Governance Frame Editorial Standards
These are the explicit editorial standards established for Governance Frame Research. They bind manuscripts, briefings, newsletters, executive stories, methodology documents, and public corrections.
Companion documents:
what-governance-frame-is.md— mission and identityoperating-outline.md— roles, tools, and cadence
Core editorial rule
Governance Frame must make it possible for a reader to distinguish what the evidence establishes, what Governance Frame concludes, what remains uncertain, and what action is merely being recommended.
That is the central standard protecting its institutional credibility.
1. Editorial independence
- Governance Frame is not an Ironframe marketing site.
- Ironframe should almost never be the subject of Governance Frame research.
- Research conclusions must not be written backward from Ironframe’s product architecture.
- Ironframe may appear only as a clearly disclosed implementation example.
- Governance Frame must never imply that a regulator, law, or standard requires Ironframe.
- Product capabilities must be separated from research findings.
- Commercial relationships, product references, and potential conflicts of interest must be disclosed.
- Editorial decisions must remain separate from Ironframe sales and product-marketing objectives.
- “Independent” means editorially independent, not necessarily legally or financially unrelated to Ironframe.
2. Vendor neutrality
- Research must remain vendor-neutral.
- Publications must not become GRC product comparisons unless explicitly commissioned and methodologically framed as such.
- Vendor claims cannot be used as proof of industry facts.
- Competitive-analysis documents may provide secondary context but cannot serve as primary evidence.
- No publication may imply that one product, platform, database model, or technical architecture is universally necessary.
- Product examples must be labeled separately from regulatory requirements and analytical conclusions.
3. Evidence before opinion
- Material factual claims must be supported by citations.
- Primary sources should be used whenever reasonably available.
- Secondary sources may provide context but should not replace primary authority for material claims.
- A citation must support the exact claim beside it — not merely discuss the same general topic.
- Sources must be inspected before being marked verified.
- A citation may not be reused simply because it appeared in an earlier draft.
- Each source must be evaluated for authority, scope, date, applicability, and limitations.
- The source ledger must identify which claim each source supports.
- Unsupported claims must be removed, softened, or marked unresolved.
- Research must distinguish what is known from what is inferred.
4. Never invent evidence
- Do not invent citations.
- Do not invent quotations.
- Do not invent statutes, regulatory language, enforcement actions, or standards.
- Do not invent dates.
- Do not invent statistics.
- Do not invent financial figures.
- Do not invent customers, case studies, certifications, logos, or endorsements.
- Do not invent links, source titles, authors, or publication details.
- Do not mark a source verified unless it has actually been checked.
5. Separate types of statement
Every substantive publication should clearly distinguish among:
- Documented fact — directly supported by evidence.
- Analytical interpretation — Governance Frame’s reasoned conclusion.
- Illustrative example — hypothetical or simplified scenario.
- Architectural recommendation — a possible governance or control response.
- Product relevance — how a named product may implement part of the recommendation.
- Unresolved research question — an issue not yet answered by sufficient evidence.
These categories must not be blended together.
6. Regulatory precision
- A regulation must not be described as requiring something it does not expressly require.
- Laws, regulations, regulatory guidance, standards, professional frameworks, proposals, and commentary must be identified accurately.
- Final rules must be distinguished from proposed rules.
- Adopted measures must be distinguished from measures already in force.
- Guidance must not be presented as law.
- Professional frameworks such as COBIT, COSO, OCEG, or NIST voluntary guidance must not be described as binding unless made binding through another authority.
- Regulatory scope must be stated accurately.
- Sectoral and jurisdictional limitations must be preserved.
- Provider, deployer, controller, processor, registrant, covered entity, and similar legal roles must not be treated as interchangeable.
- Effective dates, transition dates, and deferrals must be checked near publication.
- A publication must not imply uniform enforcement where national or sectoral regulators differ.
- Legal determinations must remain with qualified management, counsel, regulators, courts, or other authorized parties.
