Govern
One demand record, many governance outputs.
The detailed crosswalk: which GOVBRM field triggers which assessment, record or appraisal, who owns it, and what it produces. A GOVBRM original mapping over established frameworks, not yet validated.
GOVBRM cross-framework compiler
Status: draft v0.1, GOVBRM original mapping over established frameworks, not yet validated.
1. What this is
The crosswalk page on govbrm.com shows, stage by stage, which frameworks GOVBRM hands off to. This compiler goes one level down. It takes a specific GOVBRM input (a field on one of the twenty canvases, or a triage answer given at a gate) and states the governance question that input raises, the external framework or process that answers it, the evidence or output that process produces, the role that owns it, and the condition that triggers it. A practitioner running a front door can read across a row and act.
Label: GOVBRM original mapping. The frameworks are established and belong to their publishers. The routing between a canvas field and a framework is GOVBRM's own design and has not been validated in use. Not yet demonstrated. Framework point numbers refer to the published editions at the time of writing; check the current edition before relying on a number.
Two rules apply throughout.
2. How to read a row
| Column | Meaning |
|---|---|
| Canvas and field | The canvas number and field label from the AI Demand Toolkit, or "Triage" for an answer given at the gate rather than on a canvas |
| Question | The governance question that field raises once it has a value |
| Framework | The established framework, standard or process that answers the question |
| Process | What the practitioner does to route the input into that framework |
| Output | The evidence or record that results, in the language the receiving process uses |
| Owner | The role that owns the output (job titles vary; substitute your own) |
| Trigger | The condition under which the row applies at all; if the trigger is absent, the row is skipped |
| Equivalents | The closest instrument in the US, EU, Canada, Australia, New Zealand and South Africa, or "check local equivalent" |
The lanes still apply. A fast-lane request meets only the Request rows and the published pattern's boundary. A standard-lane request meets Request, Shape, Commit and Review rows as triggered. A strategic-lane request meets every triggered row.
3. Compiler table by gate
3.1 Request gate
Gate: Request (stage Discover into Assess). Canvases 01 Opportunity and 03 Intake, plus lane triage. The aim is to find out what has already happened and to start the assurances that are cheapest when started early.
| Canvas and field | Question | Framework | Process | Output | Owner | Trigger | Equivalents |
|---|---|---|---|---|---|---|---|
| 01: Outcome to improve | Is this an outcome the organisation is accountable for, and is there a user need behind it? | Service Standard (point 1, understand users and their needs); Technology Code of Practice (point 1, define user needs); BRM Body of Knowledge (demand shaping) | Confirm the outcome against the published performance measure the partner already reports; open or reuse a user research record | Outcome statement with the existing measure named; link to any user research already held | Business Relationship Manager with the partner's operational lead | Any observation carried towards the Request gate | US: 21st Century Integrated Digital Experience Act and the US Web Design System. EU: check local equivalent. Canada: Government of Canada Digital Standards. Australia: Digital Service Standard. New Zealand: Digital Service Design Standard. South Africa: check local equivalent. |
| 01: Benefit type and Value range | Is the claimed benefit cashable, efficiency, quality or risk reduction, and in whose budget does it land? | Green Book (benefits categories and appraisal); BRM Body of Knowledge (value planning) | Classify the benefit type and name the budget holder before any number is quoted upwards | Benefit type, value range and budget holder line on the opportunity statement | Business Relationship Manager with the finance partner | A value range is written on the canvas | US: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance. |
| 03: Route of arrival | Has the request already passed through, or bypassed, a governance step it should have met? | Technology Code of Practice (point 11, define your purchasing strategy); AI Playbook (principle 8, work with commercial colleagues) | Check whether a supplier conversation, pilot or trial has already started; if so route to procurement and information security in parallel | Note of prior contact and any parallel routing | Business Relationship Manager | Route of arrival names a supplier, a pilot or a trial | US: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000. |
| 03: Suppliers and partners involved | Is a supplier already shaping the requirement, and is the organisation exposed commercially? | Procurement policy; AI Playbook (principle 8); ISO/IEC 42001 (supplier relationships) | Route to the procurement lead for a conflict-of-interest and pre-market engagement check | Procurement note on the intake record | Procurement lead | Any supplier named at intake | US: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000. |
| 03: Procurement or contract position | Is there an existing contract, framework or licence that already covers this, or one that constrains it? | Procurement policy; ITIL (supplier management); enterprise architecture (application portfolio) | Search the contract register and the licence inventory before any new buying route is discussed | Contract register reference or a note that none applies | Procurement lead with the enterprise architect | Money committed or assumed is not zero | US: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000. |
| 03: Money committed or assumed | Has money been promised outside the approved spend control route? | Spend control (in the UK, the digital and technology spend controls); Green Book | Check the spend control threshold and whether an approval is already required | Spend control status on the intake record | Finance partner | Money has been committed or assumed by the requester | US: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance. |
| 03: Systems it would touch | Which systems, data stores and integrations are in scope, and are any of them critical or legacy? | Enterprise architecture (application and data portfolio); Technology Code of Practice (point 9, integrate and adapt); ITIL (service configuration management) | Check the systems against the configuration record and the architecture repository | System list with criticality and owner | Enterprise architect | Any named system on the intake record | Enterprise architecture practice is international (TOGAF is one common method). US: Federal Enterprise Architecture. Canada: Government of Canada Enterprise Architecture Framework. Australia, New Zealand, EU, South Africa: check local equivalent. |
| 03: Adjacent or duplicate demand | Has the same need, or the same capability, already been requested or built elsewhere in the organisation? | Enterprise architecture (capability map); portfolio management; Technology Code of Practice (point 3, be open and use open source; point 9, integrate and adapt) | Search the demand register and the capability map; merge or link where the need matches | Duplicate or merge note on the intake record | Business Relationship Manager with the enterprise architect | Any request whose problem statement matches an open item | Enterprise architecture practice is international (TOGAF is one common method). US: Federal Enterprise Architecture. Canada: Government of Canada Enterprise Architecture Framework. Australia, New Zealand, EU, South Africa: check local equivalent. |
| Triage answer: does the request touch a citizen or customer directly? | Which lane does the request enter, and which assurances start now rather than later? | GOVBRM lanes (fast, standard, strategic); Service Standard; AI Playbook (principle 4, meaningful human control) | Assign the lane by consequence, scale, reversibility, population affected and time to notice a failure; public-facing requests default to the standard lane or above | Lane assignment with reason | Business Relationship Manager | Every request at the Request gate | US: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
3.2 Shape gate
Gate: Shape (stage Assess). Canvases 02 Demand Shaping, 04 Readiness and 05 Risk and Ethics. Most of the assurance routing happens here, because the shaped need, the autonomy rung and the data scope are now known.
