Back to GOVBRM

Understand

Method Specification v1.0.

The method stated once, under change control, with every component labelled established, adapted, GOVBRM original or hypothesis.

GOVBRM Method Specification v1.0

Status: draft v1.0, GOVBRM original with adapted and established components labelled throughout, not yet validated.

1. Purpose

This document is the written specification of the GOVBRM method. It fixes, in one place and under change control, what the method is: its stages, gates, canvases, lanes, models and rules. Everything else GOVBRM publishes (the AI Demand Toolkit, the AI Demand Framework, the courses, the workbook, the crosswalk and the provenance page) is an expression of what is written here. Where a published artefact and this specification disagree, this specification is the reference and the artefact is corrected.

It exists for four readers:

  • practitioners who run a front door and want the rules stated once, without the teaching around them;
  • sponsors, finance partners and assurance colleagues who want to know what the method will ask of them and when;
  • people building tools, courses or assessments on the method, who need a stable definition to build against;
  • reviewers, now and later a Method Council, who need a baseline to argue with and a process for changing it.

Label: GOVBRM original.

2. Scope

In scope:

  • demand for AI capability arriving in a public or regulated organisation by any route, including demand nobody has yet requested;
  • the decisions between an observation and a funded build, and between a handover and a review of the value that arrived;
  • the records those decisions leave behind, and what those records feed.

Out of scope, and never replaced by GOVBRM:

  • business cases and their appraisal method;
  • procurement and commercial assurance;
  • security assurance and information risk;
  • privacy and data protection assessments;
  • equality, anti-discrimination and human rights assessments;
  • transparency records and registers;
  • service and delivery assessments;
  • AI management systems such as those built to ISO/IEC 42001;
  • delivery methods, whether agile, stage-gated or product-led;
  • the engineering of the solution itself.

GOVBRM is written for public and regulated organisations anywhere. Wherever this document names a framework it is as one version of a type of instrument; the reader substitutes their own jurisdiction's equivalent.

Label: GOVBRM original (the scope boundary); Established (the existence and purpose of the governance it routes into).

3. Definitions

TermDefinitionLabel
AI demandAny request, opportunity or observation that would, if acted on, put a model or an autonomous system into an organisation's work.GOVBRM original
Front doorThe single route by which AI demand enters the organisation's decision-making. One route in, no wrong door.Adapted (from service management and BRM intake practice)
Relationship layerThe people who do the work of Business Relationship Management, under that title or another: business partners, engagement leads, product and portfolio leads. They sign four of the six gates.Adapted (BRM Body of Knowledge)
PartnerThe business function or service whose outcome the demand serves, and whose sponsor puts their name to the request.Adapted (BRM Body of Knowledge)
StageOne of six phases of work between an observation and a review: Discover, Assess, Prioritise, Design, Adopt, Realise.GOVBRM original
GateA decision point with a named question, a named signatory and a record. Six gates: Request, Shape, Rank, Commit, Build, Review.GOVBRM original
CanvasA single-page structured working document that leads to one decision, completed in a working session of about ninety minutes. Twenty in the toolkit.GOVBRM original
LaneThe governance route an item takes according to its blast radius: fast, standard or strategic.GOVBRM original
Blast radiusWhat a wrong output reaches before a person sees it: a draft, a record, a payment, a citizen or customer, another organisation.Adapted (from engineering and incident practice)
Autonomy rungThe position of a proposed solution on the five-rung autonomy ladder.GOVBRM original
Need sentenceThe need, the gap, the observed cause and the cost, in one sentence, with no tool, model or rung in it.GOVBRM original
Value rangeA lower and upper bound of expected value in the partner's own unit, with the conditions for the upper half stated and the probability kept separate.Adapted (benefits management practice on uncertainty)
Committed numberThe value figure a named business owner signs at the Commit gate and is reviewed against at the Review gate.GOVBRM original
Business ownerThe named role that signs the committed number and owns the benefit after handover. Not the requester by default, and never the build team.Adapted (benefits management)
Value Realisation ReviewThe Review gate session at which measured value is set against the committed number. Default at month nine after go-live, booked at Commit.GOVBRM original
Exposure ratingThe output of the risk and ethics triage: Standard, Elevated or Significant.GOVBRM original
Three value conversationsValue planning, value realisation and value optimisation, treated as three distinct bookable conversations.Adapted (BRM value lifecycle)

4. Principles

Each principle is a rule the method is built to enforce. Where two principles pull against each other, the earlier one in this list takes precedence.

