# Decision Evidence Applicability Specification

**Acronym:** DEAS  
**Subtitle:** A cross-regime assurance specification for evaluating the applicability, sufficiency, and non-equivalence of evidence generated by AI-assisted decisions and agentic workflows  
**Status:** Working specification  
**Version:** 0.2.0  
**Date:** 2026-07-17  
**Author:** Mark Julius Banasihan  
**ORCID:** 0009-0001-8121-2878

## 1. Bounded thesis

A recurring set of decision-evidence objects may be relevant under multiple regulatory, standards, contractual, and institutional governance regimes.

DEAS evaluates:

1. whether a defined evidence artifact is applicable to a specified governance requirement;
2. what bounded assurance claim that artifact may support;
3. what additional local evidence is required;
4. whether the artifact is insufficient under the governing authority, actor, scope, threshold, timing, or procedural conditions;
5. where apparently similar requirements are non-equivalent.

DEAS does not make governance, controls, findings, evidence, or legal conclusions portable across regimes.

## 2. Problem

Crosswalks commonly compare terms, principles, controls, or framework categories. Those mappings can conceal differences in:

- legal or normative force;
- regulated actor;
- governed object;
- jurisdiction and territorial scope;
- decision stage;
- evidence burden;
- assurance method;
- procedural posture;
- enforcement consequence;
- remedy.

The same artifact may be relevant in several regimes while remaining sufficient in none, sufficient in one, or acceptable only when combined with regime-specific evidence.

The missing layer is a machine-readable determination of what a specific evidence artifact can support under a specific requirement.

## 3. Unit of analysis

The unit of analysis is one relationship between:

- one identified decision-evidence artifact or artifact set; and
- one identified external governance requirement.

A DEAS determination is invalid when either side is left as an unbounded framework category.

## 4. Scope boundary

DEAS does not:

- define an agent runtime governor;
- intercept, permit, deny, sandbox, or terminate agent actions;
- compile policy into harness or runtime configuration;
- provide a universal control library or policy pack;
- create or verify cryptographic receipts;
- define signed-receipt canonicalization, signatures, or chain rules;
- establish cross-implementation receipt conformance;
- certify legal compliance or standards conformity;
- declare evidence legally admissible or sufficient;
- assume that evidence accepted in one regime carries the same force in another.

DEAS begins with an identified evidence artifact and an identified external requirement.

The traceability path is:

**external requirement → required assurance proposition → evidence artifact → applicability test → local evidence condition → sufficiency boundary → non-equivalence finding**

Runtime controls and signed receipts are evidence-producing or evidence-integrity mechanisms. They are inputs to DEAS rather than functions that DEAS performs.

## 5. Relationship to the portfolio

- **Governed Decision Intelligence (GDI)** structures the decision question, evidence, alternatives, uncertainty, authority, outcome, and obligations in a Governed Decision Record.
- **Human Influence Telemetry (HIT)** evaluates whether documented human access, judgment, authority, correction, repair, and reform retained practical force.
- **DEAS** evaluates what a defined GDI, HIT, runtime-control, monitoring, or receipt artifact may support under a specified governance requirement.

The artifacts remain separable. A GDR can exist without HIT. HIT can assess records other than GDRs. DEAS can evaluate evidence artifacts produced by either system or by an external system.

## 6. Boundary against adjacent systems

### 6.1 Microsoft Agent Governance Toolkit

Microsoft AGT operates at the runtime action-governance layer. It evaluates configured policy, identity, capability, approval, sandbox, and execution conditions and records allow, deny, approval, and audit outcomes.

DEAS does not perform those functions. An AGT policy or enforcement event may be evaluated as evidence under DEAS.

### 6.2 ScopeBlind / Acta signed receipts

ScopeBlind test vectors and Acta receipt implementations evaluate signed-receipt schema, canonicalization, signature validity, attribution, ordering, and chain linkage across implementations.

DEAS does not provide receipt interoperability or cryptographic conformance. A verified receipt may strengthen provenance or integrity evidence while leaving payload truth, governance quality, applicability, and sufficiency unresolved.

### 6.3 Credo AI

Credo AI provides policy packs, policy-to-code translation, risk and control mappings, governance workflows, compliance mapping, evidence collection, monitoring, and runtime agent-governance capabilities.

DEAS does not replace those platform functions or provide a universal harmonized-control model. It evaluates the bounded assurance use of a specific evidence artifact under a specific requirement and must preserve local conditions and non-equivalence.

## 7. Core terms

### Evidence artifact

A defined record, event, log, assessment, receipt, decision record, approval record, review note, model or system artifact, monitoring result, appeal record, repair record, or reform record with identifiable provenance.

### External governance requirement

A requirement created by an identified law, regulation, standard, contract, policy, regulatory instrument, governance framework, or assurance procedure.

