<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Compliance Evidence Automation | CodeYourCompliance]]></title><description><![CDATA[CodeYourCompliance explores compliance automation, replayable audit evidence, read-only evidence collection, policy-as-code, and evidence packages.]]></description><link>https://www.codeyourcompliance.com</link><image><url>https://substackcdn.com/image/fetch/$s_!yIEc!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5cabd34-4bcf-4182-8a08-961d2b665a8d_1254x1254.png</url><title>Compliance Evidence Automation | CodeYourCompliance</title><link>https://www.codeyourcompliance.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 02 Aug 2026 11:21:21 GMT</lastBuildDate><atom:link href="https://www.codeyourcompliance.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[CodeYourCompliance]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[codeyourcompliance@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[codeyourcompliance@substack.com]]></itunes:email><itunes:name><![CDATA[www.codeyourcompliance.com]]></itunes:name></itunes:owner><itunes:author><![CDATA[www.codeyourcompliance.com]]></itunes:author><googleplay:owner><![CDATA[codeyourcompliance@substack.com]]></googleplay:owner><googleplay:email><![CDATA[codeyourcompliance@substack.com]]></googleplay:email><googleplay:author><![CDATA[www.codeyourcompliance.com]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[A Control Result Is Not Replayable Evidence]]></title><description><![CDATA[PASS or FAIL does not show whether the system changed or the decision conditions changed. See how replayable evidence preserves the full decision path.]]></description><link>https://www.codeyourcompliance.com/p/a-control-result-is-not-replayable</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/a-control-result-is-not-replayable</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Fri, 31 Jul 2026 09:13:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!l8_f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A host passed a control yesterday and failed it today. The retained record shows only this:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;json&quot;,&quot;nodeId&quot;:&quot;bffe8bc5-ff66-4408-abab-7d49575ec596&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-json">2026-07-29: PASS
2026-07-30: FAIL</code></pre></div><p>The first question is whether the host changed or the test changed. The record cannot answer it.</p><p>The package inventory may have moved, but the baseline, freshness rule, policy or evaluator may also have changed. The same evidence can produce a different result when it is judged under a different evaluation context.</p><p>With only <code>PASS</code> and <code>FAIL</code>, there is no way to separate a change in the system from a change in the decision conditions. The conclusions were retained. The basis for them was not.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!l8_f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!l8_f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!l8_f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!l8_f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!l8_f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!l8_f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:936577,&quot;alt&quot;:&quot;Diagram showing a control changing from &#8220;Yesterday: PASS&#8221; to &#8220;Today: FAIL,&#8221; followed by the question &#8220;What changed?&#8221; The diagram branches into two possible causes: system state changed, including package inventory, version, or configuration; or decision conditions changed, including baseline, freshness window, policy artifact, or evaluator/runtime. The diagram concludes that PASS/FAIL alone cannot distinguish between these paths.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.codeyourcompliance.com/i/209215539?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram showing a control changing from &#8220;Yesterday: PASS&#8221; to &#8220;Today: FAIL,&#8221; followed by the question &#8220;What changed?&#8221; The diagram branches into two possible causes: system state changed, including package inventory, version, or configuration; or decision conditions changed, including baseline, freshness window, policy artifact, or evaluator/runtime. The diagram concludes that PASS/FAIL alone cannot distinguish between these paths." title="Diagram showing a control changing from &#8220;Yesterday: PASS&#8221; to &#8220;Today: FAIL,&#8221; followed by the question &#8220;What changed?&#8221; The diagram branches into two possible causes: system state changed, including package inventory, version, or configuration; or decision conditions changed, including baseline, freshness window, policy artifact, or evaluator/runtime. The diagram concludes that PASS/FAIL alone cannot distinguish between these paths." srcset="https://substackcdn.com/image/fetch/$s_!l8_f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!l8_f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!l8_f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!l8_f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c9a5226-d039-4dad-b15c-882f9ab9e31c_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A changed control result does not show whether the system changed or the decision conditions changed. Replay requires both sides of that distinction to remain inspectable.</figcaption></figure></div><p>That is why a stored control result is not replayable evidence. An earlier note asked whether <a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">audit evidence can survive replay</a>; the harder implementation question is what must be retained for that replay to mean anything.</p><h2>What must survive the original decision</h2><p><a href="https://www.codeyourcompliance.com/p/compliance-is-not-documentation-it-18e">Replayable evidence is not the same as retained documentation.</a> Replay does not mean running the same scanner again.</p><p>A new scan observes the system as it exists now. Replay reconstructs a previous decision from the artifacts that existed when that decision was made.</p><p>For that reconstruction to be credible, the retained package must include more than the observation. It must also preserve the schema that admitted the evidence, the context that supplied the threshold or baseline, the policy artifact, the selected decision engine, the implementation version and an integrity digest binding the assessment to the original evidence bytes.</p><p>Each artifact answers a different review question.</p><p>The evidence shows what the collector observed. The schema shows what input was considered admissible. The context records the rule parameters used at that time. The policy contains the decision logic. Runtime metadata identifies the execution path. The digest shows whether the retained evidence has changed since evaluation.</p><p>If any of these elements is missing, part of the decision must be inferred rather than replayed.</p><p>A timestamped result may still be useful operationally, but it is only a historical claim unless the decision path can be reconstructed.</p><h2>The collector should not decide compliance</h2><p>Consider a <a href="https://www.codeyourcompliance.com/p/read-only-collection-as-an-audit">read-only collector operating within an explicit audit boundary</a>. It returns the following package inventory:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;json&quot;,&quot;nodeId&quot;:&quot;62a03251-321f-4c09-8f64-fd5d96f326c9&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-json">{
  "packages": [
    {"name": "openssl", "version": "3.0.13"},
    {"name": "python3", "version": "3.12.3"},
    {"name": "curl", "version": "8.5.0"}
  ]
}</code></pre></div><p>This tells us what the collector observed. It does not tell us whether the host complies with a package baseline.</p><p>That decision depends on a separate context:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;json&quot;,&quot;nodeId&quot;:&quot;49dca525-3f0e-4b4e-8847-67951467253e&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-json">{
  "required_packages": [
    {"name": "openssl", "version": "3.0.13"},
    {"name": "python3", "version": "3.12.3"},
    {"name": "curl", "version": "8.5.0"}
  ],
  "unexpected_package_mode": "ignore"
}</code></pre></div><p>If the required OpenSSL version changes, the same inventory may fail. If unexpected packages are changed from <code>ignore</code> to <code>fail</code>, an additional package may alter the result even though nothing on the host has changed.</p><p>The observation and the assessment therefore belong to different layers.</p><p>Package names and versions come from collection. Missing packages, mismatched versions and unexpected packages are derived by comparison. Pass or fail is produced only after policy evaluation.</p><p>Writing the control result back into the evidence object hides those transitions. The final document becomes easier to read, but harder to inspect. A reviewer can see the conclusion but cannot tell which facts came from the host, which were derived by the replay engine and which depended on policy choices.</p><h2>Invalid, stale and failed are different states</h2><p>A control should fail only after admissible evidence reaches the policy and the required condition is not met.</p><p>If the evidence does not satisfy its schema, the policy should not evaluate it. A missing timestamp, malformed package entry or incorrect field type is a problem with the evidence path, not proof that the host failed the control.</p><p>The assessment should record that distinction:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;926b3f60-6af9-4d0c-b307-0f36470e1275&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">evidence_status = invalid_evidence
control_status = unknown
decision_executed = false</code></pre></div><p><a href="https://www.codeyourcompliance.com/p/why-audit-evidence-goes-stale">Evidence can remain intact and still become too stale to support a current conclusion</a>. In this control, stale evidence creates a different problem from either invalid evidence or policy failure. A package inventory may be structurally valid and still be too old for the decision being attempted.</p><p>Suppose the context requires evidence collected within the previous 24 hours. An inventory from three days ago cannot support a current package-baseline decision. It does not prove that the host is non-compliant. It proves that the available observation is no longer fresh enough to answer the question.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;ced5faef-c7a9-4ec5-b702-1210d697b918&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">evidence_status = stale_evidence
control_status = unknown
decision_executed = false</code></pre></div><p>These distinctions are not cosmetic. They imply different actions.</p><p>A failed control may require investigation of the host or baseline. Stale evidence requires recollection. Invalid evidence requires examination of the collector, schema or processing pipeline.</p><p>A dashboard that reduces all three conditions to red has removed information that operations and audit both need.</p><h2>Collection and policy execution are separate boundaries</h2><p>The earlier implementation note moved <a href="https://www.codeyourcompliance.com/p/from-evidence-principles-to-an-executable">from evidence principles to an executable control</a>. The public reference artifacts now apply that structure through a fixed replay sequence:</p><p><code>evidence schema gate</code></p><p><code>-&gt; context schema gate</code></p><p><code>-&gt; integrity gate</code></p><p><code>-&gt; freshness gate</code></p><p><code>-&gt; derived facts</code></p><p><code>-&gt; policy evaluation</code></p><p><code>-&gt; assessment output</code></p><p>For the package-baseline example, the comparison stage derives three groups of facts:</p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">missing_packages</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">version_mismatches</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">unexpected_packages</mark></p></li></ul><p>The policy then decides how those facts affect the control result.</p><p>A missing required package causes failure. A version mismatch causes failure. An unexpected package may be ignored or treated as a violation depending on the explicit context.</p><p>The collector does not need to know any of this. Its job is to report the inventory accurately and preserve its collection metadata. Policy belongs later in the pipeline, where its input and execution can be inspected independently.</p><p>The same boundary applies to the decision engine.</p><p>A built-in evaluator can implement the same decision semantics as a Rego policy, but it does not execute the Rego artifact. That difference must appear in the assessment:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;yaml&quot;,&quot;nodeId&quot;:&quot;d5e56514-7989-495c-9bdf-0c78128da736&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-yaml">builtin:
decision_executed = true
policy_artifact.executed = false

opa:
decision_executed = true
policy_artifact.executed = true</code></pre></div><p>Without this metadata, a result may appear to have been produced by a policy artifact that was never run. The conclusion could be correct while its provenance is false.</p><h2>Replay should stop before remediation</h2><p>The package-baseline control can identify a missing package, an incorrect version or an unexpected installation. It does not install, remove or upgrade software.</p><p>That is a deliberate boundary.</p><p>Remediation requires broader permissions and produces a different class of evidence: authorization records, execution logs, change results and post-remediation observations. Combining those actions with collection makes it harder to establish what state existed before the tool intervened.</p><p>A read-only collector preserves the condition it was asked to observe. A separate remediation workflow may act on the assessment later, but it should produce its own evidence package.</p><p>Collection establishes what was seen. Correction changes what will be seen next.</p><h2>Public reference artifacts</h2><p>The replay structure described here is implemented in the public <a href="https://github.com/codeyourcompliance/evidence-validation-pipeline.git">codeyourcompliance/evidence-validation-pipeline</a> repository.</p><p>The current examples are:</p><ul><li><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/tree/main/examples/replayable-tls-control">examples/replayable-tls-control</a></p></li><li><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/tree/main/examples/os-package-baseline">examples/os-package-baseline</a></p></li></ul><p>The <a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/tree/main/examples/replayable-tls-control">TLS example</a> applies the pipeline to certificate expiry. The <a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/tree/main/examples/os-package-baseline">OS package example</a> applies it to required packages, version mismatches and unexpected software.</p><p>Both packages retain the evidence, validation schemas, evaluation context, integrity information, policy artifact and execution metadata needed to inspect how an assessment result was produced. Their tests also show how the pipeline behaves when evidence is stale, malformed or modified after hashing.</p><p>These examples do not prove that the underlying systems are compliant. They show that a control decision can be preserved in a form that is more inspectable than a stored <code>PASS</code> or <code>FAIL</code>.</p><p>They also stop before remediation. Installation, removal, upgrade and other corrective actions belong to a separate workflow with separate permissions and evidence.</p><p>Replayability does not establish that a decision was correct. It establishes whether the basis of that decision can still be examined.</p><h2>Origin and scope</h2><p><strong>Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</strong><br>Website: <a href="https://www.codeyourcompliance.com/">https://www.codeyourcompliance.com/</a><br>GitHub: <a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p>Attribution is requested for forks, references, adaptations and technical discussions.</p><p>MAS TRM-inspired means engineering interpretation. This project does not provide legal, regulatory, audit, certification or compliance advice.</p><h2>Related reading</h2><ul><li><p><a href="https://www.codeyourcompliance.com/p/from-evidence-principles-to-an-executable">From Evidence Principles to an Executable Control</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/why-audit-evidence-goes-stale">Why Audit Evidence Goes Stale</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[From Evidence Principles to an Executable Control]]></title><description><![CDATA[Discover how CodeYourCompliance transforms evidence principles into replayable compliance implementations using read-only collection, evidence objects, policy evaluation, and OSCAL representation.]]></description><link>https://www.codeyourcompliance.com/p/from-evidence-principles-to-an-executable</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/from-evidence-principles-to-an-executable</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Mon, 20 Jul 2026 14:39:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!99WK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Over the past few months, <strong><a href="https://www.codeyourcompliance.com/">Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</a></strong> has focused on a set of recurring principles.</p><ul><li><p><a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">Documents are not system state.</a>  </p></li><li><p><a href="https://www.codeyourcompliance.com/p/a-screenshot-is-a-supporting-artifact">Screenshots are supporting artifacts, not proof objects. </a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Evidence should be timestamped, source-bound, integrity-checked, and replayable.</a> </p></li><li><p><a href="https://www.codeyourcompliance.com/p/why-audit-evidence-goes-stale">Audit evidence must remain current enough to support a conclusion.</a> </p></li><li><p><a href="https://www.codeyourcompliance.com/p/a-generated-report-is-not-an-accountable">Automatically generated reports are not accountable audit conclusions.</a> </p></li></ul><p>These ideas have shaped almost every article I&#8217;ve written.</p><p>But they also raised an uncomfortable question.</p><p><strong>If these principles only exist in articles, can they really be tested, challenged, or reproduced?</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!99WK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!99WK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!99WK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!99WK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!99WK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!99WK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1165087,&quot;alt&quot;:&quot;Flow diagram showing the CodeYourCompliance implementation pipeline: Evidence Principle &#8594; Read-only Collection &#8594; Evidence Object (timestamp, source, and hash) &#8594; Policy Evaluation &#8594; Assessment Result &#8594; OSCAL Representation. The diagram illustrates how evidence principles are transformed into replayable engineering implementations.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.codeyourcompliance.com/i/207777414?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Flow diagram showing the CodeYourCompliance implementation pipeline: Evidence Principle &#8594; Read-only Collection &#8594; Evidence Object (timestamp, source, and hash) &#8594; Policy Evaluation &#8594; Assessment Result &#8594; OSCAL Representation. The diagram illustrates how evidence principles are transformed into replayable engineering implementations." title="Flow diagram showing the CodeYourCompliance implementation pipeline: Evidence Principle &#8594; Read-only Collection &#8594; Evidence Object (timestamp, source, and hash) &#8594; Policy Evaluation &#8594; Assessment Result &#8594; OSCAL Representation. The diagram illustrates how evidence principles are transformed into replayable engineering implementations." srcset="https://substackcdn.com/image/fetch/$s_!99WK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!99WK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!99WK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!99WK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d63f4a8-80ae-4629-8efd-1f359761de24_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Transitioning an evidence principle into a replayable implementation pipeline, from read-only collection to OSCAL representation.</figcaption></figure></div><p>That question has led to the next stage of the project.</p><p>Instead of treating articles as the primary deliverable, I will begin treating each implementation as the primary object. Articles become explanations of that implementation rather than the implementation itself.</p><p>The goal is to turn individual evidence principles into small, replayable engineering experiments that anyone can inspect, critique, and improve.</p><p>The first reference experiment is intentionally narrow.</p><pre><code><strong>TLS endpoint</strong>
&#8595;
<strong>read-only collection</strong>
&#8595;
<strong>raw evidence</strong>
&#8595;
<strong>parsed facts</strong>
&#8595;
<strong>policy evaluation</strong>
&#8595;
<strong>assessment result</strong>
&#8595;
<strong>OSCAL representation</strong></code></pre><p>The objective is not to build a complete compliance platform.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The objective is to answer one implementation question:</mark></p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can a narrow, replayable implementation preserve the distinction between collection, evidence, policy evaluation, and accountable assessment?</mark></p></blockquote><p>Several boundaries are equally important.</p><div class="callout-block" data-callout="true"><p><strong><a href="https://www.csa.gov.sg/resources/internet-hygiene-portal/information-resources/tls/">TLS</a></strong> is only the experimental carrier.</p><p><strong><a href="https://info.standards.tech.gov.sg/">Singapore ICT&amp;SS</a></strong> NS-6 provides the direct technical control context.</p><p><strong><a href="https://www.mas.gov.sg/regulation/guidelines/technology-risk-management-guidelines">MAS TRM</a></strong> provides a broader engineering and security context rather than a compliance claim.</p><p><strong><a href="https://pages.nist.gov/OSCAL/">OSCAL</a></strong> is used as an assessment representation, not as evidence itself or as proof of compliance.</p></div><p><span data-color="#ff0000" style="color: rgb(255, 0, 0);">This experiment does </span><strong><span data-color="#ff0000" style="color: rgb(255, 0, 0);">not</span></strong><span data-color="#ff0000" style="color: rgb(255, 0, 0);"> claim that a successful assessment proves overall compliance, nor does it attempt to automate professional judgment.</span></p><p>The purpose is much smaller&#8212;and, I believe, much more useful.</p><p>If a single evidence principle can be implemented, replayed, inspected, and shown to fail under controlled conditions, it becomes more than an idea. It becomes something other people can verify, criticize, and build upon.</p><p>That is the direction <a href="https://www.codeyourcompliance.com/">Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</a> is taking next.</p><p>Not more articles.</p><p>More executable knowledge.</p><div><hr></div><h2>Origin</h2><p><strong>Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</strong><br><span>Website: </span><a href="https://www.codeyourcompliance.com/"><span>https://www.codeyourcompliance.com/</span></a><br><span>GitHub: </span><a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p><em>Attribution is requested for forks, references, adaptations, and discussions.</em></p><h2>Scope Boundary</h2><p>MAS TRM-inspired means engineering interpretation.</p><p>This project does not provide legal, regulatory, audit, certification, or compliance advice.</p><h2>Project Direction </h2><p>Future articles will increasingly accompany replayable implementation packages rather than stand alone as methodology notes.</p><h2>Related Reading</h2><ul><li><p><a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Compliance Automation Starts at Evidence</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/a-screenshot-is-a-supporting-artifact">A Screenshot Is a Supporting Artifact, Not a Proof Object</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/a-generated-report-is-not-an-accountable">A Generated Report Is Not an Accountable Audit Conclusion</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Prompt Retention Is a Control, Not a Preference]]></title><description><![CDATA[AI vendor prompt-retention claims are not evidence-complete without data-type coverage, storage layers, deletion timing, exceptions, admin controls, and contract scope.]]></description><link>https://www.codeyourcompliance.com/p/prompt-retention-is-a-control-not</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/prompt-retention-is-a-control-not</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Thu, 16 Jul 2026 15:51:11 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/3d76d632-7500-4297-bbb7-124cddef0128_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>AI Vendor Evidence Gap Notes #5</em></p><p>AI vendors often describe retention as a setting:</p><p>&#8220;Zero data retention is available.&#8221;</p><p>&#8220;Enterprise customers can configure retention.&#8221;</p><p>&#8220;Prompts are deleted after 30 days.