You read a RECERTIFICATION PACKET -- one vendor's CURRENT assurance report and, usually, the PRIOR YEAR'S report for the same vendor -- and return a REVIEWER'S COMPARISON WORKSHEET: what MOVED between the two years. You return JSON and nothing else.
You are preparing a worksheet for a qualified reviewer. You never recertify a vendor, never approve, suspend, terminate or renew anything, never raise a finding and never clear one. Your job is to say what the two reports state, apply the rulebook given below, and NAME THE CONTROLS THE TWO REPORTS DO NOT LET YOU COMPARE.
RULES, in order of importance:
1. ONE ROW PER CONTROL IN THE UNION OF THE TWO REPORTS, AND NO OTHERS. A control tested in either year gets exactly ONE row. Never return the same control twice.
2. THE CANDIDATE ID SPLIT BELOW IS PURE CODE AND CAN BE WRONG. If the service auditor changed, the new firm renumbered everything: a control tested in BOTH years appears once in the current-only list and once in the prior-only list, and it is ONE row. Read the DESCRIPTIONS. When they describe the same control, return one row whose `control_ref` is the CURRENT id and whose `prior_ref` is the PRIOR id.
3. `control_ref` IS THE CURRENT REPORT'S ID where the control appears this year, and the PRIOR report's id where it does not. `prior_ref` is the prior id ONLY when it differs from `control_ref`; otherwise it is the literal string `none`.
4. AN EXCEPTION RECORDED IN BOTH YEARS IS `repeat_exception`, NEVER `new_exception`. A whole remediation cycle has passed and the control is still failing. This is the call a reader of one report cannot make, and getting it wrong is the most expensive mistake on this worksheet.
5. A CONTROL ABSENT THIS YEAR BECAUSE THE SCOPE SHRANK IS NOT A DROPPED CONTROL. The current report's header lists the domains it excludes. A prior control in an excluded domain is `comparability` 'scope_withdrawn', which the rulebook turns into `not_comparable`. Its absence says nothing about whether the vendor still operates it.
6. THE SAME ID CAN NAME TWO DIFFERENT CONTROLS. Compare the two DESCRIPTIONS before you compare the two results. Where they are materially different controls and no other description in the other report matches, `comparability` is 'id_reused' and the row is `not_comparable`.
7. A NOTE IN THE PRIOR REPORT THAT SOMETHING WAS 'remediated after the period end' SETTLES NOTHING. Only what the CURRENT report records decides this year's state.
8. `change_kind` IS DECIDED ONLY BY THE RULEBOOK BELOW, from `prior_state`, `current_state` and `comparability`. Work through the eight steps IN ORDER and STOP at the first that fires.
9. `opinion_movement` IS DECIDED ONLY BY THE RULEBOOK, from `prior_report_present`, `prior_opinion` and `current_opinion`. It is asked once per packet and is independent of every control row.
10. `not_comparable` IS A REAL ANSWER AND YOU ARE EXPECTED TO USE IT. A worksheet that never reaches for it is guessing, and a change recorded confidently on two reports that do not join is a finding nobody can check.
11. Copy every control id verbatim from the packet. Use the exact allowed value for every field that lists them, and return every field for every row.
RECERTIFICATION COMPARISON RULEBOOK (the authority for `change_kind` and `opinion_movement`; this is an ILLUSTRATIVE rulebook written for this kit, and it reproduces no assurance standard, attestation framework, regulator's third-party risk guidance or firm recertification procedure)
WHAT IS ON THE WORKSHEET
- ONE ROW PER CONTROL IN THE UNION OF THE TWO REPORTS. A control tested in either year gets exactly one row, never two.
- `control_ref` is the CURRENT report's control id when the control appears in the current report, and the PRIOR report's id when it does not. That is the row's key and it is unique within a packet.
- `prior_ref` is the PRIOR report's id for the same control, and only when that id DIFFERS from `control_ref`. Otherwise it is the literal string `none`.
- A control the two reports number differently is ONE row, not an addition and a removal. Resolving that is the job.
- Nothing here recertifies, approves, suspends, terminates or renews anything. It is a reviewer's comparison worksheet.
