AI Governance, Risk & Red Teaming
Visionary · M10 · lesson 10 of 14 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Setting Enterprise AI Risk Appetite - The 3-Year Plan
📖
now learning

Setting Enterprise AI Risk Appetite - The 3-Year Plan

15 min

Acme's Q2 2026 board meeting opens with the lead independent director closing her binder and turning to the newly-appointed Chief AI Risk Officer (CAIRO) Maya Okafor: "Maya, the AI Risk Appetite Statement we ratified last May is a fine annual artifact. But this board allocates capital on three-year horizons. The CFO is presenting a three-year capital plan next quarter. The audit-committee chair is presenting a three-year ISO and SOC engagement roadmap. Where is your three-year AI risk roadmap? I do not want next year's appetite. I want the trajectory. Show me how the firm's AI risk posture, AI investment, vendor mix, and regulator engagement evolve from 2026 through 2028. You have sixty days." Maya has the L4 AIRA artifact (lesson 074) that the firm ratified in April 2026. She has the eight-dimension framework, the KRI thresholds, the breach-response protocol, the twelve-section template. What she does not yet have is the strategic horizon view: the L5 executive artifact that links AI risk appetite to enterprise strategy, capital allocation, vendor diversification, talent build, and proactive regulator engagement across a three-year planning window. The annual AIRA is the operating instrument. The three-year AIRA plan is the strategic instrument. The board signs both. This lesson is the L5 executive-tier framework for the three-year AIRA plan: why the three-year horizon is non-negotiable in 2026, the eight-component plan structure, the five L5 strategic dimensions added on top of the L4 eight, the investment-and-vendor-and-regulator ladders, the seven common 2026-2028 planning mistakes, and the Acme worked example showing Maya's sixty-day delivery: €4.8M (2026) → €7.2M (2027) → €5.9M (2028) with a vendor-concentration trajectory of 78% → 55% → 38% and a FAIR ALE_95 trajectory of €11.8M → €8.4M → €6.1M, board-ratified with annual refresh.

Why the Three-Year Horizon Is Non-Negotiable in 2026

The L4 AI Risk Appetite Statement is the operating instrument the board re-signs annually. It declares the current-year ceilings on autonomy, Annex III inventory share, vendor concentration, fairness disparity, FRIA coverage, and aggregate Article 99 worst-case. It is the right artifact for the AI Governance Committee to operate against: the KRI dashboard is monthly, the AIGC review is quarterly, the board AI subcommittee review is semi-annual, and the full-board ratification is annual. But the annual AIRA is structurally incapable of carrying the strategic horizon questions a 2026 board now asks. The CAIRO who walks into a Q2 2026 board meeting with only the annual AIRA will be sent away with the same instruction Maya received: bring back the three-year view.

Five forcing functions converge in 2026 to make the three-year horizon non-negotiable. First, the EU AI Act enforcement schedule does not align to a single-year planning cycle. Article 5 prohibitions and Article 4 literacy went live Feb 2, 2025. Article 50 transparency went live Aug 2, 2026. GPAI Chapter V obligations for systemic-risk models are running through the AI Office Code of Practice. The Omnibus VII timeline (published Q4 2025) deferred Annex III high-risk full enforcement to Dec 2, 2027 and Annex I (product-safety) integrated high-risk to Aug 2, 2028. A firm planning AI risk capacity on an annual cycle through this enforcement runway will under-invest in 2026, over-react in 2027, and miss the Annex I product-safety conformity-assessment notified-body queue in 2028. The three-year plan absorbs the enforcement runway as a sequenced capacity build.

Second, the major capital-and-program cycles that AI governance depends on are themselves three-year cycles. ISO/IEC 42001:2023 certification runs on a three-year cycle (Stage 1 + Stage 2 + annual surveillance + recertification at year three). SOC 2 + AI Type II reports run on annual examinations with three-year vendor-trust building. Notified-body engagement for Annex III conformity assessment (where the deployer has voluntarily moved to a third-party module) is a two-to-three-year queue. Board AI subcommittee charters are typically three-year mandates with annual review. CAIRO tenure expectations are three-to-five years. Capital allocation for AI governance technology stack (AI inventory platform, model risk management platform, AI red team tooling, Annex IV TDF generation, Article 72 PMM ingestion) is amortized on three-to-five-year curves. Annual planning collides with all of these cycles.