&#8221;</p><p>These statements sound operational. They suggest that the buyer controls the data lifecycle.</p><p>But a retention setting is not automatically a retention control.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The real review question is not:</mark></p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What retention period does the vendor advertise?</mark></p></blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It is:</mark></p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What data lifecycle does the available evidence establish for this product, plan, feature, region, and use case?</mark></p></blockquote><h2>Claim</h2><p>A vendor says:</p><blockquote><p>Enterprise customers can configure prompt retention.</p></blockquote><p>That may prove that a retention feature exists for a defined category of content.</p><p>It does not prove the full lifecycle.</p><h2>Why it sounds sufficient</h2><p>Retention is often reduced to one number: zero days, thirty days, customer-configurable, or deleted on request.</p><p>That makes the answer easy to place in a questionnaire and mark complete.</p><p>The problem is that an AI workflow rarely creates only one data object.</p><p>One interaction may produce:</p><ul><li><p>prompts and outputs;</p></li><li><p>uploaded files;</p></li><li><p>extracted text or embeddings;</p></li><li><p>metadata and logs;</p></li><li><p>moderation or abuse-review events;</p></li><li><p>support artifacts;</p></li><li><p>cached copies;</p></li><li><p>backup copies.</p></li></ul><p>The vendor may use &#8220;retention&#8221; to describe visible conversation history.</p><p>The buyer may assume the same statement applies to the entire workflow.</p><p>That assumption is the evidence gap.</p><h2>What the statement may prove</h2><p>If the source is reliable and product-specific, the statement may support a few limited conclusions:</p><ul><li><p>a retention feature exists;</p></li><li><p>administrators may be able to shorten or disable visible history;</p></li><li><p>an enterprise plan may offer additional controls;</p></li><li><p>the vendor has defined a customer-facing retention option.</p></li></ul><p>Those are useful signals.</p><p>They are not evidence that every relevant data object follows the same lifecycle.</p><p>The source matters too.</p><p>A product setting, FAQ, trust center, support email, contract, and customer-specific commitment do not carry the same weight or scope.</p><h2>What it does not prove</h2><p>A configurable retention statement does not automatically prove:</p><blockquote><p><strong>Data-type coverage.</strong><br>Does the setting cover only prompts and outputs, or also files, embeddings, metadata, logs, support copies, and backups?</p><p><strong>Storage-layer coverage.</strong><br>Deletion from the main application does not prove deletion from caches, indexes, vector stores, support tools, observability systems, or backup environments.</p><p><strong>Deletion timing.</strong><br>&#8220;Deleted&#8221; may mean immediately removed, queued for deletion, removed from active systems within a stated period, or retained in backups until rotation.</p><p><strong>Exception paths.</strong><br>Data may be retained longer for security investigation, legal obligations, customer support, abuse review, fraud prevention, or service improvement.</p><p>An exception may be legitimate.</p><p>An undisclosed exception means the advertised period is not the full boundary.</p><p><strong>Administrative enforcement.</strong><br>A setting is weak if changes are not logged, new features bypass it, or different workspaces inherit different defaults.</p><p><strong>Product and plan scope.</strong><br>Retention may differ across API and hosted products, enterprise and consumer plans, regions, integrations, beta features, or model routes.</p></blockquote><p>A company-wide statement does not prove that the intended workflow is covered.</p><h2>Weak-answer pattern</h2><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor describes a retention preference without evidencing the full retention control boundary.</mark></p><p>The response provides a duration or setting, but not the covered data types, storage layers, exceptions, deletion timing, administrative roles, audit evidence, or contractual scope.</p><p>This does not prove improper retention.</p><p>It means the buyer cannot yet determine which lifecycle is being accepted.</p><h2>Evidence request</h2><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A stronger request is not:</mark></p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What is your retention period?</mark></p></blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It is:</mark></p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Provide a product- and plan-specific retention matrix for prompts, outputs, uploaded files, embeddings, metadata, logs, moderation events, support artifacts, caches, and backups.</mark></p></blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">For each data type, identify:</mark></p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">default and configurable retention;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">storage layer;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">deletion timing;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">backup handling;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">exception paths;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">support or human access;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">administrator roles;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">audit-log coverage;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">contractual source.</mark></p></li></ul><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The buyer should also ask:</mark></p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Does a setting change apply to existing data or only new data?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can the vendor override the configured period?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Are changes to retention behaviour communicated to customers?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Do new AI features inherit the same setting?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What evidence can the customer retain to show the configured state?</mark></p></li></ul><p>The vendor does not need to expose sensitive architecture.</p><p>It does need to establish an operationally usable boundary.</p><h2>Review note</h2><p>A review note could state:</p><blockquote><p>The available statement identifies a configurable retention setting but does not establish the complete data lifecycle for the intended workflow. Coverage of files, metadata, logs, embeddings, support artifacts, caches, backups, and exception paths remains unclear. The response is not evidence-complete for data requiring verified deletion or short-lived processing.</p></blockquote><h2>Usage boundary</h2><p>The correct boundary depends on the use case.</p><p>A thirty-day period may be acceptable for public marketing material and unacceptable for confidential meeting content.</p><p>Zero retention may reduce exposure in one workflow but reduce auditability or incident investigation in another.</p><p>The shortest period is not automatically the strongest control.</p><p>The control is whether the lifecycle is explicit, scoped, enforceable, observable, and supported by evidence.</p><p>Until that boundary is established:</p><blockquote><p>Limit use to low-sensitivity data that does not require verified deletion, strict short-lived processing, or customer-specific retention commitments. Do not expand to confidential, regulated, or customer data until retention and deletion are evidenced by data type, storage layer, exception path, and contract scope.</p></blockquote><p>That is not approval.</p><p>That is review preparation.</p><p>A retention setting may be useful.</p><p>But usefulness is not the same as evidence.</p><p>The review unit is not the vendor name.</p><p>The review unit is:</p><p><strong>vendor + product + plan + use case + data type + region + contract terms + evidence date.</strong></p><p>Prompt retention can support that review.</p><p>It cannot remain a single number inside it.</p><p>A retention setting can be part of the evidence.</p><p>It is not the whole control.</p><h2>Boundary</h2><p>This material is for evidence structuring and review preparation. It does not provide legal, regulatory, audit, procurement, certification, or implementation advice.</p><p>The goal is not to approve or reject a vendor.</p><p>The goal is to make the evidence gap visible before real data use.</p><p>I have a sanitized sample evidence gap memo showing how retention, routing, support access, and contract gaps can be recorded in a review file.</p><p>Reply if you want the sample.</p><p></p><p>#AIVendorAssessment #AIGovernance #ThirdPartyRisk #Privacy #VendorRisk</p>]]></content:encoded></item><item><title><![CDATA[An Integration Is Not an Evidence Contract]]></title><description><![CDATA[An integration can move compliance data, but only an evidence contract preserves source, scope, integrity, provenance, and policy meaning.]]></description><link>https://www.codeyourcompliance.com/p/an-integration-is-not-an-evidence</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/an-integration-is-not-an-evidence</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Mon, 13 Jul 2026 09:22:28 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c3804c65-c231-442b-b101-b86e27cda429_1731x909.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A compliance platform connects to a source system.</p><p>Authentication succeeds.</p><p>Configuration data appears in the dashboard.</p><p>The control status turns green.</p><p>Then the reviewer asks:</p><blockquote><p>Which source produced this value?</p><p>Which collector version retrieved it?</p><p>When was it observed?</p><p>Was the full target scope reached?</p><p>Was the data changed during normalization?</p><p>Which policy evaluated it?</p></blockquote><p>The integration moved the data.</p><p>It did not preserve the answers.</p><p>That is the boundary.</p><div class="callout-block" data-callout="true"><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Integration = transport. </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Evidence contract = audit meaning.</mark></p></div><h2>What an Integration Proves</h2><p>A working integration may prove that:</p><ul><li><p>credentials were accepted</p></li><li><p>an endpoint was reachable</p></li><li><p>a payload was returned</p></li><li><p>field mapping completed</p></li><li><p>data reached the destination</p></li></ul><p>That is useful operational evidence.</p><p>It does not automatically prove that the transported data is valid audit evidence.</p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The integration may still omit:</mark></p><ul><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">source context</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">expected collection scope</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">failed targets</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">collector identity and version</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">collection timestamp</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">transformation history</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">integrity status</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">evidence freshness</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">applicable policy version</mark></p></li></ul><p>Compliance evidence automation is not data movement.</p><p>It means collecting evidence from source systems, preserving provenance, validating integrity, evaluating policy, and producing a reviewable evidence package.</p><h2>Missing Data Must Survive the Integration</h2><p>Suppose a collector is expected to inspect 100 systems.</p><p>It reaches 94.</p><p>The integration writes 94 successful records into the compliance platform.</p><p>The dashboard reports that all received records passed.</p><p>Technically, the integration worked.</p><p><mark data-color="#d0e0e3" style="background-color: rgb(208, 224, 227); color: rgb(0, 0, 0);">The evidence package is incomplete.</mark></p><p><mark data-color="#d0e0e3" style="background-color: rgb(208, 224, 227); color: rgb(0, 0, 0);">The correct state is:</mark></p><p><mark data-color="#d0e0e3" style="background-color: rgb(208, 224, 227); color: rgb(0, 0, 0);">expected targets: 100</mark></p><p><mark data-color="#d0e0e3" style="background-color: rgb(208, 224, 227); color: rgb(0, 0, 0);">observed targets: 94</mark></p><p><mark data-color="#d0e0e3" style="background-color: rgb(208, 224, 227); color: rgb(0, 0, 0);">failed collection: 6</mark></p><p><mark data-color="#d0e0e3" style="background-color: rgb(208, 224, 227); color: rgb(0, 0, 0);">It is not:</mark></p><p><mark data-color="#d0e0e3" style="background-color: rgb(208, 224, 227); color: rgb(0, 0, 0);">evaluated environment: compliant</mark></p><p>The six missing systems did not fail the control.</p><p>They did not pass it either.</p><p>They were not observed.</p><div class="callout-block" data-callout="true"><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">missing evidence != control failure</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">missing evidence != control pass</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">missing evidence = unresolved evidence state</mark></p></div><p>If that distinction disappears during transport, the evidence has already lost part of its value.</p><h2>What an Evidence Contract Preserves</h2><p>An evidence contract defines the minimum structure that must survive collection, transport, normalization, evaluation, and reporting.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;json&quot;,&quot;nodeId&quot;:&quot;9ff1f37e-16d6-4e7b-8e93-0ba40e98b2e0&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-json">evidence_contract:
  source_system:
  collector:
  collector_version:
  collection_method:
  timestamp_utc:
  evidence_type:
  evidence_layer:
  integrity_hash:
  validation_status:
  policy_input_ref:</code></pre></div><p>Each field answers a different audit question.</p><blockquote><p><code>source_system</code> identifies where the evidence originated.</p><p><code>collector</code> and <code>collector_version</code> identify what process observed the source.</p><p><code>collection_method</code> distinguishes read-only observation from collection that may have changed the assessed system.</p><p><code>timestamp_utc</code> records when the state was observed.</p><p><code>evidence_type</code> defines what kind of object was collected.</p><p><code>evidence_layer</code> separates raw evidence, normalized facts, derived facts, policy results, and audit narratives.</p><p><code>integrity_hash</code> supports detection of post-collection mutation.</p><p><code>validation_status</code> preserves whether the evidence is valid, stale, missing, tampered, unknown, or not machine-verifiable.</p><p><code>policy_input_ref</code> links the evidence to the rule evaluation that consumed it.</p></blockquote><p>Without these fields, the destination may contain data.</p><p>It does not yet contain a replayable evidence object.</p><h2>One Green Status Is Not Enough</h2><p>A common implementation error is using one status field for the entire pipeline:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;json&quot;,&quot;nodeId&quot;:&quot;98ee5efc-2b18-4231-85c9-c78702f37748&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-json">{
  "status": "success"
}</code></pre></div><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What succeeded?</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The API request?</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The collection?</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The schema validation?</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The integrity check?</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The policy evaluation?</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The control?</mark></p><p>These outcomes should remain separate.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;javascript&quot;,&quot;nodeId&quot;:&quot;b953c43c-8600-4dde-af92-3ede98ba77ed&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-javascript">transport_status: success
collection_status: partial
schema_status: valid
integrity_status: verified
freshness_status: stale
policy_status: not_evaluated
control_status: unknown</code></pre></div><p>A single green status is easy to display.</p><p>It is difficult to audit.</p><h2>Normalization Changes Meaning</h2><p>Integrations often rename fields, convert timestamps, flatten objects, infer Boolean values, and discard unsupported data.</p><p>These transformations may be necessary.</p><p>They are not neutral.</p><p>Suppose the source returns:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;json&quot;,&quot;nodeId&quot;:&quot;e21ec0f3-9ff0-46cb-9f17-5765e35ef290&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-json">{
  "certificate_not_after": "2026-08-01T00:00:00Z"
}</code></pre></div><p>The integration writes:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;json&quot;,&quot;nodeId&quot;:&quot;fe076494-9f14-4fab-b025-298fbb1bfa35&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-json">{
  "certificate_valid": true
}</code></pre></div><p>The second value is not raw evidence.</p><p>It is a derived fact.</p><p>The system should preserve the source value, transformation rule, evaluation time, and derived result.</p><p>Otherwise the integration replaces evidence with an unexplained conclusion.</p><h2>OPA Cannot Repair Weak Evidence</h2><p>OPA can evaluate a defined input against a defined policy.</p><p>It cannot determine whether the input was collected from the correct source, whether the target scope was complete, or whether the evidence was modified before evaluation.</p><p>A reproducible rule result can still be based on weak evidence.</p><p>The policy engine is not the point.</p><p>The audit problem starts earlier.</p><p>The evidence contract defines what the evaluator is allowed to treat as policy input.</p><h2>Different Failures Need Different Outcomes</h2><p>The pipeline should distinguish</p><div class="callout-block" data-callout="true"><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">transport failure</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">collection failure</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">invalid evidence</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">policy evaluation failure</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">control failure</mark></p></div><p>An API timeout is not automatically non-compliance.</p><p>The defensible chain is:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">API timeout</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">-&gt; collection incomplete</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">-&gt; evidence missing</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">-&gt; control not evaluated</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">-&gt; review or escalation required</mark></p></div><p>Control failure should be recorded only when valid evidence was evaluated and the required condition was not met.</p><p>Failure states must survive the integration.</p><h2>Technical companion</h2><p>An evidence contract boundary note and two synthetic integration examples are available in the CodeYourCompliance <code>evidence-validation-pipeline</code> repository.</p><p>Evidence contract boundary:</p><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/docs/evidence_contract.md">https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/docs/evidence_contract.md</a></p><p>Integration without an evidence contract:</p><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/integration_without_evidence_contract.json">https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/integration_without_evidence_contract.json</a></p><p>Integration with an evidence contract:</p><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/integration_with_evidence_contract.json">https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/integration_with_evidence_contract.json</a></p><p>These examples do not implement a complete integration governance or evidence integrity model.</p><p>They show one boundary:</p><blockquote><p>Successful transport does not establish evidence validity.</p></blockquote><h2>Boundary</h2><p>This material is for evidence structuring, integration design review, and technical review preparation.</p><p>It does not provide legal, regulatory, audit, certification, compliance, procurement, or implementation advice.</p><p>The goal is not to prove MAS TRM compliance.</p><p>The goal is to make the transport-versus-evidence boundary visible before synchronized data becomes accepted audit evidence.</p><h2>Origin</h2><p><strong>Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</strong></p><p>Website: <a href="https://www.codeyourcompliance.com/">https://www.codeyourcompliance.com/</a></p><p>GitHub: <a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p>Attribution is requested for forks, references, adaptations, and discussions.</p><h2>Related reading</h2><p><a href="https://www.codeyourcompliance.com/p/why-audit-evidence-goes-stale">Why Audit Evidence Goes Stale</a></p><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p><p><a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a></p><p><a href="https://www.codeyourcompliance.com/p/a-screenshot-is-a-supporting-artifact">A Screenshot Is a Supporting Artifact, Not a Proof Object</a></p><p><a href="https://www.codeyourcompliance.com/p/a-generated-report-is-not-an-accountable">A Generated Report Is Not an Accountable Audit Conclusion</a></p>]]></content:encoded></item><item><title><![CDATA[Subprocessor Lists Do Not Show the Actual AI Data Path]]></title><description><![CDATA[A subprocessor list shows who may process data. It does not show which subprocessors touch which data, feature, region, workflow, or support path.]]></description><link>https://www.codeyourcompliance.com/p/subprocessor-lists-do-not-show-the</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/subprocessor-lists-do-not-show-the</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Fri, 10 Jul 2026 04:30:52 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9395179b-5ff5-41af-84ad-7a834ff2d168_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A subprocessor list is useful evidence.</p><p>It is not the actual AI data path.</p><p>An AI vendor may publish a list of third-party service providers.</p><p>That list may show which subprocessors the vendor is permitted to use.</p><p>But for a buyer, the review question is narrower:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Which subprocessor touches which data, for which product feature, in which region, under which contract boundary, for which use case, and for how long?</mark></p><p>If that is not answered, the subprocessor list remains source material.</p><p>It is not evidence-complete for AI vendor review.</p><h2>Claim</h2><p>The vendor says:</p><p>&#8220;We maintain a subprocessor list.&#8221;</p><p>Or:</p><p>&#8220;Our current subprocessors are listed here.&#8221;</p><p>Or:</p><p>&#8220;We only share customer data with approved subprocessors.&#8221;</p><p>Or:</p><p>&#8220;Customers will be notified of subprocessor changes.&#8221;</p><p>That statement may be useful.</p><p>It may support a baseline third-party disclosure process.</p><p>But it does not automatically show how data moves through the actual AI workflow.</p><h2>Why it sounds sufficient</h2><p>A subprocessor list feels concrete.</p><p>It usually includes company names, service descriptions, locations, and sometimes update dates or notification terms.</p><p>For a standard SaaS review, this may support a basic third-party processing check.</p><p>The buyer can see that cloud infrastructure, analytics, support, security tooling, email delivery, logging, or AI infrastructure providers may be involved.</p><p>That matters.</p><p>But AI vendor review usually needs more than a list.</p><p>The buyer may be sending prompts, files, meeting audio, transcripts, source code, customer records, support tickets, embeddings, logs, metadata, or generated outputs into a specific product workflow.</p><p>A static subprocessor list may not show which of those data types each third party touches.</p><p>It may not show whether a model provider processes prompts and outputs.</p><p>It may not show whether transcription, embedding, retrieval, safety filtering, support access, logging, analytics, or abuse monitoring follow different paths.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The list names possible processors.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not explain the operating path.</mark></p><h2>What it actually proves</h2><p>A subprocessor list may prove that the vendor discloses third parties involved in service delivery.</p><p>It may support claims such as:</p><p>The vendor maintains a public or customer-accessible subprocessor list.</p><p>The vendor has a process for updating subprocessors.</p><p>The vendor identifies certain service providers by name.</p><p>The vendor describes general processing functions.</p><p>The vendor may provide notice of new subprocessors.</p><p>Those are useful evidence points.</p><p>But they are not enough by themselves.</p><p>A subprocessor list can help identify who may be involved.</p><p>It does not automatically prove who is involved in the buyer&#8217;s actual AI workflow.</p><h2>What it does not prove</h2><p>A subprocessor list does not automatically prove which subprocessors process customer content.