Guideline: Procured and Embedded AI
Most of the AI in a large organization was bought, not built, and most of it arrived as a feature of something else.
The failure this prevents
Procurement intake routes on contract value. AI arrives as a module of a platform you already own, a feature toggle in a service you already pay for, or a capability added by a supplier at no extra cost. None of those trip a review threshold, and each can land a decision-making system in production without a classification.
The second failure is downstream: a supplier changes the model under a managed service and the organization's approved state silently stops describing what is running. Across every sector in this guide, that is the most frequent uncontrolled change.
[Practice recommendation] Everything on this page is advice from this documentation rather than a requirement of IRGF. Disagreeing with it does not put you outside the framework; all practice recommendations are collected in Appendix B.
Route intake on AI content, not on contract value
One question added to procurement and change intake does more than any policy: does this purchase, renewal or upgrade include, enable or procure AI capability? Ask it of renewals and upgrades too, because that is where embedded AI usually appears.
The answer routes the work. A “yes” means a Use-Case Canvas and a classification, at whatever depth the tier requires — often very little. The point is not to add friction to purchasing; it is to stop systems entering the estate unclassified.
The questions vendors can actually answer
Long AI questionnaires produce long marketing answers. These eight are answerable, verifiable, and each one changes a decision.
| Ask | Why it matters | What a weak answer means |
|---|---|---|
| Which model, at which version, and how is version identity exposed to us? | Without version identity you cannot detect model change, which makes drift detection impossible. | Cap the tier: you cannot evidence what is running. |
| How and when will you notify us of a model change, and how much notice? | This clause determines whether your validated or authorized state remains knowable. | Assume changes will be silent; treat behavioral monitoring as mandatory. |
| What are your terms on our data — training, retention, sub-processors, location? | It sets D5, the lawful basis, and in several sectors whether the system may be used at all. | A change in these terms later is a Material change; make sure you would hear about it. |
| What evaluation evidence can you provide, on what population? | Vendor evaluation on a different population is a hypothesis about your deployment. | You own the evaluation; budget for it. |
| What is the machine-readable permission boundary for anything that acts? | A prose boundary cannot be compared against an IAM grant. | Do not deploy agentic capability from this supplier at Tier 3–4. |
| What logs do we get, at what latency, and can we export them? | The audit link of the agent chain and every drift comparison depends on it. | Detection latency is now the supplier's choice, not yours. |
| What is the exit path, and what do we keep? | Concentration and lock-in are governance concerns, not just commercial ones. | Escalate to portfolio level; this is a dependency decision, not a purchase. |
| Which sub-model, tool or service does your product call, and can that change? | Nested dependency is common and invisible: your supplier's supplier changes the model. | Your behavioral monitoring is the only control you have left. |
Cap the tier you cannot evidence
The framework's stated position on procured systems is workable and underused: where vendor due-diligence fields cannot be completed, either cap the system at Tier 2 or record a documented acceptance. Capping is usually better than accepting, because it constrains what the system may be used for rather than creating a permanent exception.
“Capped at Tier 2” has a practical meaning: it may not be deployed into a use that would score Tier 3 or 4. If the business need is genuinely Tier 3, the answer is a different supplier or a different design, not a stronger assertion.
Embedded AI in software you already run
An office suite, a service desk, a CRM or an ERP gains an assistant. Nobody procured it, no project exists, and it may be enabled by default. Three practices keep this manageable without pretending you can review everything:
- Default-off where the platform allows it, then enable deliberately with a classification, however light.
- A standing pattern for low-tier assistants so enabling one is self-certification rather than a review. Most of these are genuinely Tier 1.
- A named owner per platform who is accountable for knowing what AI features exist in it, reviewed quarterly against the vendor's release notes.
Concentration is a portfolio property
Every system can clear its own gate while the estate quietly accumulates a single point of failure: one supplier providing the model, the embeddings, the vector store and the assistant framework across forty systems. No individual review sees this.
Add one standing question to the Architecture Review Board's quarterly agenda: which single supplier failure would take out the most Tier 3–4 systems, and what is the exit? Record the answer. It is the cheapest portfolio-level control in the framework.
How to tell it is working
Every practice needs a failure signal, or it is a belief. These are the ones that show this guideline has stopped operating in your organization.
| Signal | What it means | What to do |
|---|---|---|
| A system is discovered in production with no classification | Intake is still routing on contract value | Add the AI content question to procurement, renewal and change intake |
| A supplier model change is discovered from behaviour, not notification | The notification clause is missing or not being honoured | Treat as a Material change, and put the clause in the next renewal |
| Vendor due-diligence fields are blank at Tier 3 | The tier is not evidenced | Cap the tier or record an explicit acceptance with an expiry |
| Nobody can name the AI features enabled in a major platform | Embedded AI is entering the estate unobserved | Assign a platform owner and review release notes quarterly |
| No one has assessed supplier concentration in a year | A portfolio-level dependency is accumulating unmonitored | Put the standing question on the board agenda |