Insights

How to build an AI strategy and 12-month delivery roadmap

Turn an AI ambition into a focused portfolio, operating model and quarterly roadmap with measurable delivery gates.
AI strategy 7 min read

An AI strategy should make choices. It should explain which business outcomes matter, where AI can improve them, what the organisation will not pursue and how evidence will control investment.

A list of tools, use cases and training sessions is an activity plan. A useful strategy connects operating priorities to a sequenced portfolio, shared capabilities, governance and measurable delivery.

Start with the business context

Before creating an AI vision, identify the forces the organisation needs to respond to over the next one to three years.

These may include demand growth, service pressure, margin, regulatory change, legacy systems, product complexity, data quality or specialist capacity. Interview business leaders and frontline teams. Review operating measures, customer feedback, risk events and transformation plans.

Write three to five outcome themes, such as:

  • Increase claims capacity without weakening control.
  • Improve the speed and consistency of complaint investigations.
  • Reduce manual product-content work and rework.
  • Give employees faster access to trusted operational knowledge.

These themes create a filter. An AI idea belongs in the strategy only if it advances an agreed outcome or builds a required capability.

Define principles that change decisions

Avoid slogans that everyone can support but nobody can apply. Useful principles resolve trade-offs.

Examples:

  • Start with workflows and user outcomes, not model adoption.
  • Use the simplest reliable method that meets the need.
  • Keep high-impact, difficult-to-reverse decisions under meaningful human control.
  • Require representative evaluation before production release.
  • Treat data, prompts, evaluations and controls as managed assets.
  • Design supplier exit and change control for critical workflows.
  • Fund adoption and operations as part of delivery.

The UK Government AI Playbook brings similar principles together across the AI lifecycle, including clear goals, responsible use, meaningful human control, commercial planning and long-term support.

Create an evidence-based use-case portfolio

Collect ideas from business teams, but do not run a popularity contest. Convert each candidate into a short brief:

  1. User and problem.
  2. Current workflow and baseline.
  3. Intended AI role.
  4. Expected outcome.
  5. Data and integration needs.
  6. Main risks and controls.
  7. Operational owner.
  8. Evaluation approach.

Score value, frequency, feasibility, risk, measurability and ownership. Our AI use-case prioritisation guide gives a fuller method.

Balance the portfolio across three horizons:

Prove: a small number of bounded workflows that can create evidence in months.

Scale: existing use cases with credible performance and a clear adoption path.

Prepare: data, integration, governance or skills work required for future opportunities.

Limit work in progress. Ten simultaneous pilots create less strategic learning than two well-evaluated workflows that reach a real production decision.

Decide which capabilities should be shared

Review the shortlist for repeated needs. Common capabilities may include:

  • Secure model access and identity.
  • Document ingestion and retrieval.
  • Prompt and configuration versioning.
  • Evaluation datasets and test execution.
  • Logging, monitoring and feedback.
  • Approval workflows and tool permissions.
  • Supplier assessment and contracting patterns.

Do not build a large central platform in anticipation of every use case. Create the thinnest shared capability justified by the first portfolio, then extend it from evidence.

Design the operating model

AI work crosses business, technology and risk responsibilities. Clarify who makes each decision.

Executive sponsor

Owns the strategic outcomes, removes organisational barriers and decides major investment trade-offs.

Portfolio owner

Maintains prioritisation, dependencies, benefits and stage gates across use cases.

Workflow owner

Owns the operational result, process change, user adoption and live performance for a use case.

Product and delivery team

Designs, builds, tests and improves the system with users and subject-matter experts.

Shape the design, assess evidence and define controls proportionate to the use case.

AI governance forum

Sets reusable policy, reviews higher-risk decisions and monitors the portfolio. It should not become the operating owner for every system.

Use a simple decision-rights matrix. Name who proposes, reviews, approves, operates and can pause each system.

Build evaluation into the strategy

The NIST AI Risk Management Framework groups activity into Govern, Map, Measure and Manage. Use those functions as a strategy test.

  • Govern: Are policies, accountability and risk tolerances clear?
  • Map: Are context, users, harms and dependencies understood?
  • Measure: Can performance and risk be evaluated with representative evidence?
  • Manage: Can the organisation prioritise action, monitor production and respond to incidents?

