Worked case · Controlled response · 12 figures

Boundary-condition verification

Test the boundary conditions

Figure 01 / 12

Determine the eligible population first

Determine the eligible population first — Boundary-condition verification. Count; records. Exact values are in the figure data below.
Count; records

Of 1,320 source records, 1,016 are within the stated synthetic scope and 304 are outside it. Eligibility here is an explicit teaching input, not a legal conclusion. Production classification must use the actual entity, product, activity, jurisdiction, and facts.

Figure data and text version
Scope stateRecords
Within stated scope1,016
Outside stated scope304

A control can work for ordinary cases and fail at a cutoff, product change, or missing-data condition. Those boundaries need deliberate evidence.

Specify inclusivity, time basis, null handling, and the relevant source before implementation.

All amounts, rates, capacity limits, and outcomes in this case are synthetic. The three conditions are separate assumptions for comparison. A better result in the response condition is not measured proof that the proposed control causes that improvement. The figures expose the calculation and its limits; a real deployment needs its own evidence.

Read the result

The case identifies 1,016 eligible records from a source population of 1,320. The required workflow completes for 1,011, but 5 completed records miss the illustrative internal target. Another 5 remain incomplete. Communication evidence covers 1,009 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

Model inputs and calculated values

Inputs below are the case-specific values. Each figure states the condition-specific assumptions and units used in its calculation. Calculated values are rounded for display.

InputValue
population1,320
eligibility0.77
Calculated valueResult
population1,320
eligible1,016
excluded304
complete1,011
incomplete5
late5
ontime1,006
notices1,009
undelivered2
pending0
reviewed5
Figure 02 / 12

A control can miss eligible records

A control can miss eligible records — Boundary-condition verification. Count at a fixed observation cutoff. Exact values are in the figure data below.
Count at a fixed observation cutoff

The required workflow completes for 1,011 of the 1,016 eligible records. The 5 remainder needs an owned exception path. Reporting completion as a percentage of all source records would answer a different question and could hide the actual coverage gap.

Figure data and text version
MeasureRecords
Eligible records1,016
Workflow completed1,011
Workflow incomplete5
Figure 03 / 12

Completion and timeliness are distinct outcomes

Completion and timeliness are distinct outcomes — Boundary-condition verification. Count; exclusive states within eligible population. Exact values are in the figure data below.
Count; exclusive states within eligible population

The illustration applies an internal target, not a statutory deadline. Of 1,011 completed records, 5 miss that target and 1,006 meet it. The 5 open records are a third state; do not automatically classify them as timely merely because their final outcome is unknown.

Figure data and text version
OutcomeEligible records
Complete within target1,006
Complete after target5
Still incomplete5
Figure 04 / 12

An obligation record connects authority to behavior

An obligation record connects authority to behavior — Boundary-condition verification. Control contract. Exact values are in the figure data below.
Control contract

This case implements test the boundary conditions. The record separates scope, trigger, required action, ownership, and retained proof. Exact legal duties belong to the applicable source and interpretation; the timing and counts in this worked example are synthetic.

Figure data and text version
ElementIllustrative value
Control subjectBoundary-condition verification
ScopeThe eligible population defined above
TriggerAn item exactly at a time or amount boundary follows the wrong branch.
Required behaviortest the boundary conditions
Ownercontrol assurance
EvidenceVersioned event, action, and communication records
Figure 05 / 12

Different clocks start from different facts

Different clocks start from different facts — Boundary-condition verification. Internal teaching timeline; not a legal deadline schedule. Exact values are in the figure data below.
Internal teaching timeline; not a legal deadline schedule

These relative times are illustrative service targets. They deliberately distinguish customer contact, receipt by the institution, classification, investigation, and communication. A routing delay must not silently replace the original receipt time when that fact matters.

Figure data and text version
EventIllustrative timeRecord
Customer reportT0Original channel and words
Institution receiptT0 + 5 minutesRetained receipt timestamp
ClassificationT0 + 20 minutesApplicable process and owner
Internal review targetT0 + 1 dayInternal target only
Outcome communicationAt decisionContent, destination, and delivery state
Figure 06 / 12

Evidence fields fail independently

Evidence fields fail independently — Boundary-condition verification. Count; overlapping field-level checks. Exact values are in the figure data below.
Count; overlapping field-level checks

Each row is one evidence requirement over the eligible population. The same record can fail several checks, so the absent counts across rows must not be added as though they were distinct customers. Completeness does not itself prove that a field is accurate.

