ZERO™ · USPTO Serial 99781150 · Class 042
Frameworks describe what good looks like. Platforms instrument it. ZERO™ operates it.
Zero-Exposure Risk Orchestration. An end-to-end AI governance operating model for regulated institutions — evidence first, examiner defensible, and built to close rather than finish.
The 2026 Governance Frontier
Three AI risks traditional governance was never built to catch
Model risk management was built for static, deterministic models. The exposures that now define examiner attention fall outside that perimeter. Not three separate disciplines — one operating problem.
01 · Frontier
Agentic AI
The liability orphan. AI that acts, not just predicts. Outside the perimeter of every framework written before 2024.
Required controls
- Agent identity and permission boundaries
- Permit-before-execute approval gates
- Kill-switch and rollback rights
- Behavioural drift monitoring against intent
02 · Frontier
Vendor-Embedded AI
The largest unmapped surface. AI features ship inside licensed platforms — CRM, core banking, contact centre — often activated by a vendor patch with no procurement gate triggered.
Required controls
- AI-specific third-party risk addendum
- Sub-threshold AI procurement gating
- Vendor AI inventory and change-notification
- Contractual evidence and explainability
03 · Frontier
AI Security
The threat surface MRM did not see. Prompt injection. Model exfiltration. Data leakage at inference. Agent identity spoofing. Adjacent to traditional cyber — not the same.
Required controls
- Prompt and output guardrails with red-team
- Inference-layer data loss prevention
- Model and weight access controls
- AI incident response with examiner evidence
The Architecture
Five stages
Posture is set by the lowest score, not the average. The weakest stage governs the whole.
D
Discover
Enterprise AI register. Vendor-embedded sweep. Shadow AI surfacing.
AgenticAgents · tools · identities · memory · instruction sources
C
Classify
Three-tier taxonomy. 3D risk logic. Vendor materiality tier.
AgenticAutonomy × blast radius × trust
A
Assign
Seven-layer accountability. Named human owner. Vendor accountable executive.
AgenticBounded authority · delegation rights · escalation authority
G
Govern
Validation framework. Evidentiary artifact pack. AI security controls.
AgenticPermission at execution · independent validation · human gate · kill switch
M
Monitor
Six monitoring dimensions. Real-time defensibility. Vendor re-attestation.
AgenticRuntime behaviour · authority drift · memory drift · evidence trail
Weakest-link rule. The weakest stage sets the institution's posture — not the average.
The Data Gate
Data is a gate. Not a service line.
ZERO™ requires evidenced data readiness before any AI system passes governance review. The gate is assessed, scored and re-tested at every cycle.
The gate rule
No evidence, no deployment.
A system that cannot show lineage and ownership of its training and inference data is not governable.
Five evidence requirements, scored 0–4 on the same scale as the five stages.
01 · LineageWhere the data came from, and every transformation since
02 · OwnershipA named human accountable for the domain, not a team
03 · QualityDocumented rules, measured, with exceptions handled
04 · AccessWho can see it, on what basis, evidenced at record level
05 · RetentionHow long, on what authority, with disposal proven
The gate decides scope, not whether we engage.
Pass
L3 or above on all five. Proceed to full ZERO™ scope.
Conditional
One or two below L3. Proceed with named data remediation running in parallel, partner-delivered.
Blocked
Three or more below L3. Data remediation precedes AI governance. Sequenced, not declined.
The Loop
Monitor does not end the model. It restarts it.
A model that runs discovery to monitoring and stops is a project plan. ZERO™ closes — monitoring produces signals that re-enter at a named stage. The loop fires on change, not only on improvement.
New system detected
Vendor patch, shadow tool, new agent.
Re-enters at Discover
Materiality changed
Autonomy, blast radius or data scope moved.
Re-enters at Classify
Owner changed
The named human left, or the role was reorganised.
Re-enters at Assign
Control or rule changed
A control failed, or new regulation landed.
Re-enters at Govern
The Agentic Control Architecture
Five questions. Twelve controls.
ZERO™ tells the institution where governance operates. The five questions frame every consequential action an agent takes. The twelve controls make those questions enforceable — and evidenced.
Who
Who acted?
- Identity
- Bounded Authority
- Trust Classification
What
What was it allowed to do?
- Delegation
- Instruction Provenance
How
How did authority travel?
- Permission at Execution
- Independent Validation
Stop
When must autonomy stop?
- Blast Radius
- Human Escalation
- Kill Switch
Prove
Can we prove what happened?
- Runtime Monitoring
- Controlled Memory
- Evidence across the chain
Applied across Discover → Classify → Assign → Govern → Monitor. The controls are not a separate programme; they are what each stage produces when the system is an agent.
Sector Translation
The same gate, named differently by sector
Banking & insuranceBCBS 239 · SR 11-7 data lineage expectations · GDPR / CCPA access and retention
Pharma & life sciencesData integrity, ALCOA+ · 21 CFR Part 11 electronic records · GAMP 5 validation
Health systemsHIPAA minimum necessary · provenance for clinical decision support
Jurisdictional Reach
The model is jurisdiction-neutral. The evidence is not.
ZERO™ is built on ISO/IEC 42001 and 27001, which are international by design. What changes between jurisdictions is which authority asks, and what evidence satisfies them. The five stages and the data gate do not change.
United StatesFederal Reserve SR 11-7 · OCC · NCUA · FFIEC · NIST AI RMF · state privacy regimes
Kingdom of Saudi ArabiaSDAIA AI Ethics Principles · SAMA supervisory expectations · PDPL · NCA Essential Cybersecurity Controls · Vision 2030 alignment
European UnionEU AI Act risk tiering and conformity obligations · GDPR · EBA guidance
International baselineISO/IEC 42001 AI management systems · ISO/IEC 27001 information security · ISO 31000 risk
An institution operating across jurisdictions runs one operating model and produces different evidence packs from it. Governing the same system twice is how programmes fail their second examination.
The Cycle
Governance is not a project. It is a calendar.
The diagnostic happens once. Everything after it runs on a rhythm the institution does not set — examination cycles, board calendars, vendor change notifications and model drift.
Q1
Re-score
- Gate and five-stage re-score against L3
- Delta report versus prior year
Q2
Validate
- Independent control testing
- Sample-based evidence pull
- Findings and remediation
Q3
Re-attest
- Vendor AI re-attestation
- New-deployment sweep
- Shadow AI discovery
Q4
Evidence
- Examiner pack refreshed
- Board attestation letter
- Next-year roadmap
The institution does not choose when the examiner arrives, when a vendor ships an AI feature into a licensed platform, or when a model drifts out of intent. Those events set the calendar.