Crosswalk
The layer between AI demand and AI delivery.
GOVBRM is not another AI governance framework. It is the operating layer that decides which AI demand should receive money, attention, autonomy and organisational change, and routes each item into the governance an organisation already has. This page shows where each stage hands off, and what GOVBRM does not replace.
What GOVBRM does not replace. Business cases and Green Book appraisal, procurement and commercial assurance, security assurance, data protection impact assessments, equality impact assessments, algorithmic transparency records, service assessments, an ISO/IEC 42001 management system, or delivery methods such as agile, PRINCE2 or product management. GOVBRM routes demand into them, in the right order, with the need, the value range, the autonomy rung and the owner already written down.
Different questions, different layers
Each framework answers its own question. GOVBRM answers the one before them.
| Framework | The question it answers | Where GOVBRM meets it |
|---|---|---|
| BRM Body of Knowledge (BRM Institute) | How does a relationship function create value with its partners? | Intellectual lineage: demand shaping, value realisation and value optimisation, expressed in GOVBRM's own words for AI demand. |
| UK AI Playbook | How should government use AI responsibly? Ten principles. | The Shape and Commit gates carry the principles on limitations, lawful and ethical use, security, human control, lifecycle, the right tool, commercial involvement and assurance. |
| Green Book | Is this investment worth it, against which options, and did it deliver? | The business case canvas feeds a five case model business case; it does not replace one. The Realise stage feeds monitoring and evaluation. |
| Technology Code of Practice | Is this technology designed, bought and run well? | User needs, accessibility, open standards, integration, purchasing strategy and sustainability are routed from the Design canvases. |
| Service Standard | Is this a good public service? | Discover and Adopt hand off to user research, whole-problem thinking, accessibility and performance data. |
| Data Ethics Framework and ATRS | Is the use of data and algorithms transparent, accountable and fair? | The risk canvas asks the scoping question for an algorithmic transparency record and routes to ethics review, contestability and redress. |
| NIST AI Risk Management Framework | How do we manage AI risk across the lifecycle? Govern, Map, Measure, Manage. | GOVBRM sits before and around it: it decides what enters the lifecycle and checks that value arrived. Assess maps, Realise measures. |
| ISO/IEC 42001 | How do we run an AI management system? | GOVBRM is not a management system and not an alternative to one. It can be the operational front door into one, and its records are evidence for it. |
| GOVBRM | Which AI demand should receive attention, money, autonomy and change, and did the value arrive? | Six stages, six gates, twenty canvases, one review that closes the loop. |
Stage by stage
Where each stage hands off.
| GOVBRM stage and canvases | UK government guidance it routes into | Standards | BRM Body of Knowledge |
|---|---|---|---|
| Discover 01 Opportunity, 02 Demand Shaping | Service Standard 1 and 2 (understand users and their needs; solve a whole problem). AI Playbook principles 1 and 6 (know what AI is and its limitations; the right tool for the job). Technology Code of Practice 1 (define user needs). | NIST AI RMF: Map. | Demand shaping; relationship strategy. |
| Assess 03 Intake, 04 Readiness, 05 Risk and Ethics | AI Playbook principles 2, 3 and 4 (lawful and ethical; secure; meaningful human control). Data Ethics Framework. Data protection impact assessment where personal data is involved. Equality impact assessment. The ATRS scoping question. Technology Code of Practice 6, 7 and 10 (secure; privacy; data). | NIST AI RMF: Map and Measure. ISO/IEC 42001: AI risk and impact assessment. | Value discovery; readiness. |
| Prioritise 06 Value Map, 07 Prioritisation, 08 Portfolio Heatmap | Green Book strategic case and option thinking. Portfolio management. AI Playbook principle 8 (work with commercial colleagues from the start). | NIST AI RMF: Govern. | Portfolio and value planning. |
| Design 09 Business Case, 10 Playbook, 11 Agent, 12 Vendor, 13 Prompt Governance, 14 Product Ownership | Green Book five case model (the canvas feeds it). Technology Code of Practice 3, 4, 9, 11 and 12 (open source; open standards; integrate and adapt; purchasing strategy; sustainability). AI Playbook principles 5, 8 and 10 (lifecycle; commercial; assurance). ATRS record where in scope. Security assurance. | NIST AI RMF: Govern and Manage. ISO/IEC 42001: lifecycle and supplier controls. | Business case; value planning. |
| Adopt 15 Stakeholder Impact, 16 Adoption, 17 Workforce Impact | Service Standard 3, 5, 7 and 8 (joined-up experience; everyone can use the service; agile; iterate). Technology Code of Practice 2 (accessible and inclusive). AI Playbook principle 9 (skills and expertise). Change management. | NIST AI RMF: Manage. | Value realisation; organisational change. |
| Realise 18 Benefits Realisation, 19 Value Review, 20 Capability Roadmap | Green Book monitoring and evaluation. Service Standard 10 (define success and publish performance data). Benefits management. AI Playbook principle 5 (the full lifecycle). | NIST AI RMF: Measure and Manage. ISO/IEC 42001: performance evaluation and improvement. | Value harvesting; value optimisation. |
Framework and standard names belong to their publishers. GOVBRM reproduces none of their text and is not affiliated with, endorsed by or certified against any of them. Numbers refer to the published principles and points of each document at the time of writing; check the current edition.
One demand, one journey, many assurance outputs
The Shape and Commit gates produce the inputs the other assurances need.
The problem in most organisations is not an absence of governance but its fragmentation: the same request is described five different ways to five different boards. A shaped request carries one need statement, one value range, one autonomy rung, one owner and one set of risk flags, and those feed:
- A data protection impact assessment, where personal data is processed
- An equality impact assessment, and a human rights assessment where relevant
- An algorithmic transparency record, for central government tools in scope
- Security assurance and the information risk process
- Commercial and procurement assessment, including exit and lock-in
- The business case, on the five case model where it applies
- The service assessment, where the Service Standard applies
- Evidence for an ISO/IEC 42001 management system, where one exists
- A sustainability assessment: model size, inference volume, hosting and energy
- Accessibility, contestability, redress and human review for the people affected
Keep the door light
Governance burden in proportion to blast radius.
Twenty canvases and six gates would be a new bureaucracy if every request went through all of them. They do not. The front door routes by consequence, and most demand never needs more than a page.
Fast lane
Low risk, a known pattern, low autonomy. Self-service against a published pattern; no canvas beyond the intake record.
Standard lane
Moderate risk or value. BRM shaping at the Shape gate, a readiness score, and the Commit gate with an owner and a number.
Strategic lane
High consequence, public-facing, cross-boundary or high autonomy. Multidisciplinary governance, the full assurance set above, and the strategic portfolio view.
Every lane
Autonomy is one dimension of risk, alongside consequence, scale, reversibility, the population affected and how quickly a failure would be noticed. And one question is asked of every item: who bears the benefit, who bears the cost, and who has no seat at the table?
Status of the numbers
Initial calibration, version 1.0.
The scoring weights, the readiness and vendor thresholds, the exposure floors, the five-rung autonomy ladder and the month-nine default are practitioner design decisions, not measured constants. They are published so that they can be argued with and calibrated through use. Set the review point from the intervention's own value curve: a chatbot may show value in a month, a fraud model may take two years; nine months is the default, not a rule. The status of every mechanism, and what is still a hypothesis, is on the provenance page.
