Figure 1. The rejected two-process arrangement, against the proposed one.
§ 02Stated with the framework
Before the argument.
No Sharia Supervisory Board has reviewed or endorsed this framework. It is an engineering proposal for how binding Sharia authority can be integrated into AI lifecycle governance, offered for scholarly and institutional review.
The Halal data certification chain is author methodology. No standard-setter recognizes such a chain. It must not be presented as an existing requirement of any Sharia standard.
§ 03Two binding authorities
Two binding authorities.
An Islamic financial institution operates under two binding authorities. A financial supervisor determines what it may do in law. A Sharia Supervisory Board determines what it may do in conscience, and in most such institutions the board’s determinations bind rather than advise. Both predate artificial intelligence and neither has specified how its authority reaches an AI system.
Figure 2. Three threads carrying Sharia authority into existing disciplines.
§ 04The second process is the error
The second process is the error.
So the institution does what institutions do when a new object arrives without a rule for it. It builds a second process beside the first. This framework proposes that the second process is unnecessary, and that building it is the mistake. The board is constituted as an authority source at the Regulatory Floor alongside the civil supervisor, so its determinations cascade through the same machinery: one governance system, two authority sources, one record set.
Figure 3. Escalation is concurrent, not sequential.
§ 05The Maqasid risk frame
The Maqasid risk frame.
What an AI decision may harm is classified in the terms the authority itself uses, rather than translated into a Western risk taxonomy and back. A framework that asks a board to recognise its own concerns in someone else’s vocabulary has added a translation step at the point where precision matters most.
§ 06Where it applies
Which institutions, and on whose authority.
Scoped to this sector by the specification
SACF is the one framework in the family scoped to a sector by its own text. It addresses an institution operating under two binding authorities, a financial supervisor and a Sharia Supervisory Board, and proposes that both be satisfied from one set of records rather than two parallel processes.
Where it bites · Islamic finance
§ 07How it has changed
The record of its own revisions.
A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.
Change history
2026-08-30 · entry v1.0 — First registry entry, status instrument-pending
Limitations recorded in the registry
No Sharia Supervisory Board has reviewed or endorsed this framework. It is an engineering proposal for how binding Sharia authority can be integrated into AI lifecycle governance, offered for scholarly and institutional review. This clause MUST accompany any presentation of SACF until an endorsement exists and can be named.
The Halal data certification chain is author methodology. No standard-setter recognizes such a chain as of the date of this registry, and it MUST NOT be presented as an existing requirement of any Sharia standard.
That a Sharia Supervisory Board would accept the dual-validation construct. No board has publicly accepted it.
Specifies the architecture by which Sharia authority enters AI governance. Makes no Sharia determination and does not substitute for scholarly opinion on any question of permissibility.
What would show this to be wrong. SACF is falsified if an institution operating the single-machinery constitution is found unable to satisfy both authorities from one set of records, so that a second and parallel record set has to be created for the Sharia authority in practice. The framework's central claim is that one governance system with two authority sources at its floor is sufficient for both. A parallel record set appearing under operation refutes that claim by observation rather than by opinion, which is what 3.6 requires, and it is observable by any party with access to the institution's records.
§ 08Scope
What it does not do.
SACF specifies the architecture by which Sharia authority enters AI governance. It does not make, and must not be read as making, any Sharia determination, and it does not substitute for scholarly opinion on any question of permissibility.
§ 09Honest limits
What this does not claim.
No institution unconnected to the author has been observed operating it, and no standard-setter has reviewed it.
§ 10Cite
Citation.
Cite this work. Sharia AI Compliance Framework (SACF), version 1.0. 10.5281/zenodo.22170143. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.
Also on SSRN. Posted 21 September 2026 as abstract 7484640. Distributed in 2 eJournals: European Economics: Macroeconomics & Monetary Economics (Vol 19, Issue 147) on 22 September 2026; Monetary Economics: International Financial Flows, Financial Crises, Regulation & Supervision (Vol 11, Issue 175) on 22 September 2026. Scheduled for IO: Regulation, Antitrust & Privatization on 11 December 2026, and Monetary Economics: Financial System & Institutions on 13 January 2027. The deposited specification is the version of record and the Zenodo concept DOI above is the one to cite; SSRN carries the same text for a finance and policy readership.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.
01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
02 · Ask
“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”
A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.
§ 12Ask an assistantLive, no key
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is search_knowledge, which searches the published corpus this framework was drawn from and returns matches with the canonical URL of each, so a definition can be checked against its source instead of recalled.
01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client and every tool, in its own words; each call is logged by tool, outcome and duration only, never with what you asked.
02 · Ask
“Using Concylium, search the corpus for this framework and return the definitions with the page each came from.”
A framework quoted from memory drifts. One returned with its source does not.
Cookies, the boring kind
No chocolate chips here, sorry. With your OK, a few cookies tell me which pages people read, so I can write more of what helps. Say no and the site works exactly the same, with no tracking cookies and no hard feelings. The fine print lives in the privacy & cookies notice.