Every funded use case should have a baseline, evaluation contract, release threshold and monitoring owner. This creates comparable evidence across the portfolio.

A practical 12-month roadmap

The sequence below is a starting pattern, not a fixed programme.

Quarter 1: focus and foundations

  • Agree outcome themes and decision principles.
  • Inventory current AI use, including unofficial tools where possible.
  • Shortlist and score use cases.
  • Select one or two bounded workflows for discovery.
  • Establish minimum policy for data, procurement, human oversight and release.
  • Define baseline measures and evaluation sets.
  • Assign executive, portfolio and workflow owners.

The quarter should end with a decision-ready portfolio and evidence plans, not a broad technology procurement.

Quarter 2: controlled proof

  • Prototype the selected workflows using realistic, protected data.
  • Run offline evaluation against agreed criteria.
  • Test with users and measure task performance.
  • Complete privacy, security, commercial and operational design.
  • Establish versioning, logs and a basic monitoring path.
  • Make go, refine or stop decisions.

Protect the option to stop. A prototype that disproves the value case has delivered useful evidence.

Quarter 3: production and adoption

  • Release the strongest workflow to a limited eligible group.
  • Monitor quality, risk, adoption, cost and outcome measures.
  • Train users and managers on scope, limitations and escalation.
  • Resolve integration and support issues.
  • Reuse proven evaluation and governance patterns for the next workflow.
  • Recalculate the value case using real operating data.

This is where the strategy meets operating reality. Make time for corrections rather than treating launch as the end.

Quarter 4: scale what works and reset the portfolio

  • Decide whether to expand, redesign or withdraw live workflows.
  • Standardise capabilities that have proven reusable.
  • Review supplier performance and architecture choices.
  • Assess whether controls work in practice.
  • Update the use-case portfolio with new evidence.
  • Set the next 12-month outcomes and investment.

Scale by user group, case type or business unit where that makes the risk and evidence easier to manage.

Use outcome-based stage gates

Tie funding to evidence rather than calendar milestones.

Discovery gate: the problem, baseline, owner and AI role are credible.

Prototype gate: representative testing shows a plausible route to quality and value.

Production gate: controls, integration, users, monitoring and support are ready.

Scale gate: live performance and adoption support expansion.

At every gate, allow proceed, refine and stop. Record the reasons and assumptions.

Measure the strategy as a portfolio

Track more than the number of pilots.

  • Workflows with named owners and baselines.
  • Time from idea to evidence-backed decision.
  • Proportion of pilots stopped or refined before expensive scaling.
  • Live systems meeting quality and risk thresholds.
  • Adoption on eligible work.
  • Realised capacity, service, quality or financial outcomes.
  • Reuse of data, evaluation and control capabilities.
  • Incidents, near misses and overdue remediation.

A healthy portfolio will contain stopped ideas. If every pilot proceeds, the gates are probably weak.

Common strategy traps

Starting with an enterprise licence. Procurement can create activity before outcomes and ownership are clear.

Creating a separate AI strategy from business strategy. This produces use cases without operational sponsorship.

Centralising every decision. Shared standards help, but workflow owners must remain accountable for outcomes.

Treating training as adoption. Users adopt a tool when the workflow, incentives, interface and support work.

Planning three years of technology detail. Capabilities and suppliers will change. Be firm about outcomes and principles, then use quarterly evidence to adapt delivery.

What the final strategy should contain

A concise AI strategy can fit into ten sections:

  1. Business context and outcome themes.
  2. Scope and explicit exclusions.
  3. Decision principles.
  4. Prioritised use-case portfolio.
  5. Shared capability roadmap.
  6. Data and technology approach.
  7. Responsible-AI and control model.
  8. Operating model and decision rights.
  9. Measures and investment gates.
  10. Twelve-month roadmap.

The strategy is complete when leaders can use it to decide what to fund, what to stop and who owns the result.

Sorsana helps organisations turn AI ambition into a focused, evidence-led delivery portfolio. Explore our services or start a strategy conversation.

  • AI strategy
  • AI roadmap
  • Operating model