The Alpha Standard Version 1 · Public calibration candidate

The standard for AI governance.

The Alpha Standard evaluates whether an enterprise can govern material AI and agentic systems. It produces one Alpha AI Governance Rating under six plain-English pillars, while identifying whether the opinion rests on public information or evidence verified by Alpha.

Release status

Version 1 is public for review and calibration.

Methodology 1.0.0-rc.2 is not yet the active production rating engine. Historical ratings retain the methodology version under which they were issued. Version 1 customer-visible ratings require completed calibration, independent methodology challenge, legal review, a functioning approval process, and authorized activation.

One Alpha AIGR. Six pillars. Two evidence bases.

Public-signal and private verified assessments do not create competing ratings. They are separate, versioned observations under one methodology, distinguished by evidence access, confidence, confidentiality, perimeter, and cutoff date.

Alpha AIGR, Public Information

Based only on attributable public evidence available by the evidence cutoff date.

Normally capped at A, or AA with disclosed independent assurance. Never AAA.

Alpha AIGR, Verified Assessment

Based on evidence verified by Alpha within a signed assessment perimeter.

Eligible for the full AAA to D scale when every publication gate is met.

Both bases use the same pillars, requirements, controls, score anchors, weights, ceilings, and rating bands. Verified evidence is isolated and cannot be disclosed through, inferred from, or silently blended into a public-information rating.

The complete governance question, in plain English.

The six public weights sum to 100%. Each pillar contains four subcategories and eight requirements, for 24 subcategories and 48 requirement assessments in total.

P1 · 20%

Leadership & Accountability

Who is responsible for AI, and can the board hold them accountable?

Board authority, executive ownership, decision rights, governance structure, accountability, and reliable reporting.

Evidence examples

  • - Board mandates
  • - Named executive owners
  • - Decision and escalation records

P2 · 22%

Safety, Security & Resilience

Can AI operate safely and withstand attack, failure, and disruption?

Safety engineering, cybersecurity, resilience, incident readiness, and controls for material AI and agentic systems.

Evidence examples

  • - Testing and red-team records
  • - Security controls
  • - Incident exercises

P3 · 15%

Data, Privacy & Transparency

Is data protected, and are AI uses, decisions, and claims clear?

Data governance, privacy, provenance, inventory, disclosure, explainability, and traceable claims about AI use.

Evidence examples

  • - Data lineage
  • - Privacy reviews
  • - AI inventories and disclosures

P4 · 14%

People & Rights

Are people treated fairly, protected from harm, and able to challenge decisions?

Fairness, human rights, workforce and customer impacts, accessibility, notice, challenge, and remediation.

Evidence examples

  • - Impact assessments
  • - Bias testing
  • - Challenge and remedy records

P5 · 15%

Compliance & Third Parties

Are legal duties, vendors, models, and external dependencies governed?

Legal and regulatory applicability, third-party oversight, contract controls, supply-chain governance, and stakeholder duties.

Evidence examples

  • - Regulatory mappings
  • - Vendor reviews
  • - Contract and assurance records

P6 · 14%

Monitoring & Improvement

Can the enterprise detect problems, intervene, correct them, and learn?

Continuous monitoring, independent assurance, override and shutdown capability, corrective action, and learning from outcomes.

Evidence examples

  • - Monitoring records
  • - Override and shutdown tests
  • - Corrective action logs

The four-quadrant matrix routes decisions. It does not change the rating.

The six pillars define what Alpha assesses. The Governance Intelligence Matrix classifies where a material risk or opportunity sits, then routes it to accountable board, committee, and management owners.

Internal Opportunity

Build & Transform

What internal AI capability can improve how the enterprise operates?

Examples: Operating model · Workforce capability · Internal AI investment

External Opportunity

Grow & Partner

What market, customer, investment, or partnership opportunity can AI create?

Examples: Customer value · Strategic partnerships · New markets

Internal Risk

Govern & Control

What internal AI exposure must be governed, controlled, or escalated?

Examples: Policy exceptions · Shadow AI · Control failures

External Risk

Monitor & Respond

What external threat, dependency, regulatory change, or competitive event requires a response?

