FL Fredrik Lindstrom


The nine steps: a stem of five and a loop of four Steps 01 Diagnose, 02 Assign, 03 Inventory, 04 Staff the capability and 05 Pilot run left to right in a line, because each supplies what the next needs. The line then enters a closed ring carrying 06 Run it, 07 Measure, 08 Scale and 09 Evidence, which repeat continuously and never complete. A dashed arrow returns from the ring to 03 Inventory: the escalation log the running agent produces is what completes the inventory. Continuous nothing here reports done Diagnose 01 Assign 02 Inventory 03 Capability 04 Pilot 05 Run it 06 Measure 07 Scale 08 Evidence 09 The escalation log redraws the inventory In order — each one supplies the next No order — and no top

Five steps that finish. Four that don’t.

The dashed line is the one most rollout diagrams leave out. You cannot finish an inventory by assessment — the last slice of it arrives when something starts enforcing a boundary and the exceptions announce themselves. Step 03 is where the inventory starts, not where it completes.


The nine

Each step names what it produces, the failure that shows up first, the instrument that does it properly, and — where one exists — the free sheet you can use today without buying anything or leaving an email address.

  1. 01

    Diagnose

    Run the four questions on the governance picture your organisation is actually using. Whatever comes back marks where a column has stopped running.

    The bump — The test gets run by the person who drew the picture.

    • The Column Test

    Free, no email: The Column Test · The AI Governance Game · Governance is not the bottom brick

  2. 02

    Assign

    One named person per column, each with a launch-hold scope, a budget line and an escalation route. Then set who is allowed to decide what.

    The bump — Owners named without authority. The map completes and nothing changes.

    • Column Ownership Map
    • Decision-Rights Register

    Free, no email: The agent halt matrix

  3. 03

    Inventory

    Every AI system and agent running, its owner, its vendor, its model version, and what it is permitted to touch. Start it here; it does not finish here. The last slice of any inventory comes out of enforcement, not out of an inventory project.

    The bump — You capture what was procured. What is running is a longer list.

    • AI & Agent Inventory and Registry

    Free, no email: You cannot govern what you cannot name · What each AI tier actually decides · AI Doesn’t Need Perfect Data

  4. 04

    Staff the capability

    Turn the twelve layer-by-column intersections into a competence requirement per seat, then make it something HR can hire and train against.

    The bump — Everyone trained, nobody competent.

    • Columns × Layers Competence Matrix
    • AI-Literacy Syllabus

    Free, no email: Columns Not Layers: the matrix · Cyber terms for the boardroom

  5. 05

    Pilot

    One bounded use case with all three columns live on it. Bounded means specified before it runs: an allowlist of what it may settle alone, everything else halting by default, enforced where the model cannot reach it rather than written into a prompt. A governance trial that happens to involve technology.

    The bump — The pilot is chosen to succeed, so it proves nothing.

    • The Practitioner Playbook
    • Acceptance Criteria

    Free, no email: Not all bad data is the same kind of bad · AI Doesn’t Need Perfect Data

  6. 06

    Run it

    Two bodies, one rhythm, a named convener, and standing agenda items that carry a number so they cannot be marked “no update”.

    The bump — The cadence gets absorbed into another committee and disappears.

    • Governance Operating Model

    Free, no email: Logs are not a leash

  7. 07

    Measure

    Four numbers — one anchor signal per column, plus spend against value. Each one a triggered diagnostic, never a target.

    The bump — The dashboard goes green and nobody samples the zero.

    • Board Metric Cards

    Free, no email: Not all bad data is the same kind of bad

  8. 08

    Scale

    Widen deployment only where the columns held, at the pace the weakest column sets.

    The bump — Scale follows the loudest function, not the readiest one.

    • Maturity Model
    • Transition Plan
  9. 09

    Evidence

    Show a regulator, an auditor or a customer that the above satisfies what applies to you. Compliance is the residue, not a separate workstream.

    The bump — Evidence assembled after the fact, by the system it evidences.

    • EU AI Act × NIST × ISO 42001 Crosswalk

    Free, no email: EU AI Act × NIST AI RMF × ISO 42001 · A regulator drew columns and called them pillars


This is not a maturity model

There is no level you reach here. Steps 01 to 05 have an order because each one supplies something the next one needs: you cannot assign an owner to a system nobody has inventoried, and you cannot staff a competence nobody has specified. That is a dependency, not a ladder.

From 06 the work is a loop, and a loop has no top. Measuring does not retire running it. Scaling does not retire measuring. The three things that decide whether AI governance holds — human capability, governance, supply chain — are not stages you clear on the way to somewhere. They run the full height of everything you build, for as long as it runs.

If a picture of AI governance shows you arriving somewhere, it is selling you the arrival.


Most boards act after it has cost them something. If you would rather work out which column is blank before that happens, book a call.