Reference

Glossary.

The regulatory instruments, sector terms, corridor regimes and framework concepts used across Direct Intelligence, defined once and grouped by section.

Advanced Manufacturing

1
UK-India CETA
UK-India Comprehensive Economic and Trade Agreement; signed 24 July 2025; NOT in force; CRaG ratification in progress; first half of 2026 entry into force expected.

Advanced Materials

2
UK Carbon Border Adjustment Mechanism (CBAM)
UK domestic mechanism mirroring the EU CBAM; established in primary law by the Finance Act 2026 (Royal Assent 18 March 2026); commencement date 1 January 2027; first accounting period 2027; first filing and payment 31 May 2028.
UK Emissions Trading Scheme (UK ETS)
UK carbon pricing mechanism; linked to UK CBAM tariff rate; quarterly rate publications.

AI and Data Infrastructure

6
Digital Omnibus
EU legislative package provisionally agreed 7 May 2026 to defer EU AI Act high-risk obligations; not yet formally adopted; until adoption, original 2 August 2026 high-risk date remains active law.
EU AI Act (Regulation (EU) 2024/1689)
World's first comprehensive AI law; prohibited practices from February 2025; GPAI obligations from August 2025; Article 50 transparency obligations from 2 August 2026; high-risk obligations provisionally deferred subject to Digital Omnibus formal adoption.
EU AI Office
EU body assuming enforcement powers for the EU AI Act fully from 2 August 2026; administers GPAI model obligations.
General-Purpose AI (GPAI)
AI models capable of performing a wide range of distinct tasks; subject to specific EU AI Act obligations (in force August 2025); GPAI models with systemic risk carry additional requirements.
ISO/IEC 42001
International AI management system standard (published December 2023); third-party certifiable; increasingly procurement-relevant in GCC, Singapore, and South Korea corridors.
Rated IT Load (data-centre capacity threshold)
The Cyber Security and Resilience Bill uses a 1 MW rated IT load threshold (10 MW for enterprise-only centres) to determine whether a data centre is in scope.

All NSI sectors

1
Notifiable Acquisition Regulations (NARs)
Secondary legislation defining the scope of mandatory-notification obligations under the NSI Act 2021; currently specify 17 sectors; expansion to 19 sectors (Critical Minerals, Semiconductors as standalones) confirmed 12 March 2026, secondary legislation pending.

All sections

3
CNI
Critical National Infrastructure. The regulated, high-scrutiny sectors and operators Direct Intelligence serves. DI operates across 24 CNI sectors across three tiers.
DIRECT
Doran Integrated Rational-Emotional Cognitive Theory. The intellectual framework underlying all Direct Intelligence services, expressed through six service pillars: NEXUS, VECTOR, SENTINEL, BEACON, STRATA, and FORGE. Intellectual property of Gary Daniel Doran; administered through Direct Intelligence Ltd with academic governance through ICDM.
ICDM
Institute of Critical Infrastructure Decision Making. The research arm of Direct Intelligence Ltd. Conducts original primary research, governs the DIRECT framework intellectual programme, and is the publishing governance body for The Signal and for FORGE commissioned research. Canonical name: Institute of Critical Infrastructure Decision Making. No variance permitted.

All services

1
In-force / announced / negotiated
The three-state regulatory distinction applied to all time-sensitive claims in Direct Intelligence outputs.

All Tier 2 CNI-adjacent sectors

1
Cyber Security and Resilience Bill
Incoming statute; key Tier 2 sectors in scope: data centres (1 MW threshold), space and satellite operators, emergency services. Royal Assent expected H2 2026.

ANZ

2
AUKUS
Trilateral security partnership between Australia, the United Kingdom and the United States. Pillar I covers the nuclear-powered submarine programme; Pillar II covers advanced capabilities. Directly enables the ITAR §126.7 licence-free defence-trade exemption for Authorised Users.
Five Eyes
Intelligence-sharing alliance comprising Australia, Canada, New Zealand, the United Kingdom and the United States. Underpins cyber-threat intelligence sharing and supply-chain posture alignment.

ANZ corridor

6
ASD (Australian Signals Directorate)
Australia's national intelligence and cyber authority; recipient of mandatory SOCI cyber-incident notifications.
Cyber Security Act 2024 (Australia)
Australia's first standalone Cyber Security Act; in force late November 2024; ransomware-payment reporting (72 hours) from 30 May 2025; smart IoT device standards from March 2026.
Essential Eight (ASD)
Australian Signals Directorate's eight baseline cybersecurity mitigation strategies; widely applied as a procurement and assurance standard for Australian government and critical-infrastructure suppliers.
Privacy Act 1988 (Australia)
Australia's data-protection regime; mid-overhaul; automated-decision-making transparency obligations commencing 10 December 2026.
Privacy Act 2020 (New Zealand)
New Zealand's data-protection regime; mandatory notifiable-privacy-breach scheme; extraterritorial reach to overseas agencies carrying on business in New Zealand.
SOCI Act (Security of Critical Infrastructure Act 2018)
Australia's critical-infrastructure security regime, covering 11 sectors; expanded by the 2024 SOCI Amendment Act to include secondary assets holding business-critical data.

