# The govrn Attestation — artifact specification (v0.2)

> **Status:** v0.2 — §6 (who signs / liability) and §7 (forcing function) are now **research-grounded and sourced**
> (see References). Remaining **[VERIFY]** items are narrow legal-specifics for counsel + insurer + the founding
> CTO/CSO. Nothing tagged **[VERIFY]** appears in client-facing or investor-facing material until cleared.
> **Why this doc exists:** three independent strategic reviews (GTM, operator, adversary) converged on the same
> gap — *"independent attestation" is a claim of authority govrn does not yet have, and nobody is currently
> required to hold one.* The moat is not the detectors (all open-source). The moat is a precisely-defined,
> trustworthy, recognized attestation artifact and the liability posture behind it. This is that definition.
> **Updated:** 2026-07-03.

---

## 1. The one-sentence definition

A **govrn attestation** is a signed, independently-produced statement — backed by a normalized, tamper-evident
evidence chain — that a named AI estate meets a defined govrn control standard at a stated assurance level, as of
a stated date, across every cloud, model, and agent in scope regardless of who built them.

It is **not**: a scan report, a monitoring dashboard, a vendor's self-declaration, or a one-time assessment that
never renews. Those are inputs. The attestation is the independent, recurring, signed conclusion drawn from them.

## 2. The structural seam (why an independent third party owns this)

The party that owns the control plane cannot credibly audit itself. Microsoft (Agent 365 / Purview), AWS, and
Google can inventory and monitor AI in their own estates — and increasingly do, for free — but a hyperscaler
attesting to the governance of its own platform is marking its own homework. Independence is the product.
This is the durable insight the reviews affirmed; everything below exists to make it *legally real* rather than
a marketing claim.

## 3. Assurance levels (tiered — this is how a voluntary attestation earns weight over time)

| Level | Name | What it means | Who signs | Year-1 reality |
|---|---|---|---|---|
| L0 | **Self-declared** | Client asserts controls; govrn structures the claim | Client officer | Free / top-of-funnel |
| L1 | **govrn-reviewed** | govrn verifies evidence exists and is current; no opinion on sufficiency | govrn | The Discovery deliverable |
| L2 | **govrn-attested** | govrn opines the estate meets the govrn standard at a point in time | govrn (defined liability) | The paid annuity product |
| L3 | **Accredited-signed** | An accredited/licensed assessor co-signs govrn's evidence | Partner attester + govrn | The endgame / consortium tier |

**[VERIFY]** The line between L2 and "practicing public accountancy / issuing an assurance report" is a legal one.
Year-one posture is almost certainly **govrn as the independent *evidence and standard* layer feeding a licensed
attester who signs** — not govrn signing a SOC-2-style opinion itself. Counsel must draw this line before L2 is sold.

## 4. What gets attested — scope maps to the 9-pillar Classification Standard

Each attestation states, per pillar, the controls in scope and the evidence backing them (see GOVRN-CLASSIFICATION.md):
Security · Model risk & bias · Guardrails & oversight · Cost & tokenization · Data & privacy · Compliance &
regulatory · Third-party & supply chain · Transparency & accountability · Infrastructure & hardware.
The **govrn Gauge** (0–100) is the client-facing rollup; the attestation is the auditable record beneath it.

## 5. The evidence chain (this is the buildable part — the "fabric")

```
detectors / sensors            normalize                evidence spine          signed conclusion
garak, promptfoo, ModelScan,   →  OCSF Compliance   →   OSCAL component +   →   govrn attestation
Nuclei, Trivy, lm-eval,           Finding (internal     assessment-results      (L1/L2/L3) with a
cloud-native signals              normalized record)    control-mapped record   tamper-evident hash chain
(GuardDuty/Defender/Vertex)       + SARIF ingest        + ISO42001/NIST crosswalk
```

- **Detectors are commodity** — integrate, don't rebuild. The value is above them.
- **Normalization → OSCAL-native, control-mapped, tamper-evident output** is the defensible artifact. **[VERIFY]**
  the tamper-evidence design (hash chain / signing) with the CSO once hired.
- Ingest is read-only by default (client-owned operating model B); govrn attests *over* the client's estate
  without holding custody of raw sensitive telemetry. This is both the trust story and the privacy posture.

