Relationships are typed, not implied.
The register asserts 31 relationships across the nine frameworks. They are not decoration on the catalogue. A framework that supplies evidence to another has a downstream consumer whose gate will not open without it, and an institution adopting one framework in isolation inherits an obligation it cannot see from that framework alone. The map is the part that says which obligations those are.
Every relationship is typed, and the types are defined in the register rather than left to inference. 7 types are authored; one of them, supersedes, is declared and carries no instances yet.
| Type | Definition, as published | Edges |
|---|---|---|
| instantiates | The source framework occupies the named MESA altitude of the target. Asserted by the subordinate framework. | 7 |
| grants-authority-to | The source grants the authority under which the target operates. Asserted by the granting framework. | 1 |
| supplies-evidence-to | An output of the source is an input or a gate entry criterion of the target. Asserted by the producing framework. | 17 |
| threads-into | The source inserts a required branch into the target's own procedure. Asserted by the authority source. | 3 |
| absorbs | The source has taken over the subject of a framework or instrument that no longer exists separately. | 2 |
| supersedes | The source replaces the target, which is retired. | — |
| worked-instance-of | The source is the application of a named law or boundary class to one domain. | 1 |
consumes-evidence-of is not an authored type. It is the derived converse of supplies-evidence-to. See section 5.4 of the governing document.
That distinction is load-bearing on this page. Where a framework is shown receiving evidence, the assertion belongs to the framework that produces it. Nothing here asserts a converse the register declines to author.
Authority has one source.
Two of the 6 types in use carry the structure. grants-authority-to appears once, and that single edge is the root of the family: AI Governance Operating Model grants the authority under which 5 of the others operate. Charter, decision rights and release authority come from one place. A framework operated without that charter is being run on the authority of whoever happened to start it.
| ID | Framework | Grants authority to | On what subject |
|---|---|---|---|
| REG-07 | AI Governance Operating Model | MESA MRM Framework™ AI Data Governance Framework™ AI Vendor Risk Framework (AVRF)™ AI Incident Response Protocol (AIRP)™ Five-Gate Deployment Model™ | Charter, decision rights, release authority |
instantiates appears 7 times and does the other structural job: it places each framework at a MESA altitude, which is how the family has a coordinate system rather than a list. MESA Framework™ is not a peer of the eight. It is the frame they are positioned in, and 6 of these edges say so on exactly that subject.
| ID | Framework | Instantiates | On what subject |
|---|---|---|---|
| REG-02 | MESA MRM Framework™ | MESA Framework™ | Position in the maturity vector |
| REG-03 | AI Data Governance Framework™ | MESA Framework™ | Position in the maturity vector |
| REG-04 | AI Vendor Risk Framework (AVRF)™ | MESA Framework™ | Position in the maturity vector |
| REG-05 | AI Incident Response Protocol (AIRP)™ | MESA Framework™ | Position in the maturity vector |
| REG-06 | Five-Gate Deployment Model™ | MESA Framework™ | Position in the maturity vector |
| REG-07 | AI Governance Operating Model | MESA Framework™ | Position in the maturity vector |
| REG-08 | Sharia AI Compliance Framework (SACF)™ | MESA Framework™ | Registration as an authority source |
What will not open without a record.
supplies-evidence-to is the commonest relationship in the register, 17 of 31 edges. It means an output of one framework is an input or a gate entry criterion of another — not that the two are related in spirit, but that one will not function correctly without a record the other produces.
The shape is worth reading off the table. AI Incident Response Protocol (AIRP)™ receives from 7, and Five-Gate Deployment Model™ receives from 6. Those two are where the family converges: a deployment gate that cannot open without upstream records, and an incident protocol that cannot reconstruct an event without them. Evidence is not filed for its own sake in this architecture. It is filed because something downstream is going to ask for it, and the map says what.
