K · Practical guide

Industry Overlays: How They Work

What a sector overlay may change, what it must not, and how to write one for a sector this guide does not cover.

The framework is deliberately sector-neutral. Its dimensions, gates and artifact set were designed to hold across industries, and the research report's anti-novelty test removed anything an existing standard already handled. That neutrality has a cost: a generic anchor for “serious consequence” tells a hospital and a supermarket the same thing, and they need different answers.

An overlay closes that gap without forking the framework. It re-reads the anchors against sector facts, names the regimes that already oblige something, states what each gate should additionally require, and identifies the monitoring signals that repay wiring first. It is a lens, not a variant.

An overlay may change • how a 3 and a 4 read on each dimension • which evidence a gate additionally requires • which controls are mandatory rather than   advisory • which runtime signals are wired first • retention periods and escalation timings • the failure modes worth watching for An overlay must not change • the five dimensions or their meaning • the two-axis tier matrix or the override   floor • the gate structure or what each gate decides • the primary record set or its ownership rules • the non-duplication rule • who holds decision rights at each tier
The boundary that keeps overlays comparable. Anything in the right-hand panel that genuinely does not fit a sector is a finding about the framework, not a local adjustment — send it to the project rather than forking.

[Practice recommendation] An overlay changes anchors, evidence depth and monitoring signals. It never changes the gate structure, the dimension set, or the tier matrix. If your sector appears to need a sixth dimension or a sixth gate, that is a finding worth sending to info@irgframework.org rather than a local fork.

The overlay template

Every overlay in this guide has the same eight sections, in the same order, so that two sectors can be read side by side. If you write your own, keep the structure — comparability is most of the value.

Section What it answers How to fill it
1. Where risk concentratesWhich parts of this sector's value chain produce high-consequence AI systems, and which look risky but are not.Walk the value chain, not the technology inventory. Name the systems the sector keeps building.
2. Regulatory interfaceWhich obligations already bind, and which IRGF record carries the evidence for each.One row per regime. Never restate the obligation; state what it requires in practice and point at the record.
3. Calibrating the dimensionsWhat a 3 and a 4 look like here, and the mis-score assessors reach for under pressure.Five rows, one per dimension. The third column is the useful one — write the error you have actually seen.
4. Gate additionsWhat each gate should require beyond the base definition.Additions only. If a gate needs nothing extra, say so; an honest empty row builds trust in the full ones.
5. Controls and evidenceWhich controls become mandatory, and what evidence each produces.Evidence is the test. A control that produces nothing checkable is a statement of intent.
6. Runtime signalsWhich drift signals to wire first, and how to respond to each.Order matters more than coverage. Three wired signals beat a platform plan.
7. Failure modesWhat goes wrong in this sector specifically, how it shows, and what answers it.Write the tell before the response. A failure mode with no detectable symptom cannot be governed.
8. A ninety-day startThe sequence that produces something defensible fastest.Eight steps at most, ordered by dependency, assuming no tooling and no programme.

What every sector shares

Before reaching for a sector-specific answer, check whether the problem is one of these. In the framework's stress-testing these recurred across every scenario, and an overlay that spends its energy on them is not adding sector value.

  • Effective autonomy exceeds recorded autonomy. Wherever a human nominally reviews, measure the override rate. See the oversight guideline.
  • Reversibility is scored on the mechanism, not the consequence. The single most common scoring error in every sector.
  • Procured AI is not classified. Intake routes on contract value, so AI arriving as a feature of a platform never reaches governance.
  • The supplier changes the model. The most frequent uncontrolled change everywhere.
  • Governance data is confidently wrong. Hand-maintained summaries drift from their sources within weeks; compile derived views or do not create them.

The overlays

Writing one for your sector

Sectors this guide does not cover include education, transport and logistics, agriculture, hospitality, real estate, defence and non-profit delivery. If you write an overlay for one, the project would publish it with attribution. What makes a contributed overlay usable:

  1. It names systems, not technologies. “Admissions eligibility scoring”, not “classification models”.
  2. Its regulatory rows point at records. The value is the mapping, not the summary of the regime.
  3. Its calibration column three is written from experience. The mis-scores you have actually watched happen are the part nobody else can write.
  4. It states what it does not know. Ranges and open questions are more useful than confident numbers with no basis.
  5. It respects the boundary above. Anchors, evidence and signals — not new dimensions or new gates.

Send drafts or outlines to info@irgframework.org. A two-page outline is a perfectly good start; so is a single corrected row in an overlay that is already here.