Skip to content
DRAFT⚠OIML SMART pilot programme · internal use only · all documents and specifications are drafts and may change without notice

The evaluation and the certificate

The laboratory's reports are in. The authority validates every row against the same model the laboratory ran, opens the review period for the participants' comments, composes the evaluation, and signs the certificate, which is then registered with the BIML and readable by anyone on the public register. The verdicts are computed, never hand-tallied.

Try this flow now

Assume the Issuing Authority persona through the identity service for the evaluation and issuance; the OIML-CS Administrator persona presents the BIML registration desk. The public register and the verify page need no account at all.

→

The flow at a glance

Three seats: the authority's certification officer in /app/ia, the BIML officer in /app/biml, and anyone at the public register (no sign-in). The arc: the reports land, the validation, the review period, the examinations and the evaluation report, the issuance, the registration, the public row. The captures below show the demo's seeded worked example (the walkthrough's drive deliberately stops before issuance, so the register's story stays the seeded one).

FIG. THE EVALUATIONFIG. THE EVALUATION5 ACTORSSTEP 01Reports invia the projectcomputesnever hand-talliedSTEP 02Validationrows vs the modelconsultsthreads resolveSTEP 03Review periodthe comment roundsignsthe attributed actSTEP 04Certificatesigned at issuepublishesanyone can checkSTEP 05RegisteredBIML + public

The walkthrough

S1

The reports land on the shared record

The laboratory's submission (flow 03, S6) does not arrive as an email attachment: it lands on the evaluation project's reports card, and the authority is notified. One project, one place to look. When every dispatched request stands fulfilled, the evaluation can begin.

Try it:sign in as Issuing Authority, then work in/app/ia/projects/…on the demo instance.

The evaluation project's test reports card: the laboratory's submitted reports on the shared record.
The evaluation project's test reports card: the laboratory's submitted reports on the shared record. Live surface · captured 2026-09-01 by the scripted apparatus.
S2

Validate the evidence, section by section

This is the substantial model-driven work of the evaluation. Each test report opens section by section (two samples times the assigned forms in the walkthrough's example), every row carrying its provenance: which sample, which run, which reading. The acceptance rules are the Recommendation's own, and the derived verdicts are computed from the model, never hand-tallied. The officer reviews and passes each section with its evidence in view; a row that fails the model's rule says so, in the open.

Try it:sign in as Issuing Authority, then work in/app/ia/test-reports/…on the demo instance.

The authority reviewing the test report: every section with its provenance, the per-section review acts, the verdicts the model computed.
The authority reviewing the test report: every section with its provenance, the per-section review acts, the verdicts the model computed. Live surface · captured 2026-09-01 by the scripted apparatus.
S3

The review period: the participants' comment round

Before the report is accepted, the review period opens: the project's participants (the laboratory, the applicant) can raise comment threads on the report, the parties are notified, and the threads must resolve before the decision completes. An open thread refuses the finalization with the thread named. Consultation is no longer a side channel of phone calls; it is a first-class, cone-gated part of the record. This surface is the newest build in the flows program, and the seeded worked example's report predates it, so the step carries the live link: open the submitted report of the walkthrough's own drive (the laboratory's submission in flow 03) and the review-period panel stands there.

Try it:sign in as Issuing Authority, then work in/app/ia/test-reports/…on the demo instance.

Open this step's live surface on the demo ↗

S4

The examinations, pre-filled from the record

The evaluation report's basic information pre-fills from what the applicant, the authority, and the laboratory already entered; the binding machinery never asks twice. The authority's own examinations (the authority information with the application number bound from the record, the synopsis, the inscriptions, the marking, the software, the documentation) are recorded from the workspace, each an act with its own evidence.

Try it:sign in as Issuing Authority, then work in/app/ia/evaluations/…on the demo instance.

Open this step's live surface on the demo ↗

S5

The synopsis composes; the verdict is computed

The synopsis composes itself from the authority's section verdicts and the accepted reports. Re-executing the verdicts re-runs the model's arithmetic over the evidence (the arithmetic authority), and the suggested verdict is exactly what the model computes. The officer finalizes at the suggested verdict with the mandatory rationale: the decision is the authority's, and the record shows what it was computed from. Where the evidence is missing, the machinery says INDETERMINATE rather than guessing.

Try it:sign in as Issuing Authority, then work in/app/ia/evaluations/…on the demo instance.

