For Executives
How to put a number on an attestation layer that a CFO will accept: the five inputs, where to get them from your own systems, the arithmetic, the cost of being too cautious, and the honest limits of the model.
Expected loss has two factors. You can reduce how often a bad event happens, or how much it costs when it happens anyway. Nearly every control you already buy attacks the first. An attestation layer attacks both, and the second is the one people forget to count.
A decision gate that refuses to proceed on missing or unverifiable evidence catches problems before money moves. Fewer bad shipments, fewer non-conformant lots, fewer approvals resting on a claim nobody checked.
When something goes wrong regardless, the cost turns heavily on one question: can you show what you knew and what you did about it, at the time? Organizations that can produce a contemporaneous, tamper-evident record settle faster, produce evidence cheaper, and are treated differently by regulators, customers and insurers than organizations reconstructing a timeline from email.
Do not estimate these. Pull them. Every one is already somewhere in your systems, and the exercise of pulling them is itself worth more than the eventual answer.
| Symbol | What it is | Where it lives in your organization |
|---|---|---|
| N | Gated decisions per year in the scope you're considering | ERP / SCM: count of PO releases above the materiality threshold, supplier onboardings, or lot acceptances. This one is exact, not estimated. |
| p | Share of those decisions that rested on a claim later found to be wrong, unsupported, or unverifiable | Supplier corrective-action records, non-conformance reports, quality holds, credit memos, and audit findings. Sample 100 closed decisions and classify them; that is a two-day exercise and beats any benchmark. |
| q | Of those, the share that reached a costly consequence rather than being caught harmlessly downstream | The same records, filtered for those that generated a charge: rework, expedite, penalty, scrap, delay credit, legal time. |
| SLE | Average cost per costly event (single loss expectancy) | Finance: the actual charges booked against those events. Include internal time at loaded rate — most organizations undercount this by half. |
| d | Detection lift: the share of those events the gate would have caught at the decision point | The only genuinely estimated input. Get it honestly: take 30 real historical failures, run the gate's criteria against the evidence that existed on the decision date, and count how many would have come back WITHHELD or CAUTION. This is a measurement, not a guess — and it is the number to defend hardest. |
| Input | Value | Basis |
|---|---|---|
| N — gated decisions/year | 480 | PO releases above $250K plus supplier onboardings |
| p — rested on a claim later found wrong | 6.5% | 31.2 decisions/year, from a 100-decision retrospective sample |
| q — reached a costly consequence | 22% | The rest were caught harmlessly at inspection or receipt |
| SLE — average cost per event | $214,000 | Rework, expedite, delay credits, scrap, legal and internal time at loaded rate |
| d — detection lift | 62% | Measured by replaying 30 historical failures against the gate criteria using only evidence available on the decision date |
| r — loss reduction on residual events | 18% | Faster evidence production, stronger liability allocation, fewer disputed facts |
| Line | Calculation | Annual |
|---|---|---|
| Frequency benefit | $1,468,000 × 0.62 | + $910,000 |
| Severity benefit on residual events | $1,468,000 × 0.38 × 0.18 | + $100,000 |
| Evidence production — internal audits | 3 audits × 120 hrs × $95 | + $34,000 |
| Evidence production — customer & regulator requests | 4 requests × 24 hrs × $95 | + $9,000 |
| Cost of caution — holds resolved within float | 44 holds × $1,800 | − $79,000 |
| Cost of caution — holds exceeding float | 14 holds × $14,500 | − $203,000 |
| Net annual value, before program cost | — | + $771,000 |
Break-even. Rather than assume a price, state the threshold: the program is value-neutral at an all-in annual cost of $771,000 — software, integration, and the internal effort to run it. Any figure materially below that is accretive. At an all-in cost of $150,000, net value is $621,000 and payback is roughly 2.3 months.
The single largest cost line above is the cost of caution — $282,000 of holds, most of which turn out to be unnecessary. That number is not fixed. Once a full outcome cycle is sealed, the recalibration identifies which required fields actually predicted failures and which merely generated friction. In the companion scenario the hold rate falls from 37% to 13% with no increase in downstream failures, because one required field was doing no predictive work at all.
| Line | Year 1 | Year 2 (post-backtest) |
|---|---|---|
| Frequency + severity benefit | $1,010,000 | $1,010,000 |
| Evidence production savings | $43,000 | $43,000 |
| Cost of caution | − $282,000 | − $99,000 |
| Net annual value | $771,000 | $954,000 |
This is the part of the value that compounds: the system gets less obstructive over time without getting less careful, and the change is documented rather than argued.
