Skip to content
Norivo

The VALID Framework

A practical operating model for AI governance.

VALID is Norivo's 25-control methodology for turning AI governance principles into repeatable operating practices. It is published under a CC BY-ND 4.0 licence and cross-mapped to the EU AI Act, ISO/IEC 42001 and NIST AI RMF.

  • 25 controls
  • 5 layers
  • 7 axioms
  • Level 0 to Level 5
  • CC BY-ND 4.0
“The question is never whether your AI system is working. The question is whether you would know if it stopped.”

VALID borrows its architectural logic from Maslow's hierarchy of needs. Governance requirements sit in a dependency hierarchy: foundational layers must be in place before higher-order capabilities can function. Unlike Maslow's hierarchy, VALID requires all five layers to be active at the same time. A gap in any one layer compromises every other layer. The framework's central claim is that AI governance failures are, at their root, detection failures.

Method

The five layers

  1. Visibility. You cannot govern what you cannot see.

    Every AI system operating in the organisation, whether built internally, procured from a vendor or embedded in a third-party product, is identified, documented and understood well enough to answer four questions: what decisions does it make or inform, who does it affect, what data does it use and where did that data come from, and what are its documented limitations and known failure modes.

  2. Accountability. Governance without proof is intention.

    The organisation can produce, on demand, documented evidence of explainability, bias testing, regulatory mapping and tamper-evident audit trails. VALID sets a three-tier explainability standard: individual, contrastive and systemic explanation.

  3. Lifecycle Monitoring. Deployment is not governance. Deployment is the beginning of governance.

    VALID identifies performance, demographic, scope and data drift, and applies a trigger-first, cadence-second principle: event-driven reviews are mandatory, calendar reviews are the safety net. Every newly deployed system gets a 90-day post-deployment review.

  4. Integrity. Governance without ownership is policy. Ownership without governance is good intentions.

    Every AI system has one named individual, not a team, not a committee, not a shared inbox, who owns it, understands it, monitors it, can escalate and hands over cleanly.

  5. Defence. Governance that cannot survive failure is not governance.

    Defence is the organisation's demonstrated capacity to anticipate, absorb, respond to and recover from AI system failure. It includes kill-switch standards, AI-specific incident response, red teaming and agentic requirements for chain-of-action auditability, scope containment and cascade circuit breakers.

Dependency

One system, not five pillars

Each layer depends on the one beneath it. Accountability requires Visibility. Lifecycle Monitoring requires Accountability. Integrity requires Lifecycle Monitoring. Defence requires Integrity. Every incident, red-team finding and rehearsal learning then feeds back from Defence into Visibility. That feedback loop is how governance matures.

Maturity

The maturity model

LevelNameLayers achievedDiagnostic signal
0UnawareNoneAsk how many AI systems the organisation operates. The answer is: we do not know.
1AwareVComplete AI inventory. Four foundational questions answered for every system.
2AccountableV + AOn-demand evidence of explainability, bias testing and audit trails.
3MonitoredV + A + LActive drift surveillance with defined triggers and a documented cadence.
4OwnedV + A + L + INamed owner for every AI system. Documented escalation paths.
5ResilientV + A + L + I + DIf the most critical AI system fails at 2am on a Sunday, the response is specific, named, timed and documented.

Principles

The seven axioms

  1. Governance is not compliance. Compliance is the minimum a regulator imposes. Governance is the standard an organisation sets for itself.

  2. The absence of evidence is not evidence of absence. An untested system is not an unbiased system. It is a system with undocumented bias.

  3. Drift is not a defect. Ignoring drift is a defect.

  4. Accountability cannot be outsourced. A vendor's compliance is not the deployer's compliance.

  5. A governance framework that cannot be understood by a non-specialist is not a governance framework.

  6. Governance must survive personnel change.

  7. The goal of governance is not to prevent AI deployment. The goal is to make AI deployment trustworthy.

Alignment

Regulation-compatible, not regulation-dependent

VALID is built on organisational truths rather than any single regulation. The published alignment map connects each layer to the EU AI Act, UK FCA/PRA guidance, the NIST AI RMF, Nigeria's NDPC requirements and ISO/IEC 42001. Norivo delivers against the EU AI Act, ISO/IEC 42001 and NIST AI RMF today; the map shows where the same five layers land in other regimes.

Implementation

The 120-day pathway

The framework sets out a 120-day implementation pathway from Level 0 towards Level 3, with Integrity and initial Defence capabilities started by day 120. Norivo's managed engagements follow this dependency sequence. "Audit-ready from 30 days" refers to the first organised evidence position; full VALID implementation is a broader programme.

Agents

Agentic AI

VALID governs agentic systems through the same five layers rather than a separate model: authority scope under Visibility, chain-of-action audit trails under Accountability, behavioural monitoring under Lifecycle Monitoring, named ownership of authority boundaries under Integrity, and cascade circuit breakers under Defence. Norivo Agentic Defence is the product implementation of that Defence capability.

A practical operating model for AI governance.