scieee AI-readable full text Open interactive document viewer

C12 – AuditLog.AI Global Compliance Matrix

Telles, Fernando

Abstract

C12 – AuditLog.AI Global Compliance Matrix provides the harmonized cross-reference between AuditLog.AI’s live runtime execution evidence and the governing clauses of FDA 21 CFR Part 11, EMA Annex 11, TGA / PIC/S PE 009-17, and international auditing standards (PCAOB AS 1105 / 1215 and ISA 230 / 500 / 240 Revised 2025). The matrix demonstrates that a single zero-custody, cryptographically anchored audit system can satisfy global validation, security, and documentation obligations across both regulatory and financial-assurance domains. All mapped evidence originates from the AuditLog.AI Runtime Execution and System Validation Evidence Dossier (DOI: [10.13140/RG.2.2.28551.25765] Zenodo: [10.5281/zenodo.17460850]), verified through UTC-synchronized timestamps, dual-hash proofs (SHA-256 + RIPEMD-160), OpenTimestamps attestation, and Bitcoin mainnet anchoring via OP_RETURN. Each clause is traceable to specific evidence items and session logs, ensuring reproducibility, human verification, and public auditability. The document establishes AuditLog.AI v4.0 as the first globally harmonized digital audit-trail system providing unified compliance alignment across FDA, EMA, TGA, PCAOB, and ISA standards. Ripemd160: fb1822a8113a1b691a7ef64bb7cd64ea2fa02bc8 Sha256: bbedad71af2064fb2456c73483984c538c66c2ed344f2a1cf34eef23cab14b81 Immutable Anchor: ORDINAL12|fb1822a8113a1b691a7ef64bb7cd64ea2fa02bc8|bbedad71 OP return: `e3dd84f739d2daf3f60177ce93e44648e9c57ef596090ef9a0474e0fc4fae326` ORDINAL: `7917e0f12fcff508d387733fd543451846316a21b16ca3f0d872b9849f94a904`

Full text

C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized, Cryptographically-Anchored Regulatory Compliance Map for Digital Audit and Reproducibility Systems Submitted as part of the AuditLog.AI Global Regulatory Submission Package (FDA/EMA/TGA/PCAOB/ISA Alignment) Date: October 28, 2025 Inventor and Primary Contact: Fernando Telles BMedSc(Adv) MD(Dist)¹ ² Position: CEO & Founder Email: [email protected] Phone: Provided on Request Address: 21 Shields St, Flemington VIC 3031, AU Web: www.aihumansynergy.org Engineers Lead Software Engineer: Dr. Jacob Yang BEng, MEng, PhD¹ Software Engineer: Benjamin Hookey BEng (Mechatronics & Robotics), FSEng (Safety Instrumented Systems)¹ Affiliations ¹ Cardiovascular Diagnostic Audit & AI Pty Ltd (ACN 638 019 431) – Registered Australian company conducting AuditLog.AI software development, audit and research services ² Telles Investments Pty Ltd (ACN 638 017 384) – Private IP holder IP Rights US Provisional #63/826,381 · AU Provisional #2025902482 · AU Trade Mark #2535745 & #2549093 IP Priority Date: 17 June 2025 (Global) C12 – AuditLog.AI Global Compliance Matrix INDEX Executive Summary Section I: FDA 21 CFR Part 11 — Compliance Evidence Matrix Section II: EMA Annex 11 + GCP Guideline Integration (2023) Section III: TGA / PIC/S PE 009-17 — Harmonized Matrix Section IV: PCAOB AS 1215 / AS 1105 — Audit Documentation & Evidence • • • • • C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 1 of 42 AUDITLOG.AI0001CME Section V: ISA 230 / ISA 500 / ISA 240 (Revised 2025) — International Assurance Alignment Annex VI — Dossier Evidence Index (Execution Evidence Cross-Reference) Annex VII – Public Verification Provenance Executive Summary This matrix provides a consolidated mapping between AuditLog.AI execution evidence and the regulatory clauses governing electronic records, validation, and audit documentation across the FDA (21 CFR Part 11), EMA (Annex 11), TGA /PIC/S PE 009-17, and international auditing standards (PCAOB AS 1105 / 1215 and ISA 230 / 500 / 240). All evidence in this compliance matrix originates from the AuditLog.AI Runtime Execution and System Validation Evidence Dossier (DOI 10.13140/RG.2.2.28551.25765 / Zenodo 10.5281/ zenodo.17460850). Each artifact is verified through UTC timestamps, dual-hash cryptographic proofs (SHA-256 + RIPEMD-160), OpenTimestamps attestation, and Bitcoin mainnet anchoring (OP_RETURN). Complete provenance and anchor TXIDs are provided in Annex VII – Public Verification. Regulatory Summary Region Submission Type Regulatory Basis Proposed Classifica‐ tion FDA (USA) Q‑Submission (Q‑Sub) 21 CFR Part 11 (Elec‐ tronic Records / e-Sig‐ natures) Standalone Electronic Records / Audit‑Trail Infrastructure (non‑device) EMA (EU) Scientific Advice (op‐ tional) + Annex 11 val‐ idation EudraLex Vol 4 Annex 11 (Computerised Sys‐ tems) GMP Computerised System for Data Integ‐ rity (non‑device) TGA (Australia) Excluded Software De‐ termination Excluded Goods De‐ termination 2018 + PIC/S PE 009‑17 Annex 11 LIMS‑category audit in‐ frastructure (non‑medical device) FDA (21 CFR Part 11) — United States electronic records and signatures EMA (Annex 11) — European Union computerized systems for GMP TGA (PIC/S PE 009-15) — Australia therapeutic goods manufacturing principles • • • • • • C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 2 of 42 AUDITLOG.AI0002CME Auditing Standards Compliance Summary Framework Standard Core Requirement AuditLog.AI Compli‐ ance Mechanism ISA / IAASB ISA 230 Audit documentation enabling experienced auditor understanding session log JSON com‐ pilation (who / what / when / meaning); ap‐ pend-only dual atomic ledgers for anchor re‐ ceipts (TXID, block); frozen folder structure ISA / IAASB ISA 500 Sufficient appropriate audit evidence (quant‐ ity + quality: relevance + reliability) cryptographic integrity + Bitcoin OP_RETURN (payload/TXID) extern‐ al verification + Open‐ Timestamps ISA / IAASB ISA 240 Professional skepticism + fraud risk assess‐ ment + management override prevention Append-only dual ledgers; non-repudi‐ able e-signatures; failclosed runtime checks; independent time at‐ testations PCAOB AS 1215 Audit documentation with 60-day assembly + 7-year retention Frozen sources UTC timestamp-locked archives; anchors link‐ ing records to public blockchain PCAOB AS 1105 Audit evidence evalu‐ ation (sufficiency + ap‐ propriateness) Public blockchain TXID verification + OTS; de‐ terministic hash parity from frozen session re‐ cords PCAOB AS 1105.10A (effect‐ ive 2025) External electronic in‐ formation reliability evaluation Bitcoin blockchain (public, decentralized) + independent block‐ chain explorer verifica‐ tion tools Notes: Evidence flow is zero-custody (proofs only); all artifacts are version-locked, nonadaptive, and human-approved prior to anchoring. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 3 of 42 AUDITLOG.AI0003CME Section I: FDA 21 CFR Part 11 — Compliance Evidence Matrix Official Reference Files: 21 CFR Part 11 (up to date as of 9-29-2025)___20251020T193619Z.pdf , 7883441_DataIntegrity___20251020T193619Z.pdf , 58358119fnl___20251020T193619Z.pdf , 58358119fnl___20251020T193619Z.pdf §11.10 Controls for Closed Systems — Evidence Mapping Clause Dossier Evidence # Relevance to AuditLog.AI Software §11.10(a) (Validation: accuracy, reliability, consist‐ ent performance, discern invalid/altered records) 4 & 8, 15-16, 38, 42-43 Pre‑/post‑hasher audits (4 & 8) confirm 1:1 parity between the manifest and generated digests, en‐ suring every expected file is processed exactly once with no additions/omissions. PRE/POST runtime screenshots (15–16) show controlled exe‐ cution and stable timing (Δ documented) consist‐ ent with intended performance. The session‑log di‐ gest parity check (38) demonstrates that the anchored payload matches the frozen session log; validation records (42–43) evidence repeatability and release‑level verification that altered or invalid records would be detected. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 4 of 42 AUDITLOG.AI0004CME Clause Dossier Evidence # Relevance to AuditLog.AI Software §11.10(b) (Generate accurate complete copies — human readable + electronic form for FDA inspec‐ tion) 14, 17-18, 20, 38-39 Post‑verification audit logs (14), frozen per‑folder audit logs (17–18), and the compiled session log (20) together provide human‑readable (NDJSON/ JSON) and machine‑verifiable copies. Di‐ gest‑match validation (38) and dual‑ledger consist‐ ency (39) demonstrate that produced copies are complete and accurate and can be supplied to in‐ spectors without transforming source evidence. §11.10(c) (Protection of records — accurate ready retrieval throughout retention period) 18, 20, 36-39 Frozen audit logs (18) and the session log (20) are held under read‑only/immutable controls, support‐ ing durable local retention and ready retrieval. Blockchain anchors (36–37), digest‑match valida‐ tion (38), and dual‑ledger checks (39) provide in‐ dependent, long‑term verifiability of record integrity and indexing without exposing content. §11.10(d) (Limiting system access to authorized individuals) 3, 21-26, 28 Access is restricted to authenticated enterprise users (21) and registered reviewers (3, 22). A valid institutional HMAC session and a user e‑signature are both required before a gate job is created (26). The FAIL/PASS tests (23–25) show fail‑closed be‐ havior; only authorized users advance to final anchoring authorization step (28). C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 5 of 42 AUDITLOG.AI0005CME Clause Dossier Evidence # Relevance to AuditLog.AI Software §11.10(e) (Secure computer-generated timestamped audit trails — independently record date/ time, no obscuring, retention) 7, 14, 17-18, 20, 36-39 OpenTimestamps (OTS) proofs (7), audit logs (14, 17–18), and the session log (20) capture com‐ puter‑generated UTC timestamps for all key events. The dual‑ledger record (39) maintains an append‑only, time‑sequenced trail; previous entries are never overwritten. Anchors (36–37) provide durable external time attestation; di‐ gest‑match validation (38) preserves traceability from record → payload → TXID. §11.10(f) (Operational system checks — enforce permitted sequencing) 4 & 8, 6-7, 12-17, 19, 26, 28-29, 31-36, 39-41 The software enforces a fixed order of operations: pre‑checks (4), hashing/OTS (6–7), audit verifica‐ tion (8), mandatory user verification prior to logging (15–17, 19), gate‑job creation only on multi-layer e-signature (26), and broadcast/confirmation (28– 36), with state‑machine transitions recorded in the dual ledger (39–41). Attempts to bypass steps are blocked by runtime checks; only sequenced events are accepted. §11.10(g) (Authority checks — ensure only author‐ ized individuals can use system, sign records, alter records) 3, 21-26, 28 Authority is dual‑gated: (1) Institutional access via HMAC session (21) and (2) Individual approval via e‑signature (3, 22). Evidence (23–25) shows that unauthorized or failed signings are rejected and do not create gate jobs; only authorized actions (26) can proceed to final anchoring (28). C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 6 of 42 AUDITLOG.AI0006CME Clause Dossier Evidence # Relevance to AuditLog.AI Software §11.10(h) (Device checks — determine validity of data input source) 4 & 8, 6A, 7A, 15-16, 38-39, 42-43 Device/input validity is enforced by accepting only frozen inputs from the controlled area documented by pre/post audits (4 & 8), by sidecar‑exclusion and naming rules embedded in the audits, and by reproducibility testing (6A, 7A). PRE/POST screen‐ shots (15–16), digest‑match (38), and dual‑ledger checks (39) confirm that only permitted, verified inputs are processed. (Optional, non‑biometric telemetry may flag automation risk but cannot ac‐ cept/deny; if triggered, a deterministic secondary verification is required.) §11.10(i) (Personnel qualification — education, training, experience to perform assigned tasks) 6A, 7A, 42-43 Release‑level validation records (42–43) and re‐ producibility audits (6A, 7A) evidence competent execution, review, and approval under the QMS (IQ/OQ/PQ). Training and role assignments for de‐ velopers/operators are managed within the QMS and are available under NDA; the artifacts here show qualified personnel performed and reviewed the validated runs. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 7 of 42 AUDITLOG.AI0007CME Clause Dossier Evidence # Relevance to AuditLog.AI Software §11.10(j) (Written policies — accountability for electronic signature actions to deter falsification) 3, 14, 20-26, 28, 37-41 Each audit log (14) captures identity, UTC time, and meaning of each e‑signature; session log compiles all audit logs, and enforces deterministic linking to prior sessions by recording anchor pay‐ load/txid (20); gates (22–26) bind actions to named users and institutional sessions. The pipeline (28) and on‑chain receipts (37) record non‑repudiable outcomes, while the dual‑ledger trail (39–41) pre‐ serves who did what, when, consistent with written accountability policies under the QMS. §11.10(k)(1) (Controls over systems documenta‐ tion distribution, access, use) 2, 18, 20, 27, 30, 33, 36-41 Zero‑custody, frozen archives (2, 18, 20) restrict modification and distribution of system records; gate‑job and receipt artifacts (27, 30, 33) evidence controlled handoff from user to anchoring service. Anchors and ledger entries (36–41) provide trace‐ able, read‑only provenance, supporting governed access and use of system documentation. §11.10(k)(2) (Revision/change control — audit trail documenting time-sequenced development/modi‐ fication) 6A, 7A, 42-43 QMS records (42–43) document versioning, ap‐ provals, and release history; reproducibility runs (6A, 7A) are tied to specific versions/parameters, demonstrating that changes are evaluated, ap‐ proved, and recorded in time sequence, with outputs independently repeatable. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 8 of 42 AUDITLOG.AI0008CME §11.30 Controls for Open Systems — Evidence Mapping Clause Dossier Evidence # Relevance to AuditLog.AI Software §11.30 (Open systems — procedures/controls en‐ suring authenticity, integrity, confidentiality includ‐ ing encryption + digital signature standards) 4 & 8, 6-7, 15-16, 18, 36-41 Authenticity and integrity are ensured by crypto‐ graphic digests (4, 6), pre/post execution audit confirming 1:1 file parity (8, 15–16), independent OTS time attestation (7), and on‑chain OP_RETURN anchoring of proof‑only payloads (36–37) that contain no source data or identifiers. Confidentiality is preserved by the zero‑custody data flow (18, 20): only digests/receipts are trans‐ mitted; raw evidence never leaves the customer’s environment. Gate‑job and anchoring approvals are bound by an individual cryptographic e‑signature (Ed25519) within an authenticated in‐ stitutional session (21–22). Dual‑ledger records and state‑machine transitions (39–41) provide dur‐ able, tamper‑evident provenance from creation to receipt. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 9 of 42 AUDITLOG.AI0009CME Annex 11 Section; Requirement Dossier Evidence # Relevance to AuditLog.AI Software Data Storage (§7); Data secured by physical and electronic means against damage; stored data checked for accessibility, readability, and accuracy; access ensured throughout the retention period 6, 18, 20, 36–39, 41 AuditLog.AI secures all records through: (1) tamper-evident dual-hash cryptography (Evidence 6 & 38: SHA-256 + RIPEMD-160 verifying bytelevel integrity); (2) frozen copies with read-only and immutable filesystem controls (Evidence 18: chmod 444 + chflags uchg ); (3) dual-ledger atomic consistency between user and master ledgers (Evidence 39); (4) session-log compilation linking each audit log to the previous session’s blockchain anchor (Evidence 20 & 41); and (5) Bit‐ coin OP_RETURN anchoring (Evidence 36–37) providing permanent public proof of existence. To‐ gether these controls satisfy EMA Annex 11 §7 re‐ quirements for secure storage, accessibility, and data integrity throughout the defined retention peri‐ od. Audit Trails (§9); System-generated record of all GMP-relevant changes and deletions; reasons documented; audit trails available in intelligible form and regularly reviewed 7, 14, 17-18, 20, 36-39 AuditLog.AI produces secure, time‑stamped audit records (OTS 7; session/audit logs 14, 17–18, 20) and on‑chain receipts (36–37); dual‑ledger events with state transitions (39) present an intelligible, append‑only trail reviewed during validation and periodic evaluation. Rationale/updates are cap‐ tured in the logs, consistent with EMA’s definitions and review expectations for audit trails. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 16 of 42 AUDITLOG.AI0016CME Annex 11 Section; Requirement Dossier Evidence # Relevance to AuditLog.AI Software Change and Configuration Management (§10); Any changes to a computerised system including system configurations should only be made in a controlled manner in accordance with a defined procedure. 6-7, 42-43 Change control is executed under the QMS (42– 43): requests, impact/risk assessment, testing, ap‐ proval, versioning, and release records (with repro‐ ducibility checks 6–7). This aligns with EMA GCP guideline A2.10 "Change control". Periodic Evaluation (§11); Computerised systems should be periodically evaluated to confirm valid state and GMP compliance; evaluations include functionality, deviation records, incidents, perform‐ ance, reliability, security, validation status 6A, 7A, 42-43 Reproducibility audits (6A, 7A) and QMS periodic reviews (42–43) confirm the system remains in a validated state; results and any actions are docu‐ mented and version‑locked. This implements EMA GCP guideline A2.9 "Periodic review". Security (§12); Physical/logical controls restricting access to authorized persons; methods include passwords, biometrics; extent depends on critical‐ ity; access authorization changes recorded; iden‐ tity of operators entering/changing data recorded with date/time 3, 21-26, 28 Access is limited to authorized users via institution‐ al authentication and e‑signature gates (3, 21–26); operator identity, UTC time, and signature mean‐ ing are linked in the record; optional non‑biometric telemetry (Layer 3) may trigger step‑up verification but never alone approves/denies. Controls map to EMA security standards and GCP 5.4 "Security and access control". Electronic Signature (§14); Electronic signatures are expected to: a) have the same impact as handwritten; b) permanently linked to their respective record; c) include the time and date 3, 14, 20-22 Electronic signatures are captured with unique user identity + time + meaning, and permanently linked in the session/gate‑job records (14, 20–22). Timestamps are system‑generated and non‑manipulable; full signature information re‐ mains accessible (user-held) for review—consist‐ ent with EMA’s e‑signature and timestamp expect‐ ations. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 17 of 42 AUDITLOG.AI0017CME Annex 11 Section; Requirement Dossier Evidence # Relevance to AuditLog.AI Software Business Continuity (§16); For systems support‐ ing critical processes, provisions ensuring continu‐ ity in event of breakdown; alternative arrange‐ ments (manual/alternative system) documented and tested; recovery time based on risk 6A, 7A, 42-43 Zero‑custody design plus independent OTS and on‑chain receipts enable offline re‑verification; re‐ producibility audits (6A, 7A) and QMS procedures (42–43) ensure reproducibility independent of AuditLog.AI tools. Archiving (§17); Data may be archived; archived data checked for accessibility, readability, integrity; if system changes, data must remain readable 14, 17-18, 20, 38-39 Frozen archives (17–18) preserve readability and integrity; audit and session logs (14, 20) remain verifiable via digest‑match (38) and ledger receipts (39). EMA requires retention of dynamic data (e.g., audit trails) in dynamic form—met via NDJSON/ JSON logs, accompanying frozen copies and OTS/ BTC receipts. EMA Clinical Trials Guideline (2023) — Supplementary Evidence Mapping Guideline Section Dossier Evidence # Relevance to AuditLog.AI Software §5.5 Timestamp (UTC + External Standard) 15–16, 7–7A, 36–38 AuditLog.AI fulfills the timestamp requirement through PRE/POST execution UTC records (Evidence 15–16: PRE_20251014T193659Z / POST_20251014T193727Z , Δ=28 s verified timeline) combined with independent external standards — OpenTimestamps proofs (Evidence 7–7A) and Bitcoin anchoring (Evidence 36–38). Together these ensure unambiguous, verifiable UTC timing synchronized to an external, decentral‐ ized standard, meeting EMA §5.5 requirements for accuracy, traceability, and time-zone transparency. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 18 of 42 AUDITLOG.AI0018CME Guideline Section Dossier Evidence # Relevance to AuditLog.AI Software §6.6 Control of Data (Recognition of Public Blockchain) 36–38 AuditLog.AI anchors anonymized, tamper-evident cryptographic digests of each session log (Evid‐ ence 38) onto the Bitcoin mainnet using OP_RETURN payloads (Evidence 36–37: TXID 9a46014d657726798449c‐ c6282de083e2084afc87aa5f23233903396d73b8d 4f , Block 919082). This implementation provides "verifiability of data (transactions) by an independ‐ ent (distributed) tamper-proof ledger" explicitly recognized under EMA §6.6 as offering "compar‐ able security to a system maintained by an inde‐ pendent service provider". The blockchain-based audit trail thereby satisfies the EMA’s requirement for independent, tamper-proof data verification and integrity assurance. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 19 of 42 AUDITLOG.AI0019CME Section III: TGA / PIC/S PE 009-17 — Harmonized Matrix Official Reference Files: pe-009-17-gmp-guide-xannexes___20251020T193619Z.pdf , Concept Paper on the Revision of Annex 11 of the Guidelines on Good Manufacturing Practice for Medicinal Products Computerised Sys‐ tems___20251020T193619Z.pdf NOTE: Australia (TGA) adopts PIC/S PE 009-17 as GMP standard. PIC/S Annex 11 uses titled sections aligning with EMA Annex 11 structure. PIC/S Annex 11 Section Dossier Evidence # Relevance to AuditLog.AI Software Validation (Project Phase 4. page 170) 6, 7, 12–14, 42–43, 6A, 7A Risk‑based validation is demonstrated across hasher + OTS runtime (6–7), VALIS prompts/logs and the AuditLog Generated record (12–14), with formal QMS validation & pre‑deployment/produc‐ tion audits (42–43). Reproducibility and stress tests (6A, 7A) evidence suitable test methods/ac‐ ceptance criteria and lifecycle verification per §4.1–4.8. Accuracy (Operational Phase 6. page 171) 4 & 8, 6, 13, 38 Pre‑Hasher Execution Audit (4) establishes the baseline; Post‑Hasher Verification (8) confirms 1:1 parity between manifest rows and generated di‐ gests; dual‑hasher runtime (6) and per‑folder VAL‐ IS logs (13) provide validated electronic checks; Session Log Digest Match Validation (38) verifies parity at session level—fulfilling the second operat‐ or or validated electronic means control. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 20 of 42 AUDITLOG.AI0020CME PIC/S Annex 11 Section Dossier Evidence # Relevance to AuditLog.AI Software Data Storage (Operational Phase 7. page 171) 18, 20, 36–39, 42–43 Frozen copies (18) apply read‑only + immutable flags for integrity; Session Log (20) ensures ac‐ cessibility/readability; on‑chain receipts and dual‑ledger (36–39) add durable, independently verifiable provenance; QMS validation records (42–43) cover restore/periodic checks expected under §7.2. Audit Trails (Operational Phase 9. page 171) 20, 33–39, 41 Session Log (20) and AMPLIFY Ledger state‑machine records (33–39) capture date/time, reasoned events, and transitions; Final Anchor Event (41) closes the trail. All artifacts are avail‐ able in intelligible form and are reviewable— consistent with §9. Change & Configuration Management (Opera‐ tional Phase 10. page 171) 42–43, 6A, 7A QMS change control and configuration manage‐ ment are evidenced in pre‑public deployment audits and runtime integrity provenance (42–43). Reproducibility audits (6A, 7A) support controlled modification and verification of the validated state. Periodic Evaluation (Operational Phase 11. page 171) 6A, 7A, 42–43 Periodic evaluations are satisfied by scheduled re‐ producibility runs (6A, 7A) and QMS‑tracked re‐ views (42–43) covering performance/reliability/ security and validation status per §11. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 21 of 42 AUDITLOG.AI0021CME PIC/S Annex 11 Section Dossier Evidence # Relevance to AuditLog.AI Software Security (Operational Phase 12. page 172) 3, 21–26, 20, 18 Layer 1–2 identity controls: institutional authentica‐ tion (21) + cryptographic e‑signature (3, 22, 25– 26). Layer 3 (optional): non‑biometric hu‐ man‑activity verification in the Signature Gate (22– 26) as a fraud‑prevention signal. All signature actions are linked in Session Log (20) with UTC time; frozen archives (18) protect records at rest. Meets access restriction, authorization lifecycle, and operator identity/time recording. Electronic Signature (Operational Phase 14. page 172) 3, 14, 20–22, 26 Electronic signatures have the same impact as hand‑written (policy/QMS), are permanently linked to their records via gate_job/session artifacts (14, 20–22, 26), and include date/time (20, 26), satisfying §14(a)–(c). Business Continuity (Operational Phasepage 16. 172) 18, 36–39, 42–43 Continuity is supported by frozen local artifacts (18), independent public anchoring + dual ledger (36–39) for off‑site verifiability, and documented contingency/restore validation within QMS audits (42–43), as required by §16. Archiving (Operational Phase 17. page 173) 14, 17–18, 20, 38–39 Authorized VALIS logs per folder (17), frozen archives (18), and session log with cross‑references to prior anchors (20) ensure ac‐ cessibility/readability/integrity; digest‑match (38) and dual‑ledger (39) preserve retrievability across system changes per §17. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 22 of 42 AUDITLOG.AI0022CME Section IV: PCAOB AS 1215 / AS 1105 — Audit Documentation & Evidence Official Reference Files: auditing_standards_audits_fybeginning_on_or_after_december_15_2024.pdf , 2024-007-adoptingrelease.pdf , pcaob-release-no-2025-004.pdf AS 1215 (Audit Documentation) — Evidence Mapping Clause; Page; Paragraph; Requirement Dossier Evidence # Relevance to AuditLog.AI Software ¶.04; p.60; Requirements; Documentation Re‐ quirement: "The auditor must prepare audit docu‐ mentation in connection with each engagement conducted pursuant to the standards of the PCAOB. Audit documentation should be prepared in sufficient detail to provide a clear understanding of its purpose, source, and the conclusions reached" 14, 20, 33–39 Self‑documenting record set: AuditLog Gener‐ ated Post‑Verification (14) and Session Log View (20) capture purpose, inputs, approver identity, UTC times, digests, and outcome; AMPLIFY ledger + anchor receipts (33–39) show the end‑to‑end conclusion (e.g., ANCHORED_RECEIPT_WRITTEN ) and source trace‐ ability via TXID/OP_RETURN payloads. ¶.06; p.60; Requirements; Work Performed: "The auditor must document the procedures performed, evidence obtained, and conclusions reached with respect to relevant financial statement assertions. Audit documentation must clearly demonstrate that the work was in fact performed" 6–7, 12–14, 15–16, 33–39 Work actually performed is provable: runtime hashing (6), OTS attestation (7), VALIS prompts and per‑folder logs (12–13), generated audit re‐ cord post‑verification (14), PRE/POST execution captures (15–16) and the dual ledgers + Bitcoin chain (33–39) together show the procedures, the evidence produced (digests/OTS/TXID) and the final conclusion state. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 23 of 42 AUDITLOG.AI0023CME Clause; Page; Paragraph; Requirement Dossier Evidence # Relevance to AuditLog.AI Software ¶.06A; p.60; Requirements; Experienced Auditor Test: "Audit documentation must contain sufficient information to enable an experienced auditor, hav‐ ing no previous connection with the engagement: (a) To understand the nature, timing, extent, and results of the procedures performed, evidence ob‐ tained, and conclusions reached, and (b) To de‐ termine who performed the work and the date such work was completed as well as the person or per‐ sons who reviewed the work and the date of such review" 14, 20–22, 26, 33–39 Reconstructible without oral explanation: (14) and (20) present the compiled session and chain‑of‑custody; access/auth and e‑signature gating (21–22, 26) identify who approved when (UTC) and for what; the ledger and anchor re‐ ceipts (33–39) fix timing/extent/results and review‐ ers/approvers in a durable record. ¶.07; p.60-61; Requirements; Documentation Factors: "In determining the nature and extent of the documentation... the auditor should consider... Nature of the auditing procedure; Risk of material misstatement; Extent of judgment required; Signi‐ ficance of the evidence; Responsibility to docu‐ ment conclusion not readily determinable" 12–13, 18, 42–43 Risk‑proportionate documentation: VALIS gat‐ ing & per‑folder output (12–13) detail what is docu‐ mented and why; frozen, read‑only artifacts (18) preserve significant items; QMS/validation and pre‑public deployment audits (42–43) evidence the risk‑based selection, testing depth, and rationale behind documentation sufficiency. ¶.09; p.61; Requirements; Presumption if Docu‐ mentation Absent: "If... the auditor becomes aware... that audit procedures may not have been performed... the auditor must determine, and if so demonstrate, that sufficient procedures were per‐ formed... To accomplish this, the auditor must have persuasive other evidence. Oral explanation alone does not constitute persuasive other evidence" 33–39, 36–37, 38 Persuasive, independent corroboration: pub‐ lic‑chain receipts and payload parity (36–37), ses‐ sion‑to‑anchor digest match (38), and the ap‐ pend‑only AMPLIFY ledger (33–39) provide third‑party‑verifiable proof of performance and results—removing reliance on oral explanation. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 24 of 42 AUDITLOG.AI0024CME Clause; Page; Paragraph; Requirement Dossier Evidence # Relevance to AuditLog.AI Software ¶.12; p.62; Requirements; Significant Findings Documentation: "The auditor must document sig‐ nificant findings or issues, actions taken to address them (including additional evidence obtained), and the basis for the conclusions reached... Significant findings include: (a) Significant accounting matters; (b) Results indicating need for significant modifica‐ tion of planned procedures; (c) Audit adjustments; (d) Disagreements among engagement team; (e) Circumstances causing significant difficulty; (f) Significant changes in assessed audit risk; (g) Matters that could result in modification of auditor's report" 20, 33–39, 40 Issue → action → conclusion, all recorded: session log (20) and ledgers (33–39) capture significant events and decisions; LLM3 correction disclosure (40) documents the issue, the reason, corrective action, and resultant conclusion with dates and author, as required. ¶.14; p.64; Retention of and Subsequent Changes to Audit Documentation; Retention Period: The auditor must retain audit documentation for seven years from the date the auditor grants per‐ mission to use the auditor's report (report release date), unless a longer period is required by law. 17–18, 20, 36–39 Durable retention & retrievability: frozen archives with file‑system immutability (17–18) + session log (20) + Bitcoin mainnet anchoring/re‐ ceipts (36–39) ensure records remain complete, readable, and retrievable for (≥) the retention peri‐ od. ¶.15; p.64; Retention of and Subsequent Changes to Audit Documentation; Assembly Deadline (Documentation Completion Date): A complete and final set of audit documentation should be as‐ sembled for retention (archived) as of a date not more than 14 days after the report release date. 15–16, 18, 33–39 Timely assembly by design: PRE/POST evid‐ ence (15–16) and frozen artifacts (18) are gener‐ ated contemporaneously; ledger/receipts (33–39) timestamp completion—demonstrating assembly well within the 14‑day window. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 25 of 42 AUDITLOG.AI0025CME ISA 500 (Audit Evidence) — Evidence Mapping Clause; Page; Paragraph; Requirement Dossier Evidence # Relevance to AuditLog.AI Software ¶4; p.362; Objective; Objective: The objective of the auditor is to design and perform audit proced‐ ures in such a way as to enable the auditor to ob‐ tain sufficient appropriate audit evidence to be able to draw reasonable conclusions on which to base the auditor's opinion 4 & 8, 6–7, 12–13, 20, 33–39, 42–43 The end‑to‑end pipeline is explicitly designed to obtain sufficient appropriate evidence: pre/post execution audits (4, 8) feed dual‑hash + OTS pro‐ cessing (6–7); VALIS controls (12–13) enforce completeness/accuracy; the compiled session log (20) captures results and linkages; AMPLIFY/Bit‐ coin artifacts (33–39) provide independent persist‐ ence; QMS validation/traceability (42–43) documents lifecycle controls. ¶5(b); p.362; Definitions; Appropriateness Defini‐ tion: Appropriateness (of audit evidence) – The measure of the quality of audit evidence; that is, its relevance and its reliability in providing support for the conclusions on which the auditor's opinion is based 6–7, 15–16, 20, 36–38, 39 Quality is established by cryptographic integrity (6) + independent time attestation (7); PRE/POST screenshots show correct context and timing (15– 16); relevance is bound to the specific session via manifest + metadata (20); reliability is elevated by external, public blockchain anchors (36–38) cross‑checked against the dual‑ledger (39). ¶5(f); p.362; Definitions; Sufficiency Definition: Sufficiency (of audit evidence) – The measure of the quantity of audit evidence. The quantity of the audit evidence needed is affected by the auditor's assessment of the risks of material misstatement and also by the quality of such audit evidence 4, 8, 12–13, 18, 20, 6A Quantity is evidenced by the pre/post hasher audits demonstrating 1:1 parity (4, 8), folder‑level VALIS logs that enumerate every input (12–13), frozen archives preserving the full set (18), and the session manifest with per‑file digests (20). Stress‑test/reproducibility runs (6A) demonstrate capacity and repeatability at scale. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 32 of 42 AUDITLOG.AI0032CME Clause; Page; Paragraph; Requirement Dossier Evidence # Relevance to AuditLog.AI Software ¶6; p.363; Requirements; Design Procedures: The auditor shall design and perform audit proced‐ ures that are appropriate in the circumstances for the purpose of obtaining sufficient appropriate audit evidence 4, 6–7, 8, 12–13, 20, 33–39, 42–43 Procedures are risk‑aligned and deterministic: par‐ ity checks (4, 8), dual‑hash + OTS (6–7), VALIS enforcement (12–13), session compilation with ac‐ ceptance checks (20), state‑machine‑controlled anchoring and confirmations (33–39), and QMS validation/controls (42–43). ¶7; p.363; Requirements; Relevance and Reliab‐ ility: When designing and performing audit pro‐ cedures, the auditor shall consider the relevance and reliability of the information to be used as audit evidence, including information obtained from an external information source 7, 36–38, 39 External reliability is provided by OpenTimestamps (7) and public Bitcoin mainnet anchors (36–38); cross‑verification against the user + AuditLog.AI dual‑ledger (39) evidences that external data agree with internal records. ¶9; p.363; Requirements; Entity-Produced In‐ formation: When using information produced by the entity, the auditor shall evaluate whether the information is sufficiently reliable for the auditor's purposes, including, as necessary in the circum‐ stances: (a) Obtaining audit evidence about the accuracy and completeness of the information 4, 8, 12–14, 20, 38 Entity‑produced logs are validated by parity audits (4, 8) and VALIS controls (12–13); the AuditLog generated post‑verification record (14) and session manifest (20) capture full lineage; digest‑match verification (38) proves that the compiled record exactly corresponds to the anchored payload. ¶A8; p.365; Application; Sufficiency-Appropriate‐ ness Interrelation: The sufficiency and appropri‐ ateness of audit evidence are interrelated. Suffi‐ ciency is the measure of the quantity of audit evid‐ ence... Appropriateness is the measure of the quality of audit evidence... Obtaining more audit evidence, however, may not compensate for its poor quality 12–13, 20, 6–7, 36–38 The system balances quantity (VALIS enumeration and manifest coverage: 12–13, 20) with quality (cryptographic/OTS proofs and public anchors: 6– 7, 36–38), showing why more evidence is unne‐ cessary when higher‑quality external proofs exist. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 33 of 42 AUDITLOG.AI0033CME Clause; Page; Paragraph; Requirement Dossier Evidence # Relevance to AuditLog.AI Software ¶A9; p.365; Application; Reliability Factors: Ap‐ propriateness is the measure of the quality of audit evidence; that is, its relevance and its reliability in providing support for the conclusions... The reliab‐ ility of evidence is influenced by its source and by its nature, and is dependent on the individual cir‐ cumstances under which it is obtained 2, 18, 20, 27, 30, 36–38, 39, 7A Source/nature are evidenced by zero‑custody provenance (2, 27, 30), frozen read‑only archives (18) and session context (20); circumstances are independently corroborated on Bitcoin mainnet (36–38) and reconciled via dual‑ledger controls (39). OTS reproducibility audits (7A) further sup‐ port credibility of the external time source. ¶A30-A38; p.368; Application; Reliability Hier‐ archy: External evidence more reliable than in‐ ternal; documentary evidence more reliable than oral; original evidence more reliable than copies 36–38, 7, 18, 20, 33–39 External documentary originals: public TXIDs/ OP_RETURN payloads (36–38) and OTS proofs (7). Internal records: frozen originals and manifest (18, 20). Cross‑checks: append‑only ledgers and public blockchain confirmations (33–39). This suite meets the reliability hierarchy. ¶A43; p.370; Application; Single Provider As‐ sessment: In some situations, there may be only one provider of certain information... the nature and extent of audit procedures that may be appro‐ priate in the circumstances is influenced by the nature and credibility of the source of the informa‐ tion 33–39, 6A, 7A, 36–38 Where a single internal provider exists (system logs), controls are tested via dual‑ledger atomicity and state transitions (33–39) and by independent external anchors (36–38). Reproducibility cam‐ paigns (6A, 7A) provide additional assurance on source credibility and the controls over receiving/ maintaining/processing the information. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 34 of 42 AUDITLOG.AI0034CME ISA 240 (Revised) (Fraud Responsibilities) — Evidence Mapping Clause; Page; Paragraph; Requirement Dossier Evidence # Relevance to AuditLog.AI Software ¶12; p.10; Introduction; Professional Skepticism and Professional Judgment: It is important that the auditor maintain professional skepticism throughout the audit, considering the potential for management override of controls, and recognizing that audit procedures that are effective for detect‐ ing error may not be effective in detecting fraud 15–16, 18, 20, 33–39, 6A, 7A Immutable, computer‑generated proofs (PRE/ POST screenshots with Δ<300s; frozen archives; session log with dual‑hash + OTS; dual-ledger + Bitcoin anchors) reduce reliance on oral explana‐ tions and support skeptical evaluation; reproducib‐ ility audits (6A, 7A) evidence consistent results over time. ¶19; p.12; Requirements; Professional Skepti‐ cism: In applying ISA 200, the auditor shall main‐ tain professional skepticism throughout the audit, recognizing the possibility that a material misstate‐ ment due to fraud could exist 4 & 8, 20, 36–39, 6A, 7A, 38, 42-43 Pre/Post‑Hasher audits (4, 8) and session log (20) expose any mismatch (38); external, independ‐ ently verifiable anchors (36–39) plus reproducibility suites (6A, 7A, 42-43) provide corroborative, third‑party‑verifiable evidence consistent with skeptical inquiry. ¶20; p.12; Requirements; Remain Alert: "The auditor shall remain alert throughout the audit for information that indicates that one or more fraud risk factors are present and circumstances that may be indicative of fraud or suspected fraud" 22–26, 23–24, 33–39 e‑Signature Gate records PASS/FAIL outcomes (22–26) and blocked attempts (23–24). State‑machine ledger entries (33–39) time‑stamp all attempts and outcomes, supporting alerting and detection of anomalous authorization patterns. ¶22; p.12; Requirements; Document Authenti‐ city: If conditions identified during the audit cause the auditor to believe that a record or document may not be authentic or that terms in a document have been modified but not disclosed to the audit‐ or, the auditor shall investigate further 18, 20, 27, 30, 36–38, 38 Frozen archives (18) + session log (20) enable im‐ mediate re‑hashing; gate job (27) → incoming receipt (30) → public TXIDs (36–37) + di‐ gest‑to‑payload parity (38) allow definitive au‐ thenticity checks without raw‑data disclosure. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 35 of 42 AUDITLOG.AI0035CME Clause; Page; Paragraph; Requirement Dossier Evidence # Relevance to AuditLog.AI Software ¶29(a)(iv); p.13-14; Requirements; Management Override Discussion: Engagement team discus‐ sion shall include... An exchange of ideas about... How management may be able to override con‐ trols 3, 21, 22–26, 33–39, 24 Controls require institutional login (21) and Ed25519 e‑signature (3, 22); optional Layer‑3 hu‐ man‑activity check can be enabled per policy (23-26). Fail‑closed event (24) shows override at‐ tempts are blocked. Ledger state machine (33–39) prevents out‑of‑sequence actions. ¶32(a)(i); p.14; Requirements; Culture and Integ‐ rity: Obtain an understanding of: How manage‐ ment's oversight responsibilities are carried out, such as the entity's culture and management's commitment to integrity and ethical values 42, 43, 33–39, 20 QMS and pre‑deployment audit (42) + live runtime integrity provenance (43) demonstrate gov‐ ernance; append‑only dual-ledgers (33–39) and session log (20) evidence traceable accountability and oversight posture. ¶42; p.17; Requirements; Respond to Assessed Risks: The auditor shall design and implement overall responses to address the assessed risks of material misstatement due to fraud at the financial statement level 6–7, 12–14, 18, 20, 33–39, 6A, 7A Risk responses are embedded as controls: dual‑hashing + OTS (6–7), VALIS enforcement and post‑verification record (12–14), frozen archives (18), linked session log (20), dual‑ledger anchoring (33–39), and periodic reproducibility audits (6A, 7A). ¶48-49; p.18; Requirements; Journal Entry Test‐ ing: The auditor shall design and perform audit procedures to test the appropriateness of journal entries recorded in the general ledger and other adjustments made in the preparation of the financial statements 4 & 8, 6, 20, 38 For financial‑audit contexts, manifest‑to‑hash parity (4, 8, 6) and session digest matching (20, 38) let auditors test that exported journals/adjust‐ ments used in procedures are complete, unaltered, and tied to a specific, timestamped evidence set. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 36 of 42 AUDITLOG.AI0036CME Clause; Page; Paragraph; Requirement Dossier Evidence # Relevance to AuditLog.AI Software ¶52; p.19; Significant Transactions Outside the Normal Course of Business or Otherwise Appear Unusual; Business Rationale Evaluation: For significant transactions that are outside the normal course of business or otherwise appear unusual, the auditor shall evaluate whether the business rationale (or the lack thereof) suggests they may have been entered into to engage in fraud‐ ulent financial reporting or to conceal misap‐ propriation of assets. 20, 33–37 Session metadata (20) captures timing/meaning and links to prior anchors; dual-ledger state history + public TXID/block height (33–37) provides inde‐ pendent timing/provenance to evaluate rationale and detect concealment via after‑the‑fact edits. ¶68; p.22-23; Requirements; Documentation: The auditor shall include in the audit documentation... The significant decisions reached during the en‐ gagement team discussion... The identified and assessed risks of material misstatement due to fraud... The overall responses to the assessed risks of material misstatement due to fraud... The nature, timing and extent of the audit procedures performed... The results of the audit procedures 20, 33–39, 41, 6A, 7A Session log (20) + dual-ledger timeline (33–39) document nature/timing/results; final anchor event (41) closes the record; reproducibility evidence (6A, 7A) documents additional procedures and conclusions related to fraud‑risk responses. C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 37 of 42 AUDITLOG.AI0037CME Annex VI — Dossier Evidence Index (Execution Evidence Cross-Reference) This annex consolidates all primary runtime evidence numbers referenced across regulatory clauses (FDA, EMA, TGA, PCAOB, ISA). All files are contained within the AuditLog.AI — Runtime Execution and System Validation Evidence Dossier (v27 Oct 2025). Evidence groups are organized by functional sequence — from pre-execution environment validation to final blockchain anchoring and reproducibility veri‐ fication. I. Zero-Custody Environment Verification 2. PRE Screenshot — AuditLog.AI Folder View Demonstrates pre-execution environment cleanliness and zero-custody architecture. Confirms no pre-existing derivatives prior to run. 27. Gate Job (Hashes Only) Shows cryptographic handoff job containing only SHA-256 and RIPEMD-160 digests— no user data transferred. 30. AuditLog.AI Incoming Anchor Job Receipt Receipt confirming secure zero-custody transfer and queueing of incoming anchor job. 33. Receipt Broadcast View Broadcast confirmation from AuditLog.AI server, showing TXID issuance and state machine transition (QUEUE_TICK → BROADCAST_QUEUED). II. System Validation and Pre/Post Execution Integrity 4. Pre-Hasher Execution State Audit Baseline inventory capture verifying controlled environment before hashing begins. 