Executive Summary
PRIISM is the financial authority layer of the AIPM Toolkit: it tests whether an AI initiative is financially defensible at every stage, from selection through retirement. At every gate it asks one question: is this still financially defensible, right now, at this stage? The default answer is no. An initiative does not continue because it was approved once; it earns yes at every stage, on the evidence, or it stops.
Five elements are judged at every gate: a Probabilistic Gate of five viability questions, one named owner with the authority to stop (Responsibility), an Investment test anchored on the downside, the full lifecycle cost (Sustainability), and a funded plan against Model decay. The second I in the name is the Interlock, the mechanism that runs the gate the same way regardless of who operates it. The rule sets the verdict; one named person owns and acts on it.
The discipline that is rare rather than borrowed comes from how disciplined traders manage risk: the exit is agreed before the position is taken. PRIISM applies it through pre-committed stop conditions, signed before any funding is released, so no initiative survives on sunk cost alone. A one-page visual companion, the PRIISM Master Infographic, presents this document’s content in a single view.
1. The One Question and the Default
At every stage of an AI initiative, PRIISM asks one question: is this still financially defensible, right now, at this stage? The default answer is NO. Past approval is not authorization; the default resets to no at every gate. PRIISM maintains a continuous financial review of an AI initiative across its full lifecycle, anchored on the downside, with the stop lines agreed before funds are committed.
2. The Six Letters: Five Elements and the Interlock
2.1 P · Probabilistic Gate
The five viability questions, each answered yes on evidence: a quantified problem, AI justified over a simpler option, the pessimistic case clears the hurdle, one owner named, and the data exists.
2.2 R · Responsibility
One named person is accountable for the investment, holds written authority to stop the initiative, and a named adoption owner is in place.
2.3 I · Investment
The probability-weighted expected value must clear the hurdle rate, and the worst case must stay above the loss floor. The pessimistic number is always shown on its own, so the downside is never hidden inside the average. The hurdle and floor are illustrative defaults; every adopting organization sets its own.
2.4 I · Interlock
Not a risk it checks: the second I is the mechanism that runs the gate. It is described in Section 3.
2.5 S · Sustainability
Can the organization afford to run and maintain the system, not just build it? The full lifecycle cost is present, with nothing hidden or deferred.
2.6 M · Model decay
AI models can lose accuracy over time, and it cannot be known in advance whether a given model will. Retraining is funded from day one as insurance, and any decline is kept inside an agreed limit.
No averaging. Each element passes or fails on its own; a strong result on one element never compensates for a failure on another. A single failure holds the gate at no.
3. The Interlock: Four Locks
The Interlock forces the four contributing functions’ evidence to combine into one verdict and runs the gate the same way regardless of who operates it. The five elements judge the initiative; the Interlock runs the machine. It operates through four named locks. The Evidence lock: inputs are confirmed in advance, or the gate does not convene. The Format lock: handoffs arrive usable, or they are flagged. The Conflict lock: when the contributing functions disagree, the conservative value governs. The Currency lock: the alignment record is kept current, and a stale record is itself a flag.
4. The Gates and the Five Verdicts
The one question is asked at every gate across the lifecycle: Gate 1, the business case; Gate 2, data and build; Gate 3, pre-deployment; Gate 4, go-live; and the live-operations reviews at 30, 60 and 90 days, six months, and the annual re-buy.
Every gate produces one of five verdicts. APPROVED: all five elements pass; the next gate still opens at no. CONTINUE WITH CONTROLS: caution signals; named mitigations, owners and dates; also the highest verdict available when Sustainability, Model decay or adoption owner check fails. REWORK OR DEFER: a fixable failure; the initiative pauses and a return condition is named. STOP: before or during delivery, an element fails and cannot be resolved; work ceases and the remaining budget is released. RETIRE: after go-live only; a live system no longer clears the hurdle and is decommissioned on a plan, not halted abruptly. A quick-reference table is given in Appendix B.
5. What Is Borrowed, and What Is Rare
PRIISM does not claim to invent. Stage gates, a single accountable owner, three financial scenarios, and model-drift monitoring are proven disciplines, drawn from project governance, capital budgeting, and machine-learning operations. The rare move is borrowed from how disciplined traders manage risk: a trader sets the exit before entering the trade, while judgement is clear, so that emotion and capital already committed cannot rescue a losing position later. PRIISM brings that same discipline into AI through the pre-committed stop conditions.
