Toolkit

Use

Run a request through the gates.

The practitioner version: canvases, lanes, scoring, routing, facilitation and evidence. Executives should read the one page instead.

GOVBRM practitioner guide

Status: draft v0.1, GOVBRM original, not yet validated.

This guide is for the Business Relationship Manager, demand lead or value owner who runs an AI request through the six gates using the AI Demand Toolkit. It assumes you have read the AI Demand Framework and have the twenty canvases to hand. Labels used: Established (externally supported), Adapted (existing practice modified), GOVBRM original, Hypothesis (not yet validated).

The canvases, by number

No.TitleStageGate
01AI Opportunity CanvasDiscoverRequest
02AI Demand Shaping CanvasDiscoverRequest to Shape
03AI Request Intake CanvasAssessRequest
04AI Readiness CanvasAssessShape
05AI Risk and Ethics CanvasAssessShape
06AI Demand Value MapPrioritiseRank
07AI Use Case Prioritisation CanvasPrioritiseRank
08AI Portfolio HeatmapPrioritiseRank
09AI Business Case CanvasDesignCommit
10AI Playbook BuilderDesignCommit to Build
11AI Agent Assessment CanvasDesignCommit
12AI Vendor Evaluation CanvasDesignCommit to Build
13AI Prompt Governance CanvasDesignBuild
14AI Product Ownership CanvasDesignCommit to Build
15AI Stakeholder Impact CanvasAdoptBuild
16AI Adoption CanvasAdoptBuild
17AI Workforce Impact CanvasAdoptBuild
18AI Benefits Realisation CanvasRealiseReview
19AI Value Realisation ReviewRealiseReview (month nine)
20AI Capability Roadmap CanvasRealiseReview

Canvases 06, 08, 10 and 20 work on the portfolio or on a category of request rather than on a single item. The rest travel with one request.

Running a request through the six gates

Gate 1: Request

Log the request as facts on canvas 03 (AI Request Intake Canvas) before anyone judges it. Record who asked (roles, not names), what they asked for verbatim, what data and systems it touches, and whether personal data, an external party, a live procurement or a public-facing output is involved. Those four answers decide whether canvas 05 opens later. If the item began as something you noticed in a partner's work rather than an incoming request, canvas 01 (AI Opportunity Canvas) decides whether it is worth writing up at all. Adapted: intake as a record is standard service management practice; the shaping-first ordering is GOVBRM original.

Gate 2: Shape

Canvas 02 (AI Demand Shaping Canvas) is the centre of the method and the ninety-minute session described below. Write the request as it arrived, then work beneath it until the room agrees on a need sentence with no tool in it. State value as a range in the partner's own unit, with the lower bound they would act on and the conditions for the upper half. Name the counterfactual. Pitch a provisional autonomy rung. Then choose one of six routes:

RouteWhenWhat opens next
Self-serviceExisting capability meets the needNothing; close the intake record
AutomationRung one or two on a stable, documented processUpdate canvas 03; canvas 05 if personal data or a decision about a person
BRM engagementThe need is real but the request would not meet itCanvas 06; canvas 04 where useful
DiscoveryNeed is real, value range wide, feasibility or data unknownCanvases 04 and 05; canvas 11 if an agent is proposed
ProjectShaped, scoped, provisional number, owner candidateCanvases 06, 07 and 09; canvas 11 if the rung is agent or above
DeclineCounterfactual acceptable, no ambition served, or value does not clear the constraintClose canvas 03 with reasons and the reopening condition

Anyone may raise a request; only the relationship layer may route it. GOVBRM original.

Where the route is Discovery or Project, two more canvases complete the Shape gate.

Canvas 04 (AI Readiness Canvas) scores five dimensions (leadership, data, process, technology, people) from 1 to 5 on evidence seen in the room, each multiplied by its weight, maximum 50. A dimension with no artefact behind it scores 1. The weakest dimension decides and the total confirms; if they disagree, the weakest wins. A weakest score of 1 or 2 rules out Go: build prerequisites first if the gap is in your control, otherwise Wait. A Go one rung lower than proposed is a legitimate verdict. Adapted from readiness assessment practice; the weakest-dimension rule is a Hypothesis.

Canvas 05 (AI Risk and Ethics Canvas) is a triage, not a risk assessment. Raise flags; the exposure rating is the highest floor among the flags raised, not the count. Standard exposure obliges the canvas on the record and an accountable role named. Elevated exposure obliges a risk register row per flag with a dated condition and owner, canvas 11 if the rung is four or above, and the accountable executive's countersignature before Commit. Significant exposure (cross-boundary sharing, live procurement, public-facing output, or consequential and hard to reverse) obliges the formal assessments your governance requires, and puts the item in the strategic lane. GOVBRM original; the floors are initial calibration.

