The MESA Framework: A Four-Altitude Diagnostic Model for Institutional AI Governance
Description
Institutional AI governance is commonly assessed as a single capability and reported as a single grade. That treatment obscures the failure that matters most: an institution can hold current policies, a chartered committee and a complete documentation set while the systems those documents describe cannot produce the evidence the documents claim.
This specification defines the MESA Framework (Maturity, Evidence, Substrate, Alignment) around one proposition: institutional AI governance is an alignment condition across distinct governance altitudes, and governance maturity should therefore be diagnosed as a multidimensional state rather than reported as a single organizational score. The framework separates governance into four altitudes, each with a definition, its inputs and outputs, a single accountable role, and an evidence requirement an auditor can test: a Regulatory Floor, a Strategic Compass, Operational Machinery and a Technical Substrate.
Five mechanisms operate the architecture: layer separation, cross-layer cascade, an enforcement constraint by which the Technical Substrate bounds the effective state of runtime-dependent controls, mandatory interface couplings between control families, and an evidence-based maturity vector. The framework is calibrated to regulated institutions operating AI systems under more than one binding authority source, including institutions for which a Sharia Supervisory Board holds binding approval power.
MESA does not replace ISO/IEC 42001 or the NIST AI Risk Management Framework. Section 3 maps the four altitudes to those documents at clause and category level and states which implementation decisions each deliberately delegates and which of those MESA instantiates. What MESA adds is diagnostic altitude: a per-layer maturity profile that names which altitude is failing, in place of a single grade that cannot.
The specification states explicitly what has not been tested, lists seven conditions that would falsify the framework, and sets out a ten-item empirical research agenda. It is a specification, not a certification scheme, and no conformity assessment body operates against it.
Version 1.1 makes two scope and naming clarifications and no normative change. The acronym is expanded as Maturity, Evidence, Substrate, Alignment; the prior expansion, Middle East Strategic Alignment, described the framework's origin rather than its scope and is retired, while the regional origin remains a matter of record and is not disclaimed. A new section derives each term from language already present in version 1.0 and states that the four terms are not the four altitudes. Section 7.6 supersedes the Governance Maturity Model published in the companion book, with an informative mapping table and a statement of why substrate maturity cannot be inferred from a prior result. The four altitudes, the five operating mechanisms, the clause-level mappings, the conformance language, the falsification conditions and the research agenda are unchanged.
Table of contents (English)
1. Scope and Definitions 2. Conceptual Model 3. Relationship to Existing Frameworks 4. Structural Properties (Normative) 5. The Four Layers (Normative) 6. Failure Taxonomy (Normative for incident classification) 7. Assessment 8. Limitations, Falsification and Research Agenda 9. Regulatory Snapshot Discipline (Normative) 10. References Appendix A. Representative assessment anchors Appendix B. Sharia-specific implementation profile Appendix C. Illustrative implementation profile Appendix D. Worked example, as a traceability trace Appendix E. Companion specificationsTechnical info (English)
Version 1.1 of the specification. 29 pages as rendered, with every figure as vector artwork rather than a raster image. 15 numbered sections and appendices, of which 4 are normative. 2 source SVG figures accompany the record and are reusable under the same licence. 22 references, each verified against a primary source. The Markdown source of record is deposited alongside the PDF, so the text is machine-readable without extraction.Notes (English)
Files
CHANGELOG.md
Files
(414.1 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:11a83dc22d240873d71ef5f6aae8803e
|
10.6 kB | Preview Download |
|
md5:018346a15105ff8d19a624dd793c0c28
|
2.9 kB | Download |
|
md5:ef123e1f934a10624290d672695792f9
|
5.7 kB | Download |
|
md5:d0927795d99ef1e4ed53245fbac1220e
|
103.2 kB | Preview Download |
|
md5:2a4e970647217835c161432baa59e2af
|
280.3 kB | Preview Download |
|
md5:864c72927c04847040051ad02bc776bb
|
5.3 kB | Download |
|
md5:a05b1dfb117cf7bcaf93d13560b690f6
|
6.1 kB | Preview Download |
Additional details
Additional titles
- Subtitle (English)
- Framework Specification, Version 1.1
- Alternative title (English)
- AI Governance Maturity Model
- Alternative title (English)
- AI Governance Maturity Assessment for Regulated Institutions
Identifiers
Related works
- Is documented by
- Other: https://nabeelkhan.com/frameworks/mesa (URL)
- Is supplement to
- Book: 978-1-0678960-1-0 (ISBN)
- References
- Standard: https://www.iso.org/standard/42001 (URL)
- Report: https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf (URL)
References
- ISO/IEC 42001:2023, Information technology. Artificial intelligence. Management system. International Organization for Standardization and International Electrotechnical Commission, Geneva, December 2023. Catalogue entry: https://www.iso.org/standard/42001. Note: clause and Annex A structure cited in Section 3.1 was triangulated across three independent published clause-by-clause listings; the standard text itself is available only under licence from ISO or a national member body.
- ISO/IEC 23894:2023, Information technology. Artificial intelligence. Guidance on risk management. ISO/IEC, Geneva, 2023.
- ISO/IEC 42005:2025, Information technology. Artificial intelligence (AI). AI system impact assessment. ISO/IEC, Geneva, 2025. Catalogue entry: https://www.iso.org/standard/42005.
