All states
MaxArc Global Health Impact Platform
Policy, Compliance, Control Testing & Attestation Governance
Cross-module policy, compliance, control-testing, and human-attestation governance.
A synthetic governance demonstration — not legal advice, not regulatory certification, not formal accreditation, not grant approval, not an external audit opinion, not an official compliance determination, not a production controls-testing system, and not a replacement for authorized legal, regulatory, audit, funder, or ministry review. Control existence does not prove operation; design adequacy and operating effectiveness remain distinct; untested controls remain untested and failed controls remain failed until retested and approved. Obligation mapping is a governance aid, not legal interpretation. Source-module records remain authoritative. No live integration, real database mutation, real signatures, real evidence upload, real file delivery, or autonomous compliance determination is implemented. AI is assistive only and never determines compliance, certifies, approves, signs, or attests.
Effective
Draft / pending
Not current
History visible
Governance aid
Explicit
Unresolved / conflicting
Not = satisfied
Remain visible
Design ≠ operating
Remain untested
Within evidence
Remain partial
Failed until retest
Evidence gap
Distinct
Distinct
Time-bound
≤ 30 days
Not effective
Not erase deficiency
In progress
Remain visible
2nd review
Priority
Draft / review
Human record
Remain visible
Remain visible
Not effective
High-risk
Blocked / pending
Blocks pass
Both retained
Superseded visible
Human review required
Append-only
Policies (states remain distinct; history is never rewritten)
Draft, approved, effective, expired, withdrawn, and superseded states remain distinct; expired or superseded policies are never current but remain historically visible; missing approval blocks effective status; material changes require a new version and linked approval; publication is not production enforcement.
| Policy | Title | State / approval | History / posture |
|---|---|---|---|
| POL-001 v2.0 owner ACT-01 · fund-accountability |
Fund Accountability & Anti-Misuse Policy | effective approved effective 2025-01-01 · expires 2026-12-31 · review 2026-01-01 |
supersedes POL-001-v1 · publication ≠ enforcement · audit AUD-P-001 |
| POL-002 v1.3 owner ACT-01 · stockpile-logistics, asset-management |
Commodity & Stockpile Accountability Policy | effective approved effective 2025-02-01 · expires 2026-12-31 · review 2026-03-01 |
publication ≠ enforcement · audit AUD-P-002 |
| POL-003 v1.1 owner ACT-01 · patient-continuity, restricted-patient-locator, identity-access-governance |
Privacy, Minimum-Necessary & Restricted-Access Policy | effective approved effective 2025-01-15 · expires 2026-12-31 · review 2026-02-01 |
publication ≠ enforcement · audit AUD-P-003 |
| POL-004 v0.9 owner ACT-01 · ai-intelligence, risk-incident-case-governance |
Draft AI-Governance & Human-Oversight Policy | draft pending effective — · expires — · review 2026-04-01 |
publication ≠ enforcement · audit AUD-P-004 |
| POL-005 v1.0 owner ACT-01 · data-quality-reconciliation |
Superseded Legacy Data-Governance Policy | superseded approved effective 2023-06-01 · expires 2025-05-31 · review 2024-06-01 |
superseded by POL-006 · publication ≠ enforcement · audit AUD-P-005 |
| POL-006 v2.0 owner ACT-01 · data-quality-reconciliation, program-performance |
Data Quality, Evidence Provenance & Reconciliation Policy | effective approved effective 2025-06-01 · expires 2026-12-31 · review 2026-05-01 |
supersedes POL-005 · publication ≠ enforcement · audit AUD-P-006 |
| POL-007 v1.0 owner ACT-01 · country-rollout |
Expired Country-Rollout Readiness Policy | expired approved effective 2024-01-01 · expires 2025-01-01 · review 2025-01-01 |
publication ≠ enforcement · audit AUD-P-007 |
| POL-008 v1.0 owner ACT-01 · authorized-review-room, executive-review-packet |
Withdrawn Duplicate Review-Room Access Policy | withdrawn withdrawn effective — · expires — · review 2025-03-01 |
publication ≠ enforcement · audit AUD-P-008 |
Compliance obligations (mapping is a governance aid, not legal advice)
Applicability is explicit; unknown applicability remains unresolved. An obligation is not satisfied merely because a control exists. Unmapped and partially mapped obligations remain visible. Formal legal interpretation remains the responsibility of authorized counsel or institutions.
