{
  "tool_id": "art-501-build-safeguarding-audit-evidence",
  "tool_version": "1.0.0",
  "display_name": "CASS 15 Safeguarding Audit Evidence Pack",
  "mcp_name": "build_safeguarding_audit_evidence",
  "mandate_type": "compliance_mandate",
  "wave": 78,
  "gpu": false,
  "url": "https://ainumbers.co/chaingraph/art-501-build-safeguarding-audit-evidence.html",
  "description": "Assembles the evidence set a qualified auditor asks a UK payment or e-money firm for at the start of a CASS 15 safeguarding audit: the reconciliation results across the declared audit period, the safeguarding method classification, a schedule of the matters those raise keyed by the individual rule reference with a management response recorded against each item, and the section 27 accountability trail over the firm's own reconciliation export. It is the first consumer of the section 27.4 attested-artifact subject class: the export is a non-OCG producer's sealed output, so its subject identifier is computed by art-502-bind-attested-subject and echoed here verbatim rather than recomputed, because a second implementation of that preimage would be a second canon. The trail counts distinct identities, never records and never signing keys; an unsigned approval record is not conformant evidence and holds the role rather than passing it; an agent identity does not satisfy a human role absent an explicit human-role mandate; and because this surface reads no clock a time-boxed override can never resolve to a silent auto-pass. Stated limit, normative: the attested subject evidences producer pinning, input binding and content integrity, never that the arithmetic inside the firm's export is correct, and the artifact omits replay_verified entirely rather than setting it false because no replay was attempted. This pack expresses neither of the two audit opinions, systems adequacy throughout the period and compliance at the period end, which belong to the safeguarding auditor and are emitted as open slots naming who decides. It records no breach, it is evidence assembled for the engagement rather than a filing, it is not submittable to the FCA, and it does not discharge the audit.",
  "input_schema_ref": "chaingraph/art-501-build-safeguarding-audit-evidence.html#manifest",
  "consumes": [],
  "feeds": [],
  "status": "live",
  "conformance_fixtures": true,
  "compute_capability": "server",
  "compute_images": [
    {
      "system": "sha256-source",
      "image_id": "sha256:5156c7482d1a3d1e1bb5c0a83beeb2ebb542c9e5cd257c31c2007cd8fc4daab8",
      "valid_from": "2026-07-10"
    },
    {
      "system": "risc0",
      "image_id": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
      "valid_from": "2026-07-31"
    }
  ],
  "compute_proof_ready": "ready",
  "export_capability": [
    "json"
  ],
  "compute_proof": {
    "type": "ZkVmReceipt",
    "system": "risc0",
    "receiptFormat": "groth16-bn254",
    "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
    "seal": "J2ptoqGO4bDqgTpyek7rDSEYEnzERsIQz9w8dgtyaOIvrb3s7YrGr2FVQbUUIoGjIFItI8E8zi5Ch102P9B26QNefUp5hNPV7mwZlo4FdXDSlZ+5g3pf6O/xpQZjLozDCnHxNydweVMidg9RvHm/bY7oBpIfVu7rGW+EVRRoJr4O0q+ETHRo+0NUfJozA3Fssh4sutm5C38WUiaTi5bivh1ONt/yg1MZgn0KbekcCSvl5eGlMOO/Ijbv1CwNLhE+IUSO0E9o/W5AXWbdjHsQ9GSbaD891rHYHNnVtH9YuTAXjDMhOz+YOVbu77SNwcSp9f16t5ZHOibgDeB87i/YSw==",
    "journal": {
      "chaingraph_version": "0.4.0",
      "kernel_digest": "sha256:5156c7482d1a3d1e1bb5c0a83beeb2ebb542c9e5cd257c31c2007cd8fc4daab8",
      "output": {
        "accountability_trail": {
          "agent_parity_findings": [],
          "by_role": {
            "approver": {
              "approval_count": 1,
              "counted_identities": [
                "did:key:zApproverSynth1"
              ],
              "counted_identity_count": 1,
              "held_by": "The firm officer with legally effective sign-off.",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject.",
              "record_count": 1,
              "rejection_count": 0,
              "role": "approver",
              "status": "satisfied",
              "unsigned_approval_count": 0
            },
            "preparer": {
              "approval_count": 1,
              "counted_identities": [
                "did:key:zPreparerSynth1"
              ],
              "counted_identity_count": 1,
              "held_by": "The firm officer who prepared the reconciliation export.",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject.",
              "record_count": 1,
              "rejection_count": 0,
              "role": "preparer",
              "status": "satisfied",
              "unsigned_approval_count": 0
            },
            "reviewer": {
              "approval_count": 1,
              "counted_identities": [
                "did:key:zAuditorSynth1"
              ],
              "counted_identity_count": 1,
              "held_by": "The qualified auditor engaged to review it.",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject.",
              "record_count": 1,
              "rejection_count": 0,
              "role": "reviewer",
              "status": "satisfied",
              "unsigned_approval_count": 0
            }
          },
          "distinctness_basis": "Roles count DISTINCT identity.id (SPEC.md §27.3), never records and never signing keys. One human rotating keys, or signing twice, counts once.",
          "foreign_subject_record_count": 0,
          "override_handling": "A §27.5 override is time-boxed and its expiry can only be judged against an instant. This kernel reads no clock, so an override record NEVER satisfies a required role here and is reported instead. On expiry an override lapses and the underlying policy reverts; it can never become a silent permanent auto-pass through this surface.",
          "override_record_count": 0,
          "record_count_over_subject": 3,
          "required_roles": [