## 6. Who signs, and the liability question (RESEARCHED — this is now decided, not open)

The adversary's sharpest question was *"who audits the auditor?"* Sourced research (2026) answers it, and the answer
constrains the model. **govrn cannot self-confer a "certification" or sign a weight-bearing "attestation" on its own.**
- **ISO/IEC 42001 certification** can only be issued by a **certification body accredited** by a national
  accreditation body (ANAB in the US, UKAS in the UK) against **ISO/IEC 17021-1 + ISO/IEC 42006:2025**. Accredited
  bodies now exist (Schellman was first ANAB-accredited; A-LIGN, BSI, SGS, DNV, TÜV following). Becoming one is a
  multi-year, witnessed-audit process — not a startup's year-one path.
- **SOC 2 / SSAE 18 attestation** can only be signed by a **licensed, independent CPA firm.** A non-CPA tech company
  issuing a "SOC 2-style" report is an overclaim auditors and procurement will reject.
- **Issuing carries E&O / professional-indemnity liability** — a negligent attestation someone relies on to their
  loss is the classic claim. That legal exposure is exactly *why* the signing role is accredited/licensed and insured.

**So the govrn structure is the proven GRC wedge, stated plainly:** govrn is the **independent evidence, standard,
and orchestration layer** that continuously maps controls, produces the audit-ready, OSCAL-native evidence pack, and
**feeds an accredited certification body / licensed CPA firm who signs** — the exact model Vanta, Drata, and Credo AI
run (none of them issue the attestation themselves; they enable the accredited signer). The govrn attestation *at L3*
is the independent signer's signature on govrn's evidence and standard. This is not a limitation to hide — it's the
independence story: **govrn never marks its own homework, and neither does the hyperscaler.**

Still genuinely open for counsel + insurer (narrow, legal-specific):
- **[VERIFY]** E&O / professional-liability sizing and whether govrn carries any residual exposure as the evidence
  preparer even when it does not sign.
- **[VERIFY]** Exact scope-and-reliance language (what the attestation warrants, effective date, no guarantee-against-failure).
- **[VERIFY]** Which accredited body / CPA firm partners for the co-sign, and the L1/L2 "govrn-reviewed" language that
  is defensible *without* an accredited signature (first-party / verified-claims framing).

## 7. The forcing function — how a voluntary credential gains pull (RESEARCHED — and it corrects our pitch)

A govrn attestation is worth exactly what the parties who *demand* it recognize. Sourced research (mid-2026) upends
the intuitive framing: **the strongest near-term pull is private-market, not regulatory.** "Regulation is coming"
is actually the *weak* pitch in the US right now (federal posture turned deregulatory; Colorado's AI Act was repealed;
EU high-risk slipped to Dec 2027). Lead with the commercial levers. Ranked by sourced realism:

1. **Procurement / vendor requirement — REAL, NOW. The single strongest lever.** ISO/IEC 42001 is moving from
   standard to RFP requirement, exactly the way SOC 2 / ISO 27001 did — enterprise buyers (finance, health, federal,
   multinationals) increasingly gate vendors on third-party AI-governance attestation. **This is the wedge:** sell
   "win the RFP / clear the security questionnaire," not "comply with the law."
2. **Cyber-insurance — REAL, ACCELERATING.** 2026 carriers introduced **"AI Security Riders"** requiring documented
   model-risk assessments, red-teaming, AI-use policies, and training as *prerequisites to coverage*, and are adding
   AI exclusions where governance is absent (the MFA/EDR playbook, replayed). The premium-discount-for-certification
   phase is the next shoe — a high-conviction bet. **Validate with a cyber-insurer/broker first** (DEMAND-VALIDATION.md).
3. **US safe-harbor statutes — REAL, NOW, and it's a carrot.** Texas TRAIGA (effective Jan 1 2026) and California
   grant a rebuttable presumption / safe harbor for adopting NIST AI RMF or ISO 42001 — certification becomes a
   **litigation shield**, which survives the deregulatory turn precisely because it's an incentive, not a mandate.
4. **Board / fiduciary (Delaware Caremark) — REAL but INDIRECT.** The oversight duty is being extended to AI risk
   (NIST AI RMF "Govern" ≈ the "information and reporting system" directors must establish); AI-securities suits and
   an SEC "AI-washing" settlement raise the temperature. This drives demand for *demonstrable* governance —
   attestation is the proof artifact, not a mandate. D&O underwriters now probe AI governance.
5. **EU AI Act — REAL but DEFERRED for the big wave.** GPAI obligations (in force since Aug 2 2025) and Article 50
   transparency + Article 4 AI-literacy bind now (retained at Aug 2 2026); high-risk Annex III slipped to **Dec 2027**
   via the Digital Omnibus. Penalties up to €35M / 7%. Matters for EU-facing deals; weaker as a *2026* US forcer.
   **[VERIFY]** every regulatory claim per surface, per jurisdiction, with counsel.
6. **US federal regulation — WEAKEST / anti-tailwind. Do not anchor GTM to it.** The Dec 2025 EO is deregulatory and
   preemption-minded; state mandates proved fragile (Colorado). Frameworks (NIST AI RMF) matter as *safe harbor*, not hammer.

