FrameworkMESA MRM FrameworkSheet 53

The MESA MRM Framework.

Validation confers the right to be believed. A six-step model risk management discipline.

← Defensible AI · How the nine relate

§ 01Status

What this is.

REG-02 · MESA MRM Framework™

Position in the architecture · Operational Machinery

Specification · Deposited. 10.5281/zenodo.22285045, CC BY 4.0.

Composition at the gates of the Five-Gate Deployment Model Five gates in sequence. Gate one, Data and Design, takes entry evidence from REG-03 classification and lineage and from REG-04 vendor clearance, and is accountable to the named data owner. Gate two, Validation, takes REG-02 steps one and two, accountable to the named validator. Gate three, Approval, takes REG-02 steps three and four and the closed dual validation of REG-08, accountable to the named executive. Gate four, Deployment, takes release authority from REG-07 and contractual controls from REG-04, accountable to the named platform owner. Gate five, Operation, takes armed triggers from REG-05 and live monitoring, accountable to the named head of the governance office. Each gate writes a gate passage record naming who approved, on what evidence, and when. Two reverse paths run backwards: rollback returns gate five to gate four with evidence preserved, and loop-back reopens gate two after an incident at gate five. Every gate passage record is an instance of the BOE Declaration. Composition at the gates of the Five-Gate Deployment Model Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170112 https://doi.org/10.5281/zenodo.22170112 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/registry COMPOSITION AT THE GATES ENTRY EVIDENCE SUPPLIED BY REG-03 classification, lineage REG-04 clearance REG-02 steps 1 and 2 inventory, pre-validation REG-02 steps 3 and 4 REG-08 dual validation both tracks closed REG-07 release authority REG-04 contract terms REG-05 triggers armed monitoring live G1 Data and Design one named data owner G2 Validation one named validator G3 Approval one named executive G4 Deployment one named platform owner G5 Operation one named office head gate record who · on what · when gate record who · on what · when gate record who · on what · when gate record who · on what · when gate record who · on what · when ROLLBACK. G5 to G4, evidence preserved LOOP-BACK. an incident at G5 reopens G2 Every gate passage record is an instance of the BOE Declaration Boundary: the gate entry criteria. Optimizer: the deployment freedom granted on passage. Evidence: the record itself. This is what makes the governance and engineering families compose. The sequence and the entry criteria are normative. A gate passed without its entry evidence is not passed. The Defensible AI Framework Registry v2.0 · Nabeel Khan · nabeelkhan.com/frameworks/registry · CC BY 4.0 · DOI 10.5281/zenodo.22170112
Figure 1. MESA MRM supplies the entry criteria for gate two and gate three of the Five-Gate Deployment Model.
§ 02The claim

The claim.

A model that has not been independently validated may be operated. Its outputs are not evidence of anything to a party outside the team that built it. That is the whole of the framework’s claim, and everything in it exists to make the moment at which a model’s fitness becomes a matter of record identifiable in time.

§ 03Six steps

Six steps.

Inventory establishes what exists. Pre-validation establishes what the builder claims. Independent validation tests the claim by someone who did not make it. Approval binds a named person to the decision. Monitoring watches the assumptions the approval rested on. Revalidation returns when those assumptions move. Each step produces a record, and the record is the artifact the next step consumes.

§ 04Two roles, never one person

Two roles, never one person.

The head of model risk owns the discipline. The named approving executive owns each approval. They must not be the same person for the same model, because independence is the property the framework exists to establish and a discipline that permits the builder to approve the build has not established it. Where a Sharia Supervisory Board holds binding approval power, validation carries a second and independent track, specified jointly with SACF.

§ 05Where it applies

Which institutions, and on whose authority.

Bites where a named instrument applies

Model risk management is where a supervisor already expects a written discipline, so this framework bites hardest where one exists — and the two instruments do not cover the same ground. OSFI Guideline E-23, effective 1 May 2027, applies to all federally regulated financial institutions in Canada, insurers included. In the United States, SR 26-2, issued 17 April 2026, superseded SR 11-7 and SR 21-8 and is expected to be most relevant to banking organizations with over thirty billion dollars in total assets; it does not reach insurance. Where an institution also has a Sharia Supervisory Board with binding approval power, validation carries a second and independent track.

Where it bites · Banking and capital markets · Insurance

§ 06How it has changed

The record of its own revisions.

A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.

Change history

  • 2026-08-30 · entry v1.0 — First registry entry
  • 2026-09-15 · entry v2.0 — Specification status moves from `source-treatment` to `deposited` on the deposit of the MESA MRM Framework specification, whose concept DOI the entry now carries
  • 2026-09-15 · entry v2.0 — Definition reconciled with that specification, which states the principle of 1.2 in its operative form and governs
  • 2026-09-15 · entry v2.0 — The `missing` limitation recording no validation report template and no worked example is closed by Annexes B and C of that specification
  • 2026-09-15 · entry v2.0 — The asserted supervisory-alignment limitation is amended to record the informative crosswalk at its Annex A and is NOT closed by it
  • 2026-09-15 · entry v2.0 — The supply edge to REG-06 now carries the revalidation trigger register at G5, resolving the question routed to this registry at 6.3 of that specification

Limitations recorded in the registry

  • Alignment with supervisory model risk expectations. The source treatment contains no written crosswalk to current Canadian or United States supervisory guidance, and an institution MUST perform that crosswalk against the primary sources in force in its jurisdiction. The deposited specification carries an informative crosswalk at its Annex A, which states its own date of reading, creates no obligation on either supervisor and no presumption in the institution's favour, and does not transfer the obligation. The limitation therefore stands.
  • Specifies the discipline, not the statistical or behavioural methods a validator applies within it.

What would show this to be wrong. MESA MRM is falsified if institutions operating the six steps with genuine second-line independence are found to approve unfit models at the same rate as institutions in which the building team validates its own work. The framework's entire claim rests on independence changing the outcome, and evidence that it does not would leave a process with no defensible reason to exist.

§ 07Honest limits

What this does not claim.

Asserted. Alignment with supervisory model risk expectations. The source treatment contains no written crosswalk to current Canadian or United States supervisory guidance. An institution relying on this for supervisory alignment must perform that crosswalk against the primary sources in force in its own jurisdiction.

Missing. No published validation report template and no worked validation example. The discipline is specified; the artifact it produces is not exemplified.

Scope. It specifies the discipline, not the statistical or behavioural methods a validator applies within it. It does not tell a validator how to validate.

§ 08Cite

Citation.

Cite this work. MESA MRM Framework, version 1.0. 10.5281/zenodo.22285045. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.

§ 09Where this sits

In the practice.

§ 10Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”

A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.

Fin · Machine-Accessible Expertise
Point your assistant at the endpoint →