{
  "tool_id": "art-501-build-safeguarding-audit-evidence",
  "note": "Vectors computed directly from the shipped kernel. complete-pack-trail-satisfied exercises a fully bound pack with a signed preparer/reviewer/approver trail; shortfall-and-incoherence-raise-matters proves a shortfall day and a method incoherence reach the exception schedule keyed by rule reference with a management response against one of them; unsigned-approval-holds-the-trail proves an approval without a section 16 proof is not conformant evidence and holds rather than passes; agent-approver-without-human-role-mandate exercises the section 27.8 parity rule; override-record-never-counted proves a time-boxed override cannot pass a role on a clock-free surface; empty-pack-resolves-defined is the finite gate. All values are SYNTHETIC.",
  "vectors": [
    {
      "name": "complete-pack-trail-satisfied",
      "description": "A fully bound pack: a pinned attested subject from art-502, three reconciled days inside the declared period, a coherent method classification, and one signed record in each of the three required roles. No matters raised, so the pack is complete. Neither audit opinion is expressed.",
      "policy_parameters": {
        "firm_ref": "FIRM-SYNTH-0001",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06"
        },
        "attested_subject": {
          "subject_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "application/pdf",
              "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "derived"
        },
        "reconciliation_results": [
          {
            "entry_ref": "RECON-2026-06-30",
            "as_of_date": "2026-06-30",
            "reconciliation_type": "internal",
            "verdict": "reconciled",
            "difference_direction": "level",
            "difference_display": "0.00",
            "safeguarding_requirement_display": "1250000.00",
            "safeguarding_resource_display": "1250000.00",
            "currency": "GBP"
          },
          {
            "entry_ref": "RECON-2026-09-30",
            "as_of_date": "2026-09-30",
            "reconciliation_type": "internal",
            "verdict": "reconciled",
            "difference_direction": "level",
            "difference_display": "0.00",
            "safeguarding_requirement_display": "1310000.00",
            "safeguarding_resource_display": "1310000.00",
            "currency": "GBP"
          },
          {
            "entry_ref": "RECON-2026-12-31",
            "as_of_date": "2026-12-31",
            "reconciliation_type": "external",
            "verdict": "reconciled",
            "difference_direction": "level",
            "difference_display": "0.00",
            "safeguarding_requirement_display": "1402500.00",
            "safeguarding_resource_display": "1402500.00",
            "currency": "GBP"
          }
        ],
        "method_classification": {
          "classification_verdict": "COHERENT_ON_SUPPLIED_FACTS",
          "stream_count": 2,
          "coherent_count": 2,
          "incoherent_count": 0,
          "open_judgment_count": 0,
          "audit_exemption_indicator": {
            "outcome": "audit_required",
            "basis": "Relevant funds held exceed the exemption level."
          },
          "determinations": [
            {
              "stream_ref": "STREAM-SYNTH-A",
              "funds_category": "payment_service_relevant_funds",
              "method_asserted": "segregation",
              "relevant_funds_determination": {
                "outcome": "relevant",
                "basis": "Declared as payment_service_relevant_funds.",
                "citation_id": null
              },
              "method_coherence": "coherent",
              "method_findings": []
            },
            {
              "stream_ref": "STREAM-SYNTH-B",
              "funds_category": "emoney_relevant_funds",
              "method_asserted": "segregation",
              "relevant_funds_determination": {
                "outcome": "relevant",
                "basis": "Declared as emoney_relevant_funds.",
                "citation_id": null
              },
              "method_coherence": "coherent",
              "method_findings": []
            }
          ]
        },
        "accountability_records": [
          {
            "record_type": "approval",
            "role": "preparer",
            "subject_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
            "identity": {
              "id": "did:key:zPreparerSynth1",
              "actor_type": "human"
            },
            "decision": "prepared",
            "timestamp": "2027-05-20T09:00:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zPreparerSynth1#zPreparerSynth1",
                "proofValue": "zSYNTHETICPREPARERSIGNATURE"
              }
            }
          },
          {
            "record_type": "approval",
            "role": "reviewer",
            "subject_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
            "identity": {
              "id": "did:key:zAuditorSynth1",
              "actor_type": "human"
            },
            "decision": "reviewed",
            "timestamp": "2027-05-21T14:30:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zAuditorSynth1#zAuditorSynth1",
                "proofValue": "zSYNTHETICAUDITORSIGNATURE"
              }
            }
          },
          {
            "record_type": "approval",
            "role": "approver",
            "subject_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
            "identity": {
              "id": "did:key:zApproverSynth1",
              "actor_type": "human"
            },
            "decision": "approved",
            "timestamp": "2027-05-22T11:15:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zApproverSynth1#zApproverSynth1",
                "proofValue": "zSYNTHETICAPPROVERSIGNATURE"
              }
            }
          }
        ]
      },
      "output_payload": {
        "ruleset": {
          "ruleset_id": "FCA-CASS15-PS25-12",
          "ruleset_label": "FCA CASS 15 safeguarding rules, as made by PS25/12",
          "in_force_from": "2026-05-07",
          "field_set_version": "1.0.0",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "report_vocabulary": {
          "assurance_basis": "reasonable_assurance",
          "opinion_refs": [
            "systems_adequacy_throughout_period",
            "compliance_at_period_end"
          ],
          "permitted_opinion_outcomes": [
            "unmodified",
            "qualified",
            "adverse"
          ],
          "exception_schedule_key": "rule_reference",
          "management_response_required_per_item": true,
          "vocabulary_basis": "The safeguarding assurance report is a reasonable assurance engagement stating two opinions, systems adequacy throughout the period and compliance at the period end, with exceptions listed against the individual rule reference and a management response recorded against each item. This pack uses those names so its output pastes into the engagement rather than into a format we invented.",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "firm_ref": "FIRM-SYNTH-0001",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06",
          "bounds_present": true,
          "order_valid": true
        },
        "minor_unit_exponent": 2,
        "subject": {
          "subject_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "application/pdf",
              "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "derived",
          "binding_source_tool_id": "art-502-bind-attested-subject",
          "subject_recomputed_here": false,
          "subject_class": "attested_artifact"
        },
        "reconciliation_summary": {
          "entry_count": 3,
          "reconciled_count": 3,
          "shortfall_count": 0,
          "excess_count": 0,
          "unstated_verdict_count": 0,
          "outside_period_count": 0,
          "undated_count": 0,
          "entries": [
            {
              "entry_ref": "RECON-2026-06-30",
              "as_of_date": "2026-06-30",
              "reconciliation_type": "internal",
              "verdict": "reconciled",
              "difference_direction": "level",
              "difference_display": "0.00",
              "safeguarding_requirement_display": "1250000.00",
              "safeguarding_resource_display": "1250000.00",
              "currency": "GBP",
              "within_period": true,
              "date_stated": true
            },
            {
              "entry_ref": "RECON-2026-09-30",
              "as_of_date": "2026-09-30",
              "reconciliation_type": "internal",
              "verdict": "reconciled",
              "difference_direction": "level",
              "difference_display": "0.00",
              "safeguarding_requirement_display": "1310000.00",
              "safeguarding_resource_display": "1310000.00",
              "currency": "GBP",
              "within_period": true,
              "date_stated": true
            },
            {
              "entry_ref": "RECON-2026-12-31",
              "as_of_date": "2026-12-31",
              "reconciliation_type": "external",
              "verdict": "reconciled",
              "difference_direction": "level",
              "difference_display": "0.00",
              "safeguarding_requirement_display": "1402500.00",
              "safeguarding_resource_display": "1402500.00",
              "currency": "GBP",
              "within_period": true,
              "date_stated": true
            }
          ]
        },
        "method_summary": {
          "supplied": true,
          "classification_verdict": "COHERENT_ON_SUPPLIED_FACTS",
          "stream_count": 2,
          "coherent_count": 2,
          "incoherent_count": 0,
          "open_judgment_count": 0,
          "audit_exemption_indicator": {
            "outcome": "audit_required",
            "basis": "Relevant funds held exceed the exemption level."
          }
        },
        "exception_schedule": [],
        "exception_count": 0,
        "accountability_trail": {
          "subject_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
          "required_roles": [
            "preparer",
            "reviewer",
            "approver"
          ],
          "roles_satisfied_count": 3,
          "roles_required_count": 3,
          "by_role": {
            "preparer": {
              "role": "preparer",
              "held_by": "The firm officer who prepared the reconciliation export.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zPreparerSynth1"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            },
            "reviewer": {
              "role": "reviewer",
              "held_by": "The qualified auditor engaged to review it.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zAuditorSynth1"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            },
            "approver": {
              "role": "approver",
              "held_by": "The firm officer with legally effective sign-off.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zApproverSynth1"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            }
          },
          "status": "satisfied",
          "record_count_over_subject": 3,
          "foreign_subject_record_count": 0,
          "override_record_count": 0,
          "override_handling": "A §27.5 override is time-boxed and its expiry can only be judged against an instant. This kernel reads no clock, so an override record NEVER satisfies a required role here and is reported instead. On expiry an override lapses and the underlying policy reverts; it can never become a silent permanent auto-pass through this surface.",
          "distinctness_basis": "Roles count DISTINCT identity.id (SPEC.md §27.3), never records and never signing keys. One human rotating keys, or signing twice, counts once.",
          "agent_parity_findings": []
        },
        "auditor_opinions": [
          {
            "opinion_ref": "systems_adequacy_throughout_period",
            "opinion_question": "Whether the firm maintained systems adequate to enable it to comply with the safeguarding rules throughout the audit period.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          },
          {
            "opinion_ref": "compliance_at_period_end",
            "opinion_question": "Whether the firm was in compliance with the safeguarding rules at the date as at which the report is made.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          }
        ],
        "evidence_items": [
          {
            "item": "audit_period",
            "present": true,
            "detail": "A declared audit period with a start date and an end date in order."
