Control Packs · DAT-005 · v1.0.0

Record Accuracy and Correction

Decide how a wrong record about a person or an organization gets found and fixed, and make sure a correction reaches every copy that decisions are read from.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Ensure a record that turns out to be wrong can be located, corrected by a named party, and propagated to the copies that decisions are read from, with the origin of a value recorded where a decision depends on it.

  • A wrong record about a person cannot be found or fixedRecords are created, copied between systems, and acted on with no stated way to locate every copy, no correction path, and no record of where a value came from, so one early error is reproduced by every decision that reads it.
Versioned applicability rule
{
  "characteristic": "SENSITIVE_DATA",
  "equals": true
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • Who can correct a record when it turns out to be wrong, and where else does that correction have to reach?A fix that only lands in one place leaves the old value in the copy something else reads. Naming the copies is what makes the correction real.DAT-005-Q1 · scope

Requirements for the coding agent

  • DAT-005-R1Provide a correction path for the confirmed parties, propagate a correction to every named copy including caches, search indexes, and downstream systems, record when a value was corrected and by whom, and re-evaluate or flag any automated outcome that was derived from the superseded value.

Tests and evidence to retain

  • CORRECTION_PROPAGATION_TESTCorrect a record that has been cached, indexed, and copied downstream, and confirm every named copy reflects the new value and the correction is recorded.
  • configuration_or_policy
  • implementation_location
  • test_result
  • operational_procedure

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • SI-18 · Personally Identifiable Information Quality OperationsNIST_SP_800_53_5_2_0 · partially addressesA correction path with propagation to named copies addresses part of information quality operations for this system; it does not cover the full control.
  • AU-2 · Event LoggingNIST_SP_800_53_5_2_0 · informsRecording who corrected which fields supports later reconstruction of how a value changed; it is not a complete audit programme.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review