Every published AI governance framework assumes a chief risk officer, a model validation function and an internal audit department. Applied to a company of 200 to 1,000 people they produce an artifact that is admired, filed and ignored, because the operating model they describe needs roles you do not have and will not hire. This blueprint starts from the opposite constraint: total governance capacity is roughly one full-time equivalent spread across four people who have other jobs. Everything that does not fit inside that budget has been left out deliberately and named, so you know what you are not doing and why.
Three design principles carry most of the weight. Each one rules out a specific way these programmes normally fail.
Five dimensions scored on the highest rather than the average: decision impact on people, autonomy, data sensitivity, exposure and regulated context. Tier then drives fourteen named requirements, from evaluation depth to approval level. A limited-risk use case should move faster because it was tiered, not slower. Uniform review for everything reliably converts governance into a queue teams learn to route around.
one register
A single intake built into the ticket system teams already live in, and a single authoritative register fed by a defined trigger rather than an annual sweep that is stale within a month. Completeness is measured against an independent sweep run by somebody who does not own the register, otherwise coverage is always 100% and always wrong.
The artifact an auditor wants is produced by doing the work: the intake ticket with its tier field, the CI run linked to a model and dataset version, the approval comment on the release ticket, the alert rule configuration. Never a retrospective memo. An experienced auditor treats that as an absence of evidence rather than weak evidence.
Name the accountable owner, stand up the governance group, and publish the decision-rights matrix including the authority to pause any production AI system without prior approval.
Policy written without knowing the estate is written against an imagined company. Sweep spend, SSO logs and dependencies, then tier what you find.
One front door as a ticket type, with the tiering rubric applied at entry and tier driving what happens next rather than everything getting the same review.
Map each control to the artifact that proves it and where it lives. Begun early it costs minutes a week; reconstructed before an audit it costs a quarter.
Not at this scale. Separating ethics from the group that holds decision rights produces advice without authority, and those bodies typically meet twice and dissolve. Put ethical judgement inside the governance group where it can actually stop a launch. Revisit if you deploy consumer-facing AI at population scale.
Not in year one. The register, intake and evidence index all work in tools you already own, and buying early encodes requirements you have not discovered yet. The genuine gap is control testing and audit workflow, which only becomes pressing once certification is committed. Defer until the register passes roughly fifty systems.
Centralised policy, tiering and register; federated execution. The central function owns the rubric, the register and high-risk decisions. Each product team names a point of contact who runs the earlier gates for their own work. Fully centralised bottlenecks past about four teams; fully federated produces five incompatible readings of the same policy.
It is built to satisfy both without restating either. Anchor to NIST AI RMF for the risk structure and vocabulary, and build ISO/IEC 42001-compatible so certification stays a six-month option rather than a rebuild. The five layers already cover most of what 42001 expects structurally.
No, but the sequence changes. Run intake and tiering retrospectively across everything to produce a tiered register in two to three weeks. Then apply the full gate sequence to high-risk systems as a production audit, four specific checks to elevated-risk ones, and register entry only to the rest. Everything new gets the full sequence.
Roughly 0.68 of a full-time equivalent annually, spread across six people, of which about a third is effort you already spend unsystematically on customer questionnaires and ad hoc evaluation. Net new is closer to 90 to 100 person-days a year.
Drop your details and we'll send AI Governance Reference Blueprint straight to your inbox - no spam, unsubscribe anytime.
Score yourself first, then bring the gap to our engineering leads and we will sequence it against your delivery calendar. A working session, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions
Talk to our engineers