Validating against a moving target: versioning regulatory knowhow
Notes from the BrainTrainAI pilot on keeping a rule base current when the rules themselves keep changing – and why a validator is only as trustworthy as the version it validates against.

Every regulated organisation has a version problem it does not call a version problem. The rules change, the documents describing the rules change, and the systems that are supposed to comply change – rarely at the same time.
In European rail, TEL TSI and OSDM are living specifications. A conformity check that was valid against last year's release may fail this year's, not because the implementation broke but because the target moved. If the validator does not know which version it is validating against, a green result means very little.
Where the knowledge actually lives
In the organisations we work with, regulatory knowledge is spread across at least four places: the published specification, the internal interpretation of it, the configuration of the systems that implement it, and the heads of the two or three people who have been doing this long enough to know where the exceptions are.
- The specification is authoritative but not operational – it does not say how your messages should look.
- The internal interpretation is operational but undocumented, or documented once and never updated.
- The system configuration is precise but opaque; nobody reads XSDs for pleasure.
- The experts are the real source of truth, and they retire.
Structure first, then validate
The first thing BrainTrainAI does is unglamorous: it turns those sources into a structured, versioned knowledge base. Each rule carries the version of the specification it comes from, the date it applies, and – where relevant – the internal interpretation attached to it.
A validator is only as trustworthy as the version it validates against.
Only once that structure exists does automated validation become meaningful. The validator checks documents, messages and data structures against a specific version of the rule base, and records which version it used. That record is what an auditor wants to see.

Governing the change
Versioning without governance is just a longer list of mistakes. The third layer adds roles, approvals and a complete audit trail: who proposed a change to a rule, who approved it, when it took effect and what it superseded.
What this looks like in practice
- A specification release is ingested and diffed against the current rule base.
- Changed rules are flagged for review by the domain owner.
- Approved changes are published as a new rule-base version with an effective date.
- Validations run against the version in force on the date of the artefact, not the newest version.
Beyond rail
None of this is specific to railways. Energy, finance and any sector under a moving regulatory framework face the same problem in a different vocabulary. Rail is where we started because it is where the group's domain knowledge is deepest, and because the standards are public, which makes the work easier to show.
The pilot continues through 2026 with European rail organisations. If you are working on the same problem, we would like to compare notes.
Frequently asked questions
Does BrainTrainAI replace a conformity assessment?
No. It prepares you for one. Automated validation against a versioned rule base finds problems earlier and documents what was checked; the formal assessment is still issued by a third party.
Which versions of TEL TSI and OSDM are covered in the pilot?
The pilot ingests the current published releases and the previous major release, so historical artefacts can be validated against the rules in force at the time.
Can the rule base include our internal interpretations?
Yes. Internal interpretations are stored as rules attached to the specification clause they refine, carry their own version and approval history, and are validated alongside the public rules.

IT executive and consultant with more than 30 years in software engineering and digital transformation, over two decades of them in European rail. Former CTO of RailNetEurope; PhD in Computer Science from Graz University of Technology.