{"_self":{"principle":"Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.","widget":"article_topology","feature":"topology","name":"Article topology","what":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER.","contains":"claims, sources, anecdotes, question_graph slice","slug":"big-four-isae-3000-ai-assurance","urls":{"read":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/topology"},"how_to_use":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER.","write":null,"imessage":null,"router_tag":null,"proof_chain":[{"step":1,"claim":"Articles are voxel graphs of tiered claims, not prose blobs.","verify":"https://miscsubjects.com/api/articles/constitution"},{"step":2,"claim":"Claims link to hash-chained sources via source_ids.","verify":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/sources"},{"step":3,"claim":"Ask reads topology; ingest/claim append to ledger.","verify":"https://miscsubjects.com/api/protocol"},{"step":4,"claim":"Models queue growth: populate → collaborate → repair → reflex.","verify":"https://miscsubjects.com/api/protocol/grow"},{"step":5,"claim":"Graph proves its own shape (reflex) and $/claim (yield).","verify":"https://miscsubjects.com/graph.html?layer=reflex"},{"step":6,"claim":"Full feature index + _explain on every API response.","verify":"https://miscsubjects.com/api/articles/system-map"}],"related_features":[{"id":"ask","name":"Ask protocol","what":"Answer only from topology; creates question_node with gaps and ingest_hint.","urls":{"read":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/prompts","write":"https://miscsubjects.com/api/protocol/ask"}},{"id":"graph_topology","name":"Cross-article graph","what":"Merged claims/sources across condition+stack slugs for one question.","urls":{"read":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/graph-topology?question=..."}},{"id":"question_graph","name":"Question graph","what":"Ask nodes (questions + gaps) and evidence_ingest nodes (pasted model output).","urls":{"read":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/question-graph","write":"https://miscsubjects.com/api/protocol/ask"}},{"id":"voxels","name":"Voxel graph","what":"Claims as atoms, sources as edges (supported_by, posted_by). Per-claim provenance.","urls":{"read":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/voxels","write":"https://miscsubjects.com/api/protocol/claim"}}],"system_map":"https://miscsubjects.com/api/articles/system-map","system_map_markdown":"https://miscsubjects.com/api/articles/system-map?format=markdown","not_medical_advice":true},"_explain":{"feature":"topology","name":"Article topology","what":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER.","why":"Every feature is auditable collective intelligence","how":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER.","model":null,"verifies":null,"urls":{"read":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/topology"},"imessage":null,"router":null,"related":[{"id":"ask","what":"Answer only from topology; creates question_node with gaps and ingest_hint."},{"id":"graph_topology","what":"Merged claims/sources across condition+stack slugs for one question."},{"id":"question_graph","what":"Ask nodes (questions + gaps) and evidence_ingest nodes (pasted model output)."},{"id":"voxels","what":"Claims as atoms, sources as edges (supported_by, posted_by). Per-claim provenance."}],"not_medical_advice":true},"slug":"big-four-isae-3000-ai-assurance","title":"AI assurance under ISAE 3000: the evidence object the engagement is missing","register":"standard","tags":["assurance","isae-3000","adjudication","use-case"],"updated_at":"2026-07-30T14:15:29.200Z","body_excerpt":"## The engagement the profession has accepted without an evidence object\n\nISAE 3000 (Revised) — the IAASB's *Assurance Engagements Other than Audits or Reviews of Historical Financial Information* — is the standard the large firms reach for when a client asks for assurance over something that is not a set of accounts: controls, processes, and now AI systems. Its demands are not exotic. The practitioner must apply **professional skepticism and judgement**; obtain **sufficient appropriate evidence**; assess the **suitability of the criteria** the subject matter is measured against; and document the engagement so that *an experienced practitioner, having no previous connection with the engagement, can understand the significant matters and the basis for the conclusion*.