The Decision Infrastructure Canon™ Founding Edition · The Decision Layer Compass™

The Approval Exists. Can You Defend the Decision?

Most governance files can show that something was reviewed, approved and reported. Far fewer can show who had the authority to commit the organisation, what evidence made the choice reasonable, where the boundary sat, who challenged it, and what would force the decision back onto the table. That is the gap this issue calls Decision Infrastructure.
Authority · Evidence · Boundaries · Traceability · Challenge · Reopening
Published29 September 2026
Read time15 minutes
Use forThe next 30 days
ClassificationFounding Canon · Executive and board circulation
The founding reference

September has a fifth Tuesday. Rather than stretch the normal monthly cycle, this Founding Edition establishes the permanent reference for Decision Infrastructure within The Decision Layer Compass™.

Future intelligence, case studies, regulatory analysis and instruments apply the six components introduced here: Authority, Evidence, Boundaries, Traceability, Challenge and Reopening.

01 · Executive summary

Three decisions requiring attention this month.

Governance can be busy and still leave no defensible decision behind. The policy may exist. The assessment may be complete. The committee may have met. Six months later, the file still may not answer the only question that matters: why was this decision reasonable at the time?

Decision Infrastructure is the layer beneath that question. It connects six things that are usually managed separately: Authority, Evidence, Boundaries, Traceability, Challenge and Reopening. None is exotic. The failure comes from treating them as separate governance activities rather than as one decision system.

This month starts with a simple discipline: take one consequential AI decision and make the decision itself, rather than the process around it, the unit of governance.

  1. Name the decision owner, not the collection of reviewers.

    A material AI decision can involve Technology, Risk, Legal, Privacy, Security, Procurement and a business sponsor. That is useful expertise. It is not authority. The organisation still needs one person who can say yes, no, not yet, or yes within a defined boundary, and who remains answerable after the meeting ends.

    Decision Infrastructure Authority · Owner Board, ARC or accountable executive · Evidence Named decision right recorded against the decision class · Escalate If the answer is a committee or a function
  2. Set the evidence standard before the next decision arrives.

    Evidence assembled after a challenge is usually slower, more expensive and less persuasive. Different decisions deserve different proof. A low-impact internal assistant may need little more than a named rationale and boundary. A customer-facing autonomous decision may require technical testing, legal interpretation, supplier evidence, independent assurance and a record of uncertainty.

    Decision Infrastructure Evidence · Owner CRO with CIO and CAE · Evidence Minimum evidence standard by decision class · Escalate If material decisions are still approved on presentation quality rather than defined evidence
  3. Give every durable decision a reopening trigger.

    A decision does not become permanent because the minutes were approved. Models change. Suppliers change. Autonomy increases. Regulation moves. Performance drifts. A decision that was sound in June can become indefensible in October without anybody doing anything wrong. The reopening trigger is what prevents a reasonable decision from ageing into an inherited assumption.

    Decision Infrastructure Reopening · Owner Original decision owner · Evidence Written trigger tied to change, threshold, incident or time · Escalate If nobody can say what would force reconsideration
02 · Five emerging risks

Where Decision Infrastructure fails before the decision visibly fails.

  1. Permission mistaken for authority

    An agent can inherit credentials that were properly granted to an employee and still exercise judgement that nobody delegated to software. The access control may be correct. The authority can still be wrong. This is becoming the cleanest example of why technical permission and organisational mandate have to be separated.

    Board implication Ask which agent actions rely on a human permission that was never re-approved as an agent decision right
  2. Evidence ageing while the decision remains open

    The model version changes. The retrieval source changes. A supplier alters the service. The workflow is tuned. The approval remains untouched because nothing crossed the organisation's formal change threshold. The evidence is still in the file, but it now describes an earlier decision environment.

    Board implication Ask what change would make the evidence supporting an existing approval no longer sufficient
  3. Supplier change without a governance event

    Contractual change rights are designed to keep services moving. They can also allow the substance of a decision to move without creating a fresh approval. A notice can be contractually valid, operationally routine and strategically material at the same time.

