# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-29T15:01:49Z", "synthesisSha256": "505d10434a4ae12b204853662afd20cb8f5d89d180a85f2813881669881d48bc", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-ACT-033", "registryId": "vr.wm-act-033", "name": "Review / Inspection / Audit", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.REV" ], "tags": [ "review", "inspection", "audit", "act.rev" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-033-review-inspection-audit/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-033", "model": { "registry_id": "vr.wm-act-033", "model_id": "WM-ACT-033", "name": "Review / Inspection / Audit", "entry_kind": "aggregate", "purpose": "Provide the format-neutral context an agent needs to commission, plan, execute, evidence, conclude, report and govern a bounded review, inspection, audit or assessment engagement: who is mandated to examine what, against which criteria, by which methods, on what evidence, yielding which findings, conclusion, assurance level, redress path and record governance.", "scope_statement": "The model is rooted on one engagement occurrence (audit, inspection, review, assessment or attestation engagement) treated as an aggregate: engagement identity governs its plan, execution log, observations, evidence appraisals, findings, conclusion, issued report or certificate, recommendations, appeals and record provenance, which share the engagement lifecycle. It is storage- and interface-neutral; JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are projections, not semantics. It carries references to the examined subject, the criteria sources, the responsible party and any remediation actions, but never reproduces those models' lifecycles. 'Audit' here means an assurance or examination activity, not IT audit-trail logging, which is a homonym.", "in_scope": [ "Engagement identity, registration and typing (audit, inspection, review, assessment, attestation, direct-reporting, surveillance, follow-up)", "Mandate, statutory or contractual authority, terms of engagement, and appointment of the three parties", "Impartiality, independence and conflict-of-interest declarations scoped to this engagement", "Subject matter, subject-matter information, scope boundary, period covered and declared exclusions", "Selection and binding of criteria to authoritative external requirement sources", "Materiality, tolerance, acceptance limits and documented decision rules including measurement-uncertainty handling", "Engagement plan, objectives, schedule, methods, sampling strategy, depth and coverage", "Fieldwork execution log, site and access conditions, and deviations from plan", "Observations, evidence items, custody and integrity, and appraisal of relevance, reliability and sufficiency", "Findings with criteria/condition/cause/effect structure, conformity determination and severity grading", "Finding identity, recurrence and baseline comparison across engagements", "Engagement conclusion, opinion, assurance level and report or certificate issuance with use restrictions", "Responsible-party views, right to be heard, appeals and complaints about this engagement", "Recommendation issuance and follow-up verification of claimed remediation", "Engagement record provenance, versioning, amendment, retention classification and quality review" ], "out_of_scope": [ "The examined subject itself (product, asset, system, process, person, programme) and its own lifecycle", "Requirement, regulation and control-catalogue texts; only references, selections and engagement-local interpretations are held here", "Corrective and preventive action execution, remediation project management and action closure", "Enterprise risk register ownership, risk treatment decisions and residual-risk acceptance", "Enforcement measures, sanctions, withdrawal, recall, prosecution and administrative penalties", "Certification, approval and accreditation decision lifecycles, including suspension and withdrawal of certificates held by the subject or the body", "Laboratory test method definition, measurement execution and uncertainty computation", "Auditor qualification, training, certification and competence-registry lifecycle", "IT system audit trails, security event logs and continuous telemetry pipelines (homonym boundary)", "The multi-engagement audit programme or annual assurance plan and its own prioritisation lifecycle", "Runtime policy evaluation, access-control enforcement and the platform audit trail that records who read these records", "Physical execution of records disposal, destruction certificates and archival transfer", "Commercial terms, fee arrangements and invoicing" ], "boundary_notes": [ { "neighbor": "Requirement / control-catalogue model", "distinction": "This model records which criteria were selected, their version binding and any engagement-local interpretation; the catalogue model owns requirement text, hierarchy and its own version lifecycle. OSCAL keeps controls in the catalogue and profile layers and only references them from assessment results.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] }, { "neighbor": "Corrective action / remediation model", "distinction": "This model issues recommendations and records follow-up verification observations. Deciding, planning, executing and closing corrective action belongs elsewhere: Regulation (EU) 2019/1020 places corrective action on the economic operator and enforcement on the authority, while the market-surveillance authority verifies follow-up.", "source_refs": [ "SRC-006", "SRC-008" ] }, { "neighbor": "Risk register model", "distinction": "OSCAL lets an assessment result carry engagement-scoped risk characterizations, but risk-treatment decisions and residual-risk acceptance migrate to the POA&M or risk model. This model therefore carries risk statements produced by the engagement, not the risk register lifecycle.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Test and measurement result model", "distinction": "Measurement values, method validation and uncertainty evaluation are produced by testing or laboratory models. This model consumes them as evidence and applies a documented decision rule, in the JCGM 106 sense, to reach a conformity determination.", "source_refs": [ "SRC-011", "SRC-006" ] }, { "neighbor": "Certification / accreditation model", "distinction": "Inspection certificates and attestations issued as engagement outputs are in scope as artifacts, but the decision lifecycle of a certification or of a body's accreditation scope is owned by the certification and accreditation models, per the EU accreditation framework.", "source_refs": [ "SRC-013", "SRC-014" ] }, { "neighbor": "Enforcement / sanction / case model", "distinction": "Article 16 measures, Article 19 serious-risk withdrawal or recall, and any penalty are enforcement acts owned by an enforcement model. This model supplies the evidenced non-compliance determination that such measures may cite.", "source_refs": [ "SRC-006" ] }, { "neighbor": "IT audit-trail and security logging model", "distinction": "Homonym boundary. System audit logs are potential evidence sources referenced by observations; this model never owns log-record semantics, log retention or log integrity enforcement.", "source_refs": [ "SRC-009", "SRC-004" ] }, { "neighbor": "Party, role and competence model", "distinction": "This model records appointment to an engagement role and the engagement-scoped impartiality declaration; qualification, training and competence-registry lifecycle belong to the party model, as separated in the IIA and INTOSAI frameworks.", "source_refs": [ "SRC-007", "SRC-008" ] }, { "neighbor": "Audit programme / assurance plan model", "distinction": "Programme-level risk-based prioritisation, coverage across many engagements and resourcing span multiple engagements and have their own lifecycle. This model holds only a reference from the engagement to its programme.", "source_refs": [ "SRC-006", "SRC-008", "SRC-007" ] }, { "neighbor": "Provenance model (W3C PROV)", "distinction": "PROV-O is an alignment target for expressing engagement-as-Activity, evidence-as-Entity and auditor-as-Agent. This model does not redefine provenance semantics and does not own generic provenance reasoning.", "source_refs": [ "SRC-005" ] } ] }, "sources": [ { "id": "SRC-001", "title": "OSCAL Assessment Results Model v1.1.2 JSON Format Metaschema Reference", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://pages.nist.gov/OSCAL-Reference/models/v1.1.2/assessment-results/json-definitions/", "version_or_date": "OSCAL v1.1.2", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Normative field-level structure for assessment results: result, observation (methods, types, subjects, origins, relevant-evidence, collected/expires), finding (target, related-observations, related-risks), risk, reviewed-controls, attestation, assessment-log, back-matter." }, { "id": "SRC-002", "title": "Assessment Results Model (OSCAL concepts documentation)", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/assessment/assessment-results/", "version_or_date": "OSCAL documentation, accessed 2026-08-29", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Explains what was assessed, how, by whom, findings and risks; observations record evidence, findings link observations to control objectives, reviewed-controls sets scope, attestations record assessor assertions, and root uuid/last-modified must change on every content change." }, { "id": "SRC-003", "title": "Assessment Plan Model (OSCAL concepts documentation)", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/assessment/assessment-plan/", "version_or_date": "OSCAL documentation, accessed 2026-08-29", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Defines planning constructs: reviewed-controls with control and control-objective selections and assessment methods, assessment subjects (locations, components, inventory items, users), assessment assets (teams, tools), tasks and activities, and terms-and-conditions / rules of engagement." }, { "id": "SRC-004", "title": "Static Analysis Results Interchange Format (SARIF) Version 2.1.0 Plus Errata 01", "organization": "OASIS", "url": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/sarif-v2.1.0.html", "version_or_date": "Version 2.1.0 Plus Errata 01, 28 August 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Machine-readable finding interchange: run, tool/driver, reportingDescriptor (rule id), result (ruleId, level, kind pass/fail/review/open/informational/notApplicable, message, locations, provenance, suppressions), artifact hashes, invocation, and fingerprints / partialFingerprints with baselineState for stable finding identity across runs." }, { "id": "SRC-005", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013; namespace http://www.w3.org/ns/prov#", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Entity/Activity/Agent with wasGeneratedBy, used, wasAttributedTo, wasAssociatedWith, wasDerivedFrom, actedOnBehalfOf, startedAtTime/endedAtTime and qualified-influence patterns; alignment target for engagement provenance and evidence derivation chains." }, { "id": "SRC-006", "title": "Regulation (EU) 2019/1020 on market surveillance and compliance of products", "organization": "European Union (European Parliament and Council)", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32019R1020", "version_or_date": "OJ L 169, 25.6.2019, consolidated text as accessed 2026-08-29", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Article 3 definitions (market surveillance, authority, non-compliance, risk, serious risk, economic operator); Article 11 risk-based checks, documentary, physical and laboratory checks on representative samples, follow-up of complaints and verification of corrective action; Article 14 powers including unannounced inspections and sampling; Article 16 proportionate measures stating exact grounds; Article 18 right to be heard; Article 19 serious risk; Article 21 accredited Union testing facilities; Articles 22-23 mutual assistance; Article 34 information and communication system." }, { "id": "SRC-007", "title": "ISSAI 100 – Fundamental Principles of Public-Sector Auditing", "organization": "International Organisation of Supreme Audit Institutions (INTOSAI)", "url": "https://www.issai.org/pronouncements/issai-100-fundamental-principles-of-public-sector-auditing/", "version_or_date": "Endorsed 2013; editorial update 2019 under the INTOSAI Framework of Professional Pronouncements", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Three-party model (auditor, responsible party, intended users); subject matter, criteria and subject-matter information; financial, performance and compliance audit; attestation versus direct-reporting engagements; reasonable versus limited assurance; principles of planning, evidence, materiality, documentation, communication, professional judgement and scepticism, quality control, reporting and follow-up." }, { "id": "SRC-008", "title": "Global Internal Audit Standards", "organization": "The Institute of Internal Auditors (IIA)", "url": "https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/", "version_or_date": "2024 edition", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Five domains and fifteen principles including Demonstrate Integrity, Maintain Objectivity, Demonstrate Competency and Exercise Due Professional Care; Domain V standards for planning engagements effectively, conducting engagement work, and communicating engagement results and monitoring action plans." }, { "id": "SRC-009", "title": "NIST SP 800-53A Rev. 5, Assessing Security and Privacy Controls in Information Systems and Organizations", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/53/a/r5/final", "version_or_date": "January 2022; patch release 5.2.0, 27 August 2025; DOI 10.6028/NIST.SP.800-53Ar5", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Methodology and procedures for control assessment within a risk-management framework; tailorable assessment procedures, assessment plan construction and analysis of assessment results across lifecycle phases." }, { "id": "SRC-010", "title": "Structured Assurance Case Metamodel (SACM), Version 2.3", "organization": "Object Management Group (OMG)", "url": "https://www.omg.org/spec/SACM/2.3/About-SACM", "version_or_date": "Version 2.3, formal, October 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Metamodel for structured assurance cases defined as auditable claims, arguments and evidence supporting a claim that a system or service satisfies particular requirements; alignment target for linking criteria-derived claims to evidence and reasoning in a conclusion." }, { "id": "SRC-011", "title": "JCGM publications, including JCGM 106:2012 'Evaluation of measurement data — The role of measurement uncertainty in conformity assessment' and JCGM 200:2012 (VIM)", "organization": "Joint Committee for Guides in Metrology / Bureau International des Poids et Mesures (BIPM)", "url": "https://www.bipm.org/en/committees/jc/jcgm/publications", "version_or_date": "JCGM 106:2012 (DOI 10.59161/JCGM106-2012); JCGM 100:2008 GUM; JCGM 200:2012 VIM", "source_type": "scientific", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Authoritative treatment of measurement uncertainty in conformity assessment, underpinning documented decision rules, tolerance limits, acceptance limits and guard bands used when an inspection converts a measured value into a pass/fail determination." }, { "id": "SRC-012", "title": "Government Auditing Standards (Yellow Book)", "organization": "U.S. Government Accountability Office (GAO)", "url": "https://www.gao.gov/yellowbook", "version_or_date": "2024 revision; effective for financial audits, attestation engagements and reviews of financial statements, and for performance audits, for periods beginning on or after 15 December 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "GAGAS engagement taxonomy (financial audits, attestation engagements, reviews of financial statements, performance audits), requirements for individual auditors and audit organizations, and the system-of-quality-management implementation and evaluation deadlines." }, { "id": "SRC-013", "title": "Commission Notice — The 'Blue Guide' on the implementation of EU product rules 2022", "organization": "European Commission", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52022XC0629(04)", "version_or_date": "2022/C 247/01, OJ C 247, 29.6.2022", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Explains conformity assessment modules, conformity assessment bodies and notified bodies, accreditation under Regulation (EC) No 765/2008 as the means of demonstrating competence, the role of inspection-body standards, technical documentation, and market-surveillance checks across the product lifecycle." }, { "id": "SRC-014", "title": "ISO/IEC 17020:2012 Conformity Assessment — Requirements for the Operation of Various Types of Bodies Performing Inspection (OSAC Registry entry)", "organization": "National Institute of Standards and Technology (NIST), Organization of Scientific Area Committees for Forensic Science", "url": "https://www.nist.gov/standard/701", "version_or_date": "Registry entry added 7 June 2022; refers to ISO/IEC 17020:2012", "source_type": "public-authority", "primary_source": false, "authority_tier": 2, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Independent public-authority confirmation that ISO/IEC 17020 is the recognised competence standard for inspection bodies. Used only as an alignment pointer: the ISO text itself is paywalled and was not retrievable, so no clause-level conformance is asserted." }, { "id": "SRC-015", "title": "GAO Issues 2024 'Yellow Book,' Updating the Standards for Government Auditing", "organization": "U.S. Government Accountability Office (GAO)", "url": "https://www.gao.gov/press-release/gao-issues-2024-yellow-book-updating-standards-government-auditing", "version_or_date": "1 February 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T00:00:00Z", "relevance": "Confirms the 2024 revision's move from quality control to a risk-based system of quality management, the option of engagement quality reviews for GAGAS audits, and application guidance on key audit matters." } ], "structure": { "bundles": [ { "id": "engagement-mandate", "name": "Engagement identity and mandate", "description": "Establishes what this engagement is, how it is classified, under what authority it is performed, and who occupies which role with what impartiality safeguards.", "rationale": "Every verified standard opens the engagement with an identified commission and a party structure: INTOSAI names the three parties, the IIA requires objectivity and competency, GAGAS defines engagement types with distinct requirements, and EU market surveillance derives inspection power from a designated authority. Without a stable identity and an authority basis, no downstream finding is attributable or contestable.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008", "SRC-012" ], "layers": [ { "id": "engagement-identity-and-typing", "name": "Identity and typing", "description": "Stable identification of the engagement occurrence and the classification that selects which requirement regime, assurance level and reporting form apply.", "source_refs": [ "SRC-001", "SRC-007", "SRC-012" ], "findings": [ { "id": "engagement-identifier-and-registration", "name": "Engagement identifier and registration", "description": "How a single engagement occurrence is uniquely identified, by which issuing system, and how that identity survives re-issue, merger, split and cross-organisation exchange.