FrameworkAI Data Governance FrameworkSheet 54

The AI Data Governance Framework.

Answerable from a record, not from a recollection. A control system for the data boundary in AI systems.

← Defensible AI · How the nine relate

§ 01Status

What this is.

REG-03 · AI Data Governance Framework™

Position in the architecture · Technical Substrate

Specification · Deposited. 10.5281/zenodo.22285047, CC BY 4.0.

Renamed. This framework was asserted in the Enterprise Playbook as the AI Data Governance Stack. The name changed because the former implied a technology stack while the content is a control taxonomy. The former name remains valid for citing the earlier work and is not an error in it.

Composition at the gates of the Five-Gate Deployment Model Five gates in sequence. Gate one, Data and Design, takes entry evidence from REG-03 classification and lineage and from REG-04 vendor clearance, and is accountable to the named data owner. Gate two, Validation, takes REG-02 steps one and two, accountable to the named validator. Gate three, Approval, takes REG-02 steps three and four and the closed dual validation of REG-08, accountable to the named executive. Gate four, Deployment, takes release authority from REG-07 and contractual controls from REG-04, accountable to the named platform owner. Gate five, Operation, takes armed triggers from REG-05 and live monitoring, accountable to the named head of the governance office. Each gate writes a gate passage record naming who approved, on what evidence, and when. Two reverse paths run backwards: rollback returns gate five to gate four with evidence preserved, and loop-back reopens gate two after an incident at gate five. Every gate passage record is an instance of the BOE Declaration. Composition at the gates of the Five-Gate Deployment Model Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170112 https://doi.org/10.5281/zenodo.22170112 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/registry COMPOSITION AT THE GATES ENTRY EVIDENCE SUPPLIED BY REG-03 classification, lineage REG-04 clearance REG-02 steps 1 and 2 inventory, pre-validation REG-02 steps 3 and 4 REG-08 dual validation both tracks closed REG-07 release authority REG-04 contract terms REG-05 triggers armed monitoring live G1 Data and Design one named data owner G2 Validation one named validator G3 Approval one named executive G4 Deployment one named platform owner G5 Operation one named office head gate record who · on what · when gate record who · on what · when gate record who · on what · when gate record who · on what · when gate record who · on what · when ROLLBACK. G5 to G4, evidence preserved LOOP-BACK. an incident at G5 reopens G2 Every gate passage record is an instance of the BOE Declaration Boundary: the gate entry criteria. Optimizer: the deployment freedom granted on passage. Evidence: the record itself. This is what makes the governance and engineering families compose. The sequence and the entry criteria are normative. A gate passed without its entry evidence is not passed. The Defensible AI Framework Registry v2.0 · Nabeel Khan · nabeelkhan.com/frameworks/registry · CC BY 4.0 · DOI 10.5281/zenodo.22170112
Figure 1. Data classification and lineage are entry criteria for gate one.
§ 02Stated with the framework

Before the argument.

The Halal data certification chain is an original construct of this framework. No standard-setter recognizes such a chain. It is author methodology and must not be presented as an industry or supervisory requirement.

§ 03The requirement

The requirement.

Whether a given item of data may sit in a given AI system should be answerable from a record rather than from a recollection. The harder half is the second: the answer has to survive the departure of the person who gave it. An institution whose data decisions live in the memory of three people has a staffing dependency, not a control.

