top of page

Why Regulated Decisions Need a Common Language

Writer: Zayon
Zayon
Jun 23
4 min read

Updated: 1 day ago

Banner preto da Zayon com Trustworthy AI Decision Infrastructure e Record. Governance. Proof. em branco e rosa.

Every financial institution that automates decisions represents them in its own way. One stores a credit decision as a row in a database. Another as a JSON document in a proprietary format. A third as a combination of log entries across four systems. Policies are written in documents, rules engines, spreadsheets and code. Evidence is referenced by internal identifiers that mean nothing outside the institution.


Inside one institution, this fragmentation is a problem. Across institutions, it becomes a structural barrier.


Regulators can't compare how institutions decide. Auditors must learn a new representation for every engagement. Agents acting across institutions have no shared way to express authority. And no one can measure, in a consistent way, whether one decision system is better governed than another.


Regulated decisions need a common language. This article describes what that language should contain, how its quality should be measured, and how Zayon approaches it.


What a common schema would represent

A schema for regulated decisions is a shared format for describing three things, readable by machines and by regulators.

  • Policy. The rules that govern a decision: criteria, thresholds, required evidence, outcome types, escalation conditions, authority levels, version, effective date and approval.

  • Evidence. The information a decision relied on: what it was, where it came from, when it was captured, and whether it met sufficiency requirements.

  • Decision. The outcome and its context: identifier, timestamp, policy version applied, evidence used, typed result, accountable actor, any human intervention, and subsequent lifecycle events.


The schema doesn't describe how decisions are computed. It describes what was decided, under which rules, on what basis. That distinction matters: a common format for representing decisions creates interoperability without requiring anyone to share the engines that produce them.


Designed against real cases

Abstract schemas tend to fail in one of two ways: too general to be useful, or too shaped by one use case to fit others. The safeguard is to design against several concrete, demanding cases at once, and accept an abstraction only if all of them exercise it.


A robust regulated decision schema should be tested simultaneously against cases as different as:

  • an anti-money-laundering rule, with alerts, analyst dispositions, escalation and reporting obligations;

  • an agentic payment mandate, with delegated authority, limits, conditions and chained delegation;

  • a content and child-protection rule on digital platforms, with proportionality, review rights and regulatory reporting.


If a concept appears in only one of them, it belongs in a domain extension, not the core. If all three need it, such as versioned policy, typed outcomes, evidence sufficiency, authority and review, it belongs in the core.


A structured normative corpus

Policies don't start from nothing. In regulated environments, they implement public norms: laws, regulations, circulars and guidance.


A second component of a common language is a structured normative corpus: public regulatory texts converted into a structured, queryable form, so that a policy rule can reference the specific provision it implements, and a change in a norm can be traced to the policies, and decisions, it affects.


Such a corpus contains no customer data and no proprietary logic. It can be built and maintained with contributions from legal and compliance professionals, without requiring them to program.


Measuring decision system quality

A schema without a way to evaluate decisions is documentation. To be adopted, it needs a measure: a way to assess the quality of a regulated decision system, not by the accuracy of its models, but by the properties that matter for governance.


We believe four properties belong at the core of any such evaluation:

Property

Question

Consistency

Do equivalent cases receive equivalent decisions under the same policy version?

Policy adherence

Do decisions actually follow the declared policy, or does practice drift from it?

Reconstructability

Can any decision be reproduced exactly from its record?

Override behavior

Are human interventions authorized, justified, recorded, and do their outcomes justify them?

Each can be tested with defined procedures and test cases. Together, they describe something that model metrics can't: how trustworthy a decision system is as an institution's instrument.


An evaluation that no one else can run is published opinion. That's why the measurement instruments themselves should be open, so that institutions, auditors and regulators can apply them independently.


What should be open, and what shouldn't

A common language for regulated decisions requires openness. It doesn't require giving everything away. The boundary is clear:

Open

Proprietary

The schema for representing policy, evidence and decisions

The decision architecture and engines

The structured normative corpus built from public texts

Simulation engines that test policy against history

Evaluation tools and benchmarks

Certification mechanisms

Methodology, documentation and reference implementations of the schema

Model weights, business rules and core systems

What is opened is the way decisions are represented and evaluated, never the machine that produces them.


That boundary serves everyone. Institutions gain interoperability and comparability without being locked into one vendor's format. Regulators gain a consistent basis for supervision. Vendors compete on the quality of their systems, measured by shared criteria, rather than on proprietary formats that trap their customers.


Why this matters now

Three developments make a common language urgent.

  • Agents cross institutional boundaries. When an agent authorized by one institution acts on another's rails, both need a shared way to express and verify authority.

  • AI regulation is converging on decisions. Emerging AI rules in many jurisdictions focus on high-risk uses, including credit, and on obligations like explainability, human oversight and record-keeping. A shared schema makes those obligations easier to meet and to verify.

  • Supervision is becoming data-driven. Supervisors increasingly want to examine decisions directly, not only reports about them. That is only practical at scale if decisions are represented consistently.


Our approach

At Zayon, we see a common language for regulated decisions as part of building the category of trustworthy AI decision infrastructure. We are working on the schema against the concrete cases above, and on the evaluation criteria that would make it measurable.


We also hold ourselves to a condition: an open repository that isn't maintained is worse than none, and is read as such by the institutions it is meant to serve. We will publish what we can commit to maintaining, starting with what is most stable.


Shared ways of representing and measuring decisions, competing systems for making them well.


Interested in contributing to a common schema for regulated decisions? Talk to our team →

Related Posts

See All

Comments


The Zayon Briefing

Topics you're interested in:

A periodic briefing on AI decision infrastructure, governance and what it means for financial institutions. No noise.

STAY INFORMED 

bottom of page