7. Financial-figure discipline
- Do not add unrelated penalties, settlements, remediation costs, compliance costs, and estimates into a synthetic total.
- Every monetary figure must be labeled by type.
- Distinguish among: civil penalties; settlements; consumer-relief funds; compliance costs; remediation costs; operational losses; insurance payments; investor losses; estimated exposure.
- Historical public figures must not be presented as an organization-specific forecast.
- Public enforcement figures are examples, not universal loss models.
- Every financial number must be traceable to a public source or reproducible methodology.
- Unsupported estimates must be excluded.
- Correct currency storage does not make a risk estimate defensible.
- Quantitative risk analysis must document assumptions, frequency, loss magnitude, uncertainty, sources, methodology, limitations, and review.
- Qualitative ratings must not be dismissed as inherently invalid.
- The defensible position is that qualitative ratings may be insufficient by themselves for some financial, capital, disclosure, or board decisions.
8. Citation and quotation standards
- Use the most authoritative available source.
- Prefer the enacted statute, official regulation, regulator release, court filing, standards publication, or official study.
- Use exact source titles and authors.
- Confirm that DOI references correspond to the stated paper.
- Do not cite a landing page when a precise instrument or report is available.
- Short quotations must preserve the original wording.
- Quotations must be used sparingly and only when exact wording matters.
- Paraphrases must not broaden the source’s meaning.
- Allegations in complaints or enforcement filings must be identified as allegations.
- Settlements must not be described as adjudicated findings unless the record supports that description.
- Dismissed, narrowed, pending, or appealed matters must be described with their current procedural status.
- Retrieval or verification dates should be retained in source records.
9. Research ledgers and traceability
- Material claims should be represented in the source-verification ledger.
- Each ledger entry should record: claim identifier; claim text or summary; supporting source; source type; verification status; exact support; limitations; date sensitivity; reviewer notes.
- References in the manuscript must correspond to ledger entries.
- Source limitations must be recorded rather than hidden.
- Open research questions should remain visible until formally resolved.
- Questions closed as out of scope should be marked as such rather than deleted silently.
- Revision history must record material editorial changes.
- Corrections must be documented.
- A significant correction should not be silently overwritten.
10. Tone and voice
Governance Frame’s voice should be: calm; analytical; practical; institutional; evidence-first; restrained; readable by executives without oversimplifying the subject.
It should avoid: hype; fear-based marketing; sensationalism; exaggerated certainty; product evangelism; adversarial language used merely for effect; claims such as “AI will replace everything”; claims that one product “solves everything”; generic SEO-style “Top 10” content unless the format has a genuine research purpose.
Terms such as “heatmap theater,” “spreadsheet theater,” “checklist industrial complex,” and “poisoned lakes” should be removed, moderated, or clearly identified as commentary rather than fact.
11. Research-paper standards
- Formal research papers must have a defined research ID.
- They must maintain a complete source package including: manuscript; references; source-verification ledger; revision history; editorial-review notes; metadata.
- Formal papers should state scope and methodological limitations.
- They should prioritize durable analysis over time-sensitive commentary.
- They should not be presented as peer-reviewed unless they have actually undergone peer review.
- They must state that they do not constitute legal advice.
- The canonical repository source remains authoritative over rendered or editorial copies.
12. Briefing standards
- A briefing should focus on one governance problem, regulatory development, or operating issue.
- It must not pretend to be a complete historical research paper.
- Its title should accurately describe its scope.
- A briefing should separate evidence, interpretation, and recommended control posture.
- It should not duplicate a formal paper without identifying itself as a companion or summary.
- Executive companion briefs should explicitly name the authoritative long-form paper.
- Briefings may be shorter and more practical, but citation standards remain the same.
- Briefings remain quarantined until operator approval.
13. Newsletter standards
- Newsletters should interpret current developments through governance rather than merely repeat headlines.
- Newsletters must distinguish what has happened from what is proposed or expected.