Canada corridor

7
Bill C-27
The proposed Digital Charter Implementation Act 2022; contained the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act; died on the Order Paper January 2025 on prorogation. Not delayed; gone.
Bill C-8
Canada's federal critical-infrastructure cyber statute, mid-passage as of June 2026; enacts the Critical Cyber Systems Protection Act (CCSPA); passed Third Reading in the House of Commons 26 March 2026; before Senate.
CCSPA (Critical Cyber Systems Protection Act)
Will establish mandatory cybersecurity duties for designated operators in federally regulated vital sectors; penalties up to CAD 15 million per day; 90-day programme obligation on designation.
CSE (Communications Security Establishment)
Canada's national cyber authority; designated recipient of CCSPA mandatory incident reports once Bill C-8 is in force.
PIPEDA
Personal Information Protection and Electronic Documents Act (2000); Canada's federal private-sector privacy baseline; unmodernised; remains the operative federal floor.
Quebec Law 25
Act to modernise legislative provisions as regards the protection of personal information (Quebec); three-stage rollout completed September 2024; GDPR-adjacent obligations; de facto operative privacy standard.
UK-Canada TCA
UK-Canada Trade Continuity Agreement; preserves CETA-equivalent terms post-Brexit; bespoke FTA negotiations paused.

Chemicals

4
COMAH 2015
Control of Major Accident Hazards Regulations 2015; active, fully enforced regime governing upper-tier and lower-tier hazardous sites; joint Competent Authority of HSE and environmental regulators.
GB GHS/CLP
GB classification, labelling, and packaging regime for hazardous chemicals; continuous compliance obligation.
PFAS (Forever Chemicals)
Per- and polyfluoroalkyl substances; progressing through the UK REACH Substance Restriction Process; not yet a uniform in-force restriction.
UK REACH
Post-Brexit GB chemicals registration and evaluation regime; HSE acts as the GB agency; registration deadlines extended multiple times since 2021; Northern Ireland follows EU REACH under the Windsor Framework.

Civil Nuclear

7
GBE-N (Great British Energy-Nuclear)
Statutory delivery body for the UK's new-nuclear capital programme; direct restructured successor to Great British Nuclear; tasked with directing the SMR programme and identifying further sites.
Hinkley Point C
Twin-EPR nuclear power station under construction; approximately £46bn capital cost; first reactor start-up expected approximately 2030.
NDA (Nuclear Decommissioning Authority)
Statutory body managing legacy civil nuclear decommissioning; approximately £132bn undiscounted cost over approximately 120 years.
ONR (Office for Nuclear Regulation)
Statutory safety and security regulator for civil nuclear sites and licensees in the UK.
RAB (Regulated Asset Base)
Financing model for Sizewell C; UK government is the largest shareholder at 44.9%; backed by primary debt via the National Wealth Fund.
Sizewell C
Twin-EPR nuclear power station; FID July 2025; financial close 4 November 2025; approximately £38bn; full construction delivery from 2026.
SMR (Small Modular Reactor)
Rolls-Royce SMR preferred bidder selected 10 June 2025; Wylfa confirmed as site 13 November 2025; delivery contract signed 13 April 2026; FID expected approximately 2029.

Construction

9
Building Safety Regulator (BSR)
Statutory body administering the Gateway regime and wider Building Safety Act obligations; transferred from HSE to MHCLG NDPB on 27 January 2026.
Central Digital Platform (CDP)
See Government and Procurement entry in Section 2.
Construction Products Reform
Policy programme following the Grenfell Tower Inquiry Phase 2; Construction Products Reform White Paper published 25 February 2026; legislative response expected.
Future Homes and Buildings Standards
Statutory instruments laid 24 March 2026; in force 24 March 2027 for standard works; 24 September 2027 for higher-risk building works.
Gateway regime (Gateways 1, 2 and 3)
Statutory hard stops under the Building Safety Act 2022 for higher-risk buildings; Gateways 2 and 3 are legal hard stops; operative from 1 October 2023.
Higher-risk building (BSA definition)
A building at least 18 metres in height or at least 7 storeys, with at least two residential units; subject to the full Gateway regime and dutyholder obligations under the Building Safety Act 2022.
Most Advantageous Tender (MAT)
See Government and Procurement entry in Section 2.
Nationally Significant Infrastructure Project (NSIP)
Large-scale infrastructure projects requiring Development Consent Orders rather than planning permission; cross-referenced across energy, water, transport, construction sectors.
Single Construction Regulator
Proposed consolidation of building-standards and safety regulation; government response to consultation expected Summer 2026.

Construction and Engineering

1
Building Safety Act 2022
In-force UK statute; three-gateway regime for higher-risk buildings (at least 18m or 7 storeys, at least 2 residential units) operative from 1 October 2023; dutyholder obligations throughout design and construction lifecycle.