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "questions": [ { "id": "eir-q-identifier", "text": "Which system of record issues the engagement identifier, and what is its issuing authority and scope of uniqueness?", "kind": "identity", "answer_data": [ "Issuing system reference", "Identifier value", "Identifier scheme name", "Uniqueness scope (organisation, jurisdiction, global)" ] }, { "id": "eir-q-surrogate", "text": "When no master-system or governed global identifier exists, which surrogate is minted and by whom?", "kind": "provenance", "answer_data": [ "Surrogate identifier (UUID or ULID)", "Minting actor reference", "Minting timestamp", "Reason no authoritative identifier was available" ] }, { "id": "eir-q-continuity", "text": "How is identity preserved when an engagement is split, merged, re-opened or superseded by a re-inspection?", "kind": "relationship", "answer_data": [ "Predecessor engagement references", "Successor engagement references", "Continuity relation code", "Effective date of the change" ] }, { "id": "eir-q-external", "text": "Which additional external references identify this engagement to counterparties and authorities?", "kind": "interoperability", "answer_data": [ "Regulator or client case reference", "Accreditation-body reference", "Cross-border notification identifier" ] } ], "data_elements": [ { "id": "de-engagement-id", "name": "engagement_identifier", "description": "Primary identifier of the engagement occurrence, qualified by its issuing system and scheme.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "de-engagement-alt-ids", "name": "alternate_identifiers", "description": "Set of additional identifiers assigned by counterparties, regulators or exchange systems, each with issuer and scheme.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-004" ] }, { "id": "de-engagement-relations", "name": "engagement_relations", "description": "Typed references to predecessor, successor, parent-programme or parallel engagements.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Identity is pure reference data carried on the engagement record itself. Materialising it as a separate artifact would create a second identity surface that could drift from the system of record, and no verified standard requires a standalone identity document." }, { "id": "engagement-type-and-assurance-classification", "name": "Engagement type and assurance classification", "description": "Classification of the engagement along the dimensions that change its normative obligations: discipline, engagement form, assurance level and reporting model.", "source_refs": [ "SRC-007", "SRC-012", "SRC-006", "SRC-008" ], "questions": [ { "id": "etc-q-type", "text": "Which engagement type applies, and which requirement standard governs that type?", "kind": "classification", "answer_data": [ "Engagement type code (financial audit, attestation engagement, review of financial statements, performance audit, compliance audit, management-system audit, product inspection, control assessment, peer review)", "Governing standard reference and version" ] }, { "id": "etc-q-assurance", "text": "Is the engagement an attestation or a direct-reporting engagement, and what level of assurance is intended?", "kind": "decision", "answer_data": [ "Engagement form code (attestation, direct reporting)", "Assurance level code (reasonable, limited, none/agreed-upon procedures)", "Basis for the chosen level" ] }, { "id": "etc-q-trigger", "text": "What triggered this engagement, and is it routine, risk-based, complaint-driven, follow-up or unannounced?", "kind": "event", "answer_data": [ "Trigger code", "Triggering event reference", "Risk-based prioritisation rationale", "Announcement status" ] }, { "id": "etc-q-independence-class", "text": "Is the examining body internal, first-party, second-party or third-party relative to the subject?", "kind": "classification", "answer_data": [ "Party-relationship code", "Independence classification of the body", "Basis for that classification" ] } ], "data_elements": [ { "id": "de-engagement-type", "name": "engagement_type_code", "description": "Coded engagement type drawn from the governing requirement standard's taxonomy.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-012" ] }, { "id": "de-assurance-level", "name": "assurance_level_code", "description": "Intended level of assurance, distinguishing reasonable, limited and non-assurance procedures.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-trigger", "name": "engagement_trigger", "description": "Reason the engagement was initiated, including risk-based selection, complaint, mandate cycle or prior finding.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "Classification consists of coded values and their justification text bound to the engagement record. The code lists themselves are owned by the governing standard's catalogue model, so this finding holds only bindings and rationale, not a document." } ] }, { "id": "mandate-authority-and-parties", "name": "Mandate, authority and parties", "description": "The legal, regulatory or contractual basis for examining the subject, the terms agreed, and the appointment and impartiality of the people and bodies involved.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008", "SRC-013" ], "findings": [ { "id": "mandate-authority-and-terms", "name": "Mandate, authority and terms of engagement", "description": "The instrument that authorises the examination, the powers it confers, its limits, and the agreed terms and conditions or rules of engagement.", "source_refs": [ "SRC-006", "SRC-003", "SRC-007", "SRC-013" ], "questions": [ { "id": "mat-q-basis", "text": "On what legal, regulatory or contractual basis is this engagement authorised, and which instrument evidences it?", "kind": "authority", "answer_data": [ "Authority basis code (statute, designation, contract, charter, accreditation scope)", "Instrument reference and version", "Designating or contracting party reference" ] }, { "id": "mat-q-powers", "text": "Which specific powers are conferred, such as entry to premises, unannounced inspection, sampling, document demand or acquisition under cover of identity?", "kind": "authority", "answer_data": [ "Enumerated power codes", "Conditions and limits on each power", "Jurisdiction in which the power is valid" ] }, { "id": "mat-q-terms", "text": "What terms and conditions, rules of engagement, liability limits and safety constraints govern the work?", "kind": "constraint", "answer_data": [ "Rules-of-engagement text reference", "Agreed constraints and prohibitions", "Liability and indemnity clauses", "Safety or security preconditions" ] }, { "id": "mat-q-limits", "text": "What does this mandate explicitly not authorise, and where does it hand over to an enforcement or certification decision?", "kind": "exception", "answer_data": [ "Excluded powers", "Hand-over point description", "Reference to the owning enforcement or certification model" ] } ], "data_elements": [ { "id": "de-authority-basis", "name": "authority_basis", "description": "Coded basis of authority with a reference to the authorising instrument and its issuing party.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-013" ] }, { "id": "de-conferred-powers", "name": "conferred_powers", "description": "Enumerated powers available for this engagement, each with conditions, limits and jurisdiction.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-rules-of-engagement", "name": "rules_of_engagement", "description": "Agreed terms, constraints, prohibitions and preconditions governing how the engagement may be performed.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "engagement-authorization-instrument", "name": "Engagement authorization instrument", "description": "The signed or issued instrument that commissions the engagement: engagement letter, work order, statutory inspection notice, designation decision or internal audit charter extract.", "media_or_form": [ "signed document", "structured record", "electronic authorisation notice" ], "serial": false, "identity_strategy": "Identified by the issuing system's instrument reference plus version; bound to the engagement identifier and to the issuing party reference.", "source_refs": [ "SRC-006", "SRC-013", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "party-appointment-and-impartiality", "name": "Party appointment and impartiality safeguards", "description": "Who acts as auditor or inspector, responsible party and intended user; how roles are appointed; and what impartiality, independence and conflict-of-interest safeguards apply to this engagement.", "source_refs": [ "SRC-007", "SRC-008", "SRC-013", "SRC-014", "SRC-006" ], "questions": [ { "id": "pai-q-parties", "text": "Which parties occupy the auditor, responsible-party and intended-user roles for this engagement?", "kind": "ownership", "answer_data": [ "Party references by role", "Role code per party", "Organisational unit and legal entity", "Contact or liaison designation" ] }, { "id": "pai-q-team", "text": "Which individuals are assigned to the engagement team, in which engagement roles, and for which periods?", "kind": "composition", "answer_data": [ "Individual party references", "Engagement role code", "Assignment start and end timestamps", "Supervision or review relationship" ] }, { "id": "pai-q-impartiality", "text": "What threats to impartiality or independence were identified, and which safeguards were applied?", "kind": "constraint", "answer_data": [ "Identified threat descriptions", "Threat category code", "Safeguard applied", "Residual-threat conclusion and approver" ] }, { "id": "pai-q-declaration", "text": "Who declared absence or presence of conflicts of interest, when, and to whom was it disclosed?", "kind": "evidence", "answer_data": [ "Declaring individual reference", "Declaration timestamp", "Disclosure recipient", "Declared interests" ] } ], "data_elements": [ { "id": "de-party-roles", "name": "engagement_party_roles", "description": "Assignment of parties and individuals to engagement roles with validity periods.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007", "SRC-008" ] }, { "id": "de-impartiality-assessment", "name": "impartiality_assessment", "description": "Recorded threats to impartiality or independence, safeguards applied and the residual conclusion.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-013" ] } ], "artifacts": [ { "id": "impartiality-and-conflict-declaration", "name": "Impartiality and conflict-of-interest declaration", "description": "Per-individual or per-body declaration covering independence, conflicts of interest and confidentiality undertakings for this engagement, with the approval of any residual threat.", "media_or_form": [ "signed declaration", "structured attestation record" ], "serial": true, "identity_strategy": "Identified by declaring-party reference plus engagement identifier plus declaration sequence; superseded rather than overwritten when circumstances change.", "source_refs": [ "SRC-008", "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "criteria-and-subject-matter", "name": "Subject matter, criteria and decision basis", "description": "Fixes what is examined, the boundary and period of examination, the criteria the subject is measured against, and the documented rules by which measured or observed states become conformity determinations.", "rationale": "INTOSAI states subject matter, criteria and subject-matter information as core elements of any audit, and OSCAL scopes an assessment by reviewed controls and control objectives. JCGM 106 shows that turning a measurement into a conformity statement requires a documented decision rule and explicit treatment of uncertainty; EU market surveillance requires proportionate measures stating exact grounds, which presupposes stated criteria.", "source_refs": [ "SRC-007", "SRC-003", "SRC-011", "SRC-006" ], "layers": [ { "id": "subject-matter-and-scope", "name": "Subject matter and scope", "description": "What is being examined, in what representation, within which boundary, over which period, and with what declared exclusions.", "source_refs": [ "SRC-007", "SRC-003", "SRC-002" ], "findings": [ { "id": "subject-matter-and-information", "name": "Subject matter and subject-matter information", "description": "Distinguishes the underlying subject matter from the subject-matter information presented about it, and identifies the concrete assessment subjects examined.", "source_refs": [ "SRC-007", "SRC-003", "SRC-002" ], "questions": [ { "id": "smi-q-definition", "text": "What is the underlying subject matter, and what subject-matter information about it is being examined?", "kind": "definition", "answer_data": [ "Subject-matter description", "Subject-matter information reference (statement, report, dataset, declaration)", "Preparer of the subject-matter information" ] }, { "id": "smi-q-subjects", "text": "Which concrete assessment subjects fall within the examination, such as locations, components, inventory items, users, batches or processes?", "kind": "composition", "answer_data": [ "Assessment subject references", "Subject type code", "Selection basis (all, sampled, targeted)", "Population size where sampling applies" ] }, { "id": "smi-q-linkage", "text": "How does each assessment subject link to the master record for that entity in its owning model?", "kind": "relationship", "answer_data": [ "Owning model reference", "Master identifier of the subject", "Resolution method for the reference" ] }, { "id": "smi-q-condition", "text": "What was the state or configuration of the subject at the moment of examination, and how was that state captured?", "kind": "state", "answer_data": [ "Observed configuration or version reference", "State capture timestamp", "Capture method" ] } ], "data_elements": [ { "id": "de-subject-matter", "name": "subject_matter", "description": "Description of the underlying subject matter and, where applicable, a reference to the subject-matter information asserted about it.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "de-assessment-subjects", "name": "assessment_subjects", "description": "References to concrete subjects included in the examination, with type, selection basis and link to the owning master record.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-002" ] } ], "artifacts": [], "inline_only_rationale": "Subject matter is expressed as typed references into models that own the examined entities, plus a short descriptive statement. Creating a local artifact would duplicate records that the asset, product or system models already govern and would risk divergence from their master state." }, { "id": "scope-boundary-period-and-exclusions", "name": "Scope boundary, period and exclusions", "description": "The declared limits of the examination in organisational, geographic, temporal and topical terms, including what was deliberately excluded and why.", "source_refs": [ "SRC-003", "SRC-007", "SRC-006", "SRC-002" ], "questions": [ { "id": "sbp-q-boundary", "text": "What organisational, contractual and topical boundary is claimed for this engagement?", "kind": "composition", "answer_data": [ "Organisational units in scope", "Processes, product families or control families in scope", "Explicit boundary statement" ] }, { "id": "sbp-q-period", "text": "Which period does the examination cover, and how does it relate to the fieldwork dates?", "kind": "temporal", "answer_data": [ "Period-covered start and end", "Fieldwork start and end timestamps", "As-at date for point-in-time subject matter" ] }, { "id": "sbp-q-location", "text": "Which physical or logical locations, sites, borders or jurisdictions are within the examination boundary?", "kind": "spatial", "answer_data": [ "Site or location references", "Jurisdiction codes", "Remote versus on-site designation per location" ] }, { "id": "sbp-q-exclusions", "text": "What was excluded from scope, on whose decision, and what effect does the exclusion have on the conclusion?", "kind": "exception", "answer_data": [ "Exclusion description", "Deciding party", "Justification", "Assessed effect on the conclusion" ] } ], "data_elements": [ { "id": "de-scope-boundary", "name": "scope_boundary", "description": "Structured statement of organisational, topical, geographic and jurisdictional limits of the examination.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "de-period-covered", "name": "period_covered", "description": "Interval of subject-matter activity covered by the engagement, distinct from the fieldwork interval.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-012" ] }, { "id": "de-scope-exclusions", "name": "scope_exclusions", "description": "Declared exclusions with deciding party, justification and assessed effect on the conclusion.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "Boundary, period and exclusions are structured attributes of the engagement that must remain queryable and comparable across engagements. They are rendered inside the plan and report artifacts, but the authoritative values are inline fields rather than a separate document." } ] }, { "id": "criteria-and-decision-basis", "name": "Criteria and decision basis", "description": "The requirements the subject is measured against and the documented rules that convert observed or measured states into conformity determinations.", "source_refs": [ "SRC-003", "SRC-007", "SRC-011", "SRC-009", "SRC-010" ], "findings": [ { "id": "criteria-selection-and-binding", "name": "Criteria selection and authoritative binding", "description": "Which criteria apply, from which authoritative source and version, how they were selected or tailored, and how each is interpreted for this engagement.", "source_refs": [ "SRC-003", "SRC-009", "SRC-007", "SRC-006", "SRC-010" ], "questions": [ { "id": "csb-q-source", "text": "Which authoritative source and version supplies each criterion, and how is that binding resolved at read time?", "kind": "provenance", "answer_data": [ "Criteria source reference", "Source version or edition", "Criterion identifier within the source", "Resolution or dereference method" ] }, { "id": "csb-q-selection", "text": "How were criteria selected, tailored or narrowed to control objectives for this engagement, and who approved the selection?", "kind": "decision", "answer_data": [ "Selection method (full set, profile, risk-based subset)", "Tailoring or exclusion decisions", "Approver reference and approval timestamp" ] }, { "id": "csb-q-suitability", "text": "Are the criteria suitable, relevant, complete, reliable, neutral and understandable for the intended users?", "kind": "quality", "answer_data": [ "Suitability assessment per attribute", "Alternative criteria considered", "Justification where criteria are established by the auditor rather than by an authority" ] }, { "id": "csb-q-interpretation", "text": "What engagement-local interpretation or acceptance guidance is applied to an ambiguous criterion, and does it conflict with the source?", "kind": "constraint", "answer_data": [ "Interpretation text", "Criterion reference", "Conflict flag and description", "Interpreting authority" ] } ], "data_elements": [ { "id": "de-criteria-binding", "name": "criteria_bindings", "description": "Per-criterion binding to an external source identifier and version, with resolution method and any engagement-local interpretation.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-009" ] }, { "id": "de-criteria-suitability", "name": "criteria_suitability_assessment", "description": "Assessment of the criteria against relevance, completeness, reliability, neutrality and understandability for the intended users.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [ { "id": "engagement-criteria-register", "name": "Engagement criteria register", "description": "The resolved set of criteria and control objectives in scope for this engagement, each bound to its authoritative source and version, with tailoring decisions and local interpretations. It holds bindings only; the criteria text remains owned by the catalogue model.", "media_or_form": [ "structured register", "tabular listing", "control-objective selection record" ], "serial": false, "identity_strategy": "Identified by engagement identifier plus register version; each entry keyed by the external criterion identifier and its source version.", "source_refs": [ "SRC-003", "SRC-009", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "materiality-tolerance-and-decision-rules", "name": "Materiality, tolerance and decision rules", "description": "The thresholds and documented decision rules that determine when a deviation is reportable and when a measured value counts as conforming, including guard bands and uncertainty treatment.", "source_refs": [ "SRC-011", "SRC-007", "SRC-012", "SRC-006" ], "questions": [ { "id": "mtd-q-materiality", "text": "What materiality or significance thresholds apply, quantitatively and qualitatively, and how were they set?", "kind": "measurement", "answer_data": [ "Quantitative threshold value and unit", "Qualitative significance factors", "Basis and approver", "Performance materiality where used" ] }, { "id": "mtd-q-decisionrule", "text": "What documented decision rule converts a measured value plus its uncertainty into a conformity determination?", "kind": "decision", "answer_data": [ "Tolerance or specification limits", "Acceptance limits and guard-band definition", "Decision-rule identifier and reference", "Permitted probability of false accept or false reject" ] }, { "id": "mtd-q-uncertainty", "text": "How is measurement uncertainty obtained and whose responsibility is it to evaluate it?", "kind": "measurement", "answer_data": [ "Uncertainty value and coverage factor", "Source of the uncertainty statement", "Reference to the owning test or measurement model" ] }, { "id": "mtd-q-riskbasis", "text": "How does the risk-based prioritisation of checks influence thresholds, sample intensity and reporting?", "kind": "requirement", "answer_data": [ "Risk factors considered", "Prioritisation method", "Effect on thresholds and coverage" ] } ], "data_elements": [ { "id": "de-materiality", "name": "materiality_thresholds", "description": "Quantitative and qualitative thresholds determining reportability, with basis and approver.