The model
Stewardship, not control
Concert's governance follows the OpenPeppol AISBL pattern — a non-profit steward with multi-stakeholder representation, transparent decision-making, and clear separation between standard governance and commercial operation.
The critical structural principle: Concert (the steward) and Score (the operator) are legally separate entities. Concert owns the intellectual property and licenses it to commercial operators including Score. This ensures the standard cannot be captured by any single commercial interest, and that alternative operators can emerge.
What follows describes the model as designed. Three of the four bodies are not yet constituted, and the page says so against each one rather than leaving it to be inferred. Until they are, decisions that would fall to them are taken under a published bootstrap clause and recorded as interim resolutions — in force, reasoned in writing, and reversible on the record.
Governance bodies
Four bodies, three of them not yet constituted
The model as designed, with the current state of each body stated against it. A body that is designed and a body that is operating are different claims, and the difference matters most to whoever is reading this to decide whether the standard is independently governed.
Network Authority (Concert Foundation)
- Sets technical standards and specifications
- Licenses the SIGNET Certified marks to implementations that pass the public conformance suite — no certifications have been issued yet
- Manages the trust framework and participant registry
- Operates the supplier identity service
- Publishes the SIGNET specification under open licence
- Composition: Independent board with buyer, supplier, technology, academic, and government representatives
- Decision-making: Consensus-seeking with supermajority voting fallback
Standards Committee
- Technical interoperability decisions
- Protocol evolution and version management
- Standards adoption and deprecation
- Testing and certification criteria
- Intended composition: Technical representatives from member organisations, invited experts, liaison with W3C/OpenPeppol/OASIS
- Intended decision-making: Technical consensus with reference implementations as proof
It is not yet constituted. It will be constituted at the first external certification. Until then, decisions that would fall to the Committee are taken under a published bootstrap clause and recorded as interim resolutions — in force, reasoned in writing, and reversible by the Committee on the record once it exists.
Buyer Councils
- Procurement rules and category governance
- Supplier entry criteria and qualification standards
- Event types and evaluation methodologies
- Compliance requirements per jurisdiction
- Intended composition: Procurement leaders from anchor buying organisations
- Intended decision-making: Per-SIGNET sovereignty (each buying community sets its own rules within the standard's framework)
AI Governance Board
- Agent safety and ethical deployment standards
- Model oversight and responsible AI requirements
- DLP, Data Governance, and AI Safety control standards
- Use case approval framework
- Intended composition: AI ethics researchers, procurement domain experts, information security specialists
- Intended decision-making: Every agent deployment type would require formal board approval with documented controls. No such approval gate operates today, because the Board is not constituted.
The interim arrangement
What operates while the bodies do not
No Standards Committee is constituted, so referring every structural decision to it would defer all of them indefinitely. Decisions taken in that window are recorded as interim resolutions: in force, reasoned in writing, and reversible by the Committee on the record rather than by silent drift. The resolutions in force are indexed at governance/ in the standard's repository; that index is the record, and this page does not restate their number.
Nothing in the standard has reached ratified status, because no Committee exists to ratify it. The interim arrangement is operated in good faith. It is not an independent standards body, and it is not described as one.
How a change is reviewed
Two tiers, by pull request only
Every change arrives by pull request; direct commits to main are not a permitted route for any change of any class. Non-normative changes take one approving review and no comment period. Normative changes — the schemas, the closed codelists, the conformance levels, the suite and the report schema, plus the mark grammar and the two closed registers — additionally require a recorded resolution and a stated comment period of at least 14 calendar days.
The process applies from 20 August 2026. Changes merged before that date followed prior practice, which included direct commits to main and pull requests merged with administrative override. They are not relabelled as having followed this process, because they did not; they are superseded from the effective date.
Who reviews and merges
Two accounts, one operator
Two GitHub accounts act on the standard's repository: concertfoundation authors changes and opens pull requests, and concertcustodian reviews, approves and merges them. Both are currently operated by the same natural person.
The separation is procedural, not independent. An approval records that a change was reviewed against the published process; it does not constitute independent review and must not be read as such. This ends when the Standards Committee is constituted, at which point review passes to accounts under separate control.
The review tiers, the interim arrangement and its limits, and the repository identities are published in full at GOVERNANCE.md. The bootstrap clause and the interim resolutions in force under it are indexed at governance/.
Membership
Three tiers of participation
Founding Members
Organisations shaping the standard from inception
Board representation, Standards Committee seat, early access to specifications, logo on concert.foundation, invitation to all governance meetings
Annual contribution, active participation in at least one governance body, commitment to deploy or support at least one SIGNET within 24 months
Members
Organisations adopting or supporting the standard
Standards Committee observer status, access to specifications and implementation guides, member directory listing, community support channels
Annual contribution, and certification against the public conformance suite where operating a SIGNET implementation
Associates
Researchers, individuals, and smaller organisations
Access to specifications, community channels, event invitations
No financial contribution required; knowledge contribution encouraged
Membership tiers are the model as designed. Several benefits name bodies that are not yet constituted, and a seat on a body that does not exist is a commitment rather than a current entitlement.
Intellectual property
Open standard, protected marks
The SIGNET specification is published under a royalty-free licence that permits implementation by any party. The IP policy follows the W3C Patent Policy model:
Participants in the Standards Committee grant a royalty-free licence to any essential claims in patents they hold that are necessarily infringed by conforming implementations. This ensures that implementing the SIGNET standard never requires patent licence negotiations.
Concert Foundation holds the SIGNET trademark and certification marks. Use of these marks requires certification that the implementation conforms to the current specification and passes the compliance test suite. This protects the ecosystem from fragmentation while keeping the standard itself open.
The standard is published under CC0 1.0 (the trademark and certification marks are carved out). Contributions are governed by CONTRIBUTING.md, which links the CLA and the CI/CLA-assistant flow. The normative/non-normative split and every versioned change are tracked in the changelog.
Certification fees are the Foundation's primary sustaining revenue, by design — so the standard itself stays free. Certification is decided solely by a public, machine-runnable suite on identical terms for every implementer; see Conformance & certification.