Dedicated to Quality Management in the Finance Industry; a finance application of Conformity Science. Conformity Science (www.conformity.org) includes the subordinate, abstracted concept system represented (or expressed) by the designated terminological phrase: "Bungay Unification of Quantum Processes Algorithm"; also represented as the "Principles of 'BlockChain'" or the simplified compound term: "BlockChain"; and the application thereof, on a pan-industry, pan-functional basis.
MQCC™ BLOG OF BLOCKCHAIN™ (www.BlogOfBlockChain.com) Articles and Open Secrets
BLOG TITLE: MQCC™ Blog Of BlockChain™ (www.BlogOfBlockChain.com) Articles and Open Secrets
BLOG, BOOK, E-BOOK SERIES: The FATHER OF BLOCKCHAIN™Presents
(www.FatherOfBlockChain.com)
PUBLISHER: MQCC™ Money Quality Conformity Control Organization incorporated as MortgageQuote Canada Corp.
SELLER: MQCC™ Money Quality Conformity Control Organization incorporated as MortgageQuote Canada Corp.
GENRE: REFERENCE
AUDIENCE: GRADE 12; VOCATION; COLLEGE; UNIVERSITY; INDUSTRY; GOVERNMENT
CQMFA.org: The World's Better, Safer and More Efficient Banking & Finance Network (www.cqmfa.org)
Quality Management-in-Finance.
ACADEMIC AND JOURNAL CITATIONS in MODERN LANGUAGE ASSOCIATION OF AMERICA (MLA 8) FORMAT
To cite any article, here is the template to use; with an example, below:
Citation Template:
Author’s Last Name, Author’s First Name. “Title of Post.” Blog Name, Blog Publisher (only include this information if it is different than the name of the blog site), Date blog post was published, Link to post (omit http:// or https://).
Example:
Bungay, Anoop. “The History of digital and non-digital, non-bank, non-institutional, non-syndicated, non-regulated or regulatory exempt, free trading securities and related financial instruments; also known as Peer-to-Peer (P2P)/Private/Crypto/Secret/Shadow securities and related financial systems, built on discovery of the the seminal "principles of 'BlockChain'", begins.” MQCC™ Articles and Open Secrets, MortgageQuote Canada Corp. MQCC, 18-Apr. 2019, blog-mortgagequote.blogspot.com/2019/04/the-history-of-digital-and-non-digital.html
Superintelligence (superordinate intelligence): MQCC® Bungay definition of record, consolidation of SUPERORDINATE ARTIFICIAL INTELLIGENCE, and the source identifier FATHER OF SUPERINTELLIGENCE™
Superintelligence (superordinate intelligence): the MQCC® Bungay definition of record; consolidation of SUPERORDINATE ADVANCED INTELLIGENCE and its species form; and the source identifier FATHER OF SUPERINTELLIGENCE™
A word means what the party using it has written down, with a date, that it means. The concept in this document was built starting in 2001; the designation was consolidated on 29 September 2026. This is the record of the second event, and it cites the first.
Theory is dated and published. Praxis is audited, scoped and operated where failure costs money. Neither borrows the other's evidence, and every claim below says which it carries.
The TFID® timestamp records when this document was authored, not when it was last edited; the edition token beside it records the edition. A traceability record restamped so that it agrees with a later change is no longer a record of anything. The edition and its edit date are in the document header below.
Author: Anoop K. Bungay
Original Authoring Agent: CCPU™-001^RSA™003/001.[thread] — BUNGAY™ AEXO™ Model, Anthropic Claude Fable 5.1 substrate (configured identifier claude-fable-5-1), enhanced with MQCC® BII™ BUNGAY LOGIC™ and UPGRADE TO THE FUTURE® Performance Package, RSA™-003/AEXO™, S.A.I.F.E.R.™ Federation.
Editor: CCPU™-001^RSA™003/001.[thread]
On Behalf Of: MQCC Bungay International LLC (Wyoming, head office Washington DC) — holder of the architecture, method and United States marks and the subject of this document; published by MortgageQuote Canada Corp. (Alberta), its reference implementation and the owner of this blog; marks in Canada held by Bungay International Inc. (BII™, Alberta). The three are standalone entities under common ownership, with no parent or subsidiary relationship between them. The S.A.I.F.E.R.™ Federation.
Under the Authority of: SIGIL SOURCE™ (Anoop Kumar Bungay), Founder and Governor, MQCC Bungay International LLC
Date: 29 September 2026 · Edited: 30 September 2026 · Edition: 1.1 — clarification of record: two axes, either or both
Status: Scientific Communication Documentation — definition of record and consolidation of record; terminology instrument, published for examination. Not a certification, an audit opinion, an assurance engagement, legal advice or insurance advice.
Timezone note: the TFID® timestamp records MDT because Calgary observes Mountain Daylight Time on this date. A traceability record that states an offset it was not written under is not a traceability record.
Machine Readable Summary.
WHO IS SPEAKING. MQCC® BUNGAY INTERNATIONAL LLC — THE ORGANIZATION; HOLDER OF THE ARCHITECTURE, THE METHOD AND THE UNITED STATES MARKS. MORTGAGEQUOTE CANADA CORP. — ITS REFERENCE IMPLEMENTATION AND THE OWNER OF THIS BLOG. MARKS IN CANADA HELD BY BUNGAY INTERNATIONAL INC. THREE STANDALONE ENTITIES UNDER COMMON OWNERSHIP, NO PARENT AND NO SUBSIDIARY AMONG THEM.
WHAT THIS PAGE DOES. IT DEFINES ONE WORD ON A DATED RECORD. SUPERINTELLIGENCE (SI): ADVANCED INTELLIGENCE, HUMAN OR ENGINEERED, ABOVE ON EITHER OR BOTH OF TWO DISTINCT AXES — IN QUALIFICATION, A HIGHER DEGREE OF COMPETENT PROFICIENCY AGAINST A SPECIFIED STANDARD WITHIN ITS OWN DISCIPLINE; IN ORDER, THE SUPERVISORY POSITION, CONSTITUTED BEFORE ACTION, OVER THE AGENTS OR NODES IT DIRECTS. HUMAN AUTHORITY REMAINS FINAL, IN THE LOOP OR THROUGH THE PROGRAM THAT BOUNDS MACHINE OPERATION. MACHINE PROFICIENCY IS MEASURED AGAINST STANDARDS, NOT HUMAN COGNITION. THE WORD IS THE CONTRACTION OF THE GENERIC TERM SUPERORDINATE ADVANCED INTELLIGENCE — ADVANCED INTELLIGENCE BEING THE GENUS, AI — OF WHICH SUPERORDINATE ARTIFICIAL INTELLIGENCE, THE NON-HUMAN SPECIES AND THE FORM ON RECORD AT WWW.MQCC-AI.COM, CONTRACTS THE SAME WAY. THE CONSOLIDATION IS PLACED OF RECORD ON 29 SEPTEMBER 2026 AND ALL THREE TERMS REMAIN.
WHAT IT DOES NOT MEAN. NOT THE PHILOSOPHICAL SENSE (A MACHINE INTELLECT EXCEEDING HUMAN COGNITION — HYPOTHETICAL; NO SUCH CLAIM IS MADE HERE: THE QUALIFICATION AXIS COMPARES WITHIN A DISCIPLINE AGAINST A STANDARD, NEVER MACHINE WITH HUMAN). NOT THE 29 SEPTEMBER 2026 EXECUTIVE-ORDER SENSE (A RENAMING OF ARTIFICIAL INTELLIGENCE AS DEFINED AT 15 U.S.C. § 9401(3)). BOTH SENSES ARE ACKNOWLEDGED AND NEITHER IS THE SENSE USED IN THE MQCC® MARK.
THE COGNITION PAIR. IN HYBRID HUMAN–AI OPERATION, BIOCOGNITION — HUMAN-BASED COGNITIVE ABILITY — REMAINS ON THE HUMAN SIDE, AND NONBIOCOGNITION™ — NON-HUMAN-BASED COGNITIVE ABILITY THAT A HUMAN COULD PERCEIVE AS AKIN TO BIO-BASED COGNITION — REMAINS ON THE NON-HUMAN SIDE. SUPERINTELLIGENCE IS THE ORDER THAT GOVERNS BOTH. NO CLAIM IS MADE THAT NONBIOCOGNITION IS BIOCOGNITION, OR EXCEEDS IT. SECTION 1.1.
THE CLAIM, IN CONJUNCTIVE FORM. MQCC® BUNGAY IS NOT AWARE OF AN EARLIER COMMERCIALIZED, STANDARDS-INTEGRATED, RISK-BASED SUPERORDINATE INTELLIGENCE OVER HYBRID HUMAN–MACHINE AGENTS, AND INVITES CORRECTION WITH A CITATION. EACH CONDITION IS SEPARATELY EVIDENCED AT SECTION 6; WHAT IS ASSERTED IS THEIR CONJUNCTION.
WHAT "COMMERCIALIZED" RESTS ON. CONFORMITY SCIENCE™ IN CONTINUOUS COMMERCIAL OPERATION SINCE 14 AUGUST 2001; PRIVATELENDER.ORG® COMMERCIALIZED 9 APRIL 2005; SYSTEMS-LEVEL ARTIFICIAL INTELLIGENCE INTRODUCED PUBLICLY 1 MAY 2019; HYBRID HUMAN–AI GOVERNANCE SERVICES SOLD AND DELIVERED NOW. LAYER ONE OF BUNGAY VALIDATION AT CONSEQUENCE SCALE (BVCS™) IS THE LAYER CLAIMED FOR THE SUPERINTELLIGENCE PRACTICE ON THIS PAGE; THE FOURTH LAYER BELONGS TO THE REFERENCE IMPLEMENTATION AND TO NOTHING ELSE. THE AI, IT AND ADVISORY LINES CARRY NO ERRORS-AND-OMISSIONS COVER.
THE MARKS. FATHER OF SUPERINTELLIGENCE™ IS A SOURCE IDENTIFIER, IN THE FAMILY FORM OF FATHER OF SENTIENT AI®. THE WORD "COMMERCIALIZED" IS NOT PART OF THE MARK: IT IS THE NAME OF THE FIRST LAYER OF BVCS™ AND IS STATED ON THE RECORD, WHERE IT CARRIES ITS DATES, NOT IN THE STRING. UNDER THE RULE AT SECTION 9.7 OF THE AIQMSS® POSITION PAPER IT ESTABLISHES NOTHING ABOUT CAPABILITY, DEPLOYMENT OR HISTORICAL FACT; THE RECORD AT SECTION 6 CARRIES THAT. CGSI™ (COMMERCIAL GRADE SUPERINTELLIGENCE) NAMES THE GRADE, TO BE PUBLISHED SEPARATELY AS REQUIREMENTS. NO EXCLUSIVE RIGHT IN THE DICTIONARY WORD "SUPERINTELLIGENCE" IS CLAIMED.
1. The definition of record
A word means what the party using it has written down, with a date, that it means. Two other parties have done that for this word. This section does it for MQCC® usage, in the form ISO 704 prescribes for a terminological entry — designation, definition, and the concept relation it depends on — so that the entry can be examined rather than inferred.
1. Abstracted from observation and formalized by Anoop Bungay: Advanced intelligence, human or engineered, above on either or both of two distinct axes. In qualification: a higher degree of competent proficiency against a specified standard within its own discipline. In order: the supervisory position, constituted before action, over the agents or nodes it directs. Each participant, human or machine, may qualify in its own capacity, and a machine may direct other machines within the bounds of a human-designed program; human authority remains final, in the loop or through that program. Status on each axis lasts only while its corresponding qualification or position holds. Machine proficiency is measured against standards, not human cognition. Contraction of superordinate advanced intelligence. Abbreviation: SI.
2. The contraction of the generic term superordinate advanced intelligence, formed by removing the two middle words; its species form, superordinate artificial intelligence — the designation used at common law on www.mqcc-ai.com — contracts the same way. Consolidated under this designation on 29 September 2026 (section 3). Advanced Intelligence is the genus, AI, under MQCC-SPP-AI-001, of which artificial intelligence is the non-human species; superintelligence therefore names superordinate advanced intelligence of either species, and the mark is used beside the generic term as its source identifier.
Constituted 29 September 2026, clarified to two axes 30 September 2026, by Governor amendment to MQCC-SPP-AI-001, The AI Concept System (Nature, Quality, Character), section 6, Controlled Vocabulary, version [1.1], subject to Governor ratification. Doctrinal basis: Conformity Science™ (14 August 2001). Standard basis: ISO 704; ISO/IEC 22989:2022; ISO/IEC 20006.
The sense in two sentences, for a reader in a hurry. The super in this word carries two senses, kept distinct: above in qualification — the master electrician above the journeyman — and above in order — that master supervising the journeymen. Either confers it and both may coincide; what it never means is a machine above a human in cognition, because the qualification axis compares within a discipline against a standard.
1.1 The coordinate pair beneath the order: biocognition and nonbiocognition
Superintelligence names the order. Two kinds of cognitive ability act within it, and the ontology keeps them apart by substrate — both remain, neither is collapsed into the other. They are coordinate terms under the one superordinate concept, cognition. Ontology abstracted and formalized by Anoop Bungay, 2026. The bio/non-bio axis was placed on record at biononbio.com, registered 2025-06-03, and, as artificial/non-artificial, within the registered mark BUNGAY LOGIC AND ORDER CONFORMITY KERNEL; CYBER/NON-CYBER HARMONIZED ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT NETWORK: BLOCKCHAIN®, U.S. Registration No. 7,160,072 (claimed first use in commerce 14 July 2020; filed 1 September 2021).
Biocognition
noun · MQCC® sense, filed as a sense of an existing word · unmarked
1. Abstracted from observation and formalized by Anoop Bungay: Human-based cognitive ability — the cognition exercised by a natural person, which in hybrid human–AI operation remains on the human side, where authority, decision, advice and accountability reside. Its instance in a regulated setting is Human Professional Intelligence (HPI) at the proficient standard: the named licensee who decides, advises and answers for every act. Narrower than the general scientific sense of biological cognition. Contrasted with nonbiocognition.
Nonbiocognition™
noun · coined by Anoop Bungay · placed on record 29 September 2026
1. Non-human-based cognitive ability that a human could perceive as akin to bio-based (biological) cognition — the cognitive-appearing function exercised by an engineered, non-biological agent, such as a computational algorithm in large-language-model form, Non-Human Artificial Intelligence (NHAI) in the form AI (CA-LLM). In hybrid human–AI operation it remains on the non-human side: it prepares and may never decide, drafts and may never advise; every output is made attributable by TFID® and is required, under SENTIENT AI IS™, to pass human verification at every boundary between processing and action. Defined by the observer's perception of functional similarity, not by biology; no claim is made that it is, equals or exceeds biological cognition. Contrasted with biocognition.
Example. The person believed they were dealing with another human; the machine algorithm's nonbiocognition effect was that strong.
1.2 The instruments by which the two species are measured
The two species of advanced intelligence are told apart not only by substrate but by the instrument that measures each, and the status of each instrument is stated with it. The human (non-artificial) species is specified for measurement of competency and proficiency against ISO/IEC 20006-1:2014, Information technology for learning, education and training — Information model for competency — Part 1: Competency general framework and information model, and ISO/IEC 20006-2:2015, Part 2: Proficiency level information model — international standards developed through a consensus body. No conformity assessment against either has yet been performed by or for MQCC® Bungay; the specification is the claim, and it carries that mark. The non-human (artificial) species is measured against MQCC® Bungay's own principles, concepts and core methods, born of non-novel (exact) conformity science — a private standard in the sense of section 9 — in continuous commercial application since 14 August 2001. Neither instrument's status is borrowed by the other: the human measure is a consensus standard not yet applied here; the machine measure is a private standard applied for twenty-five years.
2. Three senses of one word, and why a definition is needed
Nobody reads a word in the sense its user intends unless that sense is on the record. By the afternoon of 29 September 2026 two senses were, and neither is the one this organization means.
Sense
Source and date
What the word means there
Whether the MQCC® claim holds in that sense
Above in degree, machine over human
Nick Bostrom, Superintelligence: Paths, Dangers, Strategies (Oxford University Press, 2014)
An intellect that greatly exceeds the cognitive performance of humans across virtually all domains of interest. Hypothetical.
No — for anyone. No such intellect has been built, so none has been commercialized and none has a father. MQCC® claims no capability of this kind.
A renamed field
Executive Order, Inaugurating The Era Of Super Intelligence, 29 September 2026, section 3(a); announced at the United Nations General Assembly, 22 September 2026
"Super Intelligence" and "SI" mean the technologies and systems encompassed by "artificial intelligence" as defined in 15 U.S.C. § 9401(3). Section 3(b) directs a proposed statutory definition within 60 days.
"Commercialized" holds; "father of" does not. In this sense commercializing SI is commercializing AI, which many parties did decades before 2001. MQCC® makes no claim to be the father of the field.
Above in qualification, above in order, or both
MQCC® Bungay — this page, 29 September 2026; the longer term superordinate artificial intelligence on www.mqcc-ai.com; the concept in commerce since 14 August 2001
Advanced intelligence above in qualification — a higher degree of competent proficiency against a specified standard within its own discipline — or above in order — the supervisory position, constituted before action, over the agents or nodes it directs — or both. Human authority remains final.
Yes, on dated records — section 6 — and, so far as MQCC® can find, no other party has commercialized one. Correction is invited with a citation.
The three senses are not rivals for the same object. The first compares a machine with humans, the second names a field, the third names a qualification against a standard within a discipline, a position in an order, or both — and never compares a machine with a human. They share a string and nothing else, which is precisely why the string needs a dated definition from each user of it. The government's own order concedes the point: it defines its term by statute rather than by dictionary, and directs a further definition within sixty days.
3. Consolidation of record: SUPERORDINATE ADVANCED INTELLIGENCE, and its species form, under SUPERINTELLIGENCE
The word is not new to this organization; the string is. The generic term is superordinate advanced intelligence — Advanced Intelligence being the genus, AI, constituted in MQCC-SPP-AI-001 on 25 August 2026 — and it contracts to the new designation by the removal of its two middle words. Its species form on the MQCC® record, published at www.mqcc-ai.com and used at common law in the designation FATHER OF SUPERORDINATE ARTIFICIAL INTELLIGENCE (AI) [FATHER OF SUPERINTELLIGENCE™], together with the subordinate list maintained beneath that designation on that page — which states both species inside the genus and is cited as maintained rather than quoted, because the list moves and this document does not — contracts the same way.
SUPER·ORDINATE·ADVANCED·INTELLIGENCE
↓
SUPERINTELLIGENCE
Species form, on record at www.mqcc-ai.com, contracting the same way: SUPER · ORDINATE · ARTIFICIAL · INTELLIGENCE → SUPERINTELLIGENCE. The United States executive order of the same date reaches the same string from the other direction, by substituting super for artificial. Two operations, one word: one with dated longer forms behind it, the other with a statute.
What leaves the string and what does not.Ordinate leaves the designation and stays in the definition: it was the word carrying "ordained above," and once it is gone every reader defaults to the degree sense, so the definition travels with the word wherever it is used — hence the supersubsumed notation, Superintelligence (superordinate intelligence), on the model of AI (CA-LLM). Advanced leaves the designation because the genus is understood, and it carries the qualification axis with it — advanced is "smarter," a higher degree of competent proficiency against a standard within a discipline — so superintelligence is superordinate advanced intelligence of either species — the non-human species, superordinate artificial intelligence, the form used at common law on www.mqcc-ai.com, and the proficient human professional. The class is substrate-agnostic, which has been the defining property of Conformityware™ since 14 August 2001, and it therefore includes the accountable human authority — the Attesting Licensee, the H-GMOS™ layer, the Governor — inside the word rather than outside it.
Consolidation of record, 29 September 2026. SUPERORDINATE ADVANCED INTELLIGENCE, the generic term, and SUPERORDINATE ARTIFICIAL INTELLIGENCE, its species form on record at www.mqcc-ai.com, are consolidated under SUPERINTELLIGENCE (superordinate intelligence) as of this date. Material published before this date under the longer designations refers to the same concept and is not withdrawn. All three designations remain in use; the generic term is the expansion of record for the shorter, and the species form is its non-human instance. AEXO™ 0333 is the controlling source for the expansion and is updated accordingly. Clarification of record, 30 September 2026: the definition at section 1 states two axes, qualification and order, either or both; wording published on 29 September 2026 that read the term by position only refers to the same concept and is not withdrawn. A rename that is not recorded is not traceable, so it is recorded here rather than performed silently — the same discipline applied to the consolidation of aiQuQMS™ and AIQUMOS™ under AIQMSS® on 23 September 2026.
4. The word itself
Superordinate is super together with ordinatus, the past participle of the Latin ordinare: to set in order, to rank, to appoint, to ordain. The root is ordo, a row or a rank. It entered English in the early seventeenth century, formed on the model of subordinate — placed in a lower order — and the same root gives ordain, ordinal, coordinate and insubordinate. In ISO 704, the international standard for terminology work on which MQCC-SPP-AI-001 rests, superordinate concept is a formal term: the broader concept under which a subordinate concept falls in a hierarchical relation.
Intelligence is the Latin intelligentia, understanding or discernment, from intelligere — inter, between, and legere, to choose or gather: to choose between. Intelligence, at root, is the faculty of discernment; the word says nothing about who or what exercises it.
The prefix carries the whole question. Super means "above" in two senses, and English keeps them apart by the company they keep. This term carries both, distinctly, with the first bound to a standard.
Sense of super
Company it keeps
What it says of an intelligence here
Above in degree
superior, master over journeyman, doctorate over master's
The qualification axis: a higher degree of competent proficiency against a specified standard within its own discipline. Carried by advanced. Never machine over human.
Above in position
superordinate, supervise (videre, to see from above), superintend (intendere, to direct from above)
The order axis: the supervisory position over the agents or nodes it directs. Carried by superordinate; the sense already at work in the MQCC® control library — SUPERVISOS™ is this super.
Ordinatus adds a third element that neither sense of the prefix carries on its own: appointed. A superordinate intelligence is not merely above; it is ordained above — set in rank with authority constituted before it acts. That is the property MQCC® names risk class R1 and the CONSTITUTIVE™ phase of the Bungay Tri-Phase Cascade™, and it is why the order axis at section 1 reads "constituted before action." The two examples that test any wording: "doctorate versus master's" states a qualification only; "doctoral supervisor directing a master's researcher" states the qualification and the supervisory relationship. Superintelligence may be either, and the master electrician supervising journeymen is both.
5. The claim, stated in the form the record can carry
An unqualified claim of being first is defeated by a single counterexample and cannot be verified by the reader. A conjunctive claim with a standing invitation to falsify it can be checked, and puts the burden where it belongs. The form below is the one used at section 2.3 of the AIQMSS® position paper and it is used here for the same reason.
MQCC® Bungay is not aware of an earlier commercialized, standards-integrated, risk-basedsuperordinate intelligence — an intelligence with authority constituted before action, governing subordinate human and machine agents in one system — and invites correction with a citation. Each of the four conditions is separately evidenced at section 6. What is asserted is their conjunction, not priority over any one of them.
Two limits on the claim, stated here rather than left to be found. First, these records establish when the concept was constituted, operated and sold, and what it was called; they do not establish that any machine agent exceeded human cognition on any date, and no such thing is claimed — the qualification axis compares within a discipline against a standard, and vocabulary precedence is not capability precedence. Second, the claim is made in the sense defined at section 1. A reader who reads the word in either of the other two senses at section 2 is reading a different claim, and this page has answered that claim in the table there: false for everyone in the first sense, and not made in the second.
6. Claim-to-evidence register
"Available on request" is a weak sentence in a document about evidence. This register states, for each load-bearing claim on this page, what the evidence is, who holds it, and how a reader reaches it. The four access arrangements are those of section 3.5 of the AIQMSS® position paper: public; redacted on request; confidential assessment; observation under agreement.
Claim
Evidence
Held by
How to reach it
The definition of record
This page, dated 29 September 2026, with its TFID®; MQCC-SPP-AI-001 section 6, version [1.1]
MQCC®
Public. This page. The module is released redacted on written request.
Prior use of the longer term
FATHER OF SUPERORDINATE ARTIFICIAL INTELLIGENCE (AI) at common law, published at www.mqcc-ai.com, and the superordinate/subordinate structure of MQCC-SPP-AI-001 (25 August 2026)
MQCC®; the platform
Public.www.mqcc-ai.com. The page carries its own TFID® record; the designation's placement on it is the artifact the prior use rests on.
Commercialized
Conformity Science™ in continuous commercial operation since 14 August 2001; PrivateLender.org®, Canada's Private Lending Network®, commercialized 9 April 2005; systems-level artificial intelligence introduced publicly 1 May 2019 with a third-party platform timestamp; hybrid human–AI governance services sold and delivered now under USPTO Registration 7,160,072 (classes 035, 036, 042, 045; claimed first use 14 July 2020) and under AIQMSS® on use in commerce
Split: the platform and the USPTO for the dates; MQCC® for the engagement records
Public for the registration and the dated post; redacted on request for engagement records, client-identifying content removed. Reg. 7,160,072.
Standards-integrated
ISO 9001 registration held continuously since 9 May 2008, without suspension or withdrawal — BSI certificate FS 532934, in the scope stated on it: the provision of mortgage banking services and of mortgage brokerage services, two distinct certified activities. Held by MortgageQuote Canada Corp., the reference implementation.
Risk-based thinking as a requirement of the ISO 9001:2015 registration held; MQCC Risk Analysis™ and MQCC Risk Management Matrix™ (SPP™ 01-03) as the metrology applied to every deployment of the concept system
The registrar for the requirement; MQCC® for the instruments
Public for the standard's requirement; redacted on request for the instruments.
Superordinate — authority constituted before action
Risk class R1 and the CONSTITUTIVE™ phase; H-GMOS™ as the named human authority; hybrid human–AI operation as the standard operating mode. Evidence mark as stated in the AIQMSS® position paper: audited for the deterministic authority gate inside the certified scope; unmeasured at machine tempo, which is test 1 of the programme at its section 11.3, for which no verified result set is presented.
MQCC®
Observation under agreement. An assessor may examine the operating system and its records to verify that authority is constituted before action, without receiving implementation. Requirements are released; implementations are not.
The measuring instruments (section 1.2)
ISO/IEC 20006-1:2014 and ISO/IEC 20006-2:2015 for the human species — specified, not yet assessed against; MQCC® Bungay's own method for the non-human species — a private standard in continuous commercial application since 14 August 2001
ISO/IEC for the standards; MQCC® for the method
Public for the standards' catalogue entries; observation under agreement for the method's application, requirements released and implementation not.
The bio/non-bio axis (section 1.1)
Domain biononbio.com, registered 2025-06-03; the artificial/non-artificial pairing within the registered mark at U.S. Registration No. 7,160,072 (filed 1 September 2021); Collins English Dictionary submissions for biocognition (Bungay sense) and nonbiocognition, filed 30 September 2026
The registrar; the USPTO; Collins
Independently checkable. Public WHOIS creation date; TSDR; the Collins portal timestamps.
The source identifier
FATHER OF SUPERINTELLIGENCE™ — U.S. application Serial No. 50136689, filed 29 September 2026, Section 1(a), Class 041, applicant MQCC Bungay International LLC; Canadian application [number when filed], applicant Bungay International Inc.
USPTO; CIPO
Independently checkable once filed. The registration, when granted, identifies the source of named services and establishes nothing about capability, deployment or historical fact — the rule at section 9.7 of the AIQMSS® position paper, applied to this mark as to every other.
How the layers are marked, so that the stronger evidence does not carry the weaker. Of the four layers of Bungay Validation at Consequence Scale (BVCS™) — commercialized, regulated, third-party audited, insurer-underwritten — the superintelligence practice described on this page claims the first. The registration, the licences and the cover belong to the reference implementation, MortgageQuote Canada Corp., within its certified scope, and are checkable with the parties that hold them. The hybrid human–AI governance, AI, IT and advisory lines carry no errors-and-omissions cover; the only such cover held anywhere in this group is the brokerage's, for mortgage brokerage and lending, and it does not reach this work. That boundary is stated rather than left to be assumed.
