reasonsmith audit engine

Conformance Report

← landing · audit dossier
System under test CreditScoringPipeline
Declared Scope high-risk
Regulation Pack table7
Executive Headline Summary
6 requirements · 4 binding: 3 observed, 1 violated · 2 interpretive: 2 unattainable
Report Provenance: Generated without an identified source commit. Command: python docs/build_example.py
KEY FINDING

Form Completeness Does Not Imply Reason Fidelity

An evidence record can be marked COMPLETE while four of its five legally-owed reasons are missing due to proof truncation.
Evidence Record COMPLETE
Decision: APP-1042
Duty: Adverse action reasons in credit decisions
Source: ECOA / Reg B (12 CFR 1002.9)
Minimal Evidence Retained (5 of 5 Table 7 fields):
  • stored_reasons_per_decision: C01 — Income insufficient for amount of credit requested
  • model_version: credit-scoring-2026.03.1 / rules cs-rules-2026.03
  • score_factors: C01 0.7656; C02 0.6972; C03 0.6320; C04 0.6004; C05 0.5112
  • audit_ids: AAN-2026-0731-1042 / trace-9f3c1b
  • retention_for_regulatory_lookback: 25 months from notice date, per lender policy
Reason-Deletion Certificate FAIL
Query: adverse_action(APP-1042)
Engine: reference:top-1-proofs (distribution semantics)
Exact: 0.9914 Engine: 0.7656 Gap: -0.2258
Reason Audit (5 found · 4 deleted):
  • [used] C01 — Income insufficient for amount of credit requested (score 0.7656)
  • [DELETED] C02 — Length of time credit has been established is too short (score 0.6972)
  • [DELETED] C03 — Delinquent past or present credit obligations (score 0.6320)
  • [DELETED] C04 — Too many recent inquiries on credit bureau report (score 0.6004)
  • [DELETED] C05 — Insufficient number of credit references provided (score 0.5112)
Binding Duties 4 total
3 observed 1 violated
Interpretive Items 2 total
2 unattainable