Third, vendor diversification is a multi-year program, not an annual switch. A firm at 78% foundation-model concentration on a single provider (the 2026 industry average per the ENISA AI Threat Landscape 2026 surveillance) cannot drop to 38% in one year without operational rupture. The vendor-diversification ladder is a three-year trajectory: 78% → 55% (Y2) → 38% (Y3) with explicit re-platforming workstreams, vendor due-diligence cycles (lesson 089), and AIRA vendor-concentration KRI evolution. The board ratifies the ladder, not just the ceiling.

Fourth, AI risk-management talent, the named CAIRO, the AI Risk Officers, the Model Risk Managers, the AI red team leads, the FRIA program lead, the Article 72 PMM lead, is a thin 2026 market. Building the FTE bench from a Y1 skeleton (CAIRO + 2 FTE) to a Y3 mature team (CAIRO + 14 FTE) requires rotational programs, co-source benches, university pipelines, and external co-source contracts that themselves take twelve to twenty-four months to set up. A board ratifying only a single-year FTE plan cannot fund the talent ladder coherently.

Fifth, regulator engagement is a relationship, not a transaction. The European Commission AI Office, the national market-surveillance authorities, sectoral regulators (Federal Reserve, OCC, PRA, FCA, BaFin, CFPB, FDA, EEOC), and the AI Office GPAI Code-of-Practice signatory community all reward proactive multi-year engagement. A firm that signals a Y1-Y2-Y3 engagement plan, Y1 attend public consultations, Y2 submit comment letters, Y3 take a seat on an AI Office working group, builds posture that pays dividends in enforcement-prioritization decisions. A reactive single-year posture invites the opposite. The three-year plan formalizes engagement as a deliberate posture.

The aggregate effect: a three-year AIRA plan in 2026 reduces the firm's aggregate Article 99 exposure by an estimated forty to sixty percent across the planning window versus ad-hoc execution. The reduction comes from maturity acceleration (controls in place before enforcement), capacity-to-bear calibration (capital reserves matched to FAIR-quantified expected loss), vendor diversification absorbing single-provider-outage risk, and regulator-engagement goodwill reducing enforcement multipliers when incidents do occur. The three-year plan is not a planning artifact. It is a penalty-reduction instrument.

The Eight-Component Three-Year AIRA Plan Structure

The mature 2026 three-year AIRA plan is organized into eight components, each carrying its own multi-year trajectory. The eight components are the spine of the plan document; the L5 strategic dimensions (next section) overlay on the components; the document sections (later in this lesson) operationalize.

