Each gate is a short, structured review with clear entry and exit criteria. Pass the gate for your risk class and you carry evidence, not doubt, into the next phase. The gates are proportionate — a Risk Class 3 product moves through a lighter version of the same path. They align to the Group Cyber Approval Process and the ASLM asset lifecycle, so a single set of evidence serves both.
Gates map to the natural decision points of an AI build — and to the five steps of the Group Cyber Approval Process. You do not stop work to pass them; you bring the work you have already done.
Every gate ends in one of three decisions — the Group Cyber Approval vocabulary. Approved proceed · Approved with conditions proceed while named actions close · Not approved a material standard is unmet — resolve or raise an exception. Conditional approvals record the condition, an accountable owner, a due date, and a re-review trigger.
Same path, different weight. The risk class is set at Gate 0 and drives how much review each gate carries.
| Risk Class | Gate 0–2 | Gate 3 | Gate 4 |
|---|---|---|---|
| Risk Class 3 · Foundational Internal / low stakes | Self-certify against a checklist; async review | Light review with one reviewer | Metrics submitted; review by exception |
| Risk Class 2 · Elevated Client-facing, contained | Live gate reviews with the Authority | Full sign-off; Responsible AI assessment | Scheduled operate review at 30–90 days |
| Risk Class 1 · Critical High-stakes / regulated | Named reviewer across all gates | Independent Responsible AI & security sign-off | Periodic review; re-classify on any material change |
The Authority's gates are a single front end to the Group Cyber Approval Process and the ASLM asset lifecycle. Pass a gate once; satisfy all three.
| AI Design Authority gate | Cyber Approval Process | ASLM lifecycle |
|---|---|---|
| Gate 0 · Discovery & Scoping | Step I — Discovery & Scoping | Initialize → Ready to Plan |
| Gate 1 · Design & Definition | Step II — Design | Plan & Design |
| Gate 2 · Build & Data Readiness | Step III — Development / Integration | Incubation → Ready to Industrialize |
| Gate 3 · Security & Verification | Steps IV–V — Test/QA & Deployment (CISO decision) | Industrialization → Ready to Run |
| Gate 4 · Deployment & Service | Step V — Security in service | Run (→ Ready to Retire) |
Investments over €1M also dock with the Group Investment Committee (GIC) per ASLM guidelines.
Book the review, or bring a work-in-progress to office hours first. Both start in the same place.