Skip to content

ADGL

AI Deployment Governance Lifecycle (ADGL)

A practical governance methodology for taking AI safely from business approval to production deployment.

The Lifecycle

Discover, Assess, Govern, Deploy, Operate

  1. 01

    Discover

    Understand the AI system before governance begins.

  2. 02

    Assess

    Quantify exposure before any control is designed.

  3. 03

    Govern

    Design the structure, controls and oversight that reduce risk to the accepted level.

  4. 04

    Deploy

    Prove every control works, then decide.

  5. 05

    Operate

    Keep governance working after deployment.


Why ADGL Exists

Most organisations deploying AI already hold ISO 27001, SOC 2 and a GDPR programme. Yet they still lack an operational process for deploying AI into production: who owns the decision to accept an AI risk, whether retrieval is scoped so one customer cannot reach another's data, whether human review is real or has become a formality. ADGL fills that gap: a practical, implementation-first lifecycle that turns AI governance from policy into operational controls.

Five Phases

Explore Each Phase

Click a phase for its governance question, activities and gate.

01

Discover

Understand the AI system before governance begins.

Governance Question

What business problem is this AI solving, and who owns that outcome?

Activities

  • Stakeholder interviews across engineering, security, privacy, operations, legal, product and data platform
  • Identify and register every AI asset in build or production
  • Map AI data flow end to end, numbered step by step
  • Review AI application architecture against the codebase

Exit Criteria

Asset inventory completed with named owners; data flow mapped and validated against the codebase.

Gate 1 — Proceed to Assess

02

Assess

Quantify exposure before any control is designed.

Governance Question

What is the worst credible outcome for a customer, and can it be undone?

Activities

  • Score every risk across likelihood, severity, reach, reversibility and decision autonomy
  • Conduct the Data Protection Impact Assessment
  • Perform threat modelling with security engineering
  • Assess the model provider: training use, residency, retention, versioning, exit

Exit Criteria

Regulatory classification documented; residual risk accepted in writing by a named owner.

Gate 2 — Proceed to Govern

03

Govern

Design the structure, controls and oversight that reduce risk to the accepted level.

Governance Question

Who has authority to stop a deployment, and has that been exercised?

Activities

  • Design the governance operating model and committee decision rights
  • Build the RACI to individual role level
  • Design human oversight tiers and measurement thresholds
  • Build the control library mapped to existing frameworks

Exit Criteria

Control library approved and mapped; logging schema accepted by engineering.

Gate 3 — Proceed to Deploy

04

Deploy

Prove every control works, then decide.

Governance Question

Can we show this control operated, or only that it exists?

Activities

  • Configure monitoring signals, thresholds and alert routing to named responders
  • Run adversarial and cross-tenant tests, embedded in CI
  • Build the evidence repository and populate pre-deployment artefacts
  • Deliver role-based training with scenario assessment

Exit Criteria

Readiness checklist approved; deployment approved by committee and recorded.

Gate 4 — Authorise production deployment

05

Operate

Keep governance working after deployment.

Governance Question

Has the override rate fallen below the floor?

Activities

  • Tune monitoring thresholds against real production volume
  • Run independent QA sampling cycles
  • Produce the quarterly executive and board reporting pack
  • Route the next AI use case through the approval workflow

Exit Criteria

Next use case governed through the same workflow, without bespoke governance work.

Gate 5 — Governance operates without external support


Deployment-Agnostic

Supported Deployments

The lifecycle is deployment-agnostic: the activities, controls and gates hold regardless of model, vendor or industry.

  • Microsoft Copilot Enterprise
  • ChatGPT Enterprise
  • Customer Support AI
  • Internal Knowledge Assistants
  • RAG Applications
  • Agentic AI
  • AI-Enabled SaaS Platforms
  • Industry-Specific AI Systems

Deliverables

What ADGL Produces

01

Discover

Creates the documentation needed to understand the AI system before governance begins.

Key Deliverables

AI Discovery

  • AI Asset Inventory
  • Architecture Review

Data Understanding

  • AI Data Flow Mapping
  • Data Classification

Documentation

  • Prompt Flow Map
  • Findings Log
02

Assess

Produces the evidence needed to evaluate AI risk and regulatory exposure.

Key Deliverables

Risk Analysis

  • AI Risk Assessment
  • Risk Heat Map

Privacy & Security

  • DPIA
  • Threat Model

Vendor & Regulatory

  • Third-Party AI Assessment
  • Regulatory Assessment
03

Govern

Establishes governance structures, operational controls and decision rights.

Key Deliverables

Governance Structure

  • Governance Operating Model
  • RACI
  • Approval Workflow

Operational Controls

  • AI Control Library
  • Logging Specification

Oversight

  • Human Oversight Design
  • Governance KPIs
  • AI Policies & Standards
04

Deploy

Demonstrates that governance controls operate effectively before production.

Key Deliverables

Monitoring

  • Monitoring Framework
  • AI Incident Management

Evidence

  • Evidence Repository
  • Test Results Pack

Production Readiness

  • Training Record
  • Production Readiness Governance
05

Operate

Ensures governance remains effective through monitoring, reporting and continual improvement.

Key Deliverables

Monitoring

  • Threshold Tuning Report
  • QA Sampling Results

Reporting

  • Executive Reporting
  • Governance Review

Governance Improvement

  • Maturity Roadmap

Get ADGL

Download the ADGL Framework

Five phases, eighteen operational controls, risk scoring, RACI and a twelve-week delivery schedule, in one reference document.


ADGL and OPERA

AI for U&I delivers advisory engagements using the OPERA consulting methodology. ADGL is one specialised methodology within AI for U&I, focused specifically on governing AI deployments through production; OPERA remains the operating method behind how an engagement itself is run, including ADGL engagements.

See the OPERA methodology →

Deploying AI?

Let's build governance before production. Start a working conversation about a specific AI deployment with Ramya Amballa.