The Governance Evidence Taxonomy. The schema counterparties read. The evidence standard for governability.
In plain terms: the shared format insurers, lenders and acquirers use to read a company’s governability as evidence, so the risk can be priced rather than taken on trust. Everything below is how that format works.
Governance resolves into four operational layers. Source systems emit signals. The schema translates them and makes them machine-readable. Counterparties price against it. Resilience capital follows. Arkaya stewards Layer 1.
The Governance Evidence Taxonomy does two things at once. Both have to be true for capital markets to price governance at AI speed.
Insurance speaks of severity. Audit of control failure. Legal of exposure. Accounting of materiality. Finance of covenant breach. The same governance reality, five professional vocabularies that don't talk to each other. GET specifies one shared evidence grammar that every discipline can read.
The eight fields are observable values, structured for direct ingestion, sealed so a stranger can check the record. AI agents, underwriting engines, due-diligence platforms and rating systems parse evidence without human interpretation, at the speed risk now transmits.
Arkaya stewards the schema, and the schema is what makes governance evidence comparable, portable and adjudicable across parties. That property, not measurement, scoring or pricing, is the difference. The measurers, scorers, self-certifiers and pricing engines act on the evidence; none supplies the schema that gives it those properties.
Hazard found its home at Edward Lloyd's coffee house in 1688. Credit at Moody's in 1909, formalised by the SEC's NRSRO designation in 1975 and embedded in bank capital adequacy under Basel II in 2004. Governance is now the third domain, and it has been priced by inference rather than evidence for forty years.
It has always been a distinct domain of risk. What it lacked was the observation infrastructure to be classified as one, so it got lumped into compliance, ESG and operational risk. Carl Woese took decades to establish Archaea as the third domain of life, separate from Bacteria and Eukarya, on the strength of molecular sequencing. Agentic AI is doing the same work for governance: forcing the failure mode into a register no prior frame can hide.
Archaea is also the domain that thrives where the others cannot, in hydrothermal vents, polar seas, acid pools and saturated brines. The biology that lets these organisms survive hostile conditions is structurally what resilience capital does for an organisation. It is not the absence of stress. It is the apparatus that turns stress into evidence the system can read.
The Governance Evidence Taxonomy is the schema that resolves that. It translates risk across the disciplines that price it: insurance, finance, audit, legal and accounting. It makes that translation machine-readable. Eight observable fields. Sealed so a stranger can check the record. Trajectory-aware. Read by every counterparty: D&O, cyber and W&I underwriters; lenders; acquirers; reinsurers; claims handlers; defence counsel.
A declaration is never taken on its word. What a counterparty reads is a sealed record it can check for itself, and only for the interval the record covers.
The taxonomy is primitive-level by design. Counterparties read primitives and construct their own assessments. No score is summed from the schema. No rating is issued from Layer 1.
The schema organises by what an organisation governs, not what it is exposed to. A taxonomy of risk types is incomplete by construction: cyber was not a category a generation ago, AI was not one five years ago. Governance domains are stable. A new risk arrives as evidence inside an existing domain, not as a new domain. The board ranks the domains material to enterprise value; the counterparty calibrates the grade; each domain carries evidence on a four-grade ladder: Asserted, Attested, Evidenced, Verifiable.
"All I want to know is where I'm going to die, so I'll never go there."
Moody's published its first manual in 1909. The SEC introduced the NRSRO designation in 1975. Basel II embedded ratings in bank capital adequacy in 2004. Counterparties outsourced credit due diligence because a structured approach to credit rating existed. The rating became the procurement proxy. Governance ratings already exist. None surfaced Wirecard, Greensill, FTX or Credit Suisse before the moment governance was tested.
Refusing the rating-agency posture at Layer 1 is the precondition for the taxonomy to do work. The discipline that holds the architecture together: schema decisions are made on a separate governance track from commercial decisions. If the schema's evolution were biased by commercial pressure, the rating-agency failure mode would re-enter through the back door. That is the place this schema dies. It is built never to go there.
The W3C, ISO and IEEE precedents apply. A standards authority defines conformance criteria. Multiple implementations compete on engineering quality. Comparability and interoperability are preserved by certification, not by ownership.
Schema decisions are insulated by instrument, not by intention. Under the Schema Independence Charter, no commercial counterparty and no commercial function inside Arkaya may overrule a schema decision, and schema custody is not a revenue line: there is no fee for inclusion and no paid tier of the schema. Arkaya is Custodian of the schema and Founding Assessor; on handover to the Custos Foundation the assessor function devolves to accredited labs, while the Custodian role persists. Regulators reference such standards; they do not adopt them, and the regulator polices the structure of a rating, not its substance.
Engines sit at the boundary between Layer 0 source systems and Layer 1 evidence. An engine is software that reads source telemetry and emits GET-conformant evidence at the cadence the schema requires. The cadence cannot be met by point-in-time review; the engines are AI engines by necessity, not by choice. Machine-readable underwriting requires machine-cadence evidence: the decision stays human and is recorded; the observation does not.
Conformance is defined by the schema, not by any one engine. To be GET-conformant, evidence must record a named human decision against the obligation it bears on, carry the provenance of each hop, and link to that obligation at the cadence the schema sets. What conformant evidence must demonstrate is fixed by the schema. How an engine produces it is the engine's own.
Protocol: board-authored executable. Signal: from live controls. HITL Decision: the accountable judgment, named and timestamped. Evidence: captured against obligation. Improvement is what the loop produces.
Schema stewarded by the Custodian. Engines certified against it. Counterparties read both.
The GET Conformance Programme, run by the Custodian, is the open test an engine is measured against. The conformance suite and the reference adapter sit with the Custodian as part of that programme. Engines are tested for schema fidelity, and an engine that has passed can be substituted without breaking counterparty continuity. Custos Infinity is an engine built against the schema; further engines, an underwriting read surface, and distribution and capacity partners sit alongside it at Layer 2, against the same Layer 1 contract. The programme's test material is candidate and no engine has yet passed it, so none is described here as having done so. Where a programme retains risk by design, the underwriting platform from Centinel 10 finances the retained share as contingent capital. Multi-engine by open test, not by accident.
Resilience Capital is built.
Not asserted.