ADGL
AI Deployment Governance Lifecycle (ADGL)
A practical methodology for governing AI before production.
The Lifecycle
Discover, Assess, Govern, Deploy, Operate
Five phases, each answering one governance decision and producing named deliverables, from the business request that opens a deployment to the assurance evidence that outlasts it.
- 01
Discover
Weeks 1–3
Understand the AI system before governance begins.
What business problem is this AI solving, and who owns that outcome?
- 02
Assess
Weeks 3–6
Quantify exposure before any control is designed.
What is the worst credible outcome for a customer, and can it be undone?
- 03
Govern
Weeks 6–9
Design the structure, controls and oversight that reduce risk to the accepted level.
Who has authority to stop a deployment, and has that been exercised?
- 04
Deploy
Weeks 9–12
Prove every control works, then decide.
Can we show this control operated, or only that it exists?
- 05
Operate
Ongoing, quarterly cycle
Keep governance working after deployment.
Has the override rate fallen below the floor?
Why ADGL Exists
Most organisations deploying AI already hold ISO 27001, SOC 2 and a GDPR compliance programme. Yet they still lack an operational governance process for deploying AI into production: who owns the decision to accept an AI risk, and where that's recorded; whether personal data in a vector store can be erased on request; whether retrieval is scoped so one customer cannot reach another's data; whether human review is real, or has become a formality. ADGL fills that gap: a practical, implementation-first governance lifecycle that turns AI governance from policy into operational controls.
What ADGL Provides
Structure and Substance, Not a Policy Statement
Structure
- Five phases with defined activities and exit criteria
- Four decision gates before production
- Twelve-week delivery schedule
- Named owner against every activity
Substance
- Eighteen operational controls with evidence requirements
- Risk scoring and use case classification
- Human oversight design with measurement thresholds
- Monitoring, incident and readiness governance
Five Phases
What Each Phase Answers, and What It Produces
Every phase is a governance decision, not a checkbox: a specific question, a defined set of activities, and deliverables a board or regulator can actually review.
Discover
Understand the AI system before governance begins.
Governance Question
What business problem is this AI solving, and who owns that outcome?
Activities
- Stakeholder interviews across engineering, security, privacy, operations, legal, product and data platform
- Identify and register every AI asset in build or production
- Map AI data flow end to end, numbered step by step
- Review AI application architecture against the codebase
Key Deliverables
AI Asset Inventory, AI Data Flow Mapping, Prompt Flow Map, Architecture Review, Data Classification, Findings Log
Asset inventory completed with named owners; data flow mapped and validated against the codebase.
Gate 1 — Proceed to Assess
Assess
Quantify exposure before any control is designed.
Governance Question
What is the worst credible outcome for a customer, and can it be undone?
Activities
- Score every risk across likelihood, severity, reach, reversibility and decision autonomy
- Conduct the Data Protection Impact Assessment
- Perform threat modelling with security engineering
- Assess the model provider: training use, residency, retention, versioning, exit
Key Deliverables
AI Risk Assessment, Risk Heat Map, DPIA, Threat Model, Third-Party AI Assessment, Regulatory Assessment
Regulatory classification documented; residual risk accepted in writing by a named owner.
Gate 2 — Proceed to Govern
Govern
Design the structure, controls and oversight that reduce risk to the accepted level.
Governance Question
Who has authority to stop a deployment, and has that been exercised?
Activities
- Design the governance operating model and committee decision rights
- Build the RACI to individual role level
- Design human oversight tiers and measurement thresholds
- Build the control library mapped to existing frameworks
Key Deliverables
Governance Operating Model, RACI, Approval Workflow, Human Oversight Design, AI Control Library, AI Policies & Standards, Logging Specification, Governance KPIs
Control library approved and mapped; logging schema accepted by engineering.
Gate 3 — Proceed to Deploy
Deploy
Prove every control works, then decide.
Governance Question
Can we show this control operated, or only that it exists?
Activities
- Configure monitoring signals, thresholds and alert routing to named responders
- Run adversarial and cross-tenant tests, embedded in CI
- Build the evidence repository and populate pre-deployment artefacts
- Deliver role-based training with scenario assessment
Key Deliverables
Monitoring Framework, AI Incident Management, Evidence Repository, Test Results Pack, Training Record, Production Readiness Governance
Readiness checklist approved; deployment approved by committee and recorded.
Gate 4 — Authorise production deployment
Operate
Keep governance working after deployment.
Governance Question
Has the override rate fallen below the floor?
Activities
- Tune monitoring thresholds against real production volume
- Run independent QA sampling cycles
- Produce the quarterly executive and board reporting pack
- Route the next AI use case through the approval workflow
Key Deliverables
Threshold Tuning Report, QA Sampling Results, Executive Reporting, Governance Review, Maturity Roadmap
Next use case governed through the same workflow, without bespoke governance work.
Gate 5 — Governance operates without external support
Deployment-Agnostic
Typical AI Deployments Supported
The lifecycle is deployment-agnostic: the activities, controls and gates hold regardless of model, vendor or industry.
- Microsoft Copilot Enterprise
- ChatGPT Enterprise
- Customer Support AI
- Internal Knowledge Assistants
- RAG Applications
- Agentic AI
- AI-Enabled SaaS Platforms
- Industry-Specific AI Systems
Methodology
Download the Full ADGL Methodology
The complete methodology: five phases, eighteen operational controls, the risk scoring and use case approval model, RACI and a twelve-week delivery schedule, as a single reference document.
ADGL and OPERA
AI for U&I delivers advisory engagements using the OPERA consulting methodology. ADGL is one specialised methodology within AI for U&I, focused specifically on governing AI deployments through production; OPERA remains the operating method behind how an engagement itself is run, including ADGL engagements.
See the OPERA methodology →Deploying AI?
Let's build governance before production. Start a working conversation about a specific AI deployment with Ramya Amballa.