NumberPrincipleWhat it means in practiceLabel
P1The request is not the needNothing is shaped, ranked or funded on the request as stated. The need sentence is written first and contains no solution.Established (user-centred design and BRM demand shaping)
P2Minimum necessary governanceAn item receives the least governance that its blast radius requires and no more. The default is the lightest lane; the burden rises only when a criterion is met.GOVBRM original
P3Governance burden in proportion to blast radiusThe lane, the number of canvases, the assurances routed to and the seniority of the signatory are all set by what a wrong output reaches, not by how large the request sounds or who asked.GOVBRM original
P4The lowest rung that solves the taskThe autonomy rung carried forward is the lowest one that closes the need sentence. Every higher rung must name the specific thing the rung below cannot do.GOVBRM original
P5Autonomy is one dimension of risk, not a proxy for itA high rung raises attention; it does not by itself set the exposure rating. A low rung with a large effect is still governed for its effect.GOVBRM original; as a corrective to autonomy-tiered governance it is a Hypothesis
P6A named owner and a number before a buildNothing is committed without a business owner who has signed a value figure and booked the review that will test it.Adapted (benefits management; business case practice)
P7Deployment is not useValue is measured from the change in the work, not from the go-live. Adoption is planned, measured and given a failure trigger.Established (change management and benefits management)
P8The loop closes at the reviewThe Review gate sends what it learns back to the front door: shaping decisions, calibration, capability gaps.GOVBRM original
P9One description, many assurancesA shaped item is described once and routed into the organisation's assurances in the right order. Governance is orchestrated, never duplicated.GOVBRM original
P10Ask who is not in the roomOf every item: who bears the benefit, who bears the cost, and who has no seat at the table.Adapted (public value and equality practice); the modelling of it is Not yet demonstrated
P11Honest declineDecline is a route with reasons the requester can respect, not a silence.GOVBRM original
P12Published numbers are calibration, not constantsWeights, thresholds, scales and the review default are practitioner design decisions published so they can be argued with and adjusted through use.Hypothesis, by construction

5. The six stages

A stage is a phase of work. Each stage hangs on a gate: the stage's work produces what the gate needs to answer its question. Items do not have to pass through every stage; the lane decides which stages are touched and how deeply.

StageWhat it doesCanvasesGate it feedsLabel
DiscoverFinds the need beneath the request or observation and decides whether AI belongs in the answer at all.01, 02Request to ShapeGOVBRM original
AssessRecords the facts, tests readiness and surfaces risk and ethical exposure before any attention is committed.03, 04, 05ShapeGOVBRM original
PrioritiseRanks against the whole portfolio, not one backlog. Value is not priority.06, 07, 08RankGOVBRM original (Adapted from portfolio management)
DesignProduces a named owner and a number, the lowest rung that solves it, decision logic a person wrote, and ownership after launch.09 to 14Commit to BuildGOVBRM original
AdoptPlans the behaviour change, the people it disrupts and the work that changes.15, 16, 17BuildAdapted (change management)
RealiseSets measured value against the committed number, decides what to scale or stop, and sends lessons back to the front door.18, 19, 20ReviewAdapted (benefits management); the return loop is GOVBRM original

Between the stages sit the three value conversations, which are bookable and do not belong to any one gate: value planning (what will this be worth, to whom, by when), value realisation (is the number arriving, and who is changing how they work) and value optimisation (what would make it worth more or cost less). Label: Adapted (BRM value lifecycle).

6. The six gates

A gate is a decision with a question, a signatory and a record. Four of the six gates sit with nobody in most organisations; the relationship layer signs them. Delivery signs Build. Anyone may knock at Request.

GateQuestion it asksWho signsRecord it leavesWhat it produces for external governanceLabel
RequestHas a need been stated honestly, by a sponsor prepared to put their name to it? One route in, no wrong door.Anyone may enter; the partner sponsor signs the statementIntake record (03) and, where it began as an observation, the opportunity statement (01)The single description of the request that every later assessment starts from; the data sensitivity class; the first triage flagsGOVBRM original
ShapeIs the need real, does it need a model at all, and what is the lowest rung that solves it?Relationship layerDemand shaping record (02), readiness verdict (04), exposure rating and register rows (05)The need sentence and value range for the business case; the exposure rating and flags that scope a privacy or data protection assessment, an equality assessment, a transparency record and the ethics forum's review; the rung that sets the depth of security assuranceGOVBRM original
RankWhere does this sit against everything else competing for attention, and does it rank now?Relationship layerWeighted score and portfolio position (07), quarterly value map (06), heatmap decisions (08)The strategic case and option thinking for appraisal; the portfolio view leadership and finance receive; early sight for commercial colleaguesGOVBRM original
CommitWho owns the number, what is it, and at which rung, with which conditions?Relationship layer, countersigned by the sponsoring executive for fundingBusiness case canvas (09), agent assessment (11), vendor conditions (12), ownership table and booked review (14)The inputs to a full business case on whichever appraisal model applies; the read, write, send and spend list for security assurance; commercial and exit conditions for procurement; the transparency record where in scope; the review date for benefits managementGOVBRM original
BuildIs the organisation ready for the change, and does engineering own the how?DeliveryStakeholder, adoption and workforce records (15, 16, 17), prompt governance (13), playbook rules (10)The service or delivery assessment inputs; accessibility and inclusion requirements; consultation evidence for workforce representation; the prompt library and test cases for the management systemGOVBRM original
ReviewDid the value arrive against the number, and what should the organisation do now?Relationship layer; funding changes countersigned by the sponsoring executiveBenefits ledger (18), Value Realisation Review (19), capability roadmap (20)Monitoring and evaluation evidence for appraisal; performance data for service assessment; performance evaluation and improvement evidence for the management system; calibration data for the method itselfGOVBRM original

Gate rules:

  1. A gate is signed by a role that exists in the organisation. If no role exists, the ownership table names one before the gate is signed.
  2. A gate is never signed with an open Significant flag unless the residual risk has been accepted in writing by the accountable executive.
  3. Where a gate returns an item, it returns it to a named canvas with a named reason, not to a queue.
  4. Every gate record is re-run when scope, rung or data source changes. Label: GOVBRM original.