| Obligation | Description | Applicability / interpretation | Mapping / posture |
|---|---|---|---|
| OBL-001 grant-condition · financial-accountability |
Every reported expenditure must identify supporting evidence and be reconcilable to source records. | applicable interpreted modules fund-accountability |
controls: CTL-001 · satisfied by existence: no · audit AUD-O-001 |
| OBL-002 operational-procedure · commodity-accountability |
Warehouse dispatch and receipt discrepancies must be reconciled and evidenced. | applicable interpreted modules stockpile-logistics |
controls: CTL-002 · satisfied by existence: no · audit AUD-O-002 |
| OBL-003 institutional-policy · laboratory-quality |
Laboratory results must pass documented quality-control before release to clinicians. | applicable interpreted modules lab-operations |
controls: CTL-003 · satisfied by existence: no · audit AUD-O-003 |
| OBL-004 privacy-requirement · patient-continuity |
Patient continuity follow-up must preserve minimum-necessary disclosure. | applicable interpreted modules patient-continuity |
controls: CTL-004 · satisfied by existence: no · audit AUD-O-004 |
| OBL-005 privacy-requirement · restricted-access |
Restricted patient-locator searches require authorized purpose and role-scoped access. | applicable interpreted modules restricted-patient-locator |
controls: CTL-005 · satisfied by existence: no · audit AUD-O-005 |
| OBL-006 operational-procedure · asset-accountability |
Asset transfers require authorization and custody attribution. | applicable interpreted modules asset-management |
controls: CTL-006 · satisfied by existence: no · audit AUD-O-006 |
| OBL-007 grant-condition · program-performance |
Reported results must identify indicator, period, responsible entity, data source, and evidence. | applicable interpreted modules program-performance |
controls: CTL-007 · satisfied by existence: no · audit AUD-O-007 |
| OBL-008 institutional-policy · ai-governance |
AI outputs must remain assistive and human-reviewed; no autonomous determination. | partially-applicable conflicting modules ai-intelligence, risk-incident-case-governance |
controls: CTL-008 · satisfied by existence: no · audit AUD-O-008 |
| OBL-009 grant-condition · rollout-readiness |
Deployment recommendations require documented readiness evidence and human approval. | applicable interpreted modules country-rollout |
controls: CTL-009 · satisfied by existence: no · audit AUD-O-009 |
| OBL-010 program-condition · packet-review |
Authorized review-room access is minimum-necessary, time-bound, and audited. | applicable interpreted modules authorized-review-room |
controls: CTL-010 · satisfied by existence: no · audit AUD-O-010 |
| OBL-011 program-condition · evidence-package |
Executive review-packet capability claims must link to source-module evidence; unsupported claims are blocked. | applicable interpreted modules executive-review-packet |
controls: CTL-011 · satisfied by existence: no · audit AUD-O-011 |
| OBL-012 security-requirement · identity-access |
Access requires authorized role, purpose, and least-privilege scope; separation of duties enforced. | applicable interpreted modules identity-access-governance |
controls: CTL-012 · satisfied by existence: no · audit AUD-O-012 |
| OBL-013 grant-condition · data-quality |
Source-module records remain authoritative; corrections require governed, evidenced approval. | applicable interpreted modules data-quality-reconciliation |
controls: CTL-013 · satisfied by existence: no · audit AUD-O-013 |
| OBL-014 institutional-policy · incident-investigation |
Incidents and investigations must be evidence-bounded; findings never exceed evidence. | applicable interpreted modules risk-incident-case-governance |
controls: CTL-014 · satisfied by existence: no · audit AUD-O-014 |
| OBL-015 operational-procedure · operational |
Facility downtime procedures must preserve authorization and audit logging offline. | unknown unresolved modules country-rollout |
controls: unmapped · satisfied by existence: no · audit AUD-O-015 |
Obligation-to-control mappings
- MAP-001 — OBL-001 → CTL-001 mapped fullnot legal interpretation
- MAP-007 — OBL-007 → CTL-007, CTL-013 mapped fullnot legal interpretation · One obligation maps to multiple controls.
