Jerry Luftman's Strategic Alignment Maturity Model assesses how mature an organization's business-IT alignment is across six criteria (communications, competency/value measurement, governance, partnership, scope and architecture, and skills), scored on a five-level maturity scale. What is this kind of maturity model actually useful for, and what's the risk of relying on it as the primary way to manage alignment?
answer
- Luftman SAMM, six criteria
- 5-level maturity scale
- profile not single score
- governance/partnership often the real bottleneck
- Goodhart's law risk with self-reported scores
basics
~20 sThis model scores a company from 1 (worst) to 5 (best) on six areas like communication and governance, to show roughly how mature its business-IT relationship is and where the weak spots are. The risk is that chasing a higher score can become the goal itself, instead of actually improving how well IT helps the business.
solid answer
~50 sLuftman's SAMM (Strategic Alignment Maturity Model) operationalizes the fuzzy idea of 'alignment' into six assessable criteria — communications, competency/value measurement, governance, partnership, scope and architecture, and skills — each scored on a 1-5 maturity scale (from ad hoc to optimized), producing both an overall score and a profile showing which specific criteria are lagging. It's genuinely useful as a diagnostic and a common vocabulary: it gives a CIO and business leadership a structured way to talk about where the relationship is weak (e.g., 'we're mature on architecture but immature on shared governance') rather than a vague sense that 'IT and the business don't get along.' The risk is treating the score itself as the objective — running periodic self-assessments that creep upward each cycle without any corresponding change in actual business outcomes, because the assessment is largely self-reported and survey-based, making it vulnerable to the same Goodhart's-law dynamic as any metric that becomes a target.
go deeper
Should understand that alignment can be broken down into measurable areas rather than treated as one vague feeling, without needing to name all six criteria.
Should be able to name a few of the six criteria and explain why a profile of scores is more actionable than one number.
Should be able to identify which criterion is the actual bottleneck in a given scenario and argue why fixing it (not the highest-visibility one) should be prioritized.
Should be able to run or sponsor a maturity assessment as a baseline for a transformation program, guard against score-gaming by validating against independent outcome data, and decide investment sequencing across the six criteria.
## The gap SAMM fills Jerry Luftman developed the Strategic Alignment Maturity Model (SAMM) in the early 2000s as a direct response to a real gap in the alignment literature: the Henderson-Venkatraman Strategic Alignment Model is excellent at describing what alignment structurally consists of — four domains, strategic fit, functional integration — but it doesn't give an organization a way to measure how well it's currently doing, or a roadmap for improving. ## The six criteria SAMM fills that gap by decomposing alignment maturity into six assessable criteria. - **Communications** maturity asks whether business and IT understand each other's environment, share knowledge fluidly, and use a common vocabulary, versus IT and business speaking past each other in separate jargons. - **Competency/value measurement** maturity asks whether the organization has metrics that actually connect IT activity to business value (versus purely technical metrics like uptime that say nothing about business impact). - **Governance** maturity asks whether decision rights, budget authority, and prioritization for IT investment are shared and formalized between business and IT, versus IT unilaterally deciding or business unilaterally dictating with no real dialogue. - **Partnership** maturity asks whether IT is treated (and treats itself) as a trusted co-owner of business outcomes versus a pure order-taking service function. - **Scope and architecture** maturity asks whether IT's architecture is positioned to enable business agility and evolve with strategy, versus a legacy architecture that constrains what the business can do. - **Skills** maturity asks whether the organization has the human capability — technical and business-facing — to execute on alignment, including whether IT staff are rewarded and retained for business-facing skills, not just technical depth. ## The scale, and why the profile beats the number Each criterion is scored on a five-level maturity scale, structurally similar to CMM-style maturity models: | Level | What it describes | |---|---| | **level 1** | essentially ad hoc or non-existent (no shared process, communication happens by accident) | | **level 3** | typically 'established and focused' (the process exists and is followed in the areas it covers) | | **level 5** | 'optimized' (the practice is continuously improved and deeply embedded, alignment is self-sustaining rather than requiring active intervention) | An organization typically doesn't score uniformly across all six — the useful output isn't a single number but a profile, and the profile is the actual diagnostic value: a company might be a 4 on scope and architecture (a genuinely flexible, modern platform) but a 2 on governance (no real joint decision-making process), which tells leadership exactly where the next investment of effort should go, rather than a vague mandate to 'improve alignment.' ## Why a maturity model exists at all The reason this kind of model exists at all is that 'business-IT alignment' as a phrase is otherwise unfalsifiable — everyone agrees it's good, nobody can point to evidence of having more or less of it, and improvement initiatives have no way to show progress. A maturity model converts a fuzzy aspiration into a repeatable assessment (usually a structured survey or facilitated workshop with both business and IT stakeholders scoring each criterion) that can be rerun periodically and compared over time, giving change programs a before/after story and giving leadership a shared vocabulary for what specifically needs attention. ## The real risk — the score becomes the target The real risk, and the reason a principal-level architect should treat this as a diagnostic tool rather than a management objective, is Goodhart's-law-style metric gaming: because SAMM scores are largely self-reported through workshops and surveys, and because the assessment itself becomes visible to the same leadership whose performance it reflects, there's a structural incentive for the score to creep upward each cycle regardless of whether the underlying relationship actually improved. A governance score can rise because a committee started meeting monthly and dutifully checking a box, without that committee's decisions changing in substance. This mirrors a broader failure pattern with any maturity model (CMMI has the identical problem in software process): organizations optimize for passing the assessment rather than for the outcome the assessment was meant to proxy for. ## How to use it correctly The correct way to use SAMM is as one input alongside outcome-based evidence — actual business KPIs, project success rates, stakeholder satisfaction surveys taken independently of the maturity assessment itself — rather than as the primary target. A principal-level use case is: 1. running SAMM (or an internal variant) once as a baseline before a major transformation program, 2. using the profile to decide which one or two criteria to invest in first (governance and partnership are frequently the actual bottleneck, not architecture, even though architecture is what gets the engineering attention), 3. and then validating improvement against independent business outcomes rather than a re-run of the same self-reported survey, to avoid measuring the map instead of the territory.
- Why is a profile of six scores more useful than one blended alignment score?A single blended number can hide that an organization is excellent in one area and terrible in another, averaging out to a mediocre-looking overall score that gives leadership no idea where to actually invest. The profile makes the specific bottleneck (often governance or partnership, not the technology itself) visible, which is what determines what leadership should fund next.
- How would you validate that a rising SAMM score reflects real improvement rather than assessment gaming?Cross-check the self-reported score against independent, outcome-based evidence collected separately from the assessment itself — project success rates, stakeholder satisfaction surveys run by a different team, or business KPI trends the alignment effort was meant to move. If the maturity score rises but none of those independent signals move, that's a strong indicator the score is measuring participation in the assessment ritual rather than a real change in the relationship.
It's like a personal fitness assessment with six separate scores (cardio, strength, flexibility, nutrition, sleep, recovery) instead of one vague 'fitness level' — genuinely useful for spotting that your strength is a 4 but your sleep is a 1, but if you start gaming the sleep-tracker app to get a better score instead of actually sleeping more, the number goes up while the thing it was supposed to measure doesn't.
saying these in an interview costs you the question
- Treats the maturity score itself as the success metric for an alignment program
- Cannot name more than one or two of the six criteria
- Assumes a single blended score is as useful as the criterion-by-criterion profile
- Never validates the self-reported score against independent business outcomes
- Assumes architecture/technology is always the lagging criterion, ignoring governance and partnership