- ISO/IEC 42006:2025, Information technology. Artificial intelligence. Requirements for bodies providing audit and certification of artificial intelligence management systems. ISO/IEC, Geneva, 2025. Catalogue entry: https://www.iso.org/standard/42006.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. Gaithersburg, MD, January 2023. https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf. Core functions, categories and subcategories cited in Section 3.2 verified against the NIST AI Resource Center rendering of Section 5, AI RMF Core: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/. Risk-tolerance quotation verified verbatim at Section 1.1.2, Risk Tolerance: https://airc.nist.gov/airmf-resources/airmf/1-sec-risk/.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1. Gaithersburg, MD, 26 July 2024. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union.
- Regulation (EU) 2026/1744 of the European Parliament and of the Council, commonly cited as the Digital Omnibus on AI, amending Regulation (EU) 2024/1689, Regulation (EU) 2018/1139 and Regulation (EU) 2023/1230. Published in the Official Journal on 24 July 2026; entered into force 27 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng.
- Amended application dates under [8]: stand-alone high-risk AI systems under Annex III of Regulation (EU) 2024/1689 apply from 2 December 2027; AI embedded in products regulated under Annex I from 2 August 2028; Article 50 transparency obligations remain applicable from 2 August 2026, with a grace period to 2 December 2026 for the Article 50(2) marking duty on systems placed on the market before that date. The Article 4 AI-literacy obligation was amended by [8] rather than deferred or repealed, and it carries two distinct dates. It has been in application since 2 February 2025. National market surveillance authorities begin supervising and enforcing it from 2 August 2026. The duty continues to sit on providers and deployers, who shall take measures to support the development of AI literacy among their staff and among those operating systems on their behalf. What the amendment changed is that the duty is now an obligation of means rather than of result: the text does not require providers or deployers to guarantee any specific level of AI literacy in any individual, and a further paragraph tasks the Commission and the Member States with supporting those efforts, with particular regard to small and medium-sized enterprises. Verifier note: the European Commission's AI literacy questions-and-answers page renders the enforcement start as both 2 August 2026 and 3 August 2026 in different sentences. This document uses 2 August 2026, which is the AI Act's general date of application and the date carried by the Commission's own sentence on market surveillance authorities. https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers.
- Board of Governors of the Federal Reserve System, Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation. Supervisory Letter SR 26-2, Revised Guidance on Model Risk Management, 17 April 2026. Supersedes SR 11-7 (4 April 2011) and SR 21-8 (9 April 2021). https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm. Guidance attachment: https://www.federalreserve.gov/supervisionreg/srletters/SR2602.pdf. Footnote 3 of the guidance places generative AI and agentic AI models outside its scope, and it shall not be cited as an AI-specific instrument.
- Office of the Superintendent of Financial Institutions (Canada). Guideline E-23: Model Risk Management (2027). Final guideline published 11 September 2025; effective 1 May 2027 for federally regulated financial institutions. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027.
- United Arab Emirates. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Article 18 establishes a right to object to decisions issued with respect to automated processing that have legal consequences or seriously affect the data subject, including profiling. Note: the federal Executive Regulations were not yet gazetted at the date of this document; no penalty schedule is cited here for that reason.
- Kingdom of Saudi Arabia. Personal Data Protection Law, Royal Decree M/19 of 2021, as amended in 2023, together with its Implementing Regulations issued by the Saudi Data and Artificial Intelligence Authority. Automated-decision obligations sit in the Implementing Regulations and are cited generically here rather than pinned to an article number.
- Dubai International Financial Centre. Data Protection Regulations, Regulation 10, Processing Personal Data through Autonomous and Semi-autonomous Systems, in force 1 September 2023. https://www.difc.com/business/registrars-and-commissioners/commissioner-of-data-protection/regulation-10.
- Arab Republic of Egypt. Law No. 151 of 2020 on Personal Data Protection, together with its Executive Regulations issued by Ministerial Decree 816 of 2025.
- Islamic Financial Services Board. IFSB-10, Guiding Principles on Shari`ah Governance Systems for Institutions Offering Islamic Financial Services. Kuala Lumpur, December 2009. https://www.ifsb.org/wp-content/uploads/2023/10/IFSB-10-December-2009_En.pdf.
- Islamic Financial Services Board. IFSB-31, Guiding Principles for Effective Supervision of Shari`ah Governance. Kuala Lumpur, July 2025. https://www.ifsb.org/wp-content/uploads/2025/07/IFSB-31-Guiding-Principles-for-Effective-Supervision-of-Shariah-Governance.pdf. IFSB-31 builds on IFSB-10 and does not replace it.
- Accounting and Auditing Organization for Islamic Financial Institutions. Governance Standard GS 1 (Revised 2024), Shari'ah Governance Framework, together with GS 19 to GS 22 on Shari'ah Supervisory Board appointment, functions, review and application to subsidiaries. https://aaoifi.com/issued-standards-2/?lang=en.
- Institute of Internal Auditors. The IIA's Three Lines Model: An Update of the Three Lines of Defense. Lake Mary, FL, July 2020.
- The Open Group. The TOGAF Standard, 10th Edition. 2022.
- DAMA International. DAMA-DMBOK: Data Management Body of Knowledge, 2nd edition. Technics Publications, 2017. ISBN 978-1-63462-234-9.
- Khan, N. A. AI Governance & Compliance Frameworks for the Middle East: The Enterprise Playbook. iSystematic Inc., 2026. ISBN 978-1-0678960-1-0 (paperback); 978-1-0678960-2-7 (hardcover). MESA is specified in Chapter 4.