Skip to content

10 · Capstone — Full Organizational AI Tools Strategy

This capstone integrates every Level 4 module into a single deliverable: a full organizational AI tools strategy document you could present to leadership.

1. Capstone deliverable structure

Section Draws from Content
Strategic scope and guardrails Module 1 Ambition, off-limits use cases, decision rights
Governance model Module 2 Committee charter, approval tiers, escalation path
Vendor risk program Module 3 Onboarding evaluation process plus ongoing risk register and re-scoring cadence
Scaling plan Module 4 Prove/systematize/scale/sustain roadmap for the next 12-18 months
Ethics and responsible use policy Module 5 Decision-risk tiering, human-in-the-loop rules, audit cadence
Maturity baseline and targets Module 6 Current-state scoring across all dimensions, binding constraint identified, target for next review
Center of Excellence plan (if warranted) Module 7 Operating model, charter, first-year responsibilities
Future-proofing commitments Module 8 Vendor-agnostic policy language, exit-plan testing schedule, review cadence
Talent and career pathing Module 9 How the organization will grow internal AI strategist/governance capability

2. A capstone quality checklist

Check Why it matters
Every guardrail is tied to a named decision-maker Untraceable guardrails don't get enforced
The vendor risk program has a concrete re-scoring cadence, not just an initial checklist Risk assessed once and never revisited is the most common failure across this whole level
At least one decision category is tiered as "high stakes" or above with human-in-the-loop specified Confirms the ethics section is applied, not generic
The maturity baseline uses evidence, not self-report An unsupported maturity claim undermines the whole document's credibility
The scaling plan has explicit exit criteria per phase Prevents "we're always in pilot mode" or premature scale-up
Every section reflects vendor-agnostic, durable language The strategy should survive a vendor or model generation change without a rewrite
A review cadence is stated for the strategy as a whole A strategy with no revisit date is a document, not a strategy

3. Common capstone mistakes

Mistake Fix
Strategy reads as a compilation of the nine modules rather than one coherent document Rewrite with a single narrative thread: the organization's actual situation, not a generic template fill-in
No real evidence behind the maturity baseline Use section 6's method: score with evidence, not impression
CoE section included even when section 7's signals say it's premature Be willing to recommend "not yet" with a stated trigger for revisiting
Ethics section present but not wired into the governance approval process Explicitly reference decision-tiers in the governance section so they're operationally connected
No mention of how vendor risk and future-proofing interact Cross-reference: the risk register (Module 3) is the mechanism that makes future-proofing (Module 8) operational

Worked example

A capstone author drafting a strategy for a mid-size healthcare company identifies, through the maturity baseline, that governance and ethics are the binding constraints — the organization has broad AI tool adoption already but no formal decision-tiering for clinically adjacent recommendations. The strategy therefore leads with a governance and ethics buildout as the first-year priority, explicitly sequences a CoE as a second-year initiative once governance is operating, and ties the vendor risk program directly to the ethics section by flagging any vendor touching patient-adjacent data for the highest re-scoring frequency. The result is a document whose priorities are visibly derived from the actual assessed gaps, not a generic checklist.

How It Actually Works

A capstone strategy document earns real credibility with leadership to the extent every section is grounded in the mechanism-level reasoning this program has built across all four levels, rather than in claims about specific current products. The strategic scope and guardrails section should be defensible using the durable, changes-slowly properties from Module 8 (structural strengths and weaknesses of the generation mechanism itself) rather than this quarter's capability announcements; the governance model should reflect the same reasoning as Module 2 — that approval decisions require both contract-level and mechanism-level literacy, not just product familiarity; the vendor risk section should carry forward Module 3's point that concentration and dependency risk have a real technical dimension (prompt and integration portability) beyond the purely contractual one.

Presenting this to leadership as one coherent document, rather than a collection of separately-sourced module summaries, matters because the whole point of the capstone is demonstrating that these aren't independent policy choices bolted together — they're different organizational responses to the same small set of underlying mechanistic facts about how generative AI actually works: it generates fluent, plausible output with no internal truth-check; it inherits and can amplify patterns (including biased ones) from training data; its data-handling behavior is governed by contract and architecture, not by product marketing; and its reliability varies dramatically by task in ways that are predictable if you understand why, not random. A strategy that visibly reasons from these facts, rather than from a list of currently-fashionable AI initiatives, is the version of this deliverable actually built to survive contact with the next few years of change in this space — which is the entire premise the capstone, and this program, has been building toward.

Exercise

Write the full capstone strategy document for a real or plausible organization, using the section 1 structure. Run it against the section 2 checklist before considering it complete, and be explicit in the document about which Level 4 module each section's reasoning is grounded in.