{
  "format": "palo-governance-control-packs",
  "schemaVersion": "1.0.0",
  "releaseVersion": "3.1.0",
  "status": "approved-for-release",
  "updatedAt": "2026-08-23",
  "authorityBoundary": "These packs define canonical PALO governance and evidence expectations. They do not decide legal applicability, certify conformity, prove deployed control effectiveness or authorize production use.",
  "completionDefinitions": {
    "governanceComplete": "Every applicable domain has canonical owned controls, schema-valid evidence records, indicators and thresholds, gate integration, stop conditions and an accepted decision; non-applicability requires a reasoned accountable review.",
    "operationalComplete": "The adopting organization has implemented the controls in its people, processes and technology, populated current evidence from the actual system and tested operating effectiveness over an appropriate period.",
    "productionComplete": "Operational controls are non-bypassable in the deployed architecture, identity and tenant boundaries are enforced, state and keys use production infrastructure, recovery is tested and independent assurance has challenged the claims.",
    "certificationComplete": "Only an authorized independent body can determine certification against a defined standard and scope; PALO artifacts can support but never create certification."
  },
  "domains": [
    {
      "domainId": "domain-fairness-subgroups",
      "title": "Fairness and subgroup testing",
      "objective": "Make quality-of-service, allocation and representational-harm evaluation a release and monitoring requirement for affected and intersectional groups.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Can outcomes or service quality differ across affected groups?", "Does the system allocate, rank, recommend or represent people or groups?"],
      "controlIds": ["ctrl-fairness-quality-of-service", "ctrl-fair-allocation", "ctrl-harmful-representation"],
      "indicatorIds": ["kpi-subgroup-evaluation-coverage", "kri-residual-disparity-rate", "kri-harmful-representation-rate"],
      "gateIds": ["classify", "assess", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["subgroup-register", "fairness-test-result", "threshold-approval", "residual-disparity-disclosure"],
      "completionCriteria": ["Applicable groups, intersections, metrics, sample adequacy and thresholds are approved before evaluation.", "Component and whole-system tests pass or a named authority records conditions, mitigation and residual disparities."],
      "stopConditions": ["A material subgroup is omitted or a release threshold is exceeded without accepted mitigation and disclosure."],
      "residualBoundary": "PALO validates the governance record, not the scientific validity, legality or social acceptability of a fairness metric or trade-off."
    },
    {
      "domainId": "domain-system-card-explanations",
      "title": "System cards and stakeholder explanations",
      "objective": "Maintain a version-bound system card and verify that affected people, operators, reviewers and customers understand the explanation needed for their decisions.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Do stakeholders need information to understand, rely on, challenge or operate the system?"],
      "controlIds": ["ctrl-system-card-explanations"],
      "indicatorIds": ["kpi-system-card-coverage", "kpi-explanation-comprehension"],
      "gateIds": ["frame", "assess", "control", "prove"],
      "evidenceContractRefs": ["schemas/palo-system-card.schema.json", "schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["system-card", "stakeholder-explanation", "comprehension-test", "limitation-disclosure"],
      "completionCriteria": ["The card matches the deployed system and identifies use, components, data, performance, limitations, oversight and monitoring.", "Representative stakeholders meet an approved comprehension rubric in supported languages and accessible formats."],
      "stopConditions": ["A material limitation, decision consequence or human action route is absent or critically misunderstood."],
      "residualBoundary": "A system card and comprehension test do not guarantee that every individual understands an outcome or that an explanation is legally sufficient."
    },
    {
      "domainId": "domain-notice-appeal-remedy",
      "title": "Affected-person notice, appeal, independent review and remedy",
      "objective": "Turn contestability into an accessible operational case flow with accountable deadlines, conflict-independent review, reasoned outcomes and verified remedies.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Can an AI-assisted interaction or outcome materially affect an identifiable person?", "Could a person reasonably need explanation, correction or review?"],
      "controlIds": ["ctrl-affected-person-notice", "ctrl-appeal-remedy"],
      "indicatorIds": ["kpi-notice-delivery-coverage", "kpi-appeal-resolution-sla", "kri-overdue-remedy-rate"],
      "gateIds": ["classify", "control", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-affected-person-case.schema.json", "schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["notice-template", "delivery-log", "appeal-case", "independence-check", "review-outcome", "remedy-record"],
      "completionCriteria": ["Notice and intake routes are accessible, timely and connected to the correct case and system version.", "Appeals receive conflict-independent review and accepted remedies are verified before closure."],
      "stopConditions": ["A high-impact system lacks a reachable human challenge route or an urgent remedy is overdue."],
      "residualBoundary": "The adopting organization must determine legal rights, deadlines, reviewer independence and available remedies for each jurisdiction and context."
