M · Guidelines

Guideline: Procured and Embedded AI

Most of the AI in a large organization was bought, not built, and most of it arrived as a feature of something else.

The failure this prevents

Procurement intake routes on contract value. AI arrives as a module of a platform you already own, a feature toggle in a service you already pay for, or a capability added by a supplier at no extra cost. None of those trip a review threshold, and each can land a decision-making system in production without a classification.

The second failure is downstream: a supplier changes the model under a managed service and the organization's approved state silently stops describing what is running. Across every sector in this guide, that is the most frequent uncontrolled change.

AI content question at intake No AI content Normal procurement path, no further governance AI enabled in existing platform Platform owner; self-certify against the assistant pattern AI procured as a service Canvas, classification, vendor due diligence in the ADR AI that acts on our systems Agent Card and machine-readable boundary, or do not deploy Cannot evidence the vendor answers Cap at Tier 2, or record an acceptance with an expiry
One question, five routes. The value is not in the depth of any route but in the fact that every purchase reaches one of them — including renewals and upgrades, which is where embedded AI actually enters an estate.

[Practice recommendation] Everything on this page is advice from this documentation rather than a requirement of IRGF. Disagreeing with it does not put you outside the framework; all practice recommendations are collected in Appendix B.

Route intake on AI content, not on contract value

One question added to procurement and change intake does more than any policy: does this purchase, renewal or upgrade include, enable or procure AI capability? Ask it of renewals and upgrades too, because that is where embedded AI usually appears.

The answer routes the work. A “yes” means a Use-Case Canvas and a classification, at whatever depth the tier requires — often very little. The point is not to add friction to purchasing; it is to stop systems entering the estate unclassified.

The questions vendors can actually answer

Long AI questionnaires produce long marketing answers. These eight are answerable, verifiable, and each one changes a decision.

Ask Why it matters What a weak answer means
Which model, at which version, and how is version identity exposed to us?Without version identity you cannot detect model change, which makes drift detection impossible.Cap the tier: you cannot evidence what is running.
How and when will you notify us of a model change, and how much notice?This clause determines whether your validated or authorized state remains knowable.Assume changes will be silent; treat behavioral monitoring as mandatory.
What are your terms on our data — training, retention, sub-processors, location?It sets D5, the lawful basis, and in several sectors whether the system may be used at all.A change in these terms later is a Material change; make sure you would hear about it.
What evaluation evidence can you provide, on what population?Vendor evaluation on a different population is a hypothesis about your deployment.You own the evaluation; budget for it.
What is the machine-readable permission boundary for anything that acts?A prose boundary cannot be compared against an IAM grant.Do not deploy agentic capability from this supplier at Tier 3–4.
What logs do we get, at what latency, and can we export them?The audit link of the agent chain and every drift comparison depends on it.Detection latency is now the supplier's choice, not yours.
What is the exit path, and what do we keep?Concentration and lock-in are governance concerns, not just commercial ones.Escalate to portfolio level; this is a dependency decision, not a purchase.
Which sub-model, tool or service does your product call, and can that change?Nested dependency is common and invisible: your supplier's supplier changes the model.Your behavioral monitoring is the only control you have left.

Cap the tier you cannot evidence

The framework's stated position on procured systems is workable and underused: where vendor due-diligence fields cannot be completed, either cap the system at Tier 2 or record a documented acceptance. Capping is usually better than accepting, because it constrains what the system may be used for rather than creating a permanent exception.

“Capped at Tier 2” has a practical meaning: it may not be deployed into a use that would score Tier 3 or 4. If the business need is genuinely Tier 3, the answer is a different supplier or a different design, not a stronger assertion.

Embedded AI in software you already run

An office suite, a service desk, a CRM or an ERP gains an assistant. Nobody procured it, no project exists, and it may be enabled by default. Three practices keep this manageable without pretending you can review everything:

  • Default-off where the platform allows it, then enable deliberately with a classification, however light.
  • A standing pattern for low-tier assistants so enabling one is self-certification rather than a review. Most of these are genuinely Tier 1.
  • A named owner per platform who is accountable for knowing what AI features exist in it, reviewed quarterly against the vendor's release notes.

Concentration is a portfolio property

Every system can clear its own gate while the estate quietly accumulates a single point of failure: one supplier providing the model, the embeddings, the vector store and the assistant framework across forty systems. No individual review sees this.

Add one standing question to the Architecture Review Board's quarterly agenda: which single supplier failure would take out the most Tier 3–4 systems, and what is the exit? Record the answer. It is the cheapest portfolio-level control in the framework.

How to tell it is working

Every practice needs a failure signal, or it is a belief. These are the ones that show this guideline has stopped operating in your organization.

Signal What it means What to do
A system is discovered in production with no classificationIntake is still routing on contract valueAdd the AI content question to procurement, renewal and change intake
A supplier model change is discovered from behaviour, not notificationThe notification clause is missing or not being honouredTreat as a Material change, and put the clause in the next renewal
Vendor due-diligence fields are blank at Tier 3The tier is not evidencedCap the tier or record an explicit acceptance with an expiry
Nobody can name the AI features enabled in a major platformEmbedded AI is entering the estate unobservedAssign a platform owner and review release notes quarterly
No one has assessed supplier concentration in a yearA portfolio-level dependency is accumulating unmonitoredPut the standing question on the board agenda