iSOAF Architectural Doctrine Reference

Reliance Assessment Model

An Architectural Specification for Evidence-Based Reliance Assessment

A first-class architectural reference defining how iSOAF separates evidence, assessment, conclusions, reliance, and human decisions while preserving the framework boundary.

Version 1.0Architectural ReferenceEvidence-boundedHuman-governed

Purpose

The iSOAF Reliance Assessment Model (RAM) is the architectural specification that defines how iSOAF evaluates evidentiary support within a defined assessment scope. It makes explicit the conceptual progression from operational evidence to validated reliance while preserving accountability for operational decisions with the designated human authority.

iSOAF evaluates whether the available evidence provides a sufficient basis for reliance within a defined assessment scope. It does not determine what decision should be made, only whether the evidentiary basis for that decision can reasonably be relied upon. Decisions remain the responsibility of the designated human authority.

Why this Model Exists

As iSOAF matured through operational validation, it became important to distinguish between evidence, the conclusions derived from that evidence, the validation of reliance on those conclusions, and the decisions ultimately made by accountable authorities.

The Reliance Assessment Model formalizes these distinctions as part of the framework's architectural doctrine. It clarifies how iSOAF reasons from evidence to reliance without becoming a decision-making system, remediation engine, or risk-acceptance authority.

Five-Layer Architecture

The model separates the assurance progression into five conceptual layers. The first four layers are within the assurance model. The fifth layer, decision, remains outside the framework boundary.

Layer 1: EvidenceOperational signals and provenance records whose integrity, origin, completeness, and currency are evaluated.
Layer 2: AssessmentThe continuous, objective activity performed on evidence to determine strength, relevance, consistency, and alignment with defined policy or governance expectations.
Layer 3: ConclusionAssertions derived from assessed evidence, such as whether a control, recovery capability, policy condition, or operational claim remains supportable.
Layer 4: RelianceValidation that the assessed evidence provides a sufficient basis for relying upon the conclusion within the defined assessment scope.
Epistemic BoundaryEvidence-based validation ends here. Evidence may support reliance within scope, but it does not determine broader organizational, legal, ethical, strategic, or risk-appetite judgments.
Operational BoundaryFramework authority ends here. iSOAF does not determine what decision should be made and does not extend into autonomous remediation, closure, policy enforcement, or risk acceptance.
Layer 5: DecisionChoices, policy enforcement, operational closure, or risk acceptance made under accountable human authority and outside the framework decision boundary.

Framework Boundaries

Evidentiary boundary

The evidentiary boundary defines the limit of what evidence can support. iSOAF may validate whether evidence is sufficient for reliance within scope, but evidence alone cannot determine every strategic, legal, ethical, operational, or policy consequence.

Operational boundary

The operational boundary defines the limit of what the framework is authorized to do. iSOAF evaluates evidence, conclusions, and reliance. It does not perform autonomous remediation, operational closure, policy enforcement, or risk acceptance.

Human governance

Human governance remains explicit. The framework can surface evidence, identify unsupported conclusions, and block unsupported reliance, but the decision to act, defer, accept, reject, escalate, or close remains with the designated human authority.

Accountability Preservation

The framework is designed to preserve accountability with the designated human authority by limiting its scope to evidentiary reliance assessment rather than operational decision-making.

Boundary Integrity

The doctrine establishes architectural and evidentiary boundaries intended to prevent expansion from evidentiary validation into autonomous operational decision-making.

Domain Adaptability

The assurance principles remain consistent across domains, while evidence models, thresholds, and governance requirements are adapted to context.

Cross-Domain Applicability

The assurance progression remains constant across domains while evidence models, assessment criteria, thresholds, and governance requirements are adapted to the operational context.

Evidence → Assessment → Conclusion → Reliance → Human Decision
DomainEvidenceAssessmentConclusionRelianceHuman Decision
CybersecurityFirewall logs, configuration states, packet traces.Analysis against baseline traffic rules and enforcement expectations.Unauthorized inbound traffic is being blocked according to the defined policy.Evidence is sufficient or insufficient to rely on the control status within scope.Maintain policy, adjust risk treatment, or require corrective action.
Backup and RecoveryBackup logs, restore-test records, recovery timing evidence.Freshness, completeness, recoverability, and RTO/RPO alignment are evaluated.Recovery capability remains supportable under current conditions.The conclusion can or cannot be relied upon for operational closure.Close incident, keep incident open, escalate, or accept residual risk.
Executive GovernanceAccess logs, separation-of-duty records, policy mappings, approval records.Evidence lineage and policy alignment are evaluated against governance requirements.Privileged access is restricted according to policy.Evidence is sufficient or insufficient to support executive sign-off.Certify, defer, escalate, or issue a corrective action plan.
Manufacturing / OperationsSensor readings, maintenance logs, exception records, production history.Operational signals are evaluated against process thresholds and continuity requirements.The process condition remains within the defined operating envelope.Reliance is supported or withheld for operational continuation.Continue, pause, inspect, escalate, or approve corrective action.
Evidentiary AssuranceSource records, timestamps, chain-of-custody metadata, validation logs.Provenance, integrity, completeness, and independence are evaluated.The evidentiary record remains traceable and supportable.Reliance may be supported or withheld within the defined evidentiary scope.Legal, administrative, or governance authority determines the action.

Relationship to the Continuous Operational Assurance Methodology

Methodology

The Continuous Operational Assurance Methodology establishes the assurance principles and practices for continuously validating operational evidence.

RAM

The Reliance Assessment Model complements the methodology by making explicit the conceptual progression through which evidence is assessed, conclusions are evaluated, and reliance is validated.

RAM does not replace the methodology. It provides the architectural reasoning model that explains how the methodology separates evidentiary support from human decision-making authority.

Relationship to the Executive White Paper

Executive White Paper

The Executive White Paper communicates the operational motivation, validation results, and governance outcomes of iSOAF.

RAM

The Reliance Assessment Model provides the architectural abstraction that explains how those outcomes are reasoned from evidence without disclosing implementation-specific mechanisms.

This distinction preserves the different purposes of the publications: the White Paper explains operational validation and outcomes, while RAM explains the conceptual assurance architecture.

Position within iSOAF

The Reliance Assessment Model defines the conceptual reasoning model used by iSOAF to evaluate evidentiary support within a defined assessment scope. It complements the Continuous Operational Assurance Methodology by making explicit the progression from evidence to reliance while preserving human authority over operational decisions.

Together, the Continuous Operational Assurance Methodology, the Executive White Paper, the Evidence Provenance model, and the Reliance Assessment Model describe complementary aspects of the framework. The methodology establishes the assurance principles, the Executive White Paper demonstrates their operational validation, the Evidence Provenance model explains evidentiary traceability, and the Reliance Assessment Model defines the architectural progression through which evidentiary support is assessed and reliance is validated.

Back to iSOAF

Document Integrity

Reliance Assessment Model v1.1

Download verified PDF

SHA-256: f486a634315d74028047443d5f5a9c0db75044b49526fd18f1790fb31378e448
File size: 103 KB