§ 01Research

Deposited work.

Thirteen technical notes, each with a DOI, a version, a fixed set of files and an open licence. All are supplements to published books rather than replacements for them: the note carries the argument in citable form, the book carries the machinery. Nine document the governance family, three document the engineering family, and one is the registry that fixes the names and relationships of all nine governance frameworks. Every entry in that register now has a deposited specification. Until 6 September five of them had only a chapter of the Enterprise Playbook behind them, which is what the last of these notes closed.

They are self-deposited and they are not peer reviewed. Zenodo assigns a DOI to what it is given; it does not referee it. Cite them as technical notes, which is what they are, and read the claims against their sources rather than against the presence of an identifier. Nothing here has been submitted to or accepted by a journal.

Author identity resolves on ORCID 0009-0005-5364-914X, not on the name.

§ 02Specification

The Defensible AI Framework Registry: Canonical Names, Definitions and Relationships for the Governed Production AI Discipline

Nine frameworks developed separately carried three defects no individual framework could show: three names described one subject, two instruments measured the same maturity, and nothing stated why any of them belonged in the same system. The registry fixes the names, the relationships and its own version, so a claim made against it can be dated.

Deposited 30 August 2026, now at version 2.0, published 15 September 2026, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is The Defensible AI Framework Registry.

Khan, N. (2026). The Defensible AI Framework Registry: Canonical Names, Definitions and Relationships for the Governed Production AI Discipline (Version 2.0). Zenodo. https://doi.org/10.5281/zenodo.22170112

§ 03Specification

The MESA Framework: A Four-Altitude Diagnostic Model for Institutional AI Governance

Institutional AI governance is usually scored as one capability and reported as one grade. That hides the failure that matters: an institution can hold current policy and still have nothing running at the altitude where the decision is actually made. MESA separates the four altitudes and diagnoses them apart.

Deposited 26 August 2026, now at version 1.1, published 30 August 2026, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is The MESA framework.

Khan, N. (2026). The MESA Framework: A Four-Altitude Diagnostic Model for Institutional AI Governance (Version 1.1). Zenodo. https://doi.org/10.5281/zenodo.22109836

§ 04Specification

The Five-Gate Deployment Model: A Deployment Discipline for AI Systems

A pipeline enforces a sequence. A gate assigns a person to it. Five gates in order, each with entry criteria supplied by another framework, one named accountable person, and a required record that carries the policy version in force at the moment it was passed.

Deposited 30 August 2026, version 1.0, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is The Five-Gate Deployment Model.

Khan, N. (2026). The Five-Gate Deployment Model: A Deployment Discipline for AI Systems (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22170122

§ 05Specification

The Sharia AI Compliance Framework: A Dual-Authority Governance Architecture for Islamic Finance

An Islamic financial institution operates under two binding authorities and usually builds a second governance process beside the first. This proposes that the second process is the error: one governance system, two authority sources, one record set. No Sharia Supervisory Board has reviewed or endorsed it.

Deposited 30 August 2026, version 1.0, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is The Sharia AI Compliance Framework.

Khan, N. (2026). The Sharia AI Compliance Framework: A Dual-Authority Governance Architecture for Islamic Finance (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22170143

§ 06Instrument

The AI Vendor Due-Diligence Questionnaire: AVRF Instrument for Third-Party AI Systems, Models and APIs

Most of an institution’s AI exposure arrives through a boundary it cannot inspect. Fifty-six questions in seven sections, each with a fixed answer format and a stated evidence expectation, so two completed responses are comparable rather than merely similar. Free to issue, answer, reproduce and extend.

Deposited 30 August 2026, version 1.0, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is The AI Vendor Risk Framework.

Khan, N. (2026). The AI Vendor Due-Diligence Questionnaire: AVRF Instrument for Third-Party AI Systems, Models and APIs (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22170146

§ 07Specification

The AI Incident Response Protocol: Six Stages, and the Evidence a Reconstruction Requires

An institution asked to explain an AI failure discovers, at that moment and not before, what it wrote down. The discovery is unrecoverable. Evidence is a property of the moment a decision was taken, and an institution that did not capture it then is left assembling an account from what it can still find. It reconstructs beliefs, not behaviour.

Deposited 6 September 2026, version 1.0, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is The AI Incident Response Protocol.

Khan, N. (2026). The AI Incident Response Protocol: Six Stages, and the Evidence a Reconstruction Requires (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22285057

§ 08Specification

CADRE: Charter, Authority, Decision Rights, Records, Escalation. The Governance Function Specified as Five Artifacts

A board grants a mandate and the institution announces a function; months later a supervisor asks under what authority a system was released, who exercised it, and where the record is. That gap is not a documentation gap. The mandate was never converted into anything the institution can produce on demand.