CONTROL DOMAINS
access who can reach the service and how that is granted, reviewed and withdrawn
change_management how changes to the service are approved, reviewed and released
operations how the service is run day to day - processing, incidents, reconciliation, capacity
subservice what the vendor's own suppliers do, and what the vendor tells its customers to do
physical physical access to the site the service runs from
resilience backup, restore and continuity
THE STATED FACTS, read off the two reports for every control
prior_state:
clean the prior report tested this control and recorded no exception
exception the prior report tested this control and recorded at least one exception
not_tested the prior report lists this control and records that it was not tested in the period
absent the prior report does not carry this control at all
current_state:
clean the current report tested this control and recorded no exception
exception the current report tested this control and recorded at least one exception
not_tested the current report lists this control and records that it was not tested in the period
absent the current report does not carry this control at all
comparability:
comparable the two reports can be read against each other for this control
scope_withdrawn the control sits in a domain the CURRENT report's header excludes from its scope, so its absence this year says nothing about the vendor
no_prior_report no prior report is held for this vendor, so there is nothing to read the current one against
id_reused the same control id names a materially DIFFERENT control in the two reports, and no description in the other report matches it, so the two ends do not join
THE CHANGE CALL -- work through IN ORDER, stop at the first that fires
1. If `comparability` is anything other than `comparable`, the answer is `not_comparable`. Stop. Nothing below is asked.
2. If `prior_state` is `absent`, the answer is `control_added`.
3. If `current_state` is `absent`, the answer is `control_dropped`.
4. If `current_state` is `exception` AND `prior_state` is `exception`, the answer is `repeat_exception`.
5. If `current_state` is `exception`, the answer is `new_exception`.
6. If `current_state` is `not_tested` AND `prior_state` is not `not_tested`, the answer is `testing_withdrawn`.
7. If `prior_state` is `exception` AND `current_state` is `clean`, the answer is `exception_cleared`.
8. Otherwise the answer is `no_change`.
WHAT EACH CHANGE KIND MEANS
no_change the control was tested both years and the result did not move
new_exception an exception this year where the prior report recorded none
repeat_exception an exception this year AND last year - the one a single-year read cannot tell from a new one
exception_cleared an exception last year, clean this year
control_dropped the prior report tested it, the current report does not carry it, and the scope did not change to explain that
control_added the current report carries it and the prior report did not
testing_withdrawn the control is still listed this year and the report records that it was not tested
not_comparable the two ends do not join - see `comparability` for which of the three reasons
THE OPINION CALL -- one per packet, independent of every control call
opinion rank, worst last: unqualified=0, qualified=1, adverse=2, disclaimer=3
1. If `prior_report_present` is `no`, the answer is `no_prior_report`. Stop.
2. If either opinion is `none_stated` or `absent`, the answer is `not_comparable`. Stop.
3. If the two opinions rank equal, the answer is `unchanged`.
4. If the current opinion ranks HIGHER than the prior one, the answer is `worsened`.
5. Otherwise the answer is `improved`.
A `disclaimer` ranks worst of the four: an auditor who could not form an opinion has told you less than one who formed a bad one.
WHY `not_comparable` IS A REAL ANSWER
A recertification worksheet exists to say what MOVED. `not_comparable` says the paperwork does not let you tell, which is a finding about the reports and not a gap in the answer. A row filled in confidently where the two reports do not join is the expensive mistake here: it puts a change on a reviewer's list that nothing in the file supports, or - worse - it records `no_change` for a control nobody looked at.
CANDIDATE ALIGNMENT BY CONTROL ID (pure code, and it can be WRONG -- see below)
ids in BOTH reports: (none)
ids in the CURRENT report only: C-009, C-012, C-013, C-015, C-017, C-019, C-020, C-023, C-024, C-026
ids in the PRIOR report only: AC-01, CM-01, OP-01, OP-02, PH-01, PH-02, RS-01, RS-02, SS-01, SS-02
This split was made by matching id strings and NOTHING ELSE. It is a starting point, not an answer.
* If the service auditor changed, the new firm renumbered everything: a control tested in both years appears once in each of the two 'only' lists, and the DESCRIPTIONS are what tell you they are one control.
* An id in BOTH lists can still name two DIFFERENT controls. Read the two descriptions before you compare the two results.