    },
    {
      "domainId": "domain-article50-transparency",
      "title": "Article 50 marking, labelling and provenance",
      "objective": "Separate provider and deployer obligations and preserve evidence for AI-interaction notices, machine-readable marks, labels, provenance and exceptions.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Does the system interact directly with people?", "Does it generate or manipulate image, audio, video or text content covered by Article 50?", "Is the organization acting as provider, deployer or both?"],
      "controlIds": ["ctrl-article50-transparency"],
      "indicatorIds": ["kpi-machine-readable-marking-coverage", "kri-provenance-verification-failure-rate"],
      "gateIds": ["classify", "control", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-article50-transparency-record.schema.json", "schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["article50-applicability-record", "interaction-notice-test", "machine-readable-marking-test", "deployer-label-record", "content-provenance-record"],
      "completionCriteria": ["A reviewed actor, content-type, obligation and exception assessment exists for every supported modality.", "Independent samples verify notices, detectable marks, labels and provenance across the expected content transformation path."],
      "stopConditions": ["Required notices or markings are systematically absent, undetectable or not bound to the produced content."],
      "residualBoundary": "PALO records implementation claims but does not prescribe one technical marking standard or determine equivalent legal adequacy."
    },
    {
      "domainId": "domain-data-lifecycle",
      "title": "Dataset, annotation, privacy, retention and deletion lifecycle",
      "objective": "Trace material training, evaluation, prompt, retrieval, embedding and operational data through origin, transformation, quality, permission, lawful use, retention and verified disposition.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Does the system train, evaluate, retrieve, infer from or retain material data or knowledge sources?", "Is personal, sensitive, licensed or annotated data involved?"],
      "controlIds": ["ctrl-data-provenance", "ctrl-data-governance-lifecycle", "ctrl-annotation-quality", "ctrl-privacy-lifecycle"],
      "indicatorIds": ["kpi-provenance-coverage", "kpi-data-lifecycle-coverage", "kpi-annotation-quality-coverage", "kpi-deletion-verification-coverage", "kri-sensitive-data-events"],
      "gateIds": ["frame", "classify", "assess", "control", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-data-lineage-record.schema.json", "schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["dataset-lineage-record", "permission-record", "quality-test", "annotation-protocol", "lawful-basis-record", "retention-schedule", "deletion-verification"],
      "completionCriteria": ["Every material data asset has a versioned lineage, purpose, permission, quality, sensitivity and owner record.", "Retention and deletion decisions cover replicas, derived data, embeddings, caches and approved legal holds."],
      "stopConditions": ["A material dataset has unknown origin or permission, or sensitive data lacks an approved lifecycle and disposition route."],
      "residualBoundary": "Schema-valid records cannot establish lawful basis, ownership, representativeness or actual deletion without accountable and technical verification."
    },
    {
      "domainId": "domain-gpai-systemic-risk",
      "title": "GPAI provider, deployer and systemic-risk workflows",
      "objective": "Determine value-chain role, assemble applicable provider or deployer evidence and operate systemic-risk evaluation, mitigation, incident and downstream-information workflows.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Is the organization providing, modifying, integrating or deploying a general-purpose AI model?", "Could the model meet systemic-risk classification or create material cascading impacts?"],
      "controlIds": ["ctrl-gpai-provider", "ctrl-gpai-deployer", "ctrl-systemic-risk", "ctrl-third-party-due-diligence"],
      "indicatorIds": ["kpi-gpai-obligation-evidence-coverage", "kri-systemic-risk-finding-rate", "kpi-vendor-evidence-coverage"],
      "gateIds": ["classify", "assess", "control", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-gpai-systemic-risk-record.schema.json", "schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["gpai-role-assessment", "model-component-inventory", "provider-evidence-review", "systemic-risk-assessment", "model-evaluation", "risk-mitigation-record"],
      "completionCriteria": ["Actor role, model identity, modifications, applicable obligations and downstream dependencies receive accountable review.", "Systemic-risk scenarios, evaluations, mitigations, residual findings and incident routes are current for the released model."],
      "stopConditions": ["The GPAI role is undetermined, mandatory provider evidence is missing or a critical systemic-risk scenario is untested."],
      "residualBoundary": "PALO does not designate a model as systemic-risk GPAI, verify model-provider disclosures or establish compliance with the voluntary Code."
