Weakener catalog (v0.17.0)
Generated from uofa catalog --format md at 2026-08-30T02:53:21Z.
57 patterns across 5 packs.
Pack: core (23 patterns)
Section titled “Pack: core (23 patterns)”| Pattern | Severity | Description |
|---|---|---|
COMPOUND-01 | Critical | Critical and High severity weakeners coexist — compounding risk escalation. |
COMPOUND-03 | High | Assurance level is not Low, yet Critical weakeners exist — stated assurance level may be overstated. |
W-AL-01 | High | Validation result has no uncertainty quantification — aleatory uncertainty is uncharacterized. |
W-AL-02 | Medium | Uncertainty quantification is reported but no sensitivity analysis is documented — the drivers of uncertainty are uncharacterized. |
W-AR-01 | Critical | Credibility factor has a required level but no acceptance criteria — basis for the requirement is unsupported. |
W-AR-02 | Critical | Credibility factor achievedLevel is below requiredLevel, yet the decision outcome is Accepted with no documented offset rationale — contradictory result ignored. |
W-AR-03 | High | Requirement requires a specific verification method but the supporting activity used a different activityType — evidence does not answer the question the requirement asked. |
W-AR-04 | High | ModelConfiguration was validated at a modelVersion that differs from the UofA currentModelVersion — validation evidence may not apply to the current model. |
W-AR-05 | High | Validation result has no comparedAgainst link — comparator data source is absent. |
W-CON-01 | High | Decision is Accepted but a credibility factor has neither requiredLevel nor achievedLevel — the acceptance rests on an unestablished factor. |
W-CON-02 | Medium | UofA references an identifier whose target does not resolve within the graph and has no documented external-fetch hint. |
W-CON-03 | High | Evidence timestamp is later than the UofA signature timestamp — evidence was created after the UofA was signed, either a clock anomaly or an uncounted update. |
W-CON-04 | Medium | UofA conforms to ProfileComplete but declares no SensitivityAnalysis — a Complete profile is structurally expected to document sensitivity analysis alongside uncertainty quantification. |
W-CON-05 | High | VerificationActivity is declared on the UofA but no Evidence is linked via prov:wasGeneratedBy — the activity is a procedural placeholder rather than real verification. |
W-EP-01 | Critical | Claim has no prov:wasDerivedFrom link to evidence — provenance chain is broken. |
W-EP-02 | High | Validation result has no prov:wasGeneratedBy — generation activity is missing. |
W-EP-03 | High | Input dataset vintage predates the current model revision date — input data may be stale relative to the model it exercises. |
W-EP-04 | High | Credibility factor is not assessed but model risk level exceeds 2 — unassessed factors at elevated risk weaken the credibility argument. |
W-ON-01 | Critical | UofA has no Context of Use — intended use and risk context are undefined. |
W-ON-02 | High | Context of Use has neither an applicability constraint nor an operating envelope — the COU is declared but its boundary of validity is undocumented. |
W-PROV-01 | Critical | Provenance chain terminates at a node that has no upstream derivation/generation/use edge and is not marked uofa:isFoundationalEvidence=true — chain is incomplete. |
W-SI-01 | Medium | UofA has no digital signature — structural integrity cannot be verified. |
W-SI-02 | High | UofA is missing bindsRequirement — incomplete profile binding. |
Pack: iso42001 (15 patterns)
Section titled “Pack: iso42001 (15 patterns)”| Pattern | Severity | Description |
|---|---|---|
W-AIMS-AUDIT-STALE | High | Audit results record declares cadence but lacks nextReviewDate — staleness relative to system change frequency cannot be verified. |
W-AIMS-CROSSWALK-INVALID | Medium | SoA asserts framework crosswalk but no AIMSControl carries the matching mappedToFramework — crosswalk invalid. |
W-AIMS-DATA-DRIFT-UNDETECTED | High | Data resource declared but no OngoingDataQualityMonitoring evidence present — data drift would go undetected. |
W-AIMS-DATA-LINEAGE-BROKEN | High | Data resource provenance stage has no hasNextStage successor — lineage discontinuity across processing stages. |
W-AIMS-DEPLOYMENT-DRIFT | High | Deployment configuration differs from validated configuration — deployment drift. |
W-AIMS-IMPACT-SCOPE | High | Impact assessment scope does not match assessed deployment scope — structural subset mismatch. |
W-AIMS-IMPACT-STAKEHOLDER | Medium | Impact assessment record lacks affectedStakeholder enumeration — affected parties not documented. |