- MAP-008 — OBL-008 → CTL-008 partial partialnot legal interpretation · Partially mapped; governing policy still draft; remains partial and visible.
- MAP-013 — OBL-013 → CTL-013 mapped fullnot legal interpretation · A control may support multiple obligations (CTL-013 also supports OBL-007).
- MAP-015 — OBL-015 → — unmapped nonenot legal interpretation · Unmapped obligation remains visible.
Controls (design ≠ operating; automated ≠ autonomous)
Preventive, detective, corrective, and compensating controls in manual, automated, and hybrid modes. Control existence does not prove operation; compensating controls do not silently erase the primary deficiency; owners cannot independently provide final assurance where independent review is required; source-module controls remain authoritative.
| Control | Description / type | Design / operating | Governance |
|---|---|---|---|
| CTL-001 fund-accountability |
Expenditure-to-evidence reconciliation control. detective · hybrid · monthly |
design adequate operating operating deficiency none · residual low |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-001 |
| CTL-002 stockpile-logistics |
Dispatch/receipt discrepancy reconciliation control. detective · manual · per-shipment |
design adequate operating partially-operating deficiency operating-deficiency · residual medium |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-002 |
| CTL-003 lab-operations |
Laboratory QC-before-release preventive control. preventive · manual · per-result |
design adequate operating operating deficiency none · residual low |
SoD compliant automated ≠ autonomous · audit AUD-C-003 |
| CTL-004 patient-continuity |
Minimum-necessary disclosure preventive control for continuity follow-up. preventive · hybrid · continuous |
design adequate operating operating deficiency none · residual low |
SoD compliant automated ≠ autonomous · audit AUD-C-004 |
| CTL-005 restricted-patient-locator |
Restricted-locator authorized-purpose access control. preventive · hybrid · per-request |
design adequate operating operating deficiency none · residual low |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-005 |
| CTL-006 asset-management |
Asset-transfer authorization and custody-attribution control. preventive · manual · per-transfer |
design partially-adequate operating not-operating deficiency design-deficiency · residual high |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-006 |
| CTL-007 program-performance |
Result-attribution completeness control (indicator/period/entity/source/evidence). detective · hybrid · per-reporting-period |
design adequate operating operating deficiency none · residual low |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-007 |
| CTL-008 ai-intelligence, risk-incident-case-governance |
AI human-oversight preventive control (no autonomous determination). preventive · hybrid · continuous |
design adequate operating operating deficiency not-assessed · residual medium |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-008 |
| CTL-009 country-rollout |
Deployment-readiness human-approval control. preventive · manual · per-wave |
design adequate operating operating deficiency none · residual low |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-009 |
| CTL-010 authorized-review-room |
Authorized review-room minimum-necessary access control. preventive · hybrid · per-access |
design adequate operating operating deficiency none · residual low |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-010 |
| CTL-011 executive-review-packet |
Packet capability-claim evidence-linkage detective control. detective · manual · per-packet-version |
design adequate operating operating deficiency none · residual low |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-011 |
| CTL-012 identity-access-governance |
Least-privilege access and separation-of-duties preventive control. preventive · hybrid · continuous |
design adequate operating operating deficiency none · residual low |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-012 |
| CTL-013 data-quality-reconciliation |
Correction-governance control preserving source authority. corrective · hybrid · per-correction |
design adequate operating operating deficiency none · residual low |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-013 |
| CTL-014 risk-incident-case-governance |
Evidence-bounded finding control for incidents/investigations. detective · manual · per-case |
design adequate operating operating deficiency none · residual low |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-014 |
| CTL-015 asset-management |
Compensating manual custody-log reconciliation while CTL-006 design is remediated. compensating · manual · weekly |
design adequate operating operating deficiency none · residual medium |
SoD compliant 2nd review automated ≠ autonomous · audit AUD-C-015 |
Control tests & results (no conclusion exceeds evidence)
Results use pass, partial, fail, blocked, not-tested, and not-applicable states. Missing evidence blocks a pass; conflicting evidence remains visible; test performers cannot independently provide final approval; failed tests remain visible after retest; retests append new linked history rather than overwrite; not-tested and not-applicable remain distinct.
