Template Fixed before week one

The Scope Document

The Data & Model Audit is sold against an acceptance test, not a vibe. This is that test, published in full so you can read it before you talk to us rather than after we disagree. Bracketed fields are filled per engagement. Everything else is the same for every client.

Fee: $12,000, fixed
Term: 3 weeks to report
Findings committed: 5 qualified
Rejection window: 10 business days

This document sets the scope of the engagement and the standard the work is measured against. Both are fixed as of the start date. Neither side may change them while the engagement runs.

1. The system under audit

The audit covers one system, named in the signed copy: what it does, where its code lives, which datastores and pipelines it reads and writes, and which outputs depend on it. Named precisely enough that a third party could tell whether a given component is inside or outside the boundary.

Anything not named there is out of scope. If the work uncovers a defect in an adjacent system, we tell you it exists, in writing. It does not count as a delivered finding and we do not investigate it under this engagement.

2. What you receive

The report is yours to keep, use, and act on, whether or not we work together afterward.

3. What counts as a qualified finding

A finding counts toward the commitment in section 5 only if it passes all four tests:

4. Severity rubric

Severity describes consequence, not how hard the fix is. A defect that takes an hour to correct can be High. A rewrite can be Low.

Rating Any one of
HIGH A number already shown to a customer, an investor, a regulator, or a counterparty is wrong, or cannot be supported by the underlying data.

The system produces a materially wrong output under conditions that occur in normal operation.

A control that is relied on (a check, a reconciliation job, an alert) does not do what it is believed to do.
MEDIUM A number used internally for decisions is wrong or unsupportable, but has not left the company.

A defect produces wrong output only under conditions that are possible but not routine.

A failure mode is currently undetectable: it has not occurred, and nothing in place would catch it if it did.
LOW The output is correct today, but the practice that produced it will not stay correct: no point-in-time discipline, an undocumented assumption, a silent dependency.

Correctness is not at issue. Cost, latency, or maintainability is.

Rantum assigns severity against this rubric. The rubric does not change during the engagement. Disagreement about a rating is not one of the rejection grounds in section 8: if you disagree with a rating, tell us in writing and your objection is appended to the finding in the delivered report, unedited.

5. How many findings

This engagement commits to five qualified findings.

A clean system is a real result and we will not manufacture findings to reach a number. If fewer than five qualified findings are delivered, you choose one: a $3,000 rebate, or a fourth week against a second system you name, at no additional fee. That remedy exists so that padding the report is never the cheaper option for us.

Findings beyond the fifth are delivered at no additional cost. There is no cap.

6. What we will not do to reach the number

Splitting one defect into several findings, reporting the same root cause in several places, and reporting known-good behavior as a risk all fail section 3 and do not count. If you believe a finding was manufactured this way, ground 1 in section 8 is what to reject it on.

7. Evidence each finding carries

8. Rejecting a finding

You may reject a finding in writing within ten business days of report delivery, on these grounds and only these:

A rejected finding does not count toward the five, and we replace it at no charge within ten business days.

That list is exhaustive. A finding cannot be rejected for being unwelcome, for confirming something you had suspected but never written down, or for reaching a conclusion you would rather it did not. The criteria in sections 3, 4 and 8 are set before the work starts and do not move while it runs: we cannot loosen them to inflate the count, and they cannot be tightened to shrink it.

9. Access and dependencies

The three-week schedule assumes these are in place on the start date: read access to the source repositories and to the datastores the system reads and writes (production or a faithful replica), access to existing documentation, dashboards and monitoring, and a named technical contact who can answer questions within one business day.

Each business day any of those is outstanding after the start date moves the delivery date by one business day. Nothing else changes: the fee, the scope, and the commitment in section 5 all stand. If access is still outstanding ten business days after the start date, either side may pause the engagement and we agree a new start date in writing.

We do not require write access to production.

10. Out of scope

Systems other than the one named in section 1. Implementing the fixes we recommend, which is a separate engagement this one carries no obligation toward. Security or penetration testing. Legal or regulatory opinions. Ongoing monitoring after delivery.

11. Confidentiality

Your code, your data, and the findings are yours and are treated as confidential. We will not name you as a client, quote any figure from your system, or publish anything identifying the engagement without your written permission.

We may reuse generalized, non-identifying lessons: a class of defect, a method, a category of failure, with the client, the product, the sector detail, and all figures removed. If you would prefer we not do even that, the signed copy has a box to say so.

12. Fee and payment

$12,000, fixed, covering everything in section 2. There are no hourly overages, and no additional charge for findings beyond the fifth.

50% on signature, 50% on delivery of the report. Any rebate owed under section 5 is netted against the final payment, which at these terms always covers it.

What a finding looks like in practice

Three severity-rated findings from the standing internal audit of ClearTrace, our own live data product, in the format above.

The system those findings came from

ClearTrace, a live execution-quality benchmark we build and operate. The case study covers what it measures and how, which is the kind of system this document is written to be pointed at.

Questions about a clause?

Better asked now than argued in week three. Tell us which system you would point this at and we will send the scoped version.

Scope an audit