# Failure Modes This Role Prevents

The concrete production incidents this role's policy-applicability evaluation is designed to prevent.

- A control is skipped because the system is assumed 'internal only,' and a later external exposure has no control coverage on record.
- An outdated policy bundle is evaluated silently, and the audit trail cannot show which controls were actually in force at the time.
- The agent's candidate mapping is treated as a final compliance determination without owner confirmation, and a real gap goes unaddressed.
- A framework is applied because it is well-known, while a less-familiar but applicable regulation is missed entirely.
- An exception is effectively granted by loosely interpreting a 'not-applicable' result, bypassing the exception-governance role.
