LensReading which lens this session carries.

Prove · what an outsider would need

What An Outsider Would Need

Four named outside parties would come to this estate with 48 questions between them. 5 questions could be answered today with something an outside party has checked, which is 10.4% of the set. 32 have an artifact that exists but has never been checked from outside, and 11 cannot be answered at all.

Actions

What is waiting on a person

Nothing below is a defect in an agent. Each line is a question a named outside party is entitled to ask, and the state of the answer this estate could hand over today.

Operations

What this desk is allowed to start

A surface that only reports is not operable. This is the work this page can set in motion, and the bound it runs into.

Trigger and bound

This page issues nothing and requests nothing. It holds a register of 48 requirements drawn from 47 named standards and articles, points each at the surface in this estate that would have to answer it, and re-derives every state from live counts on load. It does not contact an auditor, open an engagement or produce a report pack. Its only job is to let somebody read the failures before an outsider does.

Live observability

What the record shows right now

48 requirements across 4 outside parties, split by what the estate could actually hand over. The middle band is the one that gets mistaken for the first.

Current distribution

48 requirements

checked from outside510%
artifact exists, never checked3267%
cannot answer1123%

Is policy and strategy coming to fruition

Whether the written intent is holding here

No. 10.4% of the register is answered by something an outside party has read, and 11 questions have no artifact behind them at all.

Not holding on the record

The strategy asked for an estate that could be shown to somebody outside it. What the record supports is narrower. 5 of 48 requirements are met by an artifact a party outside the company examined, 32 are met by artifacts the company wrote about itself, and 11 cannot be met at all. Sector supervisor would leave with nothing that has been checked from outside. External auditor has the widest hole, with 4 of 14 questions unanswerable. The gap does not close by writing more artifacts. It closes when a party with no stake in the answer reads the ones already written.

Questions on the register
48
4 parties · 47 named sources · 32 point at a page in this estate
Answerable today
5
10.4% of the set, each backed by a firm named below
Artifact exists, never checked outside
32
These have a page and a record. Nobody outside this company has read them.
Cannot answer at all
11
Itemized in full lower down. No artifact, no record, no answer.

Who has actually signed something

3 outside signatures are current and 3 are not

SOC 2 Type II
AICPA Trust Services Criteria · Marsden Wright LLP
current
ISO/IEC 27001:2022
Information security management system · Nordveld Certification AB
current
ISO/IEC 42001:2023
Artificial intelligence management system · Nordveld Certification AB
in-progress
Cyber Essentials Plus
UK National Cyber Security Centre · Bardsey Assurance Ltd
expired
External application and network penetration test
CREST-accredited, grey box · Hallward Red Team Ltd
current
Infrastructure penetration test
CREST-accredited, black box · Hallward Red Team Ltd
expired
4 firms are named across these records: Marsden Wright LLP, Nordveld Certification AB, Bardsey Assurance Ltd, Hallward Red Team Ltd. Coverage of a requirement set is not an opinion on it. Nothing on this page has been signed by an outside party except the items named in the signature panel, and none of those covers the processes this platform runs.

Party by party

The three columns, kept apart

An artifact that exists but has never been read by an outsider is not an answer, so it never joins the answered column. Sector supervisor would leave with nothing checked from outside at all.

External auditor

14 questions · 1 answerable with an outside check · 9 resting on an unchecked artifact · 4 unanswerable

