Legal Register
Appendix F
Reference Appendix
Appendix F · 549 words
3 min read

Appendix F — DPIA, incident simulation and audit workpapers

An assessment decision, a local test and an independent audit are different evidence objects. This appendix makes each available without claiming they discharge one another’s duties. The filled enterprise scenes are hypothetical; only identified local execution is observed.

F.1 Workpapers and acceptance boundaries

ObjectDelivered fileWhat it establishes / does not establish
Blank control/evidence workpaperEngineering templateReusable fields; blank observations are not successful execution
DPIA method and filled assessmentChapter 20’s template; DPIA-PACK-001, structured decisionsRejected combined proposal and rescope, not a real authorised launch
Incident simulationINCIDENT-PACK-001Timed known/unknown facts, separate recipients, failed delivery and retry
Notification specimensInitial Board, detailed Board, principalPrepared local documents; no transmission or established live Board channel
Independent-review specimenREVIEW-001Author-written qualified workpaper, not the actual independent book verdict
Actual local control resultsTest results and formula resultsTested input/output and numerical behavior, not supplier capability or operational compliance
SamplingPlan, calculator, recorded resultModel-dependent illustration, not a statutory sample size or zero-defect proof

F.2 Read a failed control inside a passing harness

The dossier deliberately starts with a cached pre-withdrawal allow and an unsafe snapshot promotion. Those controls fail their criteria. The harness succeeds only when it detects the bad behavior and verifies the repaired local branch. Preserve the initial observation, changed mechanism, retest input, result and limits together. Do not publish only the final green count: that hides what was actually learned.

ACK-001 remains missing after the local cache retest. The incident’s retry remains queued without proof of delivery. An audit workpaper can describe those exceptions accurately; its author cannot sign away a legal stop. A sampling result also cannot turn untested integrations into tested ones or establish that the real population has no defects.

F.3 Reproduce on a copy

From a copied book root, the integrated stdlib runner is:

python3 -B out/dossier/CASE-001/tests/run_checks.py

It writes tests/results.json; its manifest and input hashes identify the tested version. The spreadsheet formula check is:

python3 -B out/remediation/Q09/formula_checks.py

The second command uses the book-local formula dependency directory documented by the procurement packet. It is not a stdlib spreadsheet engine. Neither command establishes native Excel/LibreOffice rendering, cached values or pagination. For sector teaching gates use the command in the sector README. For the separate sampling/control catalogue use the test README.

F.4 Blank independent-review decision record

FieldReviewer supplies
Reviewer / independence / competence<identity, role, conflicts and qualification>
Scope and exact versions<files/configuration/time window, hashes, exclusions>
Work performed<source checks, samples, test commands and observed outputs>
Findings / responses<issue, severity, evidence, owner, response and retest>
Conclusion<accept, qualified, reject, or insufficient evidence; reasons>
Residuals / next review<unclosed matters, authority to decide, date/trigger>

This template is a recommended evidence discipline. The real independent book gate must read the current manuscript and artifacts and record its own judgment; neither REVIEW-001 nor an author’s local verification substitutes for it.

Contents · Appendix E · Appendix G