Chapter 31. Introducing IRGF to Delivery Teams
The framework’s adoption risk is not technical. It is that the people it governs conclude it is overhead.
31.1 The objections you will actually get
Six objections recur. Each has a legitimate core, and answering the legitimate part is more effective than defending the framework.
“This will slow us down.” Partly true and worth conceding. Tier 3–4 work will be slower, deliberately. Tier 1–2 work should be faster once patterns and self-certification are in place, and that is the claim to make and then evidence. What you must not do is promise overall speed improvement in month one, because the first quarter is slower for everyone.
“We already do this.” Often partly true. Most organizations have architecture review, some risk assessment, and some testing. The honest answer is that IRGF connects those rather than replacing them, and the specific thing that is usually missing is a single tier that drives all of them consistently. Ask the team to run the seventeen questions against one of their own systems; the gaps make the argument better than you can.
“Our system is low risk.” Frequently correct, and the framework agrees: Tier 1–2 is self-service. The response is not to argue but to run the scoring, because the scoring is what establishes the claim. A team that scores its own system honestly and lands at Tier 1 has just used the framework correctly.
“The gate will reject us.” Usually the fear is delay, not rejection. Publishing gate lead times and outcome distributions defuses this faster than reassurance does.
“We’re just piloting.” The most dangerous objection, because it sounds reasonable. Pilots reach production. The answer is the deployment-state model in Chapter 5: pilot is a state with an expiry, not an exemption.
“The vendor handles governance.” Common for procured AI and almost never accurate at the level the enterprise needs. The vendor governs their model; you govern its use in your context, including the decisions it influences and the data it processes.
31.2 What to do in the first ninety days
Make the first experience good. The first three teams through the process shape its reputation permanently. Over-support them: sit with them for the scoring, pre-review their ADR, and make sure the first gate runs to time.
Show a Tier 1 pass early. The most persuasive artifact is a system that went through the framework quickly because it was genuinely low risk. It demonstrates proportionality is real, which no amount of policy text achieves.
Publish lead times from the start. Uncertainty about how long governance takes causes more avoidance than the actual duration does.
Never let a gate be the first time a team hears about a requirement. If a gate rejects work for a requirement the team did not know existed, you have lost that team and everyone they talk to. The requirements belong in the intake conversation.
31.3 What to say about the framework’s status
You will be asked whether this is a standard. It is not, and the answer should be direct: IRGF is a designed framework that has been adversarially stress-tested but never deployed in a real organization, and it defers to the actual standards — NIST AI RMF, ISO/IEC 42001, ISO/IEC 23894, COBIT, ISO/IEC 27001 — for the things those standards already cover.
That answer is stronger than a claim of authority, for two reasons. It is accurate, and accuracy survives the first person who checks. And it invites teams to treat the thresholds as adjustable, which is exactly right, because they are reasoned defaults awaiting your calibration data.
[Practice recommendation] Make the limitations register (Appendix A) available to delivery teams rather than restricting it to the governance function. A framework that publishes its own weaknesses attracts better challenge, and the challenge is how the thresholds get calibrated.
31.4 Signs adoption is going well
Table 80.
| Signal | What it indicates |
|---|---|
| Teams arrive at G1 having already scored themselves | Classification has become routine rather than imposed |
| Scoring disputes are about anchors, not about whether to score | The mechanism is accepted; only calibration is contested |
| Tier 1 systems pass in days | Proportionality is real |
| Exceptions are requested rather than taken | The path exists and is usable |
| Teams cite pattern conformance unprompted | The library is providing value, not just constraint |
| Someone challenges a threshold with data | The framework is being calibrated rather than obeyed |
The last signal is the strongest. A framework nobody challenges is a framework nobody is really using.