Each gate is a short, structured review with clear entry and exit criteria. Pass the gate for your risk class and you carry evidence into the next phase. The gates are proportionate: a Risk Class 3 product moves through a lighter version of the same path. They align to the Group Cyber Approval Process and the ASLM asset lifecycle, so a single set of evidence serves both.
Gates map to the natural decision points of an AI build, and to the five steps of the Group Cyber Approval Process. You do not stop work to pass them; you bring the work you have already done.
Every gate ends in one of three decisions, the Group Cyber Approval vocabulary. Approved means proceed. Approved with conditions means proceed while named actions close. Not approved means a material standard is unmet; resolve it or raise an exception. Conditional approvals record the condition, an accountable owner, a due date, and a re-review trigger.
The path is the same for every risk class; only the weight changes. The risk class is set at Gate 0 and drives how much review each gate carries.
| Risk Class | Gate 0–2 | Gate 3 | Gate 4 |
|---|---|---|---|
| Risk Class 3: Foundational Internal or low stakes | Self-certify against a checklist; async review | Light review with one reviewer | Metrics submitted; review by exception |
| Risk Class 2: Elevated Client-facing, contained | Live gate reviews with the Authority | Full sign-off; Responsible AI assessment | Scheduled operate review at 30–90 days |
| Risk Class 1: Critical High-stakes or regulated | Named reviewer across all gates | Independent Responsible AI & security sign-off | Periodic review; re-classify on any material change |
The Authority's gates are a single front end to the Group Cyber Approval Process and the ASLM asset lifecycle. Pass a gate once; satisfy all three.
| AI Design Authority gate | Cyber Approval Process | ASLM lifecycle |
|---|---|---|
| Gate 0: Discovery & Scoping | Step I: Discovery & Scoping | Initialize, then Ready to Plan |
| Gate 1: Design & Definition | Step II: Design | Plan & Design |
| Gate 2: Build & Data Readiness | Step III: Development or Integration | Incubation, then Ready to Industrialize |
| Gate 3: Security & Verification | Steps IV–V: Test/QA & Deployment (CISO decision) | Industrialization, then Ready to Run |
| Gate 4: Deployment & Service | Step V: Security in service | Run (then Ready to Retire) |
Investments over €1M also dock with the Group Investment Committee (GIC) per ASLM guidelines.
Book the review, or raise an advisory request first if the work is still in progress. Both start in the same place.