# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T10:22:44Z", "synthesisSha256": "4bb94dfbe48f16da4f643209b5ba56219023b794c5f637e581b3c434bb49a069", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ACT-051", "registryId": "vr.wm-act-051", "name": "Regulatory Compliance Process", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.REG" ], "tags": [ "regulatory", "compliance", "process", "act.reg" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-051-regulatory-compliance-process/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/publications/wm-act-051-regulatory-compliance-process", "model": { "registry_id": "vr.wm-act-051", "model_id": "WM-ACT-051", "name": "Regulatory Compliance Process", "entry_kind": "aggregate", "purpose": "Represent a governed compliance cycle so agents can connect authoritative sources, bounded applicability, obligations, controls, evidence, findings and remediation without treating a process status, attestation or submission as timeless proof of compliance.", "scope_statement": "Owns one compliance-cycle identity and bounded subject, jurisdiction, scope and period; source-revision watch; attributable applicability decisions; obligation-risk-control mappings; implementation, evidence and monitoring context; assessment result intake; finding, exception, remediation, verification, attestation and reporting links; and correction lineage. Law, regulation, obligation, policy, risk, control, organization, asset, audit, assessment, evidence, incident, task, attestation, regulator submission, provenance, access audit and record masters remain external.", "in_scope": [ "Programme identity, subject and scope, source versions and changes, applicability interpretations, obligation-risk-control traceability, implementation and monitoring assertions", "Assessment result intake, findings and exceptions, remediation and verification coordination, bounded status claims, attestations, reporting, correction, privacy, retention and loss-aware projections" ], "out_of_scope": [ "Creating or changing law, authoritative obligations, generic policies, risks, control definitions, organizations, assets, audit engagements, assessments, evidence items, incidents, work tasks, regulator submissions or records", "Treating compliance as a universal binary fact or equating action completion, finding closure, attestation, submission, certification, acceptance and continuing compliance", "Providing legal advice, certification, enforcement, exception approval, regulator filing or destructive evidence handling" ], "boundary_notes": [ { "neighbor": "Law, regulation and WM-XCT-029 Obligation / Commitment", "distinction": "Authoritative sources and obligations remain external. The aggregate stores versioned references and attributable applicability and mapping decisions without rewriting authoritative text.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-014", "SRC-016" ] }, { "neighbor": "WM-KNW-015 Risk / Opportunity and WM-XCT-027 Risk / Control", "distinction": "Risk and control masters own their definitions and lifecycles. The aggregate owns compliance-specific mappings, implementation assertions, coverage and gaps.", "source_refs": [ "SRC-002", "SRC-004", "SRC-006" ] }, { "neighbor": "WM-ACT-033 Review / Inspection / Audit, WM-ACT-034 Assessment / Evaluation and WM-ECO-035 Audit / Assurance Engagement", "distinction": "Specialist models own engagement, method, evidence gathering, testing, results and assurance. This aggregate records commissioning, result intake, response and closure context.", "source_refs": [ "SRC-003", "SRC-005", "SRC-012" ] }, { "neighbor": "Evidence, incident, task and work-order models", "distinction": "External masters own evidence content, incidents and remediation work. The aggregate keeps integrity-qualified references, compliance disposition, acceptance criteria and verification status.", "source_refs": [ "SRC-005", "SRC-006", "SRC-007", "SRC-013", "SRC-015" ] }, { "neighbor": "Attestation, certification, submission and regulator response", "distinction": "A status claim, signed declaration, independent certification, filing receipt and regulator decision each retain independent authority and state. None proves continuing compliance by itself.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-012", "SRC-016" ] }, { "neighbor": "BPMN, OSCAL, SACM, SARIF, ODRL and PROV", "distinction": "These are versioned process, control-assessment, assurance, tool-result, policy and provenance projections with different scopes. No mapping is assumed lossless or universally applicable.", "source_refs": [ "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Compliance management systems - Requirements with guidance for use", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/75080.html", "version_or_date": "ISO 37301:2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Defines requirements and guidance for establishing, developing, implementing, evaluating, maintaining and improving a compliance management system; full normative text is access-restricted." }, { "id": "SRC-002", "title": "Risk management - Guidelines", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/65694.html", "version_or_date": "ISO 31000:2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides principles and a process for identifying, analyzing, evaluating, treating, monitoring and communicating risk; full normative text is access-restricted." }, { "id": "SRC-003", "title": "Guidelines for auditing management systems", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/70017.html", "version_or_date": "ISO 19011:2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides guidance on audit-program management and management-system audits; audit execution remains a sibling process and full text is access-restricted." }, { "id": "SRC-004", "title": "Security and Privacy Controls for Information Systems and Organizations", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final", "version_or_date": "NIST SP 800-53 Rev. 5 Release 5.2.0, 27 August 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides a customizable control catalog linked to mission, law, regulation, policy and risk; it is a security and privacy profile rather than a universal control set." }, { "id": "SRC-005", "title": "Assessing Security and Privacy Controls in Information Systems and Organizations", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/53/a/r5/final", "version_or_date": "NIST SP 800-53A Rev. 5 Release 5.2.0, 27 August 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Defines customizable assessment procedures, assessment plans and analysis of control-assessment results within a risk-management framework." }, { "id": "SRC-006", "title": "Open Security Controls Assessment Language", "organization": "National Institute of Standards and Technology", "url": "https://pages.nist.gov/OSCAL/", "version_or_date": "OSCAL 1.2.3, released 7 August 2026", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides machine-readable catalogs, profiles, system plans, assessment plans, results and plans of action and milestones in XML, JSON and YAML." }, { "id": "SRC-007", "title": "Evaluation of Corporate Compliance Programs", "organization": "United States Department of Justice", "url": "https://www.justice.gov/criminal-fraud/page/file/937501/dl?inline", "version_or_date": "Updated September 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides a prosecutorial evaluation profile covering design, resourcing and effectiveness, including risk assessment, policies, training, reporting, investigation, third parties, incentives, discipline and improvement." }, { "id": "SRC-008", "title": "Annotated 2025 Chapter 8, section 8B2.1 Effective Compliance and Ethics Program", "organization": "United States Sentencing Commission", "url": "https://www.ussc.gov/guidelines/2025-guidelines-manual/annotated-2025-chapter-8", "version_or_date": "2025 Guidelines Manual, effective 1 November 2025", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides a United States organizational compliance profile covering standards, oversight, due diligence, communication, monitoring, reporting, incentives, discipline, response and periodic risk assessment." }, { "id": "SRC-009", "title": "Recommendation of the Council on Public Integrity", "organization": "Organisation for Economic Co-operation and Development", "url": "https://legalinstruments.oecd.org/public/doc/353/353.en.pdf", "version_or_date": "OECD/LEGAL/0435, adopted 26 January 2017", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Supports integrity systems, risk management, standards, leadership, accountability, participation, enforcement and monitoring in the public sector." }, { "id": "SRC-010", "title": "An Anti-Corruption Ethics and Compliance Programme for Business: A Practical Guide", "organization": "United Nations Office on Drugs and Crime", "url": "https://www.unodc.org/documents/corruption/Publications/2013/13-84498_Ebook.pdf", "version_or_date": "United Nations, 2013", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides a practical anti-corruption compliance profile for risk assessment, support, controls, reporting, training, review and remediation." }, { "id": "SRC-011", "title": "Business Process Model and Notation", "organization": "Object Management Group", "url": "https://www.omg.org/spec/BPMN/2.0.2/About-BPMN", "version_or_date": "BPMN 2.0.2, formal specification, January 2014", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides process, participant, activity, event, gateway, message and exception notation for projections, not compliance semantics." }, { "id": "SRC-012", "title": "Structured Assurance Case Metamodel", "organization": "Object Management Group", "url": "https://www.omg.org/spec/SACM/2.3/About-SACM", "version_or_date": "SACM 2.3, formal specification", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Structures claims, argumentation and evidence used to communicate a defensible assurance case among operators, suppliers, acquirers and regulators." }, { "id": "SRC-013", "title": "Static Analysis Results Interchange Format", "organization": "OASIS Open", "url": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/sarif-v2.1.0-os.html", "version_or_date": "SARIF 2.1.0, OASIS Standard, 27 March 2020", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Defines portable tool-result, rule, location, severity, baseline and suppression records; use is limited to applicable automated-analysis findings." }, { "id": "SRC-014", "title": "ODRL Information Model 2.2", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/odrl-model/", "version_or_date": "W3C Recommendation, 15 February 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Models permissions, prohibitions, duties, constraints, parties and assets for policy-expression projections, not legal applicability decisions." }, { "id": "SRC-015", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides entity, activity, agent, attribution, delegation, derivation, revision, generation and invalidation semantics for compliance evidence and decisions." }, { "id": "SRC-016", "title": "Regulation (EU) 2016/679 General Data Protection Regulation", "organization": "European Union", "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj", "version_or_date": "27 April 2016, applicable from 25 May 2018", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides a jurisdictional accountability example including principles, responsibility, records, security, data-subject rights and evidence of compliance." }, { "id": "SRC-017", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/info/rfc3339/", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T10:20:00Z", "relevance": "Provides interoperable timestamps with seconds and explicit UTC relationship for source, evidence, finding, remediation and decision times." } ], "structure": { "bundles": [ { "id": "programme-identity-scope-authority-and-regulatory-context", "name": "Programme identity, scope, authority and regulatory context", "description": "Groups governed compliance context for programme identity, scope, authority and regulatory context.", "rationale": "Compliance claims are meaningful only for a versioned subject, scope, jurisdiction, source set, owner and evaluation period.