Route custom solutions to the right review lane

A governance triage tool for AI, automation, analytics, and digital products. Weighted risk scoring and hard escalation rules ensure every solution gets the right level of scrutiny — no more, no less.

Custom solutions create governance blind spots

When teams build or buy solutions outside standard channels, three risks compound quickly.

🔍

Inconsistent Triage

Without a structured intake, similar solutions get wildly different levels of review. High-risk proposals slip through while low-risk ones get buried in committee.

⚠️

Invisible Risk Accumulation

Each solution carries risk across multiple dimensions — data sensitivity, regulatory exposure, vendor dependency. Without scoring, the aggregate risk picture is invisible.

Slow, Manual Routing

Review committees waste time debating which lane a solution belongs in. Teams wait weeks for decisions that a structured framework could resolve in minutes.

Three processing lanes, one consistent framework

Every solution is scored and routed to the appropriate review lane based on risk, not opinion.

A

Rapid Triage

Low-risk solutions that fit within established guardrails. Approved with minimal documentation and fast-tracked for deployment.

  • Weighted risk score below threshold
  • No hard escalation triggers
  • Standard evidence pack
  • SLA: 2 business days
B

Standard Intake

Medium-risk solutions requiring review by subject matter experts. Structured assessment across all risk dimensions with documented rationale.

  • Moderate risk score range
  • SME review required
  • Enhanced evidence pack
  • SLA: 5 business days
C

Full Proposal

High-risk or complex solutions requiring committee review, executive sign-off, and comprehensive documentation before proceeding.

  • High risk score or escalation trigger
  • Committee review required
  • Full evidence and impact analysis
  • SLA: 10 business days

Six dimensions that determine the review lane

Each solution is scored across six weighted dimensions. Hard escalation rules override the weighted score when critical thresholds are breached.

📊

Data Sensitivity

Classification of data the solution will access, process, or store — from public datasets to regulated personal information.

⚖️

Regulatory Exposure

Applicable regulatory frameworks, compliance obligations, and jurisdictional requirements that govern the solution.

🔗

Vendor Dependency

Degree of reliance on third-party vendors, lock-in risk, and the organisation’s ability to switch or exit.

🛡️

Security Posture

Authentication, authorisation, encryption, and network exposure requirements for the solution’s deployment model.

👥

User Impact

Number of users affected, criticality to business operations, and potential disruption if the solution fails or is unavailable.

⚙️

Integration Complexity

Touchpoints with existing systems, data flows, API dependencies, and the architectural footprint of the solution.

Start a review

Use the intake form to classify and route a solution, or review the executive overview for process documentation.