Abstract
What does a resilience score measure? This paper argues that it measures sovereignty: the degree to which a regulated entity exercises actual control over its own digital operational state, as opposed to having ceded that control to vendors, instruments, unverified assumptions, or regulatory blindness. We define the resilience state of a regulated entity through five conditions (normative, data, technology, process, epistemic) separated by four boundaries. We prove that each boundary is necessary (removing it leaves the resilience state underdetermined) and that the set of four is sufficient (no fifth boundary adds independent information). The necessity proofs rest on information-theoretic independence: each boundary produces information of a type no other boundary produces. The sufficiency proof rests on exhaustive candidate analysis and a dimensionality argument. A containment theorem shows that the fourth boundary (operated vs. verified) unpacks into the four-transformation epistemic architecture established in the companion paper. The result provides the formal foundation for a reworked resilience metric – the Resilience Sovereignty Index – that scores all four boundaries rather than the technology-weighted subset current frameworks measure.
This paper was drafted with the assistance of an LLM operating under the epistemic discipline described in the companion papers. The author assumes full responsibility for the final text.
Introduction
Operational resilience frameworks proliferate. NIST CSF 2.0 defines six functions.1 ISO 27001 organises controls into four themes. COBIT 2019 specifies forty governance objectives. Dependency topology models six dependency layers. DORA mandates resilience across five pillars.2 Each defines layers, dimensions, or domains. None proves that its particular decomposition is minimal or complete. The number of layers is a design choice, not a derived result.
This paper asks whether the number can be derived rather than chosen. Specifically: given a regulated entity that must demonstrate digital operational resilience, what is the minimum set of boundaries required to fully characterise its resilience state, and can we prove that no additional boundary would add independent information?
The answer we propose is four. Not because four is a convenient number, but because four boundaries emerge from two independent criteria – information-theoretic independence (each boundary produces a distinct type of information) and completeness (the four types jointly exhaust the information space of the resilience state).
The result has a practical consequence. If the resilience state requires exactly four boundaries, then a resilience metric that scores fewer than four boundaries is structurally incomplete. We show that current metrics – including the ICT Fortress Score3 – are weighted toward two of the four boundaries (technology and process), partially cover a third (normative), and do not cover the fourth (epistemic) at all. A reworked metric must score all four.
The result also has a conceptual consequence. Each of the four boundaries separates not only two conditions of the resilience state but two domains of control. At each boundary, the entity either exercises control over the transition or has ceded it – to a vendor, an instrument, an unverified assumption, or regulatory ignorance. Section 6 argues that this control dimension is sovereignty in the precise sense: the entity’s actual capacity to determine its own digital operational state. Resilience, on this account, scales from the grounding of sovereignty. The four-boundary proof provides the structural foundation for a Resilience Sovereignty Index that measures both.
Dependency on established results
This paper takes the epistemic architecture as given. The companion paper4 proves, via the Lawvere-Yanofsky generalisation of diagonal arguments,5 that no institutional verification architecture can attest its own consistency (Theorem 5) and that the record must stand outside the verification loop (Corollary 6). The manifest6 derives five architectural properties from the formal model and operationalises them through the F(d) assertion taxonomy, the Collegium Custodum, and the epistemic routing specification.7 None of this is reproven here. The epistemic architecture is a closed component whose internal structure is established.
Structure
Section 2 defines the resilience state and the four boundaries. Section 3 proves necessity. Section 4 proves sufficiency. Section 5 states the containment theorem linking this proof to the established epistemic architecture. Section 6 derives the implications for the Resilience Sovereignty Index.
Definitions
Definition 1 (Resilience state). Let S be the state of a regulated entity with respect to its digital operational resilience. S is fully characterised if and only if the following five conditions are simultaneously determined:
|
|
|---|---|
|
(Data) |
| (iii) What it has is functioning within its authoritative domains. | (Technology) |
|
(Process) |
|
|
Definition 2 (Boundary). A boundary Bk is the transition between condition (k) and condition (k + 1). The boundary separates two qualitatively distinct states of knowledge about the entity’s resilience. There are four boundaries:
| B1 : required → known | (between conditions i and ii) |
|---|---|
| B2 : known → running | (between conditions ii and iii) |
| B3 : running → operated | (between conditions iii and iv) |
| B4 : operated → verified | (between conditions iv and v) |
Definition 3 (Information channel). Each boundary Bk is an information channel that maps an input state (the characterisation achieved by layers 1 through k) to an output state (the characterisation achieved by layers 1 through k + 1). Each channel produces information of a specific type:
B1 : normative-to-data mapping
B2 : inventory-to-liveness mapping
B3 : liveness-to-governance mapping
B4 : governance-to-verification mapping
Definition 4 (Independence). Two boundaries Bi and Bj are informationally independent if the output of Bi cannot be derived from the output of Bj and vice versa, given the same input state. Formally, the mutual information I(Bi;Bj | Sinput) = 0.