Requirement Findings

eu_ai_act_art13_transparency (EU AI Act Art. 13)
Binding Scope: high-risk SATISFIED
Strength Lattice:
unattainable observed probed proved
Requires Signals: model_and_data_version_idsextraction_timestampdataset_snapshot_hashfidelity_coverage_metricsexplanation_scopelinkage_from_decision_to_artifact
Observed over 3 decision(s): every required signal (model_and_data_version_ids, extraction_timestamp, dataset_snapshot_hash, fidelity_coverage_metrics, explanation_scope, linkage_from_decision_to_artifact) carries a value in every record. Holds on the trace supplied; nothing here extends the claim to decisions not in it.
eu_ai_act_art12_record_keeping (EU AI Act Art. 12)
Binding Scope: high-risk VIOLATED
Strength Lattice:
unattainable observed probed proved
Requires Signals: automatic_event_logsretention_schedulesigner
Violated over 3 observed decision(s): the system declares it can emit these signals, but records carry no value for signer.
VIOLATED IN TRACE — Required Signals Absent from Decision Log:
signer
VIOLATED IN TRACE — Execution Counterexample Witness (all 1 offending record):
Trace StepDecision Record Witness
Step 1artifact_logs_decision_record: {'id': 'APP-1043', 'result': 'adverse_action'}, artifact_logs_reason_explanation: C03 - Delinquent past or present credit obligations, artifact_logs_notification_latency_days: 21, artifact_logs_counteroffer_not_accepted: 0, provenance_model_version: credit-scoring-2026.03.1, provenance_constraint_set: ['cs-rules-2026.03'], provenance_active_exceptions: [], scope_statements_local_vs_global: local, scope_statements_explanation_scope: local, scope_statements_approximation_vs_guarantee: approximation, stability_signals_artifact_drift: 0.01, model_and_data_version_ids: credit-scoring-2026.03.1 / dataset cs-data-2026.03, extraction_timestamp: 2026-07-31T22:05:00Z, dataset_snapshot_hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855, fidelity_coverage_metrics: fidelity: 0.9914, coverage: 1.0000, explanation_scope: local (per-applicant decision explanation), linkage_from_decision_to_artifact: AAN-2026-0731-1043 -> cs-rules-2026.03, automatic_event_logs: event_id: EVT-1043-01, status: logged, level: info, retention_schedule: retention_period: 25 months, policy: ECOA 1002.9, per_decision_reason_string: C03 — Delinquent past or present credit obligations, feature_to_named_concept_mapping: delinquency_on_file -> C03: Delinquent obligations, dpia_cross_reference: DPIA-2026-014 s.4.2 (automated credit scoring), stored_reasons_per_decision: C03 — Delinquent past or present credit obligations, model_version: credit-scoring-2026.03.1 / rules cs-rules-2026.03, score_factors: C03 0.8120; C01 0.7210, audit_ids: AAN-2026-0731-1043 / trace-9f3c1c, retention_for_regulatory_lookback: 25 months from notice date, per lender policy
gdpr_art22_meaningful_information (GDPR Art. 22 (and Rec. 71))
Binding SATISFIED
Strength Lattice:
unattainable observed probed proved
Requires Signals: per_decision_reason_stringfeature_to_named_concept_mappingdpia_cross_reference
Observed over 3 decision(s): every required signal (per_decision_reason_string, feature_to_named_concept_mapping, dpia_cross_reference) carries a value in every record. Holds on the trace supplied; nothing here extends the claim to decisions not in it.
ecoa_reg_b_adverse_action (ECOA / Reg B 12 CFR 1002.9)
Binding SATISFIED
Strength Lattice:
unattainable observed probed proved
Requires Signals: stored_reasons_per_decisionmodel_versionscore_factorsaudit_idsretention_for_regulatory_lookback
Observed over 3 decision(s): every required signal (stored_reasons_per_decision, model_version, score_factors, audit_ids, retention_for_regulatory_lookback) carries a value in every record. Holds on the trace supplied; nothing here extends the claim to decisions not in it.
fda_gmlp_samd (FDA GMLP agency transparency guidance)
Interpretive UNATTAINABLE
Strength Lattice:
unattainable observed probed proved
Requires Signals: design_history_linksverification_logschange_control
Unattainable on the evidence supplied: no record in the supplied decision trace carries a value for change_control, design_history_links, verification_logs, and the system declared no capabilities, so nothing here can discharge this requirement. Read from that trace alone; a longer trace could show the system emitting these signals.
UNATTAINABLE AS BUILT — Missing Capability Signals:
change_controldesign_history_linksverification_logs
The system declares no capability to emit these signals. No testing trace can satisfy this requirement.
nist_ai_rmf_risk_evidence (NIST AI RMF 1.0)
Interpretive UNATTAINABLE
Strength Lattice:
unattainable observed probed proved
Requires Signals: continuous_monitoring_logsmetric_thresholds_and_alertsreviews_and_sign_offsincident_tickets
Unattainable on the evidence supplied: no record in the supplied decision trace carries a value for continuous_monitoring_logs, incident_tickets, metric_thresholds_and_alerts, reviews_and_sign_offs, and the system declared no capabilities, so nothing here can discharge this requirement. Read from that trace alone; a longer trace could show the system emitting these signals.
UNATTAINABLE AS BUILT — Missing Capability Signals:
continuous_monitoring_logsincident_ticketsmetric_thresholds_and_alertsreviews_and_sign_offs
The system declares no capability to emit these signals. No testing trace can satisfy this requirement.

Limits of this report

This report is not a compliance guarantee and is not legal advice. It assesses system capability information and trace evidence against formal specifications. Whether these findings discharge legal duties remains a determination this tool does not make and cannot make. A requirement reported without a strength was not evaluated or is not applicable, and no verdict on it should be read from this report. Recital and guidance items inform how statutory duties are interpreted but create no obligation of their own; interpretive requirements are evaluated and reported separately, and are never folded into the binding headline counts. A requirement reported not applicable was excluded either because no regulatory class was declared for the system at all, or because the class that was declared is not the one the requirement is limited to. This tool never infers that class, so an undeclared system is neither placed in scope nor cleared of the duty: read the declared scope line before reading a not-applicable result.