**Standards alignment (the posture underneath all six):** map to ISO/IEC 42001 and NIST AI RMF so a govrn attestation
*complements* the recognized standards rather than competing with them. We are the operational evidence-and-issuer
layer against accepted frameworks — not a rival framework. Marquee ISO 42001 adopters already include Anthropic, AWS,
Microsoft, OpenAI, CrowdStrike, and BCG — the credential is becoming a trust signal, which is the tailwind we ride.

> **The pitch, corrected:** sell the private-market trinity — *win the RFP · lower the premium · shield the board* —
> not "regulation is coming." That's what the sourced evidence supports as of mid-2026.

## 8. Independence & governance — resolving the Microsoft tension

The reviews flagged a real contradiction: govrn cannot be the neutral cross-vendor attestor *and* a de-facto
Microsoft asset. Resolution, to be stated publicly and structurally:
- Microsoft (and every hyperscaler) is a **first certified party / design partner — never the owner of the standard.**
- The standard's governance must be **visibly neutral** (independent governing charter; no single vendor controls
  the criteria) or AWS/Google will never certify against it and the consortium never forms.
- A near-term commercial relationship with Microsoft (co-sell, marketplace, even acquisition interest in the
  *services/tooling* entity) must be firewalled from control of the *standard* itself. **[VERIFY]** this structure
  with counsel; it likely implies two things: an operating company (services/tooling, acquirable) and a neutral
  standards/attestation function (not).

## 9. Open questions to close (owner → who resolves)

1. L2-vs-licensed-assurance legal line — **counsel**.
2. E&O / professional liability sizing — **counsel + insurer**.
3. Accredited co-signer partnership (which body/firm) — **founder + CSO**.
4. Tamper-evidence + signing design for the OSCAL output — **CTO/CSO**.
5. Insurer/board demand reality — **founder** (DEMAND-VALIDATION.md).
6. Standards-body vs. operating-company legal structure for neutrality — **counsel**.

*This spec is the product definition the raise and the Microsoft pitch both actually rest on. §6 and §7 are now
hardened with sourced research; close the remaining legal-specific [VERIFY] items with counsel before either goes out.*

---

## References (sourced 2026-07-03 — two independent research sweeps)

**Attestation authority & liability (§3, §6):**
- ISO/IEC 42006:2025 (requirements for bodies certifying AI management systems) — iso.org/standard/42006; ANAB 42001 program — anab.ansi.org.
- First accredited 42001 certification bodies: Schellman (first ANAB-accredited), A-LIGN, SGS, BSI (first UKAS, Nov 2025 → triple-accredited Mar 2026), DNV, TÜV.
- SOC 2 / SSAE 18 (AT-C 105/205) — only a licensed CPA firm may sign (Linford & Co; AICPA).
- EU AI Act Art. 43 conformity assessment; notified bodies Arts. 28–39 — artificialintelligenceact.eu.
- Auditor/attestor professional-indemnity (E&O) norms — The Hartford; industry E&O guidance.
- Comparable startups feed accredited signers, do not self-issue: Vanta (introduces vetted independent auditors), Drata, Credo AI.

**Forcing functions (§7):**
- Procurement: ISO 42001 moving from standard to vendor/RFP requirement — brightdefense.com; isms.online; orolabs.ai (exact % figures vendor-sourced, directional).
- Cyber-insurance "AI Security Riders" (2026) — compliancehub.wiki; insurancebusinessmag.com; Aon 2026 AI-risk agenda.
- Board/Caremark AI oversight + D&O + SEC AI-washing settlement — dandodiary.com; ethics.harvard.edu; bclplaw.com.
- EU AI Act Digital Omnibus (Council final 29 Jun 2026; high-risk → 2 Dec 2027; GPAI + Art. 50 + Art. 4 live) — gibsondunn.com; consilium.europa.eu.
- US: NIST AI RMF status; Dec 2025 deregulatory EO (natlawreview.com); Texas TRAIGA (eff. 1 Jan 2026); Colorado SB 24-205 repealed/replaced by SB 26-189 (crowell.com); TX/CA safe-harbor for NIST/ISO 42001 (verifywise.ai).
- ISO 42001 adopters: Anthropic (Jan 2025), AWS (Nov 2024), Microsoft (Jul 2025), OpenAI, CrowdStrike (Jan 2026), BCG (Jan 2026); ~350+ orgs certified by Apr 2026 (aggregator estimate, directional).

*Full sourced briefs retained in the session record. Figures marked directional are corroborated in direction but not from a single authoritative registry.*