    Board implication Ask which supplier changes alter a decision boundary rather than merely update a service description
02 · Five emerging risks, continued
  1. Challenge aimed at controls rather than the decision

    Risk asks whether the assessment was completed. Security asks whether the access is appropriate. Legal asks whether the contract permits the use. Internal Audit asks whether the control operated. Every question can be sensible and still miss the judgement that committed the organisation.

    Board implication Ask who challenged the decision itself, including the rejected alternative and the uncertainty being accepted
  2. The decision that never comes back

    Most governance frameworks are good at getting a proposal to approval. They are weaker at bringing an approved position back when the facts move. That matters because AI changes in increments. No single change may look material enough to trigger escalation, while the accumulated effect quietly produces a different system from the one originally approved.

    Board implication Every durable decision needs a reason to reopen, not merely a date to review
The Decision Infrastructure implication

These are not six new control families. They are six questions attached to one consequential decision. A strong framework should also be able to say that a component is working. Not every review needs to manufacture a finding.

03 · Regulatory radar

The formal deadline is only one clock.

Regulation increasingly creates a second date that matters just as much: the point at which engineering, procurement, evidence and governance lead times leave too little room to make the decision well.

DateObligation or decision pointDecision Infrastructure view
11 Sep 2026Cyber Resilience Act reporting obligations are live for actively exploited vulnerabilities and severe incidents affecting products with digital elements.Who has authority to classify and notify while evidence is incomplete?
2 Dec 2026AI Act transition for relevant synthetic-content marking requirements ends for qualifying systems placed on the market before 2 August 2026.64 days. The engineering decision may already be earlier.
2 Dec 2027Key Chapter III requirements apply to Annex III high-risk systems under the amended AI Act timetable.Classification, ownership and evidence standards need to exist before implementation becomes urgent.
11 Dec 2027Main Cyber Resilience Act product obligations apply.Product decisions made during 2027 can create evidence and design debt before the formal date.
2 Aug 2028Key Chapter III requirements apply to Annex I high-risk systems under the amended AI Act timetable.A deferred date is not a reason to defer architecture decisions.
Latest safe decision date

The legal deadline tells you when the obligation arrives. The latest safe decision date subtracts the time needed to procure, design, build, test, evidence and govern the response. Once that date passes, the organisation may still have time on the calendar while having very little choice left.

04 · Incident analysis

The upgrade nobody approved.

The following is an anonymised composite drawn from recurring advisory patterns. No firm is identifiable from it.

A regulated firm had used the same onboarding supplier for five years. The contract allowed the supplier to update decisioning components with notice, provided the service remained within agreed performance and security parameters.

The original service relied heavily on configured rules. During a routine release, one part of the identity and risk workflow became model-driven. The supplier disclosed the change in the release material. The service manager logged it. Security saw no new access. Procurement saw no contract breach. Legal saw no consent requirement under the existing clause.

Nothing in the process was obviously broken.

Four months later, complaint patterns changed and an executive asked who had approved the move from a rules-based decision step to a model-driven one.

There was no approval to find.

The contract had authorised the supplier to make the change. The process had recorded it. Nobody had decided whether the organisation was willing to accept the different judgement mechanism inside a customer outcome.

The transferable point

A contract can authorise a change. A process can record it. A dashboard can report it. None of those means the organisation made a decision about the new exposure. Supplier change clauses therefore need a reopening threshold: the point at which a valid service change becomes a fresh governance decision.

05 · Sector signals

The same six questions travel well.

SectorDecision Infrastructure signal
Financial servicesCustomer outcomes can move from human judgement to model-supported or agent-executed decisions without a matching transfer of decision rights. Authority and evidence deserve separate testing.
Healthcare and pharmaA validated or approved technology state can change through models, data, suppliers and workflows. The important question is which change reopens the original assurance position.
Employment and HRRecruitment, screening and workforce decisions expose the gap between tool approval and decision authority quickly. Boundaries should follow the employment decision, not the procurement route.
Public sectorWhere automated or AI-assisted decisions affect citizens, traceability has to preserve not just the output but the authority, evidence and challenge that made the decision defensible.
06 · Board questions

Six questions for the next committee.

One for each component. If the answer requires a reconstruction project, the delay is part of the finding.