  • (1) Year 1 - Foundation. The 2026 year of the three-year plan consolidates the governance core: AI Governance Committee charter and operating cadence (lesson 015); Chief AI Risk Officer mandate, authority, reporting line (lesson 097); annual AI Risk Appetite Statement ratified by board (lesson 074); Annex IV Technical Documentation File complete for every Tier-1 high-risk system; Article 27 FRIA complete for every Annex III deployer system; AI inventory schema beyond spreadsheet (lesson 045); first-pass vendor due-diligence questionnaires (lesson 089); Article 4 literacy program rolled to in-scope personnel; first-pass red-team baseline against OWASP LLM Top 10 (lesson 053) and MITRE ATLAS. Foundation is not optional and is not glamorous; the rest of the plan is built on it.
  • (2) Year 2 - Operating Maturity. The 2027 year scales the operating instruments. Red team rotates from baseline to continuous (purple-team integration with detection-and-response; quarterly external red team engagements). Model Risk Management (lesson 067) reaches the SR 11-7 + ISO 42001 hybrid operating standard. AI Model Inventory + Validation (IMV) reaches the production depth where every deployed model has a current model card, validation file, and Article 47 declaration where applicable. Article 72 Post-Market Monitoring (PMM) is wired to telemetry, with weekly anomaly review and monthly trend report. The first ISO 42001 certification cycle (Stage 1 + Stage 2 + first surveillance) is closed. The vendor-diversification roadmap reaches the Y2 ceiling (≤55% on any single foundation-model provider). The annual AIRA refresh integrates the lessons learned from the Y1 breach-response history.
  • (3) Year 3 - Strategic Differentiation. The 2028 year turns the operating maturity into competitive differentiation. SOC 2 + AI Type II report issued (annual examination). Vendor concentration reaches the Y3 ceiling (≤38% on any single provider; diversified across three primary providers plus open-source self-host where strategically warranted). AI Office working-group seat secured (one of: GPAI Code-of-Practice signatory committee; Annex III sectoral working group; Article 56 Code-of-Practice harmonization). Annex I product-safety enforcement readiness complete (notified body engaged where Annex I module applies). Customer-facing AI trust pages, model cards, and system cards published as competitive trust signals. The firm posture moves from compliance-reactive to compliance-leading.
  • (4) Investment ladder. The three-year plan declares the AI governance program budget per year, typically expressed in basis-points of group revenue and absolute Euro, with KPI-tied unlock gates that release Y2 and Y3 capital only on Y1 completion criteria. Typical 2026 mature trajectories cluster at 0.10-0.18% of group revenue for Y1, peaking at 0.18-0.25% in Y2 (operating-maturity year carries highest capital intensity), and settling at 0.12-0.16% in Y3 (run-rate plus differentiation). The investment ladder must be ratified by the CFO and the board audit committee, not just the AIGC.
  • (5) Risk-trajectory model. The plan carries quarter-by-quarter heat-map projections (inherent risk, residual risk, target risk) for each AIRA dimension, and FAIR-method Annual Loss Expectancy (ALE_50 and ALE_95) projections (lesson 086) for each quarter of the three-year window. The trajectory model is the quantitative evidence the board uses to test whether the investment ladder is actually moving the residual risk in the expected direction.
  • (6) Talent ladder. The named FTE buildout per year: CAIRO Y1; AI Risk Officers (2 → 4 → 6); Model Risk Managers (1 → 3 → 5); AI red team leads (1 → 2 → 3); FRIA program lead Y1; Article 72 PMM lead Y1; rotational program Y2 (rotate 4-6 second-line analysts through CAIRO office annually); co-source bench Y2 (named external co-source partner, Big-Four risk advisory, specialist AI risk firms, under master services agreement). The talent ladder also names the retention compensation framework (key-person risk being a 2026 board concern).
  • (7) Vendor diversification roadmap. The trajectory for foundation-model provider concentration: current Y0 baseline → Y1 ceiling → Y2 ceiling → Y3 ceiling. Plus the parallel diversification ladders for AI platform, AI orchestration tooling, AI inventory platform, AI red team tooling. Plus the open-source self-host strategic option (where the firm chooses to self-host a foundation model on-premise or in private cloud as a single-vendor-de-risk move). The roadmap names the re-platforming workstreams that move the concentration KRI year-over-year.
  • (8) Regulator engagement plan. The named cadence for engagement with each regulator the firm is exposed to: AI Office (public consultation participation Y1; comment letter submissions Y2; working-group seat Y3); national market-surveillance authority (annual meeting Y1; technical working group Y2; voluntary supervised pilots Y3); sectoral regulators (Federal Reserve SR 11-7 examinations; PRA SS1/23 examinations; CFPB UDAAP review; FDA SaMD interaction; EEOC employment-decision review). The plan names the executives accountable for each regulator relationship.

The eight components are not equally weighted in any single year. Y1 is dominated by components 1, 6, 7. Y2 is dominated by components 2, 4, 5. Y3 is dominated by components 3, 7, 8. The plan declares the weighting per year so the board sees the strategic emphasis shift over the planning window.

Five L5 Strategic AIRA Dimensions Beyond the L4 Eight

The L4 AIRA (lesson 074) defines eight operating dimensions: risk category, AI use-case tier, autonomy tier, consumer-impact magnitude, reversibility, geographic deployment, sector exposure, vendor concentration. These dimensions are correct, durable, and remain the operating spine. The L5 three-year plan adds five strategic dimensions on top. The L5 dimensions are not measured by monthly KRIs; they are measured by board-level strategic assessments per planning cycle.

