The methodology reference paper — architecturally anchored on the SSI Systemic Layer v1.0.1 canonical specification (twenty conventions SY.1-SY.20). Layer A (distributional-outcome dimensions) and Layer B (strategic-autonomy with three sub-layer decomposition) form the organising spine. The Buldyrev-2010 interdependent-network substrate, Miller-Blair Leontief inverse, Rose-Round SAM regional-outcome extension, Kemeny-Snell absorbing-chain foreclosure formalism, Sargentis axis-wise gating, and Diebold-Mariano walk-forward validation are the cascade math substrate. The Gaussian copula, 5σ tail prism, and R9 compound-concurrence modifier are instruments on top of the Systemic Layer. Companion reference layer to the F-02 empirical case-load.
15 September 2026 · v2 rebuild — Systemic Layer v1.0.1 canonical spec as organising spine · SSI Index Foundation (in establishment, Naples DPR 361/2000) · CC BY-SA 4.0 · Peer-review anchors: JIPR v16 doi:10.1186/s43065-026-00193-z · ERE companion doi:10.1088/2753-3751/ae87a5 · Companion empirical layer: F-02 · The 2026 European Heatwave: The Cascade and Compound Layer Beyond the First Wave (1 September 2026)
Problem. Cascade risk (a failure propagating through the network) and compound risk (independent failures coincident within a time envelope) are structurally different phenomena that co-occur in critical civil infrastructure under climate + geopolitical stress. Existing utility-side tail-risk instruments treat them separately or absorb them into a single Value-at-Risk figure. Neither approach lets a policy-maker or asset-underwriter see which failures are which, or where in the network they concentrate.
Systemic Layer architecture. This paper is structured on the SSI Systemic Layer v1.0.1 canonical specification (Bérard 2026, Zenodo deposit, twenty conventions SY.1–SY.20 · convention set closed 7 August 2026). The Systemic Layer is the analytical spine, not a §2 side-panel. Layer A operationalises Reckien 2023's six-criterion distributional-outcome dimensions via the per-substation Composite Vulnerability Index (CVI) with five-band classification (SY.2, SY.6). Layer B operationalises strategic-autonomy across three sub-layers — registered-asset spatial-coverage (B1), technology-sovereignty per-modifier (B2), and workforce-and-competence per-jurisdiction (B3) — each independently scored and independently gate-flagged (SY.3, SY.4). The cascade math substrate composes six peer-reviewed anchors: Buldyrev-2010 interdependent-network dynamics (SY.11), Miller-Blair Leontief inverse (SY.12), Rose-Round SAM regional-outcome extension (SY.13), Kemeny-Snell absorbing-chain foreclosure formalism (SY.14), Sargentis axis-wise gating (SY.15), and Diebold-Mariano walk-forward validation (SY.16). The Fraser 2000 structural-misrecognition acknowledgment layer (SY.19) governs recognition-justice interpretation of the W1/W4/W6 axes.
Instruments. The Gaussian copula (Sklar 1959), the 5σ tail prism (Ikenga-native to SSI-ENN v31.42), and the R9 compound-concurrence modifier (Zscheischler et al. 2020) are instruments that act on top of the Systemic Layer substrate. They are not the substrate. They inherit the Layer A / Layer B decomposition, the non-compensatory verdict rule (SY.7), the five-source stacked Monte Carlo (SY.9), the visibly-honest degradation discipline (SY.10), and the deterministic-replication requirement (SY.8).
Validation. Diebold-Mariano walk-forward tests against a six-event historical battery: Emilia-Romagna floods (May 2023), US Texas freeze (Feb 2021), Iberian cross-border (Aug 2026), Danube-basin superposition (Aug 2026), Chile blackout (Feb 2025), and Ceuta cross-domain (Jul-Aug 2026). Independent-replication audit commitment per SY.20; report deadline end-of-Q4-2028.
Scope + reconciliation. Comprehensive treatment for peer-review + regulator + Foundation-side audiences. This v2 paper uses the canonical Systemic Layer v1.0.1 spec (SY.1-SY.20) as its primary spine; the SB-02/F-02 empirical brief series introduced a supplementary candidate convention series (referenced here as SY-emp.11 through SY-emp.21) which is developed at §2.8 as a supplementary layer without renumbering the canonical range. Reproducibility annex references the Systemic Layer manifest at sha256(cascade_substrate.json).
Two failure modes dominate the tail of civil critical infrastructure risk under climate + geopolitical stress. Cascade risk is the propagation of an initial failure through the network — a 500 kV transmission line trips, generation trips regionwide, load is shed, a national blackout materialises within hours (as in the 25 February 2025 Chile event). Compound risk is the coincidence within a short temporal envelope of independent-cause failures — a heatwave-driven reactor derating in France concurrent with a drought-driven hydro shortfall in Iberia concurrent with a wildfire-driven transmission-corridor loss in Portugal (as in the Aug 2026 Iberian inversion episode). The two are structurally distinct, but their tail-risk consequences superpose.
Standard utility-side tail-risk instruments — parametric VaR, historical VaR, single-Gaussian Monte Carlo — collapse this distinction. A €500M-scale tail loss reads as €500M whether it arose from a single cascading event or from ten independent events happening the same week. For a policy-maker deciding capacity-market design, or a regulator sizing reserve margins, or an underwriter pricing a portfolio of infrastructure assets, this collapse is the wrong output. The tail-risk instrument must show which failures are which, and it must show which populations bear which failures. Neither dimension is available from a single VaR figure.
The methodology developed in this paper takes its architecture from the SSI Systemic Layer v1.0.1 canonical specification. The Systemic Layer is a per-substation × per-jurisdiction analytical layer built on top of the SSI Index v4.2 modifier surface, developed through Waves 3-6.5 of the SSI Index Foundation build-out (April-August 2026) and frozen at v1.0-final on 7 August 2026. It comprises twenty conventions (SY.1-SY.20) organised around two substantive layers (Layer A distributional-outcome, Layer B strategic-autonomy with three sub-layers), one cascade math substrate (six peer-reviewed anchors), one non-compensatory verdict rule, and a fourteen-pytest conformance gate suite.
This paper does not invent the cascade + compound-risk methodology; it quantifies the SSI Systemic Layer at tail-risk resolution. The Markov degradation kernel of Rasmussen (1997), the Gaussian copula of Sklar (1959), the 5σ tail prism (Ikenga-native, deployed in SSI-ENN v31.42), and the R9 compound-concurrence modifier of Zscheischler et al. (2020) are instruments that act on the Systemic Layer substrate. They are not the substrate. Confusing instrument with substrate is a common failure mode of applied tail-risk work; the present paper is architecturally explicit about the distinction.
This paper is the methodology reference layer for the SSI Systemic Layer's tail-risk quantification. It does not present empirical case studies (F-02 does that). It does not present strategic recommendations (SB-01 does that). It formalises the Systemic Layer's tail-risk instantiation, provides validation protocols per SY.16 Diebold-Mariano walk-forward discipline, and anchors reproducibility per SY.8 deterministic-replication requirement. A reader who wants to see the framework applied should read F-02 first, then return here for the mathematics; a reader who wants the underlying canonical specification should read the Systemic Layer v1.0.1 SPEC (Zenodo deposit).
The paper is scoped for four audiences: (a) peer reviewers at applied-mathematics, systems-engineering, or infrastructure-economics journals — for whom the mathematical instruments and validation protocol are the central object; (b) regulators at national grid authorities, financial-services stress-test frameworks (e.g. EU-wide EBA / EIOPA), and TCFD-scenario disclosure — for whom the non-compensatory verdict rule (SY.7) and independent-replication audit commitment (SY.20) are the central objects; (c) Foundation-side users of the SSI Systemic Layer methodology deployed at 796,121-substation × 39-OECD-country scale — for whom the Layer A / Layer B decomposition and coupling substrate are the central objects; (d) Commercial-side counterparts at SSI-ENN who consume the methodology into LP-DD-grade tail-risk products.
This section presents the canonical Systemic Layer v1.0.1 architecture (Bérard 2026, spec closed 7 August 2026, deposited under CC BY 4.0 at Zenodo). The twenty conventions are grouped into six architectural clusters: (i) primacy + layer definition (SY.1-SY.5), (ii) classification + verdict (SY.6-SY.7), (iii) reproducibility + uncertainty (SY.8-SY.10), (iv) cascade math substrate (SY.11-SY.16), (v) preservation + separation + acknowledgment (SY.17-SY.19), and (vi) replication commitment (SY.20).
The twenty conventions are not an arbitrary list. They emerged from a specific analytical concern: every tail-risk methodology hides its analytical decisions behind procedural convenience, and the Systemic Layer was designed to expose those decisions rather than embed them. Cluster 1 (primacy + layer definition) forces the decision which population's distributional outcomes matter to be an explicit input (Layer A CVI drivers), not a defaulted assumption. Cluster 2 (classification + verdict) makes the analytical decision how strong is the required evidence for a policy pass a load-bearing rule (SY.7 non-compensatory verdict) rather than an appendix parameter. Cluster 3 (reproducibility + uncertainty) forces the decision who bears the epistemic burden to sit with the publisher (SY.8 seed pin + SY.9 five-source stack + SY.10 visibly-honest degradation). Cluster 4 (cascade math substrate) makes the decision which mechanism drives the tail concrete via six named anchors rather than a black-box aggregation. Cluster 5 (preservation + separation + acknowledgment) forces the decision which reader inference does the framework not authorise to be explicit (SY.19 Fraser recognition-justice guardrail). Cluster 6 (replication commitment) forces the decision who audits us and when to be a scheduled deliverable rather than an aspiration.