          },
          {
            "item": "attested_subject",
            "present": true,
            "detail": "The §27.4 subject identifier for the firm's reconciliation export, computed by art-502."
          },
          {
            "item": "reconciliation_results",
            "present": true,
            "detail": "Reconciliation results across the audit period."
          },
          {
            "item": "method_classification",
            "present": true,
            "detail": "The safeguarding method classification for the firm's funds streams."
          },
          {
            "item": "accountability_trail",
            "present": true,
            "detail": "A signed preparer, reviewer and approver trail over the attested subject."
          },
          {
            "item": "management_responses",
            "present": true,
            "detail": "A management response recorded against every item in the exception schedule."
          }
        ],
        "missing_items": [],
        "pack_complete": true,
        "citations": {
          "safeguarding_audit": {
            "scheme": "fca-handbook",
            "id": "SUP 3A",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/SUP/3A/"
          },
          "safeguarding_resource": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.26R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "safeguarding_requirement": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.29G",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "internal_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.19R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "external_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.42R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "discrepancy_treatment": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.50R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          }
        },
        "rationale": [
          "Evidence pack assembled for firm reference FIRM-SYNTH-0001 against FCA CASS 15 safeguarding rules, as made by PS25/12, in force from 2026-05-07, for the audit period 2026-05-07 to 2027-05-06.",
          "The pack is bound to attested-artifact subject sha256:1111111111111111111111111111111111111111111111111111111111111111, computed by art-502-bind-attested-subject on the single canonical §27.4 path. This kernel echoes that identifier and deliberately does not recompute it: a second implementation of the preimage would be a second canon.",
          "3 reconciliation results carried: 3 reconciled, 0 shortfall, 0 excess. Every verdict is taken as supplied; no safeguarding arithmetic is recomputed here.",
          "Method classification carried as supplied: COHERENT_ON_SUPPLIED_FACTS across 2 streams, with 0 incoherent and 0 questions left open.",
          "The supplied results raised no matters for the auditor's attention. That is a statement about the figures supplied, not a finding that the firm complied with CASS 15.",
          "Each of the preparer, reviewer and approver roles is named by at least one signed record over this subject, counted by distinct identity.",
          "Neither audit opinion is expressed here. The systems-adequacy and period-end compliance opinions belong to the safeguarding auditor, and this pack leaves both open with the question and the decider named.",
          "This pack is evidence assembled for the engagement. It is not a filing, it is not submittable to the FCA, and it does not discharge the audit. An approval record inside it evidences that a named human acted and nothing more."
        ],
        "no_arithmetic_claim": "The attested-artifact subject this pack is bound to evidences producer pinning, input binding and content integrity. It carries no §18 compute proof and no §16/§17 re-execution claim, and it never evidences that the arithmetic inside the firm's reconciliation export is correct. This artifact deliberately omits replay_verified rather than setting it false, because no replay was attempted.",
        "not_a_filing": "This is evidence assembled for a safeguarding audit engagement. It is not a regulatory filing, it is not submittable to the FCA, it does not reproduce the prescribed report as a fillable form, and it does not discharge the audit. An approval record inside it is evidence of a human act, never a claim that any regulator has accepted anything.",
        "note": "Deterministic UK CASS 15 safeguarding audit evidence pack. Single-run and stateless: it holds no records, runs on no schedule, and retains nothing. It assembles reconciliation results, the safeguarding method classification, a schedule of matters for the auditor keyed by rule reference, and the §27 accountability trail over an attested-artifact subject computed by art-502 and echoed here rather than recomputed. It recomputes no safeguarding arithmetic, records no breach, and expresses neither of the two audit opinions, which belong to the safeguarding auditor. It is not a filing and not legal advice."
      },
      "compliance_flags": [
        "SAFEGUARDING_AUDIT_EVIDENCE_PACK_COMPLETE",
        "SAFEGUARDING_AUDIT_EVIDENCE_SUBJECT_PRODUCER_PINNED",
        "HA_TRAIL_SATISFIED",
        "SAFEGUARDING_AUDIT_OPINION_NOT_EXPRESSED"
      ],
      "golden_hash": "0e1d2275be4be9c9c31e5c363103ba130500e31abe54d79a734ba8d67e867913"
    },
    {
      "name": "shortfall-and-incoherence-raise-matters",
      "description": "A shortfall day and a method incoherence each reach the exception schedule against their own rule reference. One item carries the firm's management response and the other does not, so the outstanding-response flag fires. Nothing is recorded as a breach.",
      "policy_parameters": {
        "firm_ref": "FIRM-SYNTH-0002",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06"
        },
        "attested_subject": {
          "subject_hash": "sha256:2222222222222222222222222222222222222222222222222222222222222222",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "text/csv",
              "content_digest": "sha256:dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "declared"
        },
        "reconciliation_results": [
          {
            "entry_ref": "RECON-2026-08-31",
            "as_of_date": "2026-08-31",
            "reconciliation_type": "internal",
            "verdict": "shortfall",
            "difference_direction": "resource_below_requirement",
            "difference_display": "-4250.00",
            "safeguarding_requirement_display": "980000.00",
            "safeguarding_resource_display": "975750.00",
            "currency": "GBP"
          },
          {
            "entry_ref": "RECON-2026-09-30",
            "as_of_date": "2026-09-30",
            "reconciliation_type": "internal",
            "verdict": "reconciled",
            "difference_direction": "level",
            "difference_display": "0.00",
            "safeguarding_requirement_display": "990000.00",
            "safeguarding_resource_display": "990000.00",
            "currency": "GBP"
          }
        ],
        "method_classification": {
          "classification_verdict": "INCOHERENCE_PRESENT",
          "stream_count": 1,
          "coherent_count": 0,
          "incoherent_count": 1,
          "open_judgment_count": 0,
          "audit_exemption_indicator": {
            "outcome": "audit_required",
            "basis": "Relevant funds held exceed the exemption level."
          },
          "determinations": [
            {
              "stream_ref": "STREAM-SYNTH-C",
              "funds_category": "payment_service_relevant_funds",
              "method_asserted": "segregation",
              "relevant_funds_determination": {
                "outcome": "relevant",
                "basis": "Declared as payment_service_relevant_funds.",
                "citation_id": null
              },
              "method_coherence": "incoherent",
              "method_findings": [
                {
                  "outcome": "incoherent",
                  "basis": "Segregation is asserted, but the account holding the funds is declared as not being a designated relevant funds bank account.",
                  "citation_id": "CASS 15.3.1G"
                }
              ]
            }
          ]
        },
        "management_responses": {
          "EX-1": "The difference arose from a timing break on a same-day sweep and was paid into the relevant funds bank account on the day the reconciliation was performed. Working paper WP-SYNTH-14 refers."
