Published September 15, 2026 | Version 2.0

The Defensible AI Framework Registry: Definitions and Relationships for the Governed Production AI Discipline

Authors/Creators

  • 1. iSystematic Inc.

Description

A body of frameworks that shares an author does not thereby share an architecture. Nine frameworks for governing artificial intelligence in regulated institutions were developed and published separately, each answering a question a supervisor or a board had asked. Read together they carried three defects that no individual framework could show: three separate names described one subject, two instruments measured the same maturity, and nothing stated why any of them belonged in the same system as the others.

This registry is the instrument that fixes those defects and the authoritative record of the result. It states one architecture for the nine, assigns each framework a stable identifier and a canonical name, and publishes a normative relationship register naming which framework supplies the artifact, evidence or authority another depends on.

The architecture rests on two propositions that are already published and separately citable. The MESA Framework™, a four-altitude diagnostic model for institutional AI governance, supplies the frame: governance is an alignment condition across those altitudes, so maturity is reported as a per-altitude profile rather than as a single grade. The Boundary Invariant supplies the engineering law: a boundary is a clause the optimizer may not cross, and everything else is optimization. Between them they fix the two directions in which the composed system is read. Authority flows down, from the altitude that binds to the control that executes. Evidence flows up, from the record a control writes to the profile the institution reports.

Each of the nine entries carries a definition, a purpose, an altitude or boundary class, inputs, outputs, one accountable role, an evidence requirement, its relationships, its limitations, the condition that would falsify it, and its change history. Every accountable role must be occupiable by one person: a committee can be consulted, can review and can decide, but cannot be accountable, because the question an authority asks after a failure is which person is answerable.

The entry schema is normative and is published in machine-readable form as registry-v2.0.json, validated against a published JSON Schema, so that a machine interface and the document cannot drift apart without one of them failing a test. Relationships are asserted once and read from both ends: the converse of an edge is derived, never authored, because a dependency written down twice is a dependency that can be written down twice differently.

The registry is also the dated instrument of a consolidation. Three marks are recorded as consolidated into one framework, one instrument as superseded, one framework as renamed, and one as repositioned from peer framework to worked instance of the Boundary Invariant. Twelve asserted marks became eight marks and one deliberately unmarked framework at version 1.0. At version 2.0 the unmarked framework is renamed to CADRE™ and marked, giving nine marks, and every entry now points at a standalone deposited specification.

The contribution is architectural rather than empirical. The registry describes a composition. No institution unconnected to the author has been observed operating the composed set, no framework in it carries an independent evaluation, and the specification states separately what would falsify the composition and what would falsify any framework within it. Two frameworks depend on an authority that has not acted: no Shariah Supervisory Board has reviewed the dual-authority architecture, and no trademark clearance search has been completed on the deployment model's name. Both are recorded in their entries rather than left to be discovered.

It is a specification, not a certification scheme, and no conformity assessment body operates against it.

Table of contents (English)

1. Introduction 2. The Architecture (Normative) 3. The Registry Entry Schema (Normative) 4. The Nine Registry Entries (Normative) 5. The Relationship Register (Normative) 6. Consolidation Notice (Normative) 7. The Machine-Readable Layer (Normative) 8. Conformance (Normative) 9. Related Work 10. Limitations and What Has Not Been Tested 11. Versioning and Change Control 12. References Appendix A. Former Names and Retired Marks Appendix B. Publication Provenance

Technical info (English)

Version 1.0 of the specification. 41 pages as rendered, with every figure as vector artwork rather than a raster image. 14 numbered sections and appendices, of which 7 are normative. 4 source SVG figures accompany the record and are reusable under the same licence. 22 references, each verified against a primary source. The Markdown source of record is deposited alongside the PDF, so the text is machine-readable without extraction.

