SDV Audit-Readiness Sprint · Sample Readout
Advisory · Tier 3 · Sample readout · Fictional client

SDV Audit-Readiness Sprint

the audit before your audit · a sample of what you receive

This is the readout a sponsor forwards upward at the end of the sprint: the gap grid, the evidence inventory, the rehearsal record with every failing case cited to its standard, and the 90-day plan the team owns. The client below is fictional; the method, the instrument and the document are exactly what you get.

assess from US$6,500 · full sprint US$12–18k 2–3 weeks zero-egress instrument read-only · no production access 50% at signature · 50% on delivery
What is simulated and what is real. "Veyra Mobility Systems" is fictional and every number in this document is a labeled simulation. The reference architecture, the parameter catalog (157 thresholds, standards-traceable), the test plan and the live instrument are real Ordinara assets · demonstrated live, on request, in the first meeting. No certification, audit or homologation service is provided or implied; all standards mappings are engineering interpretation.
The 60-second read

Verdict: NOT READY · and nine weeks to change that

6 / 21
rehearsal cases failing against the fictitious plan TP-SDV-2026
every failure cited to ASPICE · 26262 · 21434 · SOTIF
8 / 19
required work products fully evidenced; 11 partial or missing
the artifact request list is on page 2
0
rollback drills ever exercised on the OTA rail
a capability described is not a capability
9 wks
projected to READY with the 90-day plan, before the Q1 OEM assessment
owners named per item
The sentence the sponsor forwards

"An outside key found six failures our own review rated green, each traced to the exact clause the assessor will probe · and left us a dated plan that fixes them before anyone official is in the room."

I · The fictional client

Veyra Mobility Systems · a Tier-1 with a date on the calendar

Veyra ships telematics and body ECUs to two OEMs. Its fleet telemetry "exists, but nobody trusts the picture": three dashboards disagree on fleet health, the OTA rail has never rolled back in anger, and the customer's ASPICE assessment is scheduled for Q1. Teams are 30% smaller than in 2024; AI copilots write half the new code and most of the documentation. Their internal review, run with their own AI on their own artifacts, rated the program green two months ago.

The two questions that opened the engagement

1 · "If the assessment were tomorrow, which of these 21 evidence items could you show me today?" · the room went quiet at item four.   2 · "Has your AI's self-review ever been graded against an answer key it didn't write?" · it hadn't, and section III shows what it missed.

II · Assess · the gap grid

Five vehicle domains × four rubric domains, rated 0–4

Vehicle domainData planeOTA disciplineField-issue loopOrg readiness
ADAS3Managed2Defined2Defined3Managed
Digital cluster4Optimizing3Managed3Managed3Managed
Infotainment3Managed3Managed2Defined2Defined
Body & chassis1Ad-hoc1Ad-hoc0Absent1Ad-hoc
Powertrain3Managed2Defined3Managed2Defined

Scale: 0 Absent · 1 Ad-hoc (exists somewhere, unowned) · 2 Defined (documented, not enforced) · 3 Managed (enforced + measured) · 4 Optimizing. Every cell in the full readout carries its evidence pointer and the roadmap item it feeds. Body & chassis is the classic blind spot: comfort failures surfacing as warranty claims 60–90 days late.

III · Assess · the evidence inventory

What the car can't show: 8 of 19 work products fully evidenced

StandardEvidencedThe gap that matters most
ASPICE 4.03 / 6Problem-resolution records (SUP.9) absent · alarms fire, nothing links them to closed problems.
ISO 262621 / 4Safety case lacks confirmation-measure reports; internal-only sign-off, no independence level argued.
ISO/SAE 21434 · R1550 / 3No field-monitoring or incident-response records · the first thing a homologation authority requests.
SOTIF · ISO 214481 / 3No unknown-unsafe discovery loop: fleet findings never feed the scenario catalogue.
OTA · R1561 / 3Rollback described in the update policy; never exercised. A drill is scheduled in week one of the plan.

The AI finding their AI could not make

Veyra's documentation is beautiful · that was the finding. Generated by the same models that wrote the code, it is consistent without corresponding: the traceability matrix references two requirement IDs that exist nowhere in the requirements set, and four of the newest unit tests assert nothing at all. Cross-checking documents against each other finds zero defects; checking them against behavior found six. An internal review cannot make this finding, structurally: it grades homework with the answer key that wrote it.

