Decision Engineering™ · The Decision Architect

DecisionEngineeringTM

How institutional purpose becomes the decisions an institution actually executes.
Issue #006 · Deepak Aggarwal
Previously in this series
Issue #001 — Layer 1 · Purpose — Coutts. NHS triage. What happens when institutions deploy systems without encoding what they actually exist to do. The gap accumulates silently. Until it doesn’t.
Issue #002 — Layer 2 · Strategy — Credit Suisse. NHS England. Eight years of drift between Purpose and what Strategy was actually serving. Nobody asked whether the two were still compatible.
Issue #003 — Layer 3 · Intent — Wells Fargo. Kaiser Permanente. A mandate issued without a boundary. The mandate was real. The outcome was not intended. The gap was never closed.
Issue #004 — Layer 4 · Rules — Wirecard AG. Orpea Group. The rules were followed precisely. The outcome was catastrophic anyway. Not misconduct within the rules. Rules that had become the architecture of the harm.
Issue #005 — Layer 5 · Judgment — Apple Card / Goldman Sachs. UnitedHealth / nH Predict. The model decided. The institution was accountable. Nobody had defined where one ended and the other began.
This issue: Layer 6 — Decision. The moment judgment becomes a recorded act. Or doesn’t. Where replayability is either built into the architecture — or permanently foreclosed.
The institutions referenced in this issue are cited on the basis of publicly documented regulatory findings, official investigations, court filings, and other published reports. All analysis is educational. Nothing here constitutes legal, regulatory, financial, or investment advice.
00 · This Issue
The decision was issued. Nobody could prove what authorised it.

Every layer before this one is preparation. Purpose sets the mandate. Strategy allocates resources. Intent defines the objective. Rules create the constraints. Judgment exercises discretion within those constraints. None of it matters if the moment of decision — the actual act of choosing and committing — leaves no verifiable record.

Layer 6 is where judgment becomes a decision. The point at which the institution commits. An action taken. A transaction executed. A patient’s care pathway altered. A customer’s credit access closed. The decision is issued.

The Layer 6 question is not whether the decision was right. It is whether the institution can prove what it decided, when it decided, under what authority, with what information in front of it. Not reconstruct. Not approximate. Prove.

Explainability produces a narrative about the decision after the fact. Replayability reconstructs the decision from a record built at the moment it was made. The distance between those two things is the governance gap this issue is about. In both cases below, the decision was issued. The record that would have made it auditable — and the institution accountable — was never built.

01 · Signals
Two institutions. Two sectors. The decision was issued. The record was not.
Knight Capital Group
Capital Markets · United States
August 2012

Knight Capital was, in August 2012, one of the largest market makers in US equities. On the morning of 1 August, the firm deployed a software update to its automated trading infrastructure. The deployment was incomplete. The new software was successfully copied to seven of the firm’s eight production servers. The eighth server was missed. When live traffic hit that single un-updated server, a legacy code component known as SMARS (Smart Market Access Routing System) — dormant for years — was unintentionally reactivated by a repurposed configuration flag.

When markets opened at 9:30am, the legacy logic began executing. It misinterpreted a newly introduced NYSE Retail Liquidity Program flag and started sending unintended orders into the market, rapidly buying and selling shares across multiple stocks. The system accumulated positions it had never been authorised to hold. The controls in place were unable to detect or stop the behaviour before losses escalated.

Over roughly 45 minutes, Knight’s systems executed millions of trades across 154 stocks, generating approximately $7 billion in unintended positions. By the time trading was halted manually, the firm had ultimately incurred a loss of more than $460 million. At that point, the institution could no longer prevent the consequences of the deployment. It could only observe them. Knight Capital did not survive the quarter and was acquired by Getco LLC later that year.

The SEC’s subsequent investigation was precise. Knight lacked adequate written supervisory procedures for the deployment. There was no effective process to verify that all production servers had received the correct software update before live trading began. The firm’s controls failed to prevent the entry of erroneous orders at scale, and there was no effective operational mechanism capable of stopping the malfunction quickly enough once it was underway.