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "layers": [ { "id": "programme-profile-identifiers-subject-scope-and-governance", "name": "Programme profile, identifiers, subject, scope and governance", "description": "Groups source-qualified compliance context for programme profile, identifiers, subject, scope and governance.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ], "findings": [ { "id": "compliance-programme-profile-root-identity-subject-and-boundary", "name": "Compliance programme profile, root identity, subject and boundary", "description": "Records compliance programme profile, root identity, subject and boundary as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ], "questions": [ { "id": "compliance-programme-profile-root-identity-subject-and-boundary-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish compliance programme profile, root identity, subject and boundary?", "kind": "identity", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "compliance-programme-profile-root-identity-subject-and-boundary-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by compliance programme profile, root identity, subject and boundary, with which authority, independence and limits?", "kind": "composition", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "compliance-programme-profile-root-identity-subject-and-boundary-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to compliance programme profile, root identity, subject and boundary, and how is it corrected?", "kind": "privacy", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "compliance-programme-profile-root-identity-subject-and-boundary-data", "name": "Compliance programme profile, root identity, subject and boundary data", "description": "Typed data for compliance programme profile, root identity, subject and boundary with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ] } ], "artifacts": [ { "id": "compliance-programme-profile-root-identity-subject-and-boundary-record", "name": "Compliance programme profile, root identity, subject and boundary record", "description": "Immutable or successor-versioned compliance evidence for compliance programme profile, root identity, subject and boundary.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for compliance-programme-profile-root-identity-subject-and-boundary; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "owner-governing-body-steward-responsible-functions-resources-and-independence", "name": "Owner, governing body, steward, responsible functions, resources and independence", "description": "Records owner, governing body, steward, responsible functions, resources and independence as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ], "questions": [ { "id": "owner-governing-body-steward-responsible-functions-resources-and-independence-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish owner, governing body, steward, responsible functions, resources and independence?", "kind": "ownership", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "owner-governing-body-steward-responsible-functions-resources-and-independence-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by owner, governing body, steward, responsible functions, resources and independence, with which authority, independence and limits?", "kind": "evidence", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "owner-governing-body-steward-responsible-functions-resources-and-independence-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to owner, governing body, steward, responsible functions, resources and independence, and how is it corrected?", "kind": "lifecycle", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "owner-governing-body-steward-responsible-functions-resources-and-independence-data", "name": "Owner, governing body, steward, responsible functions, resources and independence data", "description": "Typed data for owner, governing body, steward, responsible functions, resources and independence with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ] } ], "artifacts": [ { "id": "owner-governing-body-steward-responsible-functions-resources-and-independence-record", "name": "Owner, governing body, steward, responsible functions, resources and independence record", "description": "Immutable or successor-versioned compliance evidence for owner, governing body, steward, responsible functions, resources and independence.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for owner-governing-body-steward-responsible-functions-resources-and-independence; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "regulatory-sources-jurisdiction-effective-period-and-change", "name": "Regulatory sources, jurisdiction, effective period and change", "description": "Groups source-qualified compliance context for regulatory sources, jurisdiction, effective period and change.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016", "SRC-017" ], "findings": [ { "id": "authority-source-instrument-provision-version-jurisdiction-and-language", "name": "Authority, source instrument, provision, version, jurisdiction and language", "description": "Records authority, source instrument, provision, version, jurisdiction and language as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016", "SRC-017" ], "questions": [ { "id": "authority-source-instrument-provision-version-jurisdiction-and-language-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish authority, source instrument, provision, version, jurisdiction and language?", "kind": "provenance", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "authority-source-instrument-provision-version-jurisdiction-and-language-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by authority, source instrument, provision, version, jurisdiction and language, with which authority, independence and limits?", "kind": "ownership", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "authority-source-instrument-provision-version-jurisdiction-and-language-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to authority, source instrument, provision, version, jurisdiction and language, and how is it corrected?", "kind": "quality", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "authority-source-instrument-provision-version-jurisdiction-and-language-data", "name": "Authority, source instrument, provision, version, jurisdiction and language data", "description": "Typed data for authority, source instrument, provision, version, jurisdiction and language with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016", "SRC-017" ] } ], "artifacts": [ { "id": "authority-source-instrument-provision-version-jurisdiction-and-language-record", "name": "Authority, source instrument, provision, version, jurisdiction and language record", "description": "Immutable or successor-versioned compliance evidence for authority, source instrument, provision, version, jurisdiction and language.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for authority-source-instrument-provision-version-jurisdiction-and-language; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "publication-effective-transition-repeal-supersession-change-impact-and-watch", "name": "Publication, effective, transition, repeal, supersession, change impact and watch", "description": "Records publication, effective, transition, repeal, supersession, change impact and watch as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016", "SRC-017" ], "questions": [ { "id": "publication-effective-transition-repeal-supersession-change-impact-and-watch-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish publication, effective, transition, repeal, supersession, change impact and watch?", "kind": "temporal", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "publication-effective-transition-repeal-supersession-change-impact-and-watch-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by publication, effective, transition, repeal, supersession, change impact and watch, with which authority, independence and limits?", "kind": "measurement", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "publication-effective-transition-repeal-supersession-change-impact-and-watch-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to publication, effective, transition, repeal, supersession, change impact and watch, and how is it corrected?", "kind": "security", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "publication-effective-transition-repeal-supersession-change-impact-and-watch-data", "name": "Publication, effective, transition, repeal, supersession, change impact and watch data", "description": "Typed data for publication, effective, transition, repeal, supersession, change impact and watch with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016", "SRC-017" ] } ], "artifacts": [ { "id": "publication-effective-transition-repeal-supersession-change-impact-and-watch-record", "name": "Publication, effective, transition, repeal, supersession, change impact and watch record", "description": "Immutable or successor-versioned compliance evidence for publication, effective, transition, repeal, supersession, change impact and watch.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for publication-effective-transition-repeal-supersession-change-impact-and-watch; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016", "SRC-017" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "obligations-applicability-risk-and-control-mapping", "name": "Obligations, applicability, risk and control mapping", "description": "Groups governed compliance context for obligations, applicability, risk and control mapping.", "rationale": "The aggregate records attributable interpretations and mappings while authoritative obligations, risks and control definitions remain external masters.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016" ], "layers": [ { "id": "requirements-obligations-applicability-and-interpretation", "name": "Requirements, obligations, applicability and interpretation", "description": "Groups source-qualified compliance context for requirements, obligations, applicability and interpretation.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016" ], "findings": [ { "id": "requirement-obligation-prohibition-duty-right-and-authoritative-text-reference", "name": "Requirement, obligation, prohibition, duty, right and authoritative-text reference", "description": "Records requirement, obligation, prohibition, duty, right and authoritative-text reference as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016" ], "questions": [ { "id": "requirement-obligation-prohibition-duty-right-and-authoritative-text-reference-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish requirement, obligation, prohibition, duty, right and authoritative-text reference?", "kind": "requirement", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "requirement-obligation-prohibition-duty-right-and-authoritative-text-reference-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by requirement, obligation, prohibition, duty, right and authoritative-text reference, with which authority, independence and limits?", "kind": "exception", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "requirement-obligation-prohibition-duty-right-and-authoritative-text-reference-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to requirement, obligation, prohibition, duty, right and authoritative-text reference, and how is it corrected?", "kind": "retention", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "requirement-obligation-prohibition-duty-right-and-authoritative-text-reference-data", "name": "Requirement, obligation, prohibition, duty, right and authoritative-text reference data", "description": "Typed data for requirement, obligation, prohibition, duty, right and authoritative-text reference with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016" ] } ], "artifacts": [ { "id": "requirement-obligation-prohibition-duty-right-and-authoritative-text-reference-record", "name": "Requirement, obligation, prohibition, duty, right and authoritative-text reference record", "description": "Immutable or successor-versioned compliance evidence for requirement, obligation, prohibition, duty, right and authoritative-text reference.