# Method and governance

> How BROCS changes, how evidence is selected, what the framework cannot claim, and how corrections are handled.

Source: https://brocs.fyi/resources/method/
Framework: BROCS (Build, Run, Observe, Control, Secure), brocs.fyi. CC BY 4.0, attribute to brocs.fyi.

---


BROCS is a public working framework, not a standard, certification, benchmark, or claim
of consensus. Its job is to make gaps in an enterprise AI operating surface nameable.
It should change when field evidence exposes a missing or badly drawn boundary, and it
should remain stable when a new label would only make the acronym more comprehensive.

## What earns a place

A new letter has to pass four tests.

1. It names a distinct operational question with a distinct owner.
2. Skipping it produces a failure that is not merely a weaker version of another
   letter's failure.
3. An organization can be strong elsewhere and still be weak on it.
4. A mature adjacent discipline offers practices the framework can borrow and test.

A vertical has a lower bar, but it still needs a recognizable job, failure, and test.
Remote access entered Control in version 1.1 because repeated buyer questions exposed a
coherent gap. The reason and date are recorded in the
[changelog](/resources/changelog/).

## Evidence policy

Framework claims, field observations, and externally verified facts are different
things and should read differently.

- A **framework claim** is an argument BROCS makes. It should be testable against a real
  architecture or operating practice.
- A **field observation** comes from repeated practitioner conversations. It is useful,
  but it is not presented as survey evidence.
- A **factual claim** about an incident, regulation, standard, or measured population
  needs a source a reader can inspect. Primary sources are preferred; independent
  reporting is used when the primary record is incomplete or inaccessible.

The [failure-mode library](/resources/failure-modes/) requires a public source and an
arguable mapping to a skipped letter. Anonymous stories may inform the prose, but they
do not enter the library as evidence. Crosswalks to DORA, NIST, OWASP, the EU AI Act,
and other bodies are BROCS interpretations, not endorsements by those bodies.

## Independence

The creator's commercial affiliation is disclosed once in the
[manifesto](/manifesto/#provenance-and-disclosure). No vendor pays for inclusion,
placement, scoring, or comparison. BROCS does not name a preferred implementation, and
commercial and homegrown systems face the same questions.

## Versions, corrections, and reuse

Changes to the framework receive a version and a dated changelog entry. Editorial,
accessibility, and site changes do not. Citations should include the version so a reader
can recover the framework that was used.

Corrections and proposed changes are public in the
[BROCS repository](https://github.com/calliopeai/brocs). A useful challenge includes the
claim or boundary in question, a concrete counterexample, and a source when the dispute
is factual.

The framework text is [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).
Copying, translating, adapting, and criticizing it are explicitly allowed. Attribution
and an indication of changes are the requirements.