Gate 3: Rank

Canvas 06 (AI Demand Value Map) plots shaped demand on strategic value against volume and settles which request types stay with a person and which go to a structured or automated route. Run it once a quarter, not per item.

Canvas 07 (AI Use Case Prioritisation Canvas) scores eight criteria (strategic alignment, financial impact, citizen or customer impact, simplicity of build, containment of harm, speed to value, data availability, executive sponsorship) from 1 to 5, weights totalling 100, so the range is 100 to 500. Two columns: the sponsor scores first, on a separate sheet, with a one-line reason per score; the relationship layer then scores the same eight, with simplicity of build and containment of harm scored by a named architecture or AI execution person who will neither build nor benefit. Keep both columns. The outcome is Rank now, Hold (with a rescoring date), Merge (into a named item with an owner who accepts it) or Decline (with the criteria that decided it). Adapted from weighted scoring; the two-column rule is GOVBRM original.

Canvas 08 (AI Portfolio Heatmap) gives leadership the whole picture and asks for three portfolio moves. Refresh it each cycle.

Gate 4: Commit

Canvas 09 (AI Business Case Canvas) puts a named business owner and a committed number, as a range with a benefit type, on one page your funding forum can accept or refuse. Outcomes: Commit; Commit the lower rung; Return for prerequisites; Decline. This canvas feeds your organisation's full business case; it does not replace it.

Canvas 11 (AI Agent Assessment Canvas) is required whenever the rung is agent with tools or multi-agent. Choose the lowest rung on the five-rung ladder (deterministic script, single model call, workflow with model steps, agent with tools, multi-agent system) that solves the task, then answer the four agent questions: what it may decide and touch; who approves its actions; what a task costs at volume, as a range; how you will know it worked, decided before go-live. Outcomes: approve at the chosen rung; approve at a lower rung; build prerequisites first; decline with reasons. GOVBRM original; the ladder is initial calibration.

Canvas 14 (AI Product Ownership Canvas) names who owns each part of the service after launch, what each may decide alone, and books the month-nine review with a named owner before the build is funded. Commit is not signed without it.

Canvas 12 (AI Vendor Evaluation Canvas) applies where a supplier or platform is proposed. Eight criteria, 1 to 5, weighted to 100. Bands: 80 or above recommend with conditions; 60 to 79 recommend if conditions close; 40 to 59 paid pilot against the need or reopen the shortlist; below 40 decline. An unmet condition on data handling, security or exit forces Decline whatever the total. It informs your procurement process; it is not a procurement evaluation.

Canvas 10 (AI Playbook Builder) is written once per category of request and records the rules that let the front door route similar requests the same way every time. Build one after the third request of a kind.

Gate 5: Build

Canvas 13 (AI Prompt Governance Canvas) settles who may write, approve, test, share and retire prompts, and how you will notice when a model change alters what they do.

Canvas 15 (AI Stakeholder Impact Canvas) maps who the change touches, where each stands, where they need to stand for the number to arrive, and which conversations to book first.

Canvas 16 (AI Adoption Canvas) states who will change how they work, what it takes, how you will know from the work itself, and the point at which you admit it has not happened.

Canvas 17 (AI Workforce Impact Canvas) records, task by task, what the change removes, alters or creates, where released time goes, and what the organisation commits to its staff before the build lands.

Gate 6: Review

Canvas 18 (AI Benefits Realisation Canvas) is the evidence ledger after handover: baselines, measurement owners, readings and a corrective action trigger stated as a reading. Canvas 19 (AI Value Realisation Review) is the review itself, described below. Canvas 20 (AI Capability Roadmap Canvas) collects the prerequisites the readiness scores keep surfacing into a twelve, twenty-four and thirty-six month plan, so they are built once.

The three lanes

Governance burden in proportion to blast radius. The lane is set at Shape by consequence, and autonomy is one dimension of consequence alongside scale, reversibility, the population affected and how quickly a failure would be noticed. GOVBRM original; the lane boundaries are a Hypothesis.

LaneEntry testCanvases requiredCanvases optional
FastLow risk, a known pattern, rung one or two, no personal data or public-facing output03 AI Request Intake Canvas, 05 AI Risk and Ethics Canvas (flags only), 19 AI Value Realisation Review (a light reading at the review date), closed against a published playbook (10)02 if the need is unclear at intake
StandardModerate risk or value; Standard or Elevated exposure02, 03, 04, 05, 06, 07, 09, 14, 16, 18, 1911 if rung three or above; 12 if a supplier is proposed; 13 if prompts are run at scale; 15 and 17 where more than one team changes its work
StrategicHigh consequence, public-facing, cross-boundary, live procurement or high autonomy; Significant exposureAll twenty canvases, 01 to 20; 12 is completed as "no supplier" where none is proposedNone; the portfolio canvases 06, 08 and 20 receive the item and are updated

Ask of every item, whatever the lane: who bears the benefit, who bears the cost, and who has no seat at the table.

