Customer Transparency Register
The Customer Transparency Register (/governance/transparency) catalogues every disclosure your organization publishes about its AI systems — to customers, regulators, the public, or internal stakeholders. It implements ISO/IEC 42001:2023 Annex A.10.4 (Information for interested parties) and is available to Enterprise tier when the per-organization ISO 42001 toggle is enabled.
Audiences & types
Each disclosure tags an audience and a disclosure type:
- Audience: customers, regulators, public, internal.
- Type: notice, contract clause, DPA addendum, marketing statement.
Disclosures may be linked to a specific AI System or Use Case for traceability. The register shows KPI tiles for Active, Expiring, Withdrawn, and By-audience counts.
Lifecycle & supersede
Status flows: draft → published → (superseded or withdrawn). Use the Supersede action to publish a new version that automatically links to the previous one via supersedes_id, preserving the full disclosure history.
Withdraw records a reason, stamps withdrawn_at, and moves the record into the Archive tab. Withdrawn disclosures are never deleted — they remain available as audit evidence.
Expiry watch
expires_at date, the daily system-checks job (03:00 EST / 08:00 UTC) notifies all OrgAdmins via the in-app notification bell and emits the TRANSPARENCY_DISCLOSURE_EXPIRING_NOTIFIED audit code. The sweep is idempotent (stamped via expiry_notified_at) and does not auto-withdraw — the governance owner reviews and either republishes a new version or formally withdraws.Auditing & access
All actions write immutable entries to the org and Platform Activity Log:
TRANSPARENCY_DISCLOSURE_CREATED,_PUBLISHED,_UPDATEDTRANSPARENCY_DISCLOSURE_SUPERSEDED,_WITHDRAWNTRANSPARENCY_DISCLOSURE_EXPIRING_NOTIFIED
Read access is org-wide; admin / approver / reviewer roles can manage. The branded DOCX export (RhindonCyber_TransparencyDisclosures_<date>.docx) is available from the page toolbar.
