Registry CTRL-REG-2026.03.1
12 effective-dated controls. Each one carries a version, an effective interval, an owner, a source class, its required inputs, and named test cases. This is a read-only inspectable registry, not an admin builder: it exists to prove governance, not to let a demo visitor edit policy.
| Control | Version | Effective | Owner | Source class | Severity mapping | Tests | On flagship | Detail |
|---|---|---|---|---|---|---|---|---|
| DATA-FRESH-001 Material source freshness All tax-managed equity SMA rebalance cases | v1.4.0 | Jan 01, 2026 → open | Data Steward | Product Assumption | A missing or stale material source blocks the rebalance and suppresses every control that depends on the affected inputs. | 5 | Pass | |
| RECON-HOLD-002 Holdings reconciliation Accounts with a custodian position feed | v2.1.0 | Jan 01, 2026 → open | Data Steward | Product Assumption | An unresolved material difference blocks. An immaterial difference is recorded and warns. | 6 | Warning | |
| TAX-BASIS-003 Cost basis usability on selected sell lots Taxable accounts with proposed sells | v1.3.0 | Jan 01, 2026 → open | Operations Analyst | Product Assumption | Missing basis returns UNKNOWN and blocks tax-sensitive release. | 5 | Pass | |
| MANDATE-RESTRICT-004 Client restriction compliance All accounts with a recorded restriction set | v3.0.0 | Jan 01, 2026 → open | Compliance Officer | Product Assumption | A prohibited proposed exposure is a hard stop. Ambiguous scope requires manual review. | 6 | Pass | |
| WASH-SALE-005 Wash-sale exposure on proposed loss realization Taxable accounts realizing losses | v1.2.0 | Jan 01, 2026 → open | Operations Analyst | Regulatory | A potential match requires documented human review. Incomplete purchase history is reported as a coverage limitation, not a pass. | 6 | Warning | |
| CASH-006 Minimum cash and residual cash sufficiency All accounts with a mandate cash requirement | v1.1.0 | Jan 01, 2026 → open | Portfolio Manager | Product Assumption | A breach of the minimum or a negative residual blocks. | 5 | Pass | |
| CONCENTRATION-007 Post-trade single-name and sector concentration All accounts with concentration limits | v2.0.0 | Jan 01, 2026 → open | Portfolio Manager | Product Assumption | A post-trade breach blocks. A pre-trade breach the rebalance repairs is reported without blocking. | 5 | Pass | |
| MODEL-DEV-008 Post-trade model deviation Direct-indexed equity strategies | v1.5.0 | Jan 01, 2026 → open | Portfolio Manager | Product Assumption | Deviation above the mandate band but inside the strategy tolerance warns without blocking. Beyond the strategy tolerance, or moving away from the model, blocks. | 5 | Warning | |
| GAIN-BUDGET-009 Realized gain budget Taxable accounts with a configured gain budget | v1.2.0 | Jan 01, 2026 → open | Portfolio Manager | Product Assumption | A projected breach requires explicit authorized review before release. | 5 | Pass | |
| APPROVAL-010 Required human authorization All rebalance cases | v2.2.0 | Jan 01, 2026 → open | Compliance Officer | Product Assumption | A missing or stale approval prevents release. It does not by itself block the rebalance from being worked. | 5 | Warning | |
| POLICY-CONFLICT-011 Competing effective policy authority All rebalance cases | v1.1.0 | Jan 01, 2026 → open | Control Owner | Product Assumption | A live conflict stops automation and routes to the named control owners. | 4 | Pass | |
| HANDOFF-012 Handoff integrity at release Cases with a recorded release approval | v1.3.0 | Jan 01, 2026 → open | Control Owner | Product Assumption | A hash mismatch after approval invalidates the package and returns the case to authorized review until a fresh release is recorded. | 4 | Pass |
Exactly one version of each control is effective at a time in this registry, which is why POLICY-CONFLICT-011 passes on the flagship account. One supporting account carries two overlapping mandate versions with incompatible limits; the product reports the contradiction and names the owners rather than choosing a winner.
61 named control test cases cover pass, fail, missing-input, stale-input, exact boundary, conflict, and not-applicable behaviour. They run in the repository test suite alongside projection invariants and public-copy integrity checks.