AI Governance, Risk & Red Teaming
Visionary · M1 · lesson 1 of 14 · in progress
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
3-Year AI Risk Function Roadmap - Building the Capability
📖
now learning

3-Year AI Risk Function Roadmap - Building the Capability

15 min

Acme's Q3 2026 board AI subcommittee opens with the chair sliding two documents back to Maya Okafor, the newly-appointed Chief AI Risk Officer. The first is the 3-year AI Risk Appetite plan Maya delivered in May (lesson 098). The second is the AI Risk Officer mandate ratified in March (lesson 097). The chair leans forward: "Maya, the appetite plan tells us what risk we will accept. The mandate tells us who decides. Neither tells us what the AI Risk function looks like in 2028. I want the capability build: the maturity ladder, the FTE ramp, the sub-function integration, the ROI proof. Not appetite. Not authority. Capability. Show me the 12 quarters from Q4 2026 to Q3 2029: quarter by quarter, dimension by dimension, spend by spend, milestone by milestone. The audit committee wants the same view next month. You have six weeks." Maya has the appetite envelope (€17.9M three-year), the CAIRO mandate, the AI Governance Committee charter, the RACI, the Conformity Assessment Function design from lesson 077, and 105 lessons of operating doctrine. What she does not yet have is the function-capability roadmap: how the AI Risk function itself matures from a Year-1 skeleton (CAIRO + 8 FTE) through a Year-2 operating-maturity build (18-25 FTE) to a Year-3 strategic-differentiation posture (30-40 FTE), scored on a 5-dimensional CMMI-style maturity model, tracked through 12 quarterly milestones, defended on a 10-KPI dashboard, and proven on direct + indirect + strategic ROI. This lesson is the L5 executive-tier framework for the 3-year AI Risk function roadmap: distinct from the appetite plan, distinct from the mandate, sitting alongside both as the capability build that turns appetite-and-authority into operating evidence the regulator, the auditor, and the credit-rating agency will all test in 2027-2028.

Why Appetite + Mandate Are Not the Function Roadmap

The L5 boardroom error in 2026 is treating the AIRA plan (lesson 098) and the CAIRO mandate (lesson 097) as if together they constitute the function roadmap. They do not. The appetite plan declares the strategic envelope: capital, vendor mix, regulator posture, geographic ladder. The mandate declares authority: who decides, who reports to whom, what veto rights apply. Both are necessary. Neither is sufficient. The function roadmap is the third instrument: how the AI Risk function itself, as an organizational capability, matures from a Year-1 foundation through Year-2 operating maturity to Year-3 strategic differentiation. The roadmap is what the board uses to test whether the appetite envelope is actually being absorbed by an operating function that will pass examination.

The distinction surfaces sharply in 2026 because the EU AI Act, ISO 42001, SR 11-7, SOC 2 + AI, and Solvency II ORSA all probe function capability, not just declared appetite. The ISO 42001 Stage 2 auditor (lesson 030) tests Clause 7 resources, Clause 9 performance evaluation, and Annex A.3 organizational roles by asking: "Show me the org chart. Show me the role descriptions. Show me the named accountable individual for each Annex A control. Show me the FTE you actually have in seat versus the FTE you planned." The Federal Reserve SR 11-7 examiner asks the parallel question about Model Risk Management staffing. The CFPB UDAAP examiner asks about consumer-protection AI oversight staffing. The AI Office in 2027-2028 examinations will ask the same question through Article 17 QMS evidence. A firm with a beautiful appetite plan and a ratified CAIRO mandate but a function that is two FTE behind the ramp will fail the staffing-evidence test.

The function roadmap is structurally different from the appetite plan in five ways. (1) The unit of analysis is the sub-function (Conformity Assessment Function, AI Risk Office, Red Team, Model Risk Management + Independent Model Validation, Internal AI Audit), not the appetite dimension. (2) The maturity model is CMMI-style 1-5 per dimension (governance, policy + process, technology + tooling, people + culture, evidence + assurance), not appetite-ceiling values. (3) The investment profile is shaped by sub-function ramp curves (foundation cost-heavy Year 1; operating-maturity peak Year 2; steady-state plus strategic projects Year 3), not by appetite trajectory. (4) The ROI quantification combines direct (penalties avoided), indirect (insurance + procurement + talent), and strategic (regulator + standards + brand) returns. (5) The cadence is 12 quarterly milestones with named dependencies, not the annual + semi-annual board ratification cycle.

The 2026 mature firm runs three instruments in parallel: appetite plan (lesson 098), CAIRO mandate (lesson 097), and function roadmap (this lesson). The three are presented together at the board AI subcommittee and the audit committee. The board reads appetite. The CAIRO operates the mandate. The audit committee tests function maturity. The regulator examines all three in sequence. Missing any one of the three opens a known examination finding.

Year-by-Year Function Maturity - Foundation, Operating Maturity, Strategic Differentiation

The function matures across three named years, each with a distinct organizational shape, capital profile, and milestone density. The named years are not calendar years. They are mandate years from CAIRO appointment forward. For Acme, CAIRO Maya was appointed March 2026 (lesson 097); Year 1 runs Q2 2026 - Q1 2027; Year 2 runs Q2 2027 - Q1 2028; Year 3 runs Q2 2028 - Q1 2029. The roadmap presented to the Q3 2026 board AI subcommittee covers the 12 quarters from Q4 2026 through Q3 2029.

Year 1 - Foundation (8-10 FTE, €4-7M). The foundation year stands up the governance core and the first-pass operating instruments. The named hires: CAIRO (1) + AI Risk Officers (2) + FRIA program lead (1) + Annex IV TDF lead (1) + Article 4 literacy lead (1) + AI inventory analyst (1) + Article 72 PMM lead (1), eight FTE for a mid-sized firm; add Model Risk Manager (1) + Article 73 incident-response lead (1) for the ten-FTE mid-to-large profile. The named deliverables: AI Governance Committee charter ratified (lesson 015); CAIRO mandate ratified (lesson 097); annual AIRA v1 ratified (lesson 074); RACI codified (lesson 047); AI inventory at audit-ready depth (lesson 045); Annex IV Technical Documentation File complete for top-3 Tier-1 systems (lesson 028); Article 27 FRIA complete for tier-1 Annex III deployer systems (lesson 026); Conformity Assessment Function stood up (lesson 077); Article 4 literacy program at 85% in-scope coverage (lesson 014); first-pass red team baseline against OWASP LLM Top 10 + MITRE ATLAS (lesson 053). The named outcome: ISO 42001 readiness assessment closed in Q4 (Stage 1 in Year 2 Q2). The foundation-year function is cost-heavy because hiring lead times and tooling procurement front-load capital before operating leverage shows up.

Year 2 - Operating Maturity (18-25 FTE, €7-12M). The operating-maturity year scales the second-line and third-line sub-functions and absorbs the heaviest tooling + certification spend. The named hires: AI Red Team to full 6 FTE (lesson 081, Team Lead + Adversarial Engineer + ML Security Engineer + Application Security Engineer + Detection + Response Engineer + Operations Analyst); Model Risk Management + Independent Model Validation to 4-6 FTE (lesson 067 + lesson 070); Internal AI Audit to 2-3 FTE (lesson 093, first cycle planning); CAIRO office to 4-5 FTE (CAIRO + AI Risk Officers expand to 4 + Chief of Staff); FRIA + Article 72 PMM + Article 73 each to 2 FTE. The named deliverables: ISO 42001 Stage 1 in Q2 of Year 2 (Q6 of roadmap); ISO 42001 Stage 2 in Q4 of Year 2 (Q8 of roadmap) with certificate issued; SOC 2 + AI Type I in Q3 of Year 2 (Q7 of roadmap); first Article 73 tabletop drill in Q3 of Year 2 (lesson 037); first IMV cycle complete in Q1 of Year 2 (Q5 of roadmap); Article 72 PMM live for top-5 systems in Q1 of Year 2 (lesson 080); first ISO 42001 + SOC 2 + AI external attestation; first notified body engagement if Annex III conformity-assessment voluntary module applies (lesson 057). The named outcome: function operates at CMMI Level 2-3 across the five dimensions; first complete audit-defensibility evidence package.

Year 3 - Strategic Differentiation (30-40 FTE, €5-8M run-rate plus strategic projects). The strategic-differentiation year turns operating maturity into competitive posture and demonstrable ROI. The named hires: Internal AI Audit to full 4-5 FTE at full cycle (lesson 093); Standards + Regulatory Affairs lead added to CAIRO office (lesson 105: public testimony, comment letters, ISO JTC1 SC42 + CEN-CENELEC engagement); Red Team continues at 6-8 FTE with one rotational external co-source engagement per quarter; MRM + IMV at 5-7 FTE with full quarterly validation cycle; CAIRO office at 5-6 FTE; FRIA + PMM + Article 73 each at 2-3 FTE; AI inventory + Conformity Assessment Function at 3-4 FTE. The named deliverables: SOC 2 + AI Type II first issuance in Q1 of Year 3 (Q9 of roadmap) on the 12-month examination window opened in Q3 of Year 2 (Q7); first full Internal AI Audit annual plan delivered Q2 of Year 3 (Q10 of roadmap); CAIRO secures AI Office working-group seat or ISO JTC1 SC42 contributor status; full board-cleared 6-slide quarterly standard operating (lesson 100); ISO 42001 first surveillance audit passes clean in Q3 of Year 3 (Q11). The named outcome: function reports clean independence + measurable ROI; CMMI Level 3-4 across all five dimensions; CAIRO standards-shaping presence externally.