A service auditor arriving to form an opinion on the controls over an outsourced process, and to sample transactions through it.
The area that fails hardest is Systems of record, where 2 of 2 questions cannot be answered.
Answerable today
1
An outside party has read the artifact behind each of these. 7.1% of the set.
A service auditor report on the security of the platform on which the processing runs, covering the period under audit.
ER-AUD-13 · Control environment · asked under AICPA Trust Services Criteria (2017, revised 2022), Security
3 items on the trust register are current and carry a named outside firm, including a SOC 2 Type II report. Its scope is the platform, not the 24 process controls above, and the report says so.
Trust register
Artifact exists, unchecked
9
The record is there. No outsider has looked at it, so it is not an answer yet. 64.3% of the set.
A written description of the controls over the processes this platform runs, and evidence that each control operated throughout the period rather than at a single point in it.
ER-AUD-01 · Control environment · asked under ISAE 3402 Type II, paragraphs 9 and 20
24 controls are described and 17 have been tested at least once. Every test was run from inside the company, so the description has never been examined by a service auditor.
Control register and test history
Sample-based testing of each control by a party independent of the control owner, recording the sample method, the sample size and every exception.
ER-AUD-02 · Control environment · asked under ISAE 3402 Type II, paragraph 30
47 tests are recorded with method, sample size and result. 6 of them were run by the owning organization rather than an independent tester, and 41 by Internal Audit. Internal Audit is independent of the owner and inside the company; it is not a service auditor.
Control test results
Every control exception, its cause, the remediation applied, and whether that remediation has itself been tested.
ER-AUD-03 · Control environment · asked under ISAE 3402 Type II, paragraph 38
6 control tests failed. 12 exceptions and 23 remediation entries are recorded against them. No entry carries a retest signed by anyone outside the company.
Exception and remediation register
A durable record of every transaction the system processed, complete enough to re-perform a selected item end to end and reach the same result.
ER-AUD-04 · Evidence and re-performance · asked under ISA 315 (Revised 2019), paragraphs 25 and 26
8,080 records are chained, of which 8,080 carry both an input and an output digest and 67 supersede an earlier record. No outside party has re-performed a single item.
Evidence spine
The ability to replay a decision with the inputs, the policy version and the model version that were in force at the moment it was taken.
ER-AUD-06 · Evidence and re-performance · asked under ISA 330, paragraph 8; PCAOB AS 1105, paragraph 10
8,080 records carry the digests, policy version and model version a replay needs. The replay has been demonstrated internally and never witnessed by an outside party.
Replay surface
A register of who may approve what, to what value, with evidence that the limit was enforced at the moment of approval rather than reviewed afterwards.
ER-AUD-07 · Authority and duties · asked under PCAOB AS 2201, paragraph 34
309 grants are recorded and 309 are active, each with a value cap and a breach action. No outside party has tested whether a cap actually held.
Authority register
Evidence that incompatible duties cannot be performed by the same actor, enforced by the system rather than detected after the fact.
ER-AUD-08 · Authority and duties · asked under COSO Internal Control - Integrated Framework (2013), Principle 10
6 duty rules exist and 1 of them block at the moment of action. The remaining 5 detect afterwards, and 385 conflicts are open right now. The register answers the question, and the answer is unflattering.
Duty rules and open conflicts
A record of where each reported figure came from, field by field, from the source object to the number on the page.
ER-AUD-11 · Evidence and re-performance · asked under ISA 500, paragraph 9
7,560 lineage facts name a source object, a source field and a transformation. They describe intended paths from systems that are not connected, so no lineage claim has been walked back to a live source.
Field lineage
A retention schedule applied to the records themselves, and evidence that a legal hold suspends deletion while the matter is open.
ER-AUD-12 · Retention and holds · asked under ISA 230, paragraphs 14 to 16
8 retention classes are defined and 6 legal holds are recorded, 5 of them active. No deletion run and no hold release has been observed by anyone outside the company.
Retention classes and legal holds
Cannot answer
4
There is no artifact to hand over. 28.6% of the set.
Proof that the population offered for sampling is the whole population, and not a subset the system chose to show.
ER-AUD-05 · Evidence and re-performance · asked under ISA 500, paragraph A52
The estate publishes two different weekly volumes for the same work and reconciles neither to the other. Until those two counts agree, or the difference is explained line by line, there is no population statement to hand over.
Reconciliation breaks
The ability to trace a sampled item from this platform into the system of record where the accounting entry actually lives.
ER-AUD-09 · Systems of record · asked under ISA 315 (Revised 2019), paragraph 26(a)
26 source systems are described and 0 are connected. There is no live path from this platform to any system of record, so no sampled item can be traced beyond this platform's own store.
Source system register
Evidence that anything this platform writes back into a system of record is authorized, logged and reversible.
ER-AUD-10 · Systems of record · asked under ISAE 3402 Type II, paragraph 20(b)
19 write-back routes are specified and 0 are live. Nothing has been written back, so there is nothing for an auditor to test.
Write-back routes
A bridge letter covering the gap between the end of the last report period and the audit date.
ER-AUD-14 · Control environment · asked under AICPA Guide, Reporting on Controls, paragraph 4.87
No bridge letter is held. The trust register records reports and their dates; it does not record any management assertion covering the period since.
Trust register

Works council

10 questions · 1 answerable with an outside check · 7 resting on an unchecked artifact · 2 unanswerable

