Govern
Whose ideas these are.
The attribution record behind the provenance page: sources, originals, adaptations and marks.
GOVBRM IP provenance and attribution statement
Status: draft v0.1, GOVBRM original, not yet validated.
Purpose
It uses the four labels used across GOVBRM: Established (externally supported), Adapted (existing practice modified), GOVBRM original (written here first), Hypothesis (not yet validated).
Summary
| Layer | What it is | Label | Attribution position |
|---|---|---|---|
| Ideas from Business Relationship Management | Relationship as a strategic capability, demand shaping, value realisation, value optimisation | Established | Ideas only, expressed in GOVBRM's own words; no text, diagrams, tables or course material reproduced |
| Public-sector guidance | Business case appraisal, service standards, technology codes, data ethics, transparency recording | Established | Named as frameworks, with published principle numbering; nothing reproduced beyond names and numbering |
| External standards | AI risk management, AI management systems, IT governance, information security, service management | Established | Named as the layers GOVBRM sits beside; not reproduced; no certification, affiliation or endorsement claimed |
| GOVBRM terminology, stages, gates, lanes, ladder, review | The six stages, six gates, three lanes, autonomy ladder, Value Realisation Review | GOVBRM original | Claimed as GOVBRM's own expression and arrangement |
| Twenty canvases | Fields, prompts, scales, scoring parameters | GOVBRM original (design); Hypothesis (weights and thresholds) | Claimed as GOVBRM's own; calibration parameters marked as initial |
| Diagrams | AI Value Operating Model, Academy architecture, crosswalk diagram, Front Door poster | GOVBRM original | Claimed as GOVBRM's own artwork |
| Adapted models | Value as a range with named conditions; three value conversations | Adapted | Source practice named; adaptation described |
| Third-party trade marks | Names of standards, frameworks, bodies and platforms | Not GOVBRM's | Named only as belonging to their owners |
| Licensed material | None known | Not applicable | See "Licensed material" below |
What is drawn from Business Relationship Management
Label: Established.
GOVBRM's intellectual lineage is the discipline of Business Relationship Management as described in the BRM Body of Knowledge published by BRM Institute. The ideas used are:
- relationship as a strategic capability rather than a service desk function
- demand shaping: the request is not the need, and the relationship role shapes demand before it becomes a project
- value realisation and value optimisation as distinct activities that continue after delivery
- the value lifecycle as a set of conversations with partners rather than a reporting duty
How they are used: the ideas are applied to a specific problem, AI demand in public and regulated organisations, and expressed in GOVBRM's own words. No text, definitions, diagrams, tables, course material, examination material or assessment material from the Body of Knowledge or from any BRM Institute course is reproduced, paraphrased at length, or used as a template.
What is drawn from public-sector sources
Label: Established.
The following are read, named and mapped in the crosswalk. Their published principle numbering is referred to so that readers can check the mapping against the current text. Nothing else is reproduced.
- Green Book (UK): appraisal and the five case model, referenced as the destination of the business case canvas, not replaced by it
- AI Playbook (UK): its ten principles, referenced by number at the Shape and Commit gates
- Technology Code of Practice (UK): its points, referenced by number from the Design canvases
- Service Standard (UK): its points, referenced by number from Discover and Adopt
- Data Ethics Framework (UK): referenced as the destination for ethics review
- Algorithmic Transparency Recording Standard (UK): referenced as the destination for a transparency record; its scoping question is asked in the risk canvas
- Equivalents in other jurisdictions, named in the crosswalk at a high level: the EU AI Act and GDPR, the NIST AI Risk Management Framework, Canada's Directive on Automated Decision-Making and its Algorithmic Impact Assessment, Australia's policy for the responsible use of AI in government and Digital Service Standard, New Zealand's Algorithm Charter for Aotearoa New Zealand
Non-UK guidance is used only by name and stated purpose. Its licence terms have not been checked because nothing is reproduced. Not yet demonstrated: that every mapping in the crosswalk is accurate against the current text of each instrument.
What is drawn from external frameworks and standards
Label: Established.
Named as the layers GOVBRM sits beside, and not reproduced:
- NIST AI Risk Management Framework (Govern, Map, Measure, Manage named as its functions)
- ISO/IEC 42001 (AI management systems)
- ISO/IEC 38500 (governance of IT)
- ISO/IEC 27001 (information security management)
- ITIL (service management)
- PRINCE2, agile and product management, named in the crosswalk as delivery methods GOVBRM does not replace
Standards published by ISO and IEC are copyright works sold under licence. GOVBRM does not reproduce clause text, clause numbering, tables or annexes from any of them. GOVBRM is not certified against, affiliated with or endorsed by any standards body or framework publisher, and says so on the site.
What is GOVBRM original
Label: GOVBRM original, unless marked Hypothesis.