Critical Minerals

2
Minerals Security Partnership
Multilateral initiative (US-led) to diversify critical-minerals supply chains away from single-country dependency; UK is a member.
Vision 2035 (UK Critical Minerals Strategy)
The UK's long-term critical minerals strategy; includes up to £50m new DBT funding (detail pending).

Defence

6
Authorised User (ITAR §126.7)
Designation granted via UK ECJU coordinated with US DDTC; prerequisite for licence-free trilateral defence trade under ITAR §126.7; Final Rule effective 30 December 2025.
CMMC (Cybersecurity Maturity Model Certification)
US DoD supply-chain cybersecurity certification regime; Phase 1 live from 10 November 2025; Phase 2 (mandatory Level 2 C3PAO) from 10 November 2026; gates US federal contract eligibility.
Defence Industrial Strategy
2025 strategy restructuring MOD acquisition; establishes National Armaments Director; three-tier procurement segmentation; +£2.5bn SME spend target by 2028.
ITAR §126.7
AUKUS defence-trade exemption under US International Traffic in Arms Regulations; Final Rule effective 30 December 2025; enables licence-free transfers between designated Authorised Users.
ITAR §126.7 (AUKUS export-control exemption)
US ITAR provision enabling licence-free defence trade between AUKUS Authorised Users; applies to UK, US and Australia only; Final Rule effective 30 December 2025.
Strategic Defence Review 2025
Published 2 June 2025; 62 recommendations, all accepted; restructured MOD procurement; foundation for the Defence Industrial Strategy.

Education and Skills

3
Horizon Europe (UK association)
The UK has full association to Horizon Europe; UK researchers and institutions participate on equal terms with EU member states.
Office for Students (OfS)
Statutory regulator for higher education in England; financial sustainability monitoring is a recurring obligation for in-scope providers.
REF 2029 (Research Excellence Framework)
The next iteration of the periodic assessment of UK university research quality; formally reinstated 10 December 2025 with revised 55/25/20 weighting; submission criteria finalised late 2026; institutional submissions due autumn 2028; results published December 2029.

Emergency Services

1
Emergency Services Network (ESN)
Next-generation mission-critical communications network replacing Airwave; programme status and milestone dates require primary-source verification (Home Office publications).

Energy

7
Carbon Budget (CB)
Statutory emissions ceiling set under the Climate Change Act 2008; CB7 covers 2038 to 2042 at 535 MtCO₂e, passed into law 2 June 2026.
Clean Power 2030
Government action plan targeting at least 95% clean electricity generation by 2030; sets specific capacity targets including 43 to 50 GW offshore wind.
Energy Act 2023
Framework statute in force establishing NESO, reformed licensing, and the statutory basis for market reforms.
Great Grid Upgrade
80 critical transmission projects identified to deliver Clean Power 2030; capital investment estimated at £8bn to £14bn per year to 2030.
NESO (National Energy System Operator)
Independent system operator for Great Britain, owner of the Connections Reform and Gate 2 delivery pipeline.
NESO Gate 2
Reformed grid-connection regime; application window closed 26 August 2025; projects must meet readiness and strategic-alignment criteria for a confirmed connection date.
Seventh Carbon Budget (CB7)
Set at 535 MtCO₂e for 2038 to 2042; passed into law 2 June 2026 ahead of the 30 June 2026 statutory deadline.

Environment and Nature

7
30-by-30 (land and sea protection target)
The UK and global target to protect 30% of land and 30% of seas by 2030; referenced in the Environment Act 2021 and EIP25.
Biodiversity Net Gain (BNG)
Requirement under the Environment Act 2021 to deliver at least 10% BNG for most TCPA development; mandatory since 12 February 2024; mandatory for NSIPs from 2 November 2026.
CBAM (EU Carbon Border Adjustment Mechanism)
EU carbon border tax; definitive period began 1 January 2026; financial liability for embedded emissions in cement, steel, aluminium, fertilisers, electricity, hydrogen now applies; first certificate surrender 30 September 2027.
ISSA (UK) 5000 (sustainability assurance standard)
UK sustainability assurance standard; effective for assurance engagements on periods beginning on or after 15 December 2026.
ISSB IFRS S1 and S2
International Sustainability Standards Board baseline standards for climate-related and broader sustainability disclosures; the foundation of the UK SRS.
UK CBAM (UK Carbon Border Adjustment Mechanism)
See Tier 2 entry. Established in primary law by Finance Act 2026; commencement 1 January 2027; first accounting period 2027; first filing 31 May 2028.
UK Sustainability Reporting Standards (UK SRS S1 and S2)
Published 25 February 2026 on a voluntary basis only; NOT mandatory; FCA expected to mandate for in-scope listed entities from 1 January 2027 via listing rules, subject to final rules.

