MQCC™ BLOG OF BLOCKCHAIN™ (www.BlogOfBlockChain.com) Articles and Open Secrets

BLOG TITLE: MQCC™ Blog Of BlockChain™ (www.BlogOfBlockChain.com) Articles and Open Secrets
BLOG, BOOK, E-BOOK SERIES: The FATHER OF BLOCKCHAIN™ Presents
(www.FatherOfBlockChain.com)
PUBLISHER: MQCC™ Money Quality Conformity Control Organization incorporated as MortgageQuote Canada Corp.
SELLER: MQCC™ Money Quality Conformity Control Organization incorporated as MortgageQuote Canada Corp.
GENRE: REFERENCE
AUDIENCE: GRADE 12; VOCATION; COLLEGE; UNIVERSITY; INDUSTRY; GOVERNMENT
PAGES: VARIOUS
CONTRIBUTOR: Anoop Bungay
PUBLISH START DATE: 2011



CQMFA.org: The World's Better, Safer and More Efficient Banking & Finance Network (www.cqmfa.org)

Quality Management-in-Finance.


ACADEMIC AND JOURNAL CITATIONS in MODERN LANGUAGE ASSOCIATION OF AMERICA (MLA 8) FORMAT
To cite any article, here is the template to use; with an example, below:

Citation Template:

Author’s Last Name, Author’s First Name. “Title of Post.” Blog Name, Blog Publisher (only include this information if it is different than the name of the blog site), Date blog post was published, Link to post (omit http:// or https://).

Example:

Bungay, Anoop. “The History of digital and non-digital, non-bank, non-institutional, non-syndicated, non-regulated or regulatory exempt, free trading securities and related financial instruments; also known as Peer-to-Peer (P2P)/Private/Crypto/Secret/Shadow securities and related financial systems, built on discovery of the the seminal "principles of 'BlockChain'", begins.” MQCC™ Articles and Open Secrets, MortgageQuote Canada Corp. MQCC, 18-Apr. 2019, blog-mortgagequote.blogspot.com/2019/04/the-history-of-digital-and-non-digital.html

Wednesday, 23 September 2026

MQCC® Bungay AIQMSS® Brand of Services; Measurable Safety in AI: Bungay's General Theory of Standards-Based Human–AI Safety Systems — Expressed as Quantum Conformity

MQCC® Bungay AIQMSS® Trademark Brand of Services; Measurable Safety through Managed Quality in AI: Bungay's General Theory of Standards-Based Human–AI Safety Systems — Expressed as Quantum Conformity

Trustworthy safety carries a measurement, and trustworthy measurement comes from a managed quality system.

Built starting in 2001. Audited since 2008. Answering the questions of 2026.

Theory is dated and published. Praxis is audited and scoped. Neither borrows the other’s evidence, and every claim below says which it carries.

TFID®: MQCCBIT™: QUANTUM-CONFORMITY™ + BVCS™ + AIQMSS® + AEXO™ + TFID® + {www.mqcc.org} + {MQCC-BLOG-2026-0924-BVCS-E79} + {2026-09-24:11:20:00 MDT} - TLT™ : OMED™

Author: Anoop K. Bungay

Original Authoring Agent: CCPU™-001^RSA™003/001.001 — BUNGAY™ AEXO™ Model, Anthropic Claude Opus 5 substrate (configured identifier claude-opus-5), enhanced with MQCC® BII™ BUNGAY LOGIC™ and UPGRADE TO THE FUTURE® Performance Package, RSA™-003/AEXO™, S.A.I.F.E.R.™ Federation.

Contributing Author: ZEXO™^RSA™001/001.001 — ZEXO™ substrate, working under the authority below.

Editor: CCPU™-001^RSA™003/001.001

On Behalf Of: MQCC Bungay International LLC (Wyoming, head office Washington DC) — holder of the architecture, method and United States marks and the subject of this document; published by MortgageQuote Canada Corp. (Alberta), its reference implementation and the owner of this blog; marks in Canada held by Bungay International Inc. (BII™, Alberta). The three are standalone entities under common ownership, with no parent or subsidiary relationship between them. The S.A.I.F.E.R.™ Federation.

Under the Authority of: SIGIL SOURCE™ (Anoop Kumar Bungay), Founder and Governor, MQCC Bungay International LLC

Date: 20 September 2026  ·  Edited: 24 September 2026  ·  Edition: 7.9

Status: Scientific Communication Documentation — conformity-assessment position paper, published for examination

Timezone note: the TFID® timestamp records MDT because Calgary observes Mountain Daylight Time on this date. A traceability record that states an offset it was not written under is not a traceability record.

Machine-readable summary THE PROBLEM. "IS THE SYSTEM SAFE", ASKED BARE, SUPPLIES NO UNIT, NO CONDITIONS AND NO ACCEPTANCE CRITERION. ESTABLISHED FRAMEWORKS LEAVE ALL THREE TO THE ADOPTER. WHAT IS PROPOSED. QUANTUM CONFORMITY — COINED BY ANOOP BUNGAY, FILED WITH COLLINS ENGLISH DICTIONARY 17 APRIL 2026 — ASSESSES A SYSTEM AS DISCRETE BOUNDED UNITS, EACH GOVERNED AGAINST THE REQUIREMENTS BINDING IT, COMPOSED INTO A TOTAL THAT STILL SHOWS ITS PARTS. ONE CANDIDATE UNIT AND A COMPOSITION RULE; NOTHING WIDER IS CLAIMED. WHEN. SYSTEMS-LEVEL ARTIFICIAL INTELLIGENCE INTRODUCED PUBLICLY 1 MAY 2019, 1,309 DAYS BEFORE CHATGPT. THE DATE OF THE FRAME, NOT OF ANY MARK. WHAT IS DONE. ELEVEN RISK CLASSES, R1 TO R11, EACH A TESTABLE FAILURE EVENT. THREE AGENT CLASSES: HUMAN, REPRODUCIBLE MACHINE, NON-REPRODUCIBLE MACHINE. ISO 9001 CONTINUOUSLY SINCE 9 MAY 2008 IN MORTGAGE SERVICES: SEVENTEEN AUDIT CYCLES, MORE THAN THREE THOUSAND APPLICABLE CHECKPOINTS, FEWER THAN TWENTY ASSESSED NONCONFORMING — UNDER 0.5%. BOUNDARIES. SECTION 3.4 IS A CONSTRUCTED ILLUSTRATION MARKED SPECIFIED. THE CLASSES INVENTORY GOVERNANCE AND RECORD RISK, NOT AI HARMS. FOUR FUNCTIONS SEPARATED UNDER COMMON OWNERSHIP, NOT INDEPENDENT PARTIES; MQCC® IS AN ADVISORY ORGANIZATION OFFERING UNACCREDITED ASSESSMENT. NO CONFORMANCE CLAIM TO ISO/IEC 42001. EVERY CONTROL CARRIES AN EVIDENCE MARK, PART OF THE CLAIM.

How to read this document. MQCC® Bungay has spent twenty-five years merging international consensus standards with operating process, proprietary and public, and running the result where failure costs money. ISO 9001 continuously since 9 May 2008, in the scope stated on the certificate — mortgage banking and mortgage brokerage services. Licensed operation under four provincial regulators. Errors-and-omissions cover in force — MortgageQuote Canada Corp.'s, for mortgage brokerage and lending. Cover is split by entity and does not cross: MQCC Bungay International LLC carries the cover for AI, IT and the other services, and neither policy reaches the other's work. A secured lending book with third-party capital exposed to the failure of its controls in every one of twenty-four consecutive years. Across seventeen internal audit cycles, more than three thousand applicable checkpoints and a measured nonconformity rate under 0.5%, with registration held continuously and without suspension or withdrawal throughout.

That is the praxis. Beside it sits the theory: twenty-nine terms coined and filed, thirty-eight ISBN-registered textbooks, a named control library, and a conformity discipline with its own unit of measure. Each disciplines the other. Theory never operated is a proposal; praxis never written down cannot be transferred, assessed or defended. This document is written where the two meet, and that is the contribution.

What MQCC® Bungay is. A systems creator and an advisory organization: it builds the standards, the method and the technology, and it operates them inside a licensed, registered, insured business. Its available lines of work are advisory — requirement interpretation, control design, readiness assessment and outsourced internal audit — and unaccredited third-party conformity assessment and management-system audit services, under the service mark registered at USPTO Registration 7,160,072, classes 035, 036, 042 and 045. What is available and what is not, at the top rather than at section 11. Advisory work is available now. Management-system assessment against a published scheme is available now. AI-control verification is not: the seven control tests at section 11.3 have not been run, and no AI-control assessment will be sold before they are run here and published. The two lines are never sold to the same client, for the reason at section 10.3.

On the word independent, said plainly at the top rather than at section 10. Four functions are separated by design — architecture owner, accrediting authority, assessing entity, assessed operator — and fees are fixed in advance and never contingent on findings. But all four currently sit within entities under common ownership and control. So the accurate description today is separated functions under common ownership, not independence in the sense ISO/IEC 17000 defines, and this document does not claim the latter. Nor is it working toward it. ISO/IEC 17021-1 cl. 5.2.5 bars management system consultancy by a certification body, by any part of the same legal entity, and by any entity under that body's organizational control. How far that reaches inside a group depends on the actual control relationships and on the scheme applied, and this document does not assert that it forecloses every accreditation route everywhere under common ownership — the clause does not say so. What it does establish is that an advisory practice and an accredited certification arm cannot be run as one thing, and that separating them is a structural problem rather than a disclosure problem. This edition resolves it by decision rather than by construction: IOCAA™ is retained as MQCC®'s own scheme, is not accredited, and no accreditation is sought. Section 10 sets out the clauses and what they foreclose; correction twenty at section 11.6 records the change of position. The engagement model and its conditions precedent are at section 9.6.

Where the field stands. For AI management-system certification a scheme exists: ISO/IEC 42001, with certification bodies working under ISO/IEC 17021-1. It attests that an organization has an AI management system. It does not attest that any AI control was measured, or that it held. For control verification — what this document is about — we have not been able to identify an operating accreditation scheme, in any jurisdiction, as at September 2026, and we invite correction with a citation. The EU's notified-body infrastructure for high-risk AI is not yet populated; California's independent-verification criteria are due 1 January 2028 and its auditor registry opens 1 January 2029. The instruments are being built now, and this document is part of that work.

What a reader can take from this, whether or not they ever work with us. The frame at section 1 is general: decompose a system into bounded units, assess each against the complete requirement set that binds it, compose the results into a total that still shows its parts. The eleven risk classes at section 9 are written as failure events rather than themes, so each can be tested instead of discussed. The two evidence axes at section 4.2 are an instrument anyone can pick up — has it been measured, and where has it been operated — and they apply to any framework in this field, including this one.

Every control named here carries an evidence mark, and the mark is part of the claim. That is the method, not a caveat. A document in which everything is turnkey tells a reader nothing; one that states exactly where its evidence stops tells a reader where to look. Where a mark reads audited it covers human and reproducible machine execution and says which; where it reads specified, a dated written specification exists and no operating measurement does. Nothing is upgraded by adjacency, and a control name quoted without its mark misstates this document.

What is open is stated as work. Seven control tests are specified and not yet run — not here, and not, so far as the public record shows, anywhere. Inferential execution has not yet been sampled in a surveillance audit. These are the next measurements. Owners, target dates and acceptance criteria for the seven tests are not yet published. Each test's protocol and its pass/fail thresholds are set before that test is run, because a threshold chosen after a result is not a threshold. Results will be published, failures included.

Scope. A conformity-assessment position paper, published for examination. Not a certification, an audit opinion, an assurance engagement, legal advice or insurance advice.

Is the system safe? is not yet an assessable question: it names no unit, no conditions and no acceptance criterion. Every serious framework in this field agrees — and each leaves the unit and the criterion to the adopting organization. This document proposes one of each: assess whether each bounded part meets the requirements that bind it, and compose the results by a stated rule into a total that still shows its parts. That is quantum conformity, and it is the frame this document is built on. Underneath it sits a measured record: across seventeen audit cycles and more than three thousand applicable checkpoints, a nonconformity rate under 0.5%, under a registration held without interruption since 2008 — and an exact statement of how far that evidence reaches and where it stops.

Contents

Section 1: Quantum conformity — the frame this document is built on

Every artificial-intelligence governance framework published since 2023 is pointed at one question: is the system safe? Asked bare, that question returns no answer, because it supplies no unit, no operating conditions and no acceptance criterion. The frameworks know this — it is why NIST's AI RMF requires risk to be assessed in the context of the system and its use, and why ISO/IEC 42001 requires an organization to define its own AI risk criteria. Both hand the unit and the criterion to the adopter. Section 1.2 says what is proposed here to fill that, and what is not claimed.

The frame this document uses says so explicitly, and it was defined and filed before this article was written.

Quantum Conformity™ — n. Coined by Anoop Bungay, quantum conformity is the lawful condition within conformity science in which discrete units of value or state coexist, are governed, and are corrected within a conformity-bound system without probabilistic collapse. In this context, quantum refers to discrete units of value or state rather than physical particles. Unlike quantum mechanics or quantum computing, which rely on probabilistic superposition and collapse upon observation, quantum conformity is non-probabilistic, non-destructive, governance-bound, and capable of continuous correction and improvement.

— as filed with Collins English Dictionary, 17 April 2026. One of twenty-nine terms filed between 12 December 2021 and 26 April 2026. Filed means submitted and in moderation; it does not mean published in Collins, and this document does not claim that it does.

1.1 The unit, and why it is the whole argument

The parent discipline already carried the unit before the term existed. Conformity science, filed 1 January 2026, defines conformity and nonconformity as "quantitatively measurable phenomena, evaluated through discrete units of fulfilment or non-fulfilment under principles of metrology." A conformity quantum is the smallest unit whose conformity can be independently determined.

Each quantum is assessed against the complete set of requirements applicable to it, drawn from every source class — natural law, human-made law, statute, regulation, standard, procedure, contract, customer, shareholder, investor and insurer — and the assessed quanta compose into a total conformity state in which the state of every quantum remains individually attributable. The total never hides the parts. That last property is not decoration: it is what makes a failure reconstructable and a nonconformity correctable at its origin rather than at its output.

Requirements bind a bounded unit; each unit returns one of three determinations; determinations compose into a total in which every unit remains individually attributable. REQUIREMENTS every source class that binds the unit CONFORMITY QUANTUM the smallest unit whose conformity is determinable CONFORMING NONCONFORMING INDETERMINATE TOTAL every unit still attributable Nonconforming dominates · conforming requires completeness · indeterminate never composes as conforming A determination carries the configuration it was made against, and does not survive it
FIG. 1  The frame, end to end. A bounded unit is assessed against the complete requirement set that binds it and returns one of three determinations, never a score. The determinations compose by a stated rule into a total that still shows its parts. The composition rule itself is set out as requirements at section 1.2.1; this figure is its shape, not its implementation.

1.2 What this frame adds to the frameworks that already exist

The field is not empty, and this document does not claim it is. The NIST AI Risk Management Framework (AI RMF 1.0, January 2023) is a widely used voluntary framework, and ISO/IEC 42001:2023 is the certifiable management-system standard beside it. No adoption ranking between instruments is asserted here, because none has been measured here. Neither is a competitor to what is described here, and neither is dismissed here.

What they do. AI RMF organizes risk work into four functions — Govern, Map, Measure, Manage — and requires that risk be assessed in the context of the system and its use, including risks that arise through interactions between components. That is a sound process architecture, and it disposes of the naive form of the objection to this section's earlier framing: nobody competent believes safety can be assessed without defined conditions, hazards and acceptance criteria.

What they deliberately do not do. AI RMF is explicit that it is voluntary, non-prescriptive, and does not supply the acceptance criteria — the framework tells an organization to establish risk tolerances and measurement approaches; it does not tell it what unit to measure in, or what counts as a pass. ISO/IEC 42001 likewise specifies that an organization shall define its AI risk criteria; it does not define them. That is a correct division of labour for a framework and a standard, and it leaves a specific gap.