            "preparer",
            "reviewer",
            "approver"
          ],
          "roles_required_count": 3,
          "roles_satisfied_count": 3,
          "status": "satisfied",
          "subject_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111"
        },
        "audit_period": {
          "bounds_present": true,
          "end_date": "2027-05-06",
          "order_valid": true,
          "start_date": "2026-05-07"
        },
        "auditor_opinions": [
          {
            "assurance_basis": "reasonable_assurance",
            "citation_id": "SUP 3A",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "opinion_question": "Whether the firm maintained systems adequate to enable it to comply with the safeguarding rules throughout the audit period.",
            "opinion_ref": "systems_adequacy_throughout_period",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ]
          },
          {
            "assurance_basis": "reasonable_assurance",
            "citation_id": "SUP 3A",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "opinion_question": "Whether the firm was in compliance with the safeguarding rules at the date as at which the report is made.",
            "opinion_ref": "compliance_at_period_end",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ]
          }
        ],
        "citations": {
          "discrepancy_treatment": {
            "id": "CASS 15.8.50R",
            "in_force_from": "2026-05-07",
            "mapped_at": "2026-07-30",
            "mapped_by": "AINumbers CASS15-K-2",
            "scheme": "fca-handbook",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "external_frequency": {
            "id": "CASS 15.8.42R",
            "in_force_from": "2026-05-07",
            "mapped_at": "2026-07-30",
            "mapped_by": "AINumbers CASS15-K-2",
            "scheme": "fca-handbook",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "internal_frequency": {
            "id": "CASS 15.8.19R",
            "in_force_from": "2026-05-07",
            "mapped_at": "2026-07-30",
            "mapped_by": "AINumbers CASS15-K-2",
            "scheme": "fca-handbook",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "safeguarding_audit": {
            "id": "SUP 3A",
            "in_force_from": "2026-05-07",
            "mapped_at": "2026-07-30",
            "mapped_by": "AINumbers CASS15-K-2",
            "scheme": "fca-handbook",
            "uri": "https://handbook.fca.org.uk/handbook/SUP/3A/"
          },
          "safeguarding_requirement": {
            "id": "CASS 15.8.29G",
            "in_force_from": "2026-05-07",
            "mapped_at": "2026-07-30",
            "mapped_by": "AINumbers CASS15-K-2",
            "scheme": "fca-handbook",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "safeguarding_resource": {
            "id": "CASS 15.8.26R",
            "in_force_from": "2026-05-07",
            "mapped_at": "2026-07-30",
            "mapped_by": "AINumbers CASS15-K-2",
            "scheme": "fca-handbook",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          }
        },
        "evidence_items": [
          {
            "detail": "A declared audit period with a start date and an end date in order.",
            "item": "audit_period",
            "present": true
          },
          {
            "detail": "The §27.4 subject identifier for the firm's reconciliation export, computed by art-502.",
            "item": "attested_subject",
            "present": true
          },
          {
            "detail": "Reconciliation results across the audit period.",
            "item": "reconciliation_results",
            "present": true
          },
          {
            "detail": "The safeguarding method classification for the firm's funds streams.",
            "item": "method_classification",
            "present": true
          },
          {
            "detail": "A signed preparer, reviewer and approver trail over the attested subject.",
            "item": "accountability_trail",
            "present": true
          },
          {
            "detail": "A management response recorded against every item in the exception schedule.",
            "item": "management_responses",
            "present": true
          }
        ],
        "exception_count": 0,
        "exception_schedule": [],
        "firm_ref": "FIRM-SYNTH-0001",
        "method_summary": {
          "audit_exemption_indicator": {
            "basis": "Relevant funds held exceed the exemption level.",
            "outcome": "audit_required"
          },
          "classification_verdict": "COHERENT_ON_SUPPLIED_FACTS",
          "coherent_count": 2,
          "incoherent_count": 0,
          "open_judgment_count": 0,
          "stream_count": 2,
          "supplied": true
        },
        "minor_unit_exponent": 2,
        "missing_items": [],
        "no_arithmetic_claim": "The attested-artifact subject this pack is bound to evidences producer pinning, input binding and content integrity. It carries no §18 compute proof and no §16/§17 re-execution claim, and it never evidences that the arithmetic inside the firm's reconciliation export is correct. This artifact deliberately omits replay_verified rather than setting it false, because no replay was attempted.",
        "not_a_filing": "This is evidence assembled for a safeguarding audit engagement. It is not a regulatory filing, it is not submittable to the FCA, it does not reproduce the prescribed report as a fillable form, and it does not discharge the audit. An approval record inside it is evidence of a human act, never a claim that any regulator has accepted anything.",