Definition 5 (Necessity). Boundary Bk is necessary if removing it from the set {B1,B2,B3,B4}
reduces the joint information about S:
I(B1,...,Bk−1,Bk+1,...,B4;S) < H(S)
Definition 6 (Sufficiency). The set {B1,B2,B3,B4} is sufficient if no additional boundary B5 increases the joint information:
I(B1,B2,B3,B4,B5;S) = I(B1,B2,B3,B4;S) = H(S)
Temporal note
The resilience state S is time-indexed: S(t). Every layer and every boundary has a temporal dimension. Norms are enacted and repealed. Data ages. Technology degrades. Processes evolve. Verification expires. The temporal dimension is a property of every channel, not an additional boundary. The formal treatment operates on S(t) throughout.
Cross-cutting dimensions
Two dimensions bind the stack vertically but are not boundaries.
Organisational (culture, ownership, competence, governance): modifies the performance of every layer. It is a multiplier on the information each boundary produces, not a transition between two conditions. Neither candidate analysis nor formal construction produces a sixth condition of S from the organisational dimension.
Sovereignty: an orthogonal axis projecting through every layer. At each layer, sovereignty manifests as a constraint on how the condition is satisfied (under whose jurisdiction, with whose data, on whose substrate, by whose authority, under whose verification). Sovereignty is not a sequential transition. It is the property the Resilience Sovereignty Index measures across all four boundaries.
Proof of Necessity
For each boundary Bk, we show that it produces information of a type not produced by any other boundary (pairwise independence) and that removing it leaves at least one condition of Definition 1 undetermined.
Necessity of B1 (required vs. known)
B1 produces the mapping from the normative requirement space to the data inventory space: which regulatory obligations apply, and which data items in the entity’s inventory correspond to those obligations.
Lemma 7. The information produced by B1 is of type “normative-to-data mapping.” No other boundary produces information of this type.
Proof. B2 maps data to operational state (type: inventory-to-liveness). B2 cannot determine which data items are regulatorily relevant; it can only determine which items are running. B3 maps operational state to process execution (type: liveness-to-governance). B3 cannot determine regulatory relevance. B4 maps process execution to epistemic warrant (type: governance-to-verification). B4 cannot determine regulatory relevance. Therefore B1’s output is not derivable from B2, B3, or B4.
Proposition 8. B1 is necessary. Without B1, condition (i) of Definition 1 is undetermined.
Proof. Without B1, the entity has data (condition (ii) may be satisfied) but does not know which data items are regulatorily relevant. It is resilient against an undefined target. This is the failure mode of regulatory blindness: the entity may score well on layers 2 through 5 while being non-compliant at layer 1. Furthermore, B1 is a floor boundary. If condition (i) is undetermined, the truth values of conditions (ii) through (iv) are undefined with respect to the normative target, even if those conditions are internally satisfied. Condition (v) can verify conditions (ii) through (iv) but cannot verify them against a normative target that has not been identified. A B1 failure therefore caps the maximum achievable characterisation of S regardless of upper-layer performance.
Necessity of B2 (known vs. running)
B2 produces the mapping from data inventory to confirmed operational state: which items in the inventory actually exist and function in the operational environment.
Lemma 9. The information produced by B2 is of type “inventory-to-liveness.” No other boundary produces information of this type.
Proof. B1 maps norms to data (type: normative-to-data). B1 cannot determine whether a data item corresponds to a running system. B3 maps operational state to process execution (type: liveness-to-governance). B3 presupposes that the operational state is known. B4 maps process execution to epistemic warrant. B4 cannot determine operational state. Therefore B2’s output is not derivable from B1, B3, or B4.
Proposition 10. B2 is necessary. Without B2, the entity conflates its inventory with its operational state.
Proof. Without B2, condition (ii) is partially determined (the entity has data) but the data is not confirmed against operational reality. Condition (iii) is undetermined because the entity does not know which of its inventoried items are actually running. This is the failure mode of inventory fiction: the entity’s CMDB lists assets that have been decommissioned, its dependency model shows chains through non-existent nodes, and its capacity metrics are inflated. A B2 failure corrupts all layer 3 assessments because the technology layer’s metrics are derived from data that does not match reality.
