Riaan Kleynhans · AI Transformation Engine
From AI ambition to an operating model that runs
Readiness diagnosed on evidence, gaps closed through a causal chain, risk governed under NIST AI RMF and the EU AI Act, value proven against a signed floor — seven sessions, every one signed by the people who own it.
For boards, CIOs, CDOs, CISOs and heads of transformation who need an AI programme that survives an audit, a CFO and a regulator — not another proof of concept.
What the engine holds
Four frameworks, one engine
Each framework is a library with tests, not a slide: the engine computes the score, the chain, the classification and the coverage, and prints [ TO BE COMPLETED ] where the evidence is missing.
Ten dimensions scored on evidence, five gates that must hold before a pilot, maturity bands 0–4 — the unverified self-assessment becomes the verified Diagnostic.
10 dimensions · 5 gates
Every gap states its consequence, the capability required, the interventions across people, process, technology and governance, an owner, a horizon and a binary closure criterion — closed only by the owner’s signature.
10 gap archetypes · 4 levers
Govern · Map · Measure · Manage scored per domain with a six-plane roll-up; generative-AI risks per use case; the eight-step EU AI Act classification kept separate from the internal tier. Not legal advice — a structured record for counsel.
12 NIST 600-1 risks · 12 EU AI Act high-risk areas · 33 RMF domains
A policy without a technical control is a document. Controls, owners and tests per plane, an evidence pack a regulator can open, a value ledger in six parts — and the Transformation Contract with its signature chain re-verified on read.
12 evidence sections · 6 control planes · 10 control owners
How it runs
Seven sessions, each with a question and a test
Done means facts recorded and the owners’ signatures in a hash-chained ledger — never a facilitator’s tick.
- 1Align
What must be true for this to have been worth it — and who owns each condition?
Test: The sponsor and the CFO sign the charter.
- 2Discover
What does the organisation actually run today — processes, data, systems, people, and the AI already in use?
Test: Every domain is covered by evidence with an owner; zero systems is a recorded answer.
- 3Diagnose
How ready is the organisation, dimension by dimension — and which gaps must close before anything scales?
Test: Every score has a rationale and evidence; every gap has an owner and an acceptance criterion.
- 4Prioritize
Which use cases earn a pilot, which need a foundation first, and which are prohibited?
Test: No use case is pending on classification; every risk is applicable-with-controls or has a written rationale.
- 5Design
Where does each policy become a technical control, a human procedure and evidence?
Test: No control is a document only; every control has an owner and a passed test.
- 6Prove
What value is realised, committed, forecast — and what would a CFO refuse to count?
Test: No money without a baseline and an owner; every pilot's nine gates are closed.
- 7Scale
Can an independent reviewer reconstruct this from the evidence pack — and who runs it next quarter?
Test: Live evidence in the pack; a cadence, an incident owner and a benefits owner named.
Where it applies
One engine, three layers
The same discipline whether the workflow is a content supply chain, a voice channel or a compliance process. Creative operations is one workflow in the cycle — governed, priced and measured like every other.
The processes an enterprise actually runs — marketing and creative production, customer contact, operations — inventoried, diagnosed and redesigned with their owners.
Where agents are allowed to act, under whose keys, with which gates — bounded execution, deterministic rules, human sign-off where it matters.
Identity, evidence and memory: who did what, on which record, verifiable later — the ledgers, the audit trail and the contract.
The proof
An honest engine, not a slide
Every number here is read from the code and the last verification run. Inside the engine the same pages read your ledgers. Unknown stays unknown — it prints [ TO BE COMPLETED ], never an estimate.
- Tests
- 241/241
- verified 2026-09-19
- Sessions
- 7
- 810 facilitated minutes
- Control owners
- 10
- who signs which session
- Chained ledgers
- 6
- append-only, sha256-linked
- Capabilities
- 18
- agentic · deterministic · human
- TOM lines held
- 18/23
- 5 marked open, not hidden
Start here
Assess your readiness
10 dimensions, a few minutes, no sign-up. The result is labelled unverified until the Diagnostic — and you can carry the answers straight into the engine.