The Community Draft of the Federal Office for Information Security (BSI), Germany’s national cybersecurity authority, for the Horizontal Trustworthiness Core Module (A5) describes trustworthiness as an organizational capability that is operationalized through roles, processes, responsibilities, and evidence.
This shifts the focus of AI governance.
At first glance, the A5 Draft appears to be a catalogue of organizational requirements. On closer examination, however, it follows a different logic: it describes a governance architecture in which trustworthiness is operationalized through organizational roles, processes, responsibilities, and evidence.
The document places strong emphasis on a coherent organizational architecture. Roles are defined, responsibilities assigned, evidence requirements established, and processes linked together. Governance therefore emerges as an integrated organizational system rather than a collection of isolated controls.
This is particularly evident in the consistent connection between evidence, accountability, and auditability. Trustworthiness is expected to be demonstrable. As a result, the organization’s capability to sustain governance over time—and to provide verifiable evidence of that capability—moves to the center.
Yet this very strength creates a new governance tension.
The more systematically trustworthiness is operationalized through organizational structures, the more important the transitions within those structures become. When does continuous monitoring become a governance-relevant incident? How should organizations design the interfaces between observation, assessment, and incident management? And how can evidence remain meaningful as systems, contexts, and risks evolve over time?
These questions do not arise despite the architecture, but because of it. The more governance depends on organizational capabilities, the more critical their continuous operation, internal consistency, and adaptability become.
The A5 Draft therefore represents a broader shift in perspective.
Trustworthiness becomes an organizational capability to structure responsibility, govern processes, and maintain demonstrable governance over time.
This development is likely to extend well beyond the document itself. As AI governance becomes increasingly operationalized, attention will continue to shift away from individual technical measures toward the organizational capability to establish, maintain, and continuously demonstrate trust.
AI G&M Insight
The A5 Community Draft makes a broader structural movement visible: trustworthiness is increasingly being operationalized through organizational capabilities. As this shift continues, the central governance question changes. The primary challenge is no longer whether organizations have governance structures in place, but how effectively they can sustain, adapt, and govern those structures under changing conditions.