Net annual value before program cost, varying the two most contestable inputs. Everything else held at the worked-example values.
| Average event cost → Detection lift ↓ | SLE $100K | SLE $214K | SLE $400K |
|---|---|---|---|
| d = 40% (pessimistic) | $110,000 | $507,000 | $1,155,000 |
| d = 62% (worked example) | $233,000 | $771,000 | $1,650,000 |
| d = 80% (optimistic) | $335,000 | $988,000 | $2,055,000 |
The model stays positive across the whole grid, but note the shape: in the bottom-left corner — low event cost and low detection — the value is modest and could be erased by a heavy implementation. If your events are cheap and your evidence is already good, the honest answer is that this is a small win. The case is strongest where individual events are expensive, evidence arrives from parties you don't control, and someone external will eventually ask you to prove what you knew.
Most vendor business cases omit this line entirely. Omitting it is why those business cases don't survive contact with operations.
A gate that refuses to proceed on thin evidence will stop transactions that would have been fine. That is not a defect; it is the mechanism working. But it has a real cost, it lands on operations rather than on risk, and it is where the internal opposition will come from. Price it explicitly:
| Hold type | What happens | Typical cost driver |
|---|---|---|
| Resolved within schedule float | Evidence exists; someone chases it for two days | Buyer and supplier-quality time. Low, but high volume. |
| Exceeds float | Slip, expedite premium, re-planned inbound logistics | The expensive tail. Track these separately — they drive the political cost of the program. |
| Terminal (fold) | Re-source to an alternate supplier | Rare, large, and usually correct. Count it as a cost in the model even when it prevented a larger loss, or you will be accused of double-counting. |
The expected-value model above understates the case in one specific way: it averages. Most of the reason organizations care about this class of risk sits in the tail — the single event that is not $214,000 but $20 million, because it involved a safety recall, a regulatory finding, or a customer contract terminated for cause.
| Effect | Mechanism | How to evidence it internally |
|---|---|---|
| Tail truncation | The events that become catastrophic are disproportionately the ones where no contemporaneous record exists — because the absence of a record converts a defensible business decision into an indefensible one | Review your three largest historical loss events. Ask what fraction of the cost was the underlying failure and what fraction was the inability to demonstrate the process. In most reviews the second is larger than expected. |
| Insurance posture | Underwriters price documented, testable controls differently from asserted ones. A control that a third party can re-execute is a different object from a policy document | Raise it at renewal with a worked receipt in hand. Do not promise a premium reduction in the business case; record any that materializes as upside. |
| Contract eligibility | Passport, traceability and record-keeping obligations are moving from optional to threshold requirements in several regimes — most immediately in EU product-passport rules and AI record-keeping obligations | Count the revenue that becomes ineligible without it. In some portfolios this single line exceeds the entire risk-reduction calculation. |
| Capital and provisioning | Better-characterized loss distributions support tighter provisioning | Only relevant at scale, and only after two or more years of sealed decisions with recorded outcomes. Do not claim it in year one. |
Naming these is what makes the rest credible.
| Not priced | Why not |
|---|---|
| Reputational damage avoided | Real, and not estimable to a defensible precision. Mention it in narrative; keep it out of the arithmetic. |
| Regulatory penalties avoided | Highly regime-specific and heavily dependent on facts. If your exposure is concrete and quantified, add it as a separate, clearly-flagged line rather than folding it into SLE. |
| Decision quality improvement | The backtest genuinely improves criteria over time. Year-one value is unknown; claiming it invites the reader to discount everything else. |
| Personal liability exposure of decision-makers | The most-felt benefit and the least quantifiable. It belongs in the conversation with the individuals who carry it, not in the CFO model. |
| Speed benefits | An attestation gate is not a throughput tool. If someone puts a speed benefit in the model, remove it — the model is more persuasive without it. |
Four sentences that carry the argument, in the order that works:
"We make roughly 480 decisions a year above the materiality threshold. About seven a year go wrong on evidence that was weak at the time, at an average booked cost of $214,000 — call it $1.5 million a year, and we have not been counting it as one number until now."
"For any one of those, we cannot currently reconstruct what we knew on the decision date in a form an outside party would accept. Our record is email and recollection."
"The control refuses to approve when required evidence is missing or unverifiable, names exactly which item is missing, and produces a sealed record that an auditor can re-run on their own machine without trusting us."
"It will also stop transactions that would have been fine — we have priced that at $282,000 a year, and we have a dated commitment to reduce it using outcome data rather than argument."