| Test | Objective / evidence | Result | Conclusion |
|---|---|---|---|
| TST-001 control CTL-001 · 2025-Q2 |
Confirm expenditures reconcile to evidence. evidence complete |
pass tester control-tester · independent independent-reviewer |
Control operated effectively for the period within evidence. · audit AUD-T-001 |
| TST-002 control CTL-002 · 2025-Q2 |
Confirm dispatch/receipt discrepancies are reconciled. evidence partial |
partial tester control-tester · independent independent-reviewer |
Control partially operated; an operating deficiency is recorded. · audit AUD-T-002 |
| TST-003 control CTL-003 · 2025-Q2 |
Confirm QC precedes result release. evidence complete |
pass tester control-tester · independent independent-reviewer |
Control operated effectively within evidence. · audit AUD-T-003 |
| TST-004 control CTL-004 · 2025-Q2 |
Confirm minimum-necessary disclosure. evidence complete |
pass tester control-tester · independent independent-reviewer |
Control operated effectively within evidence. · audit AUD-T-004 |
| TST-005 control CTL-005 · 2025-Q2 |
Confirm authorized-purpose access. evidence complete |
pass tester control-tester · independent independent-reviewer |
Control operated effectively within evidence. · audit AUD-T-005 |
| TST-006 control CTL-006 · 2025-Q2 |
Confirm asset-transfer authorization and attribution. evidence partial |
fail tester control-tester · independent independent-reviewer |
Control failed; remains failed until a linked retest supports a different result. · audit AUD-T-006 |
| TST-006-R control CTL-006 · 2025-Q3 |
Retest asset-transfer control after compensating control. evidence partial · retest of TST-006 |
partial tester control-tester · independent independent-reviewer |
Retest is a new linked record; it does not overwrite TST-006 history. · audit AUD-T-006-R |
| TST-007 control CTL-007 · 2025-Q2 |
Confirm result-attribution completeness. evidence complete |
pass tester control-tester · independent independent-reviewer |
Control operated effectively within evidence. · audit AUD-T-007 |
| TST-008 control CTL-008 · 2025-Q3 |
Assess AI human-oversight control. evidence none |
not-tested tester control-tester · independent independent-reviewer |
No conclusion; control remains untested. · audit AUD-T-008 |
| TST-009 control CTL-009 · 2025-Q2 |
Confirm deployment-readiness approval. evidence complete |
pass tester control-tester · independent independent-reviewer |
Control operated effectively within evidence. · audit AUD-T-009 |
| TST-010 control CTL-010 · 2025-Q2 |
Confirm review-room minimum-necessary access. evidence conflicting |
blocked tester control-tester · independent independent-reviewer |
Test blocked pending evidence resolution; conflicting evidence remains visible. · audit AUD-T-010 |
| TST-011 control CTL-011 · 2025-Q2 |
Confirm packet capability-claim evidence linkage. evidence complete |
pass tester control-tester · independent independent-reviewer |
Control operated effectively within evidence. · audit AUD-T-011 |
| TST-012 control CTL-012 · 2025-Q2 |
Confirm least-privilege and SoD enforcement. evidence complete |
pass tester control-tester · independent independent-reviewer |
Control operated effectively within evidence. · audit AUD-T-012 |
| TST-013 control CTL-013 · 2025-Q2 |
Confirm correction governance preserves source authority. evidence complete |
pass tester control-tester · independent independent-reviewer |
Control operated effectively within evidence. · audit AUD-T-013 |
| TST-014 control CTL-014 · 2025-Q2 |
Confirm findings remain evidence-bounded. evidence not-applicable |
not-applicable tester control-tester · independent independent-reviewer |
Not applicable this period. · audit AUD-T-014 |
Deficiencies (remain visible after remediation)
- DEF-001 — Some receipts lacked timestamps, weakening dispatch/receipt reconciliation. operating-deficiency mediumcontrol CTL-002 · status open · remains visible after remediation · audit AUD-D-001
- DEF-002 — Asset-transfer authorization control design does not require independent authorization. design-deficiency highcontrol CTL-006 · status in-remediation · compensating CTL-015 · remains visible after remediation · audit AUD-D-002
- DEF-003 — Conflicting evidence on one review-room access attribution. operating-deficiency lowcontrol CTL-010 · status open · remains visible after remediation · audit AUD-D-003
Exceptions (time-bound, approved, revocable, monitored)
- EXC-001 — Interim allowance for legacy receipts without timestamps pending system update. approved activerisk medium · expires 2025-09-30 · self-approved: no · monitor: monthly reconciliation review
