FrameworkMESA FrameworkSheet 11

The MESA Framework (Maturity, Evidence, Substrate, Alignment).

One grade hides the floor it stands on. A four-altitude diagnostic model for institutional AI governance.

← Defensible AI · How the nine relate

§ 01Status

What this is.

REG-01 · MESA Framework™

Position in the architecture · None. MESA defines the altitudes and occupies none of them

Specification · Deposited. 10.5281/zenodo.22109836, CC BY 4.0.

The MESA Framework: four governance altitudes Four stacked layers. Layer 1 Regulatory Floor, binding obligations across jurisdictions. Layer 2 Strategic Compass, risk appetite, portfolio and positioning. Layer 3 Operational Machinery, gates, model risk management, data, vendor and incidents. Layer 4 Technical Substrate, telemetry, lineage, enforcement and logs. Arrows descend from Layer 1 to Layer 4 labelled strategic choice, governance machinery and runtime enforcement. A cascade arrow runs alongside in both directions. A constraint arrow runs upward from Layer 4 to Layer 3, labelled: Layer 4 constrains the effective state of runtime dependent Layer 3 controls. The MESA Framework: four governance altitudes Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22109836 https://doi.org/10.5281/zenodo.22109836 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/mesa INSTITUTIONAL AI GOVERNANCE LAYER 1 Regulatory Floor Binding obligations across jurisdictions and authorities strategic choice LAYER 2 Strategic Compass Risk appetite, portfolio, competitive positioning governance machinery LAYER 3 Operational Machinery Gates, model risk, data, vendor, incidents runtime enforcement LAYER 4 Technical Substrate Telemetry, lineage, enforcement, immutable logs cascade, both directions enforcement constraint Layer 4 constrains the effective state of any Layer 3 control whose effectiveness depends on runtime enforcement. The MESA Framework v1.1 · Nabeel Khan · nabeelkhan.com/frameworks/mesa · CC BY 4.0 · DOI 10.5281/zenodo.22109836
Figure 1. The four altitudes, each with one accountable role and an evidence requirement an auditor can test.
§ 02The single grade

The single grade.

Governance maturity reported as one number is not a summary. It is a concealment mechanism. An institution with a strong regulatory posture and a substrate that cannot enforce it scores respectably, and the score is the reason nobody looks at the substrate. MESA reports a profile across four altitudes instead, so the question stops being how mature the institution is and becomes which altitude is failing.

The MESA governance chain, closed loop A forward path runs left to right: Requirement, Decision, Control, Enforcement, Evidence. A reverse path runs right to left beneath it: Finding, Revalidation, Control change, Strategic decision, returning to Requirement. The forward path is labelled derivation and the reverse path is labelled correction. The MESA governance chain, closed loop Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22109836 https://doi.org/10.5281/zenodo.22109836 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/mesa DERIVATION Requirement Decision Control Enforcement Evidence CORRECTION Finding Revalidation Control change Strategic decision A requirement that does not complete the forward path is not governed, regardless of its documentation status. An institution that operates the forward path only has an open loop, and an open loop cannot correct itself. The MESA Framework v1.1 · Nabeel Khan · nabeelkhan.com/frameworks/mesa · CC BY 4.0 · DOI 10.5281/zenodo.22109836
Figure 2. The cross-layer cascade. Authority descends; evidence ascends.
§ 03The enforcement constraint

The enforcement constraint.

The sharp edge of the framework is a single claim: a policy operates at the maturity of the substrate that has to enforce it, not at the maturity of the policy. An institution may write an excellent standard and operate it at the maturity of the logging, lineage and access control underneath. The constraint is what makes the profile diagnostic rather than descriptive, because it says which altitude sets the ceiling.

§ 04On the name

On the name.

MESA stands for Maturity, Evidence, Substrate, Alignment. That is the only canonical expansion, established in the version 1.1 specification and recorded in the Defensible AI Framework Registry. The earlier expansion, Middle East Strategic Alignment, is RETIRED and is correct only when citing the earlier work; the framework is not regional and its scope was never geographic. Maturity reports. Evidence tests. Substrate bounds. Alignment is the proposition. Read in reverse, that is the order of derivation: the proposition first, then what it rests on, then what proves it, then what is published. The four letters are not the four altitudes, and conflating them is the error the retirement was meant to end.

§ 05What is published, and what is not

What is published, and what is not.

The four altitudes and the five maturity levels are published here and in the book. The free Readiness Self-Assessment scores against them in twelve questions, three per layer, and returns a per-layer profile immediately without gating the result. The fifty-question instrument and its five-level rubrics are published too: specified in the book and callable over MCP without a key. What is not published is the severity model and the evidence grading applied on top of them. Self-assessment tells you roughly where you stand; an examination produces an evidence-traced record.

§ 06Where it applies

Which institutions, and on whose authority.

Any regulated institution

MESA is institution-shaped rather than sector-shaped. It asks how mature an institution’s AI governance is across four altitudes, and the altitudes are the same in a bank, a hospital and a ministry. What changes by sector is which authority occupies the Regulatory Floor.

§ 07How it has changed

The record of its own revisions.

A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.

Change history

  • 2026-08-30 · entry v1.0 — First registry entry
  • 2026-08-30 · entry v1.0 — Records the retirement of the expansion Middle East Strategic Alignment at specification version 1.1, and the absorption of the Governance Maturity Model

Limitations recorded in the registry

  • That the four-altitude decomposition matches the way institutions actually fail. Recorded as untested in the framework specification.
  • The clause-level mappings to ISO/IEC 42001 and the NIST AI Risk Management Framework are the author's readings. Neither issuing body has reviewed or endorsed them.
  • No scoring dataset has been published, so no baseline exists against which a result can be positioned.
  • No institution unconnected to the author has published a MESA assessment.

What would show this to be wrong. MESA is falsified if institutions that score high at the Regulatory Floor, the Strategic Compass and Operational Machinery while scoring low at the Technical Substrate are found to experience AI governance failures at the same rate as institutions scoring high at all four. That finding would refute the enforcement constraint, which is the mechanism the four-altitude decomposition exists to express, and a framework whose central mechanism does not hold does not survive by being useful.

§ 08Honest limits

What this does not claim.

The contribution is architectural rather than empirical. No institution unconnected to the author has been observed operating the framework, and it carries no independent evaluation.

It is a diagnostic instrument, not a certification scheme. Scoring well against it establishes nothing about compliance with any statute or supervisory expectation.

§ 09Cite

Citation.

Cite this work. MESA Framework, version 1.1. 10.5281/zenodo.22109836. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.

§ 10Where this sits

In the practice.

§ 10Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”

A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.

Fin · Machine-Accessible Expertise
Point your assistant at the endpoint →