AI9GM
Type to search documentation.

Layer 6

Strategic

The Enterprise Compass

Should it be built?

Purpose

Decide which AI capabilities the organization should hold, why, and what governance capability it must build to hold them responsibly.

Scope boundary

ExcludedOwned byBoundary
Whether a system is permitted to operateL4L6 decides the capability is worth having. L4 decides it may run.
Prioritization, sequencing and funding allocationL5L6 states the outcome. L5 decides the order and the resourcing.
Model sourcing implementation and vendor contractingL2, L4L6 sets the sourcing posture. L2 admits, L4 contracts.
Risk acceptance of any kindL4Strategic ambition is not a risk acceptance.
Architecture, technology and platform selectionL2L6 decides the capability. L2 decides what builds it.
Individual work reallocation decisionsL5L6 assesses the cumulative position, not the individual case.

Layer 6 decides whether and why. It decides nothing about how.

The boundary most often crossed in practice, and it runs downward rather than upward. Every other layer in this framework has a seam where it accumulates authority belonging above it. Layer 6 has the opposite problem. It cedes authority it holds.

The mechanism is ordinary. The Portfolio Board funds initiatives. Initiatives get delivered. Someone then writes a strategy document describing what the organization is doing with AI, and it describes the sum of what was already funded. The strategy is coherent, accurate and entirely retrospective. It directed nothing.

An organization in this condition has a Layer 5 that sets strategy through funding decisions and a Layer 6 that documents it afterward. Nobody chose this and it is difficult to see from inside, because the strategy document exists and reads well.

The closure is the same shape used at Layer 5. A funding decision requires a traceable strategic outcome as an entry condition. The Portfolio Board still decides what gets funded and when, which is its competence. It cannot fund toward an outcome nobody stated.

Inputs

ItemFromForm
Aggregate exposure assessmentL4Provider concentration, correlated failure, cumulative decisioning
AI system materiality mechanismL4The threshold that determines what requires formal governance
Investment appraisal method and hurdle rateL4The basis on which a case is assessed
Regulatory obligation positionL4What the organization is already committed to
Benefit realization assessmentsL5Measured outcomes of completed initiatives
Capability and skills planL5What the organization can currently do and what it cannot
Aggregate work reallocation positionL5Cumulative effect of reallocation decisions above threshold
Capacity constraints and lead timesL1What any strategy can actually schedule
Technology roadmap and rationalization planL2Existing commitments and their end dates
Maturity assessment per layerL1Current governance capability against target
Maturity assessment per layerL2Current governance capability against target
Maturity assessment per layerL3Current governance capability against target
Maturity assessment per layerL4Current governance capability against target
Maturity assessment per layerL5Current governance capability against target
Market, competitive and regulatory directionExternalContext the organization does not control

Input 10 is the one that makes this layer a governance layer rather than a planning function. Strategy set without a view of the organization’s governance maturity produces commitments the other five layers cannot support.

Outputs

ItemToForm
Enterprise AI strategy with measurable outcomesL1Stated outcomes with the measure and the interval
Enterprise AI strategy with measurable outcomesL2Stated outcomes with the measure and the interval
Enterprise AI strategy with measurable outcomesL3Stated outcomes with the measure and the interval
Enterprise AI strategy with measurable outcomesL4Stated outcomes with the measure and the interval
Enterprise AI strategy with measurable outcomesL5Stated outcomes with the measure and the interval
Target maturity level per layerL1The governance capability the strategy requires, per layer
Target maturity level per layerL2The governance capability the strategy requires, per layer
Target maturity level per layerL3The governance capability the strategy requires, per layer
Target maturity level per layerL4The governance capability the strategy requires, per layer
Target maturity level per layerL5The governance capability the strategy requires, per layer
Capability decisions, including decisions not to use AIL4Decision records documented proportionately to materiality
Capability decisions, including decisions not to use AIL5Decision records documented proportionately to materiality
Model sourcing postureL2Build, buy or multi-provider position with the concentration limit
Model sourcing postureL4Build, buy or multi-provider position with the concentration limit
Aggregate work reallocation positionL5Accepted cumulative effect with the workforce consequence stated
Aggregate work reallocation positionExternalAccepted cumulative effect with the workforce consequence stated
Sustainability targets for AI workloadsL1Energy and carbon targets with the measurement method
Sustainability targets for AI workloadsL4Energy and carbon targets with the measurement method
Emerging technology evaluation chartersL5Scope with kill criteria and a decision date
Strategic outcome assessmentsExternalMeasured results against the stated outcomes
Strategic outcome assessmentsL5Measured results against the stated outcomes

Output 2 is what makes the framework operable as a plan rather than as a description. An organization that states a target maturity per layer has converted a governance model into a roadmap. One that does not has six layers and no destination.

