Crosswalk

Govern

One demand record, many governance outputs.

The detailed crosswalk: which GOVBRM field triggers which assessment, record or appraisal, who owns it, and what it produces. A GOVBRM original mapping over established frameworks, not yet validated.

GOVBRM cross-framework compiler

Status: draft v0.1, GOVBRM original mapping over established frameworks, not yet validated.

1. What this is

The crosswalk page on govbrm.com shows, stage by stage, which frameworks GOVBRM hands off to. This compiler goes one level down. It takes a specific GOVBRM input (a field on one of the twenty canvases, or a triage answer given at a gate) and states the governance question that input raises, the external framework or process that answers it, the evidence or output that process produces, the role that owns it, and the condition that triggers it. A practitioner running a front door can read across a row and act.

Label: GOVBRM original mapping. The frameworks are established and belong to their publishers. The routing between a canvas field and a framework is GOVBRM's own design and has not been validated in use. Not yet demonstrated. Framework point numbers refer to the published editions at the time of writing; check the current edition before relying on a number.

Two rules apply throughout.

2. How to read a row

ColumnMeaning
Canvas and fieldThe canvas number and field label from the AI Demand Toolkit, or "Triage" for an answer given at the gate rather than on a canvas
QuestionThe governance question that field raises once it has a value
FrameworkThe established framework, standard or process that answers the question
ProcessWhat the practitioner does to route the input into that framework
OutputThe evidence or record that results, in the language the receiving process uses
OwnerThe role that owns the output (job titles vary; substitute your own)
TriggerThe condition under which the row applies at all; if the trigger is absent, the row is skipped
EquivalentsThe closest instrument in the US, EU, Canada, Australia, New Zealand and South Africa, or "check local equivalent"

The lanes still apply. A fast-lane request meets only the Request rows and the published pattern's boundary. A standard-lane request meets Request, Shape, Commit and Review rows as triggered. A strategic-lane request meets every triggered row.

3. Compiler table by gate

3.1 Request gate

Gate: Request (stage Discover into Assess). Canvases 01 Opportunity and 03 Intake, plus lane triage. The aim is to find out what has already happened and to start the assurances that are cheapest when started early.

Canvas and fieldQuestionFrameworkProcessOutputOwnerTriggerEquivalents
01: Outcome to improveIs this an outcome the organisation is accountable for, and is there a user need behind it?Service Standard (point 1, understand users and their needs); Technology Code of Practice (point 1, define user needs); BRM Body of Knowledge (demand shaping)Confirm the outcome against the published performance measure the partner already reports; open or reuse a user research recordOutcome statement with the existing measure named; link to any user research already heldBusiness Relationship Manager with the partner's operational leadAny observation carried towards the Request gateUS: 21st Century Integrated Digital Experience Act and the US Web Design System. EU: check local equivalent. Canada: Government of Canada Digital Standards. Australia: Digital Service Standard. New Zealand: Digital Service Design Standard. South Africa: check local equivalent.
01: Benefit type and Value rangeIs the claimed benefit cashable, efficiency, quality or risk reduction, and in whose budget does it land?Green Book (benefits categories and appraisal); BRM Body of Knowledge (value planning)Classify the benefit type and name the budget holder before any number is quoted upwardsBenefit type, value range and budget holder line on the opportunity statementBusiness Relationship Manager with the finance partnerA value range is written on the canvasUS: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance.
03: Route of arrivalHas the request already passed through, or bypassed, a governance step it should have met?Technology Code of Practice (point 11, define your purchasing strategy); AI Playbook (principle 8, work with commercial colleagues)Check whether a supplier conversation, pilot or trial has already started; if so route to procurement and information security in parallelNote of prior contact and any parallel routingBusiness Relationship ManagerRoute of arrival names a supplier, a pilot or a trialUS: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000.
03: Suppliers and partners involvedIs a supplier already shaping the requirement, and is the organisation exposed commercially?Procurement policy; AI Playbook (principle 8); ISO/IEC 42001 (supplier relationships)Route to the procurement lead for a conflict-of-interest and pre-market engagement checkProcurement note on the intake recordProcurement leadAny supplier named at intakeUS: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000.
03: Procurement or contract positionIs there an existing contract, framework or licence that already covers this, or one that constrains it?Procurement policy; ITIL (supplier management); enterprise architecture (application portfolio)Search the contract register and the licence inventory before any new buying route is discussedContract register reference or a note that none appliesProcurement lead with the enterprise architectMoney committed or assumed is not zeroUS: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000.
03: Money committed or assumedHas money been promised outside the approved spend control route?Spend control (in the UK, the digital and technology spend controls); Green BookCheck the spend control threshold and whether an approval is already requiredSpend control status on the intake recordFinance partnerMoney has been committed or assumed by the requesterUS: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance.
03: Systems it would touchWhich systems, data stores and integrations are in scope, and are any of them critical or legacy?Enterprise architecture (application and data portfolio); Technology Code of Practice (point 9, integrate and adapt); ITIL (service configuration management)Check the systems against the configuration record and the architecture repositorySystem list with criticality and ownerEnterprise architectAny named system on the intake recordEnterprise architecture practice is international (TOGAF is one common method). US: Federal Enterprise Architecture. Canada: Government of Canada Enterprise Architecture Framework. Australia, New Zealand, EU, South Africa: check local equivalent.
03: Adjacent or duplicate demandHas the same need, or the same capability, already been requested or built elsewhere in the organisation?Enterprise architecture (capability map); portfolio management; Technology Code of Practice (point 3, be open and use open source; point 9, integrate and adapt)Search the demand register and the capability map; merge or link where the need matchesDuplicate or merge note on the intake recordBusiness Relationship Manager with the enterprise architectAny request whose problem statement matches an open itemEnterprise architecture practice is international (TOGAF is one common method). US: Federal Enterprise Architecture. Canada: Government of Canada Enterprise Architecture Framework. Australia, New Zealand, EU, South Africa: check local equivalent.
Triage answer: does the request touch a citizen or customer directly?Which lane does the request enter, and which assurances start now rather than later?GOVBRM lanes (fast, standard, strategic); Service Standard; AI Playbook (principle 4, meaningful human control)Assign the lane by consequence, scale, reversibility, population affected and time to notice a failure; public-facing requests default to the standard lane or aboveLane assignment with reasonBusiness Relationship ManagerEvery request at the Request gateUS: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.