The headcount ramp is not linear because the second-line + third-line sub-functions are the operating-maturity build. Year-1 hiring is concentrated in first-line + CAIRO office. Year-2 hiring is concentrated in second-line MRM + IMV + Red Team + tooling. Year-3 hiring is concentrated in third-line Internal AI Audit + Standards + Regulatory Affairs. A firm that front-loads Year 1 spend on tooling and consulting without Year-2 talent ramp budgeted is the single most common roadmap failure (mistake 1 in the failures section below).

Five-Dimensional CMMI-Style Maturity Scoring

The function is scored on five dimensions, each at CMMI-equivalent Levels 1-5 (Initial → Managed → Defined → Quantitatively Managed → Optimizing). The scoring is the board AI subcommittee's quantitative test of whether the function is actually advancing or simply absorbing capital without capability gain. Each dimension carries named evidence criteria; the score is set by an independent reviewer (Internal AI Audit lead from Year 2, or external co-source in Year 1) and ratified at the semi-annual board AI subcommittee review.

Dimension 1 - Governance. Level 1 (Initial): governance ad-hoc, no committee, no charter. Level 2 (Managed): AI Governance Committee operating, charter ratified, quarterly cadence documented. Level 3 (Defined): CAIRO mandate ratified, AIGC + AI Risk Office + RACI codified, board AI subcommittee operating with documented agenda. Level 4 (Quantitatively Managed): governance KPIs measured (AIGC decision quality score, board engagement consistency, escalation timeliness), independent assurance of governance operating effectiveness. Level 5 (Optimizing): governance benchmarked against peer firms and regulatory expectations; continuous-improvement program with documented annual refresh. Year-1 target: Level 2; Year-2 target: Level 3; Year-3 target: Level 4.

Dimension 2 - Policy + Process. Level 1: policies ad-hoc or absent. Level 2: AI acceptable use, vendor risk, incident response, intake, model lifecycle policies documented and approved. Level 3: policies integrated with operating runbooks (FRIA workflow, Annex IV TDF generation, Article 72 PMM cadence, Article 73 incident-response runbook, IMV cycle); RACI per process step. Level 4: process KPIs measured (FRIA completion rate, TDF coverage, PMM closure rate, Article 73 timeliness); independent assurance of process operating effectiveness. Level 5: processes benchmarked, continuous-improvement loop integrated with NIST AI RMF Manage and ISO 42001 Clause 10. Year-1 target: Level 2; Year-2 target: Level 3; Year-3 target: Level 4.

Dimension 3 - Technology + Tooling. Level 1: spreadsheet-driven; no platform. Level 2: AI inventory platform deployed; model registry operating; basic Article 72 PMM ingestion. Level 3: integrated tooling stack, inventory + registry + PMM + red team tooling (PyRIT + garak + bespoke harness per lesson 051 + 052) + FRIA workflow + Annex IV TDF generation; tooling RACI named. Level 4: tooling KPIs measured (tooling uptime, ingestion latency, evidence-retrieval time-to-evidence); independent assurance of tooling controls. Level 5: tooling benchmarked, tooling-driven continuous improvement, integrated MLBOM + SBOM-AI supply-chain tooling (lesson 091 + emerging SLSA-AI). Year-1 target: Level 1-2; Year-2 target: Level 3; Year-3 target: Level 4.

Dimension 4 - People + Culture. Level 1: no named accountable individuals; no Article 4 literacy. Level 2: CAIRO + AI Risk Officers named; Article 4 literacy program at 85%+ in-scope coverage. Level 3: full sub-function staffing per ramp curve; literacy by role with assessment evidence (lesson 016); rotational program operating; retention compensation framework. Level 4: people KPIs measured (literacy assessment scores by role, retention rate by named L5 role, rotational program throughput); independent assurance of people controls. Level 5: people development benchmarked; university partnerships operating; CAIRO public profile development (conference speaking, working-group participation, publications). Year-1 target: Level 2; Year-2 target: Level 3; Year-3 target: Level 4.

