The Method
Borrowed from safety-critical engineering: staged gates, defined entry criteria and written evidence at every transition. Nothing advances without it.
The five gates
A system that cannot clear a gate does not proceed — and that decision is documented too.
Prepare
Risk appetite, data rights and use-case triage before a single model is chosen.
Map
Obligations, controls and decision rights mapped onto the specific process.
Assure
Independent validation, red-teaming and an evidence package that survives audit.
Implement
Bounded, reversible production delivery with monitoring designed in.
Sustain
Run-state ownership, drift monitoring and periodic re-certification.
Inside each gate
Inventory current and shadow usage, establish risk appetite with the accountable executive, and triage candidate use cases against data rights and regulatory exposure.
Translate applicable regimes — EU AI Act, ISO/IEC 42001, NIST AI RMF, sector supervision — into the concrete controls, artifacts and decision rights for this process.
Validate the model, data and vendor chain independently of the build team. Red-team the failure modes that matter, and write the evidence package before go-live.
Ship into production with scoped permissions, human oversight that a reviewer can actually exercise, full logging and a rehearsed withdrawal path.
Monitor drift and performance, run incident and change processes, re-certify on a calendar, and transfer ownership to your teams with runbooks and training.
Principles
Every claim about performance, fairness or safety must be reproducible from an artifact, not from a vendor deck.
Any system we put into production can be withdrawn without halting the business process it supports.
Each control, decision and exception has a person attached to it, recorded at the time the decision was made.
Applied
The same gates, artifacts and evidence trail are implemented as software so your teams can run the method without us in the room.