MaxArc Global Health Impact Platform

Policy, Compliance, Control Testing & Attestation Governance

FOR GLOBAL FUND / CCM / AUTHORIZED PARTNER REVIEW ONLY
Policy · Compliance obligation · Control mapping · Control testing · Exception · Remediation · Attestation · Waiver · Immutable audit · Demonstration only

Cross-module policy, compliance, control-testing, and human-attestation governance.

A synthetic governance demonstrationnot legal advice, not regulatory certification, not formal accreditation, not grant approval, not an external audit opinion, not an official compliance determination, not a production controls-testing system, and not a replacement for authorized legal, regulatory, audit, funder, or ministry review. Control existence does not prove operation; design adequacy and operating effectiveness remain distinct; untested controls remain untested and failed controls remain failed until retested and approved. Obligation mapping is a governance aid, not legal interpretation. Source-module records remain authoritative. No live integration, real database mutation, real signatures, real evidence upload, real file delivery, or autonomous compliance determination is implemented. AI is assistive only and never determines compliance, certifies, approves, signs, or attests.

You are viewing the Policy, Compliance, Control Testing & Attestation Governance Dashboard — Synthetic non-identifiable demonstration data
Policy-governance posture: Policy records have owners, versions, effective dates, review dates, approval status, and audit references. Draft, approved, effective, expired, withdrawn, and superseded states remain distinct. Expired or superseded policies are never represented as current, but remain historically visible. Policy approval is attributable. Policy publication is not represented as production enforcement. Policies identify affected modules and scopes. Policy history is never silently rewritten or deleted. Material changes require a new version and a linked approval event. Missing approval blocks effective status. Conflicting policy versions remain visible until resolved. Policy interpretation requires authorized human review, and AI-generated policy summaries are not authoritative legal interpretations.
Control-testing posture: Every control test identifies its control reference, test period, objective, procedure, sample definition, synthetic sample references, tester role, independent reviewer role, evidence references, evidence completeness, result, exceptions identified, limitation notes, conclusion, review status, second-review requirement, separation-of-duties status, and audit reference. No test conclusion may exceed available evidence. Missing evidence blocks a pass where evidence is required. Conflicting evidence remains visible. A test performer cannot independently provide final approval where independent review is required. A failed test remains failed until a later linked retest supports a different result, and a retest must not overwrite prior test history. Not-tested and not-applicable remain distinct. Sample limitations remain visible. Control testing is not an external audit opinion or regulatory certification.
Attestation posture: Attestations are synthetic human-review records only. They are not legal certifications, external audit opinions, or funder, ministry, regulator, or accreditation approval, and they do not authorize deployment or replace source evidence. Insufficient evidence blocks approval. Expired, revoked, rejected, and superseded attestations remain visible. The attesting role cannot independently provide final approval where second review is required. AI cannot sign, approve, certify, or attest.
Immutable audit posture: Audit events are append-only in this demonstration model. Policy-version changes require new linked events. Control-test retests require new linked events. Exception approvals, expirations, and revocations require new linked events. Remediation effectiveness decisions require new linked events. Attestation revocations and supersessions require new linked events. Waiver approvals, denials, expirations, and revocations require new linked events. Deletion is not an allowed governance control. Source-module audit records remain authoritative. This task does not implement a production cryptographic evidence or audit ledger.
Total policies 8

All states

Current policies 4

Effective

Policies pending review 1

Draft / pending

Expired policies 1

Not current

Superseded policies 1

History visible

Total obligations 15

Governance aid

Applicable obligations 13

Explicit

Pending interpretation 2

Unresolved / conflicting

Mapped controls 4

Not = satisfied

Unmapped obligations 1

Remain visible

Controls tested 13

Design ≠ operating

Controls not tested 2

Remain untested

Controls passed 9

Within evidence

Controls partial 2

Remain partial

Controls failed 1

Failed until retest

Controls blocked 1

Evidence gap

Design deficiencies 1

Distinct

Operating deficiencies 2

Distinct

Open exceptions 2

Time-bound

Expiring exceptions 0

≤ 30 days

Expired exceptions 1

Not effective

Compensating controls 2

Not erase deficiency

Remediation open 2

In progress

Overdue remediation 2

Remain visible

Effectiveness reviews pending 1

2nd review

Residual high-risk items 3

Priority

Attestations pending 2

Draft / review

Attestations approved 1

Human record

Attestations rejected 1

Remain visible

Attestations expired 1

Remain visible

Waiver requests pending 0

Not effective

Second-review queue 8

High-risk

SoD conflicts 24

Blocked / pending

Missing evidence 1

Blocks pass

Conflicting evidence 1

Both retained

Stale evidence 1

Superseded visible

AI signals 9

Human review required

Audit events 9

Append-only

Policies (states remain distinct; history is never rewritten)

Draft, approved, effective, expired, withdrawn, and superseded states remain distinct; expired or superseded policies are never current but remain historically visible; missing approval blocks effective status; material changes require a new version and linked approval; publication is not production enforcement.

