Maturity is a statement about repeatability, not about tooling. An organization where the monthly report is correct because a specific analyst knows which three columns to ignore is immature regardless of its technology budget. One where the same report is produced correctly by whoever is on duty, with the exceptions documented, is mature. The distinction is whether knowledge lives in people or in the process.

In practice. Maturity is worth assessing per capability, not as one number. You can be genuinely strong on metadata and weak on quality, and the average of the two tells you nothing you can act on. Assess the capabilities, pick the two that block the nearest business outcome, and leave the rest.

Where it goes wrong. Maturity becomes the goal. Nobody has ever received budget for moving from 2.1 to 2.6; they receive budget for closing a regulatory finding or unblocking a launch, and maturity improves as a by-product. Present the assessment as a diagnosis, never as an objective.