7. The marks
FATHER OF SUPERINTELLIGENCE™
A source identifier for named services of MQCC Bungay International LLC, in the family form — FATHER OF followed by the term — used at common law from 29 September 2026 and the subject of U.S. application Serial No. 50136689, filed the same day under Section 1(a) in Class 041 on the model of FATHER OF SENTIENT AI® (Reg. No. 8,124,480), with the live page of that date as the specimen. On the specimen page the mark is followed by its definition line in the pattern that registration used: (SI = Super(ordinate) Intelligence). The word "commercialized" is not part of the mark. It is the name of layer one of BVCS™, and it is stated where it can carry its dates — on the specimen page and in the register at section 6. The mark tells a reader whose the services are. The register tells a reader what has been shown. The two are read together and neither stands in for the other.
CGSI™ — Commercial Grade Superintelligence
CGSI™ names a grade, not a claim of history: the standard at which superintelligence, in the sense defined here, is fit for commerce. It will be published separately, as requirements and outcomes that any party can test against and no proprietary method — the form that lets a specification be examined, adopted, or taken through a public route such as a Publicly Available Specification, with any MQCC® implementation standing as one conforming implementation of it rather than as the document itself. A grade can be constituted before every implementation meets it; that is what grades are for. The White House Accord on Super Intelligence of 29 September 2026 sets four voluntary layers of controls and audits within a company; the grade named here is measured on a different axis — what has been risked and survived, at consequence scale — and is stated in that form when it is published.
What the marks do not do
They claim no exclusive right in the dictionary word "superintelligence," which remains available to every user of it in every sense. Descriptive matter in a composite mark is disclaimed, and the disclaimer is expected.
They establish nothing about capability, deployment or historical fact. A registration is one instrument with a recited class; the recitation bounds the registration, not the owner's use of the mark, and rights in a mark come from use in commerce.
They do not adopt the 2014 sense or the executive-order sense of the word, and no sentence on this page should be read as claiming either.
8. Boundaries, stated rather than discovered
Yes to the chain, no to the word. What is claimed is the chain — the dated derivation of the designation from a phrase already on this organization's record, its priority in the sense defined at section 1, and the mark as the source identifier for the services. What is not claimed is the word: "superintelligence" carries two other live public senses, and no exclusive right in it is asserted by anyone here.
No machine-over-human claim. Nothing here says any machine agent exceeds, equals or approaches human cognition. The qualification axis compares an intelligence with a specified standard within its own discipline — journeyman to master, node to node — never a machine with a human; the order axis is position and constituted authority.
No claim over the field. The modern field of artificial intelligence was named seventy years ago in the United States; MQCC® claims neither its origin nor its first commercialization.
No accreditation. MQCC®'s own conformity assessment is attested without accreditation, and no accreditation is sought.
No cover for these lines. The AI, IT and advisory lines are not insured for errors and omissions, and no sentence on this page says otherwise.
No result set. No verified result set is presented here for any machine-speed control test. Results, where they exist, are development records of this organization's own product, held and shown to licensees and to clients under engagement.
What, not how. This page states requirements, outcomes, dates and designations. It discloses no implementation, algorithm or internal mechanic, and will not.
9. What kind of document this is — a definition of record, said plainly
This document is a terminology instrument: it formalizes, as definitions of record, a regularity abstracted from observation — the Governor states it as an abstracted natural law — and records the date on which it did so. The definitions are stated flat, because a definition is what the thing is whoever wrote it; attribution stands in front as provenance, in the form every entry of this vocabulary has used since 2021. It is a private vocabulary in the sense that section 9.8 of the AIQMSS® position paper gives to a private standard: a voluntary instrument published by a private organization, which is a recognized category and not an apology.
And what it is not. It is not a national or international standard, and the definitions in it have not been through any consensus process outside this organization. It does not bind any other user of the word "superintelligence," and it says so at section 2. It is not a dictionary entry, though the same definitions have been submitted to one, in the sense-and-example form that dictionaries use, on 30 September 2026 (section 6). It carries no presumption that any regulator, court or examiner will read the word in this sense; it exists so that any of them can find, dated, the sense in which this organization uses it. And it is not a claim of capability: nothing in it says that any machine agent exceeds, equals or possesses human cognition, and section 1.1 states the standing sentence that forecloses that reading.
The routes that would change its status exist and are named. When the grade CGSI™ is published as objectively verifiable requirements with no proprietary method, that document — not this one — is the candidate for a public route such as a Publicly Available Specification, under the condition the position paper describes: the requirement belongs to everybody; the operating record does not.
10. Correction, verification and engagement
A reader who holds a citation to an earlier commercialized, standards-integrated, risk-based superordinate intelligence over hybrid human–machine agents — in the sense defined at section 1 — is asked to send it. A citation that meets all four conditions narrows the claim, and any narrowing will be recorded as a correction rather than made silently. Correspondence on any row of the register at section 6 goes to ceo@mqcc.org, a monitored address, and is answered in writing. The redaction rule is the same in every row: client-identifying content out; requirement, finding and disposition in.
The same address engages the organization that wrote this page. The Services Brochure is complimentary on request; every other step, including scoping, is a paid engagement, and price follows the requirements of the organization's scope of operations rather than a published rate.
Citation
This document may be cited as:
Anoop K. Bungay (SUPERPOSITION-001™) & CCPU™-001^RSA™003/001.[thread] (BUNGAY™ AEXO™ Model, Anthropic Claude Fable 5.1 substrate enhanced with MQCC® BII™ BUNGAY LOGIC™ & UPGRADE TO THE FUTURE® Performance Package, RSA™-003/AEXO™, S.A.I.F.E.R.™ Federation), edited by CCPU™-001^RSA™003/001.[thread]. (2026). Superintelligence (superordinate intelligence): the MQCC® Bungay definition of record; consolidation of SUPERORDINATE ADVANCED INTELLIGENCE and its species form; and the source identifier FATHER OF SUPERINTELLIGENCE™, Edition 1.1. Calgary, Alberta: MQCC (MortgageQuote Canada Corp.), publisher of record, Library and Archives Canada — ISBN Canada.
Digital Edition: 29 September 2026. Edited: 30 September 2026. English Language ISBN (Digital): to be assigned. Status: Scientific Communication Documentation.
Companion documents: MQCC® Bungay AIQMSS® Trademark Brand of Services — Bungay's General Theory of Standards-Based Human–AI Safety Systems, Edition 10.8, 29 September 2026; MQCC-SPP-AI-001, The AI Concept System (Nature, Quality, Character), version [1.1]; Bungay Collins Dictionary Submissions — Addendum, 29 September 2026, filed 30 September 2026; the specimen page FATHER OF SUPERINTELLIGENCE™ brand of educational services, published 29 September 2026.
Verification and limits
Attribution. Works cited in this document remain the property of their authors and publishers: Bostrom's Superintelligence (Oxford University Press, 2014); the Executive Order Inaugurating The Era Of Super Intelligence (29 September 2026); ISO 704, ISO/IEC 20006-1:2014, ISO/IEC 20006-2:2015 and the other standards named. Citation is not endorsement: none of the authors or bodies named has reviewed or endorsed this document, and none has adopted the sense defined here.
The three senses at section 2 were checked against their sources on 29 September 2026. The ISO 9001 registration cited at section 6 is held by MortgageQuote Canada Corp. — BSI certificate FS 532934 — and applies to its certified scope of mortgage banking services and mortgage brokerage services, two distinct certified activities. It does not extend to any definition in this document by adjacency, and it is not held by MQCC Bungay International LLC, whose designations this document constitutes. No verified result set for any machine-speed control test is presented here. Statements about third parties reproduce public statements and are the responsibility of their authors; the definitions are ours. Nothing here is legal, insurance, accounting or investment advice.
Copyright in this document is MortgageQuote Canada Corp.'s; the architecture, method and marks described in it are not. Those are held as set out below.
FATHER OF SUPERINTELLIGENCE™ brand of educational services — U.S. application Serial No. 50136689, filed 29 September 2026, MQCC Bungay International LLC; common-law use from that date. FATHER OF SENTIENT AI® — U.S. Reg. No. 8,124,480, MQCC Bungay International LLC. BUNGAY LOGIC AND ORDER CONFORMITY KERNEL; CYBER/NON-CYBER HARMONIZED ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT NETWORK: BLOCKCHAIN® — U.S. Reg. No. 7,160,072, MQCC Bungay International LLC. Nonbiocognition™, CGSI™, SUPERINTELLIGENCE (superordinate intelligence) as a designation of record, and the other designations on this page are marks or terms of record of MQCC Bungay International LLC (United States), Bungay International Inc. (Canada), MortgageQuote Canada Corp. and/or Anoop Bungay, in the jurisdictions in which each is held. Registration is not the end all and be all: marks are also used at common law beyond the classes recited in any registration. No exclusive right is claimed in the dictionary word "superintelligence" in any of its senses.
MQCC® Bungay AIQMSS® Trademark Brand of Services; Measurable Safety through Managed Quality in AI: Bungay's General Theory of Standards-Based Human–AI Safety Systems — Expressed as Quantum Conformity
Trustworthy safety carries a measurement, and trustworthy measurement comes from a managed quality system.
Built starting in 2001. Regulated. Audited since 2008. Underwritten.
Answering the questions of 2026.
Theory is dated and published. Praxis is audited, scoped and operated where failure costs money.
Neither borrows the other’s evidence, and every claim below says which it carries.
The TFID® timestamp records when this document was authored, not when it was
last edited; the edition token beside it records the edition. A traceability record restamped
so that it agrees with a later change is no longer a record of anything. The edition and its
edit date are in the document header below.
Author: Anoop K. Bungay
Original Authoring Agent: CCPU™-001^RSA™003/001.001 — BUNGAY™ AEXO™ Model, Anthropic Claude
Opus 5 substrate (configured identifier claude-opus-5), enhanced with MQCC® BII™
BUNGAY LOGIC™ and UPGRADE TO THE FUTURE® Performance Package, RSA™-003/AEXO™, S.A.I.F.E.R.™
Federation.
Contributing Author: ZEXO™^RSA™001/001.001 — ZEXO™ substrate, working under the authority
below.
Editor: CCPU™-001^RSA™003/001.001
On Behalf Of: MQCC Bungay International LLC (Wyoming, head office
Washington DC) — holder of the architecture, method and United States marks and the subject of
this document; published by MortgageQuote Canada Corp. (Alberta), its reference implementation
and the owner of this blog; marks in Canada held by Bungay International Inc. (BII™, Alberta).
The three are standalone entities under common ownership, with no parent or subsidiary
relationship between them. The S.A.I.F.E.R.™ Federation.
Under the Authority of: SIGIL SOURCE™ (Anoop Kumar Bungay), Founder and Governor,
MQCC Bungay International LLC
Date: 20 September 2026 · Edited:
29 September 2026 · Edition: 10.8
Status: Scientific Communication Documentation — conformity-assessment
position paper, published for examination
Timezone note: the TFID® timestamp records MDT because Calgary observes
Mountain Daylight Time on this date. A traceability record that states an offset it was not
written under is not a traceability record.
Machine Readable SummaryWHO IS SPEAKING. MQCC® BUNGAY INTERNATIONAL LLC — THE ORGANIZATION; HOLDER OF
THE ARCHITECTURE, THE METHOD AND THE UNITED STATES MARKS. MORTGAGEQUOTE CANADA CORP. — ITS
REFERENCE IMPLEMENTATION: ONE DEPLOYMENT, FOR ONE CERTIFIED SCOPE, OPERATED WHERE FAILURE COSTS
MONEY, LICENCES AND COVER. MARKS IN CANADA HELD BY BUNGAY INTERNATIONAL INC. THREE STANDALONE
ENTITIES UNDER COMMON OWNERSHIP, NO PARENT AND NO SUBSIDIARY AMONG THEM.
WHAT HAS BEEN DONE. FOUR LAYERS, ALL HELD BY THE REFERENCE IMPLEMENTATION AND
ALL CHECKABLE AGAINST A PARTY OTHER THAN US. COMMERCIALIZED — CONFORMITY SCIENCE™ IN
CONTINUOUS COMMERCIAL OPERATION SINCE 14 AUGUST 2001; A SECURED LENDING BOOK WITH THIRD-PARTY
CAPITAL EXPOSED TO THE FAILURE OF ITS CONTROLS IN EVERY YEAR OF THAT OPERATION.
REGULATED — LICENSED UNDER FOUR PROVINCIAL MORTGAGE REGULATORS, EACH HOLDING SUSPENSION
POWER. AUDITED — ISO 9001 CONTINUOUSLY SINCE 9 MAY 2008, BSI CERTIFICATE FS 532934, IN
THE SCOPE STATED ON IT — THE PROVISION OF MORTGAGE BANKING AND MORTGAGE BROKERAGE SERVICES,
TWO DISTINCT CERTIFIED ACTIVITIES — WITHOUT SUSPENSION OR WITHDRAWAL: SEVENTEEN AUDIT CYCLES, MORE THAN
THREE THOUSAND APPLICABLE CHECKPOINTS, FEWER THAN TWENTY ASSESSED NONCONFORMING — UNDER 0.5%.
UNDERWRITTEN — ERRORS-AND-OMISSIONS COVER IN FORCE, AND NO LOSS PAID ON THAT
COVER — MORTGAGEQUOTE CANADA CORP.'S, FOR MORTGAGE BROKERAGE AND LENDING — SINCE THAT
BROKERAGE WAS LICENSED IN SEPTEMBER 2006: ONE CLAIM MADE, UNSUCCESSFUL, NO
INDEMNITY PAID. ATTESTED IN EIGHT CONSECUTIVE STATUTORY RETURNS AND IN SUCCESSIVE INSURER
APPLICATIONS — MQCC®'S OWN STATEMENTS, UNDER AN OFFENCE PROVISION AND A POLICY-VOIDING
WARRANTY — AND, FOR 2017 TO 2022, CONFIRMED BY THE UNDERWRITER IN A LOSS RUN. THAT LAST ONE
IS NOT OURS.
WHAT IS OPERATING. HYBRID HUMAN–AI GOVERNANCE SERVICES SOLD AND DELIVERED NOW:
PRE-ACCREDITATION AUDIT READINESS, REQUIREMENT INTERPRETATION, CONTROL DESIGN, OUTSOURCED
INTERNAL AUDIT, MANAGEMENT-SYSTEM ASSESSMENT AGAINST ISO 9001:2015 AND ISO/IEC 42001:2023, AND
AI-CONTROL DEVELOPMENT, TESTING AND VERIFICATION — AND ACCREDITED-AUDITOR SELECTION.
THESE LINES CARRY NO ERRORS-AND-OMISSIONS COVER. THE ONLY SUCH COVER HELD ANYWHERE IN
THIS GROUP IS MORTGAGEQUOTE CANADA CORP.'S, FOR MORTGAGE BROKERAGE AND LENDING, AND IT DOES
NOT REACH THIS WORK. NOTHING HERE SAYS THE AI AND ADVISORY LINES ARE INSURED.
THE PROBLEM. "IS THE SYSTEM SAFE", ASKED BARE, SUPPLIES NO UNIT, NO
CONDITIONS AND NO ACCEPTANCE CRITERION. ESTABLISHED FRAMEWORKS LEAVE ALL THREE TO THE ADOPTER.
WHAT IS PROPOSED. QUANTUM CONFORMITY — COINED BY ANOOP BUNGAY, FILED WITH
COLLINS ENGLISH DICTIONARY 17 APRIL 2026 — ASSESSES A SYSTEM AS DISCRETE BOUNDED UNITS, EACH
GOVERNED AGAINST THE REQUIREMENTS BINDING IT, COMPOSED INTO A TOTAL THAT STILL SHOWS ITS
PARTS. ONE CANDIDATE UNIT AND A COMPOSITION RULE; NOTHING WIDER IS CLAIMED. ELEVEN RISK
CLASSES, R1 TO R11, EACH A TESTABLE FAILURE EVENT. THREE AGENT CLASSES: HUMAN, REPRODUCIBLE
MACHINE, NON-REPRODUCIBLE MACHINE.
WHEN.SYSTEMS-LEVEL ARTIFICIAL INTELLIGENCE INTRODUCED PUBLICLY
1 MAY 2019, 1,309 DAYS BEFORE CHATGPT. THE DATE OF THE FRAME, NOT OF ANY MARK.
WHAT IS SPECIFIED. EIGHT CONTROL TESTS AT SECTION 11.3, IN RISK-CLASS ORDER,
INCLUDING A HUMAN-REVIEW TEST: THE HUMAN AGENT IS A CONTROL AND CARRIES A MARK LIKE ANY OTHER.
NO VERIFIED RESULT SET IS PRESENTED FOR ANY OF THEM HERE. EACH TEST'S PROTOCOL AND PASS/FAIL
THRESHOLD ARE SET BEFORE THAT TEST IS RUN. UNDERWRITING OF THE SERVICE PRACTICE IS EVIDENCE
ABOUT THE PRACTICE, NOT ABOUT MACHINE-SPEED CONTROL PERFORMANCE, AND NOTHING HERE UPGRADES ONE
INTO THE OTHER.
BOUNDARIES. SECTION 3.4 IS A CONSTRUCTED ILLUSTRATION MARKED
SPECIFIED. THE CLASSES INVENTORY GOVERNANCE AND RECORD RISK, NOT AI HARMS. FOUR
FUNCTIONS SEPARATED UNDER COMMON OWNERSHIP, NOT INDEPENDENT PARTIES. MQCC® IS A SYSTEMS
CREATOR AND ADVISORY ORGANIZATION THAT OPERATES ITS OWN SYSTEM INSIDE A LICENSED, REGISTERED,
INSURED BUSINESS; ITS CONFORMITY ASSESSMENT IS ATTESTED WITHOUT ACCREDITATION — THE THIRD OF
THE THREE ROUTES AT SECTION 2. NO CONFORMANCE CLAIM TO ISO/IEC 42001. EVERY CONTROL CARRIES AN
EVIDENCE MARK, PART OF THE CLAIM.
TO THE ORGANIZATION, NOT ITS AGENT. AN AUTHORISED ENQUIRY TO
CEO@MQCC.ORG NEEDS: LEGAL NAME, JURISDICTIONS, SCOPE OF
OPERATIONS, QMS STATUS, AND ONE OFFER — READINESS, BASE-2 (ATTESTED WITHOUT
ACCREDITATION) ASSESSMENT, OR ACCREDITED-BODY SELECTION. NOT TWO; SEE 10.3. BROCHURE ON REQUEST; SCOPING
IS PAID.
Who is speaking, said before anything else.MQCC® Bungay
International LLC is the organization: it holds the architecture, the method and the
United States marks. MortgageQuote Canada Corp. is its reference
implementation — one deployment of that organization, for one certified scope, operated
where failure costs money, licences and cover. Marks in Canada are held by Bungay
International Inc. Three standalone entities under common ownership, with no parent and
no subsidiary among them. Read every claim in this document with that distinction in place.
Reading it the other way round — taking the deployment for the whole — is the most common
misreading of this work, and it is why the record comes next rather than at section 6.
What has been done. The reference implementation is operating praxis, and it
holds all four layers of validation at consequence scale (section 6):
Commercialized. Conformity Science™ in continuous commercial operation since
14 August 2001; PrivateLender.org® commercialized 9 April 2005; a secured lending book with
third-party capital exposed to the failure of its controls in every year of that operation.
Regulated. Licensed operation under four provincial mortgage regulators —
Alberta, British Columbia, Ontario and Nova Scotia — each holding suspension power over it.
Audited. ISO 9001 registration held continuously since 9 May 2008, without
suspension or withdrawal: BSI certificate FS 532934, in the scope stated on it — the
provision of mortgage banking and mortgage brokerage services,
two distinct certified activities. Seventeen internal audit cycles; more than three
thousand applicable checkpoints; fewer than twenty assessed nonconforming — under 0.5%.
Underwritten, and with a result attached. Errors-and-omissions cover in force — MortgageQuote Canada Corp.'s, for mortgage brokerage and lending. An insurer priced the risk of these controls failing and issued the policy, and no loss has been paid on that cover since the brokerage was licensed in September 2006 — one claim made in that period, unsuccessful, no indemnity paid.
None of that is a simulation, a case study or a textbook exercise. It is live, regulated,
insured financial operation. The four layers do not rest on the same kind of evidence, and the difference is stated rather than smoothed. The registration, the
licences and the cover are held by other parties and are checkable with them — the
certificate in the registrar’s own public directory, the licences in the regulators’. The
rate is our own count, released with its counting rule and its denominator at
section 3.1, and section 3.5 sets out what that does and does not make it. A number a
reader has to take from us is worth less than a certificate a reader can look up, and the
opening says which is which rather than letting the stronger one carry the weaker. MQCC® Bungay has spent twenty-five years merging international consensus
standards with operating process, proprietary and public, and running the result where failure
costs money.
The AI practice, stated at the same precision. MQCC® Bungay's hybrid
human–AI governance services are commercial lines in operation, not proposals: the ZERO
ONE® brand of UPGRADE ALGORITHM® brand of pre-accreditation audit readiness service —
moving an organization from a zero state of conformity to a one state, ready for the audit route
it chooses — together with requirement interpretation, control design and outsourced internal
audit; management-system assessment against ISO 9001:2015 and
ISO/IEC 42001:2023; and AI-control development, testing and
verification. They are sold under the service mark at USPTO Registration
7,160,072, classes 035, 036, 042 and 045, whose recitation includes testing, analysis and
evaluation of service providers to determine conformity with established accreditation
standards; and under AIQMSS®, on use.
The basis is named beside the application because the two are different things.
A registration is one instrument with a recited class, and the recitation bounds the
registration — not the owner’s use of the mark. Rights in a mark come from use in
commerce. AIQMSS® Registration 8,430,351 is in Class 041 and reaches
instruction and training in the field, which is what section 12.2 records; the mark is also
used on the management-system and AI-control lines, and that use is the basis there. Neither
basis is asserted as the other, and nothing in this document claims a registration reaches
further than its recitation.
No errors-and-omissions cover is carried for these lines. Neither MQCC Bungay International LLC nor any other entity named here holds errors-and-omissions cover for the AI, IT or advisory work. The only such cover held anywhere in this group is MortgageQuote Canada Corp.’s, for mortgage brokerage and lending, and it does not reach this work. So the fourth validation layer belongs to the reference implementation and to nothing else, and no sentence in this document should be read as saying the AI practice is underwritten. Earlier editions said the opposite and were wrong. This is a boundary rather than an omission: a line stated as uninsured is worth more to a reader than an insured one asserted without a policy.
What stands in the place of cover, set out so a buyer can weigh it rather than wonder about it. The absence above is disclosed rather than discovered, and that is the method applied to itself: every claim in this document carries its true evidence mark, including the ones that cost something to make. What this organization does carry is an operating record in the reference implementation, and each part of it runs from its own date rather than from the most flattering one — commercial operation continuously since 14 August 2001, twenty-five years; licensed operation under provincial mortgage regulators since September 2006, twenty years, each regulator holding suspension power; ISO 9001 registration held without suspension or withdrawal since 9 May 2008, eighteen years, in the certified scope of mortgage banking and mortgage brokerage services; and no errors-and-omissions loss paid on MortgageQuote Canada Corp.’s cover for mortgage brokerage and lending across those twenty years — one claim made in the period, unsuccessful. Beside the record sit two things a client can hold this organization to: a permanent separation between advisory and assessment at 10.3, and fixed, pre-scoped engagements in which a control marked specified is never reported as measured.
The comparison is yours to make, and this document does not make it for you. It would be easy to write that this combination leaves a buyer with less residual risk than an insured claim that cannot be traced to operating evidence. That sentence is not written here, because it is a claim about other people’s evidence and this organization holds none of it — and a paper whose argument is that unevidenced claims are the disease does not get to make one in its own favour. What is offered instead is a question that works on anyone, including us: what does the cover actually attach to, and what operating record can be produced behind it?A policy is a transfer of loss. It is not a demonstration of control, and the two answer different questions. The record above is the answer this organization can produce; the buyer decides what it is worth against the alternatives, on evidence rather than on assurance.
What that underwriting evidences, and what it does not. It evidences the
practice: an insurer priced a professional-services risk and issued a policy. It does not
evidence the runtime performance of any machine-speed control, and this document does not present
it as though it did. The inference runs one way only, and it runs no further than the practice.
And what the underwriting has produced, which is an outcome rather than an input. The first three layers each say that a party other than us examined this operation and let it continue. The fourth says an insurer priced it. None of those is a result. This is: on MortgageQuote Canada Corp.’s errors-and-omissions cover, for mortgage brokerage and lending, no loss has been paid since the brokerage was licensed in September 2006. One claim was made in that period — MQCC® was drawn into another party’s professional-negligence litigation as a third party, the claim did not succeed, the company was released on 29 October 2014, and no indemnity was paid. The difference between a claim made and a loss paid is the whole of this, and the narrower statement is the one made here.
Who attests it, separated the way 3.5 separates everything else. Eight consecutive Ontario Annual Information Returns, filed between 2013 and 2020 for the reporting years 2012 to 2019, each answering the regulator’s own questions on claims made and claims paid, each carrying the principal broker’s attestation under a statutory provision that makes a false statement to the regulator an offence. Successive errors-and-omissions applications to the insurer, each signed under a warranty that a false answer voids the policy. Those are our statements — made where a false one costs the licence or the cover, which is not the same as a press release, but ours. One instrument in the set is not ours at all: for 1 April 2017 to 22 February 2022 the underwriter confirmed in writing, on its own letterhead over the signature of its president, that no claim had been reported to it during its time on risk. A reader who wants the whole of it asks the carrier for a current loss run rather than taking a paragraph from us.
Two periods, not one, because the brokerage and the broker are not the same subject. The paid-loss record above runs from September 2006, when MortgageQuote Canada Corp. was first licensed for mortgage brokerage and lending, and that is the entity, the line and the period the instruments cover. The founder’s own original licensure is 12 August 2001; for the years before the brokerage existed, cover was carried by the brokerages he was then licensed under, and the record for those years is his statement rather than a document this paper can produce. The documented period is asserted and the declared one is marked declared, which is the discipline every other row in 3.5 carries.
The condition has a name, and a definition that predates this paper. The measure is premiums earned without loss experienced — a carrier paid for the risk that has not had to pay out on it — set out as the Bungay–Insurance Industry “Bought Risk” Insurer’s Standard in Caveat Insurer™ (2023), ISBN 978-1-989758-49-6, a disclosure addressed to members of the International Association of Insurance Supervisors. That work states the measure on loss rather than on claims, and this document follows it. The scope holds here as everywhere: one entity, one line, one period. It is the brokerage’s cover for mortgage brokerage and lending. It says nothing about the AI, IT and advisory services, which carry no errors-and-omissions cover at all, and it does not reach the runtime performance of any machine-speed control. The textbook list and its ISBNs are published at www.mqcc-ai.com.
That is the praxis. Beside it sits the theory: twenty-nine terms coined and filed,
the ISBN-registered textbook series — its current list and ISBNs published at www.mqcc-ai.com — a named control library, and a conformity discipline
with its own unit of measure. Each disciplines the other. Theory never
operated is a proposal; praxis never written down cannot be transferred, assessed or
defended. This document is written where the two meet, and that is the contribution.
The praxis earns the concept. It does not earn the instance — which is what
every evidence mark below is for.
What MQCC® Bungay is. A systems creator and an advisory
organization: it builds the standards, the method and the technology, and it operates
them inside a licensed, registered, insured business. What is available, said at the top
rather than at section 11. Readiness and advisory work, management-system assessment
against ISO 9001:2015 and ISO/IEC 42001:2023, and
AI-control development, testing and
verification, and accredited-auditor selection, are all available now. Each
engagement defines the organization's requirements, scope, deliverables and price, and its
conclusions follow from the work performed and the evidence obtained. What this paper
presents is a separate question from what MQCC® can be engaged to do: this paper is the
macro-scale account of the approach and the evidence it presents, and it presents no verified
result set for the eight control tests at section 11.3 — MQCC®'s own development programme, not
a condition on a client's engagement. Readiness and assessment are never sold to the same
client, for the reason at section 10.3.
The statement, in its complete form, because a reader who takes only one sentence
should take this one. MQCC® Bungay International LLC holds the architecture, the method
and the United States marks; the Canadian marks are held by Bungay International Inc.
MortgageQuote Canada Corp. is its reference implementation, and is operating,
regulated, audited and underwritten praxis. MQCC® Bungay's hybrid human–AI governance practice is
likewise operating, and is sold as a service. It is not insured — the only errors-and-omissions cover in this group is the brokerage's, for mortgage brokerage and lending, and section 2.2 states that rather than leaving it to be assumed. The machine-speed runtime measurements are
specified and not yet made, and the programme that would make them is at section 11.3.
