Who promised, and who can stop it?
Governance is how an organisation keeps hold of the promises it makes to people. We can help you build a playbook to commit to those promises.
Putting people at the centre of governance.
Most governance is organised around the organisation’s risk of being blamed. This is organised around the people the organisation affects — which is what governance was always for. Every one of the eleven promises below is made to a person: a member of staff, someone in your data, someone your service reached, someone it did not.
AI does not change who governance is for. It changes who is making the decision, and how many people it reaches before anyone notices.
- FoundationsDoes it work here, stay up, and stay safe?Promised to staff · the person served · everyone
- PeopleHow does it treat the people it touches?Promised to the person in the data · the affected person · staff · the community
- TransformationDid it land, and did it deliver?Promised to staff · those we serve
- ControlCan we explain it, and can we stop it?Promised to the wronged · everyone
Control is last because it is what the others rest on. If something starts to go wrong for somebody, what helps them is not that you meant well — it is that someone can explain what happened, and someone can stop it. So we ask for a way to stop, and for the name of the person who can do it.
Every part of governance is a promise, made to a particular person.
These are hats, not jobs. In a small organisation one person may wear all eleven — that is fine, and worth knowing. What matters is that each promise has a name against it, and that the name is someone real.
Possible MVG time commitment.
Eleven promises across six phases, with projected time commitments. Governance does not come free, but you decide the cost.
| Promise | Intent | Design | Assure | Operate | Review | Retire | One full cycle |
|---|---|---|---|---|---|---|---|
| FoundationsDoes it work here, stay up, and stay safe? | |||||||
| F1Technical assurance | 20mTechnical assurance · IntentGive a quick read on whether it is plausible with what you already run. Flag if it needs a platform you do not have or a skill nobody holds. Name anything already in the estate that would do the job.20m · Per idea — often a five-minute conversation · Not asked at this moment | 1h45Technical assurance · DesignConfirm it works alongside the systems it touches, and name the integration points. Check the way it will be used does not expose an individual, and its terms do not expose the organisation. Confirm what people fall back to when it is down. Establish who supports it when it breaks.1h45 · Per adoption · Always asked | 2hTechnical assurance · AssureTest it against your actual setup, not the supplier's demonstration. Validate it can be supported. Use the support route once to confirm it exists. Say no, in writing, if it does not fit.2h · Per adoption · Always asked | 30mTechnical assurance · OperateWatch for it drifting out of step as other things get upgraded. Pick up the failures staff work around rather than report.30m · Monthly · Asked when the decision is big enough | 20mTechnical assurance · ReviewLook at whether the world around it has moved — new devices, a changed system it talks to, a supplier update — and whether any of that has made the tool harder to use than it was.20m · Average, Quarterly · Not asked at this moment | 2hTechnical assurance · RetireWork out what breaks, and what has to move first. Confirm information can be got out in usable form *before* access ends.2h · Per retirement · Asked when the decision is big enough | 6h55 |
| F2Locality & resilience | 20mLocality & resilience · IntentFlag if it implies information leaving the country, or sitting somewhere nobody can name.20m · Per idea, rarely · Not asked at this moment | 2hLocality & resilience · DesignEstablish where information will sit and whether that is acceptable. Ask what the recovery position is when the supplier has an outage — not if.2h · Per adoption · Not asked at this moment | 2hLocality & resilience · AssureGet it in writing from the supplier: where the information sits, what happens if they stop trading, whether you could get it out. Confirm the availability matches what people actually need.2h · Per adoption · Always asked | 20mLocality & resilience · OperateNotice when it is unavailable at the moment people need it, and record it rather than absorbing it.20m · Average, Monthly · Asked when the decision is big enough | 20mLocality & resilience · ReviewCheck it has not quietly gone out of date, moved, or changed hosting. Check the supplier still trades and still supports your version.20m · Average, Quarterly · Asked when the decision is big enough | Not asked at this moment. No time attached. | 5h |
| F3Security assurance | 20mSecurity assurance · IntentFlag if it puts sensitive information somewhere new, or widens who can reach it.20m · Per idea, rarely · Not asked at this moment | 1h30Security assurance · DesignDecide who should have access and on what basis, how access is removed and whose job that is, and how you would find out you had been breached.1h30 · Per adoption · Asked when the decision is big enough | 2hSecurity assurance · AssureConfirm access is limited to current people with no shared logins, multi-factor is on where available, and the supplier would tell you if they were breached — and how fast.2h · Per adoption · Always asked | 40mSecurity assurance · OperateRemove access when someone leaves, on the day they leave. Keep the access list current and actually check it. Act on supplier security notices rather than filing them.40m · Average, Monthly · Always asked | 20mSecurity assurance · ReviewCheck who has access now against who should. Check whether anything happened that nobody escalated.20m · Average, Quarterly · Asked when the decision is big enough | 40mSecurity assurance · RetireConfirm all access is revoked, including integration keys and service accounts with no person attached.40m · Per retirement · Not asked at this moment | 5h30 |
| PeopleHow does it treat the people it touches? | |||||||
| P1Information governance | 20mInformation governance · IntentAsk whether this needs personal information at all, before anyone designs around having it. Say early if it involves health, beliefs, or anything else that changes what is required. DPIA20m · Per idea · Asked when the decision is big enough | 2hInformation governance · DesignWrite down what it touches, why each item is needed, how long it is kept. Decide what is deliberately not collected — the cheapest way to protect information is not to hold it. Establish and record the lawful basis. Check where it goes, including anyone the supplier passes it to.2h · Per adoption · Always asked | 1hInformation governance · AssureConfirm someone here could answer a person asking what you hold about them. Confirm deletion works, by deleting something and checking it is gone.1h · Per adoption · Always asked | 40mInformation governance · OperateHandle requests from people asking what you hold. Notice scope creep — the tool used for information it was never approved for.40m · Average, Monthly · Not asked at this moment | 20mInformation governance · ReviewCheck what it is holding now against what you said it would hold.20m · Average, Quarterly · Asked when the decision is big enough | 1hInformation governance · RetireConfirm information is deleted or returned, and record that it was.1h · Per retirement · Not asked at this moment | 5h20 |
| P2Ethics & fairness | 20mEthics & fairness · IntentAsk who could be treated worse by this. Name the groups most likely to be affected and least likely to complain. Decide whether the answer could actually change the decision — if it could not, this is theatre and you should say so.20m · Per idea · Always asked | 1hEthics & fairness · DesignWhen the tool is not sure about something, what does it do — guess, refuse, or hand it to a person? Then ask who it is most often unsure about. A tool that hesitates over unusual names and breezes through common ones is not treating everyone the same, and the people it slows down are usually the ones already waiting longest.1h · Per adoption · Not asked at this moment | 30mEthics & fairness · AssureConfirm someone has looked for unfair outcomes and would stop it. Agree in advance what would count as unfair here, so it can be recognised later rather than argued about.30m · Per adoption · Asked when the decision is big enough | 1hEthics & fairness · OperateTreat complaints as evidence rather than as noise.1h · Average, Monthly · Not asked at this moment | 20mEthics & fairness · ReviewCheck whether one group is quietly getting worse outcomes. Look at who stopped using the service, not only who used it.20m · Average, Quarterly · Asked when the decision is big enough | Not asked at this moment. No time attached. | 3h10 |
| P3Human impact | 20mHuman impact · IntentAsk what this does to someone's job before it arrives. Name what any freed-up time is actually for — if nobody can say, it is a cut and should be called one. Say who is affected and whether they know yet. Also: *(folded into the row above — same conversation)* Check the definition of good is not 'fewer people doing it' wearing a different word.20m · Per idea · Always asked | 2hHuman impact · DesignShape it so the work left over is still worth doing, not merely faster. Check it does not concentrate the dull half of a job onto one person.2h · Per adoption · Asked when the decision is big enough | 2h40Human impact · AssureConfirm affected staff have seen it before the day it arrives.2h40 · Per adoption · Not asked at this moment | 40mHuman impact · OperateNotice when work has turned into machine-minding, and say so. Ask the people doing the work whether it got better or just quicker — those are different answers.40m · Average, Monthly · Asked when the decision is big enough | 20mHuman impact · ReviewReport whether the change to the job predicted at the start is what actually happened.20m · Average, Quarterly · Not asked at this moment | Not asked at this moment. No time attached. | 6h |
| P4Engagement | 20mEngagement · IntentAsk the people it affects before the decision. Include the people who never chose to be affected, not only the ones easy to reach. Record what they said, including what you decided against and why.20m · Per idea · Always asked | 20mEngagement · DesignFeed what was heard into how it is built — or say plainly that it could not be.20m · Per adoption · Not asked at this moment | 2hEngagement · AssureConfirm the people who were asked have been told what happened.2h · Per adoption · Not asked at this moment | 40mEngagement · OperateKeep the route open for someone to raise a concern, and make sure it reaches a person.40m · Average, Monthly · Not asked at this moment | 20mEngagement · ReviewTell them what you decided and why, with a route to disagree. Check whether the affected people agree it worked — their answer counts more than yours.20m · Average, Quarterly · Asked when the decision is big enough | 20mEngagement · RetireTell the people who were asked that it has stopped, and why.20m · Per retirement · Not asked at this moment | 4h |
| TransformationDid it land, and did it deliver? | |||||||
| T1Capability & training | 20mCapability & training · IntentFlag if this needs a skill nobody here currently holds.20m · Per idea · Not asked at this moment | 1hCapability & training · DesignWork out what people need to know to use it *and* to push back on it. Decide who teaches it and when — before go-live, not after the complaints.1h · Per adoption · Asked when the decision is big enough | 2hCapability & training · AssureConfirm people can use it by watching someone do it, not by asking them whether they can. Confirm they know they may disagree with its output, and how.2h · Per adoption · Always asked | 1hCapability & training · OperateWatch for over-trust — people accepting output they ought to be questioning. Support the people who arrived after the training happened; there are always some.1h · Average, Monthly · Asked when the decision is big enough | 20mCapability & training · ReviewReport where people are working around it rather than with it. That is either a training signal or a design signal, and it matters which.20m · Average, Quarterly · Not asked at this moment | Not asked at this moment. No time attached. | 4h40 |
| T2Benefit accountability | 20mBenefit accountability · IntentWrite down what good will look like. Name who gets any time it saves; if the answer is nobody, say that. Agree how you would know it had not worked — this is the part that gets skipped.20m · Per adoption · Always asked | Not asked at this moment. No time attached. | 1hBenefit accountability · AssureConfirm the measure you agreed is actually being captured, before go-live makes it too late to start.1h · Per adoption · Not asked at this moment | 1hBenefit accountability · OperateCollect the evidence as you go, rather than reconstructing it from memory later.1h · Average, Monthly · Not asked at this moment | 20mBenefit accountability · ReviewSay out loud whether the good arrived, especially when it did not. Compare against what was written at the start, not a revised memory of it. Decide on that evidence whether to continue, change, or stop.20m · Average, Quarterly · Always asked | 20mBenefit accountability · RetireRecord what was actually achieved, so the next proposal is judged on evidence rather than optimism.20m · Per retirement · Not asked at this moment | 3h |
| ControlCan we explain it, and can we stop it? | |||||||
| C1Auditability | 20mAuditability · IntentThe record starts here: what was expected, who it affects, what would make us stop.20m · Per adoption · Not asked at this moment | 6hAuditability · DesignDecide what gets recorded so one person's case can be reconstructed. Decide how long records are kept, and where.6h · Per adoption · Asked when the decision is big enough | 6hAuditability · AssureConfirm there is a record of what was decided and by whom. Test the reconstruction once — pick a case and try to explain it end to end. If you cannot, the recording is not enough.6h · Per adoption · Always asked | 1hAuditability · OperateRecord where AI was used to produce something that affected someone. Keep the decision record current when things change.1h · Average, Monthly · Asked when the decision is big enough | 20mAuditability · ReviewCheck the records would satisfy someone asking what happened to *them* — not just satisfy you.20m · Average, Quarterly · Not asked at this moment | 20mAuditability · RetireKeep the records for as long as the decisions still matter to someone.20m · Per retirement · Not asked at this moment | 14h |
| C2Revocation | 20mRevocation · IntentNote what would make you stop. This is the first draft of the trigger list.20m · Per adoption · Not asked at this moment | 2hRevocation · DesignMake sure stopping is technically possible without breaking everything around it. A stop that cannot be used is not a stop.2h · Per adoption · Not asked at this moment | 30mRevocation · AssureBe named, and confirm you can stop it without asking permission. Confirm you know you hold it — an unwitting owner is not an owner. Agree what restoring it takes: more than you alone.30m · Per adoption · Always asked | 30mRevocation · OperateCheck you have not lost access to stop it. Also: Stop it. That is the promise.30m · Average, Monthly · Always asked | 20mRevocation · ReviewCheck whether anything happened that should have triggered a stop and did not. The most useful question in the whole review.20m · Average, Monthly · Not asked at this moment | 40mRevocation · RetireStop it properly: access off, information dealt with, people told. Confirm nothing is quietly still running — an integration, a scheduled job, a copy somewhere.40m · Average, Quarterly · Always asked | 4h20 |
Each figure is what one person spends, once, each time that moment comes round. Hover or tab onto a cell to see what the time is spent on. The last column adds a row up: one pass through the whole life of one decision, for one promise. It does not multiply by how often each moment recurs, so the yearly figure is higher.
