Part 8: Enforcement and Audit

Utah Code §§ 63A-20-801 and 63A-20-802 establish the enforcement and audit framework for the SEDI program. While primarily administrative and legal in nature, these sections have technical implications for logging, evidence preservation, and auditability.

Req ID

63A-20

Requirement

Control

Governance

SEDI-ENF-01

801(1)

Complaint submission mechanism

EXPT

Statute

SEDI-ENF-02

801(4)-(6)

Attorney general enforcement support

ADMN

Statute

SEDI-ENF-03

802(1)

Legislative audit

EXPT

Statute

SEDI-ENF-04

802(2)(b)

Anti-surveillance architectural proof

EXPT

Statute

SEDI-ENF-05

802(3)(a)

Audit report deadline

ADMN

Statute

SEDI-ENF-01: Complaint submission mechanism

An individual may submit a complaint to the data privacy ombudsperson alleging a violation by the department, a digital wallet provider, a verifier, or a relying party.

Utah Code § 63A-20-801(1)

Requirement: The SEDI program SHALL provide a complaint submission mechanism accessible to holders. Complaint records SHALL be maintained by the ombudsperson's office.

Criticality: High — Without an accessible complaint mechanism, individuals have no statutory avenue to report violations, undermining the enforcement framework.

Roles: Department, Data Privacy Ombudsperson

Assessment Objectives

Determine if:

  1. a complaint submission mechanism is provided and accessible to holders;
  2. the complaint submission endpoint is reachable and accepts valid complaint payloads;
  3. submitted complaints generate a confirmation and tracking identifier for the complainant;
  4. complaint records are maintained by the ombudsperson's office, searchable, and linked to resolution status;
  5. the complaint mechanism is accessible to individuals without SEDI (physical submission option exists);
  6. the complaint mechanism is publicly documented and discoverable;
  7. complaint volume and resolution metrics are tracked.

Verification Methods

Method

Applicability

Performed By

Frequency

Limitations

AUTO

Recommended

Conformance test suite

Per-release

Cannot assess accessibility for non-digital users or verify that complaints reach the ombudsperson's office

EXPT

Mandatory

Independent assessor

Annual

Point-in-time; does not detect service degradation between assessments

ADMN

Recommended

Program auditor

Annual

Cannot verify technical availability or user experience quality

Objective coverage: AUTO → 2, 3; EXPT → 1, 4, 5; ADMN → 6, 7

Assessment objects: Complaint submission interface (digital and physical channels); complaint record database and search functionality; confirmation and tracking identifier generation logic; ombudsperson office staffing and procedural documentation; public-facing complaint mechanism documentation and discoverability assessment; complaint volume and resolution metric reports.

Statutory compliance: Expert review is mandatory because complaint mechanism adequacy requires human assessment of accessibility, usability, and end-to-end procedural completeness. Automated checks supplement by verifying technical availability.

SEDI-ENF-02: Attorney general enforcement support

Derived: Attorney general enforcement powers including civil investigative demands, civil actions, and remedies. 

(Utah Code § 63A-20-801(4) through -(6)

Requirement: All ecosystem participants SHALL maintain records sufficient to support civil investigative demands. Compliance evidence SHALL be producible upon lawful request.

Criticality: Medium — Insufficient recordkeeping could impede enforcement actions, but the primary obligation is organizational rather than system-critical.

Roles: All ecosystem participants

Assessment Objectives

Determine if:

  1. recordkeeping policies exist and specify retention periods sufficient for investigative timelines;
  2. evidence preservation procedures are documented and staff are trained on their execution;
  3. records are producible in formats suitable for legal proceedings;
  4. compliance evidence is producible upon lawful request within required timelines;
  5. prior civil investigative demands (if any) were satisfied within required timelines.

Verification Methods

Method

Applicability

Performed By

Frequency

Limitations

AUTO

N/A

Recordkeeping for legal enforcement and evidence preservation are organizational and legal compliance processes outside the SEDI system boundary

ADMN

Mandatory

Program auditor

Annual

Cannot verify completeness of records or that preservation procedures will function under actual legal process

EXPT

N/A

Attorney general enforcement powers are legal authorities; no technical specification to review

Objective coverage: ADMN → 1, 2, 3, 4, 5

Assessment objects: Recordkeeping policies and retention schedules; evidence preservation procedures and training records; record export and production capabilities documentation; prior civil investigative demand responses and timelines; staff training materials for legal hold and evidence preservation; record format specifications and legal production templates.

Statutory compliance: Only administrative verification is feasible because recordkeeping for legal enforcement and evidence preservation are organizational and legal compliance processes, not technical controls that can be programmatically validated.

SEDI-ENF-03: Legislative audit

Subject to prioritization of the Legislative Audit Subcommittee created in Utah Code § 36-12-8, the Office of the Legislative Auditor General shall conduct an audit of the program beginning on January 1, 2028.

Utah Code § 63A-20-802(1)

Requirement: The Department SHALL maintain auditable records of all program operations, technical decisions, security incidents, and compliance activities. Records SHALL be organized to support the audit scope defined in Utah Code § 63A-20-802(2).

Criticality: High — Inadequate audit records would prevent the legislative auditor from fulfilling the statutory audit mandate and could indicate program governance failures.