8. Post-Hasher Verification Audit Confirms 1:1 parity between manifest entries and generated digests; validates completeness of processing. 15. Pre-Execution Mandatory Screenshot (User-Held) System-captured pre-run record showing system state and timestamps prior to execu‐ tion. 16. Post-Execution Mandatory Screenshot (User-Held) Post-run confirmation within Δ=28 s threshold proving consistent, validated perform‐ ance. 42. AuditLog.AI Quality Management System (QMS) and Pre-Public Deployment Audit Log Documents SDLC and validation activities under Sentinel QMS prior to production re‐ lease. • • • • • • • • • C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 38 of 42 AUDITLOG.AI0038CME 43. AuditLog.AI Live Runtime Execution Audit Infrastructure Integrity Proven‐ ance Demonstrates live audit infrastructure reproducibility and integrity under runtime obser‐ vation. III. Cryptographic Proof Generation and Time Attestation 6. Dual-Hasher Runtime Execution Execution of SHA-256 + RIPEMD-160 dual-hash generation ensuring tamper-evid‐ ence. 6A. SHA-256 / RIPEMD-160 Reproducibility & Amplification Audits Independent reproducibility campaigns confirming deterministic hash parity across and amplification to 30,000+ evidence files. 7. OpenTimestamps (OTS) Runtime Execution Creation of decentralized timestamp proofs anchored to Bitcoin mainnet. 7A. OTS Explanation & Reproducibility Audits Validation of OTS proof reproducibility and independent verification using public tools. IV. Human Verification and Audit Log Authorization 12. VALIS Audit Verification Initial Prompt System prompt requesting human approval before audit log creation. 13. VALIS Audit Verification Output (Log per Folder) Generated audit verification logs for each folder, showing enforced VALIS template and compliance flags. 14. AuditLog Generated Post-Verification Automatically compiled audit log after human confirmation, recording approver identity, UTC time, and signature meaning. 17. VALIS Audit Log per Folder Authorized Authorized, frozen audit log files post-validation, marked human_verified = true. 20. Session Log View and Prior Session Anchor Audit Log Reference Composite session manifest linking all prior audit logs and their blockchain TXID, establishing chain-of-custody lineage. V. Immutable Archival & Anchoring Evidence 18. Frozen VALIS Audit Logs Demonstrates read-only and immutability protections applied to all validated audit logs. 36. Anchored Transaction – Public Explorer View #1 Public blockchain confirmation showing TXID and payload parity on Bitcoin mainnet. 37. Anchored Transaction – Public Explorer View #2 Independent explorer cross-verification (mempool.space / blockchain.com). • • • • • • • • • • • • • C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 39 of 42 AUDITLOG.AI0039CME 38. Session Log Digest Match Validation Confirms hash equivalence between frozen session log and on-chain payload (digest parity). 39. Dual-Ledger Consistency Verification Demonstrates atomic append across user ledger and master AMPLIFY_LEDGER (no divergence). 41. AuditLogger – Final Anchor Event Captures mandatory audit log entry registering the anchor event. VI. Human Signature Gate & Authorization Workflow 3. Human Verifier — Distinct e-Signature Identification Component 1 of 2 Human verifier interface executing Ed25519 personal signature bound to a unique meta_id. 21. HMAC (Layer 2) + Reviewer Login Institutional authentication verifying organizational authority and session origin. 22. e-Signature Gate (Web UI Access) Multi-layer signing interface combining personal signature, institutional HMAC, and non-biometric vector screen. 23. Signature Validation (FAIL Test) Negative-control showing system rejection of invalid or automated signature. 24. Gate Job Not Generated by False Signature Demonstrates that failed signature attempts do not generate anchor jobs. 25. Signature Validation (PASS Test) Positive-control confirming valid human signature passing multi-layer verification. 26. AuditLog.AI Pass Signature Registered – Gate Job Created Record of successful gate job creation following human authorization. 28 A & B. Final Human Authorization Blockchain Anchoring Final step showing human-approved signature event resulting in blockchain anchoring via AuditLog.AI broadcast. • • • • • • • • • • • C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 40 of 42 AUDITLOG.AI0040CME Annex VII – Public Verification Provenance Evidence citations originates from the AuditLog.AI — Runtime Execution and System Validation Evidence Dossier published 27 October 2025. Provenance File Reference: Audit‐ Log.AI_Runtime_Execution_and_System_Validation_Evidence_Dossier_FINAL_METADATA ___20251027T231047Z.pdf SHA-256: fc46851b4854ca45798b741c0fb001eaa0945eb73c98795900c87939acb30d8a RIPEMD-160: b0c8b2223eab705cac6bf7801b64945f7ed47022 OTS File: Audit‐ Log.AI_Runtime_Execution_and_System_Validation_Evidence_Dossier_FINAL_METADATA ___20251027T231047Z.pdf.hash.ots OP_RETURN Anchor: ORDINAL11|b0c8b2223eab705cac6bf7801b64945f7ed47022| fc46851b | Transaction ID: a09523a5e311d5e5213cba7cc39ec3a274aa1cc017be369c‐ fa5786c3677a1540 | Block: 921107 Ordinal Anchor: ORDINAL11|b0c8b2223eab705cac6bf7801b64945f7ed47022|fc46851b | Transaction ID: 6754818e57d5dcc16a7fccdb1d36b‐ b213cd39ae4a180e17923387738f38a3f41 | Block: 921109 Session_log: ses‐ sion_log_AuditLogAI.REG.GlobalSubmission.v4059_20251027T231229.358107Z.json SHA-256: db4451a879e62a1e34a14a6052a442172be6c8798aff163a9564a31beb768d21 RIPEMD-160: d51e9af05a7b8f32db2f85ab0a76ea7e71cadede Session OTS File: ses‐ sion_log_AuditLogAI.REG.GlobalSubmission.v4059_20251027T231229.358107Z.hash.ot s Session OP_RETURN Anchor: SENTINEL|SESSION|d51e9af05a7b8f32db2f85‐ ab0a76ea7e71cadede|db4451a8 Transaction ID: 06028cfbf809665838e437dcad6d01c48d5c4679ebd‐ be045ea12ed4c311c020e Date of Existence (UTC): 2025-10-27T23:14:36Z (TXID broadcast time confirming file existence as of Bitcoin block 921094.) Public Verification References Telles, Fernando. AuditLog.AI — Runtime Execution and System Validation Evidence Dossier End‑to‑End Operational Proof During Regulatory Global Submission. CDA AI Pty Ltd, October 2025. DOI: 10.13140/RG.2.2.28551.25765 Zenodo: 10.5281/zenodo.17460850 • • • • • • • • • • • • • C12 – AuditLog.AI Global Compliance Matrix Globally Harmonized Regulatory Compliance Map | v4.0 | 2025-10-28 Page 41 of 42 AUDITLOG.AI0041CME