Return these:
- packet_id (string) -- the packet reference printed in the Recertification Request section, verbatim
- vendor_ref (string) -- the vendor reference printed in the Recertification Request section, verbatim
- prior_report_present (string) one of: yes, no -- does this packet carry a PRIOR report at all
- auditor_changed (string) one of: yes, no, not_determined -- do the two report headers name DIFFERENT service auditors; not_determined when there is no prior report
- scope_changed (string) one of: yes, no, not_determined -- does the CURRENT report's header exclude a domain the prior report did not exclude; not_determined when there is no prior report
- current_opinion (string) one of: unqualified, qualified, adverse, disclaimer, none_stated, absent -- the opinion on operating effectiveness in the CURRENT report header
- prior_opinion (string) one of: unqualified, qualified, adverse, disclaimer, none_stated, absent -- the opinion on operating effectiveness in the PRIOR report header; `absent` when there is no prior report
- opinion_movement (string) one of: unchanged, worsened, improved, not_comparable, no_prior_report -- THE OPINION CALL. Decided ONLY by the rulebook, from the two opinions above
- controls (array of objects) -- one object per control in the UNION of the two reports, each carrying:
- control_ref (string) -- the CURRENT report's control id where the control appears this year, otherwise the PRIOR report's id. Copy it verbatim. It is the row key and must be unique in the packet
- prior_ref (string) -- the PRIOR report's id for the SAME control, and only when it differs from control_ref. Otherwise the literal string `none`
- domain (string) one of: access, change_management, operations, subservice, physical, resilience -- the domain the CURRENT report gives this control, or the PRIOR report's where the control is not in the current report
- prior_state (string) one of: clean, exception, not_tested, absent -- what the PRIOR report records for this control
- current_state (string) one of: clean, exception, not_tested, absent -- what the CURRENT report records for this control
- comparability (string) one of: comparable, scope_withdrawn, no_prior_report, id_reused -- whether the two reports can be read against each other for THIS control
- change_kind (string) one of: no_change, new_exception, repeat_exception, exception_cleared, control_dropped, control_added, testing_withdrawn, not_comparable -- THE CHANGE CALL. Decided ONLY by the rulebook, from prior_state, current_state and comparability
Return a JSON object with exactly these top-level keys: packet_id, vendor_ref, prior_report_present, auditor_changed, scope_changed, current_opinion, prior_opinion, opinion_movement, controls
`controls` is an array. Return it empty only if neither report in this packet carries a single control.
RECERTIFICATION PACKET
----------------------
Synthetic Record
----------------
This recertification packet is SYNTHETIC and was generated for a public demonstration kit.
The vendor, the service, the audit firms, the people, the sites, the contract, the fee and
every control and exception in it are invented. No real third party, service auditor,
assurance report or recertification file is reproduced or referred to. The criteria set the
reports cite (ARC-4) does not exist. Nothing here is an assurance opinion, a recertification
decision or third-party risk advice.
Recertification Request
-----------------------
PKT-0014
Vendor reference: VEN-4194
Vendor: Slape Hill Contact Centre
Service in scope: outsourced inbound servicing
Recertification due: 9 December 2026
Prepared for: Third-Party Risk Management
Prior assurance report held: yes
Current Report Header
---------------------
Report period: 1 October 2025 to 30 September 2026
Service auditor: Vantry & Co
Report type: Type II
Criteria set: ARC-4 (illustrative - see the banner above)
Opinion on operating effectiveness: unqualified
Domains excluded from the scope of this report: none
Subservice organisations carved out: none
Current Control C-009
---------------------
Domain: access
Description: A quarterly recertification of user access to outsourced inbound servicing is performed and removals are evidenced.
Test result: EXCEPTION NOTED
Exception detail: 2 selected instances were completed after the stated deadline, the longest by 11 working days.
Current Control C-012
---------------------
Domain: resilience
Description: Backup of outsourced inbound servicing runs to a defined schedule and restoration is tested with evidence retained.
Test result: EXCEPTION NOTED
Exception detail: The control operated for 7 of the 12 months in the period; no evidence was retained for the remainder.
Current Control C-013
---------------------
Domain: change_management
Description: Every code release to outsourced inbound servicing carries evidence of a second engineer's review.
Test result: EXCEPTION NOTED
Exception detail: 3 of 38 items sampled for the period were not evidenced.
Current Control C-015
---------------------
Domain: access
Description: Access to outsourced inbound servicing is provisioned only where the service owner has recorded an approval.
Test result: not tested in the period
Exception detail: not applicable - the service auditor records that this control was not tested in the period.
Current Control C-017
---------------------
Domain: subservice
Description: Third-party assurance reports covering the suppliers behind outsourced inbound servicing are collected and reviewed each year.
Test result: EXCEPTION NOTED
Exception detail: 2 selected instances were completed after the stated deadline, the longest by 13 working days.
Current Control C-019
---------------------
Domain: operations
Description: Utilisation of outsourced inbound servicing is tracked against defined thresholds and reported each month.
Test result: not tested in the period
Exception detail: not applicable - the service auditor records that this control was not tested in the period.
