ZERO™ · USPTO Serial 99781150 · Class 042

Frameworks describe what good looks like. Platforms instrument it. ZERO™ operates it.

Zero-Exposure Risk Orchestration. An end-to-end AI governance operating model for regulated institutions — evidence first, examiner defensible, and built to close rather than finish.

The 2026 Governance Frontier

Three AI risks traditional governance was never built to catch

Model risk management and computerised system validation were built for static, deterministic systems. Three categories of AI now sit outside that perimeter. Not three separate disciplines — one operating problem.
01 · Frontier

Predictive & Generative AI

Probabilistic systems inside validated workflows. Outputs can vary, drift and enter regulated records — while traditional validation assumes deterministic, repeatable behaviour.

Required controls
  • Validation basis for non-deterministic output
  • Named owner per model and per use case
  • Drift and performance monitoring against intent
  • Evidence where output enters a regulated record
02 · Frontier

Agentic AI

The liability orphan. AI that acts rather than predicts — a system can take a consequential action beyond approved authority, with no named human accountable at execution.

Required controls
  • Agent identity and permission boundaries
  • Permit-before-execute approval gates
  • Kill-switch and rollback rights
  • Behavioural drift monitoring against intent
03 · Frontier

Vendor-Embedded AI

The largest unmapped surface. AI features ship inside licensed platforms — core banking, CRM, contact centre, LIMS and clinical systems — arriving by vendor release with no procurement gate triggered.

Required controls
  • AI-specific third-party risk addendum
  • Sub-threshold AI procurement gating
  • Vendor AI inventory and change-notification
  • Contractual evidence and explainability
The Architecture

Five stages

Posture is set by the lowest score, not the average. The weakest stage governs the whole.
D

Discover

Enterprise AI register. Vendor-embedded sweep. Shadow AI surfacing.

AgenticAgents · tools · identities · memory · instruction sources
C

Classify

Three-tier taxonomy. 3D risk logic. Vendor materiality tier.

AgenticAutonomy × blast radius × trust
A

Assign

Seven-layer accountability. Named human owner. Vendor accountable executive.

AgenticBounded authority · delegation rights · escalation authority
G

Govern

Validation framework. Evidentiary artifact pack. AI security controls.

AgenticPermission at execution · independent validation · human gate · kill switch
M

Monitor

Six monitoring dimensions. Real-time defensibility. Vendor re-attestation.

AgenticRuntime behaviour · authority drift · memory drift · evidence trail

Weakest-link rule. The weakest stage sets the institution's posture — not the average.

The Data Gate

Data is a gate. Not a service line.

ZERO™ requires evidenced data readiness before any AI system passes governance review. The gate is assessed, scored and re-tested at every cycle.
The gate rule

No evidence, no deployment.

A system that cannot show lineage and ownership of its training and inference data is not governable.

Five evidence requirements, scored 0–4 on the same scale as the five stages.
01 · LineageWhere the data came from, and every transformation since
02 · OwnershipA named human accountable for the domain, not a team
03 · QualityDocumented rules, measured, with exceptions handled
04 · AccessWho can see it, on what basis, evidenced at record level
05 · RetentionHow long, on what authority, with disposal proven
The gate decides scope, not whether we engage.

Pass

L3 or above on all five. Proceed to full ZERO™ scope.

Conditional

One or two below L3. Proceed with named data remediation running in parallel, partner-delivered.

Blocked

Three or more below L3. Data remediation precedes AI governance. Sequenced, not declined.

The Loop

Monitor does not end the model. It restarts it.

A model that runs discovery to monitoring and stops is a project plan. ZERO™ closes — monitoring produces signals that re-enter at a named stage. The loop fires on change, not only on improvement.

New system detected

Vendor patch, shadow tool, new agent.

Re-enters at Discover

Materiality changed

Autonomy, blast radius or data scope moved.

Re-enters at Classify

Owner changed

The named human left, or the role was reorganised.

Re-enters at Assign

Control or rule changed

A control failed, or new regulation landed.

Re-enters at Govern
The Agentic Control Architecture

Five questions. Twelve controls.

ZERO™ tells the institution where governance operates. The five questions frame every consequential action an agent takes. The twelve controls make those questions enforceable — and evidenced.
Who

Who acted?

  • Identity
  • Bounded Authority
  • Trust Classification
What

What was it allowed to do?

  • Delegation
  • Instruction Provenance
How

How did authority travel?

  • Permission at Execution
  • Independent Validation
Stop

When must autonomy stop?

  • Blast Radius
  • Human Escalation
  • Kill Switch
Prove

Can we prove what happened?

  • Runtime Monitoring
  • Controlled Memory
  • Evidence across the chain

Applied across Discover → Classify → Assign → Govern → Monitor. The controls are not a separate programme; they are what each stage produces when the system is an agent.

Sector Translation

The same gate, named differently by sector

Banking & insuranceBCBS 239 · SR 11-7 data lineage expectations · GDPR / CCPA access and retention
Pharma & life sciencesData integrity, ALCOA+ · 21 CFR Part 11 electronic records · GAMP 5 validation
Health systemsHIPAA minimum necessary · provenance for clinical decision support
Jurisdictional Reach

The model is jurisdiction-neutral. The evidence is not.

ZERO™ is built on ISO/IEC 42001 and 27001, which are international by design. What changes between jurisdictions is which authority asks, and what evidence satisfies them. The five stages and the data gate do not change.
United StatesFederal Reserve SR 11-7 · OCC · NCUA · FFIEC · NIST AI RMF · state privacy regimes
Kingdom of Saudi ArabiaSDAIA AI Ethics Principles · SAMA supervisory expectations · PDPL · NCA Essential Cybersecurity Controls · Vision 2030 alignment
European UnionEU AI Act risk tiering and conformity obligations · GDPR · EBA guidance
International baselineISO/IEC 42001 AI management systems · ISO/IEC 27001 information security · ISO 31000 risk

An institution operating across jurisdictions runs one operating model and produces different evidence packs from it. Governing the same system twice is how programmes fail their second examination.

The Cycle

Governance is not a project. It is a calendar.

The diagnostic happens once. Everything after it runs on a rhythm the institution does not set — examination cycles, board calendars, vendor change notifications and model drift.
Q1

Re-score

  • Gate and five-stage re-score against L3
  • Delta report versus prior year
Q2

Validate

  • Independent control testing
  • Sample-based evidence pull
  • Findings and remediation
Q3

Re-attest

  • Vendor AI re-attestation
  • New-deployment sweep
  • Shadow AI discovery
Q4

Evidence

  • Examiner pack refreshed
  • Board attestation letter
  • Next-year roadmap

The institution does not choose when the examiner arrives, when a vendor ships an AI feature into a licensed platform, or when a model drifts out of intent. Those events set the calendar.

Your AI governance program may look great on paper. Will it survive a regulatory examination?

Sixty minutes. No cost. You leave with a one-page Exposure Hypothesis.