Figure 1. The rejected two-process arrangement, against the proposed one.
§ 02Stated with the framework
Before the argument.
No Sharia Supervisory Board has reviewed or endorsed this framework. It is an engineering proposal for how binding Sharia authority can be integrated into AI lifecycle governance, offered for scholarly and institutional review.
The Halal data certification chain is author methodology. No standard-setter recognizes such a chain. It must not be presented as an existing requirement of any Sharia standard.
§ 03Two binding authorities
Two binding authorities.
An Islamic financial institution operates under two binding authorities. A financial supervisor determines what it may do in law. A Sharia Supervisory Board determines what it may do in conscience, and in most such institutions the board’s determinations bind rather than advise. Both predate artificial intelligence and neither has specified how its authority reaches an AI system.
Figure 2. Three threads carrying Sharia authority into existing disciplines.
§ 04The second process is the error
The second process is the error.
So the institution does what institutions do when a new object arrives without a rule for it. It builds a second process beside the first. This framework proposes that the second process is unnecessary, and that building it is the mistake. The board is constituted as an authority source at the Regulatory Floor alongside the civil supervisor, so its determinations cascade through the same machinery: one governance system, two authority sources, one record set.
Figure 3. Escalation is concurrent, not sequential.
§ 05The Maqasid risk frame
The Maqasid risk frame.
What an AI decision may harm is classified in the terms the authority itself uses, rather than translated into a Western risk taxonomy and back. A framework that asks a board to recognise its own concerns in someone else’s vocabulary has added a translation step at the point where precision matters most.
§ 06Where it applies
Which institutions, and on whose authority.
Scoped to this sector by the specification
SACF is the one framework in the family scoped to a sector by its own text. It addresses an institution operating under two binding authorities, a financial supervisor and a Sharia Supervisory Board, and proposes that both be satisfied from one set of records rather than two parallel processes.
Where it bites · Islamic finance
§ 07How it has changed
The record of its own revisions.
A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.
Change history
2026-08-30 · entry v1.0 — First registry entry, status instrument-pending
Limitations recorded in the registry
No Sharia Supervisory Board has reviewed or endorsed this framework. It is an engineering proposal for how binding Sharia authority can be integrated into AI lifecycle governance, offered for scholarly and institutional review. This clause MUST accompany any presentation of SACF until an endorsement exists and can be named.
The Halal data certification chain is author methodology. No standard-setter recognizes such a chain as of the date of this registry, and it MUST NOT be presented as an existing requirement of any Sharia standard.
That a Sharia Supervisory Board would accept the dual-validation construct. No board has publicly accepted it.
Specifies the architecture by which Sharia authority enters AI governance. Makes no Sharia determination and does not substitute for scholarly opinion on any question of permissibility.
What would show this to be wrong. SACF is falsified if an institution operating the single-machinery constitution is found unable to satisfy both authorities from one set of records, so that a second and parallel record set has to be created for the Sharia authority in practice. The framework's central claim is that one governance system with two authority sources at its floor is sufficient for both. A parallel record set appearing under operation refutes that claim by observation rather than by opinion, which is what 3.6 requires, and it is observable by any party with access to the institution's records.
§ 08Scope
What it does not do.
SACF specifies the architecture by which Sharia authority enters AI governance. It does not make, and must not be read as making, any Sharia determination, and it does not substitute for scholarly opinion on any question of permissibility.
§ 09Honest limits
What this does not claim.
No institution unconnected to the author has been observed operating it, and no standard-setter has reviewed it.
§ 10Cite
Citation.
Cite this work. Sharia AI Compliance Framework (SACF), version 1.0. 10.5281/zenodo.22170143. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.
01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
02 · Ask
“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”
A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.
A note on cookies
This site uses Google Analytics and the Meta pixel to understand what gets read and which work reaches people. Analytics loads with storage denied, so no cookie is set and nothing is kept until you choose. The Meta pixel does not load at all unless you accept. Details in the privacy & cookies notice.