Quality Policy

Effective 2026-05-25 · v1.0 · Methodology v3.4
01

Purpose

This Quality Policy describes the standards AECO.digital commits to when operating AECO Shield and the underlying AECO Shield methodology. It applies to every score, verdict, audit artifact, and methodology revision the platform produces.

Customers, insurance carriers, state board reviewers, and procurement teams are the intended audience.

02

Scope

This policy governs:

  • The AECO Shield methodology (currently v3.4) — the scoring engine that produces ACS scores, DCS verdicts, and Stamp-Safe classifications
  • The AECO Shield application and its modules (C1 Compliance Scanner · C2 Digital Maturity · C3 Software Comparison · C4 Execution Layer)
  • The public AECO Tool Registry
  • Every artifact AECO Shield generates (audit PDFs, policy drafts, training matrices, gap reports, sign-off receipts)
  • The Standards Citation Library that grounds every methodology output

This policy does not govern customer-side use of generated artifacts. Customers remain responsible for adapting Shield output to their firm's specific circumstances under licensed professional judgment.

03

Commitments

AECO.digital makes the following operating commitments:

3.1

Methodology integrity

The AECO Shield methodology is versioned, dated, and publicly accessible. No methodology revision is applied retroactively to existing audit records. Every score, verdict, and artifact carries the methodology version under which it was produced, and that version is preserved for the artifact's full retention period.

3.2

Citation-grounded output

Every methodology output that references an external standard cites the specific section of the source document. The standards currently underwriting the methodology are: ISO 42001 (AI Management Systems), NIST AI Risk Management Framework (Govern, Map, Measure, Manage), EU AI Act (Articles 8, 9, 10, 52), CMMC 2.0 (federal AEC cybersecurity), ISO 19650 (BIM information management), and IBM AI governance principles. Standards are reviewed quarterly and incorporated into methodology revisions on a published cadence.

3.3

Calibration anchor

The Decision Confidence Score (DCS) thresholds — GREEN (≥88%), AMBER (68–87%), RED (<68%) — are anchored to v3.4 multi-framework convergent reasoning across three governance and validation frameworks the licensed professional, insurer, and regulator can verify and trust directly: ISO/IEC 42001:2023 (AI Management System Standard), NIST AI Risk Management Framework 1.0, and FDA Software-as-a-Medical-Device (SaMD) framework. Convergence of three independently-derived frameworks on the same conservative-stamping threshold is a stronger defensibility claim than alignment with any single framework. The calibration is published in the methodology document and revisited only on major methodology version increments.

3.4

Audit retention

Every artifact AECO Shield generates is retained for seven years from creation, regardless of customer subscription status. This window matches typical statute-of-limitations exposure for professional liability claims in licensed AEC practice. Customer-initiated data deletion requests are honored under applicable privacy law, but the retention default is preservation.

3.5

Transparency on AI use

AECO Shield uses AI models (currently the Anthropic Claude family) to generate artifacts. Every artifact discloses which model produced it, under which methodology version, and the source citations grounding its claims. AI-generated content is never presented as expert opinion; it is presented as draft material the licensed professional reviews and adopts under their own responsible charge.

3.6

Hard-filter discipline

Tools that fail any of the five Hard Filters (HF1 through HF5 — geographic licensure, code edition currency, BIM/ISO 19650 compatibility, cybersecurity baseline, professional indemnity coverage) cannot earn a Stamp-Safe classification regardless of their composite ACS score. This rule is not configurable by customers, AECO.digital staff, or commercial relationships.

3.7

Standards watch

AECO.digital monitors source standards for material changes (Tier 1 manual review currently; semi-automated detection and automated alerts are planned). When a relevant standard changes, the methodology kernel is reviewed within 30 days. Affected artifacts are flagged for re-stamping where the change materially alters the underlying score or verdict.

3.8

Verification before publication

No assessment enters the public AECO Tool Registry without methodology-stamped review. Pre-launch tool assessments may be produced via Claude API automation, but every published entry carries an editorial sign-off recording the methodology version, review date, and reviewer attribution.

3.9

No conflict of interest

AECO.digital does not accept payment, gifts, or other consideration from AI tool vendors in exchange for favorable assessments, registry placement, or methodology accommodation. The methodology kernel evaluates tools by published criteria only. Vendor relationships are disclosed where they exist.

04

Methodology revision policy

The AECO Shield methodology evolves on a deliberate cadence. Two version types are recognized:

Version typeCadenceTriggerEffect on prior artifacts
Minor (v3.3 → v3.4)Quarterly reviewNew standards or refined questionsForward-only; prior artifacts remain valid under the version that produced them
Major (v3.x → v4.0)As neededCalibration anchor change or domain restructuringPrior artifacts flagged for re-stamping; explicit migration guidance published

Every revision produces a methodology diff document published alongside the new version. Customers and registered tool vendors receive notification at publication.

05

Standards alignment

AECO Shield methodology v3.4 maps to the following external standards. Mapping documentation is maintained in the published methodology and the standards citation library.

StandardRelevanceMethodology mapping
ISO 42001AI Management SystemsDomains 1, 2, 4
NIST AI RMFAI Risk ManagementDomains 1, 2, 3, 4
EU AI ActArticles 8, 9, 10, 52 (high-risk AI systems)Domain 1, Q21b
CMMC 2.0Federal AEC cybersecurityDomain 5
ISO 19650BIM information managementDomain 4
IBM AI governance principlesIndustry maturity benchmarkDomain 6
06

Governance of this policy

This Quality Policy is reviewed at every minor methodology version increment. Material changes to the policy are published with a version bump and an effective date.

Questions, corrections, or formal concerns about this policy may be directed to support@aeco.digital.

AECO Shield v3.4 · Quality Policy v1.0 · Effective 2026-05-25 · 7-year audit retention applies to all referenced artifacts.