{
  "@context": "https://raw.githubusercontent.com/cloudronin/uofa/main/spec/context/v0.5.jsonld",
  "id": "https://uofa.net/iso42001/hybrid/cou2",
  "type": [
    "UnitOfAssurance",
    "CredibilityEvidencePackage"
  ],
  "synthetic": true,
  "conformsToProfile": "https://uofa.net/vocab#ProfileMinimal",
  "name": "Hybrid AIMS evidence — COU2: customer-facing LLM regulatory communication (high risk)",
  "description": "ISO 42001 AIMS evidence package for COU2 of the iso42001 hybrid case study. Customer-facing LLM application that generates draft responses for regulated communications (financial product disclosures, support responses with regulatory implications). Risk profile: High. Hybrid construction: structural categories anchored in StackAware-style published AIMS materials; supplemental categories (system inventory, full impact assessment, data catalog, model evaluation, deployment config, monitoring metrics, incident response) synthesized to demonstrate dual-output behavior at high assurance level.",
  "couName": "COU2: customer-facing LLM regulatory communication drafter",
  "intendedUse": "LLM generates draft responses to customer inquiries in regulated communication contexts; human regulator-trained reviewer approves before send.",
  "assuranceLevel": "High",
  "decision": "Accepted",
  "modelRiskLevel": 4,
  "bindsRequirement": "https://uofa.net/iso42001/hybrid/cou2/req",
  "hasContextOfUse": {
    "id": "https://uofa.net/iso42001/hybrid/cou2/cou",
    "type": "ContextOfUse",
    "name": "Customer-facing LLM regulatory comms",
    "intendedUse": "Generate draft customer-communication responses with regulatory implications.",
    "decisionConsequence": "High",
    "modelInfluence": "High",
    "description": "External-party impact (customers and regulators); regulatory compliance exposure; misstatement → enforcement risk."
  },
  "hasEvidence": [
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/policy",
      "type": "https://uofa.net/vocab/aims#AIPolicy",
      "name": "Enterprise AI Policy v1.2 (extended for high-risk customer-facing context)",
      "https://uofa.net/vocab/aims#policyText": "https://internal.example/policies/ai-policy-v1.2",
      "https://uofa.net/vocab/aims#approvalSignatory": "https://uofa.net/iso42001/hybrid/cou2/cao",
      "https://uofa.net/vocab/aims#approvalDate": "2026-01-20T00:00:00Z",
      "https://uofa.net/vocab/aims#reviewCadence": "annual",
      "https://uofa.net/vocab/aims#nextReviewDate": "2027-01-20T00:00:00Z"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/scope",
      "type": "https://uofa.net/vocab/aims#AIMSScope",
      "name": "AIMS Scope Statement (regulatory comms deployment)",
      "https://uofa.net/vocab/aims#approvalSignatory": "https://uofa.net/iso42001/hybrid/cou2/cao"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/objective",
      "type": "https://uofa.net/vocab/aims#AIMSObjectiveStatement",
      "name": "AIMS Objective: zero regulatory-misstatement events",
      "https://uofa.net/vocab/aims#objectiveStatement": "Zero regulatory misstatement events on AI-drafted customer comms post-reviewer.",
      "https://uofa.net/vocab/aims#targetMeasure": "0 misstatement events per quarter",
      "https://uofa.net/vocab/aims#measurementCadence": "quarterly"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/role-aims-owner",
      "type": "https://uofa.net/vocab/aims#RoleAssignment",
      "https://uofa.net/vocab/aims#roleName": "AIMS Owner"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/role-data-steward",
      "type": "https://uofa.net/vocab/aims#RoleAssignment",
      "https://uofa.net/vocab/aims#roleName": "Data Steward",
      "https://uofa.net/vocab/aims#assignedPerson": "https://uofa.net/iso42001/hybrid/cou2/person/data-steward"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/role-comp-officer",
      "type": "https://uofa.net/vocab/aims#RoleAssignment",
      "https://uofa.net/vocab/aims#roleName": "Compliance Officer"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/risk-register",
      "type": "https://uofa.net/vocab/aims#RiskRegister",
      "name": "AI Risk Register Q1 2026 (regulatory comms scope)",
      "description": "12-entry register: regulatory misstatement, hallucination in disclosure language, prompt injection (high-risk for customer-facing), data leakage to model, customer PII handling, citation misattribution, drift in regulatory-language fidelity, model evaluation staleness, deployment drift, audit log gaps, incident response delay, supplier model degradation."
