Commercial entry · Sprint dossier · 4 weeks

Readiness Sprint

Start with one high-risk AI system. Leave with one defensible evidence baseline.

The sprint maps evidence gaps, owners, source systems, custody, and export paths on a single in-scope system — the practical first run of Guardian before scaling across a portfolio. Fixed scope, fixed timeline, named artefacts each week.

Nordic AI Integrity runs the sprint; Guardian is the ongoing record after week four. IntegrationsEU AI Act

Offer at a glance

Buyable as a single procurement unit — four weeks, one system, named artefacts each week.

  • Fixed scope — one priority production system (live or imminently live)
  • Fixed timeline — 4 weeks from kickoff to executive readout
  • Fixed outputs — gap summary, first evidence baseline, review posture, Guardian handover outline
  • Focused team — a compliance or risk lead, a legal or governance stakeholder, and a model, data, or ML owner

Sprint worksheet

Evidence gap tracker

Illustrative worksheet from a typical engagement — each row becomes a line item in the baseline dossier.

Sprint worksheet · WS-001REF · GRD-SPR-WS
Evidence gapOwnerSource systemNext actionStatus
Threshold ownership undefinedRisk & complianceInternal monitoringAssign reviewer and escalation pathOpen
Incident evidence fragmentedML platformTicketing + observabilityConnect intake webhookLinked
Oversight sign-off not traceableAI governanceReview workflowMap custody handlerOpen
Export path unclearLegalGuardian dossierDefine audit-ready packet templateVerified

Illustrative rows · updated weekly during the sprint · owners assigned at kickoff

Sprint phases

Six phases across four weeks — same structure every engagement, always specific to your one priority system.

Sprint phase registerREF · GRD-SPR-PHS
IDPhaseWeekFocusDeliverableStatus
SPR-01Scope one systemWeek 1Lock onto one in-scope system, owners, production interfaces, and decision rights.Scope & risk framing summaryCore
SPR-02Map obligations and evidence gapsWeek 2Review monitoring inputs, oversight touchpoints, and where the governance record breaks today.Governance and control gap summaryCore
SPR-03Connect source signalsWeek 2–3Identify source systems, channels, and the minimum integration path for evidence intake.Source registry draftActive
SPR-04Run review workflowWeek 3Define thresholds, failure modes, and who reviews what before scrutiny arrives.Review & evidence readiness scorecardActive
SPR-05Produce baseline evidence recordWeek 4Executive readout, first evidence baseline, and named owners for ongoing custody.Baseline evidence recordVerified
SPR-06Define rollout pathWeek 4Guardian handover outline — owners, records, integrations — for the ongoing dossier.Rollout recommendationVerified

6 phases · 4 weeks · one in-scope system

Deliverables register

Named artefacts at readout — for internal use and for scoping Guardian, not a slide-only advisory exit.

IDDeliverableDescription
DEL-01Evidence gap mapPrioritised gaps by workstream with owners
DEL-02Source registryConnected and planned intake channels
DEL-03Traceable evidence trail baselineHandlers, reviewers, and sign-off paths
DEL-04Oversight review trailThresholds, scenarios, and review triggers
DEL-05Export-ready evidence packetFirst audit-ready baseline for the in-scope system
DEL-06Rollout recommendation30–90 day actions and Guardian handover plan
  • Scope and Annex III / high-risk exposure framing for the one system you picked
  • Governance and control gap summary tied to how you monitor and review today
  • Review and evidence-readiness scorecard (thresholds, scenarios, ownership)
  • Executive readout plus prioritised 30–90 day actions for internal stakeholders
  • Guardian rollout outline—owners, records, integration touchpoints—for the software handover
  • First evidence baseline your teams extend in Guardian, not a one-off slide narrative

Common questions

Sprint essentials

What is the Guardian Readiness Sprint?
A fixed 4-week engagement on one high-risk AI system — mapping evidence gaps, owners, sources, and export paths before scaling Guardian.
Who is it for?
Risk, AI governance, ML platform, and product teams with one live or near-live system that needs a defensible baseline now.
What do we leave with?
An evidence gap map, source registry, custody baseline, review trail, export-ready packet, and rollout recommendation.
Does it require replacing existing tools?
No. The sprint works above your monitoring and MLOps stack — connecting sources, not replacing them.

When it fits — and what changes after week four

Typical triggers

  • One live or near-live AI system is already under internal or regulatory scrutiny, and evidence is fragmented across tools
  • Leadership wants a concrete readiness baseline before funding broader governance work
  • You need a fixed-scope first step your organisation can approve quickly—not a transformation programme

Outcomes after week four

  • One coherent internal story for compliance, legal, and leadership on that system—not a rebuilt deck each time
  • A clear map of existing monitoring inputs versus governance and evidence gaps
  • A structured operating baseline you can extend to more systems—or use to stop work with explicit rationale
  • Faster, calmer responses when regulator or audit questions land

Why one system first

Most AI governance programmes become too abstract too early — policies and committees before one live system has a credible baseline. The sprint reverses that: one real system, one real set of risks, one concrete operating record that is easier to expand later.

What the executive readout includes

  • System summary and scope definition
  • Key governance gaps against how you monitor and review today
  • Priority evidence gaps by workstream
  • Recommended alert, incident, and review-record structure
  • Immediate next steps for the next 30 to 90 days
  • Recommendation on moving into Guardian as the ongoing governance record

Who it is for

If this matches your situation, the sprint is the right first buy — anchored on one system you can name at kickoff.

TeamWhy they join
Risk and compliance leadsCredible AI Act starting point and regulator-facing preparation
AI governance teamsPolicy mapping, oversight records, cross-functional accountability
ML platform teamsProduction signals, source connectivity, incident intake
Product owners of in-scope systemsNamed system, decision rights, rollout ownership

Frequently asked questions

Is the Readiness Sprint a conformity assessment?
No. The sprint is a time-boxed readiness and operational-baseline exercise around one in-scope system. A conformity assessment, where you need one, is a different process. The sprint is built to produce outputs you can use in product and in internal governance, not a certification packet.
Is this a consulting project or a path into software?
Nordic AI Integrity runs the sprint. Guardian is the product for an ongoing governance and evidence record above the monitoring you already use—not a stack replacement. Most teams use sprint outputs to fund and scope an initial Guardian rollout. The sprint is the practical commercial entry into that path.
Do we have to be sure the system is legally “high-risk” before we start?
No. You pick the system you are running as in-scope for the sprint. The work clarifies likely exposure, criticality, and what level of evidence and monitoring you should build, whatever label you use internally.
Why only one system?
One system is easier to approve, faster to execute, and the only way to get concrete evidence and a credible story inside your organisation. Programme-wide efforts without that first proof point usually stall.
What happens when the four weeks end?
You have a baseline, clear owners, and a readout. The usual next step is to move the operating pattern into Guardian: same owners, same governance and evidence record on top of your monitoring inputs. We align that handover in week four.
Is the sprint fixed-price?
The sprint is structured as a fixed-scope, fixed-timeline offer designed to be easy to evaluate and approve. Background: What an AI incident register should contain

Start with one system

Fixed length, one in-scope system, and a handover that points into Guardian on top of the monitoring you already run.

See the sprint worksheetDeliverables register