Commercial entry · Sprint dossier · 4 weeks
Start with one high-risk AI system. Leave with one defensible evidence baseline.
The sprint maps evidence gaps, owners, source systems, custody, and export paths on a single in-scope system — the practical first run of Guardian before scaling across a portfolio. Fixed scope, fixed timeline, named artefacts each week.
Buyable as a single procurement unit — four weeks, one system, named artefacts each week.
Sprint worksheet
Illustrative worksheet from a typical engagement — each row becomes a line item in the baseline dossier.
| Evidence gap | Owner | Source system | Next action | Status |
|---|---|---|---|---|
| Threshold ownership undefined | Risk & compliance | Internal monitoring | Assign reviewer and escalation path | Open |
| Incident evidence fragmented | ML platform | Ticketing + observability | Connect intake webhook | Linked |
| Oversight sign-off not traceable | AI governance | Review workflow | Map custody handler | Open |
| Export path unclear | Legal | Guardian dossier | Define audit-ready packet template | Verified |
Illustrative rows · updated weekly during the sprint · owners assigned at kickoff
Six phases across four weeks — same structure every engagement, always specific to your one priority system.
| ID | Phase | Week | Focus | Deliverable | Status |
|---|---|---|---|---|---|
| SPR-01 | Scope one system | Week 1 | Lock onto one in-scope system, owners, production interfaces, and decision rights. | Scope & risk framing summary | Core |
| SPR-02 | Map obligations and evidence gaps | Week 2 | Review monitoring inputs, oversight touchpoints, and where the governance record breaks today. | Governance and control gap summary | Core |
| SPR-03 | Connect source signals | Week 2–3 | Identify source systems, channels, and the minimum integration path for evidence intake. | Source registry draft | Active |
| SPR-04 | Run review workflow | Week 3 | Define thresholds, failure modes, and who reviews what before scrutiny arrives. | Review & evidence readiness scorecard | Active |
| SPR-05 | Produce baseline evidence record | Week 4 | Executive readout, first evidence baseline, and named owners for ongoing custody. | Baseline evidence record | Verified |
| SPR-06 | Define rollout path | Week 4 | Guardian handover outline — owners, records, integrations — for the ongoing dossier. | Rollout recommendation | Verified |
6 phases · 4 weeks · one in-scope system
Named artefacts at readout — for internal use and for scoping Guardian, not a slide-only advisory exit.
| ID | Deliverable | Description |
|---|---|---|
| DEL-01 | Evidence gap map | Prioritised gaps by workstream with owners |
| DEL-02 | Source registry | Connected and planned intake channels |
| DEL-03 | Traceable evidence trail baseline | Handlers, reviewers, and sign-off paths |
| DEL-04 | Oversight review trail | Thresholds, scenarios, and review triggers |
| DEL-05 | Export-ready evidence packet | First audit-ready baseline for the in-scope system |
| DEL-06 | Rollout recommendation | 30–90 day actions and Guardian handover plan |
Common questions
Typical triggers
Outcomes after week four
Most AI governance programmes become too abstract too early — policies and committees before one live system has a credible baseline. The sprint reverses that: one real system, one real set of risks, one concrete operating record that is easier to expand later.
If this matches your situation, the sprint is the right first buy — anchored on one system you can name at kickoff.
| Team | Why they join |
|---|---|
| Risk and compliance leads | Credible AI Act starting point and regulator-facing preparation |
| AI governance teams | Policy mapping, oversight records, cross-functional accountability |
| ML platform teams | Production signals, source connectivity, incident intake |
| Product owners of in-scope systems | Named system, decision rights, rollout ownership |
Fixed length, one in-scope system, and a handover that points into Guardian on top of the monitoring you already run.