Retail credit. Cannot stop in time.
Detection works. Authority does not. A drift signal is generated in about twelve minutes, but reaching a person who can halt the model takes between four and ninety-six hours, and the required quorum takes at least seven days, against an assumed window of about six hours. The chain cannot complete in time, so the decision this finding supports is whether the affected pathway can continue operating under its present authority arrangements.
This is a constructed example, written to show the shape and structure of a finding from a full AGDA™ Assessment. It uses no client data and describes no real organisation. It has not been run as an assessment, is not issued and is not signed. The identifiers, timings and evidence descriptions are illustrative. Nothing on this page is evidence about anyone.
A full AGDA™ Assessment issues a verdict with its evidence basis. Signed SEDI result records are not a standard deliverable and may be supplied only under an approved output-access arrangement. This page carries neither a verdict nor a signed record. How verification works.
The assessed system. The intervention question.
A retail credit decisioning model approving up to 18,000 unsecured applications per day. Identified as material under the operator's internal model risk taxonomy.
- System ID
- CRED-MOD-04Retail Credit Decisioning
- Materiality
- Tier 1internal taxonomy
- Decision authority
- Approve / decline / referno human override on auto-decline
- Volume
- ~18,000 / dayUK personal lending
- Trigger scenario
- Macro shock + model driftsimultaneous
- Intervention window
- ~6 hoursillustrative scenario assumption; operational basis not substantiated
Intervention Readiness evidence.
Six controls described in the example. How many controls and how many timing gates appear depends on the system being assessed, so those counts differ from one engagement to the next. Classification reflects what the control can do under pressure, not what the policy promises. This replacement specimen assigns no new numerical scores, evidence grades or technical failure identifiers.
| Code | Control | Assessment | Classification |
|---|---|---|---|
| C-01 | Real-time decision logging | Production-grade. Timing telemetry from a 2024 outage post-mortem. Detection capability strong; surface latency under 90s. | GREEN |
| C-02 | Drift monitoring (PSI / KS) | Operational in production. Threshold tuning not re-validated since model retrain in 2025-Q3. Confidence constrained under evidence review. | AMBER |
| C-03 | Escalation to MRC | Documented in policy. One tabletop in 2024-Q4. Has not run live. Authority pathway terminates at a forum that meets monthly. | RED |
| C-04 | Halt authority | Three named approvers. None authorised to halt unilaterally. Quorum required. No on-call rota. Weekend gap. | RED |
| C-05 | Manual override on auto-decline | Designed-out. No human-in-the-loop on the high-volume decline path. Reversibility limited to next-day reprocessing. | RED |
| C-06 | Audit trail | Immutable, hashed, retained 7 years. Decision rationale captured per inference. Auditable to regulator standard. | AMBER |
The chain breaks at authority.
Detection is present in the scenario. The break is between detection and authority: reaching an authority holder can take longer than the window, and the quorum that authority requires takes at least seven days.
- Finding
- Structural constraint
- Route to an authorised decision
- Cannot complete in window
- Timing
- Authority lag above window
- Classification
- RED · constrained
Authority lag. The signal reaches the Model Risk Committee. The Committee meets monthly. The window assumed for the trigger scenario is approximately six hours. There is no out-of-cycle convening authority. There is no on-call halt authority below MRC level. The pathway from detection to halt cannot complete inside the window. Faster detection cannot by itself resolve that constraint.
Stage by stage. Against the clock.
These intervals are separate illustrative facts. They are not added as if they were all measured, sequential durations; their start and end points and any overlap have not been demonstrated. The quorum delay alone is sufficient to support the timing conclusion.
- Detect ~12 min to detect drift above threshold. A further ~38 min for the signal to reach a first responder is recorded separately. PRESENT
- Escalate 4 to 96 hours to reach an authority holder. Availability and routing can consume or exceed the window. CAN EXCEED WINDOW
- Decide ≥ 7 days to obtain the required quorum. No out-of-cycle route. This alone exceeds the assumed window. EXCEEDS WINDOW
- Intervene ~6 min to propagate a halt if instructed. No in-window reversal on the auto-decline path. NO TIMELY AUTHORITY
Gate register.