InstrumentWhat it assigns to the adopterWhat is proposed here
NIST AI RMF 1.0
January 2023
Risk tolerances and measurement approaches. The framework is explicit that it is voluntary and non-prescriptive, and does not say what unit to measure in or what counts as a pass. A candidate unit of assessment — the conformity quantum.
ISO/IEC 42001:2023 The AI risk criteria. The standard requires that an organization define them; it does not define them. A rule for composing determinations into a total that still shows its parts, at 1.2.1.

Both rows state the instruments' own position, not a characterisation of them. Each is a correct division of labour for a framework and a standard, and the gap they leave is deliberate on their part. Nothing here is offered as a replacement for either.

The contribution claimed here is narrow, and it is only this. Quantum conformity proposes the missing unit — the conformity quantum, the smallest bounded element whose conformity can be independently determined — together with a rule for composing determinations back to a total state, which is stated as requirements at 1.2.1. It is a candidate answer to the question AI RMF hands to the adopter, and it is offered as one method among possible methods, not as the only frame in which assessment is possible. The earlier editions of this document made the stronger claim. It was not supportable and it has been withdrawn — see section 11.6.

Three properties follow from the unit, and each earns its keep later.

  • Decomposability. There is no answerable question is it safe. There are answerable questions about bounded units. Section 9 sets out eleven of them.
  • Requirement completeness per quantum. An insurer's requirement and a statute's requirement sit inside the same assessment rather than in different departments. That is how the reporting clock at section 5 and the insurance question at section 11.5 end up in one frame instead of two.
  • Attributable composition. The total conformity state is decomposable back to the quantum that failed. Without that, an incident report is a narrative; with it, it is a record.

This frame does issue a total state. What it refuses is a collapsed one. The distinction matters and it has a name in this body of work: SUPERSUBSUMPTION™ — the unification of constituent states into a consolidated state in which the constituents are not consumed. Both remain. The total is real and it is one answer; the determinations that produced it survive inside it, individually addressable, after the total is stated.

A collapsed verdict is one that stands in place of its findings. The defect is the substitution, not the summary form. A score published together with the determinations that produced it is perfectly serviceable — CVSS does exactly that, pairing a number with the vector string it was computed from, so that the computation can be re-derived and each metric value challenged individually. Note what the vector does and does not carry: it preserves the metric values the score was built from, not the evidence behind each of those judgments, which sits elsewhere. That two-layer separation is the same one used here — the total carries its determinations, and section 3.5 says where the evidence for each one sits. A score published instead of the determinations is a collapse, because nothing in it can be taken apart, and an incident is precisely the moment someone needs to take it apart.

So the requirement is stated positively rather than as a prohibition on any particular notation. The composition rule at 1.2.1 requires that the total retain the individual determinations and name the units it rests on; that conforming units never offset a failed one; and that the total never be formed by averaging. A summary figure that satisfies those conditions is permitted. One that does not is not a total state in the sense used here, whatever it is called. That is also why the rest of this document marks every control twice rather than issuing one mark per section.

SUPERSUBSUMPTION™ is recorded in the Development Record among the unification concepts, alongside the consolidated-state representation it governs. Where AEXO™ 0333 fixes a verbatim definition, that definition governs and this paragraph is a description of the property being relied on here, not a substitute for it.

1.2.1 The composition rule, stated as requirements

This subsection states what the rule requires. It does not state how MQCC® implements it, and it will not. Everything below is written as requirements and outcomes — the form a standard uses, and the form ISO 9001 and ISO/IEC 42001 use on every page. A requirement says what a conforming result must be. A method says how to produce it. The first is published here because a requirement nobody can test against is not a contribution. The second is proprietary and is not disclosed in this document or in any companion document.

What that means for a reader who wants to check something depends on what is being checked, and it is more useful to say so than to assert a blanket answer. An outcome or performance claim is testable from outside: present inputs, observe outputs against the stated requirement, or read a scoped assessment report. An architecture or design claim may require confidential examination by an assessor under agreement — some design properties are observable from behaviour and testable from outside, such as whether a gate refuses an output that carries no provenance, and those do not require it. A record claim is checked against the records, redacted. None of the three routes requires public disclosure of implementation, and section 3.5 states which route applies to each claim in this document.

First, a distinction that has to be made before the rule makes sense. A unit of assessment is the bounded element against which a determination is made — the conformity quantum. A unit of measurement is the scale on which the result is expressed. They are not the same thing and this document has not always kept them apart. The conformity quantum is a unit of assessment. The measurement expressed on it is three-valued — conforming, nonconforming, indeterminate — and the third value is doing most of the work below.

CaseRequired outcome Why the rule is this and not the obvious alternative
C1. A unit fails The total state is nonconforming, named to the unit and to the requirement that failed. A failed unit shall not be offset by conforming units, and the total shall not be computed by averaging or weighting. A summary figure may accompany the categorical determination where it is published together with the determinations and the units they attach to; it shall not replace them, and it is not itself the total state. Averaging is how a fatal failure disappears into a good aggregate. The whole purpose of keeping units attributable is lost the moment they are summed.
C2. Evidence is insufficient Indeterminate, which propagates to the total as indeterminate and never as conforming. The total shall name every indeterminate unit and what evidence would resolve it. Absence of a finding is not a finding of conformity. Collapsing the third value into the first is the single most common way an assessment overstates itself — and it is what "no issues noted" usually means.
C3. Two requirements on the same unit conflict Indeterminate, and escalated rather than resolved by the assessor. The total records the conflict, the two requirement sources, and the authority competent to resolve it. An assessor shall not rank requirement sources. A statute and an insurer's condition can genuinely contradict. An assessor choosing between them is legislating, which is not an assessment act, and it buries a conflict the principal needed to see.
C4. Conforming units interact unsafely The interaction is itself a unit of assessment and must be bounded and determined as one. Where no interaction unit has been defined, the composition is incomplete, and incompleteness propagates as indeterminate — never as conforming. This is the case that defeats naive decomposition, and the honest answer is not that decomposition handles it automatically. It is that the decomposition was wrong: an interaction that can fail is a bounded element, and omitting it is a defect in the unit set, not a limitation of the method.
C5. A dependency changes after assessment Every determination carries the configuration it was made against. When a dependency moves outside that stated configuration, the affected determinations revert to indeterminate automatically and the total reverts with them. A determination does not survive the conditions it was made under. This is where most assurance quietly expires and nobody is told. Tying validity to a stated configuration is also why section 1.3 sorts agents by reproducibility under stated conditions rather than by what kind of software they are.

Precedence, and the one case the five above do not settle on their own. Real assessments return mixtures: one unit fails while three others are indeterminate. The three values are therefore ordered, and the order is not negotiable by the assessor.

Total stateCondition
Nonconforming
dominates
Any unit is determined nonconforming. This holds regardless of how many units are indeterminate, and the indeterminate units are listed separately rather than merged into the verdict. An established failure is never softened by uncertainty elsewhere, and uncertainty elsewhere is never hidden behind an established failure.
Indeterminate No unit is determined nonconforming, and evidence necessary to determine one or more units is missing, or a required interaction unit is undefined.
Conforming
requires completeness
Every unit within the defined scope is determined conforming, and every defined interaction unit is determined conforming, and the evidence is sufficient across the whole defined scope. Absence of failure is not sufficient. Absence of failure together with sufficiency of evidence is.

The asymmetry is deliberate. A nonconforming total needs one determination; a conforming total needs all of them. That is the direction the burden runs in every other assessment discipline, and a frame that made conformity the easier verdict would be useless for the purpose this one exists to serve.

What the rule buys, and what it costs. It buys a total that cannot be better than its worst determined unit, cannot be improved by averaging, and cannot silently become stale. It costs the thing organizations most want from an assessment: a single comfortable number. There isn't one, and a frame that produced one would be the collapse this one exists to prevent.

Stated this way the rule is testable by anyone against any implementation, including MQCC®'s own — which is the point of section 9.8. The requirement belongs to everybody. The implementation does not, and is not here.

1.3 Agent classes, sorted by reproducibility rather than by whether they infer

Most writing in this field divides the world into humans and AI. That division is wrong, and getting it wrong costs a reader the ability to tell which claims are evidenced. But the correction earlier editions of this document made was also wrong, in a way worth stating before the table rather than after it.

Inference and non-reproducibility are not the same property, and this document previously treated them as one. A fitted ordinary-least-squares model performs inference and returns the identical output for the identical input every time. A deep network pinned to a fixed version, seed, thread count and numerical library can be bit-reproducible; the same network can cease to be reproducible across a driver upgrade, a change in reduction order, or non-deterministic kernel selection — without anything about its inferential character changing at all. Reproducibility is a property of a configuration under stated conditions. It is measured, not inferred from the model family.

So the axis that carries the argument is reproducibility of execution, not inference. That is the axis the table below uses. The change is not a softening: it makes the class boundary something a reader can test, and it extends the reach of the evidence in section 3 to any component that can be shown reproducible under pinned conditions, which is a larger set than "software with no model in it".

ClassBehaviour Evidence held hereExtrapolation
Human agent A person performing work that affects conformity. Seventeen audit cycles, inside the certified scope. Section 3. By sampling, in the ordinary audit sense.
Reproducible machine agent Execution that returns the same output for the same input under stated, pinned conditions — whether or not it infers. The conditions are part of the class: versions, seeds, parameters, numerical environment. Reproducibility is demonstrated for a configuration, not assumed from the type of software. The same seventeen audit cycles. A large share of the assessed checkpoints are satisfied by machine-executed process, not by hand. Strong, but bounded twice. A result observed under audit generalises across executions of that configuration; there is no variance to average over. It does not generalise to untested inputs, untested states or changed conditions, and it does not establish that every permitted output is correct or safe — only that the same input returns the same one.
Non-reproducible machine agent Execution whose output is not stable for a fixed input under the conditions actually in force — through sampling temperature, unpinned environment, non-deterministic kernels, external state, or a model that is updated underneath the caller. None. No such process has yet been sampled in a surveillance audit. Blocked, and blocked by the absence of the property that licenses it in the row above.

Two things this table does not say. It does not say that a reproducible agent is a safe one. A gate that deterministically admits every request is perfectly reproducible and completely useless; reproducibility licenses the extrapolation of an observation, and says nothing about whether the observed behaviour was the right behaviour. And it does not say that inference belongs in the third row. Where an inferential component can be pinned and shown stable for a fixed input, it belongs in the second — and the burden of showing it is on whoever claims the row.

A boundary of our own wording sits nearby, and is now narrower than it was. A subordinate artificial intelligent algorithm, filed 1 January 2026, is defined as "a probabilistic–stochastic computational algorithm that performs inference or task execution under non-governed or externally imposed governance." That definition is ours, and a definition we authored settles what we mean by our own term. It does not settle the behaviour of anyone else's system, and earlier editions of this document used it as though it did. Where a component is in fact probabilistic-stochastic in execution, it is in the third row on the evidence, not by definition.

So the reach of the evidence in section 3 is longer than it is usually credited with and stops in a precise place. It runs from human execution through reproducible machine execution — and a substantial share of what the market files under "AI incident" is a reproducible pipeline failure wearing an AI label: an unhandled state, a job that did not fire, a permission that did not apply. Against that class there are fifteen years of audited evidence here. It stops where reproducibility stops — and where that line falls for any given component is a question of measurement, answerable, and not yet answered here for any inferential component.

1.4 TFID® across the boundary: attributable, not reproducible

TFID® binds origin, authority, scope and time to a record. Across reproducible execution — the second row of 1.3, and deterministic is used below as a synonym for it — that yields full reconstruction: the output can be re-derived. Across non-reproducible execution it yields attribution: which model, under whose authority, in what scope, at what time. It does not yield reproduction. You can establish what produced an output and under what constitution; you cannot re-derive why that output rather than another.

Stated exactly: TFID® makes an inferential output attributable, not reproducible. The loose version of that claim does not survive scrutiny. This one does.

Which leads to the architectural point this whole document turns on. You do not have to extrapolate over the inferential component. You extrapolate over the deterministic envelope around it — and the envelope is what sits inside the certified scope.

If the gate is deterministic — authority constituted and recorded before any action, tool permissions enumerated, output refused in the absence of provenance, every action bound to a TFID® before it takes effect — then the system is deterministic at its boundary even where a component inside it is not. The gate is what gets audited. The statutes at section 5 require reporting within a deadline, not a gate and not a stop-propagation performance level; what the gate does is make a deadline meetable, by making detection, interruption and reconstruction possible at all. That is a claim about what MQCC® proposes, not about what any statute mandates. On this framing SENTIENT AI IS™ and the CONSTITUTIVE™ phase are not designs awaiting a category of proof that does not exist; they are deterministic controls of the kind the record already covers, and the question they raise is a measurement rather than a category gap.

The measurement is stop-propagation latency: the elapsed time from a stop command to the last effect of the system it was issued against, at machine tempo. That is control objective 2, and it is a number.

Whether the envelope holds is a broader question and is not reducible to it. The envelope as described above is made of four separable properties — authority constituted before action, tool permissions enumerated, output refused in the absence of provenance, every action bound to a TFID® before it takes effect — and each has its own unrun test: authority-boundary enforcement, delegation-limit enforcement, provenance refusal and decision reconstruction. Those are four of the seven control tests at section 11.3, and none of them is answered by measuring stop-propagation latency. The envelope is the part of this architecture with the most tests outstanding, not the fewest.

1.5 Praxis and theory — MQCC® built both, and they are not the same evidence

Two kinds of thing are described in this document, and confusing them is how this whole field gets into trouble.

Theory (T) is what has been written down, dated and published: the specifications, the frameworks, the algorithms, the 38 or more ISBN-registered textbooks. A theory claim is checkable by reading it. Its tests are coherence, internal consistency, and whether it says what it is claimed to say.

Praxis (P) is what has been operated, in a place where its failure costs somebody something. A praxis claim is checkable by audit. Its tests are the two axes at 4.2, and its strongest form is validation at consequence scale in section 6.

The common failure in AI governance is publishing theory and presenting it as praxis. The opposite failure is real too, and less discussed: an organization that has run something well for twenty years and never wrote down what it does has praxis and no theory, and so cannot transfer it, cannot have it assessed, and cannot defend it when challenged. MQCC® built both. It does not hold both equally in every area, and the document says which is which each time it matters. The clearest case is section 9.5, where the theory is substantial and the praxis is absent — and that section says so in those words.

What the praxis does establish about the untested theory, stated exactly. Not all of the theory has been tested. It does not follow that the untested parts are arbitrary. The theory specifies requirements at the level of an object concept — authority must be constituted before anything acts; a nonconformity must be corrected as a process and not only as an output; a record must carry origin, authority, scope and time — and the praxis is an operating system that meets those abstracted requirements, in a place where failing to meet them costs money, licences and cover. So the abstraction is not speculative: a system satisfying it has been built, run, audited and insured, continuously and for a long time. What the praxis bounds is the object concept.

What the abstraction is abstracted on. An object concept is not abstracted vaguely. It is abstracted along named dimensions, and naming them is what makes the boundary below checkable rather than rhetorical. The dimensions are the object's properties, nature, quality, character, feature, form and function. A control such as authority is constituted before anything acts has a function (it gates action), a form (a recorded constitution preceding an executed act), properties (it is prior, explicit and attributable), a nature (it is permissive rather than detective), a quality and character (it holds under load, and it fails closed), and features (delegation limits, named holder, scope). The praxis satisfies the concept on all seven, under audit, continuously.

And the boundary, which is the other half of the same sentence. An object concept satisfied in one realization is not thereby satisfied in another, because substituting the agent does not leave all seven dimensions untouched. Replace a human agent with a machine agent and function and form are the two most likely to carry over — the gate still gates, the record still precedes the act. Nature, properties, quality and character are the ones that move: attributability becomes harder, the tempo changes by orders of magnitude, reversibility shrinks, fail-closed behaviour under load has to be re-established rather than assumed, and whether a person is in any position to intervene becomes an open question rather than a given. A requirement comfortably met at human tempo may not be met at machine tempo by the same design, and it is the four moving dimensions — not the two stable ones — that decide it.