7. The twenty canvases

Each canvas leads to one decision, names the role that completes it, and states which canvases feed it and which it feeds. All twenty are GOVBRM original in their fields, prompts and scales; the practices several of them adapt are noted in the label column.

Lane columns: M is mandatory in that lane; O is optional; C is conditional, mandatory when the stated condition holds; P is a portfolio-level canvas run periodically, not per item. Section 8 sets the conditions.

NumberTitleStageGateFastStandardStrategicLabel
01AI Opportunity CanvasDiscoverRequestOOOGOVBRM original (Adapted from BRM demand shaping)
02AI Demand Shaping CanvasDiscoverRequest to ShapeO (pattern match only)MMGOVBRM original
03AI Request Intake CanvasAssessRequestMMMAdapted (service management intake)
04AI Readiness CanvasAssessShapeOMMGOVBRM original (weights are Hypothesis)
05AI Risk and Ethics CanvasAssessShapeO (flags only)MMGOVBRM original (floors are Hypothesis)
06AI Demand Value MapPrioritiseRankPPPAdapted (BRM demand and value planning)
07AI Use Case Prioritisation CanvasPrioritiseRankOMMAdapted (weighted portfolio scoring; weights are Hypothesis)
08AI Portfolio HeatmapPrioritiseRankPPM and PAdapted (portfolio management)
09AI Business Case CanvasDesignCommitOMMAdapted (business case practice; feeds a full appraisal, never replaces it)
10AI Playbook BuilderDesignCommit to BuildC (per category, before a fast lane pattern is published)C (per category)C (per category)GOVBRM original
11AI Agent Assessment CanvasDesignCommitNot applicableC (rung 4 or 5)MGOVBRM original
12AI Vendor Evaluation CanvasDesignCommit to BuildOC (a supplier or platform is being bought or extended)C (as standard)Adapted (supplier evaluation; bands are Hypothesis)
13AI Prompt Governance CanvasDesignBuildO (published pattern carries it)C (rung 2 or above)MGOVBRM original
14AI Product Ownership CanvasDesignCommit to BuildOMMAdapted (product and benefits ownership)
15AI Stakeholder Impact CanvasAdoptBuildOOMAdapted (stakeholder analysis)
16AI Adoption CanvasAdoptBuildOMMAdapted (change management)
17AI Workforce Impact CanvasAdoptBuildOC (roles, grades or tasks change)MAdapted (workforce and consultation practice)
18AI Benefits Realisation CanvasRealiseReviewOMMAdapted (benefits management)
19AI Value Realisation ReviewRealiseReview (default month nine)O (sampled)MMGOVBRM original
20AI Capability Roadmap CanvasRealiseReviewPPPAdapted (capability planning)

Each canvas ends in a decision with a fixed set of options. The options are part of the specification; adding, removing or renaming one is a change under section 17.

NumberDecision options
01Take to Request; Hold for evidence; Redirect to a neighbour; Park with reasons
02Self-service; Automation; BRM engagement; Discovery; Project; Decline
03Pass to shaping; Pass to shaping, risk in parallel; Hold for facts
04Ready now; Wait; Build prerequisites first (verdict by the weakest dimension)
05Clear to Rank; Clear to Rank with conditions; Hold at Shape
06Concentrate; Spread; Route first
07Rank now; Hold; Merge; Decline
08Consolidate; Clean before committing; Extend; Rebalance
09Commit; Commit the lower rung; Return for prerequisites; Decline
10Adopt and configure; Adopt, human routing only; Fix upstream first
11Approve at chosen rung; Approve at a lower rung; Build prerequisites first; Decline with reasons
12Recommend with conditions; Recommend if conditions close; Paid pilot against the need; Re-open the shortlist; Decline
13Approve for build; Approve with conditions; Hold
14Ownership complete; Ownership conditional; Ownership absent
15Ready to build; Build with named conditions; Pause before Build
16Ready to adopt; Ready with conditions; Not ready
17Proceed to Build; Proceed with conditions; Pause pending consultation; Rescope
18Continue; Adjust; Scale; Stop
19Scale; Continue; Adjust; Stop; Retire (and a gate result of passed or held)
20Endorse and fund; Endorse twelve months only; Return for rework

Canvas conventions (GOVBRM original): one page when printed; a stated completing role and the people in the room; inputs from and feeds into stated on the canvas; a "good looks like" hint against every field; a decision and rationale field written for someone who was not in the room.

8. Routing rules for the three lanes

The lane is decided at the Request gate from the intake record and confirmed or changed at the Shape gate once the rung is known. It can move up at any gate; it moves down only at Shape or Review with the reason recorded.