Knight Capital is often described as a software failure. It was more accurately a governance failure inside a high-speed decision system. The decision to deploy was made and executed. But the institution could not reliably verify what had been authorised, tested, updated, or actively running at the exact moment decisions entered the market.

Date: 1 August 2012
Duration: 45 minutes
Loss: more than $460 million ultimately
Trades: ~4 million across 154 stocks
SEC fine: $12 million · 2013
Outcome: firm acquired · December 2012
Where the decision record failed — Knight Capital Group
What was decided
Deploy the software update to production trading infrastructure on the morning of 1 August 2012, ahead of NYSE market open.
What was never recorded
Verification that all eight servers received the update. The authority under which deployment to live markets was approved. A defined kill switch procedure reachable within the loss tolerance of the firm.
The gap
The decision to deploy was made and executed. No contemporaneous record captured what had been authorised, verified, or bounded. Forty-five minutes. More than $460 million. The institution could not prove what it had sanctioned.
The algorithm did not malfunction. It did exactly what the legacy code was written to do. The failure was not in the execution. It was in the absence of a deployment decision record — a verifiable trail of what had been authorised, verified, and bounded before a single order was sent.
Theranos
Healthcare · United States
2013 — 2016

Theranos was a health technology company built around a single clinical claim: that its proprietary device, the Edison, could perform a wide range of diagnostic tests accurately from a small finger-stick blood sample, at a fraction of the cost and speed of conventional laboratory testing.

The company launched consumer testing services through Walgreens in 2013 and expanded across Arizona as patient testing volumes increased. Patients received diagnostic results associated with Theranos technology. Clinicians made treatment decisions based on those results.

But the decision to deploy the Edison into patient-facing clinical operations occurred before the technology had been independently validated at the level required for medical testing at scale. The underlying validation evidence — the record that should have demonstrated what the device was authorised to test, under what conditions, and with what known accuracy ranges — either did not exist in a clinically reliable form or was not disclosed transparently to regulators, partners, physicians, or patients.

In practice, Theranos processed many tests using conventional third-party laboratory equipment rather than the Edison itself, including modified commercial analysers working with diluted blood samples. Yet results continued to be represented publicly as evidence of proprietary breakthrough capability.

CMS inspected Theranos’s Newark, California laboratory in 2015. Its findings were direct: quality control procedures were deficient, testing practices created immediate risks to patient safety, and the laboratory failed to meet federal standards required for high-complexity clinical testing. CMS revoked the laboratory’s certification in 2016. By that point, the question was no longer whether the deployment decision had been sound. It was whether any record existed that could have made it defensible.

The Department of Justice subsequently charged founder Elizabeth Holmes and former president Ramesh Balwani with wire fraud and conspiracy. Holmes was convicted in January 2022 on four counts related to investor fraud. Balwani was convicted in July 2022 on all twelve counts.

Theranos is often remembered as a fraud case. It was also a governance failure inside a clinical decision system. Diagnostic results were produced. Clinical decisions were made. But the institution lacked an authoritative, validated, and auditable decision record capable of proving what the technology had actually been approved to do, under which conditions, and on what evidentiary basis — at the moment the first patient result was issued.

Consumer launch: Walgreens 2013
CMS inspection: 2015
Lab certification revoked: 2016
Holmes convicted: January 2022
Balwani convicted: July 2022 · 12 counts
Patient results: unverifiable accuracy
Where the decision record failed — Theranos
What was decided
Deploy the Edison for patient-facing diagnostic testing at scale through Walgreens, producing clinical results used by physicians for treatment decisions.
What was never recorded
Independent validation of the Edison’s accuracy across the test range offered to patients. The authority under which deployment was approved as clinically safe. A traceable link between each result and the specific machine that produced it — the absence of which allowed the silent, systemic substitution of modified third-party commercial analysers to go undetected at the point of result.
The gap
Patients received diagnostic results. Clinicians made treatment decisions. No contemporaneous record established what had been authorised, validated, or bounded before a single result was issued. The deployment decision had already passed the point at which it could be contained.
The clinical decision to deploy at scale preceded any validated record of what the device could accurately do. That is not a product failure. It is a decision architecture failure. The institution issued consequential clinical decisions without the record that would have made those decisions auditable — or the harm stoppable once the accuracy gap became visible to regulators.
02 · Diagnosis
The decision was made. The record that would have made it replayable was not.

