01 / Start here

What a gate pack·actually is.

If the phrase means nothing to you, this page will make more sense in ninety seconds.

A stage gate is a scheduled decision point. Before a project can spend the next tranche of budget, it comes to a meeting and shows evidence that it is safe to continue. Most organisations run four to six of them across a project's life, under PRINCE2, MSP, a PMI-aligned lifecycle or a local variant of one of those.

A gate pack is the set of documents a project brings to that meeting. Your organisation almost certainly has one already. It asks for a business case, a design, a test report, a go-live checklist. It works, because ordinary projects produce deliverables that either meet a specification or do not.

An AI initiative does not produce that. It produces a system that is right most of the time. The gate pack you already own has no question that catches the difference, so the meeting looks at a working demonstration and approves it. Which is not the same as the system being ready.

This is the gate pack for that. Six gates, thirteen documents, and one rule that does most of the work: the threshold a system has to clear is agreed and signed before anyone sees the result.

Three words used throughout
Gate
A decision point. Someone named decides whether this continues, on evidence, and signs.
Artefact
One document brought to a gate. Thirteen of them across the six gates, each with a sign-off block.
Lane
How much governance this particular initiative earns. An internal tool gets three gates. A system deciding someone's insurance claim gets all six.
In practice

How an initiative moves through it.

01

Triage it once

Fifteen questions at the start decide the lane. Light, Standard or Full. This takes minutes and is free.

02

Fill the artefacts as you go

Each gate asks for two or three documents. They are short, and each one exists to prevent a specific failure, not to satisfy a policy.

03

Sign at the gate

A named person decides. An unsigned artefact does not clear its gate, and an authorisation carries an expiry date.

04

The evidence assembles itself

What you filled in becomes the technical file a regulator, auditor, underwriter or acquirer asks for. You do not write it twice.

This is for you if
  • You run a PMO, a change function or a transformation office with formal stage gates
  • You have somewhere between two and thirty AI initiatives in flight and no consistent way to govern them
  • Someone senior has been made accountable for AI outcomes without being given a rulebook
  • Your pilots are not failing so much as never quite finishing
  • An auditor, a regulator or an acquirer will eventually ask how a decision was made
This is not for you if
  • You are building an AI product and speed is the only thing that matters right now
  • You already run an AI governance platform and it covers your delivery process as well as your models
  • You want a compliance certificate. This produces evidence, not certification
  • You want legal advice. This is documentation and tooling, and says so in the licence
02 / Productised delivery governance

The AI Delivery·Gate Pack.

The documents an AI initiative brings to each stage gate, and the evidence each one leaves behind.

Six gates, thirteen evidence artefacts and three proportionate lanes for running AI initiatives through the governance your organisation already has. Not a method. An overlay on PRINCE2, MSP or a PMI-aligned lifecycle, which produces your regulatory evidence as a by-product of running delivery rather than as a reconstruction eighteen months later.

Why AI initiatives stall in pilot
Stage gates accept specifications.
AI produces distributions.
A gate review looks at a working demonstration, has no agreed threshold to test it against, and accepts that the demonstration worked. Which is not the same as the system being ready. Months later nobody can prove the benefit arrived, because no baseline was taken before the build. Neither is a technology failure. Both are fixed by two pages of paper, signed on the right date, by the right person.
88–95%of enterprise AI pilots never reach production
61%approved on projected ROI never measured after launch
2.3AI initiatives abandoned per large enterprise in 2025
6gates, thirteen artefacts, three lanes
G0 to G5 · the overlay

Six gates, attached to the governance you already run.

Each gate maps to a decision point your process already has. Where your organisation already holds a gate at that point, add the artefacts to it rather than adding a gate. Six new gates in a process that already has five will be routed around within a quarter.

G0

Intake and Triage

Is this worth governing, and at what weight?

G1

Case and Consent

Is the case sound and the data lawful to use?

G2

Design and Data Readiness

Is it specified well enough to build?

G3

Evaluation and Acceptance

Did it meet the threshold, or did the demonstration work?

G4

Deployment Authorisation

Who is authorising this into production, and on what?

G5

Benefit and Post-Market Review

Did the benefit arrive, and is it still behaving?

Free instrument · 15 questions

Which lane is your initiative in?

Governance is proportionate or it is routed around. The triage instrument asks fifteen questions about a single AI initiative and returns its lane, the gates that apply, the evidence artefacts each gate needs, and the regulatory flags it raises. Nothing leaves your browser.

  • Light3 gates · 5 artefactsInternal tool, output reviewed by a person, reversible errors. Should not be slowed down.
  • Standard5 gates · 9 artefactsCustomer-adjacent, personal data in play, human in the loop. Needs a signature before production.
  • Full6 gates · 13 artefactsRegulated domain, agentic scope, or harm to an individual on the downside. Independent evaluation.
Run the triage →
No sign-up · nothing transmitted · indicative, not legal advice
The thirteen artefacts
  1. A1AI Use Case Intake RecordG0
  2. A2Risk Classification and Lane DeterminationG0
  3. A3AI Business Case AddendumG1
  4. A4Data Provenance and Lawful Basis StatementG1
  5. A5System Specification and Design RecordG2
  6. A6Evaluation Protocol and Acceptance ThresholdsG3
  7. A7Evaluation Results and Gate EvidenceG3
  8. A8Human Oversight and Escalation DesignG2
  9. A9Deployment Authorisation RecordG4
  10. A10Logging and Monitoring PlanG4
  11. A11Incident and Rollback ProcedureG4
  12. A12Benefit Realisation ConfirmationG5
  13. A13Post-Market Review and Drift StatementG5
Evidence, not paperwork

Every artefact ships twice: for people, and for systems.