Necessity of B3 (running vs. operated)
B3 produces the mapping from confirmed operational state to process execution evidence: which running systems are governed through controlled, tested, and repeatable processes.
Lemma 11. The information produced by B3 is of type “liveness-to-governance.” No
other boundary produces information of this type.
Proof. B1 maps norms to data. B2 maps data to operational state. B2 can confirm that a system is running but not that it is governed: a running server with no change management, no incident response, and no business continuity plan is running but not operated. B4 maps process execution to epistemic warrant but does not produce the process execution evidence itself. Therefore B3’s output is not derivable from B1, B2, or B4.
Proposition 12. B3 is necessary. Without B3, the entity conflates infrastructure availability with operational capacity.
Proof. Without B3, condition (iii) is determined (the technology is running) but condition (iv) is undetermined. This is the failure mode of unmanaged infrastructure: the entity has the technology to recover from a ransomware incident but not the processes to execute recovery. The gap between running and operated is invisible without B3.
Necessity of B4 (operated vs. verified)
B4 produces the mapping from process execution evidence to epistemic warrant: the degree to which the entity’s claims about layers 1 through 4 have been independently verified through the epistemic architecture.
Lemma 13. The information produced by B4 is of type “governance-to-verification.” No other boundary produces information of this type.
Proof. B1, B2, and B3 produce information about the entity’s state (what is required, what exists, what is running, what is operated). None produces information about whether the entity’s claims about that state are trustworthy. B4 is the only boundary where information from outside the entity’s operational chain enters the characterisation. Layers 1 through 4 are self-reports. Layer 5 is independent verification. The qualitative difference between self-report and independent verification is the information B4 produces. Therefore B4’s output is not derivable from B1, B2, or B3.
Proposition 14. B4 is necessary. Without B4, the entity’s resilience claims are unauditable.
Proof. Without B4, conditions (i) through (iv) may all be satisfied, but condition (v) is undetermined. This is the failure mode of unverified assurance: the entity reports a resilience score but the score is a number without epistemic warrant. The control testing was performed by the implementing team. The VaR calculation was produced by an LLM and accepted without assertion classification. The compliance assessment was self-assessed without external validation. Without B4, the absence of warrant is invisible to external consumers of the score (board, regulator, auditor, insurer).
Summary of necessity
Theorem 15 (Necessity of four boundaries). The four boundaries B1,B2,B3,B4 are pairwise informationally independent. Each produces information of a distinct type:
B1 : normative-to-data mapping
B2 : inventory-to-liveness mapping
B3 : liveness-to-governance mapping
B4 : governance-to-verification mapping
Each is necessary for full characterisation of S. Removing any Bk leaves at least one condition of Definition 1 undetermined and produces a distinct failure mode: regulatory blindness (B1), inventory fiction (B2), unmanaged infrastructure (B3), or unverified assurance (B4). The chain is strictly ordered: B2 requires B1’s output, B3 requires B2’s output, B4 requires B3’s output. No reordering is possible without breaking information dependency.
Proof. Follows from Lemmas 7–13 and Propositions 8–14.
Proof of Sufficiency
We show that no fifth boundary B5 adds independent information about S beyond what B1 through B4 jointly provide.
The information space of S
From Definition 1, S is fully characterised by five conditions. The four boundaries produce exactly the mappings between adjacent conditions. The information space decomposes into four independent subspaces ℐ1,ℐ2,ℐ3,ℐ4, one per boundary type. Together with the floor (condition (i), the normative base), they determine all five conditions. No condition is left undetermined. The completeness of this decomposition is tested below through
candidate analysis.
Candidate analysis
For a candidate B5 to be necessary, it must produce information of a type not present in ℐ1 through ℐ4, and that information must be required for a condition of S not covered by conditions (i) through (v).
Candidate: external attestation.
External attestation (a regulator or auditor confirming the entity’s claims) does not change the entity’s resilience state. It changes the external world’s knowledge of that state. External attestation is the function of the Resilience Sovereignty Index: translating the internally determined S into an externally communicable form. It is the output of the stack, not a boundary within it.
Candidate: current vs. historical.
The historical trajectory is a time-series of states S(t1),...,S(tn), each fully characterised by the five conditions at its respective time. The temporal dimension adds a temporal index, not a sixth condition. Trend analysis is a function of time-indexed states, not a new type of information about the current state.
Candidate: individual vs. systemic.
Systemic resilience is a property of the aggregate of entities, each with its own five-condition state. It is not a sixth condition of any individual entity. DORA Art. 28–30 (third-party management) and concentration risk are within layer 3 (supply chain domain) and layer 4 (third-party management process).
