The Method

Six layers. One spine. Evidence from strategy to external assurance.

The Architecture

Six connected operating layers

Each layer answers a distinct question, with distinct owners, cadences and proof. Layer 3 divides into 3a and 3b because design-time authority and live runtime control are different jobs. The layers form a loop, not a waterfall — assurance findings feed back into strategy.

0

Strategy, Culture and Capability

Do we have the mandate, skills, cultural readiness and operating-model legitimacy? Owned by the CEO, Head of AI and people leadership.

1

Governance

Who decides, on what evidence, with what authority and risk appetite? Owned by the board, CRO, CISO and AI governance.

2

Operationalisation

How do governance expectations become delivery work, controls, evidence and value? Owned by PMO, product, delivery and DevSecOps.

3a

Agentic Design and Boundaries

What may the AI decide and do, what requires approval, and what is prohibited? Owned by AI governance and security architecture.

3b

Runtime Operations and Intervention

Can we see, constrain, stop, recover from and learn from live AI behaviour? Owned by AI operations, SOC and incident response.

4

External Assurance and Regulatory Engagement

Can the organisation prove control to independent reviewers, auditors and regulators? Owned by audit, legal, compliance and assurance.

Technical readiness without human-system readiness is not readiness. That is why Layer 0 treats strategy, culture, capability and workforce design as upstream controls — not soft adoption topics.

The Operational Spine

One lifecycle for every AI use case

The spine runs across all six layers, giving every AI use case the same end-to-end path from discovery to continuous improvement.

IdentifyClassifyAssignControlEvidenceGateMonitorEscalateAssureImprove
From Policy to Proof

The conversion chain

The core logic beneath every layer, gate and artefact. It prevents organisations from stopping at principles, framework mappings or control statements that have no operational implementation — and enables traceability from any requirement through to the evidence that demonstrates ongoing effectiveness.

Standard / expectation Governance requirement Risk decision Control Accountable owner Delivery activity Artefact Workflow Metric Evidence Assurance test Remediation
AI Authority

Assist, Augment, Automate, Agentic

AURA separates how much decision and action authority is delegated to AI — and insists on the lowest sufficient authority that reliably delivers the outcome. A valuable AI contribution may sit at assist or augment; maximum autonomy is never the default destination.

Assist

AI supports a person's work. The person performs the task; AI accelerates, drafts or informs.

Augment

AI performs substantive work under close human direction and review. Human judgement remains in the loop.

Automate

AI executes defined tasks within set boundaries, with human oversight, monitoring and intervention pathways.

Agentic

AI holds bounded, delegated authority to decide and act — observable, interruptible and recoverable in production.

Three Separate Scales

Risk, maturity and authority are not the same thing

Mixing these concepts creates false confidence and over-engineering. AURA keeps them distinct:

ScaleWhat it measuresQuestion it answers
Risk tierControl intensity an individual use case requiresHow much control depth does this use case need?
Maturity levelHow consistently the organisation operates and evidences the methodHow reliably do we run AURA across the portfolio?
Authority stageHow much decision and action authority is delegated to AIWhat may this AI decide and do on its own?

Read the full method Get implementation support