Terminology and arrangement:
- "the operating layer between AI demand and AI delivery" as the positioning statement
- the six stages: Discover, Assess, Prioritise, Design, Adopt, Realise
- the six gates: Request, Shape, Rank, Commit, Build, Review, and the front door as a model of demand rather than delivery
- the three lanes: fast, standard, strategic, with the rule "governance burden in proportion to blast radius"
- the autonomy ladder as a shaping question, "the lowest rung that solves the task", with its five rungs and four agent questions. As a proxy for risk the ladder is a Hypothesis
- the Value Realisation Review with its default at month nine, and the loop that sends lessons back to the front door. The month-nine default is a Hypothesis
- the three value conversations (planning, realisation, optimisation) as a structure for the Value Orchestration Workbook. This is Adapted from the BRM value lifecycle, and the split into three named conversations is GOVBRM's expression
The twenty canvases, by stage, each with its fields, prompts and scales:
- Discover: AI Opportunity Canvas, AI Demand Shaping Canvas
- Assess: AI Request Intake Canvas, AI Readiness Canvas, AI Risk and Ethics Canvas
- Prioritise: AI Demand Value Map, AI Use Case Prioritisation Canvas, AI Portfolio Heatmap
- Design: AI Business Case Canvas, AI Playbook Builder, AI Agent Assessment Canvas, AI Vendor Evaluation Canvas, AI Prompt Governance Canvas, AI Product Ownership Canvas
- Adopt: AI Stakeholder Impact Canvas, AI Adoption Canvas, AI Workforce Impact Canvas
- Realise: AI Benefits Realisation Canvas, AI Value Realisation Review, AI Capability Roadmap Canvas
Scoring weights, thresholds, readiness bands, vendor bands and exposure floors inside the canvases are Hypothesis: initial calibration parameters, version 1.0, to be adjusted through use and evidence.
Diagrams and artwork, all drawn for GOVBRM: the AI Value Operating Model diagram, the Academy architecture diagram, the crosswalk diagram, the Front Door poster, the badge designs, the certificate templates, the Academy lockup and wordmarks.
Written works: the AI Demand Framework (thirteen chapters), the three free micro-courses, the practitioner masterclass material, the Value Orchestration Workbook, the newsletter essays, the provenance and crosswalk pages, the collateral pack.
Software: the static site, the toolkit runtime, the course runtime, the credential and verification scripts, the course builder and the badge, lockup and certificate generators. See the diligence checklist for the questions about authorship and tooling that sit behind this claim.
Adapted models
Label: Adapted.
| GOVBRM element | Source practice | What was changed |
|---|---|---|
| Value as a range with named conditions | Benefits management and appraisal practice on uncertainty and optimism bias | Expressed as a low, expected and high range tied to named conditions on a single canvas, rather than a point estimate with an adjustment |
| Three value conversations | The BRM value lifecycle | Split into planning, realisation and optimisation as three separately scheduled conversations with their own prompts |
| Deployment is not use | Change management and benefits management practice | Adoption measured from the work, made a gate condition at Build and a review question at Review |
| Risk canvas as triage | Risk assessment practice generally | Deliberately reduced to a routing device that sends the item to the assessments that do the full work; not a risk methodology |
| Business case canvas | Five case model thinking | Reduced to the questions that must be answered before a business case is started; it does not replace one |
Third-party trade marks
The following names appear on the site or in the method material and belong to their owners. GOVBRM claims none of them, uses them only to identify the thing named, and does not claim affiliation, endorsement or certification. The list is maintained here so the site's trade mark line can be checked against it.
- BRM Body of Knowledge, BRMBoK and BRM Institute
- Green Book, AI Playbook, Technology Code of Practice, Service Standard, Data Ethics Framework, Algorithmic Transparency Recording Standard (UK government publications)
- NIST AI Risk Management Framework (NIST)
- ISO/IEC 42001, ISO/IEC 38500, ISO/IEC 27001 (ISO and IEC)
- ITIL and PRINCE2 (their current rights holder)
- EU AI Act and GDPR (European Union legislation; not marks, but named)
- Directive on Automated Decision-Making and Algorithmic Impact Assessment (Government of Canada)
- Digital Service Standard and the policy for the responsible use of AI in government (Australian Government)
- Algorithm Charter for Aotearoa New Zealand (New Zealand Government)
- Substack, Stripe, GitHub and GitHub Pages, LinkedIn (platform operators named on the privacy and terms pages)
Licensed material
None known. As at this draft:
- no text, images, fonts or diagrams are used under a paid licence
- the site uses system font stacks; if a font is later embedded, its licence must be recorded here
- no stock photography or illustration is used
- no material generated under a third-party subscription with usage restrictions is knowingly published; see the diligence checklist on AI-generated material
Attribution rules GOVBRM applies to itself
- Name a framework, never reproduce it, unless the licence has been checked and the attribution wording added
- Refer to principle numbers so readers can check the mapping against the current text
- State plainly on every page where a standard is named that GOVBRM is not certified against, affiliated with or endorsed by its publisher
- Keep "written from practice" (provenance) separate from "validated" (evidence); the site does this and this statement does too
- Record every change to lineage, adaptation or licensing in the version history on the provenance page
Bibliography of framework and standard names
Names only. No authors, editions, page numbers or invented citations. The reader should consult the current published text of each.
Business Relationship Management
- BRM Body of Knowledge (BRM Institute)
UK public guidance
- Green Book
- AI Playbook
- Technology Code of Practice
- Service Standard
- Data Ethics Framework
- Algorithmic Transparency Recording Standard
Standards and frameworks
- NIST AI Risk Management Framework
- ISO/IEC 42001
- ISO/IEC 38500
- ISO/IEC 27001
- ITIL
- PRINCE2
Other jurisdictions
- EU AI Act
- GDPR and UK GDPR
- Directive on Automated Decision-Making and Algorithmic Impact Assessment (Canada)
- Policy for the responsible use of AI in government and Digital Service Standard (Australia)
- Algorithm Charter for Aotearoa New Zealand (New Zealand)
- Equivalents in the United States, South Africa and elsewhere are referred to generically on the site and are not listed by name here until each has been read