6. The Pre-Committed Stop Conditions
Before any funding is released, the named owner signs the exact conditions that will later stop or re-open the initiative: the specific lines, agreed in writing while judgement is clear. Hard lines are absolute; cross one and the initiative stops. Trend lines are slopes, not walls; breached across consecutive reviews they return the initiative to the funding gate, so a single poor month never ends a healthy initiative. Because the owner agreed to both before any funds were committed, there is no argument when one is crossed. This removes the strongest pressure to continue a failing initiative: the sunk cost.
7. Why It Is Not One Person’s Opinion
Two things are true at once, and they are not in tension: the rule sets the verdict, so it is not one person’s opinion, and one named person is accountable for that verdict and holds the authority to act on it, so it is never a faceless committee. The first protects against bias; the second against no one being answerable. The criteria are explicit, so the same evidence produces the same verdict no matter who applies it. The verdict is fixed by the evidence; a named owner may override the resulting action, but only in the open, with the element, the reason, a named risk owner and a mitigation on the record. At Gate 1, before funding, there is no action to override; the only cure for a failed viability check is the missing evidence. An undocumented override fails Responsibility and blocks the next gate from opening. No individual is the framework.
8. Gate 1 Stop Conditions: the Instrument
The instrument below is signed while judgement is clear, before any funds are committed. Every line is sourced from the signed business case, the cost model, the benefits baseline, or the monitoring KPIs, or it carries a labelled illustrative default. An unsourced line is invalid; blanks are set by the named owner, never assumed.
8.1 The invalidation condition
The single condition under which this investment would no longer be defensible is: _________________________________________________
If no such condition can be named, the initiative does not proceed: an investment case that cannot state what would invalidate it has not been tested.
8.2 Absolute lines
One breach acts immediately. Used only where failure is binary.
| Condition that ends the initiative | Line | Conf. | Source |
|---|---|---|---|
| Expected value fails the hurdle | Expected NPV at the hurdle rate below $0 (pessimistic NPV recorded standalone beside it) | — | Illustrative default; adopter sets the hurdle |
| Worst-case loss too large | Worst-case NPV below the loss floor | — | Illustrative default; adopter sets the floor |
| Accountability fails | Named Value Owner departs or lacks stop authority | High | Owner record |
| Data cannot support the use case | [ initiative to define ] | — | Data readiness (Qualify) |
| Safety or legal-risk floor breached | [ domain owner to set ] | — | Domain owner |
| Regulatory or compliance block | [ initiative to define ] | — | Compliance |
8.3 Trend lines
Strike one is a logged flag with a named fix; strike two the next period is a formal warning; strike three returns the initiative to the funding gate. Every strike carries an owner and a mitigation.
| Signal | Line, per review period | Conf. | Fix owner |
|---|---|---|---|
| Value realization | [ below ___% for consecutive periods ] | — | Value Owner |
| Cost run-rate | [ over plan by ___% ] | — | Cost lead / PM |
| Adoption | [ below ___ active users ] | — | Adoption Owner |
| Model drift | [ accuracy below ___ / drift past ___ ] | — | Model-health lead |
8.4 The confidence rule
Every number carries a tag set by the function that supplied it. High is hard evidence. Medium is a sound estimate. Low is a working assumption. A pass built on a Low number is a pass on probation, and it automatically tightens the review cadence until the evidence firms up.
8.5 Signature
| Field | Entry |
|---|---|
| Value Owner (named individual) | ______________________________ |
| P&L accountability confirmed | ☐ |
| Stop authority confirmed in writing | ☐ |
| Gate assessor (role, not name) | ______________________________ |
| Signed before funding | ☐ |
9. The Instrument Applied: the LexAI Case
The stop conditions were applied to a real business case, LexAI, a legal due-diligence assistant: net benefit 432,788 against a lifecycle cost of 19.0M, an 88 percent recall requirement, a base of 100 deals and 35 active users, tested against the illustrative 8 percent hurdle and the −2M loss floor. The finding was not in the filled cells but in the blanks: where the case could not state a line, the blank itself exposed what the investment case had not yet tested. The full worked example is carried in the Gate 1 Stop Conditions document.
