The Governance Layer · Clause Library · Instrument 05
The schedule set.
Each of the preceding four instruments defers its hardest content to a schedule. The authority grant requires every limit to be stated as a value and a unit; the kill-switch covenant requires each trigger to state a quantity, a threshold, a measurement window and a data source; the provenance representations refer throughout to Schedules A through J; the stressed conditions annex depends on three schedules of its own. In every case the instrument supplies the frame and the schedule supplies the governance.
None of those schedules has had a form. An institution could read all four instruments closely and still be unable to complete any of them. This is that form — a single record structure used everywhere in the library, the inventory of schedules each instrument requires, and the completion rules that determine what a blank, a zero, and an omission each mean.
Why a common structure rather than sixteen separate forms.
Three reasons, and the third is the one that matters most.
The instruments already require the same fields. A limit, a halt trigger, a stressed threshold and a reserved action are different in substance and identical in shape: an observable quantity, a value, a window, a source, and a record of who set it and when. Drafting them separately would produce four near-identical forms that drift apart.
Provenance is what converts documentation into evidence. The instruments repeatedly require not merely a threshold but a recorded rationale and a named person. A schedule that carries the number without the provenance of the number satisfies the letter of each instrument and defeats its purpose, because the question an examiner, acquirer or underwriter actually asks is not what the limit is but who decided it and on what basis.
A common structure is machine-evaluable; sixteen bespoke forms are not. Article 3 of the grant requires each limit to be a value capable of automated evaluation, and that requirement is only meaningful if there is a canonical way to express it. Once every governed quantity in the library shares one record shape, the schedules can be enforced at runtime by the same mechanism that enforces the limits, assessed without manual reading, and produced on request as a structured artifact rather than as a document someone has to interpret.
What the language derives from.
- The master-and-schedule architecture. Market convention, not a ruled provision: the ISDA Master Agreement is standard and unamended; the Schedule is where parties elect, populate and vary. That separation — stable operative text, variable annexed particulars — is the structure this library already has, and this instrument makes it explicit rather than incidental.
- The compliance certificate. Market convention, not a ruled provision: credit agreements require periodic restatement of covenant values in a prescribed form, signed by a named officer. It is a schedule brought down at intervals with attribution attached, and it is the closest existing practice to what the library requires.
- The disclosure schedule. Market convention, not a ruled provision: in acquisition practice, exceptions to representations are set out in a schedule delivered with the agreement, and the schedule's completeness is itself negotiated. Instrument 03's Schedules A through J follow this convention directly.
- Pre-set thresholds. SEC Rule 15c3-5 requires financial risk management controls with pre-set credit and capital thresholds. Pre-set means recorded before the fact; a threshold that exists only in a running system's configuration, with no record of when it was set or by whom, is not evidently pre-set at all.
- Indicator tables in recovery planning. The Financial Stability Board's "Guidance on Recovery Triggers and Stress Scenarios" (July 2013, Annex III to the Key Attributes of Effective Resolution Regimes) requires indicators with defined escalation levels set out in tabular form with stated actions at each level. The convention that a governance threshold belongs in a maintained table rather than in narrative text is established supervisory practice, not merely custom.
Part One — the governed quantity record.
Every row of every schedule in the library takes this form. Fields marked required are required for the row to be a row; a row missing any of them is incomplete and is treated under Part Three.
- Identifier (required). A stable reference, unique within the schedule, that does not change when the value changes.
- Quantity (required). The observable thing being measured, stated so that two people would measure it identically.
- Value (required). A number, or an enumerated set of permitted members. Not a standard of judgment.
- Unit (required where the value is a number).
- Measurement window (required). The period over which the quantity is evaluated. A value without a window is ambiguous between an instantaneous and a cumulative reading.
- Data source (required). The system or publication from which the quantity is derived, identified specifically enough that a substitution would be visible.
- Enforcement point (required). Where the value is enforced — the control, service or gate that applies it. A row with no enforcement point records an intention, not a limit.
- Consequence (required). What occurs when the value is reached: halt, reserved-action escalation, notification, or no automated consequence, stated expressly.
- Set by (required). The natural person who set the value. Not a team, a committee, or a system.
- Date set (required).
- Basis (required). The reason the value is what it is, in one or two sentences. A row whose basis is that the value was inherited from a prior configuration should say so; that is a real and disclosable answer.
- Review date (required).