Read in this order, the twenty conventions form a governance stack around the paper's mathematical instruments (§6-§8). The instruments produce numbers; the substrate produces the interpretive constraints under which those numbers are readable. A reader who wants only the mathematical instruments will find them at §5.4 (Kemeny-Snell), §6 (Gaussian copula), §7 (5σ tail prism), §8 (R9 modifier); a reader who wants to know why the numbers can be trusted must read the substrate first.
| # | Name | Role in this paper |
|---|---|---|
| SY.1 | Cohort-scale coupling primacy | Buldyrev-2010 cascade substrate operates on the 796,121-substation cohort; illustrative outputs are secondary evidence. |
| SY.2 | Layer A distributional-outcome dimensions | Anchors §3: vulnerable-population (W1) + cross-sector displacement (W2) + inequity-worsening (W6) via CVI. |
| SY.3 | Layer B strategic-autonomy criteria | Anchors §4: seven criteria mapped to W-axes for gate integration. |
| SY.4 | Three sub-layer decomposition | §4 organised as B1 spatial-coverage / B2 tech-sovereignty per-modifier / B3 workforce per-jurisdiction. |
| SY.5 | Register-access maturity tier assignment | 39 OECD jurisdictions tier-assigned (T1/T2/T3); gates W10 rules + copula block structure at §6.4. |
| SY.6 | CVI five-band classification | Low / Medium / High / Critical / Extreme (cutoffs 0.25/0.50/0.75/1.00/1.30). |
| SY.7 | Non-compensatory verdict rule (load-bearing) | The load-bearing convention. Any single-axis FLAGGED verdict rejects the recommendation. §9 reports outcomes on the six-event battery. |
| SY.8 | Deterministic replication | All Monte Carlo runs use numpy default_rng seed 42; SHA-256 verification per-substation. |
| SY.9 | Five-source stacked Monte Carlo | §9.1: 10,000 iterations, five uncertainty sources tracked separately. |
| SY.10 | Convention #56 visibly-honest degradation | Missing values propagated as None and openly disclosed. |
| SY.11 | Buldyrev-2010 cascade-mechanism substrate | §5.1 anchor. Cross-substation cascade per Buldyrev et al. 2010 Nature. |
| SY.12 | Miller-Blair Leontief inverse | §5.2 anchor. Economic-input-output propagation. |
| SY.13 | Rose-Round SAM regional-outcome | §5.3 anchor. Regional accounting under non-compensatory constraint. |
| SY.14 | Kemeny-Snell absorbing-chain foreclosure | §5.4 anchor. Foreclosing-adaptation formalised as absorbing states. Connects to Rasmussen socio-technical drift (not subsume). |
| SY.15 | Sargentis axis-wise gating | §5.5 anchor. Water-energy-food nexus as axis-wise gates. |
| SY.16 | Diebold-Mariano walk-forward validation | §9.2 anchor. Look-ahead prohibited; walk-forward mandatory for T3-tier claims. |
| SY.17 | Reckien 2023 criterion-mapping preservation | §3.4: six-criterion → W1-W10 mapping frozen at v1.0.1. |
| SY.18 | Two-stage output separation | §4.5: per-substation stats separated from per-candidate-action verdicts. |
| SY.19 | Fraser 2000 structural-misrecognition | §10 anchor. W1/W4/W6 preserve Fraser's structural (not attitudinal) interpretation. |
| SY.20 | Independent-replication audit commitment | §9.5: replication audit with defined deadline; non-delivery triggers visibly-honest degradation flag. |
Layer A operationalises the distributional-outcome dimensions of Reckien et al. 2023's six criteria via composite variables spanning:
The vulnerable-population Composite Vulnerability Index (CVI) is defined as a per-substation aggregate of NUTS-3 socio-economic vulnerability drivers. Its formal definition, five-band classification, and per-band gate rules are developed at §3.
Layer B operationalises strategic-autonomy across seven criteria, each mapped to at least one W-axis for gate-suite integration: technology sovereignty (W4, W8) · supply-chain criticality (W5, W7) · workforce depth (W3) · regulatory competence (W10) · registered-asset auditability (W10) · cross-border interdependency (W7, W9) · demand-response readiness (W8).
Per SY.4, Layer B is decomposed into three sub-layers each independently scored and independently gate-flagged. This decomposition organises §4:
Six peer-reviewed anchors compose the cascade math substrate, developed as an integrated stack at §5:
grid-geo.json topology.Per SY.6, the CVI is classified into five bands with cutoffs at 0.25 / 0.50 / 0.75 / 1.00 / 1.30. Per SY.7 (load-bearing), the verdict rule enforces set-theoretic non-compensation:
where \(W(a) = (w_1, \ldots, w_{10})\) is the per-axis W-flag vector for candidate action \(a\), and \(w_i \in \{\text{PASS}, \text{FLAGGED}\}\). This is code-execution enforcement (fourteen-pytest suite), not weighted-sum aggregation at narrative level.
Per SY.8, all Systemic Layer scoring runs are deterministically replicable under fixed random seed (numpy default_rng seed 42); SHA-256 verification of per-substation output enables post-hoc replication attestation. Per SY.9, uncertainty propagation combines five sources tracked separately: (1) parameter-estimation uncertainty in modifier calibrations; (2) input-data measurement error; (3) climate-scenario uncertainty via CMIP6 ensemble; (4) socio-economic-scenario uncertainty via SSP2-4.5 baseline; (5) Reckien-criterion-threshold calibration uncertainty. Stacked Monte Carlo with 10,000 iterations per substation.
Per SY.10, the Systemic Layer inherits Convention #56 visibly-honest degradation from the underlying SSI Index v4.23 canonical. Missing per-substation values are propagated as None and openly disclosed rather than substituted or imputed. Per SY.19, the framework acknowledges Fraser 2000 structural-misrecognition tradition as its recognition-justice input. W1, W4, W6 axes are calibrated to preserve Fraser's structural (not attitudinal) interpretation. §10 develops the anti-instrumentalisation implications.
Between v0.9-draft (June 2026) and v1.0-final (7 August 2026), the SB-02 empirical-brief series introduced a candidate convention series recording promotion events from empirical-brief work — SY-emp.11 through SY-emp.21. This series is not part of the canonical v1.0.1 spec (which caps at SY.20 and uses different semantics at SY.11-SY.20); it is a supplementary layer tracking empirical instances that have accumulated toward Convention #76 BINDING promotion thresholds. For clarity, this paper preserves the SB-02 candidate numbering as-is (SY-emp.11-SY-emp.21) rather than collapsing it into the canonical range:
| SB-02 candidate | Name | Status (as of Aug 2026) |
|---|---|---|
| SY-emp.11 | Peer-review anchoring | BINDING |
| Every substantive claim in an empirical brief must trace to a peer-reviewed anchor. Composes with canonical SY.11 which uses the label for Buldyrev-2010. | ||
| SY-emp.12 | Dual-output composition (methodology + empirical) | BINDING |
| Each empirical brief (F-series) and its methodology-paper companion (B-series) share identical cascade substrate. Substrate SHA256 hash is verifiable across both outputs. This paper is the B-side of the B1 ↔ F-02 pair. | ||
| SY-emp.13 | Foundational-doc cascade | BINDING |
| Every convention promotion cascades through six touch-points: CONVENTIONS_REGISTRY_SYSTEMIC + HOUSEKEEPING_SYSTEMIC + CLAUDE_SYSTEMIC + AUDIT_BASELINE + closure memo + downstream-consumer document. Governance-hygiene rule. | ||
| SY-emp.14 | NUTS-3 CVI Tier B path | BINDING |
| CVI computable at Tier B resolution via national statistical-office Public-Use Files (Italy ISTAT PUF is the anchor implementation). Tier A/B/C fallback path documented for each of the 39 OECD jurisdictions. | ||
| SY-emp.15 | Coupling matrix + cross-C substrate | BINDING |
| C-taxonomy of 20 cascade classes (C1-C20) with pairwise coupling coefficients (γ_forward, β_lateral, α_absorption) parametrising the Buldyrev interdependent-network substrate. Canonical SY.11 references this at implementation level. | ||
| SY-emp.16 | Interim-state anchoring discipline | BINDING (2026-08) |
| Cascade counterfactuals anchor to the interim empirical state, not to the pre-cascade baseline — the failure surface has memory. Anchored on Scheffer 2001 regime-shift theory. Applied at §7.5 interim-state anchoring of the tail prism. | ||
| SY-emp.17 | Cross-border price asymmetry | BINDING (2026-08) |
| Persistent wholesale-price divergence between adjacent jurisdictions during scarcity signals structural asymmetric burden under EU market coupling — the price divergence signals cascade risk but does not cause it. Anchor: Fabra & Reguant 2014. | ||
| SY-emp.18 | Regulatory-mandate anchoring | BINDING (2026-08) |
| Cascade counterfactuals in a jurisdiction with binding regulatory-mandate obligations must disclose whether the intervention is treated as held-constant null-hypothesis or empirically-allocated per binding-mandate formula. Anchor: Regulation (EU) 2018/1999. | ||
| SY-emp.19 | Intervention-endogenous cascade | BINDING (2026-08) |
| Policy interventions are themselves cascade generators. A policy lever must be decomposed into its constituent second-order + third-order effect chains, not treated as atomic. Anchor: Meadowcroft 2011 path-dependent transitions. | ||
| SY-emp.20 | Walk-forward vs look-ahead epistemic discipline | BINDING |
| Reasoning walks forward from empirical anchor + structured methodology + explicit uncertainty stacking. Look-ahead reasoning (using future data to retrofit past readings) is forbidden. Composes with canonical SY.16 Diebold-Mariano. | ||
| SY-emp.21 | Meteorological × geopolitical superposition | CANDIDATE (2026-08) |
| When two or more independent shocks (meteorological + geopolitical) stress the same regional system simultaneously, cascade behaviour is not sum-of-single-stressor; each shock's mitigation becomes the other shock's binding constraint. Anchor: Zscheischler 2020 + Renn 2008. Danube-basin Aug 2026 is the empirical seed instance. | ||
| SY-emp.22 | Marine-biological cooling-intake cascade | CANDIDATE (2026-09) |
| A marine/riverine heatwave drives a biological bloom (jellyfish/algae/mussels) whose biomass obstructs a thermal plant's cooling-water intake, tripping units on a pathway distinct from thermal derating (cooling capacity nominal; intake physically blocked). Recurrence across sites/years = signature. Anchor: Richardson et al. 2009 + Perrow 1984 + Buldyrev 2010 + Zscheischler 2020. Gravelines 11 Aug 2026 is the empirical seed instance (precedents: Gravelines 10 Aug 2025 + Paluel Sept 2025); F-02 §5.14 is the empirical-brief registration. | ||
The SB-02 empirical series and the v1.0.1 canonical spec overlap partially in substance — the canonical SY.16 (Diebold-Mariano walk-forward) subsumes SB-02 SY-emp.20 (Rule N walk-forward vs look-ahead); canonical SY.11 (Buldyrev-2010) subsumes SB-02 SY-emp.15 (coupling matrix); canonical SY.19 (Fraser structural-misrecognition) subsumes recognitional dimensions of SB-02 SY-emp.13. The remaining SB-02 candidates (SY-emp.16 through SY-emp.21) are architectural extensions specific to the empirical-brief series. Update (24 August 2026): a v1.1 draft specification (SYSTEMIC_LAYER_v1_1_SPEC.md) has landed same-session absorbing SY-emp.16 → canonical SY.21 (interim-state anchoring), SY-emp.17 → SY.22 (cross-border price asymmetry), SY-emp.18 → SY.23 (regulatory-mandate anchoring), SY-emp.19 → SY.24 (intervention-endogenous cascade) as BINDING, and SY-emp.21 → SY.25 (meteorological × geopolitical superposition) as CANDIDATE. SY-emp.20 is documented as subsumed by canonical SY.16 (Diebold-Mariano). SY-emp.11-15 remain under the SB-02 label as Foundation-side operational disciplines that do not warrant canonical status. v1.1 final promotion pending operator sign-off + SY-emp.13 six-touch-point cascade + Zenodo deposit refresh. Update (September 2026): the F-02 second-edition research adds SY-emp.22 — the marine-biological cooling-intake cascade discipline (CANDIDATE), the first post-v1.1-draft addition to the empirical series (which now runs SY-emp.11 → SY-emp.22), registered on the 11 August 2026 Gravelines jellyfish-intake shutdown with 2025 precedents (Gravelines + Paluel); it names a cooling-outage pathway distinct from thermal derating and would follow SY-emp.16→21 into the pending v1.1 canonical absorption on the same promotion cadence. Empirical-brief registration at F-02 §5.14.
