The Rest Is AI logo

Playbook

The AI Governance Playbook

How disciplined organisations implement AI without surprises — the illustrative standard TRIAI uses to assess, design, and verify.

Purpose

This playbook sets out the discipline TRIAI applies when helping enterprises implement AI in core processes — illustrated here through an invoice processing exemplar. It is written for senior leaders who want AI to deliver material value without losing control of accountability, risk, or audit.

Guiding principle

Enterprise AI should be designed to improve important decisions and outcomes — not to deploy technology for its own sake.

AI is decision support, not autonomous automation. Accountability cannot be delegated to a machine — this is the same principle underpinning TRIAI's Judgement Architecture: routine, repeatable work moves to machine execution; trade-offs, accountability, and risk ownership remain with named humans.

Human in the loop

Named humans decide. Machines prepare.

AI prepares recommendations within guardrails. A named human owner reviews, decides, and remains accountable — with a defensible audit trail.

  1. Step 1

    Work arrives

    Request enters the process

  2. Step 2

    Machine prepares

    Classify · draft · score

  3. Step 3

    Human decides

    Accountability stays here: approve · override · reject

  4. Step 4

    Action executed

    Only after explicit approval

  5. Step 5

    Audit recorded

    Decision trace stored

Risk tiering

Risk tierExamplesControlAssurance
Low riskRetrieval, drafting, triage within guardrailsControlled autonomy permittedPeriodic deep-dive audits force full human review
High riskPayments, legal approvals, contractual commitmentsMandatory human gate — no autonomous executionOverride rationale required; escalate if uncertain

Core rules

Decision support first
AI improves decisions; it does not replace accountability.
Named owner accountable
Authority cannot be delegated to AI.
Humans decide — not ratify
Reviewers must actively judge outcomes; rubber-stamping defeats the control.
Watch for rubber-stamping
Declining review times without complexity change, weak override rationale, language like "the system says…" are all red flags.

Agentic AI

Governed, not unbounded

Systems are moving from one-turn Q&A to programmes that receive a goal, plan steps, use tools, and leave an audit trail. This is agentic AI — and it does not relax the rules above. Human accountability and defensible logging are prerequisites before autonomy expands.

The maturity path — earning the right to move right

StageCapabilityWhat must be proven first
AssistClassification, extraction, drafting, triage within guardrailsA controlled pilot with defined confidence thresholds
RouteSensitivity-based routing and model selectionArchitecture and security sign-off
ActTool-backed steps with decision loggingA verified decision trace and risk review
OrchestrateMulti-step or multi-agent programmesEvidence from a successful pilot, not intention
GovernFull audit, residency, and human sign-off at scaleAn operating model with defined ownership

Multi-step or tool-backed autonomy expands only after a successful pilot and explicit sign-off. Pausing or narrowing scope is good governance — not failure.

Worked pattern

Invoice processing

Presented in the same Before → After → Boundary structure as the Patterns Library.

Before

Every invoice queues for manual classification, data entry, and matching — regardless of complexity or risk.

After

AI classifies invoices, extracts fields, and flags likely exceptions. Routine, high-confidence invoices move through a defined straight-through path.

Judgement boundary

AI does not own the approval decision or trigger payment autonomously. A named Business Decision Owner stays accountable, with a defensible audit trail for every override.

How this gets proven, not assumed: a controlled pilot first — typically 10–15% of volume, time-boxed to 6–8 weeks, with confidence thresholds and override logging agreed upfront. A pilot that proves AI doesn't deliver value here is still a successful pilot.

Adoption Framework

How this maps to Assess, Redesign, and Scale

This playbook isn't a separate methodology — it's the operating detail behind the Adoption Framework stages below.

Framework stageWhat this playbook contributes
AssessThe risk-tiering logic feeds directly into Governance & Responsible Adoption Architecture.
RedesignThe Judgement Architecture Sprint produces the Decision Specification this playbook describes — what's automated, what stays human, and where the escalation triggers sit.
ScaleImplementation Assurance verifies a built system against exactly this standard — the pilot-to-production discipline shown here.

Independence

What TRIAI does — and does not do

TRIAI designs the Decision Specification, the risk tiering, and the human-in-the-loop protocol. We verify that what gets built matches that design. We do not build the system, host it, or operate it. Whether your team or a chosen vendor implements the solution, this playbook is the standard we hold it to.

We advise on adoption. We do not supply the technology.