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for requirement-obligation-prohibition-duty-right-and-authoritative-text-reference; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "applicability-subject-activity-threshold-exemption-interpretation-and-rationale", "name": "Applicability, subject, activity, threshold, exemption, interpretation and rationale", "description": "Records applicability, subject, activity, threshold, exemption, interpretation and rationale as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016" ], "questions": [ { "id": "applicability-subject-activity-threshold-exemption-interpretation-and-rationale-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish applicability, subject, activity, threshold, exemption, interpretation and rationale?", "kind": "decision", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "applicability-subject-activity-threshold-exemption-interpretation-and-rationale-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by applicability, subject, activity, threshold, exemption, interpretation and rationale, with which authority, independence and limits?", "kind": "provenance", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "applicability-subject-activity-threshold-exemption-interpretation-and-rationale-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to applicability, subject, activity, threshold, exemption, interpretation and rationale, and how is it corrected?", "kind": "interoperability", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "applicability-subject-activity-threshold-exemption-interpretation-and-rationale-data", "name": "Applicability, subject, activity, threshold, exemption, interpretation and rationale data", "description": "Typed data for applicability, subject, activity, threshold, exemption, interpretation and rationale with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016" ] } ], "artifacts": [ { "id": "applicability-subject-activity-threshold-exemption-interpretation-and-rationale-record", "name": "Applicability, subject, activity, threshold, exemption, interpretation and rationale record", "description": "Immutable or successor-versioned compliance evidence for applicability, subject, activity, threshold, exemption, interpretation and rationale.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for applicability-subject-activity-threshold-exemption-interpretation-and-rationale; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-014", "SRC-016" ] } ], "inline_only_rationale": null } ] }, { "id": "risk-controls-objectives-ownership-and-traceability", "name": "Risk, controls, objectives, ownership and traceability", "description": "Groups source-qualified compliance context for risk, controls, objectives, ownership and traceability.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ], "findings": [ { "id": "compliance-risk-cause-event-consequence-likelihood-impact-and-tolerance-reference", "name": "Compliance risk, cause, event, consequence, likelihood, impact and tolerance reference", "description": "Records compliance risk, cause, event, consequence, likelihood, impact and tolerance reference as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ], "questions": [ { "id": "compliance-risk-cause-event-consequence-likelihood-impact-and-tolerance-reference-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish compliance risk, cause, event, consequence, likelihood, impact and tolerance reference?", "kind": "relationship", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "compliance-risk-cause-event-consequence-likelihood-impact-and-tolerance-reference-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by compliance risk, cause, event, consequence, likelihood, impact and tolerance reference, with which authority, independence and limits?", "kind": "process", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "compliance-risk-cause-event-consequence-likelihood-impact-and-tolerance-reference-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to compliance risk, cause, event, consequence, likelihood, impact and tolerance reference, and how is it corrected?", "kind": "decision", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "compliance-risk-cause-event-consequence-likelihood-impact-and-tolerance-reference-data", "name": "Compliance risk, cause, event, consequence, likelihood, impact and tolerance reference data", "description": "Typed data for compliance risk, cause, event, consequence, likelihood, impact and tolerance reference with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "compliance-risk-cause-event-consequence-likelihood-impact-and-tolerance-reference-record", "name": "Compliance risk, cause, event, consequence, likelihood, impact and tolerance reference record", "description": "Immutable or successor-versioned compliance evidence for compliance risk, cause, event, consequence, likelihood, impact and tolerance reference.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for compliance-risk-cause-event-consequence-likelihood-impact-and-tolerance-reference; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "control-objective-definition-owner-type-frequency-mapping-and-coverage", "name": "Control objective, definition, owner, type, frequency, mapping and coverage", "description": "Records control objective, definition, owner, type, frequency, mapping and coverage as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ], "questions": [ { "id": "control-objective-definition-owner-type-frequency-mapping-and-coverage-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish control objective, definition, owner, type, frequency, mapping and coverage?", "kind": "composition", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "control-objective-definition-owner-type-frequency-mapping-and-coverage-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by control objective, definition, owner, type, frequency, mapping and coverage, with which authority, independence and limits?", "kind": "validation", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "control-objective-definition-owner-type-frequency-mapping-and-coverage-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to control objective, definition, owner, type, frequency, mapping and coverage, and how is it corrected?", "kind": "state", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "control-objective-definition-owner-type-frequency-mapping-and-coverage-data", "name": "Control objective, definition, owner, type, frequency, mapping and coverage data", "description": "Typed data for control objective, definition, owner, type, frequency, mapping and coverage with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "control-objective-definition-owner-type-frequency-mapping-and-coverage-record", "name": "Control objective, definition, owner, type, frequency, mapping and coverage record", "description": "Immutable or successor-versioned compliance evidence for control objective, definition, owner, type, frequency, mapping and coverage.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for control-objective-definition-owner-type-frequency-mapping-and-coverage; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "implementation-evidence-monitoring-and-control-assurance", "name": "Implementation, evidence, monitoring and control assurance", "description": "Groups governed compliance context for implementation, evidence, monitoring and control assurance.", "rationale": "Design and operating assertions require source-qualified implementation and evidence records rather than unsupported declarations.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-010", "SRC-012", "SRC-013", "SRC-015", "SRC-017" ], "layers": [ { "id": "control-implementation-design-operation-and-responsibility", "name": "Control implementation, design, operation and responsibility", "description": "Groups source-qualified compliance context for control implementation, design, operation and responsibility.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-010" ], "findings": [ { "id": "implementation-description-component-owner-operator-scope-and-dependency", "name": "Implementation description, component, owner, operator, scope and dependency", "description": "Records implementation description, component, owner, operator, scope and dependency as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-010" ], "questions": [ { "id": "implementation-description-component-owner-operator-scope-and-dependency-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish implementation description, component, owner, operator, scope and dependency?", "kind": "definition", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "implementation-description-component-owner-operator-scope-and-dependency-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by implementation description, component, owner, operator, scope and dependency, with which authority, independence and limits?", "kind": "privacy", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "implementation-description-component-owner-operator-scope-and-dependency-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to implementation description, component, owner, operator, scope and dependency, and how is it corrected?", "kind": "identity", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "implementation-description-component-owner-operator-scope-and-dependency-data", "name": "Implementation description, component, owner, operator, scope and dependency data", "description": "Typed data for implementation description, component, owner, operator, scope and dependency with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "implementation-description-component-owner-operator-scope-and-dependency-record", "name": "Implementation description, component, owner, operator, scope and dependency record", "description": "Immutable or successor-versioned compliance evidence for implementation description, component, owner, operator, scope and dependency.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for implementation-description-component-owner-operator-scope-and-dependency; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "design-effectiveness-operating-effectiveness-frequency-execution-and-failure", "name": "Design effectiveness, operating effectiveness, frequency, execution and failure", "description": "Records design effectiveness, operating effectiveness, frequency, execution and failure as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-010" ], "questions": [ { "id": "design-effectiveness-operating-effectiveness-frequency-execution-and-failure-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish design effectiveness, operating effectiveness, frequency, execution and failure?", "kind": "validation", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "design-effectiveness-operating-effectiveness-frequency-execution-and-failure-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by design effectiveness, operating effectiveness, frequency, execution and failure, with which authority, independence and limits?", "kind": "lifecycle", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "design-effectiveness-operating-effectiveness-frequency-execution-and-failure-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to design effectiveness, operating effectiveness, frequency, execution and failure, and how is it corrected?", "kind": "classification", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "design-effectiveness-operating-effectiveness-frequency-execution-and-failure-data", "name": "Design effectiveness, operating effectiveness, frequency, execution and failure data", "description": "Typed data for design effectiveness, operating effectiveness, frequency, execution and failure with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "design-effectiveness-operating-effectiveness-frequency-execution-and-failure-record", "name": "Design effectiveness, operating effectiveness, frequency, execution and failure record", "description": "Immutable or successor-versioned compliance evidence for design effectiveness, operating effectiveness, frequency, execution and failure.