Start Implementation

EXECUTIVE LEADERSHIP
COMMUNICATION

The seamless architecture

Five to speak, seven to build, nine to run.

One programme at three resolutions. Executives navigate five phases; the application is structured as seven pillars; the engine underneath executes the nine-stage pathway. Nothing is renamed between layers — each is the same work viewed at a different depth.

  1. 5

    Top navigation · executive communication

    Align · Control · Prioritise · Deliver · Assure

    What the board sees
    01

    Align

    Strategy · readiness · value

    Pillar 1 · Stage I
    02

    Control

    Data · governance · risk · privacy

    Pillars 2–3 · Stages II–IV
    03

    Prioritise

    Use cases · value · feasibility · AI risk

    Pillar 4 · Stage V
    04

    Deliver

    Platform · pilots · evaluation · adoption

    Pillars 5–6 · Stages VI–VIII
    05

    Assure

    Evidence · monitoring · attestations · compliance

    Pillar 7 · Stage IX
  2. 7

    Application architecture

    Strategy · Data · Governance · Portfolio · Platform · Delivery · Assurance

    How the product is built
    01

    Strategy

    Readiness baseline & investment case.

    Stage I
    02

    Data

    Lineage, quality & architecture fit.

    Stage II
    03

    Governance

    Policy, risk register & oversight.

    Stages III–IV
    04

    Portfolio

    Use-case scoring & prioritisation.

    Stage V
    05

    Platform

    Vendor & technology selection.

    Stage VI
    06

    Delivery

    Pilots, evaluation & adoption.

    Stages VII–VIII
    07

    Assurance

    Evidence, monitoring & attestations.

    Stage IX
  3. 9

    Implementation Roadmap - Workflow engine

    Stage I — IX · the Corporate pathway detailed below

    What actually executes
Pillar 1 Stage I

Strategy, Readiness & Value

I — Enterprise Readiness Audit

15 questions across data lineage, retention, access control, incident history and vendor exposure, scored into a readiness baseline.

Downloads (1) PDF
Pillar 2 Stage II

Data & AI Architecture

II — Data Architecture Review

Connector inventory, schema drift and lineage gap analysis, with live probes against your actual warehouses.

Downloads (1) PDF
Pillar 3 Stages III–IV

Governance, Risk & Compliance

III — Governance Stand-Up · IV — Privacy & Security Deep Dive

AI acceptable-use policy, committee charter, model inventory and vendor register — then DPIAs, FRIAs and threat modelling for high-risk use cases.

Downloads (1) PDF
Pillar 4 Stage V

AI Portfolio & Prioritisation

V — BU-Level Use-Case Portfolio

Score every candidate use case on business value, data readiness, time-to-pilot and EU AI Act risk penalty.

Downloads (1) PDF
Pillar 5 Stage VI

Platform, Vendors & Technology

VI — Platform Decision

Build vs buy on inference, evals and observability — driven by the use cases that actually scored.

Downloads (1) PDF
Pillar 6 Stages VII–VIII

Delivery, Adoption & Scale

VII — Pilot Deployment · VIII — Centre of Excellence

Contained pilots with eval harness, human-in-the-loop and kill-switch, then a repeatable rollout playbook, training tracks and RACI.

Downloads (1) PDF
Pillar 7 Stage IX

Assurance & Continuous Improvement

IX — Continuous Compliance

Quarterly attestations, drift alerts, vendor reviews and a signed Article 9 pack export.

Downloads (1) PDF
AI Strategy Builder · Corporate Pathway v1

Make your AI program defensible — before regulators ask.

A nine-stage pathway that converts ad-hoc AI experiments into a regulator-ready program — with a verifiable audit chain a board, an auditor, and the EU AI Act will all recognise.

Readiness score · 12 min Explore the dashboard
9Stages of progressive readiness · day 0 → 90
8Dimensions assessed across data, governance, vendors
9Frameworks mapped: EU AI Act · SOC 2 · ISO 42001 · NIST AI RMF · HIPAA · SR 26-2 · DORA · Kenya & Tanzania DPA
What you produce

The four documents a regulator asks for first.

Every stage of the pathway converges on artefacts you can hand to legal, the board, or an external auditor — versioned, hashed, and timestamped.

i.

AI Acceptable Use Policy

Organisation-wide policy covering permitted use cases, prohibited content, incident reporting, employee acknowledgement.

PDF · Signed
ii.

AI Committee Charter

Membership, decision rights, escalation path, meeting cadence — the cross-functional body that owns AI risk.

DOCX · Versioned
iii.

Model Inventory

Every model in production: owner, purpose, training-data summary, last evaluation date, EU AI Act risk tier.

XLSX · Live
iv.

