Regulated organizations commonly design their compliance programs around whichever certification mechanism is currently in force. This paper argues that is a mistake of architecture, and distinguishes two layers that move at different speeds. The obligation layer — contract clauses, control standards, and liability for attestations about one's own posture — has been substantially stable for a decade. The verification layer, the mechanism by which someone checks, is revised frequently; organizations in the U.S. defense industrial base have seen it restructured repeatedly since 2019. Every verification mechanism yet proposed resolves in practice to the same two questions asked of the same artifacts: where is the evidence, and is it current? The paper describes an evidence architecture aimed at the obligation layer, built on the Open Knowledge Format (OKF), an open specification published by Google Cloud in June 2026 for representing knowledge as a directory of markdown files. It introduces okf-grc, an openly licensed set of conventions for representing controls, evidence, policies, findings, and plans of action as portable, versioned files that organizations own outright. It addresses the evidentiary weight of version history, the scoping consequences of storing evidence artifacts, the constraints required for AI systems operating over compliance knowledge, and the limits of the approach.
Patrick Parker (Wed,) studied this question.