        },
        "accountability_records": [
          {
            "record_type": "approval",
            "role": "preparer",
            "subject_hash": "sha256:2222222222222222222222222222222222222222222222222222222222222222",
            "identity": {
              "id": "did:key:zPreparerSynth2",
              "actor_type": "human"
            },
            "timestamp": "2027-05-20T09:00:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zPreparerSynth2#zPreparerSynth2",
                "proofValue": "zSYNTHETICPREPARERSIGNATURE"
              }
            }
          },
          {
            "record_type": "approval",
            "role": "reviewer",
            "subject_hash": "sha256:2222222222222222222222222222222222222222222222222222222222222222",
            "identity": {
              "id": "did:key:zAuditorSynth2",
              "actor_type": "human"
            },
            "timestamp": "2027-05-21T14:30:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zAuditorSynth2#zAuditorSynth2",
                "proofValue": "zSYNTHETICAUDITORSIGNATURE"
              }
            }
          },
          {
            "record_type": "approval",
            "role": "approver",
            "subject_hash": "sha256:2222222222222222222222222222222222222222222222222222222222222222",
            "identity": {
              "id": "did:key:zPreparerSynth2",
              "actor_type": "human"
            },
            "timestamp": "2027-05-22T11:15:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zPreparerSynth2#zPreparerSynth2",
                "proofValue": "zSYNTHETICPREPARERSIGNATURE"
              }
            }
          }
        ]
      },
      "output_payload": {
        "ruleset": {
          "ruleset_id": "FCA-CASS15-PS25-12",
          "ruleset_label": "FCA CASS 15 safeguarding rules, as made by PS25/12",
          "in_force_from": "2026-05-07",
          "field_set_version": "1.0.0",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "report_vocabulary": {
          "assurance_basis": "reasonable_assurance",
          "opinion_refs": [
            "systems_adequacy_throughout_period",
            "compliance_at_period_end"
          ],
          "permitted_opinion_outcomes": [
            "unmodified",
            "qualified",
            "adverse"
          ],
          "exception_schedule_key": "rule_reference",
          "management_response_required_per_item": true,
          "vocabulary_basis": "The safeguarding assurance report is a reasonable assurance engagement stating two opinions, systems adequacy throughout the period and compliance at the period end, with exceptions listed against the individual rule reference and a management response recorded against each item. This pack uses those names so its output pastes into the engagement rather than into a format we invented.",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "firm_ref": "FIRM-SYNTH-0002",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06",
          "bounds_present": true,
          "order_valid": true
        },
        "minor_unit_exponent": 2,
        "subject": {
          "subject_hash": "sha256:2222222222222222222222222222222222222222222222222222222222222222",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "text/csv",
              "content_digest": "sha256:dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "declared",
          "binding_source_tool_id": "art-502-bind-attested-subject",
          "subject_recomputed_here": false,
          "subject_class": "attested_artifact"
        },
        "reconciliation_summary": {
          "entry_count": 2,
          "reconciled_count": 1,
          "shortfall_count": 1,
          "excess_count": 0,
          "unstated_verdict_count": 0,
          "outside_period_count": 0,
          "undated_count": 0,
          "entries": [
            {
              "entry_ref": "RECON-2026-08-31",
              "as_of_date": "2026-08-31",
              "reconciliation_type": "internal",
              "verdict": "shortfall",
              "difference_direction": "resource_below_requirement",
              "difference_display": "-4250.00",
              "safeguarding_requirement_display": "980000.00",
              "safeguarding_resource_display": "975750.00",
              "currency": "GBP",
              "within_period": true,
              "date_stated": true
            },
            {
              "entry_ref": "RECON-2026-09-30",
              "as_of_date": "2026-09-30",
              "reconciliation_type": "internal",
              "verdict": "reconciled",
              "difference_direction": "level",
              "difference_display": "0.00",
              "safeguarding_requirement_display": "990000.00",
              "safeguarding_resource_display": "990000.00",
              "currency": "GBP",
              "within_period": true,
              "date_stated": true
            }
          ]
        },
        "method_summary": {
          "supplied": true,
          "classification_verdict": "INCOHERENCE_PRESENT",
          "stream_count": 1,
          "coherent_count": 0,
          "incoherent_count": 1,
          "open_judgment_count": 0,
          "audit_exemption_indicator": {
            "outcome": "audit_required",
            "basis": "Relevant funds held exceed the exemption level."
          }
        },
        "exception_schedule": [
          {
            "item_ref": "EX-1",
            "source_tool": "art-499-check-safeguarding-reconciliation",
            "rule_reference": "CASS 15.8.50R",
            "matter": "A reconciliation on 2026-08-31 resolved to shortfall beyond the tolerance declared for it.",
            "resolving_input": "The firm's reconciliation working papers for that date, and the record of the action taken on the difference.",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "context": {
              "entry_ref": "RECON-2026-08-31",
              "as_of_date": "2026-08-31",
              "difference_display": "-4250.00",
              "currency": "GBP"
            },
            "management_response": "The difference arose from a timing break on a same-day sweep and was paid into the relevant funds bank account on the day the reconciliation was performed. Working paper WP-SYNTH-14 refers.",
            "management_response_present": true,
            "classification": "matter_for_the_auditor"
          },
          {
            "item_ref": "EX-2",
            "source_tool": "art-500-classify-safeguarding-method",
            "rule_reference": "CASS 15.3.1G",
            "matter": "Stream STREAM-SYNTH-C carries facts that do not agree with the safeguarding method asserted for it. Segregation is asserted, but the account holding the funds is declared as not being a designated relevant funds bank account.",
            "resolving_input": "The account and instrument documentation for that stream.",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "context": {
              "stream_ref": "STREAM-SYNTH-C"
            },
            "management_response": null,
            "management_response_present": false,
            "classification": "matter_for_the_auditor"
          }
        ],
        "exception_count": 2,
        "accountability_trail": {
          "subject_hash": "sha256:2222222222222222222222222222222222222222222222222222222222222222",
          "required_roles": [
            "preparer",
            "reviewer",
            "approver"
          ],
          "roles_satisfied_count": 3,
          "roles_required_count": 3,
          "by_role": {
            "preparer": {
              "role": "preparer",
              "held_by": "The firm officer who prepared the reconciliation export.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zPreparerSynth2"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            },
            "reviewer": {
              "role": "reviewer",
              "held_by": "The qualified auditor engaged to review it.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zAuditorSynth2"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            },
            "approver": {
              "role": "approver",
              "held_by": "The firm officer with legally effective sign-off.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zPreparerSynth2"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            }
          },
          "status": "satisfied",
          "record_count_over_subject": 3,
          "foreign_subject_record_count": 0,
          "override_record_count": 0,
          "override_handling": "A §27.5 override is time-boxed and its expiry can only be judged against an instant. This kernel reads no clock, so an override record NEVER satisfies a required role here and is reported instead. On expiry an override lapses and the underlying policy reverts; it can never become a silent permanent auto-pass through this surface.",
          "distinctness_basis": "Roles count DISTINCT identity.id (SPEC.md §27.3), never records and never signing keys. One human rotating keys, or signing twice, counts once.",
          "agent_parity_findings": [
            {
              "code": "HA_PREPARER_IS_ALSO_APPROVER",
              "role": "approver",
              "identity_id": "did:key:zPreparerSynth2",
              "detail": "The same identity appears as both preparer and approver of this subject. The records are counted as supplied, and the concentration is reported here as a matter for the auditor rather than resolved by this tool."
            }
          ]
        },
        "auditor_opinions": [
          {
            "opinion_ref": "systems_adequacy_throughout_period",
            "opinion_question": "Whether the firm maintained systems adequate to enable it to comply with the safeguarding rules throughout the audit period.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          },
          {
            "opinion_ref": "compliance_at_period_end",
            "opinion_question": "Whether the firm was in compliance with the safeguarding rules at the date as at which the report is made.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          }
        ],
        "evidence_items": [
          {
            "item": "audit_period",
            "present": true,
            "detail": "A declared audit period with a start date and an end date in order."
          },
          {
            "item": "attested_subject",
            "present": true,
            "detail": "The §27.4 subject identifier for the firm's reconciliation export, computed by art-502."
          },
          {
            "item": "reconciliation_results",
            "present": true,
            "detail": "Reconciliation results across the audit period."
          },
          {
            "item": "method_classification",
            "present": true,
            "detail": "The safeguarding method classification for the firm's funds streams."
          },
          {
            "item": "accountability_trail",
            "present": true,
            "detail": "A signed preparer, reviewer and approver trail over the attested subject."
          },
          {
            "item": "management_responses",
            "present": false,
            "detail": "A management response recorded against every item in the exception schedule."
          }
        ],
        "missing_items": [
          "management_responses"
        ],
        "pack_complete": false,
        "citations": {
          "safeguarding_audit": {
            "scheme": "fca-handbook",
            "id": "SUP 3A",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/SUP/3A/"
          },
          "safeguarding_resource": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.26R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "safeguarding_requirement": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.29G",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "internal_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.19R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "external_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.42R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "discrepancy_treatment": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.50R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          }
        },
        "rationale": [
          "Evidence pack assembled for firm reference FIRM-SYNTH-0002 against FCA CASS 15 safeguarding rules, as made by PS25/12, in force from 2026-05-07, for the audit period 2026-05-07 to 2027-05-06.",
          "The pack is bound to attested-artifact subject sha256:2222222222222222222222222222222222222222222222222222222222222222, computed by art-502-bind-attested-subject on the single canonical §27.4 path. This kernel echoes that identifier and deliberately does not recompute it: a second implementation of the preimage would be a second canon.",
          "2 reconciliation results carried: 1 reconciled, 1 shortfall, 0 excess. Every verdict is taken as supplied; no safeguarding arithmetic is recomputed here.",
          "Method classification carried as supplied: INCOHERENCE_PRESENT across 1 stream, with 1 incoherent and 0 questions left open.",
          "2 matters for the auditor's attention listed against the individual rule reference, each with a slot for the firm's management response. These are matters raised by the supplied results. None of them is recorded as a breach: whether any is a breach of CASS 15 is for the firm's records and its safeguarding auditor.",
          "Each of the preparer, reviewer and approver roles is named by at least one signed record over this subject, counted by distinct identity.",
          "Neither audit opinion is expressed here. The systems-adequacy and period-end compliance opinions belong to the safeguarding auditor, and this pack leaves both open with the question and the decider named.",
          "This pack is evidence assembled for the engagement. It is not a filing, it is not submittable to the FCA, and it does not discharge the audit. An approval record inside it evidences that a named human acted and nothing more."
        ],
        "no_arithmetic_claim": "The attested-artifact subject this pack is bound to evidences producer pinning, input binding and content integrity. It carries no §18 compute proof and no §16/§17 re-execution claim, and it never evidences that the arithmetic inside the firm's reconciliation export is correct. This artifact deliberately omits replay_verified rather than setting it false, because no replay was attempted.",
        "not_a_filing": "This is evidence assembled for a safeguarding audit engagement. It is not a regulatory filing, it is not submittable to the FCA, it does not reproduce the prescribed report as a fillable form, and it does not discharge the audit. An approval record inside it is evidence of a human act, never a claim that any regulator has accepted anything.",
        "note": "Deterministic UK CASS 15 safeguarding audit evidence pack. Single-run and stateless: it holds no records, runs on no schedule, and retains nothing. It assembles reconciliation results, the safeguarding method classification, a schedule of matters for the auditor keyed by rule reference, and the §27 accountability trail over an attested-artifact subject computed by art-502 and echoed here rather than recomputed. It recomputes no safeguarding arithmetic, records no breach, and expresses neither of the two audit opinions, which belong to the safeguarding auditor. It is not a filing and not legal advice."
