From first assessment to a continuously operating governance state — the five-phase EW-AiRM™ journey (Ch. 13), proportionate to your organisation through the Core, Standard and Full implementation tiers, supported by the sixteen-tool Implementation Toolkit.
EW-AiRM™ scales with the organisation, not against it. Select the tier that matches your profile (Table 13.2 trigger criteria) to see your implementation journey. Where criteria diverge, govern at the highest indicated tier.
Tiers are cumulative: Standard includes everything in Core; Full includes everything in Core and Standard (Ch. 13, Table 13.2).
The philosophy (Ch. 13): additive, not substitutive — every activity augments existing ERM, governance structures and risk registers; and tiered, not uniform — the highest-risk systems receive the most intensive governance attention first. The goal is not a completion date but a continuous operating state.
Confirm your tier from the Table 13.2 trigger criteria, run the current-state diagnostic against every framework element, and put the five non-negotiables on record with the board.
Map every AI system against the six pillars and surface the material gaps. Inventory existing controls to the four MIT quadrants. Score HAiPECR for the top three highest-risk systems. Document current risk register entries and the AI-specific gaps.
Educate the risk committee on the seven MIT domains and 24 subdomains. Re-classify existing AI risk entries using the MIT taxonomy — to subdomain level. Identify risks not yet captured, validate with technical teams, and prioritise by impact and likelihood.
Create the pre-deployment safety case that operationalises HAiPECR, technical root-cause documentation and MIT classification. Apply the Risk↔Controls Master Mapping as the control-selection start point, re-scoring Primary / Secondary / Tertiary tiers in your context. Map controls to the four quadrants, close priority gaps, assign ownership, define KRI thresholds.
Stand up KXI monitoring for the highest-risk systems, integrate monitoring data into governance reporting, run the first post-implementation lifecycle risk review, and train the first and second lines on the enhanced framework (IIA Three Lines Model).
Review MIT taxonomy updates as released (~twice yearly) and horizon-scan emerging risks. Run the AI Black Swan scenario cycle and keep the incident classification and response capability exercised. Begin the Quantum Risk Control Set at the tier-appropriate level. Re-assess annually — including whether you have grown into the next tier.