Approve the production readiness gate for an initiative at or above materiality
Draft
Approve the production readiness gate for an initiative at or above materiality
Allocation
| L5-05 | |
|---|---|
| Decides | PMO Lead |
| Consulted | Business Accountable Executive, Model Owner and Head of Risk |
| Executes | Delivery team |
| Evidence | Gate record. The Layer 4 deployment authorization is a mandatory entry condition. Absent it, the gate cannot be approved. Where the initiative consumes an existing model, a statement that its use sits within that model card's stated purpose, or an L4-AUT-04 approval. |
| Delegated band | Delegated |
In plain terms
Confirm the initiative is ready to go live. The PMO decides delivery readiness, which is its competence. It cannot decide governance readiness, and it cannot proceed without evidence that someone who could has.
What is being judged
Delivery readiness only: is the thing built, tested, supportable and adopted. The governance question is answered elsewhere and arrives as an entry condition.
This single row is what stops the delivery pipeline from becoming an authorization bypass. Without it, an initiative passes every stage gate, reaches production, and has no classification, no named accountable executive and no deployment authorization. Nobody bypassed a control. Every gate tested delivery readiness and none tested governance readiness. That is the Layer 5 seam and it is the most common route by which an ungoverned AI system reaches production.
The PMO’s job at this gate is narrow and important: verify the authorization exists and is current, not evaluate whether it should have been granted. A PMO that assesses the quality of a Layer 4 authorization has taken on a judgment it is not positioned to make.
What this decision does not cover
It does not authorize production use, accept risk or classify. All three are Layer 4, and all three must have happened before this gate can be approved.
When it fires
On event. At the production readiness point of a material initiative. On re-entry after a failed gate. When a pilot transitions under L5-06 and enters production properly.
On cycle. None.
What you need before deciding
The Layer 4 deployment authorization, current and matching the version being deployed. The composite accountability record. Delivery evidence: test results, supportability, runbooks, the Layer 1 service level objective. Adoption readiness from L5-14. Under recommendation R2 below, a statement that the initiative sits within the model card’s stated purpose where it consumes an existing model.
How this goes wrong
The ungoverned go-live: the entry condition is treated as advisory and the gate passes on delivery evidence alone. The Layer 5 anti-pattern, and the Layer 5 metric exists to detect it. Authorization for the wrong version: the authorization names one model version and deployment serves another, which passes a check that verifies existence rather than currency. The PMO as reviewer: the gate becomes a second-guessing of Layer 4 rather than a verification, which slows delivery without improving governance.
Related decisions
Entry condition L4-AUT-01 authorization, L4-RSK-03 composite acceptance.
Upstream L4-CLS-04 classification, L5-04 earlier gates.
Downstream production operation, L1 service management.
Metric Layer 5 metric 1.
Instrument references
COBIT BAI07 change acceptance and transitioning. PMI phase gate practice. ITIL 4 release management. All specify gates against delivery criteria. None makes an authorization from a governance function a mandatory entry condition. Crosswalk gap 8.
Correction
The maintainer answers corrections. There is no service level. Responses are best-effort and opportunistic within a reasonable time: a correction raised on a Monday is answered that week or sooner.