Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
framework

AI Governance Decision Framework.

A blueprint tells you what good looks like. A checklist tells you whether one system is ready. Neither helps with certify or defer, hire or distribute, or how much authority to give an agent. Those are judgement calls with no correct answer, and they are where most of the real difficulty lives. This framework does not make them for you. It names the criteria that should drive each one, supplies a default for the common case, and defines the trigger that should make you reopen the question, which is the part that matters most.

In depth

Right Decisions That Nobody Revisited.

01

What happens by default: these calls get made implicitly.

Each one is settled under whatever pressure is present. Certification decided because a competitor announced theirs. Agent autonomy granted incrementally by engineers removing approval steps to fix workflows, so the system's real authority is something nobody ever wrote down. Customer data in training decided at six in the evening by an engineer with a deadline. And the use case you should have declined discovered after the contract was signed, which is a far worse conversation than the same one held in the abstract.

In shortAnd the use case you should have declined discovered…
02

What good decision-making does: it classifies before deciding.

Reversible and low-stakes gets delegated and moved past, because deciding quickly is worth more than deciding perfectly. Irreversible or expensive to undo gets the full treatment: written record, named decider, executive sponsor. Every entry records who disagreed and why, because that is where the risk you actually accepted is stored. And the revisit trigger is set as a condition rather than a date, because calendar reviews get skipped and conditions fire.

In shortbecause calendar reviews get skipped and conditions fire
The detail

Three Decisions Worth Making Before You Need Them.

Seven of the ten can wait until the question arrives. These three cannot, because each one otherwise gets decided under pressure by whoever is nearest.

Zone · 01

Certify or defer

against demand

A named deal requiring it is decisive. Three or more qualified prospects asking in one quarter is high. Existing ISO/IEC 27001 is high, because marginal cost falls materially. Maturity is gating, since certifying below roughly 112 is expensive theatre. The default is defer, because 42001 attests that you run a management system rather than that any AI system is safe.

Zone · 02

The agent autonomy ceiling

Five levels from advisory through read-only tools, bounded write, approved irreversible and autonomous irreversible. Bounded write is the default ceiling. The operative rule is that autonomy is granted at the tool scope rather than at the agent, because saying an agent is level two means nothing if one of its six tools can send email.

Zone · 03

The four conditions for declining

No lawful basis and none obtainable. A consequential decision about a person with no meaningful route to human review. Performance that cannot be measured against the outcome that matters. Or a use that depends on the user not realising AI is involved. Four, not fourteen: a long prohibited-use list reads as bureaucracy and gets ignored.

By the numbers

The figures that make it a board-level conversation.

10
decisions, each with criteria, a stated default and a revisit trigger
112
the maturity score below which ISO 42001 certification is expensive theatre
$95k-$240k
year-one all-in cost of ISO/IEC 42001 at mid-market scope
Inside the report

What you'll take away.

01

Step 1 - Classify the decision before making it

Reversible and low-stakes gets delegated. Irreversible or expensive to undo gets a written record, a named decider and the executive sponsor in the room.

02

Step 2 - Apply the criteria, then take the default

Each decision compares the real options on what they get right and where they break. Where nothing in your situation argues against it, take the stated default and move on.

03

Step 3 - Record who disagreed and why

The most valuable field in the log. It is where the risk you accepted is actually stored, and the first thing worth rereading when the revisit trigger fires.

04

Step 4 - Set a condition, not a date

Calendar reviews get skipped and conditions fire. Write the specific change in circumstances that should reopen each decision, then let it sit until that happens.

Questions

Frequently asked.

Should we get ISO 42001 certified?

Defer unless a named deal requires it, or three or more qualified prospects asked in a single quarter. It attests that you run a management system, not that any AI system is safe. Build the evidence pack first, because it wins more deals per dollar and is a prerequisite anyway. If you already hold ISO 27001 and score above 112, the calculation shifts.

Do we need to hire an AI governance person?

Usually not. Fund half a full-time equivalent of a named senior person and protect it in planning. The failure mode of distribution is not that the work is done badly but that it is done in whatever time remains, which in a shipping quarter is none. Reduce their delivery commitments by the same amount in writing, or the allocation is fiction.

Can we use customer data in prompts? In training?

Two separate decisions that get collapsed into one. Prompts: permit, with provider training disabled and verified in the console, retention bounded and sensitive classes blocked at the application layer. Shared-model training: prohibit. You cannot remove a customer's contribution from a trained model on request, which makes deletion obligations very hard to satisfy honestly.

How much autonomy should an agent have?

Bounded, reversible writes by default, with scoped credentials, ceilings and a tested rollback. Approved irreversible actions only with a named business owner and a tested emergency stop. Fully autonomous irreversible actions only with written executive sponsor approval and a stated loss tolerance. Grant autonomy at the tool scope, not at the agent.

Should we build this in-house or bring in a partner?

Hybrid. External for the first three layers and the control library, where experience compresses months into weeks. Internal for evaluation, monitoring and incident response, which are specific to your architecture and must be built by people who will operate them. Contract the external part on a handover milestone rather than a document deliverable.

When should we refuse an AI use case outright?

Four conditions. No lawful basis for the data use and none obtainable. A consequential decision about a person with no meaningful route to human review. Performance that cannot be measured against the outcome that matters. Or a use that depends on the user not realising AI is involved.

Get the framework

Have it emailed to you.

Drop your details and we'll send AI Governance Decision Framework straight to your inbox - no spam, unsubscribe anytime.

Download framework
Next step

Decide the agent ceiling before somebody removes an approval step.

Work through the three that cannot wait with our engineering leads, against your own architecture and pipeline. A working session, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions

Talk to our engineers