Open this step's live surface on the demo ↗

S6

Issue the certificate: the attributed signing act

The certificates desk lists the finalized evaluations ready to issue. The issuance form shows exactly what the signature will cover (the certified scope the evaluation's verdicts support, the scheme, the expiry, the remarks, the rendered preview) before the officer types the signer passphrase. The signature is the officer's attributed act over the organization's key, on the audit chain, and the certificate is CNML-signed at issue: data, not a scanned PDF. The walkthrough's capture stops at the form; the signing itself is the one act the scripted drive never performs, so the demo's register story stays the seeded one.

Try it:sign in as Issuing Authority, then work in/app/ia/certificateson the demo instance.

The issuance form on the finalized evaluation: the certified scope from the verdicts, the scheme choice, the signing key, reviewed before the signature.
The issuance form on the finalized evaluation: the certified scope from the verdicts, the scheme choice, the signing key, reviewed before the signature. Live surface · captured 2026-09-01 by the scripted apparatus.
S7

Register with the BIML

From the project's certificate card the authority submits the certificate for BIML registration (PD-05 §5.1); it walks to PENDING_REGISTRATION and lands in the BIML officer's registration inbox. The officer reviews the particulars and the evidence chain and registers: the certificate is ACTIVE and the registration record feeds the public register. The scheme's recorded direction (decided by the program on 2026-08-28) is auto-publish on verified intake, the register's trust resting on the signature and receipt machinery with the human surfaces as read postures; the demo's single-instance posture today presents the officer's register act, and this page names both honestly.

The evaluation project's certificate card: the issued certificate with its BIML registration record on the shared hub.
The evaluation project's certificate card: the issued certificate with its BIML registration record on the shared hub. Live surface · captured 2026-09-01 by the scripted apparatus.

Try it:sign in as BIML Officer, then work in/app/bimlon the demo instance.

The BIML console: the registration inbox for pending certificates and the recently registered worked-example certificate.
The BIML console: the registration inbox for pending certificates and the recently registered worked-example certificate. Live surface · captured 2026-09-01 by the scripted apparatus.
S8

The public register: anyone can read it

The register's public face needs no sign-in: the ACTIVE certificate's number, dates, and status are readable by anyone (market surveillance, buyers, other authorities), per B 18:2025 §14.8. The number resolves against the BIML-registered copy, and the same public posture backs the verify page in flow 05. The certificate's loop is closed: applied, tested, evaluated, signed, registered, and publicly checkable.

Try it:sign in as no account needed, then work in/app/registeron the demo instance.

The public Certificate Register: the ACTIVE worked-example certificate readable by anyone, no sign-in.
The public Certificate Register: the ACTIVE worked-example certificate readable by anyone, no sign-in. Live surface · captured 2026-09-01 by the scripted apparatus.

The presenter scripts

Two lengths, keyed to the steps above (S1 to S8). Print this page for a clean copy of the scripts.

The 5-minute presenter script · the committee slot

  1. 0:00The reports are in. This is the flow where the authority's judgment meets the model's arithmetic, and where the certificate is born as data. Simulated cast, nightly reset.
  2. 0:30S1-S2The reports land on the shared record, and the validation reads them section by section, every row with its provenance, the verdicts computed from the model. Nobody tallies a spreadsheet here.
  3. 1:30S3The review period: the laboratory and the applicant comment on the record, and an open thread blocks the decision. Consultation is part of the audit chain now.
  4. 2:15S4-S5The evaluation report pre-fills from everything already entered; the synopsis composes; the suggested verdict is what the model computes, and the officer finalizes with the mandatory rationale.
  5. 3:15S6The issuance: the scope, the preview, the passphrase. The signature is the officer's attributed act, and the certificate is signed data at the moment of issue.
  6. 4:00S7-S8Registration: the BIML inbox, the register act, and the public register anyone can read without an account. The loop closes: applied, tested, evaluated, signed, registered, checkable.
  7. 4:40Try it: the Issuing Authority and BIML Officer accounts, and the public register at /app/register with no account at all.

