Methodology and trust

What RIVAL measures, and what it does not promise

This page explains how a reviewed evidence pack comes about and where its limits are. It is written for the operator who sells the service and for the client, insurer, auditor, or customer who reads the pack.

Methodology and trust

1. What RIVAL measures

RIVAL records actions and current state inside one client organization: which AI tools are known and how they are classified, which policies apply and which versions people acknowledged, which claims in a review have supporting records, which gaps have owners, and what changed since the previous approved review. It measures the presence, date, and scope of records. It does not measure legal compliance, and it does not score people.

2. How evidence supports claims

A review starts from a request and uses the claim structure of the AI Governance Core release in use. Each claim carries one state: current, stale, missing, unsupported, or not applicable. A reviewer links each claim by hand to one or more records: platform records, uploaded documents, CSV imports, or supported audit-log exports. Unsupported and not-applicable claims carry a recorded reason. A claim that is stale, missing, or unsupported is a gap with one owner and one next action.

3. Human approval

A person approves every review before a pack is generated. Approval freezes the review, its claims, states, links, scope, and period. RIVAL proposes nothing as approved on its own.

4. Versioning and review lineage

An approved review never changes. A correction creates a new review version that points to the previous one, and each pack names the review version, the date, and the content releases it used. The pack for a later review lists what changed since the previous approved review.

5. Evidence integrity boundaries

The evidence ledger is append-only in normal operation: the application blocks updates and deletes, and corrections create new records that reference the corrected one. It is not cryptographically sealed, not independently timestamped, and not independently verified. A pack proves what was recorded, when, and by whom, within those boundaries.

6. Hosting and data-processing boundaries

RIVAL is built for EU data rules. What the application enforces today: each client organization is an isolated data boundary inside its operator, and every tenant-scoped query fails without an authenticated context. Transactional messages carry no tracking pixels and no remote assets. What is not settled yet: the production hosting provider, the storage region for evidence files, the subprocessor list, and the audited support-access controls for platform staff. We publish the hosting, storage, subprocessor, and evidence-processing terms before the first production client. Until then we make no claim about them.

7. No automated legal conclusion

RIVAL draws no legal conclusion. It records that a policy exists, that a person acknowledged it, or that a claim has a supporting record. Whether an organization meets an obligation remains a judgment for the organization and its advisers.

8. No automated employee assessment

RIVAL does not assess, rank, or profile individual employees automatically. Drill answers adjust what a person practices next and are stored with the exact content version the person saw. Packs report on organizational claims and controls, not on individual performance.

9. No certification or acceptance guarantee

A reviewed evidence pack is not a certificate, an audit opinion, or a guarantee of compliance with any law. No insurer, customer, auditor, procurement team, or regulator is obliged to accept it. It substantiates the answers an organization gives, so those answers rest on reviewed records rather than on memory.

This methodology has not been reviewed by an external party. We will name a reviewer here only when one has been retained.