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for design-effectiveness-operating-effectiveness-frequency-execution-and-failure; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-006", "SRC-007", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "evidence-collection-quality-freshness-and-continuous-monitoring", "name": "Evidence collection, quality, freshness and continuous monitoring", "description": "Groups source-qualified compliance context for evidence collection, quality, freshness and continuous monitoring.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015", "SRC-017" ], "findings": [ { "id": "evidence-identity-source-method-coverage-period-integrity-access-and-lineage", "name": "Evidence identity, source, method, coverage period, integrity, access and lineage", "description": "Records evidence identity, source, method, coverage period, integrity, access and lineage as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015", "SRC-017" ], "questions": [ { "id": "evidence-identity-source-method-coverage-period-integrity-access-and-lineage-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish evidence identity, source, method, coverage period, integrity, access and lineage?", "kind": "evidence", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "evidence-identity-source-method-coverage-period-integrity-access-and-lineage-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by evidence identity, source, method, coverage period, integrity, access and lineage, with which authority, independence and limits?", "kind": "quality", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "evidence-identity-source-method-coverage-period-integrity-access-and-lineage-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to evidence identity, source, method, coverage period, integrity, access and lineage, and how is it corrected?", "kind": "relationship", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "evidence-identity-source-method-coverage-period-integrity-access-and-lineage-data", "name": "Evidence identity, source, method, coverage period, integrity, access and lineage data", "description": "Typed data for evidence identity, source, method, coverage period, integrity, access and lineage with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015", "SRC-017" ] } ], "artifacts": [ { "id": "evidence-identity-source-method-coverage-period-integrity-access-and-lineage-record", "name": "Evidence identity, source, method, coverage period, integrity, access and lineage record", "description": "Immutable or successor-versioned compliance evidence for evidence identity, source, method, coverage period, integrity, access and lineage.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for evidence-identity-source-method-coverage-period-integrity-access-and-lineage; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "monitoring-signal-metric-threshold-sample-frequency-alert-anomaly-and-gap", "name": "Monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap", "description": "Records monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015", "SRC-017" ], "questions": [ { "id": "monitoring-signal-metric-threshold-sample-frequency-alert-anomaly-and-gap-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap?", "kind": "measurement", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "monitoring-signal-metric-threshold-sample-frequency-alert-anomaly-and-gap-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap, with which authority, independence and limits?", "kind": "security", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "monitoring-signal-metric-threshold-sample-frequency-alert-anomaly-and-gap-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap, and how is it corrected?", "kind": "authority", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "monitoring-signal-metric-threshold-sample-frequency-alert-anomaly-and-gap-data", "name": "Monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap data", "description": "Typed data for monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015", "SRC-017" ] } ], "artifacts": [ { "id": "monitoring-signal-metric-threshold-sample-frequency-alert-anomaly-and-gap-record", "name": "Monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap record", "description": "Immutable or successor-versioned compliance evidence for monitoring signal, metric, threshold, sample, frequency, alert, anomaly and gap.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for monitoring-signal-metric-threshold-sample-frequency-alert-anomaly-and-gap; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015", "SRC-017" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "assessment-findings-nonconformities-exceptions-and-waivers", "name": "Assessment, findings, nonconformities, exceptions and waivers", "description": "Groups governed compliance context for assessment, findings, nonconformities, exceptions and waivers.", "rationale": "Assessment results, findings and exceptions remain attributable, contestable and independently versioned.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-010", "SRC-012", "SRC-013", "SRC-015" ], "layers": [ { "id": "assessment-audit-test-scope-method-results-and-review", "name": "Assessment, audit, test, scope, method, results and review", "description": "Groups source-qualified compliance context for assessment, audit, test, scope, method, results and review.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015" ], "findings": [ { "id": "assessment-engagement-plan-criteria-procedure-sample-assessor-and-independence", "name": "Assessment engagement, plan, criteria, procedure, sample, assessor and independence", "description": "Records assessment engagement, plan, criteria, procedure, sample, assessor and independence as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015" ], "questions": [ { "id": "assessment-engagement-plan-criteria-procedure-sample-assessor-and-independence-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish assessment engagement, plan, criteria, procedure, sample, assessor and independence?", "kind": "process", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "assessment-engagement-plan-criteria-procedure-sample-assessor-and-independence-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by assessment engagement, plan, criteria, procedure, sample, assessor and independence, with which authority, independence and limits?", "kind": "retention", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "assessment-engagement-plan-criteria-procedure-sample-assessor-and-independence-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to assessment engagement, plan, criteria, procedure, sample, assessor and independence, and how is it corrected?", "kind": "requirement", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "assessment-engagement-plan-criteria-procedure-sample-assessor-and-independence-data", "name": "Assessment engagement, plan, criteria, procedure, sample, assessor and independence data", "description": "Typed data for assessment engagement, plan, criteria, procedure, sample, assessor and independence with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015" ] } ], "artifacts": [ { "id": "assessment-engagement-plan-criteria-procedure-sample-assessor-and-independence-record", "name": "Assessment engagement, plan, criteria, procedure, sample, assessor and independence record", "description": "Immutable or successor-versioned compliance evidence for assessment engagement, plan, criteria, procedure, sample, assessor and independence.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for assessment-engagement-plan-criteria-procedure-sample-assessor-and-independence; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "test-result-observation-conclusion-confidence-limit-and-contradiction", "name": "Test result, observation, conclusion, confidence, limit and contradiction", "description": "Records test result, observation, conclusion, confidence, limit and contradiction as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015" ], "questions": [ { "id": "test-result-observation-conclusion-confidence-limit-and-contradiction-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish test result, observation, conclusion, confidence, limit and contradiction?", "kind": "quality", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "test-result-observation-conclusion-confidence-limit-and-contradiction-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by test result, observation, conclusion, confidence, limit and contradiction, with which authority, independence and limits?", "kind": "interoperability", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "test-result-observation-conclusion-confidence-limit-and-contradiction-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to test result, observation, conclusion, confidence, limit and contradiction, and how is it corrected?", "kind": "constraint", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "test-result-observation-conclusion-confidence-limit-and-contradiction-data", "name": "Test result, observation, conclusion, confidence, limit and contradiction data", "description": "Typed data for test result, observation, conclusion, confidence, limit and contradiction with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015" ] } ], "artifacts": [ { "id": "test-result-observation-conclusion-confidence-limit-and-contradiction-record", "name": "Test result, observation, conclusion, confidence, limit and contradiction record", "description": "Immutable or successor-versioned compliance evidence for test result, observation, conclusion, confidence, limit and contradiction.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for test-result-observation-conclusion-confidence-limit-and-contradiction; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "finding-disposition-root-cause-exception-and-waiver", "name": "Finding disposition, root cause, exception and waiver", "description": "Groups source-qualified compliance context for finding disposition, root cause, exception and waiver.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-012", "SRC-013" ], "findings": [ { "id": "finding-nonconformity-severity-affected-scope-source-status-and-dispute", "name": "Finding, nonconformity, severity, affected scope, source, status and dispute", "description": "Records finding, nonconformity, severity, affected scope, source, status and dispute as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-012", "SRC-013" ], "questions": [ { "id": "finding-nonconformity-severity-affected-scope-source-status-and-dispute-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish finding, nonconformity, severity, affected scope, source, status and dispute?", "kind": "state", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "finding-nonconformity-severity-affected-scope-source-status-and-dispute-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by finding, nonconformity, severity, affected scope, source, status and dispute, with which authority, independence and limits?", "kind": "decision", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "finding-nonconformity-severity-affected-scope-source-status-and-dispute-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to finding, nonconformity, severity, affected scope, source, status and dispute, and how is it corrected?", "kind": "event", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "finding-nonconformity-severity-affected-scope-source-status-and-dispute-data", "name": "Finding, nonconformity, severity, affected scope, source, status and dispute data", "description": "Typed data for finding, nonconformity, severity, affected scope, source, status and dispute with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-012", "SRC-013" ] } ], "artifacts": [ { "id": "finding-nonconformity-severity-affected-scope-source-status-and-dispute-record", "name": "Finding, nonconformity, severity, affected scope, source, status and dispute record", "description": "Immutable or successor-versioned compliance evidence for finding, nonconformity, severity, affected scope, source, status and dispute.