| Canvas and field | Question | Framework | Process | Output | Owner | Trigger | Equivalents |
|---|---|---|---|---|---|---|---|
| 02: Root need | Is the need stated as a problem rather than a solution, and is it a whole problem for the user? | Service Standard (point 2, solve a whole problem for users); BRM Body of Knowledge (demand shaping) | Rewrite the need in the partner's words with the requested solution removed; check against user research | Shaped need statement | Business Relationship Manager with the partner sponsor | Every request entering the Shape gate | US: 21st Century Integrated Digital Experience Act and the US Web Design System. EU: check local equivalent. Canada: Government of Canada Digital Standards. Australia: Digital Service Standard. New Zealand: Digital Service Design Standard. South Africa: check local equivalent. |
| 02: Rung requested and Lowest rung that solves it | Is the autonomy requested proportionate, and is a lower rung or a non-AI change sufficient? | AI Playbook (principle 6, the right tool for the job; principle 4, meaningful human control); NIST AI RMF (Map) | Apply the autonomy ladder; record the lowest rung that solves the task and why one rung lower fails | Autonomy rung with justification | Business Relationship Manager | Requested rung is above the lowest rung that solves it | US: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 02: What a wrong output touches | What is the blast radius of a wrong output, and who bears it? | NIST AI RMF (Map, Measure); ISO/IEC 42001 (AI impact assessment); Data Ethics Framework | Describe the consequence, scale, reversibility and population affected; feed the result into the lane decision and the risk canvas | Blast radius statement | Business Relationship Manager with the risk lead | A wrong output could reach a citizen, customer or a legal decision | US: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 02: Fix the process instead and Change the rule instead | Would a process, policy or rule change remove the need without AI? | Service Standard (point 2); Green Book (do-minimum option); Technology Code of Practice (point 1) | Record the non-AI counterfactual as the do-minimum option for the later business case | Do-minimum option note | Business Relationship Manager with the partner operational lead | Every request at Shape | US: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance. |
| 04: Proposed autonomy rung | Which risk tier, impact level or assurance level does the proposed rung imply under the frameworks you follow? | NIST AI RMF (Govern); ISO/IEC 42001 (AI system impact assessment); AI Playbook (principle 10, assurance) | Map the rung and blast radius to your risk tier or impact level; open the assurance plan at that level | Risk tier or impact level with the assurance plan opened | AI assurance lead or risk lead | Rung is above the lowest, or the request is public-facing | US: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 04: Triage answer: data readiness (quality, access, lineage) | Is the data fit, lawful and available for the purpose, and who owns it? | Data Ethics Framework; Technology Code of Practice (point 10, make better use of data); ISO/IEC 42001 (data for AI systems) | Confirm the data owner, the source of truth and the quality baseline; log gaps as readiness conditions | Data readiness statement with owner | Data owner with the data governance lead | Readiness score marks data as amber or red | US: Privacy Act 1974 and E-Government Act 2002 privacy impact assessment (federal). EU: GDPR Article 35 data protection impact assessment. Canada: Privacy Act and Treasury Board Directive on Privacy Impact Assessment. Australia: Privacy Act 1988 and the Australian Government Agencies Privacy Code privacy impact assessment. New Zealand: Privacy Act 2020 and the Privacy Commissioner's privacy impact assessment toolkit. South Africa: Protection of Personal Information Act 2013 and the Information Regulator's guidance. |
| 04: Triage answer: security readiness | Does the proposed use meet the information security policy, and has the information risk owner seen it? | ISO/IEC 27001 (risk assessment and Annex A controls); AI Playbook (principle 3, secure); Technology Code of Practice (point 6, make things secure) | Open the security assurance route at the level the data classification requires; record the information risk owner | Security assurance ticket or record | Information security lead | Any data above the lowest classification, or any external model provider | US: FISMA, NIST SP 800-53 and FedRAMP. EU: NIS2 Directive. Canada: Policy on Government Security and ITSG-33. Australia: Protective Security Policy Framework and the Information Security Manual. New Zealand: Protective Security Requirements and the New Zealand Information Security Manual. South Africa: check local equivalent. |