3.2 Shape gate

Gate: Shape (stage Assess). Canvases 02 Demand Shaping, 04 Readiness and 05 Risk and Ethics. Most of the assurance routing happens here, because the shaped need, the autonomy rung and the data scope are now known.

Canvas and fieldQuestionFrameworkProcessOutputOwnerTriggerEquivalents
02: Root needIs the need stated as a problem rather than a solution, and is it a whole problem for the user?Service Standard (point 2, solve a whole problem for users); BRM Body of Knowledge (demand shaping)Rewrite the need in the partner's words with the requested solution removed; check against user researchShaped need statementBusiness Relationship Manager with the partner sponsorEvery request entering the Shape gateUS: 21st Century Integrated Digital Experience Act and the US Web Design System. EU: check local equivalent. Canada: Government of Canada Digital Standards. Australia: Digital Service Standard. New Zealand: Digital Service Design Standard. South Africa: check local equivalent.
02: Rung requested and Lowest rung that solves itIs the autonomy requested proportionate, and is a lower rung or a non-AI change sufficient?AI Playbook (principle 6, the right tool for the job; principle 4, meaningful human control); NIST AI RMF (Map)Apply the autonomy ladder; record the lowest rung that solves the task and why one rung lower failsAutonomy rung with justificationBusiness Relationship ManagerRequested rung is above the lowest rung that solves itUS: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
02: What a wrong output touchesWhat is the blast radius of a wrong output, and who bears it?NIST AI RMF (Map, Measure); ISO/IEC 42001 (AI impact assessment); Data Ethics FrameworkDescribe the consequence, scale, reversibility and population affected; feed the result into the lane decision and the risk canvasBlast radius statementBusiness Relationship Manager with the risk leadA wrong output could reach a citizen, customer or a legal decisionUS: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
02: Fix the process instead and Change the rule insteadWould a process, policy or rule change remove the need without AI?Service Standard (point 2); Green Book (do-minimum option); Technology Code of Practice (point 1)Record the non-AI counterfactual as the do-minimum option for the later business caseDo-minimum option noteBusiness Relationship Manager with the partner operational leadEvery request at ShapeUS: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance.
04: Proposed autonomy rungWhich risk tier, impact level or assurance level does the proposed rung imply under the frameworks you follow?NIST AI RMF (Govern); ISO/IEC 42001 (AI system impact assessment); AI Playbook (principle 10, assurance)Map the rung and blast radius to your risk tier or impact level; open the assurance plan at that levelRisk tier or impact level with the assurance plan openedAI assurance lead or risk leadRung is above the lowest, or the request is public-facingUS: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
04: Triage answer: data readiness (quality, access, lineage)Is the data fit, lawful and available for the purpose, and who owns it?Data Ethics Framework; Technology Code of Practice (point 10, make better use of data); ISO/IEC 42001 (data for AI systems)Confirm the data owner, the source of truth and the quality baseline; log gaps as readiness conditionsData readiness statement with ownerData owner with the data governance leadReadiness score marks data as amber or redUS: Privacy Act 1974 and E-Government Act 2002 privacy impact assessment (federal). EU: GDPR Article 35 data protection impact assessment. Canada: Privacy Act and Treasury Board Directive on Privacy Impact Assessment. Australia: Privacy Act 1988 and the Australian Government Agencies Privacy Code privacy impact assessment. New Zealand: Privacy Act 2020 and the Privacy Commissioner's privacy impact assessment toolkit. South Africa: Protection of Personal Information Act 2013 and the Information Regulator's guidance.
04: Triage answer: security readinessDoes the proposed use meet the information security policy, and has the information risk owner seen it?ISO/IEC 27001 (risk assessment and Annex A controls); AI Playbook (principle 3, secure); Technology Code of Practice (point 6, make things secure)Open the security assurance route at the level the data classification requires; record the information risk ownerSecurity assurance ticket or recordInformation security leadAny data above the lowest classification, or any external model providerUS: FISMA, NIST SP 800-53 and FedRAMP. EU: NIS2 Directive. Canada: Policy on Government Security and ITSG-33. Australia: Protective Security Policy Framework and the Information Security Manual. New Zealand: Protective Security Requirements and the New Zealand Information Security Manual. South Africa: check local equivalent.
05: Triage answer: personal data handledIs personal data processed, and is a data protection impact assessment or equivalent required?Data protection law (in the UK, UK GDPR and the Data Protection Act 2018); Data Ethics Framework; Technology Code of Practice (point 7, privacy)Route to the data protection officer for a screening decision; open the DPIA where the screening says soDPIA screening record, and the DPIA itself where requiredData protection officerPersonal data appears anywhere in the data scopeUS: Privacy Act 1974 and E-Government Act 2002 privacy impact assessment (federal). EU: GDPR Article 35 data protection impact assessment. Canada: Privacy Act and Treasury Board Directive on Privacy Impact Assessment. Australia: Privacy Act 1988 and the Australian Government Agencies Privacy Code privacy impact assessment. New Zealand: Privacy Act 2020 and the Privacy Commissioner's privacy impact assessment toolkit. South Africa: Protection of Personal Information Act 2013 and the Information Regulator's guidance.