EU corridor

7
CBAM (Regulation (EU) 2023/956)
Carbon Border Adjustment Mechanism. EU carbon border tax; definitive period began 1 January 2026; covers cement, steel, aluminium, fertilisers, electricity, hydrogen.
Critical ICT Third-Party Provider (DORA)
Non-EU technology providers brought into direct supervisory scope by the European Supervisory Authorities under DORA; designations rolling through 2026.
Digital Omnibus on AI
EU package provisionally agreed 7 May 2026 deferring AI Act high-risk obligations. Not yet formally adopted; not yet in EU Official Journal. Until adoption, original 2 August 2026 dates remain law.
DORA (Regulation (EU) 2022/2554)
Digital Operational Resilience Act. EU binding ICT risk-management framework for the financial sector. Directly applicable, no transposition. Fully applicable since 17 January 2025, no grace period. Lex specialis to NIS2 for financial entities.
Lex specialis
The principle that more specific law prevails over more general law where both apply to the same matter; DORA is lex specialis to NIS2 for financial entities.
NIS2 Directive ((EU) 2022/2555)
EU expanded cyber-resilience framework. Transposition deadline 17 October 2024; obligations apply country-by-country through national law; transposition uneven.
UK Adequacy Decision (EU-UK)
European Commission decisions confirming the UK provides an essentially equivalent level of data protection. Renewed 19 December 2025; valid until 27 December 2031.

Finance

5
Critical Third Parties (CTP)
UK regime (FCA PS24/16; PRA PS16/24) taking legal effect 1 January 2025; HM Treasury designates CTPs; regime going live as designations roll out through 2026.
EU DORA
Digital Operational Resilience Act (Regulation (EU) 2022/2554); fully applicable 17 January 2025; lex specialis to NIS2 for financial sector; applies extraterritorially to UK firms and ICT providers serving EU financial entities.
FCA Connect
Single regulatory platform for operational incident reporting under PRA PS7/26; 24-hour window for authorised firms; 4-hour window for payment service providers; mandatory from 18 March 2027.
ISO/IEC 27001
International information-security management standard; procurement floor across UK CNI; substantially evidences DORA ICT risk-management requirements; 2013-to-2022 transition closed October 2025.
Operational Resilience (FCA/PRA)
Regime under FCA PS21/3 and PRA SS1/21; transition ended 31 March 2025; firms must continuously operate important business services within impact tolerances.

Food and Agriculture

4
ELM (Environmental Land Management)
Multi-year public-goods funding framework replacing direct area-based payments in England; funding locked through 2028/29 fiscal year.
European Partnership Bill
Announced in King's Speech 13 May 2026; enabling legislation for potential domestic enforcement of a negotiated UK-EU SPS agreement; not yet law.
SFI 2026 (Sustainable Farming Incentive)
SFI26 reopens in dual-window schedule: Window 1 June 2026 (small farms 3 to 50ha); Window 2 September 2026 (all eligible); strict £100,000 annual cap; 71 authorised actions.
SPS Agreement (UK-EU)
Sanitary and Phytosanitary agreement; Common Understanding signed 19 May 2025; under active negotiation; NOT in force; non-binding mid-2027 implementation target.

GCC corridor

8
In-Country Value (ICV)
UAE In-Country Value programme; scores suppliers on local spend, workforce and investment; ICV certificates weighted in major tenders; 14-month validity.
Public Investment Fund (PIF)
Saudi Arabia's sovereign wealth fund; the largest sovereign wealth vehicle in the GCC.
Saudi NCA (National Cybersecurity Authority)
Issues the Essential Cybersecurity Controls mandatory for government and critical-sector entities; ECC-2:2024 issued October 2024.
Saudi PDPL
Saudi Arabia's Personal Data Protection Law; administered by SDAIA; in force with extraterritorial reach; data-residency and transfer conditions apply.
Saudi Vision 2030
Saudi Arabia's national economic diversification and transformation programme; the primary driver of sovereign procurement activity.
SDAIA (Saudi Data and AI Authority)
Administers Saudi Arabia's PDPL and national data/AI governance framework.
UK-GCC FTA
Prospective free trade agreement between the United Kingdom and the six GCC member states; negotiations began June 2022; ongoing as of May 2026; not signed, not concluded, not in force.
UKEF (UK Export Finance)
Provides export credit, insurance and direct lending to support UK exporters in GCC and other overseas markets.

Government

5
CDP (Central Digital Platform)
Mandatory publication and registration service under the Procurement Act 2023; live from 24 February 2025; suppliers must register for a unique identifier; without it, contract award is legally prohibited.
MAT (Most Advantageous Tender)
Replaces lowest-price evaluation under the Procurement Act 2023; SME inclusion, social value, prompt payment, supply-chain resilience, and decarbonisation are core evaluation criteria.
NPPS (National Procurement Policy Statement)
Cabinet Office policy lens for MAT evaluation; periodically reweighted; current version formalises decarbonisation and supply-chain resilience as core pricing criteria.
Procurement Act 2023
Post-Brexit replacement for the Public Contracts Regulations 2015; in force 24 February 2025; covers England, Wales, and Northern Ireland; Scotland retains its own regime.
Procurement Review Unit
Oversight body for the Procurement Act 2023 regime; first annual report expected H2 2026.

