work —BCG's weighting, Gartner's level vocabulary, Accenture's communicable index, Microsoft's sequence, Anthropic's criterion on data, NIST's risk taxonomy, McKinsey's economic link— and delivers it in a format a mid-sized company can actually commission and execute.
Six pillars. None of them is the algorithm.
| Pillar | What it answers | Weight |
|---|---|---|
| Purpose | Is there a business reason, with an owner, a budget and a consequence? | 20% |
| Process | Is the chosen process suitable for AI intervention? | 25% |
| Data estate | Does the raw material exist, with quality, access and permission to use it? | 20% |
| Platform | Does the technology allow building, integrating and sustaining? | 10% |
| People | Will the people who run the process adopt it or reject it? | 15% |
| Protection | Is the risk mapped and governable? | 10% |
Business, process and people add up to 60%. Data and technology, 30%. Risk, 10%. It is the 10-20-70 rule carried into a diagnostic instrument.
The algorithm weighs zero. That is not an oversight: it is a position. That part is our responsibility, not the client's.
Three design decisions that come from the regional reality
First: the unit is the process, not the organisation. McKinsey works by whole domain because its client can reorganise a whole domain. A mid-sized company cannot, and should not try. It starts with one process, resolves it, and uses that credibility to fund the next. The assessment is calibrated to that scale.
Second: the entry point lasts 45 minutes. Not three months. A structured conversation of eighteen questions produces an index, an archetype, a six-pillar radar and three findings. It is less deep than a global firm's exercise — and it is the one that actually gets carried out.
Third: the baseline is mandatory before building. In a context where sensitivity to return is high and budgets are reviewed frequently, not measuring the current cost of the process is equivalent to guaranteeing the project will not survive its first budget review.
And one rule we apply without exception: any pillar at the lowest level triggers a mandatory remediation condition, however high the average. The graveyard of proofs of concept almost always originates in one neglected pillar, not in general weakness.
What this looks like in practice
A framework only matters for what it produces. In the second article of this series we describe, without generalities, what an organisation walks away with when the exercise ends: the deliverables at each level, the baseline that almost never existed, the specification it can use to get quotes from any vendor, and what each role at the board table gains.
Including what it keeps if it decides not to go ahead with us.
Read article 2: "What a client walks away with after an AI readiness assessment".
Sources: World Economic Forum and McKinsey, BCG, Accenture, Gartner, AWS, Microsoft, Anthropic, ISO/IEC 42001, NIST AI RMF, Inter-American Development Bank.
—
Andrés Lozada
Executive Director, SUMāTO Group · Cloud · Infrastructure · Cybersecurity · Digital Transformation
linkedin.com/in/andreslozada/
Keep exploring
- Artificial Intelligence
- Strategic Consulting
- Enterprise Transformation
- Want to see where your company stands? Take the AI readiness assessment.
Frequently asked questions
What is an AI maturity framework?
It is an instrument that assesses how prepared an organisation is to adopt artificial intelligence, normally across several dimensions —strategy, data, technology, governance, people— and produces a level or a score. It serves to locate the starting point and prioritise where to invest first.
What is the difference between a consultancy framework and a vendor framework?
The strategy firms' frameworks assess organisational capability and are oriented towards broad transformations by business domain. The vendors' frameworks describe an operational adoption sequence on their own platform. The first answer where the organisation stands and how it should reorganise; the second, how to advance technically.
What is BCG's 10-20-70 rule?
It is the principle that 10% of the value of an AI initiative comes from the algorithms, 20% from technology and data, and 70% from people and processes. Its practical implication is that the choice of model is the least decisive decision in the project.
Are the big consultancies' frameworks useful for a mid-sized company?
Their principles are; their delivery format is not always. They were designed for organisations with a multi-year horizon, dedicated teams and the capacity to absorb a long diagnostic phase. A mid-sized company needs that same rigour compressed into an exercise proportional to the scale of its decision.
Is ISO/IEC 42001 mandatory?
Not by law, but it is becoming mandatory by market: large corporations require it of their suppliers as a purchasing requirement. It defines a certifiable artificial intelligence management system under a continuous improvement cycle.
Do ISO/IEC 42001 and NIST AI RMF compete with each other?
No. They complement each other and a published crosswalk exists between the two. NIST AI RMF contributes the risk management methodology under four functions —govern, map, measure and manage—; ISO/IEC 42001 contributes the certifiable management system that institutionalises it.
Why do Latin American SMEs capture less value from AI?
The World Economic Forum report with McKinsey found that six out of ten SMEs in the region capture no value at all from generative AI. The documented barriers include an unsettled digital foundation, a lack of internal experience and qualified staff —which weighs even more than cost— and disordered data.
What is SUMāTO AI Ready?
It is SUMāTO's proprietary methodology for assessing an organisation's readiness for artificial intelligence. It integrates the principles of the global frameworks into a format proportional to the Latin American mid-market: it assesses six pillars —Purpose, Process, Data estate, Platform, People and Protection— with the specific process as the unit of analysis, and its entry point lasts between 45 and 60 minutes.