EW-AiRM Enterprise-wide AI Risk Management logo
EW-AiRM™ · Enterprise-Wide AI Risk Management

The Implementation Pathway

From first assessment to a continuously operating governance state — the five-phase EW-AiRM™ journey (Ch. 13), proportionate to your organisation through the Core, Standard and Full implementation tiers, supported by the sixteen-tool Implementation Toolkit.

Step one — choose your implementation tier

EW-AiRM™ scales with the organisation, not against it. Select the tier that matches your profile (Table 13.2 trigger criteria) to see your implementation journey. Where criteria diverge, govern at the highest indicated tier.

Tiers are cumulative: Standard includes everything in Core; Full includes everything in Core and Standard (Ch. 13, Table 13.2).

Viewing journey for:

Your implementation journey

The philosophy (Ch. 13): additive, not substitutive — every activity augments existing ERM, governance structures and risk registers; and tiered, not uniform — the highest-risk systems receive the most intensive governance attention first. The goal is not a completion date but a continuous operating state.

Always on — the Five Non-Negotiables (Table 13.1) Named system owner · HAiPECR pre-deployment assessment · human override tested (≤4h) · documented risk acceptance · incident reporting pathway. Identical at every tier: the minimum below which no organisation can claim to be governing its AI responsibly.
XC-01 Attestation
Always on — the HAiPECR ethical filter (Ch. 10)
OP-01 HAiPECR
0

Foundations — set the tier, attest the floor

Before Day 1Cross-cutting

Confirm your tier from the Table 13.2 trigger criteria, run the current-state diagnostic against every framework element, and put the five non-negotiables on record with the board.

ST-00 Tier Selector & DiagnosticXC-01 Non-Negotiables Attestation
§ Ch. 3 · Ch. 13, Tables 13.1–13.2
1

Phase 1 — Assess: honest assessment

Days 1–30Strategic layer

Map every AI system against the six pillars and surface the material gaps. Inventory existing controls to the four MIT quadrants. Score HAiPECR for the top three highest-risk systems. Document current risk register entries and the AI-specific gaps.

ST-01…ST-06 Pillar assessmentsOP-02 Inventory & Shadow AIOP-04 Control mappingOP-01 HAiPECR (top 3)OP-03 Register gaps
§ Ch. 13, Table 13.3 Phase 1 · Chs. 4–9
2

Phase 2 — Enhance: risk identification

Days 30–60Operational layer

Educate the risk committee on the seven MIT domains and 24 subdomains. Re-classify existing AI risk entries using the MIT taxonomy — to subdomain level. Identify risks not yet captured, validate with technical teams, and prioritise by impact and likelihood.

OP-03 Enhanced Risk RegisterST-02 Literacy by roleST-04 Prioritisation matrix
§ Ch. 13, Table 13.3 Phase 2 · Ch. 11, Table 11.1
3

Phase 3 — Build: the control framework

Days 60–90Operational layer

Create the pre-deployment safety case that operationalises HAiPECR, technical root-cause documentation and MIT classification. Apply the Risk↔Controls Master Mapping as the control-selection start point, re-scoring Primary / Secondary / Tertiary tiers in your context. Map controls to the four quadrants, close priority gaps, assign ownership, define KRI thresholds.

OP-05 Safety CaseOP-04 Gap analysis & four-step mappingST-05 Gate log & RACIST-06 KRI thresholds
§ Ch. 13, Table 13.3 Phase 3 · Ch. 12, Tables 12.1–12.11
4

Phase 4 — Implement: monitoring infrastructure

Days 90–180Strategic layer · Pillar 6

Stand up KXI monitoring for the highest-risk systems, integrate monitoring data into governance reporting, run the first post-implementation lifecycle risk review, and train the first and second lines on the enhanced framework (IIA Three Lines Model).

ST-06 KXI Register & dashboardsST-02 Training & culture
§ Ch. 13, Table 13.3 Phase 4 · Ch. 9 · Appendix Tables 16.4–16.11

Phase 5 — Sustain: resilience & evolution

ContinuousResilience layer

Review MIT taxonomy updates as released (~twice yearly) and horizon-scan emerging risks. Run the AI Black Swan scenario cycle and keep the incident classification and response capability exercised. Begin the Quantum Risk Control Set at the tier-appropriate level. Re-assess annually — including whether you have grown into the next tier.

RS-01 Black Swan WorkbookRS-02 Incident PlaybookOP-04 Quantum Control SetXC-02 Programme Tracker
§ Ch. 13, Table 13.3 Phase 5 · Ch. 14, Tables 14.1–14.15
↺ The annual re-assessment loops back to ST-00: governance that does not adapt is governance that will eventually fail.