Decision rights

IDDecisionDecidesConsultedExecutesEvidenceDelegated bandInterpretation
L6-01Approve the enterprise AI strategyCEO or equivalentCIO, CAIO, CFO and executive committeeCIOApproved strategy with measurable outcomes and intervalsDecide what the organization is trying to achieve with AI, with measures and intervals. Without measures it is a statement of intent, and funding cannot trace to it.
L6-02Set the target maturity level per AI9GM layerCIOCAIO, CISO, Head of Risk and CFOLayer ownersTarget state per layer with the date and the gapDecide what governance capability the organization should hold, per layer. This converts the framework from a description into a roadmap and is what makes the assessment a gap analysis.
L6-03Decide whether a business capability should use AI at allBusiness OwnerCAIO and Head of RiskBusiness OwnerCapability decision record, documented proportionately to materiality, stating the option not takenDecide, for this capability, whether AI is the right answer. A decision not to use AI is recorded, because an organization that never documents restraint cannot distinguish judgment from inattention.
L6-04Set the model sourcing posture and concentration limitCIOCAIO, CFO, Head of Risk and Head of Enterprise ArchitectureHead of Enterprise ArchitectureSourcing posture with the concentration position statedDecide build, buy or multi-provider, and how much dependence on one provider is acceptable. Without a posture the estate consolidates by convenience.
L6-05Accept the aggregate work reallocation positionCEO or equivalentHead of Talent, Head of Risk and business unit headsHead of TalentAccepted position with the workforce consequence stated, including whether the organization retains enough practice to exercise oversight competently over the systems taking the workDelegatedAccept what the individual reallocation decisions amount to across the organization.
L6-06Approve a strategic initiative where required layer maturity is not yet in placeCEO or equivalentCIO, Head of Risk and AI Governance BoardCIOApproval with the maturity gap named and a remediation plan bound to itProceed past a governance gap, with the gap named in the approval and a remediation plan bound to it. Permitted deliberately: the failure being prevented is ambition nobody wrote down as a risk.
L6-07Decide that an emerging technology warrants evaluationCAIOCTO and CIOInnovation leadEvaluation charter with scope, kill criteria and decision dateDecide something is worth a bounded look, with kill criteria and a decision date. Evaluations without kill criteria are pilots under a different name.
L6-08Approve a business model change enabled by AICEO or equivalent, board where materialCIO, CFO and General CounselBusiness OwnerBoard decision recordDecide the organization will operate differently because of what AI makes possible.
L6-09Set sustainability and energy accountability targets for AI workloadsCIOCFO, Platform Owner and CAIOPlatform OwnerTarget statement with the measurement methodDecide what the organization commits to on energy and carbon for AI, and how it is measured. A target with no measurement method is a statement.
L6-10Discontinue an AI capability on strategic groundsBusiness OwnerCIO, CFO and Business Accountable ExecutivePMO LeadDiscontinuation decision with the disposition of data and modelsDecide a capability ends for reasons other than risk, with data and models dispositioned.

Three allocations carry the weight of this layer.

Triggers. Two decisions in this layer previously stated a cycle and no event.

L6-04, set the model sourcing posture and concentration limit. Fires when the Layer 4 aggregate exposure assessment reports concentration above the stated limit. On admission of a model from a provider not currently in the estate.

L6-05, accept the aggregate work reallocation position. Fires when cumulative reallocation crosses the workforce reallocation materiality threshold published at Layer 4 §5A. That threshold previously existed with nothing firing against it.

L6-04 and the Layer 4 aggregate exposure acceptance form a control loop, and it is intentional. The assessment triggers posture revision; the posture sets the limit that triggers the assessment.

The decision not to use AI is a recorded decision. Under the proportionality rule it is documented at a level matching its materiality, and for most capabilities that is a short entry. It is recorded because an organization that never documents restraint cannot distinguish between a capability it examined and rejected and one it never considered. The first is judgment. The second is a gap. From the outside they look identical, and after eighteen months they look identical from the inside too.

Aggregate reallocation can remove the competence oversight depends on. A function that no longer performs a task cannot competently review a system doing it, and EU AI Act Article 26(2) requires that competence in anyone assigned human oversight. Layer 5 sets AI literacy requirements per role and nothing else connects the two, so an organization can satisfy the literacy requirement with training while quietly removing the experience that made the training meaningful. Acceptance of a position under this decision re-triggers L5-10.

