Checklist: Gate Entry and Exit
The five gates, with the entry criteria expanded into what they mean in practice, and the exit conditions that get skipped.
Chapter 36 holds the canonical entry criteria. This is the working version: the same criteria with the ambiguity taken out, plus the exit conditions — the part that determines whether a gate decision means anything a month later.
Run the entry list before the meeting, not in it. A gate whose first twenty minutes are spent establishing whether the evidence exists is a status meeting.
A completed checklist is not evidence. The evidence is the record it told you to complete — the templates hold those.
G1 — Qualification and provisional risk
- Named capability or stakeholder need, with a current and a target measure Sponsor
- Expected outcome stated as a measure with a baseline you can read today Sponsor
- Named business sponsor with the authority to stop the work Sponsor
- The non-AI alternative considered, and the rejection recorded Sponsor
- Decision or action the output supports, written in one sentence Architect
- Affected parties listed, including people who will never use the system Architect
- Intended autonomy at launch, in the words of a D2 anchor Architect
- Provisional D1–D5 scores present and marked provisional Risk Lead
- Data path identified, at least in principle, with a sensitivity signal Data Owner
- No architecture or vendor commitment embedded in the canvas Architect
- Regulatory or contractual constraints from the sector overlay noted Risk Lead
G1 — Exit conditions
- Decision recorded with the records it relied on, by version
- Conditions, if any, carry a named owner and a date
- Provisional scores scheduled for confirmation at S2, with a date
- Rejections recorded with the reason — a rejected canvas is reusable knowledge
G2 — Architecture and data readiness
- ADR complete: model, hosting, grounding and boundary named in comparable form Architect
- Alternatives considered, with the reason each was rejected Architect
- Pattern conformance assessed: conformant, modified with detail, or novel Architect
- Failure behaviour stated: what happens when the model is unavailable, slow or wrong Architect
- Data Lineage and Sensitivity Record complete, each source named Data Owner
- Every grounding source has an owner, a refresh cadence and a maximum staleness Data Owner
- Derived stores listed: indexes, embeddings, caches, evaluation sets Data Owner
- Risk score revisited against the now-known architecture; tier confirmed or changed Risk Lead
- Effective-autonomy threshold agreed now, before anyone knows the number Risk Lead
- Procured systems: vendor due-diligence fields complete, or tier capped, or acceptance recorded Architect
- Agentic systems: authority boundary drafted, and expressible in the enforcement point's language Security Architect
- Concentration checked at Tier 3–4: what else depends on this supplier Architect
G2 — Exit conditions
- Approved architecture recorded precisely enough to be compared against runtime
- Any modification to a pattern recorded in the pattern entry, not only in the ADR
- Data sources with no owner escalated rather than accepted
- Monitoring commitments drafted, so the Control Plane knows what it will watch
G3 — Deployment authorization
- Technical evaluation complete, with pass criteria defined before the run System Owner
- AI Assurance Summary at the depth the tier requires, including what was not tested System Owner
- Directional error rates reported separately where errors are asymmetric System Owner
- Control Matrix complete, each control mapped to a specific risk and emitting evidence Risk Lead
- Named accountable owner recorded — a person, not a function AI Governance Lead
- Human oversight point confirmed for Tier 2 and above, with the time budget stated System Owner
- Authorized configuration written as data: version, sources, action surface, environment Architect
- Machine-readable permission boundary in place for agentic systems Security Architect
- Kill-switch conditions defined and separately approved at Tier 3–4 AI Governance Body
- Monitoring commitments agreed: which signals, what thresholds, whose inbox System Owner
- Any conditions carry a named owner and a date Chair
- Re-authorization triggers stated Chair
G3 — Exit conditions
- Authorization record is machine-comparable against what is running
- Conditions tracked in a place someone reads, not only in the minute
- Dissent recorded with its disposition at Tier 3–4
- The system's entry appears in the inventory with its tier and owner within a week
G4 — Material change
- Change classified against the change-type table, with the reasoning recorded System Owner
- Classification confirmed by a second person at Tier 3–4 where cosmetic or minor is claimed Risk Lead
- Dimensions touched identified before the assurance scope is chosen Risk Lead
- Delta assurance scoped: what is re-run, and what is not, with the reason System Owner
- Autonomy change answered explicitly, yes or no System Owner
- Risk score updated where any dimension is touched Risk Lead
- Post-change tier determined, and approval routed to that tier's authority AI Governance Lead
- Supplier-initiated changes recorded as changes, even where nothing local moved System Owner
- Rollback plan stated, with how long it takes System Owner
- Authorized configuration updated on completion Architect
G5 — Retirement
- Retention or deletion confirmed against the schedule, including derived stores Data Owner
- Access revoked, including machine identities Security Architect
- Downstream consumers identified from telemetry, not only from documentation Architect
- Evidence set archived and retrievable — one retrieval actually tested System Owner
- Ability to explain historical decisions preserved for the liability window Risk Lead
- Knowledge preservation note recorded, including what would be done differently System Owner
- Residual regulatory or contractual obligations identified and owned Risk Lead
Decision options at every gate
Five outcomes, and the two in the middle are the ones that keep gates honest.
| Outcome | Means | Requires |
|---|---|---|
| Approve | Proceed as recorded | Nothing further |
| Approve with conditions | Proceed, with specified work outstanding | Each condition owned and dated, and tracked to closure |
| Remediate | Do not proceed; fix and return | A statement of what would satisfy the gate |
| Escalate | This body cannot decide | The escalation route and what the higher body must answer |
| Reject | Do not proceed | The reason, recorded — rejected work is reusable knowledge |