- They should be time-stamped and checked again near publication.
- They should explain implications without overstating certainty.
- Each newsletter should have a distinct lead topic.
- Newsletters in the same editorial slate should not compete for the same primary subject.
- A newsletter should not become a disguised product promotion.
- Current-event claims must be checked against official sources at publication time.
14. Executive-storytelling standards
- Executive stories must teach a real governance lesson.
- Illustrative scenarios must be clearly labeled as hypothetical.
- Fictional organizations, events, and numbers must not be confused with documented cases.
- The story should show decisions, evidence, accountability, incentives, and consequences.
- Storytelling must not exaggerate regulatory outcomes merely for drama.
- The governance lesson must remain more important than the cinematic effect.
- Product demonstrations and Governance Frame stories should remain separate unless the commercial connection is clearly disclosed.
15. AI-use standards
- AI may assist research organization, drafting, editing, or synthesis.
- AI output must not be treated as verified evidence.
- AI-generated facts, citations, quotations, or numbers must be independently checked.
- Human reviewers remain accountable for the final publication.
- AI-assisted text must pass the same citation and editorial standards as human-drafted text.
- Sensitive, confidential, privileged, or restricted information must not be placed into unauthorized AI tools.
- AI-generated public statements require substantive human review.
- “Human in the loop” must define authority, competence, review expectations, and escalation — not merely a click.
- Governance Frame should publicly disclose its material use of AI in research and drafting.
- AI must not be listed as an author.
16. Product-reference standards
- Ironframe product facts must come from authoritative product documentation.
- Unsupported product claims must be excluded.
- Governance Frame must not claim that Ironframe is: SOC 2 certified unless it is; ISO certified unless it is; a substitute for legal counsel; a substitute for a DPO; an external auditor; a regulator; a guaranteed compliance solution.
- Fictional companies must not be presented as real customers.
- Product architecture must not be represented as regulatory language.
- Phrases such as “potential Ironframe relevance” are preferable to “the regulation requires Ironframe’s approach.”
- Any applied-product note should be visibly separated from the research body.
17. Corrections and revision policy
- Governance Frame should maintain a public corrections process.
- Material corrections should identify: what was wrong; what changed; when it changed; whether the conclusion changed.
- Minor typographical corrections may be handled differently from substantive corrections.
- Revised figures must preserve the reason for the correction.
- Source substitutions should be recorded when a stronger or more precise authority replaces a weak source.
- Removed claims should be documented when they were material.
- Publication dates and revision dates should remain distinguishable.
- Earlier versions should remain auditable where practical.
18. Approval and publication standards
- Passing automated validation does not equal editorial approval.
- A draft must not be marked final merely because formatting, tests, or citation checks pass.
- Quarantined content requires human operator approval.
- The publication workflow must distinguish: drafting; validation; source verification; editorial review; approval; publication; correction.
- Google Docs synchronization does not constitute publication.
- A filesystem queue copy does not constitute publication.
- A Postgres publication record is authoritative for public application status.
- Promotion, permission changes, and public exposure must not occur silently.
- Owner-only editorial documents must remain owner-only unless sharing is deliberately approved.
19. Authorship and institutional accountability
- Publications should identify whether the author is: a named individual; an institutional editorial unit; a contributing expert; a commissioned writer.
- Institutional authorship must not obscure responsibility for review.
- Outside contributors and reviewers should be disclosed where appropriate.
- Financial, professional, and product conflicts should be disclosed.
- Governance Frame should identify who approves research for publication.
- Editorial responsibility must not be delegated entirely to automated systems.
20. Legal and professional boundary
- Governance Frame publications are educational and analytical.
- They do not constitute legal advice.
- They do not constitute accounting advice.
- They do not constitute audit opinions.
- They do not constitute investment advice.
- They do not guarantee regulatory compliance.
- Readers should be advised to consult qualified professionals for organization-specific decisions.
- Disclaimers must not be used to excuse inaccurate research.