    },
    {
      "domainId": "domain-serious-incident-decommissioning",
      "title": "Serious-incident reporting and decommissioning",
      "objective": "Bind detection to jurisdiction-specific reporting clocks and ensure withdrawal or retirement completes stakeholder transition, revocation, data disposition and residual monitoring.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Can a system failure meet a serious-incident or other mandatory reporting threshold?", "Is the system, model, provider or material feature being withdrawn or retired?"],
      "controlIds": ["ctrl-incident-response", "ctrl-regulatory-incident-reporting", "ctrl-decommissioning"],
      "indicatorIds": ["kpi-incident-triage-time", "kpi-regulatory-reporting-clock-compliance", "kpi-decommissioning-evidence-coverage"],
      "gateIds": ["classify", "control", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-serious-incident-record.schema.json", "schemas/palo-decommission-record.schema.json", "schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["serious-incident-record", "reportability-decision", "notification-receipt", "decommission-plan", "data-disposition-record", "retirement-verification"],
      "completionCriteria": ["Clock starts, applicable deadlines, reportability decisions, notifications and corrective actions are timestamped and evidence-bound.", "Decommissioning closes only after access revocation, stakeholder transition, data disposition and residual-risk verification."],
      "stopConditions": ["A potentially reportable incident has no active accountable clock or a retirement would strand unsafe access, data or affected users."],
      "residualBoundary": "Legal reportability, authority routing and deadlines require current jurisdiction-specific review; retirement evidence needs operational verification."
    },
    {
      "domainId": "domain-accessibility",
      "title": "Accessibility of AI interactions and outcomes",
      "objective": "Test interfaces, notices, explanations, generated content, human review and remedy routes with assistive technologies and representative disabled users.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Can disabled people interact with, receive, understand or challenge system outputs?"],
      "controlIds": ["ctrl-ai-output-accessibility", "ctrl-affected-person-notice", "ctrl-system-card-explanations"],
      "indicatorIds": ["kpi-accessibility-test-pass-rate", "kri-accessibility-blocker-rate", "kpi-explanation-comprehension"],
      "gateIds": ["assess", "control", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["accessibility-test-plan", "assistive-technology-result", "user-evaluation", "conformance-report", "remediation-record"],
      "completionCriteria": ["Critical journeys and supported output modalities pass automated and manual accessibility evaluation.", "Representative disabled users can complete notice, explanation, review and remedy journeys through equivalent routes."],
      "stopConditions": ["A high-impact notice, decision, review or remedy journey has an unresolved accessibility blocker."],
      "residualBoundary": "PALO does not certify WCAG conformance or replace sector, product and jurisdiction-specific accessibility assessment."
    },
    {
      "domainId": "domain-environment",
      "title": "Environmental performance",
      "objective": "Make energy, emissions, water and hardware impacts visible through explicit boundaries, measurement or estimation, alternatives and accountable budgets.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Are training, evaluation, inference or hardware impacts material under the organization environmental boundary?"],
      "controlIds": ["ctrl-environmental-performance"],
      "indicatorIds": ["kpi-energy-measurement-coverage", "kri-environmental-budget-variance"],
      "gateIds": ["frame", "assess", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["environmental-boundary-record", "energy-measurement", "emissions-calculation", "alternative-analysis", "budget-decision"],
      "completionCriteria": ["Material workloads have declared boundaries, reproducible measurement or estimation and current baselines.", "Material regressions and alternative architectures receive an accountable budget and trade-off decision."],
      "stopConditions": ["A material workload has no baseline or exceeds an approved budget without a reviewed exception."],
      "residualBoundary": "PALO does not prescribe lifecycle-accounting methodology, verify supplier data or make environmental claims independently."