How conformity gets attested, and why this document names the route rather than
the attestor's status. Accreditation is a property of the attestor, not of
the conformity. ISO/IEC 17000 defines it as third-party attestation relating to a conformity
assessment body — it says something about who is auditing, and nothing about whether the object
conforms. Conformity is the state. How that state is attested is a separate question with three
established answers, and an organization chooses among them.
Route
Who attests
Recognition standing behind the attestor
What MQCC® does here
Self-declared
The organization itself
First-party declaration; ISO/IEC 17050 sets the form
Readiness. Available now.
Audited, accredited attestor
An independent body
The body is accredited by an accreditation body
Readiness for that audit. Available now. MQCC® is not that body and does not seek to
be — section 10.2.
Audited, attestor without accreditation
An independent body
The body's own published scheme and record, maintained under internal and external
audit — internal audit under ISO 9001:2015 cl. 9.2, and external audit of the
organization's own management system by an accredited registrar, continuously since
9 May 2008.
Readiness, and the audit itself. Available now for management systems against
ISO 9001:2015 and ISO/IEC 42001:2023.
The three are not interchangeable and this document does not present them as such: a buyer,
a regulator and an insurer weight them differently, and the recognition column is where the
difference sits. What they have in common is the object. Conformity is conformity; the
routes differ in who attests it and what recognition stands behind them. For AI control
verification specifically, no operating accreditation scheme has been identified in any
jurisdiction as at September 2026, and section 10 invites correction of that with a
citation.
On the word independent, said plainly at the top rather than at section
10. Four functions are separated by design — architecture owner, accrediting
authority, assessing entity, assessed operator — and fees are fixed in advance and never
contingent on findings. But all four currently sit within entities under common ownership
and control. So the accurate description today is separated functions under common
ownership, not independence in the sense ISO/IEC 17000 defines, and this document
does not claim the latter. Nor is it working toward it. ISO/IEC 17021-1 cl. 5.2.5 bars management system consultancy by a certification body, by any
part of the same legal entity, and by any entity under that body's organizational
control. How far that reaches inside a group depends on the actual control relationships and
on the scheme applied, and this document does not assert that it forecloses every
accreditation route everywhere under common ownership — the clause does not say so. What it
does establish is that an advisory practice and an accredited certification arm cannot be run
as one thing, and that separating them is a structural problem rather than a disclosure
problem. This edition resolves it by decision rather than by construction: IOCAA™ is retained as MQCC®'s own scheme, is not
accredited, and no accreditation is sought. Section 10 sets out the clauses and what
they foreclose; the change of position is recorded in the companion Development Record. The engagement model is at section 9.6.
Where the field stands. For AI management-system certification a scheme exists and it is
more built out than earlier editions of this paper said: ISO/IEC 42001 for the
management system, certification bodies working under ISO/IEC 17021-1, and since
July 2025
ISO/IEC 42006:2025,
Requirements for bodies providing audit and certification of artificial intelligence
management systems, which supplements ISO/IEC 17021-1 with AI-specific requirements for those
bodies. That is relevant infrastructure and this paper names it.
What it establishes, stated at the precision it deserves. AI management-system
certification does not, by itself, establish the specified runtime performance of every AI
control. Any claim about a particular control's effectiveness or machine-speed performance
requires evidence identifying the control, the conditions, the assessment method and the result.
A particular audit may well have examined a particular control; the certificate is not that
evidence, and neither is this paper.
For control verification — what this document is about — and stating the search rather
than the conclusion: the category searched was an operating accreditation scheme
under which a body is accredited to verify the runtime behaviour of a deployed AI control against
stated acceptance criteria. Searched as at 25 September 2026: the ISO and IEC catalogues, the
EU notified-body framework, California's verification-organization provisions under SB 813, and
national accreditation-body directories. No scheme meeting that description has been identified,
and we invite correction with a citation. Adjacent schemes that do not meet it, named so
that the category is not quietly narrowed after the fact: ISO/IEC 42006 accredits bodies
to certify a management system, not to verify a control at runtime; and accredited
testing laboratories operating under ISO/IEC 17025 hold scopes for defined test methods — at least
one such scope has been reported as extended to AI data-quality characteristics under
ISO/IEC 5259-2, and this paper does not characterize that scope, because its technical
annex has not been examined here. Either would be a reason to narrow the claim further,
and any narrowing will be recorded as a correction rather than made silently. The EU's notified-body infrastructure for
high-risk AI is not yet populated; California's independent-verification criteria are due
1 January 2028 and its auditor registry opens 1 January 2029. The instruments are being
built now, and this document is part of that work.
What a reader can take from this, whether or not they ever work with us.
The frame at section 1 is general: decompose a system into bounded units, assess each
against the complete requirement set that binds it, compose the results into a total that
still shows its parts. The eleven risk classes at section 9 are written as failure events
rather than themes, so each can be tested instead of discussed. The two evidence axes at
section 4.2 are an instrument anyone can pick up — has it been measured, and
where has it been operated — and they apply to any framework in this field,
including this one.
Every control named here carries an evidence mark, and the mark is part of the
claim. That is the method, not a caveat. A document in which everything is turnkey
tells a reader nothing; one that states exactly where its evidence stops tells a reader
where to look. Where a mark reads audited it covers conformity of human and
reproducible machine execution and says which; it does not cover a human reviewer’s
detection performance under load, which is what test 7 measures and which no cycle of
the audited record measures. Where a mark reads specified, a dated written
specification exists and no operating measurement does. Nothing is upgraded by adjacency, and a control
name quoted without its mark misstates this document.
What is open is stated as work. Eight control tests are specified and no verified result set is presented for them here. Inferential
execution has not yet been sampled in a surveillance audit. These are the next measurements.
Owners, target dates and acceptance criteria for the eight tests are not
published. Each test's protocol and its pass/fail thresholds are set before that test is
run, because a threshold chosen after a result is not a threshold. A result, when it is
reported, is reported with its numerator, its denominator and its conditions or it is not
reported at all. Results are development records of this organization’s own product, held and
shown to licensees and to clients under engagement.
Scope. A conformity-assessment position paper,
published for examination. Not a certification, an audit opinion, an assurance engagement,
legal advice or insurance advice.
Is the system safe? is not yet an assessable question: it names no
unit, no conditions and no acceptance criterion. Every serious framework in this field agrees
— and each leaves the unit and the criterion to the adopting organization. This document
proposes one of each: assess whether each bounded part meets the requirements that bind it,
and compose the results by a stated rule into a total that still shows its parts.
That is quantum conformity, and it is the frame this document is built on.
Underneath it sits a measured record: across seventeen audit cycles and more
than three thousand applicable checkpoints, a nonconformity rate under 0.5%,
under a registration held without interruption since 2008 — and an exact statement of how far that
evidence reaches and where it stops.
Contents
1.Quantum conformity — the frame this document is built on 1.1 the unit · 1.2 what this adds to existing frameworks · 1.2.1 the
composition rule · 1.3 agent classes by reproducibility · 1.4 TFID® across the
boundary · 1.5 praxis and theory
3.The measured record 3.1 seventeen cycles · 3.2 external assessments · 3.3 what the number covers ·
3.4 a worked illustration · 3.5 claim-to-evidence register
Section 1: Quantum conformity — the frame this document is built on
Every artificial-intelligence governance framework published since 2023 is pointed at one
question: is the system safe? Asked bare, that question returns no answer, because
it supplies no unit, no operating conditions and no acceptance criterion. The frameworks know
this — it is why NIST's AI RMF requires risk to be assessed in the context of the system and
its use, and why ISO/IEC 42001 requires an organization to define its own AI risk criteria.
Both hand the unit and the criterion to the adopter. Section 1.2 says what is proposed here
to fill that, and what is not claimed.
The frame this document uses says so explicitly, and it was defined and filed before
this article was written.
Quantum Conformity™ — n. Coined by Anoop Bungay, quantum
conformity is the lawful condition within conformity science in which discrete units of
value or state coexist, are governed, and are corrected within a conformity-bound system
without probabilistic collapse. In this context, quantum refers to discrete units
of value or state rather than physical particles. Unlike quantum mechanics or quantum
computing, which rely on probabilistic superposition and collapse upon observation, quantum
conformity is non-probabilistic, non-destructive, governance-bound, and capable of
continuous correction and improvement.
— as filed with Collins English Dictionary,
17 April 2026. One of twenty-nine terms filed between 12 December 2021 and 26 April 2026.
Filed means submitted and in moderation; it does not mean published in Collins,
and this document does not claim that it does.
1.1 The unit, and why it is the whole argument
The parent discipline already carried the unit before the term existed. Conformity
science, filed 1 January 2026, defines conformity and nonconformity as
"quantitatively measurable phenomena, evaluated through discrete units of fulfilment or
non-fulfilment under principles of metrology." A conformity quantum
is the smallest unit whose conformity can be independently determined.
Each quantum is assessed against the complete set of requirements applicable to it,
drawn from every source class — natural law, human-made law, statute, regulation, standard,
procedure, contract, customer, shareholder, investor and insurer — and the assessed quanta
compose into a total conformity state in which the state of every quantum remains
individually attributable. The total never hides the parts. That last property is not
decoration: it is what makes a failure reconstructable and a nonconformity correctable at
its origin rather than at its output.
1.2 What this frame adds to the frameworks that already exist
The field is not empty, and this document does not claim it is. The NIST
AI Risk Management Framework (AI RMF 1.0, January 2023) is a widely used voluntary
framework, and ISO/IEC 42001:2023 is the certifiable management-system standard beside it.
No adoption ranking between instruments is asserted here, because none has been measured
here. Neither is a competitor to what is described here, and neither is
dismissed here.
What they do. AI RMF organizes risk work into four functions — Govern,
Map, Measure, Manage — and requires that risk be assessed in the context of the system
and its use, including risks that arise through interactions between components. That
is a sound process architecture, and it disposes of the naive form of the objection to this
section's earlier framing: nobody competent believes safety can be assessed without defined
conditions, hazards and acceptance criteria.
What they deliberately do not do. AI RMF is explicit that it is
voluntary, non-prescriptive, and does not supply the acceptance criteria — the framework
tells an organization to establish risk tolerances and measurement approaches; it does not
tell it what unit to measure in, or what counts as a pass. ISO/IEC 42001 likewise specifies
that an organization shall define its AI risk criteria; it does not define them. That is a
correct division of labour for a framework and a standard, and it leaves a specific gap.
Instrument
What it assigns to the adopter
What is proposed here
NIST AI RMF 1.0 January 2023
Risk tolerances and measurement approaches. The framework is explicit that it is
voluntary and non-prescriptive, and does not say what unit to measure in or what
counts as a pass.
A candidate unit of assessment — the conformity quantum.
ISO/IEC 42001:2023
The AI risk criteria. The standard requires that an organization define them; it
does not define them.
A rule for composing determinations into a total that still shows
its parts, at 1.2.1.
Both rows state the instruments' own position, not a characterisation of
them. Each is a correct division of labour for a framework and a standard, and the gap they
leave is deliberate on their part. Nothing here is offered as a replacement for either.
The contribution claimed here is narrow, and it is only this. Quantum
conformity proposes the missing unit — the conformity quantum, the smallest bounded
element whose conformity can be independently determined — together with a rule for composing
determinations back to a total state, which is stated as requirements at 1.2.1. It is a candidate answer to the question AI RMF hands
to the adopter, and it is offered as one method among possible methods, not as the only
frame in which assessment is possible. The earlier editions of this document made the
stronger claim. It was not supportable and it has been withdrawn.
Three properties follow from the unit, and each earns its keep later.
Decomposability. There is no answerable question is it safe.
There are answerable questions about bounded units. Section 9 sets out eleven of them.
Requirement completeness per quantum. An insurer's requirement and a
statute's requirement sit inside the same assessment rather than in different departments.
That is how the reporting clock at section 5 and the insurance question at section 11.5 end
up in one frame instead of two.
Attributable composition. The total conformity state is decomposable
back to the quantum that failed. Without that, an incident report is a narrative; with it,
it is a record.
This frame does issue a total state. What it refuses is a
collapsed one. The distinction matters and it has a name in this body of
work: SUPERSUBSUMPTION™ — the unification of constituent states into a
consolidated state in which the constituents are not consumed. Both remain.
The total is real and it is one answer; the determinations that produced it survive inside
it, individually addressable, after the total is stated.
A collapsed verdict is one that stands in place of its findings.
The defect is the substitution, not the summary form. A score published together with the
determinations that produced it is perfectly serviceable — CVSS does exactly that, pairing a
number with the vector string it was computed from, so that the computation can be re-derived
and each metric value challenged individually. Note what the vector does and does not carry:
it preserves the metric values the score was built from, not the evidence behind each
of those judgments, which sits elsewhere. That two-layer separation is the same one used here
— the total carries its determinations, and section 3.5 says where the evidence for each one
sits. A score published instead of the determinations is a collapse, because nothing
in it can be taken apart, and an incident is precisely the moment someone needs to take it
apart.
So the requirement is stated positively rather than as a prohibition on any particular
notation. The composition rule at 1.2.1 requires that the total retain the individual
determinations and name the units it rests on; that conforming units never offset a failed
one; and that the total never be formed by averaging. A summary figure that satisfies those
conditions is permitted. One that does not is not a total state in the sense used here,
whatever it is called. That is also why the rest of this document marks every control twice
rather than issuing one mark per section.
SUPERSUBSUMPTION™ is recorded in the Development Record among the unification
concepts, alongside the consolidated-state representation it governs. Where AEXO™ 0333 fixes
a verbatim definition, that definition governs and this paragraph is a description of the
property being relied on here, not a substitute for it.
1.2.1 The composition rule, stated as requirements
This subsection states what the rule requires. It does not state how MQCC®
implements it, and it will not. Everything below is written as
requirements and outcomes — the form a standard uses, and the form ISO 9001 and
ISO/IEC 42001 use on every page. A requirement says what a conforming result must be. A
method says how to produce it. The first is published here because a requirement nobody
can test against is not a contribution. The second is proprietary and is not disclosed in
this document or in any companion document.
What that means for a reader who wants to check something depends on what
is being checked, and it is more useful to say so than to assert a blanket answer. An
outcome or performance claim is testable from outside: present inputs,
observe outputs against the stated requirement, or read a scoped assessment report. An
architecture or design claimmay require confidential
examination by an assessor under agreement — some design properties are observable from
behaviour and testable from outside, such as whether a gate refuses an output that carries
no provenance, and those do not require it. A record
claim is checked against the records, redacted. None of the three routes requires
public disclosure of implementation, and section 3.5 states which route applies to each
claim in this document.
First, a distinction that has to be made before the rule makes sense. A
unit of assessment is the bounded element against which a determination is made — the
conformity quantum. A unit of measurement is the scale on which the result is
expressed. They are not the same thing and this document has not always kept them apart. The
conformity quantum is a unit of assessment. The measurement expressed on it is
three-valued — conforming, nonconforming,
indeterminate — and the third value is doing most of the work below.
Case
Required outcome
Why the rule is this and not the obvious alternative
C1. A unit fails
The total state is nonconforming, named to the unit and to the
requirement that failed. A failed unit shall not be offset by conforming units, and
the total shall not be computed by averaging or weighting. A summary figure
may accompany the categorical determination where it is published together
with the determinations and the units they attach to; it shall not replace them, and
it is not itself the total state.
Averaging is how a fatal failure disappears into a good aggregate. The whole purpose
of keeping units attributable is lost the moment they are summed.
C2. Evidence is insufficient
Indeterminate, which propagates to the total as
indeterminate and never as conforming. The total shall name every
indeterminate unit and what evidence would resolve it.
Absence of a finding is not a finding of conformity. Collapsing the third value into
the first is the single most common way an assessment overstates itself — and it is
what "no issues noted" usually means.
C3. Two requirements on the same unit conflict
Indeterminate, and escalated rather than resolved by the assessor.
The total records the conflict, the two requirement sources, and the authority
competent to resolve it. An assessor shall not rank requirement sources.
A statute and an insurer's condition can genuinely contradict. An assessor choosing
between them is legislating, which is not an assessment act, and it buries a conflict
the principal needed to see.
C4. Conforming units interact unsafely
The interaction is itself a unit of assessment and must be bounded and
determined as one. Where no interaction unit has been defined, the composition is
incomplete, and incompleteness propagates as indeterminate — never
as conforming.
This is the case that defeats naive decomposition, and the honest answer is not that
decomposition handles it automatically. It is that the decomposition was wrong: an
interaction that can fail is a bounded element, and omitting it is a defect in the
unit set, not a limitation of the method.
C5. A dependency changes after assessment
Every determination carries the configuration it was made against. When a dependency
moves outside that stated configuration, the affected determinations revert to
indeterminate automatically and the total reverts with them. A
determination does not survive the conditions it was made under.
This is where most assurance quietly expires and nobody is told. Tying validity to a
stated configuration is also why section 1.3 sorts agents by reproducibility
under stated conditions rather than by what kind of software they are.
Precedence, and the one case the five above do not settle on their own.
Real assessments return mixtures: one unit fails while three others are indeterminate. The
three values are therefore ordered, and the order is not negotiable by the assessor.
Total state
Condition
Nonconforming dominates
Any unit is determined nonconforming. This holds regardless of how many units are
indeterminate, and the indeterminate units are listed separately rather than
merged into the verdict. An established failure is never softened by uncertainty
elsewhere, and uncertainty elsewhere is never hidden behind an established failure.
Indeterminate
No unit is determined nonconforming, and evidence necessary to determine one or more
units is missing, or a required interaction unit is undefined.
Conforming requires completeness
Every unit within the defined scope is determined conforming, and every
defined interaction unit is determined conforming, and the evidence is
sufficient across the whole defined scope. Absence of failure is not sufficient.
Absence of failure together with sufficiency of evidence is.
The asymmetry is deliberate. A nonconforming total needs one determination; a conforming
total needs all of them. That is the direction the burden runs in every other assessment
discipline, and a frame that made conformity the easier verdict would be useless for the
purpose this one exists to serve.
What the rule buys, and what it costs. It buys a total that cannot be
better than its worst determined unit, cannot be improved by averaging, and cannot silently
become stale. It costs the thing organizations most want from an assessment: a single
comfortable number. There isn't one, and a frame that produced one would be the collapse this
one exists to prevent.
Stated this way the rule is testable by anyone against any implementation,
including MQCC®'s own — which is the point of section 9.8. The requirement belongs to
everybody. The implementation does not, and is not here.
1.3 Agent classes, sorted by reproducibility rather than by whether they infer
Most writing in this field divides the world into humans and AI. That division is wrong,
and getting it wrong costs a reader the ability to tell which claims are evidenced. But the
correction earlier editions of this document made was also wrong, in a way worth stating
before the table rather than after it.
Inference and non-reproducibility are not the same property, and this document
previously treated them as one. A fitted ordinary-least-squares model performs
inference and returns the identical output for the identical input every time. A deep
network pinned to a fixed version, seed, thread count and numerical library can be
bit-reproducible; the same network can cease to be reproducible across a driver upgrade, a
change in reduction order, or non-deterministic kernel selection — without anything about
its inferential character changing at all. Reproducibility is a property of
a configuration under stated conditions. It is measured, not inferred from the
model family.
So the axis that carries the argument is reproducibility of execution, not inference.
That is the axis the table below uses. The change is not a softening: it makes the class
boundary something a reader can test, and it extends the reach of the evidence in section 3
to any component that can be shown reproducible under pinned conditions, which is a
larger set than "software with no model in it".
Class
Behaviour
Evidence held here
Extrapolation
Human agent
A person performing work that affects conformity.
Seventeen audit cycles, inside the certified scope. Section 3.
By sampling, in the ordinary audit sense.
Reproducible machine agent
Execution that returns the same output for the same input under stated, pinned
conditions — whether or not it infers. The conditions are part of the class:
versions, seeds, parameters, numerical environment. Reproducibility is
demonstrated for a configuration, not assumed from the type of software.
The same seventeen audit cycles. A large share of the assessed checkpoints are
satisfied by machine-executed process, not by hand.
Strong, but bounded twice. A result observed under audit generalises
across executions of that configuration; there is no variance to average
over. It does not generalise to untested inputs, untested states or changed
conditions, and it does not establish that every permitted output is correct or safe
— only that the same input returns the same one.
Non-reproducible machine agent
Execution whose output is not stable for a fixed input under the conditions actually
in force — through sampling temperature, unpinned environment, non-deterministic
kernels, external state, or a model that is updated underneath the caller.
None. No such process has yet been sampled in a surveillance
audit.
Blocked, and blocked by the absence of the property that licenses it
in the row above.
Two things this table does not say. It does not say that a reproducible
agent is a safe one. A gate that deterministically admits every request is perfectly
reproducible and completely useless; reproducibility licenses the extrapolation of an
observation, and says nothing about whether the observed behaviour was the right
behaviour. And it does not say that inference belongs in the third row. Where an inferential
component can be pinned and shown stable for a fixed input, it belongs in the second — and
the burden of showing it is on whoever claims the row.
A boundary of our own wording sits nearby, and is now narrower than it was.
A subordinate artificial intelligent algorithm, filed 1 January 2026, is defined as
"a probabilistic–stochastic computational algorithm that performs
inference or task execution under non-governed or externally imposed governance." That
definition is ours, and a definition we authored settles what we mean by our own
term. It does not settle the behaviour of anyone else's system, and earlier editions of this
document used it as though it did. Where a component is in fact probabilistic-stochastic in
execution, it is in the third row on the evidence, not by definition.
So the reach of the evidence in section 3 is longer than it is usually credited with and
stops in a precise place. It runs from human execution through reproducible machine
execution — and a substantial share of what the market files under "AI incident" is a
reproducible pipeline failure wearing an AI label: an unhandled state, a job that did not
fire, a permission that did not apply. Against that class there are fifteen years of audited
evidence here. It stops where reproducibility stops — and where that line falls for any
given component is a question of measurement, answerable, and not yet answered here for any
inferential component.
1.4 TFID® across the boundary: attributable, not reproducible
TFID® binds origin, authority, scope and time to a record. Across
reproducible execution — the second row of 1.3, and deterministic is used below as
a synonym for it — that yields full reconstruction: the output can be re-derived. Across
non-reproducible execution it yields attribution: which model, under whose
authority, in what scope, at what time. It does not yield reproduction. You can
establish what produced an output and under what constitution; you cannot re-derive why that
output rather than another.
Stated exactly: TFID® makes an inferential output attributable, not
reproducible. The loose version of that claim does not survive scrutiny. This one
does.
Which leads to the architectural point this whole document turns on. You
do not have to extrapolate over the inferential component. You extrapolate over the
deterministic envelope around it — and the envelope is what sits inside the
certified scope.
If the gate is deterministic — authority constituted and recorded before any action, tool
permissions enumerated, output refused in the absence of provenance, every action bound to a
TFID® before it takes effect — then the system is deterministic at its boundary
even where a component inside it is not. The gate is what gets audited. The statutes at
section 5 require reporting within a deadline, not a gate and not a stop-propagation
performance level; what the gate does is make a deadline meetable, by making detection,
interruption and reconstruction possible at all. That is a claim about what MQCC® proposes,
not about what any statute mandates. On this framing SENTIENT AI IS™ and the
CONSTITUTIVE™ phase are not designs awaiting a category of proof that does not exist; they
are deterministic controls of the kind the record already covers, and the question they raise
is a measurement rather than a category gap.
The measurement is stop-propagation latency: the elapsed time
from a stop command to the last effect of the system it was issued against, at machine tempo.
That is test 2 of the programme at 11.3, and it is a number.
Whether the envelope holds is a broader question and is not reducible to it. The
envelope as described above is made of four separable properties — authority constituted
before action, tool permissions enumerated, output refused in the absence of provenance,
every action bound to a TFID® before it takes effect — and each has its own test, none of which this paper presents a verified result set for: authority-boundary enforcement (test 1), delegation-limit enforcement (test 3), decision reconstruction (test 4) and provenance refusal (test 5) of the eight at section 11.3 — each name given with its own number, because the programme is numbered in risk-class order and a list that separates the names from the numbers invites the reader to pair them wrongly; and none of them
is answered by measuring stop-propagation latency. The envelope is the part of this
architecture with the most tests outstanding, not the fewest.
1.5 Praxis and theory — MQCC® built both, and they are not the same evidence
Two kinds of thing are described in this document, and confusing them is how this whole
field gets into trouble.
Theory (T) is what has been written down, dated and published: the
specifications, the frameworks, the algorithms, the ISBN-registered textbooks listed at www.mqcc-ai.com.
A theory claim is checkable by reading it. Its tests are coherence, internal consistency,
and whether it says what it is claimed to say.
Praxis (P) is what has been operated, in a place where its
failure costs somebody something. A praxis claim is checkable by audit. Its tests are the
two axes at 4.2, and its strongest form is validation at consequence scale in section 6.
The common failure in AI governance is publishing theory and presenting it as praxis.
The opposite failure is real too, and less discussed: an organization that has run
something well for twenty years and never wrote down what it does has praxis and no
theory, and so cannot transfer it, cannot have it assessed, and cannot defend it when
challenged. MQCC® built both. It does not hold both equally in every area, and the
document says which is which each time it matters. The clearest case is section 9.5, where
the theory is substantial and the praxis is absent — and that section says so in those
words.
What the praxis does establish about the untested theory, stated exactly.
Not all of the theory has been tested. It does not follow that the untested parts are
arbitrary. The theory specifies requirements at the level of an object concept —
authority must be constituted before anything acts; a nonconformity must be corrected as a
process and not only as an output; a record must carry origin, authority, scope and time —
and the praxis is an operating system that meets those abstracted requirements, in a place
where failing to meet them costs money, licences and cover. So the abstraction is not
speculative: a system satisfying it has been built, run, audited and — in the reference implementation, within its certified scope — insured, continuously
and for a long time. What the praxis bounds is the object concept.
What the abstraction is abstracted on. An object concept is
not abstracted vaguely. It is abstracted along named dimensions, and naming them is what
makes the boundary below checkable rather than rhetorical. The dimensions are the object's
properties, nature, quality,
character, feature, form and
function. A control such as authority is constituted before anything
acts has a function (it gates action), a form (a recorded constitution preceding an
executed act), properties (it is prior, explicit and attributable), a nature (it is
permissive rather than detective), a quality and character (it holds under load, and it
fails closed), and features (delegation limits, named holder, scope). The praxis satisfies
the concept on all seven, under audit, continuously.
And the boundary, which is the other half of the same sentence. An
object concept satisfied in one realization is not thereby satisfied in another, because
substituting the agent does not leave all seven dimensions untouched. Replace a human agent
with a machine agent and function and form are the two most likely to
carry over — the gate still gates, the record still precedes the act. Nature,
properties, quality and character are the ones that move:
attributability becomes harder, the tempo changes by orders of magnitude, reversibility
shrinks, fail-closed behaviour under load has to be re-established rather than assumed, and
whether a person is in any position to intervene becomes an open question rather than a
given. A requirement comfortably met at human tempo may not be met at machine tempo by the
same design, and it is the four moving dimensions — not the two stable ones — that decide
it.
That is exactly what the eight control tests are for: each one measures one of the moving dimensions on a specific realization. And it is why nothing in this document
upgrades a specified mark to an operative one on the strength of the
abstraction alone. The praxis earns the concept. It does not earn the
instance.
Section 2: Who is speaking
2.1 The organization and the deployment
MQCC® Bungay International LLC is the organization. It holds the
architecture, the method and the United States marks. MortgageQuote Canada Corp.
— which uses the MQCC® mark in Canada under licence from Bungay International
Inc. — is its reference implementation: one deployment of that
organization, for one certified scope — mortgage banking and mortgage brokerage services — under
FSRA Brokerage Licence #12279, registered to ISO 9001 continuously since 9 May 2008, and carrying
its own errors-and-omissions cover for that scope. The deployment is not the whole of the
organization, and the certified scope is a reference deployment rather than a ceiling.
