LoB Latent Maturity Model  ·  for Northstar

We never observe maturity.
We observe checks, and infer θ.

The LoB Latent Maturity Model is how Northstar turns assessment evidence into a maturity number. A Line of Business passes some assessment items and fails others. Each item has a learned difficulty. From that pattern we estimate one hidden number per dimension — how mature this LoB actually is. Here is exactly how that number gets picked, arithmetic and all.

01Three different things

What we see, what we learned, what we infer

These get confused constantly in review meetings. They are separate quantities with separate owners.

Observed
Pass / fail per item
Evidence from the assessment. Auditable, dated, and the only thing anyone actually recorded.
Learned item property
Difficulty  b
How hard an item is, calibrated across every LoB. A property of the question, not of any one LoB.
Latent
Maturity  θ
The hidden capability level of this LoB in this dimension. Nobody measures it directly. We estimate it.

The Rasch model ties all three together with one line: P(pass) = 1 / (1 + e−(θ − b)). When an LoB's maturity equals an item's difficulty, it has a coin-flip chance of passing. Above the difficulty, better than even. Below it, worse.

02Security dimension · LoB Payments

Four items, four difficulties, one observed pattern

Flip any response below. Every number on this page recomputes from what you set here.

Item Assessment check Difficulty scale −2 … +2 b Observed

Item characteristic curves — probability of passing, at every possible maturity

03Candidate sweep

Try five candidate θ values and score each one

For a candidate θ, the model predicts a pass probability for every item. We then ask: how likely is the pattern we actually saw? Pass items contribute P. Fail items contribute 1 − P. Multiply the four together and you get the likelihood of that candidate.

Likelihood across the whole θ range

Likelihood of the observed pattern Best estimate ̂θ
Estimated security maturity
Best of the five candidates

The peak sits near the point where the passed items are comfortably below the LoB's maturity and the failed items are comfortably above it. That crossover is the estimate.

04Common confusion

Weight is not θ

Weight belongs to the framework: how much Security matters in the Northstar rating, set once by architecture governance. θ belongs to the LoB: how mature this one team actually is. Drag the weights — the overall score moves, the θ bars do not.

Dimension
Weight (governance)
w
θ (this LoB)

Northstar rating — LoB Payments

/ 100

Weight changes the question — what this portfolio cares about. θ changes only when the LoB's evidence changes. Raising the Security weight does not make Payments any more secure; it just makes their security gap count for more.

05Second example

Two LoBs, two passes each — same score, different substance

LoB Ledger passes the two easy items. LoB Vault passes the two hard ones. A checklist counts both as 2 of 4. Watch what the model does.

Likelihood curves — each scaled to its own peak, so both are readable

LoB Ledger — passed S1, S2 LoB Vault — passed S3, S4