The Governance Meridian

The Governance Meridian is a publication of decision-grade briefings on cyber, AI, and digital sovereignty, written for operators across pan-African institutions and emerging-markets contexts. Its premise is straightforward. The frameworks that govern technology adoption in African institutions must be built for the continent’s actual topology, its regulatory environments, its capital structures, its institutional histories, rather than imported wholesale from elsewhere. Imported frameworks describe a world that does not quite exist here. The work of governance is to describe the world that does, and to build accordingly.

Three lines of work shape the publication.

Posture and frameworks. The first pillar is the African Security Maturity Model (ASMM), a continental reference model for cyber and AI security under constraint. ASMM organizes around ten Domains, five Postures, a diagnostic instrument that requires evidence rather than self-rating, and explicit cost reality bands for African reference organizations. It is built for environments where infrastructure is unreliable, talent is volatile, regulators vary by jurisdiction and by year, vendors hold asymmetric leverage, and the security function operates inside state-actor demand. ASMM is published here in iteration. It will be sharpened under operator critique or it will not be useful. The Certified Information Security Manager (CISM) credential anchors the methodological discipline behind the work.

Executive controls and procurement discipline. The second pillar examines the gating, sourcing, and accountability mechanisms that determine whether AI and cloud adoption survives a regulator, a board, or its own operational complexity. This is the unglamorous infrastructure of governance: vendor evaluation, contractual gating, control inheritance, audit posture, the separation of technical evaluation from political pressure on procurement. It is where most transformations succeed or fail, and where imported procurement discipline tends to assume conditions that do not hold across the continent. The Project Management Professional (PMP) credential informs how this work is structured.

AI sovereignty in practice. The third pillar engages the question every African institution is now navigating: what does sovereign AI actually require, and what is the gap between sovereignty as a stated policy and sovereignty as an operating reality? This work is being built in public alongside the Advanced in AI Security Management (AAISM) credential, which is currently in progress. The build-in-public posture is deliberate, here and throughout the publication. Frameworks suited to the continent do not yet exist in mature form, and developing them transparently is more useful than presenting finished conclusions.

The publication is written for the operators who carry the consequences of these decisions: chief executives, chief information security officers, regulators, board members, and the institutional investors whose capital depends on getting governance right. It is not written for commentators, and it does not aim to produce commentary. Each briefing exists to inform a specific class of decision.

The work is offered with an invitation. Take what is useful. Push back on what is not. Document the gap. The frameworks improve through contact with operators who use them, or they do not improve at all.

A paid Founding Circle tier will open later this year for readers who want to support and shape the work earlier in its arc. Until then, everything is free.

User's avatar

Subscribe to The Governance Meridian

Decision-grade governance briefings on cyber, AI, and the African frontier. Transitioning practice from the United States to the continent — for the operators who carry the consequences.

People