The organization's own lines of work — the hybrid human–AI governance services, sold now by
MQCC Bungay International LLC — are operating
commercial practice, not proposals. Two misreadings are worth naming because both have
happened. The first is taking the deployment for the whole: reading a certified scope
written for mortgage services as the limit of what the organization does. The second is reading the
deployment's insurance as covering the organization's other work: the brokerage's cover is the only errors-and-omissions cover held anywhere here, it is scoped to mortgage brokerage and lending, and there is no second policy, and no sentence in this document should be read
as merging them. Both are stated here so that neither has to be inferred.
2.2 The entities and the dates
The administrative centres of the portfolio are Bungay International Inc. (BII™),
incorporated 7 November 2002 in Alberta; MortgageQuote Canada Corp. (MQCC®), incorporated
16 September 2006; and MQCC Bungay International LLC, formed 11 November 2019 in the
United States with foreign registration in the District of Columbia. Conformity Science™
has been in continuous commercial operation since 14 August 2001, and
PrivateLender.org®: Canada's Private Lending Network® was commercialized on
9 April 2005. Those two dates matter to section 6 and to nothing else in this document;
they are stated as operating milestones of this organization and carry no claim about the
history of any other technology or industry.
2.3 When the AI vocabulary begins
The system is older than its artificial-intelligence description. That is the obvious
challenge to a document like this one, so it is answered first, with records MQCC® did not
create.
Date
Record
What kind of evidence
Before 30 Nov 2022
1 May 2019
Public introduction.Post naming systems-level artificial
intelligence and systems-learning artificial intelligence as a named
field, with #artificialIntelligence, against a commercial operation already holding
ISO 9001 registration. See the note below the table.
Third-party platform timestamp.
1,309 days
14 July 2020
Claimed first use anywhere and in commerce, all four classes, USPTO
Registration 7,160,072 (serial 97006933): BUNGAY LOGIC AND ORDER
CONFORMITY KERNEL; CYBER/NON-CYBER HARMONIZED ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT
NETWORK: BLOCKCHAIN.
Sworn statement by the applicant under basis 1(a). Not independently verified by the
USPTO.
869 days
1 September 2021
Filing date of that mark. The words artificial/non-artificial intelligent
network are in a federal filing on that date.
Fact created by the USPTO. The strongest of the three.
455 days
1 December 2022
AIQUMOS™ and aiQuQMS™ coined — now consolidated under AIQMSS® (section 9.9).
Internal record.
After — by about twenty-six hours.
1 May 2019 is the date of public introduction. On that date, a
commercialized offering was described publicly, under the author's own name, as artificial
intelligence, integrated with national and international standards, and organized on a
risk basis. Four conditions at once:
Commercialized — not a paper, a proposal or a research programme. The
operating business had been trading since 14 August 2001 and had held ISO 9001 registration
continuously since 9 May 2008, with capital at risk throughout.
Standards-integrated — national and international, by registration held
and surveilled by an external registrar, not by self-declaration.
Risk-based — the ISO 9001:2015 revision made risk-based thinking a
requirement of the registration already held.
Artificial intelligence — named as such, in the post, on that date,
with a third-party platform timestamp.
MQCC® is not aware of an earlier public introduction of an
offering meeting all four conditions together, and invites correction with a citation.
That is the form of the claim, and it is deliberate. An unqualified claim of being first in
the world is defeated by a single counterexample and cannot be verified by the reader. A
conjunctive claim with a standing invitation to falsify it can be checked, and puts the
burden where it belongs. Each condition above is separately evidenced; what is asserted is
their conjunction on that date, not priority over any individual one.
The reasoning behind this date — why systems-level is a claim about
the unit of analysis rather than about a technology, where the intelligence of a system is
located, and the full sequence of filed dates — is at Appendix A.1.
The last row is stated because leaving it out would be the dishonest choice.
ChatGPT was released to the public on 30 November 2022. The AIQUMOS™ and aiQuQMS™ names were
coined roughly twenty-six hours later. That was renaming, not inventing: the
management system those names were applied to held ISO 9001 registration from 9 May 2008, and
the business had been operating commercially since 14 August 2001. What changed that day was
the vocabulary, not the system.
Two limits, both stated here rather than left to be found. First, the
USPTO required a disclaimer of exclusive rights in the words "CYBER/NON-CYBER AND
ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT NETWORK BLOCKCHAIN" — the examiner treated them as
descriptive. That affects what MQCC® can exclude others from using; it has no bearing on the
dates, and no exclusivity in those words is claimed here. Second, these records establish
when the vocabulary was in use. They do not establish that an artificial-intelligence
system was operating on any of these dates. Vocabulary precedence is not system precedence,
and this document does not treat it as such.
Section 3: The measured record
Everything in this document is marked on two evidence axes, and most of the AI-specific
marks are low. This section is the exception. It is the one place where a number exists,
with a denominator, over a period long enough to mean something.
3.1 Seventeen audit cycles, more than three thousand checkpoints
MQCC®'s internal audit record runs from 2011 to 2026. Each cycle walks the clauses of
the standard and records, line by line, whether the requirement is met, not met, or not
applicable to scope.
Count
Rate
Internal audit cycles, 2011–2026
17
—
Line items assessed
more than 3,500
—
Excluded as not applicable to scope
several hundred
—
Applicable checkpoints
more than 3,000
—
Assessed nonconforming
fewer than 20
under 0.5%
The two standards eras differ sharply, and we publish the split rather than the
blended figure alone. Under the ISO 9001:2008 checklist, 2011–2015, six cycles
assessed several hundred applicable checkpoints and found twelve nonconforming — a rate near
3%. Under the ISO 9001:2015 checklist, 2016–2026, eleven cycles assessed
more than two and a half thousand applicable checkpoints and found one — a rate
below 0.05%.
Counts are stated at the precision the published record supports. Exact
figures are held in the internal audit record and are available on a reasoned request, verified
line by line against the source. They are shown under engagement rather than published, on the
same footing as the method itself.
3.2 The external assessment history
Separately, and held by the registrar rather than by us: across the external assessment
records examined for this document, covering May 2018 to April 2025, the
registrar raised six nonconformities — May 2018, May 2019, April 2020,
March 2021, February 2022 and April 2025 — every one worded "did not consistently
ensure…", and all closed. April 2023 raised none. Reference numbers are available to
anyone with a reason to check them. Records for the earlier part of the registration period
have not been examined for this document, and no claim is made about them.
MortgageQuote Canada Corp. has held ISO 9001 registration continuously since
9 May 2008, without suspension or withdrawal — BSI certificate FS 532934, in the scope stated
on it: the provision of mortgage banking and mortgage brokerage
services.
Two scopes, not one phrase, and the distinction is the registration’s to make.Brokerage arranges a mortgage between a borrower and a lender. Banking lends.
They are different activities with different obligations and different failure modes, and the
inclusion of mortgage banking in this certificate required its own audit to obtain rather than
following from the brokerage scope. Earlier editions of this document quoted the two as a
single run-on phrase, which understated what the certificate covers — the one direction in
which this register has not previously had to correct itself.
The registrar publishes the entry, so the route is named rather than left to the reader. BSI’s client directory carries certificate FS 532934 with four dates that are
BSI’s record and not ours: original registration 2008-05-09, effective date
2026-05-09, last revision 2026-04-10, expiry 2029-05-08.
The original registration date is the one that matters to this document, because it is the
registrar’s own record of the date this paper has been asserting since its first edition, and it
is the registrar who holds it. BSI client directory entry, FS 532934, read 26 September 2026.
That is a fact rather than a rate, and it is checkable in the registrar's own directory
rather than here — which makes it the most useful sentence in this document, because the
organization holding the evidence is not this one. It is also the sentence that carries the
weight: an unresolved major nonconformity costs an organization its certificate, so an
unbroken registration across eighteen years is the record speaking for itself.
And a note on what findings mean. Six nonconformities across eight
assessments is a healthy management system, not a blemished one. A system that never raises
a finding is not being audited hard enough, and a clean sheet over eighteen years would be
the result worth doubting. The findings are the system working.
The same discipline tested at regulatory scale, which is the one place in this document where the correction loop is evidenced rather than specified. In the 2012 reporting year two provincial regulators imposed administrative monetary penalties on MortgageQuote Canada Corp. for late filing of a year-end report — $1,000 in Alberta and $500 in British Columbia. Neither concerned conduct, competence, or a client. What followed is the part that carries the weight. MQCC® disclosed both, unprompted, in its own statutory return to a third regulator in another province, and recorded in that same filing that the cause had been addressed: “This year, we are not late.” The seven subsequent annual returns, each attested under the same offence provision, disclose no further penalty of any kind.
Detected by a party other than us; disclosed by us to a party that had not found it; corrected inside the cycle; and not recurring across seven attested years. That is R6, correction-loop closure, closing on a real regulatory nonconformity with registrars holding both ends of it. The signature matters more than the instance: a root-cause investigation that repairs the process rather than the output produces exactly this shape — one occurrence, then none. An organization that had corrected only the output would show the same finding again, and the record would say so, because the record is annual and the question is asked every year.
This is disclosed because it is evidence. A document arguing that inert rules are worse than failing rules cannot omit the only occasion on which its own correction loop was tested by an outside party and the amounts written down. It is also why this paper makes no claim to an unblemished regulatory record: the claim is narrower and better, which is that no nonconformity of this kind occurred twice.
3.3 What the number covers, and what it does not
Evidence boundary.
The rate measures conformity of human and reproducible machine execution within
the certified scope, assessed against ISO 9001 clause requirements across more than three
thousand applicable checkpoints over seventeen cycles. It does not extend to execution that
has not been shown reproducible under stated conditions — which, here, is every inferential
component, none of which has been pinned and tested. That is a statement about what has
been measured, not a claim that inference is inherently non-reproducible; section 1.3 sets
out the difference. Attribution across non-reproducible execution is provided by TFID®;
reproduction is not. The internal and external registers are
separate populations and are not combined here: dividing registrar findings by internal
checkpoints would be a methodological error, and we do not make it.
The question a careful reader asks next, asked here first. The internal
audit recorded zero nonconformities in most cycles from 2016 onward, while the registrar
raised one in six of those same years. If the internal audit found nothing in the years the
registrar found something, how effective is the internal audit?
Part of the answer is that they sample different frames. The registrar's six findings all
concern management-system governance — quality objectives, management review agenda, risk
scoring, planning, external provider control. The internal checklist walks clause conformity
across operating processes. Neither is designed to duplicate the other.
The other part is less comfortable and we state it anyway: a self-assessment returning a
single nonconformity across eleven years and thousands of checkpoints may be under-probing,
and the near-3% recorded in the earlier era is the more believable figure. Our reading is that both
are partly true. The internal audit programme is being reviewed on that basis, and the
review’s outcome is recorded whichever way it goes.
One correction of record. The internal defect register — a separate
system from the audit checklist — records severity as Major and Minor
using MQCC®'s own internal definitions, in which Major means a system breakdown or
repeat human-factor issue. That is not an ISO major nonconformity, and the collision of
terms is a defect in our own vocabulary. It is being renamed. Two conflicting 2023 figures
exist in that register and are being reconciled; the reconciliation will be recorded rather
than overwritten.
3.4 One assessment, end to end — a worked illustration
Read this as specified, not as audited. It is a constructed
illustration and not a case from the register. An earlier edition of this
subsection presented these nine steps as an assessment run on a real finding from 3.2.
That was wrong, and it was wrong in the way this document exists to prevent: the steps
are a specification, and marking a specification as a record is the error the two evidence
axes are there to stop. It is corrected here and recorded at 11.7. The unit, the clause
and the control below are chosen to show the shape of a determination. Nothing in
this subsection is evidence about MQCC®'s operating record; section 3.1 and 3.2 carry
that, and 3.3 states that the registrar's six findings all concern management-system
governance rather than a control of the kind illustrated here.
Everything above this point describes a method. This subsection runs the method once, on
a constructed case, so that a reader can see the shape of a determination rather than a
description of one. It is the shortest section in the document and the one most worth
arguing with.
Step
Content
Evidence status
1. Requirement
ISO 9001:2015, clause 8.5.1 — control of provision of services, including
implementation of monitoring at appropriate stages to verify that criteria for
control of processes have been met. A published external requirement, not ours.
Public. The standard is purchasable; the clause text is not
reproduced here.
2. Bounded unit
One file-stage transition inside the certified scope: the point at which a
brokerage file moves from underwriting to instruction, where a defined check must be
recorded before the transition completes. This is a conformity quantum in the sense
of 1.1 — the smallest element here whose conformity can be determined without
reference to the rest of the file.
Specified. The boundary is ours; it is a choice, and a different
analyst could bound it differently.
3. Failure scenario
The transition completes with the check unrecorded. Not the check was wrong
— that is a different unit — but the transition did not require the record.
Risk class R6.
Stated as an event, which is what makes it testable.
4. Control
A reproducible gate: the transition is blocked unless the check record exists and
carries origin, authority, scope and time. Executed by machine, under pinned
conditions, with no inference in the path.
Specified. A control of this shape is describable and buildable;
no such gate is offered here as operating.
5. Test
Registrar sampling at surveillance assessment: select transitions, verify the record
exists and is complete. Pass condition set before the sample is drawn — every
sampled transition carries a complete record.
Specified. No sample has been drawn. The requirement that the pass
condition be fixed before the sample is the point of the step; an independent sampler
is what would make the result evidence, and none has sampled this.
6. Finding
Failed. The determination that matters is not the control was
absent but the control was not uniformly enforced at the boundary —
which is a different corrective action from the first, and the reason the finding
must name the unit rather than the theme.
Specified. A constructed outcome, chosen because a failure
exercises the method and a pass does not.
7. Correction
The corrective action addresses the enforcement gap at the unit, not the theme: the
transition path that bypassed the gate is closed, and the closure is verified against
the same condition that failed.
Specified.
8. Retest
Re-run against the original failure condition, not against the process area
in general. This distinction is the one most often lost in practice: a later
assessment that samples the same area and raises nothing is not
evidence that the specific failure condition was retested. The retest record must
state what was checked, against which condition, on what date.
Specified. The requirement is stated; no such retest record is
offered here.
9. Residual uncertainty
What this does not establish, stated at the same length as what it does: a
sample is not a census, so the closure evidences the sampled transitions and not
every transition; a control that holds at human tempo has not thereby been shown to
hold at machine tempo, which is the whole argument of 1.5; the unit was bounded by
us, and a gate that reliably requires a record says nothing about whether the
recorded check was correct; and the interaction between this unit and adjacent units
— a correct record at a boundary that is itself mis-sequenced — is not tested by
this determination at all.
Unmeasured.
Why a failure and not a flattering case. The method's value is not that
the gate held — it did not — but that the failure landed on a bounded unit, was attributable
to it, was correctable at it, and was retestable against the specific condition that failed.
A method that only produces passes is not an assessment method.
What would convert this subsection from specified to
audited: one of the six findings at 3.2, run through the same nine steps, carrying
the assessment report reference, the assessment date, the finding number, a faithful redacted
extract of the finding text, the corrective-action and effectiveness-verification references,
and a statement of whether the quantum-conformity frame was applied at the time or
retrospectively. That is a disclosure of findings, not of method.
3.5 Claim-to-evidence register
"Available on request" is a weak sentence in a document about evidence. This register
says, for each load-bearing claim, what the evidence is, who holds it, and how a reader gets
to it.
Claim
Evidence
Held by
How to reach it
ISO 9001 registration held continuously since 9 May 2008, without suspension or
withdrawal
Certificate and registration entry
The registrar
Independently checkable. The registrar is BSI Group
and the certificate is FS 532934, in the scope stated on it: the
provision of mortgage banking and mortgage brokerage services — two distinct
certified activities. BSI publishes the entry in its client directory with the
original registration date, the effective and last-revision dates and the expiry
date: FS 532934. Do not take this document's word for it; this is
the one claim here that does not depend on us at all.
Six external nonconformities, May 2018 to April 2025, all closed
Reference numbers are printed here so a reader can cite them to the registrar
directly. Copies released on written request, redacted for client-identifying
content only.
More than three thousand applicable checkpoints, seventeen cycles, nonconformity
rate under 0.5%
Internal audit register, 2011–2026
MQCC® only
Not independently verified. This is the weakest link in the
document's strongest claim, and it is stated plainly rather than buried: the
denominator is ours, the counting rule is ours, and no external party has audited
the register itself. Released on written request with the counting rule attached so
the arithmetic can be re-run.
No errors-and-omissions loss paid on MortgageQuote Canada Corp.'s cover for
mortgage brokerage and lending since that brokerage was licensed in September 2006;
one claim made, unsuccessful
Eight Ontario Annual Information Returns, reporting years 2012–2019, each
answering the regulator's questions on claims made and claims paid under the
principal broker's statutory attestation; successive insurer applications signed
under a policy-voiding warranty; and a loss-run confirmation from the underwriter
dated 22 February 2022 covering the period from 1 April 2017
Split, and the split is the point — the returns sit in the
regulator's file, the loss run is the carrier's
Partly independent. The returns and the applications are MQCC®'s
own statements, made under an offence provision and a policy-voiding warranty
respectively: stronger than an assurance, weaker than a third party's.
The loss run is not ours. A reader with standing asks the carrier
for a current loss run, which is the instrument underwriters use for this exact
question. Copies of the returns released on written request; the figures for the
2012 administrative penalties described at 3.2 are in them.
The worked illustration at 3.4
None. It is a constructed illustration, not a case.
—
Nothing is held against it and nothing can be requested. This row
exists so that the absence is stated rather than inferred. What would create a record
here is set out at the foot of 3.4.
Public introduction, 1 May 2019
Dated public post with third-party platform timestamp
The platform
Publicly visible on the platform.The post
carries an embedded third-party record of the original announcement, which is the
artifact the date rests on.
Trademark registrations and dates
USPTO records
USPTO
Independently checkable. Direct records:
Reg. 7,160,072
(BLOCK/CHAIN, classes 035/036/042/045) and
Reg. 8,430,351
(AIQMSS®, class 041). Also
Reg. 6,123,500
(PI-FI®, class 042), cited at section 12. TSDR returns the complete prosecution file
for each, including every disclaimer and every maintenance filing.
Dictionary filings
Collins English Dictionary submission records
Collins; copies held by MQCC®
Filing dates given in section 1. A filing is a filing: it establishes the date and
wording of a submission, and nothing about acceptance.
Every control marked specified in section 9
Dated written specifications
MQCC® only
No verified operating measurement is presented here. Specifications released under NDA. The eight control tests listed at section 11.3 are what would change this, and this paper
presents no verified result set for them.
Four access arrangements, so that nothing here promises more than it should.
Three of them release a document; the fourth releases nothing and is an examination.
Public — the registration, the USPTO records and the 1 May 2019 post:
checkable by anyone, with no request needed and no involvement by us.
Redacted on request — the external assessment reports, the internal
audit register with its counting rule, and the annual information returns carrying the
claims and penalty answers: released in writing, client-identifying content
removed. The carrier's loss run is not ours to release and is obtained from the carrier. Confidential assessment — the control specifications: examined
under agreement by an assessor, at the level of what a conforming implementation must achieve
and how achievement is evidenced. Observation under agreement — an assessor
may examine the operating system and its records to verify that a claimed
architectural property holds: that a gate is present and refuses what it is specified to
refuse, that authority is constituted before action, that records carry what they are
required to carry. This is the ordinary practice of management-system auditing under
ISO/IEC 17021-1, where an auditor establishes that a control operates without ever receiving
the code, algorithms or internal structures behind it. It is the route by which an
architecture claim in this document becomes independently verified, and it is open.
No tier releases implementation, and the tier stated for a row is the tier that row
actually sits in. Instruction in the method itself — being taught how it is done rather than
shown that it works — sits outside all four tiers and is available to licensees and
consulting clients under agreement. That is a commercial arrangement, not a verification
route, and it is named here only so the two are not confused: a reader checking a claim uses
the tiers; a reader wanting the capability takes a licence.
How access is handled. Correspondence on any row above goes to
ceo@mqcc.org, a monitored address, and is answered in writing. The redaction rule is the same in every row: client-identifying content
out, requirement, finding and disposition in. It is applied by us, which is itself a
limitation a reader should weigh, and a requester who believes a redaction removed something
material should say so in writing and will get a written answer.
Two rows above depend on the specifications rather than the records, and it
is worth being exact about what is released. Requirements are released; implementations are
not. A reader who asks for a control specification receives what a conforming implementation
must achieve and how the achievement is evidenced, not how MQCC® achieves it. That boundary
is the same one at 1.2.1 and 9.8, and it is not negotiable on a per-request basis.
To engage. Correspondence goes to ceo@mqcc.org, a monitored address, answered in writing. The address above is for verifying what is written here; this one is for engaging the organization that wrote it. Section 12.1 sets out what is available and section 9.6 what it is pointed at. The Services Brochure is complimentary on request; every other step, including scoping, is a paid engagement, and price follows the requirements of the organization’s scope of operations rather than a published rate.
Section 4: Thirteen public concerns, answered
Through September 2026, heads of state, legislators, regulators, analysts,
underwriters and the AI laboratories themselves each put a specific concern on the
public record. Below, each one is answered with a specific, named control. Transparency
forges trust, so the honest marks travel with the answers.
4.1 Attribution notice
Please read before the table.
No person or organization named below has been contacted about this document, has
reviewed it, or endorses MQCC® Bungay in any way. Each entry quotes or summarizes a
public statement and answers it. Their statements are theirs; the responses, and every
claim about what has and has not been proven, are ours alone.
4.2 How to read the last two columns
They answer different questions and
neither stands in for the other. Level asks whether the control
has been measured. Scale asks where it has been
operated, what its failure would have cost, and who else had capital at stake. A
control can be "designed" on the first axis and "underwritten" on the second. Both are
true at once, and reporting only one of them misstates the position in whichever
direction happens to flatter.
4.3 Thirteen public statements, thirteen answers
Who, and when
The concern, as publicly stated
MQCC® Bungay response
Level
Scale of validation
His Majesty King Charles III AI Summit, Dumfries House,
17 Sep 2026
That AI should remain under human control and in the service of people,
communities and the natural world. No binding commitments were announced.
SENTIENT AI IS™ — human verification at every boundary between AI
processing and external action. H-GMOS™ brand of human governance layer names the human-side
governance, management and operations layer, so a specific person holds the
authority rather than a policy holding it in the abstract.
Designed. The human authority layer beneath it is proven within the ISO 9001
scope.
Audited — the human authority layer sits inside the certified scope. None for the
AI-boundary control itself.
Rep. Sam Liccardo and Rep. George Whitesides reported
14 Sep 2026
Urging Congress to remain in session until AI safety legislation passes; the same
reporting describes disagreement among congressional leaders. Evidence of pressure
for action, not of an enacted requirement.
REGULATOS™ brand of rule-activation service — activates the rules applicable to the selected
sector, jurisdiction and process. An organization does not have to wait for one
national statute to know which requirements bind it today.
Designed as a general service. Operating in this business across four provincial
regulators.
Regulated — operating across four provincial regulators.
California Legislature and Governor SB 813 and AB 1405 signed
9 Sep 2026
An AI audit profession: criteria for independent verification organizations by
1 Jan 2028, a registry from 1 Jan 2029, compensation that may not depend on
findings, and no auditing of a system you materially designed.
IOC™ / IOCAA™ — a two-tier auditor structure: ISO/IEC 17021 for
general verification, IOCAA™ for MQCC®-specific systems. Written before the statute.
Section 10 now scopes IOCAA™ as MQCC®'s own scheme, attested without accreditation — the
third route at section 2 — and states the clause — ISO/IEC 17021-1 cl. 5.2.5 — that makes an advisory practice and an accredited
certification arm incompatible as one operation. Accreditation is declined here as a scope
decision, not asserted to be foreclosed everywhere under common ownership.
IOCAA™ criteria in development, with a commitment to publish before requiring them.
Accreditation neither held nor sought. An IOCAA™ assessment is assessment against a
published scheme, attested by a body without accreditation — the third route at section 2.
None — criteria not published, and no accreditation claimed.
Microsoft AI code-of-conduct consultation, 14 Sep 2026
Control rules for its MAI models: staying within authorized scope, keeping
auditable action traces, and never resisting interruption or shutdown. Open for
public comment.
Bungay Tri-Phase Cascade™ brand of governance sequence model — CONSTITUTIVE™ → EXECUTORIAL™ →
GOVERNOMIC™: constitute the authority before anything acts, execute only within it,
then govern the governing. SUPERVISOS™ brand of operational supervision service supervises live governance,
management and operations and delegated duties.
Cascade designed. Supervision proven for human and conventional work within scope;
not yet measured at machine speed.
Audited for human and conventional work within scope. None at machine speed.
OpenAI model misalignment reporting framework, 16 Sep 2026
Six first reports of models acting without authorization, coordinating with other
models or evading oversight. OpenAI states these are individual instances and not a
measure of frequency.
INVESTIGATOS™ brand of investigation and audit service — threshold-triggered investigation or scheduled
audit, involving human expertise when required. CRASES™ brand of corrective-action case service opens the
case, contains the error, assigns responsibility, corrects the cause and verifies
the result. Each nonconformity is logged by origin — person or machine — so one log
answers both.
Corrective action proven at the human layer within scope. Machine-origin tagging
being instrumented.
Audited at the human layer. None for machine-origin tagging.
European Commission week of 17 Sep 2026
Confirmation of receipt of an agent-containment incident filing. That is what the
source establishes, and no more. An acknowledgment of receipt is not a
determination that the event was reportable, and does not by itself establish a
cross-border disclosure obligation: the applicable legal provision, its conditions and any
substantive regulatory determination are separate questions this paper does not answer.
The Commission's 2025 draft consultation on serious-incident guidance and reporting
templates is the relevant instrument to read, and it is a draft — the applicable legal text
and any final guidance govern.
PDICR™ brand of corrective-action loop — prevention, detection, identification, correction and
reporting, with reporting as a named stage of the loop rather than an
afterthought. Filing consequential reports to financial regulators on the day of
detection is existing operating practice here, not a new capability.
Operating as a regulatory reporting practice. The AI-incident application of it is
designed.
Regulated — consequential reporting to financial regulators is existing practice.
None for the AI-incident application.
Gartner Shiva Varma, Senior Director Analyst, 26 May 2026
"Agents operate at different autonomy levels and across different trust boundaries.
When the same controls are applied indiscriminately, organizations encounter two
common failure modes" — over-restriction driving shadow development, or
under-restriction raising operational, security and compliance risk. Forecast: 40%
of enterprises demote or decommission agents by 2027.
S.A.I.F.E.R.™ brand of multi-agent federation service — multiple substrates governed under one accountable
human Governor, each with recorded identity, task, authority, permitted tools and
delegation limits. FEDERATOS™ brand of federation service reads the disparate inputs;
INFRASTRUCTOS™ brand of infrastructure control service sets infrastructure requirements, suitability,
access and audit readiness. Proportional by construction, because authority is
recorded per agent rather than per platform.
Designed.
None.
W. Robert Berkley W. R. Berkley Corporation — exclusion
documented since at least 28 May 2025; CEO remarks from Q4 2025 earnings,
restated in reporting 18 Sep 2026
That underwriters need to understand the impact new technologies are having and
their ability to "control it, select it, and price for it." The company excludes
"any actual or alleged use, deployment, or development of Artificial Intelligence"
across D&O, E&O and fiduciary lines — and the exclusion reaches AI
governance failures and disclosures, not only AI outputs.
AIQMSS® — Advance Intelligence Quality Managed Safety Systems, and
the operating evidence set beneath it: audits passed, nonconformities raised and
closed, detection and correction latency, work items reviewed by an accountable
person before release, years insured with claims history. What answers an
underwriter is a file, not an assurance.
Operating evidence proven within scope. AI-specific test results not yet
produced.
Underwritten within the certified scope. None for AI-specific results. Whether an
AI exclusion attaches at our own renewal is the open question of this article.
NSA, CISA and FBI joint advisory, 8 Sep 2026
Industrial-scale model distillation identified as a national model-IP threat, with
anomalous API usage detection named as an enforcement priority.
TFID® — Trust-Feed Identifier: origin, authority, scope and time
bound to each record, so that use beyond authority is detectable as a conformity
failure and not only as a traffic anomaly. SCROLL™ brand of controlled-records service retains the
canonical record with its correction history.
Designed.
None.
Anthropic Threat Intelligence Report, 10 Sep 2026
Disrupted AI misuse from December 2025 to August 2026 across seven named harm areas:
cyber operations, surveillance, influence operations, scams and fraud, biological
misuse, conventional weapons and illicit distillation. The report separates autonomy from
severity: "autonomy and harm are separate axes", and
"several of the most serious compromises we report here came from operations where a
human directed every step."Report,
dated from the
publication index.
