Alpha AIGR, Public Information
Based only on attributable public evidence available by the evidence cutoff date.
Normally capped at A, or AA with disclosed independent assurance. Never AAA.
The Alpha Standard Version 1 · Public calibration candidate
The Alpha Standard evaluates whether an enterprise can govern material AI and agentic systems. It produces one Alpha AI Governance Rating under six plain-English pillars, while identifying whether the opinion rests on public information or evidence verified by Alpha.
Release status
Methodology 1.0.0-rc.2 is not yet the active production rating engine. Historical ratings retain the methodology version under which they were issued. Version 1 customer-visible ratings require completed calibration, independent methodology challenge, legal review, a functioning approval process, and authorized activation.
Canonical rating model
Public-signal and private verified assessments do not create competing ratings. They are separate, versioned observations under one methodology, distinguished by evidence access, confidence, confidentiality, perimeter, and cutoff date.
Alpha AIGR, Public Information
Based only on attributable public evidence available by the evidence cutoff date.
Normally capped at A, or AA with disclosed independent assurance. Never AAA.
Alpha AIGR, Verified Assessment
Based on evidence verified by Alpha within a signed assessment perimeter.
Eligible for the full AAA to D scale when every publication gate is met.
Both bases use the same pillars, requirements, controls, score anchors, weights, ceilings, and rating bands. Verified evidence is isolated and cannot be disclosed through, inferred from, or silently blended into a public-information rating.
Six pillars
The six public weights sum to 100%. Each pillar contains four subcategories and eight requirements, for 24 subcategories and 48 requirement assessments in total.
P1 · 20%
Who is responsible for AI, and can the board hold them accountable?
Board authority, executive ownership, decision rights, governance structure, accountability, and reliable reporting.
Evidence examples
P2 · 22%
Can AI operate safely and withstand attack, failure, and disruption?
Safety engineering, cybersecurity, resilience, incident readiness, and controls for material AI and agentic systems.
Evidence examples
P3 · 15%
Is data protected, and are AI uses, decisions, and claims clear?
Data governance, privacy, provenance, inventory, disclosure, explainability, and traceable claims about AI use.
Evidence examples
P4 · 14%
Are people treated fairly, protected from harm, and able to challenge decisions?
Fairness, human rights, workforce and customer impacts, accessibility, notice, challenge, and remediation.
Evidence examples
P5 · 15%
Are legal duties, vendors, models, and external dependencies governed?
Legal and regulatory applicability, third-party oversight, contract controls, supply-chain governance, and stakeholder duties.
Evidence examples
P6 · 14%
Can the enterprise detect problems, intervene, correct them, and learn?
Continuous monitoring, independent assurance, override and shutdown capability, corrective action, and learning from outcomes.
Evidence examples
Growth and governance
The six pillars define what Alpha assesses. The Governance Intelligence Matrix classifies where a material risk or opportunity sits, then routes it to accountable board, committee, and management owners.
Internal Opportunity
What internal AI capability can improve how the enterprise operates?
Examples: Operating model · Workforce capability · Internal AI investment
External Opportunity
What market, customer, investment, or partnership opportunity can AI create?
Examples: Customer value · Strategic partnerships · New markets
Internal Risk
What internal AI exposure must be governed, controlled, or escalated?
Examples: Policy exceptions · Shadow AI · Control failures
External Risk
What external threat, dependency, regulatory change, or competitive event requires a response?
Examples: Regulatory change · Vendor concentration · External threats
Every classified signal, finding, incident, opportunity, or governance action has exactly one quadrant and at least one pillar. The matrix is not a seventh pillar and has no rating weight. Opportunity size, growth potential, and expected financial return never increase the Alpha AIGR. Evidence that an enterprise governs opportunity decisions well may affect the applicable pillar requirements.
Evidence
Every material assertion is attributable, dated, versioned, and re-testable. Alpha separates source facts from analyst judgment and records gaps instead of inferring a pass.
Panel A
Filings, disclosures, policies, regulator records, incidents, litigation, standards activity, and attributable reporting, each with a source and cutoff date.
Panel B
Board and committee records, AI and agent inventories, control tests, change logs, vendor registers, incidents, and corrective actions verified within an agreed perimeter.
Panel C
Structured, documented engagement with named owners across strategy, risk, compliance, security, operations, audit, and board oversight.
Panel D
Independent assurance, regulator actions, observed outcomes, credible third-party evidence, and peer context used to test management claims.
Score anchors
Applicable missing evidence produces NR. It is never converted to zero, treated as neutral, or inferred as a pass.
Score 0
The practice is absent, contradicted, or demonstrably ineffective.
Score 1
Intent or isolated activity exists, but ownership, coverage, or repeatability is weak.
Score 2
The practice is documented and assigned, but implementation or evidence is incomplete.
Score 3
The practice operates across material systems with current evidence of execution and monitoring.
Score 4
Effectiveness is demonstrated under stress and independently reviewed where appropriate.
Rating process
The data flow keeps raw source records, normalized evidence, derived metrics, and final rating observations separate. No automated calculation can publish a rating.
Resolve the legal entity, company profile, jurisdictions, AI-system roles, material use cases, evidence basis, assessment perimeter, and cutoff date.
Collect public or verified evidence with source, date, provenance, confidentiality, freshness, and assurance metadata. Missing evidence remains missing.
Assess 48 requirements and core controls using the same 0 to 4 anchors for both evidence bases. Inapplicable requirements require a documented rationale.
Aggregate requirement results into 24 subcategories and six weighted pillar scores, then apply evidence limits and critical-pillar ceilings.
Resolve identity, source, scoring, and post-cutoff conflicts. Analyst review, independent challenge, documented human approval, and disclosure approval are required before publication.
Store the versioned rating, basis, rationale, outlook, evidence cutoff, limitations, and complete audit trail. New material evidence triggers review, not silent overwriting.
Regulatory alignment
The Standard maps evidence and controls to relevant laws, listing standards, supervisory expectations, and voluntary frameworks. Applicability depends on legal entity, jurisdiction, sector, listing or registration status, AI-system role, use case, affected persons, risk classification, and effective date.
Applicable legislation, regulator rules, guidance, enforcement, and securities disclosure obligations.
Board duties, committee oversight, enterprise risk, internal control, audit, and disclosure governance.
Recognized AI risk, management-system, security, privacy, and assurance frameworks used as control references.
A mapping indicates relevance or possible applicability. It is not legal advice, certification, safe harbor, proof of compliance, or a claim that frameworks are equivalent.
Transparency boundary
Alpha publishes the six pillars, pillar weights, score anchors, evidence bases, rating scale, process, regulatory approach, matrix, and limits of opinion.
Public
Controlled