  • (1) Competitive risk acceptance. Is the firm willing to lag competitors in AI adoption to maintain a risk-conservative posture, or willing to lead competitors in AI deployment at higher risk acceptance to capture first-mover differentiation? The dimension is sector-dependent: in financial services and healthcare, lagging is often the regulator-rewarded posture; in retail technology and consumer software, leading is the market-rewarded posture; in defense and critical infrastructure, the answer is set by procurement frameworks rather than firm choice. The CAIRO defends the competitive risk acceptance position to the CEO and the board's strategy committee. The 2026 most-common posture for L5 mature firms: "selective leader": lead in two named use-case categories, lag in two others, default to peer-median in the rest.
  • (2) Capital reserve risk acceptance. How much capital is the firm willing to reserve for AI-related loss events? The dimension is the bridge to Solvency II Own Risk and Solvency Assessment (ORSA) framing, appetite is not just risk-tolerance, it is also capacity-to-bear. The CAIRO + CFO + Group Treasurer jointly translate the FAIR-method ALE_95 portfolio number (lesson 086) into a capital reserve set-aside, an insurance-procurement plan (lesson 088), and an operating-expense plan for the residual. The Solvency II warning applies: a firm that declares high risk appetite but reserves no capital to bear the loss is in an incoherent appetite posture the regulator will mark. The L5 plan declares the capital-to-bear figure per year, ratified by the CFO, audit committee chair, and board.
  • (3) Geographic deployment risk. The L5 dimension extends the L4 geographic dimension to a strategic ladder: EU-only (lowest-risk operating jurisdiction with the heaviest regulatory load, paradoxically); US-only (highest risk by sectoral overlay heterogeneity); global (highest aggregate exposure, but with risk diversification benefits across enforcement-priority shifts). The L5 plan declares the geographic deployment ladder per year: the firm may deliberately constrain a high-risk use case to EU-only deployment in Y1 to harvest regulator-engagement goodwill, expand to UK + US in Y2 once Annex III enforcement matures, and add APAC in Y3 once GPAI Code-of-Practice signatory posture is established.
  • (4) Acquisition risk. The L5 dimension addresses M&A target evaluation for inherited AI risk. Every acquisition target in 2026 carries inherited AI exposure: shadow AI in business units (unauthorized SaaS-AI deployments); legacy AI models without model cards or validation files; vendor contracts inherited without ISO 42001 attestation; Annex III deployer systems inherited without completed FRIA; Article 47 declarations inherited from previous owners that may or may not be current. The CAIRO joins M&A due-diligence sessions in the L5 mature firm. The three-year plan names the M&A AI-risk-due-diligence playbook and the post-close 90-day integration plan. The board sets the appetite for inherited AI risk per acquisition.
  • (5) Talent retention risk. The L5 dimension recognizes that the 2026 AI risk-management talent market is thin and competitive. The departure of a CAIRO, a Model Risk Officer, or an AI Red Team Lead is itself a governance event that can rupture controls operating effectiveness. The three-year plan names the retention framework: long-term incentive compensation for named L5 roles, succession planning for each named role, rotational program to broaden bench, university-pipeline partnerships, public profile development (conference speaking, publications, working-group participation) as both retention and recruiting instrument. The board declares the appetite for talent concentration risk and ratifies the retention framework.

The five L5 strategic dimensions intersect with the L4 eight in ways that surface only at the three-year horizon. A firm with high competitive risk acceptance, EU-only geography, and high-acquisition appetite needs a CAIRO-office FTE buildout that anticipates inherited-AI-risk integration capacity. A firm with capital-reserve constraint (low Solvency II capacity-to-bear) needs a vendor-diversification roadmap that prioritizes vendor risk transfer over operating-cost optimization. The L5 dimensions are how the CAIRO defends the integrated three-year plan to the CEO, the CFO, and the full board.

The Investment, Vendor, and Regulator Ladders

The three ladders are the core operational mechanics that turn the eight-component plan into board-ratifiable capital allocations and named accountable workstreams. The ladders are presented as appendices to the plan document but are the most-frequently-consulted artifacts in operating use.

Investment ladder. The three-year capital plan, expressed in basis-points of group revenue and absolute Euro per year, with KPI-tied unlock gates. The Y1 budget is fully approved and committed. The Y2 budget is provisionally approved and unlocks on completion of named Y1 KPIs (annual AIRA ratified; AIGC operating with documented quarterly cadence; CAIRO mandate ratified; Annex IV TDF complete for all Tier-1 high-risk systems; Article 4 literacy program at ≥85% in-scope coverage; first-pass red-team baseline complete; AI inventory at audit-ready depth). The Y3 budget is indicatively approved and unlocks on completion of named Y2 KPIs (ISO 42001 certification achieved; vendor concentration at ≤55%; Article 72 PMM operating to telemetry-driven cadence; red team continuous-operating; rotational program operating with first cohort completed). The unlock-gate mechanism prevents the failure mode of "Y3 ambition without Y1 foundation", capital is not deployed to advanced workstreams while foundation is incomplete. Typical 2026 mature trajectory for a €10B-turnover firm: Y1 €4.8M (10 bps); Y2 €7.2M (15 bps); Y3 €5.9M (12 bps). The total three-year envelope is €17.9M with the Y2 peak reflecting the operating-maturity build.

