§1.1 Purpose
This framework provides plain-language implementation guidance for governing world models. It answers the question: if you are building, operating, or auditing a system that claims to model the world — whether that system is a research substrate, an autonomous agent, a robotics platform, or an organizational governance architecture — what structural commitments does that system need, and how do you verify they are present?
The framework is grounded in the Decision Lineage Protocol (DLP): the nineteen structural primitives at the core of the governance matrix are DLP's, and DLP-Core is the reference substrate against which this guidance is specified. Systems built on DLP apply the framework directly; systems on other substrates apply it by first mapping their own universal grammar to the nineteen primitives (§2.4). The framework is therefore not substrate-neutral — it is a DLP-based governance framework, offered with a bridge to the COSO/ISO/NIST vocabulary practitioners already carry.
The framework is organized around a governance matrix: ten ingredients that any world model requires, cross-walked against the nineteen DLP structural primitives that test whether each ingredient's implementation is structurally complete. The matrix produces 190 named control objectives — one for every ingredient-primitive intersection — and every cell must have a declared position. Five governance disciplines (Authority Mapping, Decision Boundary, Constraint Propagation, Evidence Obligations, Accountability Resolution) serve as a COSO-bridged navigational overlay grouping the nineteen primitives. This is the forcing-function discipline: no cell left blank, no ingredient ungoverned, no governance discipline unapplied.
The framework does not replace COSO, ISO, or NIST. It tests the structural connective tissue that those frameworks assume but do not specify. An organization that implements COSO's five components without authority mapping, decision boundaries, constraint propagation rules, evidence obligations, and accountability resolution will produce contradictions under load and nobody will know which output to trust. This framework names that connective tissue, makes it auditable, and maps it explicitly to COSO's seventeen principles so practitioners can see where world model governance extends their existing practice.
§1.2 Audience
The framework serves two audiences simultaneously, layered rather than separated:
Governance practitioners — internal auditors, compliance officers, risk managers, AI governance leads — who already carry COSO/ISO/NIST vocabulary and need to see why this framing adds something their existing frameworks do not cover. For this audience, the framework uses the vocabulary they already trust (control objectives, findings, corrective actions, risk assessment, evidence quality, attestation) and shows where world model governance extends it.
Founders and operators — building or deploying world-model-adjacent systems without audit or compliance backgrounds — who need governance but lack the vocabulary to implement it. For this audience, each concept is grounded in plain language before any technical term is introduced, and the "what goes wrong without it" framing makes the stakes concrete.
The framework does not choose between these audiences. Each section carries both registers.
§1.3 Relationship to Existing Frameworks
COSO, ISO, and NIST are strong on what should be governed. They provide component models (COSO's five components), process models (ISO 31000's risk management process), and function models (NIST AI RMF's four functions). What they underspecify is the structural connective tissue that makes the components, processes, and functions interact reliably.
This framework provides that connective tissue through nineteen structural primitives organized into four conformance categories (Structural, Behavioral, Temporal, Mechanical), with five governance disciplines serving as a COSO-bridged overlay:
- Who authorized this component to operate? (Authority Mapping discipline — maps to Control Environment, Principles 1-5)
- Where exactly in this process is a human making a choice? (Decision Boundary discipline — maps to Risk Assessment, Principles 6-9)
- When this component's requirement conflicts with that component's requirement, which wins? (Constraint Propagation discipline — maps to Control Activities, Principles 10-12)
- What artifact proves this component operated? (Evidence Obligations discipline — maps to Information & Communication, Principles 13-15)
- When this component fails, how is the failure resolved? (Accountability Resolution discipline — maps to Monitoring, Principles 16-17)
Every framework in the field answers some of these implicitly. Most are missing at least two explicitly. This framework makes all five explicit, referenceable, and auditable — and maps them to the COSO components that practitioners already know so the extension is traceable rather than foreign. Beneath these five disciplines, the nineteen-primitive test surface ensures no structural dimension is left ungoverned.
§1.4 What This Framework Is Not
This framework is not a standard. It does not specify conformance criteria or gate systems. It is implementation guidance — it tells you what to build and why, not how to certify that you built it. Standards that operationalize this guidance may exist in the implementing organization's governance substrate and may emerge in other governance traditions as the field matures.
This framework is not substrate-neutral. Its nineteen-primitive test surface is the Decision Lineage Protocol's; an implementation on a different substrate must first establish a mapping from its own universal grammar to those primitives (§2.4). The framework is directly applicable to DLP-based systems and adaptable, with that mapping, to others — but it does not claim to be grammar-agnostic.