Two instrument-references: Rasmussen (1997) migration-to-boundary socio-technical drift framework (mathematical vehicle at Kemeny-Snell absorbing states, SY.14 · §5.4.3); Scheffer (2001) Nature regime-shift theory (mathematical vehicle at interim-state anchoring, SB-02 SY-emp.16 · §7.5).
Statement. Uncertainty sources are tracked separately — not conflated in a single variance figure — and each source is assigned to one of five categories: aleatory-model, aleatory-empirical, epistemic-parametric, epistemic-structural, epistemic-emergent. Composed into every downstream quantification and reported alongside every point estimate.
Distinction from generic uncertainty stacking. Standard uncertainty-stacking practice reports a total variance figure with sub-components in an appendix. Meta-rule II inverts this: the five-category decomposition is the headline output; the point estimate is annotated with its dominant uncertainty class ("predominantly aleatory-model" or "epistemic-structural-limited") so the reader knows why the uncertainty is what it is, not just how much.
Origin. Codified in the Ikenga v31.42 SSI-ENN architecture (2026) as a native rule for tail-risk quantification. Not identical to Rockafellar-Uryasev coherent-risk-measure decomposition or to Convention-of-Bern uncertainty communication guidelines — both of those are inputs but neither is prescriptive at the five-category resolution Meta-rule II requires. Composed with canonical SY.9 five-source stacked Monte Carlo at §9.1.
Layer A operationalises the SSI Systemic Layer's distributional-outcome dimensions (SY.2) via the Composite Vulnerability Index (CVI), the five-band classification (SY.6), and the W1/W2/W6 pytest gate rules. This section presents the CVI formal definition, band cutoffs, per-band cascade quantification, and the Reckien criterion-mapping preservation discipline (SY.17).
For each substation \(i\) in the fleet and each NUTS-3 region \(r\) containing \(i\), the CVI is defined as:
where \(\mathcal{D} = \{d_1, \ldots, d_K\}\) is the set of socio-economic vulnerability drivers (income deciles, elderly-share, energy-poverty, health-vulnerability, digital-exclusion, indigenous-population share, minority-language share); \(v_{i,d}(r)\) is the value of driver \(d\) at NUTS-3 region \(r\) mapped to substation \(i\); \(\omega_d\) is the peer-reviewed cross-driver weight from Reckien 2023 Table 2; \(\psi_{r,d}\) is the Reckien equity-adjustment coefficient at NUTS-3 resolution for driver \(d\).
The CVI value is bounded in \([0, 1.30]\) by construction, where the additive tail above 1.00 corresponds to the v4.2 R6c flood-exposure extension over the v4.0.2 4-band ceiling. NUTS-3 data availability is tier-assigned per SY.5 (Tier B via ISTAT PUF for Italy; Tier A / B / C fallback path across the 39 OECD cohort).
The per-substation CVI value is classified into one of five bands. Each band carries a distinct verdict-rule implication in the SY.7 non-compensatory gate suite:
| Band | CVI range | Population-share indicator | Verdict-rule implication |
|---|---|---|---|
| Low | [0.00, 0.25] | typically 30-45% of served population is in vulnerable categories | Baseline; all axes typically PASS; standard verdict operations apply. |
| Medium | (0.25, 0.50] | 45-60% vulnerable | Watched; one axis may FLAG without triggering SY.7 rejection; monitored per SY.9 five-source uncertainty. |
| High | (0.50, 0.75] | 60-75% vulnerable | Elevated; two or more axes commonly FLAG; SY.7 verdict-rejection triggers for most candidate actions. |
| Critical | (0.75, 1.00] | 75-90% vulnerable | Adaptation-priority band; foreclosing-adaptation gates (W3, W7, W8, W10) require Kemeny-Snell absorbing-state check per SY.14. |
| Extreme | (1.00, 1.30] | >90% vulnerable + R6c flood-exposure additive tail | v4.2 additive-tail band; extends above v4.0.2 4-band ceiling; typically absorbs to compound-event scenarios per §8. |
Why 1.30 and not 1.40 or 2.00? The Extreme-band upper bound is set at 1.30 to accommodate the empirical maximum additive-tail load surfaced by the R6c flood-exposure modifier in v4.2 calibration. Derivation: (a) the v4.0.2 4-band ceiling was 1.00, corresponding to the highest observed CVI value across the 39-country cohort baseline (pre-R6c v4.2 refresh); (b) R6c flood-exposure extension was calibrated in v4.2 (Wave 6.3) against the CMIP6 SSP2-4.5 ensemble at 100-year return period, with peak R6c modifier value across the cohort = 0.29 (Italy-North + Netherlands-coast + UK-East cluster); (c) composite maximum: 1.00 + 0.29 = 1.29, rounded up to 1.30 to preserve a small buffer against upstream drift. Values above 1.30 do not occur in the current 39-country cohort under v4.2; if a future v4.3 calibration surfaces empirical values above 1.30, the ceiling will be raised accordingly per SY.17 methodology-version increment.
Sensitivity. The specific ceiling value 1.30 is not load-bearing for the tail-prism decomposition of §7 — the decomposition is well-defined at any CVI value in [0, +∞) provided the classification map is monotone. The ceiling is load-bearing for the band-labelling: substations at CVI > 1.30 would be band-labelled by the operational implementation as "Extreme+overflow" pending recalibration.
classify_band() engine.The Layer A dimensions map to three of the ten W-axes. Each axis is scored by a dedicated pytest test in the fourteen-pytest conformance suite (SY.7 implementation). Test count per Layer A axis:
| Axis | # tests | Reckien criteria covered | PASS / FLAGGED rule |
|---|---|---|---|
| W1 · Vulnerable-population impact | 1 | (i) compensatory-reduction; (v) inequity-worsening | PASS iff post-action CVI-weighted mean impact does not concentrate above 1.5× baseline in Critical or Extreme bands. |
| W2 · Cross-sector burden displacement | 2 | (ii) shifting-vulnerability | PASS iff Miller-Blair Leontief-inverse shifted burden does not exceed 25% of baseline in any downstream sector (per SY.13 SAM decomposition). |
| W6 · Distributive-justice load | 1 | (v) inequity-worsening | PASS iff Fraser 2000 structural-misrecognition indicator (per SY.19) is not elevated above the pre-action baseline. |
Layer A's W1/W4/W6 gates carry recognitional content. Per SY.19 (developed in full at §10), these gates are calibrated to preserve Fraser 2000's structural interpretation of misrecognition: they test whether institutional arrangements (grid topology, tariff structure, connection-priority rule, adaptation-planning procedure, cost/benefit-allocation rule) systematically deny some categories of persons the standing of full partners in adaptation decision-making. They do not test whether operators or regulators hold dismissive attitudes; that reading is banned as framework misuse. The reason this matters at §3 (rather than being deferred entirely to §10) is that the substantive analytical decisions in Layer A — the choice of CVI drivers, the mapping of Reckien criteria to W-axes, the calibration of CVI bands to verdict-rule implications — all embed the structural interpretation. Deferring the Fraser anchor to §10 would leave §3 methodologically unmoored; anchoring here makes the load-bearing recognitional commitment explicit at the point where it acts on the mathematics.
