DDC assessment model
DDC structures assurance around the transition being claimed or attempted: who had authority, what requirements applied, what changed, what evidence exists, and whether verification was sufficiently independent.
Core assurance principles
Evidence over assertion
A system claim is not accepted merely because the producer, implementation, or model reports success. Conclusions must be supported by evidence appropriate to the claim.
Failure-path independence
The verifier should not inherit the critical assumptions of the thing it verifies. Independence is evaluated in terms of shared dependencies, authority sources, evidence sources, semantic assumptions, and correlated failure paths.
Adverse evidence is retained
Invalid, failed, contradictory, and adverse observations are not silently removed to improve an outcome. Their effect on the conclusion must be explicit.
Scope is conserved
The conclusion cannot legitimately become broader than the authority, requirements, evidence, and execution actually assessed.
Result language
| Result | Meaning |
|---|---|
| PASS | The assessed requirement or claim was supported under the stated scope and conditions. |
| FAIL | The assessed requirement or claim was contradicted or not satisfied under the stated conditions. |
| INVALID | The test or evidence cannot support a valid conclusion, while the adverse observation remains part of the record. |
| INCONCLUSIVE | Available evidence is insufficient to reach the required conclusion. |
| NOT ASSESSED | The matter falls outside the authorized assessment scope or was not tested. |
What an assessment does not mean
A DDCAL result does not automatically establish system-wide safety, regulatory compliance, absence of undiscovered vulnerabilities, suitability for every deployment, or behaviour under future versions and environments.