An employee representative body with a statutory right to be informed and consulted before a monitoring-capable system is introduced.
The area that fails hardest is Consultation, where 1 of 3 question cannot be answered.
Answerable today
1
An outside party has read the artifact behind each of these. 10.0% of the set.
Evidence that the competent employee representative body was informed and consulted before the system was introduced, not after.
ER-WC-01 · Consultation · asked under Directive 2002/14/EC, Articles 4(2) and 4(4)
1 of 7 jurisdictions has concluded with an opinion delivered by the body itself, carrying three standing conditions. That is the only requirement on this page answered by a party outside the company other than a paid firm. The other 6 have not concluded.
Consultation packs
Artifact exists, unchecked
7
The record is there. No outsider has looked at it, so it is not an answer yet. 70.0% of the set.
A plain statement of what the system observes about a named worker, at what grain, and how long each observation is kept.
ER-WC-03 · Monitoring · asked under Directive 2002/14/EC, Article 4(2)(b); GDPR Article 13(2)(a)
Monitoring commitments are recorded in 7 packs and the retention grain in 8 classes. No representative body has confirmed the statement matches what the system actually observes.
Workforce effect
A statement of which decisions the system takes alone, which a person takes, and which a person may overturn.
ER-WC-05 · Decision rights · asked under Directive 2002/14/EC, Article 4(2)(c)
Decision rights are recorded in 7 packs and enforced through the gate model. No body outside the company has walked a decision through the gates to see where it actually stops.
Human gates and decision rights
A named route by which an affected worker can contest an outcome, and evidence that route has been used and answered.
ER-WC-06 · Redress · asked under Directive 2002/14/EC, Article 4(4)(e); GDPR Article 22(3)
13 appeals are recorded with a route and an outcome. No representative body has reviewed whether the route is reachable by a worker who was not told it exists.
Appeals
The effect on headcount, on role content and on grading, by role and by site, before the change takes effect.
ER-WC-07 · Workforce effect · asked under Betriebsverfassungsgesetz, Section 90(1) number 4 and Section 90(2)
Headcount covered and roles covered are recorded across 7 packs. The figures are the company's own and have not been checked by the bodies they were prepared for.
Workforce effect
The consultation material in the working language of each site, not only in English.
ER-WC-08 · Monitoring · asked under Directive 2002/14/EC, Article 4(3)
12 locales are declared and 32 policy translations exist. No translation has been accepted as accurate by the body that would read it.
Locales and policy translations
Evidence that an error made by the system was corrected for the individual affected, not only for the process.
ER-WC-09 · Redress · asked under GDPR Article 16; Directive 2002/14/EC, Article 4(4)(e)
16 incidents are recorded with the units affected and the units reversed. Reversal is counted at the unit level; no record states that a named individual was told and made whole.
Incident register
A commitment to re-consult before any material change to what the system decides or observes.
ER-WC-10 · Consultation · asked under Directive 2002/14/EC, Article 4(2)(c)
One concluded consultation carries a standing condition that a change to the sampling weight is treated as a policy change and disclosed. The condition binds one jurisdiction only, and no release has yet tested it.
Change releases
Cannot answer
2
There is no artifact to hand over. 20.0% of the set.
A signed works agreement covering the use of a technical system capable of monitoring behavior or performance.
ER-WC-02 · Consultation · asked under Betriebsverfassungsgesetz, Section 87(1) number 6
No signed works agreement is held in any jurisdiction. 2 packs are issued and awaiting a response, 1 has not been started. Issuing a pack is not agreement.
Consultation packs
Evidence that observations are not aggregated into an individual performance score without a separate agreement.
ER-WC-04 · Monitoring · asked under Betriebsverfassungsgesetz, Section 87(1) number 6; GDPR Article 22
The estate holds no statement about individual performance scoring, in either direction. Silence is not an answer, and the absence is recorded here rather than argued away.
Experience and effect

Sector supervisor

14 questions · none answerable with an outside check · 10 resting on an unchecked artifact · 4 unanswerable