Candidate: technical vs. human.
The organisational dimension modifies the performance of every layer. It is a multiplier, not a transition between two conditions. It does not add a sixth condition.
Candidate: sovereignty boundary.
Sovereignty is an orthogonal axis projecting through every layer. It constrains how conditions (i) through (v) are satisfied, but does not add a sixth condition. Layer 3 already carries the sovereignty domain as one of its three authoritative-domain faces.
Candidate: static vs. dynamic.
Behaviour under stress is the content of layer 4. The distinction between availability at rest and capacity under stress is exactly what B3 separates (running vs. operated).
Candidate: design vs. implementation.
The gap between intended architecture and actual deployment is a special case of B2: the data layer contains the design; the technology layer contains the deployment. B2 maps from data to operational state, which is exactly this gap.
Sufficiency conclusion
Theorem 16 (Sufficiency of four boundaries). Seven candidate fifth boundaries have been tested. Each resolves to one of five categories: output of the stack, temporal index, aggregate property, cross-cutting modifier, or already encoded in an existing boundary. No candidate produces a sixth condition of S. No candidate produces information of a type not present in ℐ1 through ℐ4. The candidate analysis covers both additional boundaries between existing layers and additional layers that would create new boundaries: candidates such as systemic resilience, organisational resilience, and sovereignty were tested as potential sixth layers and shown to be cross-cutting dimensions or properties of existing layers, not independent conditions. The four boundaries span the information space of S.
Containment Theorem
Theorem 17 (Containment). B4 (operated vs. verified) is the external name for the transition that the epistemic architecture performs internally. The information produced by B4 is the joint output of the four epistemic transformations T1 through T4 (classification, routing, review, bounding), as established in the companion paper and the manifest.
Proof. The epistemic architecture produces epistemic warrant through four transformations: T1 determines the evidential basis, T2 determines the verification depth, T3 produces the human judgment, T4 states the limits of the judgment. The joint output of T1–T4 is the epistemic warrant. The output of B4 is the epistemic warrant. The two are identical. Layer 5 is therefore not a black box: its internal structure is the four-transformation chain, and its completeness is established by the companion paper’s proof that the four transformations are necessary and sufficient for epistemic warrant.
Corollary 18 (Two-dimensional scoring). The Resilience Sovereignty Index must carry two dimensions:
Layer scores: one component per layer, subject to capping logic from lower layers. A failure at B1 or B2 caps the composite score regardless of upper-layer performance.
Epistemic quality scores: derived from the T1–T4 metrics (classification coverage, routing compliance, Collegium staffing, approval validity). This dimension measures
the reliability of the layer 1–4 scores themselves.
The composite index is a function of both dimensions. An entity with high layer scores but low epistemic quality has an unreliable index. An entity with moderate layer scores but high epistemic quality has a reliable index.
The Resilience Sovereignty Index
The formal results of Sections 2–5 establish the boundary structure: four boundaries, each necessary, jointly sufficient, with the fourth unpacking into the established epistemic architecture. This section develops the interpretive consequence: what the four boundaries jointly measure, and why the resulting index carries two names.
The four-boundary proof reframes what a resilience score measures. Each boundary marks a domain where the entity exercises or cedes sovereignty over its own digital operational state. Before developing this claim, a clarification is necessary.
The duality of resilience and sovereignty
Resilience and sovereignty are related but distinct. Resilience is the property of the system: can it hold under stress? Sovereignty is the property of the entity’s relationship to the system: does the entity control whether it holds? The two are not interchangeable and do not reduce to each other, but their relationship has a definite direction.
Sovereignty grounds resilience. Resilience scales from the foundation of sovereignty, not the other way around. An entity cannot build trustworthy resilience on a layer it does not control. It can measure the layer. It can report a score for the layer. But the score is someone else’s claim that the entity happens to be reporting. Without sovereignty, resilience metrics are inherited assertions, not verified ones.
This grounding direction does not imply autarky. Sovereignty does not mean doing everything oneself. A medium-sized financial institution does not run its own datacentre, build its own SIEM, or employ its own TLPT red team. It delegates. The sovereignty question is not “do you do this yourself” but “do you control the delegation.” Can you audit the vendor? Can you exit the contract within a defined timeline? Do you hold the encryption keys or does the provider? Is the sub-outsourcing chain transparent to the last link? Do you have tested alternatives? An entity that delegates with full contractual control, tested exit plans, key custody, and audit rights is sovereign over its technology layer – even though it owns none of the hardware. An entity that runs everything in-house but has not mapped its regulatory obligations is not sovereign at layer 1, regardless of
how much infrastructure it controls.