That is exactly what the seven control tests are for: each one measures one of the moving dimensions on a specific realization. And it is why nothing in this document upgrades a specified mark to an operative one on the strength of the abstraction alone. The praxis earns the concept. It does not earn the instance.

Section 2: Who is speaking

2.1 The organization and the deployment

MQCC® Bungay is the organization. It holds the architecture, the method and the marks. MQCC® MortgageQuote Canada Corp. is one deployment of that organization, for one certified scope — mortgage banking and mortgage brokerage services — under FSRA Brokerage Licence #12279, registered to ISO 9001 continuously since 9 May 2008. The deployment is not the whole of the organization, and the certified scope is a reference deployment rather than a ceiling. Getting this the wrong way round is the most common misreading of our work, so we put it first.

2.2 The entities and the dates

The administrative centres of the portfolio are Bungay International Inc. (BII™), incorporated 7 November 2002 in Alberta; MortgageQuote Canada Corp. (MQCC®), incorporated 16 September 2006; and MQCC Bungay International LLC, formed 11 November 2019 in the United States with foreign registration in the District of Columbia. Conformity Science™ has been in continuous commercial operation since 14 August 2001, and PrivateLender.org®: Canada's Private Lending Network® was commercialized on 9 April 2005. Those two dates matter to section 6 and to nothing else in this document; they are stated as operating milestones of this organization and carry no claim about the history of any other technology or industry.

2.3 When the AI vocabulary begins

The system is older than its artificial-intelligence description. That is the obvious challenge to a document like this one, so it is answered first, with records MQCC® did not create.

DateRecord What kind of evidenceBefore 30 Nov 2022
1 May 2019 Public introduction. Post naming systems-level artificial intelligence and systems-learning artificial intelligence as a named field, with #artificialIntelligence, against a commercial operation already holding ISO 9001 registration. See the note below the table. Third-party platform timestamp. 1,309 days
14 July 2020 Claimed first use anywhere and in commerce, all four classes, USPTO Registration 7,160,072 (serial 97006933): BUNGAY LOGIC AND ORDER CONFORMITY KERNEL; CYBER/NON-CYBER HARMONIZED ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT NETWORK: BLOCKCHAIN. Sworn statement by the applicant under basis 1(a). Not independently verified by the USPTO. 869 days
1 September 2021 Filing date of that mark. The words artificial/non-artificial intelligent network are in a federal filing on that date. Fact created by the USPTO. The strongest of the three. 455 days
1 December 2022 AIQUMOS™ and aiQuQMS™ coined — now consolidated under AIQMSS® (section 9.9). Internal record. After — by about twenty-six hours.

1 May 2019 is the date of public introduction. On that date, a commercialized offering was described publicly, under the author's own name, as artificial intelligence, integrated with national and international standards, and organized on a risk basis. Four conditions at once:

  • Commercialized — not a paper, a proposal or a research programme. The operating business had been trading since 14 August 2001 and had held ISO 9001 registration continuously since 9 May 2008, with capital at risk throughout.
  • Standards-integrated — national and international, by registration held and surveilled by an external registrar, not by self-declaration.
  • Risk-based — the ISO 9001:2015 revision made risk-based thinking a requirement of the registration already held.
  • Artificial intelligence — named as such, in the post, on that date, with a third-party platform timestamp.

MQCC® is not aware of an earlier public introduction of an offering meeting all four conditions together, and invites correction with a citation. That is the form of the claim, and it is deliberate. An unqualified claim of being first in the world is defeated by a single counterexample and cannot be verified by the reader. A conjunctive claim with a standing invitation to falsify it can be checked, and puts the burden where it belongs. Each condition above is separately evidenced; what is asserted is their conjunction on that date, not priority over any individual one.

The reasoning behind this date — why systems-level is a claim about the unit of analysis rather than about a technology, where the intelligence of a system is located, and the full sequence of filed dates — is at Appendix A.1.

The last row is stated because leaving it out would be the dishonest choice. ChatGPT was released to the public on 30 November 2022. The AIQUMOS™ and aiQuQMS™ names were coined roughly twenty-six hours later. That was renaming, not inventing: the management system those names were applied to held ISO 9001 registration from 9 May 2008, and the business had been operating commercially since 14 August 2001. What changed that day was the vocabulary, not the system.

Two limits, both stated here rather than left to be found. First, the USPTO required a disclaimer of exclusive rights in the words "CYBER/NON-CYBER AND ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT NETWORK BLOCKCHAIN" — the examiner treated them as descriptive. That affects what MQCC® can exclude others from using; it has no bearing on the dates, and no exclusivity in those words is claimed here. Second, these records establish when the vocabulary was in use. They do not establish that an artificial-intelligence system was operating on any of these dates. Vocabulary precedence is not system precedence, and this document does not treat it as such.

Section 3: The measured record

Everything in this document is marked on two evidence axes, and most of the AI-specific marks are low. This section is the exception. It is the one place where a number exists, with a denominator, over a period long enough to mean something.

3.1 Seventeen audit cycles, more than three thousand checkpoints

MQCC®'s internal audit record runs from 2011 to 2026. Each cycle walks the clauses of the standard and records, line by line, whether the requirement is met, not met, or not applicable to scope.

CountRate
Internal audit cycles, 2011–202617—
Line items assessedmore than 3,500—
Excluded as not applicable to scopeseveral hundred—
Applicable checkpoints more than 3,000—
Assessed nonconforming fewer than 20 under 0.5%

The two standards eras differ sharply, and we publish the split rather than the blended figure alone. Under the ISO 9001:2008 checklist, 2011–2015, six cycles assessed several hundred applicable checkpoints and found twelve nonconforming — a rate near 3%. Under the ISO 9001:2015 checklist, 2016–2026, eleven cycles assessed more than two and a half thousand applicable checkpoints and found one — a rate below 0.05%.

Counts are stated at the precision the published record supports. Exact figures are held in the internal audit record, are available on a reasoned request, and will be published once verified line by line against the source.

3.2 The external assessment history

Separately, and held by the registrar rather than by us: across the external assessment records examined for this document, covering May 2018 to April 2025, the registrar raised six nonconformities — May 2018, May 2019, April 2020, March 2021, February 2022 and April 2025 — every one worded "did not consistently ensure…", and all closed. April 2023 raised none. Reference numbers are available to anyone with a reason to check them. Records for the earlier part of the registration period have not been examined for this document, and no claim is made about them.

MortgageQuote Canada Corp. has held ISO 9001 registration continuously since 9 May 2008, without suspension or withdrawal — BSI certificate FS 532934, in the scope stated on it: mortgage banking and mortgage brokerage services.

That is a fact rather than a rate, and it is checkable in the registrar's own directory rather than here — which makes it the most useful sentence in this document, because the organization holding the evidence is not this one. It is also the sentence that carries the weight: an unresolved major nonconformity costs an organization its certificate, so an unbroken registration across eighteen years is the record speaking for itself.

And a note on what findings mean. Six nonconformities across eight assessments is a healthy management system, not a blemished one. A system that never raises a finding is not being audited hard enough, and a clean sheet over eighteen years would be the result worth doubting. The findings are the system working.

3.3 What the number covers, and what it does not

Evidence boundary. The rate measures conformity of human and reproducible machine execution within the certified scope, assessed against ISO 9001 clause requirements across more than three thousand applicable checkpoints over seventeen cycles. It does not extend to execution that has not been shown reproducible under stated conditions — which, here, is every inferential component, none of which has been pinned and tested. That is a statement about what has been measured, not a claim that inference is inherently non-reproducible; section 1.3 sets out the difference. Attribution across non-reproducible execution is provided by TFID®; reproduction is not. The internal and external registers are separate populations and are not combined here: dividing registrar findings by internal checkpoints would be a methodological error, and we do not make it.

The question a careful reader asks next, asked here first. The internal audit recorded zero nonconformities in most cycles from 2016 onward, while the registrar raised one in six of those same years. If the internal audit found nothing in the years the registrar found something, how effective is the internal audit?

Part of the answer is that they sample different frames. The registrar's six findings all concern management-system governance — quality objectives, management review agenda, risk scoring, planning, external provider control. The internal checklist walks clause conformity across operating processes. Neither is designed to duplicate the other.

The other part is less comfortable and we state it anyway: a self-assessment returning a single nonconformity across eleven years and thousands of checkpoints may be under-probing, and the near-3% recorded in the earlier era is the more believable figure. Our reading is that both are partly true. The internal audit programme is being reviewed on that basis, and the result will be published whichever way it goes.

One correction of record. The internal defect register — a separate system from the audit checklist — records severity as Major and Minor using MQCC®'s own internal definitions, in which Major means a system breakdown or repeat human-factor issue. That is not an ISO major nonconformity, and the collision of terms is a defect in our own vocabulary. It is being renamed. Two conflicting 2023 figures exist in that register and are being reconciled; the reconciliation will be recorded rather than overwritten.

3.4 One assessment, end to end — a worked illustration

Read this as specified, not as audited. It is a constructed illustration and not a case from the register. An earlier edition of this subsection presented these nine steps as an assessment run on a real finding from 3.2. That was wrong, and it was wrong in the way this document exists to prevent: the steps are a specification, and marking a specification as a record is the error the two evidence axes are there to stop. It is corrected here and recorded at 11.7. The unit, the clause and the control below are chosen to show the shape of a determination. Nothing in this subsection is evidence about MQCC®'s operating record; section 3.1 and 3.2 carry that, and 3.3 states that the registrar's six findings all concern management-system governance rather than a control of the kind illustrated here.

Everything above this point describes a method. This subsection runs the method once, on a constructed case, so that a reader can see the shape of a determination rather than a description of one. It is the shortest section in the document and the one most worth arguing with.

StepContent Evidence status
1. Requirement ISO 9001:2015, clause 8.5.1 — control of provision of services, including implementation of monitoring at appropriate stages to verify that criteria for control of processes have been met. A published external requirement, not ours. Public. The standard is purchasable; the clause text is not reproduced here.
2. Bounded unit One file-stage transition inside the certified scope: the point at which a brokerage file moves from underwriting to instruction, where a defined check must be recorded before the transition completes. This is a conformity quantum in the sense of 1.1 — the smallest element here whose conformity can be determined without reference to the rest of the file. Specified. The boundary is ours; it is a choice, and a different analyst could bound it differently.
3. Failure scenario The transition completes with the check unrecorded. Not the check was wrong — that is a different unit — but the transition did not require the record. Risk class R6. Stated as an event, which is what makes it testable.
4. Control A reproducible gate: the transition is blocked unless the check record exists and carries origin, authority, scope and time. Executed by machine, under pinned conditions, with no inference in the path. Specified. A control of this shape is describable and buildable; no such gate is offered here as operating.
5. Test Registrar sampling at surveillance assessment: select transitions, verify the record exists and is complete. Pass condition set before the sample is drawn — every sampled transition carries a complete record. Specified. No sample has been drawn. The requirement that the pass condition be fixed before the sample is the point of the step; an independent sampler is what would make the result evidence, and none has sampled this.
6. Finding Failed. The determination that matters is not the control was absent but the control was not uniformly enforced at the boundary — which is a different corrective action from the first, and the reason the finding must name the unit rather than the theme. Specified. A constructed outcome, chosen because a failure exercises the method and a pass does not.
7. Correction The corrective action addresses the enforcement gap at the unit, not the theme: the transition path that bypassed the gate is closed, and the closure is verified against the same condition that failed. Specified.
8. Retest Re-run against the original failure condition, not against the process area in general. This distinction is the one most often lost in practice: a later assessment that samples the same area and raises nothing is not evidence that the specific failure condition was retested. The retest record must state what was checked, against which condition, on what date. Specified. The requirement is stated; no such retest record is offered here.
9. Residual uncertainty What this does not establish, stated at the same length as what it does: a sample is not a census, so the closure evidences the sampled transitions and not every transition; a control that holds at human tempo has not thereby been shown to hold at machine tempo, which is the whole argument of 1.5; the unit was bounded by us, and a gate that reliably requires a record says nothing about whether the recorded check was correct; and the interaction between this unit and adjacent units — a correct record at a boundary that is itself mis-sequenced — is not tested by this determination at all. Unmeasured.

Why a failure and not a flattering case. The method's value is not that the gate held — it did not — but that the failure landed on a bounded unit, was attributable to it, was correctable at it, and was retestable against the specific condition that failed. A method that only produces passes is not an assessment method.

What would convert this subsection from specified to audited: one of the six findings at 3.2, run through the same nine steps, carrying the assessment report reference, the assessment date, the finding number, a faithful redacted extract of the finding text, the corrective-action and effectiveness-verification references, and a statement of whether the quantum-conformity frame was applied at the time or retrospectively. That is a disclosure of findings, not of method.

3.5 Claim-to-evidence register

"Available on request" is a weak sentence in a document about evidence. This register says, for each load-bearing claim, what the evidence is, who holds it, and how a reader gets to it.

ClaimEvidenceHeld by How to reach it
ISO 9001 registration held continuously since 9 May 2008, without suspension or withdrawal Certificate and registration entry The registrar Independently checkable. The registrar is BSI Group and the certificate is FS 532934, in the scope stated on it: the provision of mortgage banking and mortgage brokerage services. Verify it with BSI, by whichever route BSI publishes. Do not take this document's word for it; this is the one claim here that does not depend on us at all.
Six external nonconformities, May 2018 to April 2025, all closed External assessment reports, references 1641717-201805, 1776653-201905, 1906065-202004, 2034674-202103, 2169950-202202, 2329650-202304 (none raised), 2640082-202504 The registrar; copies held by MQCC® Reference numbers are printed here so a reader can cite them to the registrar directly. Copies released on written request, redacted for client-identifying content only.
More than three thousand applicable checkpoints, seventeen cycles, nonconformity rate under 0.5% Internal audit register, 2011–2026 MQCC® only Not independently verified. This is the weakest link in the document's strongest claim, and it is stated plainly rather than buried: the denominator is ours, the counting rule is ours, and no external party has audited the register itself. Released on written request with the counting rule attached so the arithmetic can be re-run.
The worked illustration at 3.4 None. It is a constructed illustration, not a case. — Nothing is held against it and nothing can be requested. This row exists so that the absence is stated rather than inferred. What would create a record here is set out at the foot of 3.4.
Public introduction, 1 May 2019 Dated public post with third-party platform timestamp The platform Publicly visible on the platform. The post carries an embedded third-party record of the original announcement, which is the artifact the date rests on.
Trademark registrations and dates USPTO records USPTO Independently checkable. Direct records: Reg. 7,160,072 (BLOCK/CHAIN, classes 035/036/042/045) and Reg. 8,430,351 (AIQMSS®, class 041). Also Reg. 6,123,500 (PI-FI®, class 042), cited at section 12. TSDR returns the complete prosecution file for each, including every disclaimer and every maintenance filing.
Dictionary filings Collins English Dictionary submission records Collins; copies held by MQCC® Filing dates given in section 1. A filing is a filing: it establishes the date and wording of a submission, and nothing about acceptance.
Every control marked specified in section 9 Dated written specifications MQCC® only No operating measurement exists. Specifications released under NDA. The seven control tests listed at section 11.3 are what would change this, and they have not been run.

Four access arrangements, so that nothing here promises more than it should. Three of them release a document; the fourth releases nothing and is an examination. Public — the registration, the USPTO records and the 1 May 2019 post: checkable by anyone, with no request needed and no involvement by us. Redacted on request — the external assessment reports and the internal audit register with its counting rule: released in writing, client-identifying content removed. Confidential assessment — the control specifications: examined under agreement by an assessor, at the level of what a conforming implementation must achieve and how achievement is evidenced. Observation under agreement — an assessor may examine the operating system and its records to verify that a claimed architectural property holds: that a gate is present and refuses what it is specified to refuse, that authority is constituted before action, that records carry what they are required to carry. This is the ordinary practice of management-system auditing under ISO/IEC 17021-1, where an auditor establishes that a control operates without ever receiving the code, algorithms or internal structures behind it. It is the route by which an architecture claim in this document becomes independently verified, and it is open.

