Control gap · CPS 230
You cannot show an auditor what your AI agents did.
Under CPS 230 you owe evidence of how a critical operation ran, including the parts an automated agent ran on your behalf. The records those agents leave were built for debugging. They are not signed, not sequenced, and not checkable by anyone outside the system that wrote them.
What NOMARK is
NOMARK is an open evidence protocol and verification toolkit for AI agent activity, built in Australia for APRA-regulated investment managers. Agents emit signed, sequenced records; anyone — your auditor included — can verify the stream offline, without NOMARK present.
Why CPS 230 reaches the agentEvidence pipeline
01–0501
Agent action
An agent acts inside a governed operation.
02
Signed record
The action is written as a signed, sequenced record.
03
Chained stream
Records hash-chain into a tamper-evident stream.
04
Independent verifier
Built from source. Runs offline, vendor absent.
05
Assessor verdict
PASS or FAIL. Evidence, not assertion.
Refusal is the output
Verify an evidence stream yourself.
The verification exercise runs offline, on a machine you control. It checks a set of evidence streams and fails when a tampered or truncated stream is not rejected. There is no account to create.
The kit's shipped streams and the verdicts the verifier must produce. A negative stream that verifies is a failed run.
An assessment is answered with artifacts.
An assessor asks three things about an automated control. Which actions ran, on whose authority, and what stopped the actions that should not have run. A console owned by the system under review answers none of them, because the reviewer has to trust the thing being reviewed.
CPS 234 asks the same question of access and change. A control you cannot evidence is a control you cannot claim.
The question arrives in a due diligence review.
An institutional client sends an operational due diligence questionnaire. One line asks which steps in the investment process are performed or assisted by automated agents, and how that is evidenced. The answer available today is a description of the process and a screenshot.
A description passes the first review. The second one asks for the record behind it.
Most consoles assert.
NOMARK verifies.
Most vendors demand trust.
NOMARK ships the verifier.
Most claims are retyped.
NOMARK's are derived.
The architecture is the proof.
The evidence format is an open wire protocol, and the verifier is independent of the system that produced the records.
SOLUTION.md
Read the protocolThe verification kit is built from source in this repository, so an auditor can run it without the vendor present.
standards/policy-packs/tools/build-auditor-kit.cjs
See the verification kitThe vendor assessment pack is written into the repository, including its security addendum and its open items.
docs/vendor-assessment/
Read the assessment packThis site cannot overstate
Derived at buildThis site is built from the NOMARK repository. Every figure is computed from source at build time. Capabilities that exist only as specification are labelled. A claim that cannot be derived fails the build.
What is unfinished says so, with the count. Read the current gaps — including what the vendor pack does not yet publish — on the Trust centre.
Map the gap before an assessor does.
The control-gap briefing: 45 minutes with your risk or investment-operations lead. Where agent activity touches your CPS 230 critical operations, what evidence exists today, and what an assessor will ask for. You leave with the gap mapped, whether or not you go further.
The fastest way to reach us is email. A short note describing the operation is more useful than a meeting request.