Both failures carry the same structural signature. Different sectors. Different scales. Different consequences. The same underlying absence.

A decision was issued — to deploy, to operate, to release clinical results at scale. The moment of that decision passed without a record that could answer three questions: what was authorised, by whom, under what verified conditions. In both cases, the institution could produce a narrative after the fact. In neither case could it produce a verifiable record from the moment the decision was made.

This is the Layer 6 failure. Not a wrong decision. An unrecorded one. The absence of what the DIC™ calls a replay-ready decision record — the contemporaneous capture of authority, scope, verification status, and the information set present at the moment a consequential decision was committed.

The distance between explainability and replayability is sharpest at Layer 6. Explainability reconstructs what likely happened. Replayability returns to what was recorded as happening. Knight Capital’s operators could tell the SEC what they believed the deployment decision had encompassed. They could not show it. Theranos could assert the Edison had been validated for clinical use. It could not prove it from a contemporaneous record.

The gap between what an institution decided and what it can prove it decided is not a compliance gap. It is a decision architecture gap. Compliance asks what happened. Replayability asks what was recorded as happening — at the moment it happened. Only one of those is recoverable after the fact.

The DIC™ is specific here. A decision is not an output. It is a recorded act — the moment at which the institution commits to a course of action, with a contemporaneous record of the authority, scope, and information set that governed that commitment. Without that record, the institution has not decided. It has acted. The distinction matters enormously when the act is challenged.

In both cases, the act could not be defended from a record. It could only be explained from memory. And explanation is not proof.

02B · The Distinction
What each produces. What each requires. Why only one is governance.
Path A
Explainability
Reconstructed after the fact
Path B
Replayability
Captured at the moment of commitment
The question it asks
What happened?
The question it asks
What was recorded as happening — at the moment it happened?
What it produces
A coherent narrative. Assembled from memory, surviving documentation, and the most defensible account available.
What it produces
A verifiable record. Authority, scope, verification status, and information set — captured at the moment of commitment.
Knight Capital Group · 1 August 2012
What it produced
Knight could tell the SEC what the deployment had been intended to encompass. The account was coherent. It was the best account available from memory.
What it would have required
Confirmation — recorded before market open — that all eight servers received the correct update, and that a named individual held authority to halt trading within a defined loss threshold.
The gap
The institution could explain the intent. It could not prove the verification. Forty-five minutes. The gap was not recoverable once trading began.
Theranos · 2013 — 2016
What it produced
Theranos could assert the Edison had been developed and deployed in good faith. The account held together until regulators examined the underlying evidence.
What it would have required
Independent validation of the Edison’s accuracy, captured at the moment the first patient result was issued — with a traceable link between each result and the specific machine that produced it.
The gap
The institution could explain the intent. It could not prove the authorisation. Every patient result issued between 2013 and 2016. The gap was not visible until CMS arrived.
The structural difference
Explainability
Available to every institution after every failure. Requires only memory and counsel. Produces a narrative.
Replayability
Available only to institutions that built the record before the failure occurred. Requires architecture. Produces proof.

That is why Layer 6 is the governance layer. Not because decisions happen here — decisions happen at every layer. Layer 6 is where the decision becomes a recorded act. Or doesn’t. And that distinction — between a decision that was made and a decision that can be proved — is the difference between an institution that is accountable and one that is merely explainable.

03 · Engineering Note
What Layer 6 governance actually requires.

Three mechanisms every institution needs at Layer 6.