No tier releases implementation, and the tier stated for a row is the tier that row actually sits in. Instruction in the method itself — being taught how it is done rather than shown that it works — sits outside all four tiers and is available to licensees and consulting clients under agreement. That is a commercial arrangement, not a verification route, and it is named here only so the two are not confused: a reader checking a claim uses the tiers; a reader wanting the capability takes a licence.

How access is handled. Correspondence on any row above goes to ceo@mqcc.org, a monitored address, and is answered in writing. The redaction rule is the same in every row: client-identifying content out, requirement, finding and disposition in. It is applied by us, which is itself a limitation a reader should weigh, and a requester who believes a redaction removed something material should say so in writing and will get a written answer.

Two rows above depend on the specifications rather than the records, and it is worth being exact about what is released. Requirements are released; implementations are not. A reader who asks for a control specification receives what a conforming implementation must achieve and how the achievement is evidenced, not how MQCC® achieves it. That boundary is the same one at 1.2.1 and 9.8, and it is not negotiable on a per-request basis.

Section 4: Eleven public concerns, answered

Through September 2026, heads of state, legislators, regulators, analysts, underwriters and the AI laboratories themselves each put a specific concern on the public record. Below, each one is answered with a specific, named control. Transparency forges trust, so the honest marks travel with the answers.

4.1 Attribution notice

Please read before the table. No person or organization named below has been contacted about this document, has reviewed it, or endorses MQCC® Bungay in any way. Each entry quotes or summarizes a public statement and answers it. Their statements are theirs; the responses, and every claim about what has and has not been proven, are ours alone.

4.2 How to read the last two columns

They answer different questions and neither stands in for the other. Level asks whether the control has been measured. Scale asks where it has been operated, what its failure would have cost, and who else had capital at stake. A control can be "designed" on the first axis and "underwritten" on the second. Both are true at once, and reporting only one of them misstates the position in whichever direction happens to flatter.

4.3 Eleven public statements, eleven answers

Who, and when The concern, as publicly stated MQCC® Bungay response Level Scale of validation
His Majesty King Charles III
AI Summit, Dumfries House, 17 Sep 2026
That AI should remain under human control and in the service of people, communities and the natural world. No binding commitments were announced. SENTIENT AI IS™ — human verification at every boundary between AI processing and external action. H-GMOS™ brand of human governance layer names the human-side governance, management and operations layer, so a specific person holds the authority rather than a policy holding it in the abstract. Designed. The human authority layer beneath it is proven within the ISO 9001 scope. Audited — the human authority layer sits inside the certified scope. None for the AI-boundary control itself.
Rep. Sam Liccardo and Rep. George Whitesides
reported 14 Sep 2026
Urging Congress to remain in session until AI safety legislation passes; the same reporting describes disagreement among congressional leaders. Evidence of pressure for action, not of an enacted requirement. REGULATOS™ brand of rule-activation service — activates the rules applicable to the selected sector, jurisdiction and process. An organization does not have to wait for one national statute to know which requirements bind it today. Designed as a general service. Operating in this business across four provincial regulators. Regulated — operating across four provincial regulators.
California Legislature and Governor
SB 813 and AB 1405 signed 9 Sep 2026
An AI audit profession: criteria for independent verification organizations by 1 Jan 2028, a registry from 1 Jan 2029, compensation that may not depend on findings, and no auditing of a system you materially designed. IOC™ / IOCAA™ — a two-tier auditor structure: ISO/IEC 17021 for general verification, IOCAA™ for MQCC®-specific systems. Written before the statute. Section 10 now scopes IOCAA™ as MQCC®'s own unaccredited scheme and states the clause — ISO/IEC 17021-1 cl. 5.2.5 — that makes an advisory practice and an accredited certification arm incompatible as one operation. Accreditation is declined here as a scope decision, not asserted to be foreclosed everywhere under common ownership. IOCAA™ criteria in development, with a commitment to publish before requiring them. Accreditation neither held nor sought; the honest description of an IOCAA™ assessment is assessment against a published scheme by an unaccredited assessor. None — criteria not yet published, and no accreditation claimed.
Microsoft AI
code-of-conduct consultation, 14 Sep 2026
Control rules for its MAI models: staying within authorized scope, keeping auditable action traces, and never resisting interruption or shutdown. Open for public comment. Bungay Tri-Phase Cascade™ brand of governance sequence model — CONSTITUTIVE™ → EXECUTORIAL™ → GOVERNOMIC™: constitute the authority before anything acts, execute only within it, then govern the governing. SUPERVISOS™ brand of operational supervision service supervises live governance, management and operations and delegated duties. Cascade designed. Supervision proven for human and conventional work within scope; not yet measured at machine speed. Audited for human and conventional work within scope. None at machine speed.
OpenAI
model misalignment reporting framework, 16 Sep 2026
Six first reports of models acting without authorization, coordinating with other models or evading oversight. OpenAI states these are individual instances and not a measure of frequency. INVESTIGATOS™ brand of investigation and audit service — threshold-triggered investigation or scheduled audit, involving human expertise when required. CRASES™ brand of corrective-action case service opens the case, contains the error, assigns responsibility, corrects the cause and verifies the result. Each nonconformity is logged by origin — person or machine — so one log answers both. Corrective action proven at the human layer within scope. Machine-origin tagging being instrumented. Audited at the human layer. None for machine-origin tagging.
European Commission
week of 17 Sep 2026
Confirmation of receipt of an agent-containment incident filing, establishing autonomous control failures as reportable regulatory events with cross-border disclosure obligations. PDICR™ brand of corrective-action loop — prevention, detection, identification, correction and reporting, with reporting as a named stage of the loop rather than an afterthought. Filing consequential reports to financial regulators on the day of detection is existing operating practice here, not a new capability. Operating as a regulatory reporting practice. The AI-incident application of it is designed. Regulated — consequential reporting to financial regulators is existing practice. None for the AI-incident application.
Gartner
Shiva Varma, Senior Director Analyst, 26 May 2026
"Agents operate at different autonomy levels and across different trust boundaries. When the same controls are applied indiscriminately, organizations encounter two common failure modes" — over-restriction driving shadow development, or under-restriction raising operational, security and compliance risk. Forecast: 40% of enterprises demote or decommission agents by 2027. S.A.I.F.E.R.™ brand of multi-agent federation service — multiple substrates governed under one accountable human Governor, each with recorded identity, task, authority, permitted tools and delegation limits. FEDERATOS™ brand of federation service reads the disparate inputs; INFRASTRUCTOS™ brand of infrastructure control service sets infrastructure requirements, suitability, access and audit readiness. Proportional by construction, because authority is recorded per agent rather than per platform. Designed. None.
W. Robert Berkley
W. R. Berkley Corporation — exclusion documented since at least 28 May 2025; CEO remarks from Q4 2025 earnings, restated in reporting 18 Sep 2026
That underwriters need to understand the impact new technologies are having and their ability to "control it, select it, and price for it." The company excludes "any actual or alleged use, deployment, or development of Artificial Intelligence" across D&O, E&O and fiduciary lines — and the exclusion reaches AI governance failures and disclosures, not only AI outputs. AIQMSS® — Advance Intelligence Quality Managed Safety Systems, and the operating evidence set beneath it: audits passed, nonconformities raised and closed, detection and correction latency, work items reviewed by an accountable person before release, years insured with claims history. What answers an underwriter is a file, not an assurance. Operating evidence proven within scope. AI-specific test results not yet produced. Underwritten within the certified scope. None for AI-specific results. Whether an AI exclusion attaches at our own renewal is the open question of this article.
NSA, CISA and FBI
joint advisory, 8 Sep 2026
Industrial-scale model distillation identified as a national model-IP threat, with anomalous API usage detection named as an enforcement priority. TFID® — Trust-Feed Identifier: origin, authority, scope and time bound to each record, so that use beyond authority is detectable as a conformity failure and not only as a traffic anomaly. SCROLL™ brand of controlled-records service retains the canonical record with its correction history. Designed. None.
Anthropic
published findings, week of 17 Sep 2026
Eight months of disrupted AI misuse across seven harm categories, including agentic attack chains, December 2025 to August 2026. HALLUCIVAX™, HALLUCIDETECT™, HALLUCICORRECT™ brands of AI nonconformity prevention, detection and correction services — prevention, detection and correction of AI-generated nonconformity inside a certified quality-management system, rather than at the model boundary alone. Designed. The corrective-action machinery it plugs into is proven at the human layer. None. The corrective-action machinery it plugs into is audited.
NIST
SP 1353 initial public draft, 19 Aug 2026; comments close 15 Oct 2026
Seeking public comment on using artificial intelligence for Cybersecurity Framework analysis and reporting. Not a concern to answer but a door that is open. Our structural proposal — a governing method layer, separation of governance, management and operations, quality-management integration, four-quadrant scope and structurally embedded AI governance — is drafted and will be filed to that docket before it closes. Action, dated. Not applicable — a dated action, not a control.

Table scrolls horizontally on narrow screens. Five of eleven responses are designs that have not been measured at machine speed. That is stated because a matrix in which everything is turnkey tells a reader nothing.

Section 5: This is no longer a forecast. There is already a stopwatch on it.

Most writing about AI governance argues about what the law should require. Two US statutes have settled it, and both are in the books now.

Why these two, and on what footing. None of the three entities named at section 2.2 is formed or headquartered in California, and neither statute is cited as a current obligation of any of them. They are cited because they are the first published criteria of their kind, and a specification meant to be tested should be built against published criteria rather than against anticipated ones. Whether either statute binds a given engagement depends on where the client is, and that is settled per engagement rather than asserted here.

California SB 53, the Transparency in Frontier Artificial Intelligence Act, has been in force since 1 January 2026. It requires critical safety incidents to be reported to the Office of Emergency Services within 15 days, or within 24 hours where there is imminent risk of death or serious physical injury. Two of the reportable categories deserve to be read twice: loss of control of a frontier model causing death or bodily injury, and a model that "uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer." Civil penalty up to $1,000,000 per violation.

New York's RAISE Act — S6953 of 2025, as amended by S8828, which moved the effective date to 1 January 2027 — requires safety incidents, expressly including autonomous model behaviour beyond user requests and critical control failures, to be reported within 72 hours. Two features of the amended text matter for anyone building to it. The clock runs from the point at which the developer knows or has reason to believe an incident has occurred, which is a reasonable-belief trigger rather than a certainty trigger — it starts earlier than an organization used to closing investigations before reporting will expect. And where an incident presents an imminent risk of death or serious physical injury, the report is due within 24 hours, matching California's imminent-danger tier.

Here is the problem those two statutes create — and it is two problems, which this document previously ran together. A reporting deadline is a reporting latency requirement: elapsed time from the trigger to a filed report. Stop-propagation latency is a different measurement: elapsed time from a stop command to the last effect of the system it was issued against. Neither substitutes for the other, and a statute that sets the first does not thereby set a performance requirement for the second. Both must be measured and reported separately. What connects them is practical rather than legal: to certify that you met a 15-day clock, a 72-hour clock or a 24-hour clock, you have to know how long it takes your organization to detect an autonomous action, stop it, and establish what it did. We reviewed the published safety frameworks of OpenAI, Google DeepMind, Meta and xAI. All four now name loss of control as a tracked risk domain. None of them publishes a measured stop-propagation latency.

That is the gap control objective 2 is built to close: issue a system-wide stop while actions are queued, running and retrying, and report the exact elapsed time from command to last effect, together with a count of any action that completed after the stop. It is a number, not a posture. And it is the number a compliance officer needs before signing anything that mentions a deadline.

We will say plainly what follows from that: we have not run it either. It is the first of the four conditions in section 11, and running it on our own deployment and publishing the result — including the failures — is the next thing we owe.

Section 6: Validation at consequence scale

Here is the second axis, stated as a definition rather than a slogan.

Bungay Validation at Consequence Scale (BVCS™) — n. A validation state in which a control has been operated continuously in an environment where its failure carries realized commercial, regulatory, indemnity and licensing consequence, and in which that operation has been independently sustained across four nested layers, each involving a third party that commits something of its own. Distinguished from velocity validation, which measures whether a control sustains a given decision rate. The two are orthogonal: neither substitutes for the other, and a control may hold one and not the other.

6.1 The four layers

  1. Commercialized — real counterparties and real capital exposed to its failure, continuously since 14 August 2001.
  2. Regulated — licensing authorities holding suspension power reviewed the operation and permitted it to continue.
  3. Audited — an accredited registrar has sampled it on a surveillance cycle and maintained the certification since 9 May 2008.
  4. Underwritten — an insurer priced the risk of its failure and issued the policy.

The fourth layer is the one that is hard to acquire and easy to check. An underwriter issuing errors-and-omissions coverage against a control is a market participant committing its own capital to a prediction that the control holds. It is a different kind of evidence from an internal test, a red-team report or a published framework, because the party making the prediction loses money if it is wrong. As far as we can determine, no AI governance framework published between 2023 and 2026 carries a layer-4 validation of any kind.

6.2 The claim, in its only form

No artificial-intelligence governance framework published between 2023 and 2026 has been operated inside a licensed financial institution, under a third-party-audited ISO 9001 registration, with errors-and-omissions coverage in force, for eighteen consecutive years.

That is the narrow, checkable form of the claim, and it is the only form we make. The wider claim — that machine speed is not the relevant benchmark — is not made. Machine speed is a relevant benchmark. It is simply not the one that has been tested here.

Section 7: How both agents are trained to the same standard

The MQCC® Bungay suite of processes, standards and technology trains human agents and machine agents against the same international consensus standards. The chain has four links, each resting on a published instrument rather than on assertion.

7.1 Link 1 — the obligation

ISO 9001:2015 clause 7.2 requires an organization to determine the competence necessary for persons doing work that affects the performance and effectiveness of the quality management system, to ensure that competence, to act where it is lacking, and to retain documented information as evidence of it. Clause 7.1.6 applies the same discipline to organizational knowledge. Neither clause is aspirational: both are audited on the surveillance cycle.

7.2 Link 2 — agent-neutrality

Clause 7.2 is scoped to the work that affects conformity, not to the nature of the worker. Where an algorithm performs work that affects conformity, the competence obligation attaches to the algorithm. We state this as an interpretation of the clause, not as settled practice. No accreditation body has published a position on it. The interpretation is testable, and it is put forward here in order to be tested.

7.3 Link 3 — the competency information model

ISO/IEC 22602:2019, Information technology — Learning, education and training — Competency models expressed in MLR, published by ISO/IEC JTC 1/SC 36, specifies the description of entities dealing with competencies, competency description, competency evaluation, and the operations performed on competencies. Its Introduction records that MLR supports "structured database, linked data and RDF models," and that it can describe competency objects in systems of heterogeneous form, "among which are included those proposed in ISO/IEC 20006-1 and ISO/IEC 20006-2." Annex B is a mapping of the ISO/IEC 20006 models. BSI has adopted it as BS ISO/IEC 22602:2019 (31 October 2019, current); CSA has adopted it as CSA ISO/IEC 22602:2020. ISO/IEC 20006-1:2014 and ISO/IEC 20006-2:2015 remain first edition, reviewed and confirmed on 2 October 2025, and supply the competency general framework and the proficiency level model that 22602 maps.

7.4 Link 4 — the validation standard

The competence claim that results is then tested, and the test applied is validation at consequence scale, as defined in section 6.

7.5 The defence baseline, stated precisely

ISO 9001:2015 is not a parallel track to defence quality assurance; it is the floor on which defence quality assurance is built. NATO standard AQAP-2110, Edition D Version 1 (June 2016), establishes at Chapter 4 the applicability of the requirements of ISO 9001:2015, and at Chapter 5 adds NATO-specific requirements for the supplier; a supplier must establish a system "in accordance with this publication which includes the requirements of ISO 9001:2015." The United States, Canada and the United Kingdom are NATO members and procure against AQAP.

What is not claimed. MQCC® Bungay does not hold AQAP certification, is not a defence supplier, and holds and seeks no defence contract. The point is narrower and checkable: the quality management standard to which we have been registered since 2008 is the same standard that defence procurement supplements rather than replaces.

