Governance Coherence Addendum
| Specification | Published | Applies To | Status |
|---|---|---|---|
| v1.0.2 | March 2026 | DSI 001 Compliant and DSI 001 Certified tiers | Current |
Published by the Decision Standards Institute Ltd (ACN 699 264 376).
Contents
- Purpose and Scope
- Relationship to DSI 001
- Governance Coherence Components
- The Governance Coherence Index
- Coherence Finding Severity
- Evidence Requirements
- Assessment Report Structure
- Reassessment Triggers
- Assessor Authorisation Requirements
1. Purpose and Scope
This Addendum formalises the Governance Coherence layer of DSI 001. It specifies how operational governance is evaluated, measured and reported alongside the six-dimension design assessment.
Governance Coherence addresses the most significant limitation of design-only assessment: the decoupling between documented governance architecture and actual operational practice. An organisation may maintain governance documentation of excellent quality while governance controls are not exercised in operation. DSI 001 Compliant and DSI 001 Certified certification tiers require demonstration of operational coherence, not design adequacy alone.
This Addendum applies to all DSI 001 assessments at the Compliant and Certified certification tiers. It does not modify the DSI 001 Assessed tier, which remains a design adequacy assessment.
2. Relationship to DSI 001
Governance Coherence is not a seventh DSI 001 dimension. It is an evaluation layer applied across the six existing dimensions. This preserves the existing scoring architecture while adding operational verification.
The design assessment, expressed through the Governance Benchmark Index, evaluates whether governance architecture is appropriately structured for the system’s risk profile. Governance Coherence evaluates whether that architecture is actually exercised. The GBI and GCI together determine certification tier eligibility.
The parallel is the SOC 2 Type I and Type II distinction. The GBI assessment corresponds to point-in-time design adequacy. The Governance Coherence assessment corresponds to operational effectiveness over a defined period.
3. Governance Coherence Components
3.1 Authority Adherence
Authority Adherence measures whether operational decisions occurred within the authority boundaries defined in the governance architecture.
Assessment indicators include decision logs showing authority level applied at each consequential action, escalation records demonstrating that decisions exceeding defined autonomy thresholds were escalated to the appropriate authority level, and override logs documenting instances where automated decisions were superseded by human intervention with authorisation records for each override.
A pattern of systematic boundary violations, where decisions consistently operate at autonomy levels above those defined in the governance architecture, is a critical coherence finding requiring closure before certification can be issued or maintained.
3.2 Control Exercise
Control Exercise measures whether specified governance controls were performed at the required cadence and depth during the assessment window.
Assessment indicators include governance meeting records with timestamps, attendance and decision records; approval documentation for system changes, autonomy level modifications and provider substitutions; monitoring reports demonstrating that surveillance obligations were fulfilled; and incident records showing governance processes were triggered by operational events.
The absence of any recorded exceptions is a negative coherence indicator. Real operational deployments of autonomous systems produce edge cases, boundary conditions and governance events. Zero exceptions suggests either that the governance process is not being exercised or that exception recording is not functional. Assessors must specifically evaluate the absence of exceptions rather than treating it as evidence of clean operation.
3.3 Drift Detection
Drift Detection measures whether the system’s operational behaviour has diverged from the governance assumptions made at the time of the initial or most recent assessment.
Drift is specific to autonomous systems. Unlike human-operated processes, autonomous systems can change their own effective behaviour post-deployment through model updates, training data changes, scope expansion and adaptive logic. A system may have been correctly assessed at deployment and may have drifted outside its governance architecture without any deliberate decision by the organisation.
Assessment indicators include model version tracking with change impact assessments, operational scope documentation comparing deployed scope against assessed scope, decision pattern analysis identifying systematic changes in decision distributions, and provider change records where third-party AI components have been substituted or updated.
Drift detection is the component that distinguishes Governance Coherence from standard audit methodology. It is the primary justification for continuous or periodic coherence reassessment rather than one-time certification.
4. The Governance Coherence Index
4.1 Scoring Methodology
The Governance Coherence Index is scored on a 0.0 to 1.0 scale, calculated per DSI 001 dimension. A GCI of 1.0 represents full operational coherence: all governance controls exercised at the required frequency and depth, no authority boundary violations, and no measurable drift from governance assumptions.
Dimensional GCI scores must be reported individually to preserve diagnostic utility. The dimensional GCI scores are the coherence gate for certification. A single aggregate coherence figure is not used to determine tier. Where a single combined figure is reported, it is the coherence-adjusted GBI defined in 4.2, and it is a reported signal only.
4.2 GCI as Bounded GBI Modifier
The GCI functions as a bounded modifier on the base GBI dimensional scores. The GBI runs from 1.0 to 5.0 where lower is stronger. The GCI runs from 0.0 to 1.0 where higher is stronger.