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for finding-nonconformity-severity-affected-scope-source-status-and-dispute; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-012", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "exception-waiver-authority-rationale-scope-compensating-control-expiry-and-review", "name": "Exception, waiver, authority, rationale, scope, compensating control, expiry and review", "description": "Records exception, waiver, authority, rationale, scope, compensating control, expiry and review as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-012", "SRC-013" ], "questions": [ { "id": "exception-waiver-authority-rationale-scope-compensating-control-expiry-and-review-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish exception, waiver, authority, rationale, scope, compensating control, expiry and review?", "kind": "exception", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "exception-waiver-authority-rationale-scope-compensating-control-expiry-and-review-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by exception, waiver, authority, rationale, scope, compensating control, expiry and review, with which authority, independence and limits?", "kind": "state", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "exception-waiver-authority-rationale-scope-compensating-control-expiry-and-review-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to exception, waiver, authority, rationale, scope, compensating control, expiry and review, and how is it corrected?", "kind": "temporal", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "exception-waiver-authority-rationale-scope-compensating-control-expiry-and-review-data", "name": "Exception, waiver, authority, rationale, scope, compensating control, expiry and review data", "description": "Typed data for exception, waiver, authority, rationale, scope, compensating control, expiry and review with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-012", "SRC-013" ] } ], "artifacts": [ { "id": "exception-waiver-authority-rationale-scope-compensating-control-expiry-and-review-record", "name": "Exception, waiver, authority, rationale, scope, compensating control, expiry and review record", "description": "Immutable or successor-versioned compliance evidence for exception, waiver, authority, rationale, scope, compensating control, expiry and review.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for exception-waiver-authority-rationale-scope-compensating-control-expiry-and-review; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-012", "SRC-013" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "remediation-verification-attestation-reporting-and-regulator-interface", "name": "Remediation, verification, attestation, reporting and regulator interface", "description": "Groups governed compliance context for remediation, verification, attestation, reporting and regulator interface.", "rationale": "Corrective action, verification, declaration, submission and external acceptance are separate stages with separate authorities.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-015", "SRC-016" ], "layers": [ { "id": "remediation-planning-execution-verification-and-closure", "name": "Remediation planning, execution, verification and closure", "description": "Groups source-qualified compliance context for remediation planning, execution, verification and closure.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ], "findings": [ { "id": "remediation-action-owner-priority-due-date-resource-dependency-and-progress", "name": "Remediation action, owner, priority, due date, resource, dependency and progress", "description": "Records remediation action, owner, priority, due date, resource, dependency and progress as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ], "questions": [ { "id": "remediation-action-owner-priority-due-date-resource-dependency-and-progress-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish remediation action, owner, priority, due date, resource, dependency and progress?", "kind": "lifecycle", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "remediation-action-owner-priority-due-date-resource-dependency-and-progress-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by remediation action, owner, priority, due date, resource, dependency and progress, with which authority, independence and limits?", "kind": "identity", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "remediation-action-owner-priority-due-date-resource-dependency-and-progress-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to remediation action, owner, priority, due date, resource, dependency and progress, and how is it corrected?", "kind": "composition", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "remediation-action-owner-priority-due-date-resource-dependency-and-progress-data", "name": "Remediation action, owner, priority, due date, resource, dependency and progress data", "description": "Typed data for remediation action, owner, priority, due date, resource, dependency and progress with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ] } ], "artifacts": [ { "id": "remediation-action-owner-priority-due-date-resource-dependency-and-progress-record", "name": "Remediation action, owner, priority, due date, resource, dependency and progress record", "description": "Immutable or successor-versioned compliance evidence for remediation action, owner, priority, due date, resource, dependency and progress.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for remediation-action-owner-priority-due-date-resource-dependency-and-progress; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "acceptance-criteria-independent-verification-residual-risk-reopen-and-closure", "name": "Acceptance criteria, independent verification, residual risk, reopen and closure", "description": "Records acceptance criteria, independent verification, residual risk, reopen and closure as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ], "questions": [ { "id": "acceptance-criteria-independent-verification-residual-risk-reopen-and-closure-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish acceptance criteria, independent verification, residual risk, reopen and closure?", "kind": "validation", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "acceptance-criteria-independent-verification-residual-risk-reopen-and-closure-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by acceptance criteria, independent verification, residual risk, reopen and closure, with which authority, independence and limits?", "kind": "classification", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "acceptance-criteria-independent-verification-residual-risk-reopen-and-closure-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to acceptance criteria, independent verification, residual risk, reopen and closure, and how is it corrected?", "kind": "evidence", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "acceptance-criteria-independent-verification-residual-risk-reopen-and-closure-data", "name": "Acceptance criteria, independent verification, residual risk, reopen and closure data", "description": "Typed data for acceptance criteria, independent verification, residual risk, reopen and closure with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ] } ], "artifacts": [ { "id": "acceptance-criteria-independent-verification-residual-risk-reopen-and-closure-record", "name": "Acceptance criteria, independent verification, residual risk, reopen and closure record", "description": "Immutable or successor-versioned compliance evidence for acceptance criteria, independent verification, residual risk, reopen and closure.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for acceptance-criteria-independent-verification-residual-risk-reopen-and-closure; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "attestation-disclosure-reporting-submission-and-response", "name": "Attestation, disclosure, reporting, submission and response", "description": "Groups source-qualified compliance context for attestation, disclosure, reporting, submission and response.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-015", "SRC-016" ], "findings": [ { "id": "compliance-status-claim-scope-basis-qualifier-signer-authority-and-assurance", "name": "Compliance-status claim, scope, basis, qualifier, signer, authority and assurance", "description": "Records compliance-status claim, scope, basis, qualifier, signer, authority and assurance as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-015", "SRC-016" ], "questions": [ { "id": "compliance-status-claim-scope-basis-qualifier-signer-authority-and-assurance-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish compliance-status claim, scope, basis, qualifier, signer, authority and assurance?", "kind": "authority", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "compliance-status-claim-scope-basis-qualifier-signer-authority-and-assurance-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by compliance-status claim, scope, basis, qualifier, signer, authority and assurance, with which authority, independence and limits?", "kind": "relationship", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "compliance-status-claim-scope-basis-qualifier-signer-authority-and-assurance-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to compliance-status claim, scope, basis, qualifier, signer, authority and assurance, and how is it corrected?", "kind": "ownership", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "compliance-status-claim-scope-basis-qualifier-signer-authority-and-assurance-data", "name": "Compliance-status claim, scope, basis, qualifier, signer, authority and assurance data", "description": "Typed data for compliance-status claim, scope, basis, qualifier, signer, authority and assurance with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-015", "SRC-016" ] } ], "artifacts": [ { "id": "compliance-status-claim-scope-basis-qualifier-signer-authority-and-assurance-record", "name": "Compliance-status claim, scope, basis, qualifier, signer, authority and assurance record", "description": "Immutable or successor-versioned compliance evidence for compliance-status claim, scope, basis, qualifier, signer, authority and assurance.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for compliance-status-claim-scope-basis-qualifier-signer-authority-and-assurance; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-015", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "report-notification-submission-recipient-deadline-receipt-acceptance-and-followup", "name": "Report, notification, submission, recipient, deadline, receipt, acceptance and follow-up", "description": "Records report, notification, submission, recipient, deadline, receipt, acceptance and follow-up as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-015", "SRC-016" ], "questions": [ { "id": "report-notification-submission-recipient-deadline-receipt-acceptance-and-followup-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish report, notification, submission, recipient, deadline, receipt, acceptance and follow-up?", "kind": "event", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "report-notification-submission-recipient-deadline-receipt-acceptance-and-followup-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by report, notification, submission, recipient, deadline, receipt, acceptance and follow-up, with which authority, independence and limits?", "kind": "authority", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "report-notification-submission-recipient-deadline-receipt-acceptance-and-followup-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to report, notification, submission, recipient, deadline, receipt, acceptance and follow-up, and how is it corrected?", "kind": "measurement", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "report-notification-submission-recipient-deadline-receipt-acceptance-and-followup-data", "name": "Report, notification, submission, recipient, deadline, receipt, acceptance and follow-up data", "description": "Typed data for report, notification, submission, recipient, deadline, receipt, acceptance and follow-up with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-015", "SRC-016" ] } ], "artifacts": [ { "id": "report-notification-submission-recipient-deadline-receipt-acceptance-and-followup-record", "name": "Report, notification, submission, recipient, deadline, receipt, acceptance and follow-up record", "description": "Immutable or successor-versioned compliance evidence for report, notification, submission, recipient, deadline, receipt, acceptance and follow-up.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for report-notification-submission-recipient-deadline-receipt-acceptance-and-followup; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-012", "SRC-015", "SRC-016" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "lifecycle-governance-correction-retention-and-interoperability", "name": "Lifecycle, governance, correction, retention and interoperability", "description": "Groups governed compliance context for lifecycle, governance, correction, retention and interoperability.", "rationale": "Safe agent operation requires append-only decisions, current-head resolution, protected evidence and mappings that declare scope and loss.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "layers": [ { "id": "programme-cycle-status-review-change-correction-and-supersession", "name": "Programme cycle status, review, change, correction and supersession", "description": "Groups source-qualified compliance context for programme cycle status, review, change, correction and supersession.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015", "SRC-017" ], "findings": [ { "id": "cycle-status-review-period-trigger-material-change-and-continuous-improvement", "name": "Cycle status, review period, trigger, material change and continuous improvement", "description": "Records cycle status, review period, trigger, material change and continuous improvement as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015", "SRC-017" ], "questions": [ { "id": "cycle-status-review-period-trigger-material-change-and-continuous-improvement-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish cycle status, review period, trigger, material change and continuous improvement?", "kind": "lifecycle", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "cycle-status-review-period-trigger-material-change-and-continuous-improvement-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by cycle status, review period, trigger, material change and continuous improvement, with which authority, independence and limits?", "kind": "requirement", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "cycle-status-review-period-trigger-material-change-and-continuous-improvement-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to cycle status, review period, trigger, material change and continuous improvement, and how is it corrected?", "kind": "exception", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "cycle-status-review-period-trigger-material-change-and-continuous-improvement-data", "name": "Cycle status, review period, trigger, material change and continuous improvement data", "description": "Typed data for cycle status, review period, trigger, material change and continuous improvement with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015", "SRC-017" ] } ], "artifacts": [ { "id": "cycle-status-review-period-trigger-material-change-and-continuous-improvement-record", "name": "Cycle status, review period, trigger, material change and continuous improvement record", "description": "Immutable or successor-versioned compliance evidence for cycle status, review period, trigger, material change and continuous improvement.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for cycle-status-review-period-trigger-material-change-and-continuous-improvement; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "correct-amend-withdraw-supersede-reopen-appeal-and-noncascade-lineage", "name": "Correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage", "description": "Records correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015", "SRC-017" ], "questions": [ { "id": "correct-amend-withdraw-supersede-reopen-appeal-and-noncascade-lineage-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage?", "kind": "provenance", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "correct-amend-withdraw-supersede-reopen-appeal-and-noncascade-lineage-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage, with which authority, independence and limits?", "kind": "constraint", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "correct-amend-withdraw-supersede-reopen-appeal-and-noncascade-lineage-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage, and how is it corrected?", "kind": "provenance", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "correct-amend-withdraw-supersede-reopen-appeal-and-noncascade-lineage-data", "name": "Correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage data", "description": "Typed data for correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015", "SRC-017" ] } ], "artifacts": [ { "id": "correct-amend-withdraw-supersede-reopen-appeal-and-noncascade-lineage-record", "name": "Correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage record", "description": "Immutable or successor-versioned compliance evidence for correct, amend, withdraw, supersede, reopen, appeal and non-cascade lineage.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for correct-amend-withdraw-supersede-reopen-appeal-and-noncascade-lineage; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-015", "SRC-017" ] } ], "inline_only_rationale": null } ] }, { "id": "access-retention-assurance-projection-and-agent-controls", "name": "Access, retention, assurance, projection and agent controls", "description": "Groups source-qualified compliance context for access, retention, assurance, projection and agent controls.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "findings": [ { "id": "purpose-access-redaction-privilege-confidentiality-legal-hold-retention-and-disposition", "name": "Purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition", "description": "Records purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "questions": [ { "id": "purpose-access-redaction-privilege-confidentiality-legal-hold-retention-and-disposition-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition?", "kind": "privacy", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "purpose-access-redaction-privilege-confidentiality-legal-hold-retention-and-disposition-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition, with which authority, independence and limits?", "kind": "event", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "purpose-access-redaction-privilege-confidentiality-legal-hold-retention-and-disposition-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition, and how is it corrected?", "kind": "process", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "purpose-access-redaction-privilege-confidentiality-legal-hold-retention-and-disposition-data", "name": "Purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition data", "description": "Typed data for purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "artifacts": [ { "id": "purpose-access-redaction-privilege-confidentiality-legal-hold-retention-and-disposition-record", "name": "Purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition record", "description": "Immutable or successor-versioned compliance evidence for purpose, access, redaction, privilege, confidentiality, legal hold, retention and disposition.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for purpose-access-redaction-privilege-confidentiality-legal-hold-retention-and-disposition; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "oscal-bpmn-sacm-sarif-odrl-prov-projection-version-scope-loss-and-round-trip", "name": "OSCAL, BPMN, SACM, SARIF, ODRL and PROV projection, version, scope, loss and round trip", "description": "Records oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip as source-qualified compliance context while keeping authoritative rules, controls, assessments, evidence, work and external decisions in their owning systems.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ], "questions": [ { "id": "oscal-bpmn-sacm-sarif-odrl-prov-projection-version-scope-loss-and-round-trip-q01", "text": "Which stable identities, class, scope, source-qualified assertions and explicit unknowns establish oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip?", "kind": "interoperability", "answer_data": [ "identifiers, class and scope", "source-qualified assertions", "unknown and not-applicable states" ] }, { "id": "oscal-bpmn-sacm-sarif-odrl-prov-projection-version-scope-loss-and-round-trip-q02", "text": "Who owns, interprets, performs, reviews, approves, disputes or is affected by oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip, with which authority, independence and limits?", "kind": "temporal", "answer_data": [ "actors, roles and separation of duties", "authority, independence and limits", "review, dispute and exception path" ] }, { "id": "oscal-bpmn-sacm-sarif-odrl-prov-projection-version-scope-loss-and-round-trip-q03", "text": "Which source-effective, evidence-coverage, assessment, finding, remediation, verification, decision, recorded, ingested and knowledge times apply to oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip, and how is it corrected?", "kind": "validation", "answer_data": [ "distinct regulatory and record times", "evidence, validation and uncertainty", "successor correction and retention" ] } ], "data_elements": [ { "id": "oscal-bpmn-sacm-sarif-odrl-prov-projection-version-scope-loss-and-round-trip-data", "name": "OSCAL, BPMN, SACM, SARIF, ODRL and PROV projection, version, scope, loss and round trip data", "description": "Typed data for oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip with identity, scope, source, authority, status, event and knowledge times, evidence and provenance.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "artifacts": [ { "id": "oscal-bpmn-sacm-sarif-odrl-prov-projection-version-scope-loss-and-round-trip-record", "name": "OSCAL, BPMN, SACM, SARIF, ODRL and PROV projection, version, scope, loss and round trip record", "description": "Immutable or successor-versioned compliance evidence for oscal, bpmn, sacm, sarif, odrl and prov projection, version, scope, loss and round trip.", "media_or_form": [ "logical compliance assertion", "scope, mapping, implementation, evidence, assessment, finding, exception, remediation, attestation or projection record" ], "serial": true, "identity_strategy": "Programme ID plus independent source, obligation, control-mapping, evidence, finding, exception, remediation, attestation or assertion ID for oscal-bpmn-sacm-sarif-odrl-prov-projection-version-scope-loss-and-round-trip; organization, rule title, date and status never identify a record alone.