Vendor diversification ladder. The trajectory for foundation-model provider concentration plus the parallel ladders for AI platform, AI orchestration, AI inventory, AI red team tooling. The named workstreams that move the concentration KRI per quarter: Q1 baseline; Q2 vendor-due-diligence cycle for two alternative providers; Q3 contract negotiation and pilot deployment; Q4 production cutover for a named workload tranche; iterate per quarter. The vendor-diversification ladder also names the open-source self-host strategic option: for firms with the engineering capacity to self-host a foundation model (Llama-class, Mistral-class, or a fine-tuned base model), self-host is the strongest single-vendor de-risk move and the most expensive engineering commitment. Typical 2026 mature trajectory: Y0 (current) 78%; Y1 target 65% (interim); Y2 target 55%; Y3 target 38% with three named primary providers + open-source self-host for a defined workload tranche.

Regulator engagement plan. The named cadence per regulator. AI Office: Y1 attend the public consultations published Q3 2026 and Q1 2027; Y2 submit named comment letters on harmonized standards under preparation; Y3 secure working-group seat on Annex III sectoral implementation (financial services, healthcare, employment, sector-appropriate). National market-surveillance authority: Y1 inaugural meeting with named CAIRO-led delegation; Y2 attend technical working group on Article 72 PMM ingestion standards; Y3 voluntary supervised pilot for a high-impact use case. Sectoral regulators per the firm's sector mix. The engagement plan names the executive accountable for each regulator relationship: CAIRO for AI Office and market-surveillance; CRO for Federal Reserve and PRA; Chief Compliance Officer for CFPB and EEOC; Chief Medical Officer (if life-sciences) for FDA. The plan also names the cadence calendar so the board sees engagement frequency.

The Twelve-Section Three-Year Plan Document

The plan document follows a twelve-section structure that the board, the CAIRO office, the audit committee, and the regulator can each navigate to the section relevant to their role.

  • Section 1 - Vision and strategic context. Why the firm pursues AI, what business value it expects across the planning window, what posture (selective leader / peer-median / risk-conservative / first-mover) the firm chooses per use-case category, the relationship to the corporate strategy and the three-year financial plan. Signed by the CEO and the board chair.
  • Section 2 - Scope and entity coverage. Legal entities, jurisdictions, subsidiaries, joint ventures, and named M&A integration sequence. Cross-reference to the enterprise risk appetite statement and the cybersecurity risk appetite statement scope.
  • Section 3 - Strategy alignment. Explicit linkage between the three-year AIRA plan and the three-year financial plan, the three-year capital plan, the three-year technology roadmap, the three-year ESG and sustainability plan, and the M&A pipeline.
  • Section 4 - Eight-component plan. The eight components above, Y1 Foundation; Y2 Operating Maturity; Y3 Strategic Differentiation; Investment ladder; Risk-trajectory model; Talent ladder; Vendor diversification roadmap; Regulator engagement plan.
  • Section 5 - Five L5 strategic dimensions. The competitive / capital / geographic / acquisition / talent-retention dimensions with the firm's declared posture per year.
  • Section 6 - Risk-trajectory model. Quarter-by-quarter heat-map projections and FAIR ALE_50 + ALE_95 trajectories per quarter. The quantitative evidence the board uses to test the plan against execution.
  • Section 7 - KPIs and unlock gates. The named Y1 → Y2 → Y3 unlock-gate KPIs with measurement methodology, data sources, owners. The mechanism that prevents capital deployment on incomplete foundation.
  • Section 8 - Governance ratification cadence. Board ratification at planning origination; annual board re-ratification at Q2 (aligned with annual AIRA ratification); semi-annual board AI subcommittee review against trajectory; quarterly AIGC review against KPIs; monthly CAIRO-office review against operating KRIs. The cadence cascade is explicit.
  • Section 9 - Refresh triggers. The events that trigger an off-cycle plan refresh: substantial regulatory change (Omnibus VIII, sectoral AI rule, US federal AI law); major incident (Article 73 serious incident, FAIR Loss Event > €5M); M&A integration of significant target; significant business strategy shift; sustained breach of three or more AIRA KRIs in a single quarter.
  • Section 10 - Accountability matrix. Named accountable executive per component per year. The matrix is the operationalization of the eight-component plan into RACI-level clarity.
  • Section 11 - Capacity-to-bear assessment. The Solvency-II-style assessment that links the AIRA appetite to the firm's capital base, insurance program, and operating expense capacity. The CFO and Group Treasurer co-sign.
  • Section 12 - Board signature page. CEO, CFO, CRO, CAIRO, board chair, audit committee chair, lead independent director, AI subcommittee chair. The signature date is the planning effective date; the next ratification date is twelve months later.