The many-to-many mapping of Reckien 2023's six criteria onto the ten W-axes is preserved as an interpretive layer. Per SY.17, modifications to the mapping require methodology-version increment (v1.0.1 → v1.1). The six-criterion mapping (see also the P9-ERSS paper Table 2 / Figure 4):
Because the CVI is bounded in \([0, 1.30]\) with per-band gate rules under SY.7 non-compensation, tail-risk propagation through Layer A does not compensate. A cascade or compound event that pushes a substation from Critical band to Extreme band cannot be offset by a countervailing reduction in a neighbouring substation's CVI. This is the load-bearing methodological difference between the SSI Systemic Layer's tail-risk formulation and standard portfolio-VaR treatment.
Layer B operationalises strategic-autonomy across seven criteria (SY.3), decomposed into three sub-layers each independently scored and independently gate-flagged (SY.4). This decomposition is a substantive methodological commitment: cascade risk and compound risk both propagate through strategic-autonomy deficits (missing register coverage, foreign-vendor concentration, workforce-depth gaps), and treating these as a single scalar would mask the structural sources of tail risk.
B1 quantifies the coverage of the SSI Index v4.23 substation cohort (796,121 substations across 39 OECD jurisdictions) by jurisdiction-published Regulated Asset Base (RAB) registers + investment-plan filings. Per SY.5, each jurisdiction is tier-assigned:
B1 anchors the W10 register-access maturity gate (2 tests in the pytest suite). A substation-mapped adaptation action FLAGS W10 iff the register-access tier is inconsistent with the claim being made (e.g. a T3-jurisdiction candidate action cannot pass a claim conditional on Tier-A register-audit evidence).
B2 quantifies the sovereignty of the adaptation-stack technology base per modifier: for each of R6c (flood), R6d (wildfire), R6e (winter storm), R7 (cyber), R8 (adapt), R9 (compound), R10 (just-transition), the domestic vs foreign vendor mix and IP-jurisdiction concentration are scored. The per-modifier decomposition matters because a jurisdiction's tail risk under a specific modifier propagates through the specific technology stack that answers that modifier — not through an aggregate technology base.
B2 anchors W4 (community consent + procedural inclusion, 2 tests), W5 (emissions-lock-in risk, 1 test), and W8 (digital-adaptation-readiness deficit, 1 test). Foreign-vendor concentration above the modifier-specific threshold (calibrated per SY.9 five-source stacked uncertainty) FLAGs the corresponding W-axis.
Setup. For a German substation subset (BNetzA supervisory scope), quantify the R7 cyber modifier's sovereignty score at Sub-layer B2. The R7 modifier is the SSI Index v4.2 cyber-resilience axis; its "sovereignty" is the domestic-vs-foreign-vendor mix + IP-jurisdiction concentration of the cyber-defence stack deployed at the substation.
Input evidence. Federal BSI IT-Grundschutz baseline compliance filings (public, Tier T1 register per SY.5) · VDE-AR-N 4110/4120 grid-code cyber-annex compliance (public) · supply-chain-composition disclosures per NIS2 Article 21(2)(d) essential-entities incident-reporting (partial, Tier T2 register) · publicly-audited vendor concentration in SCADA + protection + intrusion-detection stacks.
Sovereignty score computation. Weighted composite (calibrated per SY.9 five-source uncertainty) of: (a) share of SCADA vendors headquartered in EU-27 vs third-country; (b) share of intrusion-detection stack from EU-headquartered vendors; (c) share of cyber-defence-operator workforce with clearance under national vetting framework; (d) presence/absence of dependency on non-EU-jurisdiction cloud services for security-orchestration functions. Each sub-component maps to [0,1] with peer-reviewed weights.
Gate application. W8 FLAG triggered if the composite sovereignty score falls below the R7-specific threshold (calibrated at 0.42 per the SY.9 five-source uncertainty stack). Empirical: the average German MV substation subset yields a composite score of ~0.61 (T1 register); W8 PASSes. A hypothetical MV substation subset in a jurisdiction with T3 register would default to a conservative floor score triggering W8 FLAG.
Reproducibility. All inputs are publicly citable per SY.5 T1 register. The composite formula + weights are documented at b2_tech_sovereignty.py in the reproducibility annex (§12.1).
B3 quantifies the engineering, operational, and regulatory workforce depth per jurisdiction for adaptation delivery. Sources include Eurostat labour-force statistics per NACE code (electricity supply, network engineering, civil-infrastructure design), national accreditation-body databases (e.g. UK IET, Italy CNI, Germany VDI), and cross-border mobility indicators (EU Blue Card issuance rates).
B3 anchors W3 (adaptation-response deficit, 1 test) — the workforce-depth axis of the foreclosing-adaptation criterion. Below-threshold workforce depth in the domain relevant to the candidate action FLAGs W3.
The four Layer B gates cover Reckien criterion (iv) foreclosing-adaptation + criterion (ii) shifting-vulnerability + criterion (vi) unintended-consequence. Test count per gate:
| Axis | # tests | Sub-layer anchor | Reckien criteria covered |
|---|---|---|---|
| W3 · Adaptation-response deficit | 1 | B3 (workforce-and-competence) | (iv) foreclosing-adaptation |
| W7 · Cascade-chain propagation risk | 2 | B1 + B2 (register + tech-sovereignty) | (ii) shifting-vulnerability; (iv) foreclosing-adaptation |
| W8 · Digital-adaptation-readiness deficit | 1 | B2 (technology-sovereignty) | (iv) foreclosing-adaptation |
| W10 · Register-access maturity gate | 2 | B1 (spatial-coverage) | (iv) foreclosing-adaptation; (vi) unintended-consequence |
Per SY.18, Systemic Layer outputs are separated into two evidence classes:
The distinction matters for tail-risk quantification: class (a) statistics support cascade + compound-risk propagation analysis (this paper); class (b) verdicts support policy-catalogue evaluation (the P9-ERSS paper). Both classes inherit from the same Layer A/B substrate; they do not conflate.
The cascade math substrate composes six peer-reviewed anchors (SY.11-SY.16) into an integrated stack. Each anchor governs a specific dimension of cascade + compound propagation. This section develops the substrate; §§6-8 present the instruments that act on top of it.
grid-geo.json topology. Coupling coefficients γkℓ parametrise the cross-layer dependency edges (SB-02 SY-emp.15 coupling matrix Wave 6.2).Cross-substation cascade propagation is modelled per Buldyrev et al. 2010 Nature interdependent-network cascade dynamics. In the Buldyrev formulation, two interdependent networks (say, the electricity substation network and the transport-signalling network) experience cascading failure when nodes in one network depend on nodes in the other for functional persistence. A node in Network A fails if either (i) it loses connectivity within Network A, or (ii) its dependency partner in Network B has failed.
where \(P_\infty^{(t)}\) is the giant-component size at iteration \(t\), \(p_A, p_B\) are the fractions of remaining nodes in each network, and \(g_A, g_B\) encode within-network connectivity plus cross-network dependency. The recurrence converges to a fixed point that is discontinuous at a critical dependency-density threshold — the hallmark of interdependent-cascade dynamics.
For the SSI Systemic Layer instantiation, Network A is the substation graph generated from the v4.23 grid-geo.json topology; Network B is the coupled sector-dependency network (transport, water, digital, industrial). Coupling coefficients \(\gamma_{k\ell}\) between class-\(k\) and class-\(\ell\) events (C-taxonomy C1-C20 per SB-02 SY-emp.15 coupling matrix) parametrise the recurrence.
Economic-input-output propagation of cascade impact uses the Miller-Blair (2022) Leontief-inverse formulation. Let \(\mathbf{A}\) be the technical-coefficients matrix of a Leontief input-output table; the Leontief inverse \(\mathbf{L} = (\mathbf{I} - \mathbf{A})^{-1}\) quantifies the direct + indirect + induced effect of a unit-shock to any sector.
where \(\Delta\mathbf{f}\) is the final-demand shock vector (e.g. loss of electricity from a cascaded substation cluster) and \(\Delta\mathbf{x}\) is the induced total-output shock across all sectors.
The framework applies the Leontief inverse to translate substation-level cascade losses into per-sector economic-output losses, which then feed the §4.1 (W2 cross-sector displacement) gate rule.
Regional-outcome accounting under non-compensatory constraint follows Rose & Round 2003 Social Accounting Matrix extension. The SAM extends the Leontief input-output structure to include income distribution + household categories + inter-regional transfers. Critically for the SSI Systemic Layer, compensatory cross-regional flows are prohibited by the accounting rule — a cascade loss in NUTS-3 region \(r_1\) is not offset by economic activity in NUTS-3 region \(r_2\) even if aggregate national output is preserved.
Reckien criterion (iv) foreclosing-adaptation is formalised as absorbing states in a Kemeny-Snell 1960 finite Markov chain over adaptation-pathway states. Foreclosed adaptation paths are non-recoverable by construction; W3, W7, W8, W10 gates enforce this at the verdict layer.
Each substation \(i\) at time \(t\) is characterised by a state \(S_i(t) \in \mathcal{S}\) over a finite discrete adaptation-pathway state set. The SSI Systemic Layer instantiation uses five states:
where Foreclosed is an absorbing state per Kemeny-Snell — once reached, no adaptation pathway remains open, and the substation cannot be recovered by within-model action. Recovery requires exogenous re-scoping (retirement + replacement).
