Evidence first.
Human decision.
The AI Change Evidence Engine helps a reviewer understand one completed material change without reconstructing its evidence across disconnected systems.
It does not approve the change, replace source systems, prove control effectiveness, or determine APRA compliance.From source event to reviewer trace
- 01
Observe
Receive a narrowly scoped event from an approved read-only source and retain only the metadata needed for review.
- 02
Normalise
Map source-specific fields into one evidence model without replacing the upstream system of record.
- 03
Correlate
Connect records using explicit change, commit, workflow, artefact and deployment identifiers.
- 04
Evaluate
Apply a versioned, bank-defined profile. Report matched, incomplete or attention—not compliance.
- 05
Present
Give the named reviewer provenance, limitations and a digest-bearing export for a human decision.
Visible provenance and explicit rules
- Every matched record names its source and source reference.
- Direct, derived and asserted lineage are distinguished.
- Requirements and accepted statuses are versioned data.
- Missing evidence stays unresolved and visible.
- The representative export has a reproducible content digest.
Authority remains outside the product
- Source systems remain authoritative.
- Delegated authority must be confirmed by the bank.
- A successful tool result is not automatically an effective control.
- A digest detects modification; it does not authenticate the source.
- The final decision belongs to a named human reviewer.
What exists now—and what does not
Representative case and deterministic profile evaluation
Verified ingress, multi-fact normalisation, exact correlation and live read model
Release cases, evidence keys, deliveries and evaluation snapshots
Deterministic SHA-256 digest; deliberately unsigned
Representative records only; no live customer connection
Not represented as a current capability
The live GitHub path is implemented. Customer use would still require approved connections, customer-defined policies, identity and access controls, operational monitoring and production key management.
Learn how this was engineered →