ZoikoDigital
Compliance and Assurance

Compliance evidence with scope, dates, and limits

Applicability context, control mappings, assessments, artifacts, findings, remediation, access levels, limitations, and correction history — each as a distinct record. What an artifact does not cover is stated alongside what it does.

SecurityPrivacyPlatform ReliabilitySystem Status

A compliance lead reviewing control mappings, assessment artifacts, and evidence records on a governance dashboard

Scope invariant

An assurance artifact is useful only when you can recover what it covers, what it does not cover, when it was valid, who issued it, which evidence supports it, and what changed afterward.

Certification and professional boundary

Certification is scoped evidence — not a universal compliance guarantee.

Every certificate, report, and assessment applies only to its issuer, subject, standard and version, period, product, environment, entity, region, and stated exclusions. Outside those boundaries it proves nothing, and reading it as broader than it is remains the most common error in procurement.

  • A certificate does not cover your configuration unless the certificate says so.
  • It does not cover local employment law, payroll handling, or your downstream systems.
  • A control mapping is not regulator approval and is not a legal conclusion.
  • Internal self-review is never presented as an independent audit. The two are separate record types with separate weight.

ZoikoTime does not interpret law for you. Compliance depends on your configuration, practices, contracts, jurisdiction, and workforce context. We provide scoped evidence and stated limitations; assessing whether that meets your obligations requires your own legal and professional review.

Statement owner: Trust & Governance · Last reviewed 12 Jul 2026 · Next review 12 Jan 2027 ·

Shared responsibility

Assurance Taxonomy

Twelve Record Types That Must Not Become One Badge

An obligation is not a control. A control is not evidence. Evidence is not an opinion. Collapsing them is how a compliance page becomes decoration.

Requirement source

Law, regulation, standard, contract, policy, or customer requirement used as context.

Not a legal conclusion. Applicability requires authorized review.

Control objective

The desired risk or compliance outcome.

Does not prove implementation.

Control implementation

A specific process, technical, or administrative measure.

Scope, version, owner, and operating state required.

Evidence source

A record supporting the design or operation of a control.

Quality, date, lineage, sensitivity, and retention required.

Control mapping

The relationship between a requirement and one or more controls or evidence sources.

A mapping is not regulator approval and not universal compliance.

Assessment / audit

Evaluation by an internal or external assessor using a defined method and period.

Sampling, limitations, findings, and opinion scope required.

Certification

An issued certificate for a defined subject, standard version, period, and scope.

No scope expansion beyond the certificate's own facts.

Report / statement

A description, attestation, test report, or other assurance artifact.

Issuer, date, access level, and limitation required.

Finding

An observed deficiency, exception, gap, or improvement item.

Not hidden by default. Severity and public detail are governed.

Corrective action

A planned or completed response to a finding.

Closure requires evidence and verification — not just task completion.

Exception / residual risk

A time-bound deviation or residual risk accepted by an eligible authority.

Not equivalent to passing, and not equivalent to compliance.

Customer responsibility

Configuration, process, policy, consultation, or downstream action assigned to you.

Must be explicit — never used to evade a ZoikoTime-owned control.

Current Assurance Summary

Eight Artifact Statuses

Prepared, planned, expired, superseded, and under-review artifacts can never appear as current. There is no score and no percentage anywhere on this page.

CurrentExpiringUnder reviewSupersededExpiredWithdrawnEvidence-gatedUnavailable

Expiring is not failure

An artifact approaching its renewal threshold is shown as Expiring with its renewal state. That is a normal lifecycle position, not a deficiency — and hiding it until renewal completes would be worse.

Unknown blocks positive claims

If registry state cannot be determined, no positive summary appears. We show the uncertainty rather than defaulting to the last good answer.

Counts never leak existence

Summary counts are scoped to public visibility. A restricted artifact is not revealed by appearing in a total.

Control Mappings & Coverage

Eight Coverage States, Including the Uncomfortable Ones

Partial coverage names the uncovered elements. Conflicting coverage blocks a conclusion entirely and routes to human review.

