Across all modules
MaxArc Global Health Impact Platform
Data Quality, Evidence Provenance & Reconciliation Governance
Cross-module data quality, evidence provenance, and reconciliation with human approval.
A synthetic governance demonstration — not a production master-data-management system, live national data warehouse, certification engine, autonomous correction service, or replacement for source-system records. Source-module records remain authoritative; this module assesses and reconciles but never silently rewrites source records. No live integration, real database mutation, autonomous correction, or real file delivery is implemented. Every quality case identifies its source module, source record, owner, reporting period, dimensions, evidence, status, reviewer, and audit reference. AI is assistive only and never changes records, approves reconciliation or corrections, certifies quality, or closes escalations.
Under assessment
Evidence-backed
Unsupported / SoD
Independent review
Awaiting resolution
Remain visible
Candidates only
Need re-verification
Values in conflict
Between modules
Priority
Evidence present
Evidence verified
Dimension score
Dimension score
Dimension score
Dimension score
Awaiting approval
Remain visible
Remain visible
High-risk
Blocked or pending
Timeliness < 70%
Human review required
Append-only
Quality dimensions (distinct & explainable)
Completeness, validity, consistency, timeliness, uniqueness, conformity, provenance, and evidence strength remain distinct. Source data and derived quality signals remain distinguishable. Low confidence is never represented as verified fact.
- Completeness — Required fields and records are present.
- Validity — Values conform to defined formats and ranges.
- Consistency — Values agree across related records and modules.
- Timeliness — Records are captured and reported within expected windows.
- Uniqueness — Records are free of unreviewed duplicates.
- Conformity — Records conform to reference standards and code sets.
- Provenance — Record origin and capture chain are attributable.
- Evidence strength — Supporting evidence is present, verified, current, and non-conflicting.
Quality cases
Every case identifies source module, source record, owner, steward, reviewer, reporting period, dimensions assessed, evidence, status, and audit reference. Unresolved cases are never reported as reconciled.
| Case | Period / scope | Owner / dimensions | Status |
|---|---|---|---|
| DQC-001 fund-accountability · FUND-DISB-1187 |
RP-2025Q1 CN-A · FAC-A1 · PRG-HIV |
owner OWN-01 · steward STW-01 · reviewer REV-01 C 92 · V 98 · Cs 78 · T 88 · unique · partial |
open SoD compliant 2nd review audit: DQA-001 |
| DQC-002 stockpile-logistics · PROC-ORD-4421 |
RP-2025Q1 CN-A · FAC-B1 · PRG-MAL |
owner OWN-02 · steward STW-02 · reviewer REV-01 C 100 · V 100 · Cs 84 · T 75 · unique · verified |
reconciled SoD compliant audit: DQA-002 |
| DQC-003 stockpile-logistics · DISP-7781 |
RP-2025Q2 CN-A · FAC-B1 · PRG-MAL |
owner OWN-02 · steward STW-02 · reviewer REV-01 C 88 · V 100 · Cs 62 · T 70 · unique · missing |
blocked SoD violation 2nd review rule: SOD-006 audit: DQA-003 |
| DQC-004 stockpile-logistics · STOCK-BAL-A1-0925 |
RP-2025Q3 CN-A · FAC-A1 · PRG-TB |
owner OWN-02 · steward STW-02 · reviewer REV-01 C 96 · V 97 · Cs 71 · T 90 · unique · partial |
open SoD compliant audit: DQA-004 |
| DQC-005 lab-operations · LAB-ORD-3390 |
RP-2025Q2 CN-A · FAC-A1 · PRG-HIV |
owner OWN-03 · steward STW-01 · reviewer REV-01 C 100 · V 96 · Cs 100 · T 82 · unique · verified |
reconciled SoD compliant audit: DQA-005 |
| DQC-006 lab-operations · RES-55121 |
RP-2025Q2 CN-A · FAC-A1 · PRG-HIV |
owner OWN-03 · steward STW-01 · reviewer REV-01 C 90 · V 100 · Cs 66 · T 60 · unique · partial |
blocked SoD violation 2nd review rule: SOD-007 audit: DQA-006 |
| DQC-007 patient-continuity · REF-2201 |
RP-2025Q2 CN-A · FAC-A2 · PRG-TB |
owner OWN-04 · steward STW-01 · reviewer REV-01 C 74 · V 95 · Cs 70 · T 68 · unique · missing |
open SoD compliant audit: DQA-007 |
| DQC-008 restricted-patient-locator · LOC-REQ-770 |
RP-2025Q2 CN-A · FAC-A1 · PRG-HIV |
owner OWN-05 · steward STW-01 · reviewer REV-01 C 100 · V 100 · Cs 100 · T 95 · unique · verified |
reconciled SoD compliant 2nd review audit: DQA-008 |
| DQC-009 asset-management · ASSET-9032 |
RP-2025Q3 CN-A · FAC-A1 · PRG-MAL |
owner OWN-02 · steward STW-02 · reviewer REV-01 C 86 · V 100 · Cs 64 · T 72 · duplicate-candidate · partial |
open SoD compliant audit: DQA-009 |
| DQC-010 program-performance · PRG-RES-6612 |
RP-2025Q2 CN-A · FAC-A2 · PRG-TB |
owner OWN-04 · steward STW-02 · reviewer REV-01 C 100 · V 80 · Cs 58 · T 90 · unique · partial |
blocked SoD violation 2nd review rule: SOD-008 audit: DQA-010 |
| DQC-011 ai-intelligence · AIC-2050 |
RP-2025Q2 CN-A · FAC-A1 · PRG-HIV |
owner OWN-01 · steward STW-01 · reviewer REV-01 C 82 · V 90 · Cs 60 · T 88 · unique · partial |
open SoD compliant 2nd review audit: DQA-011 |
| DQC-012 country-rollout · RDY-CLAIM-330 |
RP-2025Q3 CN-B · FAC-B1 · PRG-MAL |
owner OWN-04 · steward STW-02 · reviewer REV-01 C 78 · V 92 · Cs 55 · T 80 · unique · missing |
blocked SoD compliant audit: DQA-012 |
| DQC-013 authorized-review-room · RR-CLAIM-91 |
RP-2025Q2 CN-A · FAC-A1 · PRG-HIV |
owner OWN-04 · steward STW-01 · reviewer REV-02 C 94 · V 96 · Cs 88 · T 85 · unique · verified |
reconciled SoD compliant audit: DQA-013 |
| DQC-014 executive-review-packet · PKT-CLAIM-14 |
RP-2025Q3 CN-A · FAC-A1 · PRG-HIV |
owner OWN-04 · steward STW-01 · reviewer REV-02 C 88 · V 85 · Cs 40 · T 82 · unique · conflicting |
blocked SoD violation 2nd review rule: SOD-010 audit: DQA-014 |
| DQC-015 identity-access-governance · IAG-DEC-508 |
RP-2025Q3 CN-A · FAC-A1 · PRG-HIV |
owner OWN-05 · steward STW-01 · reviewer REV-01 C 96 · V 100 · Cs 52 · T 70 · unique · partial |
open SoD violation 2nd review rule: SOD-011 audit: DQA-015 |
| DQC-016 fund-accountability · FUND-DISB-1188 |
RP-2025Q1 CN-A · FAC-A1 · PRG-HIV |
owner OWN-01 · steward STW-01 · reviewer REV-01 C 60 · V 90 · Cs 100 · T 40 · unique · missing |
open SoD compliant audit: DQA-016 |
Discrepancies
Conflicting evidence remains visible. Outliers are not automatically treated as fraud, error, or misconduct. Unsupported reconciliation claims remain blocked.
| Discrepancy | Type / severity | Expected vs observed | Status |
|---|---|---|---|
| DSC-001 DQC-001 |
value-variance medium | expected 100000 · observed 96500 rule RRULE-01 · tol ±2% |
unresolved expenditure below disbursement beyond tolerance |
| DSC-002 DQC-003 |
dispatch-receipt-gap high | expected 5000 · observed 4600 rule RRULE-03 · tol ±1% |
blocked receipt confirmation missing |
| DSC-003 DQC-004 |
balance-movement-gap medium | expected 795 · observed 820 rule RRULE-04 · tol ±1% |
unresolved recorded balance exceeds movement-derived balance |
| DSC-004 DQC-006 |
result-routing-mismatch high | expected routed · observed not-routed rule RRULE-06 · tol exact |
blocked restricted result not routed to clinician |
| DSC-005 DQC-010 |
target-result-implausible high | expected 1000 · observed 1380 rule RRULE-10 · tol ±10% |
blocked reported result implausibly exceeds target |
| DSC-006 DQC-014 |
claim-capability-contradiction high | expected planned · observed operational rule RRULE-14 · tol exact |
blocked packet claim contradicts verified capability state |
| DSC-007 DQC-015 |
access-expiration-contradiction medium | expected active · observed expired rule RRULE-15 · tol exact |
unresolved approved access decision with expired authorization still represented as active |
Reconciliation rules
Each rule declares source modules, compared fields, tolerance, exception handling, evidence requirements, human reviewer role, second-review requirement, escalation threshold, outcome states, and audit requirement.
| Rule | Compared fields | Reviewer / escalation | Outcomes |
|---|---|---|---|
| Fund disbursement versus expenditure evidence RRULE-01 · fund-accountability |
disbursedAmount, reportedExpenditure tol ±2% |
independent-reconciliation-reviewer · 2nd review escalate: variance > 5% or missing evidence |
reconciled open blocked escalated e.g. DQC-001 |
| Procurement order versus delivery evidence RRULE-02 · stockpile-logistics |
orderedQty, deliveredQty tol ±3% |
independent-reconciliation-reviewer escalate: shortfall > 5% |
reconciled open blocked e.g. DQC-002 |
| Warehouse dispatch versus receipt RRULE-03 · stockpile-logistics |
dispatchedQty, confirmedReceivedQty tol ±1% |
independent-reconciliation-reviewer · 2nd review escalate: missing receipt or gap > 2% |
reconciled blocked escalated e.g. DQC-003 |
| Stock balance versus movement history RRULE-04 · stockpile-logistics |
recordedBalance, movementDerivedBalance tol ±1% |
independent-reconciliation-reviewer escalate: divergence > 3% |
reconciled open e.g. DQC-004 |
| Laboratory order versus specimen versus result RRULE-05 · lab-operations |
orderId, specimenId, resultId tol exact linkage |
independent-reconciliation-reviewer escalate: broken linkage |
reconciled open blocked e.g. DQC-005 |
| Laboratory result versus clinician-routing status RRULE-06 · lab-operations |
resultStatus, routingStatus tol exact |
independent-reconciliation-reviewer · 2nd review escalate: restricted result not routed |
reconciled blocked escalated e.g. DQC-006 |
| Patient referral versus transfer versus follow-up RRULE-07 · patient-continuity |
referralId, transferId, followUpStatus tol exact linkage |
independent-reconciliation-reviewer escalate: missing follow-up beyond window |
reconciled open e.g. DQC-007 |
| Restricted-locator request versus disclosure decision RRULE-08 · restricted-patient-locator |
requestId, disclosureDecisionId tol exact linkage |
independent-reconciliation-reviewer · 2nd review escalate: decision-request linkage broken |
reconciled open blocked e.g. DQC-008 |
| Asset register versus custody verification RRULE-09 · asset-management |
registerStatus, custodyVerification tol exact |
independent-reconciliation-reviewer escalate: unverified custody on active asset |
reconciled open e.g. DQC-009 |
| Program target versus reported result RRULE-10 · program-performance |
targetValue, reportedValue, numerator, denominator tol ±10% |
independent-reconciliation-reviewer · 2nd review escalate: result > 120% of target or implausible denominator |
reconciled open blocked escalated e.g. DQC-010 |
| AI signal versus source evidence RRULE-11 · ai-intelligence |
aiSignal, sourceEvidenceRef tol confirmation-required |
independent-reconciliation-reviewer · 2nd review escalate: unconfirmed high-severity signal |
reconciled open e.g. DQC-011 |
| Rollout readiness claim versus dependency status RRULE-12 · country-rollout |
readinessClaim, dependencyStatus tol exact |
independent-reconciliation-reviewer escalate: readiness contradicts dependency |
reconciled blocked escalated e.g. DQC-012 |
| Review-room claim versus source-module evidence RRULE-13 · authorized-review-room |
reviewRoomClaim, sourceModuleEvidenceRef tol evidence-linkage |
compliance-reviewer escalate: claim without evidence |
reconciled open blocked e.g. DQC-013 |
| Executive packet claim versus verified capability state RRULE-14 · executive-review-packet |
packetClaim, verifiedCapabilityState tol exact |
compliance-reviewer · 2nd review escalate: claim contradicts capability state |
reconciled blocked escalated e.g. DQC-014 |
| Identity access decision versus approval and expiration status RRULE-15 · identity-access-governance |
approvalStatus, expirationStatus tol exact |
independent-reconciliation-reviewer · 2nd review escalate: expired access represented as active |
reconciled open escalated e.g. DQC-015 |
Separation-of-duties rules
Violations remain blocked or pending, identify the violated rule, require reassignment or second review, remain auditable, and are never silently overridden.
| Rule | Enforcement | Override / audit |
|---|---|---|
| Case creator cannot independently approve final reconciliation. SOD-001 |
blocked | never silently overridden auditable · e.g. DQC-001 |
| Correction requestor cannot approve their own correction. SOD-002 |
blocked | never silently overridden auditable · e.g. CR-003 |
| Evidence capturer cannot independently verify high-risk evidence. SOD-003 |
pending | never silently overridden auditable · e.g. EVD-010 |
| Source-data owner cannot independently close a disputed case where independent review is required. SOD-004 |
blocked | never silently overridden auditable · e.g. DQC-004 |
| Fund reconciliation preparer cannot independently certify the final outcome. SOD-005 |
blocked | never silently overridden auditable · e.g. DQC-001 |
| Warehouse dispatcher cannot independently reconcile a receipt discrepancy. SOD-006 |
blocked | never silently overridden auditable · e.g. DQC-003 |
| Laboratory result preparer cannot independently reconcile restricted result release. SOD-007 |
blocked | never silently overridden auditable · e.g. DQC-006 |
| Program-result submitter cannot independently approve a material correction. SOD-008 |
blocked | never silently overridden auditable · e.g. DQC-010 |
| AI case generator cannot independently close or certify the case. SOD-009 |
blocked | never silently overridden auditable · e.g. DQC-011 |
| Executive-packet author cannot independently reconcile unsupported claims. SOD-010 |
blocked | never silently overridden auditable · e.g. DQC-014 |
| Identity-access approver cannot independently resolve an audit discrepancy involving their own decision. SOD-011 |
blocked | never silently overridden auditable · e.g. DQC-015 |
Correction lifecycle (attributable & auditable)
- CR-001 — fund-accountability · reportedExpenditure proposed96500 → 100000 · requestor fund-accountant · approver independent-reconciliation-reviewer · source-system update proven: no
- CR-002 — stockpile-logistics · recordedBalance approved820 → 795 · requestor warehouse-manager · approver independent-reconciliation-reviewer · source-system update proven: no
- CR-003 — program-performance · reportedValue blocked SoD violation1380 → 980 · requestor program-result-submitter · approver program-result-submitter · source-system update proven: no
- CR-004 — asset-management · custodyVerification rejectednot-verified → verified · requestor warehouse-manager · approver independent-reconciliation-reviewer · source-system update proven: no
- CR-005 — patient-continuity · followUpStatus withdrawnmissing → completed · requestor program-manager · approver independent-reconciliation-reviewer · source-system update proven: no
- CR-006 — stockpile-logistics · deliveredQty reversed11800 → 12000 · requestor warehouse-manager · approver independent-reconciliation-reviewer · source-system update proven: no
- CR-007 — fund-accountability · supportingEvidence supersededEVD-018 → EVD-018-superseded · requestor fund-accountant · approver independent-reconciliation-reviewer · source-system update proven: no
- CR-008 — executive-review-packet · packetClaim requested SoD violationlive-dhis2-integration-operational → integration-planned · requestor executive-packet-author · approver compliance-reviewer · source-system update proven: no
The requestor cannot approve their own correction; the original record is never silently overwritten; rejected, withdrawn, reversed, and superseded corrections remain visible; correction approval does not prove a source-system update occurred.
Evidence provenance (presence ≠ verification)
- EVD-001 — disbursement-voucher present verified currentfund-accountability · case DQC-001 · expires 2025-09-05
- EVD-002 — expenditure-report present unverified currentfund-accountability · case DQC-001 · expires 2025-09-06
- EVD-003 — delivery-note present verified currentstockpile-logistics · case DQC-002 · expires 2025-08-20
- EVD-004 — receipt-confirmation missing missing currentstockpile-logistics · case DQC-003 · expires
- EVD-005 — movement-log present verified currentstockpile-logistics · case DQC-004 · expires 2026-03-10
- EVD-006 — specimen-chain-of-custody present verified currentlab-operations · case DQC-005 · expires 2025-11-11
- EVD-007 — routing-record present unverified currentlab-operations · case DQC-006 · expires 2025-11-14
- EVD-008 — follow-up-record missing missing currentpatient-continuity · case DQC-007 · expires
- EVD-009 — disclosure-decision-record present verified currentrestricted-patient-locator · case DQC-008 · expires 2025-11-02
- EVD-010 — custody-verification present unverified currentasset-management · case DQC-009 · expires 2026-02-01
- EVD-011 — result-source-document present unverified currentprogram-performance · case DQC-010 · expires 2025-12-20
- EVD-012 — ai-signal-source-link present unverified currentai-intelligence · case DQC-011 · expires 2025-12-01
- EVD-013 — dependency-status-record missing missing currentcountry-rollout · case DQC-012 · expires
- EVD-014 — source-module-evidence present verified currentauthorized-review-room · case DQC-013 · expires 2025-11-15
- EVD-015 — claim-source-a present verified currentexecutive-review-packet · case DQC-014 · expires 2026-01-01
- EVD-016 — capability-state-record present verified currentexecutive-review-packet · case DQC-014 · expires 2026-01-02
- EVD-017 — access-decision-record present unverified currentidentity-access-governance · case DQC-015 · expires 2026-02-15
- EVD-018 — expenditure-report present verified supersededfund-accountability · case DQC-016 · expires 2025-05-01
Cross-module contradictions
- XMC-001 — ai-intelligence ✕ fund-accountability mediumAI signal suggests duplicate disbursement; source ledger shows a single disbursement pending review · unresolved · human review: yes
- XMC-002 — executive-review-packet ✕ identity-access-governance highPacket claims operational integration while access to the integration is expired · blocked · human review: yes
Missing / stale / duplicate / outlier
- MIS-001 — follow-up visibleFollow-up record missing; remains visible and blocks reconciliation.
- MIS-002 — receipt-confirmation visibleReceipt confirmation missing; remains visible.
- STL-001 — FUND-DISB-1188 staleEvidence older than review window; must not support current verification without review.
- DUP-001 — ASSET-9032, ASSET-9032B candidateDuplicate asset candidate; remains a candidate until human review. Not auto-merged.
- DUP-002 — FUND-DISB-1187, FUND-DISB-1187R candidatePossible duplicate disbursement candidate flagged by AI; not confirmed.
- OUT-001 — result-far-above-target flagged-for-reviewtreated as fraud: no · Outlier flagged for human review; not automatically treated as fraud, error, or misconduct.
- OUT-002 — balance-movement-divergence flagged-for-reviewtreated as fraud: no · Outlier flagged for human review only.
Risk signals (human review required)
- value-variance — Fund disbursement and expenditure diverge beyond tolerance. mediumhuman review: yes · autonomous action: no · open
- missing-record — Warehouse receipt confirmation missing. highhuman review: yes · autonomous action: no · open
- balance-divergence — Recorded stock balance diverges from movement history. mediumhuman review: yes · autonomous action: no · open
- restricted-result-unrouted — Restricted lab result not routed to clinician. highhuman review: yes · autonomous action: no · open
- missing-followup — Follow-up record missing for completed transfer. mediumhuman review: yes · autonomous action: no · open
- duplicate-candidate — Possible duplicate asset record; remains a candidate until human review. mediumhuman review: yes · autonomous action: no · open
- outlier — Program result far above target; outlier not automatically classified as fraud or error. highhuman review: yes · autonomous action: no · open
- unconfirmed-ai-signal — AI duplicate-disbursement signal not yet confirmed against source evidence. mediumhuman review: yes · autonomous action: no · open
- unsupported-claim — Readiness claim contradicts an incomplete dependency. highhuman review: yes · autonomous action: no · open
- conflicting-evidence — Packet claim conflicts with verified capability state; conflicting verified evidence remains visible. highhuman review: yes · autonomous action: no · open
- expired-access-active — Approved access decision with expired authorization still represented as active. mediumhuman review: yes · autonomous action: no · open
- stale-evidence — Supporting evidence older than the review window. mediumhuman review: yes · autonomous action: no · open
Immutable audit events (append-only)
- DQA-001 — case-opened openindependent-reconciliation-reviewer · fund-accountability · 2025-03-08T09:05:00Z · immutable: yes
- DQA-002 — case-reconciled reconciledindependent-reconciliation-reviewer · stockpile-logistics · 2025-02-25T09:05:00Z · immutable: yes
- DQA-003 — case-blocked blockedindependent-reconciliation-reviewer · stockpile-logistics · 2025-06-01T09:05:00Z · immutable: yes
- DQA-006 — case-blocked blockedindependent-reconciliation-reviewer · lab-operations · 2025-05-15T09:05:00Z · immutable: yes
- DQA-010 — case-escalated blockedindependent-reconciliation-reviewer · program-performance · 2025-06-21T09:05:00Z · immutable: yes
- DQA-018 — correction-approved DQC-004-S1 correction of DQA-004independent-reconciliation-reviewer · stockpile-logistics · 2025-09-20T09:05:00Z · immutable: yes
- DQA-020 — correction-rejected DQC-009-S0independent-reconciliation-reviewer · asset-management · 2025-08-10T09:05:00Z · immutable: yes
- DQA-022 — correction-reversed DQC-002-S2 reversal of DQA-002independent-reconciliation-reviewer · stockpile-logistics · 2025-03-10T09:05:00Z · immutable: yes
- DQA-023 — evidence-superseded DQC-016-S1independent-reconciliation-reviewer · fund-accountability · 2025-05-02T09:05:00Z · immutable: yes
Audit events are append-only in this demonstration model; corrections and reversals require new linked events; deletion is not an allowed correction method; source-module audit records remain authoritative. This task does not implement a production cryptographic audit ledger.
Cases by module
- fund-accountability 2
- stockpile-logistics 3
- lab-operations 2
- patient-continuity 1
- restricted-patient-locator 1
- asset-management 1
- program-performance 1
- ai-intelligence 1
- country-rollout 1
- authorized-review-room 1
- executive-review-packet 1
- identity-access-governance 1
Cases by country
- CN-A 15
- CN-B 1
Cases by organization
- ORG-MOH-A 7
- ORG-IP-1 6
- ORG-AUDIT-1 1
- ORG-FUNDER-1 2
Cases by reporting period
- RP-2025Q1 3
- RP-2025Q2 8
- RP-2025Q3 5
AI posture — assistive only, non-autonomous
AI assists with
- detect missing, stale, duplicate, inconsistent, or outlier records
- compare values across authorized source modules
- identify evidence gaps
- identify conflicting evidence
- prioritize high-risk quality cases
- suggest reconciliation rules
- suggest correction candidates
- detect expired evidence
- identify unresolved dependencies
- summarize case history for authorized reviewers
- recommend cases for second review or escalation
- reconcile metadata and reference mappings
AI must never
- autonomously change source records
- autonomously approve reconciliation
- autonomously approve corrections
- autonomously certify data quality
- autonomously classify an outlier as fraud or misconduct
- autonomously suppress conflicting evidence
- autonomously delete missing, duplicate, or stale records
- autonomously fabricate evidence
- autonomously resolve disputed values
- autonomously close escalations
- bypass human approval, second review, separation of duties, evidence, expiration, or audit controls
AI is assistive only. It surfaces quality signals, comparisons, and candidates for authorized human reviewers and never changes source records, approves reconciliation or corrections, certifies quality, or closes escalations.
Runtime boundary & module coverage
- Impact runtime:
impact.maxarchealth.comon127.0.0.1:3201. - Assesses and reconciles records from fund accountability, stockpile & logistics, lab operations, patient continuity, restricted locator, asset management, program performance, AI intelligence, country rollout, the authorized review room, the executive review packet & controlled download center, and identity & access governance — without coupling to MaxTrax EHR.
- Medical Library boundary remains separate at
library.maxarchealth.com(port3101) and is not used here. - MaxTrax EHR remains separate; this is not a full EHR and implements no live integration or real database mutation.