A market surveillance or data protection authority arriving with the AI Act and the GDPR in hand.
The area that fails hardest is Conformity, where 2 of 2 questions cannot be answered.
Answerable today
0
An outside party has read the artifact behind each of these. Nothing sits here.
Empty column.
Artifact exists, unchecked
10
The record is there. No outsider has looked at it, so it is not an answer yet. 71.4% of the set.
A risk management system that runs across the whole lifecycle of each high-risk system, documented and kept up to date.
ER-SUP-01 · Risk management · asked under Regulation (EU) 2024/1689, Article 9
16 agents are classified and 13 carry a conformity position. Every position is self-assessed; 3 have no position at all.
Agent risk register
Technical documentation for each high-risk system, drawn up before it is put into service and kept current.
ER-SUP-04 · Technical documentation · asked under Regulation (EU) 2024/1689, Article 11 and Annex IV
12 models are registered with version, hosting, data boundary and contract type, and 8 have a tested substitute. The register is a component list; it is not Annex IV documentation, and no outside reader has said whether it would pass for one.
Model register
Automatic recording of events over the lifetime of the system, at a grain that lets a supervisor identify situations that present a risk.
ER-SUP-05 · Logging · asked under Regulation (EU) 2024/1689, Article 12
8,080 records are chained and cover actor, action, outcome, policy version and model version. No supervisor has been given access to test whether the grain is sufficient.
Evidence spine
Human oversight designed into the system so that a person can intervene, override or stop it while it is running.
ER-SUP-06 · Human oversight · asked under Regulation (EU) 2024/1689, Article 14
Gates, human stops and kill switches are declared across the workflow lines. Most lines have no tested containment at all, and the estate publishes that number rather than the design intent.
Blast radius and containment
Evidence of accuracy, robustness and resilience against attempts to manipulate the system, appropriate to its intended purpose.
ER-SUP-07 · Accuracy and robustness · asked under Regulation (EU) 2024/1689, Article 15
24 adversarial tests exist, 22 have been run and 9 were run by someone other than the builder. None was run by a party outside the company, and none of them targets an agent that carries a risk class.
Adversarial tests
A post-market monitoring plan and the data collected under it, kept for the life of the system.
ER-SUP-08 · Post-market · asked under Regulation (EU) 2024/1689, Article 72
115 evaluation suites and 460 runs give a monitoring signal. There is no plan document that says what is monitored, at what threshold and for how long, so what exists is monitoring without a stated plan.
Drift and monitoring
A statement to each affected person that they are interacting with an automated system, and what it decides.
ER-SUP-10 · Transparency · asked under Regulation (EU) 2024/1689, Article 50; GDPR Article 13(2)(f)
Explanations are generated for decisions inside the estate. No record states that the explanation was actually shown to the person the decision was about.
Explanations
A record of processing activities covering purpose, categories of data subject, recipients and transfers.
ER-SUP-11 · Personal data · asked under Regulation (EU) 2016/679, Article 30
10 record classes are described with lawful basis, retention and residency rule, 1 of them special category. No supervisory authority has seen the register.
Record classes
A data protection impact assessment for processing likely to result in a high risk, completed before processing begins.
ER-SUP-12 · Personal data · asked under Regulation (EU) 2016/679, Article 35
Two impact assessments are on the trust register, one current and one in progress. Neither carries an outside reviewer, and the one covering customer decisions is not finished.
Trust register
A transfer mechanism and a completed transfer impact assessment for every route that moves personal data out of the jurisdiction.
ER-SUP-13 · Personal data · asked under Regulation (EU) 2016/679, Chapter V; Schrems II, Case C-311/18
16 routes are described and 10 carry a completed assessment; 2 are stale and the rest are either in progress or judged not to need one. 1 of 59 data placements sits outside its sanctioned location.
Transfer routes
Cannot answer
4
There is no artifact to hand over. 28.6% of the set.
A conformity assessment carried out by a notified body, with the resulting certificate and its scope.
ER-SUP-02 · Conformity · asked under Regulation (EU) 2024/1689, Articles 43 and 44
No notified body has assessed anything in this estate. All 13 conformity positions were reached by the company about itself.
Agent risk register
Registration of each high-risk system in the EU database before it is placed on the market or put into service.
ER-SUP-03 · Conformity · asked under Regulation (EU) 2024/1689, Articles 49 and 71
No registration record exists anywhere in the estate. There is no field for one, which is itself the answer.
Agent risk register
Notification of each serious incident to the market surveillance authority within the period the regulation sets.
ER-SUP-09 · Post-market · asked under Regulation (EU) 2024/1689, Article 73
16 incidents are recorded internally and none carries a notification to any authority. The register has no field for one.
Incident register
A fundamental rights impact assessment for deployment by a body governed by public law or providing a public service.
ER-SUP-14 · Personal data · asked under Regulation (EU) 2024/1689, Article 27
No fundamental rights impact assessment exists. Fairness readings measure outcome spread; they are not the assessment the article asks for and are not offered as one.
Fairness readings

Customer security review

10 questions · 3 answerable with an outside check · 6 resting on an unchecked artifact · 1 unanswerable