The plan document is typically 28-48 pages. Shorter and the risk-trajectory model and accountability matrix are under-specified; longer and the board will not read it. A four-page board-facing executive summary is prefixed for the annual ratification meeting; the eight-component summary, the five L5 dimensions, the investment ladder, the vendor-diversification trajectory, the risk-trajectory FAIR projection, and the year-over-year change log fit on those four pages. Directors read the executive summary; the CAIRO operates from the full document; the audit committee and AI subcommittee chair operate from Sections 6, 7, 8, 11; the regulator examines all four artifacts.

Common 2026-2028 Three-Year Planning Mistakes

Seven mistakes recur in 2026 three-year AIRA plans. Each is predictable and fixable in a single planning cycle.

  • (1) Annual AIRA without three-year frame. The firm ratifies an annual AIRA but does not place it inside a three-year horizon. The CAIRO presents the annual ceiling each year without trajectory. The board cannot see whether the appetite is converging on a strategic target or oscillating ad-hoc. Fix: every annual AIRA refresh is presented inside the three-year plan envelope with a year-over-year change log against the plan trajectory.
  • (2) Appetite without capacity-to-bear. The AIRA declares high risk appetite without reserving the capital or insurance capacity to bear the FAIR-quantified loss. The Solvency-II warning applies, the regulator views an incoherent appetite-to-capacity posture as a leadership-commitment failure. Fix: Section 11 of the three-year plan explicitly reconciles AIRA appetite to capital reserve set-aside, insurance program coverage, and operating expense capacity, co-signed by the CFO.
  • (3) No investment ladder. The plan declares ambition without naming the capital trajectory. The CFO is asked annually to fund unfunded ambition. The investment cycle becomes incoherent. Fix: Section 7 of the plan declares Y1 / Y2 / Y3 budget with KPI-tied unlock gates; the CFO and audit committee co-ratify the ladder at planning origination.
  • (4) No vendor diversification ladder. The plan declares a vendor-concentration ceiling but no trajectory. The firm sits at 78% concentration in Y0 and is still at 78% in Y2 because no quarterly workstream moves the number. The first major foundation-model provider outage in Y2 ruptures operations. Fix: the vendor-diversification ladder names quarterly workstreams (due-diligence cycle, pilot, cutover) with named workload tranches that move the concentration KRI per quarter.
  • (5) No regulator engagement plan. The plan treats regulator interaction as reactive only, when the regulator asks, the firm responds. The firm misses the Y1 → Y3 trajectory from observer to working-group participant to AI Office signatory. The first enforcement action lands without prior relationship goodwill. Fix: Section 4 component 8 names the engagement cadence per regulator with named executive accountability.
  • (6) Y3 ambition without Y1 foundation. The plan declares Y3 SOC 2 + AI Type II issuance without Y1 ISO 42001 readiness. The Y3 target is unattainable because Y1 foundation is incomplete. Compliance theater results: the plan looks ambitious to the board, fails on execution by Y2, and damages CAIRO credibility for the next planning cycle. Fix: the KPI-tied unlock gates in Section 7 explicitly require Y1 KPI completion before Y2 capital releases. Capital is the discipline that forces sequential execution.
  • (7) Skipping competitive risk dimension. The plan omits the competitive risk acceptance dimension (Section 5). The firm cannot articulate whether it is choosing to lead, lag, or match peers in AI adoption per use-case category. The CEO and the board strategy committee fill the vacuum with implicit decisions that diverge from the operating posture. The result: the CAIRO operates conservative while the business operates aggressive, and the incoherence surfaces in a major incident. Fix: Section 5 explicitly declares competitive risk posture per named use-case category, refreshed annually with the AIRA ratification.

Each mistake compounds with the others. A firm that makes mistakes (3), (4), and (6) together, no investment ladder, no vendor ladder, Y3 ambition without Y1 foundation, has a plan that will fail by mid-Y2 and rupture board confidence in the CAIRO mandate. A firm that makes mistakes (1) and (5) together, annual-only frame, no regulator engagement, has a plan that will survive operating use but will be sub-optimal in enforcement posture. A firm that makes mistakes (2) and (7) together, no capacity-to-bear, no competitive posture, has a plan that will pass internal review but fail external audit and regulator scrutiny.

Acme Worked Example - Maya's Sixty-Day Delivery

Acme Inc. is the same €10B-turnover diversified financial-services firm from the L4 AIRA worked example (lesson 074). Maya Okafor was appointed CAIRO in March 2026 (per the lesson 097 framework). The board's instruction at the Q2 2026 meeting was a sixty-day delivery of the three-year AIRA plan, in time for the Q3 2026 board off-site where the CFO would present the three-year capital plan.

Section 1 - Vision and strategic context. Acme's vision: "AI accelerates retail banking, life insurance, and consumer credit decisioning with mature governance that the regulator and the customer both trust." Posture per use-case category: selective leader in retail banking customer service (Tier 2-3 autonomy agents); peer-median in life insurance underwriting; risk-conservative in consumer credit decisioning (Annex III §5(b)); laggard in autonomous claims adjudication pending regulator clarity. Signed by the CEO and the board chair on May 16, 2026.

Section 4 - Eight-component plan. Y1 Foundation (2026): AIGC operating quarterly; CAIRO mandate ratified with €1.4M direct office budget; AIRA v2026.Q2 ratified with KRI dashboard operating; Annex IV TDF complete for all 11 Tier-1 high-risk systems by Q4; Article 27 FRIA complete for all 18 Annex III deployer systems by Q3; Article 4 literacy at 88% in-scope coverage by year-end; first-pass red team baseline complete by Q4; AI inventory at audit-ready depth (61 named systems with model cards). Y2 Operating Maturity (2027): ISO 42001 Stage 1 in Q2 + Stage 2 in Q4; vendor concentration from 78% to ≤55%; red team transitions to continuous-operating with two external engagements; MRM at SR 11-7 + ISO 42001 hybrid; Article 72 PMM operating to telemetry-driven monthly cadence; rotational program with first cohort of four analysts completing. Y3 Strategic Differentiation (2028): SOC 2 + AI Type II report issued in Q3; vendor concentration to ≤38% with three named primary providers + open-source self-host for retail-banking customer service tier; AI Office working-group seat secured on Annex III §5 financial services implementation; Annex I enforcement-ready posture for two product-safety-adjacent systems; customer trust pages and model cards published.

Investment ladder. Y1 2026 €4.8M (10 bps of group revenue), fully approved and committed. Y2 2027 €7.2M (15 bps), provisionally approved, unlocks on Y1 KPI completion. Y3 2028 €5.9M (12 bps), indicatively approved, unlocks on Y2 KPI completion. Three-year envelope €17.9M. Y1 breakdown: €1.4M CAIRO office (Maya + 2 AI Risk Officers + analyst); €0.9M AIGC operating + AIRA program + Annex IV TDF generation; €0.6M FRIA program + Article 4 literacy; €0.7M red team baseline + tooling; €0.5M AI inventory platform + AI model registry; €0.7M external advisory + co-source bench setup.

Vendor diversification trajectory. Y0 (2026 baseline) 78% foundation-model concentration on a single provider. Y1 target 65% (interim) achieved by Q4 2026 via cutover of customer-service tier-1 workloads to a second provider. Y2 target ≤55% achieved by Q2 2027 via cutover of internal-knowledge-management workloads to a third provider plus open-source self-host pilot. Y3 target ≤38% achieved by Q4 2028 via production-scale open-source self-host for retail-banking customer-service plus continued tranche cutover.

FAIR ALE_95 trajectory. Q1 2026 baseline €11.8M (calibrated against the firm's 61 named systems with FAIR-method per lesson 086). Y1 end-of-year €10.4M (modest reduction from Annex IV TDF completion + FRIA completion + red team baseline). Y2 end-of-year €8.4M (significant reduction from ISO 42001 operating + vendor diversification + MRM maturity). Y3 end-of-year €6.1M (continued reduction from SOC 2 + AI continuing + vendor diversification at ≤38% + open-source self-host de-risking single-provider exposure). The three-year FAIR ALE_95 trajectory is the quantitative evidence Maya brings to the board to defend the €17.9M envelope.

Five L5 strategic dimensions. Competitive: selective leader (retail banking customer service); peer-median (life insurance); risk-conservative (consumer credit Annex III §5(b)). Capital reserve: €12M reserve set-aside Y1; €9M Y2; €7M Y3 (declining as residual risk reduces; capital released to operating reinvestment). Geographic: EU-only for Annex III §5(b) consumer credit Y1; expand to UK in Y2 after Stage 2 ISO 42001; consider US in Y3 only after Texas TRAIGA + Colorado AI Act enforcement clarity. Acquisition: appetite for one strategic AI-adjacent acquisition per year with named 90-day post-close integration playbook. Talent retention: long-term incentive comp for CAIRO + 3 named L5 roles; succession plan named for each; rotational program funded; university partnership with two named programs by Y2.