The three threads from the Sharia Supervisory Board into existing machinery The Sharia Supervisory Board sits at the Regulatory Floor as an authority source. Its determinations pass through a Maqasid risk frame, which classifies what an AI decision may harm in the terms of faith, life, intellect, lineage and wealth, and which determines materiality rather than inferring it. Three threads then enter machinery the institution already operates. Thread one, dual validation, enters model risk management at the independent validation step: a civil track and a Sharia track run concurrently and both must close before approval. Thread two, the Halal data certification chain, enters data governance and runs source permissibility, transform integrity and certified use, where an unattested hop breaks the chain. Thread three, Sharia screening, enters vendor risk at the diligence stage and screens the conduct of the vendor's AI in the institution's use. Each thread extends a discipline rather than standing up a parallel one, and each produces evidence that joins the institution's single record set. The three threads from the Sharia Supervisory Board into existing machinery Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170143 https://doi.org/10.5281/zenodo.22170143 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/sacf THREE THREADS INTO EXISTING MACHINERY REGULATORY FLOOR · AUTHORITY SOURCE Sharia Supervisory Board binding. Its determinations are satisfied, never weighed Maqasid risk frame what the decision may harm: faith · life · intellect · lineage · wealth materiality is determined by the board, never inferred by the institution THREAD 1 Dual validation into model risk management, at independent validation civil track Sharia track both must close before approval and THREAD 2 Halal data certification into data governance, at classification source permissibility transform integrity certified use an unattested hop breaks the chain THREAD 3 Sharia screening into vendor risk, at diligence the conduct of the vendor AI in the institution use the attestation records whether it rests on the vendor own statement evidence joins the institution single record set, not a second one The Sharia AI Compliance Framework v1.0 · Nabeel Khan · nabeelkhan.com/frameworks/sacf · CC BY 4.0 · DOI 10.5281/zenodo.22170143
Figure 2. The Halal data certification chain enters this framework at classification.
§ 04Five stages

Five stages.

Classify establishes what the data is. Bound establishes where it may go. Prove establishes that the boundary held. Gate refuses passage where it did not. Release records what left and under what authority. A lineage graph with one unattested hop is not a lineage graph, because the artifact exists to be reconstructed end to end and a single gap defeats the reconstruction.

§ 05Where it applies

Which institutions, and on whose authority.

Any regulated institution

The data boundary is sharpest wherever a classification regime already binds the institution, which is most acute in healthcare and in the public sector. The framework does not assume a regime; it assumes there is one and makes the answer to “may this data be here” a record rather than a recollection.

Where it bites · Healthcare · Government

§ 06How it has changed

The record of its own revisions.

A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.

Change history

  • 2026-08-30 · entry v1.0 — First registry entry
  • 2026-08-30 · entry v1.0 — Records the rename from AI Data Governance Stack, and the repositioning as the worked treatment of the data boundary class
  • 2026-09-15 · entry v2.0 — Specification status moves from `source-treatment` to `deposited` on the deposit of the AI Data Governance Framework specification, whose concept DOI the entry now carries
  • 2026-09-15 · entry v2.0 — Definition reconciled with that specification to record the residency rule set and its published schema
  • 2026-09-15 · entry v2.0 — The `missing` limitation recording no machine-readable classification schema is closed by residency-rule-set-schema-v1.0.json

Former names. AI Data Governance Stack. Each remains the correct citation for the work published under it and must not be used for new work.

Limitations recorded in the registry

  • The Halal data certification chain is an original construct of this framework. No standard-setter recognizes such a chain as of the date of this registry. It MUST be presented as author methodology and MUST NOT be presented as an industry or supervisory requirement.
  • Governs the data boundary. Does not specify data quality measurement methods, storage architecture or transformation tooling, and extends rather than replaces a general data management body of knowledge.

What would show this to be wrong. AI Data Governance is falsified if institutions maintaining attested lineage to the point of use are found unable to answer a data provenance question from an authority any faster, or any more defensibly, than institutions maintaining classification alone. The framework's cost sits almost entirely in the attestation of each hop, and evidence that the attestation adds nothing to the answer would remove its justification.

§ 07Honest limits

What this does not claim.

Missing. The registry recorded the absence of a machine-readable classification schema as the largest gap in this entry. The deposit closes it. A JSON Schema for a residency rule set, and for the selection made against it, is published with the specification and served at the identifier it declares: nabeelkhan.com/schema/residency-rule-set/1.0. It closes the corresponding gap in Cross-Border AI Architecture Patterns in the same object, because a rule set expressed once and read from both ends cannot drift. What it does not do is settle the question: a passing validation satisfies one of the seven requirements it was built to support, and part of a second. A pass is not a check.

§ 08Cite

Citation.

Cite this work. AI Data Governance Framework, version 1.0. 10.5281/zenodo.22285047. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.

§ 09Where this sits

In the practice.

§ 10Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”

A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.

Fin · Machine-Accessible Expertise
Point your assistant at the endpoint →