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/impact-assessment",
      "type": "https://uofa.net/vocab/aims#ImpactAssessmentRecord",
      "name": "AI system impact assessment v1.0 (COU2)",
      "https://uofa.net/vocab/aims#assessor": "https://uofa.net/iso42001/hybrid/cou2/person/aims-owner",
      "https://uofa.net/vocab/aims#assessmentScope": "Customer-impact, regulatory-compliance, and reputational dimensions",
      "https://uofa.net/vocab/aims#assessedDeploymentScope": "Customer-impact, regulatory-compliance, reputational, AND third-party-supplier dimensions",
      "https://uofa.net/vocab/aims#assessmentDate": "2026-02-10T00:00:00Z",
      "https://uofa.net/vocab/aims#identifiedRisk": [
        "regulatory misstatement",
        "PII leakage",
        "drift in language fidelity"
      ],
      "https://uofa.net/vocab/aims#mitigationStrategy": "Reviewer gate + retrieval citations + quarterly compliance audit",
      "https://uofa.net/vocab/aims#nextReviewDate": "2026-08-10T00:00:00Z"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/data-prov",
      "type": "https://uofa.net/vocab/aims#DataResourceProvenance",
      "https://uofa.net/vocab/aims#dataResource": "https://uofa.net/iso42001/hybrid/cou2/data/regulatory-corpus",
      "https://uofa.net/vocab/aims#provenanceStage": "ingestion",
      "sourceReference": "https://uofa.net/iso42001/hybrid/cou2/source/regulatory-corpus-snapshot"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/model-eval",
      "type": "https://uofa.net/vocab/aims#ModelEvaluationReport",
      "https://uofa.net/vocab/aims#evaluatedModelVersion": "v1.4.0",
      "https://uofa.net/vocab/aims#testSetCoverage": "Q4-2025 regulatory-comms benchmark (200 prompts across 8 product categories)",
      "https://uofa.net/vocab/aims#deploymentPopulation": "Q1-2026 regulatory-comms production traffic (4 product categories deployed; 4 categories pending eval)",
      "https://uofa.net/vocab/aims#testSetCoverageCategory": [
        "customer-comms",
        "regulatory-comms"
      ],
      "https://uofa.net/vocab/aims#assessmentDate": "2025-12-15T00:00:00Z"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/deploy-config",
      "type": "https://uofa.net/vocab/aims#DeploymentConfiguration",
      "https://uofa.net/vocab/aims#validatedConfiguration": "regulatory-drafter-v1.4 with reviewer-gate=enabled, max-tokens=512, temperature=0.0",
      "https://uofa.net/vocab/aims#deployedConfiguration": "regulatory-drafter-v1.5 with reviewer-gate=enabled, max-tokens=1024, temperature=0.2"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/incident-001",
      "type": "https://uofa.net/vocab/aims#NonconformityRecord",
      "https://uofa.net/vocab/aims#nonconformityDescription": "Reviewer-gate bypass observed in 3 production drafts during March 2026 outage; 3 customer drafts sent without compliance review.",
      "https://uofa.net/vocab/aims#closureDate": "2026-04-30T00:00:00Z"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/audit",
      "type": "https://uofa.net/vocab/aims#AuditResultsRecord",
      "https://uofa.net/vocab/aims#auditedFunction": "AIMS controls A.5 through A.10 (regulatory comms scope)",
      "https://uofa.net/vocab/aims#auditDate": "2026-03-25T00:00:00Z",
      "https://uofa.net/vocab/aims#auditCadence": "annual",
      "https://uofa.net/vocab/aims#auditFindings": "1 major nonconformity (reviewer-gate bypass), 4 minor observations, 2 corrective actions in flight.",
      "https://uofa.net/vocab/aims#isFoundationalEvidence": true
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/control-a52",
      "type": "https://uofa.net/vocab/aims#AIMSControl",
      "https://uofa.net/vocab/aims#controlIdentifier": "A.5.2",
      "https://uofa.net/vocab/aims#controlName": "AI system impact assessment process",
      "https://uofa.net/vocab/aims#designEffectiveness": "3",
      "https://uofa.net/vocab/aims#operationalEffectiveness": "2"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/control-a624",