The 20-minute presenter script · the working visit

  1. 0:00Frame: evaluation is where liability lives, so this flow is built to show its working. The promise: every verdict shows what it was computed from. Simulated cast, nightly reset.
  2. 1:00S1The reports card: the submissions land on the project, the authority is notified, and the evaluation waits for every dispatched request to be fulfilled.
  3. 3:00S2The validation, in depth: the sections, the provenance per row, the acceptance rules as the Recommendation's own. Compute a verdict live: change nothing, re-execute, watch the model's arithmetic return the same answer. That reproducibility is the point.
  4. 5:30S2The honesty cases: a row against the model's rule fails in the open; missing evidence reads INDETERMINATE, never a guess. The officer still decides; the machinery shows its working.
  5. 7:30S3The review period: open a thread as a participant, resolve it, and show the refusal when one stands open. Consultation with a record, cone-gated so exactly the parties take part.
  6. 9:30S4The examinations: the pre-filled authority information (the application number bound from the record), the inscriptions, the marking, the software, the documentation. Never asked twice is a design rule, not a courtesy.
  7. 11:30S5The synopsis and the suggested verdict: the composition from the officer's own section verdicts, the re-execution as the arithmetic authority, the mandatory rationale at finalize. Judgment stays human; arithmetic stays the model's.
  8. 13:30S6The issuance form: what the signature covers, reviewed before the passphrase. The attributed act, the org key, the audit chain, the CNML-signed artifact. Be explicit that the scripted drive never signs: the seeded certificate is the demo's register story.
  9. 15:30S7The registration: the PENDING_REGISTRATION walk, the BIML inbox, the officer's act. Then the doctrine, honestly: the recorded decision is auto-publish on verified intake; the demo shows the human act today; the page names both.
  10. 17:30S8The public register: no account, the number, the dates, the status. Then the verify page as the closer: anyone can check a certificate against the registered copy, with the revocation and suspension checks.
  11. 19:00Questions. The usual: liability (the same Declaration, stronger evidence, never a wider act) and acceptance of other authorities' work (the chain is verifiable; full cross-authority chain verification is the roadmap leg). Close on the try-it paths.

Today (SMART) and the vision (SMART+)

Today · SMART

  • The per-report validation with computed verdicts, the review period with its resolution gate, the examinations, the composed synopsis. the IA console ↗
  • The issuance as the attributed signing act, the CNML-signed certificate, the BIML registration, the public register and verify page. the register ↗
  • The certificate as verifiable data: the VC, SD-JWT, DPP, and AAS carrier forms on the same record. the CNML page ↗

The vision · SMART+

  • Auto-publish on verified register intake (the recorded doctrine decision; the register's model carries it, the capstone wave lands the surface). roadmap ↗
  • The twin-fed evaluation: evidence arriving from the instrument's twin between bench sessions (roadmap). roadmap ↗
  • Suspension and withdrawal propagated to every verifiable copy the moment the authority acts (roadmap). roadmap ↗

The honest questions

Who decides, the model or the officer?

The officer. The model computes the Recommendation's arithmetic and states what the evidence supports, including INDETERMINATE where evidence is missing. The review, the evaluation, the finalization with its mandatory rationale, and the signature are the authority's acts, recorded as theirs. The machinery's discipline is that it shows its working.

Does the BIML registration widen anyone's liability?

No. The registration is the act the scheme already requires (PD-05 §5.1); the platform makes it a signed, receipt-tracked submission instead of an emailed PDF. The published record is exactly what the authority signed and sent. The recorded auto-publish direction keeps the same trust basis (the signature and the receipt machinery) with the human surfaces as read postures, and it is named openly wherever it is described.

Can participants really comment on the record?

Yes: the review period opens at each report's finalization, the comment threads are cone-gated to the project's participants (and the scheme's oversight), everyone is notified, and an unresolved thread refuses the finalization with the thread named. The consultation is part of the audit chain, not a side channel.

Is the certificate still a PDF?

The human rendering exists and prints (the PDF never dies), but the certificate of record is signed data: schema-validated against the Recommendation, verifiable by anyone without an account, and carried in the VC, SD-JWT, DPP, and AAS forms for software consumers. The verification story is on the CNML technology page.

Verified 2026-09-01: every surface above was opened headlessly against the live demo by scripts/capture-walkthroughs.ts (the seeded worked example's report, evaluation, issuance form, BIML inbox, and public register; the scripted drive never signs or registers) and each capture carries its assertion record in public/img/walkthroughs/manifest.json. The step names and machine states match the engineering record (DEMO_FLOWS/04) in the smart repository; where the built posture differs from the flow text, the step says so (S7).