8.1 Criteria

Seven criteria decide the lane. Each is answered from the intake record and the demand shaping canvas, not inferred from the size of the request.

CriterionQuestionFast lane answerStandard lane answerStrategic lane answer
ConsequenceWhat does a wrong output cost the person it touches?Inconvenience recoverable in the same conversationRework, delay or a correctable recordMoney, rights, access, safety, reputation or a public position
ReversibilityCan a wrong output be reversed, and by whom, how fast?Same day, by the userWithin the normal correction processNot fully reversible, or reversible only by exception
Affected populationWho is touched, and how many?The requester's own teamOne function or a bounded internal populationCitizens or customers, staff across the organisation, or a vulnerable group
AutonomyAt what rung does the shaped solution sit?Rung 1 or 2Rung 2 or 3Rung 4 or 5, or any rung where an output is acted on before a person sees it
Public-facingWould a citizen or customer see, receive or act on the output without a person checking it first?NoNo, or a person checks every outputYes
Financial commitmentWhat money, contract or licence is at stake?Within an existing licence and a published budget lineA new spend within delegated authorityAbove delegated authority, a new procurement, or a multi-year commitment
Cross-boundaryDoes information or accountability move between organisations, jurisdictions or legal entities?NoNo, or under an existing agreementYes

Label: GOVBRM original; the thresholds inside each cell are Hypothesis.

8.2 Assignment rule

  1. An item is fast lane only if every criterion gives the fast lane answer and the request matches a published playbook pattern (canvas 10).
  2. An item is strategic lane if any one criterion gives the strategic lane answer.
  3. Everything else is standard lane.
  4. A Significant exposure rating from canvas 05 moves an item to the strategic lane regardless of the other criteria.
  5. The lane sets the minimum. The relationship layer may raise an item's lane with a recorded reason; it may not lower one below the rule.

Label: GOVBRM original.

8.3 What each lane carries

LaneWho shapesCanvasesGates with a personAssurances routed toSignatory at Commit
FastSelf-service against a published patternIntake record only; the pattern carries its own prompt governance and playbookRequest and a sampled ReviewThose the pattern was assured for when publishedThe pattern's owner, in advance
StandardRelationship layer at the Shape gate02, 03, 04, 05, 07, 09, 14, 16, 18, 19, plus conditionalsShape, Commit, ReviewPrivacy, security and equality where flagged; the business case; benefits managementRelationship layer with the business owner
StrategicMultidisciplinary, convened by the relationship layerAll applicable canvases; 11, 13, 15 and 17 mandatoryAll sixThe full assurance set: privacy or data protection, equality and human rights, transparency record, security, commercial and exit, business case on the full appraisal model, service or delivery assessment, management system evidence, sustainability, accessibility, contestability and redressAccountable executive, with the ethics or governance forum's review recorded

Label: GOVBRM original; the proportion of demand that lands in each lane is Not yet demonstrated.

9. Risk methodology

GOVBRM's risk methodology is a triage and routing system. It decides how much attention an item needs and which assessments it goes to, in which order. It does not replace a full risk assessment, weigh likelihood against impact quantitatively, or produce a residual risk figure. The assessments it routes to do that.

9.1 Dimensions

Each dimension is assessed separately and recorded separately. No dimension is derived from another, and no single dimension stands in for the rest. An item is triaged on the dimensions that apply; the highest floor among the raised flags sets the exposure rating.

DimensionQuestion askedWhere it is recordedLabel
ConsequenceWhat does a wrong output cost the person or organisation it reaches?02, 05, 11Established
LikelihoodHow often, at the expected volume, will a wrong output occur?05 register row; 11Established
UncertaintyHow confident are we in the consequence and likelihood judgements, and what evidence would tighten them?05 register rowAdapted
ScaleHow many outputs, decisions or people per period?03, 11Established
ReversibilityCan a wrong output be undone, by whom and how fast?05 flag (consequential and hard to reverse), 11Established
DetectabilityHow quickly would a failure, silent or loud, be noticed, and by whom?11 (failure question), 13 (drift check)Adapted (from engineering and quality practice)
Affected populationWho is touched, including groups under-represented in the data or vulnerable in the service?05 (bias potential), 15, 17Established
AutonomyAt what rung does the solution sit, and what does it act on before a person sees it?02, 11GOVBRM original
Human oversightIs a control step defined that a person would actually exercise, and can a person stop the system part-way?05 flag, 11 (approval and stop questions)Established
Legal exposureDoes the item conflict with, or fall outside, a statute, regulation or the organisation's own AI policy?05 flag (AI policy compliance)Established
PrivacyIs personal data processed at any step, and is a privacy or data protection assessment scoped?03 (sensitivity class), 05 flag (personal data)Established
SecurityDoes the solution need connectivity, credentials or hosting not yet assured for this class of data?05 flag (security assurance), 12Established
EqualityCould the output treat groups differently, or does the data under-represent some of them?05 flag (bias potential), 15, 17Established
OperationalWhat breaks in the service if the system fails or is withdrawn?04 (process readiness), 11 (blast radius), 14 (retirement)Established
FinancialWhat is at stake in spend, licence, contract and cost per task at volume?09, 11 (cost and evaluation), 12Established
CommercialIs procurement live, is there lock-in, is exit priced?05 flag (live procurement), 12Established
ReputationalWould a failure reach the public, the press or a regulator?05 flags (public-facing, executive or political decision-making)Established
Public trustWould the people served accept this use if they understood it, and can they contest it?05 (explainability), 15 (the people the service is for)Adapted (public value practice); modelling of it Not yet demonstrated
AccountabilityIs a business role named that would answer for a harmful output?05 flag (accountability chain undefined), 14Established

