K · Practical guide

The IRGF Practical Guide

The part of the documentation you use with a system in front of you: sector overlays, fill-in templates, working guidelines and checklists you can print.

Chapters 1 to 37 explain the framework: what each gate decides, how the dimensions are scored, why the artifact set is the size it is. This part assumes you have read enough of that to start, and answers the next question — what do I actually write down, in my sector, this week.

Nothing here overrides the chapters. Where the Practical Guide and a chapter appear to disagree, the chapter governs and the discrepancy is a defect worth reporting. Everything in this part is advice at the level the framework marks [Practice recommendation]: useful defaults, not requirements of IRGF.

Industry overlays What changes when the sector is banking, healthcare, government, energy — anchors, evidence depth, monitoring signals. Never the gate structure. Templates The sixteen primary records as fill-in forms, with a filled example and a plain-text version to paste into your own tooling. Guidelines How to do the six things that decide whether any of it works: scoring, evidence, oversight, procurement, generative systems, proportionality. Checklists Printable, tickable lists for gates, classification, data, assurance, agents, runtime and change. Ticks are saved in your browser.
Four sets, one purpose. Each set answers a different question about the same system: where does my sector read differently, what do I write down, how do I do it well, and did I miss anything.

The four sets

If this is your first week

The order below produces something defensible fastest. It assumes one architect and one risk lead, part-time, with no tooling.

  1. Read Chapter 27, the minimum viable framework, and decide what you are not doing this year.
  2. Open your sector's overlay and read section 1 and section 3. Twenty minutes.
  3. Inventory what exists. Use the classification checklist and expect the inventory to be the hardest part.
  4. Score three systems with the Risk Classification Record, with an independent countersigner in the room.
  5. Run one G3 dry run on a system already in production. The gap list is your real backlog.
  6. Wire one runtime signal — the one your overlay names first. Not a platform, one signal.

Status caveat. Everything in this part inherits the status of the framework itself: IRGF has not been deployed in a real organization. The sector overlays are reasoned from published regulation and common practice, not from field calibration, and the tier examples in them are illustrations of how the anchors read — not classifications you can adopt. Score your own systems. If a row in an overlay is wrong for your organization, that is exactly the feedback the project needs.

Conventions in this part

Convention Meaning
Tier badges in diagramsThe tier systems of that kind typically reach in that sector. Not a shortcut around scoring, and not a floor.
Illustrative D1–D5 rowsHow the anchors in Chapter 6 read against sector facts. A range means it depends on a design choice named in the same row.
“The tell” and “the response”Failure modes are written as a detectable symptom and the action that answers it, because a failure mode you cannot detect is not actionable.
Ticks in checklistsStored in your browser only, per checklist. Nothing is transmitted; clearing site data clears them.
Plain-text template blocksCopyable versions for pasting into a wiki, a form builder or an issue template. The HTML page is not the record.