This is the DORA Art. 28–30 regime stated in architectural terms. DORA does not prohibit outsourcing. It requires that the outsourcing relationship be governed: audit rights, exit strategies, sub-outsourcing transparency, concentration risk limits. These are sovereignty conditions on delegated operations. The Resilience Sovereignty Index measures whether those conditions hold at each boundary.
Projected on the layers, the duality manifests concretely. At layer 3, resilience means the computational substrate is available, redundant, and recoverable. Sovereignty means the entity controls the terms under which those properties hold – where it runs, who holds the keys, who can be compelled, whether the entity can exit. An entity can have a resilient technology layer (redundant, fast recovery) with low sovereignty over that layer (running entirely on a foreign hyperscaler with provider-managed keys under extraterritorial compulsory process). The technology works. The entity does not control whether it continues to work. The resilience is real but fragile: it persists only as long as the provider’s incentives and the geopolitical environment remain aligned with the entity’s needs.
The capping logic follows from the grounding direction. A lower-layer sovereignty failure caps the composite score not because the entity must do everything itself at that layer, but because the entity has lost control over whether that layer’s resilience is real. If the entity does not control its data layer (no provenance chain, no confirmed inventory, no data quality governance), then the technology and process layers built on that data operate on unverified foundations. The cap is on the trustworthiness of the claim, not on the operational state.
The name “Resilience Sovereignty Index” carries both terms deliberately. Sovereignty is the ground. Resilience is what scales from it. The index measures both: how resilient the entity is at each layer, and how much sovereignty the entity exercises over that resilience. The two scores are reported together, not collapsed into a single number, because an entity with high resilience and low sovereignty is in a fundamentally different position from an entity with moderate resilience and high sovereignty. The first is operationally functional but fragile. The second is operationally modest but trustworthy. A regulator, a board, and an insurer need to see both.
Sovereignty at each boundary
Each boundary marks a sovereignty domain:
B1 marks sovereignty over one’s own regulatory position. An entity that has not identified its obligations has ceded normative sovereignty to the regulator’s next
inspection.
B2 marks sovereignty over one’s own inventory. An entity whose data does not match its operational reality has ceded informational sovereignty to drift.
B3 marks sovereignty over one’s own operational execution. An entity with running but ungoverned infrastructure has ceded operational sovereignty to the next incident.
B4 marks sovereignty over one’s own knowledge claims. An entity that cannot verify its own resilience assertions has ceded epistemic sovereignty to the instrument, the vendor, or the unexamined assumption.
The Resilience Sovereignty Index is therefore not a measure of “how resilient is this entity” in the colloquial sense. It is a measure of “how much sovereignty does this entity exercise over its own resilience state.” The distinction matters because an entity can be operationally functional (servers run, processes execute) while having ceded sovereignty at multiple boundaries (regulatory obligations unmapped, data unconfirmed, verification absent). The current ICT Fortress Score measures operational functionality. The Resilience Sovereignty Index measures the sovereignty that makes operational functionality trustworthy.
Gap analysis of current metrics
The current ICT Fortress Score (CF 23, v1.0.0) has five components: ICT Capital Ratio (30%), ICT Liquidity Ratio (25%), ICT Risk Coverage (25%), Control Effectiveness (10%), and Compliance Status (10%). These map to the four-boundary stack as follows:
B1 (normative): Compliance Status (10%) partially covers this boundary. No component measures regulatory-change currency, third-party contractual coverage, or supervisory finding closure.
B2 (data): no component measures data completeness, provenance integrity, data quality, or inventory confirmation against operational state.
B3 (technology/process): ICT Capital Ratio, ICT Liquidity Ratio, ICT Risk Coverage, and Control Effectiveness collectively cover the technology and process layers. These four components account for 90% of the score weight.
B4 (epistemic): no component measures assertion classification coverage, verification routing compliance, Collegium staffing, approval validity, or simulacrum detection.
The current score is 90% weighted toward B3 (technology and process), 10% toward B1 (normative), and 0% toward B2 (data) and B4 (epistemic). This is structurally incomplete. The four-boundary proof shows that B2 and B4 are independently necessary. A score that omits them cannot fully characterise S.
Design principles for the reworked index
The reworked Resilience Sovereignty Index must:
Include at least one scored component per boundary.
Implement capping logic: a B1 or B2 failure caps the composite regardless of B3/B4 performance.
Include the epistemic quality dimension per the containment theorem (Corollary 18).
Carry the sovereignty axis as a property within each layer’s score, surfacing asymmetries (e.g., EU-regulated entity on US-controlled cloud with provider-managed keys) rather than averaging them away.
