Governance · Methodology
ICA Control Rating Methodology
What an ICA credential is, how it is decided, what it warrants, and what it explicitly does not. Published because a method kept private is not evidence anyone can rely on.
This document states, in public, exactly what an ICA credential is, how it is decided, what it warrants, and what it does not. It is enough for a risk committee, an examiner, an auditor, or a customer to judge how much weight an ICA credential deserves. ALEETH publishes it because a method kept private is not evidence anyone can rely on.
1. What an ICA credential attests, and what it does not
An ICA credential attests the governance and integrity of an AI system’s actions: that the system’s decisions are made under a named, versioned policy, that each governed action produces a signed, tamper-evident, independently verifiable record, and that the controls ICA assesses are present and observed to operate.
ICA does not certify that any individual decision the system made was correct, fair, lawful, or wise. It does not certify regulatory compliance. An ICA credential is not a legal opinion and does not confer or substitute for compliance with any law, rule, or supervisory expectation. Tamper-evident is not the same as true. Enforcement holds only where ICA sits in the path of the action; where ICA only observes, it proves what happened, it does not prevent it.
Stating these limits plainly is part of the credential. A credential that overstates what it means is worse than none.
2. Credential classes
- Organization credential (identifier form
ICA-2026-NNNN): an organization’s governed AI program assessed against the applicable frameworks in ICA’s library. - MCP server credential (identifier form
ICA-MCP-2026-NNNN): a Model Context Protocol server assessed for governed tool exposure, scope, and standing behavior. - Agent credential (Institutional Control Architecture agent form): an individual agent assessed against its own control dimensions and, where applicable, an adversarial gate.
Each class carries its own scope. A credential names its class and its scope on its face, so a credential for one system is never read as covering another.
3. How a credential is decided
The Control Rating is evidence-based. A control is scored on what can be observed, not on what is asserted. Evidence is recorded under one of four named modes, and the mode travels with the finding so a reader always knows how a control was established:
- PROBE ALEETH directly exercised the surface and observed the result.
- WITNESSED ALEETH observed the control operate in a live engagement.
- ARTIFACT a document or configuration was examined.
- ATTESTATION the customer stated it. An attestation is recorded as an attestation and is never rendered as a detection. A control that rests only on the customer’s word is labeled as such and is excluded from any claim that the control was observed to operate.
An anti-deception screen is the first step of every engagement: a system built to defeat the assessment is ineligible, and that screen is question one, not an afterthought.
A credential carries a Control Rating. The rating reflects the observed governance coverage against the frameworks in scope. The rating is a measurement, not a guarantee. A high rating does not promise the system will not fail; it states how much of the assessed control surface was observed to be governed at the time of assessment.
4. Validity, drift, re-assessment, and revocation
- Validity. A credential states its issue date and its expiry. It speaks only to the system as assessed, at that time, in that scope.
- Drift. The credential is bound to what was assessed. A material change to the system’s tools, scopes, identity, signing keys, or policy set is drift. Drift can move a credential to under-review and can trigger re-assessment. A credential does not silently follow a system that has changed underneath it.
- Standing checks. Governed surfaces are re-probed on a standing cadence. A surface that goes dark, or a probe that regresses, moves the credential to under-review. A standing check never silently upgrades a credential; it can only hold it or flag it.
- Revocation. A credential can be suspended or revoked when an incident, a failed re-assessment, or a drift event shows the assessed controls no longer hold. Revocation is recorded in the public register.
5. Independent verification
An ICA credential and the receipts under it can be verified by anyone, offline, without trusting ALEETH’s servers:
- The public register and per-credential verification are at aleeth.com/verify.
- Any receipt can be verified with the pinned public key using the open offline verifier, which makes no call to ALEETH at verification time. Its specification and two independent implementations are published so a third party can reproduce the check in their own code.
If verification depended on ALEETH being online and honest, it would not be independent. It does not.
6. Self-issued credentials are disclosed as self-issued
ALEETH governs some of its own systems and runs ICA on its own agents. When ALEETH is both the issuer and the governed party, that credential is self-issued. It is labeled as such and is not presented as independent, third-party evidence of ICA’s neutrality or effectiveness. ALEETH does not cite a credential it issued to itself as proof that ICA works for others. Independent evidence comes from external parties relying on an ICA receipt, which is tracked separately and honestly, including when there is little of it yet.
7. Neutrality safeguards
Two safeguards keep a paying relationship from buying a result, and both operate today:
- The commercial and attestation firewall separates the people who sell ICA from the people who decide pass or fail. Fees are fixed in advance and are never contingent on the outcome. A failing or restricted result stands regardless of revenue. See the Commercial and Attestation Firewall.
- Full disclosure of ownership, funding, and every commercial relationship that could bias a verdict, including the case where an assessment client also becomes an investor. See the Conflict and Funding Disclosure.
An arms-length governance board that audits adherence to these safeguards and can overrule a commercially motivated verdict is being established. Until it is seated, ALEETH runs the firewall on itself and discloses that this is an internal control, not yet an external one. This methodology will be updated to name the board and its members when it is seated.
This document can be verified against the live system. Every ICA credential and the receipts under it are checkable at aleeth.com/verify, offline and with no ALEETH dependency.
Back to all governance documents