Dimension 5 - Evidence + Assurance. Level 1: no evidence repository; audit findings repeat. Level 2: evidence repository operating with version control; first ISO 42001 readiness assessment closed. Level 3: ISO 42001 certificate issued (Stage 1 + Stage 2); SOC 2 + AI Type I attestation issued; Annex IV TDF for all Tier-1 systems; first Article 73 tabletop drill complete; first IMV cycle complete. Level 4: SOC 2 + AI Type II issued; ISO 42001 surveillance clean; Internal AI Audit annual plan operating; FAIR-quantified residual loss reduction demonstrated quarter-over-quarter. Level 5: external standards-shaping (AI Office working group, ISO JTC1 SC42 contributor, CEN-CENELEC participation); independent benchmarking against peer firms; public trust pages and model cards. Year-1 target: Level 2; Year-2 target: Level 3; Year-3 target: Level 4.

The five-dimensional CMMI scoring is presented at the board AI subcommittee as a single radar chart with the year-end target and the current reading per dimension. The radar chart visualizes function-balance, a function that scores Level 4 on Technology but Level 2 on People is unbalanced and will fail a regulator examination on the staffing-evidence test even if the tooling is impressive. The balanced-maturity target by Year 3 is Level 3-4 across all five dimensions, with no single dimension below Level 3.

12-Quarter Milestone Calendar - Q1 through Q12

The roadmap is operationalized through 12 quarterly milestones, each with a named deliverable, a named accountable executive, a named dependency on prior milestones, and a named test of completion. The calendar runs from Q1 (the first full quarter after CAIRO appointment) through Q12 (end of Year 3). For Acme with CAIRO Maya appointed March 2026, Q1 = Q2 2026, Q12 = Q1 2029.

  • Q1 - Charter + RACI + AIRA v1. AIGC charter ratified by board; RACI codified across intake-to-decommission lifecycle (lesson 047); annual AIRA v1 ratified by board (lesson 074); CAIRO mandate ratified (lesson 097). Accountable: CAIRO + board chair. Dependency: prior board approval to stand up function. Test: signed artifacts in board minutes.
  • Q2 - Annex IV TDF for top-3 Tier-1 systems. Technical Documentation File complete for the three highest-risk systems per inventory (lesson 028). Accountable: CAIRO + Annex IV TDF lead. Dependency: AI inventory at audit-ready depth (Q1). Test: TDF reviewed by external advisor and accepted as Stage-1-readiness-grade evidence.
  • Q3 - ISO 42001 readiness + first FRIA. ISO 42001 readiness assessment closed (Clause 4-10 + Annex A gap closure plan documented, lesson 030); first Article 27 FRIA for an Annex III deployer system complete (lesson 026). Accountable: CAIRO + Conformity Assessment Function lead. Dependency: Annex IV TDF for top-3 systems (Q2). Test: readiness assessment report + signed FRIA.
  • Q4 - First red team engagement; CAF first 4 KPI dashboard. First-pass red team baseline against OWASP LLM Top 10 + MITRE ATLAS (lesson 053); Conformity Assessment Function publishes first 4 KPI dashboard (FRIA completion rate, Annex IV TDF coverage, Article 4 literacy coverage, AI inventory coverage). Accountable: CAIRO + Red Team Lead + CAF lead. Dependency: red team tooling (PyRIT + garak), CAF stood up (Q1-Q3). Test: red team findings report + KPI dashboard published to AIGC.
  • Q5 - First IMV cycle; Article 72 PMM live for top-5. First Independent Model Validation cycle complete for a high-risk system (lesson 070); Article 72 Post-Market Monitoring live for top-5 systems with telemetry ingestion (lesson 080). Accountable: CAIRO + MRM + IMV lead + Article 72 PMM lead. Dependency: MRM staffing (Year-2 hire), PMM tooling. Test: IMV validation report + PMM weekly anomaly review evidence.
  • Q6 - ISO 42001 Stage 1. ISO 42001 Stage 1 audit complete with findings remediation plan (lesson 030). Accountable: CAIRO + Conformity Assessment Function lead. Dependency: ISO 42001 readiness (Q3) + ongoing Annex A control build-out (Q3-Q5). Test: Stage 1 report from external certification body (BSI, Schellman, A-LIGN, or equivalent).
  • Q7 - SOC 2 + AI Type I; first Article 73 tabletop drill. SOC 2 + AI Type I attestation issued (lesson 034); first Article 73 serious-incident tabletop drill complete (lesson 037). Accountable: CAIRO + Article 73 incident-response lead + external attestor. Dependency: ISO 42001 Stage 1 (Q6), control evidence inventory. Test: SOC 2 + AI Type I report + Article 73 drill post-mortem.
  • Q8 - ISO 42001 Stage 2 + certificate. ISO 42001 Stage 2 audit complete; certificate issued by external certification body; surveillance plan ratified for Years 2-3. Accountable: CAIRO + CAF lead + certification body. Dependency: Stage 1 findings closed (Q6-Q7). Test: ISO 42001 certificate, surveillance plan signed.
  • Q9 - SOC 2 + AI Type II window starts. 12-month Type II examination window opens (closes Q12 with Type II report issuance). Accountable: CAIRO + external attestor. Dependency: SOC 2 + AI Type I issued (Q7) + sustained control operating effectiveness. Test: Type II window confirmation letter from attestor.
  • Q10 - Internal AI Audit annual plan v1. First full Internal AI Audit annual plan delivered to audit committee (lesson 093); third-line independence confirmed; quarterly review cadence operating. Accountable: Internal AI Audit lead + audit committee chair. Dependency: Internal AI Audit function staffed (Year-3 hire), operating maturity at CMMI Level 3. Test: annual plan ratified by audit committee.
  • Q11 - Notified body engagement (if applicable). For firms with Annex III voluntary third-party conformity assessment exposure: notified body selected, engagement letter signed, conformity assessment scoped (lesson 057). For firms with internal-control posture only: Article 47 Declaration of Conformity refresh cycle ratified (lesson 105). Accountable: CAIRO + General Counsel + CAF lead. Dependency: ISO 42001 surveillance clean (Q11 or earlier). Test: signed engagement letter or refreshed declaration.
  • Q12 - Full board-cleared 6-slide standard. Quarterly AI risk board brief 6-slide standard operating at full audit-defensible quality (lesson 100); SOC 2 + AI Type II report issued; ISO 42001 surveillance audit complete; FAIR-quantified residual loss reduction demonstrated cumulative across 12 quarters. Accountable: CAIRO + board AI subcommittee chair. Dependency: all prior milestones. Test: board minutes ratifying 6-slide standard + Type II report + surveillance report + FAIR cumulative trajectory.