Figure data and text version
Evidence fieldPresentAbsent
scope1,0142
trigger1,0133
action1,0115
notice1,0142
evidence1,0124
Figure 07 / 12

A generated notice is not a delivered notice

A generated notice is not a delivered notice — Boundary-condition verification. Count; generated equals delivered plus unresolved. Exact values are in the figure data below.
Count; generated equals delivered plus unresolved

1,011 completed records generate a modeled notice event. 1,009 have a delivered state and 2 do not. The system must distinguish generation, dispatch, delivery evidence, and any required follow-up under the actual process.

Figure data and text version
Communication stateNotices
Generated1,011
Delivered state recorded1,009
Delivery unresolved2
Figure 08 / 12

Authority differs by operation

Authority differs by operation — Boundary-condition verification. Illustrative permission matrix. Exact values are in the figure data below.
Illustrative permission matrix

The access matrix is a proposed teaching separation of duties. Read, propose, approve, and administer are distinct capabilities. The final policy must match the organization’s actual roles and obligations, with controlled emergency access and an audit trail.

Figure data and text version
RoleRead evidencePropose actionApprove release
control assuranceScopedYesNo
Independent approverScopedNoYes
SupportLimitedRequest onlyNo
System administratorOperational logsNoNo
Figure 09 / 12

Exceptions need capacity and a closing state

Exceptions need capacity and a closing state — Boundary-condition verification. Records per observation window. Exact values are in the figure data below.
Records per observation window

The control has 5 incomplete records. The available exception capacity covers 5, leaving 0 pending. A pending state requires an owner and a next action; changing a status label without resolving the required behavior does not close the gap.

Figure data and text version
Queue itemRecordsMeaning
Exceptions opened5Eligible workflow incomplete
Capacity applied5Records handled in this window
Pending exceptions0Still require an owned response
Figure 10 / 12

A rate includes its denominator

A rate includes its denominator — Boundary-condition verification. Percent; named populations. Exact values are in the figure data below.
Percent; named populations

These rates deliberately use different populations. Overall throughput, eligible coverage, completed-record timeliness, and delivery evidence are not interchangeable. Each needs the same cohort, cutoff, and definition every time it is compared.

Figure data and text version
MetricNumeratorDenominatorPercent
Eligible coverage1,0111,01699.51
On-time among completed1,0061,01199.51
On-time among eligible1,0061,01699.02
Delivered among generated1,0091,01199.8
Figure 11 / 12

A change needs an evidence trail

A change needs an evidence trail — Boundary-condition verification. Control-change lifecycle. Exact values are in the figure data below.
Control-change lifecycle

The trigger is An item exactly at a time or amount boundary follows the wrong branch.. A controlled change connects the revised requirement or interpretation to implementation, replay, customer impact, and approval. The old version remains relevant to decisions already made under it.

Figure data and text version
StageRetained proof
InterpretScope, source, effective date, and owner
ImplementVersioned logic, data contract, and message template
VerifyBoundary cases and affected-population comparison
ReleaseApproval, start time, and rollback condition
CorrectAffected records and customer outcome where required
Figure 12 / 12

Correction follows the affected population

Correction follows the affected population — Boundary-condition verification. Illustrative correction responsibilities. Exact values are in the figure data below.
Illustrative correction responsibilities

A remediation map links the defect to affected records, financial consequences, communication, and closure evidence. It should retain exclusions and unresolved cases. A change that prevents future failures does not by itself correct earlier customer outcomes.

Figure data and text version
FromToRelationship
Boundary-condition verificationAffected populationReproducible query
Affected populationFinancial reviewAmount and balance impact
Affected populationCustomer messageRequired communication
Financial reviewClosure evidenceVerified adjustment
Customer messageClosure evidenceDelivery and follow-up

Connect the result to the system

Specify inclusivity, time basis, null handling, and the relevant source before implementation.

Check the population, evidence, permitted action, and actual effect together. A balanced calculation can still use the wrong population; a successful response can still leave an unknown financial outcome. The case’s numerical result applies only to its stated assumptions.

Sources and further reading

The chapter sources support the concepts and scope. They do not prescribe the synthetic model rates.

  1. Regulation B, 12 CFR 1002.9: notifications
  2. Regulation E, 12 CFR 1005.11: error resolution
  3. Federal Reserve SR 23-4: third-party relationships