Discover
Surface existing usage through an inventory campaign. The first entry is voluntary; the goal is visibility, not punishment.
Behind AIZEC there is not only software but a working model designed to govern enterprise AI usage. This page explains that model.
The model is built on convenience, visibility and proportionate control. The themes Gartner and McKinsey put at the front of the enterprise AI agenda meet at the same place: clear ownership, risk tiering and measurable business impact.
If an employee has to ask "is this forbidden?", the process is not visible enough. The goal is that the approved path is obvious while they are still filling in the form.
Each of the four stages has an owner, an output and a defined duration.
Surface existing usage through an inventory campaign. The first entry is voluntary; the goal is visibility, not punishment.
Every use-case lands on the Green, Amber or Red tier. The rationale is written down and permanent.
DLP, risk assessment, testing and legal approval apply according to the tier. A kill switch is mandatory at red.
Gateway traffic, time-to-decision and business impact are measured. Results feed the next period's tiering criteria.
A five-level model used to determine where your governance programme is today and what the next step should be.
| Level | Definition | Typical symptom | Next step |
|---|---|---|---|
| 1. Unaware | AI is used, but nothing is recorded. | Usage has never even been surveyed. | Launch a voluntary inventory campaign. |
| 2. Visible | An inventory exists and usage is known. | Spreadsheets exist, but no decision mechanism. | Establish use-case intake and a triage SLA. |
| 3. Governed | Tiering and approval flows are running. | Decisions get made, but evidence is scattered. | Turn on the audit trail and gateway integration. |
| 4. Measured | Metrics are reported regularly. | Coverage and time-to-decision are tracked. | Measure business impact metrics and reuse. |
| 5. Optimised | Decision criteria improve from data. | Reuse rises and decision time falls. | Partially automate the red-tier criteria. |
The maturity level is a position check, not a target. The real gain comes in the move from level 2 to level 3, when the decision mechanism is put in place. Gartner and McKinsey describe the same threshold in their enterprise AI work as the step from pilots to a governed operation.
Governance programmes do not start with a large launch. They start with the first real decision.
Tenant creation, SSO connection, business unit and role definitions. Identifying the CoE team and spoke representatives.
Voluntary inventory entry, a communication plan and field work with spoke representatives. First coverage measurement.
Opening the use-case intake form, first tiering decisions and the start of SLA tracking. Building the approved alternatives catalogue.
Gateway log integration, the first monthly report snapshot and the first governance briefing to the board.
The model requires every decision to have exactly one owner.
| Role | Responsibility | Decision authority | Accountable metric |
|---|---|---|---|
| AI CoE (Hub) | Policy, tiering, catalogue | Green and Amber approval | Coverage rate, time-to-decision |
| Spoke representative | Field adoption, steering | Recommendation | Unit inventory coverage |
| Security | Gateway, risk, kill switch | Red assessment and revocation | Violation count, approved traffic ratio |
| Legal & Compliance | Regulation and personal data | Red legal approval | Open compliance findings |
| Executive | Priority and resourcing | Programme approval | Business impact, return on investment |
We will determine your current maturity level together and draw up the first 90-day plan.