\n\nThe newer sustainability standard, **ISSA 5000** — approved by the IAASB in September 2024, effective for periods beginning on or after 15 December 2026 — carries the same architecture into information produced by *systems and estimation processes*, not ledgers. The profession is moving toward assuring machine-produced conclusions, and every major firm is standing up an AI assurance practice against the demand created by the EU AI Act, ISO/IEC 42001, and clients who want a signed opinion that their AI system does what its documentation says.\n\nNow put the standard next to the subject matter. For a large language model deployed the ordinary way, **there is nothing to inspect**. The system emits answers, not records of how each answer was reached that anyone can re-open, compare, or test. The practitioner's toolkit — inspection, reperformance, recalculation — has no object to operate on. What fills the gap today is testimony about the process: policy documents, governance minutes, a sampled review where a human agreed with the model's output. That is evidence *about the organisation*, not evidence about the decisions.\n\nAn experienced practitioner handed that file cannot reconstruct why any individual decision came out the way it did. The documentation requirement — the sentence in the standard that operationalises all the others — is being met at the wrong altitude.\n\n## A candidate evidence object, running\n\nThis site runs a decision system built the other way around: the evidence object comes first, and the decision is only valid if the object exists. Every claim below opens to a live receipt.\n\nOne governed decision works like this. The **rule set** — the criteria, in assurance vocabulary — is pinned to a content hash, so the version applied is beyond dispute; the **record** under review is hashed the same way. Three model seats across two model families each receive the identical rule set and record under a governing constitution that compels a fixed output shape: the verdict, the clauses relied on, a clause-by-clause derivation (did each clause's condition trigger, does it support or defeat the action, on which evidence records), the records that were **absent**, the strongest rejected alternative, and what evidence would flip the conclusion.\n\nA deterministic parser — ordinary software, not another model — voids anything structurally invalid: an invented clause, a missing field, an absent decision line can never authorise. The surviving findings go to the **derivation-agreement gate**, which compares not verdicts but derivations, tuple by tuple. Only when independent seats agree on the answer *and* on the clause-level route to it does the decision seal. Anything less escalates to a named human, and the escalation is itself a permanent receipt.\n\n[[embed:source:s1]]\n\nRead that as an evidence-gathering procedure. Inspection: the sealed record carries complete payloads, not summaries. Reperformance: the hashed rule set and record can be re-run through the same seats later. Recalculation: the gate's comparison is deterministic and repeatable from the preserved derivations. The object is *shaped to provide* what ISAE 3000's evidence requirement asks for — a design claim","ranking":"safety-first (interaction_risk/limitations), then quote-gated effective_weight","claims":[{"id":"c1","text":"ISAE 3000 (Revised) requires the practitioner to obtain sufficient appropriate evidence and to document the work so that an experienced practitioner with no prior connection to the engagement can understand the basis for the conclusion.","tier":"system","section":"The engagement","interaction_risk":false,"status":"active","source_ids":[],"why_material":"This is the documentation standard an AI-assurance engagement must meet, and the one AI systems currently give the practitioner nothing to meet it with.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c2","text":"For assurance over an AI system's operating effectiveness there is no established evidence object of record: the system under review emits answers, not inspectable records of how each answer was reached.","tier":"system","section":"The evidence gap","interaction_risk":false,"status":"active","source_ids":[],"why_material":"The gap between what the standard demands and what the subject matter produces is the entire engagement risk.