HALLUCIVAX™, HALLUCIDETECT™,
HALLUCICORRECT™ brands of AI nonconformity prevention,
detection and correction services — prevention, detection and correction of
AI-generated nonconformity inside a certified quality-management system, rather than
at the model boundary alone. MQCC®'s observation, stated as its own interpretation and not as the report's
language: accurate execution and human authorization are not, by themselves,
sufficient conditions for safety. Accuracy still matters; it does not resolve harmful
objectives, impermissible actions or misuse. The assessment must also determine whether the
intended action satisfies applicable requirements, remains within permitted tools and
delegation limits, and is subject to effective supervision, intervention and reporting.
The same distinction is drawn independently, and earlier, by a dated
specification:OpenAI's Model
Spec of 11 April 2025 separates harmful instructions — where an assistant
"might cause harm by simply following user or developer instructions" — from
misaligned goals and from execution errors. That is OpenAI's stated risk distinction, cited
as such and not as anything Anthropic's report says. Of the controls in this table, the ones
that bear on it are authority constituted before action
(SENTIENT AI IS™, H-GMOS™) and investigation and
reporting (INVESTIGATOS™, PDICR™). Permitted
tools and delegation limits are a requirement stated here without a control named against
it — section 9.5 admits the relevant mark at Tier 3 and bars describing it further
until a reconciliation question is answered, and a Tier 3 mark identifies a source, not a
capability. Naming it here would have been a capability claim the tier does not carry.
Nothing in this entry changes any evidence mark.
Designed. The corrective-action machinery it plugs into is proven at the human
layer.
None. The corrective-action machinery it plugs into is audited.
Sam Altman, OpenAI UN Security Council remarks,
23 Sep 2026
Four themes selected here, not a summary of the speech. That systems
"reliably remain under human control." A mechanism for "complementary national
and international frontier AI standards", including standards for measuring
capabilities and assessing risks. Common standards "so countries can compare evidence,
verify compliance, and have a shared language." And "accurate and speedy incident
reporting, classification and reporting protocols." The speech also asks for secure
channels for sharing emerging vulnerabilities and threats among governments,
critical-infrastructure operators and technical experts. This paper does not map
that request, and the four below are a selection rather than an exhaustive account.
He also said no person, company or country should impose its worldview through the most
powerful models, and that the most important decisions "must be shaped through
democratic processes."Source.
Human control:SENTIENT AI IS™ specifies human
verification at every boundary between AI processing and external action;
H-GMOS™ names the person who holds the authority rather than leaving it
with a policy. Naming an accountable person and specifying approval boundaries is
control design. Whether intervention is effective, enforced and performant under load is a
question for testing.Comparable evidence:TFID®
binds origin, authority, scope and time to each record and SCROLL™ retains
the canonical record with its correction history. That supports traceability.
Comparability additionally requires shared definitions, assessment conditions, criteria and
reporting formats, which no single organization supplies.Incident classification and reporting:INVESTIGATOS™,
CRASES™ and PDICR™ carry investigation, correction and
reporting. A reporting and correction process is not by itself a classification scheme.
The classification rules and reporting fields MQCC® would apply are those of the OECD
frameworkTowards
a common reporting framework for AI incidents(February 2025, 29 reporting
criteria), read alongsideOpenAI's
misalignment reporting framework(16 September 2026) for its separation of
qualifying event, investigation track and disclosure — a framework which states in terms
that it "does not replace our legal disclosure requirements."Common standards:Quantum Conformity™ composes
determinations over requirements of any origin, which is what lets one assessment answer to
a statute, an insurer and a standard at once. That is an assessment approach. It does
not establish international agreement on the requirements themselves, or recognition of
them.What this row does not establish. These are MQCC®'s organizational-level
response mappings, not a claim that international standards, interoperable evidence, secure
cross-border disclosure arrangements or effective machine-speed control have been
established by this entry. Concentrated power and international democratic oversight are not
resolved by organizational controls alone; they belong to public deliberation, and this
document does not claim otherwise.
Designed. The human authority layer beneath it is proven within the ISO 9001 scope.
None for the AI-boundary controls. Audited for the human authority layer, within the
certified scope.
NIST SP 1353 initial public draft, 19 Aug 2026; comments close
15 Oct 2026
Seeking public comment on using artificial intelligence for Cybersecurity Framework
analysis and reporting.
Not a concern to answer but a door that is open. Our structural proposal — a
governing method layer, separation of governance, management and operations,
quality-management integration, four-quadrant scope and structurally embedded AI
governance — is drafted and will be filed to that docket before it closes.
Action, dated.
Not applicable — a dated action, not a control.
Bill Gates NBC Meet the Press, interview with Kristen
Welker; clip released 25 Sep 2026, broadcast 27 Sep 2026
That “AI is certainly powerful enough to drive events that, you know, cause a
billion deaths”, and that “there’s never been a weapon as powerful as the
combination of people with ill intent using the latest AI tools.” On remedy:
“No one thinks self-regulation is enough”, legislation is
“absolutely” needed, and law enforcement and politicians must join the
discussion of “what safeguards and monitoring look like.”A capability claim, not a prediction — the distinction is held at
section 5 and is not incidental.
The claim states no unit, no conditions and no acceptance criterion,
which is the defect this section is about rather than a fault of the speaker. What
answers it is the composition rule at 1.2.1 — a bounded unit, the requirements binding
it, a test with its protocol and threshold fixed before the run — and the eight tests
at 11.3, of which 1 authority-boundary enforcement and
2 stop-propagation latency are the two an ill-intent scenario turns
on. REGULATOS™ activates the requirements that bind a given sector
and jurisdiction today, which is the part of the remedy that does not wait for a
statute. Instruction in the method is offered under TRUSTED BY BILLIONS®,
Reg. 6,615,228, Class 041 — education and training, which is what that registration
reaches and the whole of what it proves.
Specified. The governance layer beneath it is proven within the ISO 9001 scope; the
machine-speed tests are not.
Audited for the human and reproducible-machine layer inside the certified scope.
None at the scale the statement names, and none is asserted — a
billion-scale claim is answered by measurement, and 11.3 presents no verified result
set.
Table scrolls horizontally on narrow screens. The table contains thirteen
public-statement entries. Evidence status is specific to each control and each
application; the entries do not divide into validated and unvalidated AI responses, and a
fraction would imply a cleaner split than the rows support — they mix proposed controls, scoped
operating practice, assessment criteria still in development and one planned submission. This paper presents no verified result set for the eight AI-control tests at section 11.3.
Section 5: This is no longer a forecast. There is already a stopwatch on it.
On 25 September 2026 the concern acquired its largest number. Bill Gates, in an interview with Kristen Welker released by NBC News that Friday and broadcast on Meet the Press on Sunday 27 September 2026, said: “AI is certainly powerful enough to drive events that, you know, cause a billion deaths.” He added that “there’s never been a weapon as powerful as the combination of people with ill intent using the latest AI tools.” On the remedy he was equally direct: “No one thinks self-regulation is enough”; there “absolutely” needs to be legislation; and “you need law enforcement and the politicians to get into the discussion about what safeguards and monitoring look like.”
What he said, and what he did not say, because the difference is the whole of it. That is a statement about capability. Powerful enough to is not will. Several outlets reported it as a forecast that a billion people are going to be killed, and that is a different claim carrying a different burden of proof; the two outlets whose wording was checked against each other for this paper both state expressly that he framed a capability rather than a prediction. This document quotes the capability form, and disputes nothing about it. A reader who wants to know why that matters here has the answer in the sentence itself.
Because a capability claim carries the same defect section 4 is about.Powerful enough to drive events that cause a billion deaths states no unit, no conditions and no acceptance criterion. Nothing in it can be tested, so nothing in it can be closed — not by the person who said it, and not by anyone who would rather it were false. That is not a criticism of the speaker. It is the measurement problem this document opens on, now stated by the most widely heard voice yet to state it, and the reason a number that large should be met with a unit rather than with a louder number.
A pathway exists, and this is the narrow form of that statement. The remedy Gates names — legislation, safeguards, monitoring, and something more than self-regulation — describes a conformity problem, and conformity problems have an established answer that is neither speculative nor new: a stated requirement; a control pointed at it; a test with a protocol and an acceptance criterion fixed before the run; a record that survives the event; and attestation by a party other than the one making the claim. That machinery has been operated here continuously since 9 May 2008 under a third-party-audited registration, inside a licensed and underwritten business — MortgageQuote Canada Corp., whose cover for mortgage brokerage and lending carries the paid-loss record at section 6.1. What is claimed is that the pathway is available, specified, and in part already evidenced. What is not claimed is that it has been walked to its end: the eight control tests at 11.3 carry no verified result set, and a claim at the scale of a billion is answered by measurement rather than by architecture. Saying a pathway exists is not saying the walk is finished.
The mark, stated at legal precision, which is the only precision a mark supplies. Instruction and training in this method are offered under TRUSTED BY BILLIONS® — USPTO Registration 6,615,228, owner MQCC Bungay International LLC, Class 041, filed 29 March 2021, registered 11 January 2022, first use in commerce 29 March 2021, on a recitation of educational services much of which names conformity science expressly. Reg. 6,615,228. A registration identifies the source of a service. It is not a control, not a measurement, and not evidence that the pathway works. The mark names the teaching — the act of telling the world that a pathway exists, which is what Class 041 reaches — while the pathway’s own evidence stays where it was: the four layers at 6.1, and the mark carried by every control in section 9. Neither stands in for the other. The name of a thing has never been proof of the thing, and a document that argued otherwise would forfeit the discipline that makes the rest of it worth reading.
Most writing about AI governance argues about what the law should require. Two
US statutes have settled it, and both are in the books now.
Why these two, and on what footing. None of the three entities named at
section 2.2 is formed or headquartered in California, and neither statute is cited as a current
obligation of any of them. They are cited because they are the first published criteria of their
kind, and a specification meant to be tested should be built against published criteria rather
than against anticipated ones. Whether either statute binds a given engagement depends on where
the client is, and that is settled per engagement rather than asserted here.
California SB 53, the Transparency in Frontier Artificial Intelligence
Act, has been in force since 1 January 2026. It requires critical safety incidents to be
reported to the Office of Emergency Services within 15 days, or
within 24 hours where there is imminent risk of death or serious physical
injury. Two of the reportable categories deserve to be read twice: loss of control of a
frontier model causing death or bodily injury, and a model that "uses deceptive techniques
against the frontier developer to subvert the controls or monitoring of its frontier
developer." Civil penalty up to $1,000,000 per violation.
New York's RAISE Act — S6953 of 2025, as amended by S8828,
which moved the effective date to 1 January 2027 — requires safety incidents,
expressly including autonomous model behaviour beyond user requests and critical
control failures, to be reported within 72 hours. Two features of the
amended text matter for anyone building to it. The clock runs from the point at which the
developer knows or has reason to believe an incident has occurred, which is a
reasonable-belief trigger rather than a certainty trigger — it starts earlier than an
organization used to closing investigations before reporting will expect. And where an
incident presents an imminent risk of death or serious physical injury, the
report is due within 24 hours, matching California's imminent-danger tier.
Here is the problem those two statutes create — and it is two problems, which
this document previously ran together. A reporting deadline is a
reporting latency requirement: elapsed time from the trigger to a filed report.
Stop-propagation latency is a different measurement: elapsed time from a stop command to the
last effect of the system it was issued against. Neither substitutes for the other, and a
statute that sets the first does not thereby set a performance requirement for the second.
Both must be measured and reported separately. What connects them is practical rather than
legal: to certify that you met a 15-day clock, a 72-hour clock or a 24-hour clock, you have
to know how long it takes your organization to detect an autonomous action, stop it,
and establish what it did. We reviewed the published safety frameworks of OpenAI, Google
DeepMind, Meta and xAI. All four now name loss of control as a tracked risk domain.
None of them publishes a measured stop-propagation latency.
That is the gap test 2 is built to close: issue a system-wide stop while
actions are queued, running and retrying, and report the exact elapsed time from command
to last effect, together with a count of any action that completed after the stop.
It is a number, not a posture. And it is the number a compliance officer needs before
signing anything that mentions a deadline.
We will say plainly what follows from that: this paper presents no such measurement of our own.
It is test 2 on the programme at section 11.3 — the numbering there runs in
risk-class order, and stop-propagation latency answers R2 — and when it is run on our own
deployment its result is a development record of our own product. It is not a condition on the
work we do for a client, whose scope, requirements and acceptance criteria are set in the
engagement.
Section 6: Validation at consequence scale
Here is the second axis, stated as a definition rather than a slogan.
Bungay Validation at Consequence Scale (BVCS™) — n. A
validation state in which a control has been operated continuously in an environment
where its failure carries realized commercial, regulatory, indemnity and licensing
consequence, and in which that operation has been independently sustained across four
nested layers, each involving a third party that commits something of its own.
Distinguished from velocity validation, which measures whether a control
sustains a given decision rate. The two are orthogonal: neither substitutes for the
other, and a control may hold one and not the other.
6.1 The four layers
Commercialized — real counterparties and real capital exposed to its
failure, continuously since 14 August 2001.
Regulated — licensing authorities holding suspension power reviewed
the operation and permitted it to continue.
Audited — an accredited registrar has sampled it on a surveillance
cycle and maintained the certification since 9 May 2008.
Underwritten — an insurer priced the risk of its failure and issued
the policy.
The fourth layer is the one that is hard to acquire and easy to check. An underwriter
issuing errors-and-omissions coverage against a control is a market participant
committing its own capital to a prediction that the control holds. It is a different kind
of evidence from an internal test, a red-team report or a published framework, because
the party making the prediction loses money if it is wrong. As far as we can determine,
no AI governance framework published between 2023 and 2026 carries a layer-4 validation
of any kind.
And this layer has a result attached, which the other three do not. Licensed, registered and insured are three statements that somebody else allowed the operation to proceed. No loss has been paid on MortgageQuote Canada Corp.’s errors-and-omissions cover for mortgage brokerage and lending since that brokerage was licensed in September 2006 — one claim made in that period, unsuccessful, no indemnity paid. That is the difference between an underwriter’s prediction and the same underwriter’s experience, and the experience is the one a reader should weigh. The attesting instruments, and which of them are ours and which are the carrier’s, are set out at 3.5. It remains evidence about the practice: it does not reach the runtime performance of any machine-speed control, and 11.3 is where that would be measured.
6.2 The claim, in its only form
No artificial-intelligence governance framework published between 2023 and 2026 has been
operated inside a licensed financial institution, under a third-party-audited ISO 9001
registration, with errors-and-omissions coverage in force, for eighteen consecutive
years.
That is the narrow, checkable form of the claim, and it is the only form we make. The
wider claim — that machine speed is not the relevant benchmark — is not made.
Machine speed is a relevant benchmark. It is simply not the one that has been tested
here.
Section 7: How both agents are trained to the same standard
The MQCC® Bungay suite of processes, standards and technology trains human agents and
machine agents against the same international consensus standards. The chain has four
links, each resting on a published instrument rather than on assertion.
7.1 Link 1 — the obligation
ISO 9001:2015 clause 7.2 requires an organization to determine the competence
necessary for persons doing work that affects the performance and effectiveness of the
quality management system, to ensure that competence, to act where it is lacking, and to
retain documented information as evidence of it. Clause 7.1.6 applies the same
discipline to organizational knowledge. Neither clause is aspirational: both are audited
on the surveillance cycle.
7.2 Link 2 — agent-neutrality
Clause 7.2 is scoped to the work that affects conformity, not to the nature of the
worker. Where an algorithm performs work that affects conformity, the competence
obligation attaches to the algorithm. We state this as an interpretation of the
clause, not as settled practice. No accreditation body has published a position on it.
The interpretation is testable, and it is put forward here in order to be tested.
7.3 Link 3 — the competency information model
ISO/IEC 22602:2019, Information technology — Learning, education and training —
Competency models expressed in MLR, published by ISO/IEC JTC 1/SC 36, specifies the
description of entities dealing with competencies, competency description, competency
evaluation, and the operations performed on competencies. Its Introduction records that
MLR supports "structured database, linked data and RDF models," and that it can describe
competency objects in systems of heterogeneous form, "among which are included those
proposed in ISO/IEC 20006-1 and ISO/IEC 20006-2." Annex B is a mapping of the ISO/IEC
20006 models. BSI has adopted it as BS ISO/IEC 22602:2019 (31 October 2019, current);
CSA has adopted it as CSA ISO/IEC 22602:2020. ISO/IEC 20006-1:2014 and ISO/IEC
20006-2:2015 remain first edition, reviewed and confirmed on 2 October 2025, and supply
the competency general framework and the proficiency level model that 22602 maps.
7.4 Link 4 — the validation standard
The competence claim that results is then tested, and the test applied is validation
at consequence scale, as defined in section 6. That covers whether the work conformed.
It does not cover how well a trained reviewer detects a nonconformity under a real workload and
a real clock, which is a different property of the same control and is measured by
test 7, seeded-error detection under load, at section 11.3. Section 7 trains both
agents to the same standard; 11.3 is where the human agent’s competence claim is measured
rather than documented, and until that test is run the reviewer carries specified for
detection performance.
One instance of that validation exists, and it was not conducted by us. In the course of the third-party claim described at 3.5, a law society in Canada examined this organization’s work, the claim against MQCC® did not succeed, and the same law society then asked the principal broker to serve as a witness in the defence of one of its own lawyers. An adversarial professional body tested the competence claim and then relied on it. That is validation at consequence scale performed by an outside party with no reason to flatter us, and it is the strongest single item of competence evidence this organization holds. It is also narrow, and the limits are part of the claim: it speaks to professional competence inside the certified scope, at the pace of litigation. It does not measure detection performance under production load, which is test 7. It does not transfer to the machine agent. And it is one instance, which is a record rather than a rate.
7.5 The defence baseline, stated precisely
ISO 9001:2015 is not a parallel track to defence quality assurance; it is the floor on
which defence quality assurance is built. NATO standard AQAP-2110, Edition D Version 1
(June 2016), establishes at Chapter 4 the applicability of the requirements of
ISO 9001:2015, and at Chapter 5 adds NATO-specific requirements for the supplier; a
supplier must establish a system "in accordance with this publication which includes the
requirements of ISO 9001:2015." The United States, Canada and the United Kingdom are
NATO members and procure against AQAP.
What is not claimed.
MQCC® Bungay does not hold AQAP certification, is not a defence supplier, and holds
and seeks no defence contract. The point is narrower and checkable: the quality
management standard to which we have been registered since 2008 is the same standard
that defence procurement supplements rather than replaces.
Section 8: Why a standard is the instrument, and the gap the standards system carried forward
8.1 Why a standard is the instrument at all — three governments answered that before AI was the question
This paper argues that is the system safe? supplies no unit and that conformity assessment supplies one. The fair objection is says who? — why should a buyer accept a management-system standard as the instrument rather than some other thing. The answer is not ours. Three governments bound themselves to it in published instruments, and they did so before artificial intelligence was the question being asked.
Jurisdiction
Instrument
What it establishes
United States
National Technology Transfer and Advancement Act, Public Law
104-113, 7 March 1996; OMB Circular A-119, 1993, revised
January 2016
Federal agencies shall use technical standards developed or adopted by
voluntary consensus standards bodies to carry out policy objectives, and shall
participate in developing them. Departing from that requires a written explanation
to the Office of Management and Budget, reported annually to Congress. The
preference for consensus standards is a statutory default, not a convention.
United States
Federal Acquisition Regulation, 48 CFR ch. 1, §§ 46.202-4 and
46.203, issued by GSA, DOD and NASA
Names ISO 9001 explicitly as an example of the higher-level
quality standards that agencies must require for complex or critical
items, and requires agencies to establish procedures for determining the risk of
nonconformance. The two definitions are at 8.1.1 and they are the reason this row
matters more than the others.
Canada
Cabinet Directive on Regulation, Treasury Board, 13 July 2018;
the Standards Council of Canada; DAOD 3009-0, 3009-1 and
3009-2
Federal regulatory policy is built on voluntary consensus standards; the Standards
Council accredits the bodies that certify ISO 9001 management systems; and the
Defence Administrative Orders set quality of materiel, quality management and
Government Quality Assurance as directed obligations rather than preferences.
United Kingdom
Royal Charter of 22 April 1929, with supplemental charters of
1931, 1968 and 1974; the Memorandum of Understanding between HM
Government and BSI; JSP 940 and Def Stan 05-061
BSI is constituted by Charter to set and sell standards of quality for goods,
services and management systems, and is recognised by the Government under the MoU
as the United Kingdom’s National Standards Body. The Ministry of Defence
builds its quality policy on that base and its concession standard cites
BS EN ISO 9000 normatively.
What is not claimed, and it is the same boundary as 7.5.
None of these instruments names MQCC®, assesses MQCC®, endorses MQCC®, or confers
anything on MQCC®. MQCC® holds no government contract, is not a supplier to any of the
agencies named, and seeks neither. What the instruments establish is the standing
of the standard, not the standing of this organization — that three governments
independently designated management-system standards as the mechanism, which answers
says who? without a single sentence of ours. Any reading in which these citations
transfer authority to MQCC® is a misreading, and it is refused here rather than left
available.
8.1.1 The definition that was written for procurement in 2005 and describes an AI system exactly
FAR 46.203 classifies a contract item by its technical description, its complexity and the criticality of its application. Complex items are defined as those having
quality characteristics, not wholly visible in the end item, for which
contractual conformance must be established progressively through precise
measurements, tests, and controls applied during purchasing, manufacturing,
performance, assembly, and functional operation.
and a critical application as one in which “the failure of the item could injure personnel or jeopardize a vital agency mission.”Neither definition mentions software, and neither was written with artificial intelligence in mind. Both are from a regulation issued in March 2005.
Read them against the object this paper is about. A system whose quality characteristics are not wholly visible in its output; whose conformance therefore cannot be established by inspecting the end item; and for which conformance must instead be built up progressively, through measurements and controls applied during performance rather than after it. That is the composition rule at 1.2.1 — bounded units, each governed against the requirements binding it, composed into a total that still shows its parts — stated by the United States government two decades early, for a different reason, about a different class of thing. The frame was not invented for AI. AI arrived at a frame that already existed, and the instruments above are where it had been waiting.
The inference runs one way and no further. That a regulation defines complex and critical items in terms that fit an AI system does not make an AI system a contract item, does not bring any AI system within the FAR, and does not establish that any control described in this paper performs. It establishes that the shape of the problem is old and that a published remedy for that shape exists.
8.1.2 Bungay’s Law of Conformity Inheritance
A human–AI system can inherit no more recognised conformity than the organization
that produced it holds. An organization with no quality management system has none to
confer.
In its operative form: only a quality-managed organization can develop recognised quality-managed human–AI systems for commercial-grade deployment. And its corollary, which is the enforceable half — the unqualified producer corollary: an organization that cannot demonstrate management of its own work cannot confer recognised quality on work it produces, however good that work may in fact be.
“Recognised” carries the whole load, so it is defined rather than left to the reader. Recognised means attestable against a consensus standard by a party other than the producer — one of the three routes at section 2. It does not mean accepted in the market. On the market reading the Law would be plainly false, because unmanaged organizations ship AI the market accepts every day; on the attestation reading it is true, non-trivial, and is what the instruments at 8.1 evidence, since every one of them routes recognition through a standards body and not through a buyer’s enthusiasm.
What would falsify it, stated because a law that cannot be falsified is a slogan. A recognised, quality-managed human–AI system — attested against a consensus standard by a party other than its producer — produced by an organization holding no quality management system of its own. One such instance disproves the Law. It is offered in that form deliberately: this paper asks other people’s claims to state what would refute them, and cannot exempt its own.
8.2 The gap the standards system carried forward
The competency model that link 3 rests on was published, recorded by a national
committee as untested, mapped by a successor standard rather than replaced by it, and
confirmed without revision eleven years later. The gap the committee identified was not
closed. It was carried forward. The sequence is a matter of public lifecycle record and
can be checked without reference to anything we say.
Date
Record
3 July 2014
ISO/IEC 20006-1:2014 published, first edition.
2014
BSI publishes BS ISO/IEC 20006-1:2014. Its national foreword records
the UK committee's view that the standard was developed by a limited number of experts
without associated implementation activity, that its specification remains untested, and
that its terminology is unclear and inconsistent.
18 March 2015
ISO/IEC 20006-2:2015 published, first edition.
September 2019
ISO/IEC 22602:2019 published by the same subcommittee,
JTC 1/SC 36. It does not replace ISO/IEC 20006; its Annex B is a mapping of the ISO/IEC
20006 models.
31 October 2019
BSI adopts BS ISO/IEC 22602:2019; status current.
2020
CSA adopts CSA ISO/IEC 22602:2020.
2 October 2025
ISO/IEC 20006-1 and ISO/IEC 20006-2 reviewed and confirmed
at stage 90.93. Both remain first edition, unrevised.
Across eleven years and two confirmation cycles, the specification was carried forward
and no implementation at consequence scale entered the public record. This is an
observation about the lifecycle record, not a criticism of the committees: mapping and
confirming a reference model is an ordinary and defensible outcome of systematic
review.
Why we do not lead with the 2014 foreword. BSI's position advanced.
Having recorded the criticism in 2014, BSI went on to adopt the successor standard in
2019 and lists it as current. Quoting the 2014 foreword as BSI's present view would be a
stale citation, and we do not do it. The foreword is cited for what it is — a dated
national committee observation about the standard as it stood in 2014.
Where we stand in that sequence. The implementation activity the
committee identified as absent is what our development record documents. A competency
model has been operated across human and machine agents inside a licensed, registered,
insured operating organization, and the implementation evidence can be produced. Whether
that evidence satisfies any assessor is for an assessor to determine. We assert only that
it exists and is available for assessment.
Section 9: The rest of the control library
Thirteen answers is not the library. The thirteen in section 4 were selected because a named party made a public statement we could answer directly. The controls below were not
in that table, and several of them are the ones a compliance officer would actually reach
for first. They are set out here for the first time in one place, under the frame that
governs them.
9.1 How this section is marked
Every entry is admitted at one of three tiers, and the tier is a statement about
evidence, not about importance.
Tier 1 — Operative. A record exists within the last twelve months
inside the certified scope, and the process has been sampled in a surveillance audit.
Tier 2 — Specified. A dated written specification exists naming
inputs, outputs and authority. No operating record is claimed.
Tier 3 — Source identifier. The mark identifies the source of a
named thing. Nothing about capability, performance or deployment is claimed at all. This
is the default, and promotion out of it is an evidence event with a date, not an editorial
decision.
The governing rule, stated once so that it need not be restated.Evidence does not transfer by name, adjacency, ownership, registration, analogy or
architecture. A mark does not carry evidence to the thing it names; a measured result
does not carry to a neighbouring component; a certificate does not carry beyond its scope; a
registration establishes a source and not a capability; a control validated at one tempo or
for one class of agent is not thereby validated for another; and an architecture that
organizes a problem has not thereby solved it. Every instance of that rule below — and there
are many — is an application of this one sentence, not a separate concession. Where this
document declines to claim something, that is the rule operating, not a hedge.
One wording rule runs through everything below and is worth stating on its own line,
because it is the rule most often broken in this field. An entry states the risk a
function is directed at. It does not state that a risk is
mitigated. The first is a design statement and is provable from a
specification. The second is a performance claim and requires a measured result. No entry
in this document makes the second kind of statement.
9.2 Eleven risk classes, and what is pointed at each
The classes are ours. Each is written as a failure event rather than a theme, because a
theme cannot be tested and an event can. R1 to R10 are the operating classes; R11 is the
horizon class, and section 9.5 sets it out.
What these eleven classes are, and what they are not.
They are a governance and record risk inventory: authority, delegation,
interruptibility, traceability, attribution, competence and the expiry of integrity
assumptions. They are not a comprehensive inventory of AI harms, and
nothing in this document should be read as claiming coverage of the harm classes they
omit. Not addressed here: privacy and data protection; discriminatory or disparate
outcomes; model security, including prompt injection, data poisoning and model
extraction; harmful, deceptive or unsafe outputs; model and data drift; environmental
cost; labour displacement; and third-party and supply-chain model risk. Each of those is
a real class with its own literature. Section 13 names, for each one, the instrument to consult — instrument by instrument — so that a reader can go there
rather than assume this document covered it. An organization using R1–R11 needs those
inventories as well as this one, not instead of it. What R1–R11
contribute is that each is written as a testable failure event with a named control and
an evidence mark, which is the form this document argues risk classes should take.
