# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-29T16:26:37Z", "synthesisSha256": "1c57d5445446608717d43492cc4fae8677e1242b0c59f5afc1f3f00a851a55da", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-ACT-034", "registryId": "vr.wm-act-034", "name": "Assessment / Evaluation", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.ASM" ], "tags": [ "assessment", "evaluation", "act.asm" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-034-assessment-evaluation/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-034", "model": { "registry_id": "vr.wm-act-034", "model_id": "WM-ACT-034", "name": "Assessment / Evaluation", "entry_kind": "aggregate", "purpose": "Give an agent the context needed to understand, create, inspect and operate an assessment or evaluation record: what was assessed, against which criteria at which version, by which method, on what evidence, yielding which criterion outcomes, scores, composite result and stated conclusion, with declared validity, assurance, lifecycle, disclosure and interoperability.", "scope_statement": "Format-neutral structure of a single assessment/evaluation instance and the bindings it carries to reusable definitional components (criteria source, instrument, scale, decision rule). It spans framing and scoping, criteria binding and tailoring, method and execution parameters, evidence and observation capture, criterion-level determination, aggregation, conclusion and validity, assurance of assessor competence and impartiality, and record lifecycle, disclosure, retention referral and external projection. It is subject-domain agnostic and applies equally to conformity assessment, security control assessment, accessibility evaluation, educational measurement, clinical risk assessment and peer review. It is modelled as an aggregate because the assessment act, its inputs and its determinations share one identity boundary and one finalisation event.", "in_scope": [ "Identity, granularity and versioning of an assessment record and its supersession chain", "Assessment type, stakes, mandate, scheme reference and first/second/third-party relationship", "Subject reference, pinned assessed state, scope boundary, sampling and generalisation limits", "Binding of criteria to a named catalogue at a pinned version, plus selection, tailoring and interpretation notes", "Declared method, mode, depth and coverage, and the instrument or rubric that operationalises each criterion", "Execution parameters needed for reproducibility: tool and model references, versions, configuration, input snapshots", "Evidence item references, criterion linkage, sufficiency, admissibility and confidentiality qualifiers", "Observation records with distinct event and recording times, plus declared uncertainty and traceability pointers", "Criterion-level outcomes, rationale, severity and locators; raw, normalised and maximum scores", "Aggregation model, weighting, composite score or level, and result-vector expression", "Conclusion statement, decision authority, qualifications, dissent, validity window and surveillance obligations", "Assessor identity and roles, competence and authorisation references, impartiality and conflict declarations", "Independent review, moderation, rater agreement, and validity/reliability/fairness evidence for the instrument", "Record state machine, correction, appeal and supersession; disclosure classification, redaction and retention referral", "Crosswalks and vocabulary bindings for projection into external assessment reporting formats" ], "out_of_scope": [ "Internal structure, lifecycle and state management of the assessed subject itself", "Authoring, versioning, publication and normative interpretation of the criteria catalogue or standard", "Runtime execution and orchestration of testing tools, scanners, graders or evaluator engines and their operational telemetry", "Issuance, signing, suspension, withdrawal and verification of certificates, credentials or attestations", "Enforcement of consequences: certification decisions with legal effect, licensing, sanction, market withdrawal or remediation workflow", "Identity management, employment and qualification records of persons and organisations", "Physical or digital custody, storage and chain-of-custody execution for evidence objects", "Calibration programmes, metrological traceability management and instrument maintenance", "Training, validation and deployment lifecycle of predictive or generative scoring engines", "Platform audit-trail and access-log semantics, storage and evaluation", "Execution of retention, destruction, transfer or erasure actions", "Risk register lifecycle, risk treatment and plan-of-action-and-milestones case management", "Population-level aggregation of many assessments into reputation scores or league tables", "Commercial terms, scheduling and cost accounting of assessment services" ], "boundary_notes": [ { "neighbor": "Measurement / observation model", "distinction": "An assessment consumes measured or observed values as evidence and adds criterion-referenced judgement; a bare measured value with an uncertainty statement is a measurement result, not an assessment. Units, uncertainty evaluation and calibration traceability are referenced from the metrology model.", "source_refs": [ "SRC-015", "SRC-007" ] }, { "neighbor": "Criteria / requirement catalogue model", "distinction": "This model carries a criterion reference, its pinned catalogue version, local applicability and interpretation notes only. Criterion text, structure, normative status and catalogue lifecycle belong to the catalogue, exactly as OSCAL separates a control catalogue from assessment results and XCCDF separates a Benchmark from a TestResult.", "source_refs": [ "SRC-002", "SRC-004", "SRC-010" ] }, { "neighbor": "Attestation / certificate / credential model", "distinction": "ISO/IEC 17000 separates determination and review from decision and from attestation. This model ends at the recorded conclusion; issuing, signing, suspending or revoking a certificate or credential is a downstream act, and in EU product law only a designated notified body may give that act legal effect.", "source_refs": [ "SRC-001", "SRC-012" ] }, { "neighbor": "Evaluator or test-execution engine", "distinction": "EARL records the assertor and the test mode as attributes of an assertion, and XCCDF records the checking system as a reference. Naming a tool, its version and its configuration never transfers ownership of running that tool, its scheduling, or its operational logs.", "source_refs": [ "SRC-005", "SRC-004" ] }, { "neighbor": "Risk register and treatment model", "distinction": "OSCAL keeps observations, findings and risks distinct and hands risks onward to a POA&M. This model may produce findings that seed risks, but risk characterisation lifecycle, mitigating factors, remediation tracking and deadlines belong to the risk model.", "source_refs": [ "SRC-002" ] }, { "neighbor": "Party, competence and accreditation registry", "distinction": "Assessor identity, competence evidence, accreditation and designation scope are referenced by identifier and version. Whether a body is accredited or notified, and for what scope, is asserted and maintained by the accreditation authority, not by an assessment record.", "source_refs": [ "SRC-011", "SRC-012" ] }, { "neighbor": "Provenance and audit-trail models", "distinction": "Content provenance (which agent produced which determination, from which evidence, when) is mixed in from a PROV-aligned model and retained. Platform-level record access and change logging is a separate audit model whose storage and evaluation this model does not own.", "source_refs": [ "SRC-006" ] }, { "neighbor": "Records retention and disposition model", "distinction": "This model declares a retention class, a retention trigger event and a legal-hold flag, and records the referral. Setting periods and executing destruction, transfer or erasure is owned by the adopting Dimension's records policy.", "source_refs": [ "SRC-012", "SRC-003" ] }, { "neighbor": "Aggregate rating / reputation model", "distinction": "schema.org AggregateRating rolls many individual ratings into counts and averages across a population. That population-level statistic is a sibling concern; this model bounds one assessment occasion on one declared subject and scope.", "source_refs": [ "SRC-014" ] }, { "neighbor": "Assessment programme / scheme model", "distinction": "A conformity assessment scheme, examination programme or continuous-monitoring programme defines recurring rules, cycles and eligibility. This model references the scheme and carries the parameters it fixed for this occasion; the scheme's own rules and cycle belong to the programme model.", "source_refs": [ "SRC-012", "SRC-010" ] } ] }, "sources": [ { "id": "SRC-001", "title": "ISO/IEC 17000:2020 Conformity assessment — Vocabulary and general principles", "organization": "ISO/IEC (Joint Technical Committee)", "url": "https://www.iso.org/standard/73029.html", "version_or_date": "Second edition, 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:00:00Z", "relevance": "Canonical vocabulary for the functional approach to conformity assessment — object of conformity assessment, specified requirement, selection, determination, review, decision, attestation and surveillance — which grounds the separation of determination from decision and from attestation in this model. Catalogue record and the review/decision/attestation definitions were verified; the full text is paywalled and was not retrieved." }, { "id": "SRC-002", "title": "OSCAL Assessment Results Model (Assessment Layer)", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/assessment/assessment-results/", "version_or_date": "Page last updated 2025-03-03", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:02:00Z", "relevance": "Machine-readable assessment-results structure: reviewed-controls, assessment-subject, assessment-assets, attestation, assessment-log, and the explicit separation of observations (evidence) from findings (criterion-referenced determinations) from risks. Grounds evidence/observation/finding layering and the requirement to update record identity on change." }, { "id": "SRC-003", "title": "NIST SP 800-53A Rev. 5 — Assessing Security and Privacy Controls in Information Systems and Organizations", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/53/a/r5/final", "version_or_date": "January 2022; release 5.2.0, August 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:04:00Z", "relevance": "Assessment procedures with determination statements, assessment methods (examine, interview, test), assessment objects (specifications, mechanisms, activities, individuals), depth and coverage attributes, and satisfied / other-than-satisfied findings. Grounds the method, depth/coverage and criterion-verdict findings." }, { "id": "SRC-004", "title": "NISTIR 7275 Rev. 4 — Specification for the Extensible Configuration Checklist Description Format (XCCDF) Version 1.2", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/ir/7275/r4/upd1/final", "version_or_date": "March 2012 (Update 1)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:06:00Z", "relevance": "Benchmark/Rule/Group/Value/Profile definitions versus TestResult and rule-result instances; scoring models (default, flat, flat-unweighted, absolute); and a nine-value result vocabulary including notapplicable, notchecked, notselected, error and informational. Grounds scale, aggregation and indeterminate-outcome handling." }, { "id": "SRC-005", "title": "Evaluation and Report Language (EARL) 1.0 Schema", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/EARL10-Schema/", "version_or_date": "W3C Working Group Note, 2 February 2017", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:08:00Z", "relevance": "Minimal normative shape of an evaluation assertion: assertedBy, subject, test, result and mode, with OutcomeValue (passed, failed, cantTell, inapplicable, untested) and TestMode (automatic, manual, semiAuto, undisclosed). Grounds the assertion quadruple, indeterminate outcomes and mode declaration." }, { "id": "SRC-006", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:10:00Z", "relevance": "Entity/Activity/Agent with wasGeneratedBy, used, wasAssociatedWith, wasAttributedTo, wasDerivedFrom, actedOnBehalfOf, startedAtTime/endedAtTime, Plan and Role. Grounds the provenance mix-in, attribution of determinations to assessors and the derivation chain from evidence to conclusion." }, { "id": "SRC-007", "title": "FHIR R5 RiskAssessment resource", "organization": "Health Level Seven International (HL7)", "url": "https://hl7.org/fhir/R5/riskassessment.html", "version_or_date": "FHIR v5.0.0, 26 March 2023", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:12:00Z", "relevance": "A domain assessment record with identifier, status, method, code, subject, occurrence, performer, basis (source data), prediction with probability/qualitativeRisk/when/rationale, and mitigation. Grounds subject/method/basis/prediction separation, status vocabulary and the assessment-versus-observation boundary." }, { "id": "SRC-008", "title": "Question and Test Interoperability (QTI) 3.0 — Implementation and Best Practices", "organization": "1EdTech Consortium (formerly IMS Global)", "url": "https://www.imsglobal.org/spec/qti/v3p0/impl", "version_or_date": "QTI 3.0.1, Final Release, 1 October 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:14:00Z", "relevance": "Item and test structure with responseDeclaration, outcomeDeclaration, responseProcessing, SCORE/MAXSCORE outcomes, sessionStatus, and a separate results-reporting model (assessmentResult, itemResult, testResult). Grounds instrument/item definition, raw-versus-maximum score and separation of instrument definition from result records." }, { "id": "SRC-009", "title": "Common Vulnerability Scoring System v4.0 Specification Document", "organization": "Forum of Incident Response and Security Teams (FIRST)", "url": "https://www.first.org/cvss/v4-0/specification-document", "version_or_date": "Document version 1.2, 1 November 2023 (updated 18 June 2024)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:16:00Z", "relevance": "A governed scoring specification with metric groups, a mandatory vector string published alongside the numeric score, and a qualitative severity band mapping. Grounds the rule that a published score must travel with the inputs, scale and model that produced it." }, { "id": "SRC-010", "title": "Common Criteria for Information Technology Security Evaluation, CC:2022 Release 1, and CEM:2022", "organization": "Common Criteria Recognition Arrangement (CCRA)", "url": "https://www.commoncriteriaportal.org/cc/index.cfm", "version_or_date": "CC:2022 Release 1 with Errata v1.2; CC v3.1 R5 usable to 30 June 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:18:00Z", "relevance": "Five-part evaluation framework (general model, functional components, assurance components, framework for evaluation methods and activities, predefined packages) plus a separate evaluation methodology. Grounds the separation of criteria catalogue, evaluation method specification and evaluation instance, and the notion of predefined assurance packages." }, { "id": "SRC-011", "title": "ILAC-G8:09/2019 Guidelines on Decision Rules and Statements of Conformity (ILAC Guidance Series)", "organization": "International Laboratory Accreditation Cooperation (ILAC)", "url": "https://ilac.org/publications-and-resources/ilac-guidance-series/", "version_or_date": "09/2019", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-29T11:20:00Z", "relevance": "Decision rules for issuing statements of conformity to a specification, as required of laboratories by ISO/IEC 17025:2017, covering how uncertainty is handled before a pass/fail statement. Grounds the decision-rule, threshold and abstention finding and the report-identity strategy." }, { "id": "SRC-012", "title": "Conformity assessment (Single Market — Goods, building blocks)", "organization": "European Commission", "url": "https://single-market-economy.ec.europa.eu/single-market/goods/building-blocks/conformity-assessment_en", "version_or_date": "Accessed 2026-08-29; references the Blue Guide (2022)", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:22:00Z", "relevance": "Regulated conformity assessment: manufacturer-performed versus notified-body assessment, the declaration of conformity content, CE marking sequencing, and the explicit warning that certificates from non-notified bodies have no legal value. Grounds the mandate/authority findings and the rule that legal effect is not inferable from method quality." }, { "id": "SRC-013", "title": "Website Accessibility Conformance Evaluation Methodology (WCAG-EM) 2.0", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/WCAG-EM/", "version_or_date": "W3C Group Note, 23 July 2026 (WCAG-EM 1.0, 2014)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:24:00Z", "relevance": "Five-step evaluation methodology: define scope, explore the target, select a representative sample (structured plus ~10% random), evaluate, and report; plus the explicit limit that conformance claims cannot be made for a whole product from a sampled subset. Grounds scope/sampling/generalisation and optional aggregated scoring with documented methodology." }, { "id": "SRC-014", "title": "schema.org Rating, Review and AggregateRating types", "organization": "Schema.org Community Group (W3C)", "url": "https://schema.org/Rating", "version_or_date": "schema.org V30.0, released 19 March 2026", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-29T11:26:00Z", "relevance": "Widely deployed minimal rating vocabulary: ratingValue with bestRating/worstRating bounds, ratingExplanation, reviewAspect, author and itemReviewed, plus AggregateRating counts. Grounds scale-bound and direction declaration and marks the boundary to population-level aggregation." }, { "id": "SRC-015", "title": "JCGM publications, including JCGM 106:2012 The role of measurement uncertainty in conformity assessment and JCGM 100:2008 (GUM)", "organization": "Joint Committee for Guides in Metrology (BIPM)", "url": "https://www.bipm.org/en/committees/jc/jcgm/publications", "version_or_date": "JCGM 106:2012; JCGM 100:2008 with Amendment 1 (2026); JCGM 200:2012 (VIM)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T11:28:00Z", "relevance": "Authoritative treatment of measurement uncertainty and its role in conformity decisions, and the metrological vocabulary for quantity, unit, measurement result and traceability. Grounds the uncertainty/traceability finding and the requirement to state uncertainty before deciding conformity." }, { "id": "SRC-016", "title": "Standards for Educational and Psychological Testing (open-access edition)", "organization": "AERA, APA and NCME", "url": "https://www.testingstandards.net/open-access-files.html", "version_or_date": "2014 edition (1999 edition also available)", "source_type": "scientific", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-29T11:30:00Z", "relevance": "Joint professional standards treating validity, reliability/precision and fairness as foundations, with operations chapters on test design, scores and cut scores, administration, scoring, reporting, supporting documentation and test-taker rights. Grounds the validity/reliability/fairness evidence finding and appeal rights of the assessed subject." } ], "structure": { "bundles": [ { "id": "bn-frame", "name": "Assessment Frame, Subject and Scope", "description": "What this assessment is, who mandated it, what it is about, and where its boundary lies.", "rationale": "Every reviewed standard begins by fixing an object of assessment and a bounded scope before any criterion is applied: OSCAL names an assessment-subject and reviewed-controls, WCAG-EM makes scope definition and sampling the first two steps, and FHIR RiskAssessment requires a subject. Framing errors invalidate everything downstream, so identity, mandate, subject and scope are grouped as one top-level concern.", "source_refs": [ "SRC-002", "SRC-013", "SRC-007", "SRC-012" ], "layers": [ { "id": "ly-identity-mandate", "name": "Identity and Mandate", "description": "How the assessment record is identified and versioned, and the authority and purpose under which it exists.", "source_refs": [ "SRC-002", "SRC-012", "SRC-007" ], "findings": [ { "id": "fd-record-identity", "name": "Assessment record identity, granularity and versioning", "description": "The identifier that authoritatively designates this assessment, the unit of record it covers, and how successive versions and supersessions are distinguished from independent re-assessments.", "source_refs": [ "SRC-002", "SRC-007", "SRC-011" ], "questions": [ { "id": "q-record-identifier", "text": "Which identifier authoritatively designates this assessment record, and which system issued it?", "kind": "identity", "answer_data": [ "Issuing system of record", "Primary identifier value and its scheme", "Alternate or business identifiers with their schemes" ] }, { "id": "q-record-granularity", "text": "What is the atomic unit of the record: one subject, one criteria set, one occasion, or a combination?", "kind": "definition", "answer_data": [ "Declared record granularity", "Components of the composite key", "Rules for splitting or merging records" ] }, { "id": "q-record-version", "text": "How are successive versions of the same assessment distinguished from a new, independent assessment?", "kind": "lifecycle", "answer_data": [ "Version label or sequence", "Supersedes and superseded-by pointers", "Rule distinguishing amendment from re-assessment" ] }, { "id": "q-record-derivation", "text": "Which prior assessment, plan or request does this record derive from or fulfil?", "kind": "provenance", "answer_data": [ "Basis or derived-from reference", "Fulfilled request or engagement reference", "Relationship type between the records" ] } ], "data_elements": [ { "id": "de-assessment-id", "name": "Assessment identifier", "description": "Authoritative identifier of the assessment record, with its issuing scheme.