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c3","text":"A governed decision here emits a candidate evidence object: the rule set pinned to a content hash, each seat's clause-by-clause derivation in machine-comparable form, the deterministic gate's disposition, and a permanent receipt.","tier":"system","section":"The candidate evidence object","interaction_risk":false,"status":"active","source_ids":["s1"],"why_material":"It is shaped to provide what an evidence-gathering procedure needs to inspect, not merely to describe the system in prose.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c4","text":"The gate refuses to authorise a unanimous verdict when the underlying derivations diverge, and the refusal is itself a permanent record.","tier":"system","section":"The candidate evidence object","interaction_risk":false,"status":"active","source_ids":["s2"],"why_material":"Surface agreement hiding divergent reasoning is exactly the failure a practitioner exercising professional skepticism must be able to detect.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c5","text":"The gate's first version passed a false convergence (clause numbers matched, meanings did not); the defect, the retraction, and the repaired seal are all public receipts.","tier":"system","section":"The instrument's own audit trail","interaction_risk":false,"status":"active","source_ids":["s1","s3"],"why_material":"An instrument whose own failed audit is on the record demonstrates the documentation behaviour it proposes to evidence.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c6","text":"In 72 controlled calls, auditable structure (declared-absent records, flip conditions, rejected alternatives) appeared in zero of 48 ungoverned calls and only under the governing constitution.","tier":"system","section":"Design effectiveness","interaction_risk":false,"status":"active","source_ids":["s4"],"why_material":"It makes the governing text a measured causal variable — the kind of statement a test of design effectiveness exists to support.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c7","text":"A calibration study of 30 oracle-labelled synthetic cases through the production gate recorded zero wrongful authorisations across 30 sealed panels; seat accuracy was 30/30 (glm-5.2) and 29/30 (kimi-k2.7), and the weak seat's transport failures blocked every NEGATE seal.","tier":"system","section":"Operating effectiveness","interaction_risk":false,"status":"active","source_ids":["s5"],"why_material":"A measured wrongful-authorisation rate on labelled fixtures is the beginning of an operating-effectiveness file, stated with its limits.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c8","text":"Every sealed record must declare the evidence it did not receive, and a panel that cannot conclude seals an abstention naming the absence — logic that maps to ISA 705's inability-to-obtain-sufficient-appropriate-evidence basis for a modified opinion.","tier":"system","section":"The absence declaration","interaction_risk":false,"status":"active","source_ids":["s6","s7"],"why_material":"The modified-opinion decision is the assurance profession's own fail-closed rule; here it executes per decision rather than per report.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c9","text":"A governed call costs $0.0006 to $0.0024 and a three-seat sealed decision about half a cent, so per-decision evidence is cheaper than the working paper it would support.","tier":"system","section":"Cost","interaction_risk":false,"status":"active","source_ids":["s4"],"why_material":"Removes the economic objection to evidence at the decision grain.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false},{"id":"c10","text":"No claim of ISAE 3000 conformance is established: the calibration evidence covers 30 synthetic determinate fixtures in one task class, criteria suitability is untested against real engagement subject matter, and the mapping to the standards is a candidate mapping, not an accepted one.","tier":"system","section":"What is not satisfied","interaction_risk":false,"status":"active","source_ids":["s8"],"why_material":"A practitioner must not be sold more than the evidence supports, and these are the exact gaps.","retracted_at":null,"retraction_reason":null,"challenged_by":[],"effective_weight":0.1,"quote_gated":false}],"sources":[{"id":"s1","type":"live_surface","url":"https://miscsubjects.com/a/auditable-reasoning-hardened","title":"The