The 12-quarter calendar is the operating instrument the CAIRO uses to track function maturity. Each quarter's milestone has a named dependency on prior milestones, Q6 ISO 42001 Stage 1 depends on Q3 readiness; Q8 Stage 2 depends on Q6 Stage 1 findings closed; Q9 Type II window depends on Q7 Type I issued. Missing a quarter ripples downstream: a Q3 readiness slip pushes Stage 1 to Q7, Stage 2 to Q9, Type II window to Q10, Type II report to Q1 of Year 4. The board AI subcommittee tracks the calendar at every meeting and ratifies slip recovery plans when milestones drift.

Investment Profile, ROI Quantification, and 10-KPI Function Dashboard

The function roadmap carries three quantitative instruments that the audit committee and the CFO co-test: the investment profile (capital deployed per year by sub-function), the ROI quantification (direct + indirect + strategic returns), and the 10-KPI function maturity dashboard (operating KPIs that prove function effectiveness quarter-over-quarter).

Investment profile. The three-year capital envelope is shaped by sub-function ramp curves. Year 1 €4-7M is foundation cost-heavy: CAIRO office stand-up + AIGC operating + Conformity Assessment Function build + first-pass tooling procurement + Article 4 literacy + Annex IV TDF generation + first FRIA cycles + first red team baseline. Typical Year-1 breakdown for a €10B-turnover firm: CAIRO office (€1.4-1.8M); CAF + Annex IV TDF + FRIA program (€0.9-1.4M); Article 4 literacy + AI inventory platform (€0.6-1.0M); red team baseline + tooling procurement (€0.7-1.2M); MRM + IMV initial hires (€0.5-0.9M); external advisory + co-source bench setup (€0.7-1.0M). Year 2 €7-12M is operating-maturity peak: full red team build (€1.5-2.5M), MRM + IMV scale-up (€1.5-2.5M), ISO 42001 + SOC 2 + AI certification spend (€0.8-1.4M), Article 72 PMM tooling at scale (€0.6-1.0M), notified body engagement if applicable (€0.5-1.2M), Internal AI Audit stand-up (€0.5-0.9M), CAIRO office expansion (€0.6-1.0M), rotational program (€0.4-0.7M), continuous tooling enhancements (€0.6-1.0M). Year 3 €5-8M is steady-state plus strategic projects: full FTE run-rate (€4-6M), strategic projects (standards engagement, public trust pages, customer model cards, AI Office working group seat, €0.7-1.2M), surveillance + recertification spend (€0.4-0.8M). The three-year envelope clusters at €16-27M for a €10B-turnover firm; basis-points of group revenue clusters at 10-18 bps in Year 1, 14-24 bps in Year 2 (peak), 10-16 bps in Year 3 (run-rate plus strategic).

