What this is.
Position in the architecture · Operational Machinery
Specification · No standalone specification is deposited for this framework. Its authoritative treatment is Chapter 12 of AI Governance and Compliance Frameworks for the Middle East: The Enterprise Playbook, ISBN 978-1-0678960-1-0. This page and registry entry REG-02 are the most complete normative statement available in citable form.
The claim.
A model that has not been independently validated may be operated. Its outputs are not evidence of anything to a party outside the team that built it. That is the whole of the framework’s claim, and everything in it exists to make the moment at which a model’s fitness becomes a matter of record identifiable in time.
Six steps.
Inventory establishes what exists. Pre-validation establishes what the builder claims. Independent validation tests the claim by someone who did not make it. Approval binds a named person to the decision. Monitoring watches the assumptions the approval rested on. Revalidation returns when those assumptions move. Each step produces a record, and the record is the artifact the next step consumes.
Two roles, never one person.
The head of model risk owns the discipline. The named approving executive owns each approval. They must not be the same person for the same model, because independence is the property the framework exists to establish and a discipline that permits the builder to approve the build has not established it. Where a Sharia Supervisory Board holds binding approval power, validation carries a second and independent track, specified jointly with SACF.
Which institutions, and on whose authority.
Model risk management is where a supervisor already expects a written discipline, so this framework bites hardest where one exists — and the two instruments do not cover the same ground. OSFI Guideline E-23, effective 1 May 2027, applies to all federally regulated financial institutions in Canada, insurers included. In the United States, SR 26-2, issued 17 April 2026, superseded SR 11-7 and SR 21-8 and is expected to be most relevant to banking organizations with over thirty billion dollars in total assets; it does not reach insurance. Where an institution also has a Sharia Supervisory Board with binding approval power, validation carries a second and independent track.
Where it bites · Banking and capital markets · Insurance
The record of its own revisions.
A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.
Change history
- 2026-08-30 · entry v1.0 — First registry entry
Limitations recorded in the registry
- Alignment with supervisory model risk expectations. The source treatment contains no written crosswalk to current Canadian or United States supervisory guidance, and an institution MUST perform that crosswalk against the primary sources in force in its jurisdiction.
- No published validation report template and no worked validation example a validator could copy.
- Specifies the discipline, not the statistical or behavioural methods a validator applies within it.
What would show this to be wrong. MESA MRM is falsified if institutions operating the six steps with genuine second-line independence are found to approve unfit models at the same rate as institutions in which the building team validates its own work. The framework's entire claim rests on independence changing the outcome, and evidence that it does not would leave a process with no defensible reason to exist.
What this does not claim.
Asserted. Alignment with supervisory model risk expectations. The source treatment contains no written crosswalk to current Canadian or United States supervisory guidance. An institution relying on this for supervisory alignment must perform that crosswalk against the primary sources in force in its own jurisdiction.
Missing. No published validation report template and no worked validation example. The discipline is specified; the artifact it produces is not exemplified.
Scope. It specifies the discipline, not the statistical or behavioural methods a validator applies within it. It does not tell a validator how to validate.
Citation.
Cite this framework. No standalone specification is deposited. Its authoritative treatment is Chapter 12 of AI Governance and Compliance Frameworks for the Middle East: The Enterprise Playbook, ISBN 978-1-0678960-1-0, and its normative statement in citable form is registry entry REG-02 in 10.5281/zenodo.22170112.
In the practice.
- Governed production AI, the discipline this framework belongs to
- Defensible AI, the family and the register
- AI Governance and Compliance Frameworks for the Middle East, the source treatment
- Model risk, the service this framework is applied through
- AI governance in the wiring, on where governance actually lives