Procedures & SOPs

Effective 2026-05-25 · v1.0 · Methodology v3.4
01

Purpose

This document describes the standard operating procedures AECO.digital follows when maintaining the AECO Shield methodology, operating the AECO Shield platform, and producing audit artifacts. It is the operational complement to the AECO.digital Quality Policy.

The intended audience is customers performing due diligence, insurance underwriters reviewing platform credibility, and procurement teams evaluating whether AECO Shield meets their internal governance requirements.

02

Scope

These procedures govern five operational areas:

  • Methodology revision and publication
  • Standards Citation Library maintenance
  • Tool Registry publication
  • Audit artifact generation and retention
  • Incident response and disclosure

These procedures do not govern customer workflows inside AECO Shield. Customer-side procedures are produced by Shield's AI Policy Generator and adapted to firm-specific circumstances.

03

Standard operating procedures

SOP-01

Methodology revision procedure

Purpose
Ensure every increment of the AECO Shield methodology is reviewed, documented, and traceable.
Scope
Applies to all methodology version changes, minor or major.
Procedure
  1. Trigger evaluation. Methodology revisions are triggered by one of three sources: scheduled quarterly review, material change in an underlying standard, or accumulated feedback from operator practice. The trigger is documented before drafting begins.
  2. Draft preparation. The proposed revision is drafted against the current methodology document. Every change is recorded as a discrete edit with rationale and citation reference.
  3. Internal validation. The draft is validated against the v3.4 multi-framework calibration anchor (ISO/IEC 42001 + NIST AI RMF + FDA SaMD for DCS thresholds) and the standards citation library. Any divergence from prior calibration is documented explicitly.
  4. Cross-AI validation (where applied). Material question revisions may be validated through structured comparison across multiple AI models where the operator determines such validation adds confidence. When applied, the validation procedure produces a comparison record retained with the revision documentation.
  5. Publication. Approved revisions are published with: methodology PDF (versioned and dated), diff document, effective date, and notification to active customers and registered tool vendors.
  6. Artifact handling. Prior artifacts retain their original methodology version stamp. For major version increments, affected artifacts are flagged for re-stamping with explicit guidance on what changed and why.
Frequency
Minor revisions on quarterly cadence; major revisions as needed.
Records retained
Draft documents, validation outputs, diff documents, publication notifications. Retention period: methodology lifetime plus seven years.
SOP-02

Standards Citation Library maintenance

Purpose
Ensure every methodology output is grounded in verified citations from current versions of underwriting standards.
Scope
Applies to the standards citation library that grounds all Claude API calls inside AECO Shield (the AI Policy, Training Matrix, Gap Report, and Standards Mapping generators).
Procedure
  1. Source intake. New standards or revised editions are added to the citation library only after the canonical source document has been obtained from the issuing body (ISO, NIST, EU, DoD, IBM, etc.).
  2. Section indexing. Each relevant clause is indexed with its section identifier, full text, and publication date. The library is structured for retrieval by section reference, not full-text search.
  3. Methodology mapping. Each citation is mapped to one or more methodology domains and question identifiers. The mapping is reviewed at every methodology revision.
  4. Version tracking. When a source standard publishes a new version, both the prior and new versions remain in the library. Methodology outputs continue to reference the version active when the output was produced.
  5. Public-readability. The citation library is queryable but not directly editable by customers. Modifications require operator action with revision logging.
Frequency
Continuous (event-driven). Quarterly review for completeness.
Records retained
All historical versions of source standards plus their mapping tables. Retention period: indefinite.
SOP-03