ROI quantification, three categories. Direct ROI: penalties avoided. The function maturity reduces aggregate Article 99 exposure 40-65% per FAIR (lesson 086); for a firm with a €11.8M Q1 2026 ALE_95 baseline, that is a €4.7-7.7M annual residual loss expectancy reduction by Year 3. Fines avoided in shadow incidents, incidents that would have triggered Article 73 reporting and Article 99 fines but were detected and contained pre-incident through red team + IMV + PMM. Indirect ROI: cyber insurance premium reduction (typically 5-15% premium reduction once SOC 2 + AI Type II is issued and ISO 42001 certificate is in place, per 2026 broker market data); procurement win-rate uplift (B2B prospects increasingly require ISO 42001 + SOC 2 + AI in RFPs; firms with both in 2026 report 15-30% RFP win-rate uplift versus firms without); talent attraction (CAIRO-led function with public profile attracts AI risk talent in a thin market, reducing hiring costs and time-to-hire). Strategic ROI: regulator-engagement quality (proactive Y1 → Y3 engagement reduces enforcement multipliers when incidents occur, per ENISA AI Threat Landscape 2026 surveillance data); standards-shaping influence (AI Office working-group seat or ISO JTC1 SC42 contributor status sets harmonization defaults that match the firm's operating posture); brand-trust signal (public trust pages + model cards + ISO 42001 + SOC 2 + AI Type II differentiate the firm in consumer-facing and B2B markets). The audit committee tests all three ROI categories at the semi-annual function-roadmap review.

10-KPI function maturity dashboard. The function publishes a 10-KPI dashboard at every AIGC monthly review and rolls it up to the board AI subcommittee semi-annually. (1) AI inventory coverage, % of in-scope systems with current model card and risk tier classification. (2) FRIA completion rate, % of Annex III deployer systems with current Article 27 FRIA on file. (3) Red team coverage, % of high-risk systems with red team engagement in last 6 months. (4) IMV closure rate, % of independent model validations closed within target SLA (typically 90 days from initiation). (5) Article 73 timeliness, % of serious incidents reported within 15-day Article 73 window. (6) ISO 42001 surveillance findings, count and severity of findings from most recent surveillance audit. (7) SOC 2 + AI exception count, count of SOC 2 + AI exceptions and remediation status. (8) Vendor DDQ throughput, average days to complete vendor due diligence questionnaire cycle (lesson 089). (9) AIGC decision quality, % of AIGC decisions executed within ratified RACI, measured against post-decision review. (10) Board-engagement consistency, % of scheduled board AI subcommittee meetings held with full agenda coverage and quorum. Each KPI carries a Year-1, Year-2, Year-3 target. Year-1 targets are foundation (inventory ≥85%, FRIA ≥70%, red team ≥40%); Year-2 targets are operating maturity (inventory ≥95%, FRIA ≥90%, red team ≥75%); Year-3 targets are differentiation (inventory ≥98%, FRIA 100%, red team ≥90%).

Six Common Roadmap Failures and Acme Worked Example

Six failures recur in 2026-2028 AI Risk function roadmaps. Each is predictable and fixable in a single planning cycle.