// L6 Governance Mechanisms
01
The Decision Record — Built at the Moment of Commitment
A decision record is not post-hoc documentation of what happened. It is a contemporaneous capture — built at the moment the decision is committed — of the authority under which the decision was made, the scope of what was authorised, the verification status at time of commitment, and the information set present when it was issued. If it is not built at the moment of commitment, it is reconstruction. Reconstruction is not a decision record. It is a narrative.
Knight Capital
A deployment decision record: confirmation that all eight production servers received the update, the authority under which live-market deployment was approved, and the defined loss tolerance and kill switch procedure reachable within that tolerance — all captured before market open.
Theranos
A clinical deployment record: the validated accuracy range of the Edison across each test offered to patients, the authority under which patient-facing deployment was approved as clinically safe, and the protocol linking each result to the device version and validation data that governed it.
02
The Verification Gate — Before Commitment, Not After
Every consequential decision has a verification gate: a defined set of conditions that must be confirmed — and recorded as confirmed — before the decision is committed. Not audited after the fact. Confirmed before commitment. The gate is not a checklist. It is a logical precondition. If the conditions are not met and recorded as met, the decision cannot be issued. The gate is what makes the decision record verifiable rather than asserted.
Knight Capital
Deployment to live markets requires recorded confirmation that all production servers received the update, that a kill switch procedure was tested and available, and that a named individual held authority to halt trading if pre-defined loss thresholds were breached. If any condition is unmet, deployment does not proceed.
Theranos
Patient-facing deployment requires recorded independent validation of device accuracy across each offered test, confirmation of laboratory director qualifications against federal requirements, and a defined protocol for result-level traceability linking each result to the device and validation data that governed it.
03
Replayability Infrastructure — The Audit Trail That Exists Before It Is Needed
A replayable institution does not build its audit trail in response to an investigation. It builds it as a precondition of consequential operation. The record exists before it is needed — because the moment it is needed is always after the decision has been made. An institution that can reconstruct what happened from contemporaneous records is replayable. An institution that reconstructs what likely happened from memory is not. The difference is not a matter of effort. It is a matter of architecture.
Knight Capital
A live trading system with no reachable kill switch and no server-level deployment verification is not a replayable system. It is an operable one. The distinction matters at 9:31am on 1 August 2012, when it is already too late to build the record.
Theranos
A clinical testing system that cannot link each patient result to a specific device version and contemporaneous validation record is not a replayable system. By the time CMS arrived, the records that would have made the deployment defensible no longer existed in a form that could be verified.
04 · The Board Question
Your institution made consequential decisions last week. Trades executed. Credit issued or denied. Clinical pathways altered. Policies deployed to production systems.

For each one: is there a contemporaneous record — built at the moment of commitment — of the authority under which it was made, the scope of what was authorised, and the verification status at time of decision?

If that record does not exist, the decision is not replayable. You can explain what happened. You cannot prove what was decided. When those two things diverge — under regulatory scrutiny, in litigation, in a crisis — explanation is not a defence. The record is.
Decision Engineering™ Series · Paper 3
If this issue raised a question about what happens at network scale —
Issue 006 examined the Layer 6 failure at the single institution level. One decision. One deployment. One record that was never built.
The third paper in the Decision Engineering™ series takes this further: what happens when multiple programmable institutions interact across jurisdictions — and the decision chain runs in seven seconds across three regulatory regimes before any governance gap can be detected?
When the Protocol Decides — Replay-Ready Infrastructure for Programmable Financial Institutions
SSRN Author ID 9450612
Decision Integrity Chain™ · Layer 6 of 8
L1
Purpose
L2
Strategy
L3
Intent
L4
Rules
L5
Judgment
L6
Decision
L7
Outcome
L8
Feedback
Decision
The act of committing to a course of action — the moment at which judgment becomes a recorded institutional choice. A decision is not an output. It is a contemporaneous record: of the authority under which it was made, the scope of what was authorised, the verification status at time of commitment, and the information set present when it was issued. Without that record, the institution has not decided. It has acted. The distinction is the difference between a replayable institution and an irrecoverable one.
Issue #007 moves to Layer 7 — Outcome. Where the decision meets reality. Where the gap between what was intended and what was produced becomes visible — and where the institution either has a feedback loop capable of detecting that gap, or discovers it when the regulator does.