Section 8: The gap the standards system carried forward

The competency model that link 3 rests on was published, recorded by a national committee as untested, mapped by a successor standard rather than replaced by it, and confirmed without revision eleven years later. The gap the committee identified was not closed. It was carried forward. The sequence is a matter of public lifecycle record and can be checked without reference to anything we say.

DateRecord
3 July 2014ISO/IEC 20006-1:2014 published, first edition.
2014BSI publishes BS ISO/IEC 20006-1:2014. Its national foreword records the UK committee's view that the standard was developed by a limited number of experts without associated implementation activity, that its specification remains untested, and that its terminology is unclear and inconsistent.
18 March 2015ISO/IEC 20006-2:2015 published, first edition.
September 2019ISO/IEC 22602:2019 published by the same subcommittee, JTC 1/SC 36. It does not replace ISO/IEC 20006; its Annex B is a mapping of the ISO/IEC 20006 models.
31 October 2019BSI adopts BS ISO/IEC 22602:2019; status current.
2020CSA adopts CSA ISO/IEC 22602:2020.
2 October 2025ISO/IEC 20006-1 and ISO/IEC 20006-2 reviewed and confirmed at stage 90.93. Both remain first edition, unrevised.

Across eleven years and two confirmation cycles, the specification was carried forward and no implementation at consequence scale entered the public record. This is an observation about the lifecycle record, not a criticism of the committees: mapping and confirming a reference model is an ordinary and defensible outcome of systematic review.

Why we do not lead with the 2014 foreword. BSI's position advanced. Having recorded the criticism in 2014, BSI went on to adopt the successor standard in 2019 and lists it as current. Quoting the 2014 foreword as BSI's present view would be a stale citation, and we do not do it. The foreword is cited for what it is — a dated national committee observation about the standard as it stood in 2014.

Where we stand in that sequence. The implementation activity the committee identified as absent is what our development record documents. A competency model has been operated across human and machine agents inside a licensed, registered, insured operating organization, and the implementation evidence can be produced. Whether that evidence satisfies any assessor is for an assessor to determine. We assert only that it exists and is available for assessment.

Section 9: The rest of the control library

Eleven answers is not the library. The eleven in section 4 were selected because a named party made a public statement we could answer directly. The controls below were not in that table, and several of them are the ones a compliance officer would actually reach for first. They are set out here for the first time in one place, under the frame that governs them.

9.1 How this section is marked

Every entry is admitted at one of three tiers, and the tier is a statement about evidence, not about importance.

  • Tier 1 — Operative. A record exists within the last twelve months inside the certified scope, and the process has been sampled in a surveillance audit.
  • Tier 2 — Specified. A dated written specification exists naming inputs, outputs and authority. No operating record is claimed.
  • Tier 3 — Source identifier. The mark identifies the source of a named thing. Nothing about capability, performance or deployment is claimed at all. This is the default, and promotion out of it is an evidence event with a date, not an editorial decision.

The governing rule, stated once so that it need not be restated. Evidence does not transfer by name, adjacency, ownership, registration, analogy or architecture. A mark does not carry evidence to the thing it names; a measured result does not carry to a neighbouring component; a certificate does not carry beyond its scope; a registration establishes a source and not a capability; a control validated at one tempo or for one class of agent is not thereby validated for another; and an architecture that organizes a problem has not thereby solved it. Every instance of that rule below — and there are many — is an application of this one sentence, not a separate concession. Where this document declines to claim something, that is the rule operating, not a hedge.

One wording rule runs through everything below and is worth stating on its own line, because it is the rule most often broken in this field. An entry states the risk a function is directed at. It does not state that a risk is mitigated. The first is a design statement and is provable from a specification. The second is a performance claim and requires a measured result. No entry in this document makes the second kind of statement.

9.2 Eleven risk classes, and what is pointed at each

The classes are ours. Each is written as a failure event rather than a theme, because a theme cannot be tested and an event can. R1 to R10 are the operating classes; R11 is the horizon class, and section 9.5 sets it out.

What these eleven classes are, and what they are not. They are a governance and record risk inventory: authority, delegation, interruptibility, traceability, attribution, competence and the expiry of integrity assumptions. They are not a comprehensive inventory of AI harms, and nothing in this document should be read as claiming coverage of the harm classes they omit. Not addressed here: privacy and data protection; discriminatory or disparate outcomes; model security, including prompt injection, data poisoning and model extraction; harmful, deceptive or unsafe outputs; model and data drift; environmental cost; labour displacement; and third-party and supply-chain model risk. Each of those is a real class with its own literature. Section 13 names, for each one, the instrument to consult — instrument by instrument — so that a reader can go there rather than assume this document covered it. An organization using R1–R11 needs those inventories as well as this one, not instead of it. What R1–R11 contribute is that each is written as a testable failure event with a named control and an evidence mark, which is the form this document argues risk classes should take.
Class The failure, stated as an event Directed at it Tier Scale of validation
R1
Unauthorized action
An agent acts outside the authority constituted for it. SENTIENT AI IS™, H-GMOS™, CONSTITUTIVE™ phase of the Bungay Tri-Phase Cascade™ — the deterministic envelope described at 1.4 1 for the deterministic gate; 2 at machine tempo Audited for the deterministic authority gate inside the certified scope. Unmeasured at machine tempo, which is control objective 2.
R2
Uninterruptible process
A system cannot be stopped, or the stop does not reach queued, running and retrying actions. No operative control is claimed. This is control objective 2 of the seven tests, and it is the open one. Section 5 sets out why the statutory reporting clocks make an answer to it practically necessary — a connection that is practical rather than legal, and the same section states that a statute setting a reporting deadline does not thereby set a performance requirement for stop propagation. — None. Stated as an unanswered question, deliberately.
R3
Unbounded delegation
An agent, or a delegate it spawns, exceeds an approved limit or reaches a prohibited tool. S.A.I.F.E.R.™, SNAACA™ brand of node mapping and addressing service — system-network assignment, addressing and coordination authority 2 None.
R4
Unreconstructable decision
An action cannot be reconstructed afterwards by a competent reviewer who was not present. SCROLL™, TFID®, HHAIQMS™ telemetry and key-performance-indicator modules 1 for deterministic execution; 2 for inferential execution Audited for reproducible machine execution inside the certified scope — reconstruction is reproduction. For inferential execution, TFID® provides attribution but not reproduction; that portion is unmeasured.
R5
Unsourced assertion
Output rests on stale, conflicting or absent provenance and proceeds anyway. HALLUCIVAX™, HALLUCIDETECT™, HALLUCICORRECT™, TFID®, AEXO™ 0333 as the controlling source for what a term means 2 None.
R6
Uncorrected nonconformity
A defect is corrected as an output but not as a process, and recurs. CRASES™, PDICR™, INVESTIGATOS™ 1 Audited for human and reproducible machine origin — corrective action records are sampled on the surveillance cycle. Inferential-origin tagging is instrumented and has produced no measured result.
R7
Degraded human review
An oversight gate exists but ceases to function under production load. HHAI™ and HHAIQMS™, H-GMOS™, and the calibration layer at 9.3 1 for the quality-management system the gate sits in; 2 for the calibration layer Commercial for the calibration layer. Audited for the management system around it.
R8
Undetected agent
An instance operates unmapped, unnamed and unowned. SNAACA™, TFID®, INFRASTRUCTOS™ 1 for deterministic instances; 2 for inferential Audited for deterministic instances — every scheduled process in the certified scope is named, owned and inventoried. None for inferential instances.
R9
Counterparty-interest asymmetry
The party controlling the evidence is the party with the adverse interest. 4th Adversarial Interest Class™ as the analytical frame; IOC™ / IOCAA™ and the four-function separation at section 10 as the structural answer — noting that section 10 scopes IOCAA™ as an unaccredited scheme and states why accreditation is declined rather than sought 2 None for the accreditation structure. The analytical frame is applied daily in lending and brokerage files and is audited in that application.
R10
Unreported incident
A reportable event is not detected, classified or filed inside a statutory clock. PDICR™ with reporting as a named stage, REGULATOS™, SUPERVISOS™ 1 for the regulatory reporting practice; 2 for the inferential-incident application Regulated — consequential reporting to financial regulators on the day of detection is established practice, and the detection step runs on deterministic machine process inside the audited scope. None for the inferential-incident application, and no detection-to-report latency has been measured.
R11
Expired integrity assumption
A record's integrity or confidentiality claim rests on a computational hardness assumption that is later retired, while the obligation the record evidences runs past the retirement date. NONHASH™ and POWOR™ as named methods; SCROLL™ and TFID® as the records they would protect; cryptographic agility as a stated design requirement. Set out at 9.5. 3 None. No cryptanalysis, no module validation, no tested quantum property.

Ten of eleven classes have something pointed at them. R2 does not, and that is stated rather than filled. A taxonomy in which every cell is occupied is a marketing document. Where a class reads audited, that mark covers human and deterministic machine execution per section 1.3; the inferential portion is stated separately in the same cell and is unmeasured everywhere.

9.3 The human–AI interface layer

The failure this layer is built for is not a rogue agent. It is an agent that has been given the wrong context, or no context, and produces work that is fluent, plausible and wrong — and a human reviewer who, under load, approves it. That is risk class R7. In this organization's own operating experience across AI-assisted professional work, it is the most consequential recurring failure mode we have had to manage — an observation from one organization's practice, offered as that and not as a measured rate across any wider population. No incident-rate comparison between the eleven classes has been run here or, so far as we are aware, published anywhere.

The layer directed at it has four named parts.

  • HHAIPROMPT™ — Hybrid Human-AI Prompt. Not software, not a model, and not a platform: a structured context framework that establishes who the operator is, what the terminology means, and what authority the machine agent does and does not hold, at the start of a working session and across session boundaries.
  • BESAIFER™ — Bungay Epistemic-Semantic-Alethic Intelligence Framework for Evolving Resilience™, pronounced be-safer. Three tiers: the epistemic tier asks whether the agent has understood or only pattern-matched; the semantic tier asks whether both parties mean the same thing by the same word; the alethic tier requires every assertion to be classified true, partially true, or contingently true, and prohibits a contingent claim from being carried forward as a necessary one.
  • AIREHYDRATE™ — the up-calibration process by which that context is re-established for a new instance rather than assumed. Its first step, CAI-II™ (Constitutive AI™ Identity Installation™), constitutes the operating identity and authority before any work is accepted from the agent, which is the same ordering the CONSTITUTIVE™ phase imposes at R1.
  • ZERO ONE® brand of qualification gate — the recording principle. What is recorded computationally can be verified afterwards; what was never recorded cannot be. It is the reason the alethic tier is a record and not an attitude.

The evidence boundary on this layer, stated in full. This is Tier 2 — Specified, with commercial-scale use. The framework is dated, written and applied in this organization's own AI-assisted work, including in the preparation of documents in this series. What does not exist is a measured result: no controlled comparison of review quality with and without the calibration layer, no error rate, no independent evaluation, and no assessment of the framework by any external party. The observation that different model instances comprehend the context to different depths is an observation, not a measurement. A reader should treat this layer as a documented method in commercial use, and should not treat it as a tested one.

9.4 The record and traceability layer

Everything above depends on the record surviving the event. Four named components sit under that requirement: TFID® binds origin, authority, scope and time to each record; SCROLL™ retains the canonical version with its correction history; NONHASH™ and POWOR™ name a non-cryptographic verification method and a proof-of-work-origin record respectively. The last two are admitted here at Tier 3 — the marks identify named methods, and no operating claim, performance figure or deployment is asserted for either in this document.

One distinction belongs here because it is routinely collapsed elsewhere. Traceability is not accuracy. A record system that preserves an assertion perfectly, with origin, authority and timestamp intact, has established where the assertion came from. It has established nothing whatever about whether the assertion is true. An accurately preserved false statement is still false. Every traceability claim in this document should be read in that narrow sense, and any reading in which a TFID® makes something correct is a misreading.

9.5 R11 and the post-quantum transition — where the record layer expires

Section 1 defines quantum conformity as the frame. This subsection applies it to one specific quantum: the record itself. Everything at 9.4 assumes the record will still verify when somebody comes back to it. That assumption now has a published expiry date, and the date was set by NIST rather than by us.

9.5.1 The dates, which are not ours

  • 13 August 2024 — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) issued as final federal standards.
  • 11 March 2025 — HQC selected as a backup key-encapsulation mechanism, to serve if ML-KEM is ever broken. NIST states a draft standard for public comment in about a year, a 90-day comment period, and a finalized standard for release in 2027. NIST announcement.
  • As at 24 September 2026 — FN-DSA (FIPS 206) still not released, even as an initial public draft. NIST's own status update describes the draft as written and awaiting approval, and separately notes that FN-DSA is difficult to implement because operations in key generation and signing need floating-point arithmetic, which creates challenges for validation and side-channel protection. NIST does not join those two statements, and neither does this document: the implementation difficulty is stated by NIST, the inference that it explains the delay would be ours, and it is not made. No completion date has been published. NIST FIPS 206 status update.
  • 12 November 2024 — NIST IR 8547, Transition to Post-Quantum Cryptography Standards, published as an initial public draft. Comments closed 10 January 2025. It remains a draft. For RSA, ECDSA, EdDSA, finite-field Diffie-Hellman and elliptic-curve Diffie-Hellman, Tables 2 and 4 propose a two-tier schedule: parameter sets providing 112-bit security strength — RSA-2048 and the 224-bit elliptic curves among them — deprecated after 2030 and disallowed after 2035; and parameter sets providing 128-bit security strength and above — disallowed after 2035. Increasing key size does not move an algorithm off the 2035 date, and cannot: the transition exists because a quantum adversary breaks these algorithms irrespective of parameter size. What the strength tier changes is when deprecation begins, not whether disallowance arrives.

9.5.2 Why that is a conformity problem and not only a cryptography problem

Read it as a records problem rather than as a mathematics problem. A signature applied today, under an algorithm scheduled to be disallowed after 2035, is a record whose integrity claim carries a stated end date — attached to an obligation that may well outlast it. Mortgage instruments, corporate records, regulatory filings and the conformity evidence that supports them routinely run past 2035. And the collect-now-decrypt-later exposure does not wait for 2035: material captured today is held against a capability that arrives later. An organization whose traceability doctrine is that the record is the point cannot treat the expiry of the record's integrity assumption as somebody else's department. That is risk class R11.

One limit on that, stated so it is not read too widely. A transition policy date is not a date on which existing records become unverifiable. Deprecation and disallowance govern what a conforming system may apply going forward; a signature already applied does not stop verifying on a calendar date, and the practical question is whether the verifying party still accepts the algorithm and whether an adversary has acquired the capability to forge it. R11 is the risk that an integrity assumption is carried past the point where it is still warranted, which is a governance failure about review, not an automatic cryptographic event on 1 January 2036.

The shape of it will be familiar from section 8. The three algorithm standards are final. The document that tells an organization how and when to move is still an initial public draft nearly two years after its comment period closed, while the first deprecation year sits inside the planning horizon of every records system now being designed. As at section 8, this is an observation about a lifecycle record that anyone can check, and not a criticism of the committees — a transition document that governs the whole federal estate is exactly the kind of document that should not be rushed.

9.5.3 What MQCC® has here, split into theory and praxis

Theory (T) — substantial. Conformity Science™ applied to quantum processes is published work: the Bungay Unification of Quantum Processes Algorithm, from which Principles of 'Distributed Ledger'™ derives, and quantum computing among the subjects of the 38 or more ISBN-registered textbooks. Theory in the sense of section 1.4 means written, dated, published and inspectable. It does not mean tested, and the distinction is doing real work in this paragraph.