Remain communicable: a board member must understand the composite in thirty seconds.
Detailed scoring methodology, component weights, and threshold calibration are the subject of the reworked CF 23 specification. This paper provides the structural foundation.
Security as Boundary Preservation
The four boundaries are structural conditions. They hold or they do not. But between the formal proof and the operational reality lies a prerequisite the proof takes for granted: the boundaries must be protected. Security is not a fifth boundary. It is the operational condition under which the four boundaries remain intact.
A boundary that can be circumvented, tampered with, or rendered unavailable is a boundary in name only. The formal proof establishes what must hold. Security establishes that it continues to hold under adversarial conditions, operational failure, and institutional negligence. The relationship is orthogonal: the proof is valid regardless of whether the boundaries are protected, but the institution’s sovereignty depends on both the boundaries and their protection.
The CIA triad mapped to four boundaries
The classical information security triad – confidentiality, integrity, availability – applies to each boundary with a distinct operational meaning.
B1 (normative → data): Integrity. The external verification record must not be tampered with. If the record of which inscription was operative, whose it was, and when it was verified can be modified after the fact, the self-attestation bound (Boundary 1) is operationally violated: the loop has gained write access to its own consistency claim. Integrity controls – append-only storage, cryptographic chaining, segregation of write authority – are the operational expression of the Lawvere bound at the record layer.
B2 (data → technology): Confidentiality. The metalanguage position requires that the verification operation has epistemic access to the truth conditions of the assertion language. This access must be protected. If the inscription (the model weights, the RLHF policy, the system prompt) is sealed under trade-secret protection and the verifier has no access, the Tarski bound is operationally present: the institution cannot define truth conditions over outputs it cannot inspect. Conversely, if the institution does hold metalanguage access, that access is a high-value asset. Confidentiality controls – access management, key custody, need-to-know enforcement – protect the metalanguage position from compromise, leakage, or erosion.
B3 (technology → process): Integrity. The F(d) classification and the routing
table determine which assertions receive which verification depth. If the classification can be manipulated – an assertion reclassified from D (requires expert review) to A (automated pass) – the graduated verification regime collapses to a uniform threshold by adversarial action rather than by the architectural failure the Boundary 3 proof describes. Integrity controls on the classification pipeline, the routing configuration, and the threshold parameters are the operational expression of the partition argument applied to the control plane.
B4 (process → verified): Availability. The human gate must be present and functional. If the gate can be bypassed – by timeout, by queue overflow, by process exception, by an automated fallback that promotes assertions without human judgment – the gate is operationally a trivial machine regardless of the reviewer’s competence. Availability controls – guaranteed reviewer capacity, escalation paths, circuit breakers that halt rather than bypass, monitoring of gate throughput and approval rates – are the operational expression of the non-triviality preservation conditions the Boundary 4 proof identifies.
Control objectives per boundary
The mapping yields twelve control objectives (three per boundary, one per CIA dimension). Not all twelve are equally weighted: each boundary has a primary security dimension (indicated below) and two supporting dimensions. The primary dimension is the one whose failure directly violates the boundary’s formal condition.
B1: Primary: Integrity. The record is append-only, cryptographically chained, and segregated from the systems it records. Supporting: Availability (the record is accessible for audit). Confidentiality (the record’s content is protected where it contains sensitive assertion data).
B2: Primary: Confidentiality. The metalanguage position – the verifier’s access to truth conditions – is protected from disclosure, exfiltration, or erosion. Supporting: Integrity (the metalanguage artefacts have not been altered). Availability (the verifier can access the metalanguage when needed).
B3: Primary: Integrity. The classification pipeline, routing table, and threshold parameters have not been tampered with. Supporting: Availability (the routing function is operational). Confidentiality (the routing configuration is not disclosed to parties who could game it).
B4: Primary: Availability. The human gate is staffed, reachable, and cannot be bypassed. Supporting: Integrity (the gate’s decision is faithfully recorded). Confidentiality (the gate’s deliberation is protected from outside influence).
Adoption bridge: IT-SEC, GRC, IT-OPS, DevSecOps
The twelve control objectives are expressed in a vocabulary that maps directly to existing operational disciplines:
IT-SEC (Information Security Management, CISM scope): The CIA-to-boundary mapping is a risk assessment input. Each boundary defines a protection objective. The primary CIA dimension per boundary defines the control priority. Existing control frameworks (ISO 27001, NIST CSF, BSI IT-Grundschutz) provide implementation controls; the four-boundary structure provides the completeness criterion that tells the security function which controls are structurally necessary and which are optional hardening.