    },
    {
      "domainId": "domain-ai-literacy",
      "title": "AI literacy and competence effectiveness",
      "objective": "Move beyond attendance records by testing role-specific knowledge, practical control behavior and refresh needs after system or obligation changes.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Does a role develop, deploy, operate, review, procure, oversee or use AI on the organization behalf?"],
      "controlIds": ["ctrl-ai-literacy-effectiveness"],
      "indicatorIds": ["kpi-ai-literacy-competence-rate", "kri-trained-control-error-rate"],
      "gateIds": ["frame", "control", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["role-competence-matrix", "learning-record", "competence-assessment", "observed-practice-test", "refresh-record"],
      "completionCriteria": ["Every in-scope role has approved competencies and current role-specific learning.", "People demonstrate competence in practical assessments and observed control behavior, with failures routed to refresh and redesign."],
      "stopConditions": ["A high-authority role lacks current demonstrated competence for the system and decisions in scope."],
      "residualBoundary": "PALO cannot establish competence from attendance, self-attestation or a generic quiz and does not define an organization curriculum."
    },
    {
      "domainId": "domain-iso42001-aims",
      "title": "ISO/IEC 42001 management-system overlay",
      "objective": "Connect system-level PALO cases to organizational context, leadership, policy, objectives, support, operations, performance evaluation, internal audit, management review and corrective action.",
      "completionLevel": "governance-control-plane",
      "applicabilityQuestions": ["Is the organization establishing, operating or assessing an AI management system?"],
      "controlIds": ["ctrl-aims-leadership-objectives", "ctrl-aims-internal-audit", "ctrl-aims-management-review-capa"],
      "indicatorIds": ["kpi-aims-objective-coverage", "kpi-aims-audit-completion", "kpi-corrective-action-closure"],
      "gateIds": ["frame", "classify", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-aims-overlay-record.schema.json", "schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["aims-scope", "ai-policy", "aims-objectives", "audit-programme", "management-review-record", "corrective-action", "effectiveness-check"],
      "completionCriteria": ["The AIMS scope, policy, objectives, roles, resources and documented-information controls are approved and connected to applicable PALO cases.", "Internal audit, management review, nonconformity and corrective-action cycles operate with independence and effectiveness evidence."],
      "stopConditions": ["Material AI activities fall outside the declared AIMS scope without review or a critical nonconformity is overdue."],
      "residualBoundary": "This is an implementation overlay, not the licensed ISO/IEC 42001 text, a clause-by-clause legal interpretation or certification."
    },
    {
      "domainId": "domain-palo-ai-production",
      "title": "PALO-AI production identity, persistence, tenancy, keys and execution",
      "objective": "Fail closed unless the deployed runtime demonstrates workload identity, tenant isolation, durable recovery, external key custody, non-bypassable policy enforcement, trusted connectors and verified effects.",
      "completionLevel": "reference-runtime-only",
      "applicabilityQuestions": ["Will PALO-AI authorize or execute consequential actions in a production environment?", "Will multiple tenants, external connectors or regulated evidence use the runtime?"],
      "controlIds": ["ctrl-agentic-authority", "ctrl-runtime-production-boundary"],
      "indicatorIds": ["kpi-production-admission-coverage", "kri-execution-bypass-rate", "kri-tool-call-error-rate", "kri-override-failure-rate"],
      "gateIds": ["classify", "control", "measure", "prove"],
      "evidenceContractRefs": ["schemas/palo-production-profile.schema.json", "schemas/palo-governance-assurance-record.schema.json"],
      "minimumEvidenceKinds": ["production-profile", "identity-test", "tenant-isolation-test", "persistence-recovery-test", "key-custody-attestation", "bypass-resistance-test", "connector-attestation"],
      "completionCriteria": ["The production admission validator passes only against deployment-specific, current and independently challengeable evidence.", "Every protected external effect is observed through a claim, decision, one-time capability, trusted receipt and authoritative outcome-verification chain."],
      "stopConditions": ["Shared tokens, process-local keys, SQLite-only state, unscoped tenant data or an in-process bypass route remain in the production path."],
      "residualBoundary": "PALO 3.1 supplies a fail-closed admission contract and reference tests; it does not claim production completion until external infrastructure and independent deployment evidence satisfy that contract."
    }
  ]
}
