Governance, membership & waivers

Who sets the bar, and how it moves.

The Authority is a small, senior, cross-functional body with clear decision rights. It owns the standards, runs the reviews, and is the only route to an exception. It operates as the AI-specialist complement to the Group Industrialization Design Authority (IDA), applying Group and Business Line policy to AI product work — see Foundations.

Membership

A core team, plus the expertise each review needs.

Standing members hold the bar and the cadence. A rotating bench of practitioners brings deep expertise to individual reviews so the core stays lean.

Lead

Ian Davies. Accountable for the Authority. Owns the cadence, breaks ties, and holds the final decision on delivery escalations.

Pillar leads (×4)

One senior owner per pillar — Responsible AI, Architecture, Product & UX, Delivery. Each maintains their standards and leads reviews in their domain.

Responsible AI lead

Independent authority on ethics, safety, and regulation. Holds a standing veto on Responsible AI grounds that the Lead cannot override.

Secretary

Runs intake, scheduling, and the decision record. Keeps the standards library and waiver register current.

CISO & DPO (coordinated)

Not members, but decision-holders the Authority coordinates with: the CISO owns cybersecurity approval and exceptions; the DPO owns data protection sign-off.

Reviewer bench

A rotating pool of senior engineers, data scientists, and designers who staff reviews. Rotation spreads the standard and avoids single points of failure.

Sponsor

Etienne Grass. Mandates the Authority, unblocks resourcing, and represents it to the wider practice and to the IDA.

Chief AI Asset Product Owner Lead

A member of the Authority, connecting it to the AI Asset Product Owner community and the asset creation process. See Asset Lifecycle.

Decision rights

Who decides what.

Clear ownership prevents both bottlenecks and quiet gaps. Every decision has one accountable role.

DecisionAccountableNotes
Asset technology approvalAI Design AuthorityThe technology lens at Step 4 of the asset process
Risk class of a productReviewer, confirmed by pillar leadSet at Gate 0; re-classified on material change
Gate Pass / Hold decisionAssigned reviewerEscalates to Lead if contested
Responsible AI sign-offResponsible AI leadIndependent; not overridable by the Lead
Cybersecurity approval & exceptionsCISOGroup Exception Management process; Authority coordinates
Data protection sign-offDPORequired for sensitive or live personal data
Granting a waiver / exceptionPillar lead + Authority LeadCyber exceptions to CISO; RAI exceptions to the RAI lead
Investment docking (>€1M)Group Investment Committee (GIC)Per ASLM; aligns Group IT, Cyber, Legal, Portfolio
Adding or changing a standardAuthority, by consensusLead decides if consensus is not reached
Delivery escalationLeadFinal within the Authority; sponsor beyond
Cadence

A predictable rhythm teams can plan around.

Weekly

Office hours & reviews

Open drop-in plus scheduled gate reviews. The working heartbeat of the Authority.

Fortnightly

Authority session

Standing members meet to decide waivers, contested gates, and standards changes.

Quarterly

Standards review

The full library is reviewed against new regulation, tooling, and lessons from live products.

Annually

Charter & effectiveness

The sponsor reviews the Authority's mandate, membership, and measured impact.

Living standards

How a standard is born, changes, and retires.

The library is version-controlled and dated, and structured as an AI management system aligned to ISO/IEC 42001. Anyone can propose a change; the Authority ratifies it. A standard that no longer earns its place is retired, not left to rot.

01 Propose

Propose

Any practitioner raises a gap or a change, with the problem and evidence behind it.

02 Review

Review

The relevant pillar lead drafts or refines the standard and tests it against real builds.

03 Ratify

Ratify & publish

The Authority agrees the wording and level, versions it, and communicates the change with a lead time.

04 Retire

Retire

Standards overtaken by regulation or practice are deprecated and archived, with the reason recorded.

Exceptions & waivers

A disciplined way to say "not yet".

Sometimes a mandatory standard genuinely cannot be met in time. An exception makes that a conscious, owned, time-boxed decision — never a silent gap. Cybersecurity exceptions follow the Group Exception Management process and require CISO sign-off.

How an exception works

1

Request

State the standard, why it cannot be met, a risk assessment, and the compensating controls and mitigation plan.

2

Decide

The pillar lead and Authority Lead decide — the Responsible AI lead for safety or ethics, the CISO for cybersecurity exceptions. Granted, refused, or narrowed.

3

Time-box

Every exception carries a named owner and an expiry date. It closes when the standard is met, or it is reviewed again.

4

Track

All live exceptions sit on a visible register the Authority reviews at each session. Nothing expires unnoticed.

What cannot be waived. Legal and regulatory obligations, prohibited use cases, and core Responsible AI protections are not waivable. If you cannot meet these, the product does not ship in that form.

A waiver is not a shortcut

It is a recorded, senior decision to accept a known risk for a defined time. Teams that lean on waivers to skip standards will find the bar comes back at the next gate.

Measuring ourselves

We track gate pass rates, waiver volume and age, and time-to-decision — and publish them. The Authority is accountable for being fast and fair, not just strict.

Want to propose a standard or raise a waiver?

Both start at the same intake. Bring the problem and the evidence — we will take it from there.