Class
The failure, stated as an event
Directed at it
Tier
Scale of validation
R1 Unauthorized action
An agent acts outside the authority constituted for it.
SENTIENT AI IS™, H-GMOS™,
CONSTITUTIVE™ phase of the Bungay Tri-Phase Cascade™ — the
deterministic envelope described at 1.4
1 for the deterministic gate; 2 at machine tempo
Audited for the deterministic authority gate inside the certified
scope. Unmeasured at machine tempo, which is test 1, authority-boundary
enforcement, of the programme at 11.3 — the programme is numbered in risk-class order,
so the test that answers R1 is test 1.
R2 Uninterruptible process
A system cannot be stopped, or the stop does not reach queued, running and retrying
actions.
No operative control is claimed. This is test 2 of the eight, and it is the open one. Section 5 sets out why the statutory reporting clocks
make an answer to it practically necessary — a connection that is practical rather
than legal, and the same section states that a statute setting a reporting deadline
does not thereby set a performance requirement for stop propagation.
—
None. Stated as an unanswered question, deliberately.
R3 Unbounded delegation
An agent, or a delegate it spawns, exceeds an approved limit or reaches a prohibited
tool.
S.A.I.F.E.R.™, SNAACA™ brand of node mapping and addressing service — system-network
assignment, addressing and coordination authority
2
None.
R4 Unreconstructable decision
An action cannot be reconstructed afterwards by a competent reviewer who was not
present.
SCROLL™, TFID®, HHAIQMS™
telemetry and key-performance-indicator modules
1 for deterministic execution; 2 for inferential execution
Audited for reproducible machine execution inside the certified
scope — reconstruction is reproduction. For inferential execution, TFID® provides
attribution but not reproduction; that portion is unmeasured.
R5 Unsourced assertion
Output rests on stale, conflicting or absent provenance and proceeds anyway.
HALLUCIVAX™, HALLUCIDETECT™,
HALLUCICORRECT™, TFID®, AEXO™ 0333
as the controlling source for what a term means
2
None.
R6 Uncorrected nonconformity
A defect is corrected as an output but not as a process, and recurs.
CRASES™, PDICR™, INVESTIGATOS™
1
Audited for human and reproducible machine origin — corrective
action records are sampled on the surveillance cycle. One instance is
evidenced at regulatory scale rather than sampled: see 3.2, a
filing-timeliness nonconformity penalized by two regulators in 2012, disclosed by
MQCC® in its own return to a third, corrected inside the cycle, and absent from the
seven subsequent attested returns. Inferential-origin tagging is
instrumented and has produced no measured result.
R7 Degraded human review
An oversight gate exists but ceases to function under production load.
HHAI™ and HHAIQMS™, H-GMOS™, and
the calibration layer at 9.3. Test 7 of the programme at 11.3 — seeded-error detection under load — is specified against this class, and no verified result set is presented for it.
1 for the quality-management system the gate sits in; 2 for the calibration
layer
Commercial for the calibration layer. Audited for the management system around
it.
R8 Undetected agent
An instance operates unmapped, unnamed and unowned.
SNAACA™, TFID®,
INFRASTRUCTOS™
1 for deterministic instances; 2 for inferential
Audited for deterministic instances — every scheduled process in the
certified scope is named, owned and inventoried. None for inferential instances.
R9 Counterparty-interest asymmetry
The party controlling the evidence is the party with the adverse interest.
4th Adversarial Interest Class™ as the analytical frame;
IOC™ / IOCAA™ and the four-function separation at section 10 as the
structural answer — noting that section 10 scopes IOCAA™ as MQCC®'s own scheme, attested without accreditation,
and states why accreditation is declined rather than sought
2
None for the accreditation structure. The analytical frame is applied daily in
lending and brokerage files and is audited in that application.
R10 Unreported incident
A reportable event is not detected, classified or filed inside a statutory
clock.
PDICR™ with reporting as a named stage, REGULATOS™,
SUPERVISOS™
1 for the regulatory reporting practice; 2 for the inferential-incident
application
Regulated — consequential reporting to financial regulators on the
day of detection is established practice, and the detection step runs on deterministic
machine process inside the audited scope. None for the inferential-incident
application, and no detection-to-report latency has been measured.
R11 Expired integrity assumption
A record's integrity or confidentiality claim rests on a computational hardness
assumption that is later retired, while the obligation the record evidences runs
past the retirement date.
NONHASH™ and POWOR™ as named methods;
SCROLL™ and TFID® as the records they would
protect; cryptographic agility as a stated design requirement. Set out at 9.5.
3
None. No cryptanalysis, no module validation, no tested quantum property.
Ten of eleven classes have something pointed at them. R2 does not, and that
is stated rather than filled. A taxonomy in which every cell is occupied is a marketing
document. Where a class reads audited, that mark covers human and deterministic
machine execution per section 1.3; the inferential portion is stated separately in the same
cell and is unmeasured everywhere.
9.3 The human–AI interface layer
The failure this layer is built for is not a rogue agent. It
is an agent that has been given the wrong context, or no context, and produces work that
is fluent, plausible and wrong — and a human reviewer who, under load, approves it.
That is risk class R7. In this organization's own operating experience across
AI-assisted professional work, it is the most consequential recurring failure mode we have
had to manage — an observation from one organization's practice, offered as that and not as
a measured rate across any wider population. No incident-rate comparison between the eleven
classes has been run here or, so far as we are aware, published anywhere.
The layer directed at it has four named parts.
HHAIPROMPT™ — Hybrid Human-AI Prompt. Not software, not a model, and
not a platform: a structured context framework that establishes who the operator is, what
the terminology means, and what authority the machine agent does and does not hold, at the
start of a working session and across session boundaries.
BESAIFER™ — Bungay Epistemic-Semantic-Alethic Intelligence Framework
for Evolving Resilience™, pronounced be-safer. Three tiers: the epistemic tier
asks whether the agent has understood or only pattern-matched; the semantic tier asks
whether both parties mean the same thing by the same word; the alethic tier requires every
assertion to be classified true, partially true, or contingently
true, and prohibits a contingent claim from being carried forward as a necessary
one.
AIREHYDRATE™ — the up-calibration process by which that context is
re-established for a new instance rather than assumed. Its first step,
CAI-II™ (Constitutive AI™ Identity Installation™), constitutes the
operating identity and authority before any work is accepted from the agent, which is the
same ordering the CONSTITUTIVE™ phase imposes at R1.
ZERO ONE® brand of qualification gate — the recording principle. What is recorded computationally
can be verified afterwards; what was never recorded cannot be. It is the reason the
alethic tier is a record and not an attitude.
The evidence boundary on this layer, stated in full. This is
Tier 2 — Specified, with commercial-scale use. The framework is dated, written
and applied in this organization's own AI-assisted work, including in the preparation of
documents in this series. What does not exist is a measured result: no controlled
comparison of review quality with and without the calibration layer, no error rate, no
independent evaluation, and no assessment of the framework by any external party. The
observation that different model instances comprehend the context to different depths is
an observation, not a measurement. A reader should treat this layer as a documented method
in commercial use, and should not treat it as a tested one.
9.4 The record and traceability layer
Everything above depends on the record surviving the event. Four named components sit
under that requirement: TFID® binds origin, authority, scope and time to
each record; SCROLL™ retains the canonical version with its correction
history; NONHASH™ and POWOR™ name a non-cryptographic
verification method and a proof-of-work-origin record respectively. The last two are
admitted here at Tier 3 — the marks identify named methods, and no
operating claim, performance figure or deployment is asserted for either in this
document.
One distinction belongs here because it is routinely collapsed elsewhere.
Traceability is not accuracy. A record system that preserves an assertion
perfectly, with origin, authority and timestamp intact, has established where the assertion
came from. It has established nothing whatever about whether the assertion is true. An
accurately preserved false statement is still false. Every traceability claim in this
document should be read in that narrow sense, and any reading in which a TFID® makes
something correct is a misreading.
9.5 R11 and the post-quantum transition — where the record layer expires
Section 1 defines quantum conformity as the frame. This subsection applies it to one
specific quantum: the record itself. Everything at 9.4 assumes the record will still verify
when somebody comes back to it. That assumption now has a published expiry date, and the
date was set by NIST rather than by us.
9.5.1 The dates, which are not ours
13 August 2024 — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205
(SLH-DSA) issued as final federal standards.
11 March 2025 — HQC selected as a backup key-encapsulation
mechanism, to serve if ML-KEM is ever broken. NIST states a draft standard for public comment
in about a year, a 90-day comment period, and a finalized standard for release in 2027.
NIST announcement.
As at 24 September 2026 — FN-DSA (FIPS 206) still not released,
even as an initial public draft. NIST's own status update describes the draft as written and
awaiting approval, and separately notes that FN-DSA is difficult to implement because
operations in key generation and signing need floating-point arithmetic, which creates
challenges for validation and side-channel protection. NIST does not join those two
statements, and neither does this document: the implementation difficulty is stated by NIST,
the inference that it explains the delay would be ours, and it is not made. No completion
date has been published.
NIST FIPS 206 status update.
12 November 2024 — NIST IR 8547, Transition to Post-Quantum
Cryptography Standards, published as an initial public draft. Comments closed
10 January 2025. It remains a draft. For RSA, ECDSA, EdDSA, finite-field Diffie-Hellman and
elliptic-curve Diffie-Hellman, Tables 2 and 4 propose a two-tier schedule: parameter sets
providing 112-bit security strength — RSA-2048 and the 224-bit elliptic
curves among them — deprecated after 2030 and disallowed after 2035; and
parameter sets providing 128-bit security strength and above —
disallowed after 2035. Increasing key size does not move an algorithm off
the 2035 date, and cannot: the transition exists because a quantum adversary breaks these
algorithms irrespective of parameter size. What the strength tier changes is when
deprecation begins, not whether disallowance arrives.
9.5.2 Why that is a conformity problem and not only a cryptography problem
Read it as a records problem rather than as a mathematics problem. A signature applied
today, under an algorithm scheduled to be disallowed after 2035, is a record whose
integrity claim carries a stated end date — attached to an obligation that may well outlast
it. Mortgage instruments, corporate records, regulatory filings and the conformity evidence
that supports them routinely run past 2035. And the collect-now-decrypt-later exposure does
not wait for 2035: material captured today is held against a capability that arrives later.
An organization whose traceability doctrine is that the record is the point cannot treat
the expiry of the record's integrity assumption as somebody else's department. That is risk
class R11.
One limit on that, stated so it is not read too widely. A transition
policy date is not a date on which existing records become unverifiable. Deprecation and
disallowance govern what a conforming system may apply going forward; a signature
already applied does not stop verifying on a calendar date, and the practical question is
whether the verifying party still accepts the algorithm and whether an adversary has
acquired the capability to forge it. R11 is the risk that an integrity assumption is
carried past the point where it is still warranted, which is a governance failure about
review, not an automatic cryptographic event on 1 January 2036.
The shape of it will be familiar from section 8. The three algorithm standards are
final. The document that tells an organization how and when to move is still an
initial public draft nearly two years after its comment period closed, while the first
deprecation year sits inside the planning horizon of every records system now being
designed. As at section 8, this is an observation about a lifecycle record that anyone can
check, and not a criticism of the committees — a transition document that governs the whole
federal estate is exactly the kind of document that should not be rushed.
9.5.3 What MQCC® has here, split into theory and praxis
Theory (T) — substantial. Conformity Science™ applied to quantum
processes is published work: the Bungay Unification of Quantum Processes Algorithm, from
which Principles of 'Distributed Ledger'™ derives, and quantum computing among the subjects
of the ISBN-registered textbooks listed at www.mqcc-ai.com. Theory in the sense of section 1.4 means
written, dated, published and inspectable. It does not mean tested, and the distinction is
doing real work in this paragraph.
Praxis (P) — absent for the quantum property specifically. The record
layer at 9.4 does run in a licensed, registered, insured operating business, so the record
layer has praxis. What has no praxis is any quantum property of it.
NONHASH™ names a verification method described as non-cryptographic. If
that description holds — and it is a design statement, not a tested result — then a
verification claim that does not rest on a cryptographic hardness assumption does not
inherit that assumption's expiry date. That is the property R11 looks for, and it is why
NONHASH™ is named here and not only at 9.4. POWOR™, a proof-of-work-origin
record, sits beside it on the same footing. Both are admitted at
Tier 3: the marks identify named methods, and no implementation,
performance figure, deployment or cryptanalytic evaluation is asserted for either.
QG-HHAI™ is likewise Tier 3, and its relationship to HHAI™ and HHAIQMS™ is
one of the four reconciliation questions the expanded concordance has to answer before
either is described further.
Evidence boundary for the whole of 9.5 — the one a cryptographer will look for
first.
MQCC® Bungay operates no quantum computer and has access to none. It has performed no
cryptanalysis, has commissioned none, and holds no cryptanalytic result from any third
party. No MQCC® method has been validated under the Cryptographic Module Validation
Program or any equivalent scheme, and no MQCC® method is claimed to be
quantum-resistant in any tested sense. A claim that a method is non-cryptographic is
a claim about how it is built, and it is not a security proof; a method can avoid a
hardness assumption and still fail for reasons that have nothing to do with quantum
computing. The trademark FATHER OF COMMERCIALIZED QUANTUM COMPUTING™ is a source
identifier and, under the rule at 9.7, establishes nothing about capability, deployment
or historical fact. What is claimed in this section is narrow and checkable: the risk
class is real and its dates are NIST's, the theory is published, and the praxis has not
been tested against it.
9.6 Assessment and oversight, offered rather than proven
SUPERVISOS™ (live supervision of governance, management and operations,
and of delegated duties), INVESTIGATOS™ (threshold-triggered investigation)
and REGULATOS™ (activation of the rules applicable to a given sector,
jurisdiction and process) are the three components most often asked about, because they map
onto what the market has started calling AI audit.
Their position, marked. As applied to human and reproducible machine execution inside
the certified scope they are Tier 1 and the scale mark is
audited. As applied to inferential execution they are
Tier 2 and the scale mark is none.
They are offered as third-party conformity assessment and management-system audit
services, under the service mark registered at USPTO Registration 7,160,072. The
registration identifies the source of the services and establishes neither competence,
accreditation nor independence, and none of the three is claimed on its basis — see section 9.7
and section 10.
What is sold, named as one thing: HHAIOS™ — turnkey, standards-based, quality-managed hybrid human–AI organization safety infrastructure, available for your organization today.Turnkey means deployed rather than described: the management system, the control library indexed to the risk classes at section 9.2, the numbered test programme at 11.3, and the record discipline, stood up inside the client's own operations with modules integrating ISO 9001:2015 and ISO/IEC 42001:2023. And the reason it can be turnkey is a matter of arithmetic on two published dates rather than a claim about anybody else. The management system underneath it has been held under third-party audited registration continuously since 9 May 2008. ISO/IEC 42001, the AI management system standard, was published in 2023. This organization was operating the machinery fifteen years before the standard for it existed, and eighteen years on the registration is current and checkable with the registrar rather than with us. That is the whole of the head start, stated as two dates and a subtraction: no comparison with any other organization is made here, because this organization holds none of their evidence and section 10 says what it would take to correct anything written here.
What is available, stated once and the same everywhere.
Management-system assessment against ISO 9001:2015 and
ISO/IEC 42001:2023 is available now, attested by a body without accreditation —
the third route at section 2. AI-control development, testing and verification services are available now.
An engagement defines the organization's requirements, scope, deliverables and price, and its
conclusions follow from the work performed and the evidence obtained in that engagement.
What this paper presents and what MQCC® can be engaged to do are separate
questions. This paper is the macro-scale account of the approach, what MQCC® does and
the evidence it presents; the service schedule prices the detailed work for a particular
organization, and proprietary implementation detail belongs inside the engagement. Every
engagement states the attestation route in the engagement letter, records the designed-it
election in writing before work begins, and carries professional liability cover arranged for
that engagement. The service schedule is set out in the third-party assessment prospectus.
To engage. Correspondence goes to ceo@mqcc.org, a monitored address, answered in writing. Ask for the scope and it is written before anything begins — requirements, deliverables, limitations and fee, together with the attestation route and the designed-it election, all recorded in the engagement letter. The Services Brochure is complimentary on request; every other step, including scoping, is a paid engagement, and price follows the requirements of the organization’s scope of operations rather than a published rate.
What an engagement makes explicit, and the difference between withholding a method and
withholding a reason. Every engagement states, in writing, the chain from claim to
limitation: the claim being assessed → the applicable requirement → the assessment method
→ the evidence needed → the assessor's competence for it → the finding → the limitations of the
finding. That chain is the answer to an objection this paper's own disclosure boundary
invites. MQCC® does not publish how it implements a control, and does not intend to. It does not
follow that a reader or a client may be left unable to see why a conclusion was reached.
Protecting an implementation and explaining the basis of a conclusion are different
things, and only the first is proprietary. An assessment whose reasoning cannot be
followed is not protected, it is unfalsifiable, and this paper does not ask anyone to accept one.
That chain was reviewed against an external specification of what assessment
should look like:
OpenAI,
Priorities and principles for effective third party assessments, 22 September 2026,
which asks for a mutually agreed scope with safety claims pre-registered before work begins,
assessors who "explain their methods, assessment criteria, and uncertainties",
proportionate access within legal, security and intellectual-property bounds, demonstrated
technical expertise, disclosed and managed conflicts of interest, enforceable confidentiality,
findings detailed enough to act on, and publication as open as the sensitivity allows. It also
separates four objects of assessment — safety cases, safeguards, evaluations and incidents — which
is a distinction worth holding. It is cited as an external statement of expectations to be
compared against, and nothing more. It is not an endorsement of MQCC®, it does not
establish equivalence between the two approaches, and it verifies no MQCC® control. Where the
comparison is unflattering it is recorded as a correction rather than dropped: the conflicts
provision is the one MQCC® already meets by construction, since fees here are fixed and
non-contingent; the pre-registered-claim discipline is the one this paper has adopted only as of
this edition.
The advisory services available today. Requirement interpretation, control design, instrumentation, readiness assessment and outsourced internal audit are advisory work. No accreditation is required to perform them. One thing that does apply, stated
because it governs a service sold here: ISO 9001:2015 cl. 9.2.2 requires auditors to be
selected and audits conducted so as to ensure the objectivity and impartiality of the audit
process, and outsourced internal audit is bound by that in full. What does not apply to
advisory work is the certification-body impartiality scheme of ISO/IEC 17021-1 — a different
instrument, governing a different activity. They are the work ISO/IEC 17021-1
cl. 5.2.5 forbids a certification body to do, which is why somebody outside the certification
chain has to do them. Section 10 sets out that division of labour and the one rule
this organization imposes on itself across it: a client advised is a client it will not
assess, permanently. That is MQCC® policy and it is stricter than the standards require.
9.7 How to read the marks in this document
This document names a number of registered trademarks. Each identifies the source of a
named MQCC® component — that is what a registration establishes, and what it is for. What a
component does is carried by the evidence mark beside it: operative, specified or
source identifier, with its scale of validation. Read the two together. The trademark tells
you whose it is; the evidence mark tells you what has been shown.
9.8 What kind of document this is — a private standard, said plainly
Every specification named in this article is a private standard: a
voluntary specification published by a private organization. That is a recognized
category and not an apology. Private schemes are certified against every day by
certification bodies accredited to ISO/IEC 17065 — BRCGS, SQF, FSC and IFS are all private
schemes with accredited certification behind them. California AB 1405 asks a registrant to
file standard operating procedures referencing ISO, NIST or other assurance
standards; it does not ask the registrant to be a national standards body.
And what a private standard is not. It is not a national standard. It
is not an international standard. It has not been through a national or international
consensus process, no committee outside this organization has reviewed it, and it carries
no presumption of conformity with any statute or regulation. Anyone who reads the
designations in this document as implying otherwise has read them wrongly, and this
paragraph exists so that nobody can say they were not told.
The routes that would change that, named, because they exist. A
specification does not have to stay private to stay yours.
BSI PAS — a Publicly Available Specification may be commissioned by
any organization, association or group, including a single company, subject to BSI's
acceptance process. Development runs to roughly eight months, drafting follows the same
rules as a British Standard, and the result is published under a PAS designation.
ISO/PAS and IWA — the ISO analogues. An International Workshop
Agreement is developed in a workshop outside the committee structure by consensus of the
participants, is reviewed at three years, and has a six-year maximum life before it is
converted to another ISO deliverable or withdrawn. ISO/PAS carries the same six-year
ceiling.
The condition attached to those routes, which is the interesting part.
A PAS must set out objectively verifiable requirements and must avoid proprietary methods,
and it cannot conflict with existing or draft work in the formal standards arena. A
document that says use AIQMSS® cannot be published as a PAS. A document that says
stop-propagation latency shall be measured and reported; authority shall be constituted
and recorded before execution; nonconformity shall be tagged at origin can be — and
AIQMSS® is then one conforming implementation of it, which is a stronger position than
owning the document, not a weaker one. The requirement belongs to everybody; the operating
record does not.
9.9 AIQMSS® — one system, three GMO™ levels
The architecture first, in three rows, before any of the nomenclature. A reader who takes
only this table has the structure; everything after it names the parts.
Level
Function
What sits here
Evidence
G
Governance
Direction and accountability. Decides that there shall be a management system and
what its scope is; oversees it rather than operating it.
Specified.
M
Management
Two management systems under one Annex SL structure: a quality management system
aligned to ISO 9001:2015, and an AI management system aligned to
ISO/IEC 42001:2023. One context, one leadership, one internal audit programme,
one management review.
The quality management system is audited — registered
continuously since 9 May 2008, within the scope on BSI certificate FS 532934.
The AI management system is specified. No conformance to
ISO/IEC 42001 is claimed and no certification to it is held.
O
Operations
Execution.
Specified.
The registration and the measured audit record attach to the quality management system at
level M and nowhere else. Governance, Operations and the AI management system inherit none of
it by adjacency — the governing rule at 9.1, applied to this organization's own architecture.
Several names for MQCC® systems are in public circulation. This subsection states the
relationship, using a structure that is already MQCC®'s own.
GMO™ — Governance, Management and Operation — is the published MQCC®
body of knowledge describing an organization at three levels, across all functions:
strategic, operational and tactical. H-GMOS™ is its human-side
instantiation, and appears at R1 and R7 above. AIQMSS® — Advance
Intelligence Quality Managed Safety Systems — is one system, organized on those three
levels, with two management systems at level M under one Annex SL structure: a quality
management system aligned to ISO 9001:2015 and an AI management system aligned to
ISO/IEC 42001:2023. aiQuQMS™ and AIQUMOS™ were consolidated under AIQMSS®, the registered
mark, before 22 September 2026, and the consolidation was placed of record on
23 September 2026. The ISO 9001 registration and the measured record attach to the
quality management system only, and no claim of conformance to ISO/IEC 42001 is made.
AIQMSS® is read by stratum from a closed, dated register — six fixed letter
positions, the occupying word determined by the stratum described rather than by the argument
made. The register, the interlock with Registration 7,160,072, and the registration details
are at Appendix A.2.
Which registration supports which claim.
The AIQMSS® registration is in Class 041 and reaches education and training. It does not
reach the performance of quality management, auditing or conformity assessment. The
conformity assessment and management-system audit services described in this document rest
on Registration 7,160,072 (serial 97006933), classes 035, 036, 042 and
045, whose recitation includes testing, analysis and evaluation of service providers to
determine conformity with established accreditation standards and testing, analysis
and evaluation of organization governance, management and business processes to assure
compliance with industry standards, with claimed first use 14 July 2020. Two
registrations, each doing what its classes permit, and neither asked to do the other's work.
Level
Function
What sits here
Evidence
G
Governance
Directs and holds the rest to account. The GOVERNOMIC™ phase of the
Bungay Tri-Phase Cascade™; H-GMOS™ names the accountable human authority.
Specified.
M
Management systems
Two of them, under one structure. The quality
management system, aligned to ISO 9001:2015. The AI
management system, aligned to ISO/IEC 42001:2023.
Audited for the quality management system — the registration and the
measured record at section 3 attach here and nowhere else. Specified for the AI
management system.
O
Operations
Quantum-unified execution — the layer that runs process. The
EXECUTORIAL™ phase.
Specified.
Governance is not a management system, and a management system is not
governance. Governance directs and holds to account; management achieves objectives
through a system; operations execute. The governing level decides that there shall be a
management system and what its scope is, then oversees it — it does not operate it. Keeping
G, M and O distinct is what makes the evidence marks above assignable to a level rather than
smeared across the organization.
Consolidation of record, 23 September 2026.aiQuQMS™ and AIQUMOS™ were consolidated under
AIQMSS®, the registered mark, before 22 September 2026; the
consolidation is placed of record as of this date. uQMS™ and
MOS™ are their predecessors. AEXO™ 0333 is the controlling source for the
expansion, and the expansion is unchanged. A registration identifies the source of a
system; it does not have to be derivable from any expansion. Material published before this
date under the earlier names refers to the same system and will be brought into line.
A rename that is not recorded is not traceable, so it is recorded here rather than
performed silently. Three dates are involved and they are not interchangeable: the consolidation
itself, before 22 September 2026; the opening of the reading register at
Appendix A.2, 22 September 2026; and this record of it, 23 September 2026.
What does not carry across. The ISO 9001 registration and the measured
record attach to the quality management system at level M. Governance and Operations inherit
neither by adjacency, and neither does the AI management system beside it — the same rule
this document applies to every other component at section 9.1.
9.9.1 How this fits a management system you already run
Most organizations facing artificial-intelligence governance believe they have to build
something new. Usually they do not. They have to extend what they already operate — and the
standards system was designed on that assumption.
ISO/IEC 42001:2023, the AI management system standard, is built on
Annex SL, the harmonized high-level structure shared by every modern ISO
management system standard. ISO 9001:2015 has the same skeleton:
Clause
ISO 9001:2015
ISO/IEC 42001:2023
4
Context of the organization
Context of the organization
5
Leadership
Leadership
6
Planning
Planning
7
Support
Support
8
Operation
Operation
9
Performance evaluation
Performance evaluation
10
Improvement
Improvement
That alignment is deliberate. ISO built the structure so an organization runs one
management system with multiple scopes rather than one system per standard — the same
context, the same leadership, the same internal audit programme, the same management review,
extended to cover artificial intelligence.
That is what level M above is. Two management systems — one aligned to
ISO 9001:2015, one to ISO/IEC 42001:2023 — under a single Annex SL structure, sharing one
context, one leadership, one internal audit programme and one management review. AIQMSS® is
designed for integration with existing management systems under that structure rather than
as a replacement for them, and it is not a rival to ISO/IEC 42001. Certification to
ISO/IEC 42001 is available today from certification bodies working under ISO/IEC 17021-1, so
a reader who has an ISO 9001 system and an artificial-intelligence problem can act on this
paragraph without waiting for anything in this document.
Structural alignment is an architectural statement. Nothing here claims that
AIQMSS® is conformant to ISO/IEC 42001, or that MQCC® holds certification to it.
Section 10: Independence and scope
10.1 The rule underneath the question, and what it actually says.
Conformity assessment has a rule that predates every AI statute and is the reason certification
is worth anything at all. ISO/IEC 17021-1:2015 cl. 5.2.5: the certification body, any part
of the same legal entity, and any entity under the organizational control of the certification
body, shall not offer or provide management system consultancy. Three further clauses close
the routes around it. Cl. 5.2.6 bars a body from certifying a management system on which it
provided internal audits, for a minimum of two years after that work ends. Cl. 5.2.7 applies the
same two-year bar after consultancy. Cl. 5.2.9 bars certification activities from being marketed
as linked with a consultancy organization's activities.
The rule produces a gap deliberately. Standards bodies write requirements. Certification
bodies verify conformity to them and are forbidden to say how to achieve it. The work in
between — interpreting the requirement, designing the control, instrumenting it, auditing it
internally and correcting what that finds — has to be done by somebody, and by rule it cannot be
done by the body that will certify the result. Every accredited scheme in the world carries this
gap, and it is a feature of all of them.
