SHEET 07GOVERNANCE · ISO/SAE 21434 CL.5

Governance you can
hand to an auditor.

Compliance dossiers for ISO/SAE 21434, UN R155, GB 44495-2024† and EU CRA are assembled from the item definitions, TARA and risk-treatment evidence already in the project — every approval and mutation sealed into a tamper-evident audit chain. Nothing is retyped, and nothing is taken on the reviewer's word.

See a compliance report POLICY · CATALOGS · AUTOMATIONS · ORG RULES
Governance status — computed
READINESS ISO 21434 11/18 WP · R155 gap ×2
APPROVALS 3 pending four-eyes · self-approve BLOCKED
AUDIT CHAIN HMAC ok · 0 gaps
LAST EXPORT HTML+PDF · 214 events sealed
POLICY GATE safety↔security ENFORCED
DOSSIER gap-blocked · 2 sections missing
STATION 1 · POLICY & CATALOGS

Policy, catalogs
& org rules.

Organization regulations and project policy — including the ISO 26262↔CSMS safety-security coupling gate — decide which controls and review gates apply before a risk decision counts as closed. Controls, threats and requirements live in governed catalogs (referenced, not copied), and automations enforce the gates and assemble evidence without manual steps.

CATALOGS → controls · threats · reqs
AUTOMATIONS → gates · evidence
ORG RULES → regulations per org
authored work-product body ← INPUT
second reviewer required ← SEALED
self-approval rejected ← SERVER
STATION 2 · APPROVE

Four-eyes,
or it doesn't count.

Sensitive changes — an authored work-product, an official-template publish, a CAL determination — require a second reviewer. The server rejects self-approval outright; the sealed approval, not a status field, is what downstream evidence is verified against.

ThreatZ Policy Manager — organization governance policies and gates that decide which controls and reviews apply per project.

BREAK ANY LINK → EVERY DOWNSTREAM CLAIM RE-FLAGS. AUTOMATICALLY.

STATION 3 · RECORD

A tamper-evident
audit chain.

Every mutation — generate, share, approve, revoke, rotate — is sealed into an insert-only, HMAC-chained, per-tenant-year audit log. Nothing can be edited after the fact; a GDPR erasure pseudonymizes the actor without breaking the chain.

SEALS → insert-only · HMAC chain
SCOPE → per-tenant-year log
EXPORT → auditor-ready event trail
item def · TARA · risk · V&V · SBOM ← PULLS
OEM & Tier-1 variants held apart ← BOUNDARY
PDF · HTML · JSON ← DOSSIER
STATION 4 · PROVE

Dossiers assembled,
not authored.

Readiness-gated generation pulls item definition, TARA, risk treatment, V&V and SBOM evidence straight into ISO/SAE 21434, UN R155, GB 44495-2024† and EU CRA dossiers — OEM type-approval and Tier-1 scoped-evidence variants held apart by a hard query-layer boundary, never blended.

TITLEGOVERNANCE — POLICY, APPROVAL & AUDIT EVIDENCE
STANDARDISO 21434 CL.5 · R155
FORMATSPDF · HTML · JSON
REVG-1.0