IV · Rehearse · the game day, on the instrument

Their parameters, loaded; their weak cases, failing on screen

Rehearsal runs on Ordinara's live instrument · a single inspectable HTML file executed inside the client's perimeter (their security team read it line by line first; nothing egresses). Veyra's thresholds were loaded through the golden parameter file; the team then faced the same probes their assessor will use. This is the moment the sprint sells itself: the alarm below cites the exact rule, and the engineer who owns that threshold practiced defending it out loud.

ALARM ptrain-emerging-defect · P0301 ×27 > 20/24h · cal cal-2.8.0  ·  ALARM body-stall-events · 23 > 20/24h (oscillating stall signature) · SW BC-1.4.0-rc
27P0301 / 24H
2,914BOOT P95 MS
23STALL / 24H
14 / 21CASES PASSING
11 minFIELD-ISSUE LOOP, CLOCKED
FROM THE REHEARSAL RECORD · MIXED-FAULT SCENARIO · SIMULATED FLEET · the live instrument is demonstrated in the first meeting, on request.

Two of the six failing cases, as the readout states them

TP-CH-002Active pressure-build gradientFAIL
Observed: 380 bar/s vs floor 600 bar/s · evidence lost at system qualification
ASPICESYS.4 · integration test of ESC pressure build against FMVSS 135-derived timing; no current run on record. ISO 26262Part 4 §7 · degraded actuation detected; the fault-reaction path has no refreshed evidence. 21434Actuation-path integrity under degraded supply assumed, not evidenced. SOTIFCold/viscous-fluid triggering condition present in the catalogue, untested this release.
Fix, owned: re-run the integration set on the canary group; refresh the safety-mechanism evidence. Owner: chassis lead · 2 weeks · feeds roadmap item R-03.
TP-BD-003HVAC stepper stall signature handlingFAIL
Observed: alarm active, 23 events/24h on SW BC-1.4.0-rc · no owner answered the "why 20?" question
ASPICESWE.4 · the stall-counter detector has generated tests that assert nothing (see §III). ISO 26262QM function; freedom-from-interference with ASIL partitions asserted, not evidenced. 21434Actuator-flood nuisance pattern absent from the TARA. SOTIFPre-failure signature known and documented · and disconnected from the discovery loop.
Fix, owned: real assertions on the detector; threshold rationale documented by its named owner; TARA line added. Owner: body SW lead · 1 week · feeds R-05.
V · Coach · the 90-day plan the team owns

From NOT READY to a quiet assessment day

WKS 1–3

Stop the evidence bleed

  • R-01 Rollback drill on the OTA rail · exercised, recorded, repeatable (R156's four controls closed).
  • R-02 Field-monitoring + incident-response records started (21434/R155's first ask).
  • R-05 Assert-nothing tests replaced; phantom requirement IDs purged; AI-generation guardrails written.
WKS 4–8

Close the failing six

  • R-03 Chassis integration set re-run; safety-mechanism evidence refreshed with dates that match the git history.
  • R-04 Body & chassis telemetry: state-delta ingestion for the top five subsystems (the 0-rated cell moves first).
  • R-06 Safety-case confirmation measures with an argued independence level.
WKS 9–12

Rehearse again, then the real one

  • R-07 Full dress rehearsal on the instrument; target 21/21 with every owner speaking to their threshold.
  • R-08 Optional: standing cadence via the Fractional Advisor · the outside answer key, monthly, exits monthly.
VI · The method, inspectable

Why this survives your hardest questions

Coach, not referee

No assessor certification is held or claimed. You already buy referees · your OEM's assessors, your homologation authority. This engagement is run by someone who spent twenty years on the supplier side of their table, and it exists so their visit goes quietly.

Zero-egress instrument

One readable HTML file, executed in your perimeter. Your security team can verify line by line that nothing leaves. Reports carry judgments and %-beyond-limit · never your absolute parameters.

Behavior over paper

AI-written documentation is consistent by construction; it is checked against the system, not against itself. Live probes, thread pulls, and the one question no model can answer for an engineer: "why is this threshold what it is?"

The blind-probe challenge

Founding clients: your QA lead picks three threads at random and gives the method two hours. No finding your own team agrees is real · no fee.

VII · Terms

Fixed scope, fixed clock, no production access

Assess-only from US$6,500 · full sprint (assess + rehearse + coach) US$12,000–18,000 · 2–3 weeks · read-only artifacts and interviews · 50% at signature, 50% on delivery · completion guarantee · tooling licensed for the engagement; the report and the plan are yours.

The instrument is demonstrated live, in the first meeting.

Bring your AI's latest self-review · the first disagreement is usually visible within fifteen minutes.

Book a call See the instrument teaser → Assess phase, worked end to end on a cockpit program →