Health

4
ICB (Integrated Care Board)
Local delivery bodies for NHS commissioning; roughly 42 currently; NHS Modernisation Bill proposes consolidation to approximately 26 clusters.
MHRA
Medicines and Healthcare products Regulatory Agency; UK regulator for medicines and medical devices; Post-Market Surveillance regime in force from June 2025; pre-market SI and International Reliance Framework expected 2026.
NHS Modernisation Bill
Introduced King's Speech 13 May 2026; second reading completed 1 June 2026; abolishes NHS England and transfers functions to DHSC; legal abolition targeted April 2027; not yet law.
PMS (Post-Market Surveillance)
MHRA PMS regime active from June 2025 under Part 4A of the UK Medical Devices Regulations 2002; 15-day serious-incident reporting window.

India corridor

5
CERT-In
Indian Computer Emergency Response Team; issues mandatory cyber-incident reporting directions: six-hour reporting window from detection.
CRaG (Constitutional Reform and Governance Act 2010)
UK parliamentary scrutiny process through which international treaties, including UK-India CETA, are ratified before entry into force.
DPDP Act 2023
India's Digital Personal Data Protection Act; operationalised by DPDP Rules notified 13 November 2025; three-phase commencement: Phase 1 (November 2025), Phase 2 (November 2026), Phase 3 substantive obligations (13 May 2027, no grace period).
Press Note 3 (2020)
FDI screening overlay requiring prior government approval for investment from entities in countries sharing a land border with India.
Significant Data Fiduciary
A class designation under the DPDP Act carrying enhanced obligations; designations expected 2026 to 2027.

Logistics and Ports

2
Border Target Operating Model (BTOM)
UK import-control framework for goods from the EU; full SPS physical inspections on medium-risk EU goods in force from 31 March 2025.
Sanitary and Phytosanitary (SPS) controls
Measures to protect human, animal and plant health in trade; the basis for the UK-EU SPS agreement currently under negotiation.

Professional Services

6
Alternative Business Structure (ABS)
Law firms owned in whole or in part by non-lawyers; regulated by the SRA under the Legal Services Act 2007.
ARGA (Audit, Reporting and Governance Authority)
Proposed replacement for the FRC; formally scrapped January 2026; the FRC is confirmed as the permanent UK audit regulator.
FCA AML supervisory role
FCA announced 21 October 2025 as future single AML supervisor for professional services; consultation outcome and migration timetable expected Autumn 2026.
FRC (Financial Reporting Council)
UK statutory audit regulator; confirmed as permanent regulator following the January 2026 scrapping of the proposed ARGA replacement.
Legal Services Board (LSB)
Oversight regulator for the legal services regulatory framework; issued Statutory Directions to the SRA following the Axiom Ince case.
Solicitors Regulation Authority (SRA)
The professional regulator for solicitors in England and Wales; subject to LSB Statutory Directions following the Axiom Ince enforcement case.

Quantum Technologies

3
AUKUS Quantum Arrangement (AQuA)
Trilateral quantum information-sharing and capability-development arrangement under AUKUS.
Post-Quantum Cryptography (PQC)
Cryptographic algorithms designed to be secure against quantum-computer attacks; NIST PQC standards finalised 2024; migration timeline being set across CNI sectors.
Quantum Key Distribution (QKD)
Cryptographic protocol using quantum mechanics to distribute encryption keys; secure against quantum-computer attacks; UK government investment programme.

Research

2
Evidentiary Standard
The common standard governing all ICDM and Direct Intelligence outputs: a claim is either sourced (source stated) or labelled as an assessment (basis and confidence level stated). The in-force / announced / under-negotiation distinction is applied to every regulatory reference.
The Signal
The editorial publication of ICDM. Publishes original analysis on emergent risk, governance and institutional behaviour across critical national infrastructure. Not a newsletter or aggregator. Published when analysis warrants it. Open access, no registration required.

Research section

3
Gated Research
ICDM research formats that require verified-access request rather than open download: Position Papers, Monographs, Applied Research series and the Dossier Series. Access via /briefing-gate.
The Dossier Series
Verified-access deep-dive documents structured for institutional decision-makers, positioned beneath every authority page on the DI site.
Verified Access
The access model for gated ICDM research. Readers request access through /briefing-gate; access is granted to verified institutional readers.

Research section (/research)

1
Research Hub
The landing page at /research. Describes the three-part research architecture: ICDM (the institute), The Signal (the channel) and FORGE (the service). Not a content page; a navigation and orientation page.

Research section (ICDM RP-07)

1
Regulatory Readiness Index (RRI)
Annual cross-sector benchmark measuring where the UK CNI supply chain sits against incoming regulatory obligations; formalised through RP-07; annual cadence from H1 2027.

Research section (ICDM RP-10)

1
Institutional Intelligence Maturity Model (IIMM)
First structured maturity model for institutional intelligence capability in UK CNI; formalised through RP-10; annual benchmarking tool; annual cadence from Q3 2027.

