# Deviation Attribution Requires Contemporaneous Evidence

- **Artifact ID:** CHQ-SCA-2026-007
- **Canonical source ID:** CHQ-J-2026-007
- **Version:** v1.0
- **Status:** ISSUED
- **Public record:** https://record.cybersecurityhq.com/assessments/chq-sca-2026-007
- **Machine-record SHA-256:** `c53cbf8069a8983a5d3bfa40c596ea69b98ce7e374e827c4ccd7f2400a35fb49`

## Complete structured record

```json
{
  "id": "CHQ-J-2026-007",
  "title": "Deviation Attribution Requires Contemporaneous Evidence",
  "status": "ISSUED",
  "issuance_date": "2026-01-23",
  "version": "v1.0",
  "judgment_type": "ARCHITECTURAL",
  "classification_tag": "Exception & Deviation Attribution",
  "decision_surfaces_safe": [
    "Exception & Deviation Authorization Record",
    "Breach Causality Attribution (Organizational)"
  ],
  "decision_surfaces_unsafe": [
    "Sworn Technical Assertion (Personal)",
    "Individual Accountability Insulation",
    "Insurer Control Interpretation Conflict",
    "Transactional Security Representation Defense"
  ],
  "load_bearing_assumptions": [
    {
      "id": "A1",
      "label": "Deviation Inevitability",
      "type": "LOAD-BEARING",
      "text": "Control deviation exists in complex systems due to operational, technical, or organizational constraints."
    },
    {
      "id": "A2",
      "label": "Authorization Ambiguity",
      "type": "LOAD-BEARING",
      "text": "Authorization for deviation may be absent, implicit, tolerated, or undocumented at time of execution."
    },
    {
      "id": "A3",
      "label": "Evidentiary Asymmetry",
      "type": "LOAD-BEARING",
      "text": "Post-incident reconstruction materially differs from contemporaneous operational evidence."
    },
    {
      "id": "A4",
      "label": "Outcome Non-Determinism",
      "type": "CONTEXTUAL",
      "text": "Not all adverse outcomes materially depend on specific deviations."
    }
  ],
  "core_judgment": "Deviation from documented controls is an attributable cause of failure only where the deviation lacked recognized authorization at the time of decision and where contemporaneous evidence demonstrates that the adverse outcome depended on that deviation.",
  "observability_conditions": [
    {
      "number": 1,
      "title": "Decision-State Anchor",
      "text": "The evidence was created or recorded prior to the finalization of the decision that authorized, tolerated, or allowed the deviation, and before any binding determination to investigate, remediate, or disclose the deviation or its consequences.\nEvidence generated during incident response, forensic investigation, legal preparation, or post-incident review does not qualify."
    },
    {
      "number": 2,
      "title": "Mandated Operational Origin",
      "text": "The evidence originated from systems, processes, or roles performing their assigned operational function, rather than from activity undertaken to document, justify, or contextualize the deviation after its identification or escalation.\nEvidence produced for explanatory, defensive, or retrospective purposes does not qualify."
    },
    {
      "number": 3,
      "title": "Outcome-Independent Sufficiency",
      "text": "The evidence supports the dependency assessment without requiring reference to the adverse outcome for its probative value.\nIf the evidence cannot be evaluated as materially relevant absent knowledge of the outcome, it does not qualify as contemporaneous."
    }
  ],
  "boundary_of_safe_citation": "This judgment governs organizational attribution logic under architectural deviation.\n\nIt must not be cited to establish evidentiary sufficiency for:\n• Individual testimony\n• Personal liability insulation\n• Insurance coverage interpretation\n• Transactional disclosure adequacy\n\nCitation outside the defined safe decision surfaces risks misapplication of scope and inversion of evidentiary burden.",
  "retirement_triggers": [
    {
      "number": 1,
      "title": "Cryptographically Enforced Policy Execution",
      "text": "Control enforcement becomes cryptographically bound to execution such that deviation is architecturally prevented or instantaneously detected with non-repudiable attribution at runtime."
    },
    {
      "number": 2,
      "title": "Tamper-Evident Exception Lifecycle",
      "text": "Control exceptions are issued, tracked, and expired through automated systems that produce immutable, authority-bound audit records, rendering authorization presence binary and contemporaneous by design."
    },
    {
      "number": 3,
      "title": "Deterministic Decision Capture at Execution",
      "text": "Organizational decision authority for deviations is captured at execution time through mandatory, attributable decision mechanisms, eliminating tolerated or undocumented deviation states."
    },
    {
      "number": 4,
      "title": "Strict Liability Standard for Deviation",
      "text": "Regulatory, judicial, or statutory frameworks adopt a strict liability standard under which deviation constitutes liability irrespective of outcome dependency or contemporaneous evidence."
    },
    {
      "number": 5,
      "title": "Judicial Rejection of Contemporaneous Evidence Requirements",
      "text": "Courts or regulators explicitly accept post-incident reconstruction as sufficient for causality attribution, negating the evidentiary premise on which this judgment rests."
    }
  ]
}
```