A completed initiative validates rather than being read, and assembles into an evidence bundle cross referenced to EU AI Act Annex IV headings and ISO/IEC 42001 clauses. The assembler catches six things a document review cannot.

i
A threshold agreed after the result that tests it. The evaluation protocol is dated and signed before the results exist, or the gate is theatre.
ii
An outcome recorded as met while a threshold was not. The demonstration-worked failure, caught mechanically.
iii
A benefit measured against a baseline that moved. The baseline is fixed at G1 and carried forward unaltered.
iv
A rollback that was designed but never exercised. An untested rollback is a hope, and the date is a field.
v
An authorisation that has quietly expired. Authorisations carry an end date, because a permanent one is an unreviewed one.
vi
A material model absent from the inventory. Flagged wherever SS1/23 or an equivalent model-risk regime applies.
In the download

A worked case, filled end to end.

The specimen is a general insurer's claims triage assistant, taken through all six gates on the Full lane. It shows a threshold set before evaluation, a subgroup threshold catching what the aggregate hid, an honest attribution note at the benefit review, and a benefit only partially realised with the initiative continued rather than declared a success.

01

The pack

Twenty-eight pages. Gate definitions with entry and exit criteria, thirteen artefact specifications, sign-off blocks, the regulatory crosswalk, and a mapping to PRINCE2, MSP and PMI.

02

The schema

Every artefact in machine readable form, with lane-conditional requirements. A completed initiative validates rather than being read.

03

The assembler

Turns a completed initiative into an evidence bundle, cross referenced to Annex IV headings and ISO/IEC 42001 clauses, and refuses the bundles that would not survive a review.

04

The worked case

All thirteen artefacts filled, plus the bundle the assembler produces from them. Break a field deliberately and watch which check catches it.

03 / Licence

One purchase, used on every initiative·in scope.

Licensed per team, not per reader. Twelve months of updates included, which matters because the EU AI Act timeline will move again before 2028. Adapt it internally as you like: rename the gates, move the lane thresholds, extend the crosswalk to your own control framework. Everything you produce with it is yours outright.

Single programme
£1,950

One programme, one delivery team. Card payment; the pack is sent to your inbox within two working days.

  • All six gates and thirteen artefacts
  • Editable documents plus PDF
  • Machine readable schema and assembler
  • Worked case, fully filled
  • Twelve months of updates
Buy the pack
Organisation
£4,950

Unlimited internal programmes across one legal entity. Invoiced on thirty-day terms.

  • Everything in Single programme
  • Unlimited internal use
  • Your gate names and lane thresholds substituted
  • Crosswalk extended to your own control framework
  • Twelve months of updates
Enterprise
£14,950

Organisation licence plus tailoring. Invoiced on thirty-day terms.

  • Everything in Organisation
  • Half-day tailoring workshop with your PMO
  • Pack aligned to your existing stage gates
  • One initiative walked through end to end
  • Twenty-four months of updates
Independent review · from £8,500

Have someone independent walk a gate.

The pack makes the review credible. The review is what your board actually wants. An independent gate review reads one live initiative against the pack, reports what would and would not survive scrutiny, and produces a finding list your internal audit function will recognise.

Single programme: card payment through Lemon Squeezy as merchant of record, applicable VAT or sales tax calculated at checkout · Organisation and Enterprise invoiced against a purchase order on thirty-day terms, VAT as stated on invoice · Delivered within two working days of signature
04 / Before you ask

The four questions we get·every time.

Is this just templates?

No, and the difference is testable. A template pack gives you documents. This gives you documents plus a schema and an assembler that refuses a bundle where the thresholds were agreed after the evaluation, or the benefit was measured against a baseline that moved. Break a field in the worked case deliberately and watch which check catches it. That demonstration takes thirty seconds and settles the question.

We already have an AI governance platform. Does this overlap?

Very little. Those platforms sell to the CISO, the Chief AI Officer, Legal and Compliance, and they govern the model. This is built for the PMO and the delivery function, and it governs the delivery. If you have a platform, this is what feeds it. If you do not, this is what a change budget can actually buy.

The EU AI Act high-risk deadline moved. Why now?

The Digital Omnibus deferred the standalone Annex III obligations to 2 December 2027 and product-embedded ones to 2 August 2028. It did not defer the Article 50 transparency obligations or the Article 4 AI literacy duty, which applied from 2 August 2026. Part of it is already live, and the deferral on the rest is preparation time rather than relief. Initiatives entering delivery now will still be running in December 2027.

We are not in financial services.

The pack is framework-neutral. The worked case is an insurer because that is where the governance vocabulary is sharpest, but the gates map to PRINCE2, MSP and PMI lifecycles rather than to any sector rulebook. The model risk references are marked optional throughout.

The evidence discipline behind the pack is the book — By Evidence  ·  The wider practice is AI Governance