ADGL
AI Deployment Governance Lifecycle (ADGL)
A practical governance methodology for taking AI safely from business approval to production deployment.
The Lifecycle
Discover, Assess, Govern, Deploy, Operate
- 01
Discover
Understand the AI system before governance begins.
- 02
Assess
Quantify exposure before any control is designed.
- 03
Govern
Design the structure, controls and oversight that reduce risk to the accepted level.
- 04
Deploy
Prove every control works, then decide.
- 05
Operate
Keep governance working after deployment.
Why ADGL Exists
Most organisations deploying AI already hold ISO 27001, SOC 2 and a GDPR programme. Yet they still lack an operational process for deploying AI into production: who owns the decision to accept an AI risk, whether retrieval is scoped so one customer cannot reach another's data, whether human review is real or has become a formality. ADGL fills that gap: a practical, implementation-first lifecycle that turns AI governance from policy into operational controls.
Five Phases
Explore Each Phase
Click a phase for its governance question, activities and gate.
01Discover
Understand the AI system before governance begins.
Discover
Understand the AI system before governance begins.
Governance Question
What business problem is this AI solving, and who owns that outcome?
Activities
- Stakeholder interviews across engineering, security, privacy, operations, legal, product and data platform
- Identify and register every AI asset in build or production
- Map AI data flow end to end, numbered step by step
- Review AI application architecture against the codebase
Exit Criteria
Asset inventory completed with named owners; data flow mapped and validated against the codebase.
Gate 1 — Proceed to Assess
02Assess
Quantify exposure before any control is designed.
Assess
Quantify exposure before any control is designed.
Governance Question
What is the worst credible outcome for a customer, and can it be undone?
Activities
- Score every risk across likelihood, severity, reach, reversibility and decision autonomy
- Conduct the Data Protection Impact Assessment
- Perform threat modelling with security engineering
- Assess the model provider: training use, residency, retention, versioning, exit
Exit Criteria
Regulatory classification documented; residual risk accepted in writing by a named owner.
Gate 2 — Proceed to Govern
03Govern
Design the structure, controls and oversight that reduce risk to the accepted level.
Govern
Design the structure, controls and oversight that reduce risk to the accepted level.
Governance Question
Who has authority to stop a deployment, and has that been exercised?
Activities
- Design the governance operating model and committee decision rights
- Build the RACI to individual role level
- Design human oversight tiers and measurement thresholds
- Build the control library mapped to existing frameworks
Exit Criteria
Control library approved and mapped; logging schema accepted by engineering.
Gate 3 — Proceed to Deploy
04Deploy
Prove every control works, then decide.
Deploy
Prove every control works, then decide.
Governance Question
Can we show this control operated, or only that it exists?
Activities
- Configure monitoring signals, thresholds and alert routing to named responders
- Run adversarial and cross-tenant tests, embedded in CI
- Build the evidence repository and populate pre-deployment artefacts
- Deliver role-based training with scenario assessment
Exit Criteria
Readiness checklist approved; deployment approved by committee and recorded.
Gate 4 — Authorise production deployment
05Operate
Keep governance working after deployment.
Operate
Keep governance working after deployment.
Governance Question
Has the override rate fallen below the floor?
Activities
- Tune monitoring thresholds against real production volume
- Run independent QA sampling cycles
- Produce the quarterly executive and board reporting pack
- Route the next AI use case through the approval workflow
Exit Criteria
Next use case governed through the same workflow, without bespoke governance work.
Gate 5 — Governance operates without external support
Deployment-Agnostic
Supported Deployments
The lifecycle is deployment-agnostic: the activities, controls and gates hold regardless of model, vendor or industry.
- Microsoft Copilot Enterprise
- ChatGPT Enterprise
- Customer Support AI
- Internal Knowledge Assistants
- RAG Applications
- Agentic AI
- AI-Enabled SaaS Platforms
- Industry-Specific AI Systems
Deliverables
What ADGL Produces
01Discover
Creates the documentation needed to understand the AI system before governance begins.
Discover
Creates the documentation needed to understand the AI system before governance begins.
Key Deliverables
AI Discovery
- AI Asset Inventory
- Architecture Review
Data Understanding
- AI Data Flow Mapping
- Data Classification
Documentation
- Prompt Flow Map
- Findings Log
02Assess
Produces the evidence needed to evaluate AI risk and regulatory exposure.
Assess
Produces the evidence needed to evaluate AI risk and regulatory exposure.
Key Deliverables
Risk Analysis
- AI Risk Assessment
- Risk Heat Map
Privacy & Security
- DPIA
- Threat Model
Vendor & Regulatory
- Third-Party AI Assessment
- Regulatory Assessment
03Govern
Establishes governance structures, operational controls and decision rights.
Govern
Establishes governance structures, operational controls and decision rights.
Key Deliverables
Governance Structure
- Governance Operating Model
- RACI
- Approval Workflow
Operational Controls
- AI Control Library
- Logging Specification
Oversight
- Human Oversight Design
- Governance KPIs
- AI Policies & Standards
04Deploy
Demonstrates that governance controls operate effectively before production.
Deploy
Demonstrates that governance controls operate effectively before production.
Key Deliverables
Monitoring
- Monitoring Framework
- AI Incident Management
Evidence
- Evidence Repository
- Test Results Pack
Production Readiness
- Training Record
- Production Readiness Governance
05Operate
Ensures governance remains effective through monitoring, reporting and continual improvement.
Operate
Ensures governance remains effective through monitoring, reporting and continual improvement.
Key Deliverables
Monitoring
- Threshold Tuning Report
- QA Sampling Results
Reporting
- Executive Reporting
- Governance Review
Governance Improvement
- Maturity Roadmap
Get ADGL
Download the ADGL Framework
Five phases, eighteen operational controls, risk scoring, RACI and a twelve-week delivery schedule, in one reference document.
ADGL and OPERA
AI for U&I delivers advisory engagements using the OPERA consulting methodology. ADGL is one specialised methodology within AI for U&I, focused specifically on governing AI deployments through production; OPERA remains the operating method behind how an engagement itself is run, including ADGL engagements.
See the OPERA methodology →Deploying AI?
Let's build governance before production. Start a working conversation about a specific AI deployment with Ramya Amballa.