05: Triage answer: decisions about peopleDoes the system make, or materially influence, a decision with legal or similarly significant effect on a person?Data protection law (automated decision-making provisions); AI Playbook (principle 4); Data Ethics FrameworkRoute to the data protection officer and the legal team; require a human review route and a contestability path before CommitAutomated decision-making assessment and human review designData protection officer with the legal leadDecision affects entitlement, enforcement, eligibility or a similarly significant outcomeUS: due process protections and Administrative Procedure Act review. EU: GDPR Article 22 and AI Act rights to explanation for affected persons. Canada: Directive on Automated Decision-Making recourse requirements. Australia: administrative law review and the Ombudsman's automated decision-making guidance. New Zealand: Algorithm Charter and Ombudsman oversight. South Africa: Promotion of Administrative Justice Act 2000.
05: Rights, entitlements and accessibilityDoes the change affect protected groups differently, and has the equality duty been considered?Equality duty (in the UK, the Public Sector Equality Duty); human rights law; Data Ethics FrameworkOpen an equality impact assessment; add a human rights assessment where liberty, privacy or family life are engagedEquality impact assessment, and a human rights assessment where relevantEquality lead with the policy ownerAny public-facing use, or any use affecting staff termsUS: Title VI of the Civil Rights Act 1964 and agency civil rights offices. EU: Charter of Fundamental Rights and the AI Act fundamental rights impact assessment for public-body deployers. Canada: Canadian Human Rights Act and Gender-based Analysis Plus. Australia: Racial, Sex, Disability and Age Discrimination Acts. New Zealand: Human Rights Act 1993 and New Zealand Bill of Rights Act 1990. South Africa: Constitution section 9 and the Promotion of Equality and Prevention of Unfair Discrimination Act 2000.
05: Rights, entitlements and accessibility (accessibility element)Can everyone who needs to use or be affected by the service do so, including disabled people?WCAG 2.2 AA; public-sector accessibility duties (in the UK, the Public Sector Bodies Accessibility Regulations 2018); Service Standard (point 5, make sure everyone can use the service); Technology Code of Practice (point 2)Add accessibility acceptance criteria to the need statement; plan an accessibility audit before Build closesAccessibility requirements and audit planAccessibility lead with the service ownerAny user-facing interface or outputUS: Section 508 of the Rehabilitation Act and the Americans with Disabilities Act. EU: Web Accessibility Directive 2016/2102 and the European Accessibility Act. Canada: Accessible Canada Act. Australia: Disability Discrimination Act 1992 and the Digital Service Standard. New Zealand: New Zealand Government Web Accessibility Standard. South Africa: check local equivalent.
05: Challenge, human review and redressCan an affected person understand, challenge and get a decision reviewed by a person?AI Playbook (principle 4); Data Ethics Framework; administrative law and complaints proceduresDesign the challenge route, the human reviewer role and the redress path; confirm with the complaints ownerContestability and redress designService owner with the complaints leadAny decision or recommendation reaching a citizen or customerUS: due process protections and Administrative Procedure Act review. EU: GDPR Article 22 and AI Act rights to explanation for affected persons. Canada: Directive on Automated Decision-Making recourse requirements. Australia: administrative law review and the Ombudsman's automated decision-making guidance. New Zealand: Algorithm Charter and Ombudsman oversight. South Africa: Promotion of Administrative Justice Act 2000.
05: Triage answer: transparency record scopingDoes the use fall within the scope of a transparency record or register, and what is the basis for that reading?Algorithmic Transparency Recording Standard (UK); Data Ethics Framework (transparency principle)Run the ATRS applicability prompt; route the result to the transparency lead and the published guidanceScoping decision with basis and ownerTransparency lead or the AI governance leadAny algorithmic tool that influences a decision or interacts with the publicUS: federal AI use case inventory under the current Office of Management and Budget AI memorandum. EU: AI Act registration in the EU database for high-risk systems and the transparency obligations. Canada: Directive on Automated Decision-Making, published Algorithmic Impact Assessment. Australia: transparency statement under the policy for the responsible use of AI in government. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
05: Responsible, Accountable, Consulted, InformedWho is accountable for the outcome of the AI system, and is that role recorded where the management system expects it?ISO/IEC 42001 (roles, responsibilities and authorities); ISO/IEC 38500 (responsibility)Record the accountable executive in the AI system inventory or registerInventory entry with accountable roleAI governance leadEvery item in the standard or strategic laneInternational standard; the same instrument applies in the US, EU, Canada, Australia, New Zealand and South Africa where the organisation has adopted it.
05: Who benefits, and who bears the costIs the distribution of benefit and cost fair, and who has no seat at the table?Data Ethics Framework (public benefit and fairness); equality duty; NIST AI RMF (fairness characteristic)Name the unrepresented group and how they will be consulted or representedDistribution statement with representation planBusiness Relationship Manager with the equality leadEvery item at ShapeUS: Title VI of the Civil Rights Act 1964 and agency civil rights offices. EU: Charter of Fundamental Rights and the AI Act fundamental rights impact assessment for public-body deployers. Canada: Canadian Human Rights Act and Gender-based Analysis Plus. Australia: Racial, Sex, Disability and Age Discrimination Acts. New Zealand: Human Rights Act 1993 and New Zealand Bill of Rights Act 1990. South Africa: Constitution section 9 and the Promotion of Equality and Prevention of Unfair Discrimination Act 2000.