A second authority changes the procedure.
threads-into is the strongest claim in the vocabulary: the source inserts a required branch into the target's own procedure. Not an input — a change to how the other framework runs. All 3 instances come from one framework, Sharia AI Compliance Framework (SACF)™, and the register notes the type is asserted by the authority source rather than by the framework being modified.
That is the structural consequence of a second binding authority. Where a Sharia Supervisory Board holds approval power, validation does not gain a checklist item; it gains a second and independent track, and the same is true at data certification and at vendor diligence. An institution outside that scope runs the three unmodified procedures. An institution inside it runs three different procedures, and the difference is asserted here rather than left to be discovered during an examination.
| ID | Framework | Threads into | On what subject |
|---|---|---|---|
| REG-08 | Sharia AI Compliance Framework (SACF)™ | MESA MRM Framework™ | The dual-validation branch at step three |
| REG-08 | Sharia AI Compliance Framework (SACF)™ | AI Data Governance Framework™ | The Halal data certification chain |
| REG-08 | Sharia AI Compliance Framework (SACF)™ | AI Vendor Risk Framework (AVRF)™ | Sharia vendor screening at diligence |
What was folded in, and from where.
absorbs records where the family changed shape. 2 edges account for 4 instruments that no longer exist separately, each folded into a framework that took over its subject. This is the part of the register that makes the work auditable over time rather than only at present: a reader who met one of these names in an earlier draft can see what happened to it, and that it was consolidated rather than quietly dropped.
| ID | Framework | Absorbs | On what subject |
|---|---|---|---|
| REG-01 | MESA Framework™ | Governance Maturity Model, retired | The maturity vector replaces the retired instrument |
| REG-07 | AI Governance Operating Model | Governance Office Blueprint, retired RACI-AI Matrix, retired Governance Cadence Framework, retired | Structure, decision rights and cadence become three sections of one framework |
A framework set that only ever shows its current state asks to be taken on trust. Naming the retired instruments, and which framework now carries each subject, is what lets someone check that the consolidation was a consolidation and not a loss. The register also declares supersedes and has not yet used it: nothing in the family has been replaced outright.
One edge leaves the register.
One edge crosses out of the governance family entirely. worked-instance-of means the source is the application of a named law or boundary class to one domain, and the single instance connects the register to the engineering family: Cross-Border AI Architecture Patterns™ is a worked instance of the Boundary Invariant, which is specified in the Pattern Language rather than in the register.
That is the only structural link between the two families, and it is deliberately narrow. The families are governed by different documents — registry section 2.6 gives the Pattern Language precedence on its own side — and one worked instance is a claim about a single framework, not a merger of two bodies of work. Defensible AI is the umbrella over both; it is not a third framework.
The engineering family is not catalogued here and carries no REG ids, deliberately. Its two constructs have their own deposited specifications: PEVG, the planner, executor, verifier and generator decomposition, and PARA, the four faculties and the authority each one holds.
| ID | Framework | Worked instance of | On what subject |
|---|---|---|---|
| REG-09 | Cross-Border AI Architecture Patterns™ | The Boundary Invariant, data residency boundary class, 10.5281/zenodo.22109864 | Residency is the boundary; topology is the optimization |
What each asserts, and what is asserted of it.
The same 31 edges, arranged by framework. The two columns are not symmetrical and the asymmetry is the point: the left column is what this framework claims, and the right column is what other frameworks claim about it. The register attributes every assertion to the framework that makes it, so a reader can tell whose claim they are reading.
