Every control in the control matrix leaves its own record as it runs. Nothing has to be collected by hand, and every report can be produced again later, figure for figure.

The records

The auditor role reads everything the venue keeps, and writes nothing; the block list is the register keeper’s, read on its own node. Every read names the point on the ledger it was read at, so a report produced today can be reproduced later.

A test plan

  1. Test the design: walk through each family page with the control matrix, confirming that each risk has a control, and each control an owner and a record; and confirm the shared-responsibility table names a party for every part the matrix leaves out.
  2. Test who decides: for a sample of mints, burns, block-list entries and forced moves, confirm the register keeper’s signature, or the consent or agreement it signed that the act ran under.
  3. Test operating effectiveness: for the period, sample each control’s records using its “How to test” column. For example:
    • four eyes: sample operations and confirm distinct makers and approvers;
    • loosened policies: confirm two approvers and the delay, and, for the supply terms, the register keeper’s acceptance;
    • reconciliation: confirm runs on schedule, each blocking finding released by two approvers with a reason, and each reserve’s cover recomputed from its reports;
    • forced transfers: match each move to its consent, the register keeper’s agreement in force, and its order’s hash.
  4. Reperform: recompute a sample of payments, payouts and distributions from their units and prices (Pricing), and the cap table at a chosen point from the ledger.
  5. Test privacy: read a sample investor’s view and confirm it shows nothing of other investors.
Related: Control matrix · Records and privacy · Mapping to your regulation