Vendor & DPA Register

Catalogue every AI vendor touching your data with risk tier, DPA status, sub-processor chain, retention terms.

XLSX · Audited
  1. I

    Enterprise Readiness Audit

    15 questions across data lineage, retention, access control, incident history, vendor exposure.

    Readiness score · PDF Stages 0 of 9 · day 0 → 7
  2. II

    Data Architecture Review

    Connector inventory, schema drift, lineage gap analysis. Live probes to your actual warehouses.

    Connector probe report day 8 → 18
  3. III

    Governance Stand-Up

    AI Acceptable Use Policy, AI Committee charter, Model inventory, Vendor & DPA register.

    4 governance docs EU AI Act · Art. 9 · 10 · 13
  4. IV

    Privacy & Security Deep Dive

    DPIAs, FRIAs for high-risk use cases, threat modelling, secrets and PII scanning of training data.

    DPIA · FRIA Art. 27 · GDPR Art. 35
  5. V

    BU-Level Use-Case Portfolio

    Score each candidate use case across business value, data readiness, time-to-pilot, and EU AI Act risk penalty.

    Ranked portfolio day 35 → 49
  6. VI

    Platform Decision

    Build vs buy on inference, evals, observability — driven by the use cases that actually scored.

    Platform RFP day 50 → 60
  7. VII

    Pilot Deployment · 3 BUs

    Three pilots with eval harness, human-in-the-loop, kill-switch, weekly review. Real users, contained blast radius.

    Pilot eval pack day 60 → 75
  8. VIII

    Centre-of-Excellence

    Repeatable rollout playbook, training tracks, RACI for net-new use cases, prompt & eval registry.

    CoE handbook day 75 → 88
  9. IX

    Continuous Compliance

    Quarterly attestations, drift alerts, vendor reviews, signed Article 9 pack export.

    Article 9 pack · signed on-demand
How it works

From first question to signed Article 9 pack — without the consultant invoice.

Step 01

Answer, don't author

Each stage is a structured Q&A. We synthesise the policy, charter, and inventory from your answers — you review and sign.

Step 02

Attach evidence

Drop DPAs, board minutes, training data manifests. Every file is hashed and pinned to the audit chain at upload time.

Step 03

Probe live systems

Read-only connectors to Snowflake, GitHub, Salesforce, Databricks. Probes verify lineage, retention, and access claims.

Step 04

Export the pack

One click produces the regulator-ready bundle: cover memo, evidence index, hash manifest, signed timestamps.

Use-case ranker

AI use cases, ranked for the data you actually have.

Every candidate use case is scored across business value, data readiness from your live connectors, shipping speed, and EU AI Act risk penalty. The ranker re-runs as your pathway progresses.

I

Shipment Exception Handler

Logistics Data Ready Limited-Risk 14 day pilot

Your Snowflake shipments and exceptions tables contain 18 months of high-quality labelled data. Low regulatory overhead. Revenue protection est. USD 240–480k per year.

87/ 100
value data speed risk
II

SOP Compliance Q&A

Operations Data Ready Limited-Risk 10 day pilot

340-page SOP library already indexed in Confluence. Retrieval-grounded agent cuts supervisor handover time ~35%. Advisory output, not directive — risk stays low.

81/ 100
value data speed risk
V

KYC Adverse-Media Screener

FinServ High-Risk · EU AI Act 45 day pilot

High business value but classified high-risk under EU AI Act Annex III. Requires FRIA, human-oversight design, and Article 14 documentation — recommended only after Stage IV.

58/ 100
value data speed risk
Frameworks mapped · click any pack to preview

One pathway, nine frameworks. Export the one your regulator speaks.

Defensibility Bundle · enterprise add-on
Pack-agnostic. Wraps every regulation above.
Hash-chained audit-chain export · regulator-response agent · weekly continuous-monitoring sweeps. $1,499/mo, cancel anytime.
See the bundle →

“We replaced a six-month consultancy engagement with a 90-day pathway and walked into our SOC 2 audit with every artefact already hashed and signed. The auditor asked for the vendor register first — we had it open in another tab.”

Ada N. · Chief Risk Officer · multinational logistics group, Nairobi
Get started today

Start with the readiness score. Decide afterwards.

Twelve minutes, fifteen questions, no card. You'll know within the hour whether your data stack can take an AI program — and exactly which gaps to close first.

$49/ month · Business plan
  • Full 9-stage Corporate pathway
  • Live connector probes & evidence vault
  • Use-case ranker + auto-recompute
  • Signed exports for SOC 2 · EU AI Act · DPA
  • Stakeholder invites & scoped review
Upgrade to Business Or try the readiness score · free
buildstrategy_builder · v1.0 regionmulti · EU · KE · TZ · US audit_chained25519 · sha256 last_export2026-04-19
Loading...