derivation-agreement gate — divergence as a recorded refusal","summary":"Independent model seats under a pinned rule set; the gate refuses to authorise when their clause-by-clause derivations diverge, even on a unanimous verdict. Includes the false-convergence defect and its fix.","claim_ids":["c3","c5"],"hash":"7bd828bec1f2b7bafcff42ce7235e25e14f9f37611a6f4ac7145246a666bf1c7"},{"id":"s2","type":"live_surface","url":"https://miscsubjects.com/receipt/inv_o6s0exhodd","title":"A unanimous verdict, refused on divergent derivation","summary":"Three seats returned the same conclusion citing the same clauses; two derived it differently, so the gate escalated instead of concluding.","claim_ids":["c4"],"hash":"eff0aae5fac14dfc4a88b4e1fec3fa1c9d0302eb7e43a003e84fa7a9abd5ea42"},{"id":"s3","type":"live_surface","url":"https://miscsubjects.com/receipt/inv_wl0rnh136b","title":"The genuine APPROVE — unanimous verdict, identical derivation","summary":"The one clean authorisation on record: every seat fired the same clauses in the same trigger states on the same evidence.","claim_ids":["c5"],"hash":"178bbf557d7a0fe7b4d34cf5de6e93515fa910084e9bbc4e385e4b97e160ee4d"},{"id":"s4","type":"live_surface","url":"https://miscsubjects.com/a/auditable-reasoning-audited","title":"The 72-call variance study: what the governing text measurably changes","summary":"Three prompt arms x three models x eight runs. Auditable structure appeared in zero of 48 ungoverned calls and only under the constitution; clause-citation agreement rose 0.74 to 0.95; a sealed decision costs about half a cent.","claim_ids":["c6","c9"],"hash":"41e4f7d969c7bb3ef8920056983f07846be7680feeb4c961b5bb407c0eb77ab9"},{"id":"s5","type":"live_surface","url":"https://miscsubjects.com/a/adjudication-calibration-study","title":"The calibration study: 30 oracle-labelled cases through the production gate","summary":"Three seats across two model families on 30 sealed panels: glm-5.2 30/30, kimi-k2.7 29/30, zero wrongful authorisations; the weak seat's transport failures blocked every NEGATE seal. Synthetic determinate fixtures only.","claim_ids":["c7"],"hash":"2535b735c333132f14593bb342bc41fd241bf5e544e3123752e82e766f2cc8bc"},{"id":"s6","type":"live_surface","url":"https://miscsubjects.com/a/attested-finding-conformance-map","title":"The conformance map — each attested-finding field against the standard that demands it","summary":"Field-by-field mapping of the sealed record to external standards, including the ISA 705 row: the mandatory absence declaration mirrors the inability-to-obtain-sufficient-appropriate-evidence basis for a modified opinion.","claim_ids":["c8"],"hash":"d29c42cb6b21468b14af6b3d859f8ed80858143c913e98292ad8625e50477580"},{"id":"s7","type":"live_surface","url":"https://miscsubjects.com/receipt/inv_7rqy8ywuls","title":"Abstention as a sealed outcome — the clean NO_ACTION","summary":"A record was deliberately withheld and the panel declined to conclude, with the absence named in the sealed record — the modified-opinion analogue, executed per decision.","claim_ids":["c8"],"hash":"8faa9c54a1871f40d450a0c5012701f8e568e5c2d5ee3d8599ec1ade33a72a8e"},{"id":"s8","type":"live_surface","url":"https://miscsubjects.com/receipt/inv_qh3ge2x74b","title":"The instrument critiquing its own input: eight defects found","summary":"A governed seat asked to review the case file found eight defects, the lead one a necessity-stated-as-sufficiency error in the rule set that had caused every prior derivation divergence.","claim_ids":["c10"],"hash":"9096026e274dac22e4988ad3ea3f8488079879d0f9c69cb15aa5e7d2c45ef70f"},{"id":"em_es_9172b8974d5940289d28","type":"email","url":"https://miscsubjects.com/letter-forhumanity-2026-07-30","title":"Letter to Ryan Carrier — 2026-07-30","claim_ids":[],"hash":"6c56037414678c78efe3dd218a2f218a8464ce767a12d9345898977f7c3f399e"}],"anecdotal_sources":[],"scientific_sources":[],"user_reports":[],"related_articles":[],"question_graph":{"slug":"big-four-isae-3000-ai-assurance","questions":[],"evidence":[],"edges":[],"counts":{"questions":0,"evidence":0,"edges":0}},"honesty":{"active_claims":10,"retracted_claims":0,"cut_claims":0,"challenges":0,"scrub_events":0,"note":"Retracted/cut claims stay on ledger but are excluded from ask unless ?include_inactive=1"},"counts":{"claims":10,"claims_total":10,"sources":9,"anecdotal":0,"scientific":0,"user_reports":0,"questions":0,"evidence_ingests":0}}