3.3 Rank gate

Gate: Rank (stage Prioritise). Canvases 06 Value Map, 07 Prioritisation and 08 Portfolio Heatmap. The rows here keep ranking consistent with appraisal and keep the decisions auditable.

Canvas and fieldQuestionFrameworkProcessOutputOwnerTriggerEquivalents
06: Value test appliedIs the value test consistent with how the organisation appraises benefits, so ranks survive the business case?Green Book (benefits appraisal); BRM Body of Knowledge (value planning)Align the value test with the finance partner's benefit categories before rankingAgreed value testFinance partner with the Business Relationship ManagerFirst run of the value map, and any change to the testUS: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance.
07: Cost to first measured outcomeIs the cost estimate on the same basis the business case will use, including optimism bias where your appraisal method requires it?Green Book (optimism bias and cost estimation); Technology Code of Practice (point 11)Estimate on the appraisal basis the finance partner will later apply, and label the confidenceCost estimate with basis and confidenceFinance partnerAny item scored at RankUS: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance.
07: Shared capacity it competes forWhich shared platforms, data teams or security assurance capacity does this compete for?Enterprise architecture (capacity planning); ITIL (capacity and performance management)Check capacity with the platform and assurance owners before committing a rankCapacity note on the prioritisation recordEnterprise architect with the platform ownerItem depends on a shared platform or teamEnterprise architecture practice is international (TOGAF is one common method). US: Federal Enterprise Architecture. Canada: Government of Canada Enterprise Architecture Framework. Australia, New Zealand, EU, South Africa: check local equivalent.
07: Position held or concededIs the ranking decision recorded in a form that would survive audit or a freedom of information request?Records management (ISO 15489); ISO/IEC 38500 (conformance); freedom of information lawWrite the decision, the criteria and the sponsor's dissent into the decision logDecision log entryPortfolio leadAny rank changed after sponsor challengeUS: Freedom of Information Act and Federal Records Act. EU: Regulation 1049/2001 on public access to documents. Canada: Access to Information Act. Australia: Freedom of Information Act 1982. New Zealand: Official Information Act 1982. South Africa: Promotion of Access to Information Act 2000.
08: Concentration of exposureIs the portfolio concentrated on one supplier, one model provider or one data source?Procurement policy (supplier concentration and exit); ISO/IEC 27001 (supplier relationships); NIST AI RMF (Govern, third-party risk)Report concentration to the procurement lead and the risk register ownerConcentration entry on the risk registerProcurement lead with the risk leadMore than a locally set share of the portfolio depends on one supplier or providerUS: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000.

3.4 Commit gate

Gate: Commit (stage Design). Canvases 09 Business Case, 10 Playbook, 11 Agent Assessment, 12 Vendor Evaluation and 14 Product Ownership. The rows here feed the business case, the contract and the controls.