Research section (ICDM)

4
Decision Architecture (academic discipline)
The formal discipline established through the DIRECT framework and the Decision Architecture Series. The systematic study of how individuals, groups, organisations and societies structure, sequence and execute decisions.
ICDM Research Programmes (RP-01 to RP-10)
Ten structured research programmes forming the ICDM forward research agenda. RP-01: CNI Workforce Competency (Q3 2026). RP-02: AI Governance Readiness (Q4 2026). RP-03: ISO 42001 Adoption (Q1 2027). RP-04: Decision Architecture Study (Q2 2027). RP-05: NSI Act Market Navigation (Q3 2027). RP-06: Sovereign AI Deployment (Q4 2026). RP-07: Regulatory Readiness Index (H1 2027). RP-08: Corridor Regulatory Divergence Monitor (Q1 2027). RP-09: Multi-Standard Compliance Burden (Q2 2027). RP-10: Institutional Intelligence Maturity (Q3 2027).
Primary Research
Original research conducted from primary data collection and direct analysis, not aggregated or synthesised from third-party reports.
The Contact Institute
The dual publisher imprint used for the Decision Architecture Series: The Contact Institute / ICDM. ISBN Agency: Nielsen UK.

Sectors (all NSI)

1
NSI Act
National Security and Investment Act 2021. The UK's mandatory-notification screening regime for acquisitions in sensitive sectors. Currently covers 17 sensitive sectors; expansion to 19 sectors confirmed 12 March 2026; secondary legislation not yet enacted.

Services (Consultancy)

4
Decision architecture
The structured reconstruction of an institutional decision: what is actually being decided, who holds it and who can block it, the sequence of moves required, and the dependency between them.
Friction definition
The opening stage of a Consultancy engagement: naming the specific institutional decision that is stalled, contested or mis-sequenced.
Regulated-market entry
The process of entering or expanding in a UK market governed by statutory screening regimes, procurement frameworks, and sector-specific regulatory perimeters.
VECTOR
The Decision-Architecture Engine; the decision-architecture pillar of the DIRECT framework. Translates institutional friction into defensible, sequenced advisory positions.

Services (Intelligence)

3
Buyer decision architecture
A structured analysis of how a specific institutional buyer makes a given decision: who decides, who can veto, what the institution is optimising for behind its stated criteria, and where in its real process the outcome is determined.
Decision-environment scoping
The opening stage of an Intelligence engagement: fixing the specific institutional decision, the live timeframe, and the confidence threshold needed to act.
NEXUS
The Intelligence Engine; the decision-intelligence pillar of the DIRECT framework. Sector signal, buyer behaviour and regulatory data fused into a single decision view.

Services (Research)

2
Commissioned research
Original research conducted under ICDM governance and scoped to a specific institutional question on behalf of a verified client, delivered with a defensibility review.
FORGE
The Research pillar of the DIRECT framework; the commissioned research service. The route by which a verified institution commissions Direct Intelligence to conduct original research on a specific question, under ICDM governance. Distinct from the institute's published research, available through The Signal.

Services (Standards, Systems)

2
ASSURE AI
DI's planned AI assurance product; confirmed as a DI product; canonical v2 does not yet exist; Phase 2 build.
ISO/IEC 42001:2023
The world's first international AI management system standard; published December 2023; third-party certifiable.

Services (Standards)

11
Continuous-posture governance
The ongoing management of a certification and compliance architecture as a live, demonstrable state between surveillance assessments and recertification cycles.
Cyber Essentials Plus
The UK government-backed baseline cybersecurity certification scheme, independently assessed. Layered under the multi-standard management system architecture.
DORA
Digital Operational Resilience Act (EU). In force for financial-sector entities; ICT-risk-management requirements substantively evidenced by an operational ISO 27001 management system.
ISO 14001
ISO 14001 is the international standard for Environmental Management Systems (EMS). It provides a framework for organisations to manage their environmental responsibilities in a systematic way that contributes to the environmental pillar of sustainability.
ISO 22301
ISO 22301 is the international standard for Business Continuity Management Systems (BCMS). It specifies requirements to plan, establish, implement, operate, monitor, review, maintain and continually improve a documented management system to protect against, reduce the likelihood of occurrence, prepare for, respond to, and recover from disruptive incidents.
ISO 45001
ISO 45001 is the international standard for Occupational Health and Safety Management Systems (OH&S). It provides a framework for organisations to improve employee safety, reduce workplace risks and create better, safer working conditions.
ISO 9001
ISO 9001 is the internationally recognised standard for Quality Management Systems (QMS), published by the International Organization for Standardization. It specifies requirements for a QMS that organisations can use to demonstrate the ability to consistently provide products and services that meet customer and regulatory requirements.
ISO/IEC 27001:2022
The international standard for information security management systems; procurement-prerequisite across UK CNI; 2013-to-2022 transition closed 31 October 2025.
ISO/IEC 27701
ISO/IEC 27701 is an international standard that extends ISO/IEC 27001 to include requirements and guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS).
SENTINEL
The Assurance Engine; the governance-and-standards pillar of the DIRECT framework. One platform, multiple standards, continuous compliance governed end to end.
Statement of Applicability
A required ISO 27001 document listing the controls selected and the justification for those selections.