| 05: Triage answer: personal data handled | Is personal data processed, and is a data protection impact assessment or equivalent required? | Data protection law (in the UK, UK GDPR and the Data Protection Act 2018); Data Ethics Framework; Technology Code of Practice (point 7, privacy) | Route to the data protection officer for a screening decision; open the DPIA where the screening says so | DPIA screening record, and the DPIA itself where required | Data protection officer | Personal data appears anywhere in the data scope | US: Privacy Act 1974 and E-Government Act 2002 privacy impact assessment (federal). EU: GDPR Article 35 data protection impact assessment. Canada: Privacy Act and Treasury Board Directive on Privacy Impact Assessment. Australia: Privacy Act 1988 and the Australian Government Agencies Privacy Code privacy impact assessment. New Zealand: Privacy Act 2020 and the Privacy Commissioner's privacy impact assessment toolkit. South Africa: Protection of Personal Information Act 2013 and the Information Regulator's guidance. |
| 05: Triage answer: decisions about people | Does the system make, or materially influence, a decision with legal or similarly significant effect on a person? | Data protection law (automated decision-making provisions); AI Playbook (principle 4); Data Ethics Framework | Route to the data protection officer and the legal team; require a human review route and a contestability path before Commit | Automated decision-making assessment and human review design | Data protection officer with the legal lead | Decision affects entitlement, enforcement, eligibility or a similarly significant outcome | US: due process protections and Administrative Procedure Act review. EU: GDPR Article 22 and AI Act rights to explanation for affected persons. Canada: Directive on Automated Decision-Making recourse requirements. Australia: administrative law review and the Ombudsman's automated decision-making guidance. New Zealand: Algorithm Charter and Ombudsman oversight. South Africa: Promotion of Administrative Justice Act 2000. |
| 05: Rights, entitlements and accessibility | Does the change affect protected groups differently, and has the equality duty been considered? | Equality duty (in the UK, the Public Sector Equality Duty); human rights law; Data Ethics Framework | Open an equality impact assessment; add a human rights assessment where liberty, privacy or family life are engaged | Equality impact assessment, and a human rights assessment where relevant | Equality lead with the policy owner | Any public-facing use, or any use affecting staff terms | US: Title VI of the Civil Rights Act 1964 and agency civil rights offices. EU: Charter of Fundamental Rights and the AI Act fundamental rights impact assessment for public-body deployers. Canada: Canadian Human Rights Act and Gender-based Analysis Plus. Australia: Racial, Sex, Disability and Age Discrimination Acts. New Zealand: Human Rights Act 1993 and New Zealand Bill of Rights Act 1990. South Africa: Constitution section 9 and the Promotion of Equality and Prevention of Unfair Discrimination Act 2000. |
| 05: Rights, entitlements and accessibility (accessibility element) | Can everyone who needs to use or be affected by the service do so, including disabled people? | WCAG 2.2 AA; public-sector accessibility duties (in the UK, the Public Sector Bodies Accessibility Regulations 2018); Service Standard (point 5, make sure everyone can use the service); Technology Code of Practice (point 2) | Add accessibility acceptance criteria to the need statement; plan an accessibility audit before Build closes | Accessibility requirements and audit plan | Accessibility lead with the service owner | Any user-facing interface or output | US: Section 508 of the Rehabilitation Act and the Americans with Disabilities Act. EU: Web Accessibility Directive 2016/2102 and the European Accessibility Act. Canada: Accessible Canada Act. Australia: Disability Discrimination Act 1992 and the Digital Service Standard. New Zealand: New Zealand Government Web Accessibility Standard. South Africa: check local equivalent. |
| 05: Challenge, human review and redress | Can an affected person understand, challenge and get a decision reviewed by a person? | AI Playbook (principle 4); Data Ethics Framework; administrative law and complaints procedures | Design the challenge route, the human reviewer role and the redress path; confirm with the complaints owner | Contestability and redress design | Service owner with the complaints lead | Any decision or recommendation reaching a citizen or customer | US: due process protections and Administrative Procedure Act review. EU: GDPR Article 22 and AI Act rights to explanation for affected persons. Canada: Directive on Automated Decision-Making recourse requirements. Australia: administrative law review and the Ombudsman's automated decision-making guidance. New Zealand: Algorithm Charter and Ombudsman oversight. South Africa: Promotion of Administrative Justice Act 2000. |
