DISPATCHES · Summit Cognitive

← All dispatches

EvidenceArchitecture NotesJuly 27, 20264 min read

The compliance channel needs custody

A secure submission service protects transport, but the organization still needs exact custody from the approved evidence through transmission, acknowledgement, correction, and retention.

A protected portal can provide confidentiality, integrity, and authentic delivery. It cannot establish that the organization uploaded the approved document, used the correct model identifier, included every required attachment, retained the acknowledgement, or can reproduce the submitted package later. Transport security is one link in evidence custody.

The Commission's GPAI guidance directs providers to EU SEND for several document types, including systemic-risk notifications, reassessment requests, serious-incident reports, and certain safety and security materials. The channel solves important transmission problems. The submitting organization still owns package assembly and internal continuity.

Build a submission manifest before upload. Name the authority, document type, legal basis, provider and representative, model or system identifiers, covered release, evidence cutoff, required attachments, file hashes, confidentiality classification, approving owners, and deadline. Validate the package against that manifest rather than trusting a download folder assembled by hand.

Preserve both sides of transmission

Retain the exact bytes submitted and the channel's acknowledgement, timestamp, submission identifier, account or representative used, and any field values entered outside the uploaded documents. Screenshots can supplement the receipt but should not be the sole evidence when structured exports or confirmations are available.

Identity continuity deserves attention. Staff change, authorized representatives rotate, multifactor devices fail, and accounts become unavailable. Maintain role-based ownership, reviewed alternates, and periodic access checks without sharing credentials. The submission path should not depend on one person's browser state during a deadline.

Secure delivery proves where bytes traveled; custody proves which approved claim those bytes represented.

Corrections should link to the original package. If a document was incomplete, misleading, or tied to the wrong model, preserve the discovered error, impact, corrected bytes, approval, submission receipt, and authority correspondence. Do not overwrite the internal copy of the original; that destroys the record needed to explain the correction.

Test confidentiality through the working path. Temporary exports, local downloads, email attachments, collaboration tools, and support tickets can create copies outside the protected service. Minimize staging locations, set restrictive permissions, remove temporary material under a documented process, and prove cleanup without deleting the retained canonical package.

Reconcile submissions against the obligation ledger. A successful upload should update the applicable model and requirement with its receipt. An upcoming deadline without an accepted receipt should remain visible. This closes the gap between compliance work performed in a portal and the institutional record used for release and assurance decisions. Periodically select accepted submissions and reconstruct the complete package from retained custody evidence; missing bytes, approvals, identifiers, or acknowledgements should become records-management defects with owners and deadlines.

Make the obligation operational

Begin with the approved submission manifest, exact package, authorized identity, protected transport, acknowledgement, correction chain, and obligation-ledger reconciliation. Express it as a control object rather than a policy summary: scope, triggering condition, applicable system or model version, permitted exception, effective time, evidence source, and the consequence when the control cannot establish compliance. This lets engineering, product, legal, and operations examine the same boundary without pretending their responsibilities are interchangeable.

The minimum receipt should retain document and attachment hashes, approvals, model and release identifiers, channel fields, receipt and timestamp, access check, temporary-copy cleanup, and correction linkage. Keep the record proportionate and protect confidential information, but make it possible to determine which rule, artifact, system version, and accountable decision governed the event. A folder of undated screenshots may show that work occurred; it rarely proves that the operative control held for the affected release.

Test the implementation by assembling packages with wrong versions, missing attachments, unavailable submitters, expired access, rejected files, corrections, and temporary-copy leakage in a non-production exercise. Include ordinary cases, boundary cases, degraded dependencies, and known exceptions. Preserve the starting state, observed output, machine-readable evidence, user-visible result, and any human intervention. Re-run the test after changing a model, content pipeline, interface, standard, provider, or policy interpretation.

The regulatory-submission custodian with records and security owners should decide whether the evidence supports continued operation, a narrower scope, a compensating control, or a hold. The owner needs authority over the affected release and access to the evidence. Record unresolved interpretation separately from a technical defect so an engineering patch does not masquerade as a legal conclusion.

Monitor both presence and effectiveness. A marker can exist but be stripped downstream. A disclosure can render but arrive after exposure. A document can be submitted but refer to an obsolete model. Pair a control-presence measure with a consequence or comprehension test, give the claim a review date, and reopen it when a dependency changes.

Maintain a dependency register for the control. Model endpoints, editing pipelines, content formats, user interfaces, identity services, submission portals, vendors, and external standards can change the evidence without changing the policy text. Name which changes invalidate the last test and which monitoring signal proves that the dependency remains inside the reviewed state.

Exercise the exception path as carefully as the ordinary path. Record who can invoke it, which facts they must supply, how long it lasts, what capability or distribution is reduced, and which compensating evidence remains. An exception without expiry and re-entry criteria becomes a second operating model that can silently outlive the reason it was approved.

Keep public and executive claims no broader than the tested boundary. Say which systems, releases, formats, routes, and dates the evidence covers, and identify material exclusions. When a control fails or a dependency moves, update the claim and the remediation record together. A transparent limitation protects more credibility than a universal statement built from a narrow passing test.

— Dispatches · Summit Cognitive

Continue from here

Turn the argument into a practice.

Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.