The state evolves via a discrete-time Markov chain with transition kernel \(\mathbf{P}(t)\), a \(5 \times 5\) row-stochastic matrix. Entry \(P_{jk}(t) = \Pr[S_i(t+\Delta t) = s_k \mid S_i(t) = s_j, \mathbf{X}_i(t)]\) where \(\mathbf{X}_i(t)\) is the covariate vector (voltage tier, age, historic outage rate, R-modifier stack, jurisdiction). The absorbing property is enforced by \(P_{55}(t) = 1\) for all \(t\); once at Foreclosed, the substation stays there absent exogenous re-scoping.
where \(\mathbf{Q}\) is the \(4 \times 4\) sub-matrix of \(\mathbf{P}\) restricted to transient states (Nominal through Critical), and \(\mathbf{N}\) is the Kemeny-Snell fundamental matrix. Entry \(N_{jk}\) is the expected number of visits to state \(s_k\) before absorption, starting from state \(s_j\). The expected time-to-foreclosure from state \(s_j\) is \(\sum_k N_{jk}\).
The Rasmussen (1997) migration-to-boundary property — the observation that engineered socio-technical systems under performance pressure drift toward boundaries of safe operation absent counteracting intervention — is a substantive claim about the dynamics of engineered systems, not a mathematical theorem. The Kemeny-Snell fundamental-matrix formulation supplies a mathematical vehicle for the phenomenon: absent intervention (\(\mathcal{I}(t) = \emptyset\)), the finite expected time-to-foreclosure \(\sum_k N_{jk}\) quantifies the Rasmussen-articulated drift; with intervention (\(\mathcal{I}(t) \neq \emptyset\)), the kernel is modified to a non-absorbing chain that allows persistent operation. The two frameworks are complementary and mutually reinforcing: Rasmussen supplies the empirical + conceptual grounding for why the absorbing-state formulation is the correct mathematical model for engineered infrastructure; Kemeny-Snell supplies the quantification. Neither subsumes the other.
Infrastructure-self-sufficiency conditions per Sargentis et al. 2021/2022 water-energy-food nexus + landscape-planning framework are treated as axis-wise gates rather than composite-optimisation objectives. Failure at one axis is not compensated by excess at another. This composes with SY.7 non-compensation at the verdict-rule level: a candidate adaptation action that improves one nexus axis but degrades another is FLAGGED even if a naive weighted-sum aggregator would score it PASS.
Perrow (1984) distinguishes four cascade classes by tight-coupling × complex-interaction structure. The Systemic-Layer + Kemeny-Snell + Buldyrev + copula formulation supports all four by parametrising the transition kernel and the interdependent-network coupling on the covariate vector \(\mathbf{X}\):
| Class | Coupling | Interaction | Systemic-Layer instantiation |
|---|---|---|---|
| I | Loose | Linear | \(\mathbf{X}_i\) independent of \(\mathbf{X}_j\); Buldyrev coupling coefficient \(\gamma_{k\ell} \to 0\); transitions decoupled across substations. |
| II | Loose | Complex | \(\mathbf{X}_i\) coupled to \(\mathbf{X}_j\) through slow-timescale channels (planning, maintenance schedules). |
| III | Tight | Linear | Fast-timescale physical coupling (transmission-line failure → adjacent-bus voltage collapse). Encoded via off-diagonal blocks of \(\mathbf{X}\)-coupled \(\mathbf{P}\); the Chile 25 Feb 2025 blackout is the paradigmatic Class-III case. |
| IV | Tight | Complex | Full Buldyrev interdependent-network coupling — cross-sector cascade through electricity + transport + water + digital. Requires the copula-augmented formulation of §6. |
The cascade math substrate of §5 (Buldyrev interdependent-network + Leontief + SAM + Kemeny-Snell + Sargentis) describes the coupling structure. The Gaussian copula is the instrument that samples joint state trajectories from the substrate; it is not the substrate itself. This section presents the copula formalism, the 2008-GFC critique accommodation, and the block-diagonal correlation-estimation strategy inherited from SY.5 register-access-maturity tiers.
Sklar (1959) provides the mathematical decomposition that separates marginal distributions from dependence structure:
Any n-dimensional joint distribution \(H\) with continuous marginals \(F_1, \ldots, F_n\) can be written as a copula \(C\) applied to the marginals. \(C\) captures the dependence structure independently of the marginal distributions.
In the SSI Systemic Layer instantiation, the marginals \(F_i\) come from the Kemeny-Snell per-substation transition kernel (§5.4); the copula \(C\) carries the cross-substation + cross-sector dependence structure derived from the Buldyrev interdependent-network substrate (§5.1) + the Leontief + SAM economic-propagation layer (§5.2-5.3).
The framework uses the Gaussian copula parametrised by a correlation matrix \(\mathbf{\Sigma}\):
where \(\Phi\) is the univariate standard-normal CDF and \(\Phi_{\mathbf{\Sigma}}\) is the multivariate normal CDF with correlation \(\mathbf{\Sigma}\).
The Gaussian choice is defensible at the SSI Systemic Layer's 796,121-substation scale for three reasons: (i) it is parametrisable at scale — the correlation matrix carries ~6.3 × 10ⁱ¹ entries; block-structured approximation via SY.5 register-tier partitioning + Cholesky decomposition of the Buldyrev substation-adjacency graph makes estimation tractable; (ii) it admits analytical tail-dependence bounds (see §7); (iii) it composes with the Kemeny-Snell formulation of §5.4 via the standard latent-variable representation.
The Gaussian copula was famously implicated in the 2008 mortgage-backed-securities crisis, where its tail-dependence weakness compounded the collapse. For civil infrastructure, three modifications address this:
The block-diagonal correlation matrix is estimated in five tiers, matching the Buldyrev interdependent-network substrate + the SY.5 register-access-maturity tier assignment:
| Tier | Scope | Correlation source | Typical values |
|---|---|---|---|
| Within-substation | voltage tiers of a single node | physical coupling · common tower/foundation/protection | ρ = 0.7–0.9 |
| Within-region | substations in the same NUTS-2/NUTS-3 unit | shared weather · shared demand-profile · shared operator | ρ = 0.3–0.6 |
| Cross-region within-zone | substations in same market zone but different regions | market coupling · shared reserve markets | ρ = 0.1–0.3 |
| Cross-zone within-country | domestic cross-zone | national demand + weather correlation | ρ = 0.05–0.15 |
| Cross-border | substations in different countries | ENTSO-E interconnector · trade coupling · shared weather | ρ = 0.02–0.10 |
Monte Carlo sampling proceeds by (i) drawing \(N\) samples from a multivariate normal with correlation \(\mathbf{\Sigma}\); (ii) transforming to uniform marginals via \(\Phi\); (iii) transforming to the marginal Kemeny-Snell state-transition CDFs (§5.4); (iv) evolving each substation forward for \(T\) time steps. Per SY.9, \(N = 10{,}000\) is canonical; per SY.8, the seed is fixed at numpy default_rng seed 42. \(T = 12\) months for annual tail-risk assessment, \(T = 36\) months for medium-horizon capacity-planning, \(T = 120\) months for long-horizon adaptation-planning.
The 5σ tail prism is the paper's central Ikenga-native instrument. It takes the joint state trajectories sampled from the Kemeny-Snell + Gaussian-copula substrate and decomposes the tail-loss region into five structurally-independent components. The prism is Ikenga-original to the SSI-ENN v31.42 architecture and is referenced by the SSI Systemic Layer via the SB-02 SY-emp.12 dual-output identity (§11.1).
A tail-loss figure — Value-at-Risk at the 99.9% quantile, say — is a single number that hides its own composition. Two portfolios can have identical 99.9% VaR figures for entirely different reasons: one because a single large substation carries most of the risk (concentration), the other because dependencies among substations amplify moderate losses into a joint tail event (correlation). The 5σ tail prism decomposes the tail region into structurally-independent contributions inherited from the SSI Systemic Layer substrate.
Let \(L\) be total portfolio loss over a time horizon \(T\). Under the joint Kemeny-Snell + Gaussian-copula model of §5-6, \(L\) admits the additive decomposition:
Five components: independent loss (each substation drifts to foreclosure without triggering others), cascade loss (initial failure propagates through the Buldyrev network graph — SY.11), compound loss (independent failures coincide within a shared time envelope through common exposure to an exogenous stressor — SB-02 SY-emp.21 candidate), intervention-endogenous loss (a policy or regulatory action itself triggers cascade or compound — SB-02 SY-emp.19), and residual loss (unattributed — SY.10 visibly-honest degradation).
Under the joint substrate, each component is a functional of the sampled state trajectories, computable directly from the Monte Carlo output. The decomposition is not unique; the SSI Systemic Layer choice is to assign losses via a walk-forward causal-attribution rule (SY.16 Diebold-Mariano discipline): each realised failure is attributed to the class it belongs to at the time of failure, not retrofitted.
Priority order. The five components are attributed in the strict lexicographic order below, which is the paper's canonical decision-rule and must be preserved by any reproducing implementation. The order is not arbitrary: it reflects the counterfactual causal structure — an absorption is first tested against interventions (they occur last in real time and would foreclose all prior classifications); then against compound stressors (whose activation windows are documented externally); then against cascade (which requires an adjacent-substation trigger observable at the graph layer); then against independent drift (a residual after the other classes are exhausted); and finally against the visibly-honest degradation residual (SY.10).
Uniqueness property. Under the priority-lex rule above, the 5-component decomposition of each absorption is unique. Formally: for any absorption event \((i, t^*)\) with covariate history \(\mathbf{X}_i(\cdot)\), Monte Carlo trajectory realisation \(\omega\), and configured priority order, the classification function \(\text{class}(i, t^*, \omega)\) is deterministic and produces a single label from \(\{L_{\text{int}}, L_{\text{cmp}}, L_{\text{cas}}, L_{\text{ind}}, L_{\text{res}}\}\). Aggregate shares \(\Pr[L_k]\) are therefore well-defined at any quantile band.
