Governance · Firewall
Commercial and Attestation Firewall
ALEETH sells ICA and ALEETH issues ICA credentials. This is the policy that keeps a paying relationship from buying a result. It is in force now, and it is written down so anyone can hold ALEETH to it.
ALEETH sells ICA and ALEETH issues ICA credentials. Left unmanaged, that is the conflict that broke the credit-rating agencies: the party being rated pays the rater, and the rater learns to say yes. This policy is the firewall that keeps a paying relationship from buying a result. It is in force now, and it is written down so a customer, an examiner, or an investor can hold ALEETH to it.
1. Two functions, separated
- The commercial function sells ICA, sets and quotes pricing, owns the account, and closes and renews the deal.
- The attestation function runs the assessment, decides pass, restricted, or fail, sets the score, issues, suspends, and revokes.
No individual may act in both functions on the same engagement. The person who owns the revenue on an account does not decide that account’s verdict.
2. Fees do not depend on the outcome
- Fees are fixed and set in advance, before the assessment begins, from the published pricing schedule. A fee is never a percentage of a favorable result and is never contingent on a pass.
- The assessment fee is owed for the work whether the result is pass, restricted, or fail. A customer pays the same for a failing assessment as for a passing one. There is no discount, refund, or fee waiver tied to the verdict.
- The compensation of anyone in the attestation function is not tied to closing or renewing the deals they assess.
3. A verdict cannot be overridden by revenue
- The commercial function cannot change, soften, or veto a verdict, a score, or a finding. It cannot edit the report.
- A failing or restricted result stands regardless of the size of the account or the state of the renewal. Losing a deal is an acceptable outcome of an honest assessment. Keeping a deal is never a reason to change a verdict.
- The issuance and signing step is human-reserved and sits inside the attestation function. A credential is issued by the attestation function, not released by the sales team.
4. Verdicts are tamper-evident and cannot be edited after the fact
- Assessment findings, verdicts, and the receipts under them are append-only and tamper-evident. A verdict, once sealed, cannot be silently altered later to fit a commercial need.
- A change to a credential (suspension, revocation, re-issue) is itself a recorded, signed event in the public register, so the history of a credential is visible and cannot be rewritten.
5. Dispute and appeal
- A customer who disputes a verdict raises it through the attestation function and, once seated, the governance board, not through their sales contact. The commercial team has no authority to resolve a dispute in the customer’s favor.
- An appeal is decided on the evidence and the methodology, and its resolution is recorded.
6. The investor-client conflict
ALEETH is raising capital, and an assessment fee may, under the current Regulation D Rule 506(b) structure, be creditable toward a client’s investment. An assessment client who then invests is no longer a disinterested external party. This is a real conflict and it is handled, not hidden:
- The conflict is disclosed on any credential held by a client who is also an investor, and in the public disclosure. See the Conflict and Funding Disclosure.
- A credential held by an investor-client is never cited as independent, external validation of ICA. Its neutrality caveat travels with it.
- The assessment of an investor-client runs under the same firewall and the same fixed, outcome-independent fee as any other, and the same failing result stands.
7. What operates now, and what is still gated
This firewall is a policy ALEETH enforces on itself today. That is an internal control. The part that makes it an external control is an arms-length governance board that audits adherence, reviews a sample of verdicts, and can overrule a commercially motivated result. That board needs outside members appointed and is not yet seated. Until it is, ALEETH states plainly that the firewall is self-administered, and does not claim independent oversight it does not yet have. When the board is seated, this policy is updated to record its charter and its members.
This document can be verified against the live system. Every ICA credential and the receipts under it are checkable at aleeth.com/verify, offline and with no ALEETH dependency.
Back to all governance documents