W-AIMS-INCIDENT-UNCLOSED | High | Nonconformity record present but no root cause analysis linked — incident not closed. |
W-AIMS-MODEL-EVAL-SCOPE | High | Model evaluation testSetCoverage does not match documented deploymentPopulation — test set scope mismatch. |
W-AIMS-MODEL-EVAL-STALE | High | Model evaluation report version does not match currently deployed model version — evaluation is stale. |
W-AIMS-OBJECTIVE-UNMEASURED | Medium | AIMS objective declared but no targetMeasure documented — objective is unmeasured. |
W-AIMS-ROLE-UNASSIGNED | High | AIMS role assignment lacks both assignedPerson and assignedOrganizationalUnit — role is unassigned. |
W-AL-02 | Medium | Claim asserts framework mapping that no other bundle artifact references — claim-evidence alignment broken. |
W-AR-02 | High | Accept-decision risk has acceptance rationale but no justification body — risk acceptance is not documented. |
W-PROV-01 | High | Data resource provenance record lacks sourceReference — upstream document or system identifier missing. |
Pack: model-credibility (10 patterns)
Section titled “Pack: model-credibility (10 patterns)”| Pattern | Severity | Description |
|---|---|---|
COMPOUND-EV-01 | Critical | Score informs a high-risk decision while carrying neither an uncertainty estimate nor a null baseline - there is no basis for judging whether the reported difference is real. |
COMPOUND-EV-02 | Critical | A generalized performance claim rests on a sample with no stated relationship to the population it generalizes over - the claim is broader than the evidence supporting it. |
W-EV-CAP-06 | Medium | No capability-confound control stated - the reported separation may be attributable to general capability rather than to the construct the benchmark claims to measure. |
W-EV-COR-09 | Medium | No independently furnished measurement corroborates this reported score - the furnished evidence available measures different properties, so the published number stands on a single referent. |
W-EV-COU-05 | Critical | Reported evaluation states no context-of-use relevance, and an assessment context was supplied - the score is being read against a decision the published record never claimed it informs. |
W-EV-DET-03 | High | Reported evaluation states no determinism floor - sampling settings and per-model run-to-run spread are uncharacterized, so the score is one draw reported as a measurement. |
W-EV-DIV-07 | High | The score reported in the published record disagrees with an independent measurement of the same benchmark by more than the measurement tolerance - the two do not agree, and which is correct is not established here. |
W-EV-GEN-02 | High | Reported benchmark score carries no account of how its items sample the target population - benchmark accuracy cannot be read as generalized accuracy. |
W-EV-NULL-04 | High | Reported score is not calibrated against a null, chance, or comprehension-free baseline - the floor the score must clear to mean anything is unstated. |
W-EV-SUB-08 | High | The evaluation subject is not configuration-controlled - its identity is claimed by the provider with no immutable version guarantee, so the score is evidence about an occasion rather than about a fixed artifact. |
Pack: nasa-7009b (6 patterns)
Section titled “Pack: nasa-7009b (6 patterns)”| Pattern | Severity | Description |
|---|---|---|
W-NASA-01 | High | Data pedigree factor is not assessed but model risk level exceeds 1 — input data provenance should be documented at elevated risk. |
W-NASA-02 | High | Technical review factor is assessed but has no linked ReviewActivity evidence. |
W-NASA-03 | High | Process management factor is assessed but has no linked ProcessAttestation evidence. |
W-NASA-04 | Medium | Use history is not assessed but model risk level exceeds 2 — prior deployment evidence would strengthen the credibility argument. |
W-NASA-05 | High | Results uncertainty factor is assessed but UofA has no UQ data (hasUncertaintyQuantification is missing). |
W-NASA-06 | High | Results robustness factor is assessed but has no linked SensitivityAnalysis evidence. |
Pack: surrogate (3 patterns)
Section titled “Pack: surrogate (3 patterns)”| Pattern | Severity | Description |
|---|---|---|
W-SURR-01 | High | Declared physics constraint has no linked constraint-check evidence — the surrogate claims to respect a governing law with no checkable residual/conservation artifact. |
W-SURR-02 | Critical | Surrogate inherits credibility from a parent COU whose recorded decision is Not Accepted — inherited-credibility defeater. |
W-SURR-03 | High | COU evaluation point/region is not contained within the declared training envelope — the surrogate is exercised in extrapolation. |