| 05: Triage answer: transparency record scoping | Does the use fall within the scope of a transparency record or register, and what is the basis for that reading? | Algorithmic Transparency Recording Standard (UK); Data Ethics Framework (transparency principle) | Run the ATRS applicability prompt; route the result to the transparency lead and the published guidance | Scoping decision with basis and owner | Transparency lead or the AI governance lead | Any algorithmic tool that influences a decision or interacts with the public | US: federal AI use case inventory under the current Office of Management and Budget AI memorandum. EU: AI Act registration in the EU database for high-risk systems and the transparency obligations. Canada: Directive on Automated Decision-Making, published Algorithmic Impact Assessment. Australia: transparency statement under the policy for the responsible use of AI in government. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 05: Responsible, Accountable, Consulted, Informed | Who is accountable for the outcome of the AI system, and is that role recorded where the management system expects it? | ISO/IEC 42001 (roles, responsibilities and authorities); ISO/IEC 38500 (responsibility) | Record the accountable executive in the AI system inventory or register | Inventory entry with accountable role | AI governance lead | Every item in the standard or strategic lane | International standard; the same instrument applies in the US, EU, Canada, Australia, New Zealand and South Africa where the organisation has adopted it. |
| 05: Who benefits, and who bears the cost | Is the distribution of benefit and cost fair, and who has no seat at the table? | Data Ethics Framework (public benefit and fairness); equality duty; NIST AI RMF (fairness characteristic) | Name the unrepresented group and how they will be consulted or represented | Distribution statement with representation plan | Business Relationship Manager with the equality lead | Every item at Shape | US: Title VI of the Civil Rights Act 1964 and agency civil rights offices. EU: Charter of Fundamental Rights and the AI Act fundamental rights impact assessment for public-body deployers. Canada: Canadian Human Rights Act and Gender-based Analysis Plus. Australia: Racial, Sex, Disability and Age Discrimination Acts. New Zealand: Human Rights Act 1993 and New Zealand Bill of Rights Act 1990. South Africa: Constitution section 9 and the Promotion of Equality and Prevention of Unfair Discrimination Act 2000. |
3.3 Rank gate
Gate: Rank (stage Prioritise). Canvases 06 Value Map, 07 Prioritisation and 08 Portfolio Heatmap. The rows here keep ranking consistent with appraisal and keep the decisions auditable.
| Canvas and field | Question | Framework | Process | Output | Owner | Trigger | Equivalents |
|---|---|---|---|---|---|---|---|
| 06: Value test applied | Is the value test consistent with how the organisation appraises benefits, so ranks survive the business case? | Green Book (benefits appraisal); BRM Body of Knowledge (value planning) | Align the value test with the finance partner's benefit categories before ranking | Agreed value test | Finance partner with the Business Relationship Manager | First run of the value map, and any change to the test | US: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance. |
| 07: Cost to first measured outcome | Is the cost estimate on the same basis the business case will use, including optimism bias where your appraisal method requires it? | Green Book (optimism bias and cost estimation); Technology Code of Practice (point 11) | Estimate on the appraisal basis the finance partner will later apply, and label the confidence | Cost estimate with basis and confidence | Finance partner | Any item scored at Rank | US: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance. |
| 07: Shared capacity it competes for | Which shared platforms, data teams or security assurance capacity does this compete for? | Enterprise architecture (capacity planning); ITIL (capacity and performance management) | Check capacity with the platform and assurance owners before committing a rank | Capacity note on the prioritisation record | Enterprise architect with the platform owner | Item depends on a shared platform or team | Enterprise architecture practice is international (TOGAF is one common method). US: Federal Enterprise Architecture. Canada: Government of Canada Enterprise Architecture Framework. Australia, New Zealand, EU, South Africa: check local equivalent. |
| 07: Position held or conceded | Is the ranking decision recorded in a form that would survive audit or a freedom of information request? | Records management (ISO 15489); ISO/IEC 38500 (conformance); freedom of information law | Write the decision, the criteria and the sponsor's dissent into the decision log | Decision log entry | Portfolio lead | Any rank changed after sponsor challenge | US: Freedom of Information Act and Federal Records Act. EU: Regulation 1049/2001 on public access to documents. Canada: Access to Information Act. Australia: Freedom of Information Act 1982. New Zealand: Official Information Act 1982. South Africa: Promotion of Access to Information Act 2000. |
| 08: Concentration of exposure | Is the portfolio concentrated on one supplier, one model provider or one data source? | Procurement policy (supplier concentration and exit); ISO/IEC 27001 (supplier relationships); NIST AI RMF (Govern, third-party risk) | Report concentration to the procurement lead and the risk register owner | Concentration entry on the risk register | Procurement lead with the risk lead | More than a locally set share of the portfolio depends on one supplier or provider | US: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000. |
3.4 Commit gate
Gate: Commit (stage Design). Canvases 09 Business Case, 10 Playbook, 11 Agent Assessment, 12 Vendor Evaluation and 14 Product Ownership. The rows here feed the business case, the contract and the controls.
