Use a Maturity Model to Diagnose Asymmetry, Not to Climb
The QA work I was proudest of mapped to a Level 5 process area — in an organisation with no test policy, no strategy and no monitoring reporting. That gap is the finding.
The QA work I am proudest of is a Level 5 process area.
The same organisation has no test policy, no test strategy, no test design model and no monitoring and control reporting. Holes right through Level 2.
I did not discover that by being clever. I discovered it by putting the programme next to TMMi and reading the map honestly, which took an afternoon and was mildly humiliating.
What the Map Showed
Escape analysis. Pattern banking — turning recurring defect shapes into named, reusable knowledge. Live leakage dashboards showing where defects were getting past which gate.
That is Defect Prevention, and Defect Prevention sits at Level 5. It is the top of the model, the part organisations spend years working towards.
Underneath it: nothing written down about what testing is for on this programme. No document anyone could point to that says how testing is approached, what it is expected to achieve, or what happens when it cannot. No agreed model for how test conditions are derived. No routine reporting through which any of those dashboards were actually reviewed by anybody.
The most advanced practice in the function was several levels above the weakest foundational one. Both facts were true on the same day, in the same team, produced by the same person.
Why Nobody Sees This From Inside
Because sophisticated analytics feel like maturity.
They produce artefacts. Charts, categorised defect banks, trend lines that go in a direction someone can react to. They are the kind of output that gets shown in a steering meeting and generates approving noises. Nobody in that meeting is thinking about test policy, because a policy document has never once made a room say "oh, that's interesting."
So the signal you get back is uniformly positive, and it is positive about the exact thing that is furthest ahead. Nothing in the feedback loop points at the floor. The floor is invisible precisely because everyone is looking at the ceiling.
There is a second reason, and it is less comfortable. The advanced work is the interesting work. Given a free afternoon, I will build another analytical layer before I will write a test policy, every single time, and I will have a good reason ready for why that was the higher-value choice.
What a Level 5 Practice Without a Level 2 Floor Actually Is
It is one person's side project. Not a process.
Three things follow from that, and each of them is a specific failure rather than a general worry.
The numbers have nowhere to go. Defect Prevention produces findings, and findings need a reporting cadence to be acted on — that is what monitoring and control gives you. Without it, the analysis lands in whichever conversation the analyst happens to be in that week, and its influence depends on who was listening.
Nothing defines what the numbers are steering towards. A policy is what states the objective. Without one, leakage going down is good and leakage going up is bad, and that is the whole of the interpretation available. There is no threshold, no target, no agreed consequence — so the data can describe the programme but cannot direct it.
And it evaporates. Everything in that layer lives in the practices, judgement and habits of the person who built it. The day that person leaves, there is no policy to inherit, no strategy that names the activity, no reporting line that would notice it stopped. The dashboards keep rendering for a while and then quietly stop meaning anything.
The Rule
Use a maturity model to diagnose asymmetry, not to climb.
The climbing reading — "we are at Level 2, next stop Level 3" — is the one everybody starts with, and it is the least useful thing the model does. It turns into a certification exercise, it invites box-ticking, and it produces an argument about which level you are really at that consumes more energy than any of the improvements would have.
The diagnostic reading is different. You are not looking for your level. You are looking for the distance between your strongest practice and your weakest foundational one, because that distance tells you what kind of organisation you are: one with a process, or one with a few talented individuals compensating for the absence of one.
Running the Diagnosis
- Map what you actually do, not what your documentation claims. List the QA activities that genuinely happen every sprint, then find each one in the model. Be strict — an activity that happens when someone remembers is not a practice.
- Find your highest and your lowest, and write both down side by side. The pair is the finding. One number tells you nothing; the gap between them tells you whether your best work is supported or suspended.
- For every advanced practice, name the foundational one it depends on. Escape analysis depends on a reporting cadence. Pattern banking depends on an agreed model for how test conditions get derived. If the dependency is missing, the advanced practice is running on the goodwill of whoever maintains it.
- Build the floor underneath what you already do, before adding anything on top. This is the unglamorous conclusion and it is the correct one. A test policy that gives the existing dashboards a purpose is worth more than a second dashboard.
Why the Honest Version Is Hard to Say Out Loud
Because it reads as an attack on your own best work, and it is not.
The Level 5 practice is real, it found real defects, and it should not be dismantled. The problem is not that it exists too early. The problem is that it exists alone — and alone means fragile, unreviewed and personal rather than organisational.
That framing is also the one that makes the conversation possible with a delivery lead. "We are immature" invites defensiveness and a debate about levels. "Our most advanced QA practice has no policy above it and no reporting cadence around it, so it disappears if I get hit by a bus" is a risk statement, and risk statements get acted on.
Map your own function this week. What is your strongest practice, what is your weakest foundational one — and how many levels apart are they?