  • (1) Front-loading Year 1 spend without Year 2 talent ramp budgeted. Firm spends €6M in Year 1 on tooling + consulting + external advisors but did not budget Year 2 second-line hiring (Red Team 6 FTE, MRM + IMV 4-6 FTE, Internal AI Audit 2-3 FTE). Year 2 capital request is rejected by CFO as "unfunded growth." Function plateaus at Year 1 maturity. Fix: investment profile front-loads talent ramp in the multi-year envelope before front-loading tooling; KPI-tied unlock gates require Year 2 hiring plan ratified at Year 1 origination.
  • (2) Skipping Internal AI Audit (third-line) buildout. Firm builds AIGC + CAIRO + AI Risk Office + Red Team + MRM but does not stand up Internal AI Audit (lesson 093) until forced by external auditor or regulator. The third-line gap is the standard ISO 42001 Stage 2 finding and the standard SR 11-7 examination finding for financial-services firms. Fix: Internal AI Audit ramp is named in Year 2-3 of the roadmap with named FTE, annual plan delivery, and quarterly review cadence; independence from CAIRO is structural (reports to Chief Audit Executive, dotted-line to Audit Committee chair).
  • (3) Treating ISO 42001 as one-off, no surveillance maintenance. Firm achieves ISO 42001 Stage 2 certificate in Year 2 Q8 and reduces CAF + evidence management capacity. Year-3 surveillance audit finds material drift in control operating effectiveness; certificate suspended or non-conformity raised. Fix: surveillance + recertification budget is named in Year 3 envelope; CAF + evidence management retain Year-2 capacity; quarterly internal review against Annex A controls operates continuously.
  • (4) Red team without MRM coordination (siloed). Red Team operates with full 6-FTE build but its findings are not integrated with MRM + IMV cycle. Red team finds prompt injection vulnerability; MRM does not know; IMV does not re-validate; model deploys to production with the finding outstanding. Fix: red team findings flow through MRM intake; MRM re-validation is a named dependency on red team finding closure; AIGC ratifies the integration runbook in Year 2 Q5 (when MRM + Red Team are both staffed).
  • (5) Function reports to CIO, independence breach Year 1 corrupts Year 2-3. CAIRO reports to Chief Information Officer rather than CEO or Chief Risk Officer (lesson 097). Year-1 independence breach is invisible because function is small. Year-2 ISO 42001 Stage 2 finds the reporting line as a Clause 5.1 leadership finding. Year-3 Internal AI Audit cannot operate third-line independence because the second-line CAIRO is structurally captured by the first-line CIO. The roadmap is fundamentally corrupted at origination. Fix: CAIRO reports to CEO or CRO with dotted-line to board AI subcommittee chair from Year 1; the reporting line is named in the mandate ratified at Q1.
  • (6) No investment-tied unlock gates, capital flows without accountability. CFO approves Year 1 / Year 2 / Year 3 capital at planning origination without KPI-tied unlock gates. Year-1 KPIs miss; Year-2 capital releases anyway; function under-delivers on Year-2 KPIs; Year-3 capital releases anyway; function plateaus at Year-1 maturity by Year 3. Fix: investment profile uses KPI-tied unlock gates (lesson 098); Year-2 capital releases only on Year-1 KPI completion; Year-3 only on Year-2 KPI completion; CFO + Audit Committee chair co-ratify the unlock-gate KPIs at planning origination.

Acme worked example, Maya's 6-week delivery. Maya's roadmap to the Q4 2026 board AI subcommittee covers 12 quarters from Q4 2026 (CAIRO Q1) to Q3 2029 (CAIRO Q12). Year 1 (Q1-Q4): foundation. CAIRO + 2 AI Risk Officers + FRIA + Annex IV TDF + Article 4 literacy + AI inventory + PMM leads + 1 MRM = 9 FTE total. Year-1 spend €5.4M (11 bps of €10B revenue). Milestones: Q1 charter + RACI + AIRA v1 ratified; Q2 Annex IV TDF for top-3 of 11 Tier-1 systems; Q3 ISO 42001 readiness + first FRIA for Annex III §5(b) consumer credit; Q4 first red team engagement (PyRIT + garak baseline against OWASP LLM Top 10) + CAF first 4-KPI dashboard. CMMI scoring at end of Year 1: Governance Level 2, Policy Level 2, Technology Level 2, People Level 2, Evidence Level 2, balanced foundation. Year 2 (Q5-Q8): operating maturity. Headcount expands to 21 FTE: CAIRO office to 4 (CAIRO + 3 AI Risk Officers + Chief of Staff); Red Team to 6; MRM + IMV to 5; Internal AI Audit to 2 (first cycle); CAF + Annex IV TDF to 2; FRIA + PMM + Article 73 each to 1.5 average. Year-2 spend €9.8M (20 bps, operating-maturity peak). Milestones: Q5 first IMV cycle + Article 72 PMM live for top-5; Q6 ISO 42001 Stage 1; Q7 SOC 2 + AI Type I + first Article 73 tabletop drill; Q8 ISO 42001 Stage 2 + certificate. CMMI end of Year 2: Governance Level 3, Policy Level 3, Technology Level 3, People Level 3, Evidence Level 3, balanced operating maturity. Year 3 (Q9-Q12): strategic differentiation. Headcount expands to 34 FTE: full Internal AI Audit 4; Standards + Regulatory Affairs lead added; Red Team 7 (added 1 detection + response engineer); MRM + IMV 6; CAIRO office 5; CAF + Annex IV TDF 3; FRIA + PMM + Article 73 each at 2.5 average. Year-3 spend €7.1M (14 bps, run-rate plus strategic). Milestones: Q9 SOC 2 + AI Type II window starts; Q10 Internal AI Audit annual plan v1 delivered to audit committee; Q11 notified body engagement signed for one Annex III §5(b) system; Q12 full board-cleared 6-slide standard operating + SOC 2 + AI Type II report issued + ISO 42001 first surveillance clean. CMMI end of Year 3: Governance Level 4, Policy Level 4, Technology Level 4, People Level 3, Evidence Level 4, strategic differentiation with People dimension trailing slightly (CAIRO targets Level 4 by Q14 with rotational program second cohort). Three-year envelope: €22.3M. FAIR ALE_95 reduction: €11.8M Q1 2026 baseline → €5.7M Q12 2029 (52% reduction across 12 quarters; aggregate Article 99 exposure reduction estimated 48% versus 2025 ad-hoc execution baseline). Board AI subcommittee ratifies the roadmap October 24 2026; audit committee ratifies November 18 2026; full board notes the roadmap December 12 2026.

