Verdict: NOT READY · and nine weeks to change that
"An outside key found six failures our own review rated green, each traced to the exact clause the assessor will probe · and left us a dated plan that fixes them before anyone official is in the room."
Veyra Mobility Systems · a Tier-1 with a date on the calendar
Veyra ships telematics and body ECUs to two OEMs. Its fleet telemetry "exists, but nobody trusts the picture": three dashboards disagree on fleet health, the OTA rail has never rolled back in anger, and the customer's ASPICE assessment is scheduled for Q1. Teams are 30% smaller than in 2024; AI copilots write half the new code and most of the documentation. Their internal review, run with their own AI on their own artifacts, rated the program green two months ago.
1 · "If the assessment were tomorrow, which of these 21 evidence items could you show me today?" · the room went quiet at item four. 2 · "Has your AI's self-review ever been graded against an answer key it didn't write?" · it hadn't, and section III shows what it missed.
Five vehicle domains × four rubric domains, rated 0–4
| Vehicle domain | Data plane | OTA discipline | Field-issue loop | Org readiness |
|---|---|---|---|---|
| ADAS | 3Managed | 2Defined | 2Defined | 3Managed |
| Digital cluster | 4Optimizing | 3Managed | 3Managed | 3Managed |
| Infotainment | 3Managed | 3Managed | 2Defined | 2Defined |
| Body & chassis | 1Ad-hoc | 1Ad-hoc | 0Absent | 1Ad-hoc |
| Powertrain | 3Managed | 2Defined | 3Managed | 2Defined |
Scale: 0 Absent · 1 Ad-hoc (exists somewhere, unowned) · 2 Defined (documented, not enforced) · 3 Managed (enforced + measured) · 4 Optimizing. Every cell in the full readout carries its evidence pointer and the roadmap item it feeds. Body & chassis is the classic blind spot: comfort failures surfacing as warranty claims 60–90 days late.
What the car can't show: 8 of 19 work products fully evidenced
| Standard | Evidenced | The gap that matters most |
|---|---|---|
| ASPICE 4.0 | 3 / 6 | Problem-resolution records (SUP.9) absent · alarms fire, nothing links them to closed problems. |
| ISO 26262 | 1 / 4 | Safety case lacks confirmation-measure reports; internal-only sign-off, no independence level argued. |
| ISO/SAE 21434 · R155 | 0 / 3 | No field-monitoring or incident-response records · the first thing a homologation authority requests. |
| SOTIF · ISO 21448 | 1 / 3 | No unknown-unsafe discovery loop: fleet findings never feed the scenario catalogue. |
| OTA · R156 | 1 / 3 | Rollback described in the update policy; never exercised. A drill is scheduled in week one of the plan. |
The AI finding their AI could not make
Veyra's documentation is beautiful · that was the finding. Generated by the same models that wrote the code, it is consistent without corresponding: the traceability matrix references two requirement IDs that exist nowhere in the requirements set, and four of the newest unit tests assert nothing at all. Cross-checking documents against each other finds zero defects; checking them against behavior found six. An internal review cannot make this finding, structurally: it grades homework with the answer key that wrote it.
Their parameters, loaded; their weak cases, failing on screen
Rehearsal runs on Ordinara's live instrument · a single inspectable HTML file executed inside the client's perimeter (their security team read it line by line first; nothing egresses). Veyra's thresholds were loaded through the golden parameter file; the team then faced the same probes their assessor will use. This is the moment the sprint sells itself: the alarm below cites the exact rule, and the engineer who owns that threshold practiced defending it out loud.
Two of the six failing cases, as the readout states them
From NOT READY to a quiet assessment day
Stop the evidence bleed
- R-01 Rollback drill on the OTA rail · exercised, recorded, repeatable (R156's four controls closed).
- R-02 Field-monitoring + incident-response records started (21434/R155's first ask).
- R-05 Assert-nothing tests replaced; phantom requirement IDs purged; AI-generation guardrails written.
Close the failing six
- R-03 Chassis integration set re-run; safety-mechanism evidence refreshed with dates that match the git history.
- R-04 Body & chassis telemetry: state-delta ingestion for the top five subsystems (the 0-rated cell moves first).
- R-06 Safety-case confirmation measures with an argued independence level.
Rehearse again, then the real one
- R-07 Full dress rehearsal on the instrument; target 21/21 with every owner speaking to their threshold.
- R-08 Optional: standing cadence via the Fractional Advisor · the outside answer key, monthly, exits monthly.
Why this survives your hardest questions
No assessor certification is held or claimed. You already buy referees · your OEM's assessors, your homologation authority. This engagement is run by someone who spent twenty years on the supplier side of their table, and it exists so their visit goes quietly.
One readable HTML file, executed in your perimeter. Your security team can verify line by line that nothing leaves. Reports carry judgments and %-beyond-limit · never your absolute parameters.
AI-written documentation is consistent by construction; it is checked against the system, not against itself. Live probes, thread pulls, and the one question no model can answer for an engineer: "why is this threshold what it is?"
Founding clients: your QA lead picks three threads at random and gives the method two hours. No finding your own team agrees is real · no fee.
Fixed scope, fixed clock, no production access
Assess-only from US$6,500 · full sprint (assess + rehearse + coach) US$12,000–18,000 · 2–3 weeks · read-only artifacts and interviews · 50% at signature, 50% on delivery · completion guarantee · tooling licensed for the engagement; the report and the plan are yours.
Bring your AI's latest self-review · the first disagreement is usually visible within fifteen minutes.