9.2 Autonomy is one dimension of risk

Autonomy is recorded as one dimension among the nineteen above. It is not a proxy for risk and it does not set the exposure rating on its own. A rung 2 system that drafts letters to every citizen or customer of a service carries more consequence, scale and reputational exposure than a rung 4 agent that tidies an internal filing queue. Governance that tiers by autonomy alone will over-govern the second and under-govern the first. GOVBRM raises attention at rung 4 and 5 (the four agent questions become mandatory) and still assesses consequence, scale, reversibility, affected population and detectability separately from the rung, whatever the rung is. Label: GOVBRM original; as a claim about better outcomes, Hypothesis.

9.3 Flags, floors and exposure rating

Canvas 05 carries sixteen flags in two groups: governance flags (sensitivity class, personal data, third-party processing, cross-boundary sharing, live procurement, executive or political decision-making, public-facing output, security assurance) and ethics and accountability flags (bias potential, consequential and hard to reverse, human oversight and override, explainability, accountability chain undefined, training data provenance, proportionality, AI policy compliance). A flag is ticked when the statement is true or when nobody in the room can say it is false.

Each flag carries a floor, the lowest exposure rating an item can receive while the flag is raised. Four flags carry a Significant floor: cross-boundary sharing, live procurement, public-facing output, and consequential and hard to reverse. The rest carry an Elevated floor. The exposure rating is the highest floor among the flags raised; the count of flags does not change it.

RatingConditionObligations
StandardNo flag raisedCanvas recorded; accountable role named; flags re-run at Review or on any change of scope, rung or data source
ElevatedOne or more Elevated flags, no Significant flag, each closable within the organisation's controlA register row per flag with a dated condition and an owner; canvas 11 where the rung is 4 or above; the accountable executive countersigns before Commit
SignificantAny Significant flag raisedA formal impact assessment; review by the ethics or governance forum; written acceptance of residual risk by the accountable executive; written evidence that a lower rung was considered and ruled out; otherwise Hold at Shape

Label: the flag list is Adapted (from privacy, equality, transparency and AI assurance practice); the floor mechanism and the three ratings are GOVBRM original; the assignment of floors to flags is Hypothesis.

9.4 Routing to assurance

A raised flag routes to the assessment that owns the dimension, in this order: privacy or data protection first where personal data is involved, because it constrains everything after it; then equality and human rights; then security; then commercial; then transparency; then the service or delivery assessment. The shaped item's single description is the input to each. Label: GOVBRM original (the ordering); Established (the assessments).

10. Autonomy model

10.1 The ladder

Five rungs. Cost per task, blast radius and difficulty of evaluation rise with each rung.

RungNameDescriptionFails when
1Deterministic scriptRules only, no model. If the whole task can be written as rules, stop here and route to Automation.The input is unstructured language or the decision needs judgement
2Single model callOne prompt, one answer, and a person reads the output before anything happens.The volume is too high for a person to read every output
3Workflow with model stepsA fixed path designed by a person; the model fills the language or judgement steps inside it.The path cannot be known in advance
4Agent with toolsChooses its own steps and calls its own systems. The blast radius now includes those systems.Needed only when the route to the outcome genuinely varies case by case
5Multi-agent systemAgents delegating to agents. Evaluation is hardest here.Needed only when no single agent can hold the whole task and the failure of one must not stop the rest

Label: GOVBRM original.

10.2 The shaping rule: the lowest rung that solves the task

At the Shape gate the relationship layer records the rung requested, the lowest rung that solves the need sentence, why the rung below cannot do it, and what a wrong output touches at the chosen rung. If nobody in the room can name what the rung below cannot do, the rung comes down and the answer is rewritten. Everything downstream is governed at the chosen rung. The line that matters most is between a system that answers and a system that acts; most requests that arrive as "build us an agent" describe a system that answers. Label: GOVBRM original.

10.3 The four agent questions

Asked of anything that acts rather than only answers, at the Commit gate, before a build team exists. They are the same four questions as canvas 11, the practitioner guide and the courses. Each answer becomes a condition on the commitment and an input to security assurance.

  1. What is it allowed to touch? What it reads, writes, sends and spends, and against which systems. The list is the scope; everything not on it is out of scope until a person adds it.
  2. Who approves what it does, and at which step? Every action gets an approver that is a role that exists, and a threshold at which a person steps in.
  3. What does a single task cost, and what does that become at volume? A range per task, at planned volume and at peak, in the unit the supplier charges.
  4. How will we know it worked, before we find out that it did not? A pre-live evaluation set with awkward cases, a live success signal with an owner, and a design that makes a silent failure visible.

Two conditions follow from the answers and sit on the same canvas: who can stop it, how quickly and what happens to work in flight; and how its actions are rolled back and repaired. If a condition cannot be met, the rung comes down. An agent that cannot be stopped is an assistant with a person pressing the button, and the method prefers that to an agent nobody can stop. Label: GOVBRM original.

11. Value model

ElementRuleLabel
Value as a rangeEvery value statement is a lower and upper bound in the partner's own unit (hours a week, cases a month, days of cycle time, or money) over the first twelve months after the change lands. A point estimate is not accepted. The lower bound is the figure the partner would still act on; if there is none, the item stops.Adapted (appraisal practice on uncertainty and optimism bias)
Conditions for the upper halfWhat has to be true for the upper half to arrive, each condition checkable by a named role within weeks.GOVBRM original
Probability kept separateLow, medium or high, with a reason, recorded apart from the range. A large potential at low probability is a different conversation from a modest one that is nearly certain.Adapted (benefits management)
Benefit typesCashable; non-cashable; avoided cost; quality; strategic. One primary type per item; a secondary only if the partner would fund the work on the secondary alone.Adapted (public sector benefits categorisation)
Potential versus realisedPotential value is the range signed at Commit. Realised value is what the benefits ledger (18) reads from the source system after handover. The two are never conflated, and the review sets one against the other.Adapted (benefits management)
Owner after handoverThe business owner named on canvas 14 owns the benefit from handover to retirement. The build team owns nothing after handover. The review owner (usually the relationship layer) convenes the review; the business owner brings the evidence.Adapted (product and benefits ownership)
Cost per task at volumeFor rung 3 and above, cost per task and the evaluation cost are recorded alongside the value range so the cheaper rung can be chosen on its merits.GOVBRM original
Where value leaksThe three value conversations name the leak points: between planning and commitment, between deployment and use, and between use and the review.Adapted (BRM value lifecycle)

12. Adoption model

Deployment is not use. The adoption model is what stands between a go-live and a number that arrives.

ElementRuleCanvasLabel
Stakeholder mapWho the change touches, where each stands today, where they need to stand for the number to arrive, and which conversations are booked in the next thirty days15Adapted (stakeholder analysis)
The objection that may be rightEvery objection is recorded and at least one is tested as if it were correct before Build15GOVBRM original
The people the service is forThe citizens, customers or staff on the receiving end, and whether they were consulted or only counted15Adapted (service design)
Behaviour changes requiredNamed, per role, from the current way of working to the new one16Established (change management)
Training, support, communication, championsPlanned and owned, not assumed16Established
Adoption measuresMeasured from the work (use of the output in the process), not from logins or licences16Established (benefits management)
First ninety days and the failure triggerThe point at which the organisation admits adoption has not happened, written down before Build16GOVBRM original
Workforce impact task by taskWhat the change removes, alters or creates in people's work; skills that shift; time released and where it goes; roles and grades affected; consultation and representation; reskilling; what the organisation will not do17Adapted (workforce and consultation practice)

13. Review model

13.1 The Value Realisation Review

The Review gate is where the loop closes. The review sets the measured value from the benefits ledger against the committed number, records what was not expected, reviews the shaping decisions that were made, decides what to do with the capability now, and writes what returns to the front door. Its decision is one of Scale, Continue, Adjust, Stop or Retire, and the gate result is passed or held. The relationship layer signs; a change to funding is countersigned by the sponsoring executive. Label: GOVBRM original.

13.2 Timing

The default review point is month nine after go-live, booked at the Commit gate. Nine months of use is long enough for adoption to have happened or failed, and short enough that the people who shaped the item are still in post and the money can still be redirected. It is a default, not a rule. The review date is fixed on canvas 14 before the build is funded, and it is set from the item's own value curve.

FactorMoves the review earlier whenMoves the review later when
Speed of value emergenceThe first measured outcome is expected inside three months (an assistant or a drafting tool)The outcome depends on an annual cycle or a slow-moving caseload
ConsequenceA wrong output reaches money, rights or a citizen or customer, so an early check is worth its costConsequence is low and the cost of the review outweighs what it would change
InvestmentSpend is staged and the next tranche depends on evidenceSpend is committed once and cannot be redirected
Adoption curveAdoption is expected to be fast, or the failure trigger on canvas 16 is set earlyAdoption depends on a training programme or a role change that will take longer
Operational riskThe service has a live operational dependency on the systemThe system is advisory and the process runs without it
Benefits dependencyOther funded items depend on this benefit arrivingThe benefit stands alone

Where the factors disagree, consequence and benefits dependency take precedence. Whatever date is chosen, an interim reading of the benefits ledger (18) is taken at the earlier of month three or the first expected outcome. Label: GOVBRM original; the month-nine default is Hypothesis.

13.3 What returns to the front door

14. Governance interfaces

GOVBRM produces inputs; it does not produce the assessments. The table names the interface, what GOVBRM hands over and at which gate.

InterfaceWhat GOVBRM hands overGateLabel
Business case and appraisalNeed sentence, value range with conditions and probability, benefit types, alternatives including the lower rung, pre-mortem, named ownerCommitEstablished (the interface); Adapted (the canvas)
Privacy or data protection assessmentSensitivity class, personal data flag, third-party processing flag, data flow at the chosen rungShapeEstablished
Equality, anti-discrimination and human rights assessmentBias potential flag, affected population, the people the service is forShape and BuildEstablished
Transparency record or registerThe scoping question and the single descriptionShape and CommitEstablished
Security assurance and information riskThe read, write, send and spend list, connectivity and hosting flags, supplier assurance evidenceCommitEstablished
Commercial and procurementNeed statement to buy against, live procurement flag, commercial model and exit conditions, supplier's definitions recorded verbatimCommitEstablished
Service or delivery assessmentUser need, accessibility and inclusion requirements, adoption measures, performance data at reviewBuild and ReviewEstablished
Ethics or governance forumExposure rating, register rows, residual risk for acceptanceShape and CommitEstablished
AI management system (where one exists)Every gate record as evidence; prompt library, test cases and drift checksAllEstablished
Portfolio and financeValue map, weighted scores, heatmap decisions, committed numbersRank and CommitEstablished
Benefits managementCommitted number, review date, ledger readings, review decisionCommit and ReviewEstablished
Workforce representation and consultationTask by task impact, roles and grades affected, reskilling plan, what the organisation will not doBuildEstablished
Sustainability and enterprise architectureModel size, inference volume, hosting, integration pointsCommitRouted to, not covered: Not yet demonstrated

15. External framework relationships

This section is short by design. The detailed mapping, principle by principle, is the crosswalk and its compiler, which are separate documents under their own change control.

GOVBRM sits before and around the frameworks an organisation already uses. Each of them answers its own question; GOVBRM answers the one before them: which AI demand should receive attention, money, autonomy and change, and did the value arrive.

Framework or standardIts questionRelationshipLabel
BRM Body of KnowledgeHow does a relationship function create value with its partners?Intellectual lineage. Ideas used, expression GOVBRM's own; no text, diagrams or assessment material reproduced.Adapted
Business case and appraisal guidance (the Green Book's five case model is one version)Is this investment worth it, and did it deliver?Canvas 09 feeds it; Realise feeds its monitoring and evaluation.Established
AI use guidance for public bodies (the AI Playbook is one version; equivalents exist in the US, EU, Canada, Australia, New Zealand and South Africa)How should a public body use AI responsibly?The Shape and Commit gates carry the principles on limitations, lawful use, security, human control, lifecycle, the right tool, commercial involvement and assurance.Established
Technology and service standards (Technology Code of Practice and Service Standard are two versions)Is this technology bought and run well; is this a good service?Discover, Design and Adopt hand off to user needs, accessibility, open standards, purchasing and performance.Established
Data ethics and transparency instruments (Data Ethics Framework and the Algorithmic Transparency Recording Standard are two versions)Is the use of data and algorithms transparent, accountable and fair?Canvas 05 asks the scoping question and routes to ethics review, contestability and redress.Established
NIST AI Risk Management FrameworkHow do we manage AI risk across the lifecycle?GOVBRM decides what enters the lifecycle and checks that value arrived. Assess maps; Realise measures.Established
ISO/IEC 42001How do we run an AI management system?GOVBRM is not a management system and not an alternative to one. It can be the operational front door into one; its records are evidence for it.Established
ISO/IEC 38500, ISO/IEC 27001, ITILGovernance of IT; information security; service managementNamed as the governance, security and service layers GOVBRM's records feed and its intake practice adapts.Established
EU AI Act, GDPR and national data protection lawWhich risk tier, and is personal data processed lawfully?Canvas 05 and the readiness score feed classification and documentation; the privacy interface carries lawful basis and impact assessment.Established; mapping is Not yet demonstrated at principle level
Automated decision-making directives and algorithm charters (Canada, Australia, New Zealand)Does an automated decision system meet its required impact level?Canvas 05 and the readiness score ask the same questions an algorithmic impact assessment does.Established; mapping is Not yet demonstrated at principle level

GOVBRM reproduces none of their text, is not certified against, affiliated with or endorsed by any of their publishers, and claims none of their names.

16. Provenance

GOVBRM was written by one practitioner from the receiving end of AI requests in public and regulated organisations, worked out in public through the GOVBRM Newsletter during 2026, and turned into the toolkit, the framework, the courses and the workbook. Written from practice is a claim about provenance, not about validation, and the two are kept apart.

What is original to GOVBRM: the six-gate front door as a model of AI demand rather than of delivery; the twenty canvases, their fields, prompts and scales; the autonomy ladder as a shaping question; the four agent questions; the three lanes and the seven routing criteria; the flag and floor mechanism; the three value conversations as distinct bookable conversations; the month-nine default and the review that sends lessons back; the AI Value Operating Model.

What is adapted: demand shaping, value realisation and value optimisation from the BRM Body of Knowledge; value as a range and benefit typing from appraisal and benefits management; adoption measured from the work from change management; intake as a record from service management; stakeholder and workforce analysis from change and consultation practice.

What is established and used as found: the assessments GOVBRM routes into and the questions they ask.

Label: statement of fact about provenance, GOVBRM original.

17. Known limitations

  1. The risk methodology is a triage and routing system. It records nineteen dimensions separately but does not weigh them against one another quantitatively, does not produce a residual risk figure and does not model systemic or velocity effects. It routes to the assessments that do.
  2. The value range is not an appraisal and the business case canvas does not replace a full business case.
  3. Public value, and who has no seat at the table, is asked of every item but not yet modelled.
  4. Sustainability and enterprise architecture are routed to, not covered.
  5. The lane criteria thresholds, the readiness weights, the prioritisation weights, the vendor bands, the flag floors and the month-nine default are initial calibration parameters.
  6. The method is founder-led. There is no Method Council or external advisory group yet.
  7. Accessibility of the published artefacts is built to WCAG 2.2 AA and has not been audited.
  8. Non-UK framework mappings were made from the publicly documented purpose of each instrument, not from a principle-by-principle reading.

Label: GOVBRM original (statement of limitations).

18. Evidence status

Claim or mechanismStatusEvidence
The request is not the needEstablishedUser-centred design and BRM demand shaping practice
Deployment is not useEstablishedChange management and benefits management practice
Value as a range with named conditionsAdaptedAppraisal and benefits management practice on uncertainty and optimism bias
Three value conversationsAdaptedBRM value lifecycle
Six gates and the routing modelGOVBRM originalPractitioner design; exercised in the toolkit; Not yet demonstrated in any organisation
Three lanes and seven criteriaGOVBRM originalPractitioner design; Not yet demonstrated
Autonomy ladder as a shaping deviceGOVBRM originalPractitioner design; Not yet demonstrated
Autonomy as one dimension of risk, not a proxyHypothesisArgued from consequence; Not yet demonstrated
Four agent questionsGOVBRM originalPractitioner design; Not yet demonstrated
Flags, floors and exposure ratingsGOVBRM original; floor assignments HypothesisNot yet demonstrated
Readiness, prioritisation and vendor weights and thresholdsHypothesisInitial calibration, version 1.0; Not yet demonstrated
Month-nine defaultHypothesisA default, not a rule; Not yet demonstrated
Twenty canvases in ninety-minute sessionsGOVBRM originalPractitioner design; session length Not yet demonstrated
Minimum necessary governance reduces burden without raising harmHypothesisNot yet demonstrated
The review loop improves later shapingHypothesisNot yet demonstrated

No pilots have run. No controlled comparisons, inter-rater studies or outcome measurements exist. No customer, testimonial or endorsement exists. The verification registry is empty. None of this is concealed in any published artefact.

19. Change-control process

19.1 Versioning

The specification carries a semantic version: major.minor.patch.

ChangeVersion stepExamples
BreakingMajorAdding, removing, renaming or reordering a stage, gate or lane; changing a gate's question or signatory; adding or removing a canvas; changing a canvas's decision options; changing a principle; changing the lane assignment rule; changing the exposure rating levels or which flags carry a Significant floor; changing the rungs of the ladder or the four agent questions
Compatible addition or recalibrationMinorAdding a routing criterion; adjusting a weight, threshold, band or floor; adding a dimension to the risk table; adding a canvas field; changing the review default; adding a governance interface; extending the framework relationships
EditorialPatchWording, corrections, examples, formatting, labels updated on new evidence without changing the mechanism

A breaking change requires a migration note stating what a practitioner mid-way through an item must do. Published artefacts state which specification version they implement.

19.2 Approval

PeriodWho approvesHow
NowThe ownerA change is proposed in writing against a numbered section, labelled Established, Adapted, GOVBRM original or Hypothesis, with its evidence. The owner accepts, rejects or holds it, and the decision is recorded in the version history.
Proposed, laterA Method Council

19.3 Evidence-driven change

Calibration parameters change on evidence from the Review gate and from implementations, recorded anonymised. A change to a label from Hypothesis to Adapted or Established requires the evidence to be cited in the version history. A label never moves in that direction on argument alone.

Label: GOVBRM original.

20. Version history

VersionDateChangeApproved by
1.014 September 2026First written specification. Consolidates the six stages, six gates, twenty canvases, three lanes, the risk triage, the autonomy, value, adoption and review models, the governance interfaces and the change-control process as published in the toolkit, framework, crosswalk and provenance page, and adds the seven lane criteria, the nineteen risk dimensions and the review timing factors as written rules. All calibration parameters marked as initial.Owner (pending)

Dates come to members first

Courses and certifications are announced in the GOVBRM Newsletter before anywhere else.

Join free for the essays behind the framework, the access code for the free micro-courses, and first word of every cohort. Paid membership adds the toolkit, the framework and a seat at the masterclasses.