Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
framework

AI Governance Reference Blueprint.

Every published AI governance framework assumes a chief risk officer, a model validation function and an internal audit department. Applied to a company of 200 to 1,000 people they produce an artifact that is admired, filed and ignored, because the operating model they describe needs roles you do not have and will not hire. This blueprint starts from the opposite constraint: total governance capacity is roughly one full-time equivalent spread across four people who have other jobs. Everything that does not fit inside that budget has been left out deliberately and named, so you know what you are not doing and why.

In depth

Well-Built Controls With No Mandate Underneath Them.

01

What happens by default: you start at the control layer.

It is the concrete part, so an evaluation tool gets bought, a control checklist gets written, and a workshop on responsible AI principles gets run. Six months later there are controls nobody is required to follow, applied to a system list nobody maintains, approved by nobody with authority to stop a launch. The documents are good and the programme is decorative, and the first customer security review finds that out faster than you will.

In shortThe documents are good and the programme is decorati…
02

What good sequencing does: it builds the layers in order.

Mandate first, because a named owner with written authority to pause a launch is what separates a governance function from an advisory one, and advisory loses to shipping deadlines every time. Then policy, then a single intake and register, then controls inside the delivery workflow, then assurance. Governance runs on the rails teams already use, which means the ticket queue, the pull request and the procurement workflow rather than a new portal. And the evidence index starts in week one, because it is the only artifact in the programme that cannot be caught up later.

In shortAnd the evidence index starts in week one, because i…
The detail

What Makes This An Operating Model, Not A Policy Library.

Three design principles carry most of the weight. Each one rules out a specific way these programmes normally fail.

Zone · 01

Tiering that earns its keep

Five dimensions scored on the highest rather than the average: decision impact on people, autonomy, data sensitivity, exposure and regulated context. Tier then drives fourteen named requirements, from evaluation depth to approval level. A limited-risk use case should move faster because it was tiered, not slower. Uniform review for everything reliably converts governance into a queue teams learn to route around.

Zone · 02

One front door

one register

A single intake built into the ticket system teams already live in, and a single authoritative register fed by a defined trigger rather than an annual sweep that is stale within a month. Completeness is measured against an independent sweep run by somebody who does not own the register, otherwise coverage is always 100% and always wrong.

Zone · 03

Evidence as a by-product

The artifact an auditor wants is produced by doing the work: the intake ticket with its tier field, the CI run linked to a model and dataset version, the approval comment on the release ticket, the alert rule configuration. Never a retrospective memo. An experienced auditor treats that as an absence of evidence rather than weak evidence.

By the numbers

The figures that make it a board-level conversation.

5
layers, built in order, because each one consumes the output of the layer above
70/25/5
the tier split a calibrated rubric produces across limited, elevated and high risk
5-7 months
realistic elapsed time to a defensible baseline with AI already in production
Inside the report

What you'll take away.

01

Step 1 - Write the mandate down and publish it

Name the accountable owner, stand up the governance group, and publish the decision-rights matrix including the authority to pause any production AI system without prior approval.

02

Step 2 - Build the register before the policy

Policy written without knowing the estate is written against an imagined company. Sweep spend, SSO logs and dependencies, then tier what you find.

03

Step 3 - Put intake in the tool teams already use

One front door as a ticket type, with the tiering rubric applied at entry and tier driving what happens next rather than everything getting the same review.

04

Step 4 - Start the evidence index in week one

Map each control to the artifact that proves it and where it lives. Begun early it costs minutes a week; reconstructed before an audit it costs a quarter.

Questions

Frequently asked.

Do we need an AI ethics board or committee?

Not at this scale. Separating ethics from the group that holds decision rights produces advice without authority, and those bodies typically meet twice and dissolve. Put ethical judgement inside the governance group where it can actually stop a launch. Revisit if you deploy consumer-facing AI at population scale.

Should we buy an AI governance platform?

Not in year one. The register, intake and evidence index all work in tools you already own, and buying early encodes requirements you have not discovered yet. The genuine gap is control testing and audit workflow, which only becomes pressing once certification is committed. Defer until the register passes roughly fifty systems.

Centralised or federated?

Centralised policy, tiering and register; federated execution. The central function owns the rubric, the register and high-risk decisions. Each product team names a point of contact who runs the earlier gates for their own work. Fully centralised bottlenecks past about four teams; fully federated produces five incompatible readings of the same policy.

How does this map to NIST AI RMF and ISO 42001?

It is built to satisfy both without restating either. Anchor to NIST AI RMF for the risk structure and vocabulary, and build ISO/IEC 42001-compatible so certification stays a six-month option rather than a rebuild. The five layers already cover most of what 42001 expects structurally.

We already have AI in production. Is it too late?

No, but the sequence changes. Run intake and tiering retrospectively across everything to produce a tiered register in two to three weeks. Then apply the full gate sequence to high-risk systems as a production audit, four specific checks to elevated-risk ones, and register entry only to the rest. Everything new gets the full sequence.

What does this cost to run once built?

Roughly 0.68 of a full-time equivalent annually, spread across six people, of which about a third is effort you already spend unsystematically on customer questionnaires and ad hoc evaluation. Net new is closer to 90 to 100 person-days a year.

Get the framework

Have it emailed to you.

Drop your details and we'll send AI Governance Reference Blueprint straight to your inbox - no spam, unsubscribe anytime.

Download framework
Next step

The blueprint is the target. The gap is the plan.

Score yourself first, then bring the gap to our engineering leads and we will sequence it against your delivery calendar. A working session, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions

Talk to our engineers