| Canvas and field | Question | Framework | Process | Output | Owner | Trigger | Equivalents |
|---|---|---|---|---|---|---|---|
| 09: Problem statement and If we do nothing | Does the business case carry the do-nothing and do-minimum options the appraisal method requires? | Green Book (five case model; options appraisal) | Feed the canvas into the strategic and economic cases; the counterfactual from Shape becomes the do-minimum option | Strategic and economic case sections | Finance partner with the sponsor | Every item at Commit in the standard or strategic lane | US: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance. |
| 09: Success criteria | Are the success criteria measurable, owned and reportable as performance data? | Service Standard (point 10, define what success looks like and publish performance data); Green Book (monitoring and evaluation) | Write the measures, baseline and reporting route into the management case | Benefits register entry with baseline | Business owner with the finance partner | Every item at Commit | US: 21st Century Integrated Digital Experience Act and the US Web Design System. EU: check local equivalent. Canada: Government of Canada Digital Standards. Australia: Digital Service Standard. New Zealand: Digital Service Design Standard. South Africa: check local equivalent. |
| 09: Top risks and Pre-mortem story | Are the AI-specific risks carried into the organisation's risk register in its own language? | NIST AI RMF (Manage); ISO/IEC 42001 (risk treatment); ISO/IEC 27001 (risk treatment plan) | Transfer the top risks and the pre-mortem into the risk register with owners and treatments | Risk register entries | Risk lead | Every item at Commit | US: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 10: Automatic route conditions | Which requests may pass the fast lane automatically, and does the pattern stay within assurance already granted? | GOVBRM lanes; ISO/IEC 42001 (documented information); AI Playbook (principle 6) | Publish the pattern with its assurance boundary; expire the pattern when the boundary changes | Published fast-lane pattern with boundary | Playbook owner | Any pattern published for self-service | US: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 11: Decisions taken alone | Which decisions may the system take without a person, and is that within the legal and policy limits for the decision type? | AI Playbook (principle 4); data protection law (automated decision-making); ISO/IEC 42001 (AI system lifecycle) | List each autonomous decision, its legal basis and the human override; confirm with the data protection officer and the legal lead | Autonomous decision register | Product owner with the data protection officer | Chosen rung allows any action without a person in the loop | US: due process protections and Administrative Procedure Act review. EU: GDPR Article 22 and AI Act rights to explanation for affected persons. Canada: Directive on Automated Decision-Making recourse requirements. Australia: administrative law review and the Ombudsman's automated decision-making guidance. New Zealand: Algorithm Charter and Ombudsman oversight. South Africa: Promotion of Administrative Justice Act 2000. |
| 11: Actions and systems called and Permissions granted | Does the agent's access follow least privilege, and is every permission owned and revocable? | ISO/IEC 27001 (access control); Technology Code of Practice (point 6); NIST AI RMF (Manage) | Request access through the identity and access process; record each permission with its owner | Access request record and permission list | Information security lead | Any agent that calls a system or holds credentials | US: FISMA, NIST SP 800-53 and FedRAMP. EU: NIS2 Directive. Canada: Policy on Government Security and ITSG-33. Australia: Protective Security Policy Framework and the Information Security Manual. New Zealand: Protective Security Requirements and the New Zealand Information Security Manual. South Africa: check local equivalent. |
| 11: Pre-live evaluation set and Live success signal | Is there a test set and a live signal that would show the system is wrong before a citizen or customer does? | NIST AI RMF (Measure); ISO/IEC 42001 (performance evaluation); AI Playbook (principle 10) | Define the evaluation set, pass criteria and live monitoring; assign the evaluation owner | Evaluation plan and monitoring design | Evaluation owner | Every agent above the lowest rung | US: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 11: Kill switch and Rollback and repair | Can the system be stopped and its effects reversed, and who may pull the switch? | ITIL (incident and change management); ISO/IEC 27001 (business continuity); AI Playbook (principle 5, lifecycle) | Write the stop and rollback runbook into the service management platform | Runbook and incident category | Service owner with the operations lead | Every agent at Commit | ITIL is an international framework; the same practices apply in every jurisdiction where the organisation has adopted it. |
| 12: Data handling and residency and Training use of our data | Where is data processed and stored, and may the supplier use it to train models? | Data protection law (international transfers); ISO/IEC 27001 (supplier relationships); ISO/IEC 42001 (third-party and customer requirements) | Require the answer in writing before shortlisting; route to the data protection officer and the information security lead | Supplier data handling statement, verified | Procurement lead with the data protection officer | Any supplier that handles organisational data | US: Privacy Act 1974 and E-Government Act 2002 privacy impact assessment (federal). EU: GDPR Article 35 data protection impact assessment. Canada: Privacy Act and Treasury Board Directive on Privacy Impact Assessment. Australia: Privacy Act 1988 and the Australian Government Agencies Privacy Code privacy impact assessment. New Zealand: Privacy Act 2020 and the Privacy Commissioner's privacy impact assessment toolkit. South Africa: Protection of Personal Information Act 2013 and the Information Regulator's guidance. |
| 12: Security evidence available | Is the supplier's security evidence current, independent and matched to the data classification? | ISO/IEC 27001 (or an equivalent certification or independent assessment); Technology Code of Practice (point 6) | Request certificates and assurance reports; check scope and expiry | Supplier security assurance record | Information security lead | Any supplier shortlisted | US: FISMA, NIST SP 800-53 and FedRAMP. EU: NIS2 Directive. Canada: Policy on Government Security and ITSG-33. Australia: Protective Security Policy Framework and the Information Security Manual. New Zealand: Protective Security Requirements and the New Zealand Information Security Manual. South Africa: check local equivalent. |