Notes (English)

Version 2.0, a new version under the same concept DOI, which always resolves to the latest version and is the identifier to cite. Zenodo mints the version DOI at publish time, so none is supplied here. THIS IS A MAJOR VERSION FOR ONE REASON: registry entry REG-07 is renamed from the AI Governance Operating Model to CADRE, effective 1 September 2026, and the registry's own rule at 11.1 classifies a canonical name change as major. The identifier REG-07 is unchanged and the former name is RETAINED AS THE FRAMEWORK'S DESCRIPTOR rather than withdrawn from use, which distinguishes it from the registry's other rename; work published under the former name remains citable and is not an error. REG-07's mark status moves from unmarked to trademarked, so the governance family now carries nine marks and none deliberately unmarked; NO TRADEMARK CLEARANCE SEARCH HAS BEEN COMPLETED for the name CADRE, no registration has issued, no registered-mark symbol is used, and the specification records that as an open limitation rather than a closed question. THIS RECORD MUST PUBLISH AFTER THE FIVE SPECIFICATIONS IT NOW POINTS AT, because a reserved DOI does not resolve until the record it belongs to is published: all five entries that resolved only to a book chapter at version 1.0 move to `deposited` here, so every entry in the registry now points at a standalone specification. Each of the five is reconciled with its specification, THE SPECIFICATION GOVERNING, and each reconciliation is named in that entry's change history rather than applied silently. Two questions routed here by those specifications are disposed of and both change the register: the MESA MRM supply edge to the Five-Gate Deployment Model now carries the revalidation trigger register at gate five, and the authority grant from REG-07 now names REG-09, which held none. The CADRE specification states that the framework grants authority to five others; that was true of the register published at version 1.0 and is superseded here. The edge count is unchanged at thirty-one, the nine identifiers are unchanged, the entry schema and the conformance requirements are unchanged, so a version 1.0 conformance claim remains valid unless it named REG-07 by its former name. VERSION 1.0 IS NOT AMENDED and stays citable at its own version DOI; one error in it, an item at 11.4 stating that REG-01 might move from a status it did not hold, is corrected here and recorded rather than fixed silently. The Boundary Invariant, the BOE Declaration, PEVG and PARA remain deliberately unmarked. The CC BY 4.0 licence applies to the text and grants no rights in the marks. This is a specification, not a certification scheme; no conformity assessment body operates against it and conformance must not be represented as certification.

Files

CHANGELOG.md

Files (1.5 MB)

Name Size Download all
md5:6aa1c99d102f9500dcd4b4bf9048c07c
21.6 kB Preview Download
md5:07ca03906b6656ee2bde179ded7e9459
5.5 kB Download
md5:412fc3cd61dd2145be3bce20e902c06d
156.8 kB Preview Download
md5:7581a3235e52b81ffba1f494b7ce6e49
1.1 MB Preview Download
md5:97d671f4b3e220e589a84c3fccb2fce7
11.7 kB Preview Download
md5:8865a922979ff0d0ce0b85f2467669cd
9.6 kB Download
md5:523b5a017bd986862641a517dbab30a4
9.4 kB Download
md5:26acbf1df7266b51b8bf60aa1448c79d
10.3 kB Download
md5:86837e8426f739054bfedb14cf4c4540
7.4 kB Download
md5:e7250a90a04b3ef967776051b2cd7ccd
24.6 kB Preview Download
md5:42da6f256c8fc40a4765e7e37f3f6bd4
56.9 kB Preview Download

Additional details

Additional titles

Subtitle (English)
Registry Specification, Version 2.0
Alternative title (English)
AI Governance Framework Registry
Alternative title (English)
Enterprise AI Governance Frameworks: Canonical Names, Definitions, Relationships and Evidence Levels

