The National AI Governance Playbook · Part II · Chapter 5
The full policy and regulatory chain
A principle binds only when it reaches a control a deployed system must pass. This chapter sets out the six links of the policy and regulatory chain that carry it there, locates the two regimes' instruments along the chain, and gives completeness a working test: the chain can be walked in both directions.
Evidence basis: MindXO design recommendation. A MindXO traceability chain connecting principles to operational controls.
By Myriam Ayada · MindXO · Version 1.1 · Updated 21 July 2026
In brief
A principle binds only when it survives translation into evidence a deployed system must produce. Six links connect the principle to a two-layer evidence record. The horizontal regime supplies reusable technical evidence; the usage-based regime adds contextual evidence and makes the regulatory decision. A Regime Interface Agreement states what can be reused, what each sector adds, who may request more, and how findings escalate. A complete chain can be walked down to both evidence layers and back up to the rule that requires them.
Why the chain matters
Governments write principles; deployed systems run controls. Everything in between is translation, and each step of that translation is performed by a different institution using a different instrument. A national strategy declares that AI must be safe and accountable. What a bank operates, three years later, is a model inventory, a testing schedule and an escalation procedure. The distance between those two artefacts is not rhetoric; it is a sequence of documents, each converting the one above it into something a narrower audience can act on.
Chapter 2 examined the states a governance program passes through, and Chapter 4 grouped the machinery into two regimes. This chapter follows a single thread down the whole length of the system: the chain of instruments that connects a principle at the top to a control at the bottom. It matters because the chain is where designs actually fail. Programs rarely lack principles, and organisations rarely lack controls. What breaks is the middle: laws no rulebook translates, rulebooks that cite no standard, controls whose evidence never travels back up.
The six links
Six links recur in every jurisdiction, whatever the legal tradition. The names of the instruments vary; the sequence does not.
L1. Principle: what the country stands for
Owner: cabinet, through the national strategy. Instrument: the strategy itself, and the international principles it adopts (Chapter 1). Force: declaratory. It obliges no one, and it legitimises everything below it.
L2. Designed policy: what the principle means in practice
Owner: the design stage of Chapter 2, wherever the jurisdiction houses it. Instrument: a white paper, an impact assessment, a designed policy with scope, roles and funding. Force: administrative. It commits the government's intent without yet binding anyone outside it.
L3. Binding instrument: what makes it law
Owner: the legislature or the executive, depending on the vehicle. Instrument: a statute, a decree, targeted amendments or an existing statutory plan; Chapter 8 chooses among them. Force: legal and general. From this link down, obligations exist.
L4. Regulatory rulebook: what a sector must do
Owner: the sector regulators of the usage-based regime. Instrument: rules, supervisory guidance and licence conditions, written in each sector's terms. Force: legal and specific. This is where an obligation acquires a supervisor, an inspection and a sanction.
L5. Standard and assurance scheme: what technical evidence can be reused
Owner: standards body and accreditation authority. Instrument: common technical baselines and accredited schemes for evaluation and assurance providers. Force: technical, by reference. It creates reusable evidence, not a complete deployment judgment.
L6. Controls and two-layer evidence: what the deployment must demonstrate
Owner: deployers and independent assurance providers, with requirements set and decisions made by sector regulators. Instrument: technical evidence plus local data, intended use, human oversight, workflow, outcomes, monitoring and incident response. Force: operational and evidentiary.
Sheet 05 of 13: rulebooks at link four define contextual requirements; common standards and accredited schemes at link five supply reusable technical evidence; link six combines both layers for the sector regulator's decision. The Regime Interface Agreement governs reuse, requests and escalation.
Where the two regimes sit on the chain
The usage-based regime occupies links three and four: law creates obligations and sectoral rulebooks make them specific, including contextual assurance requirements. The safety and security regime is concentrated at link five, where standards, evaluation methods and accredited schemes create reusable evidence. Link six is shared: deployers and independent providers combine technical and contextual evidence, while sector regulators decide and enforce.
The interface is more than a citation. Each rulebook must identify the technical evidence it accepts, contextual evidence it still requires, events that permit more testing, disclosure and confidentiality rules, and the escalation path. In every design, the rulebook must say where reusable evidence ends and contextual judgment begins.
Traceability, in both directions
The test of a complete chain is that it can be walked both ways. Downward, from any principle: which instrument binds it, which rulebook applies it, which standard defines it, which control evidences it. Upward, from any control: which rule requires it, under which law, in service of which principle. The downward walk answers how a commitment is enforced. The upward walk answers why a control exists, and it is the walk auditors, courts and boards actually take.
Walked this way, the symptoms of Chapter 2 acquire an address. An undated international commitment is a break between links one and three: a principle with no binding carrier. An overlapping mandate is two owners claiming the same link. A rulebook that demands safety without citing any standard is a break between links four and five, and it quietly delegates the meaning of safety to every firm and every assessor separately. Evidence that is produced but never read is a break at link six, where the chain fails to close. Locating a gap on the chain converts a general unease about implementation into a named document that is missing, with an owner who can be asked to produce it.
Common failure mode. A certificate without context. Reusable technical evidence is treated as proof that a deployment is acceptable, while no one tests local data, intended use, human oversight, workflow, outcomes, monitoring or incident response. The certificate is valid for what it covers and misleading for what it does not.
What the chain settles
- Completeness has a definition. A governance program is complete when every principle it declares reaches at least one control, through named instruments with owners and dates. Anything less is a chain with missing links, however polished the strategy.
- The interface is a design decision. Each rulebook must state which technical evidence it reuses, which contextual evidence it adds, who may request more and who decides.
- Evidence must have a return path. Link six produces the only proof the system generates. Who reads it, at what cadence, and what it can trigger belongs to the measurement design of Chapter 12.
- The vehicle question is scoped. Only link three is about choosing a legal vehicle. Treating the whole chain as a legislation problem overloads the statute; Chapter 8 sizes the instrument to the link.
The chain closes Part II. The architecture now has its two regimes, their interface, and the instruments that carry both from principle to control. Part III turns to the design phase itself: Chapter 6 opens the five questions that allocate the links to institutions, beginning with the question every other one depends on, who does what.
Three questions for every government
- For each principle the strategy declares, which binding instrument, rulebook and control carry it, and can the walk be made in both directions?
- Where does each sectoral rulebook state the technical evidence it reuses, the contextual evidence it adds, and the authority that decides?
- Which links of the chain have a named owner and a date, and which exist so far only as intent?
Selected public sources
- Regulation (EU) 2024/1689 (AI Act), European Union, 2024
- Standardisation request to CEN-CENELEC in support of safe and trustworthy AI, European Commission, 2023
- A pro-innovation approach to AI regulation, white paper and government response, United Kingdom, 2023 and 2024
- Introduction to AI assurance, UK Department for Science, Innovation and Technology, 2024
- FEAT Principles, Monetary Authority of Singapore, 2018
- AI Verify, IMDA and AI Verify Foundation, Singapore, 2022
- ISO/IEC 42001, AI management systems, ISO/IEC, 2023
- AI Risk Management Framework and Generative AI Profile, NIST, 2023 and 2024