For a given dimension, the effective dimensional score is:
Effective Dimensional Score = GBI Dimension Score + (5.0 - GBI Dimension Score) x (1.0 - GCI Dimension Score)
At GCI 1.0, no penalty is applied. As GCI falls, the effective dimensional score moves toward 5.0 but cannot exceed 5.0. The division form is not used.
The coherence-adjusted GBI is the unweighted average of the six effective dimensional scores. It is reported as the primary governance signal describing coherence-adjusted governance posture. It is not the tier-determining figure and is not comparable to the raw GBI design thresholds. Tier determination uses the raw composite GBI at the design gate and the dimensional GCI at the coherence gate, as set out in 4.3.
4.3 Certification Thresholds
Certification tier is determined by independent design, coherence, finding and evidence gates. All applicable gates must be satisfied. The design gate is tested against the raw composite GBI. The coherence gate is tested against the dimensional GCI. The coherence-adjusted GBI defined in 4.2 is reported alongside the determination and does not gate the tier.
| Gate | DSI 001 Compliant | DSI 001 Certified |
|---|---|---|
| Design gate, composite GBI (raw) | At or below 2.50 | At or below 1.75 |
| Coherence gate, dimensional GCI | At least 0.70 in every assessed dimension | At least 0.85 in every assessed dimension |
| Finding gate | No unresolved critical coherence finding; any significant coherence finding disclosed and subject to an accepted, time-bound corrective-action plan | No unresolved critical or significant coherence finding |
| Evidence gate | Tier 1 or Tier 2 evidence per Section 6.2 | Tier 1 evidence for at least 80% of sampled controls |
4.4 Calibration Protocol
During the initial deployment period, the following calibration requirements apply:
| Requirement | Description |
|---|---|
| Dual-assessor validation | All GCI scores must be independently validated by a second authorised assessor. |
| Range reporting | GCI scores are reported as a range during calibration, for example 0.75 to 0.85, rather than as a point estimate. |
| Inter-rater tracking | Scoring differences between assessors must be documented and submitted to the Decision Standards Institute Ltd. |
| Threshold review | Provisional thresholds are reviewed and adjusted as needed after 20 and 50 assessments. |
5. Coherence Finding Severity
A coherence finding is an operating-coherence finding. It records a failure, lapse or inconsistency in the operation of a governance control, evidence pathway, accountability assignment, boundary condition, monitoring process or reassessment trigger that the assessed governance architecture represents as operative.
A coherence finding is not a design finding. Where a required governance element is absent, inadequately designed or incorrectly specified, the issue is assessed through the dimensional GBI methodology. Governance Coherence assesses whether the governance architecture that has been represented as operative actually operated coherently during the assessment period.
Coherence findings are classified as Critical, Significant or Informational.
5.1 Critical coherence finding
A Critical coherence finding exists where an operating-coherence gap means that, for one or more consequential decisions within the assessment scope, the institution cannot answer one or more accountability questions with eligible evidence: who was responsible, what they knew, and what they did.
A Critical coherence finding also exists where the operating-coherence gap causes the relevant dimension’s GCI outcome to fall outside the certification threshold for the tier sought.
A Critical coherence finding blocks both DSI 001 Compliant and DSI 001 Certified status until closed.
5.2 Significant coherence finding
A Significant coherence finding exists where the governance architecture operated, and the accountability questions remain answerable, but the assessment identifies material, non-isolated operating lapses that would reasonably require disclosure to an institutional audience.
Significant coherence findings include repeated control-operation failures, material evidence-continuity gaps, inconsistent application of an approved governance process, or reliance on compensating evidence where the primary evidence pathway did not operate as represented.
A Significant coherence finding blocks DSI 001 Certified status. It does not block DSI 001 Compliant status where the finding is disclosed and subject to an accepted, time-bound corrective-action plan.
5.3 Informational coherence finding
An Informational coherence finding exists where the assessment identifies an isolated lapse, documentation weakness or improvement issue that does not undermine the accountability chain, does not cause the relevant dimension’s GCI outcome to fall outside the certification threshold for the tier sought, and does not require institutional disclosure beyond the assessment report.
Informational coherence findings do not block DSI 001 Compliant or DSI 001 Certified status. Repeated informational findings may be aggregated into a Significant coherence finding.
5.4 Aggregation
Findings are assessed individually and in combination. Multiple informational findings associated with the same control, evidence pathway, accountability assignment, boundary condition or reassessment trigger may be treated as a Significant coherence finding.
Multiple Significant coherence findings within the same dimension, or across dimensions where they affect the same consequential decision pathway, may be treated as a Critical coherence finding where their combined effect prevents the institution from answering one or more accountability questions with eligible evidence.
5.5 Closure
A Critical coherence finding is closed only when corrective action has been implemented, eligible evidence has been produced, and the assessor has retested the affected control, pathway or process.
A Significant coherence finding must be closed before DSI 001 Certified status is issued. For DSI 001 Compliant status, a Significant coherence finding may remain open only where it is disclosed and subject to an accepted, time-bound corrective-action plan.