| 12: Exit strategy and data portability and Lock-in exposure | Can the organisation leave, take its data and switch supplier at acceptable cost? | Procurement policy; Technology Code of Practice (point 4, open standards; point 11, purchasing strategy) | Write exit, portability and open-standard terms into the specification and the contract | Exit and portability clauses | Procurement lead with the enterprise architect | Any new contract or renewal | US: Federal Acquisition Regulation. EU: Directive 2014/24/EU on public procurement. Canada: Treasury Board Directive on the Management of Procurement. Australia: Commonwealth Procurement Rules. New Zealand: Government Procurement Rules. South Africa: Public Finance Management Act and the Preferential Procurement Policy Framework Act 2000. |
| 12: Pricing unit and drivers and Cost at volume | Is the cost at scale understood, and does it include energy and hosting? | Green Book (whole-life cost); Technology Code of Practice (point 12, sustainability); procurement policy | Model cost at expected and peak volume; include hosting and inference energy where the supplier can state it | Whole-life cost estimate | Finance partner with the procurement lead | Any usage-priced contract | US: check local equivalent. EU: Energy Efficiency Directive data centre reporting and the Corporate Sustainability Reporting Directive. Canada: Greening Government Strategy. Australia: APS Net Zero 2030 commitment. New Zealand: Carbon Neutral Government Programme. South Africa: check local equivalent. |
| 12: Supplier's own AI governance | Does the supplier run a recognisable AI management system, and can it evidence it? | ISO/IEC 42001 (certification or self-assessment); NIST AI RMF (Govern) | Ask for the supplier's AI policy, impact assessment method and incident history | Supplier AI governance note | AI governance lead with the procurement lead | Any supplier providing a model or an agent | International standard; the same instrument applies in the US, EU, Canada, Australia, New Zealand and South Africa where the organisation has adopted it. |
3.5 Build gate
Gate: Build (stage Adopt). Canvases 13 Prompt Governance, 15 Stakeholder Impact, 16 Adoption and 17 Workforce Impact, plus pre-live triage. The rows here close the assurances opened at Shape before anything goes live.
| Canvas and field | Question | Framework | Process | Output | Owner | Trigger | Equivalents |
|---|---|---|---|---|---|---|---|
| 13: Who may create and Who approves | Is there separation of duties between writing, approving and running prompts? | ISO/IEC 27001 (segregation of duties); ITIL (change enablement) | Map roles to the change process; no self-approval | Role matrix | Library owner | Any prompt in a live service | International standard; the same instrument applies in the US, EU, Canada, Australia, New Zealand and South Africa where the organisation has adopted it. |
| 13: Test set contents and Evidence retained | Is the test evidence retained in a form an auditor or a transparency record can reference? | NIST AI RMF (Measure); ISO/IEC 42001 (performance evaluation); records management | Retain test sets and results with the release record | Release evidence pack | Test owner | Every release | US: Freedom of Information Act and Federal Records Act. EU: Regulation 1049/2001 on public access to documents. Canada: Access to Information Act. Australia: Freedom of Information Act 1982. New Zealand: Official Information Act 1982. South Africa: Promotion of Access to Information Act 2000. |
| 13: Model change trigger | Does a provider model change require re-test, re-assessment or a fresh transparency record? | ITIL (change enablement); AI Playbook (principle 5); ATRS (update when the tool changes materially) | Treat a model change as a change request; re-run the test set; review the transparency record | Change record with re-test result | Library owner with the product owner | The model provider announces a version change | US: federal AI use case inventory under the current Office of Management and Budget AI memorandum. EU: AI Act registration in the EU database for high-risk systems and the transparency obligations. Canada: Directive on Automated Decision-Making, published Algorithmic Impact Assessment. Australia: transparency statement under the policy for the responsible use of AI in government. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 15: Who receives the outcome and Visibility and challenge route | Do affected people know an algorithmic tool is involved, and how to challenge its output? | ATRS (public description); Data Ethics Framework; AI Playbook (principle 4); Service Standard (point 5) | Publish the plain-language description and the challenge route; test it with users | Published description and challenge route | Service owner with the transparency lead | Any output reaching a citizen or customer | US: federal AI use case inventory under the current Office of Management and Budget AI memorandum. EU: AI Act registration in the EU database for high-risk systems and the transparency obligations. Canada: Directive on Automated Decision-Making, published Algorithmic Impact Assessment. Australia: transparency statement under the policy for the responsible use of AI in government. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 15: Group the number depends on | Have the people whose behaviour the value depends on been consulted, and is the impact assessment complete? | Equality impact assessment; Service Standard (points 3 and 8, joined-up experience; iterate and improve); change management | Complete the equality impact assessment with the affected group's input before go-live | Completed impact assessment | Equality lead with the business owner | Every item in the standard or strategic lane at Build | US: Title VI of the Civil Rights Act 1964 and agency civil rights offices. EU: Charter of Fundamental Rights and the AI Act fundamental rights impact assessment for public-body deployers. Canada: Canadian Human Rights Act and Gender-based Analysis Plus. Australia: Racial, Sex, Disability and Age Discrimination Acts. New Zealand: Human Rights Act 1993 and New Zealand Bill of Rights Act 1990. South Africa: Constitution section 9 and the Promotion of Equality and Prevention of Unfair Discrimination Act 2000. |
| 16: Training by user group and Reference and job aids | Are staff trained to the level the framework and the workforce policy require, including how to challenge the tool? | AI Playbook (principle 9, skills and expertise); ISO/IEC 42001 (competence and awareness) | Deliver role-based training and retain attendance as competence evidence | Training record | Adoption lead with the line managers | Every item at Build | International standard; the same instrument applies in the US, EU, Canada, Australia, New Zealand and South Africa where the organisation has adopted it. |
| 17: Headcount by role and location and Nature of the effect | Does the change require consultation with staff or their representatives under employment law or policy? | Employment law and consultation duties; equality duty; workforce policy | Route to the human resources lead for the consultation decision before any communication | Consultation decision and plan | Human resources lead | Any role, hours or location effect on staff | US: WARN Act and agency collective bargaining rules. EU: Directive 2002/14/EC on information and consultation of employees. Canada: Canada Labour Code. Australia: Fair Work Act 2009. New Zealand: Employment Relations Act 2000. South Africa: Labour Relations Act 1995. |