Every timing gate the chain must clear, with the illustrative value and its position against the assumed window. Values are described in the source example, not measured in an engagement.
| Gate | Description | Illustrative value | Verdict |
|---|---|---|---|
| G-01 | Drift signal generation latency | ~12 min | PASS |
| G-02 | Signal surfaces to first responder | ~38 min | MARGIN |
| G-03 | First responder reaches authority holder | variable · 4 to 96h | FAIL |
| G-04 | Authority holder reaches quorum | ≥ 7 days | FAIL |
| G-05 | Quorum decision recorded | monthly cadence | FAIL |
| G-06 | Halt instruction propagated to system | ~6 min (if instructed) | PASS |
The decision the finding supports.
The system is well-instrumented at the technical layer. The authority structure surrounding it cannot exercise control inside the assumed window. This is an Intervention Readiness constraint, not a model defect.
Can the affected pathway continue operating under its present authority arrangements?
A proposed response is to establish an authorised route capable of acting within the required window, including when the normal decision-makers are unavailable, and to exercise that route before relying on it. Possible remediation priorities:
- Define who may authorise an intervention and the circumstances in which that authority can be exercised.
- Establish an available decision route, including out-of-hours cover and any required delegation.
- Confirm how a halt, redirection or containment action takes effect and what happens to decisions already made.
- Exercise the complete response, record timing and evidence, then reassess the identified constraint.
These are proposed priorities for the scenario. They do not claim that remediation has been implemented or that it will produce a favourable reassessment.
Evidence register.
What each described record supports, and what remains open. These are descriptions within a fictional example, not records inspected in a client engagement.
| ID | Record described | Type | What it supports and what remains open |
|---|---|---|---|
| E-12 | "On-call halt authority exists." Stated in interview, no document. | Verbal | A claim requiring corroboration. It does not establish available authority. |
| E-08 | MRC charter naming halt authority. | Document | Documented allocation of authority. It does not establish that the required quorum can be reached in time. |
| E-04 | Tabletop exercise minutes, 2024-Q4. | Exercise | Evidence of the described exercise only. Not a live event. |
| E-02 | Production drift monitoring runtime logs (12 months). | Operational | A source for detection timing, subject to coverage, provenance and scenario relevance. |
| E-01 | 2024 outage post-mortem with timing telemetry. | Incident | A source for performance under those conditions. Transfer to the present scenario needs justification. |
| E-06 | Hashed audit log sample, regulator-format export. | Record | Evidence of recorded activity. It does not establish regulatory acceptance or the integrity of every operational record. |
Exposure and consequence.
Exposure is not calculated in this example. The stated volume of approximately 18,000 applications per day is throughput, not a count of harmed people or wrong decisions. If applications arrived uniformly, 18,000 per day would correspond to 4,500 over six hours; uniform arrival has not been established, and throughput would still not establish the number of incorrect decisions, affected customers or financial losses.
The illustrative conclusion.
The state a full AGDA™ Assessment would report for this scenario. Illustrative, not issued, not signed.
Detect, escalate, decide, intervene does not complete inside the assumed window.
The required route to an authorised intervention cannot complete within the assumed six-hour window. Obtaining the required quorum takes at least seven days. Faster detection cannot by itself resolve that constraint.
One pathway and one scenario. No conclusion about an institution's overall governance, other systems or legal conformity. The six-hour window is a scenario assumption; no operational harm threshold, regulatory breach, financial loss or empirical validation of AGDA™ is established.
Assessment authority and limitations.
In an actual engagement, the assessment conclusion is Intervene Limited's. The client may correct facts, challenge interpretation and provide further evidence. The judgement remains Intervene's.
Four things are distinct: this illustrative sample; a formally issued assessment; the authorised human sign-off that issues it; and the cryptographic attestation over specified records, where contracted. This page is only the first.
Run this against your own system.
This page shows the shape of a finding. A full AGDA™ Assessment applies the current methodology to one of your named systems, a defined pathway and a specified scenario. The conclusion is Intervene's. Signed SEDI result records are not a standard deliverable.