- EXC-002 — Temporary reliance on compensating manual custody log while design deficiency is remediated. approved activerisk high · expires 2025-08-30 · self-approved: no · monitor: weekly custody-log review
- EXC-003 — Requested extension of expired rollout-readiness policy. pending not-effectiverisk medium · expires — · self-approved: no · monitor: n/a until approved
- EXC-004 — Historical expired exception retained for visibility. approved expiredrisk low · expires 2025-01-31 · self-approved: no · monitor: closed
Compensating controls (do not erase primary deficiency)
- CTL-015 — for CTL-006 / DEF-002 partially-effectivedoes not erase primary deficiency · reviewed by independent-reviewer
Effectiveness reviews (completion ≠ effectiveness)
- EFR-001 — remediation REM-003 ineffectiveRemediation completed but did not resolve the conflict; deficiency remains visible and may trigger reopen. · 2nd review second-reviewer
- EFR-002 — remediation REM-002 pendingHigh-risk remediation effectiveness pending; requires second review. · 2nd review second-reviewer
Remediation (overdue & ineffective remain visible)
Remediation completion is not effectiveness. Overdue and ineffective remediation remain visible. High-risk remediation effectiveness requires second review. Remediation does not erase failed tests or prior evidence.
- REM-001 — Enforce timestamp capture on receipts. in-progress pendingcompletion ≠ effectiveness · verify not-verified · reopen: recurrence of missing timestamps · audit AUD-R-001
- REM-002 — Redesign asset-transfer control to require independent authorization. in-progress overdue pendingcompletion ≠ effectiveness · verify not-verified · reopen: ineffective redesign or continued unauthorized transfers · audit AUD-R-002
- REM-003 — Resolve conflicting review-room access attribution record. completed ineffectivecompletion ≠ effectiveness · verify verification-in-progress · reopen: attribution conflict recurs · audit AUD-R-003
Attestations (synthetic human-review records only)
Attestations are not legal certifications, external audit opinions, funder/ministry/regulator/accreditation approval, or deployment authorization, and do not replace source evidence. Insufficient evidence blocks approval; expired, revoked, rejected, and superseded attestations remain visible; the attesting role cannot independently provide final approval where second review is required; AI cannot sign, approve, certify, or attest.
| Attestation | Subject / roles | Status | Limitations / posture |
|---|---|---|---|
| ATT-001 Fund-accountability control operation · 2025-Q2 |
CTL-001 role attesting-officer · reviewer independent-reviewer |
approved 2nd review SoD compliant |
Synthetic demonstration; not a legal certification. · not legal certification · does not authorize deployment · audit AUD-A-001 |
| ATT-002 Stockpile control operation · 2025-Q2 |
CTL-002 role attesting-officer · reviewer independent-reviewer |
pending-review 2nd review SoD compliant |
Operating deficiency disclosed. · not legal certification · does not authorize deployment · audit AUD-A-002 |
| ATT-003 Asset-management control operation · 2025-Q2 |
CTL-006 role attesting-officer · reviewer independent-reviewer |
rejected 2nd review SoD compliant |
Design deficiency and failed test disclosed. · not legal certification · does not authorize deployment · audit AUD-A-003 |
| ATT-004 AI human-oversight control · 2025-Q3 |
CTL-008 role attesting-officer · reviewer independent-reviewer |
blocked-insufficient-evidence 2nd review SoD compliant |
Control untested; evidence insufficient. · not legal certification · does not authorize deployment · audit AUD-A-004 |
| ATT-005 Rollout-readiness control · 2024-Q4 |
CTL-009 role attesting-officer · reviewer independent-reviewer |
expired 2nd review SoD compliant |
Prior-period attestation. · not legal certification · does not authorize deployment · audit AUD-A-005 |
| ATT-006 Restricted-locator access control · 2025-Q2 |
CTL-005 role attesting-officer · reviewer independent-reviewer |
revoked 2nd review SoD compliant |
Attestation revoked after new information. · not legal certification · does not authorize deployment · audit AUD-A-006 |
| ATT-007 Data-quality correction control (v1) · 2025-Q1 |
CTL-013 role attesting-officer · reviewer independent-reviewer |
superseded 2nd review SoD compliant |
Superseded by a later attestation. · not legal certification · does not authorize deployment · audit AUD-A-007 |
| ATT-008 Data-quality correction control (v2) · 2025-Q2 |
CTL-013 role attesting-officer · reviewer independent-reviewer |
draft 2nd review SoD compliant |
Synthetic demonstration only. · not legal certification · does not authorize deployment · audit AUD-A-008 |
Waivers (not effective without approval)
- WAV-001 — Interim waiver of timestamp requirement pending system update. approved activerisk medium · 2nd review: no · requestor approved own: no · does not rewrite policy · audit AUD-W-001
- WAV-002 — High-risk waiver request for asset-transfer control. denied not-effectiverisk high · 2nd review: yes · requestor approved own: no · does not rewrite policy · audit AUD-W-002
- WAV-003 — Requested waiver against expired rollout policy. expired expiredrisk medium · 2nd review: yes · requestor approved own: no · does not rewrite policy · audit AUD-W-003
Approval chains
- CHN-001 — policy POL-001policy-owner:draft(complete) → policy-approver:approve(complete)
- CHN-002 — attestation ATT-001attesting-officer:prepare(complete) → independent-reviewer:review(complete) → second-reviewer:second-review(complete)
- CHN-003 — waiver WAV-002control-owner:request(complete) → compliance-reviewer:decide(denied) → second-reviewer:second-review(complete)
Separation-of-duties rules
Violations remain blocked or pending, identify the violated rule, require reassignment, independent review, or second review, remain auditable, and are never silently overridden.
| Rule | Enforcement | Override / audit |
|---|---|---|
| A policy author cannot independently provide final policy approval. SOD-001 · policy-author-cannot-approve-policy |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| An obligation mapper cannot independently approve a disputed interpretation. SOD-002 · obligation-mapper-cannot-approve-disputed-interpretation |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| A control owner cannot independently approve control design where independent review is required. SOD-003 · control-owner-cannot-approve-control-design |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A control performer cannot independently test and finally approve the same control. SOD-004 · control-performer-cannot-test-and-approve |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A test performer cannot independently provide final test approval. SOD-005 · test-performer-cannot-final-approve-test |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| An evidence capturer cannot independently verify high-risk evidence. SOD-006 · evidence-capturer-cannot-verify-high-risk-evidence |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A deficiency owner cannot independently close the deficiency. SOD-007 · deficiency-owner-cannot-close-deficiency |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| An exception requestor cannot independently approve the exception. SOD-008 · exception-requestor-cannot-approve-exception |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| An exception owner cannot independently verify compensating-control effectiveness. SOD-009 · exception-owner-cannot-verify-compensating-control |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| A remediation owner cannot independently verify high-risk remediation effectiveness. SOD-010 · remediation-owner-cannot-verify-high-risk-remediation |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| An attestation preparer cannot independently provide final attestation approval. SOD-011 · attestation-preparer-cannot-approve-attestation |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A waiver requestor cannot independently approve the waiver. SOD-012 · waiver-requestor-cannot-approve-waiver |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A fund-control preparer cannot independently attest fund compliance. SOD-013 · fund-control-preparer-cannot-attest-fund-compliance |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A warehouse control performer cannot independently close a stock-accountability deficiency. SOD-014 · warehouse-performer-cannot-close-stock-deficiency |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| A laboratory control performer cannot independently approve a laboratory-quality exception. SOD-015 · lab-performer-cannot-approve-lab-quality-exception |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A restricted-locator access reviewer cannot independently attest to a case involving their own access decision. SOD-016 · locator-reviewer-cannot-attest-own-access-case |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| An asset custodian cannot independently attest to control effectiveness over their own custody records. SOD-017 · asset-custodian-cannot-attest-own-custody |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A program-result submitter cannot independently attest result-control effectiveness. SOD-018 · program-submitter-cannot-attest-result-control |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| An AI case generator cannot independently certify control effectiveness. SOD-019 · ai-generator-cannot-certify-control-effectiveness |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A rollout assessor cannot independently attest deployment readiness. SOD-020 · rollout-assessor-cannot-attest-deployment-readiness |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A review-packet author cannot independently attest unsupported capability compliance. SOD-021 · packet-author-cannot-attest-unsupported-capability |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| An identity approver cannot independently test and close a control involving their own decision. SOD-022 · identity-approver-cannot-test-close-own-control |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| A data-quality correction approver cannot independently attest reconciliation effectiveness. SOD-023 · dq-correction-approver-cannot-attest-reconciliation |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| An incident investigator cannot independently attest remediation effectiveness for their own case. SOD-024 · incident-investigator-cannot-attest-own-remediation |
pending | never silently overridden auditable · requires reassignment / independent / second review |
Evidence (presence ≠ verification; conflicts remain visible)
- EVD-001 — reconciliation-record present verified currentfund-accountability · control CTL-001
- EVD-002 — dispatch-receipt-record present partially-verified currentstockpile-logistics · control CTL-002
- EVD-003 — qc-record present verified currentlab-operations · control CTL-003
- EVD-004 — disclosure-log present verified currentpatient-continuity · control CTL-004
- EVD-005 — access-purpose-record present verified currentrestricted-patient-locator · control CTL-005
- EVD-006 — authorization-record missing unverified currentasset-management · control CTL-006
- EVD-007 — result-record present verified currentprogram-performance · control CTL-007
- EVD-008 — signal-review-record present unverified currentai-intelligence · control CTL-008
- EVD-009 — readiness-approval-record present verified currentcountry-rollout · control CTL-009
- EVD-010 — access-attribution-record present conflicting currentauthorized-review-room · control CTL-010
- EVD-011 — capability-claim-record present verified currentexecutive-review-packet · control CTL-011
- EVD-012 — access-decision-record present verified currentidentity-access-governance · control CTL-012
- EVD-013 — correction-record present verified currentdata-quality-reconciliation · control CTL-013
- EVD-014 — case-evidence-record present verified currentrisk-incident-case-governance · control CTL-014
- EVD-015 — legacy-correction-record present verified supersededdata-quality-reconciliation · control CTL-013
AI risk signals (human review required)
- unmapped-or-partial-obligation — Obligation OBL-008 remains partially mapped. confidence mediumhuman review: yes · autonomous action: no
- expired-policy — Policy POL-007 is expired. confidence highhuman review: yes · autonomous action: no
- missing-test-evidence — Control CTL-008 remains untested. confidence highhuman review: yes · autonomous action: no
- overdue-remediation — Remediation REM-002 is overdue. confidence highhuman review: yes · autonomous action: no
- expiring-exception — Exception EXC-002 expires soon. confidence mediumhuman review: yes · autonomous action: no
- unsupported-attestation — Attestation ATT-004 unsupported by evidence. confidence highhuman review: yes · autonomous action: no
- potentially-ineffective-compensating-control — Compensating control CMP-001 may be only partially effective. confidence mediumhuman review: yes · autonomous action: no
- inconsistent-conclusion-check — Test TST-006 conclusion consistent with recorded evidence. confidence mediumhuman review: yes · autonomous action: no
- expiring-waiver — Waiver WAV-001 expires within the review window. confidence mediumhuman review: yes · autonomous action: no
Immutable audit events (append-only)
Policy-version changes, control-test retests, exception events, remediation-effectiveness decisions, attestation revocations and supersessions, and waiver events all require new linked events; deletion is not an allowed governance control; source-module audit records remain authoritative. This is not a production cryptographic audit ledger.