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-012" ] }, { "id": "de-decision-rule", "name": "decision_rule", "description": "Documented rule mapping measured value and uncertainty onto conformity, including tolerance limits, acceptance limits and guard band.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-risk-prioritisation", "name": "risk_prioritisation_basis", "description": "Recorded risk factors and method used to prioritise checks, coverage and thresholds for this engagement.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "decision-rule-and-materiality-statement", "name": "Decision rule and materiality statement", "description": "The agreed, dated statement of decision rules, tolerance and acceptance limits, guard bands and materiality thresholds applied in this engagement, referenced by every conformity determination made.", "media_or_form": [ "structured statement", "annex to the engagement plan", "scheme rule reference" ], "serial": false, "identity_strategy": "Identified by engagement identifier plus statement version; where a scheme-wide rule applies, carries a reference to the governing scheme rule identifier and version.", "source_refs": [ "SRC-011", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "planning-and-fieldwork", "name": "Planning and fieldwork", "description": "Converts the mandate and criteria into an executable plan with methods, sampling and coverage, and records what was actually done, where, when and by whom, including departures from plan.", "rationale": "OSCAL's assessment plan makes objectives, methods, subjects, assets, tasks and rules of engagement explicit and separates them from results; the IIA requires effective engagement planning and conduct; EU market surveillance requires checks on an adequate scale using documentary, physical and laboratory means on representative samples. The execution record is what makes a conclusion reproducible and contestable.", "source_refs": [ "SRC-003", "SRC-008", "SRC-006", "SRC-009" ], "layers": [ { "id": "engagement-planning", "name": "Engagement planning", "description": "Objectives, schedule, methods, sampling, depth and coverage, and the assets and tooling used to perform the work.", "source_refs": [ "SRC-003", "SRC-009", "SRC-008", "SRC-006" ], "findings": [ { "id": "objectives-plan-and-schedule", "name": "Engagement objectives, plan and schedule", "description": "The stated objectives of the engagement, the tasks and milestones planned to meet them, and the resources committed.", "source_refs": [ "SRC-003", "SRC-008", "SRC-007" ], "questions": [ { "id": "ops-q-objectives", "text": "What are the engagement objectives, and how does each trace to a criterion or control objective?", "kind": "requirement", "answer_data": [ "Objective statements", "Traceability links to criteria or control objectives", "Objective priority" ] }, { "id": "ops-q-tasks", "text": "What tasks, activities and milestones are planned, in what sequence, and with which dependencies?", "kind": "process", "answer_data": [ "Task and activity definitions", "Planned start and end timestamps", "Dependency relations", "Responsible role per task" ] }, { "id": "ops-q-approval", "text": "Who approved the plan, when, and what changes require re-approval?", "kind": "authority", "answer_data": [ "Approver reference", "Approval timestamp", "Plan version", "Re-approval triggers" ] }, { "id": "ops-q-communication", "text": "What communication with the responsible party is planned before, during and after fieldwork?", "kind": "process", "answer_data": [ "Planned communication events", "Recipients", "Opening and closing meeting schedule" ] } ], "data_elements": [ { "id": "de-objectives", "name": "engagement_objectives", "description": "Stated objectives with traceability to criteria or control objectives and assigned priority.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-008" ] }, { "id": "de-planned-tasks", "name": "planned_tasks", "description": "Planned tasks, activities, milestones, dependencies and responsible roles with planned timings.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "engagement-plan-document", "name": "Engagement plan", "description": "The approved plan covering objectives, scope, schedule, team, communication and terms of engagement, versioned and re-approved when materially changed.", "media_or_form": [ "plan document", "structured assessment plan record" ], "serial": false, "identity_strategy": "Identified by engagement identifier plus plan version; each version records its approver and approval timestamp and supersedes rather than replaces the prior version.", "source_refs": [ "SRC-003", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "methods-sampling-and-coverage", "name": "Methods, sampling, depth and coverage", "description": "Which examination methods are applied to which subjects, how samples are drawn from populations, and what depth and coverage are claimed.", "source_refs": [ "SRC-009", "SRC-003", "SRC-006", "SRC-001" ], "questions": [ { "id": "msc-q-methods", "text": "Which examination methods are used per objective, such as document examination, interview, observation, test, physical check or laboratory analysis?", "kind": "process", "answer_data": [ "Method code per activity", "Objects the method is applied to (specifications, mechanisms, activities, individuals)", "Procedure or work-programme reference" ] }, { "id": "msc-q-sampling", "text": "How is the sample drawn from the population, and is the approach judgement-based or statistical?", "kind": "measurement", "answer_data": [ "Population definition and size", "Sample size", "Sampling method and selection rule", "Representativeness justification" ] }, { "id": "msc-q-coverage", "text": "What depth and coverage are claimed, and what does that imply about the extrapolation of results to the population?", "kind": "validation", "answer_data": [ "Depth attribute value", "Coverage attribute value", "Extrapolation limits", "Confidence statement where statistical" ] }, { "id": "msc-q-tools", "text": "Which tools, platforms and automated analysers are used, at which versions and configurations?", "kind": "provenance", "answer_data": [ "Tool or assessment-platform reference", "Tool version and rule-set version", "Configuration parameters", "Operator reference" ] } ], "data_elements": [ { "id": "de-method-assignment", "name": "method_assignments", "description": "Mapping of examination methods to objectives, subjects and object classes, with procedure references.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009", "SRC-003" ] }, { "id": "de-sampling-plan", "name": "sampling_plan", "description": "Population definition, sample size, selection method and representativeness justification.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-assessment-assets", "name": "assessment_assets", "description": "Tools, analysers and platforms used, with version, rule-set version and configuration.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "method-and-sampling-protocol", "name": "Method and sampling protocol", "description": "The documented examination procedures, work programme, sampling scheme and tool configuration applied, sufficient for an independent party to repeat the procedure.", "media_or_form": [ "work programme", "procedure or method statement", "structured activity definition" ], "serial": false, "identity_strategy": "Identified by engagement identifier plus protocol version; references any standing scheme procedure by its own identifier and version rather than copying it.", "source_refs": [ "SRC-009", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "fieldwork-execution", "name": "Fieldwork execution", "description": "The record of what was actually performed, under what conditions and access, by whom, and how execution departed from plan.", "source_refs": [ "SRC-002", "SRC-001", "SRC-006", "SRC-005" ], "findings": [ { "id": "fieldwork-log-conditions-and-deviations", "name": "Fieldwork execution log, conditions and deviations", "description": "Chronological record of performed actions with actor, time and location, the site and access conditions that constrained them, and any departures from the approved plan.", "source_refs": [ "SRC-002", "SRC-001", "SRC-006", "SRC-005" ], "questions": [ { "id": "flc-q-actions", "text": "Which assessment actions were performed, by whom, and at what start and end times?", "kind": "event", "answer_data": [ "Action reference and title", "Performing individual references", "Action start and end timestamps", "Related task or activity reference" ] }, { "id": "flc-q-location", "text": "Where was each action performed, and was it on-site, remote or at a border or testing facility?", "kind": "spatial", "answer_data": [ "Location reference or coordinates", "Location mode code (on-site, remote, border, laboratory)", "Access route or facility identifier" ] }, { "id": "flc-q-conditions", "text": "What access, availability, safety or security conditions constrained execution?", "kind": "constraint", "answer_data": [ "Condition description", "Condition category", "Effect on the action", "Party responsible for the constraint" ] }, { "id": "flc-q-deviation", "text": "Where did execution deviate from the approved plan, why, who authorised it, and what is the consequence for coverage?", "kind": "exception", "answer_data": [ "Planned versus actual description", "Deviation reason code", "Authorising party and timestamp", "Assessed effect on coverage and conclusion" ] } ], "data_elements": [ { "id": "de-assessment-log", "name": "assessment_log_entries", "description": "Serial entries recording performed actions with actor, timing, location and related planned task.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-001" ] }, { "id": "de-execution-conditions", "name": "execution_conditions", "description": "Access, availability, safety and security conditions encountered, with their effect on the action.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-plan-deviations", "name": "plan_deviations", "description": "Recorded departures from the approved plan with reason, authorisation and assessed effect on coverage.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-012" ] } ], "artifacts": [ { "id": "fieldwork-execution-log", "name": "Fieldwork execution log", "description": "Append-only log of assessment actions performed during the engagement, each with actor, timestamps, location mode, conditions and any deviation from plan.", "media_or_form": [ "append-only log record", "assessment log entry set", "field notebook export" ], "serial": true, "identity_strategy": "Each entry identified by engagement identifier plus a monotonically increasing entry sequence and the entry's own surrogate identifier; entries are never edited, only superseded by a correcting entry that references the original.", "source_refs": [ "SRC-002", "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "evidence-and-observation", "name": "Evidence and observation", "description": "How raw observations are captured with their collection method and subject, how evidence items are identified, held and kept intact, and how their relevance, reliability and sufficiency are appraised.", "rationale": "OSCAL models observations separately from findings, with methods, subjects, origins, relevant evidence and collection and expiry times, and SARIF attaches artifact hashes and provenance to results. INTOSAI requires sufficient and appropriate evidence; EU market surveillance permits evidence gathered by one authority to support another's investigation, which only works if integrity and appraisal are recorded.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-006" ], "layers": [ { "id": "evidence-acquisition", "name": "Evidence acquisition", "description": "Capture of observations and the identification, custody and integrity of the evidence items that support them.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006" ], "findings": [ { "id": "observation-record-and-method", "name": "Observation record and collection method", "description": "An atomic recorded observation: what was seen or measured, by which method, about which subject, when collected and when it ceases to be current.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "questions": [ { "id": "orm-q-what", "text": "What exactly was observed, expressed independently of any judgement about conformity?", "kind": "definition", "answer_data": [ "Observation title and description", "Observation type code", "Subject reference", "Related activity or task reference" ] }, { "id": "orm-q-method", "text": "By which collection method was the observation obtained, and by which actor or tool?", "kind": "process", "answer_data": [ "Collection method code (examine, interview, test, observe, automated analysis)", "Origin actor reference (person, tool, party)", "Tool version where automated" ] }, { "id": "orm-q-time", "text": "When was the observation collected, when did the observed condition occur, and when does the observation expire?", "kind": "temporal", "answer_data": [ "Collected timestamp", "Event or condition occurrence timestamp", "Expiry timestamp", "Ingestion timestamp into the record system" ] }, { "id": "orm-q-support", "text": "Which evidence items support this observation, and are they sufficient on their own?", "kind": "evidence", "answer_data": [ "Relevant evidence references", "Support strength note", "Corroborating observation references" ] } ], "data_elements": [ { "id": "de-observation", "name": "observation", "description": "Atomic observation with type, subject, description and origin, recorded without a conformity judgement.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "de-observation-method", "name": "observation_methods", "description": "Collection methods applied to produce the observation, with the actor or tool origin.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "de-observation-times", "name": "observation_time_set", "description": "Separate collected, occurred, ingested and expiry timestamps for the observation.", "value_kind": "timestamp", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "observation-record", "name": "Observation record", "description": "A single recorded observation with its methods, subjects, origins, timing and links to supporting evidence, usable both to demonstrate conformity and to underpin a nonconformity.", "media_or_form": [ "structured observation record", "field note", "automated tool result entry" ], "serial": true, "identity_strategy": "Identified by a surrogate identifier assigned at capture, scoped by the engagement identifier; carries the origin actor or tool reference and is immutable after the engagement is issued.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "evidence-item-custody-and-integrity", "name": "Evidence item identity, custody and integrity", "description": "Identification of each evidence item, where it came from, who held it, and how its integrity is demonstrable to a challenging party.", "source_refs": [ "SRC-004", "SRC-006", "SRC-005", "SRC-002" ], "questions": [ { "id": "eci-q-identity", "text": "How is each evidence item identified, and what is its authoritative source location?", "kind": "identity", "answer_data": [ "Evidence item identifier", "Source system or location reference", "Item type and format", "Acquisition method" ] }, { "id": "eci-q-integrity", "text": "What integrity mechanism demonstrates that the item has not changed since acquisition?", "kind": "security", "answer_data": [ "Digest algorithm identifier", "Digest value", "Sealing or signature reference", "Verification timestamp and verifier" ] }, { "id": "eci-q-custody", "text": "Who has held the item since acquisition, in which transfers, and under what storage conditions?", "kind": "provenance", "answer_data": [ "Custody transfer entries with holder, timestamp and reason", "Storage condition description", "Seal or container identifier" ] }, { "id": "eci-q-privacy", "text": "Does the item contain personal, commercially confidential or classified material, and what handling class applies?", "kind": "privacy", "answer_data": [ "Sensitivity classification", "Personal-data categories present", "Redaction or minimisation applied", "Legal basis for holding it" ] }, { "id": "eci-q-reuse", "text": "Under what conditions may the item be reused or shared with another authority or engagement?", "kind": "access", "answer_data": [ "Permitted recipients", "Sharing basis or legal gateway", "Reuse constraints", "Onward-disclosure conditions" ] } ], "data_elements": [ { "id": "de-evidence-item", "name": "evidence_item", "description": "An identified item of evidence with source, type, acquisition method and format.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-004" ] }, { "id": "de-evidence-digest", "name": "evidence_integrity_digest", "description": "Cryptographic digest with algorithm identifier and verification record demonstrating item integrity.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-custody-chain", "name": "custody_chain", "description": "Ordered custody transfers with holder, timestamp, reason and storage conditions.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "de-evidence-sensitivity", "name": "evidence_sensitivity", "description": "Sensitivity classification, personal-data categories and handling constraints for the item.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "evidence-item-package", "name": "Evidence item package", "description": "The retained or referenced evidence itself: documents, samples, photographs, extracts, test reports, screenshots or tool output, held with format, digest and sensitivity classification.", "media_or_form": [ "document", "physical sample", "image or recording", "data extract", "referenced external record" ], "serial": true, "identity_strategy": "Identified by the source system's item identifier where one exists, otherwise a surrogate assigned at acquisition; always paired with a digest and an acquisition timestamp.", "source_refs": [ "SRC-004", "SRC-002", "SRC-006" ] }, { "id": "chain-of-custody-record", "name": "Chain-of-custody record", "description": "Ordered record of possession and transfer of an evidence item from acquisition to disposition, enabling a challenging party to test integrity.", "media_or_form": [ "custody log", "signed transfer record" ], "serial": true, "identity_strategy": "Identified by evidence item identifier plus transfer sequence; append-only, with corrections recorded as new entries referencing the original.", "source_refs": [ "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "evidence-appraisal", "name": "Evidence appraisal", "description": "Judgement about whether the evidence obtained is relevant, reliable, sufficient and appropriate, and what limitations qualify it.", "source_refs": [ "SRC-007", "SRC-012", "SRC-010", "SRC-006" ], "findings": [ { "id": "evidence-relevance-reliability-and-sufficiency", "name": "Relevance, reliability, sufficiency and limitations", "description": "The recorded appraisal of evidence quality against the objectives, together with scope restrictions, unavailable evidence and their effect on the conclusion.", "source_refs": [ "SRC-007", "SRC-012", "SRC-010", "SRC-006" ], "questions": [ { "id": "err-q-relevance", "text": "Is each item of evidence relevant to the objective and criterion it is used to support?", "kind": "quality", "answer_data": [ "Relevance judgement per evidence-to-criterion link", "Justification", "Assessor reference" ] }, { "id": "err-q-reliability", "text": "How reliable is the evidence given its source, generation method and susceptibility to manipulation?", "kind": "quality", "answer_data": [ "Reliability rating", "Source independence assessment", "Method of generation", "Corroboration status" ] }, { "id": "err-q-sufficiency", "text": "Is the accumulated evidence sufficient and appropriate to support the intended level of assurance?", "kind": "validation", "answer_data": [ "Sufficiency conclusion", "Assurance level targeted", "Residual doubt description", "Additional procedures performed" ] }, { "id": "err-q-limitation", "text": "What evidence could not be obtained, why, and how does that limit the finding or conclusion?", "kind": "exception", "answer_data": [ "Unavailable evidence description", "Cause code (access refused, destroyed, out of period, not retained)", "Effect on scope and conclusion", "Modification to the opinion where applicable" ] } ], "data_elements": [ { "id": "de-evidence-appraisal", "name": "evidence_appraisal", "description": "Per-item or per-link appraisal of relevance and reliability with justification and assessor.