Examples: Regulatory change · Vendor concentration · External threats

Every classified signal, finding, incident, opportunity, or governance action has exactly one quadrant and at least one pillar. The matrix is not a seventh pillar and has no rating weight. Opportunity size, growth potential, and expected financial return never increase the Alpha AIGR. Evidence that an enterprise governs opportunity decisions well may affect the applicable pillar requirements.

Public signals and verified evidence share one control model.

Every material assertion is attributable, dated, versioned, and re-testable. Alpha separates source facts from analyst judgment and records gaps instead of inferring a pass.

Panel A

Public Record

Filings, disclosures, policies, regulator records, incidents, litigation, standards activity, and attributable reporting, each with a source and cutoff date.

Panel B

Verified Operating Evidence

Board and committee records, AI and agent inventories, control tests, change logs, vendor registers, incidents, and corrective actions verified within an agreed perimeter.

Panel C

Management and Board Evidence

Structured, documented engagement with named owners across strategy, risk, compliance, security, operations, audit, and board oversight.

Panel D

External Corroboration

Independent assurance, regulator actions, observed outcomes, credible third-party evidence, and peer context used to test management claims.

Every applicable requirement uses the same 0 to 4 scale.

Applicable missing evidence produces NR. It is never converted to zero, treated as neutral, or inferred as a pass.

  1. Score 0

    Absent

    The practice is absent, contradicted, or demonstrably ineffective.

  2. Score 1

    Initial

    Intent or isolated activity exists, but ownership, coverage, or repeatability is weak.

  3. Score 2

    Defined

    The practice is documented and assigned, but implementation or evidence is incomplete.

  4. Score 3

    Managed

    The practice operates across material systems with current evidence of execution and monitoring.

  5. Score 4

    Assured

    Effectiveness is demonstrated under stress and independently reviewed where appropriate.

Traceable from legal entity to published opinion.

The data flow keeps raw source records, normalized evidence, derived metrics, and final rating observations separate. No automated calculation can publish a rating.

  1. Scope

    Resolve the legal entity, company profile, jurisdictions, AI-system roles, material use cases, evidence basis, assessment perimeter, and cutoff date.

  2. Assemble Evidence

    Collect public or verified evidence with source, date, provenance, confidentiality, freshness, and assurance metadata. Missing evidence remains missing.

  3. Test Requirements

    Assess 48 requirements and core controls using the same 0 to 4 anchors for both evidence bases. Inapplicable requirements require a documented rationale.

  4. Calculate

    Aggregate requirement results into 24 subcategories and six weighted pillar scores, then apply evidence limits and critical-pillar ceilings.

  5. Challenge and Approve

    Resolve identity, source, scoring, and post-cutoff conflicts. Analyst review, independent challenge, documented human approval, and disclosure approval are required before publication.

  6. Publish and Monitor

    Store the versioned rating, basis, rationale, outlook, evidence cutoff, limitations, and complete audit trail. New material evidence triggers review, not silent overwriting.

Jurisdiction-aware, without claiming compliance.

The Standard maps evidence and controls to relevant laws, listing standards, supervisory expectations, and voluntary frameworks. Applicability depends on legal entity, jurisdiction, sector, listing or registration status, AI-system role, use case, affected persons, risk classification, and effective date.

Regulatory sources

Applicable legislation, regulator rules, guidance, enforcement, and securities disclosure obligations.

Governance sources

Board duties, committee oversight, enterprise risk, internal control, audit, and disclosure governance.

Technical sources

Recognized AI risk, management-system, security, privacy, and assurance frameworks used as control references.

A mapping indicates relevance or possible applicability. It is not legal advice, certification, safe harbor, proof of compliance, or a claim that frameworks are equivalent.

Public enough to evaluate. Controlled enough to preserve integrity.

Alpha publishes the six pillars, pillar weights, score anchors, evidence bases, rating scale, process, regulatory approach, matrix, and limits of opinion.

Public

  • - Six pillars and their weights
  • - Public and verified evidence-basis rules
  • - Score anchors, rating scale, process, and publication gates
  • - Governance Intelligence Matrix and its no-weight rule

Controlled

  • - Rating-band thresholds and critical-pillar ceiling logic
  • - Full control tests, signal libraries, and analyst guidance
  • - Private evidence files and confidential assessment records
  • - Company-specific calculations and conflict dispositions

Request the Version 1 methodology briefing.