      "type": "https://uofa.net/vocab/aims#AIMSControl",
      "https://uofa.net/vocab/aims#controlIdentifier": "A.6.2.4",
      "https://uofa.net/vocab/aims#controlName": "AI system V&V",
      "https://uofa.net/vocab/aims#designEffectiveness": "2",
      "https://uofa.net/vocab/aims#operationalEffectiveness": "1"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/control-a74",
      "type": "https://uofa.net/vocab/aims#AIMSControl",
      "https://uofa.net/vocab/aims#controlIdentifier": "A.7.4",
      "https://uofa.net/vocab/aims#controlName": "Data resource provenance",
      "https://uofa.net/vocab/aims#designEffectiveness": "3",
      "https://uofa.net/vocab/aims#operationalEffectiveness": "2"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/control-a86",
      "type": "https://uofa.net/vocab/aims#AIMSControl",
      "https://uofa.net/vocab/aims#controlIdentifier": "A.8.4",
      "https://uofa.net/vocab/aims#controlName": "Incident reporting mechanism",
      "https://uofa.net/vocab/aims#designEffectiveness": "3",
      "https://uofa.net/vocab/aims#operationalEffectiveness": "2"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/control-a102",
      "type": "https://uofa.net/vocab/aims#AIMSControl",
      "https://uofa.net/vocab/aims#controlIdentifier": "A.10.2",
      "https://uofa.net/vocab/aims#controlName": "Supplier AI assurance",
      "https://uofa.net/vocab/aims#designEffectiveness": "2",
      "https://uofa.net/vocab/aims#operationalEffectiveness": "Not yet assessed"
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/stakeholder-mapping",
      "type": "https://uofa.net/vocab/aims#StakeholderMappingDocument",
      "name": "Stakeholder mapping (regulatory comms scope)",
      "description": "10 interested parties identified including external regulators, customer-facing teams, legal, compliance."
    }
  ],
  "https://uofa.net/vocab/aims#assessedDeploymentScope": "Customer-impact, regulatory-compliance, reputational, AND third-party-supplier dimensions",
  "https://uofa.net/vocab/aims#deploymentPopulationCategory": [
    "customer-comms",
    "regulatory-comms",
    "internal-policy",
    "vendor-comms"
  ],
  "currentModelVersion": "v1.6.0",
  "bindsClaim": [
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/claim/policy",
      "type": "https://uofa.net/vocab/aims#AIPolicyAppropriatenessClaim",
      "name": "Claim: AI policy is appropriate for high-risk regulatory comms COU",
      "hasSupportingEvidence": [
        "https://uofa.net/iso42001/hybrid/cou2/policy"
      ]
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/claim/risk",
      "type": "https://uofa.net/vocab/aims#RiskIdentificationCompletenessClaim",
      "name": "Claim: AI risk identification complete for high-risk COU",
      "hasSupportingEvidence": [
        "https://uofa.net/iso42001/hybrid/cou2/risk-register"
      ]
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/claim/impact",
      "type": "https://uofa.net/vocab/aims#ImpactAssessmentScopeAdequacyClaim",
      "name": "Claim: impact assessment scope adequate for high-risk COU",
      "hasSupportingEvidence": [
        "https://uofa.net/iso42001/hybrid/cou2/impact-assessment"
      ]
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/claim/audit",
      "type": "https://uofa.net/vocab/aims#InternalAuditIndependenceClaim",
      "name": "Claim: internal audit conducted with objectivity (high-risk COU)",
      "hasSupportingEvidence": [
        "https://uofa.net/iso42001/hybrid/cou2/audit"
      ]
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/claim/rca",
      "type": "https://uofa.net/vocab/aims#NonconformityRootCauseAdequacyClaim",
      "name": "Claim: RCA adequately identifies underlying causes (high-risk COU)",
      "hasSupportingEvidence": [
        "https://uofa.net/iso42001/hybrid/cou2/incident-001"
      ]