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-012" ] }, { "id": "de-sufficiency-conclusion", "name": "sufficiency_conclusion", "description": "Judgement that accumulated evidence is or is not sufficient and appropriate for the intended assurance level.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-evidence-limitations", "name": "evidence_limitations", "description": "Scope restrictions and unavailable evidence, with cause and assessed effect on the conclusion.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Appraisal is professional judgement expressed as structured attributes attached to evidence items, observations and evidence-to-criterion links. Emitting it as a standalone artifact would detach the judgement from the item it qualifies and invite inconsistency between the two; the working-paper rendering is a projection of these inline fields." } ] } ] }, { "id": "findings-conclusion-and-reporting", "name": "Findings, conclusion and reporting", "description": "How evidence becomes a structured finding with a conformity determination and severity, how findings retain identity across engagements, and how the engagement reaches and communicates a conclusion.", "rationale": "OSCAL distinguishes observations from findings that carry control-objective status; SARIF gives results a rule reference, level, kind and stable fingerprints with baseline state; GAGAS and INTOSAI require findings developed against criteria and reported with the views of responsible officials. Reporting is where use restrictions and confidentiality obligations attach.", "source_refs": [ "SRC-001", "SRC-004", "SRC-012", "SRC-007", "SRC-006" ], "layers": [ { "id": "finding-construction", "name": "Finding construction", "description": "The internal structure of a finding, the determination and grading applied to it, and how it is identified and matched over time.", "source_refs": [ "SRC-001", "SRC-004", "SRC-012", "SRC-011" ], "findings": [ { "id": "finding-statement-structure", "name": "Finding statement structure", "description": "The elements that make a finding intelligible and contestable: the criterion, the condition observed, the cause and the actual or potential effect, with traceability to observations.", "source_refs": [ "SRC-012", "SRC-001", "SRC-010", "SRC-006" ], "questions": [ { "id": "fss-q-elements", "text": "For this finding, what are the criterion, the observed condition, the cause and the effect or potential effect?", "kind": "definition", "answer_data": [ "Criterion reference and version", "Condition statement", "Cause analysis", "Effect or potential effect statement" ] }, { "id": "fss-q-trace", "text": "Which observations and evidence items support each element of the finding?", "kind": "evidence", "answer_data": [ "Related observation references", "Evidence item references per element", "Sufficiency note" ] }, { "id": "fss-q-argument", "text": "What reasoning connects the evidence to the claim that the criterion is or is not met?", "kind": "validation", "answer_data": [ "Argument or reasoning statement", "Assumptions relied on", "Counter-evidence considered" ] }, { "id": "fss-q-grounds", "text": "Are the grounds stated precisely enough to support a proportionate measure or a contested response?", "kind": "requirement", "answer_data": [ "Exact grounds statement", "Referenced legal or contractual provision", "Precision self-assessment" ] } ], "data_elements": [ { "id": "de-finding-elements", "name": "finding_elements", "description": "Criterion reference, condition, cause and effect statements forming the body of the finding.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-001" ] }, { "id": "de-finding-traceability", "name": "finding_traceability", "description": "Links from the finding to the observations, evidence items and criteria that support it.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] } ], "artifacts": [ { "id": "finding-record", "name": "Finding record", "description": "A single structured finding carrying its criterion binding, condition, cause, effect, determination, severity, supporting observations and any responsible-party response.", "media_or_form": [ "structured finding record", "report section", "exchange result object" ], "serial": true, "identity_strategy": "Identified by a surrogate identifier assigned on creation, scoped by the engagement identifier, plus a recurrence key computed from criterion, subject and condition signature for cross-engagement matching.", "source_refs": [ "SRC-001", "SRC-004", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "conformity-determination-and-grading", "name": "Conformity determination and severity grading", "description": "The verdict attached to a finding against its criterion and the severity or significance grade assigned, with the scheme that defines the permitted values.", "source_refs": [ "SRC-001", "SRC-004", "SRC-011", "SRC-006", "SRC-009" ], "questions": [ { "id": "cdg-q-determination", "text": "What determination is recorded against the criterion, and from which controlled value set?", "kind": "decision", "answer_data": [ "Determination value (for example satisfied, other than satisfied, conforming, non-conforming, not applicable, not tested)", "Value-set identifier and version", "Determining party" ] }, { "id": "cdg-q-severity", "text": "What severity, significance or risk grade is assigned, under which grading scheme?", "kind": "classification", "answer_data": [ "Severity or grade code", "Grading scheme identifier and version", "Grading rationale", "Escalation threshold reached" ] }, { "id": "cdg-q-rule", "text": "Which decision rule and uncertainty treatment produced the determination for a measured characteristic?", "kind": "measurement", "answer_data": [ "Decision rule reference", "Measured value and uncertainty", "Acceptance limit applied", "Residual risk of false accept" ] }, { "id": "cdg-q-notapplicable", "text": "On what basis is a criterion recorded as not applicable, not tested or inconclusive rather than passed or failed?", "kind": "exception", "answer_data": [ "Non-determination reason code", "Justification", "Effect on coverage claims" ] } ], "data_elements": [ { "id": "de-determination", "name": "conformity_determination", "description": "Coded verdict against a criterion, bound to a versioned value set and attributed to a determining party.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "de-severity", "name": "severity_grade", "description": "Severity, significance or risk grade with the identifier and version of the grading scheme used.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "The determination and grade are typed attributes of a finding record that already exists as an artifact. Duplicating them into a separate artifact would create two authoritative verdicts for one finding; the grading scheme itself is owned by the criteria or scheme model and is referenced here by identifier and version." }, { "id": "finding-identity-recurrence-and-baseline", "name": "Finding identity, recurrence and baseline comparison", "description": "How a finding keeps a stable identity across engagements and report revisions so that new, unchanged, updated and closed findings can be distinguished and trends measured.", "source_refs": [ "SRC-004", "SRC-001", "SRC-008", "SRC-006" ], "questions": [ { "id": "fir-q-fingerprint", "text": "What stable key identifies the same underlying issue across engagements even when the artifact or wording changes?", "kind": "identity", "answer_data": [ "Recurrence or fingerprint key definition", "Key inputs (criterion, subject, condition signature)", "Key version" ] }, { "id": "fir-q-baseline", "text": "Against which baseline engagement is this finding compared, and what is its baseline state?", "kind": "relationship", "answer_data": [ "Baseline engagement reference", "Baseline state code (new, unchanged, updated, absent)", "Matching method" ] }, { "id": "fir-q-repeat", "text": "Is this a repeat finding, and how many consecutive engagements has it persisted through?", "kind": "state", "answer_data": [ "Repeat flag", "First-raised engagement reference", "Consecutive occurrence count", "Ageing since first raised" ] }, { "id": "fir-q-suppression", "text": "Has the finding been suppressed, accepted or excluded from reporting, on whose authority and with what justification?", "kind": "authority", "answer_data": [ "Suppression status", "Justification", "Authorising party", "Validity period of the suppression" ] } ], "data_elements": [ { "id": "de-recurrence-key", "name": "recurrence_key", "description": "Stable computed key enabling matching of the same underlying issue across engagements and revisions.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-baseline-state", "name": "baseline_state", "description": "Comparison state of the finding relative to a nominated baseline engagement.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-suppression", "name": "suppression_record", "description": "Suppression or reporting-exclusion decision with justification, authorising party and validity period.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "Recurrence keys, baseline states and suppression decisions are computed or decided attributes carried on the finding record and on the engagement-to-engagement comparison. They have no independent document existence, and materialising them separately would let the derived state diverge from the finding it describes." } ] }, { "id": "conclusion-and-reporting", "name": "Conclusion and reporting", "description": "Aggregation of findings into an engagement-level conclusion at a stated assurance level, and the issuance of the report or certificate with responsible-party views and use restrictions.", "source_refs": [ "SRC-007", "SRC-012", "SRC-006", "SRC-013" ], "findings": [ { "id": "engagement-conclusion-and-assurance-statement", "name": "Engagement conclusion and assurance statement", "description": "How individual findings aggregate into an overall conclusion or opinion, at what assurance level, with what modifications and emphases.", "source_refs": [ "SRC-007", "SRC-012", "SRC-010", "SRC-002" ], "questions": [ { "id": "eca-q-conclusion", "text": "What is the overall conclusion or opinion, and how does it follow from the findings and their severity?", "kind": "decision", "answer_data": [ "Conclusion statement", "Aggregation rule applied", "Findings that drive the conclusion", "Opinion type code" ] }, { "id": "eca-q-assurance", "text": "What level of assurance is expressed, and does it match the level planned?", "kind": "quality", "answer_data": [ "Assurance level expressed", "Planned versus expressed comparison", "Explanation of any reduction" ] }, { "id": "eca-q-modification", "text": "Is the conclusion modified, qualified, adverse or a disclaimer, and on what grounds?", "kind": "exception", "answer_data": [ "Modification type", "Grounds for modification", "Affected scope areas", "Emphasis or other-matter paragraphs" ] }, { "id": "eca-q-attestation", "text": "Which assertions does the examining party itself attest to, and who signs them?", "kind": "authority", "answer_data": [ "Attestation statements", "Signing party reference", "Signature timestamp", "Basis for the attestation" ] } ], "data_elements": [ { "id": "de-conclusion", "name": "engagement_conclusion", "description": "Overall conclusion or opinion with its type, aggregation rule and driving findings.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-012" ] }, { "id": "de-conclusion-modification", "name": "conclusion_modification", "description": "Modification, qualification, adverse conclusion or disclaimer with its grounds and affected scope.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-attestation", "name": "attestation_statements", "description": "Assertions made by the examining party, with signing party and signature timestamp.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [], "inline_only_rationale": "The conclusion is a structured statement carried on the engagement record so that it remains machine-comparable and independent of any rendering. It is presented inside the report artifact, but treating the rendered text as authoritative would make the conclusion format-dependent and would break comparison across engagements." }, { "id": "report-issuance-views-and-use-restrictions", "name": "Report issuance, responsible-party views and use restrictions", "description": "Issuance of the engagement report or certificate, incorporation of the responsible party's views, and the restrictions on distribution, reliance and publication attached to it.", "source_refs": [ "SRC-012", "SRC-007", "SRC-006", "SRC-013" ], "questions": [ { "id": "riv-q-issue", "text": "Who issues the report or certificate, to which addressees, and on what date does it take effect?", "kind": "event", "answer_data": [ "Issuing party reference", "Addressee and intended-user references", "Issue timestamp", "Effective and expiry dates" ] }, { "id": "riv-q-views", "text": "How were the responsible party's views obtained and represented, including any disagreement?", "kind": "process", "answer_data": [ "Request-for-comment timestamp", "Response received timestamp", "Verbatim or summarised views", "Disagreement statement and auditor rebuttal" ] }, { "id": "riv-q-restrictions", "text": "What restrictions govern reliance, onward distribution, publication and use of the report or certificate?", "kind": "access", "answer_data": [ "Reliance restriction text", "Permitted recipients", "Publication permission and redaction rules", "Confidentiality classification" ] }, { "id": "riv-q-mandatory", "text": "Which mandatory content and statements must the report carry under the governing standard or law?", "kind": "requirement", "answer_data": [ "Mandatory content checklist", "Governing standard reference", "Compliance statement wording", "Grounds statement where a measure may follow" ] } ], "data_elements": [ { "id": "de-issuance", "name": "issuance_record", "description": "Issuing party, addressees, issue timestamp and effective or expiry dates of the report or certificate.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-013" ] }, { "id": "de-responsible-party-views", "name": "responsible_party_views", "description": "Views, comments or disagreement of the responsible party, with request and response timestamps.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-006" ] }, { "id": "de-use-restrictions", "name": "use_restrictions", "description": "Reliance, distribution, publication and confidentiality restrictions attached to the issued output.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-013" ] } ], "artifacts": [ { "id": "engagement-report", "name": "Engagement report", "description": "The issued report communicating scope, criteria, work performed, findings, conclusion, responsible-party views and restrictions on use, in whatever rendering the recipient requires.", "media_or_form": [ "report document", "structured assessment result record", "published summary" ], "serial": false, "identity_strategy": "Identified by engagement identifier plus report version; each issued version is sealed with a digest, records its issue timestamp and issuing party, and supersedes rather than replaces earlier versions.", "source_refs": [ "SRC-012", "SRC-007", "SRC-002" ] }, { "id": "inspection-certificate-or-attestation", "name": "Inspection certificate or attestation", "description": "A short-form issued statement of the examination outcome for a specific item, batch, installation or system, typically with validity dates and defined reliance conditions.", "media_or_form": [ "certificate", "attestation record", "signed statement" ], "serial": true, "identity_strategy": "Identified by the issuing body's certificate number where one exists, otherwise a surrogate, always bound to the engagement identifier and to the examined subject reference. The certification decision lifecycle remains with the certification model.", "source_refs": [ "SRC-013", "SRC-014", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "lifecycle-governance-and-exchange", "name": "Lifecycle, record governance and exchange", "description": "The engagement state machine and closure, redress and follow-up, the provenance, retention and quality governance of the engagement record set, and its exchange with other systems and standards.", "rationale": "OSCAL requires the root identifier and last-modified value to change on every content change, PROV-O supplies the vocabulary for attributing that change, EU market surveillance grants a right to be heard and requires follow-up of complaints and verification of corrective action, and GAGAS 2024 introduces a risk-based system of quality management with optional engagement quality reviews. Exchange with SARIF, OSCAL and PROV is what makes findings comparable beyond the issuing organisation.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-015", "SRC-004" ], "layers": [ { "id": "engagement-lifecycle-and-redress", "name": "Engagement lifecycle and redress", "description": "States the engagement passes through, the recommendations it leaves behind and their verification, and the routes by which its results can be contested.", "source_refs": [ "SRC-002", "SRC-006", "SRC-008" ], "findings": [ { "id": "engagement-state-model-and-closure", "name": "Engagement state model and closure", "description": "The permitted states of an engagement, the transitions between them, who may effect each transition, and the conditions for closure or abandonment.", "source_refs": [ "SRC-002", "SRC-003", "SRC-008", "SRC-012" ], "questions": [ { "id": "esm-q-states", "text": "Which states may an engagement occupy, and which transitions are permitted between them?", "kind": "state", "answer_data": [ "State value set", "Permitted transition pairs", "Entry and exit conditions per state" ] }, { "id": "esm-q-authority", "text": "Who is authorised to effect each transition, and what evidence must exist before it is allowed?", "kind": "authority", "answer_data": [ "Authorised role per transition", "Preconditions to be satisfied", "Approval record reference" ] }, { "id": "esm-q-closure", "text": "What conditions must hold for the engagement to be closed, and what remains open after closure?", "kind": "lifecycle", "answer_data": [ "Closure criteria", "Closure timestamp and approver", "Open items carried forward", "Reopening conditions" ] }, { "id": "esm-q-abandon", "text": "How is an engagement suspended, withdrawn or abandoned, and how is partial work disclosed?", "kind": "exception", "answer_data": [ "Termination reason code", "Deciding party", "Disclosure obligation to intended users", "Status of partial results" ] } ], "data_elements": [ { "id": "de-engagement-state", "name": "engagement_state", "description": "Current lifecycle state of the engagement drawn from a governed value set.