Method and governance
How BROCS changes, how evidence is selected, what the framework cannot claim, and how corrections are handled.
BROCS is a public working framework, not a standard, certification, benchmark, or claim of consensus. Its job is to make gaps in an enterprise AI operating surface nameable. It should change when field evidence exposes a missing or badly drawn boundary, and it should remain stable when a new label would only make the acronym more comprehensive.
What earns a place
A new letter has to pass four tests.
- It names a distinct operational question with a distinct owner.
- Skipping it produces a failure that is not merely a weaker version of another letter’s failure.
- An organization can be strong elsewhere and still be weak on it.
- A mature adjacent discipline offers practices the framework can borrow and test.
A vertical has a lower bar, but it still needs a recognizable job, failure, and test. Remote access entered Control in version 1.1 because repeated buyer questions exposed a coherent gap. The reason and date are recorded in the changelog.
Evidence policy
Framework claims, field observations, and externally verified facts are different things and should read differently.
- A framework claim is an argument BROCS makes. It should be testable against a real architecture or operating practice.
- A field observation comes from repeated practitioner conversations. It is useful, but it is not presented as survey evidence.
- A factual claim about an incident, regulation, standard, or measured population needs a source a reader can inspect. Primary sources are preferred; independent reporting is used when the primary record is incomplete or inaccessible.
The failure-mode library requires a public source and an arguable mapping to a skipped letter. Anonymous stories may inform the prose, but they do not enter the library as evidence. Crosswalks to DORA, NIST, OWASP, the EU AI Act, and other bodies are BROCS interpretations, not endorsements by those bodies.
Independence
The creator’s commercial affiliation is disclosed once in the manifesto. No vendor pays for inclusion, placement, scoring, or comparison. BROCS does not name a preferred implementation, and commercial and homegrown systems face the same questions.
Versions, corrections, and reuse
Changes to the framework receive a version and a dated changelog entry. Editorial, accessibility, and site changes do not. Citations should include the version so a reader can recover the framework that was used.
Corrections and proposed changes are public in the BROCS repository. A useful challenge includes the claim or boundary in question, a concrete counterexample, and a source when the dispute is factual.
The framework text is CC BY 4.0. Copying, translating, adapting, and criticizing it are explicitly allowed. Attribution and an indication of changes are the requirements.