Purpose
The iSOAF Reliance Assessment Model (RAM) is the architectural specification that defines how iSOAF evaluates evidentiary support within a defined assessment scope. It makes explicit the conceptual progression from operational evidence to validated reliance while preserving accountability for operational decisions with the designated human authority.
Why this Model Exists
As iSOAF matured through operational validation, it became important to distinguish between evidence, the conclusions derived from that evidence, the validation of reliance on those conclusions, and the decisions ultimately made by accountable authorities.
The Reliance Assessment Model formalizes these distinctions as part of the framework's architectural doctrine. It clarifies how iSOAF reasons from evidence to reliance without becoming a decision-making system, remediation engine, or risk-acceptance authority.
Five-Layer Architecture
The model separates the assurance progression into five conceptual layers. The first four layers are within the assurance model. The fifth layer, decision, remains outside the framework boundary.
Framework Boundaries
Evidentiary boundary
The evidentiary boundary defines the limit of what evidence can support. iSOAF may validate whether evidence is sufficient for reliance within scope, but evidence alone cannot determine every strategic, legal, ethical, operational, or policy consequence.
Operational boundary
The operational boundary defines the limit of what the framework is authorized to do. iSOAF evaluates evidence, conclusions, and reliance. It does not perform autonomous remediation, operational closure, policy enforcement, or risk acceptance.
Human governance
Human governance remains explicit. The framework can surface evidence, identify unsupported conclusions, and block unsupported reliance, but the decision to act, defer, accept, reject, escalate, or close remains with the designated human authority.
Accountability Preservation
The framework is designed to preserve accountability with the designated human authority by limiting its scope to evidentiary reliance assessment rather than operational decision-making.
Boundary Integrity
The doctrine establishes architectural and evidentiary boundaries intended to prevent expansion from evidentiary validation into autonomous operational decision-making.
Domain Adaptability
The assurance principles remain consistent across domains, while evidence models, thresholds, and governance requirements are adapted to context.
Cross-Domain Applicability
The assurance progression remains constant across domains while evidence models, assessment criteria, thresholds, and governance requirements are adapted to the operational context.
| Domain | Evidence | Assessment | Conclusion | Reliance | Human Decision |
|---|---|---|---|---|---|
| Cybersecurity | Firewall logs, configuration states, packet traces. | Analysis against baseline traffic rules and enforcement expectations. | Unauthorized inbound traffic is being blocked according to the defined policy. | Evidence is sufficient or insufficient to rely on the control status within scope. | Maintain policy, adjust risk treatment, or require corrective action. |
| Backup and Recovery | Backup logs, restore-test records, recovery timing evidence. | Freshness, completeness, recoverability, and RTO/RPO alignment are evaluated. | Recovery capability remains supportable under current conditions. | The conclusion can or cannot be relied upon for operational closure. | Close incident, keep incident open, escalate, or accept residual risk. |
| Executive Governance | Access logs, separation-of-duty records, policy mappings, approval records. | Evidence lineage and policy alignment are evaluated against governance requirements. | Privileged access is restricted according to policy. | Evidence is sufficient or insufficient to support executive sign-off. | Certify, defer, escalate, or issue a corrective action plan. |
| Manufacturing / Operations | Sensor readings, maintenance logs, exception records, production history. | Operational signals are evaluated against process thresholds and continuity requirements. | The process condition remains within the defined operating envelope. | Reliance is supported or withheld for operational continuation. | Continue, pause, inspect, escalate, or approve corrective action. |
| Evidentiary Assurance | Source records, timestamps, chain-of-custody metadata, validation logs. | Provenance, integrity, completeness, and independence are evaluated. | The evidentiary record remains traceable and supportable. | Reliance may be supported or withheld within the defined evidentiary scope. | Legal, administrative, or governance authority determines the action. |
Relationship to the Continuous Operational Assurance Methodology
Methodology
The Continuous Operational Assurance Methodology establishes the assurance principles and practices for continuously validating operational evidence.
RAM
The Reliance Assessment Model complements the methodology by making explicit the conceptual progression through which evidence is assessed, conclusions are evaluated, and reliance is validated.
RAM does not replace the methodology. It provides the architectural reasoning model that explains how the methodology separates evidentiary support from human decision-making authority.
Relationship to the Executive White Paper
Executive White Paper
The Executive White Paper communicates the operational motivation, validation results, and governance outcomes of iSOAF.
RAM
The Reliance Assessment Model provides the architectural abstraction that explains how those outcomes are reasoned from evidence without disclosing implementation-specific mechanisms.
This distinction preserves the different purposes of the publications: the White Paper explains operational validation and outcomes, while RAM explains the conceptual assurance architecture.
Position within iSOAF
The Reliance Assessment Model defines the conceptual reasoning model used by iSOAF to evaluate evidentiary support within a defined assessment scope. It complements the Continuous Operational Assurance Methodology by making explicit the progression from evidence to reliance while preserving human authority over operational decisions.
Together, the Continuous Operational Assurance Methodology, the Executive White Paper, the Evidence Provenance model, and the Reliance Assessment Model describe complementary aspects of the framework. The methodology establishes the assurance principles, the Executive White Paper demonstrates their operational validation, the Evidence Provenance model explains evidentiary traceability, and the Reliance Assessment Model defines the architectural progression through which evidentiary support is assessed and reliance is validated.