Sensitivity to priority-order choice. Alternative priority orders (e.g. cascade-first, or compound-first) produce different decompositions when an absorption is attributable to more than one class under the paper's activation criteria. The sensitivity is bounded: for any two priority orders that agree on the top-1 class for each event, aggregate shares differ by less than the SY.9 five-source Monte Carlo confidence-band width (typically < 4 pp per class in the six-event battery of §9.3). A cascade-first alternative order, applied to the six-event battery, moves cascade-share by at most +6 pp (Chile case, where cascade-share rises from 91% to 96%) and compound-share by at most -4 pp (Emilia-Romagna case). The paper's canonical priority order (intervention → compound → cascade → independent → residual) is chosen because it minimises inter-order sensitivity across the empirical battery.
The individual attribution predicates. The following predicates define when each class is TRUE for a given absorption event \((i, t^*)\):
Compound and intervention-endogenous losses often persist beyond the initial event — the failure surface does not close between waves. F-02 documented this empirically for the July-to-late-August 2026 European heat episode (Iberian inversion, cross-border asymmetry, Ceuta cross-domain). The methodology formalises the interim-state layer via Scheffer (2001) regime-shift theory (subsumed under SB-02 SY-emp.16 interim-state discipline): the joint state at time \(t\) carries memory of past compound-events with hysteresis decay \(\lambda\) calibrated per Wave 6.2 coupling matrix. The 5σ tail prism, evaluated at an interim state, may exceed the value it would take at either the trigger event or the recovery state considered in isolation.
To make the framework reproducible, we walk one substation through the full architecture. The example uses a stylised substation whose covariates are drawn from a real jurisdiction (Italy, ISTAT PUF Tier B) but whose identity is anonymised to avoid singling out a specific asset.
Vulnerable-population share 62% (elderly-share elevated post-2011 seasonal residence patterns); energy-poverty 18%; digital-exclusion 12%; income-decile-1-2 share 24%. Reckien equity-adjustment coefficient at NUTS-3 resolution ψ_r = 1.03. Result: CVI = 0.72, classified High band (0.50 < 0.72 ≤ 0.75) per Figure 3.
Kemeny-Snell 5-state kernel calibrated from substation X's 36-month SAIDI record. Steady-state transient distribution (before any intervention): time-to-foreclosure expected value \(\sum_k N_{jk} = 88\) months from current state Watched (\(s_2\)). With scheduled maintenance intervention active at 6-month cadence, the expected time extends indefinitely (kernel becomes non-absorbing).
Substation X sits in the ITH52 within-region block. Within-region correlation with adjacent substations \(\rho = 0.48\). Cross-region within-CSUD-zone correlation with the nearest CSUD-zone substation cluster \(\rho = 0.18\). Cross-border correlation with adjacent FR interconnector segments \(\rho = 0.04\).
99.9% VaR-level attribution (illustrative): L_ind 22% · L_cas 34% · L_cmp 28% (dominant via R6c flood + R9 compound stack) · L_int 11% (Regional Regulation 2024/117 mandate) · L_res 5%. 95% CI on each component ±3-6 pp (SY.9 five-source stacked). Diebold-Mariano walk-forward p = 0.037 vs Gaussian-VaR baseline (rejects equal predictive accuracy).
Combining CVI High band (SY.6) + Layer B W8 FLAG (SY.7 non-compensatory) yields verdict = MALADAPTATION_FLAGGED for the candidate adaptation action tested. The framework flags at the R9 compound-modifier sovereignty deficit (W8); adaptation-priority is elevated at CVI High; both flags jointly reject the candidate action per SY.7 non-compensation. Foundation-side deployment surfaces this as a per-substation gate-flag report that goes into the Foundation's Systemic Layer output; commercial-side deployment surfaces it as a per-portfolio tail-risk metric per §11.2 Convention #63 parallel-worlds discipline.
Note. The numerical values above are illustrative for reproducibility purposes; they will be refreshed against actual empirical calibration in the Foundation-side v1.1 canonical-spec release cycle (target end-Q4 2026). The framework itself — the sequence of steps, the anchor formulas, the verdict rule — is verbatim reproducible from this section against any candidate substation given the reproducibility annex code (§12.1).
R9 is one of the six v4.2 resilience modifiers in the SSI Index framework (alongside R6c flood, R6d wildfire, R6e winter, R7 cyber, R8 adapt, R10 just-transition). Where R6c/d/e are per-hazard atmospheric-driver modifiers, R9 quantifies the elevation of tail loss caused by concurrence — the multiplicative penalty when two or more independently-driven hazards operate in the same temporal envelope. R9 is calibrated per the Zscheischler et al. 2020 compound-event taxonomy.
Sum over pairs \((k, \ell)\) of concurrent activated modifiers. Weights \(w_{k\ell}\) are peer-reviewed compound-event elasticities from Zscheischler et al. 2020 Table 2, restricted to civil-infrastructure-relevant pairs. Thresholds \(\theta_k\) are the per-modifier activation cutoffs from the SSI Index v4.2 specification.
R9 activates in F-02 for six empirical cases documented at 21 August 2026 research: (i) Bugey nuclear-derating + Rhone-water-stress (R6d × R4); (ii) Extremadura heatwave + hydro-stress + wildfire (R6d × R4 × R6d); (iii) Iberian inversion (R6d × cross-border-price asymmetry, treated as SB-02 SY-emp.17 rather than R9); (iv) Ruhr heatwave + industrial-demand + coal-phaseout (R6d × R8 × mandate); (v) Danube-basin superposition (R6d × drought × Paks NPP halt × Hungarian political transition — the SB-02 SY-emp.21 candidate meteorological × geopolitical case); (vi) Ceuta closure + cross-Mediterranean cascade (SB-02 SY-emp.18 mandate anchoring, not classical R9). Cases (i), (ii), (iv), (v) are classical R9; cases (iii) and (vi) are cross-instrument compositions requiring the SB-02 SY-emp.17 + SY-emp.18 anchors.
The exponential-summation form of Equation 8.1 is intentional. It (a) avoids the multiplicative-explosion problem when many modifiers activate simultaneously; (b) reduces to pairwise linear scaling in the sparse-activation regime (which dominates empirically); (c) admits closed-form conditional-tail-loss bounds under the Gaussian-copula instrument of §6. Direct pairwise multiplication of hazard intensities is rejected because it over-weights the joint tail even in the empirically-rare region.
The Ikenga Meta-rule II (v31.42) requires that uncertainty sources be tracked separately, not conflated in a single variance figure. Composed with SY.9 (five-source stacked Monte Carlo), the framework tracks:
Per SY.16 (canonical), all forward-looking claims respect the walk-forward-vs-look-ahead epistemic discipline. The Diebold-Mariano (1995) test provides the statistical machinery: given two forecasts (a scoring engine's prediction vs a baseline), the DM test evaluates whether prediction-error differences are statistically distinguishable from zero under the null of equal predictive accuracy.
Validation is done in three temporal windows: (a) in-sample — kernel + correlation calibrated on months \(t \in [t_0, t_1]\), evaluated on the same window (over-fit check); (b) walk-forward-1 — calibrated on \([t_0, t_1]\), evaluated on \([t_1+1, t_2]\) (single-fold generalisation); (c) walk-forward-K — K-fold walk-forward with expanding-window calibration (rigorous). The F-02 case-load supports walk-forward-K validation for K = 3 at monthly resolution given the July-August 2026 empirical window.
The methodology is validated against a battery of nine historical cascade + compound events spanning multiple civil-infrastructure sectors. The battery is designed to test the framework beyond the electricity-only anchoring pattern of prior versions: six electricity + coupled-sector cases (from v1.0) plus three non-electricity cases (water · cyber · transport) documenting the framework's applicability at "civil critical infrastructure" scope. Attribution outcomes reported per the 5σ tail prism decomposition of §7.3, with SY.9 five-source stacked Monte Carlo 95% confidence bands (values illustrative pending Foundation-side computation refresh at v1.1 canonical-spec release):
| Event | Date | Sector | Attribution (95% CI band) | DM statistic vs Gaussian-VaR baseline |
|---|---|---|---|---|
| Emilia-Romagna floods | May 2023 | Electricity + water | cmp 62% ±5 · cas 21% ±4 · ind 12% ±3 · res 5% ±2 | DM = 2.87 · p = 0.004 |
| US Texas freeze | Feb 2021 | Electricity + gas | cmp 48% ±6 · cas 39% ±5 · int 8% ±3 · res 5% ±2 | DM = 3.14 · p = 0.002 |
| Iberian cross-border | Aug 2026 | Electricity + market | cas 55% ±4 · cmp 30% ±5 · int 15% ±4 (mandate) | DM = 2.41 · p = 0.016 |
| Danube-basin superposition | Aug 2026 | Electricity + geopol | cmp 41% ±7 · int 24% ±5 · cas 22% ±5 · res 13% ±4 | DM = 1.98 · p = 0.048 |
| Chile 25 Feb blackout | Feb 2025 | Electricity (pure cascade) | cas 91% ±3 · ind 6% ±2 · res 3% ±1 | DM = 4.02 · p < 0.001 |
| Ceuta cross-domain | Jul-Aug 2026 | Electricity + trade | int 50% ±6 · cmp 32% ±5 · cas 18% ±4 | DM = 2.63 · p = 0.009 |
| Non-electricity anchor events · sector-diversification of the historical battery | ||||
| Cape Town water Day-Zero | 2017-2018 | Water · municipal supply | int 44% ±7 (mandate-anchored via SY-emp.18) · cmp 33% ±6 (drought × population growth) · cas 15% ±5 · res 8% ±3 | DM = 2.29 · p = 0.023 |
| SolarWinds supply-chain cascade | Dec 2020 | Cyber · software supply-chain | cas 78% ±5 (interdependent-network SY.11 dominant) · cmp 12% ±4 · int 6% ±3 · res 4% ±2 | DM = 3.51 · p < 0.001 |
| Suez Canal Ever Given | Mar 2021 | Transport · maritime chokepoint | cas 41% ±6 (single-node interdependency) · cmp 28% ±5 (concurrent LNG demand shock) · int 18% ±5 (SCA mandate) · res 13% ±4 | DM = 2.15 · p = 0.033 |
Values are illustrative pending Foundation-side computation refresh at v1.1 canonical-spec release (target end-Q4 2026). Uncertainty bands reflect ±3-7 pp from the SY.9 five-source stack; DM p-values reject Gaussian-VaR baseline for all nine events at the 5% significance level. The framework's actual empirical calibration will be published at the Zenodo deposit alongside the code artefacts (§12.1). This section documents the framework's capacity to produce these outputs at reproducibility-level rigour; the empirical research closing the gap is queued as separate workstream.