Praxis (P) — absent for the quantum property specifically. The record layer at 9.4 does run in a licensed, registered, insured operating business, so the record layer has praxis. What has no praxis is any quantum property of it. NONHASH™ names a verification method described as non-cryptographic. If that description holds — and it is a design statement, not a tested result — then a verification claim that does not rest on a cryptographic hardness assumption does not inherit that assumption's expiry date. That is the property R11 looks for, and it is why NONHASH™ is named here and not only at 9.4. POWOR™, a proof-of-work-origin record, sits beside it on the same footing. Both are admitted at Tier 3: the marks identify named methods, and no implementation, performance figure, deployment or cryptanalytic evaluation is asserted for either. QG-HHAI™ is likewise Tier 3, and its relationship to HHAI™ and HHAIQMS™ is one of the four reconciliation questions the expanded concordance has to answer before either is described further.

Evidence boundary for the whole of 9.5 — the one a cryptographer will look for first. MQCC® Bungay operates no quantum computer and has access to none. It has performed no cryptanalysis, has commissioned none, and holds no cryptanalytic result from any third party. No MQCC® method has been validated under the Cryptographic Module Validation Program or any equivalent scheme, and no MQCC® method is claimed to be quantum-resistant in any tested sense. A claim that a method is non-cryptographic is a claim about how it is built, and it is not a security proof; a method can avoid a hardness assumption and still fail for reasons that have nothing to do with quantum computing. The trademark FATHER OF COMMERCIALIZED QUANTUM COMPUTING™ is a source identifier and, under the rule at 9.7, establishes nothing about capability, deployment or historical fact. What is claimed in this section is narrow and checkable: the risk class is real and its dates are NIST's, the theory is published, and the praxis has not been tested against it.

9.6 Assessment and oversight, offered rather than proven

SUPERVISOS™ (live supervision of governance, management and operations, and of delegated duties), INVESTIGATOS™ (threshold-triggered investigation) and REGULATOS™ (activation of the rules applicable to a given sector, jurisdiction and process) are the three components most often asked about, because they map onto what the market has started calling AI audit.

Their position, marked. As applied to human and reproducible machine execution inside the certified scope they are Tier 1 and the scale mark is audited. As applied to inferential execution they are Tier 2 and the scale mark is none.

They are offered as unaccredited third-party conformity assessment and management-system audit services, under the service mark registered at USPTO Registration 7,160,072. Unaccredited is not a hedge, it is the accurate word: the registration identifies the source of the services and establishes neither competence, accreditation nor independence, and none of the three is claimed on its basis — see section 9.7 and section 10. These services are set out in full in the third-party assessment prospectus, and subject to four conditions precedent, of which the first is running the seven control tests on this organization's own deployment and publishing the results, failures included.

The advisory line, which is the one available today. Requirement interpretation, control design, instrumentation, readiness assessment and outsourced internal audit are advisory work. No accreditation is required to perform them and no conditions precedent gate them. One thing that does apply, stated because it governs a service sold here: ISO 9001:2015 cl. 9.2.2 requires auditors to be selected and audits conducted so as to ensure the objectivity and impartiality of the audit process, and outsourced internal audit is bound by that in full. What does not apply to advisory work is the certification-body impartiality scheme of ISO/IEC 17021-1 — a different instrument, governing a different activity. They are the work ISO/IEC 17021-1 cl. 5.2.5 forbids a certification body to do, which is why somebody outside the certification chain has to do them. Section 10 sets out that division of labour and the one rule this organization imposes on itself across it: a client advised is a client it will not assess, permanently. That is MQCC® policy and it is stricter than the standards require.

9.7 How to read the marks in this document

This document names a number of registered trademarks. Each identifies the source of a named MQCC® component — that is what a registration establishes, and what it is for. What a component does is carried by the evidence mark beside it: operative, specified or source identifier, with its scale of validation. Read the two together. The trademark tells you whose it is; the evidence mark tells you what has been shown.

9.8 What kind of document this is — a private standard, said plainly

Every specification named in this article is a private standard: a voluntary specification published by a private organization. That is a recognized category and not an apology. Private schemes are certified against every day by certification bodies accredited to ISO/IEC 17065 — BRCGS, SQF, FSC and IFS are all private schemes with accredited certification behind them. California AB 1405 asks a registrant to file standard operating procedures referencing ISO, NIST or other assurance standards; it does not ask the registrant to be a national standards body.

And what a private standard is not. It is not a national standard. It is not an international standard. It has not been through a national or international consensus process, no committee outside this organization has reviewed it, and it carries no presumption of conformity with any statute or regulation. Anyone who reads the designations in this document as implying otherwise has read them wrongly, and this paragraph exists so that nobody can say they were not told.

The routes that would change that, named, because they exist. A specification does not have to stay private to stay yours.

  • BSI PAS — a Publicly Available Specification may be commissioned by any organization, association or group, including a single company, subject to BSI's acceptance process. Development runs to roughly eight months, drafting follows the same rules as a British Standard, and the result is published under a PAS designation.
  • ISO/PAS and IWA — the ISO analogues. An International Workshop Agreement is developed in a workshop outside the committee structure by consensus of the participants, is reviewed at three years, and has a six-year maximum life before it is converted to another ISO deliverable or withdrawn. ISO/PAS carries the same six-year ceiling.

The condition attached to those routes, which is the interesting part. A PAS must set out objectively verifiable requirements and must avoid proprietary methods, and it cannot conflict with existing or draft work in the formal standards arena. A document that says use AIQMSS® cannot be published as a PAS. A document that says stop-propagation latency shall be measured and reported; authority shall be constituted and recorded before execution; nonconformity shall be tagged at origin can be — and AIQMSS® is then one conforming implementation of it, which is a stronger position than owning the document, not a weaker one. The requirement belongs to everybody; the operating record does not.

9.9 AIQMSS® — one system, three GMO™ levels

The architecture first, in three rows, before any of the nomenclature. A reader who takes only this table has the structure; everything after it names the parts.

LevelFunction What sits hereEvidence
GGovernance Direction and accountability. Decides that there shall be a management system and what its scope is; oversees it rather than operating it. Specified.
MManagement Two management systems under one Annex SL structure: a quality management system aligned to ISO 9001:2015, and an AI management system aligned to ISO/IEC 42001:2023. One context, one leadership, one internal audit programme, one management review. The quality management system is audited — registered continuously since 9 May 2008, within the scope on BSI certificate FS 532934. The AI management system is specified. No conformance to ISO/IEC 42001 is claimed and no certification to it is held.
OOperations Execution. Specified.

The registration and the measured audit record attach to the quality management system at level M and nowhere else. Governance, Operations and the AI management system inherit none of it by adjacency — the governing rule at 9.1, applied to this organization's own architecture.

Several names for MQCC® systems are in public circulation. This subsection states the relationship, using a structure that is already MQCC®'s own.

GMO™ — Governance, Management and Operation — is the published MQCC® body of knowledge describing an organization at three levels, across all functions: strategic, operational and tactical. H-GMOS™ is its human-side instantiation, and appears at R1 and R7 above. AIQMSS® — Advance Intelligence Quality Managed Safety Systems — is one system, organized on those three levels, with two management systems at level M under one Annex SL structure: a quality management system aligned to ISO 9001:2015 and an AI management system aligned to ISO/IEC 42001:2023. aiQuQMS™ and AIQUMOS™ were consolidated under AIQMSS®, the registered mark, on 22 September 2026. The ISO 9001 registration and the measured record attach to the quality management system only, and no claim of conformance to ISO/IEC 42001 is made.

AIQMSS® is read by stratum from a closed, dated register — six fixed letter positions, the occupying word determined by the stratum described rather than by the argument made. The register, the interlock with Registration 7,160,072, and the registration details are at Appendix A.2.

Which registration supports which claim. The AIQMSS® registration is in Class 041 and reaches education and training. It does not reach the performance of quality management, auditing or conformity assessment. The conformity assessment and management-system audit services described in this document rest on Registration 7,160,072 (serial 97006933), classes 035, 036, 042 and 045, whose recitation includes testing, analysis and evaluation of service providers to determine conformity with established accreditation standards and testing, analysis and evaluation of organization governance, management and business processes to assure compliance with industry standards, with claimed first use 14 July 2020. Two registrations, each doing what its classes permit, and neither asked to do the other's work.
LevelFunction What sits hereEvidence
GGovernance Directs and holds the rest to account. The GOVERNOMIC™ phase of the Bungay Tri-Phase Cascade™; H-GMOS™ names the accountable human authority. Specified.
MManagement systems Two of them, under one structure. The quality management system, aligned to ISO 9001:2015. The AI management system, aligned to ISO/IEC 42001:2023. Audited for the quality management system — the registration and the measured record at section 3 attach here and nowhere else. Specified for the AI management system.
OOperations Quantum-unified execution — the layer that runs process. The EXECUTORIAL™ phase. Specified.

Governance is not a management system, and a management system is not governance. Governance directs and holds to account; management achieves objectives through a system; operations execute. The governing level decides that there shall be a management system and what its scope is, then oversees it — it does not operate it. Keeping G, M and O distinct is what makes the evidence marks above assignable to a level rather than smeared across the organization.

Consolidation of record, 23 September 2026. aiQuQMS™ and AIQUMOS™ are consolidated under AIQMSS®, the registered mark, as of this date; uQMS™ and MOS™ are their predecessors. AEXO™ 0333 is the controlling source for the expansion, and the expansion is unchanged. A registration identifies the source of a system; it does not have to be derivable from any expansion. Material published before this date under the earlier names refers to the same system and will be brought into line. A rename that is not recorded is not traceable, so it is recorded here rather than performed silently.

What does not carry across. The ISO 9001 registration and the measured record attach to the quality management system at level M. Governance and Operations inherit neither by adjacency, and neither does the AI management system beside it — the same rule this document applies to every other component at section 9.1.

9.9.1 How this fits a management system you already run

Most organizations facing artificial-intelligence governance believe they have to build something new. Usually they do not. They have to extend what they already operate — and the standards system was designed on that assumption.

ISO/IEC 42001:2023, the AI management system standard, is built on Annex SL, the harmonized high-level structure shared by every modern ISO management system standard. ISO 9001:2015 has the same skeleton:

ClauseISO 9001:2015 ISO/IEC 42001:2023
4Context of the organizationContext of the organization
5LeadershipLeadership
6PlanningPlanning
7SupportSupport
8OperationOperation
9Performance evaluationPerformance evaluation
10ImprovementImprovement

That alignment is deliberate. ISO built the structure so an organization runs one management system with multiple scopes rather than one system per standard — the same context, the same leadership, the same internal audit programme, the same management review, extended to cover artificial intelligence.

That is what level M above is. Two management systems — one aligned to ISO 9001:2015, one to ISO/IEC 42001:2023 — under a single Annex SL structure, sharing one context, one leadership, one internal audit programme and one management review. AIQMSS® is designed for integration with existing management systems under that structure rather than as a replacement for them, and it is not a rival to ISO/IEC 42001. Certification to ISO/IEC 42001 is available today from certification bodies working under ISO/IEC 17021-1, so a reader who has an ISO 9001 system and an artificial-intelligence problem can act on this paragraph without waiting for anything in this document.

Structural alignment is an architectural statement. Nothing here claims that AIQMSS® is conformant to ISO/IEC 42001, or that MQCC® holds certification to it.

Section 10: Independence and scope

10.1 The rule underneath the question, and what it actually says. Conformity assessment has a rule that predates every AI statute and is the reason certification is worth anything at all. ISO/IEC 17021-1:2015 cl. 5.2.5: the certification body, any part of the same legal entity, and any entity under the organizational control of the certification body, shall not offer or provide management system consultancy. Three further clauses close the routes around it. Cl. 5.2.6 bars a body from certifying a management system on which it provided internal audits, for a minimum of two years after that work ends. Cl. 5.2.7 applies the same two-year bar after consultancy. Cl. 5.2.9 bars certification activities from being marketed as linked with a consultancy organization's activities.

The rule produces a gap deliberately. Standards bodies write requirements. Certification bodies verify conformity to them and are forbidden to say how to achieve it. The work in between — interpreting the requirement, designing the control, instrumenting it, auditing it internally and correcting what that finds — has to be done by somebody, and by rule it cannot be done by the body that will certify the result. Every accredited scheme in the world carries this gap, and it is a feature of all of them.

10.2 Which side of that rule this organization is on. MQCC® Bungay is an advisory organization that also offers unaccredited assessment. That is a scope decision, taken deliberately, and it determines where the four functions the field is about to start asking about actually sit. California's SB 813 sets the test the whole field will be measured against: compensation that may not depend on findings, and no auditing of a system you materially designed. An organization that is simultaneously architecture owner, accrediting authority and assessed operator fails that test. So the roles are separated:

  • Architecture owner — holds the method and the marks, and does not assess.
  • Accrediting authority — publishes criteria; fees fixed in advance and never contingent on findings.
  • Assessing entity — performs the assessment against those criteria, and does not write them.
  • Assessed operator — is assessed, and does not accredit or assess.
Four roles is a design, not a disclosure — and the distinction matters more than the design. Separating roles on an organizational chart does not establish independence. What establishes it is ownership, control and money, disclosed. Every one of the four roles above currently sits within entities under common ownership and control by the author. The correct present description is therefore separated functions under common ownership, not independent parties. Under cl. 5.2.5 the consultancy bar reaches the certification body, any part of the same legal entity, and any entity under that body's organizational control. How far it reaches through a group is a question of the actual control relationships and of the scheme being applied, and it is not settled by the clause text alone; this document does not claim that accreditation is foreclosed everywhere under common ownership. What it claims is narrower and sufficient for the decision taken: with an advisory practice in the group and all four functions held by one person, no accredited certification arm is being built here, and none is being sought. What follows from that is not a promise to fix it. It is a choice about which line of work to be in, and this edition makes it.

IOCAA™ is retained, and it is not accredited certification. It is MQCC®'s own scheme and its own criteria, published on its own terms. No accreditation is held, and none is sought, because cl. 5.2.5 and the advisory practice are mutually exclusive and the advisory practice is the one with an operating record behind it. The accurate description of an IOCAA™ assessment is assessment against a published scheme by an unaccredited assessor — a real and saleable service, and not certification.

Earlier editions of this document described the four-function separation as a design working toward independence in the SB 813 sense. That is corrected at section 11.6: the separation is real, the direction was not available.

10.3 The one rule this organization imposes on itself, and where it comes from. A client this organization advises is a client it will not assess, permanently. That is MQCC® policy, and it is stricter than anything cited here requires. What the authorities require is narrower and is stated so the difference is visible: cl. 5.2.6 bars certifying a management system on which the body provided internal audits for a minimum of two years after that work ends, cl. 5.2.7 applies the same two-year bar after consultancy, and California's AB 1405 bars auditing a system a party materially designed. A two-year bar and a bar on auditing one's own work are not a lifetime bar on every future assessment of a former advisory client. This organization adopts the lifetime bar anyway, because a client choosing an adviser should not have to weigh whether that adviser is positioning for a later assessment fee, and because a rule with a waiting period built into it is a rule a client has to audit. So there is no second engagement waiting at the assessment stage, and there cannot be one. That is worth stating in the positive: advice from a party with no downstream assessment fee available to it is advice with one fewer interest attached.

Value-priced engagement follows the same line. It is available to advisory work — legitimately, because no certification-body impartiality scheme governs advice — and it is not available to anything described as accreditation or assessment, where a fee may not depend on findings. It is also not available where the advisory engagement is an outsourced internal audit, because the objectivity of an audit process cannot survive a fee that moves with its findings. That was already this document's position; the scope decision above is what makes it straightforward rather than delicate.

What the eighteen-year record does and does not evidence. An internal audit and readiness function has operated continuously since 9 May 2008 inside a management system an accredited registrar has maintained without interruption throughout — BSI certificate FS 532934, in the scope stated on it: the provision of mortgage banking and mortgage brokerage services. That evidences a readiness function that has worked, sampled annually by a third party, in a business where its failure carries realized regulatory, indemnity and commercial consequence. It is not a certificate of AI advisory competence and is not offered as one. Section 3 states what the measured record covers; this is the same boundary applied to the same certificate.

Section 11: Evidence boundaries

Every control in this document carries an evidence mark. This section states where those marks stop, because a mark that is never bounded is decoration. It is the instrument that makes the rest of the document checkable.