Tool Registry publication procedure

Purpose
Ensure every entry in the public AECO Tool Registry meets methodology-stamped standards before publication.
Scope
Applies to all tool assessments published to the public-facing registry, whether produced manually or through Claude API automation.
Procedure
  1. Assessment production. Tool assessments are produced by running the candidate tool through the 22-question methodology under the current version. Assessments may be drafted via Claude API for efficiency, but draft status is preserved until editorial review completes.
  2. Hard-filter verification. Hard Filters HF1 through HF5 (geographic licensure, code edition currency, BIM/ISO 19650 compatibility, cybersecurity baseline, professional indemnity coverage) are verified independently of the composite ACS score. A tool failing any hard filter cannot publish as Stamp-Safe regardless of composite score.
  3. Editorial review. A draft assessment is reviewed by AECO.digital editorial staff for: methodology compliance, citation accuracy, factual correctness regarding the tool's stated capabilities, and absence of conflicts of interest. The reviewer is recorded with the assessment.
  4. Sign-off. Publication requires sign-off attestation that the assessment reflects the methodology under its stated version. The sign-off is preserved in the audit log.
  5. Vendor notification. When an assessment is published, the tool vendor (if identifiable) is notified. Material corrections submitted by vendors are evaluated against the methodology; commercially-motivated objections are noted but do not alter scoring. AECO.digital may, at its discretion, offer a structured right-of-reply window on a per-assessment basis.
  6. Re-stamping cadence. Published assessments are reviewed for re-stamping when: the methodology version changes materially, an underlying standard updates, or the tool publishes a material capability change.
Frequency
Event-driven for new publications; annual review for all published entries.
Records retained
All historical assessment versions plus editorial sign-offs. Retention period: seven years per artifact.
SOP-04

Audit artifact retention

Purpose
Ensure every artifact AECO Shield generates is preserved for the duration appropriate to licensed AEC professional liability exposure.
Scope
Applies to all customer-generated artifacts: ACS assessments, FMP firm maturity profiles, policy documents, training matrices, gap reports, project sign-off receipts, project audit reports.
Procedure
  1. Generation stamping. Every artifact carries: methodology version, generation timestamp, generating user, customer firm identifier, and source standard citations.
  2. Storage commitment. Artifacts are retained for seven years from generation date in the AECO Shield database, regardless of customer subscription status during that period.
  3. Customer access. Customers retain read access to their artifacts under any active or expired subscription. Export to PDF is available for the artifact's full retention period.
  4. Deletion requests. Customer-initiated deletion is honored under applicable privacy law (GDPR Article 17, CCPA, etc.) within the timeframes those laws require. Once deleted, artifacts cannot be reconstructed; this is documented to the customer before deletion proceeds.
  5. Methodology integrity on retention. Retained artifacts continue to display under the methodology version that produced them. Methodology updates do not modify prior artifacts; they may add advisory flags indicating recommended re-stamping.
Frequency
Continuous.
Records retained
Artifacts plus generation metadata plus deletion logs where applicable. Retention period: seven years.
SOP-05

Incident response and disclosure

Purpose
Ensure security incidents, methodology errors, or platform availability events are handled transparently and within applicable regulatory timeframes.
Scope
Applies to incidents materially affecting customer data confidentiality, methodology output integrity, or platform availability.
Procedure
  1. Detection and triage. Incidents are categorized by impact: confidentiality (data exposure), integrity (methodology output error), or availability (platform downtime exceeding posted SLA).
  2. Containment. Initial containment is the first operational priority. Documentation of containment actions begins concurrently.
  3. Customer notification. Customers materially affected by an incident are notified within the timeframe required by applicable law — generally within 72 hours of confirmed impact under GDPR Article 33 and analogous frameworks. Notification includes: nature of the incident, scope of affected data or artifacts, containment status, and remediation timeline.
  4. Methodology integrity events. Errors in methodology output (incorrect scoring logic, broken citation, miscalibrated threshold) trigger artifact re-stamping for affected records. Customers receive notification with a list of affected artifacts and the corrected versions.
  5. Post-incident review. Within 30 days of incident closure, a written post-incident review is produced and retained. Material findings inform methodology or operational procedure updates.
  6. Public disclosure. Material incidents are disclosed on the AECO.digital status page. Material is defined as: any incident affecting more than ten customers, any methodology integrity event, or any confidentiality breach.
Frequency
Event-driven.
Records retained
Incident logs, notifications, post-incident reviews. Retention period: seven years.
04

Governance of these procedures

These procedures are reviewed at every minor methodology version increment. Material procedural changes are published with a version bump and an effective date.

When a procedure is materially revised, the prior version is preserved in the operational record alongside the new version. Customers and registered tool vendors are notified of procedural changes that affect their interaction with the platform.

Procedural questions, corrections, or formal concerns may be directed to support@aeco.digital.

AECO Shield v3.4 · Procedures & SOPs v1.0 · Effective 2026-05-25 · 7-year audit retention applies to all referenced artifacts.