  • Authority: Who had the right to make our most consequential AI decision this quarter, and what could that person decide without further approval?
  • Evidence: What evidence had to exist before that person could say yes, and was the standard defined before the decision arrived?
  • Boundaries: What exactly did the approval permit, and which change would move the activity outside that boundary?
  • Traceability: Could a successor reconstruct the decision in fifteen minutes without interviewing the original participants?
  • Challenge: Who was expected to contest the judgement, not merely confirm that the process was followed?
  • Reopening: What event, threshold or elapsed time would force the decision back onto the table?
07 · Actions for the next 30 days
ActionTest of completionOwner
Select one consequential AI decisionA named decision from the last six months, not a programme, policy or inventoryCRO / CIO
Write the authority lineOne named person, the decision they may take, and the point at which they must escalateExecutive sponsor
Set the evidence standardThe minimum evidence required for this class of decision is written before the next case arrivesCRO with CAE
Define the reopening triggerAt least one measurable change, threshold, incident or time condition that returns the decision to governanceDecision owner
Run the 15-minute reconstruction testA person who was not in the original meeting can explain the decision, evidence, boundary, challenge and reopening condition from the record aloneCAE / Assurance
08 · Decision dashboard

One page. Take it into the room.

Editorial position for this issue. These scores are not a firm-level assessment.

Decision Infrastructure confidence
48
New baseline
Editorial position
Decision Infrastructure risk radar
Decision authority ambiguity91
Evidence ageing86
Reopening gap84
Supplier change without reapproval82
Challenge scope mismatch76
Traceability fragmentation68
Regulatory clock
CRA vulnerability / incident reportingLive
AI synthetic-content transition64 days
Annex III high-risk timetable2 Dec 2027
CRA main product obligations11 Dec 2027
Annex I high-risk timetable2 Aug 2028
Open positions this issue
Named decision owner by decision classOpen
Minimum evidence standardOpen
Supplier change thresholdDefine
15-minute reconstruction testRun once
Reopening trigger libraryOpen
The six components
AuthorityHigh attention
EvidenceHigh attention
BoundariesTest
TraceabilityTest
ChallengeTest
ReopeningHigh attention
The one thing
If the board does one thing this month

Take one consequential decision and reconstruct it. If you cannot show who decided, on what evidence, within which boundary, after what challenge, and what would reopen it, the governance file is not finished.

09 · Evidence and sources
  1. Regulation (EU) 2026/1744, amending Regulation (EU) 2024/1689. The amended timetable includes 2 December 2026 for the transition affecting relevant Article 50(2) synthetic-content marking obligations, 2 December 2027 for relevant Annex III high-risk provisions and 2 August 2028 for relevant Annex I high-risk provisions.
  2. European Commission, Safer and more secure digital products, 11 September 2026. Cyber Resilience Act reporting obligations apply from 11 September 2026; the main product obligations apply from 11 December 2027.
  3. Regulation (EU) 2022/2554, Digital Operational Resilience Act. Financial entities remain responsible for ICT risk, including ICT third-party risk, and must maintain a register of information for ICT third-party contractual arrangements.
  4. Incident analysis is an anonymised composite drawn from recurring advisory patterns. It illustrates the distinction between a valid service change and a fresh governance decision. No firm is identifiable from it.
  5. The Decision Infrastructure components and dashboard positions are editorial constructs of The Decision Layer Compass™. Dashboard scores are issue positions, not measured sector benchmarks or firm-level assessments.
Source discipline

Regulatory positions are current to 25 September 2026 and should be revalidated against primary sources before circulation if the publication date moves. Interpretive statements in this issue are editorial analysis, not legal advice.

Apply the Canon

Test one consequential decision. Use the AI Decision Reconstruction Test™ to see whether you can reconstruct the authority, evidence, boundary, traceability, challenge, and reopening logic without calling the people who were in the room.

Run the AI Decision Reconstruction Test™ →

Next in the cycle

The regular publication cycle resumes on Tuesday 6 October with Board AI Risk Intelligence · Issue 03. From that edition onward, Authority, Evidence, Boundaries, Traceability, Challenge and Reopening become the standing Decision Infrastructure lens across The Decision Layer Compass™.

Contact

Replies to this Founding Edition are read by the author.

Maman Ibrahim
maman@thedecisionlayer.online
https://thedecisionlayer.online