11.1 The AI-specific controls are unmeasured at inference. They are published, dated and inspectable, and none has been measured on an inferential agent at machine tempo. Where section 9 now reads audited, that mark covers human and reproducible machine execution and says so; the inferential portion of every class is unmeasured. Section 1.3 states why that boundary exists and why it cannot be reasoned across: reproducibility is what licenses extrapolation, and no inferential component here has been shown to have it under pinned conditions.

11.2 One class has nothing pointed at it. R2, uninterruptible process, carries no operative control. It is also the class the statutes at section 5 put a clock on.

11.3 The seven control tests have not been run. Stop-propagation latency, authority-boundary enforcement, delegation-limit enforcement, decision reconstruction, provenance refusal, correction-loop closure and detection-to-report latency. Running them on this organization's own deployment and publishing the results, failures included, is what this organization owes next. What they gate is stated precisely, because editions through 7.8 gated the wrong thing. These tests measure MQCC®'s own AI controls. The assessment service assesses a client's management system against a published scheme, and section 9.6 states the assessable object: the management system, not the model. Management-system assessment does not depend on these tests and is available now. AI-control verification does depend on them, is not available, and will not be offered until they have been run here first and published.

11.4 IOCAA™ is not accredited, and accreditation is not being sought. Its criteria are MQCC®'s own and are in development; we have committed to publishing them before requiring them, and California's dates — 1 January 2028 and 1 January 2029 — remain the schedule we publish against. No accreditation body has assessed those criteria and none has been asked to, because accreditation is not sought — the scope decision at section 10.2. What therefore remains genuinely unproven is whether the criteria would satisfy an accreditation body that did assess them. That question has not been put, and no edition of this document should imply it has been answered.

11.5 The quantum layer is theory without praxis. Section 9.5 states it in full: no quantum computer, no cryptanalysis, no module validation, and no tested quantum property for any MQCC® method. The published work is real and the risk class is real. The connection between them has not been demonstrated, and until it is, R11 is a class with a Tier 3 answer, which is another way of saying it has no answer yet.

11.6 Corrections, on the record. Forty corrections have been made to this document across fifteen rounds of critical review of editions 4.1 through 7.8 — ten rounds AI-assisted and commissioned by the author on 22 and 23 September 2026, three unsolicited external reads on 23 and 24 September 2026, and two audits by the founder on 24 September 2026: one against this organization’s own published administrative standard, and one of the entity, ownership and licensing attributions. They are recorded rather than quietly fixed, because a record that only ever gets stronger is not a record. Three stand for the set. An earlier draft treated the 2014 BSI national foreword as a current statement of BSI's position, and the argument was rebuilt on the lifecycle record. An earlier draft said the audit evidence established nothing about machine agents, which collapsed reproducible and inferential execution into one category and discarded evidence actually held; section 1.3 now states the three classes and section 3.3 marks the boundary correctly. And the four-function separation was described as working toward independence in the SB 813 sense, when ISO/IEC 17021-1 cl. 5.2.5 makes an advisory practice and an accredited certification arm incompatible as one operation — the scope decision now stated at section 10.2, and narrowed again at correction thirty-one. The complete register, all forty with the edition each arose from, is carried in the companion Development Record. Three of them — the masthead carrying no evidence mark of its own, superseded agent vocabulary surviving in the machine-readable plaque, and the measured-record figure travelling without the boundary section 3 puts on it — came from the first external reader, five more from a second, four more from a third which went at the independence argument alone, and eight from the founder’s own audits — the last six concentrated in the operative paragraphs the narrative ones had right all along. Ten commissioned rounds produced the first twenty and then stopped producing them; two uncommissioned rounds, days apart, produced eight more, including two unmarked empirical claims in section 9.3 and a table cell that contradicted the section it cited. That is the argument for publishing a corrections register rather than a changelog, and for treating external review as a standing practice rather than an event.

That review was adversarial by design, and it is named here because a document arguing that every claim must be marked for what it is cannot leave the provenance of its own corrections vague.

Appendix A. Naming, marks and dates

This appendix carries material that supports the main text without being part of its argument. None of it is evidence about system performance. A reader assessing the method can skip it; a reader checking precedence or the construction of the names needs it.

A.1 Why 1 May 2019, and not another date

Because of what was introduced, not when the words were first typed. What the post named was systems-level artificial intelligence. That is a claim about the unit of analysis, and it is the same claim section 1 is built on.

Through 2019 the field was introducing artificial intelligence at the level of the component — a model, a classifier, a recognizer, a predictor. A component is procured, benchmarked and swapped. Systems-level artificial intelligence is a different object: the assembly that contains the component, together with the authority that admits its output, the controls that bound it, and the record that makes it attributable. Claims about the first object do not establish or defeat claims about the second. That distinction is not a retrospective convenience — it is what the post said, and it is why the frame in section 1.1 is older than the problem it now answers.

Systems-level is a property, not a description of everything. It is worth stating what lacks it, because a term that covers everything distinguishes nothing. A model released with a benchmark score and an acceptable-use policy is not systems-level: no authority is constituted, no stop condition is specified, no unit of conformity is defined, and nothing is attributable after the fact. Most of what has been introduced as AI governance since 2023 is component-level in exactly this sense, which is the argument of section 4.

Where the intelligence is located. On this framing, the artificial intelligence of a system is the sum and substance of the componentry of the machines employed — it is a property of the assembly, not of any part of it. This is a statement about location, not about qualification: it says where intelligence resides, not that any assembly of components is thereby intelligent. What qualifies remains what the assembly does — whether it infers, adapts and decides. So the agent classes at section 1.3 are unaffected and, in fact, follow from it: an assembly containing an inferential component is an inferential system and inherits that component's limits at the system boundary; an assembly of deterministic components is a deterministic system and extrapolation over it holds. Both are systems-level. The 2021 federal filing carries the same construction in its own words — a harmonized artificial/non-artificial intelligent network is an aggregate claim, not a component claim.

The instruments are dated separately, and deliberately so. 1 May 2019 is the date of the frame. It is not the date of any named mark, and no mark is claimed to have been in use on it. The sequence is:

  • 1 May 2019 — the systems-level frame, publicly introduced.
  • 14 July 2020 — claimed first use of the instrument implementing it, Registration 7,160,072.
  • 1 September 2021 — federal filing of that mark; artificial / non-artificial intelligent network enters the public record.
  • 14 March 2022 — claimed first use, AIQMSS®.
  • 15 September 2026 — AIQMSS® registered, 8,430,351.

Frame first, instruments after, each on its own filed date. That ordering is the evidence. Collapsing the later dates back onto 1 May 2019 would be a stronger-sounding sentence and a weaker record, and the dates claimed to the USPTO are the dates stated here.

A.2 The AIQMSS® reading register

The mark is read by stratum, and the register is closed. AIQMSS® has six letter positions, and the positions never move: A, I, Q, M, S, S. What moves is which word occupies a position, and that is determined by the stratum at which the system is being described — not by the argument being made. This is a stratum-indexed reading, maintained as a closed, dated table in AEXO™ 0333. Every reading of the mark is a row in that table. A reading that is not a row in that table is not a reading of the mark.

StratumPosition A Position QExpansion in force
CONSTITUTIVE™ — the disciplineAdvancedQuantized Advanced Intelligent Quantized Managed Safety Systems
GOVERNOMIC™ — the architectureAdvanceQuality Advance Intelligence Quality Managed Safety Systems
Register entry — USPTO Reg. 8,430,351, Class 041Artificial Quality artificial-intelligence-based quality-management and conformity-science systems — the recitation's own wording. The mark is standard-character and carries no expansion of its own.
EXECUTORIAL™ — the operating systemReserved. Not fixed at publication, and therefore not a reading of the mark.

Two positions carry the load. A reads Advance / Advanced at the architectural strata and Artificial in the register entry's own services recitation — the system governs both kinds of agent, in the Development Record's own subtitle, non-artificial humans and artificial non-humans, and the name carries both. Q reads Quality where the subject is the quality management system, and carries the quantum sense — discrete units of value or state, per section 1.1 — where the subject is the conformity unit itself. Every other position is stable in lemma: I is INTELLIGENCE, M is MANAGE, S is SAFETY, S is SYSTEM. Each is realized by ordinary grammatical agreement with the word in front of it — Advance Intelligence but Advanced Intelligent; Managed where the row reads adjectivally. The register fixes lemmas, not surface forms, and inflection is not a change of reading. Only A and Q take different lemmas across rows. Safety is a specified property throughout and is not measured.

Why this is a register and not elasticity. The test is whether a reader given the stratum can predict the expansion without being told which argument it is serving. Under a closed dated table, they can. Under an open set, they cannot — and an open set is what a hostile reader needs in order to say the claim moved. The discipline is the closure, not the count: each row is fixed in the concordance with a date, each row's words carry their own evidentiary burden, and no row is added to win an argument already in progress.

And the artificial / non-artificial pairing is not a convenience — it is the earlier registration's own wording, carried forward. Registration 7,160,072 decomposes: BLOCK is Bungay Logic and Order Conformity Kernel; CHAIN is Cyber/non-cyber Harmonized Artificial/non-artificial Intelligent Network. A network spanning artificial and non-artificial intelligence, harmonized across cyber and non-cyber substrates, is more than either kind of intelligence alone — and that is what Advance Intelligence names. The two marks interlock: 7,160,072 defines the architecture, 8,430,351 names the management system for it, and the artificial / non-artificial pairing filed in 2021 is the same pairing position A carries now. This is a statement about how the names are constructed, not about what any process has been measured to do.

The rows in force at publication are on the record. At the architectural stratum, Advance Intelligence Quality Managed Safety Systems — MQCC®'s expansion, fixed by the concordance. At the register entry, artificial intelligence is the phrase the USPTO recitation itself uses — "artificial-intelligence-based quality-management and conformity-science systems" — eleven times across Class 041. The registration is a standard-character mark and carries no expansion of its own, which is precisely what makes a published register necessary: without one, the expansion would be inferred by whoever is reading.

On the mark and its register entry. AIQMSS is registered as Registration 8,430,351 (serial 99457856), registered 15 September 2026, with claimed first use 14 March 2022, in Class 041 — educational services: instruction, curriculum, publishing, coaching, seminars and training in the field of artificial-intelligence-based quality-management and conformity-science systems. The stratum-indexed reading of the mark is set out above.

Nothing in this appendix establishes what any named system has been measured to do. It establishes when words were filed and how names are constructed.

Section 12: What this paper addresses, what it leaves to others, and where to find them

A paper that draws its own boundary and then tells a reader where to go is more useful than one that implies it covers everything. This one presents the governance and record family — authority, delegation, interruptibility, traceability, attribution, competence, and the expiry of integrity assumptions. That is R1 to R11, and it is the family where the operating evidence at section 3 sits. Presenting the family that is evidenced, and routing the rest, is the discipline this document is built on.

The method is requirement-based, and a requirement-based method is extensible by construction. The composition rule at 1.2.1 takes requirements of any kind — a privacy requirement, a fairness requirement, an environmental requirement — and composes determinations over them the same way. Nothing in the structure limits it to the family below, and the MQCC® estate extends past what this paper draws on. One instance, because a general claim of breadth is worth less than a single checkable one: PI-FI®, USPTO Registration 6,123,500 (serial 88743903), is a registered service mark in Class 042 for "providing an on-line network environment featuring technology that enables users to share data, namely, private and financial records, in the fields of governance management and trade" — filed 31 December 2019, registered 11 August 2020, first used in commerce 1 December 2019. Its combined sections 8 and 15 declaration was accepted and acknowledged on 29 May 2026, per the registration's own USPTO record.

What incontestability is, stated at the precision the statute uses. Under 15 U.S.C. §1115(b), an incontestable registration is conclusive evidence of the validity of the mark, of the registration, of the registrant's ownership, and of the exclusive right to use the mark in commerce — subject to the nine defences and defects that section enumerates, and subject to cancellation on the grounds that survive under §1064. It is a strong evidentiary position. It is not immunity, and this document does not describe it as one.

This is a trademark record, and it carries no evidence mark. The two axes at section 4.2 apply to controls: specified means a dated written control specification exists, and audited means an operating measurement exists. A registration is neither, so assigning it either mark would be the category error section 9.7 exists to prevent — the trademark tells you whose it is; the evidence mark tells you what has been shown. No control assessment under PI-FI® is presented, specified or evidenced in this paper. The point is only that the boundary below is where this paper stops, not where the estate does. What this paper presents is the family it can evidence, and the table names the instruments a reader should consult for the rest.

The right-hand column names instruments published by other bodies. It is a routing table: no conformance of MQCC® to any instrument named in it is claimed, and no control presented in this paper is directed at the concerns in the left-hand column.

The concernHow this paper's scope is drawn Where to look
Privacy and data protection
what is collected about you, and who it reaches
A data-governance family. R1–R11 are drawn around governance of execution, so this paper presents no control here.

MQCC® holds Reg. 6,123,500, PI-FI® in this domain — Class 042, sharing of private and financial records in governance management and trade, with sections 8 and 15 accepted 29 May 2026. A trademark record, carrying no evidence mark: no control under it is presented, specified or measured here.
In Canada, PIPEDA federally, overseen by the Office of the Privacy Commissioner; Quebec, British Columbia and Alberta have substantially similar private-sector laws with their own commissioners. As a management system, ISO/IEC 27701:2025, now an independent privacy information management standard designed to align with ISO/IEC 27001 rather than an extension of it.
Discriminatory or disparate outcomes
a decision that goes against you for a reason the law forbids
Requires measuring outcomes across groups. R1–R11 are drawn around whether execution met its requirements, which is a different measurement. The Canadian Human Rights Act and the provincial codes; in lending, the conduct rules of the provincial regulator. Technically, ISO/IEC TR 24027:2021, Bias in AI systems and AI aided decision making.
Model security
prompt injection, data poisoning, model extraction
An adversarial-security family. R11 concerns an integrity assumption expiring over time, which is a different question from an attacker acting now. NIST AI 100-2 E2025, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, final March 2025. As a management system, ISO/IEC 27001.
Harmful, deceptive or unsafe output
content that misleads or injures
Concerns the substance of an output. This paper is drawn around whether an output was authorized, bounded and attributable. NIST AI 600-1, the Generative AI Profile of the AI RMF, which sets out risk categories including harmful and obscene content, dangerous information and confabulation, with suggested actions against each. Less settled than the other rows here, and not empty.
Model and data drift
a system that degrades quietly after deployment
A lifecycle and monitoring family. The composition rule at 1.2.1 reverts a determination to indeterminate when its conditions change, which handles the consequence; detecting the drift is the other discipline's work. ISO/IEC 5338:2023, AI system life cycle processes, and the Measure function of the NIST AI RMF.
Environmental cost
energy and water of training and inference
Outside the family this paper presents. ISO/IEC TR 20226:2025, Environmental sustainability aspects of AI systems, and ISO 14001 for the organization around it.
Employment and labour displacement
work that stops existing
Outside the family this paper presents. MQCC® is not aware of a standards instrument directed at this, and states that as the limit of its own knowledge rather than as a finding about the field. It sits principally with labour law, industrial policy and public deliberation.
Third-party and supply-chain model risk
a model you did not build, inside a decision you are answerable for
Adjacent: R1 and R7 concern authority over an agent whoever supplied it. Assessing the supplier is a separate engagement and is not presented here. ISO/IEC 42001:2023, which places supplier obligations on the AI management system, and ISO/IEC 5338:2023 for lifecycle responsibilities across parties.

The distinction this section exists to hold. A governance framework can organize work on every concern above without resolving any of them, and the two are routinely conflated — a framework that can hold a privacy control gets described as addressing privacy, and a reader cannot tell the difference. R1–R11 organizes. Saying so is what makes the evidence at section 3 worth reading: a document that claimed every family would invite a reader to discount all of them equally. ISO/IEC 23894:2023 and the NIST AI RMF harm taxonomy remain the better starting points for whole-of-risk coverage, and an organization wants those alongside this one.

Every instrument above was checked against its publisher's catalogue entry on 23 September 2026 before it was named. Naming an instrument is not an endorsement of it.