      },
      "compliance_flags": [
        "SAFEGUARDING_AUDIT_EVIDENCE_PACK_INCOMPLETE",
        "SAFEGUARDING_AUDIT_EVIDENCE_SUBJECT_PRODUCER_PINNED",
        "HA_TRAIL_SATISFIED",
        "SAFEGUARDING_AUDIT_OPINION_NOT_EXPRESSED",
        "SAFEGUARDING_AUDIT_EXCEPTIONS_PRESENT",
        "SAFEGUARDING_AUDIT_MANAGEMENT_RESPONSE_OUTSTANDING",
        "SAFEGUARDING_SHORTFALL_IN_PERIOD",
        "HA_PREPARER_IS_ALSO_APPROVER"
      ],
      "golden_hash": "c369b348ac5097154b053e290e1a4bfdf9a3f7ea6592244b1e8519e54992fb26"
    },
    {
      "name": "unsigned-approval-holds-the-trail",
      "description": "Approval records naming all three roles but carrying no section 16 proof. An unsigned approval record is not conformant section 27 evidence, so every role holds rather than passes and the pack is incomplete.",
      "policy_parameters": {
        "firm_ref": "FIRM-SYNTH-0003",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06"
        },
        "attested_subject": {
          "subject_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "application/pdf",
              "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "derived"
        },
        "reconciliation_results": [
          {
            "entry_ref": "RECON-2026-06-30",
            "as_of_date": "2026-06-30",
            "reconciliation_type": "internal",
            "verdict": "reconciled",
            "difference_direction": "level",
            "difference_display": "0.00",
            "currency": "GBP"
          }
        ],
        "method_classification": {
          "classification_verdict": "COHERENT_ON_SUPPLIED_FACTS",
          "stream_count": 1,
          "coherent_count": 1,
          "incoherent_count": 0,
          "open_judgment_count": 0,
          "determinations": []
        },
        "accountability_records": [
          {
            "record_type": "approval",
            "role": "preparer",
            "subject_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333",
            "identity": {
              "id": "did:key:zPreparerSynth3"
            },
            "timestamp": "2027-05-20T09:00:00Z"
          },
          {
            "record_type": "approval",
            "role": "reviewer",
            "subject_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333",
            "identity": {
              "id": "did:key:zAuditorSynth3"
            },
            "timestamp": "2027-05-21T09:00:00Z"
          },
          {
            "record_type": "approval",
            "role": "approver",
            "subject_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333",
            "identity": {
              "id": "did:key:zApproverSynth3"
            },
            "timestamp": "2027-05-22T09:00:00Z"
          }
        ]
      },
      "output_payload": {
        "ruleset": {
          "ruleset_id": "FCA-CASS15-PS25-12",
          "ruleset_label": "FCA CASS 15 safeguarding rules, as made by PS25/12",
          "in_force_from": "2026-05-07",
          "field_set_version": "1.0.0",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "report_vocabulary": {
          "assurance_basis": "reasonable_assurance",
          "opinion_refs": [
            "systems_adequacy_throughout_period",
            "compliance_at_period_end"
          ],
          "permitted_opinion_outcomes": [
            "unmodified",
            "qualified",
            "adverse"
          ],
          "exception_schedule_key": "rule_reference",
          "management_response_required_per_item": true,
          "vocabulary_basis": "The safeguarding assurance report is a reasonable assurance engagement stating two opinions, systems adequacy throughout the period and compliance at the period end, with exceptions listed against the individual rule reference and a management response recorded against each item. This pack uses those names so its output pastes into the engagement rather than into a format we invented.",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "firm_ref": "FIRM-SYNTH-0003",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06",
          "bounds_present": true,
          "order_valid": true
        },
        "minor_unit_exponent": 2,
        "subject": {
          "subject_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "application/pdf",
              "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "derived",
          "binding_source_tool_id": "art-502-bind-attested-subject",
          "subject_recomputed_here": false,
          "subject_class": "attested_artifact"
        },
        "reconciliation_summary": {
          "entry_count": 1,
          "reconciled_count": 1,
          "shortfall_count": 0,
          "excess_count": 0,
          "unstated_verdict_count": 0,
          "outside_period_count": 0,
          "undated_count": 0,
          "entries": [
            {
              "entry_ref": "RECON-2026-06-30",
              "as_of_date": "2026-06-30",
              "reconciliation_type": "internal",
              "verdict": "reconciled",
              "difference_direction": "level",
              "difference_display": "0.00",
              "safeguarding_requirement_display": null,
              "safeguarding_resource_display": null,
              "currency": "GBP",
              "within_period": true,
              "date_stated": true
            }
          ]
        },
        "method_summary": {
          "supplied": true,
          "classification_verdict": "COHERENT_ON_SUPPLIED_FACTS",
          "stream_count": 1,
          "coherent_count": 1,
          "incoherent_count": 0,
          "open_judgment_count": 0,
          "audit_exemption_indicator": null
        },
        "exception_schedule": [],
        "exception_count": 0,
        "accountability_trail": {
          "subject_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333",
          "required_roles": [
            "preparer",
            "reviewer",
            "approver"
          ],
          "roles_satisfied_count": 0,
          "roles_required_count": 3,
          "by_role": {
            "preparer": {
              "role": "preparer",
              "held_by": "The firm officer who prepared the reconciliation export.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 1,
              "rejection_count": 0,
              "counted_identity_count": 0,
              "counted_identities": [],
              "status": "hold",
              "reason": "Approval records were supplied for this role but none carries a §16 proof bound to the named identity. An unsigned approval record is not conformant §27 evidence, so the role is held rather than passed."
            },
            "reviewer": {
              "role": "reviewer",
              "held_by": "The qualified auditor engaged to review it.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 1,
              "rejection_count": 0,
              "counted_identity_count": 0,
              "counted_identities": [],
              "status": "hold",
              "reason": "Approval records were supplied for this role but none carries a §16 proof bound to the named identity. An unsigned approval record is not conformant §27 evidence, so the role is held rather than passed."
            },
            "approver": {
              "role": "approver",
              "held_by": "The firm officer with legally effective sign-off.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 1,
              "rejection_count": 0,
              "counted_identity_count": 0,
              "counted_identities": [],
              "status": "hold",
              "reason": "Approval records were supplied for this role but none carries a §16 proof bound to the named identity. An unsigned approval record is not conformant §27 evidence, so the role is held rather than passed."
            }
          },
          "status": "hold",
          "record_count_over_subject": 3,
          "foreign_subject_record_count": 0,
          "override_record_count": 0,
          "override_handling": "A §27.5 override is time-boxed and its expiry can only be judged against an instant. This kernel reads no clock, so an override record NEVER satisfies a required role here and is reported instead. On expiry an override lapses and the underlying policy reverts; it can never become a silent permanent auto-pass through this surface.",
          "distinctness_basis": "Roles count DISTINCT identity.id (SPEC.md §27.3), never records and never signing keys. One human rotating keys, or signing twice, counts once.",
          "agent_parity_findings": []
        },
        "auditor_opinions": [
          {
            "opinion_ref": "systems_adequacy_throughout_period",
            "opinion_question": "Whether the firm maintained systems adequate to enable it to comply with the safeguarding rules throughout the audit period.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          },
          {
            "opinion_ref": "compliance_at_period_end",
            "opinion_question": "Whether the firm was in compliance with the safeguarding rules at the date as at which the report is made.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          }
        ],
        "evidence_items": [
          {
            "item": "audit_period",
            "present": true,
            "detail": "A declared audit period with a start date and an end date in order."
          },
          {
            "item": "attested_subject",
            "present": true,
            "detail": "The §27.4 subject identifier for the firm's reconciliation export, computed by art-502."
          },
          {
            "item": "reconciliation_results",
            "present": true,
            "detail": "Reconciliation results across the audit period."
          },
          {
            "item": "method_classification",
            "present": true,
            "detail": "The safeguarding method classification for the firm's funds streams."
          },
          {
            "item": "accountability_trail",
            "present": false,
            "detail": "A signed preparer, reviewer and approver trail over the attested subject."
          },
          {
            "item": "management_responses",
            "present": true,
            "detail": "A management response recorded against every item in the exception schedule."
