The Method

Six layers. One spine. Evidence from strategy to external assurance.

The Architecture

Six connected operating layers

Each layer answers a distinct question, with distinct owners, cadences and proof. Layer 3 divides into 3a and 3b because technical enforcement inside the system and operational control around it are different jobs. The layers form a loop, not a waterfall — assurance findings feed back into strategy.

0

Enterprise AI Authority Decisions

What must be true, and what does the organisation authorise? The constitutional decisions that govern the governors: authority and automation boundaries, competence as a precondition for delegated AI authority, protected challenge rights, AI-contribution disclosure obligations, incentive boundaries and workforce principles. Owned by the board and CEO.

1

Governance

Who decides, on what evidence, with what authority and risk appetite? Owned by the board, CRO, CISO and AI governance.

2

Operationalisation

How do governance expectations become delivery work, controls, evidence and value? Owned by PMO, product, delivery and DevSecOps.

3a

Technical Runtime Enforcement

Are authority, boundaries and prohibitions enforced in the system itself — permissions, guardrails, tool and agent boundaries? Owned by AI governance and security architecture.

3b

Operational Runtime Control

Can we see, constrain, stop, recover from and learn from live AI behaviour? Owned by AI operations, SOC and incident response.

4

External Assurance and Regulatory Engagement

Can the organisation prove control to independent reviewers, auditors and regulators? Owned by audit, legal, compliance and assurance.

Layer 0 decides what must be true and what the organisation authorises. Delivery determines how the organisation will make it true. Layer 0 contains the decisions that govern the governors.

The Operational Spine

One lifecycle for every AI use case

The spine runs across all six layers, giving every AI use case the same end-to-end path from discovery to continuous improvement.

IdentifyClassifyAssignControlEvidenceGateMonitorEscalateAssureImprove
From Policy to Proof

The conversion chain

The core logic beneath every layer, gate and artefact. It prevents organisations from stopping at principles, framework mappings or control statements that have no operational implementation — and enables traceability from any requirement through to the evidence that demonstrates ongoing effectiveness.

Standard / expectation Governance requirement Risk decision Control Accountable owner Delivery activity Artefact Workflow Metric Evidence Assurance test Remediation

See the chain in action — try the live demo

AI Authority

Assist, Augment, Automate, Agentic

AURA separates how much decision and action authority is delegated to AI — and insists on the lowest sufficient authority that reliably delivers the outcome. A valuable AI contribution may sit at assist or augment; maximum autonomy is never the default destination.

Assist

AI supports a person's work. The person performs the task; AI accelerates, drafts or informs.

Augment

AI performs substantive work under close human direction and review. Human judgement remains in the loop.

Automate

AI executes defined tasks within set boundaries, with human oversight, monitoring and intervention pathways.

Agentic

AI holds bounded, delegated authority to decide and act — observable, interruptible and recoverable in production.

Three Separate Scales

Risk, maturity and authority are not the same thing

Mixing these concepts creates false confidence and over-engineering. AURA keeps them distinct:

ScaleWhat it measuresQuestion it answers
Risk tierControl intensity an individual use case requiresHow much control depth does this use case need?
Maturity levelHow consistently the organisation operates and evidences the methodHow reliably do we run AURA across the portfolio?
Authority stageHow much decision and action authority is delegated to AIWhat may this AI decide and do on its own?

Read the full method Get implementation support