Regulator engagement plan. AI Office Y1 attend Q3 2026 public consultation on Annex III §5 harmonized standards; Y2 submit comment letter on PMM ingestion technical standard; Y3 working-group seat application on Annex III §5 financial-services implementation working group. National market-surveillance authority (BaFin given Acme's German legal entity domicile): Y1 inaugural meeting Q4 2026; Y2 technical working group on PMM ingestion; Y3 voluntary supervised pilot. Federal Reserve SR 11-7 examination expected Q2 2027; PRA SS1/23 examination expected Q4 2027.

Board ratification. Q3 2026 board off-site, September 18-19. The CFO presents the three-year capital plan; Maya presents the three-year AIRA plan; the CRO presents the integration; the audit committee chair signs off on the unlock-gate KPIs; the lead independent director signs the planning effective date as October 1, 2026 with next ratification October 1, 2027. The change log is opened; the plan moves into Q4 2026 operating cadence with the first AIGC quarterly review against the plan in December.

Audit-defensibility outcome. When the firm's external auditor tests the three-year AIRA plan in the November 2026 readiness assessment for the 2027 ISO 42001 Stage 1, the plan is cited as evidence of Clause 6 planning maturity (the strongest finding) and Annex A.5 resource adequacy (capital ladder is explicit). The audit committee notes the three-year plan reduces the firm's 2026-2028 aggregate Article 99 exposure by an estimated 48% versus the 2025 ad-hoc execution baseline, per the FAIR-method projection. The board's Q3 2026 ratification of the plan is the L5 strategic governance evidence the regulator, the auditor, and the credit-rating agency will all reference in 2027-2028 examinations.

Key Takeaways

  • The annual AIRA (lesson 074) is the operating instrument; the three-year AIRA plan is the L5 strategic instrument. The board signs both. The CAIRO who walks into a Q2 2026 board meeting with only the annual artifact will be sent back for the three-year trajectory.
  • Five forcing functions converge in 2026 to make the three-year horizon non-negotiable: EU AI Act enforcement runway (Annex III Dec 2 2027; Annex I Aug 2 2028); ISO 42001 + SOC 2 + AI + notified-body cycles are themselves three-year; vendor diversification cannot drop concentration in one year without rupture; AI risk talent build requires twelve-to-twenty-four-month lead times; regulator engagement is a multi-year relationship.
  • Eight-component plan structure: Y1 Foundation (AIGC + CAIRO + AIRA + Annex IV TDF + FRIA + literacy + red team baseline + inventory); Y2 Operating Maturity (ISO 42001 cert + red team continuous + MRM + PMM + vendor ≤55%); Y3 Strategic Differentiation (SOC 2 + AI + vendor ≤38% + AI Office working-group seat + Annex I-ready); Investment ladder; Risk-trajectory model (FAIR ALE_95 per quarter); Talent ladder; Vendor diversification roadmap; Regulator engagement plan.
  • Five L5 strategic dimensions added on top of the L4 eight: competitive risk acceptance (lead / lag / match per use-case); capital reserve risk acceptance (Solvency-II ORSA framing, appetite must equal capacity-to-bear); geographic deployment risk (EU-only / US-only / global ladder); acquisition risk (inherited AI risk in M&A targets); talent retention risk (named L5 roles with retention compensation and succession).
  • Investment ladder uses KPI-tied unlock gates: Y2 capital releases only on Y1 KPI completion; Y3 on Y2 completion. The unlock-gate mechanism is the discipline that forces sequential execution and prevents Y3 ambition without Y1 foundation. Typical 2026 mature trajectory: Y1 10 bps revenue / Y2 15 bps / Y3 12 bps.
  • Vendor diversification trajectory: 78% Y0 → 65% Y1 (interim) → 55% Y2 → 38% Y3 with named quarterly workstreams (due-diligence + pilot + cutover) per workload tranche; open-source self-host is the strongest single-vendor de-risk move for firms with engineering capacity.
  • Seven common 2026 mistakes: annual-only frame; appetite without capacity-to-bear; no investment ladder; no vendor ladder; no regulator engagement plan; Y3 ambition without Y1 foundation; skipped competitive risk dimension. Each compounds with the others.
  • Cross-walks: EU AI Act Articles 17, 27, 71, 72, 99 + Omnibus VII timeline; NIST AI RMF Govern 1.1, 1.5, 5.1; ISO 42001 Clauses 6 + 9 + Annex A.3 + A.5; SR 11-7 + Basel-style capital framing; Solvency II ORSA capacity-to-bear; OECD AI Principle 1. Penalty reduction from three-year plan vs ad-hoc: estimated 40-60% across the planning window.