Skip to content

ADGL

AI Deployment Governance Lifecycle (ADGL)

A practical methodology for governing AI before production.

The Lifecycle

Discover, Assess, Govern, Deploy, Operate

Five phases, each answering one governance decision and producing named deliverables, from the business request that opens a deployment to the assurance evidence that outlasts it.

  1. 01

    Discover

    Weeks 1–3

    Understand the AI system before governance begins.

    What business problem is this AI solving, and who owns that outcome?

  2. 02

    Assess

    Weeks 3–6

    Quantify exposure before any control is designed.

    What is the worst credible outcome for a customer, and can it be undone?

  3. 03

    Govern

    Weeks 6–9

    Design the structure, controls and oversight that reduce risk to the accepted level.

    Who has authority to stop a deployment, and has that been exercised?

  4. 04

    Deploy

    Weeks 9–12

    Prove every control works, then decide.

    Can we show this control operated, or only that it exists?

  5. 05

    Operate

    Ongoing, quarterly cycle

    Keep governance working after deployment.

    Has the override rate fallen below the floor?


Why ADGL Exists

Most organisations deploying AI already hold ISO 27001, SOC 2 and a GDPR compliance programme. Yet they still lack an operational governance process for deploying AI into production: who owns the decision to accept an AI risk, and where that's recorded; whether personal data in a vector store can be erased on request; whether retrieval is scoped so one customer cannot reach another's data; whether human review is real, or has become a formality. ADGL fills that gap: a practical, implementation-first governance lifecycle that turns AI governance from policy into operational controls.

What ADGL Provides

Structure and Substance, Not a Policy Statement

Structure

  • Five phases with defined activities and exit criteria
  • Four decision gates before production
  • Twelve-week delivery schedule
  • Named owner against every activity

Substance

  • Eighteen operational controls with evidence requirements
  • Risk scoring and use case classification
  • Human oversight design with measurement thresholds
  • Monitoring, incident and readiness governance

Five Phases

What Each Phase Answers, and What It Produces

Every phase is a governance decision, not a checkbox: a specific question, a defined set of activities, and deliverables a board or regulator can actually review.

01
Phase 1Weeks 1–3

Discover

Understand the AI system before governance begins.

Governance Question

What business problem is this AI solving, and who owns that outcome?

Activities

  • Stakeholder interviews across engineering, security, privacy, operations, legal, product and data platform
  • Identify and register every AI asset in build or production
  • Map AI data flow end to end, numbered step by step
  • Review AI application architecture against the codebase

Key Deliverables

AI Asset Inventory, AI Data Flow Mapping, Prompt Flow Map, Architecture Review, Data Classification, Findings Log

Asset inventory completed with named owners; data flow mapped and validated against the codebase.

Gate 1 — Proceed to Assess

02
Phase 2Weeks 3–6

Assess

Quantify exposure before any control is designed.

Governance Question

What is the worst credible outcome for a customer, and can it be undone?

Activities

  • Score every risk across likelihood, severity, reach, reversibility and decision autonomy
  • Conduct the Data Protection Impact Assessment
  • Perform threat modelling with security engineering
  • Assess the model provider: training use, residency, retention, versioning, exit

Key Deliverables

AI Risk Assessment, Risk Heat Map, DPIA, Threat Model, Third-Party AI Assessment, Regulatory Assessment

Regulatory classification documented; residual risk accepted in writing by a named owner.

Gate 2 — Proceed to Govern

03
Phase 3Weeks 6–9

Govern

Design the structure, controls and oversight that reduce risk to the accepted level.

Governance Question

Who has authority to stop a deployment, and has that been exercised?

Activities

  • Design the governance operating model and committee decision rights
  • Build the RACI to individual role level
  • Design human oversight tiers and measurement thresholds
  • Build the control library mapped to existing frameworks

Key Deliverables

Governance Operating Model, RACI, Approval Workflow, Human Oversight Design, AI Control Library, AI Policies & Standards, Logging Specification, Governance KPIs

Control library approved and mapped; logging schema accepted by engineering.

Gate 3 — Proceed to Deploy

04
Phase 4Weeks 9–12

Deploy

Prove every control works, then decide.

Governance Question

Can we show this control operated, or only that it exists?

Activities

  • Configure monitoring signals, thresholds and alert routing to named responders
  • Run adversarial and cross-tenant tests, embedded in CI
  • Build the evidence repository and populate pre-deployment artefacts
  • Deliver role-based training with scenario assessment

Key Deliverables

Monitoring Framework, AI Incident Management, Evidence Repository, Test Results Pack, Training Record, Production Readiness Governance

Readiness checklist approved; deployment approved by committee and recorded.

Gate 4 — Authorise production deployment

05
Phase 5Ongoing, quarterly cycle

Operate

Keep governance working after deployment.

Governance Question

Has the override rate fallen below the floor?

Activities

  • Tune monitoring thresholds against real production volume
  • Run independent QA sampling cycles
  • Produce the quarterly executive and board reporting pack
  • Route the next AI use case through the approval workflow

Key Deliverables

Threshold Tuning Report, QA Sampling Results, Executive Reporting, Governance Review, Maturity Roadmap

Next use case governed through the same workflow, without bespoke governance work.

Gate 5 — Governance operates without external support


Deployment-Agnostic

Typical AI Deployments Supported

The lifecycle is deployment-agnostic: the activities, controls and gates hold regardless of model, vendor or industry.

  • Microsoft Copilot Enterprise
  • ChatGPT Enterprise
  • Customer Support AI
  • Internal Knowledge Assistants
  • RAG Applications
  • Agentic AI
  • AI-Enabled SaaS Platforms
  • Industry-Specific AI Systems

Methodology

Download the Full ADGL Methodology

The complete methodology: five phases, eighteen operational controls, the risk scoring and use case approval model, RACI and a twelve-week delivery schedule, as a single reference document.


ADGL and OPERA

AI for U&I delivers advisory engagements using the OPERA consulting methodology. ADGL is one specialised methodology within AI for U&I, focused specifically on governing AI deployments through production; OPERA remains the operating method behind how an engagement itself is run, including ADGL engagements.

See the OPERA methodology →

Deploying AI?

Let's build governance before production. Start a working conversation about a specific AI deployment with Ramya Amballa.