Coverage stateMeaningWhat must be displayed with it
FullApproved controls and evidence address the mapped requirement within stated scope.Mapping basis and limitations. Still not a legal compliance conclusion.
PartialOnly part of the requirement is addressed.The uncovered elements, and the responsible party for each.
Customer responsibilityYour configuration, process, or contractual action is required.The exact responsibility and the evidence expectation.
Provider dependencyA named approved provider contributes to coverage.The dependency and ZoikoTime's governance of it — no blind transfer of responsibility.
Not applicableAn approved reviewer determined the requirement falls outside stated scope.Rationale category, reviewer, and date.
Not mappedNo approved relationship exists.Nothing inferred — neither failure nor compliance.
Under reviewApplicability or mapping is being reassessed.Interim limitation and safe next action.
ConflictingSources or reviewers disagree.The current conclusion is blocked and routed to human review.

Illustrative mapping register with synthetic identifiers. No framework name, regulator, or assessor appears without approved permission and exact scope.

"Not mapped" is the honest one

It is tempting to omit unmapped requirements so a coverage table looks complete. Omission is how a mapping package becomes misleading. An unmapped requirement is shown as unmapped, and nothing is inferred from it in either direction.

Assessments, Audits, Certifications & Reports

What an Artifact Record Must Carry

The exclusions block is not fine print. It is the part that determines whether the artifact answers your question.

ART-0117 · Independent assessment (synthetic example)

Under review
Artifact type
External assessment — not a certification
Issuer / assessor
Named only in the released artifact, under approved permission
Subject
Core platform, defined service set
Standard / version
Stated in the artifact; not summarized here
Period covered
Defined assessment window
Environment
Production
Entity / region
Stated scope only
Method
Sampling-based; limitations documented
Access level
Controlled — governed request
Owner
Security & Trust Governance
Last reviewed
01 Jul 2026
Correction history
Preserved and linked

Exclusions and limitations. Does not cover customer configuration, customer-managed identity providers, third-party integrations you authorize, local employment or payroll law, downstream systems, or any environment outside the stated scope. Sampling-based methods do not establish absence of deficiency. This artifact is currently under review — do not rely on it as settled.

What is not named on this page

  • No certification name or framework logo
  • No assessor or issuer name
  • No report title or regulator reference
  • No assessment score or percentage

Each requires current permission and exact scope. A logo without those is a claim we have not earned the right to make.

How to find out what exists

Submit an assurance review request. You receive either the current artifact with its full scope, period, and exclusions — or a clear statement that no current artifact supports your request.

"Unavailable" carries no future-state implication. It means no current artifact exists, not that one is coming.

Findings, Exceptions & Remediation

Findings Are Not Hidden by Default

A finding is omitted only where disclosure would itself create risk — never because it is inconvenient. Omission that would materially mislead a public assurance claim is prohibited.

Finding record

Current

Objective: make material deficiencies visible at an appropriate level of abstraction.

Recorded
Finding ID, source assessment, safe title, severity category, affected scope, detected date, owner, status, due date
Also recorded
Corrective action, re-test result, and accepted residual risk
Exceptions
Rationale, approver, scope, start and end dates, and compensating controls
Explicit states
Overdue and unknown are shown as such, not smoothed over

Limitations: public summaries use safe abstraction; controlled detail stays protected. Finding severity is never used to rank customers or workers — it describes a control condition, not a person or an account.

Corrective action & verification

Current

Objective: ensure a closed finding means a restored control, not a completed ticket.

Plan carries
Owner, milestones, evidence, due date, dependencies, status, and verification criteria
Closure requires
Independent or eligible verification appropriate to the risk
Reopening
Preserves the full prior history rather than replacing it

Limitations: task completion alone is not evidence of control restoration — that distinction is the entire point of the verification step. No guaranteed completion date is published unless it has been approved.

Nine remediation states

PlannedIn progressBlockedReady for verificationVerifiedClosedReopenedAccepted residual riskSuperseded

Accepted residual risk is not the same as passing. It records that an eligible authority decided to live with a known gap, with compensating controls and an end date — which is a legitimate decision, and a materially different one from having no gap.

Shared Responsibility

Four Ownership States, No Vague Transfers

ZoikoTime-owned

  • Platform control design and operation
  • Evidence collection and retention
  • Assessment coordination and artifact governance
  • Finding management and verification
  • Correction and public disclosure within scope

Customer-owned

  • Configuration and access review
  • Internal policies and their accuracy
  • Worker consultation obligations
  • Local employment and payroll law
  • Downstream reconciliation and destinations

Shared & provider-dependent

  • Support, incident, and implementation access
  • Custom integrations and their scope
  • Provider-delivered contracted services
  • Provider evidence, governed rather than inherited

Two things a responsibility matrix must never do

Transfer a ZoikoTime-owned obligation to you through a vague disclaimer. Or let anyone infer that your organization is compliant because a default setting exists — a default is a starting point, not an assessment of your practice.