Services (Systems)

8
BEACON
The Execution Engine; the applied-AI pillar of the DIRECT framework. AI built to human-in-the-loop and EU AI Act risk-management standards from inception.
Compliance-by-architecture
The design principle of building governance, audit-trail and documentation into an AI system from inception.
DI Systems Flywheel
The DI methodology for building human-governed AI systems: train humans first, codify their knowledge into the AI, feed AI outputs back into human understanding, then build the AI to augment humans while humans govern it.
EU AI Act Article 14
The EU AI Act's human-oversight requirement for high-risk AI systems.
EU AI Act Article 9
The EU AI Act's risk-management requirement for high-risk AI systems; treated as a build specification for all Systems service outputs by default.
Human-in-the-loop
An AI system design pattern in which defined human control points, reviewable decision records and named accountability roles are structural properties of the system, not nominal sign-off steps.
ISO 27001 Annex A.8.20 to A.8.22
The network security controls within ISO/IEC 27001:2022 (A.8.20 network security, A.8.21 security of network services, A.8.22 segregation of networks); the architectural basis for sovereign private AI deployments.
Sovereign private deployment
A DI Systems service delivery model in which hardware and software are installed within the client's physical perimeter, running a private large-language model closed from public networks.

Services (Talent)

6
Advisory sprint
A bounded advisory engagement that works a senior leader through a defined decision, or set of decisions, applying the DIRECT individual register.
Capability mapping
The assessment and benchmarking of an organisation's institutional decision-making capability across functions and seniority bands.
Competency architecture
A structured model of the competencies a specific regulated operating role requires, mapped to domains and built to the demonstrable-mastery standard.
Demonstrable competency
The evidence standard STRATA is designed to produce: proof that a named role holds the competencies its operating environment requires, produced to a standard that survives scrutiny.
Dual-track design
The STRATA design principle of separating frontline operational models from management and oversight models.
STRATA
The Workforce Engine; the workforce pillar of the DIRECT ecosystem. Applies the DIRECT framework at the individual register (senior decision advisory) and the organisational register (capability mapping). Not externally accredited.

Singapore

1
CPTPP
Comprehensive and Progressive Agreement for Trans-Pacific Partnership. The UK has acceded; Singapore, Canada and New Zealand are founding members.

Singapore corridor

8
Cybersecurity (Amendment) Act 2024
Act 19 of 2024; key provisions commenced 31 October 2025; third-party CII responsibility, STCC, expanded incident reporting including supply-chain incidents. Parts 3C and 3D (ESCI and foundational digital infrastructure) enacted but not commenced.
Cybersecurity Act 2018 (Singapore)
Singapore's national cybersecurity statute; expanded by the Cybersecurity (Amendment) Act 2024; key provisions commenced 31 October 2025.
Entity of Special Cybersecurity Interest (ESCI)
New category created by the Cybersecurity (Amendment) Act 2024 Part 3C; enacted but not yet commenced; designation watch.
GeBIZ
Government Electronic Business; Singapore's public-procurement system and supplier-accreditation perimeter.
MAS (Monetary Authority of Singapore)
Singapore's financial regulator; sets technology-risk-management and outsourcing requirements that function as de facto entry conditions for financial-sector technology suppliers.
Model AI Governance Framework
Singapore's non-statutory AI governance framework; increasingly treated as a procurement and assurance expectation by institutional buyers; not binding legislation.
PDPA (Singapore)
Personal Data Protection Act 2012 (as amended 2020); breach notification threshold: significant harm or 500 or more individuals; extraterritorial effect.
UK-Singapore Digital Economy Agreement
One of the world's most comprehensive digital-trade agreements; primary UK-Singapore bilateral instrument for digital-sector engagement.

South Korea corridor

8
AI Basic Act (South Korea)
Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust; promulgated 21 January 2025; in force with Enforcement Decree from 22 January 2026; obligations live; penalty provisions deferred approximately one year.
DAPA (Defense Acquisition Program Administration)
Governs Korean defence capital acquisition, indigenisation content requirements and offset obligations.
K-ISMS-P
Korea Information Security Management System; administered through KISA; mandatory for certain ICT service providers; increasingly treated as a de facto procurement precondition.
KISA (Korea Internet and Security Agency)
Administers the K-ISMS-P certification and the network-security incident regime.
MSIT (Ministry of Science and ICT)
Lead ministry for the AI Basic Act; issues the Enforcement Decree and implementing regulations.
PIPA (South Korea)
Personal Information Protection Act; one of the more stringent data-protection regimes in Asia; extraterritorial reach; enforced by PIPC; amendment commencement 11 September 2026 raises penalty ceiling.
PIPC (Personal Information Protection Commission)
Korea's independent data-protection authority; enforces PIPA including its extraterritorial provisions.
UK-Korea Upgraded FTA
Concluded in principle 15 December 2025; tariff-free access across 98% of Korean tariff lines; not yet signed; legal-text finalisation continuing.