- Supersedes (required where the row replaces an earlier row). The identifier and version of the row replaced.
Each schedule as a whole carries a schedule identifier, a version, an effective date, and the identifier and version of the instrument to which it attaches. This structure is published as a JSON Schema on the capital pillar's open data surface, for an institution that wants to validate a completed schedule mechanically rather than read it — or to build one directly without setting up a validator first.
Part Two — the schedule inventory.
The schedules each instrument requires, and what distinguishes each from the common record above.
Attaching to Instrument 01, the agent authority grant.
- S-01-A Permitted actions. Enumerated, not described. Value field holds the enumerated set; consequence field states what occurs on an attempted action outside it.
- S-01-B Quantitative limits. The core schedule. Every field required.
- S-01-C Reserved actions. Value field is the enumerated action; enforcement point is where the reservation is enforced rather than merely stated.
- S-01-D Termination triggers. Adds a test interval field and a last-tested field.
- S-01-E Identity and credentials. One row per credential the system uses, with the systems and services that credential can reach. A credential shared with any other system or user is disclosed as such rather than omitted.
- S-01-F Accountable individual chain. One row per designation, with effective and end dates, retained rather than overwritten.
- S-01-G Records specification. One row per record class required for reconstruction, with retention period and production interval.
Attaching to Instrument 02, the kill-switch covenant.
- S-02-A Trigger schedule. Adds a manner field — immediate or orderly — and a common-use field recording whether the operator believes the quantity is in common use among market participants.
- S-02-B Persons able to halt. Names, titles, and hours of availability.
- S-02-C Test record. One row per test, retained including tests in which no halt resulted. This schedule is append-only; rows are never superseded.
Attaching to Instrument 03, the provenance representations.
Schedules A through J as enumerated in that instrument, identified by letter rather than by the S-0n-X scheme used elsewhere in this Part. This is a deliberate, recorded exception, not an inconsistency: see the drafting note below. These schedules differ from the rest of the library in substance as well — they are disclosure schedules recording facts rather than governance schedules setting values, so the value, unit, measurement window and enforcement point fields do not apply. The provenance fields — set by, date, basis, supersedes — apply unchanged, and the version convention is the same.
Attaching to Instrument 04, the stressed conditions annex.
- S-04-A Stressed conditions. The entries whose occurrence brings the annex into effect.
- S-04-B Stressed limits. One row per row of S-01-B. The identifier field carries the identifier of the ordinary limit it displaces, so the correspondence is explicit and a missing counterpart is visible.
- S-04-C Stressed triggers. One row per row of S-02-A, on the same correspondence.
Part Three — completion rules.
These rules resolve an inconsistency across the library and govern in place of any contrary provision in the instruments to which a schedule attaches.
3.1 Three states, distinguished. A schedule row may be completed, expressly blank, or omitted, and they are not the same thing.
3.2 Governance schedules: omission is zero. Where a schedule sets values that authorize action — S-01-A, S-01-B, S-01-C, S-04-B, S-04-C — a row that is omitted authorizes nothing, and the action to which it relates shall not be taken. An operator who has not decided a limit has not authorized the activity it would govern.
3.3 Disclosure schedules: omission is a bare representation. Where a schedule records facts qualifying a representation — Instrument 03's Schedules A through J — a schedule referred to but not delivered is treated as delivered blank, and the representation is given without qualification. An omitted disclosure is not a shelter.
3.4 Why the two defaults differ. Both resolve against the party who controls the schedule. In a governance schedule that party is the operator, and the conservative outcome is that unauthorized activity does not occur. In a disclosure schedule that party is the representing party, and the conservative outcome is that an unqualified statement stands. The principle is constant even though the mechanics invert, and stating it here is the point of this Part.
3.5 Expressly blank is a completed row. An operator may record that a value is deliberately unset, and that row is complete provided it carries a basis, a person, and a date. This is the honest way to record an open question, and it is materially better than an omission because it is visible.
3.6 Incomplete rows. A row missing a required field is incomplete and is treated as omitted under 3.2 or 3.3 as applicable. Systems enforcing schedules should reject incomplete rows rather than apply their populated portion.
3.7 Versioning. Schedules are versioned independently of the instruments they attach to. Where an instrument refers to a schedule, it refers to the version in effect on the instrument's effective date unless the instrument provides otherwise. Superseded rows are retained, not deleted.
Drafting notes.