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-compliance-cycle", "name": "Register compliance cycle", "description": "Governed operation to register compliance cycle without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "subject", "scope", "authority sources", "owner mandate" ], "outputs": [ "programme root and constituent slots" ], "preconditions": [ "stable identity, subject, jurisdiction, scope, period and authority pass" ], "effects": [ "one bounded compliance cycle is registered without asserting compliance" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010" ] }, { "id": "register-regulatory-source-change", "name": "Register regulatory source change", "description": "Governed operation to register regulatory source change without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "authoritative source", "version", "effective dates", "change notice" ], "outputs": [ "source revision and impact-review trigger" ], "preconditions": [ "authenticity, jurisdiction, language, dates and predecessor pass" ], "effects": [ "the programme can reassess applicability without copying or rewriting the law" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-014", "SRC-016" ] }, { "id": "assess-applicability", "name": "Assess applicability", "description": "Governed operation to assess applicability without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "source provisions", "subject facts", "thresholds", "interpreter authority" ], "outputs": [ "versioned applicability decision" ], "preconditions": [ "facts, jurisdiction, scope, rationale, uncertainty and reviewer pass" ], "effects": [ "an attributable interpretation is recorded without becoming legal authority" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-016" ] }, { "id": "map-obligations-risks-and-controls", "name": "Map obligations, risks and controls", "description": "Governed operation to map obligations, risks and controls without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "applicable obligations", "risk references", "control definitions" ], "outputs": [ "traceability and coverage map" ], "preconditions": [ "external identities, versions, mapping rationale, owner and gaps pass" ], "effects": [ "coverage assertions are visible without absorbing obligation, risk or control masters" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-006" ] }, { "id": "record-implementation-and-monitoring-evidence", "name": "Record implementation and monitoring evidence", "description": "Governed operation to record implementation and monitoring evidence without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "control mapping", "implementation assertions", "evidence", "monitoring observations" ], "outputs": [ "source-qualified implementation and evidence index" ], "preconditions": [ "coverage period, method, source, integrity, access, freshness and contradictions pass" ], "effects": [ "design and operation claims become inspectable but not automatically effective" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-015" ] }, { "id": "commission-or-link-assessment", "name": "Commission or link assessment", "description": "Governed operation to commission or link assessment without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "scope", "criteria", "assessor", "procedures", "evidence references" ], "outputs": [ "assessment binding and result intake" ], "preconditions": [ "independence, authority, criteria version, sample and limitations pass" ], "effects": [ "audit or assessment remains external while its result is incorporated by reference" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-012" ] }, { "id": "record-finding-or-exception", "name": "Record finding or exception", "description": "Governed operation to record finding or exception without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "assessment result", "affected scope", "severity", "authority", "rationale" ], "outputs": [ "finding, exception or waiver record" ], "preconditions": [ "source, status, dispute, compensating control, expiry and review pass" ], "effects": [ "the obligation and prior evidence remain intact and contestable" ], "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-010", "SRC-013" ] }, { "id": "plan-track-and-verify-remediation", "name": "Plan, track and verify remediation", "description": "Governed operation to plan, track and verify remediation without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "finding", "action references", "owner", "criteria", "due dates" ], "outputs": [ "remediation status and independent verification" ], "preconditions": [ "authority, dependencies, evidence, residual risk and closure criteria pass" ], "effects": [ "action completion stays separate from accepted remediation closure" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-010" ] }, { "id": "attest-report-submit-and-record-response", "name": "Attest, report, submit and record response", "description": "Governed operation to attest, report, submit and record response without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "bounded status claim", "evidence basis", "signer", "recipient", "deadline" ], "outputs": [ "attestation, report, receipt and response links" ], "preconditions": [ "scope, qualifier, authority, assurance level, disclosure and recipient profile pass" ], "effects": [ "submission, receipt, acceptance, certification and continuing compliance remain separate" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009", "SRC-012", "SRC-016" ] }, { "id": "correct-project-retain-disclose-and-audit", "name": "Correct, project, retain, disclose and audit", "description": "Governed operation to correct, project, retain, disclose and audit without hidden legal interpretation, enforcement or mutation of external masters.", "inputs": [ "programme", "target profile", "access and retention policy" ], "outputs": [ "successor, projection, disclosure, tombstone or disposition event" ], "preconditions": [ "mapping versions, loss, privacy, privilege, legal hold and idempotency pass" ], "effects": [ "context stays protected, reconstructable and explicit about current head and loss" ], "source_refs": [ "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] } ], "composition": [ { "target": "WM-XCT-029 Obligation / Commitment, law, regulation and policy models", "relation": "REFERENCE", "purpose": "Resolve authoritative requirements and obligations while keeping applicability interpretation attributable and local to the cycle.", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-014", "SRC-016" ] }, { "target": "WM-KNW-015 Risk / Opportunity and WM-XCT-027 Risk / Control", "relation": "REFERENCE", "purpose": "Bind versioned risk and control masters to compliance-specific coverage, implementation and gap assertions.", "required": true, "source_refs": [ "SRC-002", "SRC-004", "SRC-006" ] }, { "target": "WM-ACT-033 Review / Inspection / Audit, WM-ACT-034 Assessment / Evaluation and WM-ECO-035 Audit / Assurance Engagement", "relation": "REFERENCE", "purpose": "Bind assessment and assurance work without owning its execution, independence or evidence-gathering lifecycle.", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-012" ] }, { "target": "Evidence, incident, task, work-order, attestation, regulator-submission, provenance, access-audit and record models", "relation": "REFERENCE", "purpose": "Resolve evidence, remediation execution, declarations, external interactions and records without copying their lifecycles.", "required": false, "source_refs": [ "SRC-005", "SRC-006", "SRC-007", "SRC-012", "SRC-013", "SRC-015", "SRC-016" ] }, { "target": "OSCAL 1.2.3, BPMN 2.0.2, SACM 2.3, SARIF 2.1.0, ODRL 2.2 and PROV-O", "relation": "ALIGN", "purpose": "Project version-pinned control, process, assurance, tool-result, policy and provenance views with scope and information-loss declarations.", "required": false, "source_refs": [ "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension owner and compliance-governance mandate", "Authoritative law, regulation, obligation, policy, risk, control, organization, asset, assessment, evidence, finding, incident, task, attestation, submission, provenance, audit and record registries", "Approved jurisdiction, sector, control, assessment, reporting, privacy, retention and interoperability profiles", "Legal-interpretation, independence, escalation, privilege, disclosure and agent-operation policies" ], "namespace_guidance": "Mint programme, scope, applicability, mapping, implementation, evidence, monitoring, finding, exception, remediation, verification, attestation, submission, correction, disclosure and event IDs; preserve authoritative source and sibling-model identifiers.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize each programme and constituent by authoritative master-system identifier, owning organization and record kind; never by organization, regulation title, date or status alone.", "Keep authoritative source, obligation, applicability interpretation, control definition, implementation assertion, evidence, assessment, finding, exception, remediation, attestation, submission and external response distinct." ], "patch_rules": [ "Extensions declare jurisdiction, sector, subject, control, evidence, assessment, reporting, privacy, retention and interoperability effects.", "Released applicability, mapping, evidence, finding, exception, remediation, verification and attestation records are immutable; corrections create linked successors.", "Never silently change scope, source version, applicability, obligation, control, evidence period, result, finding, exception, action, status, authority, disclosure or provenance." ], "compatibility_rules": [ "Ignore additive fields only when identity, scope, authoritative source, constituent kind, authority, status, time, evidence and provenance survive.", "Every projection pins profile, source and classification versions and declares jurisdiction, sector, assurance level and information loss." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier for each compliance programme, applicability decision, mapping, evidence item, finding, exception, remediation, attestation or submission, qualified by owning organization and record kind.", "Governed globally resolvable compliance-record IRI.", "Dimension UUID when neither preceding identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; distinguish source publication and effective, evidence coverage, assessment, finding, remediation, verification, attestation, submission, response, recorded, ingested and knowledge times whenever they differ.", "serial_naming_rule": "Use {programme-id}--{scope-mapping-evidence-finding-remediation-attestation-or-assertion-id}--{artifact-kind}--{revision-id}.", "integrity_rule": "Store digest, media type, record kind, scope, authoritative source and profile versions, actor, event and knowledge times, status, access marking and provenance." }, "policies": [ "The aggregate does not own Law, Regulation, Obligation, Policy, Risk, Control, Organization, Asset, Audit, Assessment, Evidence, Incident, Task, Attestation, Regulator Submission, Provenance, Access Audit or Record masters.", "Applicability, implementation, effectiveness, finding, exception, remediation, attestation, certification, submission and regulator response remain separate claims with independent sources and times.", "A closed remediation, submitted report or signed attestation never proves regulator acceptance, certification or continuing compliance.", "Agents cannot issue legal interpretations, certify compliance, approve exceptions, enforce controls, file regulator submissions, alter external statuses, disclose privileged evidence or dispose records outside explicit authority." ], "crud": { "read": [ "Resolve purpose, programme profile, subject and scope, source revisions, applicability, mappings, implementation, evidence, assessments, findings, exceptions, remediation, attestations, lineage, holds and projection loss." ], "create": [ "Bind stable programme and constituent identity, subject, jurisdiction, scope, owner, authoritative source, status and effective time before recording a compliance assertion." ], "update": [ "Append successor applicability, mapping, implementation, evidence, finding, exception, remediation, verification, attestation, submission, response and correction events with reason, authority, expected revision, event time and knowledge time." ], "delete": [ "Apply legal, regulatory, privilege, evidence, audit, litigation-hold and adopting-Dimension retention policy; retire or tombstone only the programme or named constituent without cascading to Law, Obligation, Risk, Control, Assessment, Evidence, Incident, Task, Submission or other masters, and let the external records policy execute physical disposition." ] }, "roles": [ { "name": "Compliance programme owner", "responsibilities": [ "Own programme purpose, scope, resources, governance and accountable status claims." ] }, { "name": "Legal or regulatory interpreter", "responsibilities": [ "Own attributable applicability interpretation and uncertainty within professional authority." ] }, { "name": "Control owner and operator", "responsibilities": [ "Own control mapping, implementation and operating evidence within scope." ] }, { "name": "Independent assessor or auditor", "responsibilities": [ "Own assessment criteria, method, evidence use, result, limitations and independence declaration." ] }, { "name": "Finding and remediation owner", "responsibilities": [ "Own response, action coordination, due dates, escalation and closure evidence." ] }, { "name": "Attestor or reporting officer", "responsibilities": [ "Own bounded declarations, disclosures and submissions within signing authority." ] }, { "name": "Interoperability steward", "responsibilities": [ "Own versioned projections with jurisdiction, profile, maturity and loss declarations." ] }, { "name": "Privacy, privilege, records and assurance steward", "responsibilities": [ "Own protected views, privilege handling, disclosures, holds, retention and auditability." ] } ], "access": { "default_rule": "Deny compliance evidence, findings, legal interpretations and privileged context unless a purpose-bound policy permits the minimum necessary view.