Two thirds of it lands before anyone depends on it. Design and Assure together are 41h15 of the 61h55 — the work of fitting the thing and checking it holds. That is also the part that gets cut first when a date slips.
Deciding whether to do it at all costs 3h40. Twenty minutes per promise, across all eleven. The cheapest column on this grid is the one that governs every other column — and it is the one most organisations skip.
One promise is almost a quarter of the total. Being able to explain what happened to somebody costs 14h on its own, because it has to be built in rather than added afterwards. If you want one number to argue about, argue about that one.
You decide the cost. How much of this fires depends on how far a decision reaches, not on how serious you are. A short version that names who holds what, and can be stopped, is real governance. Doing less of this is not failing at it.
A gap is a risk.
You are allowed to say “We won’t do this”. Each decision leaves a fingerprint in your playbook.
| Promise unheld | Who gets hurt, and how | What the organisation carries |
|---|---|---|
| FoundationsDoes it work here, stay up, and stay safe? | ||
| F1Technical assurance | It will not run on the devices people have, or beside the tools they already use, so they work around it — and the people you serve get handled inconsistently. | Failed integration cost, and a shadow process nobody can see, support or hand over. |
| F2Locality & resilience | It vanishes at the moment somebody needs it, and nobody can say why, or how to get it back. | No recovery route, contract exposure, and information sitting somewhere you never disclosed. |
| F3Security assurance | Somebody is harmed through your system — by an attacker who got in, or by a colleague using it in a way nobody anticipated. | Compromise, extortion, and disclosure of the people you serve. |
| PeopleHow does it treat the people it touches? | ||
| P1Information governance | Personal information is used in ways the person never agreed to, and cannot find out about. | Regulatory exposure, breach notification, loss of trust. |
| P2Ethics & fairness | One group quietly receives worse outcomes, and nobody is looking. | Discriminatory practice, reputational and legal exposure. |
| P3Human impact | Staff are deskilled or displaced without being consulted; the work becomes machine-minding. | People leave, and the knowledge leaves with them. |
| P4Engagement | Decisions are made about people without them, and they find out afterwards. | Rejection at rollout, money wasted late. |
| TransformationDid it land, and did it deliver? | ||
| T1Capability & training | The organisation splits into people who use it and people who do not, with no agreed way of working between them — and nobody able to challenge what it produces. | Two ways of doing one job, over-trust in the output, and errors that accumulate unseen. |
| T2Benefit accountability | The improvement promised never arrives, and nobody says so. | Continued spend on something not working; the next case is disbelieved. |
| ControlCan we explain it, and can we stop it? | ||
| C1Auditability | Something goes wrong and nobody can tell the person what happened, or why. | Cannot investigate, cannot defend, cannot learn. |
| C2Revocation | Harm carries on after it is known, because stopping has no owner. | Prolonged exposure — the multiplier on every other risk. |
Every risk here is bounded by how quickly it can be stopped. Leave stopping unheld and every line above it gets worse. If your organisation can hold exactly one promise, hold that one.
Creating your playbook.
Your playbook is put together by procedural code, not by a model. It follows fixed rules, which means the same answers produce the same document every time — and we can tell you exactly why any line of it says what it says.
A future version may be able to run the review step in your browser as well. Until it can, nothing you type here leaves this page: the only thing that travels is the file you choose to download to your own machine.
Your answers become the structure
Which promises apply, who holds them, how often they come round, when each approval runs out, and what the operating cost in time works out at. All of it worked out by rules, from what you typed.
Then you write it in your words
The part no rule can judge, and no model can know: the actual person each promise is made to, the specific harm it prevents, and why you govern at all — in the language your organisation really uses about the people it serves. You write this, because you are the only one who can.
Then a model checks your work
Validate, tidy, consolidate. Where does it contradict itself, promise more than it delivers, or say the same thing twice? We hand you a prompt built from your own answers — you take it to whichever AI you already trust, and it reviews what you wrote rather than writing it for you.
Stages one and two are live today and run entirely in your browser: the rules build the structure, and you fill in the parts only you can write. Stage three is yours to run — the builder hands you a review prompt made from your own answers, and you take it to whichever AI you already use. Nothing is sent anywhere on your behalf.
Time spent now is transparency later.
Eleven screens of plain questions. Invest the time in capturing what you already do, and you end up with a written playbook — names against promises, dates against approvals, and an honest account of what you are not covering — ready for the questions that arrive later, from a funder, a trustee, or the person a decision affected.