Key Takeaways

  • The function roadmap is the third L5 instrument alongside the appetite plan (lesson 098) and the CAIRO mandate (lesson 097). Appetite declares envelope; mandate declares authority; the function roadmap declares capability, how the AI Risk function itself matures from Year-1 Foundation (8-10 FTE) through Year-2 Operating Maturity (18-25 FTE) to Year-3 Strategic Differentiation (30-40 FTE).
  • Year-by-year sub-function ramp: Year 1 stands up CAIRO office + CAF + AIRA + Annex IV TDF + FRIA + literacy + inventory + first-pass red team (€4-7M, foundation cost-heavy). Year 2 scales Red Team to 6 FTE + MRM + IMV at scale + Article 72 PMM + first ISO 42001 + SOC 2 + AI + notified body if applicable (€7-12M, operating-maturity peak). Year 3 brings Internal AI Audit to full cycle + Standards + Regulatory Affairs presence + ISO 42001 surveillance + SOC 2 + AI Type II + CMMI Level 3-4 across all dimensions (€5-8M, steady-state plus strategic).
  • Five-dimensional CMMI-style maturity scoring: governance, policy + process, technology + tooling, people + culture, evidence + assurance, each scored Level 1-5 by independent reviewer at the semi-annual board AI subcommittee review. Year-3 balanced target: Level 3-4 across all five dimensions with no single dimension below Level 3. The radar chart visualization is the function-balance test.
  • 12-quarter milestone calendar (Q1 charter + RACI + AIRA v1; Q2 Annex IV TDF for top-3 Tier-1; Q3 ISO 42001 readiness + first FRIA; Q4 first red team + CAF 4-KPI dashboard; Q5 first IMV + PMM top-5; Q6 ISO 42001 Stage 1; Q7 SOC 2 + AI Type I + Article 73 tabletop; Q8 ISO 42001 Stage 2 + certificate; Q9 SOC 2 + AI Type II window starts; Q10 Internal AI Audit annual plan v1; Q11 notified body engagement; Q12 6-slide board standard + Type II report + surveillance clean). Named dependencies mean slips ripple downstream.
  • Investment profile: Year 1 €4-7M (foundation cost-heavy: 10-18 bps revenue); Year 2 €7-12M (operating-maturity peak: 14-24 bps); Year 3 €5-8M (steady-state plus strategic: 10-16 bps). Three-year envelope clusters at €16-27M for €10B-turnover firm.
  • ROI quantification across three categories: direct (penalties avoided, 40-65% Article 99 exposure reduction per FAIR; €4.7-7.7M annual residual loss reduction for the worked example); indirect (cyber insurance premium reduction 5-15% on SOC 2 + AI Type II + ISO 42001 cert; procurement RFP win-rate uplift 15-30%; talent attraction); strategic (regulator-engagement quality; standards-shaping influence; brand-trust signal via public trust pages + model cards).
  • 10-KPI function maturity dashboard published at every AIGC monthly review: AI inventory coverage; FRIA completion rate; red team coverage; IMV closure rate; Article 73 timeliness; ISO 42001 surveillance findings; SOC 2 + AI exception count; vendor DDQ throughput; AIGC decision quality; board-engagement consistency. Year-1 / Year-2 / Year-3 named targets per KPI.
  • Six common 2026-2028 roadmap failures: (1) front-loading Year 1 spend without Year 2 talent ramp; (2) skipping Internal AI Audit; (3) treating ISO 42001 as one-off; (4) red team without MRM coordination; (5) function reports to CIO (independence breach); (6) no investment-tied unlock gates. Cross-walks: EU AI Act Articles 17, 27, 71, 72, 73, 99 + Omnibus VII; ISO 42001 Clauses 6, 9, 10 + Annex A.3 + A.5; SR 11-7 framework maturity expectations; SLSA-AI emerging for supply-chain.