{
  "tool_id": "art-534-aml-lookback-disposition-rollup",
  "kernel_id": "art-534-aml-lookback-disposition-rollup",
  "display_name": "AML Lookback Disposition Rollup",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_control",
  "purpose": "Closes the loop art-470 (lookback-completeness-reconciler) and art-471 (disposition-sampling-frame) leave open. Art-470 reconciles that the RE-SCREENING extract was complete; art-471 builds a deterministic sample of the resulting dispositions for independent review; neither checks that a disposition was actually recorded for every sampled item, that a filed or no-SAR determination carries a rationale, or that the sample frame's declared population size still reconciles to the completeness population. This node rolls those three axes up: disposition-coverage against the sample frame's own declared size, disposition-rationale-presence on every filed/no-SAR determination, and a population-to-sample tie-out between art-470's and art-471's declared population sizes. Emits a closed §27.4 gate-policy value: full coverage with rationale present on every filed/no-SAR item yields auto_pass; any missing disposition evaluated as of a caller-declared date on or after the lookback's declared close date yields escalate; a population tie-out failure or an explicit caller-declared sampling-frame discrepancy yields hold; a disposition present without its required rationale yields review_required. Customer id and alert id cross this kernel already salted -- callers supply a sha256-salted@1 commitment string, never the plaintext identifier -- and the kernel never sees, requests, or computes over the plaintext. Deterministic rollup arithmetic only. Zero network, zero PII.",
  "control_description": "Closes the loop art-470 (lookback-completeness-reconciler) and art-471 (disposition-sampling-frame) leave open. Art-470 reconciles that the RE-SCREENING extract was complete; art-471 builds a deterministic sample of the resulting dispositions for independent review; neither checks that a disposition was actually recorded for every sampled item, that a filed or no-SAR determination carries a rationale, or that the sample frame's declared population size still reconciles to the completeness population. This node rolls those three axes up: disposition-coverage against the sample frame's own declared size, disposition-rationale-presence on every filed/no-SAR determination, and a population-to-sample tie-out between art-470's and art-471's declared population sizes. Emits a closed §27.4 gate-policy value: full coverage with rationale present on every filed/no-SAR item yields auto_pass; any missing disposition evaluated as of a caller-declared date on or after the lookback's declared close date yields escalate; a population tie-out failure or an explicit caller-declared sampling-frame discrepancy yields hold; a disposition present without its required rationale yields review_required. Customer id and alert id cross this kernel already salted -- callers supply a sha256-salted@1 commitment string, never the plaintext identifier -- and the kernel never sees, requests, or computes over the plaintext. Deterministic rollup arithmetic only. Zero network, zero PII.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:2263d143a5cbc54da93c78d3d8fb7d028dd161856f55cf8007414c81efad7778",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-08-04",
  "last_validated": "2026-08-04",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 83,
  "source_url": "https://ainumbers.co/chaingraph/art-534-aml-lookback-disposition-rollup.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