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Declared legal, regulator, auditor, subject-rights, investigation, court or emergency access must cite authority, scope, purpose, privilege treatment and time limit where applicable and must be logged." ], "audit_requirements": [ "Log actor, agent, role, purpose, programme and constituent, operation, authority, policy, RFC 3339 time, affected fields, source revision and outcome without duplicating protected evidence unnecessarily." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension legal-authority, compliance, evidence, assessment, independence, privilege, privacy, access, correction, records and agent policies.", "Read this aggregate and linked regulation, obligation, policy, risk, control, organization, asset, audit, assessment, evidence, incident, task, attestation, submission, provenance and record models before mutation." ] } }, "coverage": { "claim": "WM-ACT-051 covers a source-qualified regulatory-compliance-cycle aggregate for a bounded subject, scope, jurisdiction and period. It connects authoritative-source revisions, applicability decisions, obligation-risk-control mappings, implementation evidence, monitoring, assessment intake, findings, exceptions, remediation, verification, attestation and reporting without treating status as timeless proof. Jurisdiction and sector profiles, missing registry relations, access-restricted ISO clauses, release-pinned mappings and independent external review remain deferred.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Identity is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "classification and definition", "status": "covered", "notes": "Classification and definition is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "direct properties", "status": "covered", "notes": "Direct properties is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Recognition and observation is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Capabilities and possible actions is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "composition", "status": "covered", "notes": "Composition is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "lifecycle", "status": "covered", "notes": "Lifecycle is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "relationships", "status": "covered", "notes": "Relationships is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "temporal", "status": "covered", "notes": "Temporal is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "spatial", "status": "covered", "notes": "Spatial is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "provenance", "status": "covered", "notes": "Provenance is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Ownership and stewardship is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "validation and quality", "status": "covered", "notes": "Validation and quality is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "access and privacy", "status": "covered", "notes": "Access and privacy is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention and deletion is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." }, { "dimension": "interoperability", "status": "covered", "notes": "Interoperability is explicit; jurisdiction, sector, missing relations, access-restricted ISO clauses and release-pinned validation remain held where applicable." } ], "known_omissions": [ "Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.", "No relation-ledger edge is registered for WM-ACT-051, so links to obligation, risk/control, audit, assessment, assurance, incident, task, attestation and record models remain candidate boundary notes.", "Financial services, healthcare, product safety, environment, labor, tax, privacy, anti-corruption, competition, export control, AI and other regimes require jurisdiction and sector profiles.", "ISO normative clauses are access-restricted; NIST, DOJ, USSC, OECD, UNODC, GDPR, OSCAL and SARIF each have sectoral, jurisdictional or technical scope and require release-pinned validation." ], "conflicts": [ "Authoritative requirement and attributable applicability interpretation are not interchangeable.", "Control design, implementation, operation, assessment result and operating effectiveness are separate assertions.", "Remediation action completion, finding closure, attestation, submission, certification, regulator acceptance and continuing compliance are not equivalent." ], "regional_assumptions": [ "Legal effect, applicability, professional privilege, regulator authority, reporting, certification, retention and disclosure depend on jurisdiction, sector and facts.", "DOJ and USSC are United States profiles, GDPR is European Union law and OECD or UNODC guidance is not itself binding law.", "Local control libraries, regulatory taxonomies, severity scales, assurance levels, evidence rules and exception authorities require versioned profiles." ], "adversarial_checks": [ "Reject a programme or constituent without stable identity, scope, authoritative source, responsible authority, status, effective time and lineage head.", "Reject a compliance status that lacks evaluation scope, time, evidence basis, qualifiers, uncertainty and accountable signer.", "Reject applicability or control mapping that copies altered legal text, hides interpretation, loses source version or treats guidance as binding law.", "Reject finding closure that relies only on action completion and lacks independent verification against acceptance criteria and residual risk.", "Reject autonomous legal interpretation, certification, exception approval, regulator filing, control enforcement, privileged disclosure or disposition outside explicit authority." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The subject composes multiple independently identifiable decisions, mappings, evidence records, findings, exceptions, actions and declarations over one governed cycle. Aggregate is more accurate than event. The frozen record_plane world-model and catalogue entry_kind standalone-mm are separate axes from this subject-schema decision." }, "decisions": [ { "concept": "Authoritative source and applicability interpretation", "disposition": "accepted", "rationale": "Law, regulation and obligations keep external authority. The process stores a versioned reference and attributable, contestable applicability decision for defined facts, scope, jurisdiction and time." }, { "concept": "Obligation, risk, control and implementation separation", "disposition": "accepted", "rationale": "External masters own definitions and lifecycle. Compliance-specific mappings, coverage, implementation and gap assertions remain independently sourced and versioned." }, { "concept": "Evidence, assessment result and finding separation", "disposition": "accepted-external", "rationale": "Evidence and specialist audit or assessment records retain their own identity, method, authority and access. The aggregate owns qualified links, result intake, disposition and response context." }, { "concept": "Exception, remediation and closure", "disposition": "accepted", "rationale": "A waiver does not erase an obligation, action completion does not close a finding, and closure requires attributable verification against criteria with residual risk and reopen rules." }, { "concept": "Attestation, submission and external acceptance", "disposition": "accepted", "rationale": "A bounded compliance claim, signed declaration, filing receipt, certification and regulator decision are separate assertions. None proves continuing compliance by itself." }, { "concept": "Relationship completeness", "disposition": "deferred", "rationale": "No relation-ledger edge is registered. Plausible links to obligation, risk/control, audit, assessment, assurance, evidence, incident, task, attestation, submission and record models remain candidate boundary notes and create no cascade behavior." }, { "concept": "ISO access and jurisdictional sources", "disposition": "accepted-with-source-hold", "rationale": "ISO catalogue metadata is authoritative but normative clauses are access-restricted. DOJ, USSC, GDPR, OECD, UNODC, NIST and SARIF each have jurisdictional, sectoral or technical scope and cannot be generalized silently." }, { "concept": "Machine-readable projections", "disposition": "accepted-with-validation-hold", "rationale": "OSCAL, BPMN, SACM, SARIF, ODRL and PROV cover different control, process, assurance, tool-result, policy and provenance surfaces. Every mapping must pin version, scope and information loss." }, { "concept": "Single-provider waiver and no-tools audit", "disposition": "accepted-with-mandatory-hold", "rationale": "One Claude Sonnet and one Grok 4.6 research attempt each timed out after 120 seconds. Codex audited the frozen validated result and comparison locally without tools or new research facts. Confidence remains medium and assurance remains reviewable-draft." } ], "publicationHolds": [ "Absence-of-external-review hold: one Claude Sonnet and one Grok 4.6 research attempt for WM-ACT-051 each timed out after 120 seconds. No external research result was admitted.", "Relationship-completeness hold: no relation-ledger edge is registered for obligation, risk/control, audit, assessment, assurance, evidence, incident, task, attestation, submission or record models.", "Source-access hold: ISO 37301:2021, ISO 31000:2018 and ISO 19011:2018 official catalogue entries were verified, but their full normative clauses are access-restricted and are not claimed by this draft.", "Jurisdiction and sector hold: legal effect, applicability, privilege, assurance, certification, reporting, retention and disclosure require regime-specific profiles.", "Interoperability hold: OSCAL, BPMN, SACM, SARIF, ODRL and PROV projections require release-pinned mappings, scope constraints, licensing review where applicable, loss declarations and validation.", "Compliance-claim hold: adopters must preserve bounded scope, evaluation time, evidence basis, qualifiers, uncertainty and signer authority and may not use published status as proof of compliance.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Approve or reject registry relations to obligation, risk/control, audit, assessment, assurance, evidence, incident, task, attestation, submission and record models.", "Create jurisdiction and sector profiles for financial services, healthcare, product safety, environment, labor, tax, privacy, anti-corruption, competition, export control and AI regimes.", "Perform licensed clause-level review of ISO 37301, ISO 31000 and ISO 19011 before any conformance claim.", "Test release-pinned OSCAL, BPMN, SACM, SARIF, ODRL and PROV mappings with round-trip and information-loss evidence.", "Obtain supplemental independent external review and resolve any material challenge before canonical promotion." ] }, "statistics": { "sources": 17, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }