Can you show it.
A board can ask one question about AI that no dashboard answers. Not whether the model is accurate, and not whether a policy exists, but whether the institution can show that its AI operated inside the limits it set for itself, on the day it mattered, to someone who was not in the room.
A policy library does not answer it. A policy states an intention; a control enforces one. Where the two were never connected, the institution holds documents no system executes and logs no document explains, and the space between them is where the auditor, the supervisor and the claimant all arrive.
Closing that space is not a matter of principle. It takes a way to name what the institution may not cross, a way to turn each limit into something the running system enforces, and a record each enforcement leaves so the limit can be shown to have held. That work does not decompose into one framework. It decomposes into nine, and what follows is the decomposition rather than a collection.
Authority flows down. Evidence flows up.
The chain runs in one direction, and each link is a place it breaks.
Governance is where an institution states what binds it: statutes, supervisors, contracts, its own risk appetite, and in some institutions a Sharia Supervisory Board, where it holds binding approval power. Boundaries are what those obligations become once written precisely enough to enforce: a clause the system may not cross, held apart from everything the system is free to optimize. AI architecture is where that separation is either designed in or lost, because a boundary the platform cannot express is one it will cross while scoring well on every metric it was given. Controls are boundaries made executable: the residency rule that routes the request, the gate that will not open without a named signature, the authority ceiling an agent cannot raise for itself. Evidence is what a control leaves so the boundary can be shown to have held, months later, to someone who was not there.
Authority travels down that chain. Evidence travels back up it. An institution that cannot trace both directions for one of its controls has not found a documentation gap. It has found its first finding.
A policy states an intention. A control enforces one.
Nine frameworks, and what each is for.
REG-01 MESA Framework™
Governance maturity reported as one grade is the mechanism by which a strong regulatory posture conceals a substrate that cannot hold it up. MESA separates institutional AI governance into four altitudes, each carrying one accountable role and an evidence requirement an auditor can test, and reports a profile that names which altitude is failing. Its enforcement constraint is the sharp edge: a policy operates at the maturity of the substrate that has to enforce it, not at the maturity of the policy.
REG-02 MESA MRM Framework™
Validation confers the right to be believed. MESA MRM specifies model risk management as six steps: inventory, pre-validation, independent validation, approval, monitoring and revalidation. A model that has not been independently validated may be operated, and its outputs are not evidence of anything to anyone outside the team that built it. The approval record names a person, never a committee. Where a Sharia Supervisory Board holds binding approval power, validation carries a second and independent track.
REG-03 AI Data Governance Framework™
Whether a given item of data may sit in a given AI system should be answerable from a record rather than from a recollection, and the answer should survive the departure of the person who gave it. Five stages carry it: classify, bound, prove, gate, release. A lineage graph with one unattested hop is not a lineage graph, because the artifact exists to be reconstructed end to end and a single gap defeats the reconstruction.
REG-04 AI Vendor Risk Framework (AVRF)™
Most of an institution’s AI exposure arrives through a boundary it cannot inspect. AVRF governs it in five stages: classify, diligence, contract, monitor, exit. Its instrument is a fifty-six-question due-diligence questionnaire in seven sections, every question carrying a fixed answer format and a stated evidence expectation, which is what makes two completed responses comparable rather than merely similar. An answer submitted without evidence is recorded as a vendor assertion.
REG-05 AI Incident Response Protocol (AIRP)™
An institution can contain an incident it cannot explain, and it is the explanation an authority asks for. AIRP runs six stages: signal, classify, contain, escalate, reconstruct, close. Its hardest requirement sits in the fifth. An incident is explainable only if the evidence needed to reconstruct it existed at the moment of the decision, bound to the policy version then in force. Evidence assembled afterwards reconstructs the institution’s beliefs, not the system’s behaviour.
REG-06 Five-Gate Deployment Model™
Five-Gate is the lifecycle spine of the family. No AI system reaches production, or remains there, except by passing five gates in order: G1 Data and Design, G2 Validation, G3 Approval, G4 Deployment, G5 Operation. Each gate carries entry criteria supplied by another framework, one named accountable person, and a required record. A pipeline enforces a sequence. A gate assigns a person to it.
REG-07 AI Governance Operating Model
A mandate that is not exercised on a schedule and recorded is an intention. The Operating Model specifies how the governance function itself exists, in three parts: structure, the office and its place in the three lines; decision rights, with exactly one person accountable per decision; and cadence, the rhythm on which the function operates and the escalation paths on which disputes terminate. A cadence with no meeting records is not a cadence.
REG-08 Sharia AI Compliance Framework (SACF)™
An Islamic financial institution operates under two binding authorities, and the usual response is to build a second governance process beside the first. SACF proposes that the second process is the error. The Sharia Supervisory Board is constituted as an authority source at the Regulatory Floor alongside the civil supervisor, so its determinations cascade through the same machinery: one governance system, two authority sources, one record set. Three threads carry it into existing disciplines, and escalation is concurrent rather than sequential.
