Cabier Global Assurance · Architecture

    Global Assurance Registry

    An inventory of models tells an institution what it bought. A registry of assurance states tells it what is running, on whose authority, reaching what data, under which law, with what evidence, and when that position expires.

    Published here as a conceptual record structure. The point of the structure is that every field has an owner and a date, so nothing in it can quietly become an assumption.

    Published as reference architecture. This is a record structure, not a public directory, and no provider or institution is listed or rated.

    The record

    Fifteen fields. Any one of them changing moves the assurance position.

    AI system identityModel and providerModel version and change historyOwner and accountable personAgent identity and delegation depthPurpose and permitted activityConsequence class and risk positionJurisdictions engagedApplicable obligationsControl set and control stateEvaluation recordEvidence position and residencyIncident historyAssurance stateExpiry and reassessment date

    Lifecycle

    Assurance is a state with an expiry, not a certificate. Withdrawal is recorded rather than deleted, because a supervisor's question is usually about the past.

    Registered

    The system exists, is owned, and is described well enough to be assured.

    Assured

    A current assurance state established on dated evidence, with an expiry.

    Under condition

    Permitted inside a stated boundary, with the condition, owner and closing date recorded.

    Under review

    A change, incident or expiry has moved the system back to institutional decision.

    Withdrawn

    No longer permitted, or no longer running. Recorded rather than deleted.

    The same structure, read at population level by an authority that needs aggregate assurance rather than transaction detail.

    See the supervisory view