Prototype — this is a working draft, shared for feedback and discussion. Not a finished, certified, or officially adopted framework. Scope — not intended for use as, or in the development of, a regulated medical device.
End-to-end AI delivery playbook

Deliver trusted AI.
From idea to impact.

A practical playbook for delivering secure, responsible and compliant AI solutions that create real business and patient value. Grounded in existing research and standards. Vendor-neutral by design.

Built for Trust

Governance, risk management, and compliance built in.

Executable & Practical

Clear processes, roles, artifacts, and gates for every stage.

Evidence Driven

Test, validate, and document with confidence.

Cross-Functional

Align teams. Clarify accountability. Drive outcomes.

Maria Febus

Governance enables innovation — turning principles into practice and trust into impact.

Maria Febus
Sr. PM / Data Scientist | ML Practitioner
CPMAI AIGP (Candidate)
Implementation Toolkit

Practical & Reusable

Artifacts, decision points, controls, and supporting resources across the AI lifecycle

Representative examples are shared publicly; the broader implementation toolkit can be tailored to organizational needs.
Roles & Accountability

RACI

Clear roles and accountability

Know who is Responsible, Accountable, Consulted, and Informed.
Regulatory Traceability

Standards to Execution

19 regulatory, standards, and guidance sources mapped to delivery practice

See how requirements translate into specific delivery controls, artifacts, and evidence →
Real-World Example

HistoTriage

AI in action for breast cancer triage

End-to-end example application with tests and evidence. A recall-optimized breast cancer detection CNN that flags high-risk histopathology tissue patches for pathologist review. A research/portfolio project, not a cleared or regulated medical device.

Why I built this

Throughout my career, I've been drawn to one challenge: turning governance principles into practical execution. As I moved into data science and AI, I found myself asking the same question in a new context: how do we turn responsible AI guidance into everyday practice?

AI doesn't have a guidance problem — we have strong foundations in NIST, ISO/IEC, OWASP, the EU AI Act, HIPAA, GDPR, OECD, and more. The challenge is translating that guidance into requirements, risk assessments, design reviews, testing, deployment gates, and monitoring that teams can actually use. This playbook is my contribution to closing that gap — curating, connecting, and translating existing guidance into practical delivery practices, while crediting the organizations behind it.

Responsible AI shouldn't live only in policy documents — it should be woven into everyday practice.

Use: This public prototype is shared for demonstration, feedback, and discussion. Selected examples illustrate the approach; implementation materials, customization, and broader toolkit access are not granted through publication of this site.

Put the Playbook to Work

Every organization has a different AI risk profile, operating model, regulatory environment, and level of maturity. The public playbook demonstrates the framework and selected examples; implementation can be adapted to the context of a specific organization or AI initiative.

  • Apply the framework to an AI initiative or portfolio
  • Assess gaps in an existing AI delivery lifecycle
  • Tailor governance, risk, evidence, and decision controls
  • Develop fit-for-purpose implementation artifacts and operating practices
  • Facilitate AI delivery and governance working sessions

Interested in exploring how the playbook could apply in your environment?

Let's Talk →

Or reach out directly: mfebus@gmail.com

Built on Leading Standards
& Best Practices
NISTAI RMF
OWASPLLM · Agentic · ML Security
ISO/IEC42001 · 22989
21 CFR 11GxP / FDA
HIPAASecurity Rule
GDPREU 2016/679
EU AI ActReg. 2024/1689
OECDAI Principles