Worked case · Reference condition · 12 figures

Boundary-condition verification

Test the boundary conditions

Figure 01 / 12

Determine the eligible population first

Determine the eligible population first — Boundary-condition verification. Count; records. Exact values are in the figure data below.
Count; records

Of 1,320 source records, 1,016 are within the stated synthetic scope and 304 are outside it. Eligibility here is an explicit teaching input, not a legal conclusion. Production classification must use the actual entity, product, activity, jurisdiction, and facts.

Figure data and text version
Scope stateRecords
Within stated scope1,016
Outside stated scope304

A control can work for ordinary cases and fail at a cutoff, product change, or missing-data condition. Those boundaries need deliberate evidence.

The reference case starts with the stated population and a functioning evidence path. The owner is control assurance.

All amounts, rates, capacity limits, and outcomes in this case are synthetic. The three conditions are separate assumptions for comparison. A better result in the response condition is not measured proof that the proposed control causes that improvement. The figures expose the calculation and its limits; a real deployment needs its own evidence.

Read the result

The case identifies 1,016 eligible records from a source population of 1,320. The required workflow completes for 986, but 15 completed records miss the illustrative internal target. Another 30 remain incomplete. Communication evidence covers 976 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

Model inputs and calculated values

Inputs below are the case-specific values. Each figure states the condition-specific assumptions and units used in its calculation. Calculated values are rounded for display.

InputValue
population1,320
eligibility0.77
Calculated valueResult
population1,320
eligible1,016
excluded304
complete986
incomplete30
late15
ontime971
notices976
undelivered10
pending0
reviewed30
Figure 02 / 12

A control can miss eligible records

A control can miss eligible records — Boundary-condition verification. Count at a fixed observation cutoff. Exact values are in the figure data below.
Count at a fixed observation cutoff

The required workflow completes for 986 of the 1,016 eligible records. The 30 remainder needs an owned exception path. Reporting completion as a percentage of all source records would answer a different question and could hide the actual coverage gap.

Figure data and text version
MeasureRecords
Eligible records1,016
Workflow completed986
Workflow incomplete30
Figure 03 / 12

Completion and timeliness are distinct outcomes

Completion and timeliness are distinct outcomes — Boundary-condition verification. Count; exclusive states within eligible population. Exact values are in the figure data below.
Count; exclusive states within eligible population

The illustration applies an internal target, not a statutory deadline. Of 986 completed records, 15 miss that target and 971 meet it. The 30 open records are a third state; do not automatically classify them as timely merely because their final outcome is unknown.

Figure data and text version
OutcomeEligible records
Complete within target971
Complete after target15
Still incomplete30
Figure 04 / 12

An obligation record connects authority to behavior

An obligation record connects authority to behavior — Boundary-condition verification. Control contract. Exact values are in the figure data below.
Control contract

This case implements test the boundary conditions. The record separates scope, trigger, required action, ownership, and retained proof. Exact legal duties belong to the applicable source and interpretation; the timing and counts in this worked example are synthetic.

Figure data and text version
ElementIllustrative value
Control subjectBoundary-condition verification
ScopeThe eligible population defined above
TriggerAn item exactly at a time or amount boundary follows the wrong branch.
Required behaviortest the boundary conditions
Ownercontrol assurance
EvidenceVersioned event, action, and communication records
Figure 05 / 12

Different clocks start from different facts

Different clocks start from different facts — Boundary-condition verification. Internal teaching timeline; not a legal deadline schedule. Exact values are in the figure data below.
Internal teaching timeline; not a legal deadline schedule

These relative times are illustrative service targets. They deliberately distinguish customer contact, receipt by the institution, classification, investigation, and communication. A routing delay must not silently replace the original receipt time when that fact matters.

Figure data and text version
EventIllustrative timeRecord
Customer reportT0Original channel and words
Institution receiptT0 + 5 minutesRetained receipt timestamp
ClassificationT0 + 20 minutesApplicable process and owner
Internal review targetT0 + 1 dayInternal target only
Outcome communicationAt decisionContent, destination, and delivery state
Figure 06 / 12

Evidence fields fail independently

Evidence fields fail independently — Boundary-condition verification. Count; overlapping field-level checks. Exact values are in the figure data below.
Count; overlapping field-level checks

Each row is one evidence requirement over the eligible population. The same record can fail several checks, so the absent counts across rows must not be added as though they were distinct customers. Completeness does not itself prove that a field is accurate.