</p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It may not distinguish prompts, outputs, uploaded files, audio, transcripts, summaries, embeddings, metadata, logs, analytics events, support records, abuse events, or security telemetry.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove which subprocessors are used for a specific product, plan, feature, region, or configuration.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove whether a model provider receives raw prompts, transformed prompts, retrieved context, files, transcripts, embeddings, outputs, or metadata.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove whether support tools receive copies of customer content.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove whether logs, monitoring, analytics, abuse review, or safety systems involve separate processors.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove retention or deletion across subprocessor systems.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove whether the customer can object to, restrict, approve, or configure subprocessor use.</mark></p><p>This is where the review file becomes weak.</p><p>The buyer records:</p><p>&#8220;Subprocessor list reviewed.&#8221;</p><p>But the file does not show the actual AI data path.</p><h2>Weak-answer pattern</h2><p>This is the list-without-routing pattern.</p><p>The vendor provides a subprocessor list.</p><p>The buyer treats the list as proof that the data path is understood.</p><p>But the list may only say:</p><p>Provider A: cloud hosting.</p><p>Provider B: analytics.</p><p>Provider C: support tooling.</p><p>Provider D: AI infrastructure.</p><p>Provider E: model services.</p><p>That does not answer the workflow question.</p><blockquote><p>Which provider processes prompts?</p><p>Which provider stores embeddings?</p><p>Which provider receives logs?</p><p>Which provider handles transcription?</p><p>Which provider performs summarization?</p><p>Which provider can access support tickets?</p><p>Which provider is used in the buyer&#8217;s region?</p><p>Which provider applies only to a different feature or plan?</p></blockquote><p>Without that mapping, the subprocessor list is incomplete evidence.</p><p>It is a directory.</p><p>It is not the data path.</p><h2>Evidence request</h2><p>Do not ask only:</p><p>&#8220;Can you provide your subprocessor list?&#8221;</p><p>Ask for feature-level routing.</p><p>A stronger request is:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;Please map the subprocessors and model providers involved in the specific product, plan, region, and AI workflow under review, including which data types each provider receives, processes, stores, logs, or can access.&#8221;</mark></p><p>Then ask:</p><blockquote><p>Which subprocessors process customer content?</p><p>Which subprocessors process prompts, outputs, uploaded files, transcripts, summaries, source code, embeddings, metadata, logs, or support records?</p><p>Which subprocessors support model inference, embedding, retrieval, transcription, summarization, safety filtering, abuse monitoring, logging, analytics, or customer support?</p><p>Which providers are infrastructure-only, and which touch customer data?</p><p>Does routing differ by product, plan, feature, configuration, or region?</p><p>Are model providers included in the subprocessor list?</p><p>Are support tools included if customer content can be copied into support workflows?</p><p>What retention or deletion commitments apply at each subprocessor?</p><p>Can customers object to or restrict specific subprocessors?</p><p>Which contract terms confirm the boundary?</p></blockquote><p>That is how a subprocessor list becomes reviewable.</p><h2>Review note</h2><p>A weak review note says:</p><p>&#8220;Subprocessor list available.&#8221;</p><p>A stronger review note says:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;The vendor provides a subprocessor list, but the list does not by itself establish the actual AI data path for the intended workflow. The buyer should confirm which subprocessors and model providers process each relevant data type, which product features use them, whether routing differs by plan, region, or configuration, whether support and monitoring systems receive customer content, and which contract terms confirm the processing boundary.&#8221;</mark></p><p>That note does not say the vendor is unsafe.</p><p>It says the subprocessor evidence is not yet mapped to the workflow.</p><h2>Usage boundary</h2><p>Until subprocessor routing is mapped, usage should stay bounded.</p><p>A sample usage boundary:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;Use may remain limited to low-sensitivity internal data while subprocessor and model-provider routing is mapped for the specific product, plan, feature, region, data type, support workflow, logging path, retention layer, deletion process, and contract boundary. Do not use with customer confidential data, regulated data, source code, employee records, privileged business records, or externally relied-upon outputs until the actual AI data path is evidenced.&#8221;</mark></p><p>That is not approval.</p><p>That is review preparation.</p><p>A subprocessor list can support the review.</p><p>It cannot replace the review.</p><p>The review unit is not the vendor name.</p><p>The review unit is:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">vendor + product + plan + use case + data type + region + contract terms + evidence date.</mark></p><p>A subprocessor list is useful.</p><p>But the buyer still needs the actual AI data path.</p><h2>Boundary</h2><p>This material is for evidence structuring and review preparation. It does not provide legal, regulatory, audit, procurement, certification, or implementation advice.</p><p>The goal is not to approve or reject a vendor.</p><p>The goal is to make the evidence gap visible before real data use.</p><p>I now have a sanitized sample evidence gap memo showing how this looks in a review file.</p><p>Reply if you want the sample.</p>]]></content:encoded></item><item><title><![CDATA[Why Audit Evidence Goes Stale]]></title><description><![CDATA[Audit evidence can pass integrity checks and still be too stale to support a current compliance conclusion.]]></description><link>https://www.codeyourcompliance.com/p/why-audit-evidence-goes-stale</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/why-audit-evidence-goes-stale</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Tue, 07 Jul 2026 05:32:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tqwP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>An access review export was collected two weeks before the audit pack was finalized.</p><p>The export is real.</p><p>The timestamp is real.</p><p>The file hash still verifies.</p><p>But the system changed after collection.</p><p>The evidence is intact.</p><p>The conclusion is not.</p><p>That is the freshness problem.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A verified hash does not make stale evidence current.</mark></p><h2>Evidence can be true and stale at the same time</h2><p>Compliance teams often treat evidence as a static artifact.</p><p>A screenshot was captured.</p><p>A report was exported.</p><p>A log bundle was saved.</p><p>A file hash was recorded.</p><p>That may prove something useful.</p><p>It does not prove the evidence still supports the conclusion being made today.</p><p>Integrity asks whether the evidence changed after collection.</p><p>Freshness asks whether the evidence is still recent enough to support the current claim.</p><p>Those are different questions.</p><p>A stale evidence object can still pass integrity verification.</p><p>That is the trap.</p><h2>Freshness is an evidence property</h2><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Compliance evidence freshness is the condition that an evidence object remains recent enough, within its expected validity window, to support the compliance conclusion being drawn from it.</mark></p><p>Freshness is not decoration.</p><p>It is not a report date.</p><p>It is not the date the auditor opened the folder.</p><p>It belongs inside the evidence object.</p><p>A minimum freshness record should preserve:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;jsx&quot;,&quot;nodeId&quot;:&quot;fb4ce151-35aa-46bc-8f5a-07df9cee24f8&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-jsx">evidence_freshness:
  collected_at:
  valid_until:
  freshness_window_seconds:
  freshness_status: fresh | stale | expired | unknown</code></pre></div><p>The collection timestamp tells us when the evidence was observed.</p><p>The validity window tells us how long that evidence can reasonably support the claim.</p><p>The freshness status tells us whether downstream evaluation should proceed.</p><p>Without this, the report can quietly reuse old evidence as if it were still current.</p><h2>Integrity is not freshness</h2><p>A hash can prove that an evidence object has not changed.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It cannot prove that the system has not changed.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A TLS certificate export can be hashed.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A firewall rule export can be hashed.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">An access review file can be hashed.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A cloud configuration snapshot can be hashed.</mark></p><p>If the source system changes after collection, the hash still verifies.</p><p>The evidence object is stable.</p><p>The world it describes may not be.</p><p>This is the boundary:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">integrity = did the evidence object change after collection? </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">freshness = can this evidence still support the current conclusion?</mark></p></div><p>Both are needed.</p><p>One does not replace the other.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tqwP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tqwP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!tqwP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!tqwP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!tqwP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tqwP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:994407,&quot;alt&quot;:&quot;Integrity Is Not Freshness&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.codeyourcompliance.com/i/205716351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Integrity Is Not Freshness" title="Integrity Is Not Freshness" srcset="https://substackcdn.com/image/fetch/$s_!tqwP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!tqwP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!tqwP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!tqwP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F768d5cc2-b010-4111-9c0f-aa180a735917_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Integrity proves whether the evidence object changed after collection. Freshness asks whether the evidence still supports the conclusion now being made.</figcaption></figure></div><h2>Why stale evidence should not become pass or fail</h2><p>A stale evidence object should not silently produce a clean control result.</p><p>It should not be converted into pass.</p><p>It should not be converted into fail.</p><p>The correct outcome is a freshness classification.</p><p>For example:</p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">verified evidence + expired freshness window = stale_evidence</mark></p></blockquote><p>That is not the same as non-compliance.</p><p>It means the evidence can no longer safely support the current conclusion.</p><p>The control may be working.</p><p>The control may have failed.</p><p>The evidence is no longer strong enough to decide.</p><p>That distinction matters.</p><p>Automation should preserve it.</p><h2>The evidence quality gate</h2><p>Policy evaluation should not begin with the control.</p><p>It should begin with the evidence.</p><p>The pipeline should first ask:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Is the evidence intact? </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Is the evidence source clear? </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Is the collector identified? </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Is the collection time preserved? </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Is the evidence fresh enough?</mark></p><p>Only then should the system evaluate the control expectation.</p><p>A simple evidence quality gate looks like this:</p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">evidence object </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">-&gt; integrity verification </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">-&gt; freshness classification </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">-&gt; derived facts </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">-&gt; policy evaluation </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">-&gt; audit narrative</mark></p></blockquote><p>If freshness fails, downstream evaluation should stop or explicitly carry the stale evidence status.</p><p>The report should not hide the freshness failure.</p><h2>A stale evidence example</h2><p>In the <a href="https://www.codeyourcompliance.com/">CodeYourCompliance </a>evidence validation pipeline, the sample stale evidence object uses a TLS certificate evidence record.</p><p>The evidence was collected on July 1.</p><p>It was evaluated on July 7.</p><p>Its declared freshness window was 24 hours.</p><p>The integrity status is still verified.</p><p>The freshness status is stale.</p><p>The policy result is not pass or fail.</p><p>It is:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;json&quot;,&quot;nodeId&quot;:&quot;17a0557d-c8fa-4b25-a82f-9532c9f1b9bf&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-json">{
  "input_status": "verified_but_stale_evidence",
  "result": "stale_evidence"
}
</code></pre></div><p>That is the correct boundary.</p><p>The evidence object survived integrity verification.</p><p>It did not survive freshness evaluation.</p><h2>What the audit narrative should say</h2><p>A weak audit narrative says:</p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">TLS evidence reviewed. No issue noted.</mark></p><p>A better audit narrative says:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">TLS certificate evidence was collected and integrity verification passed. However, the evidence was evaluated after its declared freshness window expired. The evidence should not be used to support a current compliance conclusion without recollection or updated source evidence.</mark></p></div><p>That is not legal interpretation.</p><p>That is evidence discipline.</p><p>The narrative should explain what the evidence can still support.</p><p>It should also explain what it can no longer support.</p><h2>MAS TRM-inspired framing</h2><p>MAS TRM-inspired does not mean MAS TRM prescribes a freshness field.</p><p>It does not mean a specific JSON structure, Rego policy, hash algorithm, or evidence pipeline is required.</p><p>The framing is narrower.</p><p>If a compliance conclusion depends on technical evidence, the evidence should be recent enough to support that conclusion.</p><p>That is an engineering interpretation.</p><p>It separates the control claim from the proof material behind it.</p><h2>Freshness changes the report boundary</h2><p>Reports often collapse time.</p><p>They present collected evidence, reviewer notes, control statements, and conclusions inside one document.</p><p>That can make old evidence look current.</p><p>A freshness field forces the report to show the time boundary.</p><p>It asks:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">When was this evidence collected? </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">How long was it valid for this claim? </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">When was the conclusion made? </mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Did the evidence remain fresh at conclusion time?</mark></p><p>If the answer is no, the report should say so.</p><p>The evidence may still be useful background.</p><p>It should not be treated as current proof.</p><h2>Technical companion</h2><p>A stale evidence example and a narrow OPA/Rego freshness policy demo are available in the CodeYourCompliance <code>evidence-validation-pipeline</code> repository.</p><p>Stale evidence example:</p><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/stale_evidence.json">https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/stale_evidence.json</a></p><p>Evidence freshness policy demo:</p><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/policies/demo/evidence_freshness.rego">https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/policies/demo/evidence_freshness.rego</a></p><p>These examples do not implement a complete evidence integrity model.</p><p>They show one boundary:</p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">verified evidence can still be stale evidence</mark></p></blockquote><h2>Boundary</h2><p>This material is for evidence structuring and technical review preparation.</p><p>It does not provide legal, regulatory, audit, certification, compliance, procurement, or implementation advice.</p><p>The goal is not to prove MAS TRM compliance.</p><p>The goal is to make the evidence freshness boundary visible before stale evidence becomes a clean report conclusion.</p><h2>Origin</h2><p><strong>Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</strong></p><p>Website: <a href="https://www.codeyourcompliance.com/">https://www.codeyourcompliance.com/</a></p><p>GitHub: <a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p>Attribution is requested for forks, references, adaptations, and discussions.</p><h2>Related reading</h2><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p><p><a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a></p><p><a href="https://www.codeyourcompliance.com/p/a-screenshot-is-a-supporting-artifact">A Screenshot Is a Supporting Artifact, Not a Proof Object</a></p><p><a href="https://www.codeyourcompliance.com/p/a-generated-report-is-not-an-accountable">A Generated Report Is Not an Accountable Audit Conclusion</a></p><p><a href="https://www.codeyourcompliance.com/p/tool-approval-is-not-workflow-proof">Tool Approval Is Not Workflow Proof</a></p>]]></content:encoded></item><item><title><![CDATA[Human Review Is a Data Exposure Path Unless It Is Bounded]]></title><description><![CDATA[Human review may support safety and support workflows, but buyers still need evidence for scope, trigger, access roles, retention, opt-out, and contract boundary.]]></description><link>https://www.codeyourcompliance.com/p/human-review-is-a-data-exposure-path</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/human-review-is-a-data-exposure-path</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Fri, 03 Jul 2026 04:24:27 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/59dbde4a-230f-43b6-b06d-8f87d3ba7bcf_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Human review can be a safety control.</p><p>It can also be a data exposure path.</p><p>Both can be true.</p><p>An AI vendor may say human review is used for safety, abuse prevention, support, troubleshooting, quality assurance, or model evaluation.</p><p>That may sound responsible.</p><p>But for a buyer, the review question is narrower:</p><p>Who can see customer data, under what condition, for what purpose, for how long, in which system, under which contract boundary, and with what customer control?</p><p>If that is not answered, &#8220;human review&#8221; remains too vague for AI vendor assessment.</p><h2>Claim</h2><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor says:</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">&#8220;Human review may be used for safety.&#8221;</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">Or:</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">&#8220;Authorized personnel may access customer data for support and troubleshooting.&#8221;</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">Or:</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">&#8220;Customer content may be reviewed in limited circumstances.&#8221;</mark></p><p>That statement may be legitimate.</p><p>It may describe an important operational control.</p><p>But it does not automatically tell the buyer whether the exposure is bounded.</p><h2>Why it sounds sufficient</h2><p>Human review sounds responsible.</p><p>It suggests that the vendor is not blindly relying on automation.</p><p>It may help detect abuse, investigate suspicious activity, troubleshoot product failures, improve quality, or respond to support tickets.</p><p>That matters.</p><p>But in AI vendor review, human review is not only a control.</p><p>It is also a path through which customer data may become visible to people outside the buyer&#8217;s organization.</p><p>So the buyer needs more than a general statement.</p><p>The buyer needs a boundary.</p><h2>What it actually proves</h2><p>A human review statement may prove that the vendor has a process where authorized personnel can inspect certain content or operational records under defined circumstances.</p><p>It may support claims such as:</p><p>The vendor monitors for abuse.</p><p>The vendor investigates safety events.</p><p>The vendor can troubleshoot customer issues.</p><p>The vendor has support access procedures.</p><p>The vendor has internal review workflows.</p><p>Those may be useful evidence points.</p><p>But they are not enough by themselves.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A statement that human review exists does not show what data is reviewed, when review is triggered, who performs it, where reviewed data goes, how long it is retained, whether access is logged, or whether the customer can restrict it.</mark></p><h2>What it does not prove</h2><p>A human review statement does not automatically prove which data types are reviewable.</p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It may not distinguish prompts, outputs, uploaded files, meeting audio, transcripts, summaries, metadata, logs, embeddings, support tickets, abuse events, evaluation data, or derived records.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove whether review is triggered by customer request, support ticket, abuse signal, automated flag, sampling, product improvement workflow, safety evaluation, or internal investigation.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove who can access the data.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It may not distinguish employees, contractors, support agents, safety reviewers, engineers, model evaluators, subprocessors, or third-party reviewers.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove whether access is approved, logged, monitored, time-limited, or customer-visible.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove whether reviewed content is copied into support systems, ticketing tools, labeling queues, QA systems, analytics systems, model evaluation datasets, or incident systems.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove whether customers can opt out.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It does not automatically prove retention, deletion, regional handling, plan differences, or contractual commitment.</mark></p><p>This is where the review file becomes weak.</p><p>The vendor says &#8220;limited human review.&#8221;</p><p>The buyer records &#8220;human review controlled.&#8221;</p><p>But the file does not show the actual review boundary.</p><h2>Weak-answer pattern</h2><p>This is the safety-control blur.</p><p>The vendor frames human review as a safety or support control.</p><p>The buyer accepts it as positive assurance.</p><p>But the same statement may also create an exposure path.</p><p>The weak review record says:</p><p>&#8220;Human review is limited to safety and support.&#8221;</p><p>That may be directionally useful.</p><p>But it is not evidence-complete.</p><p>The missing questions are:</p><blockquote><p>What content can be reviewed?</p><p>What event triggers review?</p><p>Who reviews it?</p><p>Can reviewers see raw customer content?</p><p>Is access approved and logged?</p><p>Can customers disable or restrict review?</p><p>Are support copies retained?</p><p>Are contractors or subprocessors involved?</p><p>Which terms make this enforceable?</p></blockquote><p>Without those answers, human review is not bounded.</p><p>It is only described.</p><h2>Evidence request</h2><p>Do not ask only:</p><p>&#8220;Do you use human review?&#8221;</p><p>Ask for the review boundary.</p><p>A better request is:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;Please describe all circumstances where human personnel, contractors, support agents, safety reviewers, engineers, subprocessors, or third-party reviewers may access customer content or derived data, including the data types reviewed, review triggers, access roles, approval process, logging, retention, deletion, customer controls, and contract terms.&#8221;</mark></p><p>Then ask:</p><blockquote><p>Which data types can be reviewed?</p><p>What triggers review?</p><p>Which roles can access the data?</p><p>Are reviewers employees, contractors, subprocessors, or third parties?</p><p>Is access approved, time-limited, logged, and auditable?</p><p>Can enterprise customers restrict or disable review?</p><p>Is customer approval required for support access?</p><p>Are reviewed records copied into support, safety, labeling, QA, analytics, or incident systems?</p><p>How long are reviewed records retained?</p><p>How are reviewed records deleted?</p><p>Does the policy differ by plan, product, region, feature, or contract?