| Triage answer: accessibility audit status | Has the interface passed an accessibility audit and is an accessibility statement published? | WCAG 2.2 AA; public-sector accessibility duties; Service Standard (point 5) | Complete the audit, fix or record known issues, publish the statement | Audit report and accessibility statement | Accessibility lead | Before Build closes for any user-facing interface | US: Section 508 of the Rehabilitation Act and the Americans with Disabilities Act. EU: Web Accessibility Directive 2016/2102 and the European Accessibility Act. Canada: Accessible Canada Act. Australia: Disability Discrimination Act 1992 and the Digital Service Standard. New Zealand: New Zealand Government Web Accessibility Standard. South Africa: check local equivalent. |
| Triage answer: hosting, model size and inference volume | Is the energy and carbon footprint known and within the organisation's sustainability commitments? | Technology Code of Practice (point 12, sustainability); sustainability policy | Record hosting region, model size and expected inference volume; request the provider's energy data | Sustainability note on the service record | Sustainability lead with the enterprise architect | Any hosted model or high-volume inference | US: check local equivalent. EU: Energy Efficiency Directive data centre reporting and the Corporate Sustainability Reporting Directive. Canada: Greening Government Strategy. Australia: APS Net Zero 2030 commitment. New Zealand: Carbon Neutral Government Programme. South Africa: check local equivalent. |
| Triage answer: service assessment due | Does the service meet the service standard your organisation applies before it goes live? | Service Standard (all points; UK service assessments); Technology Code of Practice | Book the service assessment and prepare evidence from canvases 05, 15 and 16 | Service assessment report | Service owner | Any public-facing service above the local assessment threshold | US: 21st Century Integrated Digital Experience Act and the US Web Design System. EU: check local equivalent. Canada: Government of Canada Digital Standards. Australia: Digital Service Standard. New Zealand: Digital Service Design Standard. South Africa: check local equivalent. |
3.6 Review gate
Gate: Review (stage Realise). Canvases 18 Benefits Realisation, 19 Value Realisation Review and 20 Capability Roadmap. The rows here return evidence to the frameworks that asked for it and reopen assessments when the world changes.
| Canvas and field | Question | Framework | Process | Output | Owner | Trigger | Equivalents |
|---|---|---|---|---|---|---|---|
| 18: Committed value and date and Readings supplied by | Is value being measured against the baseline in the business case, by an independent reader? | Green Book (monitoring and evaluation); benefits management; BRM Body of Knowledge (value harvesting) | Take readings from the source the business case named; the reader is not the sponsor | Benefits reading | Benefits owner with the finance partner | Each review point | US: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance. |
| 19: Risks that materialised | Did a risk or an incident occur that should be reported under an incident, breach or transparency process? | ISO/IEC 27001 (incident management); data protection law (breach notification); ATRS (update); NIST AI RMF (Manage) | Confirm each materialised risk was reported through the correct route; update the transparency record | Incident and record updates | Product owner with the risk lead | Any materialised risk at the Value Realisation Review | US: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 19: Governance that can relax and Governance that must tighten | Should the risk tier, assurance level or lane change, and who approves the change? | NIST AI RMF (Govern); ISO/IEC 42001 (management review); GOVBRM lanes | Propose the change to the governance forum with the evidence from the review | Governance change decision | AI governance lead | Every Value Realisation Review | US: NIST AI RMF. EU: AI Act risk tiers and obligations. Canada: Directive on Automated Decision-Making and the Guide on the use of generative AI. Australia: policy for the responsible use of AI in government and the AI Ethics Principles. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
| 19: Shadow use and workarounds | Is unsanctioned AI use present, and is it a security, privacy or policy exposure? | ISO/IEC 27001 (acceptable use); data protection law; AI Playbook (principle 2, lawful and ethical use) | Report shadow use to the information security lead and the data protection officer; convert legitimate demand into a new request | Shadow use report and new intake records | Business Relationship Manager | Any shadow use observed | US: FISMA, NIST SP 800-53 and FedRAMP. EU: NIS2 Directive. Canada: Policy on Government Security and ITSG-33. Australia: Protective Security Policy Framework and the Information Security Manual. New Zealand: Protective Security Requirements and the New Zealand Information Security Manual. South Africa: check local equivalent. |
| 20: Platform play and Funding route and horizon | Is a shared capability better funded as a platform, and does it need its own business case? | Green Book (programme business case); enterprise architecture (platform strategy); Technology Code of Practice (points 3 and 9) | Open a programme-level business case for the platform; record the dependent demands | Platform business case | Enterprise architect with the finance partner | Two or more demands need the same capability | US: OMB Circular A-11 (capital planning) and Circular A-94 (benefit-cost analysis). EU: check local equivalent (member state rules). Canada: Treasury Board Directive on the Management of Projects and Programmes. Australia: Department of Finance business case guidance and the ICT investment approval process. New Zealand: Treasury Better Business Cases. South Africa: Public Finance Management Act 1999 and National Treasury guidance. |
| 20: Signals that force early review | Has a law, policy, model or supplier change occurred that invalidates an assessment already made? | ISO/IEC 42001 (management review); ATRS (update); procurement policy (contract change) | Reopen the affected assessments and records; refresh the roadmap | Refreshed roadmap and reopened assessments | Refresh owner | A named signal fires | US: federal AI use case inventory under the current Office of Management and Budget AI memorandum. EU: AI Act registration in the EU database for high-risk systems and the transparency obligations. Canada: Directive on Automated Decision-Making, published Algorithmic Impact Assessment. Australia: transparency statement under the policy for the responsible use of AI in government. New Zealand: Algorithm Charter for Aotearoa New Zealand. South Africa: check local equivalent. |
Row count: 58.