Canvas and fieldQuestionFrameworkProcessOutputOwnerTriggerEquivalents
09: Problem statement and If we do nothingDoes the business case carry the do-nothing and do-minimum options the appraisal method requires?Green Book (five case model; options appraisal)Feed the canvas into the strategic and economic cases; the counterfactual from Shape becomes the do-minimum optionStrategic and economic case sectionsFinance partner with the sponsorEvery item at Commit in the standard or strategic laneUS: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance.
09: Success criteriaAre the success criteria measurable, owned and reportable as performance data?Service Standard (point 10, define what success looks like and publish performance data); Green Book (monitoring and evaluation)Write the measures, baseline and reporting route into the management caseBenefits register entry with baselineBusiness owner with the finance partnerEvery item at CommitUS: 21st Century Integrated Digital Experience Act and the US Web Design System. EU: check local equivalent. Canada: Government of Canada Digital Standards. Australia: Digital Service Standard. New Zealand: Digital Service Design Standard. South Africa: check local equivalent.
09: Top risks and Pre-mortem storyAre the AI-specific risks carried into the organisation's risk register in its own language?NIST AI RMF (Manage); ISO/IEC 42001 (risk treatment); ISO/IEC 27001 (risk treatment plan)Transfer the top risks and the pre-mortem into the risk register with owners and treatmentsRisk register entriesRisk leadEvery item at CommitUS: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
10: Automatic route conditionsWhich requests may pass the fast lane automatically, and does the pattern stay within assurance already granted?GOVBRM lanes; ISO/IEC 42001 (documented information); AI Playbook (principle 6)Publish the pattern with its assurance boundary; expire the pattern when the boundary changesPublished fast-lane pattern with boundaryPlaybook ownerAny pattern published for self-serviceUS: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
11: Decisions taken aloneWhich decisions may the system take without a person, and is that within the legal and policy limits for the decision type?AI Playbook (principle 4); data protection law (automated decision-making); ISO/IEC 42001 (AI system lifecycle)List each autonomous decision, its legal basis and the human override; confirm with the data protection officer and the legal leadAutonomous decision registerProduct owner with the data protection officerChosen rung allows any action without a person in the loopUS: due process protections and Administrative Procedure Act review. EU: GDPR Article 22 and AI Act rights to explanation for affected persons. Canada: Directive on Automated Decision-Making recourse requirements. Australia: administrative law review and the Ombudsman's automated decision-making guidance. New Zealand: Algorithm Charter and Ombudsman oversight. South Africa: Promotion of Administrative Justice Act 2000.
11: Actions and systems called and Permissions grantedDoes the agent's access follow least privilege, and is every permission owned and revocable?ISO/IEC 27001 (access control); Technology Code of Practice (point 6); NIST AI RMF (Manage)Request access through the identity and access process; record each permission with its ownerAccess request record and permission listInformation security leadAny agent that calls a system or holds credentialsUS: FISMA, NIST SP 800-53 and FedRAMP. EU: NIS2 Directive. Canada: Policy on Government Security and ITSG-33. Australia: Protective Security Policy Framework and the Information Security Manual. New Zealand: Protective Security Requirements and the New Zealand Information Security Manual. South Africa: check local equivalent.
11: Pre-live evaluation set and Live success signalIs there a test set and a live signal that would show the system is wrong before a citizen or customer does?NIST AI RMF (Measure); ISO/IEC 42001 (performance evaluation); AI Playbook (principle 10)Define the evaluation set, pass criteria and live monitoring; assign the evaluation ownerEvaluation plan and monitoring designEvaluation ownerEvery agent above the lowest rungUS: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
11: Kill switch and Rollback and repairCan the system be stopped and its effects reversed, and who may pull the switch?ITIL (incident and change management); ISO/IEC 27001 (business continuity); AI Playbook (principle 5, lifecycle)Write the stop and rollback runbook into the service management platformRunbook and incident categoryService owner with the operations leadEvery agent at CommitITIL is an international framework; the same practices apply in every jurisdiction where the organisation has adopted it.
12: Data handling and residency and Training use of our dataWhere is data processed and stored, and may the supplier use it to train models?Data protection law (international transfers); ISO/IEC 27001 (supplier relationships); ISO/IEC 42001 (third-party and customer requirements)Require the answer in writing before shortlisting; route to the data protection officer and the information security leadSupplier data handling statement, verifiedProcurement lead with the data protection officerAny supplier that handles organisational dataUS: Privacy Act 1974 and E-Government Act 2002 privacy impact assessment (federal). EU: GDPR Article 35 data protection impact assessment. Canada: Privacy Act and Treasury Board Directive on Privacy Impact Assessment. Australia: Privacy Act 1988 and the Australian Government Agencies Privacy Code privacy impact assessment. New Zealand: Privacy Act 2020 and the Privacy Commissioner's privacy impact assessment toolkit. South Africa: Protection of Personal Information Act 2013 and the Information Regulator's guidance.
12: Security evidence availableIs the supplier's security evidence current, independent and matched to the data classification?ISO/IEC 27001 (or an equivalent certification or independent assessment); Technology Code of Practice (point 6)Request certificates and assurance reports; check scope and expirySupplier security assurance recordInformation security leadAny supplier shortlistedUS: FISMA, NIST SP 800-53 and FedRAMP. EU: NIS2 Directive. Canada: Policy on Government Security and ITSG-33. Australia: Protective Security Policy Framework and the Information Security Manual. New Zealand: Protective Security Requirements and the New Zealand Information Security Manual. South Africa: check local equivalent.
12: Exit strategy and data portability and Lock-in exposureCan the organisation leave, take its data and switch supplier at acceptable cost?Procurement policy; Technology Code of Practice (point 4, open standards; point 11, purchasing strategy)Write exit, portability and open-standard terms into the specification and the contractExit and portability clausesProcurement lead with the enterprise architectAny new contract or renewalUS: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000.
12: Pricing unit and drivers and Cost at volumeIs the cost at scale understood, and does it include energy and hosting?Green Book (whole-life cost); Technology Code of Practice (point 12, sustainability); procurement policyModel cost at expected and peak volume; include hosting and inference energy where the supplier can state itWhole-life cost estimateFinance partner with the procurement leadAny usage-priced contractUS: check local equivalent. EU: Energy Efficiency Directive data centre reporting and the Corporate Sustainability Reporting Directive. Canada: Greening Government Strategy. Australia: APS Net Zero 2030 commitment. New Zealand: Carbon Neutral Government Programme. South Africa: check local equivalent.
12: Supplier's own AI governanceDoes the supplier run a recognisable AI management system, and can it evidence it?ISO/IEC 42001 (certification or self-assessment); NIST AI RMF (Govern)Ask for the supplier's AI policy, impact assessment method and incident historySupplier AI governance noteAI governance lead with the procurement leadAny supplier providing a model or an agentInternational standard; the same instrument applies in the US, EU, Canada, Australia, New Zealand and South Africa where the organisation has adopted it.