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-008" ] }, { "id": "de-state-transitions", "name": "state_transitions", "description": "Ordered transition history with actor, timestamp, preconditions satisfied and approval reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-002" ] } ], "artifacts": [], "inline_only_rationale": "Lifecycle state and its transition history are governed attributes of the engagement aggregate, expressed as a code plus an append-only transition list. A separate artifact would create a second source of truth for status; the platform workflow engine that drives transitions is referenced, not owned, by this model." }, { "id": "recommendation-issuance-and-followup-verification", "name": "Recommendation issuance and follow-up verification", "description": "Recommendations or required actions arising from findings, and the later verification that claimed remediation is evidenced, without owning the remediation work itself.", "source_refs": [ "SRC-008", "SRC-006", "SRC-002", "SRC-012" ], "questions": [ { "id": "rif-q-recommendation", "text": "What recommendation or required action does each finding carry, addressed to whom and by when?", "kind": "requirement", "answer_data": [ "Recommendation text", "Addressee party reference", "Requested completion date", "Linked finding reference" ] }, { "id": "rif-q-boundary", "text": "Which model owns the planning, execution and closure of the resulting action, and what is referenced from here?", "kind": "ownership", "answer_data": [ "Owning remediation or enforcement model reference", "Action identifier in that model", "Fields carried locally versus referenced" ] }, { "id": "rif-q-verification", "text": "How and when is implementation verified, by which procedure, and with what evidence?", "kind": "validation", "answer_data": [ "Verification method", "Verification timestamp", "Verifying party", "Evidence references", "Verification outcome code" ] }, { "id": "rif-q-escalation", "text": "What happens when verification fails or the deadline passes, and to whom is it escalated?", "kind": "process", "answer_data": [ "Escalation route", "Escalation trigger condition", "Recipient of escalation", "Reference to the enforcement or governance model that acts" ] } ], "data_elements": [ { "id": "de-recommendation", "name": "recommendation", "description": "Recommendation or required action linked to a finding, with addressee and requested completion date.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-006" ] }, { "id": "de-remediation-reference", "name": "remediation_reference", "description": "Reference to the action record in the owning remediation, corrective-action or enforcement model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-002" ] }, { "id": "de-verification-outcome", "name": "followup_verification_outcome", "description": "Outcome of verifying claimed implementation, with method, verifying party, timestamp and evidence links.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-008" ] } ], "artifacts": [ { "id": "recommendation-record", "name": "Recommendation record", "description": "A single recommendation or required action arising from a finding, with addressee, requested completion date and a reference to the action record owned by the remediation model.", "media_or_form": [ "structured recommendation record", "report section", "action request notice" ], "serial": true, "identity_strategy": "Surrogate identifier scoped by the engagement identifier and bound to the originating finding identifier; carries a reference to, and never a copy of, the action record in the owning remediation model.", "source_refs": [ "SRC-008", "SRC-006" ] }, { "id": "followup-verification-record", "name": "Follow-up verification record", "description": "Record of a verification act confirming or rejecting claimed implementation, with method, evidence and outcome. It records verification only; it does not close the underlying action.", "media_or_form": [ "structured verification record", "follow-up engagement result" ], "serial": true, "identity_strategy": "Surrogate identifier scoped by the recommendation identifier plus verification sequence; where verification is performed as a distinct engagement, also carries that engagement's identifier.", "source_refs": [ "SRC-006", "SRC-008", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "right-to-be-heard-appeals-and-complaints", "name": "Right to be heard, appeals and complaints", "description": "Procedural rights of the responsible party before and after a result is recorded, and the handling of appeals against a determination or complaints about the conduct of the engagement.", "source_refs": [ "SRC-006", "SRC-013", "SRC-012", "SRC-014" ], "questions": [ { "id": "rha-q-hearing", "text": "Was the affected party given the opportunity to be heard before the result was acted on, with what notice period?", "kind": "process", "answer_data": [ "Notice issued timestamp", "Grounds communicated", "Response window granted", "Response received or waived" ] }, { "id": "rha-q-appeal", "text": "Who may appeal which determination, to which body, and within what time limit?", "kind": "authority", "answer_data": [ "Appellant eligibility", "Appealable determination references", "Appeal body reference", "Time limit and computation basis" ] }, { "id": "rha-q-independence", "text": "How is the appeal or complaint reviewed independently of the individuals who produced the original result?", "kind": "constraint", "answer_data": [ "Reviewer independence declaration", "Exclusion of original engagement team", "Escalation to an external body" ] }, { "id": "rha-q-outcome", "text": "What outcomes can an appeal produce, and how are they reflected in the engagement record and any issued output?", "kind": "lifecycle", "answer_data": [ "Outcome code (upheld, partially upheld, rejected, withdrawn)", "Amendment or withdrawal of the finding or report", "Notification obligations", "Outcome timestamp" ] } ], "data_elements": [ { "id": "de-hearing-record", "name": "hearing_record", "description": "Notice, grounds communicated, response window and response for the affected party's right to be heard.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-appeal-case", "name": "appeal_case", "description": "Appeal or complaint with appellant, target determination, reviewing body, independence basis and outcome.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-013" ] } ], "artifacts": [ { "id": "appeal-or-complaint-case-record", "name": "Appeal or complaint case record", "description": "Record of an appeal against a determination or a complaint about the conduct of the engagement, including independence of the reviewer, outcome and any consequent amendment or withdrawal.", "media_or_form": [ "case record", "structured appeal record", "decision notice" ], "serial": true, "identity_strategy": "Identified by the handling body's case reference where one exists, otherwise a surrogate; bound to the engagement identifier and to the specific determination or finding contested.", "source_refs": [ "SRC-006", "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null } ] }, { "id": "record-governance-and-quality", "name": "Record governance and quality", "description": "Provenance and amendment of the engagement record set, its retention classification and disposition, and the quality review that supports reliance on it.", "source_refs": [ "SRC-002", "SRC-005", "SRC-015", "SRC-012", "SRC-007" ], "findings": [ { "id": "record-provenance-versioning-and-amendment", "name": "Record provenance, versioning and amendment", "description": "How every change to the engagement record set is attributed, timestamped and versioned, and how an issued output is corrected without rewriting history.", "source_refs": [ "SRC-002", "SRC-005", "SRC-001", "SRC-004" ], "questions": [ { "id": "rpv-q-attribution", "text": "Which agent generated or modified each record, acting on behalf of which organisation?", "kind": "provenance", "answer_data": [ "Agent reference", "Delegation or acted-on-behalf-of relation", "Activity reference", "Generation timestamp" ] }, { "id": "rpv-q-version", "text": "How is a content change signalled, and what identifier and modification timestamp must change with it?", "kind": "validation", "answer_data": [ "Record version identifier", "Last-modified timestamp", "Change signalling rule", "Digest of the canonical form" ] }, { "id": "rpv-q-amendment", "text": "How is an issued report or finding corrected, withdrawn or re-issued, and how is the original preserved?", "kind": "lifecycle", "answer_data": [ "Amendment type code (erratum, correction, withdrawal, re-issue)", "Reason for amendment", "Superseded version reference", "Notification to prior recipients" ] }, { "id": "rpv-q-derivation", "text": "From which prior records is this record derived, including imported plans and prior engagements?", "kind": "relationship", "answer_data": [ "Derived-from references", "Imported plan reference", "Prior engagement reference", "Derivation description" ] } ], "data_elements": [ { "id": "de-record-provenance", "name": "record_provenance", "description": "Agent, activity, delegation and timing information attributing generation and modification of each record.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-002" ] }, { "id": "de-record-version", "name": "record_version", "description": "Version identifier and last-modified timestamp that must change whenever record content changes.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-001" ] }, { "id": "de-amendment", "name": "amendment_record", "description": "Amendment, withdrawal or re-issue of a previously issued output, with reason, superseded version and recipient notification.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "Provenance and version metadata are properties of every record in the aggregate rather than a document in their own right. Externalising them would decouple attribution from the record it attributes; the platform activity log that records who touched a record is referenced by, and not owned by, this model." }, { "id": "retention-disposition-and-legal-hold", "name": "Retention, disposition and legal hold", "description": "Classification of engagement records for retention, the trigger and period that govern disposition, and holds that suspend it, without asserting ownership of disposal execution.", "source_refs": [ "SRC-006", "SRC-012", "SRC-007", "SRC-002" ], "questions": [ { "id": "rdl-q-class", "text": "Which retention class applies to each record type in this engagement, and which schedule authority defines it?", "kind": "retention", "answer_data": [ "Retention class code per record type", "Schedule authority reference", "Jurisdiction", "Minimum retention period" ] }, { "id": "rdl-q-trigger", "text": "What event starts the retention clock, and when does the disposition become due?", "kind": "temporal", "answer_data": [ "Retention trigger event code", "Trigger timestamp", "Computed disposition due date", "Recomputation rule on re-issue" ] }, { "id": "rdl-q-hold", "text": "Is a legal, regulatory or appeal-related hold in force, who placed it and when may it be released?", "kind": "exception", "answer_data": [ "Hold status", "Placing authority", "Placement timestamp", "Release condition and timestamp" ] }, { "id": "rdl-q-execution", "text": "Which model or Dimension policy executes disposition, and what tombstone remains here afterwards?", "kind": "ownership", "answer_data": [ "Owning records-management model or policy reference", "Tombstone content specification", "Disposition confirmation reference", "Fields retained for referential integrity" ] }, { "id": "rdl-q-personal", "text": "How are personal-data minimisation and erasure obligations reconciled with evidentiary retention duties?", "kind": "privacy", "answer_data": [ "Personal-data inventory reference", "Legal basis for continued retention", "Redaction or pseudonymisation applied", "Conflict resolution decision and approver" ] } ], "data_elements": [ { "id": "de-retention-class", "name": "retention_class", "description": "Retention classification per record type with schedule authority, jurisdiction and minimum period.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-006" ] }, { "id": "de-retention-trigger", "name": "retention_trigger", "description": "Event that starts the retention clock and the computed disposition due date.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-legal-hold", "name": "legal_hold", "description": "Hold suspending disposition, with placing authority, placement timestamp and release condition.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Retention is expressed as classification and hold attributes plus references to an externally owned retention schedule. This model deliberately holds no disposal artifact because the execution of destruction, transfer and disposal certification belongs to the records-management model and the adopting Dimension's policy, and claiming an artifact here would imply ownership of that execution." }, { "id": "engagement-quality-review-and-competence-evidence", "name": "Engagement quality review and competence evidence", "description": "The review performed on the engagement itself before issuance and the evidence that assigned personnel were competent for it, as required by a risk-based system of quality management.", "source_refs": [ "SRC-015", "SRC-012", "SRC-008", "SRC-007" ], "questions": [ { "id": "eqr-q-review", "text": "Was an engagement quality review performed, by whom, and what was its scope and conclusion?", "kind": "quality", "answer_data": [ "Review performed flag", "Reviewer reference and independence basis", "Review scope", "Review conclusion and timestamp" ] }, { "id": "eqr-q-trigger", "text": "Under which risk-based criteria is an engagement quality review required rather than optional?", "kind": "requirement", "answer_data": [ "Triggering criteria", "Governing standard reference", "Decision and approver", "Documented rationale where not performed" ] }, { "id": "eqr-q-competence", "text": "What evidence shows that each assigned individual was competent for their engagement role?", "kind": "evidence", "answer_data": [ "Competence evidence references in the owning party model", "Role-specific competence requirement", "Assessment or confirmation timestamp" ] }, { "id": "eqr-q-supervision", "text": "How was the work supervised and reviewed within the engagement team before conclusions were formed?", "kind": "process", "answer_data": [ "Supervision structure", "Working-paper review records", "Unresolved matters escalated", "Sign-off timestamps" ] } ], "data_elements": [ { "id": "de-quality-review", "name": "engagement_quality_review", "description": "Record of the engagement quality review with reviewer, independence basis, scope, conclusion and timestamp.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015", "SRC-012" ] }, { "id": "de-competence-evidence-ref", "name": "competence_evidence_references", "description": "References into the owning party or competence model demonstrating role fitness for this engagement.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-007" ] } ], "artifacts": [ { "id": "engagement-quality-review-record", "name": "Engagement quality review record", "description": "The record of the review of the engagement performed before issuance, covering scope, significant judgements examined, matters raised and the reviewer's conclusion.", "media_or_form": [ "structured review record", "review checklist", "sign-off memorandum" ], "serial": false, "identity_strategy": "Identified by engagement identifier plus review sequence; bound to the reviewer party reference and to the report version it clears for issue.", "source_refs": [ "SRC-015", "SRC-012", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "exchange-and-alignment", "name": "Exchange and alignment", "description": "How engagement records are projected onto external exchange standards without asserting conformance, and where those mappings lose information.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ], "findings": [ { "id": "exchange-binding-and-standard-crosswalk", "name": "Exchange binding and standard crosswalk", "description": "Declared mappings between this model's concepts and external exchange formats and ontologies, with explicit statements of lossiness, direction and version dependence.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-010", "SRC-006" ], "questions": [ { "id": "ebs-q-target", "text": "Which external standard and version is each binding declared against, and in which direction is it valid?", "kind": "interoperability", "answer_data": [ "Target standard identifier and version", "Direction (export, import, bidirectional)", "Binding version", "Maintainer of the binding" ] }, { "id": "ebs-q-mapping", "text": "Which local concept maps to which target construct, and which local concepts have no target equivalent?", "kind": "composition", "answer_data": [ "Concept-to-construct mapping entries", "Unmapped local concepts", "Unmapped target constructs", "Default values supplied on export" ] }, { "id": "ebs-q-loss", "text": "Where is the mapping lossy or semantically approximate, and what is the effect on a consumer?", "kind": "quality", "answer_data": [ "Lossy mapping entries", "Nature of the loss", "Consumer impact statement", "Mitigation or accompanying note" ] }, { "id": "ebs-q-conformance", "text": "What conformance is claimed, and what evidence supports the claim?", "kind": "validation", "answer_data": [ "Conformance claim level (aligned, partially conformant, none claimed)", "Validation evidence reference", "Validating party and timestamp" ] }, { "id": "ebs-q-transmission", "text": "Under what conditions may an engagement record be transmitted to another authority or system, and what must accompany it?", "kind": "access", "answer_data": [ "Permitted destination systems or authorities", "Legal or contractual gateway", "Mandatory accompanying metadata", "Onward-use conditions" ] } ], "data_elements": [ { "id": "de-binding-target", "name": "binding_target", "description": "External standard identifier, version and mapping direction for a declared exchange binding.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] }, { "id": "de-mapping-entries", "name": "mapping_entries", "description": "Concept-to-construct mapping entries with lossiness annotations and unmapped-concept lists.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-001" ] }, { "id": "de-conformance-claim", "name": "conformance_claim", "description": "Declared conformance level with supporting validation evidence, validating party and timestamp.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-010" ] } ], "artifacts": [ { "id": "exchange-binding-profile", "name": "Exchange binding profile", "description": "A versioned, machine-readable crosswalk from this model's concepts to an external target such as OSCAL assessment results, SARIF results or PROV-O, with lossiness annotations and the conformance level actually claimed.", "media_or_form": [ "mapping table", "structured binding profile", "transformation definition" ], "serial": false, "identity_strategy": "Identified by target standard identifier plus target version plus binding version; each binding is independently versioned from the model so a target revision does not force a model revision.