REG-01 MESA Framework™
Asserts · 1 · Is named by · 7 · Detailed usage →
absorbs→ Governance Maturity Model, retired — The maturity vector replaces the retired instrument
- MESA MRM Framework™
instantiatesthis — Position in the maturity vector - AI Data Governance Framework™
instantiatesthis — Position in the maturity vector - AI Vendor Risk Framework (AVRF)™
instantiatesthis — Position in the maturity vector - AI Incident Response Protocol (AIRP)™
instantiatesthis — Position in the maturity vector - Five-Gate Deployment Model™
instantiatesthis — Position in the maturity vector - AI Governance Operating Model
instantiatesthis — Position in the maturity vector - Sharia AI Compliance Framework (SACF)™
instantiatesthis — Registration as an authority source
REG-02 MESA MRM Framework™
Asserts · 3 · Is named by · 5 · Detailed usage →
instantiates→ MESA Framework™ — Position in the maturity vectorsupplies-evidence-to→ Five-Gate Deployment Model™ — Validation and approval records, at G2 and G3supplies-evidence-to→ AI Incident Response Protocol (AIRP)™ — Validation and approval records, for reconstruction
- AI Governance Operating Model
grants-authority-tothis — Charter, decision rights, release authority - AI Data Governance Framework™
supplies-evidence-tothis — Data lineage and classification, at pre-validation - AI Vendor Risk Framework (AVRF)™
supplies-evidence-tothis — Vendor evidence where the model under validation is third-party - AI Incident Response Protocol (AIRP)™
supplies-evidence-tothis — Revalidation triggers - Sharia AI Compliance Framework (SACF)™
threads-intothis — The dual-validation branch at step three
REG-03 AI Data Governance Framework™
Asserts · 5 · Is named by · 2 · Detailed usage →
instantiates→ MESA Framework™ — Position in the maturity vectorsupplies-evidence-to→ MESA MRM Framework™ — Data lineage and classification, at pre-validationsupplies-evidence-to→ Five-Gate Deployment Model™ — Classification, lineage and residency attestations, at G1supplies-evidence-to→ Cross-Border AI Architecture Patterns™ — The residency rule set the patterns architect aroundsupplies-evidence-to→ AI Incident Response Protocol (AIRP)™ — Classification and lineage records, for reconstruction
- AI Governance Operating Model
grants-authority-tothis — Charter, decision rights, release authority - Sharia AI Compliance Framework (SACF)™
threads-intothis — The Halal data certification chain
REG-04 AI Vendor Risk Framework (AVRF)™
Asserts · 4 · Is named by · 2 · Detailed usage →
instantiates→ MESA Framework™ — Position in the maturity vectorsupplies-evidence-to→ MESA MRM Framework™ — Vendor evidence where the model under validation is third-partysupplies-evidence-to→ Five-Gate Deployment Model™ — Vendor clearance at G1, contractual controls at G4supplies-evidence-to→ AI Incident Response Protocol (AIRP)™ — Vendor risk records and monitoring logs, for reconstruction
- AI Governance Operating Model
grants-authority-tothis — Charter, decision rights, release authority - Sharia AI Compliance Framework (SACF)™
threads-intothis — Sharia vendor screening at diligence
REG-05 AI Incident Response Protocol (AIRP)™
Asserts · 3 · Is named by · 8 · Detailed usage →
instantiates→ MESA Framework™ — Position in the maturity vectorsupplies-evidence-to→ MESA MRM Framework™ — Revalidation triggerssupplies-evidence-to→ Five-Gate Deployment Model™ — Armed detection triggers at G5, and loop-back reopening G2
- AI Governance Operating Model
grants-authority-tothis — Charter, decision rights, release authority - MESA MRM Framework™
supplies-evidence-tothis — Validation and approval records, for reconstruction - AI Data Governance Framework™
supplies-evidence-tothis — Classification and lineage records, for reconstruction - AI Vendor Risk Framework (AVRF)™
supplies-evidence-tothis — Vendor risk records and monitoring logs, for reconstruction - Five-Gate Deployment Model™
supplies-evidence-tothis — Gate passage records, for reconstruction - AI Governance Operating Model
supplies-evidence-tothis — Escalation paths and escalation records - Sharia AI Compliance Framework (SACF)™