Roles: Department

Assessment Objectives

Determine if:

  1. audit log infrastructure is operational and accepting entries;
  2. log entries contain required fields (timestamp, actor, action, outcome);
  3. log retention meets the minimum audit-readiness period for the 2028 legislative audit;
  4. auditable records cover program operations, technical decisions, security incidents, and compliance activities;
  5. records are organized to support the audit scope defined in Utah Code § 63A-20-802(2) (surveillance restrictions, program effectiveness, privacy protections);
  6. records are retrievable and producible for the legislative auditor;
  7. a recordkeeping policy exists and references Utah Code § 63A-20-802(2) audit scope;
  8. staff are trained on audit-ready documentation practices.

Verification Methods

Method

Applicability

Performed By

Frequency

Limitations

AUTO

Recommended

Conformance test suite

Quarterly

Cannot assess whether log content is substantively complete or organized for the audit scope in Utah Code § 63A-20-802(2)

EXPT

Mandatory

Independent assessor

Annual

Point-in-time; cannot guarantee records will remain complete and organized through the 2028 audit

ADMN

Recommended

Program auditor

Annual

Cannot verify technical completeness or accuracy of records

Objective coverage: AUTO → 1, 2, 3; EXPT → 4, 5, 6; ADMN → 7, 8

Assessment objects: Audit log infrastructure configuration and health monitoring; log entry samples and field completeness reports; log retention policies and storage capacity planning; program operation records and decision documentation; security incident records and response reports; compliance activity documentation; record organization schema mapped to Utah Code § 63A-20-802(2) scope; staff training records for audit-ready documentation; record retrieval and export procedures.

Statutory compliance: Expert review is mandatory because audit readiness requires professional assessment of whether records substantively cover the legislative audit scope. Automated checks supplement by verifying log infrastructure is operational and retaining entries.

SEDI-ENF-04: Anti-surveillance architectural proof

The audit shall evaluate whether the department has met the restrictions on monitoring, surveillance, and tracking described in Utah Code § 63A-20-301.

Utah Code § 63A-20-802(2)(b)

Requirement: The Department SHALL be able to demonstrate, through architectural documentation, system logs, and independent analysis, that its systems are incapable of monitoring, surveilling, or tracking presentations. This is a "prove the negative" requirement that demands architectural evidence, not merely policy assertions.

Criticality: Critical — Inability to prove anti-surveillance architecture would fail the legislative audit and undermine the foundational privacy guarantee of the program.

Roles: Department

Assessment Objectives

Determine if:

  1. Department systems do not contain presentation metadata fields (verifier identity, presentation timestamp correlations, holder-verifier linkage);
  2. no API endpoints in Department systems accept or return presentation tracking data;
  3. status-list queries are unlinkable to specific credentials;
  4. systems are structurally incapable of monitoring, surveilling, or tracking presentations;
  5. no Department system contains data that could reconstruct presentation patterns;
  6. architectural documentation demonstrates anti-surveillance design and is current;
  7. independent security assessments of anti-surveillance architecture have been completed and findings addressed;
  8. Department policy prohibits collection or retention of presentation metadata.

Verification Methods

Method

Applicability

Performed By

Frequency

Limitations

AUTO

Recommended

Conformance test suite

Per-release + CI

Cannot detect metadata leakage through side channels, operational logs, or infrastructure-level telemetry

EXPT

Mandatory

Security assessor / Independent assessor

Annual + pre-audit

Point-in-time; architectural changes after review could introduce surveillance capability

ADMN

Recommended

Program auditor

Annual

Policy assertions alone are insufficient; cannot substitute for technical architectural proof

Objective coverage: AUTO → 1, 2, 3; EXPT → 4, 5, 6; ADMN → 6, 7, 8

Assessment objects: System architecture diagrams and anti-surveillance design documentation; API endpoint inventories and data field specifications; status-list implementation and query linkability analysis; data flow diagrams showing absence of presentation metadata paths; system log configurations and retention policies; independent security assessment reports and remediation records; Department policy documents on presentation metadata; infrastructure telemetry and operational log configurations.

Statutory compliance: Expert review is mandatory because "prove the negative" requires independent professional analysis of architecture, data flows, and system capabilities, not merely automated scans. Automated testing supplements by continuously verifying no presentation metadata surfaces in Department systems.

SEDI-ENF-05: Audit report deadline

Complete the audit report by October 31, 2028.

Utah Code § 63A-20-802(3)(a)

Requirement: Administrative timeline; no direct technical requirement. The Department SHALL cooperate fully with audit activities to support timely completion.

Criticality: Medium — The deadline is a statutory obligation of the Legislative Auditor General; the Department's role is to ensure its cooperation does not cause delay.

Roles: Legislative Auditor General

Assessment Objectives

Determine if:

  1. the audit engagement timeline is on track for October 31, 2028 completion;
  2. the Department has responded to audit requests within agreed timelines;
  3. no outstanding audit information requests are overdue;
  4. the Department has cooperated fully with audit activities to support timely completion.

Verification Methods

Method

Applicability

Performed By

Frequency

Limitations

AUTO

N/A

Audit timeline compliance is an administrative coordination obligation between the Department and the Legislative Auditor General, not a technical property of the SEDI system

ADMN

Mandatory

Program auditor

As needed (pre-deadline)

Cannot enforce audit completion by an external legislative office; Department can only control its own cooperation

EXPT

N/A

Audit scope and methodology are organizational decisions; no technical system to review

Objective coverage: ADMN → 1, 2, 3, 4

Assessment objects: Audit engagement letter and project timeline; Department response logs for audit information requests; outstanding request tracker and overdue item reports; Department cooperation records and correspondence with the Legislative Auditor General.

Statutory compliance: Only administrative verification is feasible because this is a statutory deadline for a legislative office. No technical control can enforce audit completion timing.