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-engagement", "name": "Register engagement", "description": "Create the engagement aggregate root with its identity, classification, mandate reference and party roles, making it addressable before any planning or fieldwork occurs.", "inputs": [ "Authority basis and authorising instrument reference", "Engagement type and intended assurance level", "Party references for auditor, responsible party and intended users", "Master-system identifier if issued, otherwise a minted surrogate" ], "outputs": [ "Registered engagement record with resolved identifier", "Initial lifecycle state", "Provenance entry attributing creation" ], "preconditions": [ "An authorising instrument or designation exists and is referenced", "The issuing system for the identifier is declared", "Engagement type maps to a governing requirement standard" ], "effects": [ "Engagement becomes addressable and referenceable by other records", "Identifier and issuing authority are fixed and thereafter immutable", "Lifecycle state set to the initial planned or commissioned state" ], "source_refs": [ "SRC-002", "SRC-006", "SRC-007", "SRC-013" ] }, { "id": "bind-criteria-set", "name": "Bind criteria set", "description": "Resolve and attach the criteria and control objectives in scope for the engagement, each bound to an external source identifier and version, with tailoring decisions and local interpretations recorded.", "inputs": [ "Criteria source references and versions", "Selection, profile or tailoring decisions", "Approver reference" ], "outputs": [ "Engagement criteria register", "Suitability assessment record", "Traceability links from objectives to criteria" ], "preconditions": [ "Engagement is registered", "Criteria sources resolve to a specific version", "Selection is approved by an authorised role" ], "effects": [ "Findings can be created only against bound criteria", "Criteria versions are pinned for the engagement, insulating it from later catalogue revisions", "No criterion text is copied locally; only bindings and interpretations are stored" ], "source_refs": [ "SRC-003", "SRC-009", "SRC-007", "SRC-010" ] }, { "id": "record-observation", "name": "Record observation", "description": "Capture an atomic observation with its collection method, subject, origin actor or tool, supporting evidence references and separated event, collection and ingestion timestamps.", "inputs": [ "Observation description and type", "Collection method and origin", "Subject reference", "Evidence item references", "Event, collection and ingestion timestamps" ], "outputs": [ "Observation record", "Evidence-to-observation links", "Fieldwork execution log entry" ], "preconditions": [ "Engagement is in an executing state", "Collection method is one declared in the method and sampling protocol", "Any evidence item referenced has an integrity digest recorded" ], "effects": [ "Observation becomes available for finding construction", "Execution log gains an append-only entry", "No conformity judgement is asserted by this operation" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-005" ] }, { "id": "appraise-evidence", "name": "Appraise evidence", "description": "Record the judgement of relevance, reliability, sufficiency and appropriateness for evidence supporting an objective, together with limitations and unavailable evidence.", "inputs": [ "Evidence item and observation references", "Objective or criterion reference", "Assessor reference" ], "outputs": [ "Appraisal attributes on evidence links", "Sufficiency conclusion", "Recorded evidence limitations" ], "preconditions": [ "Observations and evidence items exist", "The targeted assurance level is declared", "Assessor is assigned to an engagement role" ], "effects": [ "Sufficiency conclusion becomes a precondition for issuing an engagement conclusion", "Limitations propagate to scope and to any conclusion modification", "Appraisal is attributed to a named assessor and timestamp" ], "source_refs": [ "SRC-007", "SRC-012", "SRC-010" ] }, { "id": "construct-finding-and-determine-conformity", "name": "Construct finding and determine conformity", "description": "Assemble criterion, condition, cause and effect into a finding, attach the supporting observations, apply the documented decision rule and record the determination and severity grade.", "inputs": [ "Bound criterion reference", "Supporting observation references", "Decision rule and materiality statement reference", "Determination and grading value sets" ], "outputs": [ "Finding record with determination and severity", "Recurrence key and baseline state", "Traceability links to observations and evidence" ], "preconditions": [ "Criterion is bound with a pinned version", "At least one supporting observation exists", "A decision rule is referenced where a measured characteristic is involved" ], "effects": [ "Finding becomes citable by recommendations, reports and appeals", "Recurrence key enables cross-engagement matching", "Grounds are stated precisely enough to support a contested response" ], "source_refs": [ "SRC-001", "SRC-004", "SRC-012", "SRC-011", "SRC-006" ] }, { "id": "issue-conclusion-and-report", "name": "Issue conclusion and report", "description": "Aggregate findings into an engagement conclusion at a stated assurance level, incorporate the responsible party's views, and issue the sealed report or certificate with its use restrictions.", "inputs": [ "Finding set with determinations", "Sufficiency conclusion", "Responsible-party views", "Addressee and intended-user references", "Use and distribution restrictions" ], "outputs": [ "Engagement conclusion statement", "Sealed engagement report version", "Inspection certificate or attestation where applicable" ], "preconditions": [ "Evidence sufficiency is concluded", "Responsible party has been given the opportunity to comment", "Any required engagement quality review has been completed" ], "effects": [ "Report version is sealed with a digest and becomes immutable", "Findings become append-only; later change requires an amendment or re-issue", "Certification and enforcement decisions that may follow remain owned by their models" ], "source_refs": [ "SRC-012", "SRC-007", "SRC-002", "SRC-015", "SRC-006" ] }, { "id": "register-appeal", "name": "Register appeal or complaint", "description": "Record a challenge to a determination or to the conduct of the engagement, assign an independent reviewer, and capture the outcome and any consequent amendment.", "inputs": [ "Appellant reference", "Contested determination or finding reference", "Grounds of appeal", "Receipt timestamp" ], "outputs": [ "Appeal or complaint case record", "Reviewer independence declaration", "Outcome and any amendment or withdrawal reference" ], "preconditions": [ "The contested determination exists and is identified", "The appellant is eligible under the declared appeal route", "The assigned reviewer is independent of the original engagement team" ], "effects": [ "Disposition of the affected records is suspended while the appeal is open", "An upheld appeal triggers an amendment, re-issue or withdrawal", "This model records the appeal outcome; it does not conduct legal proceedings or enforcement" ], "source_refs": [ "SRC-006", "SRC-013", "SRC-014" ] }, { "id": "record-followup-verification", "name": "Record follow-up verification", "description": "Record a verification act testing whether claimed implementation of a recommendation is evidenced, and its outcome, without changing the state of the action in the owning remediation model.", "inputs": [ "Recommendation reference", "Remediation action reference in the owning model", "Verification method and evidence references", "Verifying party and timestamp" ], "outputs": [ "Follow-up verification record", "Verification outcome code", "New observations where the verification generates evidence" ], "preconditions": [ "A recommendation exists and is addressed to a party", "The remediation action is referenced rather than duplicated", "The verifying party is authorised for this engagement or its follow-up engagement" ], "effects": [ "Verification outcome is available to escalation and programme reporting", "No action state in the remediation model is written by this operation", "Failed verification may trigger a new engagement or an escalation reference" ], "source_refs": [ "SRC-006", "SRC-008", "SRC-012" ] }, { "id": "close-engagement", "name": "Close engagement", "description": "Transition the engagement to a closed state once closure criteria are met, fixing open items, retention triggers and the record set that must be preserved.", "inputs": [ "Closure criteria evaluation", "Approver reference", "Open item list", "Retention trigger event" ], "outputs": [ "Closed engagement state with closure timestamp", "Retention trigger timestamp and computed disposition due date", "Carried-forward open items" ], "preconditions": [ "Report or certificate has been issued, or a documented termination reason exists", "No unresolved appeal is open unless explicitly carried forward", "Retention class has been assigned to each record type" ], "effects": [ "Record set becomes read-only except through amendment or appeal outcomes", "Retention clock starts and disposition due date is computed", "Reopening requires an authorised transition with a recorded reason" ], "source_refs": [ "SRC-002", "SRC-008", "SRC-012", "SRC-006" ] }, { "id": "export-engagement-record", "name": "Export engagement record to a binding target", "description": "Project the engagement record set onto a declared external exchange binding, applying the versioned crosswalk and emitting the lossiness notes and conformance level actually claimed.", "inputs": [ "Engagement record set", "Target standard identifier and version", "Binding profile version", "Recipient and permitted-use context" ], "outputs": [ "Target-format representation", "Lossiness report", "Conformance claim statement" ], "preconditions": [ "A binding profile exists for the target standard and version", "Use and distribution restrictions permit the transmission", "Sensitivity classification has been evaluated for the recipient" ], "effects": [ "No source record is modified; the export is a projection", "Unmapped concepts are reported rather than silently dropped", "Conformance is claimed only at the level supported by recorded validation evidence" ], "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ] } ], "composition": [ { "target": "WM-ACT-009 (registered parent activity model)", "relation": "CHILD", "purpose": "Inherit generic activity semantics - occurrence identity, actor participation, temporal bounds and lifecycle - and specialise them for evidence-against-criteria examination. Generic activity machinery is not redefined here.", "required": true, "source_refs": [ "SRC-005", "SRC-007", "SRC-008" ] }, { "target": "Requirement, regulation and control-catalogue model", "relation": "REFERENCE", "purpose": "Resolve each criterion to an external source identifier and version. This model carries the binding, the selection or tailoring decision and any engagement-local interpretation; it never holds requirement text or the catalogue's own version lifecycle.", "required": true, "source_refs": [ "SRC-003", "SRC-009", "SRC-013" ] }, { "target": "Examined subject model (product, asset, system, process, organisation)", "relation": "REFERENCE", "purpose": "Identify assessment subjects by their master identifiers so that findings attach to the authoritative record. Subject state, configuration history and lifecycle remain with the owning model.", "required": true, "source_refs": [ "SRC-003", "SRC-002", "SRC-006" ] }, { "target": "Party, role and competence model", "relation": "REFERENCE", "purpose": "Resolve auditors, inspectors, responsible parties and intended users, and point to competence evidence. Qualification, training and competence-registry lifecycle stay with the party model; only engagement-scoped appointment and impartiality declarations are held here.", "required": true, "source_refs": [ "SRC-007", "SRC-008", "SRC-013" ] }, { "target": "Corrective action and remediation model", "relation": "REFERENCE", "purpose": "Link a recommendation to the action record that will be planned, executed and closed elsewhere. This model records issuance and verification observations only, never action state, ownership or closure.", "required": false, "source_refs": [ "SRC-006", "SRC-008" ] }, { "target": "Risk register and risk treatment model", "relation": "REFERENCE", "purpose": "Hand over engagement-scoped risk statements for treatment and residual-risk acceptance. Risk scoring policy, treatment decisions and register lifecycle are not owned here.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "Test, measurement and laboratory result model", "relation": "REFERENCE", "purpose": "Consume measured values with their stated uncertainty as evidence. Method validation, calibration traceability and uncertainty evaluation remain with the measurement model; only the decision rule application is local.", "required": false, "source_refs": [ "SRC-011", "SRC-006" ] }, { "target": "Certification, approval and accreditation model", "relation": "REFERENCE", "purpose": "Carry the reference from an issued certificate or attestation to the certification decision it feeds, and from the examining body to its accreditation scope. Grant, suspension and withdrawal lifecycles are not owned here.", "required": false, "source_refs": [ "SRC-013", "SRC-014" ] }, { "target": "Enforcement, measure and sanction model", "relation": "REFERENCE", "purpose": "Supply the evidenced determination and stated grounds that an enforcement measure may cite. Deciding, imposing, appealing at law and executing measures such as withdrawal or recall are entirely outside this model.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "Audit programme and assurance plan model", "relation": "REFERENCE", "purpose": "Place the engagement within a multi-engagement programme for prioritisation and coverage reporting. Programme risk assessment, resourcing and its own lifecycle are not modelled here.", "required": false, "source_refs": [ "SRC-006", "SRC-008", "SRC-007" ] }, { "target": "Records management, retention schedule and disposition model", "relation": "REFERENCE", "purpose": "Resolve retention classes and hand disposition execution to the owning records model or adopting-Dimension policy. This model holds classification, trigger, hold state and tombstone specification only.", "required": true, "source_refs": [ "SRC-012", "SRC-006" ] }, { "target": "W3C PROV-O provenance ontology", "relation": "ALIGN", "purpose": "Express the engagement as prov:Activity, evidence and reports as prov:Entity, and auditors and bodies as prov:Agent, using wasGeneratedBy, used, wasAttributedTo and actedOnBehalfOf. Alignment only; provenance reasoning semantics are not reproduced.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "NIST OSCAL assessment-plan and assessment-results models", "relation": "ALIGN", "purpose": "Map plan, observation, finding, risk, reviewed-controls, attestation and assessment-log constructs for exchange in control-assessment contexts. Alignment is versioned separately and no conformance is claimed without validation evidence.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003" ] }, { "target": "OASIS SARIF v2.1.0 result interchange format", "relation": "ALIGN", "purpose": "Map findings onto result objects with ruleId, level, kind, locations, fingerprints and baselineState for tool-generated inspection results. The mapping is lossy for pass-type results and is annotated as such.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "OMG Structured Assurance Case Metamodel (SACM) 2.3", "relation": "ALIGN", "purpose": "Express the criteria-to-evidence reasoning of a conclusion as claims, argument and evidence when a structured assurance case is required by the recipient. Argumentation semantics remain owned by SACM.", "required": false, "source_refs": [ "SRC-010" ] }, { "target": "Record provenance and versioning mix-in", "relation": "MIX-IN", "purpose": "Apply a common attribution, version-identifier and last-modified pattern to every record in the aggregate so that any content change is signalled uniformly, as OSCAL requires of its root elements.", "required": true, "source_refs": [ "SRC-002", "SRC-005" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension must designate a named accountable owner for the engagement record set who is organisationally separate from the engagement team, and record that owner in the package manifest alongside the escalation route.", "The owner package must declare which authoritative master system issues engagement identifiers, which surrogate scheme is used when none exists, and which value sets govern engagement type, determination, severity and lifecycle state, each pinned to a version.", "The owner package must declare every referenced model it depends on - criteria catalogue, examined subject, party, remediation, risk, measurement, certification, enforcement, programme and records management - and must not fork or copy their content into this model.", "The owner package must declare the applicable jurisdictions, the governing requirement standard per engagement type, and the retention schedule authority, since none of these are universal and all change the obligations." ], "namespace_guidance": "Use a Dimension-controlled namespace of the form /wm-act-033// for locally minted identifiers and code values, and never mint identifiers inside an external standard's namespace. External criteria, control, rule and subject identifiers are carried verbatim in their own namespace with the source version attached. Exchange binding profiles are namespaced by target standard and target version so that a target revision does not collide with an existing binding.", "registry_links": [ "Registry entry vr.wm-act-033 (WM-ACT-033, nav path NAV.ACT.REV, domain tag ACT.REV) is the authoritative record for this model's status and review state.", "Parent registry entry WM-ACT-009 governs the generic activity semantics this model specialises.", "Each ALIGN target is registered as an external alignment with its standard identifier, version and the binding profile version, so that alignment drift is visible without editing the model." ] }, "canon_and_patch": { "canonicalization_rules": [ "Serialise records with deterministic member ordering and Unicode NFC text normalisation before computing any digest, so that a digest is stable across JSON, YAML and document projections.", "Normalise all time values to RFC 3339 with whole seconds and an explicit offset, and retain the originally recorded offset as a separate field where local time carries evidential meaning such as a site visit hour.", "Normalise identifiers by trimming whitespace and preserving case exactly as issued by the master system; never case-fold an externally issued identifier.", "Exclude volatile transport fields such as retrieval timestamps and cache markers from the canonical form used for sealing an issued report." ], "patch_rules": [ "Observations, evidence items, custody entries and execution-log entries are append-only from the moment they are recorded; a correction is a new entry that references and supersedes the original.", "After a report version is issued and sealed, findings and conclusions may not be mutated in place; change requires an erratum, correction, withdrawal or re-issue that names the superseded version and the reason.", "Every patch must carry the acting agent, the activity, the modification timestamp and a new record version identifier; a content change without a version and last-modified change is invalid.", "Patches to a criteria binding are prohibited after issuance; a criteria change requires a new engagement or a documented re-issue with restated scope." ], "compatibility_rules": [ "Adding a new optional field, a new code value in an open value set, or a new binding profile is a compatible change.", "Changing the meaning of a determination value, altering a severity grading scheme, changing a decision rule, or narrowing the recurrence-key inputs is breaking and requires a new value-set or scheme version and a migration note.", "Exchange binding profiles are versioned independently of the model, so that adopting a new target-standard revision does not force a model revision.", "Consumers must reject a record whose declared value-set or scheme version they do not recognise rather than coercing it to a known value." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the system of record for the engagement or artifact - for example the audit or inspection management system's engagement number, a regulator's case reference, or an issuing body's certificate number - recorded together with its issuing system and scheme.", "Governed global identifier or IRI where one exists, such as a persistent URI minted in the adopting Dimension's governed namespace or an identifier assigned by a recognised registry or accreditation body.", "UUID or ULID minted by the adopting Dimension only when neither of the above exists, recorded explicitly as a surrogate with its minting agent, minting timestamp and the reason no authoritative identifier was available.", "A date, report title, file name, sequence label, engagement year or subject name is never an identifier and must not be used as one, alone or in combination." ], "timestamp_rule": "All time values are recorded as RFC 3339 date-times with at least whole seconds and an explicit numeric UTC offset or the literal Z; a date alone is permitted only where the governing standard defines a date-precision concept such as a period covered or a certificate expiry. Where they differ, event time (when the observed condition, act or non-compliance occurred), activity time (when the examiner performed the procedure, as start and end), observation or collection time (when the observation was captured), and ingestion time (when the record entered the system of record) are stored as separate fields and are never inferred from one another; the originally recorded local offset is retained where the hour of a site visit carries evidential meaning.", "serial_naming_rule": "Serial artifacts - observation records, evidence items, custody entries, execution-log entries, finding records, recommendation records, verification records, appeal cases, certificates and impartiality declarations - are named by the parent identifier plus a strictly monotonic, gapless sequence number within that parent, plus the artifact's own surrogate identifier. Sequence numbers are never reused after a supersession, the sequence carries no semantic meaning beyond ordering of recording, and a gap must be explained by an explicit void entry.", "integrity_rule": "Every artifact carries a cryptographic digest with its algorithm identifier, computed over the canonical form; issued reports and certificates are additionally sealed and, where the governing regime requires it, signed by the issuing party. Evidence items carry a digest recorded at acquisition and a verification record on each custody transfer. Any record whose recomputed digest does not match its stored digest is treated as unverified and must not be used to support a conclusion until reconciled, with the discrepancy recorded rather than silently corrected." }, "policies": [ "No finding may be created against a criterion that is not bound to an external source identifier and version, and no conformity determination for a measured characteristic may be recorded without a referenced decision rule and a stated uncertainty treatment.", "No conclusion may be issued before evidence sufficiency has been concluded, the responsible party has been given a recorded opportunity to comment, and any required engagement quality review has been completed.", "This model records determinations and stated grounds; it never decides, imposes or executes an enforcement measure, a certification decision, a corrective action, or a records disposal, all of which are owned by the referenced models and the adopting Dimension.", "Impartiality threats and conflicts of interest must be declared before fieldwork begins and re-declared when circumstances change; an undeclared conflict discovered later invalidates reliance on the affected findings until reviewed.", "Alignment to an external standard is declared as a versioned binding with lossiness annotations; conformance is asserted only where recorded validation evidence exists, and never inferred from structural similarity." ], "crud": { "read": [ "Read access is granted per scope - bundle, layer, finding or artifact - and resolves references to other models without copying their content, so that a reader always sees the referenced model's current state through its own access controls.", "Reading an issued report version returns the sealed canonical form together with its digest and issuing metadata; readers must be able to verify the digest independently.", "Reads of evidence items carrying personal, commercially confidential or classified material require the sensitivity classification to be evaluated against the requester's authorisation before content is returned; metadata-only reads are the default fallback." ], "create": [ "An engagement may be created only with a resolved identifier under the declared identity priority, a referenced authorising instrument and at least the auditor and responsible-party roles populated.", "Observations, evidence items, custody entries and execution-log entries are created append-only with the acting agent and the full timestamp set; creation never asserts a conformity judgement.", "A finding may be created only against a bound, version-pinned criterion with at least one supporting observation; a determination for a measured characteristic additionally requires a referenced decision rule." ], "update": [ "Before issuance, records may be updated in place provided every change writes a new record version identifier, a last-modified timestamp and the acting agent; silent update is invalid.", "After issuance, findings, conclusions and reports are effectively immutable: change proceeds only by erratum, correction, withdrawal or re-issue that names the superseded version, the reason and the recipients notified.", "Updates to identity fields, criteria bindings and issuing metadata are prohibited after issuance; an error in these requires withdrawal and re-issue rather than amendment." ], "delete": [ "Hard deletion of engagement records is prohibited within this model. Records are classified for retention, held until the retention trigger plus the minimum period defined by the schedule authority for the applicable jurisdiction, and then presented for disposition.", "Execution of disposition - destruction, anonymisation, transfer to archive and disposal certification - is owned by the referenced records-management model and the adopting Dimension's retention policy; this model records only the classification, the trigger event, the computed due date, the hold state and the disposition confirmation reference returned to it.", "On confirmed disposition a tombstone is retained carrying the engagement identifier, engagement type, period covered, issuing party, disposition date, disposition authority and the confirmation reference, so that inbound references from findings, certificates, appeals and other engagements remain resolvable and are not silently broken.", "Disposition is suspended for any record subject to a legal, regulatory or appeal-related hold; the hold is released only by the placing authority, and an open appeal automatically suspends disposition of the contested determination and its supporting evidence.", "Where a personal-data erasure obligation conflicts with an evidentiary retention duty, the conflict, the legal basis relied on, any redaction or pseudonymisation applied, and the approving authority are recorded here; the resolution itself is a decision of the adopting Dimension's privacy and records policy, not of this model." ] }, "roles": [ { "name": "Engagement record owner", "responsibilities": [ "Hold accountability for the completeness, integrity and retention classification of the engagement record set independently of the engagement team.", "Approve identity scheme use, value-set versions and the escalation route recorded in the owner package." ] }, { "name": "Model steward", "responsibilities": [ "Maintain this model's structure, value sets, boundary notes and composition links, and keep them consistent with the registry entry vr.wm-act-033.", "Version exchange binding profiles when a target standard is revised, and record lossiness and conformance claims with their validation evidence." ] }, { "name": "Engagement lead (lead auditor or inspector)", "responsibilities": [ "Plan and direct the engagement, bind criteria, supervise fieldwork and construct findings against the documented decision rules.", "Declare impartiality threats and safeguards, and form and sign the engagement conclusion within the mandated authority." ] }, { "name": "Engagement quality reviewer", "responsibilities": [ "Review significant judgements, evidence sufficiency and the draft conclusion before issuance, independently of the engagement team.", "Record the review scope, matters raised and conclusion, and clear a specific report version for issue or withhold clearance." ] }, { "name": "Responsible-party liaison", "responsibilities": [ "Receive notices and requests for comment, coordinate the responsible party's views and disagreements, and confirm receipt of the issued output.", "Exercise or waive the right to be heard within the notice period and initiate appeals where the regime allows." ] }, { "name": "Records custodian", "responsibilities": [ "Maintain custody chains, integrity digests and sensitivity classifications for evidence items and issued outputs.", "Apply and release holds, present records for disposition to the owning records-management process, and record the disposition confirmation and tombstone." ] } ], "access": { "default_rule": "Deny by default. Access is granted only to an identified principal with a declared purpose, scoped to the narrowest node that satisfies it, and is further constrained by the use, distribution and confidentiality restrictions attached to the engagement and to individual evidence items. Draft engagement material is restricted to the engagement team, the quality reviewer and the record owner until issuance; the responsible party receives only the material the governing regime requires for the right to be heard.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "The responsible party is granted read access to the findings and grounds that concern it before a measure is acted on, in order to exercise the right to be heard, even while the wider engagement remains restricted.", "An independent appeal reviewer is granted read access to the contested determination and its full supporting evidence, including material otherwise restricted to the engagement team, for the duration of the appeal.", "Another competent authority may be granted access to evidence and determinations where a legal gateway for mutual assistance or cross-border cooperation exists, subject to recorded onward-use conditions.", "Publication of outcomes, where a regime requires or permits it, is limited to a redacted projection whose redaction rules are recorded with the issued report version.", "Evidence items containing personal, commercially confidential or classified material are withheld or returned as metadata-only unless the requester's authorisation matches the item's sensitivity classification." ], "audit_requirements": [ "The adopting Dimension's platform must log every access decision, grant and denial against these records with principal, purpose, scope, node identifier and RFC 3339 timestamp. That log is an external control owned by the platform's logging and access-control services; this model neither defines log-record semantics nor owns the audit trail.", "Access grants that rely on an exception must record the exception invoked, the authorising role and the validity period, and this record is held here as an access-decision reference rather than as a copy of the platform log.", "Disclosure of engagement material to a third party or another authority must record the recipient, the legal or contractual gateway relied on, and the onward-use conditions, so that a later challenge can be answered from this model's own records.", "Verification that logging and enforcement are operating is a matter for the adopting Dimension's control assessment; this model records only the reference to any such assessment and never asserts that enforcement occurred." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Owner", "Version" ], "read_order": [ "Read AGENTS.md first and resolve Name, Type and Version to confirm which model and version is present before any other action.", "Follow Specification URL to obtain this model's structure - bundles, layers, findings, questions, data elements and artifact rules - and the identity, timestamp and integrity rules.", "Follow Storage type URL to learn how records are physically held and addressed in this deployment, whether that is Git, MongoDB, a document store or a filesystem; treat it strictly as a projection of the specification.", "Follow Interface URL to learn how to read and write records in this deployment, including MCP tool surfaces or APIs, and the access scopes and authentication required.", "Follow Processes URL to learn the operational procedures - registration, issuance, amendment, appeal, follow-up and disposition - and which steps require an authorised role or an external model.", "Only after all five have been read, resolve composition links and value-set versions, and refuse to write if a referenced value set or binding profile version is unrecognised." ] } }, "coverage": { "claim": "Single-provider (Claude) coverage of the engagement-level context of a review, inspection, audit or assessment: engagement identity and mandate, parties and impartiality, subject matter and scope, criteria binding and decision rules, plan and methods, fieldwork execution, evidence acquisition, custody and appraisal, finding construction and conformity determination, conclusion and report or certificate issuance, redress and follow-up verification, record provenance, retention and exchange bindings — grounded in fifteen sources that the provider states it verified, thirteen of them primary and tier 1 or 2 (NIST, OASIS, W3C, EU, INTOSAI, IIA, OMG, BIPM, GAO). Two dimensions are declared gaps (sensitivity-classification scheme, statistical sampling method), ISO vocabulary alignment is absent because the texts were unretrievable, and the composition links, artifact rules and access rules asserted by the coverage checklist are not present in the audited pack and are therefore unverified here. No universal, metaphysical or cross-jurisdictional completeness is claimed, no standard conformance is asserted without recorded validation evidence, and the result remains a reviewable draft carrying an owner-authorized single-provider hold.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Engagement identifier with issuing system and uniqueness scope, surrogate minting rules, continuity across split, merge and re-issue, alternate external references, and a separate recurrence key for cross-engagement finding matching. Identity priority is fixed in artifact_rules and excludes dates and titles." }, { "dimension": "lifecycle", "status": "covered", "notes": "Engagement state value set, permitted transitions with authorised roles and preconditions, closure criteria, suspension, withdrawal and abandonment with disclosure obligations, and reopening conditions. Lifecycles of remediation, certification and enforcement are explicitly excluded and referenced." }, { "dimension": "relationships", "status": "covered", "notes": "Typed links to predecessor and successor engagements, parent programme, assessment subjects, criteria sources, observations, evidence, recommendations and remediation actions, plus sixteen composition links each with a stated ownership boundary." }, { "dimension": "temporal", "status": "covered", "notes": "Period covered is separated from fieldwork interval; event, activity, collection and ingestion times are distinct fields; observation expiry, certificate validity, notice periods, retention triggers and disposition due dates are modelled. RFC 3339 with seconds and explicit offset is mandated." }, { "dimension": "provenance", "status": "covered", "notes": "Agent, activity and delegation attribution aligned to PROV-O; version identifier and last-modified must change on any content change, following the OSCAL rule; derivation from imported plans and prior engagements; amendment, withdrawal and re-issue preserve superseded versions." }, { "dimension": "ownership", "status": "covered", "notes": "Three-party model of auditor, responsible party and intended users; engagement record owner and records custodian roles; explicit statements of which neighbouring model owns each excluded concept, restated in boundary notes, composition purposes and function effects." }, { "dimension": "validation", "status": "covered", "notes": "Evidence sufficiency and appropriateness, relevance and reliability appraisal, depth and coverage attributes, engagement quality review, digest verification, and conformance claims that require recorded validation evidence rather than structural similarity." }, { "dimension": "access", "status": "covered", "notes": "Deny by default with the four required scopes, five named exceptions covering right to be heard, appeal review, mutual assistance, publication redaction and sensitive evidence, and audit requirements phrased as obligations on the platform's logging service rather than as ownership of the audit trail." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Hard deletion prohibited within the model; retention class, schedule authority, jurisdiction, trigger event and computed due date are held locally; execution of disposition is owned by the records-management model and the adopting Dimension; a tombstone preserves referential integrity; holds and appeals suspend disposition; personal-data erasure conflicts are recorded, not resolved, here." }, { "dimension": "interoperability", "status": "covered", "notes": "Versioned binding profiles to OSCAL assessment plan and results, SARIF results with fingerprints and baseline state, PROV-O and SACM, each with direction, unmapped-concept lists, lossiness annotations and an explicit conformance level." }, { "dimension": "impartiality and independence", "status": "covered", "notes": "Threat identification, safeguards, residual-threat approval, per-individual declarations that supersede rather than overwrite, party-relationship classification of the body, and independent review of appeals. Grounded in IIA, INTOSAI, GAGAS and the EU accreditation framework." }, { "dimension": "measurement and uncertainty", "status": "covered", "notes": "Documented decision rules, tolerance and acceptance limits, guard bands and false-accept risk grounded in JCGM 106, with uncertainty evaluation explicitly left to the owning measurement model." }, { "dimension": "spatial and site context", "status": "covered", "notes": "Location references, on-site, remote, border and laboratory modes, jurisdiction codes, and access and safety conditions constraining execution. Detailed geospatial representation is left to a geometry model and is not specified here." }, { "dimension": "evidence integrity and custody", "status": "covered", "notes": "Item identity, acquisition method, digest with algorithm identifier, append-only custody transfers, sensitivity classification and cross-authority reuse conditions." }, { "dimension": "security classification of engagement content", "status": "gap", "notes": "Sensitivity classification is modelled as a code with handling constraints, but no verified primary source in this set defines a classification scheme for audit and inspection material. The scheme must be supplied by the adopting Dimension and is marked as unsupported structure rather than presented as canonical." }, { "dimension": "sampling statistics", "status": "gap", "notes": "Population, sample size, selection method and representativeness are captured, but no verified source in this set specifies acceptance sampling plans or statistical confidence computation. The statistical method itself is referenced, not defined here." } ], "known_omissions": [ "Sector-specific inspection and audit schemes - food and feed, aviation, maritime, nuclear, clinical GxP, financial supervision, forensic and building control - are not enumerated; each adds mandatory content, qualification and reporting rules that an adopting Dimension must layer on.", "Rules of evidence admissibility in judicial or administrative proceedings are not modelled; custody and integrity are captured, but admissibility is jurisdiction-specific and belongs to a legal-process model.", "Acceptance sampling plans, statistical confidence computation and extrapolation methods are referenced but not specified.", "Interviewee protection, whistleblower confidentiality and anonymous-source handling are acknowledged through sensitivity classification but not modelled as a distinct concern.", "Machine-readable competence and qualification taxonomies for auditors and inspectors are