FrameworkMESA MRM FrameworkSheet 53

Validation confers the right to be believed.

A six-step model risk management discipline.

← Defensible AI

§ 01Status

What this is.

REG-02 · MESA MRM Framework™

Position in the architecture · Operational Machinery

Specification · No standalone specification is deposited for this framework. Its authoritative treatment is Chapter 12 of AI Governance and Compliance Frameworks for the Middle East: The Enterprise Playbook, ISBN 978-1-0678960-1-0. This page and registry entry REG-02 are the most complete normative statement available in citable form.

Composition at the gates of the Five-Gate Deployment Model Five gates in sequence. Gate one, Data and Design, takes entry evidence from REG-03 classification and lineage and from REG-04 vendor clearance, and is accountable to the named data owner. Gate two, Validation, takes REG-02 steps one and two, accountable to the named validator. Gate three, Approval, takes REG-02 steps three and four and the closed dual validation of REG-08, accountable to the named executive. Gate four, Deployment, takes release authority from REG-07 and contractual controls from REG-04, accountable to the named platform owner. Gate five, Operation, takes armed triggers from REG-05 and live monitoring, accountable to the named head of the governance office. Each gate writes a gate passage record naming who approved, on what evidence, and when. Two reverse paths run backwards: rollback returns gate five to gate four with evidence preserved, and loop-back reopens gate two after an incident at gate five. Every gate passage record is an instance of the BOE Declaration. Composition at the gates of the Five-Gate Deployment Model Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170112 https://doi.org/10.5281/zenodo.22170112 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/registry COMPOSITION AT THE GATES ENTRY EVIDENCE SUPPLIED BY REG-03 classification, lineage REG-04 clearance REG-02 steps 1 and 2 inventory, pre-validation REG-02 steps 3 and 4 REG-08 dual validation both tracks closed REG-07 release authority REG-04 contract terms REG-05 triggers armed monitoring live G1 Data and Design one named data owner G2 Validation one named validator G3 Approval one named executive G4 Deployment one named platform owner G5 Operation one named office head gate record who · on what · when gate record who · on what · when gate record who · on what · when gate record who · on what · when gate record who · on what · when ROLLBACK. G5 to G4, evidence preserved LOOP-BACK. an incident at G5 reopens G2 Every gate passage record is an instance of the BOE Declaration Boundary: the gate entry criteria. Optimizer: the deployment freedom granted on passage. Evidence: the record itself. This is what makes the governance and engineering families compose. The sequence and the entry criteria are normative. A gate passed without its entry evidence is not passed. The Defensible AI Framework Registry v1.0 · Nabeel Khan · nabeelkhan.com/frameworks/registry · CC BY 4.0 · DOI 10.5281/zenodo.22170112
Figure 1. MESA MRM supplies the entry criteria for gate two and gate three of the Five-Gate Deployment Model.
§ 02The claim

The claim.

A model that has not been independently validated may be operated. Its outputs are not evidence of anything to a party outside the team that built it. That is the whole of the framework’s claim, and everything in it exists to make the moment at which a model’s fitness becomes a matter of record identifiable in time.

§ 03Six steps

Six steps.

Inventory establishes what exists. Pre-validation establishes what the builder claims. Independent validation tests the claim by someone who did not make it. Approval binds a named person to the decision. Monitoring watches the assumptions the approval rested on. Revalidation returns when those assumptions move. Each step produces a record, and the record is the artifact the next step consumes.

§ 04Two roles, never one person

Two roles, never one person.

The head of model risk owns the discipline. The named approving executive owns each approval. They must not be the same person for the same model, because independence is the property the framework exists to establish and a discipline that permits the builder to approve the build has not established it. Where a Sharia Supervisory Board holds binding approval power, validation carries a second and independent track, specified jointly with SACF.

§ 05Honest limits

What this does not claim.

Asserted. Alignment with supervisory model risk expectations. The source treatment contains no written crosswalk to current Canadian or United States supervisory guidance. An institution relying on this for supervisory alignment must perform that crosswalk against the primary sources in force in its own jurisdiction.

Missing. No published validation report template and no worked validation example. The discipline is specified; the artifact it produces is not exemplified.

Scope. It specifies the discipline, not the statistical or behavioural methods a validator applies within it. It does not tell a validator how to validate.

§ 06Cite

Citation.

Cite this framework. No standalone specification is deposited. Its authoritative treatment is Chapter 12 of AI Governance and Compliance Frameworks for the Middle East: The Enterprise Playbook, ISBN 978-1-0678960-1-0, and its normative statement in citable form is registry entry REG-02 in 10.5281/zenodo.22170112.

§ 07Where this sits

In the practice.

§ 10Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”

A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.

Fin · Machine-Accessible Expertise
Point your assistant at the endpoint →