Worker Rights & Consultation Boundary

Assurance Evidence Never Erases a Worker Right

No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration.

Worker rights persist

Visibility, explanation, correction, human review, and escalation remain available regardless of what any assurance artifact says.

Consultation is yours

Product assurance does not replace consultation, bargaining, or local employment obligations. Those responsibilities remain with your organization.

Decisions stay human

Assurance status is never used to automate an employment, payroll, disciplinary, or legal outcome. Deterministic classification is not AI; Kairos decides nothing.

Audit evidence has limits

Evidence collected for assurance purposes is never repurposed as covert productivity surveillance. That would defeat the invariant above.

Assurance Evidence Directory

Public Records, Honestly Stated

Record typeFramework contextProduct scopeEnvironmentRegionStatusAccess levelOwnerLast reviewed

Assurance taxonomy definitions

PUBLIC

The twelve record types, their meanings, and their boundaries.

Owner
Trust & Governance
Reviewed
12 Jul 2026
Status
Current

Limitation: definitional only. Not a legal framework guide.

Coverage state definitions

PUBLIC

Eight mapping coverage states and required display rules for each.

Owner
Trust & Governance
Reviewed
12 Jul 2026
Status
Current

Limitation: a mapping is not regulator approval.

Shared responsibility matrix

PUBLIC

Ownership by control objective and deployment context.

Owner
Product governance
Reviewed
04 Jul 2026
Status
Current

Limitation: your configured model may differ; confirm in review.

Control mapping packages

CONTROLLED

Requirement-to-control relationships with basis, coverage state, and gaps.

Owner
Security & Governance
Reviewed
01 Jul 2026
Status
Current

Access: governed request. Includes unmapped requirements.

Independent assessment

CONTROLLED

Scope, period, method, sampling limitations, findings, and exclusions.

Owner
Security
Reviewed
01 Jul 2026
Status
Under review

Under review — do not rely on it as settled.

Certification register

CONTROLLED

Any current certificates with issuer, version, subject, scope, dates, and exclusions.

Owner
Trust & Governance
Reviewed
Status
Unavailable

No current public certification claim exists. This carries no future-state implication.

Withdrawn, expired, and superseded artifacts are excluded from default results and from structured data. Controlled, customer-specific, and restricted evidence is never indexed, and search terms are never captured in analytics.

Controlled Assurance Review

Request Non-Public Assurance Evidence

Public evidence is never withheld to capture a lead. Controlled artifacts require identity, purpose, and entitlement because of their content.

Step 1

What are you looking for?

Step 2

Scope

Step 3

Optional message and consent

Do not include

Credentials, worker-level records, health information, union or representative details, legal strategy, security-sensitive findings, or any other restricted information.

You receive a reference ID. Approved artifacts are delivered securely with expiry, revocation, and audit. No response time is promised, because none is approved for this route.

Request states

ReceivedNeeds clarificationUnder reviewApprovedPartially approvedDeclined with reason categoryExpiredWithdrawn

Changes, Expiry, Renewal & Withdrawal

An Expired Claim Is Removed, Then Recorded

ItemPreviousNewReasonEffectiveOwner
ART-0117 independent assessmentCurrentUnder reviewScope and wording reassessment01 Jul 2026Security
MAP-0042 mapping packagev3Superseded by v4Unmapped requirements added for transparency28 Jun 2026Governance
Legacy "audit-ready platform" wordingPublishedWithdrawnUnsupported — implied an assurance opinion that does not exist02 Jun 2026Trust & Governance
FIND-0088 corrective actionReady for verificationReopenedRe-test did not confirm control restoration20 Jun 2026Security

Illustrative change log with synthetic identifiers. Incorrect, expired, or withdrawn assurance claims are corrected visibly and removed from current search and structured data.

The reopened row matters: the task was complete and the finding was nearly closed, but verification failed. Task completion is not control restoration, and the record reflects that rather than the intent.

Direct Answers

Nine Assurance Questions

Applicability is context-specific, and we do not reach legal conclusions. What we can provide is scoped evidence: control mappings showing which requirements relate to which controls, with coverage state and gaps stated. Whether that satisfies an obligation for your organization depends on your configuration, practices, contracts, and jurisdiction — and requires your own legal review. Start with control mappings or a review request.