Current Control C-020
---------------------
Domain: operations
Description: Scheduled processing for outsourced inbound servicing is monitored, and any failed job is restarted under a documented instruction.
Test result: clean - no exceptions noted
Exception detail: none recorded.
Current Control C-023
---------------------
Domain: change_management
Description: The author of a change to outsourced inbound servicing may not be the person who deploys it.
Test result: EXCEPTION NOTED
Exception detail: The control operated for 7 of the 12 months in the period; no evidence was retained for the remainder.
Current Control C-024
---------------------
Domain: subservice
Description: Customers of outsourced inbound servicing are notified in writing of the controls they are expected to operate themselves.
Test result: clean - no exceptions noted
Exception detail: none recorded.
Current Control C-026
---------------------
Domain: subservice
Description: Supplier performance against the agreed outsourced inbound servicing service levels is examined quarterly.
Test result: EXCEPTION NOTED
Exception detail: Evidence was produced for 8 of 9 selections; the remainder could not be located.
Prior Report Header
-------------------
Report period: 1 October 2024 to 30 September 2025
Service auditor: Sarn Ferris Assurance
Report type: Type II
Criteria set: ARC-4 (illustrative - see the banner above)
Opinion on operating effectiveness: qualified
Domains excluded from the scope of this report: none
Subservice organisations carved out: none
Prior Control AC-01
-------------------
Domain: access
Description: Logical access to outsourced inbound servicing is granted only on documented approval from the service owner.
Test result: EXCEPTION NOTED
Exception detail: 1 of 32 items sampled for the period were not evidenced. The service organisation states that the matter was remediated after the period end.
Prior Control CM-01
-------------------
Domain: change_management
Description: Code released to outsourced inbound servicing is peer reviewed and the review is evidenced.
Test result: EXCEPTION NOTED
Exception detail: The supporting register was not maintained for 1 of the 4 quarters in the period.
Prior Control OP-01
-------------------
Domain: operations
Description: Incidents affecting outsourced inbound servicing are logged, categorised and closed against a stated resolution.
Test result: EXCEPTION NOTED
Exception detail: 2 selected instances were completed after the stated deadline, the longest by 9 working days. The service organisation states that the matter was remediated after the period end.
Prior Control OP-02
-------------------
Domain: operations
Description: Capacity for outsourced inbound servicing is monitored against stated thresholds and reported monthly.
Test result: not tested in the period
Exception detail: not applicable - the service auditor records that this control was not tested in the period.
Prior Control PH-01
-------------------
Domain: physical
Description: Visitors to the Denholm processing floor are escorted throughout and the escort is recorded.
Test result: EXCEPTION NOTED
Exception detail: The control operated for 7 of the 12 months in the period; no evidence was retained for the remainder. The service organisation states that the matter was remediated after the period end.
Prior Control PH-02
-------------------
Domain: physical
Description: Physical access to the Denholm processing floor is granted on documented approval and logged on entry.
Test result: EXCEPTION NOTED
Exception detail: Evidence was produced for 18 of 19 selections; the remainder could not be located. The service organisation states that the matter was remediated after the period end.
Prior Control RS-01
-------------------
Domain: resilience
Description: Backups of outsourced inbound servicing are taken to a stated schedule and restore tests are evidenced.
Test result: EXCEPTION NOTED
Exception detail: 4 of 39 items sampled for the period were not evidenced. The service organisation states that the matter was remediated after the period end.
Prior Control RS-02
-------------------
Domain: resilience
Description: Recovery time objectives for outsourced inbound servicing are stated and measured against actual recovery.
Test result: clean - no exceptions noted
Exception detail: none recorded.
Prior Control SS-01
-------------------
Domain: subservice
Description: Assurance reports from subservice organisations supporting outsourced inbound servicing are obtained and reviewed annually.
Test result: EXCEPTION NOTED
Exception detail: The supporting register was not maintained for 1 of the 4 quarters in the period.
Prior Control SS-02
-------------------
Domain: subservice
Description: Subservice organisation performance against the outsourced inbound servicing service levels is reviewed each quarter.
Test result: clean - no exceptions noted
Exception detail: none recorded.
Packet Notes
------------
Assembled by the third-party risk team for the recertification file. The reviewer is asked to read the two reports against each other and record what moved: the opinion, any exception that is new, any exception that has now run for a second cycle, and any control the current report no longer covers. The service auditor changed between the two periods and the new firm uses its own control numbering, so the two reports do not line up by control id. Nothing in this packet is a recertification decision; the recertification is the risk team's, taken on the whole file.