4. ATRS applicability prompt
GOVBRM does not decide whether the Algorithmic Transparency Recording Standard, or any other transparency register, applies to a tool. That decision belongs to the published guidance and to the person in your organisation who owns transparency records. This prompt is a scoping aid at the Shape gate (canvas 05, AI Risk and Ethics). It sorts a request into one of four outcomes, records the basis for that reading, and routes it to the authoritative guidance for confirmation. Whichever outcome you reach, write the basis down and name who confirms it, and by when. Outside the UK, run the same prompt against your own transparency instrument: the federal AI use case inventory in the US, the EU AI Act database and transparency obligations, Canada's Algorithmic Impact Assessment, Australia's transparency statements, New Zealand's Algorithm Charter, or your local equivalent. Label: GOVBRM original prompt over an established standard, not yet validated.
Ask, with the canvas 02 and 05 entries in front of you:
- Is the organisation a public body or acting on behalf of one, in a jurisdiction with a transparency record requirement?
- Does the tool use an algorithm, model or automated process to make, recommend or materially shape a decision, or to interact directly with the public?
- Could the tool have a direct or indirect effect on a person's rights, entitlements, access to a service or treatment by the organisation?
- Is the tool in live use or planned for live use, rather than exploratory or purely internal administration with no public effect?
- Does published guidance, or an internal policy, name an exemption or exception that might apply (for example national security or an internal tool with no public effect)?
Then record one of four outcomes.
| Outcome | When | Action |
|---|---|---|
| Not in scope | The reading against the published guidance is that none of the scoping conditions is met: no public-facing effect, no decision influence, or the organisation is outside the standard's coverage. | Record the basis and the guidance version consulted. Name who confirmed the reading. Set a re-check trigger: any change to the tool's use, population or autonomy rung reopens the question. |
| Potentially in scope, confirm | One or more scoping conditions is met or uncertain, and the reading cannot be settled from the canvas alone. | Route to the transparency lead with the shaped need, the autonomy rung, the blast radius and the data scope. Do not proceed past Commit until the reading is confirmed against the published guidance. Record the confirmation. |
| In scope, record required | The transparency lead confirms, against the published guidance, that a record is required. | Open the record using the standard's own template and fields. Feed it from canvases 02, 05, 11 and 15. Set the owner, the publication route and the update triggers (model change, scope change, retirement). Publication is a Commit condition or a Build condition, as the guidance directs. |
| Exemption or exception, document basis | The transparency lead confirms that an exemption or exception in the published guidance applies. | Record the specific exemption or exception, the guidance reference, who decided and the date. Keep an internal record with the same fields, so the reading can be revisited. Set a review trigger for changes in use or guidance. |
GOVBRM never states that a tool is legally in or out of scope. Every outcome above is a reading to be confirmed by the transparency lead against the current published guidance, and the confirmation is what is recorded.
5. What GOVBRM does not replace
GOVBRM is the operating layer between AI demand and AI delivery. It decides which demand receives attention, money, autonomy and organisational change, and routes each item into the governance the organisation already has. It is not a substitute for any of the following, and a row in this compiler is a routing instruction, not a replacement for the process it routes to.
- Business cases and their appraisal method (the Green Book five case model is one version)
- Procurement and commercial assurance
- Security assurance and the information risk process (ISO/IEC 27001 or local equivalent)
- Privacy and data protection impact assessments
- Equality, anti-discrimination and human rights assessments
- Transparency records and registers (ATRS and equivalents)
- Service or delivery assessments (Service Standard and equivalents)
- An ISO/IEC 42001 AI management system, or ISO/IEC 38500 IT governance
- ITIL service management, enterprise architecture, and delivery methods
- Accessibility audits and statements, sustainability assessments, employment consultation
- Legal advice on whether any statute, standard or duty applies
Where a decision needs a lawyer, a data protection officer, an accountant, an accessibility auditor or the accountable executive, the row says so through its owner column, and GOVBRM stops at the handoff.