supplies-evidence-tothis — Sharia-materiality classification and board approvals - Cross-Border AI Architecture Patterns™
supplies-evidence-tothis — Routing evidence per request, for reconstruction
REG-06 Five-Gate Deployment Model™
Asserts · 2 · Is named by · 7 · Detailed usage →
instantiates→ MESA Framework™ — Position in the maturity vectorsupplies-evidence-to→ AI Incident Response Protocol (AIRP)™ — Gate passage records, for reconstruction
- AI Governance Operating Model
grants-authority-tothis — Charter, decision rights, release authority - MESA MRM Framework™
supplies-evidence-tothis — Validation and approval records, at G2 and G3 - AI Data Governance Framework™
supplies-evidence-tothis — Classification, lineage and residency attestations, at G1 - AI Vendor Risk Framework (AVRF)™
supplies-evidence-tothis — Vendor clearance at G1, contractual controls at G4 - AI Incident Response Protocol (AIRP)™
supplies-evidence-tothis — Armed detection triggers at G5, and loop-back reopening G2 - Sharia AI Compliance Framework (SACF)™
supplies-evidence-tothis — Dual-validation closure, at G3 - Cross-Border AI Architecture Patterns™
supplies-evidence-tothis — The deployment topology, approved at G4
REG-07 AI Governance Operating Model
Asserts · 4 · Is named by · 0 · Detailed usage →
instantiates→ MESA Framework™ — Position in the maturity vectorabsorbs→ Governance Office Blueprint, retired, RACI-AI Matrix, retired, Governance Cadence Framework, retired — Structure, decision rights and cadence become three sections of one frameworkgrants-authority-to→ MESA MRM Framework™, AI Data Governance Framework™, AI Vendor Risk Framework (AVRF)™, AI Incident Response Protocol (AIRP)™, Five-Gate Deployment Model™ — Charter, decision rights, release authoritysupplies-evidence-to→ AI Incident Response Protocol (AIRP)™ — Escalation paths and escalation records
Nothing is asserted about it by another framework.
REG-08 Sharia AI Compliance Framework (SACF)™
Asserts · 6 · Is named by · 0 · Detailed usage →
instantiates→ MESA Framework™ — Registration as an authority sourcesupplies-evidence-to→ Five-Gate Deployment Model™ — Dual-validation closure, at G3supplies-evidence-to→ AI Incident Response Protocol (AIRP)™ — Sharia-materiality classification and board approvalsthreads-into→ MESA MRM Framework™ — The dual-validation branch at step threethreads-into→ AI Data Governance Framework™ — The Halal data certification chainthreads-into→ AI Vendor Risk Framework (AVRF)™ — Sharia vendor screening at diligence
Nothing is asserted about it by another framework.
REG-09 Cross-Border AI Architecture Patterns™
Asserts · 3 · Is named by · 1 · Detailed usage →
supplies-evidence-to→ Five-Gate Deployment Model™ — The deployment topology, approved at G4supplies-evidence-to→ AI Incident Response Protocol (AIRP)™ — Routing evidence per request, for reconstructionworked-instance-of→ The Boundary Invariant, data residency boundary class, 10.5281/zenodo.22109864 — Residency is the boundary; topology is the optimization
- AI Data Governance Framework™
supplies-evidence-tothis — The residency rule set the patterns architect around
The register governs, this page is derived.
This page is a rendering. The instrument it renders is the Defensible AI Framework Registry, and its canonical machine form is registry-v1.0.json, served unmodified against its published schema. Every edge above is read from that file at build time rather than transcribed. The relationships array carries all 31, each with its type, its subject, and the altitude it applies at.
Cite the register as: The Defensible AI Framework Registry, version 1.0. 10.5281/zenodo.22170112. That is the concept DOI and it always resolves to the latest version. CC BY 4.0.
The specification document governs, the JSON represents it, and this page is derived from the JSON. Where the page and the JSON differ the page is defective; where the JSON and the specification differ the JSON is defective. Nothing on this page should be cited in place of the register.