### Assurance proposition

The bounded statement the evidence is offered to support. Examples include that a named authority was assigned, a review occurred, an intervention mechanism existed, a control executed, an appeal was available, or a record retained integrity properties.

### Applicability

The relationship between an evidence artifact and the actor, object, stage, scope, and proposition governed by the external requirement.

Applicability means relevance. It does not mean sufficiency.

### Sufficiency boundary

The point beyond which the artifact cannot support the assurance proposition without additional evidence, qualified interpretation, procedural testing, or legal or standards review.

### Local evidence condition

An additional requirement imposed by the specific regime, jurisdiction, actor role, sector, decision stage, or assurance procedure.

### Non-equivalence

A material difference that prevents two requirements, controls, findings, or evidence requests from being treated as interchangeable.

## 8. Determination states

Each mapping must return one primary determination:

- `applicable_but_unreviewed`: the artifact is relevant, but assurance sufficiency has not received the required review;
- `applicable_with_local_evidence`: the artifact is relevant only when combined with identified local evidence;
- `applicable_and_bounded`: the artifact supports the stated assurance proposition within declared conditions and limitations;
- `insufficient`: the artifact is relevant but cannot support the proposition under the stated threshold;
- `non_equivalent`: a material difference prevents reuse of the source relationship as an equivalent target relationship;
- `not_applicable`: the artifact does not address the governed actor, object, stage, or proposition;
- `indeterminate`: the available authority or evidence cannot resolve the relationship.

No determination state means legal compliance, certification, conformity, admissibility, or universal reuse.

## 9. Mapping record

Each DEAS mapping must record:

- mapping identifier and specification version;
- evidence artifact identifier, type, version, producer, provenance, and integrity status;
- source authority and authoritative citation;
- source type and legal or normative force;
- requirement identifier and text or bounded paraphrase;
- regulated actor;
- governed object;
- decision or lifecycle stage;
- jurisdiction or institutional scope;
- assurance proposition;
- applicability rationale;
- required evidence;
- evidence supplied;
- assurance test;
- determination state;
- local evidence condition;
- sufficiency boundary;
- point of non-equivalence;
- mapping confidence;
- reviewer competence and conflict disclosure;
- review date and update condition.

## 10. Evidence classes

DEAS must distinguish at least:

- authoritative requirement evidence;
- implementation evidence;
- runtime control or enforcement evidence;
- decision-record evidence;
- human-influence assessment evidence;
- monitoring and incident evidence;
- cryptographic integrity evidence;
- appeal, repair, and reform evidence;
- interpretive mapping;
- unresolved hypothesis.

Evidence classes must not be collapsed merely because they share a filename, control label, or framework term.

## 11. Initial scope

Version 0.2 will test one agentic workflow in which an AI system retrieves evidence, recommends a decision, prepares an action, and requires human authorization before execution.

The initial comparison set is:

- NIST AI Risk Management Framework;
- ISO/IEC 42001 and selected supporting standards;
- European Union Artificial Intelligence Act;
- selected Chinese agent-governance requirements as a comparative annex;
- one institutional policy requirement;
- one runtime-control event;
- one signed-receipt integrity result;
- one Governed Decision Record;
- one Human Influence Telemetry assessment record.

## 12. Acceptance conditions

DEAS will advance beyond working-specification status only when:

1. every mapping links to an authoritative source;
2. each mapping identifies one bounded assurance proposition;
3. each regime contains at least one explicit point of non-equivalence or an evidenced reason why none applies;
4. one core decision record validates under at least two jurisdictional or institutional overlays without changing historical facts;
5. each overlay may require additional local evidence;
6. missing authority, intervention, logging, provenance, or integrity evidence produces a defined determination;
7. external requirements map to identifiable evidence artifacts without claiming universal control equivalence;
8. outputs state applicability, local evidence conditions, sufficiency boundaries, and non-equivalence;
9. outputs never declare legal compliance, certification, conformity, or admissibility;
10. adjacent-system claims are reviewed against Microsoft AGT, ScopeBlind/Acta, and Credo AI;
11. the draft receives legal or standards review and technical assurance review.

## 13. Migration from DEPS 0.1.1

The prior working title **Decision Evidence Portability Specification (DEPS)** is deprecated.

The rename to **Decision Evidence Applicability Specification (DEAS)** corrects an overbroad implication. The project does not claim that evidence retains the same legal meaning, assurance weight, sufficiency, or consequence when moved across regimes.

The ontology remains under development. Existing notes may be migrated when they are rewritten as bounded evidence-to-requirement determinations under this specification.

## 14. Current status

This document establishes the revised name, bounded thesis, adjacent-system boundary, determination states, and acceptance conditions.

The machine-readable schema, overlays, authoritative mappings, worked workflow, cases, reviewer protocol, and validation suite remain in development.

## 15. Citation

Banasihan, Mark Julius. “Decision Evidence Applicability Specification.” Working specification, version 0.2.0, July 17, 2026.
