Policy is not a decision criterion generated by the AI System itself, but is established through legitimate Governance Authority. AI Systems and Vigilance Functions may reference Policy and evaluate its application, but they do not independently modify Policy or create new Authority. This separation connects the Governance Basis of System Behavior to Institutional Governance rather than to internal AI judgment.

Policies referenced by a Policy Tag can broadly be divided into External / Institutional Policies and Internal / Organizational Policies. External Policies include Laws, Regulations, Regulatory Requirements, Industry Standards, Professional Rules, and Jurisdictional Requirements, each established by an Institution with legitimate Authority.

Internal Policies include Corporate Policies, Internal Rules, Authority Rules, Risk Requirements, and Operational Policies. Organizations may establish these according to their operations, Risk Appetite, and Operational Context, but they must maintain Alignment with applicable External Governance and higher-level Institutional Requirements. Internal Policy cannot arbitrarily override a higher-level Applicable Requirement.

A Policy Tag preserves not only Policy content but also the information required to identify it as Governance Evidence. Applicable Policy identifies the relevant Rule or Requirement, while Governance Authority identifies the Authorized Body that established it. Scope defines its applicability across dimensions such as Jurisdiction, Organization, Function, or User. Policy ID / Version, Effective Period, and Applicable Conditions establish which Policy was valid, when it was valid, and under what conditions.

Policy also changes over time. When Laws, Regulations, or Organization Policies are revised, a Policy that did not exist at the time of a past Decision must not be retrospectively applied to that Decision. Policy State therefore preserves states such as Applicable, Superseded, and Exception, enabling reconstruction of the Policy Version and Conditions that actually applied at the time of the Decision.

Where Vigilance identifies a Policy Gap, Conflict, or previously unanticipated Risk, the Finding may be fed back into Governance and trigger Policy Review. However, Policy modification itself occurs through an Authorized Governance Process. This separates the Function through which Vigilance observes Governance and supports improvement from the Function through which Governance Authority determines Policy.

A Policy Tag therefore functions not merely as a reference to a Rule, but as Evidence of the Applicable Governance Basis at the time of a Decision. While the Fact Tag preserves “what existed or occurred,” the Policy Tag preserves “what Governed it at that time,” making it possible to verify the Governance Basis upon which subsequent Evaluation was formed.