- AUD-P-001 — policy-version-approved effectivepolicy-approver · fund-accountability · 2025-01-01T10:00:00Z · immutable: yes
- AUD-T-006 — control-test-recorded failcontrol-tester · asset-management · 2025-06-30T10:00:00Z · immutable: yes
- AUD-T-006-R — control-retest-recorded partial retest of TST-006control-tester · asset-management · 2025-09-15T10:00:00Z · immutable: yes
- AUD-E-002 — exception-approved approvedcompliance-reviewer · asset-management · 2025-07-01T10:00:00Z · immutable: yes
- AUD-EFR-001 — remediation-effectiveness-decided ineffectiveindependent-reviewer · authorized-review-room · 2025-10-15T10:00:00Z · immutable: yes
- AUD-A-006 — attestation-revoked revoked revocation of ATT-006compliance-reviewer · restricted-patient-locator · 2025-07-08T10:00:00Z · immutable: yes
- AUD-A-007 — attestation-superseded superseded supersession of ATT-007compliance-reviewer · data-quality-reconciliation · 2025-07-09T10:00:00Z · immutable: yes
- AUD-W-002 — waiver-denied deniedcompliance-reviewer · asset-management · 2025-07-03T10:00:00Z · immutable: yes
- AUD-W-003 — waiver-expired expiredcompliance-reviewer · country-rollout · 2025-03-01T10:00:00Z · immutable: yes
Controls by source module
- fund-accountability 1
- stockpile-logistics 1
- lab-operations 1
- patient-continuity 1
- restricted-patient-locator 1
- asset-management 2
- program-performance 1
- ai-intelligence 1
- risk-incident-case-governance 2
- country-rollout 1
- authorized-review-room 1
- executive-review-packet 1
- identity-access-governance 1
- data-quality-reconciliation 1
Obligations by category
- financial-accountability 1
- commodity-accountability 1
- laboratory-quality 1
- patient-continuity 1
- restricted-access 1
- asset-accountability 1
- program-performance 1
- ai-governance 1
- rollout-readiness 1
- packet-review 1
- evidence-package 1
- identity-access 1
- data-quality 1
- incident-investigation 1
- operational 1
Controls by type
- detective 5
- preventive 8
- corrective 1
- compensating 1
Tests by result / remediation by status
- pass 9
- partial 2
- fail 1
- not-tested 1
- blocked 1
- not-applicable 1
- in-progress 2
- completed 1
AI posture — assistive only, non-autonomous
AI assists with
- map policies and obligations to candidate controls
- identify unmapped or partially mapped obligations
- detect expired or superseded policies
- identify stale reviews
- detect control-design gaps
- identify missing test evidence
- compare test results across periods
- flag inconsistent conclusions
- identify overdue remediation
- identify expiring exceptions and waivers
- detect separation-of-duties conflicts
- summarize evidence for authorized human reviewers
- identify unsupported attestations
- recommend items for independent or second review
- reconcile module-control references
- identify potentially ineffective compensating controls
AI must never
- provide legal advice
- determine regulatory applicability autonomously
- certify compliance
- approve policies
- approve control design
- approve control-test results
- approve exceptions
- approve waivers
- approve remediation effectiveness
- sign or approve attestations
- convert missing evidence into a pass
- suppress failed tests, deficiencies, exceptions, or conflicting evidence
- alter source-module records
- fabricate evidence
- authorize deployment
- notify regulators, funders, ministries, auditors, or other external parties
- bypass human approval, independent review, second review, separation of duties, evidence, expiration, revocation, or audit controls
AI is assistive only. It may map policies and obligations to candidate controls, identify unmapped or partially mapped obligations, detect expired or superseded policies and stale reviews, detect control-design gaps and missing test evidence, compare test results across periods, flag inconsistent conclusions, identify overdue remediation and expiring exceptions and waivers, detect separation-of-duties conflicts, summarize evidence for authorized human reviewers, identify unsupported attestations, recommend items for independent or second review, reconcile module-control references, and identify potentially ineffective compensating controls. AI never determines compliance, certifies, approves, signs, or attests, and never bypasses human review, evidence, expiration, revocation, separation of duties, or audit controls.
Runtime boundary & module coverage
- Impact runtime:
impact.maxarchealth.comon127.0.0.1:3201. - Maps policies, obligations, and controls across fund accountability, stockpile & logistics, lab operations, patient continuity, restricted locator, asset management, program performance, AI intelligence, country rollout, the authorized review room, the executive review packet & controlled download center, identity & access governance, data quality & reconciliation, and risk, incident & case governance — without coupling to MaxTrax EHR.
- Medical Library boundary remains separate at
library.maxarchealth.com(port3101) and is not used here. - MaxTrax EHR remains separate; this is not a full EHR and implements no live integration or real database mutation.