The AutoGovern Governance Standard
Version 1.0. The published, versioned methodology behind every AutoGovern Rating — every table on this page is rendered directly from the same scoring code the Rating API runs, not a hand-written copy. If the weights below ever change, this page changes with them, on the same day.
1. Rating dimensions
A rating combines up to four dimensions at these base weights. Any dimension a system has no data for (e.g. no Control Plane activity yet) is dropped and the remaining weights are renormalized — a system is never penalized for a signal it has no way to produce.
| Dimension | Base weight | What it measures |
|---|---|---|
| Assessment readiness | 55% | The underlying assessment score (0–100) from the Governance Assessor or Workbench dossier the Trust Passport was issued from. |
| Assurance level | 20% | How the passport's governance claims were verified — self-reported, evidence-linked, or independently audited (see levels below). |
| Control Plane health | 15% | Deny/guardrail rate from this system's own Agent Control Plane ledger activity — only counted once a system has real logged actions. |
| Incident exposure | 10% | How closely this system's profile matches real, documented AI incidents (Incident Intelligence), banded Low → High. |
2. Assurance levels
Computed at Trust Passport issue time from linked evidence — never user-selectable. A customer can never simply claim a higher level.
| Level | Score | Definition |
|---|---|---|
| self assessed | 50/100 | Based on customer-supplied information — not independently verified. |
| evidence verified | 85/100 | Linked to real evidence (freshness-checked, control tests passed) via the Agent Control Plane ledger and Controls Register. |
| independently assured | 100/100 | Reviewed and signed off by an external auditor through the Auditor Portal. |
3. Incident exposure bands
From Incident Intelligence: how closely a system's profile matches real, documented AI incidents.
| Exposure | Score |
|---|---|
| Low | 100/100 |
| Moderate | 75/100 |
| Elevated | 45/100 |
| High | 15/100 |
4. Materiality — how much governance quality matters here
A flat weighting would treat a low-stakes internal tool the same as a biometric ID system. Materiality shifts weight away from self-reported readiness and toward evidence (Control Plane telemetry, real incident exposure) as stakes rise. A "prohibited" or "high" EU AI Act tier bumps materiality up one notch regardless of domain.
| Materiality | Domains | Readiness | Assurance | Control Plane | Incidents |
|---|---|---|---|---|---|
| High | Biometric ID / categorisation, Law enforcement, Justice & democratic processes, Critical infrastructure safety, Healthcare & medical, Migration, asylum & borders | 0.85× | 1.1× | 1.4× | 1.5× |
| Moderate | Employment, HR & recruitment, Credit & financial scoring, Insurance pricing / risk, Essential public services / benefits, Education & vocational training | 1× | 1× | 1× | 1× |
| Low | everything else | 1.15× | 0.9× | 0.7× | 0.6× |
5. Rating bands
| Band | Score range | Label |
|---|---|---|
| A | 90–100 | Exemplary |
| B | 75–89 | Strong |
| C | 60–74 | Adequate |
| D | 40–59 | Developing |
| F | 0–39 | At Risk |
Versioning
This is v1.0, published alongside the Rating's launch. Weights may be revised as the platform and its underlying data mature; any revision will be dated and disclosed on this page — a rating computed under an earlier version is never silently re-labeled as having been computed under a later one.