referenced to the party model and not defined here.", "Remote and continuous auditing modalities, including automated evidence collection cadence and expiry, are only partially represented through observation expiry and tool references.", "ISO vocabulary alignment for the terms audit, inspection, review, verification, validation, nonconformity and objective evidence is not asserted, because the relevant ISO texts could not be retrieved." ], "conflicts": [ "OSCAL separates an observation, which records evidence without judgement, from a finding, which carries control-objective status. GAGAS and INTOSAI treat a finding as already containing criteria, condition, cause and effect. This model keeps observation and finding structurally distinct and places the four elements inside the finding, which is compatible with both but identical to neither.", "SARIF result.kind admits pass, fail, review, open, informational and notApplicable, whereas most audit practice records only deviations plus an engagement-level positive conclusion. The SARIF mapping is therefore lossy in the pass direction and is annotated as such rather than silently normalised.", "Severity and grading vocabularies are irreconcilable across regimes - major and minor nonconformity and observation, error and warning and note, satisfied and other than satisfied, non-compliance and serious risk. No canonical scale is asserted; the grading scheme is referenced by identifier and version.", "ISO 19011 is guidance while ISO/IEC 17020, GAGAS, the IIA standards and EU market-surveillance law impose requirements. Because the ISO texts were not retrievable, this model states requirement-level obligations only where a requirement source was directly verified, and treats inspection-body clause structure as an unverified alignment.", "The word review denotes at least three different things: a lower-assurance engagement type in GAGAS and IAASB terms, a design or peer review with no assurance opinion, and an internal quality review of another engagement. The model classifies engagement type explicitly so that the three are never conflated.", "Audit is a homonym: the assurance activity modelled here and the IT audit trail. The model rejects any local ownership of log-record semantics and treats system logs only as evidence sources.", "EU market surveillance places corrective action on the economic operator while the authority verifies follow-up, whereas internal audit frameworks have management own action plans and the audit function monitor them. Both are handled by referencing an external action record and recording only verification here." ], "regional_assumptions": [ "The market-surveillance framing, including the right to be heard with a notice period of at least ten working days, proportionate measures stating exact grounds, and mutual assistance timelines, is specific to Regulation (EU) 2019/1020 and does not transfer to other jurisdictions without verification.", "The public-sector engagement taxonomy and quality-management deadlines are specific to US GAGAS 2024; other supreme audit institutions apply INTOSAI principles through their own national frameworks.", "The internal-audit domain and principle structure follows the IIA 2024 Global Internal Audit Standards, whose adoption and effective dates vary by jurisdiction and sector.", "Control-assessment constructs follow NIST OSCAL and SP 800-53A, which are US federal in origin; other control regimes use different assessment vocabularies.", "Retention periods, legal hold triggers and personal-data erasure obligations are entirely jurisdiction-specific and are deliberately left unfixed, with only the classification and trigger structure modelled.", "Accreditation and notified-body concepts follow the EU framework under Regulation (EC) No 765/2008 as explained in the Blue Guide; equivalent but non-identical regimes exist elsewhere." ], "adversarial_checks": [ "Tested the homonym risk that audit means an IT audit trail. Rejected any local ownership of log-record, log-retention or log-integrity semantics; system logs appear only as evidence sources, and the access audit requirements are explicitly framed as obligations on the platform's logging service.", "Searched for counterexamples where review is not an assurance activity - editorial peer review, design review, code review. Found that the criteria, evidence, finding and conclusion spine still applies but that no conformity determination is produced, so determination and severity are modelled as optional rather than required, and engagement type is classified explicitly.", "Tested whether the multi-engagement audit programme or annual assurance plan belongs here. Rejected: it spans engagements, has its own prioritisation and resourcing lifecycle, and is referenced rather than modelled, with only the engagement-to-programme link retained.", "Tested whether corrective action closure belongs here. Rejected on the evidence of Regulation (EU) 2019/1020, which places corrective action on the economic operator and enforcement on the authority while the authority verifies follow-up. Only recommendation issuance and verification observations are local.", "Tested whether OSCAL risk ownership follows the assessment result into this model. Rejected: OSCAL itself migrates risks to the POA&M for treatment, so only engagement-scoped risk statements are produced here and treatment is referenced.", "Tested whether issuing an inspection certificate implies owning a certification decision. Rejected: the certificate is an engagement output artifact, while grant, suspension and withdrawal of certification remain with the certification model.", "Checked every bundle, layer, finding and function against each composition rationale for target-owned concepts. Moved criteria text, subject state, action state, risk treatment, measurement uncertainty evaluation, competence lifecycle, disposal execution and access enforcement out to composition links, out_of_scope entries or boundary notes.", "Checked that no ISO clause text is asserted. The ISO Online Browsing Platform and catalogue returned HTTP 403 and the sample PDFs were not machine-readable, so ISO 9000, ISO 19011, ISO/IEC 17000 and ISO/IEC 17020 are cited only through an independent public-authority pointer, no clause-level conformance is claimed, and the affected vocabulary alignment is recorded as an omission.", "Checked that every finding satisfies the exclusive representation rule, that no local identifier contains a date-like component, and that identity priority never admits a date, title or file name as an identifier." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-08-29T09:06:27Z", "scope": "Queued subject-model research from WM-XCT-013 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-08-29T09:06:27Z", "reason": "The repository owner explicitly instructed the research queue to continue without Grok after repeated structured-output failures." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The aggregate root survives challenge: one engagement occurrence issues the identity under which the plan, execution log, observations, evidence appraisals, findings, conclusion, issued report or certificate, recommendations, appeals and record provenance are created, amended and closed, and no competing root appears in the pack. OSCAL assessment-results, GAGAS and the EU market-surveillance frame all key their records on the engagement rather than on the subject or the criterion. The registry's entry_kind 'standalone-mm' is a record-plane classification (this is a self-standing meta-model, not nested inside another entry) and does not contradict the modelling-level 'aggregate'; both must be carried in the published record with their planes named. Three probes did not move the root: the 'review' triple homonym and the audit/audit-trail homonym are handled by explicit engagement typing and by refusing log-record ownership; an engagement quality review or a follow-up engagement is a recursive instance of the same aggregate linked by subject or predecessor reference, not a second root; and cross-engagement finding recurrence is a derived comparison attribute. Acceptance is conditional on the corrections and holds recorded below, notably the scope-statement claim that an issued certificate shares the engagement lifecycle." }, "decisions": [ { "concept": "Aggregate root is the engagement occurrence", "disposition": "accepted", "rationale": "Engagement identity governs a record set that shares one lifecycle from registration to closure; the pack presents no rival root, and the primary sources key their assessment records on the engagement rather than on the examined subject or the criterion." }, { "concept": "Registry entry_kind 'standalone-mm' versus result entry_kind 'aggregate'", "disposition": "accepted as non-conflicting; reconcile both planes in the published record", "rationale": "These are different vocabularies: the registry field states the entry is a self-standing meta-model, the result field states the modelling shape of its root. Neither is wrong, but publishing only one hides the other, so both must appear with their plane named rather than one silently overwriting the other." }, { "concept": "Cross-engagement finding identity as a candidate second aggregate", "disposition": "rejected for this pass, deferred as a boundary re-test", "rationale": "Recurrence key, baseline state and repeat count are derived comparison attributes carried on a finding owned by the engagement that raised it, which is defensible. But repeat findings, suppression decisions and follow-up engagements give a finding a trajectory that outlives its raising engagement, so the root must be re-tested once predecessor and successor links are frozen." }, { "concept": "Scope statement claims the issued certificate shares the engagement lifecycle", "disposition": "accepted with mandatory scope-statement correction", "rationale": "The scope statement is contradicted by the model's own out_of_scope entry excluding certificate suspension and withdrawal, by the certification boundary note, and by the checklist's separate certificate-validity attribute. Only the issuance record is aggregate-owned; validity, suspension and withdrawal belong to the certification model, and the sentence must say so." }, { "concept": "SRC-011 as a single composite JCGM source identifier", "disposition": "rejected as one identifier; split into per-document pins before publication", "rationale": "One source id spanning JCGM 106:2012, JCGM 100:2008 and JCGM 200:2012 behind a publications landing page makes every decision-rule and uncertainty source_ref unresolvable at document level, so a reviewer cannot check which text supports guard bands versus vocabulary." }, { "concept": "SRC-015 GAO press release cited first for engagement quality review and for report issuance", "disposition": "demoted to a corroborating version and date pointer", "rationale": "A press release evidences that the 2024 revision exists and when it was issued; it cannot carry a quality-management or reporting requirement. SRC-012, the Yellow Book itself, is already in the set and must hold the requirement weight in both the finding and the function." }, { "concept": "SRC-014 OSAC registry pointer used to support appeal independence and impartiality safeguards", "disposition": "accepted only as an existence and scope pointer", "rationale": "The model itself records that ISO texts returned HTTP 403 and that no clause-level conformance is claimed, so a third-party registry entry naming ISO/IEC 17020 cannot supply requirement-level obligations. Requirement support for these findings must rest on SRC-006, SRC-012 and SRC-013, with SRC-014 annotated as unverified alignment." }, { "concept": "Platform term 'Dimension' inside question rdl-q-execution and the retention rationale", "disposition": "accepted with a mandatory neutrality edit", "rationale": "The purpose and scope statements declare the model storage-, interface- and platform-neutral, yet a Vercy deployment construct appears in question text that external reviewers must be able to read. Rewrite as the records-management model or the adopting deployment's policy, or define the term explicitly once." }, { "concept": "Artifact serial flag on exchange-binding-profile", "disposition": "rejected as serial:false", "rationale": "The interoperability checklist asserts versioned binding profiles to OSCAL assessment plan, OSCAL assessment results, SARIF, PROV-O and SACM. Several profiles per engagement record set cannot share one non-serial artifact identity, so the flag contradicts the declared coverage." }, { "concept": "Singularity of engagement-report and engagement-quality-review-record artifacts", "disposition": "deferred serial re-test", "rationale": "Interim, draft and final reports, separate reports to different addressees, and repeated reviews may each require serial identity. The re-test must first separate serial instances from versions, since amendment and re-issue are already governed by the provenance and versioning rule." }, { "concept": "Evidence appraisal held inline with no working-paper artifact", "disposition": "accepted provisionally, re-test against documentation requirements", "rationale": "The exclusive-representation argument is sound: detaching judgement from the item it qualifies invites divergence. But audit documentation is itself a mandated record under GAGAS 2024 and the IIA standards, and if a documentation record is required then appraisal needs an artifact home rather than a rendering." }, { "concept": "Function set versus state-changing acts present in the structure", "disposition": "gap recorded, no functions added in single-provider mode", "rationale": "Evidence-item registration with digest and custody transfer, amendment or withdrawal of an issued report, and placement or release of a legal hold are state-changing acts modelled in the structure but absent from the ten functions. The waiver forbids additions here, so this is carried forward rather than patched." }, { "concept": "Coverage-checklist claims not evidenced in the audited pack", "disposition": "held for verification, must not be published as verified", "rationale": "The checklist asserts identity priority fixed in artifact_rules, deny-by-default access with four scopes and five exceptions, and sixteen composition links with stated ownership boundaries, while the frozen relationship contract is an empty array and no rules sections appear in the pack. These claims are unauditable here." }, { "concept": "Thin question-kind coverage on access, retention and security", "disposition": "accepted for the draft, re-balance at the next pass", "rationale": "Three access questions, one retention question and one security question carry dimensions the checklist marks fully covered through non-visible rules sections. A reviewer reading only the structure cannot see deny-by-default, hold release or classification handling, which understates governance in the public draft." }, { "concept": "Meta-term collision between the Vercy structural 'finding' and the audit-domain 'finding'", "disposition": "accepted with a one-time disambiguation note", "rationale": "The domain term is canonical in GAGAS and OSCAL and must not be renamed, but a structural finding named finding-statement-structure containing a finding-record artifact is a genuine hazard for readers and for tooling that keys on the word." }, { "concept": "Audit-trail homonym boundary", "disposition": "accepted as resolved", "rationale": "The exclusion is asserted consistently in out_of_scope, in a dedicated boundary note, in the conflicts list and in an adversarial check, and access-logging duties are phrased as obligations on the platform's logging service rather than as ownership of log semantics. This survived challenge and needs no change." }, { "concept": "Personal-data erasure conflict recorded but deliberately unresolved", "disposition": "accepted as a declared limitation that must be visible in the draft", "rationale": "Refusing to resolve erasure against evidentiary retention is defensible given jurisdictional variance, but it shifts a legal obligation onto the adopting deployment, so it belongs in the published limitations rather than only in a question and a checklist note." } ], "publicationHolds": [ "Live source and version verification is outstanding for all fifteen sources before publication. Highest-risk pins: the OSCAL v1.1.2 metaschema reference path, SP 800-53A Rev. 5 patch release 5.2.0 dated 27 August 2025, the GAGAS 2024 effective dates for periods beginning on or after 15 December 2025, SARIF 2.1.0 Plus Errata 01, and the JCGM publications landing page that stands in for three separate documents. SRC-002 and SRC-003 are undated concept pages and must be published as accessed-date only, with no version claim.", "Independent second-provider review is absent by explicit repository-owner authorization: Grok was waived at 2026-08-29T09:06:27Z after repeated structured-output failures, so this result rests on one provider plus this no-tools adversarial audit. Every publication artifact must carry the visible single-provider hold, name the waived provider and the authorizing party, and keep the record a reviewable draft rather than a validated model.", "The frozen relationship contract is an empty array while the coverage checklist asserts sixteen composition links each with a stated ownership boundary. All composition and ownership-boundary claims must be marked unverified until the contract is populated and re-audited.", "The artifact_rules, access-rules and identity-priority statements that the coverage checklist relies on are not present in the audited pack. Do not present deny-by-default access, the four scopes, the five named exceptions or the identity-priority prohibition on dates and titles as verified.", "Registry-record reconciliation is outstanding: entry_kind vocabulary across the two planes, empty source_url, namespace_uri, relations_ref and validation_flags, and source_version_or_year 2026-08-22 against a research and source-access date of 2026-08-29. Reconcile explicitly rather than letting the result overwrite the frozen record.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft." ], "deferredResearch": [ "Re-test whether cross-engagement finding identity, recurrence and suppression justify a second aggregate, once predecessor, successor and repeat-finding links are frozen into the relationship contract.", "Verify the audit-documentation requirements in GAGAS 2024 and the IIA 2024 Global Internal Audit Standards to decide whether an engagement working-paper or documentation artifact must exist rather than evidence appraisal remaining inline only.", "Obtain ISO/IEC 17020, ISO 19011, ISO/IEC 17000 and ISO 9000 through a licensed channel to close the declared vocabulary-alignment omission and to replace the unverified inspection-body clause alignment currently resting on a third-party registry pointer.", "Split SRC-011 into per-document pins for JCGM 106:2012, JCGM 100:2008 and JCGM 200:2012, then re-attach the decision-rule, guard-band and uncertainty source_refs to the correct document.", "Model interviewee, whistleblower and anonymous-source protection, currently a declared omission, because it collides directly with the in-scope right to be heard, the responsible party's views in the report, and cross-authority evidence reuse.", "Close the two declared coverage gaps by finding a verified source for a sensitivity-classification scheme for audit and inspection material, and for acceptance sampling plans, statistical confidence and extrapolation to a population.", "Re-audit artifact serial flags as a whole against the distinction between serial instances and versions, starting with exchange-binding-profile, engagement-report, engagement-quality-review-record and engagement-authorization-instrument.", "Re-run the function sweep to cover evidence-item registration and custody transfer, report amendment or withdrawal, legal-hold placement and release, plan approval and re-approval, and superseding impartiality declarations, once a second provider or a further single-provider pass is authorized." ] }, "statistics": { "sources": 15, "bundles": 6, "layers": 13, "findings": 26, "questions": 107, "artifacts": 18, "functions": 10 } }