QIS-CL-005 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-24 · BUILD 37

The Governance Layer · Clause Library · Instrument 05

The schedule set.

Each of the preceding four instruments defers its hardest content to a schedule. The authority grant requires every limit to be stated as a value and a unit; the kill-switch covenant requires each trigger to state a quantity, a threshold, a measurement window and a data source; the provenance representations refer throughout to Schedules A through J; the stressed conditions annex depends on three schedules of its own. In every case the instrument supplies the frame and the schedule supplies the governance.

None of those schedules has had a form. An institution could read all four instruments closely and still be unable to complete any of them. This is that form — a single record structure used everywhere in the library, the inventory of schedules each instrument requires, and the completion rules that determine what a blank, a zero, and an omission each mean.

Why a common structure rather than sixteen separate forms.

Three reasons, and the third is the one that matters most.

The instruments already require the same fields. A limit, a halt trigger, a stressed threshold and a reserved action are different in substance and identical in shape: an observable quantity, a value, a window, a source, and a record of who set it and when. Drafting them separately would produce four near-identical forms that drift apart.

Provenance is what converts documentation into evidence. The instruments repeatedly require not merely a threshold but a recorded rationale and a named person. A schedule that carries the number without the provenance of the number satisfies the letter of each instrument and defeats its purpose, because the question an examiner, acquirer or underwriter actually asks is not what the limit is but who decided it and on what basis.

A common structure is machine-evaluable; sixteen bespoke forms are not. Article 3 of the grant requires each limit to be a value capable of automated evaluation, and that requirement is only meaningful if there is a canonical way to express it. Once every governed quantity in the library shares one record shape, the schedules can be enforced at runtime by the same mechanism that enforces the limits, assessed without manual reading, and produced on request as a structured artifact rather than as a document someone has to interpret.

What the language derives from.

Part One — the governed quantity record.

Every row of every schedule in the library takes this form. Fields marked required are required for the row to be a row; a row missing any of them is incomplete and is treated under Part Three.

Each schedule as a whole carries a schedule identifier, a version, an effective date, and the identifier and version of the instrument to which it attaches. This structure is published as a JSON Schema on the capital pillar's open data surface, for an institution that wants to validate a completed schedule mechanically rather than read it — or to build one directly without setting up a validator first.

Part Two — the schedule inventory.

The schedules each instrument requires, and what distinguishes each from the common record above.

Attaching to Instrument 01, the agent authority grant.

Attaching to Instrument 02, the kill-switch covenant.

Attaching to Instrument 03, the provenance representations.

Schedules A through J as enumerated in that instrument, identified by letter rather than by the S-0n-X scheme used elsewhere in this Part. This is a deliberate, recorded exception, not an inconsistency: see the drafting note below. These schedules differ from the rest of the library in substance as well — they are disclosure schedules recording facts rather than governance schedules setting values, so the value, unit, measurement window and enforcement point fields do not apply. The provenance fields — set by, date, basis, supersedes — apply unchanged, and the version convention is the same.

Attaching to Instrument 04, the stressed conditions annex.

Part Three — completion rules.

These rules resolve an inconsistency across the library and govern in place of any contrary provision in the instruments to which a schedule attaches.

3.1 Three states, distinguished. A schedule row may be completed, expressly blank, or omitted, and they are not the same thing.

3.2 Governance schedules: omission is zero. Where a schedule sets values that authorize action — S-01-A, S-01-B, S-01-C, S-04-B, S-04-C — a row that is omitted authorizes nothing, and the action to which it relates shall not be taken. An operator who has not decided a limit has not authorized the activity it would govern.

3.3 Disclosure schedules: omission is a bare representation. Where a schedule records facts qualifying a representation — Instrument 03's Schedules A through J — a schedule referred to but not delivered is treated as delivered blank, and the representation is given without qualification. An omitted disclosure is not a shelter.

3.4 Why the two defaults differ. Both resolve against the party who controls the schedule. In a governance schedule that party is the operator, and the conservative outcome is that unauthorized activity does not occur. In a disclosure schedule that party is the representing party, and the conservative outcome is that an unqualified statement stands. The principle is constant even though the mechanics invert, and stating it here is the point of this Part.

3.5 Expressly blank is a completed row. An operator may record that a value is deliberately unset, and that row is complete provided it carries a basis, a person, and a date. This is the honest way to record an open question, and it is materially better than an omission because it is visible.

3.6 Incomplete rows. A row missing a required field is incomplete and is treated as omitted under 3.2 or 3.3 as applicable. Systems enforcing schedules should reject incomplete rows rather than apply their populated portion.

3.7 Versioning. Schedules are versioned independently of the instruments they attach to. Where an instrument refers to a schedule, it refers to the version in effect on the instrument's effective date unless the instrument provides otherwise. Superseded rows are retained, not deleted.

Drafting notes.

On the enforcement point field, which is the one that will be resisted. Requiring each row to name where the value is actually enforced converts the schedule from a statement of policy into a map of controls, and it will immediately surface rows where the honest answer is nowhere. That is the field doing its job. A limit enforced nowhere is a position, and an institution is better served knowing which of its limits are positions.

On requiring a natural person in the set-by field. Teams and committees do not remember, are not available to be asked, and cannot explain a basis two years later. The requirement is not about blame; it is about the existence of someone who can answer the question.

On the basis field permitting inheritance. Allowing a row to record that a value was inherited from a prior configuration is deliberate. The alternative is that the field gets filled with a plausible rationalization invented after the fact, which is worse than an honest admission and much harder to detect. Make the honest answer available and it will sometimes be used.

On the common-use field in S-02-A. This records a belief rather than a fact, which is unusual, and it is carried over from Article 7 of the annex for the reason given there: the aggregate of those records is the only visibility anyone would have into whether the market is converging on shared triggers.

On append-only test records. S-02-C never supersedes a row. A test log that can be edited is a test log whose absences cannot be distinguished from deletions, and the value of retaining tests that did not fire depends entirely on the record being complete.

On Instrument 03's Schedules A through J, recorded as a deliberate exception rather than left to look like an oversight. Every other schedule in this Part carries an S-0n-X identifier keyed to the instrument it attaches to. Instrument 03's schedules do not, and the question of whether to rename them for consistency was considered and decided against. A-through-J lettering is the established convention in disclosure schedule practice, and a transactional lawyer opening Schedule C expects to find it under that name, not under S-03-C. Internal symmetry is the weaker interest here; matching the convention the reader already has is the stronger one. The exception is confined to Instrument 03 and does not extend to any schedule introduced after this instrument.

The negative space.

Relationship to the framework.

This instrument attaches to all four preceding instruments and is the form in which their evidence is produced. Where the other instruments state what an institution must be able to show, this states what showing it looks like.

Its primary counterpart is not a single firm-level question but the register's own: MARQUE Standards & interoperability, because a form that makes the library machine-evaluable is itself a conformance artifact rather than a claim of one. On KYA, it is the operative counterpart to dimension 08: an institution that can produce completed schedules in this form, rather than describe its governance in narrative, is evidenced on whether it can demonstrate conformance rather than claim it. Every other instrument's own dimension is served by this one as well, indirectly and completely — none of them can be evidenced at all without a completed schedule in the form this instrument defines.

This is an editorial form with commentary, published in the tradition of model agreements and form books. It is not legal advice, not a compliance determination, not a certification, and not a representation that any provision here is enforceable in any jurisdiction. It should be reviewed by counsel and adapted before use.