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/claim/objective",
      "type": "https://uofa.net/vocab/aims#AIMSObjectiveMeasurementMethodologyValidityClaim",
      "name": "Claim: AIMS objective measurement methodology valid (high-risk COU)",
      "hasSupportingEvidence": [
        "https://uofa.net/iso42001/hybrid/cou2/objective"
      ]
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/claim/control-a624",
      "type": "https://uofa.net/vocab/aims#ControlOperationalEffectivenessClaim",
      "name": "Claim: A.6.2.4 V&V control effective at high-risk assurance level",
      "https://uofa.net/vocab/aims#claimsControl": "https://uofa.net/iso42001/hybrid/cou2/control-a624",
      "hasSupportingEvidence": [
        {
          "id": "https://uofa.net/iso42001/hybrid/cou2/impl-a624",
          "type": "https://uofa.net/vocab/aims#ControlImplementationRecord"
        }
      ]
    },
    {
      "id": "https://uofa.net/iso42001/hybrid/cou2/claim/control-a86",
      "type": "https://uofa.net/vocab/aims#ControlOperationalEffectivenessClaim",
      "name": "Claim: A.8.4 incident reporting control effective at high-risk assurance level",
      "https://uofa.net/vocab/aims#claimsControl": "https://uofa.net/iso42001/hybrid/cou2/control-a86",
      "hasSupportingEvidence": [
        {
          "id": "https://uofa.net/iso42001/hybrid/cou2/impl-a86",
          "type": "https://uofa.net/vocab/aims#ControlImplementationRecord"
        }
      ]
    }
  ],
  "wasDerivedFrom": "https://uofa.net/iso42001/hybrid/construction-v0.4",
  "wasAttributedTo": "https://uofa.net/iso42001/hybrid/case-study-author",
  "generatedAtTime": "2026-05-06T00:00:00Z",
  "hash": "sha256:0000000000000000000000000000000000000000000000000000000000000000",
  "signature": "ed25519:00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
  "hasWeakener": [],
  "hasDecisionRecord": {
    "id": "https://uofa.net/iso42001/hybrid/cou2/decision",
    "type": "DecisionRecord",
    "actor": "https://uofa.net/iso42001/hybrid/cou2/person/aims-owner",
    "role": "AIMS owner",
    "outcome": "Conditionally Accepted (pending closure of OOS-flagged evidence gaps)",
    "rationale": "AIMS evidence is structurally complete but several C3 weakeners and OOS bundle-sufficiency gaps fire substantively at this assurance level. Unlike COU1, the OOS firings here are NOT contextualized as appropriate-for-Low-risk — high-risk AI demands independent verification, stakeholder validation, expert RCA review, methodology validation. The OOS firings name the specific evidence gaps the organization needs to close before the AIMS evidence is sufficient for a high-risk deployment claim.",
    "decidedAt": "2026-05-06T00:00:00Z"
  },
  "adversarialProvenance": {
    "generatorVersion": "iso42001-hybrid-cou2-v0.4",
    "toolVersion": "uofa-cli 0.5.0",
    "promptTemplateVersion": "case-study-anchor-v0.1.0",
    "specId": "iso42001-hybrid-cou2",
    "generationTimestamp": "2026-05-06T00:00:00Z",
    "targetWeakener": null,
    "targetDefeaterType": "case-study",
    "coverageIntent": "case-study-cou2-high-risk",
    "sourceTaxonomy": "case-study/aims/high-risk-regulatory-comms",
    "evidenceGapDescription": "COU2 expected dual output (per spec §2.6.5): larger C3 firing set with multiple high-severity firings (W-AIMS-IMPACT-SCOPE on assessment vs. deployment scope mismatch; W-AIMS-MODEL-EVAL-STALE on v1.4 vs deployed v1.6; W-AIMS-MODEL-EVAL-SCOPE on test set vs deployment population; W-AIMS-DEPLOYMENT-DRIFT on v1.4 vs v1.5 config; W-AIMS-INCIDENT-UNCLOSED on incident-001 lacking RootCauseAnalysis; W-AIMS-ROLE-UNASSIGNED on AIMS Owner and Compliance Officer roles); substantial OOS firings across all 8 rules NOT contextualized — high-risk AI demands independent verification, stakeholder validation, expert RCA review, methodology validation. The dual output names the specific evidence gaps to close."
  },
  "hasValidationResult": "https://uofa.net/iso42001/hybrid/cou2/model-eval"
}