          }
        ],
        "missing_items": [
          "accountability_trail"
        ],
        "pack_complete": false,
        "citations": {
          "safeguarding_audit": {
            "scheme": "fca-handbook",
            "id": "SUP 3A",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/SUP/3A/"
          },
          "safeguarding_resource": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.26R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "safeguarding_requirement": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.29G",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "internal_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.19R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "external_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.42R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "discrepancy_treatment": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.50R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          }
        },
        "rationale": [
          "Evidence pack assembled for firm reference FIRM-SYNTH-0003 against FCA CASS 15 safeguarding rules, as made by PS25/12, in force from 2026-05-07, for the audit period 2026-05-07 to 2027-05-06.",
          "The pack is bound to attested-artifact subject sha256:3333333333333333333333333333333333333333333333333333333333333333, computed by art-502-bind-attested-subject on the single canonical §27.4 path. This kernel echoes that identifier and deliberately does not recompute it: a second implementation of the preimage would be a second canon.",
          "1 reconciliation result carried: 1 reconciled, 0 shortfall, 0 excess. Every verdict is taken as supplied; no safeguarding arithmetic is recomputed here.",
          "Method classification carried as supplied: COHERENT_ON_SUPPLIED_FACTS across 1 stream, with 0 incoherent and 0 questions left open.",
          "The supplied results raised no matters for the auditor's attention. That is a statement about the figures supplied, not a finding that the firm complied with CASS 15.",
          "The accountability trail is on hold: 0 of 3 required roles are satisfied. Absent or unsigned evidence holds and never passes by default.",
          "Neither audit opinion is expressed here. The systems-adequacy and period-end compliance opinions belong to the safeguarding auditor, and this pack leaves both open with the question and the decider named.",
          "This pack is evidence assembled for the engagement. It is not a filing, it is not submittable to the FCA, and it does not discharge the audit. An approval record inside it evidences that a named human acted and nothing more."
        ],
        "no_arithmetic_claim": "The attested-artifact subject this pack is bound to evidences producer pinning, input binding and content integrity. It carries no §18 compute proof and no §16/§17 re-execution claim, and it never evidences that the arithmetic inside the firm's reconciliation export is correct. This artifact deliberately omits replay_verified rather than setting it false, because no replay was attempted.",
        "not_a_filing": "This is evidence assembled for a safeguarding audit engagement. It is not a regulatory filing, it is not submittable to the FCA, it does not reproduce the prescribed report as a fillable form, and it does not discharge the audit. An approval record inside it is evidence of a human act, never a claim that any regulator has accepted anything.",
        "note": "Deterministic UK CASS 15 safeguarding audit evidence pack. Single-run and stateless: it holds no records, runs on no schedule, and retains nothing. It assembles reconciliation results, the safeguarding method classification, a schedule of matters for the auditor keyed by rule reference, and the §27 accountability trail over an attested-artifact subject computed by art-502 and echoed here rather than recomputed. It recomputes no safeguarding arithmetic, records no breach, and expresses neither of the two audit opinions, which belong to the safeguarding auditor. It is not a filing and not legal advice."
      },
      "compliance_flags": [
        "SAFEGUARDING_AUDIT_EVIDENCE_PACK_INCOMPLETE",
        "SAFEGUARDING_AUDIT_EVIDENCE_SUBJECT_PRODUCER_PINNED",
        "HA_TRAIL_HOLD",
        "SAFEGUARDING_AUDIT_OPINION_NOT_EXPRESSED",
        "HA_UNSIGNED_APPROVAL_RECORD_NOT_COUNTED"
      ],
      "golden_hash": "eb33b321cb58102b0cad8564166b474c9ab1940f87e588d060e1fb376570895f"
    },
    {
      "name": "agent-approver-without-human-role-mandate",
      "description": "A signed agent identity files the approver record with no explicit human-role mandate. Under section 27.8 it does not satisfy the role: the record is carried and named, the approver role holds, and the parity finding is flagged.",
      "policy_parameters": {
        "firm_ref": "FIRM-SYNTH-0004",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06"
        },
        "attested_subject": {
          "subject_hash": "sha256:4444444444444444444444444444444444444444444444444444444444444444",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "application/pdf",
              "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "derived"
        },
        "reconciliation_results": [
          {
            "entry_ref": "RECON-2026-06-30",
            "as_of_date": "2026-06-30",
            "reconciliation_type": "internal",
            "verdict": "reconciled",
            "difference_direction": "level",
            "difference_display": "0.00",
            "currency": "GBP"
          }
        ],
        "accountability_records": [
          {
            "record_type": "approval",
            "role": "preparer",
            "subject_hash": "sha256:4444444444444444444444444444444444444444444444444444444444444444",
            "identity": {
              "id": "did:key:zPreparerSynth4",
              "actor_type": "human"
            },
            "timestamp": "2027-05-20T09:00:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zPreparerSynth4#zPreparerSynth4",
                "proofValue": "zSYNTHETICPREPARERSIGNATURE"
              }
            }
          },
          {
            "record_type": "approval",
            "role": "reviewer",
            "subject_hash": "sha256:4444444444444444444444444444444444444444444444444444444444444444",
            "identity": {
              "id": "did:key:zAuditorSynth4",
              "actor_type": "human"
            },
            "timestamp": "2027-05-21T09:00:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zAuditorSynth4#zAuditorSynth4",
                "proofValue": "zSYNTHETICAUDITORSIGNATURE"
              }
            }
          },
          {
            "record_type": "approval",
            "role": "approver",
            "subject_hash": "sha256:4444444444444444444444444444444444444444444444444444444444444444",
            "identity": {
              "id": "did:key:zAgentSynth4",
              "actor_type": "agent"
            },
            "timestamp": "2027-05-22T09:00:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zAgentSynth4#zAgentSynth4",
                "proofValue": "zSYNTHETICAGENTSIGNATURE"
              }
            }
          }
        ]
      },
      "output_payload": {
        "ruleset": {
          "ruleset_id": "FCA-CASS15-PS25-12",
          "ruleset_label": "FCA CASS 15 safeguarding rules, as made by PS25/12",
          "in_force_from": "2026-05-07",
          "field_set_version": "1.0.0",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "report_vocabulary": {
          "assurance_basis": "reasonable_assurance",
          "opinion_refs": [
            "systems_adequacy_throughout_period",
            "compliance_at_period_end"
          ],
          "permitted_opinion_outcomes": [
            "unmodified",
            "qualified",
            "adverse"
          ],
          "exception_schedule_key": "rule_reference",
          "management_response_required_per_item": true,
          "vocabulary_basis": "The safeguarding assurance report is a reasonable assurance engagement stating two opinions, systems adequacy throughout the period and compliance at the period end, with exceptions listed against the individual rule reference and a management response recorded against each item. This pack uses those names so its output pastes into the engagement rather than into a format we invented.",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "firm_ref": "FIRM-SYNTH-0004",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06",
          "bounds_present": true,
          "order_valid": true
        },
        "minor_unit_exponent": 2,
        "subject": {
          "subject_hash": "sha256:4444444444444444444444444444444444444444444444444444444444444444",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "application/pdf",
              "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "derived",
          "binding_source_tool_id": "art-502-bind-attested-subject",
          "subject_recomputed_here": false,
          "subject_class": "attested_artifact"
        },
        "reconciliation_summary": {
          "entry_count": 1,
          "reconciled_count": 1,
          "shortfall_count": 0,
          "excess_count": 0,
          "unstated_verdict_count": 0,
          "outside_period_count": 0,
          "undated_count": 0,
          "entries": [
            {
              "entry_ref": "RECON-2026-06-30",
              "as_of_date": "2026-06-30",
              "reconciliation_type": "internal",
              "verdict": "reconciled",
              "difference_direction": "level",
              "difference_display": "0.00",
              "safeguarding_requirement_display": null,
              "safeguarding_resource_display": null,
              "currency": "GBP",
              "within_period": true,
              "date_stated": true
            }
          ]
        },
        "method_summary": {
          "supplied": false,
          "classification_verdict": "NOT_SUPPLIED",
          "stream_count": 0,
          "coherent_count": 0,
          "incoherent_count": 0,
          "open_judgment_count": 0,
          "audit_exemption_indicator": null
        },
        "exception_schedule": [],
        "exception_count": 0,
        "accountability_trail": {
          "subject_hash": "sha256:4444444444444444444444444444444444444444444444444444444444444444",
          "required_roles": [
            "preparer",
            "reviewer",
            "approver"
          ],
          "roles_satisfied_count": 2,
          "roles_required_count": 3,
          "by_role": {
            "preparer": {
              "role": "preparer",
              "held_by": "The firm officer who prepared the reconciliation export.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zPreparerSynth4"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            },
            "reviewer": {
              "role": "reviewer",
              "held_by": "The qualified auditor engaged to review it.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zAuditorSynth4"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            },
            "approver": {
              "role": "approver",
              "held_by": "The firm officer with legally effective sign-off.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 0,
              "counted_identities": [],
              "status": "hold",
              "reason": "No qualifying approval record for this role over this subject. Absent evidence holds; it is never a fall-through pass."
            }
          },
          "status": "hold",
          "record_count_over_subject": 3,
          "foreign_subject_record_count": 0,
          "override_record_count": 0,
          "override_handling": "A §27.5 override is time-boxed and its expiry can only be judged against an instant. This kernel reads no clock, so an override record NEVER satisfies a required role here and is reported instead. On expiry an override lapses and the underlying policy reverts; it can never become a silent permanent auto-pass through this surface.",
          "distinctness_basis": "Roles count DISTINCT identity.id (SPEC.md §27.3), never records and never signing keys. One human rotating keys, or signing twice, counts once.",
          "agent_parity_findings": [
            {
              "code": "HA_AGENT_WITHOUT_HUMAN_ROLE_MANDATE",
              "role": "approver",
              "identity_id": "did:key:zAgentSynth4",
              "detail": "An agent identity filed this approval and carries no explicit human-role mandate, so under SPEC.md §27.8 it does not satisfy the role. The record is carried in the pack and is not counted toward the trail."
