Skip to contentThe Observability LayerSearch

Enterprise handbook · Section 27 of 30

Appendix G. Legal scope and supplier worksheets

G.1 Obligation scope worksheet

Evidence table: Field, Question to resolve, Decision evidence
FieldQuestion to resolveDecision evidence
Entity and roleWhich legal entity acts as developer, deployer, provider, controller, processor, or covered business?Named legal entity and role rationale.
GeographyWhich locations, customers, processing, and services trigger territorial scope?Jurisdiction facts and responsible legal review.
Decision and influenceDoes the agent make, substantially influence, or prepare a covered decision?Complete decision-stage map and use description.
Data and peopleWhich personal data, sensitive categories, groups, and rights are implicated?Data inventory and affected-population scope.
Instrument and statusIs the source governing text, enacted law, final regulation, guidance, official announcement, or draft?Version, exact provision, status, and retrieval date.
Obligation and clockWhat duty applies, to whom, from when, and under which incident or notice trigger?Obligation-specific calendar and legal determination.
Exception or exemptionWhich exact exemption is asserted, and does it cover this processing rather than the institution generally?Written scope rationale and review trigger.
Control and proofWhich operating mechanism discharges the duty, and how is it demonstrated?Control owner, test, records, notice or remedy evidence.
Change triggerWhich change to law, use, data, role, customer, or geography reopens the decision?Named owner and monitoring/update process.

The regulatory table in chapter 16 is a researched scope aid for the listed US and EU instruments. It is not an exhaustive jurisdictional inventory. Do not treat a voluntary framework, protocol requirement, or proposed test as a statutory duty.

G.2 Supplier evidence worksheet

Evidence table: Topic, Ask the supplier, Validate locally
TopicAsk the supplierValidate locally
Version and changeWhat is pinned, resolved, opaque, deprecated, or silently changed?Manifest joins, change triggers, and limitation record.
EvaluationWhich configuration, task population, attack budget, denominator, oracle, and exclusions support the claim?Relevant institution-specific holdouts and raw failure outcomes.
Authority and adaptersWhich tools, tokens, protocol versions, hook routes, subprocesses, and background effects are covered?Resource authorization, audience/issuer negatives, and bypass inventory.
Data handlingWhich inputs, artifacts, logs, and memory cross each boundary, with what processing and retention?Approved source/data flow, egress, deletion and restoration tests.
Monitor evidenceWhich signals are available, and are they traces, summaries, scores, or effect observations?Operating-threshold errors, unfamiliar conditions, timing, and effective intervention.
Incidents and recoveryWho notifies, contains, preserves evidence, and supports remedy?Exercise withdrawal, reconciliation, and descendant containment.
Exit and rightsCan work, evidence, permitted content, and business obligations be transferred?Fallback-specific authority and continuity drill.

G.3 Local responsibility worksheet

Assign a named local role for each mandate, resource boundary, oracle, reviewer pool, monitor, evidence store, legal determination, exception, halt, restart, supplier relationship, and retirement. Record consulted roles and escalation substitutes. The first line operates controls, the second line challenges risk, and internal audit preserves its independence.