Figure data and text version
Evidence fieldPresentAbsent
scope1,00610
trigger1,0115
action99620
notice1,00610
evidence99125
Figure 07 / 12

A generated notice is not a delivered notice

A generated notice is not a delivered notice — Boundary-condition verification. Count; generated equals delivered plus unresolved. Exact values are in the figure data below.
Count; generated equals delivered plus unresolved

986 completed records generate a modeled notice event. 976 have a delivered state and 10 do not. The system must distinguish generation, dispatch, delivery evidence, and any required follow-up under the actual process.

Figure data and text version
Communication stateNotices
Generated986
Delivered state recorded976
Delivery unresolved10
Figure 08 / 12

Authority differs by operation

Authority differs by operation — Boundary-condition verification. Illustrative permission matrix. Exact values are in the figure data below.
Illustrative permission matrix

The access matrix is a proposed teaching separation of duties. Read, propose, approve, and administer are distinct capabilities. The final policy must match the organization’s actual roles and obligations, with controlled emergency access and an audit trail.

Figure data and text version
RoleRead evidencePropose actionApprove release
control assuranceScopedYesNo
Independent approverScopedNoYes
SupportLimitedRequest onlyNo
System administratorOperational logsNoNo
Figure 09 / 12

Exceptions need capacity and a closing state

Exceptions need capacity and a closing state — Boundary-condition verification. Records per observation window. Exact values are in the figure data below.
Records per observation window

The control has 30 incomplete records. The available exception capacity covers 30, leaving 0 pending. A pending state requires an owner and a next action; changing a status label without resolving the required behavior does not close the gap.

Figure data and text version
Queue itemRecordsMeaning
Exceptions opened30Eligible workflow incomplete
Capacity applied30Records handled in this window
Pending exceptions0Still require an owned response
Figure 10 / 12

A rate includes its denominator

A rate includes its denominator — Boundary-condition verification. Percent; named populations. Exact values are in the figure data below.
Percent; named populations

These rates deliberately use different populations. Overall throughput, eligible coverage, completed-record timeliness, and delivery evidence are not interchangeable. Each needs the same cohort, cutoff, and definition every time it is compared.

Figure data and text version
MetricNumeratorDenominatorPercent
Eligible coverage9861,01697.05
On-time among completed97198698.48
On-time among eligible9711,01695.57
Delivered among generated97698698.99
Figure 11 / 12

A change needs an evidence trail

A change needs an evidence trail — Boundary-condition verification. Control-change lifecycle. Exact values are in the figure data below.
Control-change lifecycle

The trigger is An item exactly at a time or amount boundary follows the wrong branch.. A controlled change connects the revised requirement or interpretation to implementation, replay, customer impact, and approval. The old version remains relevant to decisions already made under it.

Figure data and text version
StageRetained proof
InterpretScope, source, effective date, and owner
ImplementVersioned logic, data contract, and message template
VerifyBoundary cases and affected-population comparison
ReleaseApproval, start time, and rollback condition
CorrectAffected records and customer outcome where required
Figure 12 / 12

Correction follows the affected population

Correction follows the affected population — Boundary-condition verification. Illustrative correction responsibilities. Exact values are in the figure data below.
Illustrative correction responsibilities

A remediation map links the defect to affected records, financial consequences, communication, and closure evidence. It should retain exclusions and unresolved cases. A change that prevents future failures does not by itself correct earlier customer outcomes.

Figure data and text version
FromToRelationship
Boundary-condition verificationAffected populationReproducible query
Affected populationFinancial reviewAmount and balance impact
Affected populationCustomer messageRequired communication
Financial reviewClosure evidenceVerified adjustment
Customer messageClosure evidenceDelivery and follow-up

Connect the result to the system

Specify inclusivity, time basis, null handling, and the relevant source before implementation.

Check the population, evidence, permitted action, and actual effect together. A balanced calculation can still use the wrong population; a successful response can still leave an unknown financial outcome. The case’s numerical result applies only to its stated assumptions.

Sources and further reading

The chapter sources support the concepts and scope. They do not prescribe the synthetic model rates.

  1. Regulation B, 12 CFR 1002.9: notifications
  2. Regulation E, 12 CFR 1005.11: error resolution
  3. Federal Reserve SR 23-4: third-party relationships