Appendix F — DPIA, incident simulation and audit workpapers
An assessment decision, a local test and an independent audit are different evidence objects. This appendix makes each available without claiming they discharge one another’s duties. The filled enterprise scenes are hypothetical; only identified local execution is observed.
F.1 Workpapers and acceptance boundaries
| Object | Delivered file | What it establishes / does not establish |
|---|---|---|
| Blank control/evidence workpaper | Engineering template | Reusable fields; blank observations are not successful execution |
| DPIA method and filled assessment | Chapter 20’s template; DPIA-PACK-001, structured decisions | Rejected combined proposal and rescope, not a real authorised launch |
| Incident simulation | INCIDENT-PACK-001 | Timed known/unknown facts, separate recipients, failed delivery and retry |
| Notification specimens | Initial Board, detailed Board, principal | Prepared local documents; no transmission or established live Board channel |
| Independent-review specimen | REVIEW-001 | Author-written qualified workpaper, not the actual independent book verdict |
| Actual local control results | Test results and formula results | Tested input/output and numerical behavior, not supplier capability or operational compliance |
| Sampling | Plan, calculator, recorded result | Model-dependent illustration, not a statutory sample size or zero-defect proof |
F.2 Read a failed control inside a passing harness
The dossier deliberately starts with a cached pre-withdrawal allow and an unsafe snapshot promotion. Those controls fail their criteria. The harness succeeds only when it detects the bad behavior and verifies the repaired local branch. Preserve the initial observation, changed mechanism, retest input, result and limits together. Do not publish only the final green count: that hides what was actually learned.
ACK-001 remains missing after the local cache retest. The incident’s retry remains queued without proof of delivery. An audit workpaper can describe those exceptions accurately; its author cannot sign away a legal stop. A sampling result also cannot turn untested integrations into tested ones or establish that the real population has no defects.
F.3 Reproduce on a copy
From a copied book root, the integrated stdlib runner is:
python3 -B out/dossier/CASE-001/tests/run_checks.py
It writes tests/results.json; its manifest and input hashes identify the tested version. The spreadsheet formula check is:
python3 -B out/remediation/Q09/formula_checks.py
The second command uses the book-local formula dependency directory documented by the procurement packet. It is not a stdlib spreadsheet engine. Neither command establishes native Excel/LibreOffice rendering, cached values or pagination. For sector teaching gates use the command in the sector README. For the separate sampling/control catalogue use the test README.
F.4 Blank independent-review decision record
| Field | Reviewer supplies |
|---|---|
| Reviewer / independence / competence | <identity, role, conflicts and qualification> |
| Scope and exact versions | <files/configuration/time window, hashes, exclusions> |
| Work performed | <source checks, samples, test commands and observed outputs> |
| Findings / responses | <issue, severity, evidence, owner, response and retest> |
| Conclusion | <accept, qualified, reject, or insufficient evidence; reasons> |
| Residuals / next review | <unclosed matters, authority to decide, date/trigger> |
This template is a recommended evidence discipline. The real independent book gate must read the current manuscript and artifacts and record its own judgment; neither REVIEW-001 nor an author’s local verification substitutes for it.