No Sharia Supervisory Board has reviewed or endorsed this framework. It is an engineering proposal for how binding Sharia authority can be integrated into AI lifecycle governance, offered for scholarly and institutional review.
The Halal data certification chain is author methodology. No standard-setter recognizes such a chain. It must not be presented as an existing requirement of any Sharia standard.
REG-09 Cross-Border AI Architecture Patterns™
A residency rule is not a reason a deployment cannot proceed. It is a determinant of the architecture the deployment takes. Four patterns follow from one uncrossable clause: Sovereign Silo, Federated, Regional Hub and Hybrid, selected by enumerating the boundary set per jurisdiction and classifying each workload against it. A pattern selected without a documented boundary set is a topology choice rather than a compliance position.
The catalogue.
Position is where a framework sits in the architecture. Seven of the nine occupy exactly one MESA altitude: the Regulatory Floor, the Strategic Compass, Operational Machinery or the Technical Substrate. Two do not, for opposite reasons. MESA defines the altitudes and therefore occupies none of them. Cross-Border AI Architecture Patterns sits under the Boundary Invariant rather than under an altitude, on the data residency boundary class, which is why its entry reads as a boundary class and not as an altitude.
Deposited means a standalone, versioned specification exists and carries a DOI. Source treatment means none does, and the framework’s authoritative treatment is a named chapter of a published book. The status is reported rather than smoothed over, because a framework’s version is the version of its specification and is otherwise undefined.
| ID | Canonical name | Mark | Position in the architecture | Specification |
|---|---|---|---|---|
| REG-01 | MESA Framework™ | ™ | None. The frame itself | Deposited · 10.5281/zenodo.22109836 |
| REG-02 | MESA MRM Framework™ | ™ | Operational Machinery | Source treatment · Chapter 12 of AI Governance and Compliance Frameworks for the Middle East: The Enterprise Playbook, ISBN 978-1-0678960-1-0 |
| REG-03 | AI Data Governance Framework™ | ™ | Technical Substrate | Source treatment · Chapter 13 of the Enterprise Playbook, ISBN 978-1-0678960-1-0 |
| REG-04 | AI Vendor Risk Framework (AVRF)™ | ™ | Operational Machinery | Deposited · 10.5281/zenodo.22170146 |
| REG-05 | AI Incident Response Protocol (AIRP)™ | ™ | Operational Machinery | Source treatment · Chapter 15 of the Enterprise Playbook, ISBN 978-1-0678960-1-0 |
| REG-06 | Five-Gate Deployment Model™ | ™ | Operational Machinery | Deposited · 10.5281/zenodo.22170122 |
| REG-07 | AI Governance Operating Model | Deliberately unmarked | Strategic Compass | Source treatment · Chapters 10 and 11 of the Enterprise Playbook, ISBN 978-1-0678960-1-0, read together with the consolidation notice at section 6.2 |
| REG-08 | Sharia AI Compliance Framework (SACF)™ | ™ | Regulatory Floor | Deposited · 10.5281/zenodo.22170143 |
| REG-09 | Cross-Border AI Architecture Patterns™ | ™ | data residency | Source treatment · Chapter 9 of the Enterprise Playbook, ISBN 978-1-0678960-1-0 |
The register is served unmodified as registry-v1.0.json against its published schema, so a third party can validate it rather than trust it. The specification document governs; the JSON is a representation of it, and where they disagree the JSON is defective.
A second family, and why it is unmarked.
Two families sit under Defensible AI: a governance family that fixes what the institution owes, and an engineering family that fixes what the system enforces, and each is governed by its own specification rather than by the other.
The nine above are the governance family, catalogued by the registry, and eight of them carry marks. The engineering family is A Pattern Language for Production LLM Platforms and the constructs it defines: PEVG, PARA, the Boundary Invariant and the BOE Declaration. Every name in it is deliberately unmarked, and the reason is not modesty. A mark on a design pattern suppresses the citation the pattern needs in order to spread. Their defensibility rests on a dated, citable priority record rather than on a symbol.
Where the registry and the Pattern Language specification describe the same relationship, the registry governs for the governance family and the Pattern Language specification governs for the engineering family.
A Pattern Language for Production LLM Platforms · PEVG · PARA
What this does not claim.
The contribution is architectural rather than empirical. The registry describes a composition. No institution unconnected to the author has been observed operating the composed set, no framework in it carries an independent evaluation, and the registry states what would falsify the composition as distinct from what would falsify any framework within it. It is a specification, not a certification scheme, and no conformity assessment body operates against it. Applying every framework here does not establish compliance with any statute or supervisory expectation. The frameworks are structures for producing and organizing evidence. Whether that evidence satisfies an authority is the authority’s determination.