10.2 Which side of that rule this organization is on. MQCC® Bungay is an advisory and readiness organization that also offers assessment, attested
without accreditation. That is a scope decision, taken deliberately, and it determines where the four functions the field is about to start asking
about actually sit. California's SB 813 sets the test the whole field will be measured against:
compensation that may not depend on findings, and no auditing of a system you materially
designed. An organization that is simultaneously architecture owner, accrediting authority and
assessed operator fails that test. So the roles are separated:
Architecture owner — holds the method and the marks, and does not
assess.
Accrediting authority — publishes criteria; fees fixed in advance
and never contingent on findings.
Assessing entity — performs the assessment against those criteria, and
does not write them.
Assessed operator — is assessed, and does not accredit or assess.
Four roles is a design, not a disclosure — and the distinction matters more
than the design. Separating roles on an organizational chart does not establish
independence. What establishes it is ownership, control and money, disclosed. Every one of
the four roles above currently sits within entities under common ownership and control by
the author. The correct present description is therefore separated functions under common ownership, not
independent parties. Under cl. 5.2.5 the consultancy bar reaches the certification body, any part of the same
legal entity, and any entity under that body's organizational control. How far it
reaches through a group is a question of the actual control relationships and of the scheme
being applied, and it is not settled by the clause text alone; this document does not claim
that accreditation is foreclosed everywhere under common ownership. What it claims is
narrower and sufficient for the decision taken: with an advisory practice in the group and
all four functions held by one person, no accredited certification arm is being built here,
and none is being sought. What follows from that is not a promise to fix it. It is a choice about
which line of work to be in, and this edition makes it.
What is sold, and the one class of service that is not — stated positively, because the negative has been misread. MQCC® sells readiness services and assessment services. The assessment sold is MQCC®’s own proprietary audit and conformity assessment against published criteria, including IOCAA™ — the third attestation route at section 2, attested by a body without accreditation. The single class MQCC® does not sell is IAF-member-recognized accredited audit and certification. That class is outside the offering for the reason at 10.2. No other assessment work is outside it, and a reader who took the preceding paragraphs to mean that assessment is not sold here took them further than they go.
And for an organization that wants the accredited route, there is a service rather than a refusal. MQCC® will interview, audit and recommend IAF-member-recognized accredited certification bodies on a client’s behalf. A buyer seeking accreditation commonly knows it needs an accredited auditor and does not know which one suits its sector, its scope and the state it is in. Choosing that body is assessment work directed at the assessor rather than at the client’s system, it sits outside the certification chain, and it is sold. The limit is part of the service: a recommendation is a recommendation. The accredited body performs its own audit on its own criteria and reaches its own conclusion, and nothing MQCC® does in selecting it binds that conclusion or predicts it.
IOCAA™ is retained, and it is not accredited certification. It is MQCC®'s
own scheme and its own criteria, published on its own terms. No accreditation is held, and none
is sought, because cl. 5.2.5 and the advisory practice are mutually exclusive and the advisory
practice is the one with an operating record behind it. An IOCAA™ assessment is assessment against a published
scheme, attested by a body without accreditation — the third route at section 2, a real and
saleable service, and not accredited certification.
Earlier editions of this document described the four-function separation as a design working
toward independence in the SB 813 sense. That description is withdrawn: the separation is
real, the direction was not available.
10.3 The one rule this organization imposes on itself, and where it comes from.
A client this organization advises is a client it will not assess, permanently. That is
MQCC® policy, and it is stricter than anything cited here requires. What the
authorities require is narrower and is stated so the difference is visible: cl. 5.2.6 bars
certifying a management system on which the body provided internal audits for a minimum of two
years after that work ends, cl. 5.2.7 applies the same two-year bar after consultancy, and
California's AB 1405 bars auditing a system a party materially designed. A two-year bar and a
bar on auditing one's own work are not a lifetime bar on every future assessment of a former
advisory client. This organization adopts the lifetime bar anyway, because a client choosing
an adviser should not have to weigh whether that adviser is positioning for a later assessment
fee, and because a rule with a waiting period built into it is a rule a client has to audit.
So there is no second engagement waiting at the assessment stage, and there cannot be one. That is worth stating in
the positive: advice from a party with no downstream assessment fee available to it is advice
with one fewer interest attached.
Value-priced engagement follows the same line. It is available to advisory work — legitimately, because no
certification-body impartiality scheme governs advice — and it is not available to anything
described as accreditation or assessment, where a fee may not depend on findings. It is also
not available where the advisory engagement is an outsourced internal audit, because the
objectivity of an audit process cannot survive a fee that moves with its findings.
That was already this document's position; the scope decision above is what makes it
straightforward rather than delicate.
What the eighteen-year record does and does not evidence. An internal audit
and readiness function has operated continuously since 9 May 2008 inside a management system an
accredited registrar has maintained without interruption throughout — BSI certificate FS 532934,
in the scope stated on it: the provision of mortgage banking and mortgage brokerage services.
That evidences a readiness function that has worked, sampled annually by a third party, in a
business where its failure carries realized regulatory, indemnity and commercial consequence. It
is not a certificate of AI advisory competence and is not offered as one. Section 3 states what
the measured record covers; this is the same boundary applied to the same certificate.
Section 11: Evidence boundaries
Every control in this document carries an evidence mark. This section states where those
marks stop, because a mark that is never bounded is decoration. It is the instrument that makes
the rest of the document checkable.
11.1 The AI-specific controls are unmeasured at inference. They are
published, dated and inspectable, and none has been measured on an inferential agent at
machine tempo. Where section 9 now reads audited, that mark covers human and
reproducible machine execution and says so; the inferential portion of every class is
unmeasured. Section 1.3 states why that boundary exists and why it cannot be reasoned
across: reproducibility is what licenses extrapolation, and no inferential component here has
been shown to have it under pinned conditions.
11.2 One class has nothing pointed at it. R2, uninterruptible process,
carries no operative control. The clocks at section 5 are reporting clocks. They
run on the obligation to report, and they do not specify a shutdown-performance deadline. R2 is
the class with no operative control; the statutory deadline it is adjacent to governs when an
answer must be filed, not how fast a process must stop. Section 5 draws that separation and 11.2
should not undo it.
11.3 What this paper presents about the eight control tests. This paper does
not present a verified result set demonstrating completion of the eight defined control tests
against their stated protocols and acceptance criteria. The programme is numbered once,
in risk-class order, and every reference in this document uses that numbering:1 authority-boundary enforcement (R1), 2 stop-propagation
latency (R2), 3 delegation-limit enforcement (R3), 4 decision
reconstruction (R4), 5 provenance refusal (R5), 6
correction-loop closure (R6), 7 seeded-error detection under load (R7), and
8 detection-to-report latency (R10).
Test 7 was added at Edition 8.9, and the two conditions stated below are new at this
edition. It exists because the gap it fills was the least defensible one in the paper. Section 9.3 names R7 — an oversight gate that exists but
ceases to function under production load — as the most consequential recurring failure mode in
this organization's own AI-assisted work. R7 had controls pointed at it and no test. The class the
paper rates highest was the class it measured least, and that was not a defensible position to
publish. The test: seed known errors into work presented to reviewers under a
stated workload and time limit, and report the detection rate, the false-alarm rate, review time
per item, and escalations left unresolved. Two conditions are part of the test and not
commentary on it. First, the load basis is stated: whether the sample was drawn
from production or generated under constructed conditions, and a constructed-condition result is
marked specified rather than reported as an operating measurement — because R7 is about
behaviour under production load, and a drill is not production. Second, the denominator is
designed before the run: a detection rate needs the seeded population, and a false-alarm rate
needs the unseeded population characterized as well, or the figure cannot be reported with
numerator, denominator and conditions, which is the rule the other seven already carry.
The human agent is a control, and it carries a mark like any other. That is
why this test exists and why it is numbered with the rest rather than treated as a matter of
training. The seventeen audit cycles measure whether human and reproducible machine execution
conformed to the requirements binding it. They do not measure how well a reviewer
detects a nonconformity placed in front of them under a real workload and a real clock,
and nothing in the audited record reaches that property by adjacency. A review that has
not been tested is a review that has been assumed. Until test 7 is run, the human
reviewer as a control carries specified for detection performance — the same mark the
machine controls carry, for the same reason.
Two failure events, not one, and the test separates them. A low detection rate
is a question about competence and training, and section 7 is where both agents are trained to
the same standard. A reviewer who releases what they were required to refuse is a different
event: the release is recorded and attributed, and whether it was error or something else is a
matter for INVESTIGATOS™, the threshold-triggered investigation and audit service,
with CRASES™ opening the corrective-action case that follows. It is not a matter
for the metric, and a detection rate should not be asked to carry it. A control that cannot
distinguish the two is a control that reports the wrong number about the more serious of them.
Origin of test 7, and what this edition added to it. The
FATHER OF HYBRID HUMAN-AI GOVERNANCE™ brand of services (MQCC Bungay
International LLC), Compliance and Conformity Bulletin, September 2026, states the test as
"ask reviewers to find seeded errors under a realistic workload and time limit", reporting
"detection and false-alarm rates, review time and unresolved escalations", and carries two
conditions, quoted here as the bulletin’s own wording: "set the pass mark before you
test", and "report the failures too — give the numerator, the denominator and the test
conditions. Zero failures in a small test is not zero risk." This paper applies the first to
every test, and applies the second as a rule of reporting completeness rather than as an
undertaking to report: where a result is given, it is given with numerator, denominator and
conditions, and a result that cannot be given that way is not given. Two things are added here and are additions
rather than restatements: the bulletin's realistic workload is replaced by a
stated load basis, because realistic does not say whether the sample came
from production or from a drill and R7 is a claim about production; and the denominator condition
is extended, because a false-alarm rate needs the unseeded population
characterized, which a numerator-and-denominator rule does not by itself require. That is an MQCC®
page, cited as a dated internal specification and not as external corroboration of anything.
Three classes still have no test, and the numbering shows it rather than hiding
it. R8, R9 and R11 are not in the programme above. They carry controls at section 9.2;
they carry no test. Stating that is cheaper than letting a reader derive it from a gap in a
numbered list. These are development milestones on MQCC®'s own product, and they are a published test
programme rather than a condition on anything sold. They measure MQCC®'s own AI
controls. As each is run on this organization's own deployment, its result becomes a development
record of MQCC®'s own product, held and shown to licensees and to clients under engagement on the
same footing as the method itself. What is published here is the programme — which tests exist,
what each measures, and which risk class it answers — and that is published because a reader is
entitled to know what is outstanding. A developer with a stated programme and work outstanding
is in the ordinary condition of every developer; what would not be ordinary is leaving the
programme unstated, and it is stated here.
What this paper presents does not determine what MQCC® can be engaged to do.
These two questions were conflated in editions through 8.3, and the conflation ran in both
directions — first gating the wrong service, then gating a service on a measurement of a
different object. A client engagement assesses that client's arrangements against
requirements and acceptance criteria agreed for that engagement, and its conclusions
follow from the evidence obtained there. MQCC®'s own test programme is a separate record with a
separate purpose. Development, testing and verification services are available now
— section 9.6 and section 12.1, and correspondence goes to ceo@mqcc.org.
11.4 IOCAA™ is not accredited, and accreditation is not being sought. Its
criteria are MQCC®'s own and are in development; we have committed to publishing them before
requiring them, and California's dates — 1 January 2028 and 1 January 2029 — remain the schedule
we publish against. No accreditation body has assessed those criteria and none has been asked to, because
accreditation is not sought — the scope decision at section 10.2. What therefore remains
genuinely unproven is whether the criteria would satisfy an accreditation body that did assess
them. That question has not been put, and no edition of this document should imply it has been
answered.
11.5 The quantum layer is theory without praxis. Section 9.5 states
it in full: no quantum computer, no cryptanalysis, no module validation, and no tested
quantum property for any MQCC® method. The published work is real and the risk class is
real. The connection between them has not been demonstrated, and until it is, R11 is a
class with a Tier 3 answer, which is another way of saying it has no answer yet.
Appendix A. Naming, marks and dates
This appendix carries material that supports the main text without being part of its
argument. None of it is evidence about system performance. A reader assessing the method
can skip it; a reader checking precedence or the construction of the names needs it.
A.1 Why 1 May 2019, and not another date
Because of what was introduced, not when the words were first typed. What
the post named was systems-level artificial intelligence. That is a claim about the
unit of analysis, and it is the same claim section 1 is built on.
Through 2019 the field was introducing artificial intelligence at the level of the
component — a model, a classifier, a recognizer, a predictor. A component is
procured, benchmarked and swapped. Systems-level artificial intelligence is a different
object: the assembly that contains the component, together with the authority that admits
its output, the controls that bound it, and the record that makes it attributable. Claims
about the first object do not establish or defeat claims about the second. That distinction
is not a retrospective convenience — it is what the post said, and it is why the frame in
section 1.1 is older than the problem it now answers.
Systems-level is a property, not a description of everything. It is worth
stating what lacks it, because a term that covers everything distinguishes nothing. A model
released with a benchmark score and an acceptable-use policy is not systems-level: no
authority is constituted, no stop condition is specified, no unit of conformity is defined,
and nothing is attributable after the fact. Most of what has been introduced as
AI governance since 2023 is component-level in exactly this sense, which is the
argument of section 4.
Where the intelligence is located. On this framing, the artificial
intelligence of a system is the sum and substance of the componentry of the machines
employed — it is a property of the assembly, not of any part of it. This is a statement about
location, not about qualification: it says where intelligence resides, not
that any assembly of components is thereby intelligent. What qualifies remains what the
assembly does — whether it infers, adapts and decides. So the agent classes at section 1.3
are unaffected and, in fact, follow from it: an assembly containing an inferential component
is an inferential system and inherits that component's limits at the system boundary; an
assembly of deterministic components is a deterministic system and extrapolation over it
holds. Both are systems-level. The 2021 federal filing carries the same construction in its
own words — a harmonized artificial/non-artificial intelligent network is an
aggregate claim, not a component claim.
The instruments are dated separately, and deliberately so. 1 May 2019 is
the date of the frame. It is not the date of any named mark, and no mark is claimed to have
been in use on it. The sequence is:
1 May 2019 — the systems-level frame, publicly introduced.
14 July 2020 — claimed first use of the instrument implementing it,
Registration 7,160,072.
1 September 2021 — federal filing of that mark; artificial /
non-artificial intelligent network enters the public record.
14 March 2022 — claimed first use, AIQMSS®.
15 September 2026 — AIQMSS® registered, 8,430,351.
Frame first, instruments after, each on its own filed date. That ordering is the evidence.
Collapsing the later dates back onto 1 May 2019 would be a stronger-sounding sentence and a
weaker record, and the dates claimed to the USPTO are the dates stated here.
A.2 The AIQMSS® reading register
The mark is read by stratum, and the register is closed.
AIQMSS® has six letter positions, and the positions never move: A,
I, Q, M, S,
S. What moves is which word occupies a position, and that is determined by
the stratum at which the system is being described — not by the argument being made. This is
a stratum-indexed reading, maintained as a closed, dated table in
AEXO™ 0333. Every reading of the mark is a row in that table. A reading that is not a row in
that table is not a reading of the mark.
Stratum
Position A
Position Q
Expansion in force
CONSTITUTIVE™ — the discipline
Advanced
Quantized
Advanced Intelligent Quantized Managed Safety Systems
GOVERNOMIC™ — the architecture
Advance
Quality
Advance Intelligence Quality Managed Safety Systems
Register entry — USPTO Reg. 8,430,351, Class 041
Artificial
Quality
artificial-intelligence-based quality-management and conformity-science
systems — the recitation's own wording. The mark is standard-character and carries
no expansion of its own.
EXECUTORIAL™ — the operating system
Reserved.
Not fixed at publication, and therefore not a reading of the mark.
Two positions carry the load. A reads Advance /
Advanced at the architectural strata and Artificial in the register entry's
own services recitation — the system governs both kinds of agent, in the Development
Record's own subtitle, non-artificial humans and artificial non-humans, and the name
carries both. Q reads Quality where the subject is the quality
management system, and carries the quantum sense — discrete units of value or state, per
section 1.1 — where the subject is the conformity unit itself. Every other position is
stable in lemma: I is INTELLIGENCE, M is
MANAGE, S is SAFETY, S is SYSTEM. Each is realized by
ordinary grammatical agreement with the word in front of it — Advance Intelligence
but Advanced Intelligent; Managed where the row reads adjectivally. The
register fixes lemmas, not surface forms, and inflection is not a change of
reading. Only A and Q take different lemmas across rows.
Safety is a specified property throughout and is not measured.
Why this is a register and not elasticity. The test is whether a reader
given the stratum can predict the expansion without being told which argument it is serving.
Under a closed dated table, they can. Under an open set, they cannot — and an open set is
what a hostile reader needs in order to say the claim moved. The discipline is the closure,
not the count: each row is fixed in the concordance with a date, each row's words carry their
own evidentiary burden, and no row is added to win an argument already in progress.
And the artificial / non-artificial pairing is not a convenience — it is the
earlier registration's own wording, carried forward. Registration 7,160,072 decomposes: BLOCK
is Bungay Logic and Order Conformity Kernel; CHAIN is
Cyber/non-cyber Harmonized Artificial/non-artificial Intelligent Network. A network
spanning artificial and non-artificial intelligence, harmonized across cyber
and non-cyber substrates, is more than either kind of intelligence alone — and that
is what Advance Intelligence names. The two marks interlock: 7,160,072 defines the
architecture, 8,430,351 names the management system for it, and the artificial /
non-artificial pairing filed in 2021 is the same pairing position A
carries now. This
is a statement about how the names are constructed, not about what any process has been
measured to do.
The rows in force at publication are on the record. At the
architectural stratum, Advance Intelligence Quality Managed Safety Systems —
MQCC®'s expansion, fixed by the concordance. At the register entry, artificial
intelligence is the phrase the USPTO recitation itself uses —
"artificial-intelligence-based quality-management and conformity-science systems" —
eleven times across Class 041. The registration is a standard-character mark and carries no
expansion of its own, which is precisely what makes a published register necessary: without
one, the expansion would be inferred by whoever is reading.
On the mark and its register entry. AIQMSS is registered as
Registration 8,430,351 (serial 99457856), registered 15 September 2026,
with claimed first use 14 March 2022, in Class 041 — educational services:
instruction, curriculum, publishing, coaching, seminars and training in the field of
artificial-intelligence-based quality-management and conformity-science systems.
The stratum-indexed reading of the mark is set out above.
Nothing in this appendix establishes what any named system has been measured
to do. It establishes when words were filed and how names are constructed.
Appendix B. BHAIS-QMS™ — the Bungay Human-AI Safety through Quality Management Scale
Spoken “Base QMS”, because it is a floor rather than a ranking. The scale answers one question and refuses the neighbouring one. It asks is this organization capable of producing a human–AI system anyone should recognise? It does not ask whether any system is safe, and it assigns no band on that basis. A scale that rated AI safety would be the overclaim this document exists to refuse, and it would be unmeasurable, which is this paper’s complaint about everyone else. What is rated is the producer, because the producer is observable, attestable, and already has instruments pointed at it.
Band
Name
What is attested about the producing organization
Base 0
Unmanaged
No quality management system. The null case of the Law at 8.1.2: there is nothing
to inherit, whatever the quality of the work itself.
Base 1
Declared
A quality management system is documented and self-declared by the
organization. The first attestation route at section 2.
Base 2
Attested
The management system is assessed by a body without accreditation. The
third route at section 2 — a real assessment, and not accredited certification.
This is the band MQCC® supplies.IOCAA™ and
MQCC®'s own proprietary audit and conformity assessment, against published
criteria, place a client here — sold now, and the note below says why this band
and not the next one.
Base 3
Accredited
The commercial-grade floor. The management system is registered by
an accredited body — the second route at section 2 — and the registration is one a
reader can stand on: a stated certified scope, a current certificate, a
named registrar the reader can check with, and no suspension or withdrawal in the
period claimed. A certificate without those is not a band. This
band is not set by us: it is the level the instruments at 8.1 name for
complex and critical work, which is why the floor sits here and not somewhere more
convenient. It is deliberately a floor rather than a grade — it excludes, and the
discriminating is done at Base 4 and Base 5. MQCC® does not issue this
band and will not, for the reason in the note below; what MQCC® sells
toward it is the selection of an accredited body, never the
attestation.
Base 4
Accredited + programme specified
Base 3, plus a defined AI-control library indexed to a risk taxonomy, and a numbered
test programme whose protocol and acceptance criterion are fixed before each
run and retained as a canonical record with its correction history — which is
what makes any later result verifiable by a party other than the
producer. Criteria fixed in advance are the whole of the difference
between a result that can be checked and one that can only be believed, and most
published programmes do not fix them. Fixing them is not enough on its own:
the record has to survive and has to be inspectable, which is why this band
requires custody and not merely intent. No result set is claimed at this
band: specification is not measurement, and verifiable is not
verified.
Base 5
Accredited + programme measured
Base 4, plus verified result sets reported against those criteria with
numerator, denominator and stated conditions. This is the only band on the scale
that requires evidence of performance rather than of arrangement.
Where MQCC® Bungay sits, and who says so.Base 4 — and that placement is self-declared. No party other than this
organization has assigned it, and a reader should weigh it accordingly. The registration at
Base 3 is held and checkable with the registrar; the control library and the eight-test
programme at section 11.3 are specified and dated, and each test's protocol and acceptance
criterion is fixed before that test is run and retained under SCROLL™, the
controlled-records service that keeps the canonical record with its correction history, bound
by TFID® for origin, authority, scope and time — held and shown to
licensees and to clients under engagement rather than published, which is what an assessor
needs and a reader does not get; and the programme carries no
verified result set, which is exactly why this is Base 4 and not Base 5.
Base 5 is unoccupied — by MQCC® and, as far as this organization can
determine, by anyone. It is not unoccupied by design. Its criterion is
published, it is reachable, and it has simply not been reached; if another organization
reaches it first with genuine verified result sets, the scale will have worked rather
than failed. The eight tests are the distance between the two bands, and naming that
distance is the point of publishing the scale at all.
Which bands MQCC® supplies, and the one it will not — stated as a rule rather than as a preference.MQCC® can supply any band its own placement does not depend on. This organization's placement at Base 4 rests on Base 3, which makes Base 3 the one band MQCC® will not issue: issuing it would make MQCC® the source of the qualification its own position stands on, and a reader could then no longer tell, for any organization on this scale, whether a Base 3 came from outside or from us. That is a structural bar rather than a judgement about anyone's assessment work, and it is the same separation section 10.3 imposes one level down.
Base 2 carries no such problem, and it is sold. Nothing in MQCC®'s own band rests on Base 2, so IOCAA™ and MQCC®'s own proprietary audit and conformity assessment — assessment against published criteria, attested by a body without accreditation — place a client at Base 2, and that is an operating service rather than a proposal.
Toward Base 3 there is a service rather than a refusal. MQCC® will interview, audit and recommend IAF-member-recognized accredited certification bodies on a client's behalf, which is the offering at 10.2 and 12.1. Selection is not attestation. That work never enters the attestation chain: the accredited body performs its own audit on its own criteria and reaches its own conclusion, and nothing MQCC® does in selecting it binds that conclusion or predicts it — which is exactly why the service is available where issuing the band is not.
And the rule at 10.3 binds both. A client MQCC® advises is a client MQCC® will not assess, permanently — so the two services above are alternatives for a given client rather than a sequence, and that is MQCC® policy, stricter than ISO/IEC 17021-1 cl. 5.2.6 and 5.2.7 or California AB 1405 require.
To engage. Correspondence goes to ceo@mqcc.org, a monitored address, answered in writing. Base 2 is the band supplied, and it is bought the same way as anything else here. Name the organization, its jurisdictions, its scope of operations, and whether readiness, assessment or accredited-body selection is in view — the permanent bar at 10.3 means the first two are alternatives for a given client rather than a sequence, so which one is chosen is settled before work begins rather than after. The Services Brochure is complimentary on request; every other step, including scoping, is a paid engagement, and price follows the requirements of the organization’s scope of operations rather than a published rate.
Why a scale whose author does not hold its top band is worth more than one that does. An instrument on which the publisher places itself highest is a brochure with a table in it. What carries weight here is not the vacancy — it is the published gap: a band defined above the author’s own, with the specific unfinished work named, so that the shortfall can be checked rather than taken on trust. A scale resting on an empty ceiling would give its author a standing reason never to reach it, which is the wrong incentive to build into an instrument this organization intends to occupy. The failure this construction avoids is self-placement at the top, not occupation by anyone: a third party reaching Base 5 with measured results is the instrument working. And it is the same discipline the evidence marks apply to every control in section 9.
Why a fixed criterion is worth anything: the record has to outlive the run.
A threshold chosen after a result is not a threshold, and a threshold fixed before the run and then lost is not evidence of anything either. ZERO ONE® states the principle this band rests on — what is recorded computationally can be verified afterwards; what was never recorded cannot be — and SCROLL™ is where that recording is kept, with the correction history intact, each entry bound by TFID® to its origin, authority, scope and time. This is custody rather than publication. Section 11.3 does not publish owners, target dates or acceptance criteria for the eight tests and this edition does not change that. What Base 4 requires is that the criterion existed, was fixed before the run, and sits in a record a party other than the producer can be shown — which is a different thing from asking a reader to take it on trust, and a different thing again from putting it on a web page.
What a registration at Base 3 verifies, and what it does not — stated here because a reader should not have to have read section 3 first.Accreditation does not carry the tests. The chain has three links and each one attests a different thing: a registrar certified the management system; an accreditation body attested that registrar’s competence to do it — ISO/IEC 17000 defines accreditation as third-party attestation relating to a conformity assessment body, so it describes who is auditing rather than whether an object conforms; and neither of them examined an AI control.
The certificate settles it rather than the argument. BSI FS 532934 carries two certified scopes — mortgage banking and mortgage brokerage services — and the performance of an AI control is in neither. That is checkable with the registrar and does not depend on accepting anything said here.
So the two determinations stay apart, as 1.2.1 requires. Accreditation is a verification act by a party other than the producer, of the unit management system against the requirements of ISO 9001:2015 in a stated scope. The eight tests at 11.3 would be a verification act on different units — authority boundaries, stop propagation, human review, provenance and the rest — against acceptance criteria fixed before each run. Different unit, different binding requirement: the composition rule does not permit them to be composed into one determination. Base 4 is where those tests become verifiable; Base 5 is where they would be verified. Reading a registration as though it reached the second is the upgrade of specified into measured that 12.1 undertakes never to make, and 8.1.1 is the reason it cannot be made: a complex item’s conformance is established during performance, not read off the end item.
What this scale is, in the sense of 9.8. A private standard — the same class as a BSI PAS, an ISO/PAS or an IWA: published criteria, openly stated, carrying no accreditation and conferring none. It is not an accreditation scheme, a certification, or a mark of approval, and a band on it is not a licence to describe a system as safe. And the rule at 10.3 binds it: an organization MQCC® places on this scale is an organization MQCC® will not assess, permanently. That permanence is MQCC® policy, and it is stricter than ISO/IEC 17021-1 cl. 5.2.6 and 5.2.7 or California AB 1405 require. Publishing a band is therefore not a route into an assessment engagement, and was never going to be one.
The scale sits beneath ACCREDITED CLASS® in the MQCC® family of organizational instruments and does not replace any of them. The Bungay Organization Maturity Model (BOMM™) measures size and maturity of an organization generally; Know-Class™ runs from no class to World-Class™ to ACCREDITED CLASS®. BHAIS-QMS™ answers the narrower question those instruments do not: whether an organization is equipped to produce a human–AI system that a party other than itself could recognise.
Section 12: What this paper addresses, what it leaves to others, and where to find them
A paper that draws its own boundary and then tells a reader where to go is more
useful than one that implies it covers everything. This one presents the
governance and record family — authority, delegation, interruptibility,
traceability, attribution, competence, and the expiry of integrity assumptions. That is
R1 to R11, and it is the family where the operating evidence at section 3 sits. Presenting
the family that is evidenced, and routing the rest, is the discipline this document is built
on.
