ZERO™ · USPTO Serial 99781150 · Class 042
Frameworks describe what good looks like. Platforms instrument it. ZERO™ operates it.
Zero-Exposure Risk Orchestration. An end-to-end AI governance operating model for regulated institutions — evidence first, examiner defensible, and built to close rather than finish.
The 2026 Governance Frontier
Three AI risks traditional governance was never built to catch
Model risk management and computerised system validation were built for static, deterministic systems. Three categories of AI now sit outside that perimeter. Not three separate disciplines — one operating problem.
01 · Frontier
Predictive & Generative AI
Probabilistic systems inside validated workflows. Outputs can vary, drift and enter regulated records — while traditional validation assumes deterministic, repeatable behaviour.
Required controls
- Validation basis for non-deterministic output
- Named owner per model and per use case
- Drift and performance monitoring against intent
- Evidence where output enters a regulated record
02 · Frontier
Agentic AI
The liability orphan. AI that acts rather than predicts — a system can take a consequential action beyond approved authority, with no named human accountable at execution.
Required controls
- Agent identity and permission boundaries
- Permit-before-execute approval gates
- Kill-switch and rollback rights
- Behavioural drift monitoring against intent
03 · Frontier
Vendor-Embedded AI
The largest unmapped surface. AI features ship inside licensed platforms — core banking, CRM, contact centre, LIMS and clinical systems — arriving by vendor release with no procurement gate triggered.
Required controls
- AI-specific third-party risk addendum
- Sub-threshold AI procurement gating
- Vendor AI inventory and change-notification
- Contractual evidence and explainability
The Architecture
Five stages
Posture is set by the lowest score, not the average. The weakest stage governs the whole.
D
Discover
Enterprise AI register. Vendor-embedded sweep. Shadow AI surfacing.
AgenticAgents · tools · identities · memory · instruction sources
C
Classify
Three-tier taxonomy. 3D risk logic. Vendor materiality tier.
AgenticAutonomy × blast radius × trust
A
Assign
Seven-layer accountability. Named human owner. Vendor accountable executive.
AgenticBounded authority · delegation rights · escalation authority
G
Govern
Validation framework. Evidentiary artifact pack. AI security controls.
AgenticPermission at execution · independent validation · human gate · kill switch
M
Monitor
Six monitoring dimensions. Real-time defensibility. Vendor re-attestation.
AgenticRuntime behaviour · authority drift · memory drift · evidence trail
Weakest-link rule. The weakest stage sets the institution's posture — not the average.
The Data Gate
Data is a gate. Not a service line.
ZERO™ requires evidenced data readiness before any AI system passes governance review. The gate is assessed, scored and re-tested at every cycle.
The gate rule
No evidence, no deployment.
A system that cannot show lineage and ownership of its training and inference data is not governable.
Five evidence requirements, scored 0–4 on the same scale as the five stages.
01 · LineageWhere the data came from, and every transformation since
02 · OwnershipA named human accountable for the domain, not a team
03 · QualityDocumented rules, measured, with exceptions handled
04 · AccessWho can see it, on what basis, evidenced at record level
05 · RetentionHow long, on what authority, with disposal proven
The gate decides scope, not whether we engage.
Pass
L3 or above on all five. Proceed to full ZERO™ scope.
Conditional
One or two below L3. Proceed with named data remediation running in parallel, partner-delivered.
Blocked
Three or more below L3. Data remediation precedes AI governance. Sequenced, not declined.
The Loop
Monitor does not end the model. It restarts it.
A model that runs discovery to monitoring and stops is a project plan. ZERO™ closes — monitoring produces signals that re-enter at a named stage. The loop fires on change, not only on improvement.
New system detected
Vendor patch, shadow tool, new agent.
Re-enters at Discover
Materiality changed
Autonomy, blast radius or data scope moved.
Re-enters at Classify
Owner changed
The named human left, or the role was reorganised.
Re-enters at Assign
Control or rule changed
A control failed, or new regulation landed.
Re-enters at Govern
The Agentic Control Architecture
Five questions. Twelve controls.
ZERO™ tells the institution where governance operates. The five questions frame every consequential action an agent takes. The twelve controls make those questions enforceable — and evidenced.
Who
Who acted?
- Identity
- Bounded Authority
- Trust Classification
What
What was it allowed to do?
- Delegation
- Instruction Provenance
How
How did authority travel?
- Permission at Execution
- Independent Validation
Stop
When must autonomy stop?
- Blast Radius
- Human Escalation
- Kill Switch
Prove
Can we prove what happened?
- Runtime Monitoring
- Controlled Memory
- Evidence across the chain
Applied across Discover → Classify → Assign → Govern → Monitor. The controls are not a separate programme; they are what each stage produces when the system is an agent.
Sector Translation
The same gate, named differently by sector
Banking & insuranceBCBS 239 · SR 11-7 data lineage expectations · GDPR / CCPA access and retention
Pharma & life sciencesData integrity, ALCOA+ · 21 CFR Part 11 electronic records · GAMP 5 validation
Health systemsHIPAA minimum necessary · provenance for clinical decision support
Jurisdictional Reach
The model is jurisdiction-neutral. The evidence is not.
ZERO™ is built on ISO/IEC 42001 and 27001, which are international by design. What changes between jurisdictions is which authority asks, and what evidence satisfies them. The five stages and the data gate do not change.
United StatesFederal Reserve SR 11-7 · OCC · NCUA · FFIEC · NIST AI RMF · state privacy regimes
Kingdom of Saudi ArabiaSDAIA AI Ethics Principles · SAMA supervisory expectations · PDPL · NCA Essential Cybersecurity Controls · Vision 2030 alignment
European UnionEU AI Act risk tiering and conformity obligations · GDPR · EBA guidance
International baselineISO/IEC 42001 AI management systems · ISO/IEC 27001 information security · ISO 31000 risk
An institution operating across jurisdictions runs one operating model and produces different evidence packs from it. Governing the same system twice is how programmes fail their second examination.
The Cycle
Governance is not a project. It is a calendar.
The diagnostic happens once. Everything after it runs on a rhythm the institution does not set — examination cycles, board calendars, vendor change notifications and model drift.
Q1
Re-score
- Gate and five-stage re-score against L3
- Delta report versus prior year
Q2
Validate
- Independent control testing
- Sample-based evidence pull
- Findings and remediation
Q3
Re-attest
- Vendor AI re-attestation
- New-deployment sweep
- Shadow AI discovery
Q4
Evidence
- Examiner pack refreshed
- Board attestation letter
- Next-year roadmap
The institution does not choose when the examiner arrives, when a vendor ships an AI feature into a licensed platform, or when a model drifts out of intent. Those events set the calendar.