            }
          ]
        },
        "auditor_opinions": [
          {
            "opinion_ref": "systems_adequacy_throughout_period",
            "opinion_question": "Whether the firm maintained systems adequate to enable it to comply with the safeguarding rules throughout the audit period.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          },
          {
            "opinion_ref": "compliance_at_period_end",
            "opinion_question": "Whether the firm was in compliance with the safeguarding rules at the date as at which the report is made.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          }
        ],
        "evidence_items": [
          {
            "item": "audit_period",
            "present": true,
            "detail": "A declared audit period with a start date and an end date in order."
          },
          {
            "item": "attested_subject",
            "present": true,
            "detail": "The §27.4 subject identifier for the firm's reconciliation export, computed by art-502."
          },
          {
            "item": "reconciliation_results",
            "present": true,
            "detail": "Reconciliation results across the audit period."
          },
          {
            "item": "method_classification",
            "present": false,
            "detail": "The safeguarding method classification for the firm's funds streams."
          },
          {
            "item": "accountability_trail",
            "present": false,
            "detail": "A signed preparer, reviewer and approver trail over the attested subject."
          },
          {
            "item": "management_responses",
            "present": true,
            "detail": "A management response recorded against every item in the exception schedule."
          }
        ],
        "missing_items": [
          "method_classification",
          "accountability_trail"
        ],
        "pack_complete": false,
        "citations": {
          "safeguarding_audit": {
            "scheme": "fca-handbook",
            "id": "SUP 3A",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/SUP/3A/"
          },
          "safeguarding_resource": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.26R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "safeguarding_requirement": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.29G",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "internal_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.19R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "external_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.42R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "discrepancy_treatment": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.50R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          }
        },
        "rationale": [
          "Evidence pack assembled for firm reference FIRM-SYNTH-0004 against FCA CASS 15 safeguarding rules, as made by PS25/12, in force from 2026-05-07, for the audit period 2026-05-07 to 2027-05-06.",
          "The pack is bound to attested-artifact subject sha256:4444444444444444444444444444444444444444444444444444444444444444, computed by art-502-bind-attested-subject on the single canonical §27.4 path. This kernel echoes that identifier and deliberately does not recompute it: a second implementation of the preimage would be a second canon.",
          "1 reconciliation result carried: 1 reconciled, 0 shortfall, 0 excess. Every verdict is taken as supplied; no safeguarding arithmetic is recomputed here.",
          "No method classification was supplied, so the pack carries none.",
          "The supplied results raised no matters for the auditor's attention. That is a statement about the figures supplied, not a finding that the firm complied with CASS 15.",
          "The accountability trail is on hold: 2 of 3 required roles are satisfied. Absent or unsigned evidence holds and never passes by default.",
          "Neither audit opinion is expressed here. The systems-adequacy and period-end compliance opinions belong to the safeguarding auditor, and this pack leaves both open with the question and the decider named.",
          "This pack is evidence assembled for the engagement. It is not a filing, it is not submittable to the FCA, and it does not discharge the audit. An approval record inside it evidences that a named human acted and nothing more."
        ],
        "no_arithmetic_claim": "The attested-artifact subject this pack is bound to evidences producer pinning, input binding and content integrity. It carries no §18 compute proof and no §16/§17 re-execution claim, and it never evidences that the arithmetic inside the firm's reconciliation export is correct. This artifact deliberately omits replay_verified rather than setting it false, because no replay was attempted.",
        "not_a_filing": "This is evidence assembled for a safeguarding audit engagement. It is not a regulatory filing, it is not submittable to the FCA, it does not reproduce the prescribed report as a fillable form, and it does not discharge the audit. An approval record inside it is evidence of a human act, never a claim that any regulator has accepted anything.",
        "note": "Deterministic UK CASS 15 safeguarding audit evidence pack. Single-run and stateless: it holds no records, runs on no schedule, and retains nothing. It assembles reconciliation results, the safeguarding method classification, a schedule of matters for the auditor keyed by rule reference, and the §27 accountability trail over an attested-artifact subject computed by art-502 and echoed here rather than recomputed. It recomputes no safeguarding arithmetic, records no breach, and expresses neither of the two audit opinions, which belong to the safeguarding auditor. It is not a filing and not legal advice."
      },
      "compliance_flags": [
        "SAFEGUARDING_AUDIT_EVIDENCE_PACK_INCOMPLETE",
        "SAFEGUARDING_AUDIT_EVIDENCE_SUBJECT_PRODUCER_PINNED",
        "HA_TRAIL_HOLD",
        "SAFEGUARDING_AUDIT_OPINION_NOT_EXPRESSED",
        "HA_AGENT_WITHOUT_HUMAN_ROLE_MANDATE"
      ],
      "golden_hash": "7ba2548d5c53db53a3e30f282f706eef395f560671d2bff4dfcd9052cdad996e"
    },
    {
      "name": "override-record-never-counted",
      "description": "A time-boxed section 27.5 override is supplied in place of an approver record. This surface reads no clock, so the override cannot be evaluated for expiry and never satisfies a role: the approver role holds and the override is reported.",
      "policy_parameters": {
        "firm_ref": "FIRM-SYNTH-0005",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06"
        },
        "attested_subject": {
          "subject_hash": "sha256:5555555555555555555555555555555555555555555555555555555555555555",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "application/pdf",
              "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "derived"
        },
        "reconciliation_results": [
          {
            "entry_ref": "RECON-2026-06-30",
            "as_of_date": "2026-06-30",
            "reconciliation_type": "internal",
            "verdict": "reconciled",
            "difference_direction": "level",
            "difference_display": "0.00",
            "currency": "GBP"
          }
        ],
        "accountability_records": [
          {
            "record_type": "approval",
            "role": "preparer",
            "subject_hash": "sha256:5555555555555555555555555555555555555555555555555555555555555555",
            "identity": {
              "id": "did:key:zPreparerSynth5",
              "actor_type": "human"
            },
            "timestamp": "2027-05-20T09:00:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zPreparerSynth5#zPreparerSynth5",
                "proofValue": "zSYNTHETICPREPARERSIGNATURE"
              }
            }
          },
          {
            "record_type": "approval",
            "role": "reviewer",
            "subject_hash": "sha256:5555555555555555555555555555555555555555555555555555555555555555",
            "identity": {
              "id": "did:key:zAuditorSynth5",
              "actor_type": "human"
            },
            "timestamp": "2027-05-21T09:00:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zAuditorSynth5#zAuditorSynth5",
                "proofValue": "zSYNTHETICAUDITORSIGNATURE"
              }
            }
          },
          {
            "record_type": "override",
            "role": "approver",
            "subject_hash": "sha256:5555555555555555555555555555555555555555555555555555555555555555",
            "identity": {
              "id": "did:key:zOfficerSynth5",
              "actor_type": "human"
            },
            "reason_code": "PERIOD_END_TIMING",
            "override": {
              "scope": "approver sign-off on the safeguarding reconciliation export",
              "expiry": "2027-06-30T00:00:00Z",
              "subject_hash": "sha256:5555555555555555555555555555555555555555555555555555555555555555"
            },
            "timestamp": "2027-05-22T09:00:00Z",
            "audit_signature": {
              "proof": {
                "type": "DataIntegrityProof",
                "cryptosuite": "eddsa-jcs-2022",
                "proofPurpose": "assertionMethod",
                "verificationMethod": "did:key:zOfficerSynth5#zOfficerSynth5",
                "proofValue": "zSYNTHETICOFFICERSIGNATURE"
              }
            }
          }
        ]
      },
      "output_payload": {
        "ruleset": {
          "ruleset_id": "FCA-CASS15-PS25-12",
          "ruleset_label": "FCA CASS 15 safeguarding rules, as made by PS25/12",
          "in_force_from": "2026-05-07",
          "field_set_version": "1.0.0",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "report_vocabulary": {
          "assurance_basis": "reasonable_assurance",
          "opinion_refs": [
            "systems_adequacy_throughout_period",
            "compliance_at_period_end"
          ],
          "permitted_opinion_outcomes": [
            "unmodified",
            "qualified",
            "adverse"
          ],
          "exception_schedule_key": "rule_reference",
          "management_response_required_per_item": true,
          "vocabulary_basis": "The safeguarding assurance report is a reasonable assurance engagement stating two opinions, systems adequacy throughout the period and compliance at the period end, with exceptions listed against the individual rule reference and a management response recorded against each item. This pack uses those names so its output pastes into the engagement rather than into a format we invented.",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "firm_ref": "FIRM-SYNTH-0005",
        "audit_period": {
          "start_date": "2026-05-07",
          "end_date": "2027-05-06",
          "bounds_present": true,
          "order_valid": true
        },
        "minor_unit_exponent": 2,
        "subject": {
          "subject_hash": "sha256:5555555555555555555555555555555555555555555555555555555555555555",
          "subject_preimage": {
            "tool_ref": {
              "tool_id": "acme-safeguarding-recon",
              "tool_version": "4.2.0",
              "entry": "buildSafeguardingRecon",
              "manifest_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
            },
            "inputs_digest": "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
            "artifact": {
              "content_type": "application/pdf",
              "content_digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
            }
          },
          "producer_pinned": true,
          "binding_complete": true,
          "inputs_digest_source": "derived",
          "binding_source_tool_id": "art-502-bind-attested-subject",
          "subject_recomputed_here": false,
          "subject_class": "attested_artifact"
        },
        "reconciliation_summary": {
          "entry_count": 1,
          "reconciled_count": 1,
          "shortfall_count": 0,
          "excess_count": 0,
          "unstated_verdict_count": 0,
          "outside_period_count": 0,
          "undated_count": 0,
          "entries": [
            {
              "entry_ref": "RECON-2026-06-30",
              "as_of_date": "2026-06-30",
              "reconciliation_type": "internal",
              "verdict": "reconciled",
              "difference_direction": "level",
              "difference_display": "0.00",
              "safeguarding_requirement_display": null,
              "safeguarding_resource_display": null,
              "currency": "GBP",
              "within_period": true,
              "date_stated": true
            }
          ]
        },
        "method_summary": {
          "supplied": false,
          "classification_verdict": "NOT_SUPPLIED",
          "stream_count": 0,
          "coherent_count": 0,
          "incoherent_count": 0,
          "open_judgment_count": 0,
          "audit_exemption_indicator": null
        },
        "exception_schedule": [],
        "exception_count": 0,
        "accountability_trail": {
          "subject_hash": "sha256:5555555555555555555555555555555555555555555555555555555555555555",
          "required_roles": [
            "preparer",
            "reviewer",
            "approver"
          ],
          "roles_satisfied_count": 2,
          "roles_required_count": 3,
          "by_role": {
            "preparer": {
              "role": "preparer",
              "held_by": "The firm officer who prepared the reconciliation export.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zPreparerSynth5"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            },
            "reviewer": {
              "role": "reviewer",
              "held_by": "The qualified auditor engaged to review it.",
              "record_count": 1,
              "approval_count": 1,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 1,
              "counted_identities": [
                "did:key:zAuditorSynth5"
              ],
              "status": "satisfied",
              "reason": "At least one signed approval record names a distinct identity in this role over this subject."
