Back to GOVBRM

Crosswalk

The layer between AI demand and AI delivery.

GOVBRM is not another AI governance framework. It is the operating layer that decides which AI demand should receive money, attention, autonomy and organisational change, and routes each item into the governance an organisation already has. This page shows where each stage hands off, and what GOVBRM does not replace.

What GOVBRM does not replace. Business cases and Green Book appraisal, procurement and commercial assurance, security assurance, data protection impact assessments, equality impact assessments, algorithmic transparency records, service assessments, an ISO/IEC 42001 management system, or delivery methods such as agile, PRINCE2 or product management. GOVBRM routes demand into them, in the right order, with the need, the value range, the autonomy rung and the owner already written down.

Different questions, different layers

Each framework answers its own question. GOVBRM answers the one before them.

FrameworkThe question it answersWhere GOVBRM meets it
BRM Body of Knowledge (BRM Institute)How does a relationship function create value with its partners?Intellectual lineage: demand shaping, value realisation and value optimisation, expressed in GOVBRM's own words for AI demand.
UK AI PlaybookHow should government use AI responsibly? Ten principles.The Shape and Commit gates carry the principles on limitations, lawful and ethical use, security, human control, lifecycle, the right tool, commercial involvement and assurance.
Green BookIs this investment worth it, against which options, and did it deliver?The business case canvas feeds a five case model business case; it does not replace one. The Realise stage feeds monitoring and evaluation.
Technology Code of PracticeIs this technology designed, bought and run well?User needs, accessibility, open standards, integration, purchasing strategy and sustainability are routed from the Design canvases.
Service StandardIs this a good public service?Discover and Adopt hand off to user research, whole-problem thinking, accessibility and performance data.
Data Ethics Framework and ATRSIs the use of data and algorithms transparent, accountable and fair?The risk canvas asks the scoping question for an algorithmic transparency record and routes to ethics review, contestability and redress.
NIST AI Risk Management FrameworkHow do we manage AI risk across the lifecycle? Govern, Map, Measure, Manage.GOVBRM sits before and around it: it decides what enters the lifecycle and checks that value arrived. Assess maps, Realise measures.
ISO/IEC 42001How do we run an AI management system?GOVBRM is not a management system and not an alternative to one. It can be the operational front door into one, and its records are evidence for it.
GOVBRMWhich AI demand should receive attention, money, autonomy and change, and did the value arrive?Six stages, six gates, twenty canvases, one review that closes the loop.

Stage by stage

Where each stage hands off.

GOVBRM stage and canvasesUK government guidance it routes intoStandardsBRM Body of Knowledge
Discover
01 Opportunity, 02 Demand Shaping
Service Standard 1 and 2 (understand users and their needs; solve a whole problem). AI Playbook principles 1 and 6 (know what AI is and its limitations; the right tool for the job). Technology Code of Practice 1 (define user needs).NIST AI RMF: Map.Demand shaping; relationship strategy.
Assess
03 Intake, 04 Readiness, 05 Risk and Ethics
AI Playbook principles 2, 3 and 4 (lawful and ethical; secure; meaningful human control). Data Ethics Framework. Data protection impact assessment where personal data is involved. Equality impact assessment. The ATRS scoping question. Technology Code of Practice 6, 7 and 10 (secure; privacy; data).NIST AI RMF: Map and Measure. ISO/IEC 42001: AI risk and impact assessment.Value discovery; readiness.
Prioritise
06 Value Map, 07 Prioritisation, 08 Portfolio Heatmap
Green Book strategic case and option thinking. Portfolio management. AI Playbook principle 8 (work with commercial colleagues from the start).NIST AI RMF: Govern.Portfolio and value planning.
Design
09 Business Case, 10 Playbook, 11 Agent, 12 Vendor, 13 Prompt Governance, 14 Product Ownership
Green Book five case model (the canvas feeds it). Technology Code of Practice 3, 4, 9, 11 and 12 (open source; open standards; integrate and adapt; purchasing strategy; sustainability). AI Playbook principles 5, 8 and 10 (lifecycle; commercial; assurance). ATRS record where in scope. Security assurance.NIST AI RMF: Govern and Manage. ISO/IEC 42001: lifecycle and supplier controls.Business case; value planning.
Adopt
15 Stakeholder Impact, 16 Adoption, 17 Workforce Impact
Service Standard 3, 5, 7 and 8 (joined-up experience; everyone can use the service; agile; iterate). Technology Code of Practice 2 (accessible and inclusive). AI Playbook principle 9 (skills and expertise). Change management.NIST AI RMF: Manage.Value realisation; organisational change.
Realise
18 Benefits Realisation, 19 Value Review, 20 Capability Roadmap
Green Book monitoring and evaluation. Service Standard 10 (define success and publish performance data). Benefits management. AI Playbook principle 5 (the full lifecycle).NIST AI RMF: Measure and Manage. ISO/IEC 42001: performance evaluation and improvement.Value harvesting; value optimisation.

Framework and standard names belong to their publishers. GOVBRM reproduces none of their text and is not affiliated with, endorsed by or certified against any of them. Numbers refer to the published principles and points of each document at the time of writing; check the current edition.

One demand, one journey, many assurance outputs

The Shape and Commit gates produce the inputs the other assurances need.

The problem in most organisations is not an absence of governance but its fragmentation: the same request is described five different ways to five different boards. A shaped request carries one need statement, one value range, one autonomy rung, one owner and one set of risk flags, and those feed:

  • A data protection impact assessment, where personal data is processed
  • An equality impact assessment, and a human rights assessment where relevant
  • An algorithmic transparency record, for central government tools in scope
  • Security assurance and the information risk process
  • Commercial and procurement assessment, including exit and lock-in
  • The business case, on the five case model where it applies
  • The service assessment, where the Service Standard applies
  • Evidence for an ISO/IEC 42001 management system, where one exists
  • A sustainability assessment: model size, inference volume, hosting and energy
  • Accessibility, contestability, redress and human review for the people affected

Keep the door light

Governance burden in proportion to blast radius.

Twenty canvases and six gates would be a new bureaucracy if every request went through all of them. They do not. The front door routes by consequence, and most demand never needs more than a page.

  1. Fast lane

    Low risk, a known pattern, low autonomy. Self-service against a published pattern; no canvas beyond the intake record.

  2. Standard lane

    Moderate risk or value. BRM shaping at the Shape gate, a readiness score, and the Commit gate with an owner and a number.

  3. Strategic lane

    High consequence, public-facing, cross-boundary or high autonomy. Multidisciplinary governance, the full assurance set above, and the strategic portfolio view.

  4. Every lane

    Autonomy is one dimension of risk, alongside consequence, scale, reversibility, the population affected and how quickly a failure would be noticed. And one question is asked of every item: who bears the benefit, who bears the cost, and who has no seat at the table?

Status of the numbers

Initial calibration, version 1.0.

The scoring weights, the readiness and vendor thresholds, the exposure floors, the five-rung autonomy ladder and the month-nine default are practitioner design decisions, not measured constants. They are published so that they can be argued with and calibrated through use. Set the review point from the intervention's own value curve: a chatbot may show value in a month, a fraud model may take two years; nine months is the default, not a rule. The status of every mechanism, and what is still a hypothesis, is on the provenance page.

Dates come to subscribers first

Courses and certifications are announced in the GOVBRM Newsletter before anywhere else.

Subscribe free for the essays behind the framework, the access code for the free course, and first word of every cohort.