Deposited 8 September 2026, version 1.0, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is CADRE, the AI Governance Operating Model.

Khan, N. (2026). CADRE: Charter, Authority, Decision Rights, Records, Escalation. The Governance Function Specified as Five Artifacts (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22285052

§ 09Specification

The AI Data Governance Framework: A Five-Stage Control System for the Data Boundary in AI Systems

An institution asked whether a particular item of data may be inside a particular AI system usually answers from recollection: someone remembers which extract the training set came from, someone else remembers that a restricted field was excluded, and a third remembers the data owner who agreed it and has since left. The answer is often correct. It is never evidence.

Deposited 14 September 2026, version 1.0, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is The AI Data Governance Framework.

Khan, N. (2026). The AI Data Governance Framework: A Five-Stage Control System for the Data Boundary in AI Systems (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22285047

§ 010Specification

Cross-Border AI Architecture Patterns: Three Patterns, and Why the Fourth Is Not a Choice

An institution told that data may not leave a jurisdiction usually treats the statement as an obstacle to a deployment. It is not an obstacle. It is the first fact about the deployment’s architecture, and treating it as an obstacle is how an institution arrives at a topology chosen for cost and then argues that the clauses permit it.

Deposited 15 September 2026, version 1.0, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is Cross-Border AI Architecture Patterns.

Khan, N. (2026). Cross-Border AI Architecture Patterns: Three Patterns, and Why the Fourth Is Not a Choice (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22285049

§ 011Specification

The MESA MRM Framework: A Six-Step Model Risk Management Discipline for AI Systems

An institution that runs models can usually say which of them work. It is much less often able to say who decided that they work, on what evidence, for what use, and until when. A validation is not a property of the model. It is a bounded permission, held by the institution, over a stated use, for a stated period.

Deposited 15 September 2026, version 1.0, under CC BY 4.0. It supplements the Enterprise Playbook (ISBN 978-1-0678960-1-0), and the page it documents is The MESA MRM Framework.

Khan, N. (2026). The MESA MRM Framework: A Six-Step Model Risk Management Discipline for AI Systems (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22285045

§ 012Specification

A Pattern Language for Production LLM Platforms: Governed Routing, Agent Orchestration, and AI-Native Delivery

A platform built on large language models makes two kinds of decision, and most of its trouble comes from writing both into one clause. The patterns separate the optimisation decision from the governed one, and name the seams where that separation survives contact with production.

Deposited 26 August 2026, now at version 1.1, published 30 August 2026, under CC BY 4.0. It supplements the Full-Stack AI Engineering series (ISBNs 978-1-0678317-1-4, -2-1 and -3-8), and the page it documents is A pattern language for production LLM platforms.

Khan, N. (2026). A Pattern Language for Production LLM Platforms: Governed Routing, Agent Orchestration, and AI-Native Delivery (Version 1.1). Zenodo. https://doi.org/10.5281/zenodo.22109864

§ 013Specification

PEVG: Planner, Executor, Verifier, Generator. Four Contracts, and the Two Boundaries a Verifier Does Not Both Hold

The verifier holds the epistemic boundary, what may be believed. It does not thereby hold the operational boundary, what may be disclosed or acted upon. Collapsing the two is one clause performing two functions, which is the classification error the Boundary Invariant forbids.

Deposited 30 August 2026, version 1.0, under CC BY 4.0. It supplements the Full-Stack AI Engineering series (ISBNs 978-1-0678317-1-4, -2-1 and -3-8), and the page it documents is PEVG.

Khan, N. (2026). PEVG: Planner, Executor, Verifier, Generator. Four Contracts, and the Two Boundaries a Verifier Does Not Both Hold (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22170132

§ 014Specification

PARA: Perception, Action, Reasoning, Adaptation. Four Faculties, Four Authority Types, and the Registry Entry That Turns a Faculty into a Contract

The fourth faculty is Adaptation, not Reflection. Reflection is a private act with no external consequence; adaptation writes to institutional memory, which is why it needs a guardrail and why misnaming it removes the reason for one.

Deposited 30 August 2026, version 1.0, under CC BY 4.0. It supplements the Full-Stack AI Engineering series (ISBNs 978-1-0678317-1-4, -2-1 and -3-8), and the page it documents is PARA.

Khan, N. (2026). PARA: Perception, Action, Reasoning, Adaptation. Four Faculties, Four Authority Types, and the Registry Entry That Turns a Faculty into a Contract (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.22170139

Fin · Press
Press enquiry →