Scoring and routing, in short

CanvasScaleDecision rule
04 Readiness1 to 5 per dimension, weighted, max 50Weakest dimension decides; Go only in the top band with no dimension below 3
05 Risk and EthicsFlags with floorsHighest floor sets the rating; Significant flags force the strategic lane
07 Prioritisation1 to 5 per criterion, weights total 100, range 100 to 500Sponsor column first, relationship column decides; Rank now, Hold, Merge or Decline
11 Agent AssessmentFive rungsLowest rung that solves the task; four questions answered before approval
12 Vendor Evaluation1 to 5 per criterion, weights total 100Bands at 80, 60 and 40; data, security or exit condition overrides
19 Value ReviewMeasured against committed rangeScale, Continue, Adjust, Stop, or hold for up to three months

All weights, thresholds and floors are initial calibration, version 1.0, published to be argued with.

Facilitating the ninety-minute shaping session

Who is in the room: the requester, the Business Relationship Manager, and the sponsoring executive's delegate where the value range is material. Add a data or architecture person only if the readiness canvas will be scored in the same session.

Before: the intake record (03) is complete and circulated. Print or open canvas 02, and 04 and 05 if you expect to reach them.

MinutesActivityCanvas
0 to 10Read the request back verbatim; agree what was actually asked02, signal and requested solution
10 to 30Work beneath the request; ask why until the answer is an outcome; write the need sentence with no tool in it02, root need and who feels it
30 to 45Value as a range in the partner's unit; the lower bound they would act on; the counterfactual02, value hypothesis
45 to 55Pitch the rung; ask whether it needs a model at all02, rung
55 to 70Readiness, scored on evidence in the room; risk flags04, 05
70 to 85Choose the route; write the reasons the requester can repeat02, output
85 to 90Confirm what opens next, who owns it, and the date02, next steps

Facilitation notes. Write on the canvas in front of the room, not in private notes. When the requester restates the tool, write it in the requested solution box and move on. A need sentence is finished when the requester agrees with it and it reads differently from the request. If the value range cannot be stated, the route is Discovery or BRM engagement, not Project. Score readiness only against artefacts someone can point to; an assertion scores 1. Say the decline out loud in the room and write the reopening condition beside it. Close by reading the route and its reasons back. The relationship layer signs; nobody else.

Evidence to keep

Handing off into external governance

GOVBRM produces the inputs; the receiving process makes the decision.

FromToWhat travels
Canvas 05 Significant exposureData protection impact assessment, equality assessment, AI impact or risk assessment (ISO/IEC 42001, NIST AI RMF, EU AI Act tier)Flags, accountable role, data and population affected
Canvas 09Business case and appraisal (Green Book or local equivalent)Need sentence, benefit type and range, alternatives, owner
Canvas 11Security assurance, architecture review, AI assuranceRung, systems touched, approvals, evaluation plan
Canvas 12ProcurementConditions, exit and portability terms, scores by criterion
Canvases 02, 05, 11Transparency record (Algorithmic Transparency Recording Standard or equivalent)Purpose, rung, decisions taken alone, human review
Canvases 15, 16, 17Service assessment, workforce consultationGroups affected, adoption measures, task changes
Canvases 18, 19Benefits management, audit, portfolio boardMeasured value against committed number, decision

Record on the canvas the date each handoff was made and the reference the receiving process returned. The crosswalk is GOVBRM original; each receiving framework is Established.

Running the Value Realisation Review

Default at month nine after go-live, booked at Commit, unless canvas 14 set an earlier or later date from the value curve. Bring it forward if canvas 18 shows the reading well outside the committed range.

In the room: the Business Relationship Manager as loop owner, the named business owner, the product owner and the finance business partner. Inputs: the Commit gate record (09), the benefits ledger (18), the risk register rows from 05, and the current heatmap (08).

Steps. Copy the committed number from canvas 09; do not restate it from memory. Put the measured value beside it, with the measurement confidence. Re-run the risk flags. Decide one route: Scale (at or above the range, medium or high confidence, new number and review date); Continue (inside the range, next review in six months); Adjust (value real but shaping partly wrong; change rung, scope, controls or number and re-enter at Commit); Stop (below the range and the cause is the capability or the number; retain the learning, harvest residual benefit). If measurement confidence is too low, hold the gate and reconvene within three months with named measurements. Write the decision and the two facts that decided it. Then answer the loop question: what must the front door learn about how this was shaped, and which playbook (10) or roadmap (20) entry changes as a result. The relationship layer signs; the sponsoring executive countersigns any change to funding. GOVBRM original; the month-nine default is a Hypothesis.

Dates come to members first

Courses and certifications are announced in the GOVBRM Newsletter before anywhere else.

Join free for the essays behind the framework, the access code for the free micro-courses, and first word of every cohort. Paid membership adds the toolkit, the framework and a seat at the masterclasses.