AI Centric IT Governance Model (AI9GM)

Your frameworks are correct. AI broke the seams between them.

AI9GM is a six-layer reference model. It allocates decision rights across the whole estate an AI system depends on, from infrastructure to strategy, then maps every layer onto the standards you already run.

The problem

Nobody made the wrong call. Nobody made the call at all.

A production model touches six functions before it influences a single decision. Each one follows its own framework correctly. The gap is not inside any of them.

  • DATABuilt and validated the model against a training distribution nobody re-checked after deployment.
  • PLATFORMShipped it to production on the strength of a passing test suite.
  • PROCUREMENTSigned the vendor terms, including the clause on training-data provenance.
  • SECURITYScanned the container. Did not scope the model itself as an asset.
  • BUSINESSRelies on the output daily. Has never seen a validation report.
  • RISKLearns the system exists when it produces an outcome someone escalates.
The model · six layers

Ordered by dependency, not importance.

Each layer carries a scope boundary, inputs and outputs, decision rights, required artifacts, metrics, maturity descriptors and a standards crosswalk.

On layers 3 and 4. Layer 3 operates controls and produces evidence. Layer 4 decides which controls are required and verifies that evidence. Layer 3 runs the scanner. Layer 4 decides scanning is mandatory, accepts the residual risk and answers for it.

What makes it usable

Controls you can borrow. Decision rights you have to allocate.

Every layer carries an explicit allocation of who decides, who is consulted, who executes and what evidence must survive the decision. An extract from Layer 4, which holds 38 of the framework's 94 decisions:

DecisionDecidesConsultedEvidence retained
Classify an AI system by consequence, at or above materialityAI Risk CommitteeBusiness Accountable Executive, Model Owner, CISO and General CounselClassification record with rationale and review trigger
Accept the composite decision to deploy and operate an AI systemBusiness Accountable ExecutiveDomain owners, Model Owner and Head of Internal AuditComposite accountability record referencing each domain acceptance
Authorize the business actions an agent may takeBusiness Accountable Executive, or an executive with appropriate delegated authorityCAIO, Head of Risk and General CounselAction authorization naming permitted actions and limits
Withdraw a model from production on risk groundsBusiness Accountable ExecutiveModel Owner, Head of Risk and business unit headWithdrawal decision, impact assessment, notification record

See the full allocation across all six layers →

Position

An integration layer, not a replacement.

You are not being asked to abandon anything. Each AI9GM layer maps to the instruments that already cover it, the ones that cover it partially and the governance surface none of them anticipated.

COBIT 2019ITIL 4TOGAF 10ISO/IEC 27001:2022ISO/IEC 42001NIST AI RMFEU AI ActISO/IEC 38500ISO/IEC 23894ISO 31000PMI portfolio and program standardsGreenhouse Gas Protocol, CSRDSTRATA Protocol

Open the crosswalk →

REGULATORY NOTE
Updated 15 Aug 2026

Sixteen extra months is a build window, not a reprieve.

The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026, deferring Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. GPAI provider obligations and the Article 5 prohibitions are unchanged and remain in force.

The deferral moved a deadline. It did not reduce the work. System inventory, classification, named accountability and retained evidence are an operating-model problem before they are a legal one.

How the layers map to the obligations →

Status · AI9GM v0.9

What this is, and what it has not yet earned.

AI9GM began as one technology practice's internal operating model and was published so it could be corrected. A framework that overstates its own maturity fails its first test, so:

What it is

  • A published, versioned reference model, free to adopt and adapt
  • A working artifact, used before it was published
  • An explicit crosswalk to the standards you already run
  • A self-assessment you can complete without contacting anyone

What it is not

  • Not an accredited standard. It carries no legal standing
  • No certification exists. Nobody is AI9GM-certified
  • Not community-governed yet. Independent stewardship is an intention
  • Not yet validated by measured multi-organization outcomes
  • Not independently reviewed. The editor, publisher and only implementation partner are the same person.

Read the roadmap and revision history →

Score your six layers in under ten minutes.

Eighteen questions, three per layer, produce a maturity profile per layer rather than a single score. Uneven maturity is the diagnosis. A level 4 Foundation sitting under a level 1 Control layer is the shape most estates are in. Results render immediately. Email is optional and only sends you a copy.