This framework is not static. It is expected to evolve as the field of world model governance matures, particularly as robotics and physical-world model implementations provide new evidence about what governance structures are required when models interact with physical environments.
§1.5 How to Read This Document
Part 2 defines the Computational Governance Grammar — the three-class architecture that bridges human governance language and machine-processable structure. Read this first if you need to understand how governance intent becomes enforceable.
Part 3 defines five governance disciplines as conceptual categories (§3.1-§3.5) and then introduces the conformance test architecture (§3.6) — nineteen DLP primitives organized into four conformance categories (Structural, Behavioral, Temporal, Mechanical). The disciplines are the COSO-bridged on-ramp; the nineteen primitives are the structural test surface.
Part 4 defines the ten ingredients. Each ingredient is defined, its absence condition is stated, and implementation guidance is provided. Part 4 answers what each ingredient is and why it matters.
Part 5 presents the governance matrix — 190 control objectives produced by crossing the ten ingredients against the nineteen DLP primitives. Part 5 is the structural backbone of the framework. It answers how each ingredient is governed. Read down a column to see an ingredient's full governance profile. Read across a row to see how one primitive applies across all ingredients. The five governance disciplines serve as a navigational grouping overlay.
Part 6 provides internal control guidance that bridges the governance matrix to COSO IC 2013. It maps the five governance disciplines to COSO's five components and seventeen principles, defines entity-wide controls and specific controls by governance discipline, and connects to risk assessment instruments. Read this if you are implementing or auditing internal controls over world model operations.
§1.6 The Compliance Matrix Family
This framework's governance matrix (Part 5) is one member of a compliance matrix family. A complete implementation may produce up to four complementary matrices:
| Matrix | Cross-walk | What It Tests |
|---|---|---|
| A | Universal Grammar Primitives x Ingredients | Does each ingredient participate in each structural primitive? |
| B | Directive-Record Fields x Ingredients | Does each ingredient populate each governance field? |
| C | Charter Section x Directive-Record Field Reconciliation | Does each charter section map to the governance fields it should carry? |
| D | 19 DLP Primitives x 10 Ingredients = 190 Control Objectives | Is each ingredient governed by each structural primitive? (This document, Part 5) |
All four matrices share the forcing-function discipline: every cell must have a declared position. The architectural precedent is OMB Compliance Supplement Part 3, where every compliance type must be evaluated against every control objective category. The matrices are complementary: A governs primitive participation, B governs field participation, C governs charter-section reconciliation, and D governs implementation-level control objectives. An implementation that satisfies all four matrices has been tested at every structural layer.
§1.7 The Governance Floor (Minimum Viable Governance Posture)
Before any system-specific governance is configured, a floor always applies. The Minimum Viable Governance Posture (MVGP) is the unconditional layer — the commitments that hold for every governed organization before any conditional activation runs. It answers the question: what governance exists before you run the matrix?
The floor has three components.
Three universal domains. Every organization has people, money, and knowledge. Stated in process-taxonomy terms, these are the Human Capital, Financial Management, and Knowledge Management domains. The basis for this three-domain floor is the APQC Process Classification Framework, which inventories the cross-industry process domains common to all organizations; the three named here are the subset that is unconditional. (In a lifecycle view they are the employee loop, the dollar loop, and the knowledge loop that every enterprise runs regardless of what it sells.) These three always activate; an organization that governs none of them is not yet an organization.
One baseline control framework. COSO's Internal Control — Integrated Framework is the unconditional control baseline. Every governed organization needs internal control; the question is how much, not whether.
One baseline ontology bridge. Every governed decision has provenance (W3C PROV), and everything in an organization is either a thing that persists or a thing that happens — the continuant/occurrent distinction (Basic Formal Ontology). These are the minimum representational commitments under which the governance grammar resolves.
The floor maps onto the ten ingredients unconditionally: Purpose always connects to Knowledge Management (organizational intent is a knowledge function); Entities to Human Capital (people are always entities); Memory to Financial Management and Knowledge Management (financial records and institutional knowledge are always memory); Constraints to COSO IC (internal controls are always constraints); Time to Financial Management (fiscal periods and cost-recognition timing). These unconditional connections are the part of the governance matrix that holds before any system-specific configuration; everything beyond them is conditional on what the particular world model is for.