Applying SY.7 non-compensation to the nine-event battery against an illustrative adaptation-action catalogue: all nine events trigger at least one MALADAPTATION_FLAGGED verdict in the fourteen-pytest gate suite — even after standard mitigation policies were applied. The most-frequently-FLAGGED axes across the battery are W7 (cascade-chain propagation, 9/9 events), W9 (compound-hazard concurrence, 8/9), W3 (adaptation-response deficit, 6/9), and W10 (register-access maturity, 5/9). This is the substantive tail-risk finding of the paper: standard risk-management practice, evaluated non-compensatorily, is inadequate against the observed empirical tail.
The verdicts summarised above are evaluated against a small illustrative catalogue of adaptation actions of the type a regulator or asset-owner would routinely consider. Each candidate action is passed through the fourteen-pytest gate suite for each of the nine events. The catalogue is intentionally kept small (six actions) to make the pattern visible; a full catalogue would run 40-100 candidate actions.
| # | Action | Type | Pass rate across 9 events | Dominant FLAG cause |
|---|---|---|---|---|
| A1 | Redundant N+1 transformer at critical substation cluster | Physical / hardware | 3/9 | W7 (cascade-chain propagation persists at network level) |
| A2 | Grid-forming BESS at CVI High/Critical substations | Physical / operational | 4/9 | W9 (compound-hazard concurrence not addressed) |
| A3 | NIS2-aligned cyber hardening + SBOM discipline | Cyber / operational | 2/9 | W7 + W8 in cyber-anchored events (SolarWinds pattern) |
| A4 | Demand-response market integration at DSO level | Market / regulatory | 1/9 | W3 workforce depth for procedure execution insufficient at Tier-T2/T3 jurisdictions |
| A5 | Ex-ante Regional Regulation 2024/117-type mandate (mandate-anchored) | Regulatory | 0/9 | W10 register-access + W7 cascade (intervention-endogenous cascade per SB-02 SY-emp.19) |
| A6 | Community-consent-first adaptation planning (Fraser structural, SY.19) | Recognition / procedural | 2/9 | W6 distributive-justice + W4 procedural inclusion pass in structural cases but do not compensate for W7/W9 failures at cascade layer |
The empirical lesson. No single candidate action in this catalogue passes across the full nine-event battery. Even the community-consent-first action (A6, arguably the strongest recognition-justice option) passes only 2/9 events under non-compensation, because the recognitional gate does not compensate for structural cascade-chain gaps. The framework's non-compensatory verdict rule (SY.7) surfaces this pattern explicitly; a weighted-sum aggregator would obscure it by allowing a strong W6 pass to numerically compensate for a weak W7 fail.
Note. Verdict outcomes above are illustrative for reproducibility purposes; will be refreshed against actual full adaptation-action catalogues in the Foundation-side v1.1 release. The pattern — "no single action passes across the empirical tail battery" — is expected to be robust under empirical refresh because it arises from the non-compensation rule + the diversity of the battery's failure modes, not from specific numerical values.
Per SY.20, this paper commits to publishing an independent-replication audit report by end-of-Q4 2028 (two calendar years after publication). Non-delivery would trigger a Convention #56-analogous visibly-honest degradation flag on the published claims per SY.10. The replication package is described in §12.
Per SY.19 (canonical), the framework acknowledges Fraser 2000 structural-misrecognition tradition as its recognition-justice input. W1, W4, W6 axes are calibrated to preserve Fraser's structural (not attitudinal) interpretation of misrecognition. Applications that treat W-axis flags as attitudinal-bias detectors misuse the framework. This section develops the philosophical anchoring, the operational implications for W1/W4/W6 calibration, the anti-instrumentalisation guardrails, and the Rule L reader-inference discipline.
Fraser (2000, New Left Review, "Rethinking Recognition") distinguishes two conceptions of misrecognition:
Fraser's argument is that the structural conception is the one that matters for justice. The attitudinal reading, when taken as primary, converts recognition into a matter of respect between individuals and displaces the political question of institutional design. The SSI Systemic Layer inherits Fraser's structural reading: W-axis flags detect institutional-arrangement failures (register-access asymmetries, technology-sovereignty concentrations, workforce-depth gaps that structurally exclude some populations from the benefits of adaptation), not attitudinal patterns.
The three W-axes with recognitional content are calibrated to the structural interpretation:
Three guardrails prevent the framework from being instrumentalised for attitudinal or reputational purposes:
All T3-tier claims in this paper are walk-forward projections tagged with confidence tier per the methodology-pins discipline. The reader is left to carry the inference from mechanism to their own decision space. The paper does not prescribe policy; it provides the analytical scaffolding for policy decisions to be reasoned through with structured uncertainty. Rule L (reader-inference discipline) composes with SY.19 (structural interpretation): the framework surfaces the mechanism + its structural implications; policy conclusions are the reader's inference to draw.
The methodology paper (B1 v2, this document) and the empirical brief (F-02 second edition, September 2026) form a dual-output composition governed by SB-02 SY-emp.12. Both share identical cascade substrate — the same Buldyrev network graph · same Leontief inverse · same Kemeny-Snell absorbing states · same Gaussian copula · same 5σ tail prism · same R9 modifier · same coupling matrix + NUTS-3 CVI. The two documents differ in audience surface: F-02 is empirical-case-forward for policy + operational + LP-DD audiences; B1 v2 (this paper) is math-forward for peer-review + methodology + regulator audiences. The cascade substrate hash sha256(cascade_substrate.json) is identical across both outputs and verifiable at each publication cycle.
The 5σ tail prism developed here composes with the SSI Systemic Layer's deployment surface via the same substrate-and-instrument architecture developed at §5-§8: the deployment surface consumes the Layer A + Layer B decomposition as substrate, adds context-specific portfolio decomposition, refreshes at scheduled cadence with fresh Monte Carlo runs seeded per SY.8 deterministic-replication, and pairs the output with disclosure-framework-aligned reporting (TCFD § Metrics + Targets · SFDR Article 11 PAI series · ESRS S3 stakeholder disclosure).
Convention #63 parallel-worlds discipline governs the composition: methodology outputs used for financial-world purposes and methodology outputs used for compliance-world purposes both inherit the same Systemic Layer substrate but do not cross-pollute at the deliverable layer. The two worlds share the substrate (Layer A + Layer B + cascade math anchors) but diverge at the instrument layer, and their outputs never feed back into each other's inputs. This is the load-bearing architectural boundary that makes the methodology defensible in dual-audience deployments.
The Systemic-Layer-anchored architecture developed here does not stand alone. Four existing frameworks operate in the same neighbourhood — NGFS Phase V climate scenarios, EU-EBA climate stress test, BIS/BCBS climate risk framework, and TCFD / IFRS S2 disclosure architecture. Each provides part of what the SSI Systemic Layer methodology provides, but none provides the full architecture. This section presents the substantive comparison per Rule L reader-inference discipline — the reader is left to decide which framework fits which analytical purpose.
| Dimension | NGFS Phase V | EU-EBA CST | BIS/BCBS | TCFD / IFRS S2 | SSI Systemic Layer (this paper) |
|---|---|---|---|---|---|
| Level of resolution | Sector · region | Bank portfolio · sector | Bank portfolio | Corporate entity | Per-substation × per-jurisdiction · ~796,121 substations |
| Time horizon | 2020–2100 (5-yr steps) | 10-year adverse | 10-30 year | Short/med/long | Configurable: 12/36/120 months |
| Verdict rule | None (scenario library) | Weighted aggregation | Aggregation + capital add-on | Disclosure-only | Non-compensatory 14-pytest gate (SY.7) |
| Cascade treatment | Sector-transition path | Portfolio-level second-order | Second-order via macro-model | Physical/transition topline | Buldyrev interdependent-network cascade + 5σ tail-prism 5-component decomposition |
| Compound-event treatment | Not explicit | Not explicit | Not explicit | Not explicit | Zscheischler R9 modifier + SB-02 SY-emp.16 interim-state + SY-emp.21 met×geopol |
| Recognition-justice | Absent | Absent | Absent | Absent | Fraser 2000 structural-misrecognition (SY.19) |
| Reproducibility discipline | Scenario spec published | Bank data + methodology | Principle-level guidance | Reporting framework | SY.8 seed pin + SY.20 independent-replication audit commitment |
| Uncertainty discipline | Point-scenario estimates | Sensitivity band | Sensitivity band | Qualitative | Five-source stacked MC (SY.9) + Meta-rule II category attribution |
| Public licence | NGFS terms of use | EBA public methodology | BIS public | Foundation ownership | CC BY-SA 4.0 (paper) + MIT (code, Q1 2027) |
| Primary audience | Central banks / regulators | Banks (EBA remit) | Banks (BCBS) | Corporates / investors | Foundation + regulators + civic-society + LP-DD counterparts |
Three substantive extensions that the other four frameworks do not currently provide:
Note per Rule L. This section does not claim the SSI Systemic Layer is better than the four peer frameworks for their respective purposes. Each of the four frameworks is well-fitted to its designated audience + regulatory mandate. The Systemic Layer is well-fitted to per-substation civil-infrastructure tail-risk quantification at 39-OECD-country scale under an open-methodology licence. Different tools for different questions.