3.5 Build gate

Gate: Build (stage Adopt). Canvases 13 Prompt Governance, 15 Stakeholder Impact, 16 Adoption and 17 Workforce Impact, plus pre-live triage. The rows here close the assurances opened at Shape before anything goes live.

Canvas and fieldQuestionFrameworkProcessOutputOwnerTriggerEquivalents
13: Who may create and Who approvesIs there separation of duties between writing, approving and running prompts?ISO/IEC 27001 (segregation of duties); ITIL (change enablement)Map roles to the change process; no self-approvalRole matrixLibrary ownerAny prompt in a live serviceInternational standard; the same instrument applies in the US, EU, Canada, Australia, New Zealand and South Africa where the organisation has adopted it.
13: Test set contents and Evidence retainedIs the test evidence retained in a form an auditor or a transparency record can reference?NIST AI RMF (Measure); ISO/IEC 42001 (performance evaluation); records managementRetain test sets and results with the release recordRelease evidence packTest ownerEvery releaseUS: Freedom of Information Act and Federal Records Act. EU: Regulation 1049/2001 on public access to documents. Canada: Access to Information Act. Australia: Freedom of Information Act 1982. New Zealand: Official Information Act 1982. South Africa: Promotion of Access to Information Act 2000.
13: Model change triggerDoes a provider model change require re-test, re-assessment or a fresh transparency record?ITIL (change enablement); AI Playbook (principle 5); ATRS (update when the tool changes materially)Treat a model change as a change request; re-run the test set; review the transparency recordChange record with re-test resultLibrary owner with the product ownerThe model provider announces a version changeUS: federal AI use case inventory under the current Office of Management and Budget AI memorandum. EU: AI Act registration in the EU database for high-risk systems and the transparency obligations. Canada: Directive on Automated Decision-Making, published Algorithmic Impact Assessment. Australia: transparency statement under the policy for the responsible use of AI in government. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
15: Who receives the outcome and Visibility and challenge routeDo affected people know an algorithmic tool is involved, and how to challenge its output?ATRS (public description); Data Ethics Framework; AI Playbook (principle 4); Service Standard (point 5)Publish the plain-language description and the challenge route; test it with usersPublished description and challenge routeService owner with the transparency leadAny output reaching a citizen or customerUS: federal AI use case inventory under the current Office of Management and Budget AI memorandum. EU: AI Act registration in the EU database for high-risk systems and the transparency obligations. Canada: Directive on Automated Decision-Making, published Algorithmic Impact Assessment. Australia: transparency statement under the policy for the responsible use of AI in government. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
15: Group the number depends onHave the people whose behaviour the value depends on been consulted, and is the impact assessment complete?Equality impact assessment; Service Standard (points 3 and 8, joined-up experience; iterate and improve); change managementComplete the equality impact assessment with the affected group's input before go-liveCompleted impact assessmentEquality lead with the business ownerEvery item in the standard or strategic lane at BuildUS: Title VI of the Civil Rights Act 1964 and agency civil rights offices. EU: Charter of Fundamental Rights and the AI Act fundamental rights impact assessment for public-body deployers. Canada: Canadian Human Rights Act and Gender-based Analysis Plus. Australia: Racial, Sex, Disability and Age Discrimination Acts. New Zealand: Human Rights Act 1993 and New Zealand Bill of Rights Act 1990. South Africa: Constitution section 9 and the Promotion of Equality and Prevention of Unfair Discrimination Act 2000.
16: Training by user group and Reference and job aidsAre staff trained to the level the framework and the workforce policy require, including how to challenge the tool?AI Playbook (principle 9, skills and expertise); ISO/IEC 42001 (competence and awareness)Deliver role-based training and retain attendance as competence evidenceTraining recordAdoption lead with the line managersEvery item at BuildInternational standard; the same instrument applies in the US, EU, Canada, Australia, New Zealand and South Africa where the organisation has adopted it.
17: Headcount by role and location and Nature of the effectDoes the change require consultation with staff or their representatives under employment law or policy?Employment law and consultation duties; equality duty; workforce policyRoute to the human resources lead for the consultation decision before any communicationConsultation decision and planHuman resources leadAny role, hours or location effect on staffUS: WARN Act and agency collective bargaining rules. EU: Directive 2002/14/EC on information and consultation of employees. Canada: Canada Labour Code. Australia: Fair Work Act 2009. New Zealand: Employment Relations Act 2000. South Africa: Labour Relations Act 1995.
Triage answer: accessibility audit statusHas the interface passed an accessibility audit and is an accessibility statement published?WCAG 2.2 AA; public-sector accessibility duties; Service Standard (point 5)Complete the audit, fix or record known issues, publish the statementAudit report and accessibility statementAccessibility leadBefore Build closes for any user-facing interfaceUS: Section 508 of the Rehabilitation Act and the Americans with Disabilities Act. EU: Web Accessibility Directive 2016/2102 and the European Accessibility Act. Canada: Accessible Canada Act. Australia: Disability Discrimination Act 1992 and the Digital Service Standard. New Zealand: New Zealand Government Web Accessibility Standard. South Africa: check local equivalent.
Triage answer: hosting, model size and inference volumeIs the energy and carbon footprint known and within the organisation's sustainability commitments?Technology Code of Practice (point 12, sustainability); sustainability policyRecord hosting region, model size and expected inference volume; request the provider's energy dataSustainability note on the service recordSustainability lead with the enterprise architectAny hosted model or high-volume inferenceUS: check local equivalent. EU: Energy Efficiency Directive data centre reporting and the Corporate Sustainability Reporting Directive. Canada: Greening Government Strategy. Australia: APS Net Zero 2030 commitment. New Zealand: Carbon Neutral Government Programme. South Africa: check local equivalent.
Triage answer: service assessment dueDoes the service meet the service standard your organisation applies before it goes live?Service Standard (all points; UK service assessments); Technology Code of PracticeBook the service assessment and prepare evidence from canvases 05, 15 and 16Service assessment reportService ownerAny public-facing service above the local assessment thresholdUS: 21st Century Integrated Digital Experience Act and the US Web Design System. EU: check local equivalent. Canada: Government of Canada Digital Standards. Australia: Digital Service Standard. New Zealand: Digital Service Design Standard. South Africa: check local equivalent.

3.6 Review gate

Gate: Review (stage Realise). Canvases 18 Benefits Realisation, 19 Value Realisation Review and 20 Capability Roadmap. The rows here return evidence to the frameworks that asked for it and reopen assessments when the world changes.

Canvas and fieldQuestionFrameworkProcessOutputOwnerTriggerEquivalents
18: Committed value and date and Readings supplied byIs value being measured against the baseline in the business case, by an independent reader?Green Book (monitoring and evaluation); benefits management; BRM Body of Knowledge (value harvesting)Take readings from the source the business case named; the reader is not the sponsorBenefits readingBenefits owner with the finance partnerEach review pointUS: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance.
19: Risks that materialisedDid a risk or an incident occur that should be reported under an incident, breach or transparency process?ISO/IEC 27001 (incident management); data protection law (breach notification); ATRS (update); NIST AI RMF (Manage)Confirm each materialised risk was reported through the correct route; update the transparency recordIncident and record updatesProduct owner with the risk leadAny materialised risk at the Value Realisation ReviewUS: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
19: Governance that can relax and Governance that must tightenShould the risk tier, assurance level or lane change, and who approves the change?NIST AI RMF (Govern); ISO/IEC 42001 (management review); GOVBRM lanesPropose the change to the governance forum with the evidence from the reviewGovernance change decisionAI governance leadEvery Value Realisation ReviewUS: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.
19: Shadow use and workaroundsIs unsanctioned AI use present, and is it a security, privacy or policy exposure?ISO/IEC 27001 (acceptable use); data protection law; AI Playbook (principle 2, lawful and ethical use)Report shadow use to the information security lead and the data protection officer; convert legitimate demand into a new requestShadow use report and new intake recordsBusiness Relationship ManagerAny shadow use observedUS: FISMA, NIST SP 800-53 and FedRAMP. EU: NIS2 Directive. Canada: Policy on Government Security and ITSG-33. Australia: Protective Security Policy Framework and the Information Security Manual. New Zealand: Protective Security Requirements and the New Zealand Information Security Manual. South Africa: check local equivalent.
20: Platform play and Funding route and horizonIs a shared capability better funded as a platform, and does it need its own business case?Green Book (programme business case); enterprise architecture (platform strategy); Technology Code of Practice (points 3 and 9)Open a programme-level business case for the platform; record the dependent demandsPlatform business caseEnterprise architect with the finance partnerTwo or more demands need the same capabilityUS: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance.
20: Signals that force early reviewHas a law, policy, model or supplier change occurred that invalidates an assessment already made?ISO/IEC 42001 (management review); ATRS (update); procurement policy (contract change)Reopen the affected assessments and records; refresh the roadmapRefreshed roadmap and reopened assessmentsRefresh ownerA named signal firesUS: federal AI use case inventory under the current Office of Management and Budget AI memorandum. EU: AI Act registration in the EU database for high-risk systems and the transparency obligations. Canada: Directive on Automated Decision-Making, published Algorithmic Impact Assessment. Australia: transparency statement under the policy for the responsible use of AI in government. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent.