Maturity targets are set here, per layer. This is the decision that turns AI9GM from a description into something an organization can be measured against. It also constrains ambition honestly: a strategy requiring level 4 Control cannot be approved by an organization sitting at level 1 without the row below.

Proceeding past a maturity gap is permitted and must be named. Organizations will pursue AI capabilities their governance cannot yet support, and a framework that forbids it will be ignored rather than followed. The requirement is that the gap is stated in the approval and carries a remediation plan bound to the same decision. The failure this prevents is not ambition. It is ambition that nobody wrote down as a risk.

Artifacts

NameOwnerReview cycleScopeRequired from
L6-ART-01 Enterprise AI strategy with measurable outcomes and intervalsCIOAnnuallyorganizationLevel 3
L6-ART-02 Target maturity per layer, with current state and gapCIOAnnually, assessed semi-annuallyorganizationLevel 3
L6-ART-03 Capability decision register, including decisions not to use AIBusiness OwnerOn decisionorganizationLevel 3
L6-ART-04 Model sourcing posture with concentration limitCIOAnnually, or on aggregate exposure findingorganizationLevel 4
L6-ART-05 Aggregate work reallocation positionHead of TalentPer assessment cycleorganizationLevel 4
L6-ART-06 Sustainability targets and measurement method for AI workloadsCIOAnnuallyorganizationLevel 4
L6-ART-07 Strategic outcome assessments against stated measuresCIOPer stated intervalorganizationLevel 4
L6-ART-08 Emerging technology evaluation charters with kill criteria and decision datesCAIOPer evaluationsystemper evaluation
L6-ART-09 Maturity gap approvals with bound remediation plansCIOOn approval, tracked to closuresystemper approval

Scoping. Organization-level artifacts are required from the stated maturity level. System-level artifacts are required per AI system, model, interface or event according to the condition stated. Artifacts in bold are part of the Level 2 minimum. See the minimum viable set document for what this amounts to at small scale.

The capability decision register is the artifact nobody has. Organizations keep records of what they decided to build. Almost none keep records of what they decided not to build, which means the reasoning is lost, the same proposal returns every eighteen months, and the organization relearns the same conclusion at full cost.

Metrics

NameUnitGuidance
Layers at or above their target maturityCount against sixThe framework's own measure. A profile, never a composite score.
Funded AI initiatives traceable to a stated strategic outcomePercentageBelow 100 means Layer 5 is setting strategy through funding
Capability decisions with a documented outcome, including decisions not to use AIPercentageMeasures whether restraint is visible
Emerging technology evaluations closed against their stated kill criteriaPercentageEvaluations that never close are pilots with a different name
Strategic outcomes with a measured result at the stated intervalPercentageMeasures whether the strategy is assessed or asserted

Revenue, market position and competitive measures are excluded. All are outcomes the strategy pursues rather than measures of whether this layer is governed.

Crosswalk

This table maps the layer to the instruments in AI9GM v0.9 section 5. Coverage is not a claim of compliance with any instrument named here (AI9GM-v0_9.md section 0.2).

F
Full
P
Partial
C
Companion
None
InstrumentCoverageReference
ISO/IEC 38500FEvaluate, Direct, Monitor. Responsibility, strategy, acquisition, performance, conformance principles.
COBIT 2019FEDM01 governance framework setting, EDM02 benefits delivery, EDM03 risk optimization, APO02 managed strategy, APO04 managed innovation
TOGAF 10PADM Phase A Architecture Vision, Business Architecture, Architecture Vision stakeholder management
ISO/IEC 42001PClause 4 context of the organization, clause 5 leadership and AI policy, clause 6.2 AI objectives and planning
ITIL 4PStrategy management, portfolio management, continual improvement
NIST AI RMFPGOVERN 1, policies and processes aligned to organizational strategy and risk tolerance
ISO/IEC 27001:2022PClause 4 context, clause 6.2 objectives
Greenhouse Gas Protocol, CSRDPScope 2 and 3 accounting applicable to AI workload energy. Covers focus area 5 only.
PMI portfolio and program standardsPPortfolio strategic alignment
EU AI ActThe regulation governs systems and their providers and deployers. It does not govern whether an organization should pursue an AI capability.
STRATA ProtocolSTRATA governs delivery. It has no strategic layer and does not claim one.