References

  • Khan, N. A. (2026). The MESA Framework: A Four-Altitude Diagnostic Model for Institutional AI Governance. Framework Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22109836
  • Khan, N. A. (2026). A Pattern Language for Production LLM Platforms: Governed Routing, Agent Orchestration, and AI-Native Delivery. Pattern Language Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22109864
  • Khan, N. A. (2026). The Five-Gate Deployment Model: A Deployment Discipline for AI Systems. Deployment Model Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170122
  • Khan, N. A. (2026). PEVG: Planner, Executor, Verifier, Generator. Four Contracts, and the Two Boundaries a Verifier Does Not Both Hold. Pattern Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170132
  • Khan, N. A. (2026). PARA: Perception, Action, Reasoning, Adaptation. Four Faculties, Four Authority Types, and the Registry Entry That Turns a Faculty into a Contract. Pattern Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170139
  • Khan, N. A. (2026). The Sharia AI Compliance Framework: A Dual-Authority Governance Architecture for Islamic Finance. Framework Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170143
  • Khan, N. A. (2026). The AI Vendor Due-Diligence Questionnaire: AVRF Instrument for Third-Party AI Systems, Models and APIs. Questionnaire Specification. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22170146
  • Khan, N. A. (2026). The MESA MRM Framework: A Six-Step Model Risk Management Discipline for AI Systems. Framework Specification, Version 1.0. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22285045
  • Khan, N. A. (2026). The AI Data Governance Framework: A Five-Stage Control System for the Data Boundary in AI Systems. Framework Specification, Version 1.0. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22285047
  • Khan, N. A. (2026). The AI Incident Response Protocol: Six Stages, and the Evidence a Reconstruction Requires. Protocol Specification, Version 1.0. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22285057
  • Khan, N. A. (2026). CADRE: Charter, Authority, Decision Rights, Records, Escalation. The Governance Function Specified as Five Artifacts. Framework Specification, Version 1.0. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22285052
  • Khan, N. A. (2026). Cross-Border AI Architecture Patterns: Three Patterns, and Why the Fourth Is Not a Choice. Pattern Specification, Version 1.0. Zenodo. Concept DOI https://doi.org/10.5281/zenodo.22285049
  • Khan, N. A. (2026). AI Governance and Compliance Frameworks for the Middle East: The Enterprise Playbook. First Edition. iSystematic Inc. ISBN 978-1-0678960-1-0
  • Khan, N. A. (2026). LLM Systems in Production: Cloud-Native Patterns for AI Engineers. iSystematic Inc. ISBN 978-1-0678317-1-4
  • Khan, N. A. (2026). Prompt Systems and Agent Orchestration: Engineering Multi-Model AI Workflows. iSystematic Inc. ISBN 978-1-0678317-2-1
  • Khan, N. A. (2026). DevOps for AI-Native Platforms: Building, Governing, and Scaling AI Infrastructure. iSystematic Inc. ISBN 978-1-0678317-3-8
  • International Organization for Standardization and International Electrotechnical Commission (2023). ISO/IEC 42001:2023, Information technology. Artificial intelligence. Management system. First edition, December 2023.
  • National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1, 26 January 2023. Current as of the date of this registry; a revision is in progress and not published.
  • National Institute of Standards and Technology (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1, 26 July 2024. A companion to [18], not a replacement.
  • Office of the Superintendent of Financial Institutions, Canada (2025). Guideline E-23, Model Risk Management (2027). Published 11 September 2025, effective 1 May 2027. Scope includes artificial intelligence and machine learning models and models or data sourced from third parties.
  • Board of Governors of the Federal Reserve System, Office of the Comptroller of the Currency and Federal Deposit Insurance Corporation (2026). SR 26-2, Revised Guidance on Model Risk Management. Issued 17 April 2026. Supersedes and replaces SR 11-7 (2011) and SR 21-8 (2021).
  • National Institute of Standards and Technology (2025). Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. NIST SP 800-61 Revision 3, April 2025. Supersedes Revision 2.
  • Islamic Financial Services Board (2009). IFSB-10, Guiding Principles on Shariah Governance Systems for Institutions Offering Islamic Financial Services. December 2009.
  • Islamic Financial Services Board (2025). IFSB-31, Guiding Principles for Effective Supervision of Shariah Governance. July 2025. Examined for this registry; contains no treatment of artificial intelligence or machine learning.
  • Accounting and Auditing Organization for Islamic Financial Institutions (2025). AAOIFI signs collaboration MoU with the UK-based ICMA Digital Academy to introduce Gen-AI training programs in IFIs. Announcement, 27 February 2025. A training collaboration, not a standard or exposure draft.
  • Organisation for Economic Co-operation and Development. AI Incidents and Hazards Monitor. OECD.AI. https://oecd.ai/en/incidents
  • Responsible AI Collaborative. AI Incident Database. https://incidentdatabase.ai