agile-v-compliance
Instructions
Compliance protocols for Agile V. Requires agile-v-core loaded first.
Risk Management (ISO 9001 6.1 / AS9100D 8.1.1)
Append-only, cycle-tagged register in .agile-v/RISK_REGISTER.md: RISK-ID | Cycle | Level(L0-L4) | Category | Description | Likelihood | Impact | Controls | Residual Decision | Owner | Status. Apply docs/agile-v-runtime/04_RISK_CLASSIFICATION.md; legacy R0-R3 maps only as documented there.
Categories: Technical, Process, Compliance, Security. Severity matrix: High x High = Critical, High x Med = High, High x Low / Med x Med = Medium, rest = Low. Critical risks require Human resolution or documented acceptance before Gate 2.
When: draft persisted = Req Architect identifies; independent findings = Logic Gatekeeper flags constraints; Stage 4 = Red Team finds residual; cycle boundary = Compliance Auditor reviews. Baselining requires Gate 1 approval and no unresolved mandatory finding.
CAPA Protocol (ISO 13485 8.5 / ISO 9001 10.1-10.2)
Triggers: CRITICAL finding, recurring NC across cycles, regression FAIL with no CR, 3-attempt escalation.
Record in .agile-v/CAPA_LOG.md: CAPA-XXXX with Cycle, Trigger, Nonconformity, Root Cause (5-Whys), Corrective Action, Preventive Action, Effectiveness Verification, Status (open -> corrective-complete -> preventive-complete -> verified-effective -> closed), Owner.
Workflow: Detect -> Record -> Analyze -> Correct -> Prevent -> Verify effectiveness. Compliance Auditor tracks open CAPAs at Gate 2, flags overdue (>2 cycles).