On the enforcement point field, which is the one that will be resisted. Requiring each row to name where the value is actually enforced converts the schedule from a statement of policy into a map of controls, and it will immediately surface rows where the honest answer is nowhere. That is the field doing its job. A limit enforced nowhere is a position, and an institution is better served knowing which of its limits are positions.
On requiring a natural person in the set-by field. Teams and committees do not remember, are not available to be asked, and cannot explain a basis two years later. The requirement is not about blame; it is about the existence of someone who can answer the question.
On the basis field permitting inheritance. Allowing a row to record that a value was inherited from a prior configuration is deliberate. The alternative is that the field gets filled with a plausible rationalization invented after the fact, which is worse than an honest admission and much harder to detect. Make the honest answer available and it will sometimes be used.
On the common-use field in S-02-A. This records a belief rather than a fact, which is unusual, and it is carried over from Article 7 of the annex for the reason given there: the aggregate of those records is the only visibility anyone would have into whether the market is converging on shared triggers.
On append-only test records. S-02-C never supersedes a row. A test log that can be edited is a test log whose absences cannot be distinguished from deletions, and the value of retaining tests that did not fire depends entirely on the record being complete.
On Instrument 03's Schedules A through J, recorded as a deliberate exception rather than left to look like an oversight. Every other schedule in this Part carries an S-0n-X identifier keyed to the instrument it attaches to. Instrument 03's schedules do not, and the question of whether to rename them for consistency was considered and decided against. A-through-J lettering is the established convention in disclosure schedule practice, and a transactional lawyer opening Schedule C expects to find it under that name, not under S-03-C. Internal symmetry is the weaker interest here; matching the convention the reader already has is the stronger one. The exception is confined to Instrument 03 and does not extend to any schedule introduced after this instrument.
The negative space.
- The serialization exists now and is thinner than the form.
A JSON Schema
for the governed quantity record is published on the capital pillar's open
data surface, with a conformance
fixtures file alongside it and a builder that
produces a valid instance in the browser, and together these make the
machine-evaluability argument checkable rather than theoretical. None of the
three closes this gap by itself: a schema defines what a valid record looks
like, not how two systems exchange one, and it enforces only the field-level
rules this instrument states in a way a stateless validator can actually check
— the requirement that
supersedesbe present when a row replaces an earlier one, for example, cannot be verified without the prior version to compare against, and the schema documents that rather than pretending to enforce it. - Signature and attestation are not addressed. The instruments require designations and authorizations in writing; nothing here establishes what constitutes signature of a schedule, or how a brought-down schedule is attested.
- Schedules are the natural place for sensitive material. Credentials, enforcement points, and limits together describe how to defeat a control. Nothing in this instrument addresses who within an institution may see a completed schedule, and the drafting assumption that a schedule is producible on request may conflict with the reality that it should not circulate freely.
- Cross-institution comparability. Two institutions completing the same schedules will use different quantities and different sources, and nothing here makes their completed schedules comparable. A benchmark built on these would be measuring completeness, not calibration.
- Whether a schedule identifier should be citable outside the institution that holds it. If a completed schedule is ever exchanged between parties — delivered to a counterparty, an examiner, or an acquirer — its identifier needs to be resolvable as something more than a label internal to one party's records. Whether that means a schedule identifier should be addressable as a node in the graph this library already maintains, or something else, is an open question. It is noted here rather than decided, unlike the naming question above, because the exchange practice that would answer it does not yet exist to observe.
Relationship to the framework.
This instrument attaches to all four preceding instruments and is the form in which their evidence is produced. Where the other instruments state what an institution must be able to show, this states what showing it looks like.
Its primary counterpart is not a single firm-level question but the register's own: MARQUE Standards & interoperability, because a form that makes the library machine-evaluable is itself a conformance artifact rather than a claim of one. On KYA, it is the operative counterpart to dimension 08: an institution that can produce completed schedules in this form, rather than describe its governance in narrative, is evidenced on whether it can demonstrate conformance rather than claim it. Every other instrument's own dimension is served by this one as well, indirectly and completely — none of them can be evidenced at all without a completed schedule in the form this instrument defines.
This is an editorial form with commentary, published in the tradition of model agreements and form books. It is not legal advice, not a compliance determination, not a certification, and not a representation that any provision here is enforceable in any jurisdiction. It should be reviewed by counsel and adapted before use.