        "note": "Deterministic UK CASS 15 safeguarding audit evidence pack. Single-run and stateless: it holds no records, runs on no schedule, and retains nothing. It assembles reconciliation results, the safeguarding method classification, a schedule of matters for the auditor keyed by rule reference, and the §27 accountability trail over an attested-artifact subject computed by art-502 and echoed here rather than recomputed. It recomputes no safeguarding arithmetic, records no breach, and expresses neither of the two audit opinions, which belong to the safeguarding auditor. It is not a filing and not legal advice.",
        "pack_complete": true,
        "rationale": [
          "Evidence pack assembled for firm reference FIRM-SYNTH-0001 against FCA CASS 15 safeguarding rules, as made by PS25/12, in force from 2026-05-07, for the audit period 2026-05-07 to 2027-05-06.",
          "The pack is bound to attested-artifact subject sha256:1111111111111111111111111111111111111111111111111111111111111111, computed by art-502-bind-attested-subject on the single canonical §27.4 path. This kernel echoes that identifier and deliberately does not recompute it: a second implementation of the preimage would be a second canon.",
          "3 reconciliation results carried: 3 reconciled, 0 shortfall, 0 excess. Every verdict is taken as supplied; no safeguarding arithmetic is recomputed here.",
          "Method classification carried as supplied: COHERENT_ON_SUPPLIED_FACTS across 2 streams, with 0 incoherent and 0 questions left open.",
          "The supplied results raised no matters for the auditor's attention. That is a statement about the figures supplied, not a finding that the firm complied with CASS 15.",
          "Each of the preparer, reviewer and approver roles is named by at least one signed record over this subject, counted by distinct identity.",
          "Neither audit opinion is expressed here. The systems-adequacy and period-end compliance opinions belong to the safeguarding auditor, and this pack leaves both open with the question and the decider named.",
          "This pack is evidence assembled for the engagement. It is not a filing, it is not submittable to the FCA, and it does not discharge the audit. An approval record inside it evidences that a named human acted and nothing more."
        ],
        "reconciliation_summary": {
          "entries": [
            {
              "as_of_date": "2026-06-30",
              "currency": "GBP",
              "date_stated": true,
              "difference_direction": "level",
              "difference_display": "0.00",
              "entry_ref": "RECON-2026-06-30",
              "reconciliation_type": "internal",
              "safeguarding_requirement_display": "1250000.00",
              "safeguarding_resource_display": "1250000.00",
              "verdict": "reconciled",
              "within_period": true
            },
            {
              "as_of_date": "2026-09-30",
              "currency": "GBP",
              "date_stated": true,
              "difference_direction": "level",
              "difference_display": "0.00",
              "entry_ref": "RECON-2026-09-30",
              "reconciliation_type": "internal",
              "safeguarding_requirement_display": "1310000.00",
              "safeguarding_resource_display": "1310000.00",
              "verdict": "reconciled",
              "within_period": true
            },
            {
              "as_of_date": "2026-12-31",
              "currency": "GBP",
              "date_stated": true,
              "difference_direction": "level",
              "difference_display": "0.00",
              "entry_ref": "RECON-2026-12-31",
              "reconciliation_type": "external",
              "safeguarding_requirement_display": "1402500.00",
              "safeguarding_resource_display": "1402500.00",
              "verdict": "reconciled",
              "within_period": true
            }
          ],
          "entry_count": 3,
          "excess_count": 0,
          "outside_period_count": 0,
          "reconciled_count": 3,
          "shortfall_count": 0,
          "undated_count": 0,
          "unstated_verdict_count": 0
        },
        "report_vocabulary": {
          "assurance_basis": "reasonable_assurance",
          "exception_schedule_key": "rule_reference",
          "management_response_required_per_item": true,
          "opinion_refs": [
            "systems_adequacy_throughout_period",
            "compliance_at_period_end"
          ],
          "permitted_opinion_outcomes": [
            "unmodified",
            "qualified",
            "adverse"
          ],
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30",
          "vocabulary_basis": "The safeguarding assurance report is a reasonable assurance engagement stating two opinions, systems adequacy throughout the period and compliance at the period end, with exceptions listed against the individual rule reference and a management response recorded against each item. This pack uses those names so its output pastes into the engagement rather than into a format we invented."
        },
        "ruleset": {
          "field_set_version": "1.0.0",
          "in_force_from": "2026-05-07",
          "ruleset_id": "FCA-CASS15-PS25-12",
          "ruleset_label": "FCA CASS 15 safeguarding rules, as made by PS25/12",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "subject": {
          "binding_complete": true,
          "binding_source_tool_id": "art-502-bind-attested-subject",
          "inputs_digest_source": "derived",
          "producer_pinned": true,
          "subject_class": "attested_artifact",
          "subject_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
          "subject_preimage": {
            "artifact": {
              "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
              "content_type": "application/pdf"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "tool_ref": {
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0"
            }
          },
          "subject_recomputed_here": false
        }
      }
    }
  }
}