Space and Satellites

3
GNSS (Global Navigation Satellite System)
Space-based positioning, navigation and timing infrastructure; includes GPS (US), Galileo (EU), GLONASS (Russia), BeiDou (China).
PNT (Positioning, Navigation and Timing)
Critical national infrastructure function delivered primarily via GNSS; resilience and alternative-PNT capability is a strategic UK priority.
Satellite and Space Technologies (NSI mandatory-notification sector)
One of 17 current mandatory-notification sectors under the NSI Act 2021; covers acquisition of entities involved in satellite and space technologies.

Telecoms

4
Designated Vendor Directions
Legally binding directions under the TSA 2021 issued to approximately 35 operators requiring removal of Huawei equipment from UK 5G networks by end of 2027.
High-Risk Vendor
Designation under the Telecommunications (Security) Act 2021; currently applies to Huawei; national security powers vested in the Secretary of State can extend the designation.
PSTN Switch-Off
Permanent retirement of the public switched telephone network and analogue copper infrastructure on 31 January 2027.
TSA 2021 (Telecommunications (Security) Act)
In-force UK statute; commenced 1 October 2022; codifies Telecoms Security Requirements; enforced by Ofcom with penalties up to 10% turnover or £100k per day; Tier 1 deadline 31 March 2024; Tier 2 31 March 2025; full Code 31 March 2028.

Tier 2 (Advanced Robotics, Quantum)

1
AUKUS Pillar II
Advanced capability domains under AUKUS: AI, quantum, autonomous systems, electronic warfare, hypersonics. Distinct from Pillar I (nuclear-powered submarines).

Tier 2 (Defence, Space, Advanced Robotics)

1
AUKUS Authorised User
Designation enabling licence-free defence trade under ITAR §126.7 between US, UK and Australia; applied for through national export-control systems.

Transport

4
ANPS (Airports National Policy Statement)
Planning framework for airport expansion; draft expected summer 2026; Parliamentary vote autumn 2026; governs Heathrow expansion decision pathway.
GBR (Great British Railways)
Forthcoming public body to integrate rail operations and infrastructure; does not yet legally exist; created by the Railways Bill.
Passenger Railway Services (Public Ownership) Act 2024
In-force UK statute; removed the presumption in favour of private-sector passenger rail provision; legislative foundation for renationalisation.
Railways Bill
Introduced to Parliament 5 November 2025; creates Great British Railways; NOT yet law; carries no confirmed Royal Assent date.

UK corridor

5
AI Safety Institute
UK body conducting frontier model evaluation; sits alongside the DSIT sector-led AI governance framework.
Cyber Security and Resilience (NIS) Bill
See Sectors entry. Introduced 12 November 2025; Royal Assent expected late 2026; most substantive obligations commence via secondary legislation.
Investment Security Unit (ISU)
UK government unit administering NSI Act investment-screening notifications and clearances within the Cabinet Office.
NSI Act (17 sectors, 19-sector expansion)
National Security and Investment Act 2021; 17 mandatory-notification sectors currently; expansion to 19 sectors confirmed 12 March 2026; secondary legislation not yet enacted.
PSTI Act (Product Security and Telecommunications Infrastructure Act 2022)
Sets minimum security requirements for connectable consumer products; enforced by OFCOM.

US corridor

7
Atlantic Declaration
UK-US bilateral framework (2023); provides the political context for AUKUS ITAR §126.7 cooperation.
CFIUS
Committee on Foreign Investment in the United States; reviews foreign acquisitions of US businesses in critical technologies, critical infrastructure or sensitive personal data for national security risk.
CIRCIA
Cyber Incident Reporting for Critical Infrastructure Act 2022; mandatory cyber-incident reporting for critical infrastructure operators; implementing rule being finalised through 2026.
CMMC 2.0
See Defence sector entry. Acquisition rule in force 10 November 2025; Phase 2 (mandatory Level 2 C3PAO) from 10 November 2026.
FedRAMP
Federal Risk and Authorization Management Program; authorisation programme for cloud services sold to US federal agencies; impact levels Low, Moderate, High.
NIST SP 800-171
US federal information-security standard for protecting Controlled Unclassified Information on non-federal systems; baseline for CMMC 2.0 Level 2; 110 detailed controls.
Section 889
Section 889 of the FY2019 NDAA; prohibits US federal procurement of equipment or services from named Chinese vendors and their subsidiaries.

Water

5
Cunliffe Review (Independent Water Commission)
Reported July 2025 with 88 recommendations calling for a "fundamental reset" of the water sector.
Ofwat
Economic regulator for water in England and Wales; under confirmed future abolition; remains the active regulator as of June 2026.
PR24
Ofwat's five-year price review; finalised late 2024; prices fixed 1 April 2025 to 31 March 2030; approximately £88bn industry investment.
Water (Special Measures) Act 2025
In-force UK statute; empowers Ofwat to ban water-company executive bonuses if environmental standards are missed.
Water Reform Bill
Anticipated legislation (2026 to 2027 session, expected but not guaranteed) to abolish Ofwat and establish the single integrated regulator; no confirmed timeline.