Industry Overlays: How They Work
What a sector overlay may change, what it must not, and how to write one for a sector this guide does not cover.
The framework is deliberately sector-neutral. Its dimensions, gates and artifact set were designed to hold across industries, and the research report's anti-novelty test removed anything an existing standard already handled. That neutrality has a cost: a generic anchor for “serious consequence” tells a hospital and a supermarket the same thing, and they need different answers.
An overlay closes that gap without forking the framework. It re-reads the anchors against sector facts, names the regimes that already oblige something, states what each gate should additionally require, and identifies the monitoring signals that repay wiring first. It is a lens, not a variant.
[Practice recommendation] An overlay changes anchors, evidence depth and monitoring signals. It never changes the gate structure, the dimension set, or the tier matrix. If your sector appears to need a sixth dimension or a sixth gate, that is a finding worth sending to info@irgframework.org rather than a local fork.
The overlay template
Every overlay in this guide has the same eight sections, in the same order, so that two sectors can be read side by side. If you write your own, keep the structure — comparability is most of the value.
| Section | What it answers | How to fill it |
|---|---|---|
| 1. Where risk concentrates | Which parts of this sector's value chain produce high-consequence AI systems, and which look risky but are not. | Walk the value chain, not the technology inventory. Name the systems the sector keeps building. |
| 2. Regulatory interface | Which obligations already bind, and which IRGF record carries the evidence for each. | One row per regime. Never restate the obligation; state what it requires in practice and point at the record. |
| 3. Calibrating the dimensions | What a 3 and a 4 look like here, and the mis-score assessors reach for under pressure. | Five rows, one per dimension. The third column is the useful one — write the error you have actually seen. |
| 4. Gate additions | What each gate should require beyond the base definition. | Additions only. If a gate needs nothing extra, say so; an honest empty row builds trust in the full ones. |
| 5. Controls and evidence | Which controls become mandatory, and what evidence each produces. | Evidence is the test. A control that produces nothing checkable is a statement of intent. |
| 6. Runtime signals | Which drift signals to wire first, and how to respond to each. | Order matters more than coverage. Three wired signals beat a platform plan. |
| 7. Failure modes | What goes wrong in this sector specifically, how it shows, and what answers it. | Write the tell before the response. A failure mode with no detectable symptom cannot be governed. |
| 8. A ninety-day start | The sequence that produces something defensible fastest. | Eight steps at most, ordered by dependency, assuming no tooling and no programme. |
What every sector shares
Before reaching for a sector-specific answer, check whether the problem is one of these. In the framework's stress-testing these recurred across every scenario, and an overlay that spends its energy on them is not adding sector value.
- Effective autonomy exceeds recorded autonomy. Wherever a human nominally reviews, measure the override rate. See the oversight guideline.
- Reversibility is scored on the mechanism, not the consequence. The single most common scoring error in every sector.
- Procured AI is not classified. Intake routes on contract value, so AI arriving as a feature of a platform never reaches governance.
- The supplier changes the model. The most frequent uncontrolled change everywhere.
- Governance data is confidently wrong. Hand-maintained summaries drift from their sources within weeks; compile derived views or do not create them.
The overlays
Banking and capital markets
Interfacing with an existing model risk function, and the systems that sit outside its perimeter.
Insurance
Pricing, underwriting and claims as three different problems, and the enrichment data behind all three.
Healthcare delivery
Site-level authorization, population shift, and advisory systems that are not advisory.
Pharmaceuticals and life sciences
Context of use, the validated-state boundary, and continuous model change inside GxP.
Government and public sector
Evidence that has to survive publication, appeal and a change of minister.
Energy and utilities
Operational technology on one side, disconnection decisions on the other, both reaching Tier 4.
Manufacturing and supply chain
Physical action near people, and the reversibility cliff between inspection and shipping.
Retail and consumer
A wide, shallow estate where the highest tier sits in the systems nobody calls AI.
Telecommunications and media
Closed-loop automation scored against the tail, plus a content estate with its own regime.
Professional services
Confidentiality boundaries in retrieval, and obligations that attach to a person rather than a system.
Writing one for your sector
Sectors this guide does not cover include education, transport and logistics, agriculture, hospitality, real estate, defence and non-profit delivery. If you write an overlay for one, the project would publish it with attribution. What makes a contributed overlay usable:
- It names systems, not technologies. “Admissions eligibility scoring”, not “classification models”.
- Its regulatory rows point at records. The value is the mapping, not the summary of the regime.
- Its calibration column three is written from experience. The mis-scores you have actually watched happen are the part nobody else can write.
- It states what it does not know. Ranges and open questions are more useful than confident numbers with no basis.
- It respects the boundary above. Anchors, evidence and signals — not new dimensions or new gates.
Send drafts or outlines to info@irgframework.org. A two-page outline is a perfectly good start; so is a single corrected row in an overlay that is already here.