GRC (Governance, Risk, and Compliance, CRISC scope): Each boundary
generates a risk scenario (“what if this boundary’s primary CIA dimension fails?”) and a compliance obligation (“does the regulatory framework require this boundary to hold?”). DORA Art. 5–6 (ICT risk management), Art. 11–14 (ICT incident management), and Art. 28–30 (third-party risk) each address at least one boundary. The four-boundary structure provides the completeness check for GRC assessments: if a boundary is unaddressed, the assessment is structurally incomplete.
IT-OPS (Operations): Each boundary has a monitoring requirement. B1: record integrity monitoring (tamper detection, chain validation). B2: access monitoring on metalanguage artefacts. B3: configuration drift detection on routing tables and thresholds. B4: gate throughput and approval-rate monitoring (constant-output detection is the operational signal for gate degeneration). The four-boundary structure provides the minimum monitoring set for operations.
DevSecOps (Pipeline Security): Each boundary has a pipeline integration point. B1: the verification record is a pipeline artefact (provenance chain per build, per deployment, per configuration change). B2: metalanguage artefacts are versioned, signed, and access-controlled in the pipeline. B3: the F(d) classification and routing configuration are pipeline-managed (infrastructure as code, change-gated, peer-reviewed). B4: the human gate is a pipeline stage (promotion requires human approval; the approval event is logged with identity, timestamp, and scope). The four-boundary structure provides the minimum gate set for the delivery pipeline.
The security section does not add a fifth boundary. It adds the operational protection layer that makes the four boundaries hold under real-world conditions. A formally correct architecture with unprotected boundaries is a formally correct architecture that does not work. The Resilience Sovereignty Index must therefore carry a third dimension beyond layer scores and epistemic quality: a security posture score per boundary, measuring whether the boundary’s primary CIA dimension is operationally protected.
The Collegium Custodum: Minimum Guild Derivation
The four boundaries establish what the verification architecture must satisfy. They do not prescribe who fills the verification positions. This section derives the minimum institutional structure from the boundaries themselves.
Theorem 19 (Three-Rank Minimum). Any institutional structure staffing the verification gates of a Boundary-compliant architecture requires at least three competence ranks, provided the institution’s assertion space includes classes C, D, or E. Institutions operating exclusively in the semivocale regime (classes A–B) do not require the Collegium, as B1–B4 are not triggered (Existence Condition, Algebra paper). Two ranks violate either Boundary 3 or Boundary 4.
Proof. The top rank (Magister) is required by the authority constraint: someone must verify assertions at the highest operational F(d) classes (D, E) and grant verification rights to others. Without this rank, critical assertions either pass unverified (Boundary 3 violation: over-admission) or are blanket-rejected (institutional dysfunction).
The bottom rank (Tiro) is required by the cohort constraint derived from Boundary 4’s absorbing property (Theorem 19, below). The absorbing equilibrium does not reverse without external intervention. External intervention takes one form: a non-degenerate human enters the gate. The guild must therefore maintain a formation pipeline.
Assume only two ranks (Tiro and Magister). Two failure modes follow. Case 1: the Tiro handles C-class assertions. The Tiro lacks domain expertise for expert-evaluable assertions. Over-admission follows. Boundary 3 is violated. Case 2: the Magister handles all human-verification volume (C + D + E). The combined volume accelerates gate degeneration. Boundary 4 is violated through rate saturation. Therefore at least one intermediate rank (Peritus) must exist, handling C-class assertions with domain competence and reducing the volume arriving at the Magister gate.
Theorem 20 (Cohort Constraint). Let Td be the expected operational duration before a gate operator’s epistemic vigilance degenerates under sustained volume. Let Tt be the formation time for a new operator to reach independent practice. Then any Boundary-4-compliant institution must maintain at least two temporal cohorts at all times, subject to the constraint Tt < Td.
Proof. By the Boundary 4 convergence theorem, constant-output equilibrium is absorbing: once the gate operator produces constant output, the gate does not return to nontrivial operation without external intervention. The only form of external intervention that restores the gate is introducing a non-degenerate operator. If the formation of the replacement cohort takes Tt and the current cohort degenerates after Td, then Tt ≥ Td implies a gap in which no non-trivial gate exists. The constraint Tt < Td is therefore necessary for continuous Boundary 4 compliance. This requires at least two overlapping cohorts: one operational, one in formation.