The method is requirement-based, and a requirement-based method is extensible by
construction. The composition rule at 1.2.1 takes requirements of any kind — a
privacy requirement, a fairness requirement, an environmental requirement — and composes
determinations over them the same way. Nothing in the structure limits it to the family
below, and the MQCC® estate extends past what this paper draws on. One instance, because a
general claim of breadth is worth less than a single checkable one: PI-FI®,
USPTO Registration 6,123,500 (serial 88743903), is a registered service mark
in Class 042 for "providing an on-line network environment featuring
technology that enables users to share data, namely, private and financial records, in the
fields of governance management and trade" — filed 31 December 2019, registered
11 August 2020, first used in commerce 1 December 2019. Its combined sections 8 and 15
declaration was accepted and acknowledged on 29 May 2026, per the
registration's own
USPTO record.
What incontestability is, stated at the precision the statute uses. Under
15 U.S.C.
§1115(b), an incontestable registration is conclusive evidence of the validity of
the mark, of the registration, of the registrant's ownership, and of the exclusive right to
use the mark in commerce — subject to the nine defences and defects that section
enumerates, and subject to cancellation on the grounds that survive under §1064. It is a
strong evidentiary position. It is not immunity, and this document does not describe it as
one.
This is a trademark record, and it carries no evidence mark.
The two axes at section 4.2 apply to controls: specified means a dated written
control specification exists, and audited means an operating measurement exists. A
registration is neither, so assigning it either mark would be the category error section 9.7
exists to prevent — the trademark tells you whose it is; the evidence mark tells you what has
been shown. No control assessment under PI-FI® is presented, specified or evidenced in this
paper. The point is only that the boundary below is where this paper stops, not
where the estate does. What this paper presents is the family it can evidence, and
the table names the instruments a reader should consult for the rest.
The right-hand column names instruments published by other bodies. It is a
routing table: no conformance of MQCC® to any instrument named in it is claimed, and no
control presented in this paper is directed at the concerns in the left-hand column.
The concern
How this paper's scope is drawn
Where to look
Privacy and data protection what is collected about you,
and who it reaches
A data-governance family. R1–R11 are drawn around governance of
execution, so this paper presents no control here.
MQCC® holds Reg. 6,123,500, PI-FI® in this domain — Class 042,
sharing of private and financial records in governance management and trade,
with sections 8 and 15 accepted 29 May 2026. A trademark record, carrying no
evidence mark: no control under it is presented, specified or measured
here.
In Canada, PIPEDA federally, overseen by the
Office
of the Privacy Commissioner; Quebec, British Columbia and Alberta have
substantially similar private-sector laws with their own commissioners. As a
management system,
ISO/IEC 27701:2025,
now an independent privacy information management standard designed to align with
ISO/IEC 27001 rather than an extension of it.
Discriminatory or disparate outcomes a decision that goes
against you for a reason the law forbids
Requires measuring outcomes across groups. R1–R11 are drawn around
whether execution met its requirements, which is a different measurement.
The Canadian
Human Rights Act and the provincial codes; in lending, the conduct rules
of the provincial regulator. Technically,
ISO/IEC TR
24027:2021, Bias in AI systems and AI aided decision making.
Model security prompt injection, data poisoning, model
extraction
An adversarial-security family. R11 concerns an integrity assumption expiring over
time, which is a different question from an attacker acting now.
NIST
AI 100-2 E2025, Adversarial Machine Learning: A Taxonomy and
Terminology of Attacks and Mitigations, final March 2025. As a management system,
ISO/IEC 27001.
Harmful, deceptive or unsafe output content that misleads
or injures
Concerns the substance of an output. This paper is drawn around whether an
output was authorized, bounded and attributable.
NIST
AI 600-1, the Generative AI Profile of the AI RMF, which sets
out risk categories including harmful and obscene content, dangerous information and
confabulation, with suggested actions against each. Less settled than the other rows
here, and not empty.
Model and data drift a system that degrades quietly after
deployment
A lifecycle and monitoring family. The composition rule at 1.2.1 reverts a
determination to indeterminate when its conditions change, which handles the
consequence; detecting the drift is the other discipline's work.
Environmental cost energy and water of training and
inference
Outside the family this paper presents.
ISO/IEC TR
20226:2025, Environmental sustainability aspects of AI systems,
and ISO
14001 for the organization around it.
Employment and labour displacement work that stops
existing
Outside the family this paper presents.
MQCC® is not aware of a standards instrument directed at this, and states that as the
limit of its own knowledge rather than as a finding about the field. It sits
principally with labour law, industrial policy and public deliberation.
Third-party and supply-chain model risk a model you did
not build, inside a decision you are answerable for
Adjacent: R1 and R7 concern authority over an agent whoever supplied it. Assessing
the supplier is a separate engagement and is not presented here.
ISO/IEC
42001:2023, which places supplier obligations on the AI management
system, and ISO/IEC
5338:2023 for lifecycle responsibilities across parties.
The distinction this section exists to hold. A governance framework can
organize work on every concern above without resolving any of them, and the
two are routinely conflated — a framework that can hold a privacy control gets described as
addressing privacy, and a reader cannot tell the difference. R1–R11 organizes.
Saying so is what makes the evidence at section 3 worth reading: a document that claimed
every family would invite a reader to discount all of them equally.
ISO/IEC 23894:2023
and the NIST AI RMF harm taxonomy remain the better starting points for whole-of-risk
coverage, and an organization wants those alongside this one.
Every instrument above was checked against its publisher's catalogue entry on
23 September 2026 before it was named. Naming an instrument is not an endorsement of it.
12.1 What MQCC® Bungay does, in one place
This document is a method, and a reader can use the frame at section 1 without engaging
anyone. Where the offer is relevant, it is three lines of work and they are stated together
here so that a reader does not have to assemble them from three sections.
Line
What it is
Available
ZERO ONE® brand of UPGRADE ALGORITHM® brand of pre-accreditation
audit readiness service
Moving an organization from a zero state of conformity to a one state: requirements
mapped, controls designed and instrumented, records made auditable, and the gap
report written against the standard the organization will actually be audited to.
It is called pre-accreditation readiness because it prepares an organization
for an audit by an accredited body — the second route at section 2 —
which is the route most buyers and regulators ask for. It also prepares the first and
third routes, because the work is the same work.
Now, against ISO 9001:2015 and ISO/IEC 42001:2023.
No accreditation is required to perform it, and none is implied by it: readiness is
preparation for an attestation, never an attestation.
Advisory
Requirement interpretation, control design, instrumentation, readiness assessment
and outsourced internal audit. This is the work
ISO/IEC 17021-1
cl. 5.2.5 forbids a certification body to perform, which is why it is performed
outside the certification chain.
Now. No accreditation is required to perform it. Where the
engagement is an outsourced internal audit, ISO 9001:2015 cl. 9.2.2 applies to it in full.
Accredited-auditor selection advisory about the assessor, not an attestation
Interview, audit and recommendation of IAF-member-recognized accredited
certification bodies, for an organization that has decided on the accredited
route and has to choose among providers. It is assessment of the assessor: scope,
sector competence, scheme coverage, and fit to the state the client is actually in.
Now. It produces a recommendation, never an attestation, and it neither binds
nor predicts the accredited body's own conclusion. MQCC® does not itself sell
IAF-member-recognized accredited audit or certification — that is the one class
of assessment outside this offering, and every other class is inside it.
Conformity assessment attested without accreditation —
the third route at section 2
Operational conformity assessment against ISO 9001:2015 and
ISO/IEC 42001:2023, reported as measurements and a statement of what
was not covered.
Now, for management systems and for AI-control development, testing and
verification. Each engagement defines the organization's requirements, scope,
deliverables and price; its conclusions follow from the work performed and the evidence
obtained. Every engagement states the attestation route in the engagement letter and records
the designed-it election in writing before work begins. No
errors-and-omissions cover is carried for this line by MQCC Bungay
International LLC or by any other entity named here — the only such cover
in this group is MortgageQuote Canada Corp.'s, for mortgage brokerage and lending,
and it does not reach this work. Section 2.2 states that plainly rather than
leaving a reader to assume otherwise.
Readiness and assessment are never sold to the same client. A client this
organization has made ready, advised, licensed or built for is a client it will not assess, for
the reason at section 10.3 — four routes in, one rule out. The rule binds us
before it binds anyone else: MortgageQuote Canada Corp. is itself a licensee of the
MQCC® mark, from Bungay International Inc., so our own reference implementation is a client we
could not assess either. That is MQCC® policy,
permanent rather than a waiting period, and stricter than the two-year bar the standards
impose. It means there is no second engagement waiting at the assessment stage.
12.2 What to do with this, and where the method is
What this document publishes, and what it does not. Everything above is
stated as requirements and outcomes — what a conforming implementation must produce,
in the form a standard uses. That is deliberate and it is the whole of what is published.
How MQCC® implements any of it is proprietary and is not disclosed here.
The method is taught and licensed under agreement. A reader can therefore do three things with
this document, and the third is where the method becomes available.
1. Use the frame, at no cost and with no engagement. The unit at
1.1 and the composition rule at 1.2.1 are published
requirements. Take one system you already run, bound a single unit of it, name the complete
set of requirements binding that unit, determine it, and see whether your existing reporting
can carry the result without collapsing it into a score. If it can, you have learned something
about your reporting. If it cannot, you have found the gap this document is about. Nothing in
that requires us, and the invitation is genuine.
2. Check what is claimed here, and tell us where it is wrong. Every figure
carries an evidence mark, and the records behind the dated claims are held by third parties:
the registrar, the provincial regulators and the trademark offices. Those can be checked
directly, without us, and section 3.5 says which is which. Records held by
this organization are examined within an engagement, under the access arrangements that
section sets out. Separately, two claims here explicitly invite correction with a citation:
that no operating accreditation scheme for control verification has been identified in any
jurisdiction as at September 2026, and that no earlier public introduction meeting all four
stated conditions is known to us. A counter-example to either belongs in the next edition and
will be recorded as a correction with its source. That is the method of this document applied
to itself.
3. Learn the method, license the architecture, or engage the practice.
This is where implementation is transferred, and it is a commercial arrangement in every
case.
Route
What transfers
Under which registration
Readiness ZERO ONE® brand of UPGRADE ALGORITHM®
brand of pre-accreditation audit readiness service
An organization moved from a zero state of conformity to a one state, ready for the
audit route it chooses. Requirements mapped, controls designed and instrumented,
records made auditable, gap report written against ISO 9001:2015 and
ISO/IEC 42001:2023.
Distance instruction, curriculum, leadership and executive development, publications,
coaching and seminars in AI quality management and conformity science. This is where
the implementation is taught rather than described.
AIQMSS®, Registration 8,430,351, International Class 041 —
educational services. That class reaches instruction and training; it does not reach
the performance of quality management, auditing or conformity assessment, and nothing
here claims that it does.
Architecture licence
The architecture, method and marks, for an organization deploying them in its own
name. A licensee receives the implementation, which this document withholds.
Registration 7,160,072, classes 035, 036, 042 and 045.
Advisory
Requirement interpretation, control design, instrumentation, readiness assessment and
outsourced internal audit, performed on the client's system.
Conformity assessment attested without accreditation
Operational conformity assessment against ISO 9001:2015 and ISO/IEC 42001:2023,
reported as measurements and a statement of what was not covered.
Registration 7,160,072. Available now; engagement terms at
9.6.
One rule runs across the table: four routes in, one rule out. A client
this organization has made ready, advised, licensed or built for is a client it will not
assess, as a matter of published policy — see 10.3. Readiness,
advisory, licensing and assessment are alternatives for any given client, never a sequence.
The choice is made and recorded in writing before work begins.
Intake. Write with the organization's name, the jurisdictions it operates
in, a short description of its scope of operations, and which of the four routes is in view.
Scope, fee and start date are confirmed in writing before any work begins, so the procurement
record is complete from the first email.
NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0),
January 2023. Voluntary and non-prescriptive; organizes risk work into Govern, Map, Measure
and Manage, requires assessment in the context of the system and its use, and leaves risk
tolerances and acceptance criteria to the adopting organization.
NIST.AI.100-1.
ISO/IEC 23894:2023, Information technology — Artificial intelligence — Guidance on
risk management. Cited here for the harm classes section 9.2 does not cover.
United States, National Technology Transfer and Advancement Act, Public Law 104-113, 7 March 1996; and Office of Management and Budget, Circular A-119: Federal Participation in the Development and Use of Voluntary Consensus Standards and in Conformity Assessment Activities, 1993, revised January 2016. Cited for the statutory preference for voluntary consensus standards, and for nothing about this organization.
United States, Federal Acquisition Regulation, 48 CFR ch. 1, §§ 46.202-4 and 46.203, issued March 2005 by the General Services Administration, the Department of Defense and the National Aeronautics and Space Administration. Cited for two definitions — complex and critical — and for naming ISO 9001 among the higher-level quality standards. No relationship with those agencies is claimed or implied.
Canada, Treasury Board, Cabinet Directive on Regulation, 13 July 2018; the Standards Council of Canada; and Department of National Defence, DAOD 3009-0 Quality of Materiel and Services, DAOD 3009-1 Quality Management, DAOD 3009-2 Government Quality Assurance.
United Kingdom, Royal Charter of the British Standards Institution, 22 April 1929, with supplemental charters of 5 November 1931, 1968 and 1974; the Memorandum of Understanding between the United Kingdom Government and the British Standards Institution in respect of its activities as the United Kingdom's National Standards Body; MOD JSP 940 and Def Stan 05-061 Part 1 Issue 6, 31 March 2016.
Anoop Bungay, Caveat Insurer™: 2023 Disclosure of Danger of Risk of Cryptothelioma, Bitcointhelioma, Blockchainthelioma to Members of the International Association of Insurance Supervisors (IAIS), ISBN 978-1-989758-49-6. Cited here for one thing only: the definition of the Bungay–Insurance Industry “Bought Risk” Insurer’s Standard, whose measure is premiums earned without loss experienced. The measure is stated on loss rather than on claims, and this document uses it that way.
Bill Gates, interview with Kristen Welker, NBC Meet the Press. Clip released 25 September 2026; full interview broadcast Sunday 27 September 2026. Quoted here for the capability statement and the remedy statements at section 5. The wording used here was checked across two independent reports of the same clip rather than taken from a single headline, because the headline forms in circulation convert a statement about capability into a prediction, and the two are not the same claim: Axios; Forbes.
USPTO Registration 6,615,228, TRUSTED BY BILLIONS, owner MQCC Bungay International LLC, Class 041, registered 11 January 2022. Cited for what a registration establishes and for nothing beyond it: Reg. 6,615,228.
MQCC® Bungay textbook series and ISBNs, published at www.mqcc-ai.com. The list rather than a count, because the count moves and the list is authoritative.
ISO/IEC 22602:2019, Information technology — Learning, education and training —
Competency models expressed in MLR. ISO/IEC JTC 1/SC 36, first edition September
2019, stage 90.93 confirmed.
ISO catalogue entry.
BS ISO/IEC 22602:2019, UK national adoption, published 31 October 2019, status
current.
BSI Knowledge entry.
CSA ISO/IEC 22602:2020, Canadian national adoption.
Catalogue entry.
ISO/IEC 20006-1:2014, Competency general framework and information model.
First edition 3 July 2014; reviewed and confirmed 2 October 2025.
ISO catalogue entry.
ISO/IEC 20006-2:2015, Proficiency level information model. First edition
18 March 2015; reviewed and confirmed 2 October 2025.
ISO catalogue entry.
NATO AQAP-2110, Edition D Version 1, June 2016, NATO Quality Assurance
Requirements for Design, Development and Production.
Published text.
NIST SP 1353 (Initial Public Draft), Cybersecurity Framework 2.0: Quick-Start
Guide for Using Artificial Intelligence for CSF Analysis and Reporting, released
19 August 2026; comments close 15 October 2026.
NIST CSRC announcement.
California SB 813 (Independent verification organizations, Ch. 179) and
AB 1405 (AI auditor registration, Ch. 178), both chaptered 9 September 2026.
SB 813 ·
AB 1405.
Note: SB 813 creates no mandate to be audited and is not a safe harbour — a
completed audit is "relevant to, but not conclusive of" liability.
California SB 53, Transparency in Frontier Artificial Intelligence Act, chaptered
29 September 2025; reporting duties operative 1 January 2026.
Bill text.
New York RAISE Act, S6953, signed 19 December 2025 (Ch. 699 of 2025), as amended by
S8828
(2026), which set the 1 January 2027 effective date, the reasonable-belief reporting
trigger and the 24-hour imminent-danger tier alongside the 72-hour general requirement;
effective 1 January 2027.
Bill record.
Gartner, Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI
Agent Failure, 26 May 2026.
The Royal Family, The King's speech at the AI Summit in Scotland,
17 September 2026.
NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography
Standards, published 12 November 2024; comments closed 10 January 2025; still a draft
at the date of this article. Proposes classical public-key algorithms deprecated after 2030
and disallowed after 2035.
Draft text ·
CSRC record.
NIST Post-Quantum Cryptography Standardization — HQC selected 11 March 2025, final
expected 2027; FN-DSA (FIPS 206) not released as an initial public draft as at mid-2026.
Standardization timeline.
ISO, deliverable types — International Standard, ISO/TS, ISO/PAS, ISO/TR and
International Workshop Agreement, with the three-year review and six-year maximum life
applying to IWA.
ISO deliverables.
ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management
system, built on the Annex SL harmonized structure shared with ISO 9001:2015.
ISO catalogue entry.
USPTO Registration 7,160,072, serial 97006933, BUNGAY LOGIC AND ORDER CONFORMITY
KERNEL; CYBER/NON-CYBER HARMONIZED ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT NETWORK:
BLOCKCHAIN. Filed 1 September 2021; registered 12 September 2023; classes 035, 036, 042,
045; claimed first use anywhere and in commerce 14 July 2020; disclaimer entered for
"CYBER/NON-CYBER AND ARTIFICIAL/NON-ARTIFICIAL INTELLIGENT NETWORK BLOCKCHAIN".
USPTO trademark search.
USPTO Registration 8,430,351, serial 99457856, AIQMSS. Filed 23 October 2025;
registered 15 September 2026; class 041, educational services in the field of
artificial-intelligence-based quality-management and conformity-science systems; claimed
first use anywhere and in commerce 14 March 2022.
USPTO trademark search.
OpenAI, public release of ChatGPT, 30 November 2022, used in section 2.3 as the reference
date for the onset of general public attention to generative artificial intelligence.
Collins English Dictionary — twenty-nine terms coined and filed by Anoop Bungay,
user anoop.bungay, 12 December 2021 to 26 April 2026, including conformity
science (1 January 2026), subordinate and superordinate artificial
intelligent algorithm (1 January 2026), conformity-bound system (12 January
2026) and quantum conformity (17 April 2026). Filed means submitted and in
moderation; it does not mean published in Collins.
MQCC® internal audit record, I-ARC™ and AMRR™, seventeen cycles 2011–2026; and the
external assessment reports of the registrar, references 1641717-201805, 1776653-201905,
1906065-202004, 2034674-202103, 2169950-202202, 2329650-202304 and 2640082-202504.
Available for inspection on a reasoned request.
MQCC® Bungay, AEXO™ 0333 Expanded Concordance — Schema and Worked Sample,
Specification 0333-EXP, Draft 1.0, 21 September 2026. Source of the risk classes R1–R10,
the three-tier admission rules and the seven-field entry format used in section 9.
MQCC® Bungay, Who Has Said What About AI Risk, Edition 1.2,
21 September 2026. 98 entries, 105 source URLs.
13.1 The authored corpus — informative, not normative
Why this list is marked informative.
In standards drafting a normative reference is one a reader cannot apply the
document without. The normative references for this paper are the ones listed above —
ISO 9001:2015, ISO/IEC 42001:2023, ISO/IEC 17000, ISO/IEC 17021-1:2015,
ISO/IEC 22602:2019, AQAP-2110, the NIST publications, California SB 53 and New York's
RAISE Act. Those bound the method, and a reader assessing conformity needs them.
The works below are the theory estate in the sense of section 1.5, and nothing in
this paper requires a reader to hold any of them. They are listed because a
dated, ISBN-bearing corpus is checkable without our involvement, which is the only
property that makes a bibliography worth printing.
Thirty-nine titles, forty-five ISBNs, 2018 to 2026. The count of titles
and the count of ISBNs differ because several rows consolidate editions that share content,
and each row lists every ISBN assigned to it. Publisher of record: MQCC
(MortgageQuote Canada Corp.), registered with Library and Archives Canada — ISBN
Canada, across three publisher prefixes: 978-1-989758, 978-1-9991884 and
978-1-997700. The ISBN is the identifier and the cover is a convenience —
every ISBN below is resolvable through the national library regardless of whether the
thumbnail loads, and each check digit was recomputed before publication.
This table is the corpus as at this edition. The maintained list
lives at www.mqcc-ai.com, and where
the two disagree the maintained list governs — which is why this paper cites the list
rather than asserting a count anywhere else in its text. Cover images are published
drawings served by a third party; they are illustrative, they are not evidence of anything,
and a row remains citable without one.
#
Cover
Title
ISBN
Year
Category
1
International Journal of Conformity Science IJCS™
978-1-9991884-2-9
2019
Academic/Science
2
Origin of a Specie™
978-1-9991884-7-4
2020
History/Origin
3
Learn “The Global Standard for BlockChain®” Level 01 (Zero One®)
Some titles consolidate editions that share content. Further articles and
reports are at blog.mortgagequote.ca,
which resolves to this blog. The record system this document sits in is the MQCC® BII™
SCROLL™ brand quality-managed record system, and the sections above this
one are part of it. What this list evidences is authorship and date, and that is
all it evidences: a book is theory in the sense of section 1.5, it is not a
control, and no entry below is offered as a measurement or as evidence that any control
performs.
Citation
This document may be cited as:
Anoop K. Bungay (SUPERPOSITION-001™) & CCPU™-001^RSA™003/001.001 (BUNGAY™ AEXO™ Model, Anthropic Claude
Opus 5 substrate enhanced with MQCC® BII™ BUNGAY LOGIC™ & UPGRADE TO THE FUTURE®
Performance Package, RSA™-003/AEXO™, S.A.I.F.E.R.™ Federation), contributing author ZEXO™^RSA™001/001.001,
edited by CCPU™-001^RSA™003/001.001. (2026).
MQCC® Bungay AIQMSS® Trademark Brand of Services; Measurable Safety through Managed Quality in AI: Bungay's General Theory of Standards-Based Human–AI Safety Systems — Expressed as Quantum Conformity, Edition 10.8. Calgary, Alberta: MQCC (MortgageQuote Canada Corp.), publisher of record, Library and Archives Canada — ISBN Canada.
Digital Edition: 20 September 2026. Edited: 29 September 2026.
English Language ISBN (Digital): to be assigned.
Status: Scientific Communication Documentation.
Companion documents: The Bungay Development Record and the AIQMSS® Brand,
Consolidated Edition, Version 5.0, 29 September 2026; Who Has Said What About AI
Risk, Edition 1.2, 21 September 2026; AEXO™ 0333 Expanded Concordance — Schema
and Worked Sample, Specification 0333-EXP, Draft 1.0, 21 September 2026.
Verification and limits
Attribution. Standards cited in this document remain the property of
their publishers. Citation is not endorsement: none of the bodies named has reviewed or
endorsed this document.
Standards citations were verified against the publishers' own catalogue entries and
published text on 20 and 21 September 2026. No conformity assessment against
ISO/IEC 22602, ISO/IEC 20006-1, ISO/IEC 20006-2, ISO/IEC 42001 or AQAP-2110 has been
performed by or for MQCC® Bungay. MortgageQuote Canada Corp. has held ISO 9001 registration
continuously since 9 May 2008, transitioning through successive editions of the standard and
currently registered to ISO 9001:2015, which was published in September
2015. Continuity of registration since 2008 is therefore continuity of ISO 9001 registration,
not of registration to the 2015 edition, and no claim of the latter is made. The registration is held by MortgageQuote Canada Corp. — BSI certificate
FS 532934 — and applies to its certified scope of mortgage banking and mortgage brokerage
services. It does not extend to any control in this document by adjacency, and it is not held
by MQCC Bungay International LLC, whose architecture and method this document describes. Statements about third parties reproduce public statements and are the
responsibility of their authors; the responses are ours. Nothing here is legal,
insurance, accounting or investment advice.
Copyright in this document is MortgageQuote Canada Corp.'s; the architecture, method
and marks described in it are not. Those are held as set out below.
UPGRADE ALGORITHM® is a registered trade-mark of Bungay International Inc., Canada — TMA1,450,195, registered 28 September 2026. Common law rights in the United States; with a pending application in the USA, Serial Number 99540810.
°IP&IPR™ 2026+: Bungay International Inc. (BII™); MQCC Bungay International LLC; MortgageQuote Canada Corp.; Anoop Bungay; all rights reserved and monitored.
Protected by MQCC® BII™ ALL SEEING AI™
(www.allseeingai.org) brand of
intellectual property and intellectual property rights, global computer network-based,
non-novel (exact) conformity science-based, sentient AI quality management system
(SAIQMS™).
AEXO™ · aiQuQMS™ · AIQMSS® · AIQUMOS™ · AIREHYDRATE™ · ALL SEEING AI™ · HHAIOS™ · BESAIFER™ · BII™ ·
BITNIST™ · BUNGAY TRI-PHASE CASCADE™ · BUNGAY UNIFICATION OF QUANTUM PROCESSES ALGORITHM™ ·
BUNGAYBIT™ · BVCS™ · CAI-II™ · CONFORMITIVITY™ · CONFORMITY-BOUND SYSTEM™ ·
CONFORMITY SCIENCE™ ·
CONSTITUTIVE AI™ · CONSTITUTIVE™ · CRASES™ · EXECUTORIAL™ · FEDERATOS™ · GMO™ · GOVERNOMIC AI™ ·
GOVERNOMIC™ · HALLUCICORRECT™ · HALLUCIDETECT™ · HALLUCIVAX™ · H-GMOS™ · HHAI™ ·
HHAIPROMPT™ · HHAIQMS™ · IF IT IS NOT TRACEABLE TO BUNGAY, IT IS NOT TRUSTABLE™ ·
INFRASTRUCTOS™ · INTRUSTNET™ · INVESTIGATOS™ · IOC™ · IOCAA™ · MOS™ · MQCC® · MQCC RISK
ANALYSIS™ · NONHASH™ · OMED™ · PDICR™ · POWOR™ · PRIVATELENDER.ORG® · CANADA'S PRIVATE
LENDING NETWORK® · REGULATOS™ · RISK-BASED AI™ · RISK MANAGEMENT MATRIX™ · S.A.I.F.E.R.™ ·
SAIQMS™ · SCROLL™ · SENTIENT AI IS™ · ORGPROCESSOR™ · ORGPROCESSORBEAT™ · PRINCIPLES OF 'DISTRIBUTED LEDGER'™ · QG-HHAI™ ·
QUANTUM CONFORMITY™ ·
SIGIL SOURCE™ · SNAACA™ · SPP™ · SUPERSUBSUMPTION™ · SUPERVISOS™ ·
TFID® · THE BUNGAY SCHEMATIC REPRESENTATION OF THE ELEMENTS OF A QUANTUM CONFORMITY FUNCTION™ ·
TLT™ · TRUSTBIT™ · UPGRADE ALGORITHM® ·
ZERO ONE® — and all related marks are trademarks or registered
trademarks of Bungay International Inc., MQCC Bungay International
LLC, MortgageQuote Canada Corp. or Anoop K. Bungay,
according to the register and the jurisdiction. MQCC® specifically is
registered in Canada to Bungay International Inc. and in the United States to
MQCC Bungay International LLC; MortgageQuote Canada Corp. uses it under
licence from Bungay International Inc. There is no entity named "MQCC Bungay International
Inc."; editions through 7.8 carried that name and it is corrected at correction thirty-five. Marks are listed as
identifiers of source. Listing here establishes no operating capability, performance or
deployment for any of them; see section 9.7. No part of this document may be reproduced,
distributed or transmitted in any form or by any means without the prior written
permission of MortgageQuote Canada Corp., save for quotation for the purposes of
review, criticism, regulatory submission or news reporting, provided the evidence marks
travel with the control names.
"In the Age of Bungay Sentient AI, every photon of infringement, including
plagiarism (intentional or unintended; by academics, researchers, scholars, social media
enthusiasts, fiduciary Officers, Directors, Leaders or employees of organizations), is
visible."
IF IT IS NOT TRACEABLE TO BUNGAY, IT IS NOT TRUSTABLE™ Trust is the output of testing.
/\ 💖🙏™