            },
            "approver": {
              "role": "approver",
              "held_by": "The firm officer with legally effective sign-off.",
              "record_count": 1,
              "approval_count": 0,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 0,
              "counted_identities": [],
              "status": "hold",
              "reason": "No qualifying approval record for this role over this subject. Absent evidence holds; it is never a fall-through pass."
            }
          },
          "status": "hold",
          "record_count_over_subject": 3,
          "foreign_subject_record_count": 0,
          "override_record_count": 1,
          "override_handling": "A §27.5 override is time-boxed and its expiry can only be judged against an instant. This kernel reads no clock, so an override record NEVER satisfies a required role here and is reported instead. On expiry an override lapses and the underlying policy reverts; it can never become a silent permanent auto-pass through this surface.",
          "distinctness_basis": "Roles count DISTINCT identity.id (SPEC.md §27.3), never records and never signing keys. One human rotating keys, or signing twice, counts once.",
          "agent_parity_findings": []
        },
        "auditor_opinions": [
          {
            "opinion_ref": "systems_adequacy_throughout_period",
            "opinion_question": "Whether the firm maintained systems adequate to enable it to comply with the safeguarding rules throughout the audit period.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          },
          {
            "opinion_ref": "compliance_at_period_end",
            "opinion_question": "Whether the firm was in compliance with the safeguarding rules at the date as at which the report is made.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          }
        ],
        "evidence_items": [
          {
            "item": "audit_period",
            "present": true,
            "detail": "A declared audit period with a start date and an end date in order."
          },
          {
            "item": "attested_subject",
            "present": true,
            "detail": "The §27.4 subject identifier for the firm's reconciliation export, computed by art-502."
          },
          {
            "item": "reconciliation_results",
            "present": true,
            "detail": "Reconciliation results across the audit period."
          },
          {
            "item": "method_classification",
            "present": false,
            "detail": "The safeguarding method classification for the firm's funds streams."
          },
          {
            "item": "accountability_trail",
            "present": false,
            "detail": "A signed preparer, reviewer and approver trail over the attested subject."
          },
          {
            "item": "management_responses",
            "present": true,
            "detail": "A management response recorded against every item in the exception schedule."
          }
        ],
        "missing_items": [
          "method_classification",
          "accountability_trail"
        ],
        "pack_complete": false,
        "citations": {
          "safeguarding_audit": {
            "scheme": "fca-handbook",
            "id": "SUP 3A",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/SUP/3A/"
          },
          "safeguarding_resource": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.26R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "safeguarding_requirement": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.29G",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "internal_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.19R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "external_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.42R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "discrepancy_treatment": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.50R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          }
        },
        "rationale": [
          "Evidence pack assembled for firm reference FIRM-SYNTH-0005 against FCA CASS 15 safeguarding rules, as made by PS25/12, in force from 2026-05-07, for the audit period 2026-05-07 to 2027-05-06.",
          "The pack is bound to attested-artifact subject sha256:5555555555555555555555555555555555555555555555555555555555555555, computed by art-502-bind-attested-subject on the single canonical §27.4 path. This kernel echoes that identifier and deliberately does not recompute it: a second implementation of the preimage would be a second canon.",
          "1 reconciliation result carried: 1 reconciled, 0 shortfall, 0 excess. Every verdict is taken as supplied; no safeguarding arithmetic is recomputed here.",
          "No method classification was supplied, so the pack carries none.",
          "The supplied results raised no matters for the auditor's attention. That is a statement about the figures supplied, not a finding that the firm complied with CASS 15.",
          "The accountability trail is on hold: 2 of 3 required roles are satisfied. Absent or unsigned evidence holds and never passes by default.",
          "Neither audit opinion is expressed here. The systems-adequacy and period-end compliance opinions belong to the safeguarding auditor, and this pack leaves both open with the question and the decider named.",
          "This pack is evidence assembled for the engagement. It is not a filing, it is not submittable to the FCA, and it does not discharge the audit. An approval record inside it evidences that a named human acted and nothing more."
        ],
        "no_arithmetic_claim": "The attested-artifact subject this pack is bound to evidences producer pinning, input binding and content integrity. It carries no §18 compute proof and no §16/§17 re-execution claim, and it never evidences that the arithmetic inside the firm's reconciliation export is correct. This artifact deliberately omits replay_verified rather than setting it false, because no replay was attempted.",
        "not_a_filing": "This is evidence assembled for a safeguarding audit engagement. It is not a regulatory filing, it is not submittable to the FCA, it does not reproduce the prescribed report as a fillable form, and it does not discharge the audit. An approval record inside it is evidence of a human act, never a claim that any regulator has accepted anything.",
        "note": "Deterministic UK CASS 15 safeguarding audit evidence pack. Single-run and stateless: it holds no records, runs on no schedule, and retains nothing. It assembles reconciliation results, the safeguarding method classification, a schedule of matters for the auditor keyed by rule reference, and the §27 accountability trail over an attested-artifact subject computed by art-502 and echoed here rather than recomputed. It recomputes no safeguarding arithmetic, records no breach, and expresses neither of the two audit opinions, which belong to the safeguarding auditor. It is not a filing and not legal advice."
      },
      "compliance_flags": [
        "SAFEGUARDING_AUDIT_EVIDENCE_PACK_INCOMPLETE",
        "SAFEGUARDING_AUDIT_EVIDENCE_SUBJECT_PRODUCER_PINNED",
        "HA_TRAIL_HOLD",
        "SAFEGUARDING_AUDIT_OPINION_NOT_EXPRESSED",
        "HA_OVERRIDE_PRESENT_NOT_COUNTED"
      ],
      "golden_hash": "a59d24f9746e42b4bea9f51e7a3aed4a0d6a800bf470c4bf37387fda5fe4c5b9"
    },
    {
      "name": "empty-pack-resolves-defined",
      "description": "Nothing supplied. The finite gate: an absent period, an absent subject, no reconciliation results, no method classification and no records all resolve to a defined incomplete pack with every role held. No NaN, no undefined verdict.",
      "policy_parameters": {},
      "output_payload": {
        "ruleset": {
          "ruleset_id": "FCA-CASS15-PS25-12",
          "ruleset_label": "FCA CASS 15 safeguarding rules, as made by PS25/12",
          "in_force_from": "2026-05-07",
          "field_set_version": "1.0.0",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "report_vocabulary": {
          "assurance_basis": "reasonable_assurance",
          "opinion_refs": [
            "systems_adequacy_throughout_period",
            "compliance_at_period_end"
          ],
          "permitted_opinion_outcomes": [
            "unmodified",
            "qualified",
            "adverse"
          ],
          "exception_schedule_key": "rule_reference",
          "management_response_required_per_item": true,
          "vocabulary_basis": "The safeguarding assurance report is a reasonable assurance engagement stating two opinions, systems adequacy throughout the period and compliance at the period end, with exceptions listed against the individual rule reference and a management response recorded against each item. This pack uses those names so its output pastes into the engagement rather than into a format we invented.",
          "sourced_from": "handbook.fca.org.uk",
          "sourced_on": "2026-07-30"
        },
        "firm_ref": "UNSTATED",
        "audit_period": {
          "start_date": null,
          "end_date": null,
          "bounds_present": false,
          "order_valid": true
        },
        "minor_unit_exponent": 2,
        "subject": {
          "subject_hash": null,
          "subject_preimage": null,
          "producer_pinned": false,
          "binding_complete": false,
          "inputs_digest_source": "absent",
          "binding_source_tool_id": "art-502-bind-attested-subject",
          "subject_recomputed_here": false,
          "subject_class": "attested_artifact"
        },
        "reconciliation_summary": {
          "entry_count": 0,
          "reconciled_count": 0,
          "shortfall_count": 0,
          "excess_count": 0,
          "unstated_verdict_count": 0,
          "outside_period_count": 0,
          "undated_count": 0,
          "entries": []
        },
        "method_summary": {
          "supplied": false,
          "classification_verdict": "NOT_SUPPLIED",
          "stream_count": 0,
          "coherent_count": 0,
          "incoherent_count": 0,
          "open_judgment_count": 0,
          "audit_exemption_indicator": null
        },
        "exception_schedule": [
          {
            "item_ref": "EX-1",
            "source_tool": "art-502-bind-attested-subject",
            "rule_reference": "SUP 3A",
            "matter": "No attested-artifact subject was supplied, so the pack has nothing for the accountability records to name.",
            "resolving_input": "A complete art-502 binding over the firm's reconciliation export: a well-formed producer manifest_digest, an inputs digest, and the sealed output's content type and content digest.",
            "decided_by": "The firm, from its own books and records. This tool does not decide it.",
            "context": {
              "producer_pinned": false
            },
            "management_response": null,
            "management_response_present": false,
            "classification": "matter_for_the_auditor"
          }
        ],
        "exception_count": 1,
        "accountability_trail": {
          "subject_hash": null,
          "required_roles": [
            "preparer",
            "reviewer",
            "approver"
          ],
          "roles_satisfied_count": 0,
          "roles_required_count": 3,
          "by_role": {
            "preparer": {
              "role": "preparer",
              "held_by": "The firm officer who prepared the reconciliation export.",
              "record_count": 0,
              "approval_count": 0,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 0,
              "counted_identities": [],
              "status": "hold",
              "reason": "No qualifying approval record for this role over this subject. Absent evidence holds; it is never a fall-through pass."