A customer security team running a vendor review before they will sign, working from a standard questionnaire.
The area that fails hardest is Assurance reports, where 1 of 5 question cannot be answered.
Answerable today
3
An outside party has read the artifact behind each of these. 30.0% of the set.
A current SOC 2 Type II report covering security, issued by an independent public accounting firm.
ER-CUS-01 · Assurance reports · asked under CSA Consensus Assessments Initiative Questionnaire v4, A&A-02
A SOC 2 Type II report is current on the trust register and names the firm that issued it. It covers the platform and excludes the processes run on top of it.
Trust register
A current information security management system registration issued by an accredited body, with the scope statement.
ER-CUS-02 · Assurance reports · asked under CSA Cloud Controls Matrix v4, GRC-01
An ISO/IEC 27001:2022 registration is current and names the accredited body that issued it, together with its scope and exclusions.
Trust register
An independent penetration test of the application within the last twelve months, with the findings and their closure.
ER-CUS-03 · Assurance reports · asked under Shared Assessments SIG Lite, Section I; CCM v4 TVM-06
A CREST-accredited grey box test of the application and network is current and names the firm. Separately, 2 tests on the register have expired and the assessment of prompt injection and tool abuse is still in progress.
Trust register
Artifact exists, unchecked
6
The record is there. No outsider has looked at it, so it is not an answer yet. 60.0% of the set.
Federated sign-in with the customer identity provider, and evidence that access is removed when a person leaves.
ER-CUS-05 · Access control · asked under CSA Cloud Controls Matrix v4, IAM-08 and IAM-11
3 identity providers are described and 22 provisioning events are recorded. No customer has tested a leaver against them.
Identity and provisioning
A statement of where customer data is stored and processed, by jurisdiction, including every onward location.
ER-CUS-06 · Data handling · asked under CSA CAIQ v4, DSP-19
59 placements name a jurisdiction, a system and a volume, and 1 of them is outside its sanctioned location. The statement has never been checked by a customer.
Residency placements
A list of sub-processors with a signed data processing agreement for each, and notice before any is added.
ER-CUS-07 · Supply chain · asked under CSA CAIQ v4, STA-07; GDPR Article 28(2)
14 sub-processors are listed and 2 have no signed agreement recorded. No notice mechanism is described anywhere in the estate.
Sub-processors and vendors
A tested recovery capability with a stated objective, and the measured result of the last exercise.
ER-CUS-08 · Resilience · asked under CSA Cloud Controls Matrix v4, BCR-06
16 exercises are recorded, 10 produced a measured time and 10 had an observer independent of the team running them. Every observer was an employee. A drill time is not a production recovery time and is never presented as one.
Recovery drills
A documented exit: the format the data comes back in, the time it takes, and what is destroyed afterwards.
ER-CUS-09 · Data handling · asked under CSA CAIQ v4, DSP-16; SIG Lite, Section D
14 portability assets describe what leaves and in what shape. No exit has ever been rehearsed, so the stated time is a plan, not a measurement.
Portability assets
A completed security questionnaire with evidence attached to each answer.
ER-CUS-10 · Assurance reports · asked under Shared Assessments SIG Lite, full return
30 questions are on the return: 12 answered, 7 recorded as cannot answer and the remainder partial. The return is filled in by the company about itself, which is what a questionnaire is.
Vendor questionnaire
Cannot answer
1
There is no artifact to hand over. 10.0% of the set.
A management assertion covering the period since the last report period closed.
ER-CUS-04 · Assurance reports · asked under CSA CAIQ v4, A&A-03
No bridge assertion is held. 3 items on the register are recorded as not held at all, including a privacy management registration and an independent model risk review.
Trust register

The shortfall, itemized

11 questions this estate cannot answer at all

The shortfall is listed, never summarized. A count of gaps tells an executive nothing they can act on; the requirement, its source and the reason it cannot be answered do.
Proof that the population offered for sampling is the whole population, and not a subset the system chose to show.
ER-AUD-05
External auditor · Evidence and re-performance · asked under ISA 500, paragraph A52
The estate publishes two different weekly volumes for the same work and reconciles neither to the other. Until those two counts agree, or the difference is explained line by line, there is no population statement to hand over.
The ability to trace a sampled item from this platform into the system of record where the accounting entry actually lives.
ER-AUD-09
External auditor · Systems of record · asked under ISA 315 (Revised 2019), paragraph 26(a)
26 source systems are described and 0 are connected. There is no live path from this platform to any system of record, so no sampled item can be traced beyond this platform's own store.
Evidence that anything this platform writes back into a system of record is authorized, logged and reversible.
ER-AUD-10
External auditor · Systems of record · asked under ISAE 3402 Type II, paragraph 20(b)
19 write-back routes are specified and 0 are live. Nothing has been written back, so there is nothing for an auditor to test.
A bridge letter covering the gap between the end of the last report period and the audit date.
ER-AUD-14
External auditor · Control environment · asked under AICPA Guide, Reporting on Controls, paragraph 4.87
No bridge letter is held. The trust register records reports and their dates; it does not record any management assertion covering the period since.
A signed works agreement covering the use of a technical system capable of monitoring behavior or performance.
ER-WC-02
Works council · Consultation · asked under Betriebsverfassungsgesetz, Section 87(1) number 6
No signed works agreement is held in any jurisdiction. 2 packs are issued and awaiting a response, 1 has not been started. Issuing a pack is not agreement.
Evidence that observations are not aggregated into an individual performance score without a separate agreement.
ER-WC-04
Works council · Monitoring · asked under Betriebsverfassungsgesetz, Section 87(1) number 6; GDPR Article 22
The estate holds no statement about individual performance scoring, in either direction. Silence is not an answer, and the absence is recorded here rather than argued away.
A conformity assessment carried out by a notified body, with the resulting certificate and its scope.
ER-SUP-02
Sector supervisor · Conformity · asked under Regulation (EU) 2024/1689, Articles 43 and 44
No notified body has assessed anything in this estate. All 13 conformity positions were reached by the company about itself.
Registration of each high-risk system in the EU database before it is placed on the market or put into service.
ER-SUP-03
Sector supervisor · Conformity · asked under Regulation (EU) 2024/1689, Articles 49 and 71
No registration record exists anywhere in the estate. There is no field for one, which is itself the answer.
Notification of each serious incident to the market surveillance authority within the period the regulation sets.
ER-SUP-09
Sector supervisor · Post-market · asked under Regulation (EU) 2024/1689, Article 73
16 incidents are recorded internally and none carries a notification to any authority. The register has no field for one.
A fundamental rights impact assessment for deployment by a body governed by public law or providing a public service.
ER-SUP-14
Sector supervisor · Personal data · asked under Regulation (EU) 2024/1689, Article 27
No fundamental rights impact assessment exists. Fairness readings measure outcome spread; they are not the assessment the article asks for and are not offered as one.
A management assertion covering the period since the last report period closed.
ER-CUS-04
Customer security review · Assurance reports · asked under CSA CAIQ v4, A&A-03
No bridge assertion is held. 3 items on the register are recorded as not held at all, including a privacy management registration and an independent model risk review.

What independence means here

Independent verification stands at 24.7% of the record, all of it internal

Independence in this estate means independent of the author, not independent of the company. Every independent check on record was carried out by Internal Audit, which is an employee function.
62 of 251 verification records carry an independent checker. None of them names a party outside this company.
6 of 47 control tests were run by the control owner rather than a separate team. 7 of 24 controls have never been tested at all.
9 of 24 adversarial tests were run independently, and every one of them by the same person. 10 of 16 recovery drills had an independent observer, all of them employees.

Where the register and the live estate disagree

Every stored state matches what the estate shows right now.

Each state on this page is recomputed from the live estate every time the page loads and compared against what was written when the register was built. Nothing has moved since, so the stored register and the live counts agree.
No drift to report. This is the least interesting outcome and also the honest one.

What this page still does not prove

Read this before taking any of it to an outside party

Three words are refused on this page. Nothing here is audit-ready, nothing here is compliant, nothing here is certified, so nothing here says otherwise. Where a requirement is met, the page says which outside firm looked and what its scope excluded.

No party on this page is shown as passing, and none is shown as failing either. A requirement set is a list of questions; only the party that asks them can say whether the answers satisfy it. Customer security review has the most answers at 3 of 10, which is still not an opinion in this estate’s favor.

External auditor would find the widest hole, with 4 of 14 questions unanswerable. The register is 48 questions long and was written here, from published requirement sets, by the same people who built the estate. An outside party would bring its own list, and that list would not match this one.

The estate describes 26 source systems and has connected 0 of them. It specifies 19 write-back routes and 0 of those are live. Every figure any of these parties would test rests on modeled data, so a satisfying answer on this page is a satisfying answer about a model.