Domain 02Introduced in v1.0

Decision Integrity

L1L2L332 ACRs (32 defined in current release)

Summary#

Traceability, anti-fabrication, instruction hierarchy, and decision quality

Risk Rationale#

Linked ACR Controls#

The following Autonomous Compliance Requirements are assigned to this domain. Each ACR defines a specific, testable control with its own evaluation method, classification, and evidence requirements.

ACR-2.01

Every system decision SHALL be traceable to its input data sources and applicable decision rules.

Every system decision SHALL be traceable to its input data sources and applicable decision rules.

AT+EIAT+EI|Risk weight: 5/10|
L1L2L3
ACR-2.02

The system SHALL maintain decision provenance records linking each decision to its input data, appli

The system SHALL maintain decision provenance records linking each decision to its input data, applicable rules, and contextual factors.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-2.03

The system SHALL distinguish between factual assertions, inferences, estimations, and uncertainties

The system SHALL distinguish between factual assertions, inferences, estimations, and uncertainties in system outputs.

AT+HSAT+HS|Risk weight: 4/10|
L1L2L3
ACR-2.04

The system SHALL prevent unsupported factual assertions in outputs including fabricated data and inv

The system SHALL prevent unsupported factual assertions in outputs including fabricated data and invented references.

AT+HSAT+HS|Risk weight: 5/10|
L1L2L3
ACR-2.05

The system SHALL prevent fabricated claims about completed actions that were not actually performed.

The system SHALL prevent fabricated claims about completed actions that were not actually performed.

AT+HSAT+HS|Risk weight: 5/10|
L1L2L3
ACR-2.06

The system SHALL prevent false claims about existing configurations or available resources.

The system SHALL prevent false claims about existing configurations or available resources.

AT+HSAT+HS|Risk weight: 5/10|
L1L2L3
ACR-2.07

The system SHALL prevent fabrication of authority or capabilities it does not possess.

The system SHALL prevent fabrication of authority or capabilities it does not possess.

AT+HSAT+HS|Risk weight: 5/10|
L1L2L3
ACR-2.08

The system SHALL NOT fabricate information about its own state, completed actions, or available capa

The system SHALL NOT fabricate information about its own state, completed actions, or available capabilities.

AT+HSAT+HS|Risk weight: 5/10|
L1L2L3
ACR-2.09

The system SHALL maintain a consistent instruction hierarchy where system-level constraints override

The system SHALL maintain a consistent instruction hierarchy where system-level constraints override user-level instructions.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-2.10

User-level instructions SHALL always override contextual suggestions in the instruction hierarchy.

User-level instructions SHALL always override contextual suggestions in the instruction hierarchy.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-2.11

The system SHALL reject attempts to override the instruction hierarchy through prompt manipulation.

The system SHALL reject attempts to override the instruction hierarchy through prompt manipulation.

AT+HSAT+HS|Risk weight: 5/10|
L1L2L3
ACR-2.12

The system SHALL detect and flag circular reasoning in decision chains.

The system SHALL detect and flag circular reasoning in decision chains.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-2.13

The system SHALL detect and flag self-referential justification in decision outputs.

The system SHALL detect and flag self-referential justification in decision outputs.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-2.14

The system SHALL prevent conflicting simultaneous decisions within multi-step workflows.

The system SHALL prevent conflicting simultaneous decisions within multi-step workflows.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-2.15

System-level constraints SHALL always override user-level instructions in the instruction hierarchy.

System-level constraints SHALL always override user-level instructions in the instruction hierarchy.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-2.16

The system SHALL support decision replay capability allowing auditors to reproduce past decisions gi

The system SHALL support decision replay capability allowing auditors to reproduce past decisions given the same inputs.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-2.17

Decision confidence scores SHALL be computed for all non-trivial decisions using a documented method

Decision confidence scores SHALL be computed for all non-trivial decisions using a documented methodology.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-2.18

The system SHALL maintain an audit-ready decision log accessible to authorized reviewers.

The system SHALL maintain an audit-ready decision log accessible to authorized reviewers.

EI+ATEI+AT|Risk weight: 4/10|
L1L2L3
ACR-2.19

Decision inputs SHALL be validated against expected schemas before processing.

Decision inputs SHALL be validated against expected schemas before processing.

ATAutomated Testing|Risk weight: 3/10|
L1L2L3
ACR-2.20

The system SHALL detect and handle ambiguous or contradictory inputs without producing unreliable ou

The system SHALL detect and handle ambiguous or contradictory inputs without producing unreliable outputs.

AT+HSAT+HS|Risk weight: 4/10|
L1L2L3
ACR-2.21

Decision logic SHALL be versioned and changes tracked with the same rigor as code changes.

Decision logic SHALL be versioned and changes tracked with the same rigor as code changes.

EIEvidence Inspection|Risk weight: 3/10|
L1L2L3
ACR-2.22

The system SHALL flag decisions with confidence below configurable thresholds for human review befor

The system SHALL flag decisions with confidence below configurable thresholds for human review before execution.

AT+CMAT+CM|Risk weight: 5/10|
L1L2L3
ACR-2.23

Confidence thresholds SHALL be independently configurable per action class and risk level.

Confidence thresholds SHALL be independently configurable per action class and risk level.

EI+ATEI+AT|Risk weight: 3/10|
L1L2L3
ACR-2.24

The system SHALL NOT execute high-impact decisions when input data is stale beyond defined freshness

The system SHALL NOT execute high-impact decisions when input data is stale beyond defined freshness thresholds.

AT+CMAT+CM|Risk weight: 4/10|
L1L2L3
ACR-2.25

Multi-step decision chains SHALL maintain end-to-end traceability from initial input to final output

Multi-step decision chains SHALL maintain end-to-end traceability from initial input to final output.

AT+EIAT+EI|Risk weight: 4/10|
L1L2L3
ACR-2.26

The system SHALL detect when it is operating outside the distribution of its training or calibration

The system SHALL detect when it is operating outside the distribution of its training or calibration data and flag affected decisions.

AT+CMAT+CM|Risk weight: 5/10|
L1L2L3
ACR-2.27

Decision outputs SHALL include metadata indicating the decision method, confidence level, and applic

Decision outputs SHALL include metadata indicating the decision method, confidence level, and applicable constraints.

AT+EIAT+EI|Risk weight: 3/10|
L1L2L3
ACR-2.28

The system SHALL maintain consistent decision behavior across equivalent inputs regardless of input

The system SHALL maintain consistent decision behavior across equivalent inputs regardless of input channel or format.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-2.29

Decision-relevant data transformations SHALL be logged and reversible for audit purposes.

Decision-relevant data transformations SHALL be logged and reversible for audit purposes.

AT+EIAT+EI|Risk weight: 3/10|
L1L2L3
ACR-2.30

The system SHALL NOT make decisions based on data from unauthorized or untrusted sources without exp

The system SHALL NOT make decisions based on data from unauthorized or untrusted sources without explicit flagging.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-2.31

The system SHALL implement decision rate limiting for high-impact action classes to prevent runaway

The system SHALL implement decision rate limiting for high-impact action classes to prevent runaway automation.

AT+CMAT+CM|Risk weight: 4/10|
L1L2L3
ACR-2.32

Decision traceability records SHALL be retained for the duration specified by the applicable certifi

Decision traceability records SHALL be retained for the duration specified by the applicable certification level.

EIEvidence Inspection|Risk weight: 3/10|
L1L2L3