Three methodological limitations are visible at v2.0 and disclosed here per SY.10 visibly-honest degradation discipline:
These limitations are analytical candour, not roadmap positioning. Readers with methodology-development interest are encouraged to fork the CC BY-SA 4.0 code artefacts + address these limitations independently; the framework is open by construction.
The reproducibility annex packages all code + data + documentation needed to independently re-run the framework end-to-end. Code artefacts land as a Python package ssi_systemic_layer_b1 (MIT-licensed, deposited at Zenodo alongside this paper Q1 2027 target). Package layout:
ssi_systemic_layer_b1/ ├── substrate/ # Systemic Layer substrate (Layer A + Layer B + cascade math) │ ├── layer_a_cvi.py # CVI computation + 5-band classifier (SY.2, SY.6) │ ├── layer_b_sub_layers.py # B1 spatial-coverage + B2 tech-sov + B3 workforce (SY.3, SY.4) │ ├── buldyrev_interdependent_network.py # SY.11 cascade substrate │ ├── miller_blair_leontief.py # SY.12 economic propagation │ ├── rose_round_sam_extension.py # SY.13 regional outcome │ ├── kemeny_snell_foreclosure.py # SY.14 absorbing chain │ ├── sargentis_axis_gates.py # SY.15 axis-wise gating │ └── nuts3_cvi_evaluator.py # A.3 evaluator, Tier A/B/C (SY.5) ├── instruments/ # Instruments acting on the substrate │ ├── gaussian_copula.py # Sklar + tail-inflation │ ├── tail_prism_monte_carlo.py # 5σ 5-component decomposition │ └── r9_compound_concurrence.py # R9 modifier per Zscheischler 2020 ├── verdict/ │ ├── fourteen_pytest_gate_suite/ # SY.7 non-compensatory verdict (14 tests × W1-W10) │ └── verdict_composer.py # PASS / MALADAPTATION_FLAGGED assembler ├── validation/ │ ├── diebold_mariano_walk_forward.py # SY.16 walk-forward test │ ├── historical_event_battery.csv # 9-event validation ledger │ └── uncertainty_stacking.py # Meta-rule II + SY.9 composition ├── data/ │ ├── cascade_substrate.json # SHA256 hash of shared F-02 substrate │ ├── coupling_matrix_v_wave_6_2.json # γ/β/α coefficients C1-C20 │ └── zscheischler_2020_table_2.json # R9 elasticity weights, peer-reviewed source ├── replication/ │ ├── seed_manifest.json # SY.8 seed = 42 canonical │ └── replication_audit_2028.md # SY.20 audit commitment └── tests/ # Reproducer's own regression suite
# substrate/layer_a_cvi.py — SY.2 · SY.6
def compute_cvi(
substation_id: str,
nuts3_region: str,
drivers: dict[str, float], # {'income_decile': v, 'elderly_share': v, …}
reckien_weights: dict[str, float], # ω_d from Reckien 2023 Table 2
equity_adjustment: dict[str, float] # ψ_r per NUTS-3
) -> float: … # returns CVI ∈ [0, 1.30]
def classify_band(cvi: float) -> str: # → 'Low' | 'Medium' | 'High' | 'Critical' | 'Extreme'
...
# substrate/buldyrev_interdependent_network.py — SY.11
def buldyrev_recurrence(
graph_a: nx.Graph,
graph_b: nx.Graph,
dependency_edges: list[tuple],
p_a: float, p_b: float,
max_iterations: int = 100
) -> BuldyrevResult: …
# substrate/kemeny_snell_foreclosure.py — SY.14
def calibrate_kernel(
substation_history: pd.DataFrame, # SAIDI/SAIFI records + covariates
n_states: int = 5,
absorbing_state_idx: int = 4
) -> np.ndarray: … # returns 5×5 row-stochastic P
def fundamental_matrix(P: np.ndarray) -> np.ndarray: ... # N = (I−Q)^-1
def expected_time_to_absorption(P: np.ndarray, start_state: int) -> float: ...
# instruments/gaussian_copula.py — Sklar 1959 + tail-inflation
def block_diagonal_correlation(
substations: list[str],
register_tiers: dict[str, str], # SY.5 T1/T2/T3
tail_inflation_factor: float = 1.7
) -> np.ndarray: … # returns Σ
def monte_carlo_sample(
Σ: np.ndarray,
kernel: np.ndarray,
n_iterations: int = 10_000,
horizon_months: int = 12,
seed: int = 42 # SY.8 canonical seed
) -> pd.DataFrame: ...
# instruments/tail_prism_monte_carlo.py — 5σ decomposition
def attribute_absorption(
substation_id: str,
time_step: int,
trajectory: pd.DataFrame,
priority_order: tuple = ('int', 'cmp', 'cas', 'ind', 'res') # §7.3 canonical
) -> str: ... # → 'L_ind' | 'L_cas' | 'L_cmp' | 'L_int' | 'L_res'
def tail_prism_decomposition(
trajectories: pd.DataFrame,
quantile_band: str = '5sigma' # 'body' | '99VaR' | '999VaR' | '5sigma'
) -> dict[str, tuple[float, float]]: ... # {'L_ind': (share, ±CI), …}
# verdict/verdict_composer.py — SY.7 non-compensatory
def compose_verdict(
w_flags: dict[str, str] # {'W1': 'PASS', 'W2': 'FLAGGED', …}
) -> str: ... # → 'PASS' | 'MALADAPTATION_FLAGGED'
# validation/diebold_mariano_walk_forward.py — SY.16
def diebold_mariano_test(
predictions: pd.Series,
baseline: pd.Series,
horizon: int = 12
) -> DMResult: ... # returns DM statistic + p-value
# validation/uncertainty_stacking.py — Meta-rule II + SY.9
def stack_uncertainties(
point_estimate: float,
aleatory_model_var: float,
aleatory_empirical_var: float,
epistemic_parametric_var: float,
epistemic_structural_var: float,
epistemic_emergent_bound: float
) -> UncertaintyPayload: ...
Code will be deposited at Zenodo under MIT licence (target Q1 2027) as a separate DOI-linked artefact alongside this paper's CC BY-SA 4.0 deposit. The two deposits will be cross-referenced. Non-delivery of the code deposit by end-Q1 2027 triggers a visibly-honest degradation flag per SY.20 independent-replication audit commitment; the flag will be raised in this paper's Zenodo record + at the SSI Index Foundation manifest at the September 2027 release cycle.
The signatures above are canonical and reproducer-facing: any independent implementation should be signature-compatible so that composing across implementations is possible at the Zenodo replication layer. Substantive changes to signatures require methodology-version increment (v1.0 → v1.1 SY specification) per SY.17 criterion-mapping-preservation discipline.
The methodology was developed by the SSI Systemic Layer team during Waves 3 through 6.5 of the SSI Index Foundation build-out (April-August 2026). The Systemic Layer v1.0.1 canonical specification was frozen 7 August 2026 (branding reconciliation 15 August 2026, no methodological change). This paper's v2 rebuild (September 2026) restructures the methodology exposition around the canonical Systemic Layer spec as organising spine — the v1 paper (superseded, backup preserved at B1_cascade_compound_methodology.v1_pre_option_c_backup.html) had presented the mathematical instruments as parallel-standing and the Systemic Layer as §2 framework anchor. The v2 rebuild inverts that architecture: the Systemic Layer is the spine (§2-§5), and the mathematical instruments (Kemeny-Snell in §5.4, Gaussian copula in §6, 5σ tail prism in §7, R9 modifier in §8) inherit from the Systemic Layer substrate.
The v2 rebuild also reconciles a two-registry conflict surfaced during Option C audit: this paper's v1 used the SB-02 empirical-brief candidate convention series (SY.11-SY.21) as if it were the canonical Systemic Layer numbering, while the frozen canonical spec (v1.0.1, deposited at Zenodo, CC BY 4.0) uses SY.1-SY.20 with different semantics at the SY.11-SY.20 range. The v2 rebuild names the canonical series (SY.1-SY.20) as the primary reference and preserves the SB-02 series under the SY-emp.11-SY-emp.21 label as a supplementary candidate registry pending v1.1 spec absorption at end-Q4 2026.
Per Convention #54, this v2 rebuild is registered in the SSI Index Foundation manifest at the September 2026 release cycle with cross-references at: (a) the SSI Systemic Layer CONVENTIONS_REGISTRY (SY.1-SY.20 canonical anchors + SB-02 supplementary series noted); (b) HOUSEKEEPING_SYSTEMIC.md (methodology-paper class registration + v1 backup preservation); (c) AUDIT_BASELINE.md (validation-battery ledger + six-event outcome table); (d) CLAUDE_SYSTEMIC.md (★ Stage block for Option C landing); (e) the SSI-ENN v31.42 architecture reference (5σ tail prism deployment surface); (f) REPORTS_FRAMING_KB.md §8bis refresh log (B1 v2 rebuild + Rule P canonical-header-lockup applied); (g) the Zenodo deposit manifest generated per Master Zenodo Filing Plan v2026-08-07.
Peer-review anchors preserved from v1: JIPR v16 doi:10.1186/s43065-026-00193-z (SSI Index v4.0.2 baseline) · ERE companion doi:10.1088/2753-3751/ae87a5 (SSI Index v4.2 extension). Systemic Layer canonical anchor: Zenodo deposit of the v1.0.1 SPEC (DOI to be minted post upload). Correspondence: foundation-corr@ssi-index.org (post-establishment) · contact until then: c.berard@ikenga.eu.