Remark 21 (Gate rotation as architectural law). Gate rotation — the periodic reassignment of gate operators across assertion classes and institutional domains — is not an operational preference. It is the architectural expression of the absorbing property. A gate that never rotates converges to constant-output equilibrium with probability approaching certainty given sufficient time. Empirical evidence supports this: Goggin et al. (2007) found that only 57.5% of participants produced correct results when hand-counting VVPAT ballots, with accuracy degrading further under high rejection rates and narrow margins. The human audit gate itself degenerates under volume — precisely the condition the cohort constraint addresses.
Remark 22 (The Pionier-Magister). At the inception of the Collegium within any institution, no guild ranks exist. The normative space is formally correct and operationally empty. The Pionier-Magister is a Magister from an adjacent domain (information security management, risk governance, audit) who enters the institution, calibrates existing competence onto the guild structure, and grants initial rights up to and including Magister level. The minimum viable Collegium is three: Dominus Electus (mandate), Pionier-Magister (doctrine and calibration), Tiro (formation and future).
Open Formalisation Work
The sufficiency argument (Section 4) rests on exhaustive candidate analysis rather than a closed dimensionality proof. A closed proof would require constructing ℐ(S) explicitly and showing dim (ℐ(S)) = 4. The necessity proof already establishes pairwise independence. The remaining step is to show that the four boundary types span the space, which the candidate analysis provides empirically. The gap between empirical spanning and formal
spanning is the remaining work.
Section 8.3 of the companion working document notes a speculative result: the four-boundary pattern recurs in both the epistemic architecture (four transformations) and the resilience stack (four boundaries). If this recurrence is structurally necessary rather than coincidental, there may be a meta-theorem: any architecture that must characterise both a system state and its epistemic warrant about that state requires exactly four boundaries at each level. This is noted as a direction for future work.
Acknowledgements
The five-layer resilience stack emerged from a working session on the AuroraQ DORA Compliance Framework (May 2026). The sovereignty reframe and the connection to the Chung (2026) digital sovereignty framework were developed in the same session. The formal treatment extends the Lawvere-Yanofsky apparatus established in the companion paper.
References
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (DORA).
DORA CF 23, ICT Fortress Score Framework, AuroraQ DORA Compliance Framework, v1.0.0 (2026).
Thorben Liebig, “On the Formal Foundation of Boundary 1: A Lawvere-Yanofsky Proof That Institutional Verification Architectures Cannot Attest Their Own Consistency” (2026).
F. William Lawvere, “Diagonal Arguments and Cartesian Closed Categories,” in Category Theory, Homology Theory and their Applications II, Lecture Notes in Mathematics 92 (Berlin: Springer, 1969), 134–145.
Noson S. Yanofsky, “A Universal Approach to Self-Referential Paradoxes, Incompleteness and Fixed Points,” Bulletin of Symbolic Logic 9, no. 3 (2003): 362–386.
Thorben Liebig, Instrumenta Digitalia Vobis Mando, (2026).
Thorben Liebig and Adel Kildeev, “Instrumentum Vocale and the Architecture of Responsibility: From Liability to Embedded Accountability,” v1.7.0 (2026).
AURORAQ AS-500, Epistemic Routing Specification, v1.2.0 (2026).
National Institute of Standards and Technology, Cybersecurity Framework 2.0 (2024).
Chee Hae Chung, “Redefining Digital Sovereignty: Infrastructural Dependence, Epistemic Asymmetry, and Governance Challenges in the Age of Big Tech,” Technology and Regulation, 2026, 57–70. DOI: 10.71265/q0527965.
Claude E. Shannon, “A Mathematical Theory of Communication,” Bell System Technical Journal 27, no. 3 (1948): 379–423.
National Institute of Standards and Technology, Cybersecurity Framework 2.0 (2024).↩︎
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (DORA).↩︎
DORA CF 23, ICT Fortress Score Framework, AuroraQ DORA Compliance Framework, v1.0.0
(2026).↩︎
Thorben Liebig, “On the Formal Foundation of Boundary 1: A Lawvere-Yanofsky Proof That Institutional Verification Architectures Cannot Attest Their Own Consistency” (2026).↩︎
F. William Lawvere, “Diagonal Arguments and Cartesian Closed Categories,” in Category Theory, Homology Theory and their Applications II, Lecture Notes in Mathematics 92 (Berlin: Springer, 1969), 134–145. Noson S. Yanofsky, “A Universal Approach to Self-Referential Paradoxes, Incompleteness and Fixed Points,” Bulletin of Symbolic Logic 9, no. 3 (2003): 362–386.↩︎
Thorben Liebig, Instrumenta Digitalia Vobis Mando, (2026).↩︎
AURORAQ AS-500 Epistemic Routing Specification, v1.2.0 (2026).↩︎