In discussions about safety, assurance, and governance, evidence is often treated as a matter of age.
A certificate issued ten years ago is viewed differently from one issued last month. An inspection completed several years ago carries less weight than one completed yesterday. A maintenance record from a previous cycle is considered less persuasive than a recently completed service report.
The underlying assumption appears reasonable. As evidence becomes older, confidence in its relevance declines. As evidence becomes more recent, confidence increases.
For this reason, many assurance frameworks place considerable emphasis on freshness. Certificates expire. Audits are repeated. Inspections are scheduled. Maintenance intervals are defined. Across industries, the belief persists that reducing the time between verification events improves confidence in the condition of the system being relied upon.
There is truth in this.
Fresh evidence is generally preferable to stale evidence.
The difficulty is that freshness and accuracy are not the same thing.
A certificate may be valid.
An audit may be recent.
An inspection may be current.
Yet the operational reality of the system may already have changed.
This distinction becomes increasingly important as systems become more dynamic, interconnected, and software dependent.
Historically, periodic verification often served as a practical proxy for operational condition. Mechanical systems changed relatively slowly. Environmental conditions were generally stable. Components were rarely altered without physical intervention. Under such circumstances, it was often reasonable to assume that a condition observed during inspection remained substantially unchanged until the next verification event.
Modern environments are different.
Software updates alter behaviour without changing certification status. Configuration changes occur remotely. Components are replaced like-for-like without triggering reassessment. New dependencies emerge through integration with other systems. Environmental conditions fluctuate continuously. Cyber-physical systems increasingly depend upon information that exists outside the physical boundary of the device itself.
As a result, the interval between verification and reliance becomes more significant than the verification event itself.
A system may be inspected on Monday and relied upon on Friday.
The inspection remains fresh.
The evidence remains current.
The question is whether the system remains unchanged.
Freshness establishes when evidence was collected.
It does not establish whether reality remained consistent after collection.
This creates what may be described as the expiry illusion.
The illusion is that evidence remains representative of reality simply because it remains within its declared validity period.
In practice, validity periods govern time.
They do not govern state.
A document can remain valid while the conditions it describes have already changed.
A maintenance report may accurately record the condition of a fire door at the moment it was inspected. It does not establish whether the door remained unobstructed, undamaged, and operational every day thereafter.
A cybersecurity assessment may accurately describe a system at the moment of testing. It does not establish that new vulnerabilities did not emerge the following week.
A building inspection may accurately reflect the conditions observed during the survey. It does not establish that alterations were not subsequently made.
The evidence itself is not wrong.
The problem is assuming that validity of the evidence guarantees validity of the condition.
These are separate questions.
One concerns whether the evidence remains formally valid.
The other concerns whether the state it describes remains true.
Confusing the two creates a governance blind spot.
Investigations following serious incidents frequently reveal this distinction.
Documentation often exists.
Certificates are available.
Maintenance records are complete.
Audits were conducted.
Procedures were followed.
The difficulty arises when investigators attempt to determine the condition of the system at the precise moment it was relied upon.
The question is no longer whether verification occurred.
The question becomes whether the verified condition persisted.
At this point, freshness alone ceases to answer the problem.
A report can demonstrate that a condition existed.
It cannot necessarily demonstrate that the condition continued to exist.
This becomes particularly significant where responsibility depends upon what was reasonably knowable at the time a decision was made.
Courts, insurers, regulators, and investigators routinely examine what information was available when reliance occurred. They assess whether decisions were reasonable based upon what could have been known. They examine evidence not simply to confirm that processes existed, but to determine whether reliance on a system was justified.
Where state drift occurs inside a validity window, the challenge becomes apparent.
The evidence remains current.
The reality has changed.
The assurance mechanism continues to indicate validity because the expiry date has not yet been reached.
Yet the condition upon which reliance depends may already have deteriorated.
This reveals an important limitation in traditional assurance thinking.
Expiry governs the passage of time.
It does not govern the passage of reality.
A validity period can indicate when evidence becomes too old to trust.
It cannot, by itself, determine whether the underlying state has changed before that point is reached.
The distinction may appear subtle, but its implications are substantial.
As systems become increasingly dynamic, assurance cannot be concerned solely with whether evidence remains within its validity horizon. It must also address whether the condition being evidenced remains true.
Time validity and state validity are not the same thing.
One measures age.
The other measures reality.
A governance framework capable of addressing only the first remains vulnerable to the second.
This leads to a question that existing assurance models increasingly struggle to answer.
If an artefact cannot see state drift occurring inside its own validity window, who or what governs that gap?
About the Author
Paul Mincher is the Founder and CEO of SAFE-Matter Ltd and the originator of the “Unknown Present” concept in safety governance. His work examines the evidentiary gap between regulatory compliance and demonstrable safety in cyber-physical systems.
A survivor of a childhood house fire, he has spent the past decade studying how organisations establish trust in life-critical protections and why serious incidents continue to occur despite formal certification, inspection, and oversight.
His research focuses on how organisations might evidence the operational condition of safety protections at the moment they are relied upon. This work sits at the intersection of safety engineering, accountability, and risk assurance, addressing how regulators, insurers, and duty-holders determine whether protection was actually present when it mattered.
Paul can be reached at https://www.linkedin.com/in/paul-m-4abb44310/ and [email protected]

