Mittenda

Working papers.

This is OpusDatum writing, not Mittenda. The rest of this site is a synthetic firm's document estate, published so that a compliance demonstration can be checked by anyone. This page is the account of the work done against it: how twelve documents became a finding, and what the finding is and is not entitled to claim.

The published chain runs: the firm's documents, on this site; the findings letter, which quotes them clause by clause; the risk-assessment record, which takes one finding a stage further; and an extract of the OpusDatum Risk obligations register, the clause-by-clause enumeration of the Regulation that the whole review is anchored to. The letter and the record are at opusdatum.com/synthetic; the clauses they quote are listed on the citation index.

What the chain shows is the input and the output. This page is the part in between.

What was read, and in what order

The review does not read everything at once, and the order is the method rather than a convenience. Stage one reads the governing tier: the framework, the policies and the standards, the documents that answer to the board and the regulator. Procedures are deliberately left out of it. A procedure describes how work is done; the question at stage one is what the firm has committed to, and a procedure that behaves well under a standard that requires nothing has established nothing about the standard.

Procedures are stage two's ground, and they enter where the assessed risk points rather than across the estate. That is visible in what the two specimens quote. The letter quotes five clauses from three documents, every one of them a policy or a standard. The record quotes the payments procedure, the crypto procedure and a platform design note, because the risk it assesses runs through them.

Four answers, and why silence is one of them

Every obligation on the register gets one of four answers, and each is a claim about the documents rather than about the firm.

AnswerWhat it means
CoveredThe obligation is met and the evidence is cited.
PartialPart of the obligation is answered; the remainder is not.
GapThe firm addresses the obligation, but the coverage is reviewed and found wanting.
Not evidencedNothing in the firm's documents speaks to the obligation. Never inferred from silence.

The last two are the pair that matters, and they are routinely collapsed into each other. A Gap is a judgement: the clause was found, read, and does not do what the duty requires. Not evidenced is the absence of a judgement: there was nothing to read. Recording the second as though it were the first would credit a firm with a position it has never taken, and recording it as non-compliance would accuse the firm of something the documents cannot establish either.

So 'Not evidenced' means the governing tier is silent, and nothing more. It is not a finding that the firm is in breach. It is a finding that the documents a supervisor would be shown do not answer the question, which is a different problem and often a more tractable one.

What a clause has to be about

The finding the letter leads with turns on this, and it is the part of the method that a keyword search gets wrong.

Mittenda's policy verifies customer identity against a reliable and independent source. The duty requires the accuracy of the information accompanying a transfer to be verified against a reliable and independent source. The two sentences share almost every word. They are about different objects: one is about the customer, the other is about what travels with the payment, and nothing in the governing tier requires the second to be drawn from the first.

A mapping that matches text marks that clause as coverage and moves on. Anchoring by object asks what the duty is about before asking whether a clause answers it, which is why the finding reads Not evidenced against a set of documents that appear, on their face, to address the Regulation thoroughly. Every downstream control can then run faithfully on a name the firm never verified.

Which risks may not be skipped

The Regulation expects risk-based decisions, so a firm may set a tolerance and must be able to defend where it set it. Some risks are not tolerance questions at all. Each risk on the register is put through one test: does its failure defeat what the provision exists to achieve, with no meaningful compensating control? Those that pass are key risks, and the strict ones sit upstream of duties that admit no risk-based application.

It is a cut, not a ranking. A risk is key because a provision's purpose fails without it, never because it scored highly against anything. The risk worked through in the record is one of the strict ones, which is why its evaluation records that acceptance was not available at any level: not because the assessment felt strongly about it, but because the firm's own appetite statement leaves no room, read with the designation the register carries.

How far a documents review reaches

Evidence sits on a ladder. A document shows design: what the firm has committed to. Records of the control running show implementation. Evidence that the control does what it is for, over time and under load, shows effectiveness. The three are not interchangeable, and the distinction is where supervisory findings live.

A review of documents establishes the first rung and reaches no further, and this account is worth more than a claim to the contrary. In the published record, four control areas are graded, and every one of them is graded on design alone. Three are marked as not answering the risk, and the fourth is marked unevidenced. None is marked effective, because nothing in a document set could show that it was.

Two things put the top rung out of reach here, and only one of them is a property of the method. The first is the stage: stage one is a coverage review and says so. The second is the specimen itself. Mittenda is a fiction, so there are no operating records to obtain, no sample to test, and no period over which anything ran. A published demonstration on a synthetic firm can show how the reasoning works and what it cites; it cannot show an effectiveness conclusion, and a specimen that appeared to reach one would be showing something that did not happen.

Stating the ceiling is not a caveat at the end. It is the same discipline as the fourth coverage state: the review reports what it established and declines to imply the rest.

Who decides

The machine drafts and the practitioner adjudicates and signs. Nothing enters the record without a person having decided it and without a citation to the document it rests on. That is why every finding in the letter carries the clause it turns on, and why the risk-assessment record separates what a document says from what the assessment concludes from it. A reader who disagrees with a conclusion can go to the clause and take a different view; a reader who cannot find the clause has been asked to take the conclusion on trust, which is the thing this demonstration exists to refuse.

The work here was done on ISO 31000 discipline. The published documents carry no clause numbers from it, because a compliance officer reading a finding needs the finding, not the standard it was produced under.

Back to Mittenda Limited and the document estate  ·  The citation index