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "de-assessment-version", "name": "Assessment version", "description": "Version label or sequence of this revision of the assessment.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-supersedes-ref", "name": "Supersedes reference", "description": "Pointer to the assessment version this record replaces.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-011" ] }, { "id": "de-record-granularity", "name": "Record granularity", "description": "Declared unit of record (subject-occasion, subject-criteria-set, campaign item).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Identity, granularity and supersession are pure reference data carried on the record itself — identifier values, scheme names and pointers. Nothing is rendered, captured or attached here; any document that displays these values is produced by the conclusion or disclosure findings, so declaring an artifact would duplicate them." }, { "id": "fd-type-stakes-mandate", "name": "Assessment type, stakes and mandate", "description": "The class of assessment, the party relationship between assessor and subject, the scheme or legal basis authorising it, and the consequence class its result carries.", "source_refs": [ "SRC-001", "SRC-012", "SRC-007", "SRC-010" ], "questions": [ { "id": "q-assessment-kind", "text": "Which class of assessment is this: conformity, diagnostic, formative, summative, risk, quality, appraisal or peer review?", "kind": "classification", "answer_data": [ "Assessment type code and its code system", "Purpose statement", "Formative versus summative flag" ] }, { "id": "q-party-relationship", "text": "Is this a first-party, second-party or third-party assessment relative to the subject?", "kind": "relationship", "answer_data": [ "Party-relationship code", "Description of the assessor-to-subject relationship", "Declared independence level" ] }, { "id": "q-mandate-basis", "text": "Under what mandate, scheme or legal basis is the assessment carried out?", "kind": "authority", "answer_data": [ "Scheme or programme reference with version", "Legal, regulatory or contractual basis citation", "Designation or notification reference where legal effect is claimed" ] }, { "id": "q-stakes-class", "text": "What consequences attach to the result, and who commissioned it?", "kind": "ownership", "answer_data": [ "Consequence class (informational, gating, regulatory)", "Requesting party reference", "Relying or beneficiary party reference" ] } ], "data_elements": [ { "id": "de-assessment-type", "name": "Assessment type", "description": "Coded class of assessment.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "de-party-relationship", "name": "Party relationship", "description": "First-, second- or third-party relationship of assessor to subject.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-012" ] }, { "id": "de-scheme-ref", "name": "Scheme reference", "description": "Reference to the conformity assessment scheme, programme or examination framework.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-010" ] }, { "id": "de-stakes-class", "name": "Consequence class", "description": "Declared class of consequence attaching to the result.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "These are classificatory and authority-bearing reference values that qualify the record. The scheme document, the legal instrument and the party records they point to are held and versioned by referenced sibling models, so materialising a local artifact would copy content this model must not own." } ] }, { "id": "ly-subject-scope", "name": "Subject and Scope", "description": "What was assessed, in what state, and how the assessed boundary and sample were drawn.", "source_refs": [ "SRC-013", "SRC-002", "SRC-007" ], "findings": [ { "id": "fd-subject-identification", "name": "Subject identification and assessed state", "description": "Which object of assessment was examined, at which pinned version, configuration or state, whether it is an individual, batch, population or system, and where it was located when that matters.", "source_refs": [ "SRC-002", "SRC-007", "SRC-010" ], "questions": [ { "id": "q-subject-identity", "text": "Which identifier and identifier scheme designate the object of assessment?", "kind": "identity", "answer_data": [ "Subject reference with its owning model", "Identifier scheme", "Human-readable designation for reporting" ] }, { "id": "q-subject-state", "text": "What version, configuration or state of the subject was assessed, and how is that state pinned?", "kind": "state", "answer_data": [ "Pinned state descriptor (version, build, configuration hash)", "Method used to pin the state", "Time at which the state was fixed" ] }, { "id": "q-subject-population", "text": "Is the subject an individual item, a batch, a population or a system, and how is membership defined?", "kind": "composition", "answer_data": [ "Subject kind code", "Membership or inclusion rule", "Enumerated or referenced member set" ] }, { "id": "q-subject-location", "text": "Where was the subject located or deployed at the time of assessment, when location affects the result?", "kind": "spatial", "answer_data": [ "Site or deployment reference", "Jurisdiction relevant to the criteria", "Environmental conditions affecting validity" ] } ], "data_elements": [ { "id": "de-subject-ref", "name": "Subject reference", "description": "Reference to the assessed object in its owning domain model.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "de-subject-kind", "name": "Subject kind", "description": "Whether the subject is an item, batch, population, system, person or process.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-013" ] }, { "id": "de-subject-state-descriptor", "name": "Assessed state descriptor", "description": "Pinned version, build or configuration identifier of the subject as assessed.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-004" ] }, { "id": "de-subject-site-ref", "name": "Subject site reference", "description": "Location or deployment context of the subject during assessment.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "The subject's own description, structure and lifecycle belong to its domain model; this finding holds only a reference plus a pinned state descriptor. Attaching a subject artifact here would reproduce target-owned content and create a second, divergent copy of the subject record." }, { "id": "fd-scope-sampling", "name": "Scope boundary, sampling and generalisation limits", "description": "What was explicitly inside and outside the assessed scope, how a sample was selected and sized if the whole subject was not assessed, and how far the result may legitimately be generalised.", "source_refs": [ "SRC-013", "SRC-003", "SRC-002" ], "questions": [ { "id": "q-scope-statement", "text": "What is explicitly inside and outside the assessed scope?", "kind": "definition", "answer_data": [ "Scope statement", "Enumerated exclusions with reasons", "Boundary conditions and interfaces treated as external" ] }, { "id": "q-sampling-method", "text": "If a sample was assessed rather than the whole subject, how was the sample selected and sized?", "kind": "process", "answer_data": [ "Sampling strategy (structured, random, census, risk-based)", "Sample size and selection rationale", "Proportion of randomly selected items" ] }, { "id": "q-generalisation-limit", "text": "To what extent may the result be generalised beyond the assessed sample or scope?", "kind": "constraint", "answer_data": [ "Generalisation statement or explicit prohibition", "Confidence attached to extrapolation", "Known non-representative areas" ] }, { "id": "q-scope-change", "text": "What happens to the assessment if the scope changes while it is in progress?", "kind": "exception", "answer_data": [ "Scope-change handling rule", "Re-baselining requirement", "Effect on already-recorded results" ] } ], "data_elements": [ { "id": "de-scope-statement", "name": "Scope statement", "description": "Declared inclusions and exclusions of the assessment.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-002" ] }, { "id": "de-sampling-strategy", "name": "Sampling strategy", "description": "Coded strategy used to select the assessed sample.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-003" ] }, { "id": "de-sample-size", "name": "Sample size", "description": "Number of items assessed and the population size where known.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "de-generalisation-limit", "name": "Generalisation limit", "description": "Statement of how far the result may be extended beyond the sample.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Scope, sampling design and generalisation limits are declarative statements and counts that must be readable inline by any consumer before it trusts a conclusion. WCAG-EM treats them as reported steps rather than deliverables, and the sampled items themselves are registered as evidence references elsewhere." } ] } ] }, { "id": "bn-criteria", "name": "Criteria, Method and Scale", "description": "Which criteria apply at which version, how they were examined, and the scale and decision rule by which results are expressed and decided.", "rationale": "OSCAL, XCCDF and Common Criteria all keep a versioned criteria catalogue separate from the instance that binds it, and all reviewed formats require an explicit method and result vocabulary. ILAC-G8 and JCGM 106 additionally require an explicit decision rule before a conformity statement. Binding, method and decision rule together determine whether a result is interpretable and reproducible.", "source_refs": [ "SRC-002", "SRC-004", "SRC-010", "SRC-011", "SRC-015" ], "layers": [ { "id": "ly-criteria-binding", "name": "Criteria Binding", "description": "Reference and version binding to the criteria source, and which criteria were selected, excluded or added.", "source_refs": [ "SRC-002", "SRC-004", "SRC-010" ], "findings": [ { "id": "fd-criterion-binding", "name": "Criterion reference and version binding", "description": "The catalogue, standard or rubric supplying the criteria, the version pinned for this assessment, the locator for each individual criterion, and any interpretation applied to ambiguous criterion text.", "source_refs": [ "SRC-002", "SRC-004", "SRC-010" ], "questions": [ { "id": "q-criteria-source", "text": "Which criteria catalogue, standard or rubric supplies the criteria, at which version?", "kind": "relationship", "answer_data": [ "Criteria source reference and owning model", "Pinned catalogue version or release", "Publisher and authority of the source" ] }, { "id": "q-criterion-locator", "text": "How is an individual criterion addressed unambiguously within that source?", "kind": "identity", "answer_data": [ "Criterion identifier and identifier scheme", "Path or clause locator within the source", "Statement or objective sub-locator" ] }, { "id": "q-criterion-interpretation", "text": "Where the criterion text is ambiguous, which interpretation or application note was applied?", "kind": "definition", "answer_data": [ "Interpretation note text", "Reference to a published interpretation or technical decision", "Actor who authorised the interpretation" ] }, { "id": "q-binding-stability", "text": "How is the exact criteria version preserved so the result stays reproducible after the catalogue changes?", "kind": "temporal", "answer_data": [ "Version-pinning mechanism", "Retained snapshot or digest of the bound criteria", "Policy on recomputation when the catalogue changes" ] } ], "data_elements": [ { "id": "de-criteria-source-ref", "name": "Criteria source reference", "description": "Reference to the catalogue, standard or rubric supplying criteria.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-010" ] }, { "id": "de-criteria-version", "name": "Criteria version", "description": "Pinned version of the criteria source used by this assessment.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-010" ] }, { "id": "de-criterion-id", "name": "Criterion identifier", "description": "Identifier of an individual bound criterion within the source.", "value_kind": "identifier", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-004" ] }, { "id": "de-interpretation-note", "name": "Interpretation note", "description": "Recorded interpretation applied to a criterion for this assessment.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "This finding deliberately carries only a reference, a pinned version and a locator. The criterion's normative text, structure and lifecycle are owned by the criteria catalogue model; embedding them as an artifact here would duplicate target-owned content and let a local copy drift from the authoritative source." }, { "id": "fd-criterion-selection", "name": "Criterion selection, applicability and tailoring", "description": "Which criteria from the bound source were selected, which were declared not applicable and why, and whether any criteria were added beyond the source and under whose authority.", "source_refs": [ "SRC-003", "SRC-004", "SRC-010" ], "questions": [ { "id": "q-criteria-selection", "text": "Which criteria from the source were selected for this assessment, and on what basis?", "kind": "decision", "answer_data": [ "Selected criterion set or profile reference", "Selection basis (profile, risk, scheme requirement)", "Actor who approved the selection" ] }, { "id": "q-criteria-nonapplicable", "text": "Which criteria were declared not applicable, and what justifies each exclusion?", "kind": "exception", "answer_data": [ "Not-applicable criterion list", "Justification per exclusion", "Approval reference for the exclusion" ] }, { "id": "q-criteria-additions", "text": "Were any criteria added beyond the referenced source, and under whose authority?", "kind": "authority", "answer_data": [ "Added criterion reference or local text", "Authority for the addition", "Whether the addition affects claimed conformance to the source" ] } ], "data_elements": [ { "id": "de-selected-criteria", "name": "Selected criteria set", "description": "The set of criteria in effect for this assessment, or the profile that defines it.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-003" ] }, { "id": "de-not-applicable-justification", "name": "Not-applicable justification", "description": "Reason a selected-out criterion does not apply to this subject or scope.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-003" ] }, { "id": "de-added-criterion-ref", "name": "Added criterion reference", "description": "Criterion applied beyond the referenced source, with its authority.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "Selection and tailoring are decisions about the referenced catalogue, expressible as identifier lists with justifications. Where a scheme publishes a reusable profile, that profile is a catalogue-side artifact referenced by identifier and version, not a document this model produces." } ] }, { "id": "ly-method-execution", "name": "Method and Execution", "description": "How each criterion was examined and what must be preserved for the result to be reproducible.", "source_refs": [ "SRC-003", "SRC-005", "SRC-004", "SRC-008" ], "findings": [ { "id": "fd-method-instrument", "name": "Assessment method, instrument, mode and coverage", "description": "Which methods were used to examine each criterion, whether results were produced automatically, manually or semi-automatically, the depth and coverage applied, and the instrument, rubric or item set that operationalises the criterion.", "source_refs": [ "SRC-003", "SRC-005", "SRC-008", "SRC-013" ], "questions": [ { "id": "q-method-declared", "text": "Which assessment methods were used, such as examine, interview, test, inspect or elicited judgement?", "kind": "process", "answer_data": [ "Method codes per criterion", "Method code system", "Sequence or combination rule where several methods apply" ] }, { "id": "q-mode-declared", "text": "Was each result produced automatically, manually or semi-automatically, and by which agent?", "kind": "classification", "answer_data": [ "Mode code per result", "Agent reference (human, tool, hybrid team)", "Disclosure state of the mode where it is undisclosed" ] }, { "id": "q-depth-coverage", "text": "What depth and coverage were applied, and what do they imply about assurance?", "kind": "measurement", "answer_data": [ "Depth attribute value", "Coverage attribute value", "Assurance implication statement" ] }, { "id": "q-instrument-def", "text": "Which instrument, rubric, item set or procedure defines how each criterion is examined?", "kind": "composition", "answer_data": [ "Instrument or rubric reference with version", "Item or check identifiers bound to each criterion", "Administration conditions required by the instrument" ] } ], "data_elements": [ { "id": "de-method-code", "name": "Assessment method code", "description": "Coded method applied to a criterion.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "de-mode-code", "name": "Assessment mode", "description": "Automatic, manual, semi-automatic or undisclosed production mode of a result.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "de-depth-attr", "name": "Depth attribute", "description": "Rigour applied to examination of a criterion.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-coverage-attr", "name": "Coverage attribute", "description": "Breadth of assessment objects examined for a criterion.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-instrument-ref", "name": "Instrument reference", "description": "Reference to the rubric, item set, benchmark profile or procedure used.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-004" ] } ], "artifacts": [ { "id": "af-assessment-procedure", "name": "Assessment procedure or plan", "description": "The written or machine-readable procedure that states, per criterion, which methods, objects, depth and coverage apply for this assessment.", "media_or_form": [ "structured procedure document", "machine-readable assessment plan", "checklist or profile definition" ], "serial": false, "identity_strategy": "Identified by the procedure's own master-system identifier and version issued by its publisher; the assessment references it by identifier plus version, never by title. Where the procedure is written specifically for this assessment, it takes a Dimension-assigned UUID bound to the assessment identifier.", "source_refs": [ "SRC-003", "SRC-002", "SRC-004" ] }, { "id": "af-instrument-definition", "name": "Instrument, rubric or item-set definition", "description": "The definition of the measuring instrument used: rubric levels, item bank, questionnaire or benchmark profile, including administration conditions.", "media_or_form": [ "rubric definition", "item bank or item set", "questionnaire or form definition", "benchmark or profile definition" ], "serial": false, "identity_strategy": "Publisher identifier plus edition or version for published instruments; a Dimension-assigned UUID plus version for locally authored instruments. Never identified by administration date.", "source_refs": [ "SRC-008", "SRC-016", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "fd-execution-parameters", "name": "Execution parameters and reproducibility", "description": "The tool, model or engine references, versions, configuration profiles and input snapshots that were in force when machine-generated results were produced, captured so an independent party can reproduce them.", "source_refs": [ "SRC-004", "SRC-002", "SRC-009" ], "questions": [ { "id": "q-tool-identity", "text": "Which tool, model or engine produced each machine-generated result, at which version?", "kind": "provenance", "answer_data": [ "Tool or model reference", "Version and build identifier", "Vendor or maintainer reference" ] }, { "id": "q-config-snapshot", "text": "What configuration, profile, thresholds and input data snapshot were in force during execution?", "kind": "constraint", "answer_data": [ "Configuration or profile reference with version", "Threshold and parameter values applied", "Input dataset or snapshot reference with digest" ] }, { "id": "q-reproducibility", "text": "What must be preserved for an independent party to reproduce the same results?", "kind": "quality", "answer_data": [ "Minimum reproducibility bundle contents", "Known sources of non-determinism", "Retention requirement for the reproducibility bundle" ] } ], "data_elements": [ { "id": "de-tool-ref", "name": "Tool or engine reference", "description": "Reference to the tool, model or engine that produced a machine result.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-002" ] }, { "id": "de-tool-version", "name": "Tool version", "description": "Version or build of the referenced tool at execution time.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-config-profile", "name": "Configuration profile", "description": "Configuration, profile or parameter set in force at execution.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-009" ] }, { "id": "de-input-snapshot-ref", "name": "Input snapshot reference", "description": "Reference and digest of the input data snapshot used.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "af-execution-manifest", "name": "Execution parameter manifest", "description": "An immutable capture of the tool references, versions, configuration and input snapshot digests that the assessment relies on. It documents parameters; it does not schedule, invoke or control any evaluator, which remains owned by the referenced execution model.", "media_or_form": [ "configuration manifest", "tool and version inventory", "input snapshot digest list" ], "serial": true, "identity_strategy": "Series key is the assessment identifier; a zero-padded monotonically increasing run sequence distinguishes manifests, with a cryptographic digest recorded at registration. The sequence is never derived from a date.", "source_refs": [ "SRC-004", "SRC-002", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "ly-scale-decision", "name": "Scale and Decision Rule", "description": "The vocabulary and scale in which results are expressed, and the rule that converts them into a decision.", "source_refs": [ "SRC-004", "SRC-005", "SRC-011", "SRC-014", "SRC-015" ], "findings": [ { "id": "fd-outcome-scale", "name": "Outcome scale and result vocabulary", "description": "The measurement level, bounds and favourable direction of any numeric scale, the controlled vocabulary for non-numeric outcomes, and how indeterminate, inapplicable, untested and error states are kept distinct from a negative result.", "source_refs": [ "SRC-004", "SRC-005", "SRC-014", "SRC-008" ], "questions": [ { "id": "q-scale-type", "text": "Is the outcome nominal, ordinal, interval or ratio, and what are its bounds?", "kind": "measurement", "answer_data": [ "Measurement level", "Minimum and maximum attainable values", "Permitted arithmetic on the scale" ] }, { "id": "q-outcome-vocabulary", "text": "Which controlled vocabulary expresses non-numeric outcomes for this assessment?", "kind": "classification", "answer_data": [ "Outcome code system and version", "Enumerated outcome values with definitions", "Default value where no result is produced" ] }, { "id": "q-scale-direction", "text": "Which direction of the scale is favourable, and what are the best and worst attainable values?", "kind": "definition", "answer_data": [ "Best-rating value", "Worst-rating value", "Polarity statement" ] }, { "id": "q-missing-result", "text": "How are untested, not-checked, error and not-selected states distinguished from a negative result?", "kind": "exception", "answer_data": [ "Enumerated indeterminate values", "Rule forbidding coercion to a negative result", "Downstream handling of each indeterminate value" ] } ], "data_elements": [ { "id": "de-scale-def-ref", "name": "Scale definition reference", "description": "Reference to the versioned scale definition in effect.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-014" ] }, { "id": "de-scale-min", "name": "Worst attainable value", "description": "Lowest value the scale permits.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "de-scale-max", "name": "Best attainable value", "description": "Highest value the scale permits.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014", "SRC-008" ] }, { "id": "de-outcome-code-system", "name": "Outcome code system", "description": "Identifier and version of the vocabulary supplying outcome values.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "A scale is definitional reference data — bounds, polarity, level of measurement and an enumerated vocabulary — that must be resolvable inline for any consumer to interpret a score. The authoritative scale and code-system documents are held by the vocabulary registry this model aligns to, so producing a local artifact would fork a governed vocabulary." }, { "id": "fd-decision-rule", "name": "Decision rule, thresholds and uncertainty handling", "description": "The rule that converts scored or determined values into a conformity or grade decision, the cut scores, acceptance limits and guard bands it uses, how uncertainty is accounted for beforehand, and the conditions under which the assessment must abstain.", "source_refs": [ "SRC-011", "SRC-015", "SRC-004", "SRC-009" ], "questions": [ { "id": "q-decision-rule", "text": "What decision rule converts measured or scored values into a conformity or grade decision?", "kind": "decision", "answer_data": [ "Decision rule reference and version", "Rule expression or narrative statement", "Party that set the rule" ] }, { "id": "q-threshold-values", "text": "What cut scores, acceptance limits or guard bands apply, and who set them?", "kind": "constraint", "answer_data": [ "Cut score or acceptance limit values", "Guard band width and basis", "Authority that established the thresholds" ] }, { "id": "q-uncertainty-effect", "text": "How is measurement or rater uncertainty accounted for before the decision is taken?", "kind": "measurement", "answer_data": [ "Uncertainty treatment method", "Risk of false accept or false reject accepted", "Whether the rule is binary or non-binary" ] }, { "id": "q-indeterminate-outcome", "text": "Under what conditions must the assessment abstain rather than decide?", "kind": "exception", "answer_data": [ "Abstention conditions", "Required action when abstaining", "How abstention is expressed in the outcome vocabulary" ] } ], "data_elements": [ { "id": "de-decision-rule-ref", "name": "Decision rule reference", "description": "Reference to the versioned decision rule applied.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-015" ] }, { "id": "de-cut-score", "name": "Cut score or acceptance limit", "description": "Threshold value separating outcome categories.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-016" ] }, { "id": "de-guard-band", "name": "Guard band", "description": "Interval applied to acceptance limits to control decision risk.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-015" ] }, { "id": "de-abstention-condition", "name": "Abstention condition", "description": "Condition requiring an indeterminate rather than a decided outcome.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "The decision rule must be machine-readable inline so a consumer can re-derive the conclusion from the recorded values. Where the rule is published by a scheme or laboratory quality system, it is referenced by identifier and version; enforcing or executing the rule against live systems belongs to the referenced enforcement model, not here." } ] } ] }, { "id": "bn-evidence", "name": "Evidence and Observation", "description": "What was relied on, how it links to criteria, whether it is sound, and what was actually observed.", "rationale": "OSCAL separates observations carrying evidence from findings that judge criteria; SP 800-53A ties evidence to determination statements; EARL requires a subject and a test behind every result. Evidence handling is therefore a distinct top-level concern from determination, and its quality qualifiers decide whether a conclusion is defensible.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-015" ], "layers": [ { "id": "ly-evidence-corpus", "name": "Evidence Corpus", "description": "The evidence items relied on, their linkage to criteria, and their quality and admissibility.", "source_refs": [ "SRC-002", "SRC-003" ], "findings": [ { "id": "fd-evidence-linkage", "name": "Evidence items and criterion linkage", "description": "The discrete evidence items relied on, their types, the criterion or determination statement each supports or contradicts, and the times at which each was created, collected and received.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ], "questions": [ { "id": "q-evidence-inventory", "text": "What discrete evidence items were relied on, and of what type is each?", "kind": "composition", "answer_data": [ "Evidence item references", "Evidence type codes", "Origin of each item (subject-supplied, assessor-collected, machine-generated)" ] }, { "id": "q-evidence-link", "text": "Which criterion or determination statement does each evidence item support or contradict?", "kind": "relationship", "answer_data": [ "Evidence-to-criterion linkage pairs", "Direction of support (supporting, contradicting, contextual)", "Weight or role of the item in the determination" ] }, { "id": "q-evidence-sufficiency", "text": "What makes the evidence set sufficient to support the determination for each criterion?", "kind": "evidence", "answer_data": [ "Sufficiency rule or minimum evidence requirement", "Gap statement where evidence is thin", "Actor who judged sufficiency" ] }, { "id": "q-evidence-collection-time", "text": "When was each evidence item created, collected and received?", "kind": "temporal", "answer_data": [ "Creation time of the evidence", "Collection time", "Receipt or ingestion time into the assessment" ] } ], "data_elements": [ { "id": "de-evidence-item-ref", "name": "Evidence item reference", "description": "Pointer to an evidence object held by the referenced custody model.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-003" ] }, { "id": "de-evidence-type", "name": "Evidence type", "description": "Coded type of an evidence item.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-003" ] }, { "id": "de-evidence-criterion-link", "name": "Evidence-criterion linkage", "description": "Association between an evidence item and the criterion it bears on.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-005" ] }, { "id": "de-evidence-collected-at", "name": "Evidence collection time", "description": "Time an evidence item was collected, distinct from when it was created.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "af-evidence-object", "name": "Evidence object", "description": "A discrete item of evidence relied on by the assessment. The bytes and custody remain with the referenced evidence repository; the assessment registers the pointer, type and integrity digest.", "media_or_form": [ "document", "image or screenshot", "log or machine output", "sample or specimen reference", "interview or observation record", "dataset extract" ], "serial": false, "identity_strategy": "Custody-system identifier issued by the referenced evidence repository takes priority; where none exists, a digest-derived content identifier plus a Dimension-assigned UUID. Filenames and collection dates are never identifiers.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ] }, { "id": "af-evidence-index", "name": "Evidence-to-criterion linkage register", "description": "The register mapping each registered evidence item to the criteria and determinations it supports or contradicts, with sufficiency notes.", "media_or_form": [ "linkage table", "machine-readable index" ], "serial": true, "identity_strategy": "Series key is the assessment identifier; the sequence number is the assessment version the index belongs to, so each finalised version retains its own frozen index.", "source_refs": [ "SRC-002", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "fd-evidence-quality", "name": "Evidence quality, admissibility and reuse limits", "description": "Whether each item is authentic and unaltered since collection, whether it is still current for the assessed state, which offered evidence was rejected or down-weighted, and which items carry confidentiality or personal-data constraints limiting reuse.", "source_refs": [ "SRC-002", "SRC-003", "SRC-016", "SRC-012" ], "questions": [ { "id": "q-evidence-authenticity", "text": "How is each evidence item shown to be authentic and unaltered since collection?", "kind": "security", "answer_data": [ "Integrity digest and algorithm", "Signature or witness reference", "Custody assurance statement from the referenced repository" ] }, { "id": "q-evidence-currency", "text": "Is the evidence still current for the assessed state, and when does it cease to be?", "kind": "validation", "answer_data": [ "Evidence expiry or staleness date", "Maximum permitted age per evidence type", "Effect of staleness on dependent determinations" ] }, { "id": "q-evidence-exclusion", "text": "Which offered evidence was rejected or down-weighted, and why?", "kind": "quality", "answer_data": [ "Rejected item references", "Rejection or down-weighting reason", "Actor who decided the exclusion" ] }, { "id": "q-evidence-confidentiality", "text": "Which evidence carries confidentiality, personal-data or privilege constraints that limit reuse?", "kind": "privacy", "answer_data": [ "Sensitivity classification per item", "Lawful basis or consent reference", "Permitted reuse and disclosure scope" ] } ], "data_elements": [ { "id": "de-evidence-integrity-digest", "name": "Evidence integrity digest", "description": "Digest and algorithm recorded for an evidence item at registration.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-evidence-expiry", "name": "Evidence expiry", "description": "Date after which an evidence item is no longer treated as current.", "value_kind": "date", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-evidence-exclusion-reason", "name": "Evidence exclusion reason", "description": "Reason an offered evidence item was rejected or down-weighted.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-016" ] }, { "id": "de-evidence-sensitivity-class", "name": "Evidence sensitivity class", "description": "Confidentiality or personal-data classification of an evidence item.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "Quality qualifiers are assertions attached to evidence already registered by the linkage finding: digests, expiry dates, exclusion reasons and sensitivity codes. The evidence bytes are held by the referenced custody model and the artifact for them is declared once, so restating them here would create a second registration of the same object." } ] }, { "id": "ly-observation-measurement", "name": "Observation and Measurement", "description": "Raw observed results with distinct event and recording times, and the uncertainty and traceability that qualify quantitative values.", "source_refs": [ "SRC-002", "SRC-015", "SRC-007" ], "findings": [ { "id": "fd-observation-record", "name": "Observation records, actors and timing", "description": "The raw result observed or returned for each check before judgement is applied, the actor or device that produced it, the separation of the time the observed condition held from the time the observation was recorded, and the place of observation where it matters.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007", "SRC-004" ], "questions": [ { "id": "q-observed-result", "text": "What raw result was observed or returned for each check before judgement was applied?", "kind": "measurement", "answer_data": [ "Raw observed value or return code", "Observation method", "Reference to the check or item that produced it" ] }, { "id": "q-observation-actor", "text": "Which actor or device produced the observation, and under which role?", "kind": "provenance", "answer_data": [ "Observer reference (person, device, software agent)", "Role in which the observer acted", "Delegation chain where the observer acted on behalf of another" ] }, { "id": "q-observation-times", "text": "How are the time the observed condition held and the time the observation was recorded kept distinct?", "kind": "temporal", "answer_data": [ "Event time of the observed condition", "Recording or ingestion time", "Clock source and offset handling" ] }, { "id": "q-observation-location", "text": "Where was the observation taken when site or environment materially affects the result?", "kind": "spatial", "answer_data": [ "Observation site reference", "Environmental conditions recorded", "Effect of location on interpretation" ] } ], "data_elements": [ { "id": "de-observed-value", "name": "Observed value", "description": "Raw result returned by a check before judgement.", "value_kind": "other", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-002" ] }, { "id": "de-observation-method", "name": "Observation method", "description": "Method by which an observation was obtained.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003" ] }, { "id": "de-observation-event-time", "name": "Observation event time", "description": "Time at which the observed condition held.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] }, { "id": "de-observation-recorded-time", "name": "Observation recording time", "description": "Time at which the observation was recorded or ingested.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] } ], "artifacts": [ { "id": "af-raw-result-output", "name": "Raw result output", "description": "The unmodified output of a check, field observation or candidate response session, retained so determinations can be re-derived from what was actually seen.", "media_or_form": [ "tool result file", "field observation form", "candidate response record", "instrument reading log" ], "serial": true, "identity_strategy": "Series key is the assessment identifier combined with the producing tool or observer reference; sequence increments per run. Event time and recording time are carried inside the output, never used as its identifier.", "source_refs": [ "SRC-004", "SRC-008", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "fd-uncertainty-traceability", "name": "Measurement uncertainty and traceability", "description": "The stated uncertainty of each quantitative result and how it was evaluated, the quantity, unit and reference scale each value belongs to, and the calibration or reference standard the measurement is traceable to.", "source_refs": [ "SRC-015", "SRC-011", "SRC-007" ], "questions": [ { "id": "q-uncertainty-value", "text": "What is the stated uncertainty of each quantitative result and how was it evaluated?", "kind": "measurement", "answer_data": [ "Uncertainty value and coverage factor", "Evaluation method (Type A, Type B, replicate, expert)", "Components contributing to the uncertainty budget" ] }, { "id": "q-unit-and-quantity", "text": "Which quantity, unit and reference scale does each numeric value belong to?", "kind": "definition", "answer_data": [ "Quantity kind", "Unit code and code system", "Reference scale or datum" ] }, { "id": "q-traceability-chain", "text": "To what reference standard or calibration is the measurement traceable?", "kind": "provenance", "answer_data": [ "Calibration record reference", "Reference standard identity", "Calibration validity window" ] } ], "data_elements": [ { "id": "de-measured-quantity", "name": "Measured quantity", "description": "Quantitative result with its unit.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015" ] }, { "id": "de-uncertainty", "name": "Measurement uncertainty", "description": "Stated uncertainty associated with a quantitative result.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015", "SRC-011" ] }, { "id": "de-unit-code", "name": "Unit code", "description": "Unit of measure with its code system.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015", "SRC-007" ] }, { "id": "de-calibration-ref", "name": "Calibration reference", "description": "Pointer to the calibration or reference standard establishing traceability.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015", "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "Uncertainty statements, units and traceability pointers are declared values carried alongside each quantitative result. Calibration certificates and the traceability chain are produced and maintained by the referenced metrology model; this model neither runs calibration programmes nor issues those certificates, so it declares no artifact for them." } ] } ] }, { "id": "bn-results", "name": "Determination, Scoring and Conclusion", "description": "Criterion-level verdicts and scores, their aggregation into a composite result, and the stated conclusion with its validity.", "rationale": "ISO/IEC 17000 distinguishes determination from review and from decision; OSCAL distinguishes observations from findings; XCCDF distinguishes rule-results from a scored TestResult. This bundle keeps criterion-level determination, aggregation and the accountable conclusion as separate, traceable steps rather than collapsing them into a single verdict.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-011" ], "layers": [ { "id": "ly-criterion-outcomes", "name": "Criterion-Level Outcomes", "description": "Per-criterion verdicts with rationale and locators, and the raw and normalised scores that accompany them.", "source_refs": [ "SRC-002", "SRC-005", "SRC-008" ], "findings": [ { "id": "fd-criterion-verdict", "name": "Criterion verdict, rationale and locator", "description": "The outcome value assigned to each criterion from the bound vocabulary, the reasoning connecting cited evidence to that outcome, the severity or materiality of negative outcomes, and where in the subject each negative outcome occurs.", "source_refs": [ "SRC-005", "SRC-002", "SRC-003", "SRC-004" ], "questions": [ { "id": "q-criterion-outcome", "text": "What outcome value was assigned to each criterion, from which vocabulary?", "kind": "state", "answer_data": [ "Outcome value per criterion", "Outcome code system and version", "Whether the value is determined, indeterminate or not applicable" ] }, { "id": "q-verdict-rationale", "text": "What reasoning connects the cited evidence to each criterion outcome?", "kind": "evidence", "answer_data": [ "Rationale text per outcome", "References to the evidence items relied on", "Assumptions made in reaching the outcome" ] }, { "id": "q-nonconformity-grading", "text": "How are negative outcomes graded by severity or materiality?", "kind": "classification", "answer_data": [ "Severity or materiality code", "Grading scheme reference", "Threshold at which a negative outcome blocks a positive conclusion" ] }, { "id": "q-verdict-locator", "text": "Where in the subject does each negative outcome occur?", "kind": "spatial", "answer_data": [ "Pointer or locator into the subject", "Locator notation and version", "Number of occurrences found" ] } ], "data_elements": [ { "id": "de-criterion-outcome", "name": "Criterion outcome", "description": "Outcome value assigned to a single criterion.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "de-outcome-rationale", "name": "Outcome rationale", "description": "Reasoning linking evidence to a criterion outcome.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-003" ] }, { "id": "de-nonconformity-severity", "name": "Nonconformity severity", "description": "Graded severity or materiality of a negative outcome.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-009" ] }, { "id": "de-outcome-pointer", "name": "Outcome locator", "description": "Pointer identifying where in the subject a negative outcome occurs.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Criterion outcomes are structured values keyed to criterion identifiers and must be queryable, sortable and diffable as data rather than read out of a rendered document. The report that presents them to a reader is declared once by the conclusion finding, which keeps a single authoritative rendition." }, { "id": "fd-criterion-score", "name": "Criterion scores and normalisation", "description": "The raw score recorded for each criterion against its maximum, how raw scores are normalised or rescaled before aggregation, and which scale definition version each recorded score refers to.", "source_refs": [ "SRC-008", "SRC-004", "SRC-014" ], "questions": [ { "id": "q-raw-score", "text": "What raw score, if any, was recorded for each criterion and against which maximum?", "kind": "measurement", "answer_data": [ "Raw score value", "Maximum attainable score for that criterion", "Whether partial credit was permitted" ] }, { "id": "q-normalisation", "text": "How are raw scores normalised or rescaled before aggregation?", "kind": "process", "answer_data": [ "Normalisation function or template", "Rounding and precision rules", "Treatment of out-of-range values" ] }, { "id": "q-score-scale-binding", "text": "Which scale definition version does each recorded score refer to?", "kind": "interoperability", "answer_data": [ "Scale reference with version per score", "Rule when scale versions differ across criteria", "Statement of whether historical scores are recomputed" ] } ], "data_elements": [ { "id": "de-raw-score", "name": "Raw score", "description": "Score recorded for a criterion before normalisation.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-max-score", "name": "Maximum score", "description": "Maximum attainable score for a criterion.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-normalised-score", "name": "Normalised score", "description": "Score after normalisation or rescaling.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-008" ] }, { "id": "de-score-scale-ref", "name": "Score scale reference", "description": "Versioned scale definition a score is expressed against.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-008" ] } ], "artifacts": [], "inline_only_rationale": "Scores are numeric data bound to a scale reference and must be recomputable and comparable across records. QTI keeps outcome variables as declared data separate from results reporting, and this finding follows that separation; the rendered scorecard is declared by the aggregation finding." } ] }, { "id": "ly-composite-conclusion", "name": "Composite Result, Conclusion and Validity", "description": "How criterion results roll up, what conclusion is stated and by whom, and for how long and under what conditions it holds.", "source_refs": [ "SRC-004", "SRC-001", "SRC-011", "SRC-012" ], "findings": [ { "id": "fd-aggregation-model", "name": "Aggregation model and composite result", "description": "The scoring or aggregation model that combines criterion results, the weights and precedence rules it applies, the form in which the composite is expressed, and how it is computed when some criteria are untested or indeterminate.", "source_refs": [ "SRC-004", "SRC-009", "SRC-013", "SRC-008" ], "questions": [ { "id": "q-aggregation-rule", "text": "Which scoring or aggregation model combines criterion results into a composite result?", "kind": "process", "answer_data": [ "Aggregation model identifier and version", "Model definition or reference", "Whether the model is documented as required for aggregated scores" ] }, { "id": "q-weighting", "text": "What weights or precedence rules apply, and how are unweighted and inapplicable items handled?", "kind": "constraint", "answer_data": [ "Weight per criterion or group", "Precedence and veto rules", "Treatment of not-applicable and unweighted items" ] }, { "id": "q-composite-expression", "text": "How is the composite result expressed, and must its inputs be published alongside it?", "kind": "measurement", "answer_data": [ "Composite form (score, level, grade, class, vector)", "Vector or input string required for republication", "Qualitative band mapping where one applies" ] }, { "id": "q-partial-results", "text": "How is a composite computed when some criteria are untested or indeterminate?", "kind": "exception", "answer_data": [ "Rule for excluding or imputing missing results", "Minimum completeness required for a composite", "Flag marking a composite as partial" ] } ], "data_elements": [ { "id": "de-aggregation-model", "name": "Aggregation model", "description": "Identifier of the scoring model used to combine criterion results.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-013" ] }, { "id": "de-criterion-weight", "name": "Criterion weight", "description": "Weight applied to a criterion or group in aggregation.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-composite-score", "name": "Composite score", "description": "Numeric composite produced by the aggregation model.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-009" ] }, { "id": "de-composite-level", "name": "Composite level or grade", "description": "Categorical composite result such as a level, grade or severity band.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-010" ] }, { "id": "de-result-vector", "name": "Result vector expression", "description": "Compact expression of the inputs that produced the composite score.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [ { "id": "af-score-report", "name": "Score report or scorecard", "description": "The rendition of criterion-level and composite results for a reader, carrying the aggregation model identifier, the scale reference and the result vector needed to interpret the numbers.", "media_or_form": [ "tabular scorecard", "score vector expression", "graded summary" ], "serial": true, "identity_strategy": "Series key is the assessment identifier; a zero-padded sequence increments per issued revision. Each revision cites the assessment version and the aggregation model version it was produced under.", "source_refs": [ "SRC-009", "SRC-008", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "fd-conclusion-statement", "name": "Conclusion statement, authority and qualification", "description": "The stated conclusion and its form, the actor accountable for it and whether the decision was separated from the determination work, the qualifications, adverse opinions or dissent attached, and what the conclusion entitles or obliges.", "source_refs": [ "SRC-001", "SRC-011", "SRC-012", "SRC-016" ], "questions": [ { "id": "q-conclusion-text", "text": "What is the stated conclusion, and is it binary, graded or narrative?", "kind": "definition", "answer_data": [ "Conclusion statement text", "Conclusion type code", "Scope of the subject the conclusion covers" ] }, { "id": "q-conclusion-authority", "text": "Who is accountable for the conclusion, and was the decision separated from the determination work?", "kind": "authority", "answer_data": [ "Decision maker reference", "Separation-of-duties statement", "Delegation or sign-off record reference" ] }, { "id": "q-conclusion-qualification", "text": "What qualifications, adverse opinions, dissent or minority positions attach to the conclusion?", "kind": "quality", "answer_data": [ "Qualification or caveat text", "Dissenting or minority position with its author", "Conditions attached to a qualified positive conclusion" ] }, { "id": "q-conclusion-consequence", "text": "What does the conclusion entitle or oblige, and which downstream act, if any, must follow?", "kind": "relationship", "answer_data": [ "Entitlement or obligation statement", "Referral to the attestation or certification act", "Explicit statement that no legal effect is claimed where none exists" ] } ], "data_elements": [ { "id": "de-conclusion-statement", "name": "Conclusion statement", "description": "The stated conclusion of the assessment.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-011" ] }, { "id": "de-conclusion-type", "name": "Conclusion type", "description": "Form of the conclusion: binary, graded, narrative or predictive.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "de-decision-maker-ref", "name": "Decision maker reference", "description": "Party accountable for the recorded conclusion.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-012" ] }, { "id": "de-dissent-note", "name": "Dissent or qualification note", "description": "Recorded qualification, adverse opinion or minority position.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] } ], "artifacts": [ { "id": "af-assessment-report", "name": "Assessment report or statement of conclusion", "description": "The authoritative rendition of the conclusion with its scope, criteria binding, decision rule, qualifications and validity, issued to the requesting and relying parties.", "media_or_form": [ "narrative report", "statement of conformity", "structured result document" ], "serial": true, "identity_strategy": "The assessing body's master-system report number takes priority; revisions are new zero-padded sequence numbers within the same series, each citing the revision it supersedes. Where no body-issued number exists, a Dimension-assigned UUID bound to the assessment identifier is used.", "source_refs": [ "SRC-011", "SRC-012", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "fd-validity-limits", "name": "Validity window, conditions and confidence", "description": "From when until when the conclusion is asserted to hold, the conditions whose breach voids it early, the surveillance or re-assessment needed to keep it current, and the confidence or assurance level claimed.", "source_refs": [ "SRC-001", "SRC-012", "SRC-010", "SRC-013" ], "questions": [ { "id": "q-validity-window", "text": "From when until when is the conclusion asserted to hold?", "kind": "temporal", "answer_data": [ "Valid-from timestamp", "Valid-until timestamp or open-ended flag", "Basis for the chosen duration" ] }, { "id": "q-validity-conditions", "text": "Which conditions, if breached, void the conclusion before its end date?", "kind": "constraint", "answer_data": [ "Voiding conditions", "Party obliged to report a breach", "Effect of a breach on dependent attestations" ] }, { "id": "q-surveillance-obligation", "text": "What ongoing surveillance or re-assessment is required to keep the conclusion current?", "kind": "requirement", "answer_data": [ "Surveillance activity and interval", "Party responsible for triggering it", "Consequence of a missed surveillance cycle" ] }, { "id": "q-confidence-statement", "text": "What confidence or assurance level is claimed, and on what basis?", "kind": "quality", "answer_data": [ "Assurance level or confidence value", "Basis for the claim (depth, coverage, sampling, package)", "Explicit limits of the claim" ] } ], "data_elements": [ { "id": "de-valid-from", "name": "Valid from", "description": "Time from which the conclusion is asserted to hold.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-valid-until", "name": "Valid until", "description": "Time at which the conclusion ceases to be asserted.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-010" ] }, { "id": "de-validity-condition", "name": "Validity condition", "description": "Condition whose breach voids the conclusion early.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-012" ] }, { "id": "de-confidence-level", "name": "Confidence or assurance level", "description": "Claimed level of confidence or assurance with its basis.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Validity is expressed as timestamps, conditions and a claimed assurance level that consumers must evaluate programmatically before relying on a conclusion. Surveillance activities themselves are executed under the referenced scheme or programme model, and any certificate that carries these dates is issued by the attestation model." } ] } ] }, { "id": "bn-assurance", "name": "Assurance of the Assessment Itself", "description": "Whether the people, tools and instrument behind the result can be relied on.", "rationale": "EU law makes legal effect depend on the designation of the body rather than the quality of the method; ILAC and ISO/IEC 17025 make impartiality and competence preconditions of a statement of conformity; and the AERA/APA/NCME Standards make validity, reliability and fairness foundational. Assurance of the assessor and the instrument is therefore a separate concern from the result itself.", "source_refs": [ "SRC-012", "SRC-011", "SRC-016", "SRC-001" ], "layers": [ { "id": "ly-assessor-independence", "name": "Assessor and Independence", "description": "Who performed the assessment, in what roles, with what competence and authorisation, and under what declared conflicts.", "source_refs": [ "SRC-011", "SRC-012", "SRC-006" ], "findings": [ { "id": "fd-assessor-identity", "name": "Assessor identity, roles and contribution", "description": "Which persons, teams, bodies or automated agents performed the assessment, how the roles of collecting, determining, reviewing and deciding were distributed, and which parts of the result are attributable to which agent.", "source_refs": [ "SRC-006", "SRC-005", "SRC-002" ], "questions": [ { "id": "q-assessor-who", "text": "Which persons, teams, bodies or automated agents performed the assessment?", "kind": "identity", "answer_data": [ "Assessor references with their owning party model", "Whether each assessor is human, organisational or automated", "Team composition where a panel acted" ] }, { "id": "q-assessor-role-split", "text": "How are the roles of collecting, determining, reviewing and deciding distributed?", "kind": "ownership", "answer_data": [ "Role assignment per assessor", "Separation-of-duties constraints applied", "Party acting on behalf of another" ] }, { "id": "q-contribution-attribution", "text": "Which parts of the result are attributable to which assessor or agent?", "kind": "provenance", "answer_data": [ "Attribution links from determinations to agents", "Activity start and end times per agent", "Plan or procedure the agent acted under" ] } ], "data_elements": [ { "id": "de-assessor-ref", "name": "Assessor reference", "description": "Reference to a person, body or automated agent that acted in the assessment.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-002" ] }, { "id": "de-assessor-role", "name": "Assessor role", "description": "Role in which an assessor acted.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-001" ] }, { "id": "de-attribution-link", "name": "Attribution link", "description": "Association between a recorded determination and the agent responsible for it.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Assessor identity and role assignment are references into the party model plus PROV-style attribution links. Personnel records, employment status and organisational structure are maintained by that referenced model, so this finding holds pointers and role codes only." }, { "id": "fd-competence-impartiality", "name": "Competence, authorisation and impartiality", "description": "The competence, qualification or accreditation supporting each assessor's participation, the designated scope within which the assessing body may act, declared relationships that could impair impartiality, and what the assessment explicitly does not entitle the assessor to assert.", "source_refs": [ "SRC-011", "SRC-012", "SRC-001", "SRC-016" ], "questions": [ { "id": "q-competence-basis", "text": "What competence, qualification or accreditation supports each assessor's participation?", "kind": "requirement", "answer_data": [ "Competence or qualification reference", "Accreditation or certification reference with validity", "Competence criteria the scheme requires" ] }, { "id": "q-authorisation-scope", "text": "Within what designated or accredited scope is the assessing body entitled to act here?", "kind": "authority", "answer_data": [ "Designation or notification reference", "Scope of accreditation covering these criteria", "Whether the scope covers the subject and criteria assessed" ] }, { "id": "q-conflict-declaration", "text": "What relationships, interests or prior work could impair impartiality, and how were they treated?", "kind": "constraint", "answer_data": [ "Declared interests and relationships", "Mitigation applied (recusal, second reviewer, disclosure)", "Residual impartiality risk statement" ] }, { "id": "q-authority-limits", "text": "What does this assessment explicitly not entitle the assessor to assert?", "kind": "exception", "answer_data": [ "Explicit non-claims", "Statement where no legal or regulatory effect arises", "Prohibited uses of the result" ] } ], "data_elements": [ { "id": "de-competence-ref", "name": "Competence reference", "description": "Pointer to the competence or qualification record supporting participation.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-016" ] }, { "id": "de-accreditation-ref", "name": "Accreditation or designation reference", "description": "Pointer to the accreditation, notification or designation held by the assessing body.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-011" ] }, { "id": "de-authorisation-scope", "name": "Authorisation scope", "description": "Scope within which the body is entitled to act for these criteria.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-conflict-declaration", "name": "Conflict declaration", "description": "Declared interest or relationship bearing on impartiality, with its mitigation.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Competence, accreditation and designation are asserted and maintained by accreditation authorities and party registries; this finding carries their identifiers, validity and scope plus a locally authored conflict declaration. Reproducing accreditation certificates here would copy content owned by the accreditation registry and risk asserting a status this model cannot verify." } ] }, { "id": "ly-quality-fairness", "name": "Quality Control and Instrument Quality", "description": "Review and moderation of this assessment, and the standing evidence that the instrument measures what the conclusion claims, reliably and fairly.", "source_refs": [ "SRC-001", "SRC-016", "SRC-013" ], "findings": [ { "id": "fd-review-moderation", "name": "Review, moderation and rater agreement", "description": "The independent review, second marking or moderation performed before finalisation, the inter-rater or inter-tool agreement measured against a threshold, and how disagreements between assessors or tools were resolved.", "source_refs": [ "SRC-001", "SRC-016", "SRC-002" ], "questions": [ { "id": "q-review-performed", "text": "What independent review, second marking or moderation was performed before finalisation?", "kind": "process", "answer_data": [ "Review activity type and scope", "Reviewer reference and independence from the determiner", "Review outcome and any returned items" ] }, { "id": "q-agreement-measure", "text": "What inter-rater or inter-tool agreement was measured, and what threshold applied?", "kind": "measurement", "answer_data": [ "Agreement statistic and method", "Acceptance threshold", "Sample on which agreement was computed" ] }, { "id": "q-disagreement-resolution", "text": "How were disagreements between assessors or tools resolved?", "kind": "decision", "answer_data": [ "Resolution method (adjudication, third rater, precedence rule)", "Adjudicator reference", "Record of the superseded determination" ] } ], "data_elements": [ { "id": "de-review-record", "name": "Review record", "description": "Record of an independent review or moderation activity on this assessment.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "de-agreement-statistic", "name": "Agreement statistic", "description": "Measured inter-rater or inter-tool agreement.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-resolution-method", "name": "Disagreement resolution method", "description": "Method used to settle conflicting determinations.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Review is a function of this assessment recorded as structured events, statistics and outcomes attached to the record. ISO/IEC 17000 treats review as an internal function preceding the decision rather than a deliverable, and the review's visible output is carried in the assessment report already declared." }, { "id": "fd-validity-reliability-fairness", "name": "Instrument validity, reliability and fairness evidence", "description": "The standing evidence that the instrument measures what the conclusion claims, that its results are precise and repeatable, that bias and accessibility barriers across subject groups have been checked, and the populations or contexts for which it is not validated.", "source_refs": [ "SRC-016", "SRC-013", "SRC-008" ], "questions": [ { "id": "q-validity-evidence", "text": "What evidence supports that the instrument measures what the conclusion claims?", "kind": "validation", "answer_data": [ "Validity evidence type and reference", "Intended interpretation and use the evidence supports", "Gaps in the validity argument" ] }, { "id": "q-reliability-evidence", "text": "What evidence supports the precision and repeatability of the results?", "kind": "quality", "answer_data": [ "Reliability coefficient or precision statistic", "Conditions under which it was estimated", "Standard error relevant at the cut score" ] }, { "id": "q-fairness-evidence", "text": "What checks were made for bias, differential functioning or accessibility barriers across subject groups?", "kind": "validation", "answer_data": [ "Bias or differential-functioning analysis reference", "Accommodations and accessibility provisions", "Subgroups examined and any disparities found" ] }, { "id": "q-instrument-limits", "text": "For which populations, contexts or subject types is the instrument not validated?", "kind": "constraint", "answer_data": [ "Populations or contexts outside validation", "Warning required when used outside them", "Alternative instrument recommended" ] } ], "data_elements": [ { "id": "de-validity-evidence-ref", "name": "Validity evidence reference", "description": "Pointer to evidence supporting the intended interpretation of results.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-reliability-statistic", "name": "Reliability statistic", "description": "Estimate of precision or repeatability for the instrument.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-fairness-check", "name": "Fairness check", "description": "Recorded bias, differential-functioning or accessibility check.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016", "SRC-013" ] }, { "id": "de-population-limit", "name": "Population or context limit", "description": "Population or context for which the instrument is not validated.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] } ], "artifacts": [ { "id": "af-technical-manual", "name": "Instrument validation or technical report", "description": "The standing documentation of validity, reliability and fairness evidence for the instrument, referenced by every assessment that uses it rather than restated per assessment.", "media_or_form": [ "technical manual", "validation study report", "reliability and fairness analysis" ], "serial": false, "identity_strategy": "Publisher identifier and edition of the instrument documentation where published; a Dimension-assigned UUID plus version for internally developed instruments. Referenced by identifier rather than copied when it is externally published.", "source_refs": [ "SRC-016", "SRC-013", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bn-governance", "name": "Lifecycle, Disclosure and Interoperability", "description": "How the record moves through its states, how it is corrected and challenged, who may see what, how long it is kept, and how it projects into external formats.", "rationale": "OSCAL requires record identity and last-modified to change on every content change; FHIR supplies an explicit status vocabulary including entered-in-error; the AERA/APA/NCME Standards give test takers rights that imply an appeal route; EU law limits who may publish a result with legal effect; and EARL, XCCDF, OSCAL and QTI all define incompatible result vocabularies that must be crosswalked deliberately.", "source_refs": [ "SRC-002", "SRC-007", "SRC-016", "SRC-012", "SRC-005" ], "layers": [ { "id": "ly-record-lifecycle", "name": "Record Lifecycle", "description": "States and transitions of the assessment record, and how it is corrected, challenged and superseded.", "source_refs": [ "SRC-007", "SRC-002", "SRC-016" ], "findings": [ { "id": "fd-record-state", "name": "Assessment state and transitions", "description": "The states an assessment record may occupy and the vocabulary defining them, the permitted transitions with their actors and preconditions, what becomes immutable at finalisation, and how a record that should never have existed is marked without erasing its history.", "source_refs": [ "SRC-007", "SRC-002", "SRC-011" ], "questions": [ { "id": "q-state-vocabulary", "text": "What states may an assessment record occupy, and which vocabulary defines them?", "kind": "state", "answer_data": [ "Enumerated states with definitions", "Status code system and version", "Initial and terminal states" ] }, { "id": "q-state-transition", "text": "Which transitions are permitted, who may trigger them, and what preconditions apply?", "kind": "lifecycle", "answer_data": [ "Permitted transition pairs", "Role authorised for each transition", "Preconditions checked before transition" ] }, { "id": "q-finalisation-effect", "text": "What becomes immutable at finalisation, and what may still change afterwards?", "kind": "constraint", "answer_data": [ "Frozen field set", "Fields that remain mutable after finalisation", "Mechanism enforcing immutability" ] }, { "id": "q-erroneous-record", "text": "How is a record that should never have existed marked, without deleting its history?", "kind": "exception", "answer_data": [ "Entered-in-error or withdrawn status value", "Required withdrawal reason and actor", "Effect on records that cited it" ] } ], "data_elements": [ { "id": "de-record-status", "name": "Record status", "description": "Current lifecycle state of the assessment record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-002" ] }, { "id": "de-status-changed-at", "name": "Status change time", "description": "Time at which a status transition occurred, with the acting party.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-006" ] }, { "id": "de-immutable-after-final", "name": "Immutability flag", "description": "Whether the record content is frozen following finalisation.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "States and transitions are control data on the record, consumed by callers to decide whether a conclusion may be relied on. The platform's change history and access log are owned by the referenced audit model, so this finding records status and transition times without producing or owning an audit artifact." }, { "id": "fd-correction-supersession", "name": "Correction, appeal and supersession", "description": "When an amendment is required rather than a new assessment, how the subject or a relying party may challenge the conclusion and within what period, how the outcome of a challenge is reflected, and how the chain from the original to the currently effective conclusion is navigated.", "source_refs": [ "SRC-016", "SRC-011", "SRC-002", "SRC-012" ], "questions": [ { "id": "q-amendment-trigger", "text": "What circumstances require an amendment rather than a wholly new assessment?", "kind": "decision", "answer_data": [ "Amendment trigger conditions", "Threshold at which re-assessment is mandatory", "Approving role for the amendment" ] }, { "id": "q-appeal-route", "text": "How may the subject or a relying party challenge the conclusion, and within what period?", "kind": "process", "answer_data": [ "Appeal or complaint route", "Time limit for lodging a challenge", "Rights of the assessed party during the challenge" ] }, { "id": "q-appeal-outcome", "text": "How is the outcome of an appeal or complaint reflected in the record?", "kind": "event", "answer_data": [ "Appeal outcome code and date", "Resulting amendment or reaffirmation reference", "Whether the original conclusion remains readable" ] }, { "id": "q-supersession-chain", "text": "How is the chain from the original to the currently effective conclusion navigated?", "kind": "relationship", "answer_data": [ "Superseded-by pointer", "Effective-version flag", "Rule for resolving the current effective record" ] } ], "data_elements": [ { "id": "de-amendment-reason", "name": "Amendment reason", "description": "Coded reason a new version of the assessment was issued.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-011" ] }, { "id": "de-appeal-ref", "name": "Appeal or complaint reference", "description": "Pointer to a lodged challenge against the conclusion.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016", "SRC-012" ] }, { "id": "de-superseded-by", "name": "Superseded by", "description": "Pointer to the assessment version that replaces this one.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-effective-record-flag", "name": "Effective record flag", "description": "Whether this version is the currently effective conclusion.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "Correction and supersession are expressed as reason codes, pointers and flags that let a consumer resolve the currently effective conclusion. Appeal case files, hearings and their procedural conduct are handled by the referenced dispute or case-management model; this finding retains only the reference and the recorded outcome." } ] }, { "id": "ly-disclosure-retention", "name": "Disclosure and Retention", "description": "Who may see which part of the record, what is redacted before release, and how long each part is kept before disposition is referred onward.", "source_refs": [ "SRC-012", "SRC-009", "SRC-003" ], "findings": [ { "id": "fd-disclosure-redaction", "name": "Disclosure classification and redaction", "description": "The disclosure class applying separately to the conclusion, the scores and the underlying evidence, the terms under which the assessment may be published or cited, what must be redacted before external release and who approves it, and whether a conclusion may be released without its evidence.", "source_refs": [ "SRC-012", "SRC-009", "SRC-002" ], "questions": [ { "id": "q-disclosure-class", "text": "What disclosure class applies to the conclusion, the scores and the underlying evidence separately?", "kind": "access", "answer_data": [ "Disclosure class per record part", "Classification scheme reference", "Party authorised to set the class" ] }, { "id": "q-publication-terms", "text": "Under what terms, embargo or licence may the assessment be published or cited?", "kind": "ownership", "answer_data": [ "Publication licence or terms", "Embargo end time", "Attribution and citation requirements" ] }, { "id": "q-redaction-rule", "text": "What must be redacted before external release, and who approves the redaction?", "kind": "privacy", "answer_data": [ "Redaction rule reference and version", "Approving role", "Categories of content always removed" ] }, { "id": "q-selective-disclosure", "text": "Can a relying party receive the conclusion without the evidence, and what integrity guarantee accompanies it?", "kind": "security", "answer_data": [ "Permitted selective-disclosure combinations", "Integrity digest or signature accompanying a partial release", "Minimum context that must travel with a published score" ] } ], "data_elements": [ { "id": "de-disclosure-class", "name": "Disclosure class", "description": "Classification governing release of a part of the record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-002" ] }, { "id": "de-publication-licence", "name": "Publication licence or terms", "description": "Terms under which the assessment may be published or cited.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-009" ] }, { "id": "de-redaction-rule-ref", "name": "Redaction rule reference", "description": "Versioned rule applied when producing an external rendition.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-public-rendition-ref", "name": "Public rendition reference", "description": "Pointer to the published, redacted version of the record.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-012" ] } ], "artifacts": [ { "id": "af-public-rendition", "name": "Redacted public rendition", "description": "The externally releasable version of the assessment, produced by applying a versioned redaction rule to the retained record while preserving the score context needed to interpret it.", "media_or_form": [ "published summary", "public statement abstract", "machine-readable public record" ], "serial": true, "identity_strategy": "Series key is the assessment identifier combined with the disclosure class; a zero-padded sequence increments per publication. Each rendition records the redaction rule version applied and the approving role; the retained record keeps a redaction marker rather than losing content.", "source_refs": [ "SRC-012", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "fd-retention-disposition", "name": "Retention class and disposition referral", "description": "The retention class and trigger applying to each part of the record, which policy and system execute destruction or transfer when retention ends, and how a legal hold or open appeal suspends disposition.", "source_refs": [ "SRC-012", "SRC-003", "SRC-002" ], "questions": [ { "id": "q-retention-class", "text": "What retention class and minimum retention period apply to each part of the record?", "kind": "retention", "answer_data": [ "Retention class per record part", "Minimum period and its jurisdictional basis", "Differences between conclusion, scores and evidence" ] }, { "id": "q-retention-trigger", "text": "What event starts the retention clock for the assessment and for its evidence?", "kind": "temporal", "answer_data": [ "Retention trigger event code", "Trigger timestamp", "Rule when several triggers apply" ] }, { "id": "q-disposition-owner", "text": "Which policy and which system execute destruction or transfer when retention ends?", "kind": "ownership", "answer_data": [ "Disposition policy reference", "Executing model or system reference", "Record of the referral and its acknowledgement" ] }, { "id": "q-legal-hold", "text": "How does a legal hold or open appeal suspend disposition?", "kind": "exception", "answer_data": [ "Legal hold flag and its authority", "Conditions suspending disposition", "Release procedure and who may release the hold" ] } ], "data_elements": [ { "id": "de-retention-class", "name": "Retention class", "description": "Declared retention classification for a part of the record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-003" ] }, { "id": "de-retention-trigger-event", "name": "Retention trigger event", "description": "Event that starts the retention clock.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-disposition-policy-ref", "name": "Disposition policy reference", "description": "Pointer to the policy model that owns and executes disposition.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-012" ] }, { "id": "de-legal-hold-flag", "name": "Legal hold flag", "description": "Whether disposition is currently suspended by a hold or open challenge.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-016" ] } ], "artifacts": [], "inline_only_rationale": "Retention here is a declared classification, a trigger event and a pointer to the owning records-management policy, plus a record that the referral was made. Setting periods and executing destruction, transfer or erasure — and issuing any destruction certificate — belong to that referenced model, so producing an artifact here would assert ownership of disposition this model does not hold." } ] }, { "id": "ly-interoperability", "name": "Interoperability", "description": "Projection into external assessment reporting formats and binding of the vocabularies, units and languages used.", "source_refs": [ "SRC-005", "SRC-004", "SRC-002", "SRC-014" ], "findings": [ { "id": "fd-alignment-vocabulary", "name": "External alignment and vocabulary binding", "description": "Which external assessment reporting formats this record must project into, how local outcome values map into each target vocabulary and where that mapping loses information, which code systems, units and language tags are bound at which versions, and what is claimed as conformance to an external standard.", "source_refs": [ "SRC-005", "SRC-004", "SRC-002", "SRC-008", "SRC-014" ], "questions": [ { "id": "q-target-format", "text": "Which external assessment reporting formats must this record project into?", "kind": "interoperability", "answer_data": [ "Target format references with versions", "Trigger for producing each projection", "Party consuming each projection" ] }, { "id": "q-outcome-crosswalk", "text": "How do local outcome values map to each target vocabulary, and where is the mapping lossy?", "kind": "interoperability", "answer_data": [ "Value-to-value mapping table", "Values with no target equivalent", "Loss statement carried with the projection" ] }, { "id": "q-codesystem-binding", "text": "Which code systems, units and language tags are bound, and at which versions?", "kind": "classification", "answer_data": [ "Code system identifiers with versions", "Unit code system reference", "BCP 47 language tags for narrative fields" ] }, { "id": "q-conformance-claim", "text": "What is claimed as conformance to an external standard, and what evidence supports that claim?", "kind": "validation", "answer_data": [ "Conformance or alignment claim text", "Evidence supporting the claim", "Explicit statement where only alignment, not conformance, is claimed" ] } ], "data_elements": [ { "id": "de-target-format-ref", "name": "Target format reference", "description": "External reporting format the record projects into.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-002" ] }, { "id": "de-outcome-crosswalk", "name": "Outcome crosswalk", "description": "Mapping from local outcome values to a target vocabulary, with loss notes.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "de-code-system-binding", "name": "Code system binding", "description": "Code system, unit system or vocabulary bound at a stated version.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007", "SRC-014" ] }, { "id": "de-language-tag", "name": "Language tag", "description": "BCP 47 tag for a narrative field such as rationale or conclusion.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-013" ] } ], "artifacts": [ { "id": "af-crosswalk-table", "name": "Outcome and vocabulary crosswalk", "description": "The mapping between this model's outcome values, scales and code systems and those of each target reporting format, with explicit loss statements where no equivalent exists.", "media_or_form": [ "mapping table", "machine-readable projection definition", "alignment statement" ], "serial": false, "identity_strategy": "Identified by the pair of source and target vocabulary identifiers together with their versions; a new target version produces a new crosswalk rather than an in-place edit.", "source_refs": [ "SRC-005", "SRC-004", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-frame-assessment", "name": "Frame the assessment", "description": "Open an assessment record by fixing its identity, type, mandate, subject reference, pinned subject state, scope boundary and sampling design.", "inputs": [ "Subject reference from the owning domain model", "Assessment type and consequence class", "Scheme, mandate or engagement reference", "Proposed scope statement and sampling design" ], "outputs": [ "Assessment record in draft state with an authoritative identifier", "Declared scope, exclusions and sampling design", "Pinned subject state descriptor" ], "preconditions": [ "The subject is identified and resolvable in a referenced domain model", "A mandate, scheme or engagement basis is recorded", "An accountable assessment owner is named" ], "effects": [ "Creates the record identity and its granularity declaration", "Fixes the assessed boundary and the generalisation limit for everything recorded afterwards", "Does not alter the subject or its state, which remain owned by the subject-domain model" ], "source_refs": [ "SRC-013", "SRC-002", "SRC-007" ] }, { "id": "fn-bind-criteria", "name": "Bind criteria at version", "description": "Resolve the criteria source, pin its version, select the applicable criteria, record not-applicable justifications and any additions, and retain the binding so results stay reproducible.", "inputs": [ "Criteria source reference", "Requested profile or selection basis", "Tailoring decisions with justifications" ], "outputs": [ "Version-pinned criterion binding set", "Not-applicable list with justifications", "Retained snapshot or digest of the bound criteria" ], "preconditions": [ "The criteria source resolves at a stated version", "Authority exists for any criterion added beyond the source" ], "effects": [ "Makes every later determination addressable to a specific criterion at a specific version", "Freezes the binding against later catalogue changes", "Does not author, version or publish criteria, which remain owned by the catalogue model" ], "source_refs": [ "SRC-002", "SRC-004", "SRC-010" ] }, { "id": "fn-declare-method-scale-and-rule", "name": "Declare method, scale and decision rule", "description": "Record the methods, modes, depth and coverage per criterion, the instrument used, the outcome scale and vocabulary, and the decision rule with its thresholds, guard bands and abstention conditions, before any result is produced.", "inputs": [ "Method and mode selections per criterion", "Instrument or rubric reference", "Scale definition and outcome vocabulary references", "Decision rule reference and threshold values" ], "outputs": [ "Declared method, depth and coverage set", "Bound scale and outcome vocabulary", "Declared decision rule with thresholds and abstention conditions" ], "preconditions": [ "Criteria are bound at a pinned version", "The scale and decision rule resolve at stated versions" ], "effects": [ "Fixes how results will be expressed and decided before they are observed", "Enables an independent party to re-derive the conclusion from recorded values", "Does not execute or enforce the rule against any live system" ], "source_refs": [ "SRC-003", "SRC-011", "SRC-004", "SRC-015" ] }, { "id": "fn-register-evidence", "name": "Register evidence and link it to criteria", "description": "Register a reference to an evidence object with its type, integrity digest, collection and receipt times, the criteria it bears on, its sufficiency judgement and any confidentiality constraints.", "inputs": [ "Evidence object reference from the custody model", "Evidence type and origin", "Criterion linkage and direction of support", "Sensitivity classification" ], "outputs": [ "Registered evidence reference with digest and times", "Evidence-to-criterion linkage entries", "Sufficiency and admissibility qualifiers" ], "preconditions": [ "The evidence object is resolvable in the referenced custody model", "The criteria it is linked to are already bound" ], "effects": [ "Makes each determination traceable to identified evidence", "Records rejected or down-weighted evidence rather than discarding it", "Does not take custody of the evidence bytes or manage chain of custody" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-005" ] }, { "id": "fn-record-observation", "name": "Record an observation", "description": "Record a raw observed result with its method, producing actor or device, distinct event and recording times, place where relevant, and any uncertainty and unit for quantitative values.", "inputs": [ "Raw observed value or return code", "Observer or device reference and role", "Event time and recording time", "Unit, uncertainty and calibration reference where quantitative" ], "outputs": [ "Observation entry with dual timestamps and attribution", "Quantitative value with unit and stated uncertainty" ], "preconditions": [ "The method and, for machine results, the tool and configuration are declared", "The observer is identifiable as human, organisational or automated" ], "effects": [ "Preserves what was seen separately from what was judged", "Keeps event time and recording time independently queryable", "Does not invoke, schedule or control the producing tool" ], "source_refs": [ "SRC-002", "SRC-005", "SRC-015", "SRC-006" ] }, { "id": "fn-record-criterion-outcome", "name": "Record a criterion outcome", "description": "Assign an outcome value from the bound vocabulary to a criterion, with rationale, cited evidence, severity where negative, locator, and any raw and normalised score.", "inputs": [ "Criterion reference", "Outcome value from the bound vocabulary", "Cited evidence and observation references", "Raw score and maximum where scored" ], "outputs": [ "Criterion-level determination with rationale and evidence citations", "Normalised score bound to a scale version", "Severity grading for negative outcomes" ], "preconditions": [ "The criterion is bound and applicable", "The outcome value exists in the bound vocabulary at its stated version" ], "effects": [ "Creates the traceable link from evidence through criterion to determination", "Preserves indeterminate, untested and not-applicable states without coercing them to a negative result" ], "source_refs": [ "SRC-005", "SRC-002", "SRC-003", "SRC-004" ] }, { "id": "fn-compute-composite-result", "name": "Compute the composite result", "description": "Apply the aggregation model already declared on this record to the criterion outcomes and scores recorded on it, producing a composite score, level or vector together with the inputs needed to reproduce it.", "inputs": [ "Declared aggregation model and weights", "Recorded criterion outcomes and normalised scores", "Completeness rule for missing results" ], "outputs": [ "Composite score, level or class", "Result vector expressing the inputs", "Partial-result flag where completeness is not met" ], "preconditions": [ "An aggregation model is declared and versioned", "Criterion results exist for the minimum completeness the model requires" ], "effects": [ "Derives a composite that is recomputable from recorded values alone", "Publishes the model identifier and inputs with the score", "Does not call any external evaluator, grader or scanner" ], "source_refs": [ "SRC-004", "SRC-009", "SRC-013" ] }, { "id": "fn-derive-and-record-conclusion", "name": "Derive and record the conclusion", "description": "Apply the declared decision rule to the composite result and its uncertainty, record the resulting conclusion with its type, qualifications, dissent and validity window, and name the accountable decision maker.", "inputs": [ "Composite result with uncertainty", "Declared decision rule and thresholds", "Decision maker reference and sign-off" ], "outputs": [ "Recorded conclusion with type and qualifications", "Validity window, conditions and surveillance obligations", "Referral marker where an attestation is to follow" ], "preconditions": [ "A decision rule and thresholds are declared", "A decision maker is named who is distinguishable from the determiner", "Uncertainty has been accounted for where the rule requires it" ], "effects": [ "Separates the decision from the determination work, as the conformity-assessment functional model requires", "Records what the conclusion does and does not entitle", "Does not issue a certificate, credential or licence, and does not enforce any consequence" ], "source_refs": [ "SRC-001", "SRC-011", "SRC-012", "SRC-015" ] }, { "id": "fn-review-and-finalise", "name": "Review and finalise", "description": "Record independent review or moderation, resolve disagreements, and transition the record to final, freezing the content that must not change afterwards.", "inputs": [ "Reviewer reference and review scope", "Agreement statistics and thresholds", "Disagreement resolutions" ], "outputs": [ "Review record with outcome", "Finalised assessment record with frozen content", "Assessment report artifact issued to requesting and relying parties" ], "preconditions": [ "All selected criteria have an outcome or an explicit indeterminate value", "A conclusion and decision maker are recorded", "The reviewer is independent of the determinations reviewed" ], "effects": [ "Makes bindings, evidence links, scores and the conclusion immutable", "Starts the validity window and the retention trigger", "Leaves lifecycle-scoped fields such as disclosure class and hold flag mutable" ], "source_refs": [ "SRC-001", "SRC-016", "SRC-002", "SRC-011" ] }, { "id": "fn-amend-or-supersede", "name": "Amend or supersede", "description": "Issue a new version of a finalised assessment with a reason code, link it to the version it replaces, and move the effective-record flag, or mark a record as entered in error without deleting it.", "inputs": [ "Amendment reason code", "Changed content or withdrawal decision", "Approving role reference" ], "outputs": [ "New assessment version with supersession link", "Updated effective-record flag", "Withdrawal or entered-in-error marking with reason and actor" ], "preconditions": [ "The record being amended is final", "An amendment reason is recorded and approved", "Re-assessment is used instead where the change exceeds the amendment threshold" ], "effects": [ "Preserves the superseded version as readable history", "Keeps the currently effective conclusion resolvable by consumers", "Never removes prior content to resolve a dispute" ], "source_refs": [ "SRC-002", "SRC-011", "SRC-007" ] }, { "id": "fn-register-appeal-outcome", "name": "Register an appeal or complaint outcome", "description": "Record a lodged challenge against the conclusion, the rights exercised, its outcome and the resulting amendment or reaffirmation, and suspend disposition while it remains open.", "inputs": [ "Appeal or complaint reference from the dispute model", "Lodging party and date", "Outcome decision and its authority" ], "outputs": [ "Appeal entry linked to the affected assessment version", "Resulting amendment or reaffirmation reference", "Hold flag set while the challenge is open" ], "preconditions": [ "A conclusion has been recorded and communicated to the assessed party", "The challenge is within the declared time limit or an exception is recorded" ], "effects": [ "Makes challenge history visible alongside the conclusion", "Blocks disposition while unresolved", "Does not conduct the appeal proceedings, which the referenced dispute model owns" ], "source_refs": [ "SRC-016", "SRC-012", "SRC-002" ] }, { "id": "fn-classify-disclosure-and-project", "name": "Classify disclosure and project to external formats", "description": "Set the disclosure class per record part, produce a redacted public rendition under a versioned redaction rule, and emit crosswalked projections into required external reporting formats with explicit loss statements.", "inputs": [ "Disclosure classification decision per record part", "Redaction rule reference and approval", "Target format and vocabulary crosswalks" ], "outputs": [ "Disclosure classification set", "Redacted public rendition", "External-format projections with loss statements" ], "preconditions": [ "The record is final or explicitly approved for interim release", "Crosswalks exist and are versioned for each target format", "Published scores carry their scale, aggregation model and decision rule" ], "effects": [ "Enables selective disclosure of a conclusion without its evidence, with integrity digests attached", "Records which redaction rule version was applied and who approved it", "Does not enforce access decisions, which the referenced access-control model owns" ], "source_refs": [ "SRC-012", "SRC-009", "SRC-005", "SRC-004" ] }, { "id": "fn-declare-retention-and-refer-disposition", "name": "Declare retention and refer disposition", "description": "Assign a retention class and trigger to each part of the record, register any legal hold, and refer disposition to the owning records-retention policy model when the period expires.", "inputs": [ "Retention class per record part", "Retention trigger event and timestamp", "Legal hold status and authority" ], "outputs": [ "Declared retention classification and trigger", "Disposition referral with acknowledgement", "Tombstone retaining identifier, type, reason, actor and timestamp on withdrawal" ], "preconditions": [ "A disposition policy reference resolves", "No legal hold, open appeal or unexpired validity window blocks referral" ], "effects": [ "Makes retention obligations explicit and machine-checkable", "Hands execution of destruction, transfer or erasure to the owning records model and records the referral", "Never hard-deletes an assessment record as a means of correction" ], "source_refs": [ "SRC-012", "SRC-003", "SRC-002" ] } ], "composition": [ { "target": "WM-ACT-009 (parent model in NAV.ACT)", "relation": "CHILD", "purpose": "Inherit generic activity semantics — actor, occurrence timing, status and provenance — and specialise them for criterion-referenced judgement producing a determination and a conclusion. Generic activity identity and timing machinery is not restated here.", "required": true, "source_refs": [ "SRC-006", "SRC-002" ] }, { "target": "Criteria / requirement catalogue model (control catalogue, standard clause set, rubric registry)", "relation": "REFERENCE", "purpose": "Carry the criteria source reference, its pinned version, criterion locators, local interpretation notes and tailoring decisions. Criterion text, structure, normative status, versioning and publication remain with the catalogue.", "required": true, "source_refs": [ "SRC-002", "SRC-004", "SRC-010" ] }, { "target": "Subject-domain model of the assessed object", "relation": "REFERENCE", "purpose": "Carry the subject reference and a pinned state descriptor of the object as assessed. The subject's own attributes, lifecycle and state transitions remain with the domain model.", "required": true, "source_refs": [ "SRC-007", "SRC-002" ] }, { "target": "Party, organisation and role model", "relation": "REFERENCE", "purpose": "Resolve assessor, requester, relying party and decision-maker references and their roles on this record. Party identity, contact data and organisational structure remain with the party model.", "required": true, "source_refs": [ "SRC-006", "SRC-012" ] }, { "target": "Competence, accreditation and designation registry", "relation": "REFERENCE", "purpose": "Carry accreditation, notification or designation references and the scope they cover for this assessment. Granting, surveilling, suspending and withdrawing accreditation belongs to the accreditation authority.", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "target": "Evidence custody and records repository model", "relation": "REFERENCE", "purpose": "Carry evidence pointers, integrity digests, collection times and sensitivity classes. Storage, chain-of-custody execution and retrieval of the evidence bytes remain with the repository.", "required": true, "source_refs": [ "SRC-002", "SRC-003" ] }, { "target": "Measurement, observation and metrology model", "relation": "REFERENCE", "purpose": "Carry measured values, units, stated uncertainty and calibration references used as evidence. Uncertainty evaluation methodology, calibration programmes and traceability chains remain with the metrology model.", "required": false, "source_refs": [ "SRC-015", "SRC-007" ] }, { "target": "Provenance model aligned to W3C PROV", "relation": "MIX-IN", "purpose": "Attach Entity, Activity and Agent provenance to assessment content: attribution of determinations to agents, derivation of conclusions from evidence, and start and end times of assessment activities.", "required": true, "source_refs": [ "SRC-006" ] }, { "target": "Attestation, certificate and credential model", "relation": "REFERENCE", "purpose": "Carry a referral marker and a pointer where the conclusion is attested downstream. Issuance, signing, suspension, withdrawal and verification of certificates or credentials belong entirely to that model.", "required": false, "source_refs": [ "SRC-001", "SRC-012" ] }, { "target": "Risk register and treatment model", "relation": "REFERENCE", "purpose": "Carry pointers where a determination seeds a risk entry. Risk characterisation lifecycle, mitigating factors, remediation tracking and deadlines belong to the risk model.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "Code list, vocabulary and unit registry", "relation": "ALIGN", "purpose": "Bind outcome vocabularies, scale definitions, severity schemes, unit code systems and language tags at stated versions, and publish crosswalks between them. Vocabulary authoring and deprecation belong to the registry.", "required": true, "source_refs": [ "SRC-005", "SRC-004", "SRC-014" ] }, { "target": "Records retention and disposition policy model", "relation": "REFERENCE", "purpose": "Carry the retention class, retention trigger, legal-hold flag and the disposition referral record. Setting periods and executing destruction, transfer or erasure belong to that policy model.", "required": true, "source_refs": [ "SRC-003", "SRC-012" ] }, { "target": "Access control and information classification model", "relation": "REFERENCE", "purpose": "Carry the disclosure class and publication terms per record part. Evaluating access requests, enforcing decisions and storing access logs belong to that model.", "required": true, "source_refs": [ "SRC-012", "SRC-009" ] }, { "target": "Assessment scheme, programme or examination framework model", "relation": "REFERENCE", "purpose": "Carry the scheme reference and the parameters it fixed for this occasion, such as required criteria profile, surveillance interval and eligibility. Scheme rules, cycles and governance belong to the programme model.", "required": false, "source_refs": [ "SRC-012", "SRC-010" ] }, { "target": "Dispute, appeal and complaint case model", "relation": "REFERENCE", "purpose": "Carry the appeal reference, its outcome and the hold it places on disposition. Conducting proceedings, managing timelines and recording hearings belong to the case model.", "required": false, "source_refs": [ "SRC-016", "SRC-012" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name a single accountable assessment owner and, separately, a decision authority entitled to record conclusions; the two roles must be distinguishable in every record so determination and decision remain separable.", "Declare the criteria sources, scales, outcome vocabularies and decision rules the package binds, each with a version and a publication location, and version them independently of individual assessment records.", "Declare the sibling models this package references for subject, party, evidence custody, retention, disclosure, attestation and dispute handling, and confirm that none of their lifecycle or enforcement functions is reimplemented locally.", "State explicitly which assessments carry legal, regulatory or contractual effect in the adopting jurisdiction and which are informational, and record the designation or accreditation evidence for the former." ], "namespace_guidance": "Use one namespace per assessing authority and scheme, for example `/assessment//`. Keep criterion, scale, outcome-vocabulary and decision-rule identifiers in separate registry namespaces so a record binds them by identifier plus version without copying them. Never embed a date, a score, a subject name or an assessor name in a namespace path, and never reuse a retired record identifier.", "registry_links": [ "Criteria catalogue registry supplying criterion identifiers and pinned versions", "Outcome vocabulary and severity scheme registry, including indeterminate values", "Scale, unit and decision-rule registry with published thresholds and guard bands", "Party, competence and accreditation registry for assessors and assessing bodies", "Scheme and programme registry defining recurring assessment rules and surveillance intervals", "Crosswalk registry holding versioned mappings to external reporting formats" ] }, "canon_and_patch": { "canonicalization_rules": [ "Serialise every coded value as an explicit triple of code system, code and code-system version; a bare label is never canonical.", "Represent scores as decimal strings at the precision declared by the bound scale; never apply locale-dependent number formatting and never round silently during aggregation.", "Order criterion results by criterion identifier within the bound catalogue rather than by insertion order, so digests over the record are stable.", "Distinguish three absent states explicitly: criterion not selected, criterion selected with no result yet, and criterion selected with an explicit indeterminate outcome.", "Normalise every cross-model pointer to a tuple of owning model, identifier and version, and tag every narrative field with a BCP 47 language tag." ], "patch_rules": [ "Draft records may be patched in place; final records are append-only and change only by issuing a new version that cites the version it supersedes.", "Every patch carries an actor reference, an RFC 3339 timestamp with seconds and an explicit offset, a reason code and the field paths affected.", "Patching a criteria binding, a scale, a decision rule, a recorded observation or a score after finalisation is prohibited; issue an amendment or a re-assessment instead.", "Redaction is a patch that removes content from a rendition, never from the retained record; the retained record keeps a redaction marker naming the rule version applied.", "Recomputation of a composite result after finalisation is prohibited; a changed aggregation model produces a new assessment version with its own binding." ], "compatibility_rules": [ "Adding an optional element, a new outcome code, a new severity level or a new external projection is a minor, backward-compatible change.", "Changing scale bounds, weighting, aggregation model or decision-rule thresholds is a breaking change; historical records retain their original bindings and are never recomputed against the new definition.", "Deprecate outcome codes with a documented successor mapping rather than removing them; consumers encountering an unknown outcome code must treat it as indeterminate and never as a negative result.", "A crosswalk to an external format is versioned against both source and target vocabulary versions; a new target version produces a new crosswalk rather than an in-place edit." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the system of record for the assessment — for example the assessing body's report or case number, the accreditation scheme's application number, or the assessment platform's record identifier.", "Governed global identifier or IRI where the assessment, its criteria binding or its published conclusion exists under a governed namespace — for example a DOI, a URN or a scheme-issued IRI.", "UUID or ULID assigned by the adopting Dimension where neither of the above exists; assigned once at record creation and never reissued or reused.", "A date, a score, a composite level, a subject name, a criteria version or a file name is never an identifier and may not be used as one, alone or in combination." ], "timestamp_rule": "All time values are RFC 3339 date-time strings that include seconds and an explicit UTC offset or `Z`; local times without an offset are rejected at ingestion. Record event time — when the assessed condition held, or when the assessment act occurred — separately from observation or ingestion time — when evidence was collected, when a result was returned, and when the record was written. Where these differ, both are retained and neither overwrites the other; comparisons and validity checks state which of the two they use.", "serial_naming_rule": "Serial artifacts — report revisions, evidence indexes, execution manifests, score reports, public renditions and periodic surveillance results — are named with a stable series key plus a zero-padded, monotonically increasing sequence number, for example `report-r0007`. The series key derives from the assessment identifier and, where needed, the producing agent or disclosure class. The sequence is never derived from a date, never restarted within a series, and never reused after an artifact is withdrawn.", "integrity_rule": "Every artifact records its media type, byte length and a cryptographic digest with the named algorithm, captured at registration and again at each republication. Digests are recomputed on read; a mismatch quarantines the artifact, marks every determination that cites it as unverified, and blocks reliance on any conclusion derived from it until a reviewer resolves the discrepancy." }, "policies": [ "Determination and decision are separable: the record must be able to name a different actor for evaluating evidence against criteria and for deciding the conclusion, and must state when the same actor did both.", "No conclusion is recorded without at least one version-pinned criterion binding and at least one evidence or observation reference, or an explicit declaration that the conclusion rests on expert judgement alone with that judgement's basis stated.", "Indeterminate, not-applicable, untested and error outcomes must be representable and must never be coerced into a negative result, an average, or a zero score.", "Every published score travels with the scale reference, the aggregation model identifier and the decision rule that produced it; a score published alone is treated as uninterpretable.", "Authority to assert regulatory or contractual effect is never inferred from method quality or tool sophistication; it must be evidenced by a resolvable designation, accreditation or contractual reference.", "Assessment records are never deleted to resolve a dispute or an unfavourable result; corrections proceed only by amendment, supersession or an entered-in-error marking that retains history.", "Where a sample was assessed, any claim extending to the unsampled remainder must be stated explicitly as an extrapolation with its confidence, never implied by silence." ], "crud": { "read": [ "Read by assessment identifier, or query by subject reference, criteria source and version, scheme, record status, conclusion type or validity window.", "Reading a final record returns its frozen content together with the current effective-version pointer; a consumer must resolve supersession before relying on any conclusion.", "Evidence bodies are read through the referenced custody model; this model returns pointers, digests, types and disclosure classes only.", "Reads honour disclosure class per record part, so a caller may legitimately receive a conclusion and its validity window without the scores, rationale or evidence.", "Every read of a conclusion returns the scale, aggregation model and decision rule references alongside it, so the result cannot be quoted without its interpretation context." ], "create": [ "Creation requires a resolvable subject reference, an assessment type, a mandate or scheme reference and a named owner; the record starts in draft.", "Criteria bindings must resolve at a stated version before the record may leave draft; an unresolvable or unpinned binding blocks finalisation.", "The creating actor and creation time are captured as provenance at creation and are never editable thereafter.", "Creating a record for a subject that already has an open assessment under the same scheme and criteria requires an explicit reason, so duplicates are deliberate rather than accidental." ], "update": [ "Draft records accept in-place updates to scope, sampling, criteria bindings, method declarations, evidence links, observations and criterion results.", "Transition to final requires an outcome or explicit indeterminate value for every selected criterion, a completed independent review, a named decision maker and a resolvable decision rule.", "After finalisation only lifecycle-scoped fields change: effective-version pointers, supersession links, disclosure class, publication terms, retention class, legal-hold flag and registered appeal outcomes.", "Any post-finalisation change to substantive content is rejected; the caller is directed to the amendment or re-assessment function.", "Updates that change a bound vocabulary version do not retro-apply to finalised records, which keep the version they were decided under." ], "delete": [ "Assessment records are not hard-deleted by default. Withdrawal is a status transition to `entered-in-error` or `withdrawn` accompanied by a tombstone that retains the identifier, record type, withdrawal reason code, acting party and an RFC 3339 timestamp with seconds and offset.", "The record declares a retention class and a retention trigger event per record part; the minimum retention period, the disposition action and its execution are owned by the adopting Dimension's records-retention policy model, which this model references. This model records only the classification and the referral, together with the referral's acknowledgement.", "Erasure of personal data contained in evidence is executed by the referenced evidence-custody and privacy models under their own legal basis; this model records that erasure occurred, the authority relied on, and marks every conclusion that cited the erased evidence as evidentially incomplete rather than silently unchanged.", "Disposition is blocked while a legal hold, an open appeal or complaint, or an unexpired validity window is recorded against the assessment; the hold itself is set and released by the referenced legal-hold or dispute model, not here.", "Tombstones are retained at least as long as the retention period of any assessment that references the withdrawn record, and a tombstoned identifier is never reused for a new record.", "Deletion of a derived artifact such as a score report or public rendition does not delete the record it was derived from; the record retains a marker that the rendition was withdrawn, with the reason and actor." ] }, "roles": [ { "name": "Assessment Owner", "responsibilities": [ "Accountable for the record's scope, completeness and timeliness", "Approves scope and sampling changes and records their effect on results already captured", "Names the assessors, the reviewer and the decision authority for the record" ] }, { "name": "Assessor / Evaluator", "responsibilities": [ "Performs selection and determination against the bound criteria", "Registers evidence references, linkages, sufficiency judgements and observations with dual timestamps", "Records criterion outcomes, rationale and scores, including indeterminate and not-applicable values", "Where the assessor is an automated agent, is identified as such with its tool reference, version and configuration" ] }, { "name": "Technical Reviewer / Moderator", "responsibilities": [ "Reviews determinations independently of the assessor who made them", "Records agreement statistics and adjudicates disagreements between assessors or tools", "May return a record to draft with reasons, and may not decide a conclusion on determinations they reviewed" ] }, { "name": "Decision Authority", "responsibilities": [ "Applies the declared decision rule to the composite result and its uncertainty", "Records the conclusion, its type, qualifications, dissent and validity window", "Accountable for the referral to any downstream attestation and for stating what the conclusion does not entitle" ] }, { "name": "Criteria and Vocabulary Steward", "responsibilities": [ "Maintains bindings to external criteria catalogues, scales, outcome vocabularies and decision rules", "Publishes crosswalks, successor mappings and deprecations for target reporting formats", "Assesses the impact of catalogue and vocabulary version changes on records that are still in draft" ] }, { "name": "Disclosure and Records Officer", "responsibilities": [ "Sets disclosure class and publication terms per record part and approves redactions", "Issues and withdraws public renditions and records the redaction rule version applied", "Assigns the retention class and trigger and refers disposition to the owning records-retention policy model" ] } ], "access": { "default_rule": "Deny by default. Assessment content is readable only by the assessment owner, the named assessors, the reviewer and the decision authority; every other reader requires an explicit grant that names a role, a purpose and a record part, and grants are per record part rather than per record.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "A published conclusion together with its scale, aggregation model, decision rule and validity window may be released to relying parties without the underlying evidence, provided integrity digests accompany it.", "Regulators, accreditation assessors and designated oversight bodies receive full access including rejected evidence, dissent and conflict declarations, under a recorded legal or contractual basis.", "The assessed subject receives access to the conclusion, the criterion outcomes and the rationale needed to exercise appeal rights, even where the wider record is restricted.", "Evidence carrying personal, privileged or commercially confidential data is withheld even from otherwise-authorised readers unless a purpose-specific grant exists that names the lawful basis.", "Embargoed assessments are readable only by the owner and the decision authority until the recorded embargo end time, expressed with seconds and an explicit offset." ], "audit_requirements": [ "Every access decision, grant, revocation and disclosure concerning an assessment must be recorded by the adopting Dimension's audit-log model; this model requires that the record exists but does not define, store, evaluate or retain the audit trail.", "Requests for evidence bodies must carry a role and a purpose so the referenced custody model can reconstruct who saw which evidence and why.", "Publication or withdrawal of a redacted rendition must be attributable to a named approver, with the redaction rule version applied.", "Changes to disclosure class, publication terms, retention class or legal-hold flag after finalisation must be attributable to a named actor with an RFC 3339 timestamp including seconds and an explicit offset." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Model ID", "Owner and decision authority" ], "read_order": [ "AGENTS.md — resolve Name, Type, Specification URL, Storage type URL, Interface URL and Processes URL before any read or write, whatever the backing store", "Specification URL — the bundle, layer and finding structure, the outcome vocabulary, the scale semantics and the decision-rule contract", "Storage type URL — the concrete projection in use (JSON, YAML, Markdown, HTML, Git, MongoDB, MCP) and its canonicalisation and digest rules", "Interface URL — the operations exposed, their access scopes and their per-record-part disclosure behaviour", "Processes URL — the lifecycle, review, finalisation, amendment, appeal, disclosure and disposition-referral procedures", "Referenced criteria catalogue, scale, outcome-vocabulary and crosswalk registries, resolved at the versions pinned by the record being read" ] } }, "coverage": { "claim": "Covers the format-neutral structure of one assessment occasion as submitted: identity and mandate, subject and scope, criteria binding and tailoring, method, execution parameters, evidence and observation, criterion determination, scoring, aggregation, conclusion, validity, assessor and instrument assurance, record lifecycle, disclosure, retention referral and external projection. Two dimensions do not hold as claimed: the access dimension is asserted \"covered\" with one access-kind question, no access-control boundary note and no supporting source, and retention carries a declared gap with no source-fixed periods. Audited against the submitted evidence pack only — no live URL or version resolution, no ratified relationship contract, no independent second-provider corroboration. This is a qualified reviewable-draft claim, not a completeness claim over the assessment domain.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Record identity, granularity, versioning and supersession are modelled, with a four-level identity priority placing the authoritative master-system identifier first and excluding dates and scores. Subject, criterion, assessor and instrument identities are referenced rather than minted here." }, { "dimension": "lifecycle", "status": "covered", "notes": "Draft, review, final, amended and entered-in-error states with transition preconditions, finalisation freeze, amendment thresholds, appeal registration and supersession chains. Grounded in FHIR status vocabulary and OSCAL's requirement to change record identity and last-modified on every content change." }, { "dimension": "relationships", "status": "covered", "notes": "Evidence-to-criterion linkage, criterion-to-outcome, outcome-to-composite, conclusion-to-consequence and supersession are all explicit, plus fifteen composition links that keep target-owned concepts outside the model." }, { "dimension": "temporal", "status": "covered", "notes": "Event time is kept distinct from observation and recording time at the observation level; evidence creation, collection and receipt are separate; validity windows, embargo end and retention triggers are all RFC 3339 with seconds and explicit offset." }, { "dimension": "provenance", "status": "covered", "notes": "PROV-O is mixed in for attribution of determinations to agents, derivation of conclusions from evidence and activity start/end times. Execution parameters and tool versions support independent reproduction. Platform change-logging is explicitly excluded." }, { "dimension": "ownership", "status": "covered", "notes": "Assessment owner, assessor, reviewer, decision authority, criteria steward and disclosure officer are distinguished, with separation of determination from decision enforced as a policy and reflected in the role definitions." }, { "dimension": "validation", "status": "covered", "notes": "Two distinct senses are covered: validation of the record (review, moderation, agreement statistics, adjudication) and validation of the instrument (validity, reliability and fairness evidence per the AERA/APA/NCME Standards). Conformance claims to external formats require supporting evidence." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default with grants per record part across bundle, layer, finding and artifact scopes; five exceptions including subject appeal rights and regulator access. Enforcement and access logging are referred to the access-control and audit models." }, { "dimension": "retention and deletion", "status": "gap", "notes": "The mechanism is complete — retention class, trigger event, legal hold, tombstone contents, erasure marking and an explicit referral to the owning records policy. The gap is substantive rather than structural: none of the sixteen consulted sources fixes retention periods for assessment records, so all durations are jurisdiction-owned and this model deliberately sets none. Treat any period asserted by an adopting Dimension as unsupported by this research." }, { "dimension": "interoperability", "status": "covered", "notes": "Projection into EARL, XCCDF, OSCAL, QTI results and FHIR is modelled as versioned crosswalks with explicit loss statements, plus code-system, unit and BCP 47 language binding. Conflicts between the source vocabularies are recorded rather than harmonised away." }, { "dimension": "criteria binding", "status": "covered", "notes": "Version-pinned binding, locators, interpretation notes, selection, not-applicable justification and additions, with retained snapshots so results survive catalogue changes. Catalogue authoring stays with the catalogue model." }, { "dimension": "evidence sufficiency", "status": "covered", "notes": "Evidence inventory, criterion linkage with direction of support, sufficiency judgement, authenticity digests, currency, exclusion reasons and confidentiality constraints. Custody execution stays with the repository model." }, { "dimension": "scoring and aggregation", "status": "covered", "notes": "Raw, maximum and normalised scores bound to a scale version; declared aggregation model with weights, precedence, composite form and partial-result handling; published scores must travel with their model and rule." }, { "dimension": "uncertainty and decision rules", "status": "covered", "notes": "Explicit decision rule with cut scores, guard bands, uncertainty treatment and abstention conditions, grounded in ILAC-G8 and JCGM 106. Recomputation after finalisation is prohibited." }, { "dimension": "impartiality and competence", "status": "covered", "notes": "Competence and accreditation references, designated scope, conflict declarations with mitigations, and explicit non-claims. The EU rule that legal effect depends on designation rather than method quality is carried as a policy." }, { "dimension": "fairness and bias", "status": "covered", "notes": "Bias, differential-functioning and accessibility checks, subgroup analysis and population limits, drawn from the AERA/APA/NCME Standards and WCAG-EM. Expectations are region-dependent — see regional assumptions." }, { "dimension": "sampling and generalisation", "status": "covered", "notes": "Sampling strategy, size, structured plus random selection and an explicit generalisation limit, following WCAG-EM's rule that a whole-product conformance claim cannot rest on a sampled subset." } ], "known_omissions": [ "Domain-specific criteria semantics — clinical, educational, financial, environmental, safety — are referenced but not modelled; a Dimension adopting this model in a regulated domain will need a sibling criteria model.", "Sampling statistics beyond declaration: no power analysis, confidence-interval construction or acceptance-sampling plan is modelled.", "Adaptive and computerised-adaptive testing item-selection algorithms, item exposure control and equating are outside the instrument finding.", "Benchmark harness specifics for evaluating machine-learning systems — dataset splits, contamination and leakage controls, held-out set governance — are only partly reached by the reproducibility finding.", "Panel deliberation and consensus protocols (Delphi, expert elicitation, jury scoring) are summarised as roles and agreement statistics rather than modelled as procedures.", "Cross-border mutual recognition of assessment results, and the conditions under which one jurisdiction accepts another's conclusion, are not modelled.", "Effort, cost and scheduling of assessment engagements are excluded.", "Continuous and streaming assessment is only partly covered: surveillance obligations are declared, but the monitoring cadence and its state machine belong to the programme model.", "Aggregation of many assessments into population statistics, league tables or reputation scores is excluded and left to a sibling model.", "Digital signature profiles and long-term validation of signed assessment reports are referenced through integrity digests but not specified." ], "conflicts": [ "Outcome vocabularies conflict across the primary sources and cannot be losslessly unified: EARL defines passed, failed, cantTell, inapplicable and untested; XCCDF 1.2 defines nine values including error, notchecked, notselected, informational and fixed; SP 800-53A uses satisfied and other-than-satisfied; FHIR RiskAssessment uses observation status codes. XCCDF `fixed` and `informational` have no EARL equivalent, so any crosswalk must carry an explicit loss statement.", "ISO/IEC 17000 separates review, decision and attestation as distinct functions, while EARL and XCCDF collapse determination and decision into a single result value. This model follows the ISO separation and therefore cannot round-trip the distinction through those formats without an out-of-band field.", "CVSS v4.0 requires the vector string to be published with any score, whereas schema.org Rating requires only ratingValue with optional bestRating and worstRating. A score that is portable under one convention is uninterpretable under the other; this model imposes the stricter rule.", "ILAC-G8 and JCGM 106 require an explicit decision rule that accounts for measurement uncertainty before a statement of conformity, but the machine-readable assessment formats reviewed provide no field for uncertainty or guard bands. Uncertainty is therefore modelled here and is lost on projection.", "WCAG-EM states that conformance claims cannot be made for a whole product from a sampled subset, whereas OSCAL and XCCDF assessments routinely generalise from sampled subjects without a comparable prohibition. This model requires an explicit extrapolation statement, which is stricter than two of its primary sources.", "FHIR advises using RiskAssessment rather than Observation for risk data even though risk assessments are described as a specialised observation. The assessment-versus-observation boundary is therefore convention-dependent, not derivable from first principles.", "EU product law makes legal effect depend on the designation of the body: a technically identical assessment by a non-designated body has no legal value, and voluntary certificates are described as misleading. Method quality and legal authority are orthogonal, which contradicts a common assumption that a rigorous assessment is a valid one.", "The known-relation ledger supplied for this model is empty, and the registry marks the entry as requiring boundary review. Every composition link in this submission is therefore a proposal, not a ratified contract; the parent link to WM-ACT-009 is asserted from the registry field alone, since that model's rationale was not available for comparison." ], "regional_assumptions": [ "EU conformity-assessment terminology — notified body, CE marking, declaration of conformity, modules — is specific to the EU New Legislative Framework; other jurisdictions use different designation regimes and the party-relationship and authority findings must be re-bound accordingly.", "The ISO/IEC 17000-series functional model (selection, determination, review, decision, attestation) and the ILAC accreditation ecosystem are assumed as the default vocabulary; jurisdictions outside that ecosystem may separate these functions differently.", "The AERA/APA/NCME Standards describe primarily United States practice; fairness, accommodation and test-taker rights expectations differ materially in other jurisdictions and the fairness finding is deliberately mechanism-only rather than threshold-setting.", "Retention periods, disclosure duties, appeal windows and erasure rights are jurisdiction-specific; all are referenced as classes and pointers, and none is fixed by this model.", "Language and locale of criteria, rationale and conclusions are not assumed to be English; BCP 47 tagging is required on every narrative field.", "Measurement traceability assumes an SI-based metrological infrastructure; assessments using non-metrological or purely judgemental scales bind a scale definition instead and leave the uncertainty elements empty." ], "adversarial_checks": [ "Tested whether an audit-trail layer belongs in this model. Rejected: PROV-O covers content provenance and attribution, which is retained, but platform record-access and change logging is a separate concern. The access layer therefore states audit requirements on a referenced model without defining, storing or evaluating any trail.", "Tested whether the criteria catalogue should be owned here, since criteria are central to the model's purpose. Rejected: OSCAL separates catalogue from assessment results, XCCDF separates Benchmark from TestResult, and Common Criteria separates functional and assurance components from an evaluation instance. The model keeps binding, version pinning and tailoring only.", "Tested whether certification or credential issuance belongs here, since the conclusion appears to produce it. Rejected: ISO/IEC 17000 makes attestation a function distinct from decision, and EU law reserves legally effective issuance to designated bodies. The model ends at the recorded conclusion plus a referral marker.", "Tested whether tool execution and scan orchestration belong here, given the execution-parameter finding. Rejected: EARL records the assertor and mode as attributes of an assertion and XCCDF records the checking system as a reference. The execution manifest documents parameters and explicitly disclaims scheduling or invocation.", "Tested whether 'score' implies ownership of a measurement model. Rejected: scores here are criterion-referenced and frequently non-metrological (rubric levels, severity bands, ordinal grades), so units, uncertainty evaluation and traceability are referenced from JCGM-aligned metrology rather than owned.", "Searched for counterexamples where an assessment has no criteria — open-ended appraisal, expert judgement, peer review without a rubric. Found genuine cases, so criteria binding remains required but admits an explicit declaration that the conclusion rests on expert judgement alone with that judgement's basis stated, rather than forcing a fictitious rubric.", "Tested whether the composite-result function amounts to operational evaluation owned elsewhere. Concluded it does not: it applies a model already declared on this record to values already recorded on it, and is explicitly barred from calling external evaluators, graders or scanners.", "Tested whether retention could be modelled with concrete periods. Rejected: no consulted source fixes durations for assessment records, so the checklist marks retention and deletion as a gap rather than presenting jurisdiction-specific periods as canonical.", "Checked every bundle, layer, finding and function against the composition rationales for target-owned concepts. Three candidates were moved out during drafting: a proposed evidence-custody layer became a REFERENCE link, a proposed remediation-tracking finding was moved to out_of_scope as risk-model territory, and a proposed certificate-issuance function became a referral marker inside the conclusion function." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-08-29T09:06:27Z", "scope": "Queued subject-model research from WM-XCT-013 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-08-29T09:06:27Z", "reason": "The repository owner explicitly instructed the research queue to continue without Grok after repeated structured-output failures." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The aggregate root survives challenge for a single assessment occasion: OSCAL nests observations and findings inside assessment-results, XCCDF nests rule-results inside TestResult, and FHIR RiskAssessment carries predictions inline, so determinations share the record's identity and cannot be addressed independently of it, while criteria, evidence, assessors and instruments are held by reference and pass the reuse test. The frozen registry value 'standalone-mm' is not treated as a refutation: it classifies whether the entry is a free-standing meta-model, a different axis from the internal consistency shape, and the registry's own review_state is boundary-review-required. Acceptance is conditional on three things being visible in the draft: the registry value shown alongside 'aggregate' with the mismatch flagged, the unratified parent link to WM-ACT-009 marked as a proposal, and the supersession-chain question in decision 3 routed to boundary review rather than silently resolved." }, "decisions": [ { "concept": "Aggregate root scoped to a single assessment occasion", "disposition": "accepted", "rationale": "Determinations, scores and the conclusion share one identity and one determination freeze, matching how OSCAL, XCCDF and FHIR nest results inside a single result container; every reusable component is bound by reference, so the boundary holds under the reuse test." }, { "concept": "Entry kind: research-plane 'aggregate' versus frozen registry 'standalone-mm'", "disposition": "accepted with mandatory registry reconciliation", "rationale": "The two values answer different questions and the registry marks itself boundary-review-required, so this is a provisional classification rather than a contradiction; publication must show both values and the open reconciliation." }, { "concept": "Supersession chain and the effective-record flag", "disposition": "deferred to boundary review", "rationale": "fn-amend-or-supersede moves an effective-record flag across versions, which presupposes a coordinating identity above any single record. Either the chain root is declared or the flag is made derivable from version metadata; as written, two versions can each assert effectiveness." }, { "concept": "'one finalisation event' in the scope statement", "disposition": "rejected as written; reword before publication", "rationale": "fd-record-state, fd-correction-supersession, fd-disclosure-redaction and fd-retention-disposition all permit post-finalisation mutation. The aggregate rationale should claim one determination freeze, not one lifecycle event." }, { "concept": "Artifact asymmetry across the four reusable definitional components", "disposition": "deferred pending explicit artifact-provenance semantics", "rationale": "Criteria catalogue, outcome scale and decision rule are denied artifacts as target-owned, yet the instrument definition and its technical manual are declared as artifacts on identical reasoning. Whether serial:false already encodes 'referenced, externally authored' is stated nowhere, so an adopter cannot distinguish owned from bound." }, { "concept": "af-assessment-procedure declared on the results record", "disposition": "reclassify to a referenced upstream artifact", "rationale": "SRC-002 separates the OSCAL assessment-plan model from assessment-results, and fd-record-identity already asks which plan this record fulfils. Declaring the plan here duplicates a sibling record the model says it derives from." }, { "concept": "af-evidence-object against the custody exclusion", "disposition": "accepted as reference-only registration", "rationale": "out_of_scope excludes custody and chain-of-custody execution while the artifact registers identity, type and digest only. This is consistent provided the artifact is explicitly marked externally authored and non-authoritative for the bytes." }, { "concept": "'single authoritative rendition' claim in fd-criterion-verdict", "disposition": "rejected; state the rendition hierarchy instead", "rationale": "Three rendition artifacts exist — score report, assessment report and redacted public rendition — so the inline rationale's premise is false as written. Their containment relationship must be stated or the surplus consolidated." }, { "concept": "Coverage checklist marks the access dimension 'covered'", "disposition": "rejected; downgrade to partial before the coverage claim is published", "rationale": "The submitted structure holds one access-kind question, no access-control model among the ten boundary notes, and no source_ref supporting deny-by-default grants or the five stated exceptions. The dimension is asserted rather than modelled." }, { "concept": "Checklist mechanisms absent from the submitted structure", "disposition": "rejected as coverage evidence in this pack", "rationale": "The four-level identity priority, tombstone and erasure marking, and the fifteen composition links appear only in checklist prose and in no finding, question or relation here. They must be submitted as structure or struck from the claim." }, { "concept": "Breadth of SRC-011 (ILAC-G8) citation", "disposition": "rejected; re-scope to decision-rule and statement-of-conformity findings", "rationale": "A guidance document on decision rules and statements of conformity is cited to support record identity and versioning, record state transitions, correction and appeal, and competence. Those uses read as citation of the whole guidance-series landing page, not the pinned G8:09/2019." }, { "concept": "Sources pinned to landing pages or multi-document bundles", "disposition": "deferred to live verification with mandatory re-pinning", "rationale": "SRC-010, SRC-011, SRC-012, SRC-015 and SRC-016 resolve to portals or containers, and SRC-015 bundles JCGM 106 and JCGM 100 under one identifier. This contradicts the version-pinning discipline the model itself imposes in fd-criterion-binding." }, { "concept": "SRC-012 flagged primary_source for EU legal-effect claims", "disposition": "accepted only as a navigational pointer", "rationale": "The load-bearing claim that legal effect depends on body designation drives a boundary note, a declared conflict and a competence policy, yet rests on a Commission portal page that itself refers onward to the Blue Guide. The primary instruments are not cited." }, { "concept": "No function for assessor assignment, competence and impartiality declaration", "disposition": "recorded as a gap; not remediable in single-provider mode", "rationale": "bn-assurance carries fd-assessor-identity and fd-competence-impartiality and enforces separation of determination from decision as policy, yet no function establishes those roles or records conflicts before determination begins. add_functions stays empty under the waiver, so this routes to the next revision." }, { "concept": "fn-classify-disclosure-and-project bundles two responsibilities", "disposition": "split at next revision", "rationale": "Disclosure classification and redaction approval are governance acts owned by a disclosure officer; crosswalk projection is a technical emission in a different layer. Coupling them makes redaction approval implicit in every export." }, { "concept": "Compound questions", "disposition": "split at next revision", "rationale": "q-stakes-class, q-conclusion-authority, q-composite-expression and q-depth-coverage each ask two things, and q-composite-expression imports a publication obligation belonging to the disclosure finding. Compound questions cannot be answered atomically by an adopting Dimension." }, { "concept": "Name 'Assessment / Evaluation' with empty alternate_names", "disposition": "accepted with a required scope note", "rationale": "Programme, policy and impact evaluation read naturally onto 'evaluation' but are bounded only implicitly by the criterion-referenced framing. Either add them to out_of_scope or admit OECD-DAC-style evaluation criteria as a criteria source." }, { "concept": "Retention marked as a substantive gap rather than filled", "disposition": "accepted", "rationale": "No consulted source fixes durations for assessment records, and the model declares class, trigger, legal hold and referral without inventing periods. Honest under-claiming is correct here; the residual risk is adopters reading the gap note as licence to assert periods." } ], "publicationHolds": [ "Single-provider hold: Grok was waived by the repository owner at 2026-08-29T09:06:27Z after repeated structured-output failures, so this result has had no independent second-provider review. Every published artifact must carry that waiver, its authorisation and its date, and the entry stays a reviewable draft.", "Live source and version verification hold: all sixteen URLs and version pins must be resolved live before publication. Specifically suspect: SRC-013 titled WCAG-EM 2.0 with a 23 July 2026 date but a parenthetical pointing at WCAG-EM 1.0 (2014); SRC-014 schema.org V30.0 dated 19 March 2026; SRC-015 asserting JCGM 100:2008 Amendment 1 (2026); SRC-003 attaching an August 2025 release 5.2.0 to SP 800-53A rather than to SP 800-53; SRC-012 pinned only by an access date.", "Source-pinning hold: SRC-010, SRC-011, SRC-012, SRC-015 and SRC-016 resolve to portals or multi-document containers rather than pinned documents, and SRC-015 bundles two JCGM documents under one identifier. Re-pin each to a document-level, version-stable reference before publication.", "Coverage-claim hold: do not publish the checklist as submitted. The access dimension must be downgraded from covered to partial, and the four-level identity priority, tombstone and erasure mechanics and the fifteen composition links must be supplied as structure or removed from the claim.", "Boundary and relationship hold: the relationship contract is empty, the parent link to WM-ACT-009 is asserted from a registry field with no rationale available for comparison, the registry entry_kind reads standalone-mm against a research-plane aggregate, and review_state is boundary-review-required. Every composition link publishes as a proposal, not a ratified contract.", "Retention hold: no consulted source fixes retention periods for assessment records. Publish the gap verbatim and state that any period asserted by an adopting Dimension is unsupported by this research.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft." ], "deferredResearch": [ "Ratify the composition links and the parent link to WM-ACT-009 once the relationship contract is populated, obtaining WM-ACT-009's own rationale so the parent claim can be compared rather than inherited from a registry field.", "Resolve the supersession-chain question: decide whether an assessment series is a distinct identity that owns the effective-record flag, or whether the flag must be derivable from version metadata on each record.", "Establish the source basis and a boundary note for the access-control model that the checklist refers enforcement to, then re-derive the access dimension from actual findings and questions rather than prose.", "Source jurisdiction-specific retention periods, appeal windows, disclosure duties and erasure rights from records-management and legal instruments, none of which were consulted in this research round.", "Re-source the EU legal-effect claims to primary instruments — Decision 768/2008/EC, Regulation (EU) 2019/1020 and the Blue Guide (2022) — instead of the Commission portal summary currently marked primary_source.", "Obtain independent second-provider or qualified human expert review of the aggregate boundary, artifact-ownership rules and outcome-vocabulary crosswalks when the Grok waiver is lifted or an alternative reviewer is authorised.", "Specify the artifact-provenance semantics of the serial flag, then re-test whether af-instrument-definition, af-technical-manual, af-assessment-procedure and af-crosswalk-table are owned artifacts or referenced instance-invariant assets." ] }, "statistics": { "sources": 16, "bundles": 6, "layers": 14, "findings": 28, "questions": 106, "artifacts": 11, "functions": 13 } }