# Sample conformance clause — illustrative only

Illustration for an Ariesnet engagement; hand-authored sample language, not legal advice
and not a CoreModels output. The wording an engagement actually carries is drafted with
the customer's counsel and their named control owner.

https://ariesnet.com/resources/governed-definition-end-to-end

---

## 1. Scope

This clause applies to the Core Model export in force between the parties, identified by
its project name and schema version, together with the element versions that export
carries. A new export replaces the previous one for the purposes of this clause only when
it is recorded in the change log under section 5. Renders produced from the export —
JSON Schema, ShEx, SQL views, graph projections, agent tool schemas — are in scope as
renders of that version; nothing outside the named export is governed by this clause.

## 2. Boundary behaviour

Refuse is the default. Where a request resolves to a mapping that is not agreed in the
Core Model export in force, the boundary refuses the answer and records the refusal.

Warn may be enabled only for non-binding internal use. Where warn is enabled, the answer
is returned labelled non-authoritative, and the label travels with the answer to every
consumer of it. Warn is never enabled for an answer that leaves the customer's control,
enters a filing, or is relied on by a third party.

The configuration that sets refuse or warn — including the allowlist of mappings for
which warn is permitted — is signed by the customer's named control owner. It is not set
by a vendor default, and it is not changed by a merge.

## 3. Record

Every refuse or warn decision is recorded, and each record carries the fields named in
the auditor FAQ, verbatim from that record: who approved the mapping and when, the
timestamped freeze record tied to the contested mapping id, who ran the check, the UTC
timestamp, the Core Model project with its schema version and the element version in
force, the ShEx shape and the mapping it failed, and the answer that was refused or
warned.

For a given contract version and mapping, the same input produces the same refuse or the
same warn every time. A generated answer is not reproducible word for word; the boundary
decision is what this clause makes auditable.

## 4. Retention

Records under section 3 are retained for the period set in the engagement letter,
alongside the customer's other audit artefacts, and are the customer's on exit in the
formats in which they were written.

## 5. Change

A mapping changes by the freeze procedure: the owner of each schema agrees the mapping in
the Core Model, and that agreement is the freeze. The change log records who changed what
and when, and travels with the export. Until a contested mapping is frozen, section 2
governs what the boundary does with a request that depends on it.