Two gaps this crosswalk exposes. No instrument requires an organization to record a decision not to use AI. Every framework listed governs the AI an organization has. None creates a record of the AI it considered and declined, which means restraint leaves no evidence and cannot be distinguished from inattention.

No instrument makes governance capability a precondition of strategic ambition. Each specifies what good governance looks like. None requires an organization to state what governance capability its strategy needs, or to name the gap when it proceeds without it. The maturity target and the gap approval at section 5 are AI9GM’s, and together they are the mechanism that connects the strategic layer to the five beneath it rather than leaving it as an aspiration on top.

Maturity descriptors

Maturity is scored per layer. Composite organizational scores are not produced under this specification.

LevelDescriptor
1 · InitialAI activity happens where budget and enthusiasm coincided. No stated AI strategy, or one that names technologies rather than outcomes. Decisions not to use AI are not decisions, because nobody was asked. Governance capability is not considered when commitments are made.
2 · ManagedAn AI strategy document exists and is broadly accurate. It was largely assembled from initiatives already underway. Outcomes are stated in general terms without measures or intervals. Emerging technology evaluations run without kill criteria. Sourcing happens by procurement convenience rather than by posture.
3 · DefinedThe strategy states outcomes with measures and intervals, and funding at Layer 5 requires traceability to one of them. A target maturity level is set per AI9GM layer. Capability decisions are recorded, including decisions not to proceed, documented proportionately to materiality. A model sourcing posture with a concentration limit is published. Evaluations carry kill criteria and decision dates. Where a strategic initiative outruns governance capability, the gap is named in the approval and a remediation plan is bound to it.
4 · Quantitatively ManagedStrategic outcomes are measured at the stated intervals and the results inform the next cycle. Maturity is assessed per layer against target and the trajectory is tracked rather than the position. Aggregate exposure and aggregate reallocation are reviewed as strategic positions rather than as risk reports. Benefit realization from Layer 5 is used as evidence in funding decisions.
5 · OptimizingStrategy is revised from measured outcomes on a defined cycle rather than annually by convention. Maturity targets are adjusted from what the estate actually requires rather than from ambition. Sourcing posture responds to measured concentration before it becomes exposure. The capability decision register is consulted before new proposals, so the organization stops relearning conclusions it already reached.

The distance between levels 2 and 3 is the largest in the framework, and it is almost entirely about sequence. At level 2 the strategy describes what was funded. At level 3 the funding requires a strategy to point at. No new capability is needed. The order of two existing activities has to be reversed, and that is harder than it sounds because it means the Portfolio Board has to decline a good proposal that serves no stated outcome.

Anti-patterns

  • Retroactive strategy

    The AI strategy document is accurate, coherent and describes the sum of what was already funded. It directed nothing. Layer 5 is setting strategy through funding decisions and Layer 6 is documenting the result.

    DetectionDetected by comparing the approval date of the strategy against the start dates of the initiatives it describes.

  • The unrecorded no

    Every capability the organization decided against left no trace. The same proposal returns every eighteen months and is evaluated from scratch at full cost. From outside, an organization that examined and declined AI for a process is indistinguishable from one that never considered it.

    DetectionDetected by asking for three capabilities the organization decided not to pursue in the last two years, and why.

  • Ambition without maturity

    The strategy commits to autonomous operations, agentic workflows or AI-native processes. Layer 4 has no AI system register and no published thresholds. The commitment was made without anyone stating what governance capability it required.

    DetectionDetected by reading the strategy's commitments against the current maturity profile, layer by layer.

  • Evaluations that never close

    The innovation function runs a portfolio of emerging technology evaluations. None has kill criteria and none has concluded. Evaluation has become a permanent state and the organization has pilots under a different name.

    DetectionDetected by listing open evaluations with their start dates and asking which have a decision date.

  • Concentration by default

    No sourcing posture exists, so every team selects the provider that was easiest at the time, and they converge on the same one. The organization holds a strategic dependency it never chose and cannot easily reverse.

    DetectionDetected by the provider concentration figure in the Layer 4 aggregate exposure assessment, compared against any document stating an intended position.

  • Sustainability asserted

    Energy and carbon targets are published for AI workloads. Nothing measures energy per training run or per inference, and Layer 1 was never asked to. The target is a statement rather than a position.

    DetectionDetected by asking for the measured figure the target is tracked against.

Correction

Correct 6

The maintainer answers corrections. There is no service level. Responses are best-effort and opportunistic within a reasonable time: a correction raised on a Monday is answered that week or sooner.

Attribution