Obligation
When in doubt, notify
The notification obligation applies for the life of the certification. It is prospective when a planned change can be reported before implementation and retrospective when an organization discovers that a reportable change has already occurred.
The Named Custodian, or the designated compliance officer when no Named Custodian is registered, owns the notification obligation.
Critical change
Immediate notice within 48 hours
A Critical change directly affects a safety-critical control, a certification obligation, the underlying model, guardrails, consent or data controls, required disclosures, human oversight, user population, deployment context, or another matter that formed the basis of the certification outcome.
The affected certification scope is placed under review until assessment confirms whether the certification remains valid.
Major change
Notice within 15 business days
A Major change materially alters architecture, training data, third-party integrations, governance, custodianship, user-facing behavior, ownership, deployment, or regulatory scope without directly changing a safety-critical control.
Clause5afe performs a certification-impact assessment to determine whether targeted re-audit or another controlled action is required.
Minor change
Log for scheduled review
Routine maintenance, non-material bug fixes, interface changes that preserve disclosures and consent, and infrastructure changes that do not alter system behavior or data flows may be recorded for the next scheduled review.
If a reported change does not clearly fit one class, it is treated as the higher class until Clause5afe makes a determination.
Determination
What a notification must contain
The organization provides a description, implementation date, affected components, proposed classification, and supporting evidence such as revised architecture, data-flow material, or test results. The source policy targets acknowledgment within 5 business days and a Critical or Major impact assessment within 15 business days after acknowledgment.
- No action or scheduled review for a confirmed Minor change.
- Targeted review or re-audit for a Major change when required by impact.
- Certification hold and focused re-assessment for a Critical change.
- Updated scope, conditions, status, or Registry record when the evidence requires it.
Non-notification
Late notice and concealment affect certification trust
Consequences scale with the severity and intent of the failure. An unreported Major or Critical change can require immediate assessment, a hold, re-audit, formal warning, or escalation. Intentional concealment may support suspension or revocation review.
Clause5afe may explain the likely certification impact of a proposed change. It does not advise the organization how to design or implement the change.
Authority boundary
What this policy does not authorize
A change notification is not approval of the changed system. Only the resulting evidence review and certification decision can confirm whether scope and status remain valid.
Controlled information
What remains outside the public layer
- Proprietary methodology thresholds
- Internal risk-scoring logic
- Client-confidential system and evidence details