Row count: 58.

4. ATRS applicability prompt

GOVBRM does not decide whether the Algorithmic Transparency Recording Standard, or any other transparency register, applies to a tool. That decision belongs to the published guidance and to the person in your organisation who owns transparency records. This prompt is a scoping aid at the Shape gate (canvas 05, AI Risk and Ethics). It sorts a request into one of four outcomes, records the basis for that reading, and routes it to the authoritative guidance for confirmation. Whichever outcome you reach, write the basis down and name who confirms it, and by when. Outside the UK, run the same prompt against your own transparency instrument: the federal AI use case inventory in the US, the EU AI Act database and transparency obligations, Canada's Algorithmic Impact Assessment, Australia's transparency statements, New Zealand's Algorithm Charter, or your local equivalent. Label: GOVBRM original prompt over an established standard, not yet validated.

Ask, with the canvas 02 and 05 entries in front of you:

  1. Is the organisation a public body or acting on behalf of one, in a jurisdiction with a transparency record requirement?
  2. Does the tool use an algorithm, model or automated process to make, recommend or materially shape a decision, or to interact directly with the public?
  3. Could the tool have a direct or indirect effect on a person's rights, entitlements, access to a service or treatment by the organisation?
  4. Is the tool in live use or planned for live use, rather than exploratory or purely internal administration with no public effect?
  5. Does published guidance, or an internal policy, name an exemption or exception that might apply (for example national security or an internal tool with no public effect)?

Then record one of four outcomes.

OutcomeWhenAction
Not in scopeThe reading against the published guidance is that none of the scoping conditions is met: no public-facing effect, no decision influence, or the organisation is outside the standard's coverage.Record the basis and the guidance version consulted. Name who confirmed the reading. Set a re-check trigger: any change to the tool's use, population or autonomy rung reopens the question.
Potentially in scope, confirmOne or more scoping conditions is met or uncertain, and the reading cannot be settled from the canvas alone.Route to the transparency lead with the shaped need, the autonomy rung, the blast radius and the data scope. Do not proceed past Commit until the reading is confirmed against the published guidance. Record the confirmation.
In scope, record requiredThe transparency lead confirms, against the published guidance, that a record is required.Open the record using the standard's own template and fields. Feed it from canvases 02, 05, 11 and 15. Set the owner, the publication route and the update triggers (model change, scope change, retirement). Publication is a Commit condition or a Build condition, as the guidance directs.
Exemption or exception, document basisThe transparency lead confirms that an exemption or exception in the published guidance applies.Record the specific exemption or exception, the guidance reference, who decided and the date. Keep an internal record with the same fields, so the reading can be revisited. Set a review trigger for changes in use or guidance.

GOVBRM never states that a tool is legally in or out of scope. Every outcome above is a reading to be confirmed by the transparency lead against the current published guidance, and the confirmation is what is recorded.

5. What GOVBRM does not replace

GOVBRM is the operating layer between AI demand and AI delivery. It decides which demand receives attention, money, autonomy and organisational change, and routes each item into the governance the organisation already has. It is not a substitute for any of the following, and a row in this compiler is a routing instruction, not a replacement for the process it routes to.

  • Business cases and their appraisal method (the Green Book five case model is one version)
  • Procurement and commercial assurance
  • Security assurance and the information risk process (ISO/IEC 27001 or local equivalent)
  • Privacy and data protection impact assessments
  • Equality, anti-discrimination and human rights assessments
  • Transparency records and registers (ATRS and equivalents)
  • Service or delivery assessments (Service Standard and equivalents)
  • An ISO/IEC 42001 AI management system, or ISO/IEC 38500 IT governance
  • ITIL service management, enterprise architecture, and delivery methods
  • Accessibility audits and statements, sustainability assessments, employment consultation
  • Legal advice on whether any statute, standard or duty applies

Where a decision needs a lawyer, a data protection officer, an accountant, an accessibility auditor or the accountable executive, the row says so through its owner column, and GOVBRM stops at the handoff.

Dates come to members first

Courses and certifications are announced in the GOVBRM Newsletter before anywhere else.

Join free for the essays behind the framework, the access code for the free micro-courses, and first word of every cohort. Paid membership adds the toolkit, the framework and a seat at the masterclasses.