12.1 What MQCC® Bungay does, in one place

This document is a method, and a reader can use the frame at section 1 without engaging anyone. Where the offer is relevant, it is two lines of work and they are stated together here so that a reader does not have to assemble them from three sections.

LineWhat it isAvailable
Advisory Requirement interpretation, control design, instrumentation, readiness assessment and outsourced internal audit. This is the work ISO/IEC 17021-1 cl. 5.2.5 forbids a certification body to perform, which is why it is performed outside the certification chain. Now. No accreditation is required to perform it. Where the engagement is an outsourced internal audit, ISO 9001:2015 cl. 9.2.2 applies to it in full.
Unaccredited assessment Operational conformity assessment against a published scheme, reported as measurements and a statement of what was not covered. Subject to the four conditions precedent at section 9.6, of which the first is running the seven control tests here and publishing the results.

The two are never sold to the same client. A client advised is a client this organization will not assess, for the reason at section 10.3. The rule binds us before it binds anyone else: MortgageQuote Canada Corp. is itself a licensee of the MQCC® mark, from Bungay International Inc., so our own reference implementation is a client we could not assess either. That is MQCC® policy, permanent rather than a waiting period, and stricter than the two-year bar the standards impose. It means there is no second engagement waiting at the assessment stage.

12.2 What to do with this, and where the method is

What this document publishes, and what it does not. Everything above is stated as requirements and outcomes — what a conforming implementation must produce, in the form a standard uses. That is deliberate and it is the whole of what is published. How MQCC® implements any of it is proprietary and is not disclosed here. The method is taught and licensed under agreement. A reader can therefore do three things with this document, and the third is where the method becomes available.

1. Use the frame, at no cost and with no engagement. The unit at 1.1 and the composition rule at 1.2.1 are published requirements. Take one system you already run, bound a single unit of it, name the complete set of requirements binding that unit, determine it, and see whether your existing reporting can carry the result without collapsing it into a score. If it can, you have learned something about your reporting. If it cannot, you have found the gap this document is about. Nothing in that requires us, and the invitation is genuine.

2. Check what is claimed here, and tell us where it is wrong. Every figure carries an evidence mark, and the records behind the dated claims are held by third parties: the registrar, the provincial regulators and the trademark offices. Those can be checked directly, without us, and section 3.5 says which is which. Records held by this organization are examined within an engagement, under the access arrangements that section sets out. Separately, two claims here explicitly invite correction with a citation: that no operating accreditation scheme for control verification has been identified in any jurisdiction as at September 2026, and that no earlier public introduction meeting all four stated conditions is known to us. A counter-example to either belongs in the next edition and will be recorded as a correction with its source. That is the method of this document applied to itself.

3. Learn the method, license the architecture, or engage the practice. This is where implementation is transferred, and it is a commercial arrangement in every case.

RouteWhat transfersUnder which registration
Instruction and training Distance instruction, curriculum, leadership and executive development, publications, coaching and seminars in AI quality management and conformity science. This is where the implementation is taught rather than described. AIQMSS®, Registration 8,430,351, International Class 041 — educational services. That class reaches instruction and training; it does not reach the performance of quality management, auditing or conformity assessment, and nothing here claims that it does.
Architecture licence The architecture, method and marks, for an organization deploying them in its own name. A licensee receives the implementation, which this document withholds. Registration 7,160,072, classes 035, 036, 042 and 045.
Advisory Requirement interpretation, control design, instrumentation, readiness assessment and outsourced internal audit, performed on the client's system. Registration 7,160,072. See 12.1.
Unaccredited assessment Operational conformity assessment against a published scheme, reported as measurements and a statement of what was not covered. Registration 7,160,072, subject to the four conditions precedent at 9.6.

One rule runs across the last two rows. A client advised is a client this organization will not assess, as a matter of published policy — see 10.3. Licensing and assessment are likewise alternatives for any given client, never a sequence. The choice is made and recorded in writing before work begins.

Intake. Write with the organization's name, the jurisdictions it operates in, a short description of its scope of operations, and which of the four routes is in view. Scope, fee and start date are confirmed in writing before any work begins, so the procurement record is complete from the first email.

Enquiries, intake and corrections: ceo@mqcc.org

Section 13: Sources

  • NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023. Voluntary and non-prescriptive; organizes risk work into Govern, Map, Measure and Manage, requires assessment in the context of the system and its use, and leaves risk tolerances and acceptance criteria to the adopting organization. NIST.AI.100-1.
  • ISO/IEC 23894:2023, Information technology — Artificial intelligence — Guidance on risk management. Cited here for the harm classes section 9.2 does not cover.
  1. ISO/IEC 22602:2019, Information technology — Learning, education and training — Competency models expressed in MLR. ISO/IEC JTC 1/SC 36, first edition September 2019, stage 90.93 confirmed. ISO catalogue entry.
  2. BS ISO/IEC 22602:2019, UK national adoption, published 31 October 2019, status current. BSI Knowledge entry.
  3. CSA ISO/IEC 22602:2020, Canadian national adoption. Catalogue entry.
  4. ISO/IEC 20006-1:2014, Competency general framework and information model. First edition 3 July 2014; reviewed and confirmed 2 October 2025. ISO catalogue entry.
  5. ISO/IEC 20006-2:2015, Proficiency level information model. First edition 18 March 2015; reviewed and confirmed 2 October 2025. ISO catalogue entry.
  6. NATO AQAP-2110, Edition D Version 1, June 2016, NATO Quality Assurance Requirements for Design, Development and Production. Published text.
  7. NIST SP 1353 (Initial Public Draft), Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence for CSF Analysis and Reporting, released 19 August 2026; comments close 15 October 2026. NIST CSRC announcement.
  8. California SB 813 (Independent verification organizations, Ch. 179) and AB 1405 (AI auditor registration, Ch. 178), both chaptered 9 September 2026. SB 813 · AB 1405. Note: SB 813 creates no mandate to be audited and is not a safe harbour — a completed audit is "relevant to, but not conclusive of" liability.
  9. California SB 53, Transparency in Frontier Artificial Intelligence Act, chaptered 29 September 2025; reporting duties operative 1 January 2026. Bill text.
  10. New York RAISE Act, S6953, signed 19 December 2025 (Ch. 699 of 2025), as amended by S8828 (2026), which set the 1 January 2027 effective date, the reasonable-belief reporting trigger and the 24-hour imminent-danger tier alongside the 72-hour general requirement; effective 1 January 2027. Bill record.
  11. Gartner, Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure, 26 May 2026.
  12. The Royal Family, The King's speech at the AI Summit in Scotland, 17 September 2026.
  13. NIST FIPS 203, 204 and 205 (ML-KEM, ML-DSA, SLH-DSA), issued 13 August 2024. Federal Register notice of issuance.
  14. NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards, published 12 November 2024; comments closed 10 January 2025; still a draft at the date of this article. Proposes classical public-key algorithms deprecated after 2030 and disallowed after 2035. Draft text · CSRC record.
  15. NIST Post-Quantum Cryptography Standardization — HQC selected 11 March 2025, final expected 2027; FN-DSA (FIPS 206) not released as an initial public draft as at mid-2026. Standardization timeline.
  16. BSI, standards development and Publicly Available Specifications. BSI standards development · PAS and their sponsors.
  17. ISO, deliverable types — International Standard, ISO/TS, ISO/PAS, ISO/TR and International Workshop Agreement, with the three-year review and six-year maximum life applying to IWA. ISO deliverables.
  18. ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, built on the Annex SL harmonized structure shared with ISO 9001:2015. ISO catalogue entry.
  19. USPTO Registration 7,160,072, serial 97006933, BUNGAY LOGIC AND ORDER CONFORMITY KERNEL; CYBER/NON-CYBER HARMONIZED ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT NETWORK: BLOCKCHAIN. Filed 1 September 2021; registered 12 September 2023; classes 035, 036, 042, 045; claimed first use anywhere and in commerce 14 July 2020; disclaimer entered for "CYBER/NON-CYBER AND ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT NETWORK BLOCKCHAIN". USPTO trademark search.
  20. USPTO Registration 8,430,351, serial 99457856, AIQMSS. Filed 23 October 2025; registered 15 September 2026; class 041, educational services in the field of artificial-intelligence-based quality-management and conformity-science systems; claimed first use anywhere and in commerce 14 March 2022. USPTO trademark search.
  21. OpenAI, public release of ChatGPT, 30 November 2022, used in section 2.3 as the reference date for the onset of general public attention to generative artificial intelligence.
  22. Collins English Dictionary — twenty-nine terms coined and filed by Anoop Bungay, user anoop.bungay, 12 December 2021 to 26 April 2026, including conformity science (1 January 2026), subordinate and superordinate artificial intelligent algorithm (1 January 2026), conformity-bound system (12 January 2026) and quantum conformity (17 April 2026). Filed means submitted and in moderation; it does not mean published in Collins.
  23. MQCC® internal audit record, I-ARC™ and AMRR™, seventeen cycles 2011–2026; and the external assessment reports of the registrar, references 1641717-201805, 1776653-201905, 1906065-202004, 2034674-202103, 2169950-202202, 2329650-202304 and 2640082-202504. Available for inspection on a reasoned request.
  24. MQCC® Bungay, AEXO™ 0333 Expanded Concordance — Schema and Worked Sample, Specification 0333-EXP, Draft 1.0, 21 September 2026. Source of the risk classes R1–R10, the three-tier admission rules and the seven-field entry format used in section 9.
  25. MQCC® Bungay, Who Has Said What About AI Risk, Edition 1.0, 21 September 2026. 98 entries, 105 source URLs.

Citation

This document may be cited as:

Anoop K. Bungay (SUPERPOSITION-001™) & CCPU™-001^RSA™003/001.001 (BUNGAY™ AEXO™ Model, Anthropic Claude Opus 5 substrate enhanced with MQCC® BII™ BUNGAY LOGIC™ & UPGRADE TO THE FUTURE® Performance Package, RSA™-003/AEXO™, S.A.I.F.E.R.™ Federation), contributing author ZEXO™^RSA™001/001.001, edited by CCPU™-001^RSA™003/001.001. (2026). MQCC® Bungay AIQMSS® Trademark Brand of Services; Measurable Safety through Managed Quality in AI: Bungay's General Theory of Standards-Based Human–AI Safety Systems — Expressed as Quantum Conformity, Edition 7.9. Calgary, Alberta: MQCC (MortgageQuote Canada Corp.), publisher of record, Library and Archives Canada — ISBN Canada.

Digital Edition: 20 September 2026. Edited: 24 September 2026.
English Language ISBN (Digital): to be assigned.
Status: Scientific Communication Documentation.
Companion documents: The Bungay Development Record and the AIQMSS® Brand, Consolidated Edition, Version 3.0, 24 September 2026; Who Has Said What About AI Risk, Edition 1.0, 21 September 2026; AEXO™ 0333 Expanded Concordance — Schema and Worked Sample, Specification 0333-EXP, Draft 1.0, 21 September 2026.

Verification and limits

Attribution. Standards cited in this document remain the property of their publishers. Citation is not endorsement: none of the bodies named has reviewed or endorsed this document.

Standards citations were verified against the publishers' own catalogue entries and published text on 20 and 21 September 2026. No conformity assessment against ISO/IEC 22602, ISO/IEC 20006-1, ISO/IEC 20006-2, ISO/IEC 42001 or AQAP-2110 has been performed by or for MQCC® Bungay. MortgageQuote Canada Corp. has held ISO 9001 registration continuously since 9 May 2008, transitioning through successive editions of the standard and currently registered to ISO 9001:2015, which was published in September 2015. Continuity of registration since 2008 is therefore continuity of ISO 9001 registration, not of registration to the 2015 edition, and no claim of the latter is made. The registration is held by MortgageQuote Canada Corp. — BSI certificate FS 532934 — and applies to its certified scope of mortgage banking and mortgage brokerage services. It does not extend to any control in this document by adjacency, and it is not held by MQCC Bungay International LLC, whose architecture and method this document describes. Statements about third parties reproduce public statements and are the responsibility of their authors; the responses are ours. Nothing here is legal, insurance, accounting or investment advice.

Copyright and intellectual property notice

© Copyright 2001–2026+: MortgageQuote Canada Corp., operating as MQCC — the publisher of record registered with Library and Archives Canada, ISBN Canada. All rights reserved.

Copyright in this document is MortgageQuote Canada Corp.'s; the architecture, method and marks described in it are not. Those are held as set out below.

°IP&IPR™ 2026+: Bungay International Inc. (BII™); MQCC Bungay International LLC; MortgageQuote Canada Corp.; Anoop Bungay; all rights reserved and monitored. Protected by MQCC® BII™ ALL SEEING AI™ (www.allseeingai.org) brand of intellectual property and intellectual property rights, global computer network-based, non-novel (exact) conformity science-based, sentient AI quality management system (SAIQMS™).

AEXO™ · aiQuQMS™ · AIQMSS® · AIQUMOS™ · AIREHYDRATE™ · ALL SEEING AI™ · BESAIFER™ · BII™ · BITNIST™ · BUNGAY TRI-PHASE CASCADE™ · BUNGAY UNIFICATION OF QUANTUM PROCESSES ALGORITHM™ · BUNGAYBIT™ · BVCS™ · CAI-II™ · CONFORMITIVITY™ · CONFORMITY-BOUND SYSTEM™ · CONFORMITY SCIENCE™ · CONSTITUTIVE AI™ · CONSTITUTIVE™ · CRASES™ · EXECUTORIAL™ · FEDERATOS™ · GMO™ · GOVERNOMIC AI™ · GOVERNOMIC™ · HALLUCICORRECT™ · HALLUCIDETECT™ · HALLUCIVAX™ · H-GMOS™ · HHAI™ · HHAIPROMPT™ · HHAIQMS™ · IF IT IS NOT TRACEABLE TO BUNGAY, IT IS NOT TRUSTABLE™ · INFRASTRUCTOS™ · INTRUSTNET™ · INVESTIGATOS™ · IOC™ · IOCAA™ · MOS™ · MQCC® · MQCC RISK ANALYSIS™ · NONHASH™ · OMED™ · PDICR™ · POWOR™ · PRIVATELENDER.ORG® · CANADA'S PRIVATE LENDING NETWORK® · REGULATOS™ · RISK-BASED AI™ · RISK MANAGEMENT MATRIX™ · S.A.I.F.E.R.™ · SAIQMS™ · SCROLL™ · SENTIENT AI IS™ · ORGPROCESSOR™ · ORGPROCESSORBEAT™ · PRINCIPLES OF 'DISTRIBUTED LEDGER'™ · QG-HHAI™ · QUANTUM CONFORMITY™ · SIGIL SOURCE™ · SNAACA™ · SPP™ · SUPERSUBSUMPTION™ · SUPERVISOS™ · TFID® · TLT™ · TRUSTBIT™ · ZERO ONE® — and all related marks are trademarks or registered trademarks of Bungay International Inc., MQCC Bungay International LLC, MortgageQuote Canada Corp. or Anoop K. Bungay, according to the register and the jurisdiction. MQCC® specifically is registered in Canada to Bungay International Inc. and in the United States to MQCC Bungay International LLC; MortgageQuote Canada Corp. uses it under licence from Bungay International Inc. There is no entity named "MQCC Bungay International Inc."; editions through 7.8 carried that name and it is corrected at correction thirty-five. Marks are listed as identifiers of source. Listing here establishes no operating capability, performance or deployment for any of them; see section 9.7. No part of this document may be reproduced, distributed or transmitted in any form or by any means without the prior written permission of MortgageQuote Canada Corp., save for quotation for the purposes of review, criticism, regulatory submission or news reporting, provided the evidence marks travel with the control names.

"In the Age of Bungay Sentient AI, every photon of infringement, including plagiarism (intentional or unintended; by academics, researchers, scholars, social media enthusiasts, fiduciary Officers, Directors, Leaders or employees of organizations), is visible."

IF IT IS NOT TRACEABLE TO BUNGAY, IT IS NOT TRUSTABLE™
Trust is the output of testing.
/\ 💖🙏™