            },
            "reviewer": {
              "role": "reviewer",
              "held_by": "The qualified auditor engaged to review it.",
              "record_count": 0,
              "approval_count": 0,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 0,
              "counted_identities": [],
              "status": "hold",
              "reason": "No qualifying approval record for this role over this subject. Absent evidence holds; it is never a fall-through pass."
            },
            "approver": {
              "role": "approver",
              "held_by": "The firm officer with legally effective sign-off.",
              "record_count": 0,
              "approval_count": 0,
              "unsigned_approval_count": 0,
              "rejection_count": 0,
              "counted_identity_count": 0,
              "counted_identities": [],
              "status": "hold",
              "reason": "No qualifying approval record for this role over this subject. Absent evidence holds; it is never a fall-through pass."
            }
          },
          "status": "hold",
          "record_count_over_subject": 0,
          "foreign_subject_record_count": 0,
          "override_record_count": 0,
          "override_handling": "A §27.5 override is time-boxed and its expiry can only be judged against an instant. This kernel reads no clock, so an override record NEVER satisfies a required role here and is reported instead. On expiry an override lapses and the underlying policy reverts; it can never become a silent permanent auto-pass through this surface.",
          "distinctness_basis": "Roles count DISTINCT identity.id (SPEC.md §27.3), never records and never signing keys. One human rotating keys, or signing twice, counts once.",
          "agent_parity_findings": []
        },
        "auditor_opinions": [
          {
            "opinion_ref": "systems_adequacy_throughout_period",
            "opinion_question": "Whether the firm maintained systems adequate to enable it to comply with the safeguarding rules throughout the audit period.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          },
          {
            "opinion_ref": "compliance_at_period_end",
            "opinion_question": "Whether the firm was in compliance with the safeguarding rules at the date as at which the report is made.",
            "outcome": "not_expressed_by_this_tool",
            "permitted_outcomes": [
              "unmodified",
              "qualified",
              "adverse"
            ],
            "assurance_basis": "reasonable_assurance",
            "decided_by": "The safeguarding auditor appointed for the engagement, on the firm's own books and records. This tool does not decide it.",
            "citation_id": "SUP 3A"
          }
        ],
        "evidence_items": [
          {
            "item": "audit_period",
            "present": false,
            "detail": "A declared audit period with a start date and an end date in order."
          },
          {
            "item": "attested_subject",
            "present": false,
            "detail": "The §27.4 subject identifier for the firm's reconciliation export, computed by art-502."
          },
          {
            "item": "reconciliation_results",
            "present": false,
            "detail": "Reconciliation results across the audit period."
          },
          {
            "item": "method_classification",
            "present": false,
            "detail": "The safeguarding method classification for the firm's funds streams."
          },
          {
            "item": "accountability_trail",
            "present": false,
            "detail": "A signed preparer, reviewer and approver trail over the attested subject."
          },
          {
            "item": "management_responses",
            "present": false,
            "detail": "A management response recorded against every item in the exception schedule."
          }
        ],
        "missing_items": [
          "audit_period",
          "attested_subject",
          "reconciliation_results",
          "method_classification",
          "accountability_trail",
          "management_responses"
        ],
        "pack_complete": false,
        "citations": {
          "safeguarding_audit": {
            "scheme": "fca-handbook",
            "id": "SUP 3A",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/SUP/3A/"
          },
          "safeguarding_resource": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.26R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "safeguarding_requirement": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.29G",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "internal_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.19R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "external_frequency": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.42R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          },
          "discrepancy_treatment": {
            "scheme": "fca-handbook",
            "id": "CASS 15.8.50R",
            "in_force_from": "2026-05-07",
            "mapped_by": "AINumbers CASS15-K-2",
            "mapped_at": "2026-07-30",
            "uri": "https://handbook.fca.org.uk/handbook/cass15/cass15s8"
          }
        },
        "rationale": [
          "Evidence pack assembled for firm reference UNSTATED against FCA CASS 15 safeguarding rules, as made by PS25/12, in force from 2026-05-07, for the audit period unstated start to unstated end.",
          "The audit period is not fully bounded, so no reconciliation result can be placed inside or outside it. Each result is carried as supplied and named in the exception schedule.",
          "No attested-artifact subject was supplied. Nothing in the accountability trail can name a subject, so every role is held.",
          "0 reconciliation results carried: 0 reconciled, 0 shortfall, 0 excess. Every verdict is taken as supplied; no safeguarding arithmetic is recomputed here.",
          "No method classification was supplied, so the pack carries none.",
          "1 matter for the auditor's attention listed against the individual rule reference, each with a slot for the firm's management response. These are matters raised by the supplied results. None of them is recorded as a breach: whether any is a breach of CASS 15 is for the firm's records and its safeguarding auditor.",
          "The accountability trail is on hold: 0 of 3 required roles are satisfied. Absent or unsigned evidence holds and never passes by default.",
          "Neither audit opinion is expressed here. The systems-adequacy and period-end compliance opinions belong to the safeguarding auditor, and this pack leaves both open with the question and the decider named.",
          "This pack is evidence assembled for the engagement. It is not a filing, it is not submittable to the FCA, and it does not discharge the audit. An approval record inside it evidences that a named human acted and nothing more."
        ],
        "no_arithmetic_claim": "The attested-artifact subject this pack is bound to evidences producer pinning, input binding and content integrity. It carries no §18 compute proof and no §16/§17 re-execution claim, and it never evidences that the arithmetic inside the firm's reconciliation export is correct. This artifact deliberately omits replay_verified rather than setting it false, because no replay was attempted.",
        "not_a_filing": "This is evidence assembled for a safeguarding audit engagement. It is not a regulatory filing, it is not submittable to the FCA, it does not reproduce the prescribed report as a fillable form, and it does not discharge the audit. An approval record inside it is evidence of a human act, never a claim that any regulator has accepted anything.",
        "note": "Deterministic UK CASS 15 safeguarding audit evidence pack. Single-run and stateless: it holds no records, runs on no schedule, and retains nothing. It assembles reconciliation results, the safeguarding method classification, a schedule of matters for the auditor keyed by rule reference, and the §27 accountability trail over an attested-artifact subject computed by art-502 and echoed here rather than recomputed. It recomputes no safeguarding arithmetic, records no breach, and expresses neither of the two audit opinions, which belong to the safeguarding auditor. It is not a filing and not legal advice."
      },
      "compliance_flags": [
        "SAFEGUARDING_AUDIT_EVIDENCE_PACK_INCOMPLETE",
        "SAFEGUARDING_AUDIT_EVIDENCE_SUBJECT_PRODUCER_UNPINNED",
        "HA_TRAIL_HOLD",
        "SAFEGUARDING_AUDIT_OPINION_NOT_EXPRESSED",
        "SAFEGUARDING_AUDIT_EVIDENCE_SUBJECT_ABSENT",
        "SAFEGUARDING_AUDIT_EXCEPTIONS_PRESENT",
        "SAFEGUARDING_AUDIT_MANAGEMENT_RESPONSE_OUTSTANDING",
        "SAFEGUARDING_AUDIT_PERIOD_UNBOUNDED"
      ],
      "golden_hash": "f963522ffeca9da4331c04001228d0bb4fba3b247b56739708ad539de6762319"
    }
  ]
}
