Screen 09[PLANNED]
Verification & Hand-off
Notary AI provides the preserved verification record for the scoped decision and release process — it does not determine legal truth or override Company XYZ's or LoanCore's authoritative systems. GRC is one delivery channel, not the product's center.
Company XYZ decision accountability · LoanCore Underwriting 3.2.0Lending · Applicant A-1027— Rigid credit threshold does not consider approved compensating factors
- ACCOUNT1–3→
- VERIFY4–7→
- DEFEND8–9
DEFENDScreen 09
- Question
- Can another party inspect the record without simply trusting LoanCore or Company XYZ?
- Answer
- The package exposes its evidence inventory, provenance, scope, limitations, and integrity information. Fully independent offline cryptographic verification remains planned.
- Output
- A recipient-ready record for audit, model risk, procurement, disputes, regulators, insurers, or customers.
Recipients this record is prepared for
- Internal audit
- Model risk
- Third-party risk management (TPRM)
- Procurement / buyers
- Disputes counsel
- Regulators
- Insurers
- Customers
Delivery channels
- Push to connected GRC system[PLANNED]
- Manual package export (download)[BUILT]
- Shared inspection link[PLANNED]
Live integrations
- ServiceNow[PLANNED]
- OneTrust[PLANNED]
- AuditBoard[PLANNED]
The pushes below are simulated against these planned integrations. No real system is contacted.
Independent verification capabilities
- Inspect evidence inventory, provenance, and scope in-app[BUILT]
- Fully offline, independent cryptographic verification[PLANNED]
- Public-key signature check without platform access[PLANNED]
[PLANNED]planned delivery integration
Connections and pushes below are simulated. Flow, framework mapping, and retry state match what the real GRC Integrations service will emit.
Pushes
- not pushedlending-denialApplicant A-1027 denied at score 650maps to EU AI Act · NIST AI RMF (voluntary) · OCC 2011-12 · Customer-defined controls
- not pushedprior-auth-denialPrior-auth PA-8843 auto-denied despite high-risk notemaps to EU AI Act · NIST AI RMF (voluntary) · OCC 2011-12 · Customer-defined controls
- not pushedvr-northstar-001Bereavement refund misstatement (NorthStar bot)maps to EU AI Act · NIST AI RMF (voluntary) · OCC 2011-12 · Customer-defined controls
- not pushedcustomer-service-handoffFailed escalation after 3 human requests (CH-4412)maps to EU AI Act · NIST AI RMF (voluntary) · OCC 2011-12 · Customer-defined controls
- not pushedhiring-screen-rejectionCandidate HS-2211 rejected on age-proxy featuremaps to EU AI Act · NIST AI RMF (voluntary) · OCC 2011-12 · Customer-defined controls
Connected systems
- ServiceNow GRCseeded illustration
- OneTrustseeded illustration
- AuditBoardseeded illustration
Framework mapping — hover for detail
Screen anatomy
What this screen proves
Notary AI complements — never replaces — the customer's existing GRC platform. Evidence packages can be handed to ServiceNow, OneTrust, or AuditBoard as GRC issues or findings with evidence attached and framework requirements mapped.
Retry policy
Push and package lifecycle are tracked independently. Failed pushes retry with backoff (5s, 30s, 3m, 30m) up to 24h, then require manual retry. The package remains fully inspectable regardless — the GRC push is a delivery mechanism, not the verification itself.
In the requirements
Where the story ends
Company XYZ can now account for the decision on Applicant A-1027, the authority behind it (Priya Ramanathan, checked against Marcus Bell's authorized expected behavior under Underwriting Policy 4.2), the verification of LoanCore's candidate 3.2.0 against approved 3.1.4, and the resulting release record — the same accountability chain this walkthrough began with.