Appendix A. Glossary
| Term | Definition |
|---|---|
| PRIISM | The financial authority layer of the AIPM Toolkit: Probabilistic Gate, Responsibility, Investment, Interlock, Sustainability, Model decay. It tests whether an AI initiative is financially defensible at every stage, from selection through retirement. |
| Financial authority layer | The layer holding the authority to stop, adjust or continue an AI initiative on financial evidence at every gate. |
| Probabilistic Gate (P) | The element carrying the five viability questions, each answered yes on evidence before funding. |
| Viability questions | The five Gate 1 checks: quantified problem, AI justified over a simpler option, pessimistic case clears, one owner named, data exists. |
| Responsibility (R) | One named person accountable for the investment with written stop authority, plus a named adoption owner. |
| Value Owner | The named individual who signs the stop conditions, owns the verdict, and holds the authority to stop. |
| Adoption owner | The named individual accountable for the system being used, not only delivered. |
| Investment (I) | The element requiring the probability-weighted expected value to clear the hurdle rate while the worst case stays above the loss floor, with the pessimistic case always shown standalone. |
| Expected NPV | The probability-weighted net present value across the three scenarios. |
| Hurdle rate | The minimum return the expected value must clear. An illustrative default; each adopter sets its own. |
| Loss floor | The maximum tolerable worst-case loss. An illustrative default; each adopter sets its own. |
| Interlock (the second I) | The mechanism that runs the gate: not a risk it checks. Four locks combine the functions’ evidence into one verdict, the same way regardless of who operates it. |
| Evidence lock | Inputs are confirmed in advance, or the gate does not convene. |
| Format lock | Handoffs arrive usable, or they are flagged. |
| Conflict lock | When the contributing functions disagree, the conservative value governs. |
| Currency lock | The alignment record is kept current; a stale record is itself a flag. |
| Sustainability (S) | The full lifecycle cost of running and maintaining the system, with nothing hidden or deferred. |
| Model decay (M) | The risk that a model loses accuracy over time; retraining is funded from day one and decline is kept inside an agreed limit. |
| Gate | A decision point at which the one question is asked and one of the five verdicts is issued. |
| Gate Assessor | The role, not a named person, that operates the gate under the Interlock. |
| The five verdicts | APPROVED; CONTINUE WITH CONTROLS; REWORK OR DEFER; STOP; RETIRE. One verdict of record per gate, owned by one named person. |
| Stop conditions | The pre-committed lines, signed before funding, that later stop or re-open the initiative. |
| Hard line | An absolute stop condition; one breach acts immediately. |
| Trend line | A slope condition; breaches across consecutive reviews return the initiative to the funding gate. |
| Invalidation condition | The single stated condition under which the investment would no longer be defensible. |
| Confidence tag | High, Medium or Low, set by the supplying function; a pass built on a Low number is a pass on probation. |
| Illustrative default | A stated example value, never binding; each adopting organisation sets its own. |
| Sunk cost | Funds already committed; under PRIISM, never a reason to continue. |
| Documented override | A named owner proceeding against the action of a no, in the open, with element, reason, risk owner and mitigation on record. An undocumented override fails Responsibility and blocks the next gate from opening. |
| No averaging | Each element passes or fails on its own; strength in one never compensates for failure in another. |
Appendix B. Gate and Verdict Quick Reference
| Gate | Tests | Reads | Verdicts available |
|---|---|---|---|
| Gate 1 · Business case | Defensible in principle; the five viability questions; no override exists here | P, R, I, S, M | APPROVED / REWORK / STOP |
| Gate 2 · Data and build | Does real data confirm the case; cost re-tested against reality | I, S, P | CONTINUE / REWORK / STOP |
| Gate 3 · Pre-deployment | Does it perform; retraining budget confirmed; the last point at which stopping is low cost | I, M, S | CONTINUE / REWORK / STOP |
| Gate 4 · Go-live | A re-test, not a launch; realised value against plan | I, M, R | APPROVED / REWORK / STOP |
| Live-ops reviews | 30/60/90-day, 6-month, annual re-buy: still defensible to run | I, S, M | SUSTAIN / RE-SCOPE / RETIRE |
Appendix C. The Four Locks Quick Reference
| Lock | Rule | Default if it fails |
|---|---|---|
| Evidence lock | Inputs are confirmed a set lead time before the gate (interval to be confirmed) | The gate does not convene |
| Format lock | Each function’s output arrives in the format the next function can use | An unformatted handoff is flagged, not accepted |
| Conflict lock | When two functions disagree on a shared input, adjudication is on the record | The conservative value governs |
| Currency lock | The vocabulary and stage record are kept current at each gate | A stale record is itself a flag |
Visual Companion — PRIISM Master Infographics