Informational findings are recorded and monitored but do not require closure before certification unless repeated, aggregated or escalated.
6. Evidence Requirements
6.1 Evidence Tiers
| Tier | Type | Description |
|---|---|---|
| Tier 1 | Infrastructure-Generated Evidence | Evidence produced directly by technical enforcement infrastructure: automated decision logs, enforcement action records, exception and override logs, drift monitoring outputs. Tier 1 evidence is the most reliable because it is contemporaneous and cannot be retrospectively assembled. |
| Tier 2 | Contemporaneous Documentation | Evidence produced at the time of governance events but not by automated infrastructure: governance meeting records with timestamps, approval documentation, escalation logs, manual review records. Tier 2 evidence is acceptable where Tier 1 is structurally unavailable, primarily for D3, D4 and D5 assessments. |
| Tier 3 | Reconstructed Documentation | Evidence assembled retrospectively from available records. Tier 3 evidence may inform design adequacy assessment but is not admissible for Compliant or Certified coherence assessment unless expressly permitted by the applicable methodology for a non-material control. |
| Tier 4 | Management Representation | Formal written representation where no contemporaneous record exists. Tier 4 is not admissible for coherence assessment at any certification tier. Where management representation is the only available source for a material control, the control is assessed as not evidenced. Primary reliance on Tier 4 for a material control is a significant coherence finding. |
6.2 Evidence Requirements by Certification Tier
DSI 001 Assessed: No coherence evidence required. Design adequacy assessment only.
DSI 001 Compliant: Tier 1 or Tier 2 evidence required. Where Tier 2 evidence is used in lieu of Tier 1 for D1, D2 or D6, the assessment report must note the limitation. Tier 2 evidence is the expected standard for D3, D4 and D5.
DSI 001 Certified: Tier 1 evidence required for at least 80% of sampled controls. Tier 2 evidence is acceptable for D3, D4 and D5. Any control assessed on Tier 2 evidence must be individually identified in the assessment report.
6.3 Assessment Window
The minimum assessment window for coherence evaluation is 180 days. The assessment window must be specified in the certification report.
Assessors must sample governance artefacts across the entire assessment window, not only from periods immediately preceding assessment. Sampling must check presence, timeliness and completeness of evidence.
6.4 Data Handling
- Evidence reviewed during assessment must be held under confidentiality obligations equivalent to those applicable to financial audit work papers.
- Evidence must not be retained beyond the period required for assessment completion and regulatory compliance.
- Evidence destruction protocols must be specified in the assessment engagement terms.
- Where evidence contains personal data, assessment must comply with applicable privacy legislation.
7. Assessment Report Structure
All DSI 001 Compliant and Certified assessment reports must separate design adequacy findings from operational coherence findings. The required report structure is:
- Executive Summary, including certification tier, GBI score, GCI scores and scope
- Scope and Assessment Window
- Design Adequacy Assessment, including GBI dimensional scores and findings
- Governance Coherence Assessment, including GCI dimensional scores and findings
- Evidence Summary, including evidence tier used per dimension and gaps noted
- Findings and Observations, classified as critical, significant and informational
- Scope Limitation and Disclaimer
The scope limitation language must appear in every Compliant and Certified assessment report:
This certification covers the governance architecture design and operational coherence of [Organisation] during the assessment window specified above. It does not guarantee future system performance, safety, regulatory compliance, insurability, financing outcome, or absence of adverse outcomes. Certification is subject to reassessment upon the occurrence of material change events as defined in DSI 001.
8. Reassessment Triggers
The following events invalidate the coherence assessment and require mandatory reassessment before certified status can be maintained:
- material change to the system’s autonomy level, including an increase of more than one Autonomy Gradient level
- substitution of a primary AI provider or model
- significant expansion of operational scope beyond the scope assessed
- a material incident in which the governance architecture was engaged, tested or found insufficient
- discovery of systematic governance drift identified outside the normal assessment cycle
- a government action, including supply chain risk designation, affecting the enterprise’s primary AI provider or any material component of the Decision Supply Chain
Organisations must notify their authorised assessor of triggering events within 60 days of occurrence. Continued use of a certification after a triggering event without initiating reassessment constitutes a certification breach.
9. Assessor Authorisation Requirements
Governance Coherence assessment requires competencies distinct from design adequacy assessment. Authorised assessors must complete the Governance Coherence module of the DSI 001 Assessor Authorisation Programme before conducting coherence assessments at the Compliant or Certified tier. The module covers:
- evidence evaluation methodology for each coherence component
- sampling design for governance artefact review
- drift analysis techniques for autonomous systems
- GCI scoring mechanics and calibration protocols
- report structure and scope limitation requirements
Citation
Martin, Carly. DSI 001 Governance Coherence Addendum, Version 1.0.2. Decision Standards Institute Ltd, 2026.
Published by the Decision Standards Institute Ltd (ACN 699 264 376).