G4 - Working Software Isn't the Bar. Provable Software Is.
Conventional release approval asks whether the system works. AI deployment demands a second question: could you prove — to a board, an auditor, an authority — that it is lawful, owned, baselined and watched? If not, it isn't ready, however well it works.
Where this gets hard
- Approvals test functionality and security, then wave through systems with no classification, no impact assessment and no baseline.
- Impact assessments get retrofitted after go-live, where they protect nobody and persuade no one — the date-stamp tells the story.
- Nobody at the approval table can name the single accountable owner with the authority to stop the system.
- Monitoring is ‘planned for phase two’ — which means the most surprising weeks of the system's life go unrecorded.
- Gates become political fictions: everyone knows this launch will pass, so the scoring bends to the calendar.
Where to start
- Define pass conditions as evidence, not opinion: classification recorded, assessments signed before deployment, baseline locked, owner named, monitoring live.
- Give the gate teeth: no conditional passes for your highest-risk systems, and record every hold with reasons.
- Panel the gate with three people — one of them independent — and score only artefacts produced in the room.
- Verify monitoring before production traffic arrives. You cannot retro-capture week one.
- Publish the saves. A held deployment that would have failed is your governance return on investment, not an embarrassment.
The companion consulting document on our website includes a twenty-item deployment gate checklist with evidence anchors and pass logic.
Part of RMAT's 12-part series on AI governance — Governing AI with Evidence. The companion consulting document — detailed checklists, a risk table, a maturity self-assessment and a 90-day action roadmap — is available on our website. #CEO #CTO #CIO #AI #Governance #Risk