Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

17 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Blockchain Responsibility Model (BRM)

A control- and activity-based metamodel for allocating technical, operational, legal, risk, and assurance responsibilities across heterogeneous blockchain and distributed-ledger ecosystems.

Core proposition: responsibility follows factual control, performed activity, decision authority, and economic benefit—not only technical layer, legal title, or a claim of decentralization.

Repository status

This repository is under active development. Documents marked Draft capture working models and are not approved policy, legal advice, certification criteria, or normative requirements.

Start here

Model structure

BRM analyzes a system through:

Network Profile × Component × Actor × Control Right × Activity × Jurisdiction × Lifecycle Event

It separates four planes:

  1. Technical stack: infrastructure; client/core protocol; consensus/network operation; data availability/state; interoperability/oracles; smart contracts; wallets/identity/custody; application/interface/off-chain services.
  2. Control planes: governance, upgrades, emergency powers, keys and privileges, treasury, and economic incentives.
  3. Regulatory overlays: authorization, AML/CFT, issuance, market integrity, custody, consumer protection, privacy, resilience, outsourcing, tax, records, and IP.
  4. Assurance: risk assessment, testing, audit, monitoring, evidence, certification, incident response, and reassessment.

Responsibility dimensions

BRM extends beyond a single RACI assignment and records:

  • Design Authority;
  • Implementation Responsibility;
  • Operational Control;
  • Change / Upgrade Authority;
  • Emergency Authority;
  • Key / Privilege Custodian;
  • Economic Beneficiary;
  • Legal / Regulatory Accountable;
  • Risk Owner;
  • Control Owner;
  • Evidence Owner;
  • Assurance Provider;
  • User / Counterparty Duty Owner.

Source and draft handling

  • Imported drafts retain their source and draft status.
  • Published standards are pinned by identifier, edition, and status.
  • ISO work items at AWI, WD, CD, DIS, DTS, or PRF stages are tracked as research inputs and are not represented as published requirements.
  • Regulatory claims must be checked against the activity, actor, jurisdiction, and effective date.
  • Model changes should preserve traceability from source to concept, allocation rule, control, and evidence.

Roadmap

  • canonical actor and component taxonomy;
  • machine-readable YAML/JSON responsibility-record schema;
  • network-profile templates;
  • control-right and economic-influence assessment;
  • jurisdictional regulatory-activity decision trees;
  • assurance and evidence catalogue;
  • worked examples for L1, L2, consortium DLT, cross-chain protocol, and hybrid DeFi;
  • normalization of the lifecycle draft against BRM.

About

Security and Governance Responsibility Matrix

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors