Requirement source
Law, regulation, standard, contract, policy, or customer requirement used as context.
Not a legal conclusion. Applicability requires authorized review.
Applicability context, control mappings, assessments, artifacts, findings, remediation, access levels, limitations, and correction history — each as a distinct record. What an artifact does not cover is stated alongside what it does.

Scope invariant
An assurance artifact is useful only when you can recover what it covers, what it does not cover, when it was valid, who issued it, which evidence supports it, and what changed afterward.
Certification and professional boundary
Every certificate, report, and assessment applies only to its issuer, subject, standard and version, period, product, environment, entity, region, and stated exclusions. Outside those boundaries it proves nothing, and reading it as broader than it is remains the most common error in procurement.
ZoikoTime does not interpret law for you. Compliance depends on your configuration, practices, contracts, jurisdiction, and workforce context. We provide scoped evidence and stated limitations; assessing whether that meets your obligations requires your own legal and professional review.
Statement owner: Trust & Governance · Last reviewed 12 Jul 2026 · Next review 12 Jan 2027 ·
Shared responsibilityAssurance Taxonomy
An obligation is not a control. A control is not evidence. Evidence is not an opinion. Collapsing them is how a compliance page becomes decoration.
Law, regulation, standard, contract, policy, or customer requirement used as context.
Not a legal conclusion. Applicability requires authorized review.
The desired risk or compliance outcome.
Does not prove implementation.
A specific process, technical, or administrative measure.
Scope, version, owner, and operating state required.
A record supporting the design or operation of a control.
Quality, date, lineage, sensitivity, and retention required.
The relationship between a requirement and one or more controls or evidence sources.
A mapping is not regulator approval and not universal compliance.
Evaluation by an internal or external assessor using a defined method and period.
Sampling, limitations, findings, and opinion scope required.
An issued certificate for a defined subject, standard version, period, and scope.
No scope expansion beyond the certificate's own facts.
A description, attestation, test report, or other assurance artifact.
Issuer, date, access level, and limitation required.
An observed deficiency, exception, gap, or improvement item.
Not hidden by default. Severity and public detail are governed.
A planned or completed response to a finding.
Closure requires evidence and verification — not just task completion.
A time-bound deviation or residual risk accepted by an eligible authority.
Not equivalent to passing, and not equivalent to compliance.
Configuration, process, policy, consultation, or downstream action assigned to you.
Must be explicit — never used to evade a ZoikoTime-owned control.
Current Assurance Summary
Prepared, planned, expired, superseded, and under-review artifacts can never appear as current. There is no score and no percentage anywhere on this page.
An artifact approaching its renewal threshold is shown as Expiring with its renewal state. That is a normal lifecycle position, not a deficiency — and hiding it until renewal completes would be worse.
If registry state cannot be determined, no positive summary appears. We show the uncertainty rather than defaulting to the last good answer.
Summary counts are scoped to public visibility. A restricted artifact is not revealed by appearing in a total.
Control Mappings & Coverage
Partial coverage names the uncovered elements. Conflicting coverage blocks a conclusion entirely and routes to human review.
| Coverage state | Meaning | What must be displayed with it |
|---|---|---|
| Full | Approved controls and evidence address the mapped requirement within stated scope. | Mapping basis and limitations. Still not a legal compliance conclusion. |
| Partial | Only part of the requirement is addressed. | The uncovered elements, and the responsible party for each. |
| Customer responsibility | Your configuration, process, or contractual action is required. | The exact responsibility and the evidence expectation. |
| Provider dependency | A named approved provider contributes to coverage. | The dependency and ZoikoTime's governance of it — no blind transfer of responsibility. |
| Not applicable | An approved reviewer determined the requirement falls outside stated scope. | Rationale category, reviewer, and date. |
| Not mapped | No approved relationship exists. | Nothing inferred — neither failure nor compliance. |
| Under review | Applicability or mapping is being reassessed. | Interim limitation and safe next action. |
| Conflicting | Sources or reviewers disagree. | The current conclusion is blocked and routed to human review. |
Illustrative mapping register with synthetic identifiers. No framework name, regulator, or assessor appears without approved permission and exact scope.
"Not mapped" is the honest one
It is tempting to omit unmapped requirements so a coverage table looks complete. Omission is how a mapping package becomes misleading. An unmapped requirement is shown as unmapped, and nothing is inferred from it in either direction.
Assessments, Audits, Certifications & Reports
The exclusions block is not fine print. It is the part that determines whether the artifact answers your question.
Exclusions and limitations. Does not cover customer configuration, customer-managed identity providers, third-party integrations you authorize, local employment or payroll law, downstream systems, or any environment outside the stated scope. Sampling-based methods do not establish absence of deficiency. This artifact is currently under review — do not rely on it as settled.
Each requires current permission and exact scope. A logo without those is a claim we have not earned the right to make.
Submit an assurance review request. You receive either the current artifact with its full scope, period, and exclusions — or a clear statement that no current artifact supports your request.
"Unavailable" carries no future-state implication. It means no current artifact exists, not that one is coming.
Findings, Exceptions & Remediation
A finding is omitted only where disclosure would itself create risk — never because it is inconvenient. Omission that would materially mislead a public assurance claim is prohibited.
Objective: make material deficiencies visible at an appropriate level of abstraction.
Limitations: public summaries use safe abstraction; controlled detail stays protected. Finding severity is never used to rank customers or workers — it describes a control condition, not a person or an account.
Objective: ensure a closed finding means a restored control, not a completed ticket.
Limitations: task completion alone is not evidence of control restoration — that distinction is the entire point of the verification step. No guaranteed completion date is published unless it has been approved.
Nine remediation states
Accepted residual risk is not the same as passing. It records that an eligible authority decided to live with a known gap, with compensating controls and an end date — which is a legitimate decision, and a materially different one from having no gap.
Worker Rights & Consultation Boundary
No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration.
Visibility, explanation, correction, human review, and escalation remain available regardless of what any assurance artifact says.
Product assurance does not replace consultation, bargaining, or local employment obligations. Those responsibilities remain with your organization.
Assurance status is never used to automate an employment, payroll, disciplinary, or legal outcome. Deterministic classification is not AI; Kairos decides nothing.
Evidence collected for assurance purposes is never repurposed as covert productivity surveillance. That would defeat the invariant above.
Assurance Evidence Directory
The twelve record types, their meanings, and their boundaries.
Limitation: definitional only. Not a legal framework guide.
Eight mapping coverage states and required display rules for each.
Limitation: a mapping is not regulator approval.
Ownership by control objective and deployment context.
Limitation: your configured model may differ; confirm in review.
Requirement-to-control relationships with basis, coverage state, and gaps.
Access: governed request. Includes unmapped requirements.
Scope, period, method, sampling limitations, findings, and exclusions.
Under review — do not rely on it as settled.
Any current certificates with issuer, version, subject, scope, dates, and exclusions.
No current public certification claim exists. This carries no future-state implication.
Withdrawn, expired, and superseded artifacts are excluded from default results and from structured data. Controlled, customer-specific, and restricted evidence is never indexed, and search terms are never captured in analytics.
Controlled Assurance Review
Public evidence is never withheld to capture a lead. Controlled artifacts require identity, purpose, and entitlement because of their content.
Request states
Changes, Expiry, Renewal & Withdrawal
| Item | Previous | New | Reason | Effective | Owner |
|---|---|---|---|---|---|
| ART-0117 independent assessment | Current | Under review | Scope and wording reassessment | 01 Jul 2026 | Security |
| MAP-0042 mapping package | v3 | Superseded by v4 | Unmapped requirements added for transparency | 28 Jun 2026 | Governance |
| Legacy "audit-ready platform" wording | Published | Withdrawn | Unsupported — implied an assurance opinion that does not exist | 02 Jun 2026 | Trust & Governance |
| FIND-0088 corrective action | Ready for verification | Reopened | Re-test did not confirm control restoration | 20 Jun 2026 | Security |
Illustrative change log with synthetic identifiers. Incorrect, expired, or withdrawn assurance claims are corrected visibly and removed from current search and structured data.
The reopened row matters: the task was complete and the finding was nearly closed, but verification failed. Task completion is not control restoration, and the record reflects that rather than the intent.
Direct Answers
Applicability is context-specific, and we do not reach legal conclusions. What we can provide is scoped evidence: control mappings showing which requirements relate to which controls, with coverage state and gaps stated. Whether that satisfies an obligation for your organization depends on your configuration, practices, contracts, and jurisdiction — and requires your own legal review. Start with control mappings or a review request.