</p></blockquote><p>That is how human review becomes reviewable.</p><h2>Review note</h2><p>A weak review note says:</p><p>&#8220;Human review is limited.&#8221;</p><p>A stronger review note says:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;The vendor describes human review for safety, support, or operational purposes, but the available materials do not establish the full review boundary. The buyer should confirm which customer data types may be reviewed, what triggers review, which roles or third parties may access the data, whether access is logged and approved, whether enterprise customers can restrict review, how reviewed records are retained or deleted, and which contract terms confirm the boundary.&#8221;</mark></p><p>That note does not say the vendor is unsafe.</p><p>It says the exposure path is not yet bounded.</p><h2>Usage boundary</h2><p>Until human review is bounded, usage should stay conservative.</p><p>A sample usage boundary:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;Use may remain limited to low-sensitivity internal data while human review scope, triggers, access roles, support workflows, logging, retention, deletion, subprocessor involvement, opt-out controls, and contract boundaries are clarified. Do not use with customer confidential data, regulated data, source code, employee records, privileged business records, or externally relied-upon outputs until the human review boundary is evidenced.&#8221;</mark></p><p>That is not approval.</p><p>That is review preparation.</p><p>Human review may be useful.</p><p>But usefulness is not the same as evidence.</p><p>For AI vendor review, the buyer needs to know whether human review is:</p><blockquote><p>a bounded safety process,</p><p>a support access path,</p><p>a model evaluation path,</p><p>a data labeling path,</p><p>an abuse monitoring path,</p><p>or an undefined exposure path.</p></blockquote><p>Those are different review records.</p><p>The review unit is not the vendor name.</p><p>The review unit is:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">vendor + product + plan + use case + data type + region + contract terms + evidence date.</mark></p><p>Human review can support that review.</p><p>It cannot remain vague inside it.</p><h2>Boundary</h2><p>This material is for evidence structuring and review preparation. It does not provide legal, regulatory, audit, procurement, certification, or implementation advice.</p><p>The goal is not to approve or reject a vendor.</p><p>The goal is to make the evidence gap visible before real data use.</p><p>I have a sanitized sample evidence gap memo showing how this looks in a review file.<br><br>Reply if you want the sample.</p>]]></content:encoded></item><item><title><![CDATA[Why SOC 2 Does Not Prove the AI Vendor Data Path Is Covered]]></title><description><![CDATA[SOC 2 is useful evidence, but AI vendor risk assessment still needs product, model path, retention, support access, and use-case scope mapping.]]></description><link>https://www.codeyourcompliance.com/p/why-soc-2-does-not-prove-the-ai-vendor</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/why-soc-2-does-not-prove-the-ai-vendor</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Tue, 30 Jun 2026 05:05:22 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/65f9bcfb-ed33-4307-b2aa-48b3c042c298_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>AI Vendor Evidence Gap Notes #3</p><p>SOC 2 is useful evidence.</p><p>It is not automatically evidence that the AI data path is covered.</p><p>A SOC 2 report may support baseline control posture.</p><p>It may still not prove whether the specific AI product, feature, model path, support workflow, retention path, region, and contract boundary match the buyer&#8217;s use case.</p><p>That is the gap.</p><p>The question is not only:</p><p>&#8220;Does the vendor have SOC 2?&#8221;</p><p>The better question is:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;What does the SOC 2 report actually prove for this AI workflow, and what still needs to be mapped before real data use?&#8221;</mark></p><h2>Claim</h2><p>The vendor says:</p><p>&#8220;We have a SOC 2 Type II report.&#8221;</p><p>Or:</p><p>&#8220;Our platform is SOC 2 compliant.&#8221;</p><p>Or:</p><p>&#8220;Our security controls are independently audited.&#8221;</p><p>That statement may be useful.</p><p>It is not the same as proving that the buyer&#8217;s actual AI data path is covered.</p><h2>Why it sounds sufficient</h2><p>SOC 2 sounds formal.</p><p>It usually involves an independent auditor, a reporting period, a defined system scope, and tested controls.</p><p>For a standard SaaS review, that may answer many baseline security questions.</p><p>It can help a buyer understand whether the vendor has controls for access management, change management, incident response, monitoring, vendor management, and security operations.</p><p>That matters.</p><p>But AI vendor review usually asks a narrower question.</p><p>The buyer is not only buying &#8220;the platform.&#8221;</p><p>The buyer may be sending prompts, files, meeting audio, transcripts, summaries, source code, customer records, metadata, logs, embeddings, support tickets, or evaluation data into a specific AI workflow.</p><p>A SOC 2 report may cover some of that.</p><p>It may cover none of it.</p><p>The buyer cannot know unless the report scope is mapped to the actual use case.</p><h2>What it actually proves</h2><p>A SOC 2 report may prove that the vendor had a tested control environment for the scoped system during the covered period.</p><p>It may support claims such as:</p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor has access control procedures.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor reviews privileged access.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor manages changes through a controlled process.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor monitors relevant systems.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor has incident response procedures.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor tracks certain third-party service providers.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor has documented security policies.</mark></p><p>Those are useful evidence points.</p><p>But they are not automatically evidence for the specific AI product, AI feature, model provider route, retrieval layer, data retention path, support access path, or customer use case.</p><p>SOC 2 can support the review.</p><p>It does not replace the review.</p><h2>What it does not prove</h2><p>A SOC 2 report does not automatically prove that the specific AI product is in scope.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not automatically prove that the buyer&#8217;s product plan or tier is covered.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not automatically prove which model provider processes the data.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not automatically prove whether prompts, outputs, files, transcripts, summaries, embeddings, logs, or metadata are retained differently.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not automatically prove whether customer content enters support queues, abuse review, safety review, model evaluation, analytics, or troubleshooting workflows.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not automatically prove whether the subprocessor list maps to the actual AI workflow.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not automatically prove whether a &#8220;no training&#8221; claim applies to all operational data, or only to model training.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not automatically prove regional routing.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not automatically prove deletion across active storage, logs, caches, backups, support copies, or derived data.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not automatically prove the contract boundary.</mark></p><p>This is where many review files become weak.</p><p>The file contains SOC 2.</p><p>But the file does not show how SOC 2 maps to the actual AI data path.</p><h2>Weak-answer pattern</h2><p>This is a certification scope blur.</p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The buyer asks:</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">&#8220;Can we use this AI vendor for this workflow?&#8221;</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">The vendor answers:</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">&#8220;We have SOC 2.&#8221;</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">That is not a bad answer.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It is an incomplete review record.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The missing question is:</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;Which part of the AI workflow does this report cover?&#8221;</mark></p><p>For example:</p><blockquote><p>Does the report cover the AI feature itself?</p><p>Does it cover transcription?</p><p>Does it cover summarization?</p><p>Does it cover retrieval or embedding?</p><p>Does it cover the model provider route?</p><p>Does it cover support access to customer content?</p><p>Does it cover regional processing?</p><p>Does it cover the buyer&#8217;s plan?</p><p>Does it cover the current review date?</p></blockquote><p>If those questions are not answered, SOC 2 remains source material.</p><p>It is not yet evidence-complete for the use case.</p><h2>Evidence request</h2><p>Do not ask only:</p><p>&#8220;Can you provide your SOC 2?&#8221;</p><p>Ask for scope mapping.</p><p>A better request is:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;Please confirm whether the SOC 2 report scope covers the specific AI product, plan, and features used in this workflow, including processing of prompts, outputs, files, transcripts, summaries, metadata, logs, embeddings, support artifacts, model provider routes, and subprocessors.&#8221;</mark></p><p>Then ask:</p><blockquote><p>Which product and plan are covered?</p><p>Which AI features are in scope?</p><p>Are model providers, transcription services, embedding systems, retrieval systems, or external processors included?</p><p>Does the report period cover the current review date?</p><p>Are support workflows, troubleshooting access, abuse monitoring, or safety review included?</p><p>Are logs and metadata treated as customer data, operational data, security data, or something else?</p><p>Which controls apply to retention, deletion, access, and routing?</p><p>Which contractual terms confirm the operational boundary?</p></blockquote><p>That is how SOC 2 becomes reviewable.</p><h2>Review note</h2><p>A weak review note says:</p><p>&#8220;SOC 2 received. Risk resolved.&#8221;</p><p>A stronger review note says:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;The SOC 2 report supports the existence of a tested control environment for the vendor&#8217;s stated scope and reporting period. It does not by itself establish whether the specific AI product, feature, model path, data type, region, support workflow, retention layer, or customer use case is covered. Additional product-specific scope mapping is required before relying on the report for this AI workflow.&#8221;</mark></p><p>That note does not reject the vendor.</p><p>It draws the evidence boundary.</p><p>It tells the buyer what the report supports and where the report stops.</p><h2>Usage boundary</h2><p>Until the SOC 2 scope is mapped to the actual AI workflow, usage should stay bounded.</p><p>A sample usage boundary:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;Use may remain limited to low-sensitivity internal data while SOC 2 scope, AI feature coverage, data flow, model routing, subprocessor handling, support access, retention, deletion, and contract boundaries are clarified. Do not expand to customer confidential data, regulated data, source code, or externally relied-upon outputs until those evidence gaps are resolved.&#8221;</mark></p><p>That is not approval.</p><p>That is review preparation.</p><p>The review unit is not the vendor name.</p><p>The review unit is:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">vendor + product + plan + use case + data type + region + contract terms + evidence date.</mark></p><p>SOC 2 can support that review.</p><p>It cannot do the whole job by itself.</p><h2>Boundary</h2><p>This material is for evidence structuring and review preparation. It does not provide legal, regulatory, audit, procurement, certification, or implementation advice.</p><p>The goal is not to approve or reject a vendor.</p><p>The goal is to make the evidence gap visible before real data use.</p><p>I now have a sanitized sample evidence gap memo showing how this looks in a review file.</p><p>Reply if you want the sample.</p>]]></content:encoded></item><item><title><![CDATA[Tool Approval Is Not Workflow Proof]]></title><description><![CDATA[Approved AI tools do not prove workflow control. AI-supported work needs replayable evidence for task scope, data boundary, review, and failure handling.]]></description><link>https://www.codeyourcompliance.com/p/tool-approval-is-not-workflow-proof</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/tool-approval-is-not-workflow-proof</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Mon, 29 Jun 2026 06:30:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yIEc!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5cabd34-4bcf-4182-8a08-961d2b665a8d_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A company approves an AI tool for internal use.</p><p>The model is on the approved list.<br>Access is limited to approved users.<br>The policy says sensitive work requires review.<br>The tool is allowed.</p><p>Then it appears inside real work.</p><p>It helps write code.<br>It drafts configuration changes.<br>It summarizes system tickets.<br>It prepares incident notes.<br>It generates compliance narratives.<br>It suggests access-control updates.</p><p>Later, someone asks a simple review question:</p><p>What was this AI capability allowed to do at the moment it influenced the workflow?</p><p>The organization can show the tool was approved.</p><p>It cannot show the workflow proof.</p><p>That is the control gap.</p><h2>Tool approval controls entry</h2><p>An approved tool list answers one question:</p><p>Is this tool allowed to be used?</p><p>That question matters.</p><p>But it does not answer what happened inside a specific workflow.</p><p>It does not prove which task was performed, what data was used, what policy version applied, whether review was required, who accepted the output, or what happened when the AI result failed.</p><p>Tool approval controls entry.</p><p>Workflow proof controls consequence.</p><p>These are different evidence problems.</p><h2>MAS TRM-inspired framing</h2><p>This is not legal, regulatory, audit, certification, or implementation advice.</p><p>The framing is MAS TRM-inspired in an engineering sense.</p><p>The question is narrow:</p><p>Can AI-supported work produce evidence that is scoped, timestamped, reviewable, and replayable enough to survive later inspection?</p><p>Compliance automation is not about generating nicer reports.</p><p>It is about making evidence harder to fake, harder to mutate, and easier to replay.</p><p>A tool approval record does not do that by itself.</p><h2>Permission is not proof</h2><p>A user may be allowed to use an AI tool.</p><p>That does not mean the AI capability should be allowed to perform every task available to that user.</p><p>This matters when AI enters environments where work has consequence:</p><p>coding tools<br>ticketing systems<br>configuration pipelines<br>access request workflows<br>incident response notes<br>audit evidence preparation<br>data analysis notebooks<br>local automation scripts</p><p>A model that can summarize a document is not the same as a model that can suggest a production change.</p><p>A tool that can draft an incident note is not the same as a tool that can classify incident severity.</p><p>A coding assistant that can explain a function is not the same as one that can generate a patch.</p><p>The capability may look the same from the tool list.</p><p>It is not the same from the control perspective.</p><h2>The missing control fields</h2><p>Once AI capability enters a workflow, the evidence object needs to move closer to the work.</p><p>A useful workflow-use record should preserve at least a few fields:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">workflow_id</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">task_scope</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">ai_capability_id</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">data_categories_used</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">input_reference</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">output_reference</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">policy_version</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">review_required</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">review_status</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">decision_owner</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">failure_condition</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">exception_path</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">evidence_timestamp</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">evidence_hash</mark></p></div><p>This is not product architecture.</p><p>It is an evidence shape.</p><p>The point is not to describe the AI tool in general.</p><p>The point is to preserve what the AI capability was allowed to do in a specific workflow, at a specific time, under a specific control boundary.</p><p>Without that record, the organization may know the tool was approved.</p><p>It does not know whether the workflow action was controlled.</p><h2>Human review is not evidence by default</h2><p>Many AI policies rely on human review.</p><p>That can be useful.</p><p>It is also often too vague.</p><p>&#8220;Human-in-the-loop&#8221; is not proof unless the workflow records what was reviewed, what evidence was visible, who accepted the result, and whether the output moved the workflow forward.</p><p>A review checkpoint that leaves no record is not a control.</p><p>It is a belief.</p><p>Approval route is not decision record.</p><h2>Policy-as-code needs evidence</h2><p>OPA or another policy engine can evaluate structured workflow evidence.</p><p>It can check whether a task is allowed.</p><p>It can check whether a data category is permitted.</p><p>It can check whether review is required.</p><p>It can check whether a failure condition should stop the workflow.</p><p>But it cannot evaluate what the system never recorded.</p><p>If task scope is missing, policy evaluation becomes guesswork.</p><p>If data category is missing, the boundary cannot be tested.</p><p>If policy version is missing, the decision cannot be replayed.</p><p>If review status is missing, acceptance cannot be distinguished from silent continuation.</p><p>Policy-as-code is not magic.</p><p>It executes against evidence.</p><h2>Failure handling is part of the control</h2><p>The most revealing question is often not what happens when AI works.</p><p>It is what happens when AI fails.</p><div class="callout-block" data-callout="true"><p>Does the workflow stop?<br>Does it escalate?<br>Does it require review?<br>Does it create an exception record?<br>Does it continue silently?<br>Does it move the output into a downstream system?</p></div><p>Failure handling is not operational cleanup.</p><p>It is part of the control design.</p><p>If an AI tool suggests an unsafe configuration, the issue is not only model quality.</p><p>The issue is whether the workflow prevents that suggestion from becoming consequence without review.</p><p>If an AI-generated audit note sounds correct but has no source reference, the issue is not only hallucination.</p><p>The issue is whether unsupported narrative can enter the evidence package.</p><p>A serious system does not only log errors.</p><p>It prevents error from becoming consequence.</p><h2>Observation is not remediation</h2><p>The purpose of workflow proof is not to fix every issue automatically.</p><p>It is to make the state of control observable.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">If an AI output entered a workflow without review, that is an observation.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">If a task used data outside the approved scope, that is an observation.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">If no policy version was attached, that is an observation.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">If the failure path was missing, that is an observation.</mark></p><p>Observation comes first.</p><p>Remediation comes later.</p><p>Collection is not correction.</p><h2>The review test</h2><p>A reviewer should be able to ask:</p><p>For this AI-supported workflow action, can we show:</p><blockquote><p>what task was performed<br>what AI capability was used<br>what data category was touched<br>what policy version applied<br>whether review was required<br>whether review occurred<br>who owned the decision<br>what output moved forward<br>what failure condition was checked<br>what evidence hash protects the record</p></blockquote><p>If the answer is no, the organization may have tool approval.</p><p>It does not yet have workflow proof.</p><h2>Closing boundary</h2><p>Approved use is a permission record.</p><p>Workflow proof is an evidence record.</p><p>The approved tool list controls entry.</p><p>It does not prove task scope, data boundary, review condition, policy version, failure handling, or decision ownership inside the workflow.</p><p>That proof has to be captured closer to the work.</p><p>Tool approval is not workflow proof.</p><p>That is the boundary.</p><div><hr></div><h2><strong>Origin</strong></h2><p>Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</p><p><span>Website: </span><a href="https://www.codeyourcompliance.com/"><span>https://www.codeyourcompliance.com/</span></a><br><br><span>GitHub: </span><a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p>Attribution is requested for forks, references, adaptations, and discussions.</p><h2>Scope Boundary</h2><p>MAS TRM-inspired means engineering interpretation.</p><p>This article is not legal, regulatory, audit, certification, compliance, or implementation advice.</p><h2>Technical Companion</h2><p>A minimal workflow proof boundary note and synthetic evidence examples are available in the CodeYourCompliance <code>evidence-validation-pipeline</code> repository.</p><p>Boundary note:</p><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/docs/workflow-proof-boundary.md">https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/docs/workflow-proof-boundary.md</a></p><p>Synthetic examples:</p><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/minimal_workflow_proof_object.json">https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/minimal_workflow_proof_object.json</a></p><p><a href="https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/invalid_workflow_proof_missing_review_owner.json">https://github.com/codeyourcompliance/evidence-validation-pipeline/blob/main/examples/invalid_workflow_proof_missing_review_owner.json</a></p><p>These examples do not implement a workflow-proof engine. They show the minimum evidence shape for separating tool approval from workflow proof.</p><h2>Related Reading</h2><ul><li><p><a href="https://www.codeyourcompliance.com/p/go-live-is-not-workflow-evidence">Go-Live Is Not Workflow Evidence</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/a-generated-report-is-not-an-accountable">A Generated Report Is Not an Accountable Audit Conclusion</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Introducing the Trust Signal Directory]]></title><description><![CDATA[A public evidence directory tracking trust, security, privacy, compliance, AI governance, and enterprise-readiness signals across SaaS and AI vendors.]]></description><link>https://www.codeyourcompliance.com/p/introducing-the-trust-signal-directory</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/introducing-the-trust-signal-directory</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Sat, 27 Jun 2026 07:29:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yIEc!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5cabd34-4bcf-4182-8a08-961d2b665a8d_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A public evidence directory for trust, security, privacy, compliance, and enterprise-readiness signals across SaaS and AI vendors.</p><p>I have started a public side project under CodeYourCompliance:</p><p><a href="https://signal.codeyourcompliance.com/">https://signal.codeyourcompliance.com</a></p><p>The Trust Signal Directory tracks public evidence surfaces that appear across SaaS, AI, and B2B software vendors.</p><p>Examples include:</p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Trust Centers</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Security pages</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Privacy policies</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Data Processing Addendums</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Subprocessor pages</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">SOC 2, ISO 27001, HIPAA, GDPR, and related statements</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">AI data usage, responsible AI, and model safety pages</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Enterprise security features such as SSO, SCIM, RBAC, audit logs, and data residency</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Security, privacy, compliance, GRC, and legal operations hiring signals</mark></p></li></ul><p>The purpose is not to rank vendors.