PolicyTitleState / approvalHistory / posture
POL-001 v2.0
owner ACT-01 · fund-accountability
Fund Accountability & Anti-Misuse Policy effective approved
effective 2025-01-01 · expires 2026-12-31 · review 2026-01-01
supersedes POL-001-v1 · publication ≠ enforcement · audit AUD-P-001
POL-002 v1.3
owner ACT-01 · stockpile-logistics, asset-management
Commodity & Stockpile Accountability Policy effective approved
effective 2025-02-01 · expires 2026-12-31 · review 2026-03-01
publication ≠ enforcement · audit AUD-P-002
POL-003 v1.1
owner ACT-01 · patient-continuity, restricted-patient-locator, identity-access-governance
Privacy, Minimum-Necessary & Restricted-Access Policy effective approved
effective 2025-01-15 · expires 2026-12-31 · review 2026-02-01
publication ≠ enforcement · audit AUD-P-003
POL-004 v0.9
owner ACT-01 · ai-intelligence, risk-incident-case-governance
Draft AI-Governance & Human-Oversight Policy draft pending
effective — · expires — · review 2026-04-01
publication ≠ enforcement · audit AUD-P-004
POL-005 v1.0
owner ACT-01 · data-quality-reconciliation
Superseded Legacy Data-Governance Policy superseded approved
effective 2023-06-01 · expires 2025-05-31 · review 2024-06-01
superseded by POL-006 · publication ≠ enforcement · audit AUD-P-005
POL-006 v2.0
owner ACT-01 · data-quality-reconciliation, program-performance
Data Quality, Evidence Provenance & Reconciliation Policy effective approved
effective 2025-06-01 · expires 2026-12-31 · review 2026-05-01
supersedes POL-005 · publication ≠ enforcement · audit AUD-P-006
POL-007 v1.0
owner ACT-01 · country-rollout
Expired Country-Rollout Readiness Policy expired approved
effective 2024-01-01 · expires 2025-01-01 · review 2025-01-01
publication ≠ enforcement · audit AUD-P-007
POL-008 v1.0
owner ACT-01 · authorized-review-room, executive-review-packet
Withdrawn Duplicate Review-Room Access Policy withdrawn withdrawn
effective — · expires — · review 2025-03-01
publication ≠ enforcement · audit AUD-P-008

Compliance obligations (mapping is a governance aid, not legal advice)

Applicability is explicit; unknown applicability remains unresolved. An obligation is not satisfied merely because a control exists. Unmapped and partially mapped obligations remain visible. Formal legal interpretation remains the responsibility of authorized counsel or institutions.

ObligationDescriptionApplicability / interpretationMapping / posture
OBL-001
grant-condition · financial-accountability
Every reported expenditure must identify supporting evidence and be reconcilable to source records. applicable interpreted
modules fund-accountability
controls: CTL-001 · satisfied by existence: no · audit AUD-O-001
OBL-002
operational-procedure · commodity-accountability
Warehouse dispatch and receipt discrepancies must be reconciled and evidenced. applicable interpreted
modules stockpile-logistics
controls: CTL-002 · satisfied by existence: no · audit AUD-O-002
OBL-003
institutional-policy · laboratory-quality
Laboratory results must pass documented quality-control before release to clinicians. applicable interpreted
modules lab-operations
controls: CTL-003 · satisfied by existence: no · audit AUD-O-003
OBL-004
privacy-requirement · patient-continuity
Patient continuity follow-up must preserve minimum-necessary disclosure. applicable interpreted
modules patient-continuity
controls: CTL-004 · satisfied by existence: no · audit AUD-O-004
OBL-005
privacy-requirement · restricted-access
Restricted patient-locator searches require authorized purpose and role-scoped access. applicable interpreted
modules restricted-patient-locator
controls: CTL-005 · satisfied by existence: no · audit AUD-O-005
OBL-006
operational-procedure · asset-accountability
Asset transfers require authorization and custody attribution. applicable interpreted
modules asset-management
controls: CTL-006 · satisfied by existence: no · audit AUD-O-006
OBL-007
grant-condition · program-performance
Reported results must identify indicator, period, responsible entity, data source, and evidence. applicable interpreted
modules program-performance
controls: CTL-007 · satisfied by existence: no · audit AUD-O-007
OBL-008
institutional-policy · ai-governance
AI outputs must remain assistive and human-reviewed; no autonomous determination. partially-applicable conflicting
modules ai-intelligence, risk-incident-case-governance
controls: CTL-008 · satisfied by existence: no · audit AUD-O-008
OBL-009
grant-condition · rollout-readiness
Deployment recommendations require documented readiness evidence and human approval. applicable interpreted
modules country-rollout
controls: CTL-009 · satisfied by existence: no · audit AUD-O-009
OBL-010
program-condition · packet-review
Authorized review-room access is minimum-necessary, time-bound, and audited. applicable interpreted
modules authorized-review-room
controls: CTL-010 · satisfied by existence: no · audit AUD-O-010
OBL-011
program-condition · evidence-package
Executive review-packet capability claims must link to source-module evidence; unsupported claims are blocked. applicable interpreted
modules executive-review-packet
controls: CTL-011 · satisfied by existence: no · audit AUD-O-011
OBL-012
security-requirement · identity-access
Access requires authorized role, purpose, and least-privilege scope; separation of duties enforced. applicable interpreted
modules identity-access-governance
controls: CTL-012 · satisfied by existence: no · audit AUD-O-012
OBL-013
grant-condition · data-quality
Source-module records remain authoritative; corrections require governed, evidenced approval. applicable interpreted
modules data-quality-reconciliation
controls: CTL-013 · satisfied by existence: no · audit AUD-O-013
OBL-014
institutional-policy · incident-investigation
Incidents and investigations must be evidence-bounded; findings never exceed evidence. applicable interpreted
modules risk-incident-case-governance
controls: CTL-014 · satisfied by existence: no · audit AUD-O-014
OBL-015
operational-procedure · operational
Facility downtime procedures must preserve authorization and audit logging offline. unknown unresolved
modules country-rollout
controls: unmapped · satisfied by existence: no · audit AUD-O-015

Obligation-to-control mappings

  • MAP-001 — OBL-001 → CTL-001 mapped full
    not legal interpretation
  • MAP-007 — OBL-007 → CTL-007, CTL-013 mapped full
    not legal interpretation · One obligation maps to multiple controls.
  • MAP-008 — OBL-008 → CTL-008 partial partial
    not legal interpretation · Partially mapped; governing policy still draft; remains partial and visible.
  • MAP-013 — OBL-013 → CTL-013 mapped full
    not legal interpretation · A control may support multiple obligations (CTL-013 also supports OBL-007).
  • MAP-015 — OBL-015 → — unmapped none
    not legal interpretation · Unmapped obligation remains visible.

Controls (design ≠ operating; automated ≠ autonomous)

Preventive, detective, corrective, and compensating controls in manual, automated, and hybrid modes. Control existence does not prove operation; compensating controls do not silently erase the primary deficiency; owners cannot independently provide final assurance where independent review is required; source-module controls remain authoritative.

ControlDescription / typeDesign / operatingGovernance
CTL-001
fund-accountability
Expenditure-to-evidence reconciliation control.
detective · hybrid · monthly
design adequate operating operating
deficiency none · residual low
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-001
CTL-002
stockpile-logistics
Dispatch/receipt discrepancy reconciliation control.
detective · manual · per-shipment
design adequate operating partially-operating
deficiency operating-deficiency · residual medium
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-002
CTL-003
lab-operations
Laboratory QC-before-release preventive control.
preventive · manual · per-result
design adequate operating operating
deficiency none · residual low
SoD compliant
automated ≠ autonomous · audit AUD-C-003
CTL-004
patient-continuity
Minimum-necessary disclosure preventive control for continuity follow-up.
preventive · hybrid · continuous
design adequate operating operating
deficiency none · residual low
SoD compliant
automated ≠ autonomous · audit AUD-C-004
CTL-005
restricted-patient-locator
Restricted-locator authorized-purpose access control.
preventive · hybrid · per-request
design adequate operating operating
deficiency none · residual low
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-005
CTL-006
asset-management
Asset-transfer authorization and custody-attribution control.
preventive · manual · per-transfer
design partially-adequate operating not-operating
deficiency design-deficiency · residual high
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-006
CTL-007
program-performance
Result-attribution completeness control (indicator/period/entity/source/evidence).
detective · hybrid · per-reporting-period
design adequate operating operating
deficiency none · residual low
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-007
CTL-008
ai-intelligence, risk-incident-case-governance
AI human-oversight preventive control (no autonomous determination).
preventive · hybrid · continuous
design adequate operating operating
deficiency not-assessed · residual medium
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-008
CTL-009
country-rollout
Deployment-readiness human-approval control.
preventive · manual · per-wave
design adequate operating operating
deficiency none · residual low
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-009
CTL-010
authorized-review-room
Authorized review-room minimum-necessary access control.
preventive · hybrid · per-access
design adequate operating operating
deficiency none · residual low
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-010
CTL-011
executive-review-packet
Packet capability-claim evidence-linkage detective control.
detective · manual · per-packet-version
design adequate operating operating
deficiency none · residual low
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-011
CTL-012
identity-access-governance
Least-privilege access and separation-of-duties preventive control.
preventive · hybrid · continuous
design adequate operating operating
deficiency none · residual low
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-012
CTL-013
data-quality-reconciliation
Correction-governance control preserving source authority.
corrective · hybrid · per-correction
design adequate operating operating
deficiency none · residual low
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-013
CTL-014
risk-incident-case-governance
Evidence-bounded finding control for incidents/investigations.
detective · manual · per-case
design adequate operating operating
deficiency none · residual low
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-014
CTL-015
asset-management
Compensating manual custody-log reconciliation while CTL-006 design is remediated.
compensating · manual · weekly
design adequate operating operating
deficiency none · residual medium
SoD compliant 2nd review
automated ≠ autonomous · audit AUD-C-015

Control tests & results (no conclusion exceeds evidence)

Results use pass, partial, fail, blocked, not-tested, and not-applicable states. Missing evidence blocks a pass; conflicting evidence remains visible; test performers cannot independently provide final approval; failed tests remain visible after retest; retests append new linked history rather than overwrite; not-tested and not-applicable remain distinct.

TestObjective / evidenceResultConclusion
TST-001
control CTL-001 · 2025-Q2
Confirm expenditures reconcile to evidence.
evidence complete
pass
tester control-tester · independent independent-reviewer
Control operated effectively for the period within evidence. · audit AUD-T-001
TST-002
control CTL-002 · 2025-Q2
Confirm dispatch/receipt discrepancies are reconciled.
evidence partial
partial
tester control-tester · independent independent-reviewer
Control partially operated; an operating deficiency is recorded. · audit AUD-T-002
TST-003
control CTL-003 · 2025-Q2
Confirm QC precedes result release.
evidence complete
pass
tester control-tester · independent independent-reviewer
Control operated effectively within evidence. · audit AUD-T-003
TST-004
control CTL-004 · 2025-Q2
Confirm minimum-necessary disclosure.
evidence complete
pass
tester control-tester · independent independent-reviewer
Control operated effectively within evidence. · audit AUD-T-004
TST-005
control CTL-005 · 2025-Q2
Confirm authorized-purpose access.
evidence complete
pass
tester control-tester · independent independent-reviewer
Control operated effectively within evidence. · audit AUD-T-005
TST-006
control CTL-006 · 2025-Q2
Confirm asset-transfer authorization and attribution.
evidence partial
fail
tester control-tester · independent independent-reviewer
Control failed; remains failed until a linked retest supports a different result. · audit AUD-T-006
TST-006-R
control CTL-006 · 2025-Q3
Retest asset-transfer control after compensating control.
evidence partial · retest of TST-006
partial
tester control-tester · independent independent-reviewer
Retest is a new linked record; it does not overwrite TST-006 history. · audit AUD-T-006-R
TST-007
control CTL-007 · 2025-Q2
Confirm result-attribution completeness.
evidence complete
pass
tester control-tester · independent independent-reviewer
Control operated effectively within evidence. · audit AUD-T-007
TST-008
control CTL-008 · 2025-Q3
Assess AI human-oversight control.
evidence none
not-tested
tester control-tester · independent independent-reviewer
No conclusion; control remains untested. · audit AUD-T-008
TST-009
control CTL-009 · 2025-Q2
Confirm deployment-readiness approval.
evidence complete
pass
tester control-tester · independent independent-reviewer
Control operated effectively within evidence. · audit AUD-T-009
TST-010
control CTL-010 · 2025-Q2
Confirm review-room minimum-necessary access.
evidence conflicting
blocked
tester control-tester · independent independent-reviewer
Test blocked pending evidence resolution; conflicting evidence remains visible. · audit AUD-T-010
TST-011
control CTL-011 · 2025-Q2
Confirm packet capability-claim evidence linkage.
evidence complete
pass
tester control-tester · independent independent-reviewer
Control operated effectively within evidence. · audit AUD-T-011
TST-012
control CTL-012 · 2025-Q2
Confirm least-privilege and SoD enforcement.
evidence complete
pass
tester control-tester · independent independent-reviewer
Control operated effectively within evidence. · audit AUD-T-012
TST-013
control CTL-013 · 2025-Q2
Confirm correction governance preserves source authority.
evidence complete
pass
tester control-tester · independent independent-reviewer
Control operated effectively within evidence. · audit AUD-T-013
TST-014
control CTL-014 · 2025-Q2
Confirm findings remain evidence-bounded.
evidence not-applicable
not-applicable
tester control-tester · independent independent-reviewer
Not applicable this period. · audit AUD-T-014

Deficiencies (remain visible after remediation)

  • DEF-001 — Some receipts lacked timestamps, weakening dispatch/receipt reconciliation. operating-deficiency medium
    control CTL-002 · status open · remains visible after remediation · audit AUD-D-001
  • DEF-002 — Asset-transfer authorization control design does not require independent authorization. design-deficiency high
    control CTL-006 · status in-remediation · compensating CTL-015 · remains visible after remediation · audit AUD-D-002
  • DEF-003 — Conflicting evidence on one review-room access attribution. operating-deficiency low
    control CTL-010 · status open · remains visible after remediation · audit AUD-D-003

Exceptions (time-bound, approved, revocable, monitored)

  • EXC-001 — Interim allowance for legacy receipts without timestamps pending system update. approved active
    risk medium · expires 2025-09-30 · self-approved: no · monitor: monthly reconciliation review
  • EXC-002 — Temporary reliance on compensating manual custody log while design deficiency is remediated. approved active
    risk high · expires 2025-08-30 · self-approved: no · monitor: weekly custody-log review
  • EXC-003 — Requested extension of expired rollout-readiness policy. pending not-effective
    risk medium · expires — · self-approved: no · monitor: n/a until approved
  • EXC-004 — Historical expired exception retained for visibility. approved expired
    risk low · expires 2025-01-31 · self-approved: no · monitor: closed

Compensating controls (do not erase primary deficiency)

  • CTL-015 — for CTL-006 / DEF-002 partially-effective
    does not erase primary deficiency · reviewed by independent-reviewer

Effectiveness reviews (completion ≠ effectiveness)

  • EFR-001 — remediation REM-003 ineffective
    Remediation completed but did not resolve the conflict; deficiency remains visible and may trigger reopen. · 2nd review second-reviewer
  • EFR-002 — remediation REM-002 pending
    High-risk remediation effectiveness pending; requires second review. · 2nd review second-reviewer

Remediation (overdue & ineffective remain visible)

Remediation completion is not effectiveness. Overdue and ineffective remediation remain visible. High-risk remediation effectiveness requires second review. Remediation does not erase failed tests or prior evidence.

  • REM-001 — Enforce timestamp capture on receipts. in-progress pending
    completion ≠ effectiveness · verify not-verified · reopen: recurrence of missing timestamps · audit AUD-R-001
  • REM-002 — Redesign asset-transfer control to require independent authorization. in-progress overdue pending
    completion ≠ effectiveness · verify not-verified · reopen: ineffective redesign or continued unauthorized transfers · audit AUD-R-002
  • REM-003 — Resolve conflicting review-room access attribution record. completed ineffective
    completion ≠ effectiveness · verify verification-in-progress · reopen: attribution conflict recurs · audit AUD-R-003

Attestations (synthetic human-review records only)

Attestations are not legal certifications, external audit opinions, funder/ministry/regulator/accreditation approval, or deployment authorization, and do not replace source evidence. Insufficient evidence blocks approval; expired, revoked, rejected, and superseded attestations remain visible; the attesting role cannot independently provide final approval where second review is required; AI cannot sign, approve, certify, or attest.

AttestationSubject / rolesStatusLimitations / posture
ATT-001
Fund-accountability control operation · 2025-Q2
CTL-001
role attesting-officer · reviewer independent-reviewer
approved 2nd review
SoD compliant
Synthetic demonstration; not a legal certification. · not legal certification · does not authorize deployment · audit AUD-A-001
ATT-002
Stockpile control operation · 2025-Q2
CTL-002
role attesting-officer · reviewer independent-reviewer
pending-review 2nd review
SoD compliant
Operating deficiency disclosed. · not legal certification · does not authorize deployment · audit AUD-A-002
ATT-003
Asset-management control operation · 2025-Q2
CTL-006
role attesting-officer · reviewer independent-reviewer
rejected 2nd review
SoD compliant
Design deficiency and failed test disclosed. · not legal certification · does not authorize deployment · audit AUD-A-003
ATT-004
AI human-oversight control · 2025-Q3
CTL-008
role attesting-officer · reviewer independent-reviewer
blocked-insufficient-evidence 2nd review
SoD compliant
Control untested; evidence insufficient. · not legal certification · does not authorize deployment · audit AUD-A-004
ATT-005
Rollout-readiness control · 2024-Q4
CTL-009
role attesting-officer · reviewer independent-reviewer
expired 2nd review
SoD compliant
Prior-period attestation. · not legal certification · does not authorize deployment · audit AUD-A-005
ATT-006
Restricted-locator access control · 2025-Q2
CTL-005
role attesting-officer · reviewer independent-reviewer
revoked 2nd review
SoD compliant
Attestation revoked after new information. · not legal certification · does not authorize deployment · audit AUD-A-006
ATT-007
Data-quality correction control (v1) · 2025-Q1
CTL-013
role attesting-officer · reviewer independent-reviewer
superseded 2nd review
SoD compliant
Superseded by a later attestation. · not legal certification · does not authorize deployment · audit AUD-A-007
ATT-008
Data-quality correction control (v2) · 2025-Q2
CTL-013
role attesting-officer · reviewer independent-reviewer
draft 2nd review
SoD compliant
Synthetic demonstration only. · not legal certification · does not authorize deployment · audit AUD-A-008

Waivers (not effective without approval)

  • WAV-001 — Interim waiver of timestamp requirement pending system update. approved active
    risk medium · 2nd review: no · requestor approved own: no · does not rewrite policy · audit AUD-W-001
  • WAV-002 — High-risk waiver request for asset-transfer control. denied not-effective
    risk high · 2nd review: yes · requestor approved own: no · does not rewrite policy · audit AUD-W-002
  • WAV-003 — Requested waiver against expired rollout policy. expired expired
    risk medium · 2nd review: yes · requestor approved own: no · does not rewrite policy · audit AUD-W-003

Approval chains

  • CHN-001 — policy POL-001
    policy-owner:draft(complete) → policy-approver:approve(complete)
  • CHN-002 — attestation ATT-001
    attesting-officer:prepare(complete) → independent-reviewer:review(complete) → second-reviewer:second-review(complete)
  • CHN-003 — waiver WAV-002
    control-owner:request(complete) → compliance-reviewer:decide(denied) → second-reviewer:second-review(complete)

Separation-of-duties rules

Violations remain blocked or pending, identify the violated rule, require reassignment, independent review, or second review, remain auditable, and are never silently overridden.

RuleEnforcementOverride / audit
A policy author cannot independently provide final policy approval.
SOD-001 · policy-author-cannot-approve-policy
blocked never silently overridden
auditable · requires reassignment / independent / second review
An obligation mapper cannot independently approve a disputed interpretation.
SOD-002 · obligation-mapper-cannot-approve-disputed-interpretation
pending never silently overridden
auditable · requires reassignment / independent / second review
A control owner cannot independently approve control design where independent review is required.
SOD-003 · control-owner-cannot-approve-control-design
blocked never silently overridden
auditable · requires reassignment / independent / second review
A control performer cannot independently test and finally approve the same control.
SOD-004 · control-performer-cannot-test-and-approve
blocked never silently overridden
auditable · requires reassignment / independent / second review
A test performer cannot independently provide final test approval.
SOD-005 · test-performer-cannot-final-approve-test
blocked never silently overridden
auditable · requires reassignment / independent / second review
An evidence capturer cannot independently verify high-risk evidence.
SOD-006 · evidence-capturer-cannot-verify-high-risk-evidence
blocked never silently overridden
auditable · requires reassignment / independent / second review
A deficiency owner cannot independently close the deficiency.
SOD-007 · deficiency-owner-cannot-close-deficiency
pending never silently overridden
auditable · requires reassignment / independent / second review
An exception requestor cannot independently approve the exception.
SOD-008 · exception-requestor-cannot-approve-exception
blocked never silently overridden
auditable · requires reassignment / independent / second review
An exception owner cannot independently verify compensating-control effectiveness.
SOD-009 · exception-owner-cannot-verify-compensating-control
pending never silently overridden
auditable · requires reassignment / independent / second review
A remediation owner cannot independently verify high-risk remediation effectiveness.
SOD-010 · remediation-owner-cannot-verify-high-risk-remediation
blocked never silently overridden
auditable · requires reassignment / independent / second review
An attestation preparer cannot independently provide final attestation approval.
SOD-011 · attestation-preparer-cannot-approve-attestation
blocked never silently overridden
auditable · requires reassignment / independent / second review
A waiver requestor cannot independently approve the waiver.
SOD-012 · waiver-requestor-cannot-approve-waiver
blocked never silently overridden
auditable · requires reassignment / independent / second review
A fund-control preparer cannot independently attest fund compliance.
SOD-013 · fund-control-preparer-cannot-attest-fund-compliance
blocked never silently overridden
auditable · requires reassignment / independent / second review
A warehouse control performer cannot independently close a stock-accountability deficiency.
SOD-014 · warehouse-performer-cannot-close-stock-deficiency
pending never silently overridden
auditable · requires reassignment / independent / second review
A laboratory control performer cannot independently approve a laboratory-quality exception.
SOD-015 · lab-performer-cannot-approve-lab-quality-exception
blocked never silently overridden
auditable · requires reassignment / independent / second review
A restricted-locator access reviewer cannot independently attest to a case involving their own access decision.
SOD-016 · locator-reviewer-cannot-attest-own-access-case
blocked never silently overridden
auditable · requires reassignment / independent / second review
An asset custodian cannot independently attest to control effectiveness over their own custody records.
SOD-017 · asset-custodian-cannot-attest-own-custody
blocked never silently overridden
auditable · requires reassignment / independent / second review
A program-result submitter cannot independently attest result-control effectiveness.
SOD-018 · program-submitter-cannot-attest-result-control
blocked never silently overridden
auditable · requires reassignment / independent / second review
An AI case generator cannot independently certify control effectiveness.
SOD-019 · ai-generator-cannot-certify-control-effectiveness
blocked never silently overridden
auditable · requires reassignment / independent / second review
A rollout assessor cannot independently attest deployment readiness.
SOD-020 · rollout-assessor-cannot-attest-deployment-readiness
blocked never silently overridden
auditable · requires reassignment / independent / second review
A review-packet author cannot independently attest unsupported capability compliance.
SOD-021 · packet-author-cannot-attest-unsupported-capability
blocked never silently overridden
auditable · requires reassignment / independent / second review
An identity approver cannot independently test and close a control involving their own decision.
SOD-022 · identity-approver-cannot-test-close-own-control
blocked never silently overridden
auditable · requires reassignment / independent / second review
A data-quality correction approver cannot independently attest reconciliation effectiveness.
SOD-023 · dq-correction-approver-cannot-attest-reconciliation
blocked never silently overridden
auditable · requires reassignment / independent / second review
An incident investigator cannot independently attest remediation effectiveness for their own case.
SOD-024 · incident-investigator-cannot-attest-own-remediation
pending never silently overridden
auditable · requires reassignment / independent / second review

Evidence (presence ≠ verification; conflicts remain visible)

  • EVD-001 — reconciliation-record present verified current
    fund-accountability · control CTL-001
  • EVD-002 — dispatch-receipt-record present partially-verified current
    stockpile-logistics · control CTL-002
  • EVD-003 — qc-record present verified current
    lab-operations · control CTL-003
  • EVD-004 — disclosure-log present verified current
    patient-continuity · control CTL-004
  • EVD-005 — access-purpose-record present verified current
    restricted-patient-locator · control CTL-005
  • EVD-006 — authorization-record missing unverified current
    asset-management · control CTL-006
  • EVD-007 — result-record present verified current
    program-performance · control CTL-007
  • EVD-008 — signal-review-record present unverified current
    ai-intelligence · control CTL-008
  • EVD-009 — readiness-approval-record present verified current
    country-rollout · control CTL-009
  • EVD-010 — access-attribution-record present conflicting current
    authorized-review-room · control CTL-010
  • EVD-011 — capability-claim-record present verified current
    executive-review-packet · control CTL-011
  • EVD-012 — access-decision-record present verified current
    identity-access-governance · control CTL-012
  • EVD-013 — correction-record present verified current
    data-quality-reconciliation · control CTL-013
  • EVD-014 — case-evidence-record present verified current
    risk-incident-case-governance · control CTL-014
  • EVD-015 — legacy-correction-record present verified superseded
    data-quality-reconciliation · control CTL-013

AI risk signals (human review required)

  • unmapped-or-partial-obligation — Obligation OBL-008 remains partially mapped. confidence medium
    human review: yes · autonomous action: no
  • expired-policy — Policy POL-007 is expired. confidence high
    human review: yes · autonomous action: no
  • missing-test-evidence — Control CTL-008 remains untested. confidence high
    human review: yes · autonomous action: no
  • overdue-remediation — Remediation REM-002 is overdue. confidence high
    human review: yes · autonomous action: no
  • expiring-exception — Exception EXC-002 expires soon. confidence medium
    human review: yes · autonomous action: no
  • unsupported-attestation — Attestation ATT-004 unsupported by evidence. confidence high
    human review: yes · autonomous action: no
  • potentially-ineffective-compensating-control — Compensating control CMP-001 may be only partially effective. confidence medium
    human review: yes · autonomous action: no
  • inconsistent-conclusion-check — Test TST-006 conclusion consistent with recorded evidence. confidence medium
    human review: yes · autonomous action: no
  • expiring-waiver — Waiver WAV-001 expires within the review window. confidence medium
    human review: yes · autonomous action: no

Immutable audit events (append-only)

Policy-version changes, control-test retests, exception events, remediation-effectiveness decisions, attestation revocations and supersessions, and waiver events all require new linked events; deletion is not an allowed governance control; source-module audit records remain authoritative. This is not a production cryptographic audit ledger.

  • AUD-P-001 — policy-version-approved effective
    policy-approver · fund-accountability · 2025-01-01T10:00:00Z · immutable: yes
  • AUD-T-006 — control-test-recorded fail
    control-tester · asset-management · 2025-06-30T10:00:00Z · immutable: yes
  • AUD-T-006-R — control-retest-recorded partial retest of TST-006
    control-tester · asset-management · 2025-09-15T10:00:00Z · immutable: yes
  • AUD-E-002 — exception-approved approved
    compliance-reviewer · asset-management · 2025-07-01T10:00:00Z · immutable: yes
  • AUD-EFR-001 — remediation-effectiveness-decided ineffective
    independent-reviewer · authorized-review-room · 2025-10-15T10:00:00Z · immutable: yes
  • AUD-A-006 — attestation-revoked revoked revocation of ATT-006
    compliance-reviewer · restricted-patient-locator · 2025-07-08T10:00:00Z · immutable: yes
  • AUD-A-007 — attestation-superseded superseded supersession of ATT-007
    compliance-reviewer · data-quality-reconciliation · 2025-07-09T10:00:00Z · immutable: yes
  • AUD-W-002 — waiver-denied denied
    compliance-reviewer · asset-management · 2025-07-03T10:00:00Z · immutable: yes
  • AUD-W-003 — waiver-expired expired
    compliance-reviewer · country-rollout · 2025-03-01T10:00:00Z · immutable: yes

Controls by source module

  • fund-accountability 1
  • stockpile-logistics 1
  • lab-operations 1
  • patient-continuity 1
  • restricted-patient-locator 1
  • asset-management 2
  • program-performance 1
  • ai-intelligence 1
  • risk-incident-case-governance 2
  • country-rollout 1
  • authorized-review-room 1
  • executive-review-packet 1
  • identity-access-governance 1
  • data-quality-reconciliation 1

Obligations by category

  • financial-accountability 1
  • commodity-accountability 1
  • laboratory-quality 1
  • patient-continuity 1
  • restricted-access 1
  • asset-accountability 1
  • program-performance 1
  • ai-governance 1
  • rollout-readiness 1
  • packet-review 1
  • evidence-package 1
  • identity-access 1
  • data-quality 1
  • incident-investigation 1
  • operational 1

Controls by type

  • detective 5
  • preventive 8
  • corrective 1
  • compensating 1

Tests by result / remediation by status

  • pass 9
  • partial 2
  • fail 1
  • not-tested 1
  • blocked 1
  • not-applicable 1
  • in-progress 2
  • completed 1

AI posture — assistive only, non-autonomous

AI assists with

  • map policies and obligations to candidate controls
  • identify unmapped or partially mapped obligations
  • detect expired or superseded policies
  • identify stale reviews
  • detect control-design gaps
  • identify missing test evidence
  • compare test results across periods
  • flag inconsistent conclusions
  • identify overdue remediation
  • identify expiring exceptions and waivers
  • detect separation-of-duties conflicts
  • summarize evidence for authorized human reviewers
  • identify unsupported attestations
  • recommend items for independent or second review
  • reconcile module-control references
  • identify potentially ineffective compensating controls

AI must never

  • provide legal advice
  • determine regulatory applicability autonomously
  • certify compliance
  • approve policies
  • approve control design
  • approve control-test results
  • approve exceptions
  • approve waivers
  • approve remediation effectiveness
  • sign or approve attestations
  • convert missing evidence into a pass
  • suppress failed tests, deficiencies, exceptions, or conflicting evidence
  • alter source-module records
  • fabricate evidence
  • authorize deployment
  • notify regulators, funders, ministries, auditors, or other external parties
  • bypass human approval, independent review, second review, separation of duties, evidence, expiration, revocation, or audit controls

AI is assistive only. It may map policies and obligations to candidate controls, identify unmapped or partially mapped obligations, detect expired or superseded policies and stale reviews, detect control-design gaps and missing test evidence, compare test results across periods, flag inconsistent conclusions, identify overdue remediation and expiring exceptions and waivers, detect separation-of-duties conflicts, summarize evidence for authorized human reviewers, identify unsupported attestations, recommend items for independent or second review, reconcile module-control references, and identify potentially ineffective compensating controls. AI never determines compliance, certifies, approves, signs, or attests, and never bypasses human review, evidence, expiration, revocation, separation of duties, or audit controls.

Runtime boundary & module coverage

fund-accountability stockpile-logistics lab-operations patient-continuity restricted-patient-locator asset-management program-performance ai-intelligence country-rollout authorized-review-room executive-review-packet identity-access-governance data-quality-reconciliation risk-incident-case-governance