Use
Run a request through the gates.
The practitioner version: canvases, lanes, scoring, routing, facilitation and evidence. Executives should read the one page instead.
GOVBRM practitioner guide
Status: draft v0.1, GOVBRM original, not yet validated.
This guide is for the Business Relationship Manager, demand lead or value owner who runs an AI request through the six gates using the AI Demand Toolkit. It assumes you have read the AI Demand Framework and have the twenty canvases to hand. Labels used: Established (externally supported), Adapted (existing practice modified), GOVBRM original, Hypothesis (not yet validated).
The canvases, by number
| No. | Title | Stage | Gate |
|---|---|---|---|
| 01 | AI Opportunity Canvas | Discover | Request |
| 02 | AI Demand Shaping Canvas | Discover | Request to Shape |
| 03 | AI Request Intake Canvas | Assess | Request |
| 04 | AI Readiness Canvas | Assess | Shape |
| 05 | AI Risk and Ethics Canvas | Assess | Shape |
| 06 | AI Demand Value Map | Prioritise | Rank |
| 07 | AI Use Case Prioritisation Canvas | Prioritise | Rank |
| 08 | AI Portfolio Heatmap | Prioritise | Rank |
| 09 | AI Business Case Canvas | Design | Commit |
| 10 | AI Playbook Builder | Design | Commit to Build |
| 11 | AI Agent Assessment Canvas | Design | Commit |
| 12 | AI Vendor Evaluation Canvas | Design | Commit to Build |
| 13 | AI Prompt Governance Canvas | Design | Build |
| 14 | AI Product Ownership Canvas | Design | Commit to Build |
| 15 | AI Stakeholder Impact Canvas | Adopt | Build |
| 16 | AI Adoption Canvas | Adopt | Build |
| 17 | AI Workforce Impact Canvas | Adopt | Build |
| 18 | AI Benefits Realisation Canvas | Realise | Review |
| 19 | AI Value Realisation Review | Realise | Review (month nine) |
| 20 | AI Capability Roadmap Canvas | Realise | Review |
Canvases 06, 08, 10 and 20 work on the portfolio or on a category of request rather than on a single item. The rest travel with one request.
Running a request through the six gates
Gate 1: Request
Log the request as facts on canvas 03 (AI Request Intake Canvas) before anyone judges it. Record who asked (roles, not names), what they asked for verbatim, what data and systems it touches, and whether personal data, an external party, a live procurement or a public-facing output is involved. Those four answers decide whether canvas 05 opens later. If the item began as something you noticed in a partner's work rather than an incoming request, canvas 01 (AI Opportunity Canvas) decides whether it is worth writing up at all. Adapted: intake as a record is standard service management practice; the shaping-first ordering is GOVBRM original.
Gate 2: Shape
Canvas 02 (AI Demand Shaping Canvas) is the centre of the method and the ninety-minute session described below. Write the request as it arrived, then work beneath it until the room agrees on a need sentence with no tool in it. State value as a range in the partner's own unit, with the lower bound they would act on and the conditions for the upper half. Name the counterfactual. Pitch a provisional autonomy rung. Then choose one of six routes:
| Route | When | What opens next |
|---|---|---|
| Self-service | Existing capability meets the need | Nothing; close the intake record |
| Automation | Rung one or two on a stable, documented process | Update canvas 03; canvas 05 if personal data or a decision about a person |
| BRM engagement | The need is real but the request would not meet it | Canvas 06; canvas 04 where useful |
| Discovery | Need is real, value range wide, feasibility or data unknown | Canvases 04 and 05; canvas 11 if an agent is proposed |
| Project | Shaped, scoped, provisional number, owner candidate | Canvases 06, 07 and 09; canvas 11 if the rung is agent or above |
| Decline | Counterfactual acceptable, no ambition served, or value does not clear the constraint | Close canvas 03 with reasons and the reopening condition |
Anyone may raise a request; only the relationship layer may route it. GOVBRM original.
Where the route is Discovery or Project, two more canvases complete the Shape gate.
Canvas 04 (AI Readiness Canvas) scores five dimensions (leadership, data, process, technology, people) from 1 to 5 on evidence seen in the room, each multiplied by its weight, maximum 50. A dimension with no artefact behind it scores 1. The weakest dimension decides and the total confirms; if they disagree, the weakest wins. A weakest score of 1 or 2 rules out Go: build prerequisites first if the gap is in your control, otherwise Wait. A Go one rung lower than proposed is a legitimate verdict. Adapted from readiness assessment practice; the weakest-dimension rule is a Hypothesis.
Canvas 05 (AI Risk and Ethics Canvas) is a triage, not a risk assessment. Raise flags; the exposure rating is the highest floor among the flags raised, not the count. Standard exposure obliges the canvas on the record and an accountable role named. Elevated exposure obliges a risk register row per flag with a dated condition and owner, canvas 11 if the rung is four or above, and the accountable executive's countersignature before Commit. Significant exposure (cross-boundary sharing, live procurement, public-facing output, or consequential and hard to reverse) obliges the formal assessments your governance requires, and puts the item in the strategic lane. GOVBRM original; the floors are initial calibration.
Gate 3: Rank
Canvas 06 (AI Demand Value Map) plots shaped demand on strategic value against volume and settles which request types stay with a person and which go to a structured or automated route. Run it once a quarter, not per item.
Canvas 07 (AI Use Case Prioritisation Canvas) scores eight criteria (strategic alignment, financial impact, citizen or customer impact, simplicity of build, containment of harm, speed to value, data availability, executive sponsorship) from 1 to 5, weights totalling 100, so the range is 100 to 500. Two columns: the sponsor scores first, on a separate sheet, with a one-line reason per score; the relationship layer then scores the same eight, with simplicity of build and containment of harm scored by a named architecture or AI execution person who will neither build nor benefit. Keep both columns. The outcome is Rank now, Hold (with a rescoring date), Merge (into a named item with an owner who accepts it) or Decline (with the criteria that decided it). Adapted from weighted scoring; the two-column rule is GOVBRM original.
Canvas 08 (AI Portfolio Heatmap) gives leadership the whole picture and asks for three portfolio moves. Refresh it each cycle.
Gate 4: Commit
Canvas 09 (AI Business Case Canvas) puts a named business owner and a committed number, as a range with a benefit type, on one page your funding forum can accept or refuse. Outcomes: Commit; Commit the lower rung; Return for prerequisites; Decline. This canvas feeds your organisation's full business case; it does not replace it.
Canvas 11 (AI Agent Assessment Canvas) is required whenever the rung is agent with tools or multi-agent. Choose the lowest rung on the five-rung ladder (deterministic script, single model call, workflow with model steps, agent with tools, multi-agent system) that solves the task, then answer the four agent questions: what it may decide and touch; who approves its actions; what a task costs at volume, as a range; how you will know it worked, decided before go-live. Outcomes: approve at the chosen rung; approve at a lower rung; build prerequisites first; decline with reasons. GOVBRM original; the ladder is initial calibration.
Canvas 14 (AI Product Ownership Canvas) names who owns each part of the service after launch, what each may decide alone, and books the month-nine review with a named owner before the build is funded. Commit is not signed without it.
Canvas 12 (AI Vendor Evaluation Canvas) applies where a supplier or platform is proposed. Eight criteria, 1 to 5, weighted to 100. Bands: 80 or above recommend with conditions; 60 to 79 recommend if conditions close; 40 to 59 paid pilot against the need or reopen the shortlist; below 40 decline. An unmet condition on data handling, security or exit forces Decline whatever the total. It informs your procurement process; it is not a procurement evaluation.
Canvas 10 (AI Playbook Builder) is written once per category of request and records the rules that let the front door route similar requests the same way every time. Build one after the third request of a kind.
Gate 5: Build
Canvas 13 (AI Prompt Governance Canvas) settles who may write, approve, test, share and retire prompts, and how you will notice when a model change alters what they do.
Canvas 15 (AI Stakeholder Impact Canvas) maps who the change touches, where each stands, where they need to stand for the number to arrive, and which conversations to book first.
Canvas 16 (AI Adoption Canvas) states who will change how they work, what it takes, how you will know from the work itself, and the point at which you admit it has not happened.
Canvas 17 (AI Workforce Impact Canvas) records, task by task, what the change removes, alters or creates, where released time goes, and what the organisation commits to its staff before the build lands.
Gate 6: Review
Canvas 18 (AI Benefits Realisation Canvas) is the evidence ledger after handover: baselines, measurement owners, readings and a corrective action trigger stated as a reading. Canvas 19 (AI Value Realisation Review) is the review itself, described below. Canvas 20 (AI Capability Roadmap Canvas) collects the prerequisites the readiness scores keep surfacing into a twelve, twenty-four and thirty-six month plan, so they are built once.
The three lanes
Governance burden in proportion to blast radius. The lane is set at Shape by consequence, and autonomy is one dimension of consequence alongside scale, reversibility, the population affected and how quickly a failure would be noticed. GOVBRM original; the lane boundaries are a Hypothesis.
| Lane | Entry test | Canvases required | Canvases optional |
|---|---|---|---|
| Fast | Low risk, a known pattern, rung one or two, no personal data or public-facing output | 03 AI Request Intake Canvas, 05 AI Risk and Ethics Canvas (flags only), 19 AI Value Realisation Review (a light reading at the review date), closed against a published playbook (10) | 02 if the need is unclear at intake |
| Standard | Moderate risk or value; Standard or Elevated exposure | 02, 03, 04, 05, 06, 07, 09, 14, 16, 18, 19 | 11 if rung three or above; 12 if a supplier is proposed; 13 if prompts are run at scale; 15 and 17 where more than one team changes its work |
| Strategic | High consequence, public-facing, cross-boundary, live procurement or high autonomy; Significant exposure | All twenty canvases, 01 to 20; 12 is completed as "no supplier" where none is proposed | None; the portfolio canvases 06, 08 and 20 receive the item and are updated |
Ask of every item, whatever the lane: who bears the benefit, who bears the cost, and who has no seat at the table.
Scoring and routing, in short
| Canvas | Scale | Decision rule |
|---|---|---|
| 04 Readiness | 1 to 5 per dimension, weighted, max 50 | Weakest dimension decides; Go only in the top band with no dimension below 3 |
| 05 Risk and Ethics | Flags with floors | Highest floor sets the rating; Significant flags force the strategic lane |
| 07 Prioritisation | 1 to 5 per criterion, weights total 100, range 100 to 500 | Sponsor column first, relationship column decides; Rank now, Hold, Merge or Decline |
| 11 Agent Assessment | Five rungs | Lowest rung that solves the task; four questions answered before approval |
| 12 Vendor Evaluation | 1 to 5 per criterion, weights total 100 | Bands at 80, 60 and 40; data, security or exit condition overrides |
| 19 Value Review | Measured against committed range | Scale, Continue, Adjust, Stop, or hold for up to three months |
All weights, thresholds and floors are initial calibration, version 1.0, published to be argued with.
Facilitating the ninety-minute shaping session
Who is in the room: the requester, the Business Relationship Manager, and the sponsoring executive's delegate where the value range is material. Add a data or architecture person only if the readiness canvas will be scored in the same session.
Before: the intake record (03) is complete and circulated. Print or open canvas 02, and 04 and 05 if you expect to reach them.
| Minutes | Activity | Canvas |
|---|---|---|
| 0 to 10 | Read the request back verbatim; agree what was actually asked | 02, signal and requested solution |
| 10 to 30 | Work beneath the request; ask why until the answer is an outcome; write the need sentence with no tool in it | 02, root need and who feels it |
| 30 to 45 | Value as a range in the partner's unit; the lower bound they would act on; the counterfactual | 02, value hypothesis |
| 45 to 55 | Pitch the rung; ask whether it needs a model at all | 02, rung |
| 55 to 70 | Readiness, scored on evidence in the room; risk flags | 04, 05 |
| 70 to 85 | Choose the route; write the reasons the requester can repeat | 02, output |
| 85 to 90 | Confirm what opens next, who owns it, and the date | 02, next steps |
Facilitation notes. Write on the canvas in front of the room, not in private notes. When the requester restates the tool, write it in the requested solution box and move on. A need sentence is finished when the requester agrees with it and it reads differently from the request. If the value range cannot be stated, the route is Discovery or BRM engagement, not Project. Score readiness only against artefacts someone can point to; an assertion scores 1. Say the decline out loud in the room and write the reopening condition beside it. Close by reading the route and its reasons back. The relationship layer signs; nobody else.
Evidence to keep
Handing off into external governance
GOVBRM produces the inputs; the receiving process makes the decision.
| From | To | What travels |
|---|---|---|
| Canvas 05 Significant exposure | Data protection impact assessment, equality assessment, AI impact or risk assessment (ISO/IEC 42001, NIST AI RMF, EU AI Act tier) | Flags, accountable role, data and population affected |
| Canvas 09 | Business case and appraisal (Green Book or local equivalent) | Need sentence, benefit type and range, alternatives, owner |
| Canvas 11 | Security assurance, architecture review, AI assurance | Rung, systems touched, approvals, evaluation plan |
| Canvas 12 | Procurement | Conditions, exit and portability terms, scores by criterion |
| Canvases 02, 05, 11 | Transparency record (Algorithmic Transparency Recording Standard or equivalent) | Purpose, rung, decisions taken alone, human review |
| Canvases 15, 16, 17 | Service assessment, workforce consultation | Groups affected, adoption measures, task changes |
| Canvases 18, 19 | Benefits management, audit, portfolio board | Measured value against committed number, decision |
Record on the canvas the date each handoff was made and the reference the receiving process returned. The crosswalk is GOVBRM original; each receiving framework is Established.
Running the Value Realisation Review
Default at month nine after go-live, booked at Commit, unless canvas 14 set an earlier or later date from the value curve. Bring it forward if canvas 18 shows the reading well outside the committed range.
In the room: the Business Relationship Manager as loop owner, the named business owner, the product owner and the finance business partner. Inputs: the Commit gate record (09), the benefits ledger (18), the risk register rows from 05, and the current heatmap (08).
Steps. Copy the committed number from canvas 09; do not restate it from memory. Put the measured value beside it, with the measurement confidence. Re-run the risk flags. Decide one route: Scale (at or above the range, medium or high confidence, new number and review date); Continue (inside the range, next review in six months); Adjust (value real but shaping partly wrong; change rung, scope, controls or number and re-enter at Commit); Stop (below the range and the cause is the capability or the number; retain the learning, harvest residual benefit). If measurement confidence is too low, hold the gate and reconvene within three months with named measurements. Write the decision and the two facts that decided it. Then answer the loop question: what must the front door learn about how this was shaped, and which playbook (10) or roadmap (20) entry changes as a result. The relationship layer signs; the sponsoring executive countersigns any change to funding. GOVBRM original; the month-nine default is a Hypothesis.