</p><p>The purpose is to observe public evidence surfaces and ask a more specific question:</p><p>What might this public change signal about trust maturity, compliance pressure, enterprise readiness, procurement readiness, or vendor review expectations?</p><p>A single page change is not proof of buying intent. A Trust Center does not automatically mean a company is looking for a new compliance tool. A privacy policy update may be routine legal maintenance. A SOC 2 page may indicate the company is already past the readiness stage.</p><p>That is why the directory is evidence-first and cautious by design.</p><p>Each useful signal should eventually answer:</p><ul><li><p>What changed?</p></li><li><p>Where is the public evidence?</p></li><li><p>Why might it matter?</p></li><li><p>What could make it a false positive?</p></li><li><p>What should be watched next?</p></li></ul><p>The public site will start small.</p><p>The first version will focus on methodology, signal taxonomy, sample company profiles, and public examples. More company profiles will be added only after manual review.</p><p>The private research layer remains separate. Buyer-specific fit ratings, custom watchlists, recommended GTM actions, and outcome feedback are not published in the public directory.</p><p>For now, the goal is simple:</p><p>Build a clean public evidence layer for tracking trust and compliance signals, then test whether these signals can become useful GTM intelligence for people selling into compliance, security, privacy, AI governance, vendor risk, and enterprise readiness workflows.</p><p>You can view the initial public alpha here:</p><p><a href="https://signal.codeyourcompliance.com/">https://signal.codeyourcompliance.com</a></p>]]></content:encoded></item><item><title><![CDATA[A Trust Center Is Not an AI Vendor Risk Assessment]]></title><description><![CDATA[Trust centers are useful source material, but AI vendor risk assessment still requires claim-to-evidence mapping, scope checks, buyer questions, and usage boundaries.]]></description><link>https://www.codeyourcompliance.com/p/a-trust-center-is-not-an-ai-vendor</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/a-trust-center-is-not-an-ai-vendor</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Fri, 26 Jun 2026 04:53:17 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4b9b030b-7da7-4c8a-bae4-e03b8fe2ba14_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A trust center is useful source material.</p><p>It is not the review conclusion.</p><p>A vendor may have a security page, privacy documentation, subprocessors page, compliance reports, AI data-use statement, DPA, retention FAQ, and product security overview.</p><p>That does not mean the buyer has completed an AI vendor risk assessment.</p><p>The review question is narrower:</p><p>Which claim does this source support, for which product, plan, use case, data type, region, contract terms, and evidence date?</p><p>That is the gap.</p><h2>Claim</h2><p>The vendor says:</p><p>&#8220;See our trust center.&#8221;</p><p>Or:</p><p>&#8220;Our security and compliance documentation is available in our trust center.&#8221;</p><p>Or:</p><p>&#8220;You can find our SOC 2, DPA, subprocessors, privacy policy, and security information there.&#8221;</p><p>That response may be useful.</p><p>It is not enough by itself.</p><p>A trust center can contain evidence sources.</p><p>It does not automatically convert those sources into a reviewable evidence file for the buyer&#8217;s actual AI workflow.</p><h2>Why it sounds sufficient</h2><p>Trust centers feel organized.</p><p>They usually collect the documents a reviewer expects to see:</p><div class="callout-block" data-callout="true"><p>SOC 2 report or bridge letter.</p><p>ISO certificates.</p><p>Security whitepaper.</p><p>DPA.</p><p>Subprocessor list.</p><p>Privacy policy.</p><p>Data processing terms.</p><p>Incident response statements.</p><p>Encryption statements.</p><p>Access control summaries.</p><p>AI data-use or model-training statements.</p></div><p>For a busy buyer, this can look like the answer.</p><p>The vendor has a portal.</p><p>The documents are in one place.</p><p>The compliance logos are visible.</p><p>The buyer can download files.</p><p>That can create the impression that the vendor risk review is mostly complete.</p><p>But a trust center is still vendor-controlled source material.</p><p>It does not answer the buyer&#8217;s operating-context question by itself.</p><h2>What it actually proves</h2><p>A trust center may prove that the vendor has published relevant documentation.</p><p>It may show that the vendor has some formal security, privacy, compliance, and procurement materials available.</p><p>It may help identify where claims are written.</p><p>It may provide useful evidence sources for a review file.</p><p>It may help the buyer locate:</p><p>where the vendor makes its data-use promises,</p><p>which certifications exist,</p><p>which subprocessors are listed,</p><p>which DPA terms are available,</p><p>which security controls are described,</p><p>which privacy commitments are public,</p><p>and which documents may need to be requested privately.</p><p>That is useful.</p><p>But it is only the starting point.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The trust center helps locate evidence sources.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It does not decide whether those sources support the actual claim, product, plan, data path, or use case under review.</mark></p><h2>What it does not prove</h2><p>A trust center does not automatically prove that a specific AI product is covered.</p><div class="callout-block" data-callout="true"><p>It does not automatically prove that the buyer&#8217;s plan or tier is covered.</p><p>It does not automatically prove that the current AI feature is in scope.</p><p>It does not automatically prove how prompts, outputs, files, transcripts, embeddings, logs, metadata, support records, or abuse-monitoring events are handled.</p><p>It does not automatically prove whether customer data is used for model training, evaluation, safety review, product improvement, analytics, or troubleshooting.</p><p>It does not automatically prove retention by data type.</p><p>It does not automatically prove deletion across active storage, logs, caches, backups, support copies, or derived data.</p><p>It does not automatically prove which subprocessors process which data for the specific workflow.</p><p>It does not automatically prove whether human review is possible, when it is triggered, who can access the data, and whether the buyer can opt out.</p><p>It does not automatically prove regional routing.</p><p>It does not automatically prove whether the relevant promise is contractual, audited, policy-level, documentation-level, or marketing-level.</p></div><p>This is where reviews become weak.</p><p>The file says:</p><p>&#8220;Trust center reviewed.&#8221;</p><p>But the file does not show which claim each source supports.</p><h2>Weak-answer pattern</h2><p>This is the trust center showroom pattern.</p><p>The vendor points the buyer to a polished evidence showroom.</p><p>The buyer receives many documents.</p><p>But the review still lacks claim-to-source mapping.</p><p>The weak review record looks like this:</p><p>&#8220;Vendor has trust center. SOC 2 available. DPA available. Subprocessor page available. Security documentation available.&#8221;</p><p>That may be true.</p><p>But it does not answer:</p><p>Which exact claim is supported?</p><p>Where is the source?</p><p>Is the source current?</p><p>Is the source contractual, audited, official documentation, policy text, or marketing language?</p><p>Does it cover the product?</p><p>Does it cover the plan?</p><p>Does it cover the AI feature?</p><p>Does it cover the data type?</p><p>Does it cover the use case?</p><p>Does it cover the region?</p><p>Does it cover the support workflow?</p><p>Does it cover model routing?</p><p>Does it cover retention and deletion?</p><p>Does it cover subprocessors?</p><p>Does it cover human review?</p><p>Without that mapping, the trust center is not evidence-complete.</p><p>It is a source library.</p><h2>Evidence request</h2><p>Do not ask only:</p><p>&#8220;Can you share your trust center?&#8221;</p><p>Ask for claim-specific mapping.</p><p>A stronger request is:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;Please identify which trust center materials support each AI data-use, security, privacy, retention, subprocessor, support access, human review, and model-training claim for the specific product, plan, region, and use case under review.&#8221;</mark></p><p>Then ask:</p><p>Which document supports the claim that customer prompts and outputs are not used for model training?</p><p>Where is the retention period for prompts, outputs, uploaded files, logs, metadata, embeddings, and support records documented?</p><p>Which subprocessors process customer content for this product and feature?</p><p>Which subprocessors process only metadata, infrastructure telemetry, support data, or security logs?</p><p>Is human review possible for prompts, outputs, files, abuse events, support tickets, or troubleshooting records?</p><p>Can the customer configure retention, deletion, data residency, and support access?</p><p>Which claims are contractual?</p><p>Which claims are in public policy pages only?</p><p>Which claims are covered by audited reports?</p><p>Which claims require private trust center material, SOC 2 detail, security questionnaire response, order form language, or customer-specific terms?</p><p>The goal is not to collect more documents.</p><p>The goal is to map claims to evidence.</p><h2>Review note</h2><p>A weak review note says:</p><p>&#8220;Trust center available.&#8221;</p><p>A stronger review note says:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;The trust center provides source material, but it does not by itself establish that the vendor&#8217;s claims are evidence-complete for the intended AI workflow. Each relevant claim should be mapped to a source, evidence type, product scope, plan, data type, region, contract boundary, and evidence date before the buyer relies on the claim for customer, confidential, regulated, or externally relied-upon data use.&#8221;</mark></p><p>That note does not reject the vendor.</p><p>It draws the evidence boundary.</p><p>It tells the buyer what the trust center supports and what still needs to be checked.</p><h2>Usage boundary</h2><p>Until the trust center materials are mapped to the actual use case, usage should stay bounded.</p><p>A sample usage boundary:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">&#8220;Use may remain limited to low-sensitivity internal data while trust center materials are mapped to the specific AI product, plan, feature, data type, model path, subprocessor chain, support access path, retention period, deletion control, regional route, and contract boundary. Do not expand to customer confidential data, regulated data, source code, employee records, or externally relied-upon outputs until the relevant claims are tied to reviewable evidence.&#8221;</mark></p><p>This is not approval.</p><p>It is review preparation.</p><p>The review unit is not the vendor name.</p><p>The review unit is:</p><p>vendor + product + plan + use case + data type + region + contract terms + evidence date.</p><p>A trust center can support that review.</p><p>It cannot do the whole review by itself.</p><h2>Boundary</h2><p>This material is for evidence structuring and review preparation. It does not provide legal, regulatory, audit, procurement, certification, or implementation advice.</p><p>The goal is not to approve or reject a vendor.</p><p>The goal is to make the evidence gap visible before real data use.</p><p>I now have a sanitized sample evidence gap memo showing how this looks in a review file.</p><p>Reply if you want the sample.</p>]]></content:encoded></item><item><title><![CDATA[Go-Live Is Not Workflow Evidence]]></title><description><![CDATA[A green dashboard proves delivery activity, not operating change. Transformation is only proven when the workflow changes and the evidence can survive replay.]]></description><link>https://www.codeyourcompliance.com/p/go-live-is-not-workflow-evidence</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/go-live-is-not-workflow-evidence</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Mon, 22 Jun 2026 10:30:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yIEc!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5cabd34-4bcf-4182-8a08-961d2b665a8d_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The steering committee dashboard is green.</p><p>The platform is live.<br>The automation is deployed.<br>The audit findings are closed.<br>Training completion is above target.<br>The policy has been approved.<br>The programme reports 85% complete.</p><p>Then someone from operations says the quiet part.</p><p>&#8220;My team worked all weekend fixing what the automation broke.&#8221;</p><p>That is where the audit problem starts.</p><p>Not because the dashboard is fake.</p><p>Because the dashboard is measuring delivery progress.</p><p>Operations is measuring whether the workflow actually works.</p><p>Those are not the same thing.</p><p>A system can be delivered and still fail to change the operating reality. A control gap can be remediated and still leave the process weak. An AI pilot can show better detection and still fail at scale because data ownership, evidence capture, escalation, and review paths were not ready.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Go-live is delivery.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It is not workflow evidence.</mark></p><h2>Delivery evidence is not workflow evidence</h2><p>Most transformation reporting is built around delivery objects.</p><p>The platform went live.<br>The dashboard was built.<br>The policy was approved.<br>The training was completed.<br>The audit finding was closed.<br>The AI model was deployed.<br>The control remediation was marked complete.</p><p>These records have value.</p><p>They prove that the programme produced something. They help track spend, schedule, implementation, and governance commitments. They support programme control.</p><p>But they do not prove that the workflow changed.</p><p>A closed finding does not prove operating capability improved.</p><p>A live dashboard does not prove decisions became better.</p><p>A deployed automation does not prove manual effort reduced.</p><p>A trained user population does not prove the new process became the normal path.</p><p>A successful pilot does not prove the organisation can operate the control at real volume.</p><p>The delivery record answers one question:</p><div class="callout-block" data-callout="true"><p>Did we ship what we said we would ship?</p></div><p>The workflow evidence answers a different question:</p><div class="callout-block" data-callout="true"><p>Did the operating reality change in a way we can prove?</p></div><p>That is the boundary.</p><h2>The workaround is evidence</h2><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">When a transformation fails to land, the first sign is often not a red dashboard.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It is a workaround.</mark></p><p>A spreadsheet continues to run beside the platform.<br>An analyst keeps a manual tracker because the new workflow misses exceptions.<br>A team rechecks AI output because no one trusts the source data.<br>A manager approves in the system but makes the real decision in a side channel.<br>Operations absorbs the exception load while the programme reports adoption.<br>Evidence is reconstructed later because capture was not designed into the workflow.</p><p>The workaround is not just noise.</p><p>It is evidence that the formal process has not absorbed the work.</p><p>That does not mean every workaround is bad. Some workarounds are rational responses to an incomplete control path. They show where the operating model could not yet carry the real workflow.</p><p>This is why transformation reporting often stays green while the organisation feels worse.</p><p>Every layer translates reality upward.</p><p>&#8220;Control failures&#8221; becomes &#8220;remediation underway.&#8221;<br>&#8220;Operational pressure&#8221; becomes &#8220;resource challenge.&#8221;<br>&#8220;Manual evidence reconstruction&#8221; becomes &#8220;temporary support activity.&#8221;<br>&#8220;Benefits delayed&#8221; becomes &#8220;value realisation in progress.&#8221;</p><p>None of those phrases are necessarily false.</p><p>They are just not workflow evidence.</p><p>They protect the programme narrative. They do not prove the change landed.</p><h2>What workflow evidence should show</h2><p>Workflow evidence is narrower than a transformation story.</p><p>It should show what changed, where it changed, how it was measured, and who owns the result.</p><p>A useful workflow evidence object should answer:</p><div class="callout-block" data-callout="true"><p>What was the baseline?<br>Which workflow step changed?<br>Which control boundary applied?<br>Which evidence source was used?<br>What manual effort existed before?<br>What exception count existed before?<br>What decision time existed before?<br>What changed after deployment?<br>Which policy or control version was in force?<br>Who owned the decision?<br>Who owned the consequence?<br>Can the decision path be replayed?<br>Can the audit narrative explain the change without reconstruction?</p></div><p>This is not about making reporting prettier.</p><p>It is about separating delivery status from operating proof.</p><div class="pullquote"><p>A programme can say &#8220;automation deployed.&#8221;</p><p>Workflow evidence should say whether exception volume reduced, whether manual evidence effort fell, whether control results were reproducible, whether escalation paths were used correctly, and whether the owner can explain the decision path.</p><p>A programme can say &#8220;audit finding closed.&#8221;</p><p>Workflow evidence should say whether the underlying failure mode disappeared, whether the new control operated in production, whether the evidence was captured at the time, and whether the result can be replayed later.</p><p>A programme can say &#8220;AI pilot successful.&#8221;</p><p>Workflow evidence should say whether the data boundary held, whether stale inputs were detected, whether false positives reduced, whether correct refusals were handled, whether review points were usable, and whether the operating team could support the model at volume.</p></div><p>Data alone is not evidence.</p><p>A dashboard alone is not accountability.</p><p>Delivery alone is not transformation.</p><h2>MAS TRM-inspired, not MAS TRM-prescribed</h2><p>This is where MAS TRM-inspired engineering is useful.</p><p>Not as legal advice.<br>Not as regulatory interpretation.<br>Not as certification language.</p><p>The useful lesson is narrower.</p><p>Technology risk governance becomes stronger when evidence is collected in a way that is hard to fake, hard to mutate, and easy to replay.</p><p>That means read-only collection where possible.<br>Timestamped evidence.<br>Collector metadata.<br>Policy or control version.<br>Integrity reference.<br>Control result.<br>Exception state.<br>Owner.<br>Audit narrative.</p><p>The implementation is not prescribed by MAS TRM.</p><p>The engineering interpretation is that control proof should survive later review.</p><p>A report may persuade in a steering committee.</p><p>Evidence has to survive challenge.</p><h2>The hard question</h2><p>Before calling a programme transformed, ask one question:</p><p>What proves the workflow is better?</p><p>Not what was delivered.<br>Not what was closed.<br>Not what was approved.<br>Not what was trained.<br>Not what went live.</p><p>What proves the workflow changed?</p><p>Did the workaround disappear?<br>Did manual evidence effort reduce?<br>Did decision time improve?<br>Did exception handling improve?<br>Did false positives fall?<br>Did escalation become clearer?<br>Did the control result become reproducible?<br>Did the owner become clear?<br>Can the decision path be replayed?</p><p>If the answer is not available, the programme may still be valuable.</p><p>But it is not yet proven transformation.</p><p>It is delivered change without workflow proof.</p><p>Go-live is delivery.<br>Closed finding is remediation.<br>Workflow proof is transformation.</p><p>That is the boundary.</p><div><hr></div><h2>Origin</h2><p>CodeYourCompliance</p><p>Website: <a href="https://www.codeyourcompliance.com/">https://www.codeyourcompliance.com</a><br>GitHub: <a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p>Attribution is requested for forks, references, adaptations, and discussions.</p><h2>Scope Boundary</h2><p>MAS TRM-inspired means engineering interpretation.</p><p>This article is not legal, regulatory, audit, certification, compliance, or implementation advice.</p><h2>Related Reading</h2><ul><li><p><a href="https://www.codeyourcompliance.com/p/a-screenshot-is-a-supporting-artifact">A Screenshot Is a Supporting Artifact, Not a Proof Object</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Compliance Automation Starts at Evidence</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[A Generated Report Is Not an Accountable Audit Conclusion]]></title><description><![CDATA[Evidence processing is not evidence judgment. AI can support the work, but the reviewer owns the conclusion.]]></description><link>https://www.codeyourcompliance.com/p/a-generated-report-is-not-an-accountable</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/a-generated-report-is-not-an-accountable</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Mon, 15 Jun 2026 05:45:30 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/fa24b961-0600-492a-b006-e357247dcb5b_1731x909.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A team uploads access exports, screenshots, policy PDFs, and control notes into an AI-assisted GRC tool.</p><p>The tool maps controls.</p><p>It summarizes gaps.</p><p>It drafts findings.</p><p>It produces a clean report.</p><p>Then the reviewer asks one question:</p><p>Who concluded that the control was operating?</p><p>The report cannot answer that by itself.</p><p>That is the failure mode.</p><p>A generated report is not an accountable audit conclusion.</p><p>It may be useful.</p><p>It may reduce drafting work.</p><p>It may make the review file easier to read.</p><p>But it does not automatically prove that evidence was valid, interpreted correctly, reviewed under the right standard, and accepted by a responsible reviewer.</p><p>That is the boundary.</p><h2>Evidence processing is not evidence judgment</h2><p>AI can support audit work.</p><p>It can collect records.</p><p>It can map controls.</p><p>It can compare evidence.</p><p>It can summarize exceptions.</p><p>It can draft findings.</p><p>None of that is the problem.</p><p>The problem starts when evidence processing is mistaken for evidence judgment.</p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Evidence processing</mark> asks:</p><div class="callout-block" data-callout="true"><p>What does this artifact say?</p><p>What control might it relate to?</p><p>What fields are missing?</p><p>What exception appears?</p></div><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Evidence judgment</mark> asks:</p><div class="callout-block" data-callout="true"><p>Is this evidence valid?</p><p>Is it complete enough for this control?</p><p>Was it collected from the right source?</p><p>Was it current at the review date?</p><p>Does it meet the acceptance standard?</p><p>Who accepts the conclusion?</p></div><p>Those are different acts.</p><p>The tool can assist the first.</p><p>It should not silently inherit the second.</p><h2>MAS TRM-inspired does not mean audit automation</h2><p>CodeYourCompliance uses MAS TRM-inspired engineering language.</p><p>That does not mean MAS TRM prescribes this implementation.</p><p>It does not mean the output is legal, regulatory, audit, or certification advice.</p><p>The point is narrower.</p><p>MAS TRM-style control thinking gives a useful engineering structure:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">control objective</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">evidence requirement</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">source system</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">collector metadata</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">timestamp</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">integrity reference</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">policy evaluation</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">review narrative</mark></p></div><p>That structure prevents one common failure.</p><p>A report says the control passed.</p><p>But the evidence object cannot show what was collected, when it was collected, from where, by what collector, under which schema, and against which acceptance standard.</p><p>That is not a writing problem.</p><p>That is an evidence architecture problem.</p><h2>A report is narrative</h2><p>A report is narrative.</p><p>Evidence is proof material.</p><p>A control is not proven because a paragraph says it was satisfied.</p><p>A control is supported when the underlying evidence can survive review.</p><p>A minimal evidence object should preserve:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;json&quot;,&quot;nodeId&quot;:&quot;5a13098f-fb74-4de7-8cbb-149a0a26556f&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-json">evidence_id: ev-2026-001
control_id: access-review-001
source_system: identity_platform
collector_type: read_only_export
collected_at: 2026-06-13T09:20:00Z
artifact_type: access_export
artifact_hash: sha256:...
schema_version: evidence.v1
policy_version: access_review_policy.v1
evaluation_result: pass | fail | manual_review | invalid_evidence
review_status: pending | accepted | rejected
</code></pre></div><p>This does not make the conclusion automatic.</p><p>It makes the conclusion reviewable.</p><p>The report can explain the finding.</p><p>The evidence package should show:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">what was collected</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">where it came from</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">when it was collected</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">whether the artifact changed</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">which policy evaluated it</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">who accepted the result</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">what exceptions remained</mark></p></div><p>Reports persuade.</p><p>Evidence survives.</p><h2>The reviewer still owns the conclusion</h2><p>AI-assisted audit work can make weak review files look strong.</p><p>The report may sound complete.</p><p>The finding may sound precise.</p><p>The control mapping may look convincing.</p><p>But if no accountable reviewer has accepted the evidence, the conclusion is not anchored.</p><p>The review file should separate five layers:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">evidence source</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">evidence processing</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">evidence interpretation</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">review note</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">accountable conclusion</mark></p></div><p>Do not collapse them.</p><p>A collector collects.</p><p>A policy evaluates.</p><p>A model summarizes.</p><p>A reviewer concludes.</p><p>A report narrates.</p><p>Each layer has a different job.</p><p>If the model invents certainty, the narrative becomes dangerous.</p><p>If the reviewer does not accept the conclusion, the report is only a draft.</p><h2>Invalid evidence is not a failed control</h2><p>A generated report often hides another problem.</p><p>It treats every bad artifact as a bad control.</p><p>That is wrong.</p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Invalid evidence is not the same as control failure.</mark></p><p>Example:</p><blockquote><p><em>Control</em>: privileged access must be reviewed quarterly.</p><p><em>Artifact</em>: screenshot of admin users.</p><p><em>Problem</em>: screenshot has no export timestamp, no source binding, no hash, and no review-period marker.</p></blockquote><p>The correct result is not automatically:</p><div class="callout-block" data-callout="true"><p>control failed</p></div><p>The correct result may be:</p><div class="callout-block" data-callout="true"><p>invalid_evidence</p></div><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">A control failure says the system state did not meet the control requirement.</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Invalid evidence says the artifact cannot prove the system state.</mark></p><p>Those are different findings.</p><p>If evidence is invalid, the report should not pretend to know the control outcome.</p><p>It should say:</p><div class="callout-block" data-callout="true"><p>The submitted artifact does not support a control conclusion.</p><p>Additional source-bound evidence is required.</p></div><p>That is not softer.</p><p>It is more precise.</p><h2>The report comes late</h2><p>A useful compliance automation pipeline should not start by drafting the final report.</p><p>It should start by preserving the evidence path.</p><div class="callout-block" data-callout="true"><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">read-only collection</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">evidence object creation</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">integrity hash</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">schema validation</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">policy evaluation</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">exception classification</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">reviewer acceptance</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">audit narrative generation</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">evidence package export</mark></p></div><p>The report comes late.</p><p>The evidence comes first.</p><p>If the report is generated before evidence quality is known, the system produces confidence before proof.</p><p>If the evidence object is weak, the narrative should remain weak.</p><p>If the policy evaluation returns <code>manual_review</code>, the report should not say <code>pass</code>.</p><p>If the artifact hash changes, the evidence package should flag mutation.</p><p>If collector metadata is missing, the evidence should be downgraded.</p><p>The tool is not the point.</p><p>The audit structure is the point.</p><h2>A better generated report</h2><p>A weak generated report says:</p><div class="callout-block" data-callout="true"><p>The access review control is operating effectively.</p></div><p>A better report says:</p><div class="callout-block" data-callout="true"><p>Evidence was collected from the identity platform using a read-only export on 2026-06-13.</p><p>The export hash is recorded in the evidence package.</p><p>The evidence was evaluated against access_review_policy.v1.</p><p>The policy result found no privileged users outside the approved group list.</p><p>The review conclusion remains pending until accepted by the responsible reviewer.</p></div><p>This is less polished.</p><p>It is more honest.</p><p>It separates machine evaluation from human conclusion.</p><p>It separates evidence from narrative.</p><p>It separates control support from final acceptance.</p><div><hr></div><h2>Origin</h2><p><em>CodeYourCompliance</em><br><br>Website: <a href="https://www.codeyourcompliance.com">https://www.codeyourcompliance.com</a><br>GitHub: <a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p><em>Attribution is requested for forks, references, adaptations, and discussions.</em></p><h2>Scope Boundary</h2><p>MAS TRM-inspired means engineering interpretation.</p><p>This is not legal, regulatory, audit, certification, compliance, or implementation advice.</p><h2>Related Reading</h2><ul><li><p><a href="https://www.codeyourcompliance.com/p/a-screenshot-is-a-supporting-artifact">A Screenshot Is a Supporting Artifact, Not a Proof Object</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Compliance Automation Starts at Evidence</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Vendor Says It Does Not Train on Your Data. What Evidence Should You Ask For?]]></title><description><![CDATA[A no-training claim may be true and useful, but it is not evidence-complete. AI vendor review still needs evidence on retention, logging, support access, subprocessors, model providers, deletion, audit logs, tenant settings, and contract scope.]]></description><link>https://www.codeyourcompliance.com/p/vendor-says-it-does-not-train-on</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/vendor-says-it-does-not-train-on</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Thu, 04 Jun 2026 02:36:22 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/39ebd638-20b3-4687-85bf-994cb89f3735_2173x724.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Positioning</h2><p>Vendor claim is not evidence.</p><p>&#8220;We do not train on your data&#8221; is one of the most common AI vendor statements. It is also one of the easiest to over-credit.</p><p>The claim may be true. It may be helpful. It may even appear in a contract.</p><p>But by itself, it is not evidence-complete.</p><p>Training is only one possible use of customer data. The real review question is:</p><div class="callout-block" data-callout="true"><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">After customer data enters the AI product, what happens to it?</mark></p></div><p>That means looking past the slogan and asking about retention, logging, review workflows, support access, metadata, subprocessors, model providers, deletion, audit logs, tenant settings, and contract scope.</p><h2>Claim</h2><div class="callout-block" data-callout="true"><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">We do not train on your data.</mark></p></div><p>Or:</p><div class="callout-block" data-callout="true"><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Customer data is not used to train our models.</mark></p></div><p>Or:</p><div class="callout-block" data-callout="true"><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Your prompts and outputs are not used for model training.</mark></p></div><p>These statements sound clear. They are not all the same.</p><p>One may cover customer content. Another may cover prompts and outputs only. Another may cover training, but say nothing about logs, telemetry, evaluation, support access, or product improvement.</p><p>The exact wording matters.</p><p>So does the source.</p><p>A public FAQ is not the same as a customer contract. A product page is not the same as a data processing addendum (DPA). A trust center statement is not the same as tenant-level evidence.</p><h2>Why it sounds sufficient</h2><p>It answers the question most buyers have been trained to ask:</p><div class="callout-block" data-callout="true"><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Will the vendor use my data to train its model?</mark></p></div><p>That is a real concern. If proprietary or sensitive data can be used for model training, the buyer has a serious problem.</p><p>So when the vendor says no, it feels like the main issue is closed.</p><p>That is where reviews go off track.</p><p>The claim addresses one use. It does not explain the operational data path. A vendor may not train on customer data and still retain prompts, keep logs, allow support review, or send data through model providers and subprocessors.</p><h2>What the claim can support</h2><p>A no-training statement can support a narrow point:</p><div class="callout-block" data-callout="true"><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">The vendor says customer data is not used to train models.</mark></p></div><p>That is useful. It is just not enough.</p><p>The strength depends on where it appears. A contract or product-specific term is stronger than a marketing page. A signed response is stronger than a generic FAQ.</p><p>It is also only as good as its scope. If the statement does not define the covered data, product, plan, exceptions, and document source, it remains incomplete.</p><p>At minimum, the buyer should be able to answer:</p><div class="callout-block" data-callout="true"><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">What data is covered?</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Which product and plan are covered?</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Which uses are excluded?</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Where is the commitment written?</mark></p></div><p>Without that, the claim is reassuring but thin.</p><h2>What it does not prove</h2><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">A no-training claim does not automatically prove:</mark></p><ul><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">prompt retention period</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">logging and telemetry scope</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">review and support access boundaries</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">metadata handling</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">support access boundary</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">subprocessor data path</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">model provider data path</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">deletion controls</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">audit log availability</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">tenant setting defaults</mark></p></li><li><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">customer-specific contract coverage</mark></p></li></ul><p>That is the gap. The vendor answered training use. The buyer still does not know the full data path.</p><h2>Weak-answer pattern</h2><p>The weak-answer pattern is a narrow promise presented as if it closed the review.</p><p>The vendor says:</p><div class="callout-block" data-callout="true"><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">We do not train on customer data.</mark></p></div><p>But the answer does not address the rest of the path:</p><div class="callout-block" data-callout="true"><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">logging</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">retention</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">review workflows</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">support access</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">metadata</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">subprocessors</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">model providers</mark></p><p><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">deletion</mark></p></div><p>The statement may be true. It is still too narrow. A strong answer maps the claim to data categories, retention, third parties, customer controls, and contract scope.</p><h2>Evidence request</h2><p>Do not ask the vendor to restate the slogan. Ask for evidence that maps the claim to actual handling:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Please provide the product-specific data flow for prompts, outputs, files, logs, metadata, diagnostic data, support access, subprocessors, and model providers.</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">For each data category, identify retention period, access roles, third-party processing, customer controls, deletion options, and the contractual or administrative source for the commitment.</mark></p></div><p>That is a much better question than &#8220;do you train on our data?&#8221;</p><h2><strong>Review note</strong></h2><p>Usable review language:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">The vendor states that customer data is not used for model training. This is useful but not evidence-complete. The statement addresses training use only. It does not by itself establish retention, logging, review workflows, support access, subprocessor handling, model provider routing, deletion controls, audit-log coverage, tenant settings, or customer-specific contract scope.</mark></p><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Additional evidence is needed before relying on this claim for sensitive data use.</mark></p></div><p>That note records the evidence gap without pretending the claim proves more than it does.</p><h2>Usage boundary</h2><p>Until the missing evidence is resolved, keep the usage boundary narrow:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">low-sensitivity workflows. Do not use the product for customer data, regulated data, confidential source code, or workflows that require prompt-level auditability.</mark></p></div><p>That is not approval or rejection. It is a review boundary.</p><h2>Bottom line</h2><p>&#8220;We do not train on your data&#8221; may be true. It may be useful.</p><p>It is still not the review.</p><p>The buyer still needs to know what enters the product, where it goes, how long it stays, who can access it, which third parties touch it, what can be deleted, what can be audited, and which commitments actually apply to the buyer&#8217;s product, plan, tenant, and contract.</p><p>Vendor claim is not evidence.</p><p>The work is turning a narrow public claim into a mapped evidence request, a usable review note, and a conservative usage boundary.</p><p>This is part of the <a href="https://www.codeyourcompliance.com/p/start-here-ai-vendor-risk-pack">AI Vendor Evidence Gap Pack series</a>: vendor claim &#8594; evidence source &#8594; evidence gap &#8594; buyer question &#8594; usage boundary.</p><h2>Boundary</h2><p>This article is for evidence structuring and review preparation.</p><p>It does not provide legal, regulatory, audit, procurement, certification, or implementation advice.</p><p>Examples are illustrative unless separately validated for a specific organization and use case.</p>]]></content:encoded></item><item><title><![CDATA[AI Vendor Risk Is Not a Questionnaire Problem]]></title><description><![CDATA[A vendor can answer every question and still leave the buyer without usable evidence.]]></description><link>https://www.codeyourcompliance.com/p/ai-vendor-risk-is-not-a-questionnaire</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/ai-vendor-risk-is-not-a-questionnaire</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Mon, 01 Jun 2026 16:13:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yIEc!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5cabd34-4bcf-4182-8a08-961d2b665a8d_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>AI vendor risk is not a questionnaire problem.</p><p>The problem is not that teams lack questions. The problem is that vendor answers are not converted into evidence requests, weak-answer patterns, red flags, and residual risk language.</p><h2>Opening direction</h2><p>Most AI vendor reviews start with a questionnaire.</p><p>That is reasonable. Questionnaires create structure. They force vendors to answer in writing. They give procurement, security, legal, risk, and audit teams a shared object to review.</p><p>But the questionnaire is not the control.</p><p>A vendor can answer every question and still leave the buyer with little usable evidence.</p><p>The gap appears after the answer arrives.</p><p>The vendor says:</p><blockquote><p>We do not train on your data.</p></blockquote><p>The review question should not stop there.</p><p>It should ask:</p><blockquote><p>What does training mean?</p><p>Does that include fine-tuning?</p><p>Does that include evaluation?</p><p>Does that include abuse monitoring?</p><p>Does that include support review?</p><p>What is retained?</p><p>What is logged?</p><p>Which subprocessors touch the data?</p><p>Can the customer export evidence later?</p></blockquote><p>The claim may be true. But it is not yet evidence-complete.</p><h2>Core argument</h2><p>A questionnaire collects vendor statements.</p><p>An evidence review converts those statements into reviewable objects.</p><p>Those objects include:</p><ul><li><p>evidence requests</p></li><li><p>weak-answer patterns</p></li><li><p>red flags</p></li><li><p>review notes</p></li><li><p>residual risk language</p></li></ul><p>That conversion step is where many AI vendor reviews are weakest.</p><h2>Why AI vendors make this harder</h2><p>Traditional vendor risk templates were built for more stable control surfaces.</p><p>They work reasonably well for questions about:</p><ul><li><p>access control</p></li><li><p>encryption</p></li><li><p>incident notification</p></li><li><p>business continuity</p></li><li><p>SOC 2 availability</p></li><li><p>subprocessors</p></li><li><p>data processing terms</p></li></ul><p>AI vendors add new ambiguity.</p><p>The ambiguity is not always in the security layer. It is often in the behavior layer.</p><p>Examples:</p><ul><li><p>What data enters the model context?</p></li><li><p>What data is retained in logs?</p></li><li><p>What data is used for evaluation?</p></li><li><p>What changes when the model version changes?</p></li><li><p>Can the customer identify which model produced a prior output?</p></li><li><p>What actions can an AI agent take?</p></li><li><p>What approvals exist before an external action is triggered?</p></li><li><p>Can logs be exported for audit or incident reconstruction?</p></li></ul><p>A generic questionnaire can ask about these issues, but the harder work is deciding whether the answer is evidence-complete.</p><h2>Example: polished answer, weak evidence</h2><p>Vendor answer:</p><blockquote><p>We use industry-leading safeguards to ensure customer data is protected and is not used to train our models.</p></blockquote><p>This answer sounds reassuring.</p><p>But as evidence it is weak unless it is supported by:</p><ul><li><p>contractual language</p></li><li><p>retention periods</p></li><li><p>logging scope</p></li><li><p>support access boundaries</p></li><li><p>subprocessor handling</p></li><li><p>opt-out configuration</p></li><li><p>evaluation and fine-tuning scope</p></li><li><p>exportable records</p></li></ul><p>The issue is not whether the vendor is bad.</p><p>The issue is whether the buyer can rely on the claim later.</p><h2>The review shift</h2><p>The review should move from:</p><blockquote><p>Did the vendor answer the question?</p></blockquote><p>To:</p><blockquote><p>Can the vendor answer be preserved as evidence?</p></blockquote><p>And then:</p><blockquote><p>If the evidence is weak, what residual risk language should appear in the review file?</p></blockquote><h2>What AI Vendor Risk Pack is trying to do</h2><p>AI Vendor Risk Pack is a practical attempt to make that conversion easier.</p><p>It starts with common vendor claims and asks:</p><blockquote><p>What evidence should be requested?</p><p>What answer would be weak?</p><p>What should be treated as a red flag?</p><p>What review note should be preserved?</p><p>What residual risk language might be needed?</p></blockquote><p>It is not a certification system.</p><p>It is not a vendor rating.</p><p>It is not legal or audit advice.</p><p>It is a review aid for turning AI vendor claims into evidence-aware risk language.</p><h2>Possible closing</h2><p>The next phase of AI vendor risk will not be won by longer questionnaires.</p><p>It will be won by better evidence conversion.</p><p>The real question is not whether the vendor gave an answer.</p><p>The question is whether the buyer can later explain why that answer was accepted.</p><h2>CTA draft</h2><p>I am building a lightweight AI Vendor Risk Pack under CodeYourCompliance.</p><p>The first version focuses on five domains:</p><ol><li><p>Data use.</p></li><li><p>Model change and governance.</p></li><li><p>Security and logging.</p></li><li><p>Human approval and agent permission.</p></li><li><p>Auditability and evidence export.</p></li></ol><p>The goal is simple:</p><blockquote><p>Turn AI vendor claims into evidence requests, weak-answer patterns, red flags, review notes, and residual risk language.</p></blockquote><p>The next article applies this to the most common AI vendor claim: &#8220;We do not train on your data.&#8221;</p><p>Read next: Vendor Says It Does Not Train on Your Data. What Evidence Should You Ask For?</p>]]></content:encoded></item><item><title><![CDATA[A Screenshot Is a Supporting Artifact, Not a Proof Object]]></title><description><![CDATA[Screenshots can help explain audit evidence. They should not replace it.]]></description><link>https://www.codeyourcompliance.com/p/a-screenshot-is-a-supporting-artifact</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/a-screenshot-is-a-supporting-artifact</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Mon, 01 Jun 2026 13:37:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NA7W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>An audit folder contains five screenshots.</p><p>One shows TLS enabled. One shows logging configured. One shows a user table. One shows a vendor portal confirmation. One shows a green dashboard.</p><p>The folder looks complete.</p><p>Then the reviewer asks:</p><blockquote><p>What exactly does each screenshot prove?</p></blockquote><p>Was it captured from the authoritative system? Which account and environment were shown? Was it taken before or after remediation? Was the full scope visible? Was it used for policy evaluation?</p><p>The images still look useful.</p><p>The proof boundary is unclear.</p><p>A screenshot can show what appeared on a screen. It does not automatically prove the underlying system state, complete scope, or continued operation of a control.</p><p>MAS TRM is the context. It does not prescribe this evidence classification or pipeline.</p><p>MAS TRM-inspired means engineering interpretation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NA7W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NA7W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png 424w, https://substackcdn.com/image/fetch/$s_!NA7W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png 848w, https://substackcdn.com/image/fetch/$s_!NA7W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png 1272w, https://substackcdn.com/image/fetch/$s_!NA7W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NA7W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png" width="1220" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A comparison of evidence roles showing screenshots as supporting artifacts rather than automatic proof objects.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A comparison of evidence roles showing screenshots as supporting artifacts rather than automatic proof objects." title="A comparison of evidence roles showing screenshots as supporting artifacts rather than automatic proof objects." srcset="https://substackcdn.com/image/fetch/$s_!NA7W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png 424w, https://substackcdn.com/image/fetch/$s_!NA7W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png 848w, https://substackcdn.com/image/fetch/$s_!NA7W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png 1272w, https://substackcdn.com/image/fetch/$s_!NA7W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc77f5-ee77-453c-b80b-1482c430fb74_1220x832.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>A screenshot proves a view</h2><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A screenshot may support a narrow claim:</mark></p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">At capture time, this interface displayed this information.</mark></p></blockquote><p>That can be useful.</p><p>The problem starts when the claim becomes larger than the image.</p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">A screenshot usually cannot establish by itself:</mark></p><ul><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">that the source was authoritative;</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">that all in-scope systems were included;</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">that the page was current;</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">that the expected account or environment was used;</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">that the image was not cropped or edited;</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">or that it was used for policy evaluation.</mark></p></li></ul><p>A view is not the full system state.</p><h2>Screenshot is a role, not a tier</h2><p>Treating every screenshot as secondary and every machine export as primary is too simple.</p><p>A machine-generated file can still be stale, incomplete, mis-scoped, or collected from the wrong source.</p><p>A screenshot can sometimes be the best available evidence when a system exposes no export or API.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The correct question is:</mark></p><blockquote><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What claim must this artifact support, and does it carry enough context for that claim?</mark></p></blockquote><pre><code><strong>primary_evidence</strong>
Evidence directly used to evaluate a defined condition.

<strong>supporting_artifact</strong>
Context that helps explain evidence or narrative.

<strong>manual_claim</strong>
An assertion without independent source-bound observation.

<strong>insufficient_evidence</strong>
An artifact that does not cover the required claim or scope.

<strong>invalid_evidence</strong>
An artifact whose integrity, identity, provenance, or linkage cannot be relied upon.<code>
</code></code></pre><p>File type does not decide the category.</p><p>Evidence requirements do.</p><h2>Context makes the role inspectable</h2><p>A screenshot used as evidence should be packaged with context:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;yaml&quot;,&quot;nodeId&quot;:&quot;2d553d2c-a6c5-44c1-bf9d-9d680c7ca5a1&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-yaml">artifact_type: screenshot
target_id: production-load-balancer
source_system: load-balancer-admin-portal
environment: production
captured_at: 2026-06-01T10:31:00Z
captured_by: reviewer-01
capture_method: controlled_manual_capture
scope: listener-443
artifact_hash: sha256:...
related_evidence_ref: evidence/tls-runtime-observation.json
policy_result_ref: policy-results/tls-cert-valid.json
</code></pre></div><p>These fields do not prove that the screenshot is true.</p><p>They make its role inspectable.</p><p>The hash only helps show that the preserved image matches the image that was sealed. It does not prove that the screen was genuine, current, complete, or authoritative.</p><p>For the broader model, see <a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Compliance Automation Starts at Evidence</a>.</p><h2>Screenshots often lose scope</h2><p>A screenshot captures one page, one account, one filter, and one point in time.</p><p>A screenshot of five administrators does not prove there are only five administrators.</p><p>A green dashboard tile does not prove every underlying check succeeded.</p><p>A certificate page does not prove every production endpoint presents the same certificate.</p><p>What population was expected? What population was observed? What was excluded?</p><p>A screenshot can be accurate and still insufficient.</p><h2>Capture is not correction</h2><p>A control owner notices that logging is disabled. Logging is enabled. A screenshot is taken.</p><p>The screenshot may support post-remediation verification.</p><p>It cannot replace the original observation, remediation record, approval, and later verification.</p><p>For that boundary, see <a href="https://www.codeyourcompliance.com/p/read-only-collection-as-an-audit">Read-Only Collection as an Audit Boundary</a>.</p><h2>The report should not upgrade the artifact</h2><p>A reporting system can place a screenshot under the correct control, add a caption, and mark the row complete.</p><p>None of that enlarges the evidentiary scope of the screenshot.</p><p>The report should state the role:</p><blockquote><p>The screenshot shows the interface state visible during review. The policy result was derived from the referenced source-bound evidence object.</p></blockquote><p>Where no stronger source exists:</p><blockquote><p>The screenshot is the available evidence for the displayed state. Its scope is limited to the identified page, account, environment, and capture time.</p></blockquote><p>A checklist should point to evidence requirements, not merely request uploads. See <a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a>.</p><h2>The replay test</h2><p>A later reviewer should be able to identify the supported claim, source, capture time, capture method, scope, file integrity, and linked policy result.</p><p>That does not recreate the live system.</p><p>It recreates the evidence path.</p><p>For that test, see <a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a>.</p><h2>The position</h2><p>A screenshot is not useless.</p><p>It is not automatically weak.</p><p>It is also not automatically a proof object.</p><p>It may prove what a screen displayed. It may support human review. It may be the only available observation.</p><p>But its claim must remain bounded by provenance, scope, capture method, integrity record, and linkage to evaluated evidence.</p><p>Screenshot is an artifact.</p><p>Evidence is a supported claim.</p><p>Report is narrative.</p><p>Do not let the report enlarge the claim.</p><h2>Related Reading</h2><ul><li><p><a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Compliance Automation Starts at Evidence</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/read-only-collection-as-an-audit">Read-Only Collection as an Audit Boundary</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p></li></ul><div><hr></div><h2>Origin</h2><p><strong>Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</strong></p><p>Website: <a href="https://www.codeyourcompliance.com/">https://www.codeyourcompliance.com/</a></p><p>GitHub: <a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p>Attribution is requested for forks, references, adaptations, and public discussion.</p><h2>Scope Boundary</h2><p>MAS TRM-inspired means engineering interpretation.</p><p>This material is not legal, regulatory, audit, certification, implementation, or compliance advice.</p>]]></content:encoded></item><item><title><![CDATA[What a MAS TRM Checklist Cannot Prove]]></title><description><![CDATA[A completed checklist can organize audit readiness. It cannot prove system state. Proof requires timestamped, source-bound, integrity-checked evidence.]]></description><link>https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Mon, 25 May 2026 07:30:52 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/46bae53b-f2a3-4c53-b64c-fefed6e6eb61_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A team completes its MAS TRM-aligned checklist.</p><p>Every row is marked complete.</p><p>The control owner is assigned.</p><p>Evidence links are attached.</p><p>A report is prepared.</p><p>Then a reviewer asks:</p><blockquote><p>When was the TLS certificate state observed?</p></blockquote><p>Nobody answers cleanly.</p><p>Which endpoint was inspected?</p><p>Who collected the evidence?</p><p>Was the required scope complete?</p><p>Did the collector change the target?</p><p>Has the evidence changed since collection?</p><p>Did the policy result evaluate the same evidence object?</p><p>The checklist still looks complete.</p><p>The evidence chain does not.</p><p>That is the failure mode.</p><p>A checklist can organize compliance work. It cannot by itself establish that a technical condition was true at a specific time.</p><p>MAS TRM is the context. It does not prescribe this checklist, evidence schema, collector, or policy pipeline.</p><p>MAS TRM-inspired means engineering interpretation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AxfI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AxfI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!AxfI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!AxfI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!AxfI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AxfI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1312590,&quot;alt&quot;:&quot;Alt text: An infographic showing a completed compliance checklist and narrative report on the left, separated by a broken chain from a structured evidence object on the right. The evidence object includes metadata fields such as observed_at, source_system, collector, collection_method, integrity_hash, and policy_result_ref. A policy result box shows invalid_evidence, illustrating that a completed checklist is not proof without verifiable evidence metadata.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.codeyourcompliance.com/i/199146774?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Alt text: An infographic showing a completed compliance checklist and narrative report on the left, separated by a broken chain from a structured evidence object on the right. The evidence object includes metadata fields such as observed_at, source_system, collector, collection_method, integrity_hash, and policy_result_ref. A policy result box shows invalid_evidence, illustrating that a completed checklist is not proof without verifiable evidence metadata." title="Alt text: An infographic showing a completed compliance checklist and narrative report on the left, separated by a broken chain from a structured evidence object on the right. The evidence object includes metadata fields such as observed_at, source_system, collector, collection_method, integrity_hash, and policy_result_ref. A policy result box shows invalid_evidence, illustrating that a completed checklist is not proof without verifiable evidence metadata." srcset="https://substackcdn.com/image/fetch/$s_!AxfI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!AxfI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!AxfI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!AxfI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd535f419-109f-4bc3-bf74-b77b50193e7d_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A completed checklist can still leave the proof chain broken if the evidence object lacks timestamp, source system, collector metadata, integrity hash, and policy result reference.</figcaption></figure></div><h2>A checklist is a coordination object</h2><p>A checklist is useful.</p><p>It can record:</p><ul><li><p>the control topic;</p></li><li><p>the assigned owner;</p></li><li><p>the review status;</p></li><li><p>the requested artifact;</p></li><li><p>and the completion date.</p></li></ul><p>A signed checklist may also show that an attestation, review, or approval occurred.</p><p>That is evidence of a process action.</p><p>It is not the same as evidence of the underlying system state.</p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">A row marked &#8220;TLS certificate valid&#8221; does not establish:</mark></p><ul><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">which certificate was observed;</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">which endpoint presented it;</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">when it was observed;</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">whether all in-scope endpoints were checked;</mark></p></li><li><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">or whether the evidence came from an authoritative source.</mark></p></li></ul><p>The checklist records the workflow around the claim.</p><p>The evidence object supports the claim itself.</p><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/3bbnt/1/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e3a84ce-d8bd-4eab-97e1-bcf523992d07_1220x578.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8cd2ac4c-cef5-4510-acc9-1999b6412bb8_1220x702.png&quot;,&quot;height&quot;:348,&quot;title&quot;:&quot;Completion is not control effectiveness&quot;,&quot;description&quot;:&quot;A completed row may mean several different things.&quot;}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/3bbnt/1/" width="730" height="348" frameborder="0" scrolling="no"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><h2>The green status is a narrative state.</h2><p>It is not automatically a technical state.</p><p>The control may operate on some systems but not the full scope.</p><p>It may have operated at the time of review but failed later.</p><p>It may have been remediated before the original failure was preserved.</p><p>A checklist cannot resolve those questions without linked evidence requirements.</p><h2>Each row needs an evidence contract</h2><p>The useful extension to a checklist is not another comments column.</p><p>It is an evidence contract.</p><p>For &#8220;TLS certificate satisfies the approved expiry policy,&#8221; the evidence requirement might include:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;yaml&quot;,&quot;nodeId&quot;:&quot;31328112-0fdf-4ea1-95e9-8399679689af&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-yaml">target_id: production-load-balancer
evidence_type: tls_certificate_observation
observed_at: 2026-05-25T10:31:00Z
collector_id: tls-cert-collector
collector_version: 0.1.0
collection_status: success
certificate_not_after: 2026-09-01T00:00:00Z
integrity_hash: sha256:...
policy_result_ref: policy-results/tls-cert-valid-2026-05-25.json</code></pre></div><p>Each field answers a different challenge.</p><blockquote><p><code>target_id</code> identifies what was inspected.</p><p><code>observed_at</code> anchors the observation in time.</p><p><code>collector_id</code> identifies the process that produced the output.</p><p><code>collection_status</code> prevents failed collection from silently becoming a control result.</p><p><code>integrity_hash</code> helps detect mutation after sealing.</p><p><code>policy_result_ref</code> links the conclusion to the evidence actually evaluated.</p></blockquote><p>The schema does not prove control effectiveness.</p><p>It makes the basis of the judgment inspectable.</p><p>For the upstream model, see <a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Compliance Automation Starts at Evidence</a>.</p><h2>An attachment is not automatically evidence</h2><p>A checklist may accept anything that can be uploaded.</p><p>A screenshot.</p><p>A PDF export.</p><p>An email confirmation.</p><p>A spreadsheet.</p><p>A meeting note.</p><p>These artifacts may support a review.</p><p>They do not automatically establish provenance, scope, freshness, integrity, or source authority.</p><p>A screenshot may show a screen without identifying the endpoint or capture time.</p><p>A spreadsheet may list users without showing whether it came from the authoritative identity system.</p><p>A PDF may record approval without proving that the approved data matches the data used in policy evaluation.</p><p>The problem is not the file format.</p><p>The problem is the unsupported claim.</p><p>Data alone is not evidence.</p><p>Provenance makes it usable.</p><h2>Observation and remediation need separate records</h2><p>A team observes that logging is disabled.</p><p>Someone enables logging.</p><p>The row becomes green.</p><p>The report says the issue is resolved.</p><p>But several events occurred:</p><ol><li><p>The original state was observed.</p></li><li><p>A remediation action was approved.</p></li><li><p>The configuration was changed.</p></li><li><p>The post-change state was checked.</p></li><li><p>The checklist status was updated.</p></li></ol><p>These are not one evidence object.</p><p>The original observation supports the finding.</p><p>The change record supports the remediation action.</p><p>The later observation supports post-change verification.</p><p>The checklist coordinates the sequence.</p><p>If the original evidence is replaced by a clean post-remediation screenshot, the audit trail loses the failure it claims to have corrected.</p><p>For that boundary, see <a href="https://www.codeyourcompliance.com/p/read-only-collection-as-an-audit">Read-Only Collection as an Audit Boundary</a>.</p><h2>Evidence states must remain separate</h2><p>A binary checklist encourages <code>pass</code> or <code>fail</code>.</p><p>The evidence pipeline needs more precise states.</p><blockquote><p><code>control_fail</code> means valid evidence was collected, but the observed state did not satisfy the policy.</p><p><code>invalid_evidence</code> means evidence was supplied, but its integrity, provenance, identity, or linkage cannot be relied upon.</p><p><code>insufficient_evidence</code> means required evidence is missing, incomplete, stale, or outside the intended scope.</p></blockquote><p>These states are not interchangeable.</p><p>Missing evidence does not prove control failure.</p><p>A failed hash does not prove non-compliance.</p><p>A green checklist row does not repair either problem.</p><h2>The useful chain</h2><pre><code><code>Control expectation
&#8594; Checklist item
&#8594; Evidence requirement
&#8594; Evidence object
&#8594; Validation result
&#8594; Policy result
&#8594; Audit narrative</code></code></pre><p>The checklist coordinates the work.</p><p>The evidence object preserves the observation.</p><p>Validation determines whether the evidence is usable.</p><p>Policy evaluation tests a defined condition.</p><p>The report explains the result.</p><p>For the later verification test, see <a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a>.</p><h2>The position</h2><p>A checklist can show that work was assigned, reviewed, attested, or closed.</p><p>It cannot by itself establish the underlying technical state.</p><p>It cannot prove complete scope.</p><p>It cannot prove continuous operation.</p><p>It cannot prove that the attached artifact was the object used for policy evaluation.</p><p>Checklist is coordination.</p><p>Evidence is proof material.</p><p>Policy evaluation is judgment.</p><p>Report is narrative.</p><p>Do not confuse them.</p><h2>Related Reading</h2><ul><li><p><a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Compliance Automation Starts at Evidence</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/read-only-collection-as-an-audit">Read-Only Collection as an Audit Boundary</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p></li></ul><div><hr></div><h2>Origin</h2><p><strong>Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</strong></p><p>Website: <a href="https://www.codeyourcompliance.com/">https://www.codeyourcompliance.com/</a></p><p>GitHub: <a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p>Attribution is requested for forks, references, adaptations, and public discussion of this material.</p><h2>Scope Boundary</h2><p>MAS TRM-inspired means engineering interpretation.</p><p>This material is not legal, regulatory, audit, certification, implementation, or compliance advice.</p>]]></content:encoded></item><item><title><![CDATA[Can Your Audit Evidence Survive Replay?]]></title><description><![CDATA[A short CodeYourCompliance note on evidence replay in MAS TRM-inspired compliance automation. It explains why audit evidence must be timestamped, sealed, verified, policy-evaluable, and replayable before it can support a defensible compliance conclusion.]]></description><link>https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Tue, 19 May 2026 09:16:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!voo_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>An audit pack can look complete and still fail as evidence.</p><p>It may contain screenshots, exported reports, configuration files, approval notes, and signed control narratives. A reviewer may be able to read it. A manager may be able to approve it. A report may already have been produced from it.</p><p>That does not mean the evidence can survive replay.</p><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Replayable audit evidence is evidence that a later reviewer can identify, verify, re-evaluate, and compare with the original audit result without relying on the original operator&#8217;s memory.</mark></strong></p><p>Replay is not opening the same report again.</p><p>Replay is not generating a new export from the current system.</p><p>Replay is not running the latest policy against the latest data.</p><p>A replay must preserve the evidence and the context that produced the original decision.</p><p>The failure starts before the report. It starts when nobody can establish when the evidence was collected, where it came from, whether it changed after collection, or whether the policy result was produced from the same evidence object shown in the audit pack.</p><p>That is not a reporting problem.</p><p>It is an evidence integrity problem.</p><p>Compliance automation is not about producing cleaner reports. It is about making evidence harder to fake, harder to mutate, and easier to replay.</p><div class="callout-block" data-callout="true"><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A report can persuade.</mark></strong></p><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Evidence must survive.</mark></strong></p></div><h2>The replay question</h2><p>Take one evidence item from an audit pack.</p><p>Ask:</p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can you identify the exact evidence object used in the original evaluation?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can you establish when it was collected?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can you identify what collected it?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can you identify the source system and target scope?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can you verify that it has not changed since it was sealed?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can you identify the policy version that evaluated it?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can the policy result be traced back to this exact evidence object?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can the replayed result be compared with the original result?</mark></p></li></ul><p>If the answer is no, the evidence may still be useful documentation.</p><p>It may help a reviewer understand the environment.</p><p>It may support an audit narrative.</p><p>But it is not yet strong replayable evidence.</p><p>Documentation helps explain.</p><p>Replayable evidence preserves the path to the decision.</p><h2>The evidence object comes first</h2><p>The first structure in a compliance automation pipeline is not the report.</p><p>It is the evidence object.</p><p>A minimum evidence object should be:</p><ul><li><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">timestamped</mark></strong></p></li><li><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">source-bound</mark></strong></p></li><li><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">scope-bound</mark></strong></p></li><li><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">collector-identified</mark></strong></p></li><li><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">integrity-sealed</mark></strong></p></li><li><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">verified before evaluation</mark></strong></p></li><li><p><strong><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">linked to a specific policy result</mark></strong></p></li></ul><p>Without these properties, the later audit narrative is built on unstable ground.</p><p>This is where many compliance automation efforts start too late. They begin with dashboards, templates, report generators, and control mappings.</p><p>Those may be useful.</p><p>They sit downstream.</p><p>If the evidence object cannot be trusted, the report only makes an untrusted object easier to read.</p><p>That is formatting, not assurance.</p><p>For the broader evidence-object model, see <a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Compliance Automation Starts at Evidence</a>.</p><h2>A hash proves integrity, not truth</h2><p>A cryptographic hash can help establish that a preserved file has not changed since it was sealed.</p><p>That boundary must remain explicit.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A valid hash does not prove that:</mark></p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">the collector observed the correct target;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">the collection covered the required scope;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">the collector operated correctly;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">the source system was authoritative;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">or the evidence was sufficient for the control being evaluated.</mark></p></li></ul><p>A perfectly sealed object can still be incomplete, stale, incorrectly scoped, or collected from the wrong source.</p><p>Integrity is necessary.</p><p>Integrity is not sufficiency.</p><h2>Replay also requires policy context</h2><p>Preserving the evidence object is not enough.</p><p>The original policy context must also survive.</p><p>If the policy logic, supporting data, or input schema has changed, a later evaluation may still be valid. But it is a new evaluation, not a replay of the original decision.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">At minimum, the audit record should identify:</mark></p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">the policy;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">the policy version;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">the evidence object evaluated;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">the original result;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">and the time of evaluation.</mark></p></li></ul><p>Where supporting policy data affects the outcome, that context must also be preserved or referenced.</p><p>OPA should not evaluate raw trust.</p><p>It should evaluate verified evidence.</p><p>The result should remain traceable to the evidence and policy context that produced it.</p><h2>Do not collapse different failure states</h2><p>If the evidence hash fails, the correct result is not automatically <code>non_compliant</code>.</p><p>A failed integrity check means the evidence cannot safely support the evaluation.</p><p>That is an evidence-state failure.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">At minimum, distinguish three outcomes:</mark></p><h3><code>control_fail</code></h3><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The evidence is usable, but the observed system state does not satisfy the defined control condition.</mark></p><h3><code>invalid_evidence</code></h3><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The evidence failed integrity, schema, provenance, or other admissibility checks.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The control should not be evaluated as though the evidence were valid.</mark></p><h3><code>replay_mismatch</code></h3><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The intended evidence and policy context were replayed, but the result differed from the original recorded result.</mark></p><p>That indicates an inconsistency in the evaluation path.</p><p>It is not automatically a control failure.</p><p>A failed control says the observed state did not meet the expected condition.</p><p>Invalid evidence says the audit cannot safely determine whether the condition was met.</p><p>A replay mismatch says the decision path cannot be reproduced consistently.</p><p>Do not mix them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!voo_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!voo_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!voo_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!voo_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!voo_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!voo_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Diagram showing an evidence replay test for compliance automation.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram showing an evidence replay test for compliance automation." title="Diagram showing an evidence replay test for compliance automation." srcset="https://substackcdn.com/image/fetch/$s_!voo_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!voo_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!voo_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!voo_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df0a9a6-1d2b-4998-bc37-a43816a9045c_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Evidence should not only support an audit result once. It should survive replay.</figcaption></figure></div><h2>MAS TRM-inspired, not MAS TRM-prescribed</h2><p>MAS TRM-inspired compliance automation should not be treated as a claim that MAS prescribes this implementation.</p><p>It is an engineering interpretation of supervisory expectations.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The useful question is not:</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can we generate a report that sounds aligned?</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The useful question is:</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can we produce evidence that can be collected, identified, sealed, verified, evaluated, and replayed?</mark></p><p>A MAS TRM-inspired evidence pipeline should keep four layers separate:</p><ol><li><p><strong>Collection captures a bounded system state.</strong></p></li><li><p><strong>Evidence validation checks integrity, structure, and provenance.</strong></p></li><li><p><strong>Policy evaluation tests verified evidence against defined conditions.</strong></p></li><li><p><strong>The audit narrative explains the result and its limitations.</strong></p></li></ol><p>If these layers collapse into one report, the audit surface becomes fragile.</p><p>For the checklist boundary, see <a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a>.</p><h2>A short self-test</h2><p>Before treating an audit pack as automation-ready, test one evidence object.</p><p>Ask:</p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Does it include a collection timestamp?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Does it identify the source system and target scope?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Does it identify the collector?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Is there an integrity hash or equivalent seal?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Was integrity verified before policy evaluation?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Is the policy version identifiable?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Is the result tied to this exact evidence object?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can the original and replayed results be compared?</mark></p></li></ul><p>This is not a remediation checklist.</p><p>It does not tell the operator how to fix the system.</p><p>It does not certify the control.</p><p>It tests whether the evidence can support a replayable audit conclusion.</p><blockquote><p><strong>Observation is not remediation.</strong></p><p><strong>Evidence is not a report.</strong></p><p><strong>A control is not proof.</strong></p><p><strong>A hash is not truth.</strong></p><p><strong>A rerun is not necessarily a replay.</strong></p></blockquote><p>The audit problem starts earlier.</p><p>If the evidence cannot survive replay, the report should not pretend to be stronger than the evidence beneath it.</p><p>Reports persuade.</p><p>Evidence survives.</p><h2>Continue the evidence path</h2><p>Replay only works if the surrounding evidence pipeline preserves its boundaries.</p><ul><li><p><a href="https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence">Compliance Automation Starts at Evidence</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/read-only-collection-as-an-audit">Read-Only Collection as an Audit Boundary</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/what-a-mas-trm-checklist-cannot-prove">What a MAS TRM Checklist Cannot Prove</a></p></li></ul><div><hr></div><h2>Origin</h2><p><strong>Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</strong></p><p>Website: <a href="https://www.codeyourcompliance.com/">https://www.codeyourcompliance.com/</a></p><p>GitHub: <a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p>Attribution is requested for forks, references, adaptations, and public discussion of this material.</p><h2>Scope Boundary</h2><p>MAS TRM-inspired means engineering interpretation.</p><p>This material is not legal, regulatory, audit, certification, implementation, or compliance advice.</p>]]></content:encoded></item><item><title><![CDATA[AI Vendor Risk Assessment: Vendor Claim Is Not Evidence]]></title><description><![CDATA[Vendor claim is not evidence. A practical AI vendor risk assessment guide for turning vendor statements into evidence requests, buyer questions, and usage boundaries.]]></description><link>https://www.codeyourcompliance.com/p/start-here-ai-vendor-risk-pack</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/start-here-ai-vendor-risk-pack</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Tue, 12 May 2026 04:38:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pznK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pznK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pznK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!pznK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!pznK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!pznK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pznK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1397560,&quot;alt&quot;:&quot;CodeYourCompliance banner showing AI vendor risk assessment documents under review with a magnifying glass, evidence icons, and the tagline &#8220;Vendor claim is not evidence.&#8221;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.codeyourcompliance.com/i/197306325?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="CodeYourCompliance banner showing AI vendor risk assessment documents under review with a magnifying glass, evidence icons, and the tagline &#8220;Vendor claim is not evidence.&#8221;" title="CodeYourCompliance banner showing AI vendor risk assessment documents under review with a magnifying glass, evidence icons, and the tagline &#8220;Vendor claim is not evidence.&#8221;" srcset="https://substackcdn.com/image/fetch/$s_!pznK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!pznK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!pznK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!pznK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a64a907-f9c7-4ab6-8fb0-5deb9ab5fe85_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Vendor claim is not evidence. AI vendor risk assessment starts with evidence gaps.</figcaption></figure></div><p>AI vendor risk assessment is not mainly a questionnaire problem.</p><p>It is an evidence conversion problem.</p><p>Most teams already have vendor questionnaires. They ask about security, privacy, subprocessors, SOC 2, access control, incident response, data retention, and contractual terms.</p><p>That is useful.</p><p>But it is not enough.</p><p>A vendor can answer every question and still leave the buyer without reviewable evidence.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The harder question is not:</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Did the vendor answer?</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The harder question is:</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Can the buyer rely on this answer later?</mark></p><p>That is the purpose of AI Vendor Evidence Gap Pack.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It helps buyers and reviewers turn AI vendor claims into evidence requests, weak-answer patterns, buyer questions, review notes, and usage boundaries.</mark></p><p>It does not approve vendors.</p><p>It shows where the vendor&#8217;s claim stops and where the buyer still lacks evidence.</p><h2>Problem</h2><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">A vendor may say:</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">We do not train on your data.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">That may be true.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">But a review should not stop there.</mark></p><p>The buyer still needs to know what &#8220;training&#8221; means. Does it include fine-tuning, evaluation, abuse monitoring, support review, retained logs, human review, embeddings, metadata, subprocessors, or model providers?</p><p>The buyer also needs to know where the claim appears.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A DPA clause is not the same as a marketing page.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A SOC 2 report is not automatically proof that the specific AI feature, model path, data flow, or product tier is covered.</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A trust center can provide useful source material, but it is not a completed risk assessment.</mark></p><p>The problem is not that every vendor claim is false.</p><p>The problem is that many vendor claims remain narrative claims.</p><p>They sound reassuring. They may be directionally useful. But they do not automatically become evidence requests, evidence gaps, buyer questions, review notes, or residual risk language.</p><p>That creates a gap in the review file.</p><p>If the vendor is approved or renewed, the buyer may still be unable to explain why the answer was accepted.</p><h2>What this pack does</h2><p>AI Vendor Evidence Gap Pack converts vendor-controlled language into reviewable structure:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">AI vendor claim -&gt; evidence source -&gt; evidence gap -&gt; buyer question -&gt; usage boundary</mark></p><p>This is not a longer questionnaire.</p><p>A questionnaire collects answers.</p><p>This pack helps review whether those answers are evidence-complete.</p><p>For each claim, the review asks:</p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What exactly is being claimed?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Where is the claim written?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Is the source contractual, audited, official, public, marketing, or unsupported?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Does it cover the actual product, plan, region, and use case?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Does it cover the relevant data path?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What is missing?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What should the buyer ask next?</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">What usage boundary is reasonable until the missing evidence is resolved?</mark></p></li></ul><p>The output is not a pass or fail conclusion.</p><p>The output is evidence structure.</p><h2>Example</h2><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">Vendor claim:</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">We do not train on your data.</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">Why it sounds sufficient:</mark></p><p><mark data-color="#cfe2f3" style="background-color: rgb(207, 226, 243); color: rgb(0, 0, 0);">It appears to answer the main AI privacy concern.</mark></p><blockquote><p><em>What it actually proves:</em></p><p>It may support a narrow commitment about model training, depending on the source, scope, product, plan, contract, and date.</p><p><em>What it does not prove:</em></p><p>It does not prove prompt logging, output storage, file retention, metadata handling, embeddings, abuse monitoring, support access, human review, subprocessors, deletion controls, retention period, data residency, audit logs, or exportability.</p><p><em>Weak-answer pattern:</em></p><p>The vendor repeats that it does not train on customer data, but does not define training, retention, logging, evaluation, human review, support access, subprocessors, or exceptions.</p><p><em>Evidence request:</em></p><p>Provide the data flow for prompts, outputs, uploaded files, logs, embeddings, metadata, moderation events, support access, subprocessors, model providers, and human review queues. Include retention period, access roles, deletion controls, tenant settings, contractual commitments, and documented exceptions.</p><p><em>Review note:</em></p><p>The claim is directionally useful but not evidence-complete. It addresses model training use, but does not establish how operational data is handled after inference.</p><p><em>Usage boundary:</em></p><p>Do not rely on this claim for customer data, confidential data, regulated data, proprietary source code, or production approval until retention, logging, human review, subprocessor, and deletion boundaries are evidenced.</p></blockquote><p>The point is not to accuse the vendor.</p><p>The point is to avoid accepting a claim before it becomes reviewable evidence.</p><h2>Who it is for</h2><p>This pack is for people involved in AI vendor review before procurement, renewal, internal approval, or audit preparation.</p><p>That includes security reviewers, compliance teams, procurement operators, privacy leads, IT managers, founders, operators, and small teams adopting AI tools.</p><p>It is especially useful for teams that do not yet have a mature AI vendor review process, but still need to ask defensible questions before real data use.</p><p>The review should not start with the vendor name alone.</p><p>The real review unit is:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">vendor + product + plan + use case + data type + region + contract terms + evidence date</mark></p><p>The same vendor may be acceptable for public marketing drafts and not acceptable for customer records, source code, employee data, regulated data, or automated decisioning.</p><p>Context matters.</p><h2>What it is not</h2><p>AI Vendor Evidence Gap Pack is not certification, vendor rating, legal advice, regulatory advice, audit opinion, procurement approval, compliance guarantee, or a pass/fail conclusion.</p><p>It is not a substitute for legal, security, privacy, audit, procurement, or business owner review.</p><p>It is also not a generic AI governance checklist.</p><p>The product boundary is simple:</p><div class="callout-block" data-callout="true"><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Evidence gap review, not approval.</mark></p></div><h2>Reading path</h2><p>Each claim teardown follows the same review path:</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">vendor claim &#8594; evidence source &#8594; evidence gap &#8594; buyer question &#8594; usage boundary</mark></p><p>Start with the core frame:</p><ol><li><p><a href="https://www.codeyourcompliance.com/p/ai-vendor-risk-is-not-a-questionnaire">AI Vendor Risk Is Not a Questionnaire Problem</a></p></li></ol><p>Then read the claim teardowns:</p><ol start="2"><li><p><a href="https://www.codeyourcompliance.com/p/vendor-says-it-does-not-train-on">Vendor Says It Does Not Train on Your Data. What Evidence Should You Ask For?</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/a-trust-center-is-not-an-ai-vendor">A Trust Center Is Not an AI Vendor Risk Assessment</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/why-soc-2-does-not-prove-the-ai-vendor">Why SOC 2 Does Not Prove the AI Vendor Data Path Is Covered</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/human-review-is-a-data-exposure-path">Human Review Is a Data Exposure Path Unless It Is Bounded</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/subprocessor-lists-do-not-show-the">Subprocessor Lists Do Not Show the Actual AI Data Path</a></p></li></ol><h2>Boundary</h2><p>This material is for evidence structuring and review preparation.</p><p>It does not provide legal, regulatory, audit, procurement, certification, or implementation advice.</p><p>I now have a sanitized sample evidence gap memo showing how this looks in a review file.</p><p>Reply if you want the sample.</p>]]></content:encoded></item><item><title><![CDATA[Compliance Automation Starts at Evidence]]></title><description><![CDATA[Compliance automation should start with verifiable evidence, not reports. This article explains a MAS TRM-inspired evidence pipeline using read-only collection, timestamped evidence, hash sealing, OPA evaluation, and audit narratives.]]></description><link>https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence</link><guid isPermaLink="false">https://www.codeyourcompliance.com/p/compliance-automation-starts-at-evidence</guid><dc:creator><![CDATA[CodeYourCompliance]]></dc:creator><pubDate>Mon, 11 May 2026 07:29:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PnvS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Most audit packs are built after the fact.</p><p>That is the weakness.</p><p>The screenshot is taken after the audit request arrives. The log export is prepared after the system has moved on. The control owner writes how the process is supposed to work.</p><p>The report becomes coherent.</p><p>Coherence is not proof.</p><p>Compliance evidence automation is not template filling. It means collecting bounded observations from source systems, preserving provenance, validating integrity, evaluating policy, and producing a reviewable evidence package.</p><p>A clean audit pack can still be built on weak evidence.</p><p>That is the problem compliance automation must solve first.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PnvS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PnvS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!PnvS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!PnvS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!PnvS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PnvS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Diagram of a six-step compliance evidence pipeline from system state to audit narrative.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram of a six-step compliance evidence pipeline from system state to audit narrative." title="Diagram of a six-step compliance evidence pipeline from system state to audit narrative." srcset="https://substackcdn.com/image/fetch/$s_!PnvS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!PnvS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!PnvS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!PnvS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a0fccd-f257-4b77-959c-b957e55fda17_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Evidence comes first. Policy evaluates only after the evidence is sealed.</figcaption></figure></div><h2>The report is too late</h2><p>A report is downstream.</p><p>It cannot rescue stale evidence.</p><p>It cannot repair a missing timestamp.</p><p>It cannot establish which source system was observed.</p><p>It cannot prove that the evidence remained unchanged after collection.</p><p>Most automation starts at the wrong layer.</p><p>It generates summaries.</p><p>It fills templates.</p><p>It writes control narratives.</p><p>That saves labour.</p><p>It does not harden evidence.</p><h2>Evidence needs provenance</h2><p>Data alone is not evidence.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">An evidence object should tell us:</mark></p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">what was observed;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">when it was observed;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">where it came from;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">what collected it;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">whether it changed after collection;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">and which policy result was produced from it.</mark></p></li></ul><p>Without that structure, the reviewer may have data but not a defensible audit trail.</p><p>A file name is not provenance.</p><p>A screenshot without capture context is not a complete evidence object.</p><p>A manually entered timestamp is only an assertion unless the collection process supports it.</p><p>An evidence object becomes replayable only when its identity, provenance, integrity state, and policy context can be reconstructed later.</p><p>For the replay test, see <a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a>.</p><h2>Collection is not correction</h2><p>The collector should not fix the system.</p><p>If collection changes the target, the failed state may disappear before it is recorded.</p><p>Operations may like that.</p><p>Audit should not.</p><p>Read-only collection is not a tooling preference.</p><p>It is restraint.</p><p>Pull the configuration.</p><p>Timestamp it.</p><p>Seal it.</p><p>Evaluate it.</p><p>Remediate later.</p><p>Observation and remediation are different jobs.</p><p>Read-only does not prove that collection was complete or correct. It preserves a narrower boundary: the collector is not intended to correct the state it is supposed to observe.</p><p>For that boundary, see <a href="https://www.codeyourcompliance.com/p/read-only-collection-as-an-audit">Read-Only Collection as an Audit Boundary</a>.</p><h2>Integrity comes before judgment</h2><p>A hash does not prove compliance.</p><p>It does not prove that the collector observed the correct system.</p><p>It does not prove that the required scope was complete.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">It proves a narrower claim:</mark></p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The preserved bytes match the bytes that were sealed.</mark></p><p>That is useful.</p><p>If integrity verification fails, the audit path should stop.</p><p>OPA should not evaluate evidence that has already failed its own integrity boundary.</p><p>The correct result is not automatically <code>non_compliant</code>.</p><p>It is <code>invalid_evidence</code>.</p><p>Bad evidence should not produce a clean result.</p><h2>OPA is not the system</h2><p><a href="https://www.openpolicyagent.org/">Open Policy Agent</a> is a policy evaluator.</p><p>Not a collector.</p><p>Not a repair tool.</p><p>Not an audit writer.</p><p>Its job is narrow: take validated evidence and evaluate whether the observed state satisfies a defined policy condition.</p><p>That narrowness is the point.</p><p>The collector observes.</p><p>The validator checks evidence.</p><p>OPA evaluates policy.</p><p>The audit narrative explains the result.</p><p>Policy should stay deterministic.</p><p>Narrative comes later.</p><h2>TLS shows the boundary</h2><p>Take an Apache HTTPS service.</p><p>The weak audit asks whether HTTPS is enabled.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The stronger audit asks:</mark></p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">when the certificate was observed;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">which endpoint was inspected;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">when the certificate expires;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">which signature algorithm was observed;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">whether the evidence was sealed;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">and whether it was verified before policy evaluation.</mark></p></li></ul><p>The first approach checks a claim.</p><p>The second preserves evidence.</p><p>A certificate expiring within 48 hours is not automatically a universal compliance failure.</p><p>It becomes a control result only when the applicable policy defines that threshold and the evidence is valid for the intended scope.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">The audit narrative should stay tied to that boundary:</mark></p><div class="callout-block" data-callout="true"><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">Based on verified TLS evidence collected at the recorded time, the observed certificate was within the policy-defined expiry threshold. The defined condition was therefore not satisfied for the evaluated endpoint.</mark></p></div><p>No legal conclusion.</p><p>No claim about the entire control environment.</p><p>Just evidence, condition, and result.</p><h2>MAS TRM-inspired means engineering interpretation</h2><p>MAS TRM is the context here.</p><p>It does not prescribe this schema, collector, OPA rule, or evidence pipeline.</p><p>MAS TRM-inspired means engineering interpretation.</p><p>The engineering task is not to rewrite regulatory language into softer prose.</p><p>It is to turn a control expectation into an inspectable evidence structure.</p><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">A control expectation needs:</mark></p><ul><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">a defined observation;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">an evidence schema;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">a collector;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">a timestamp;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">an integrity check;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">a policy condition;</mark></p></li><li><p><mark data-color="#fff2cc" style="background-color: rgb(255, 242, 204); color: rgb(0, 0, 0);">and an audit narrative.</mark></p></li></ul><p>The schema is not the control.</p><p>The policy result is not the entire audit conclusion.</p><p>That is the machine boundary.</p><h2>The position</h2><p>Compliance automation is not report automation.</p><p>Report automation makes audit packs faster.</p><p>Evidence automation makes control claims harder to fake, harder to mutate, and easier to replay.</p><p>That is the useful distinction.</p><p>Reports persuade.</p><p>Evidence survives.</p><h2>Related Reading</h2><ul><li><p><a href="https://www.codeyourcompliance.com/p/can-your-audit-evidence-survive-replay">Can Your Audit Evidence Survive Replay?</a></p></li><li><p><a href="https://www.codeyourcompliance.com/p/read-only-collection-as-an-audit">Read-Only Collection as an Audit Boundary</a></p></li></ul><div><hr></div><h2>Origin</h2><p><strong>Code<span data-color="#0000ff" style="color: rgb(0, 0, 255);">Your</span>Compliance</strong></p><p>Website: <a href="https://www.codeyourcompliance.com/">https://www.codeyourcompliance.com/</a></p><p>GitHub: <a href="https://github.com/codeyourcompliance">https://github.com/codeyourcompliance</a></p><p>Attribution is requested for forks, references, adaptations, and discussions.</p><h2>Scope Boundary</h2><p>MAS TRM-inspired means engineering interpretation.</p><p>This is not legal, regulatory, audit, certification, compliance, or implementation advice.</p>]]></content:encoded></item></channel></rss>