Browse by subject:
CHAPTER 9 OF 18
Decision Accounting
~46 min full text
EDITORIAL REVIEW IN PROGRESS
This chapter is public working text. Its sequence and numerical framework have been reconciled, while wording, citations, and study-guide material remain under editorial review. For the learning sequence, return to the curriculum.
CORE LESSON
Decision Accounting — a proposed governance record
~16 min
Decision Accounting as a Report-Incentive MechanismThe Information-Exclusion FoundationEvidence for Decision Accounting
The pattern: information existed, reasoning occurred, the record was never created
When a scandal finally reaches an investigator, the striking discovery is usually not that the organization was ignorant. It is that the organization already knew. The facts that would have flagged the harm sat in inboxes, trading logs, and meeting minutes before the decision was made, yet no one had gathered them into a record that stated, at the moment of choice, what was being risked and why. Decision Accounting begins from that recurring gap. Catastrophic governance failures, it argues, tend to share an architectural feature rather than a failure of knowledge: the information existed, but it was never structured into a record that outlived the decision itself. So when the examiner arrives — a regulator, a litigator, a congressional committee, a grand jury — the reconstruction has to begin from fragments. Decision Accounting asks a different question: what changes when the reasoning is captured at the moment of decision, by the decision-maker, in a structured form that later examiners can read?
The evidence: four cases where absence enabled failure
The Evidence That Decision Accounting Works paper presents four documented cases1 where the absence of a Decision-Accounting record was a necessary condition for catastrophic governance failures: Wells Fargo's cross-selling scandal2, Purdue Pharma's opioid crisis3, Volkswagen's emissions fraud4, and the UK Post Office Horizon scandal. In each case5, the information that would have revealed the harm existed within the organization before the decision was made. It was never structured into a record that forced a system-welfare assessment at the time of decision. The paper then presents two cases where the presence of such records prevented harm or caught bad decisions: Singapore's Monetary Authority enforcement actions6 and the UK Senior Managers and Certification Regime. The paper7 formalizes a falsification condition: if any organization with a fully implemented Decision-Accounting system suffers a comparable failure, the framework is falsified. The burden of proof then shifts to the skeptic to produce a counterexample.
Non-decisions are decisions: the SVB lesson
Some of the most consequential decisions never look like decisions at all. Silicon Valley Bank kept choosing not to hedge its interest-rate exposure8; each quarter that choice was renewed, and each time it passed as ordinary inaction rather than a decision anyone would think to record. Decision Accounting treats those repeated non-decisions as decisions, and it reads the decision timeline against the event timeline running beside it: Federal Reserve inflation warnings, speeches about coming rate increases, futures-market signals, liquidity warnings, deposit-flow changes, risk-leadership vacancies, and internal risk reports.
This is where the software earns its place. A Decision Accounting system watches the event record and prompts the user when it implies a decision that was never logged: if the firm has recorded a choice not to hedge several times while fresh interest-rate warnings keep arriving, the system asks whether a new non-decision record is due. Pairing decisions, non-decisions, events, predictions, and outcomes this way is one of the architecture's largest practical gains.
The discovery: regulatory convergence without coordination
The seventeen fields were not designed at a desk. Sixteen regulatory regimes on four continents had already converged on the same reconstruction architecture over sixty years, each without knowing what the others were doing. Read any one regime and it looks like a local rulebook; read all sixteen side by side and the same core fields appear again and again. That is why the framework is better described as discovered than invented — the pattern was sitting in the regulatory record, waiting to be noticed. Only the seventeenth field, system welfare, had to be added, and it came from the Missing System Theory. The reason the convergence stayed hidden is that no discipline reads across the others. Banking regulation belongs to financial economists, nuclear safety to reliability engineers, aviation certification to human-factors researchers, pharmaceutical approval to regulatory-science specialists. Each studies its own regime in isolation, so no one was standing where all four regimes overlap.
The architecture: seventeen fields, three components
Decision Accounting is a seventeen-field decision record. Fields 1-14 record WHO, WHAT, WHEN, WHERE, WHY, EVIDENCE, AUTHORITY, TRAINING, REVIEW, STAKEHOLDERS, CONSEQUENCES, CONSTRAINTS, UNCERTAINTY, and COMMUNICATION. These fourteen fields reconstruct the ordinary decision record: the information any competent examiner would need to understand what happened and why. Field 15 is ALTERNATIVES: the strongest options considered and rejected, and why each was declined. Field 16 is PREDICTION: a quantified pre-decisional prediction with confidence interval and time horizon — the field scored most directly against later outcomes. Field 17 is SYSTEM WELFARE: the impact of the decision on the system that makes the transaction possible. This field emerged from the Missing System Theory, which establishes that the system-welfare coordinate is invisible to bilateral analysis. The theorem shows that an economy's system-welfare coordinate W is not a function of the parties' payoffs of any transaction by the W-Independence result9 (Proposition 2), which is proved from the three foundational axioms rather than assumed. The same fact appears as an information-exclusion result10: W is absent from the disclosed records firms and markets report, by the same construction that keeps W out of the payoff space.
Append-only records and reconstruction
The glossary defines reconstruction precisely. In Decision Accounting, reconstructability means the software is designed to recover the point-in-time governance state in seconds: the rules, authority, decision records, and prior decisions that governed the organization at a particular moment. Once timestamped, the original decision record is permanent. It cannot be edited, corrected, modified, redacted, or anonymized. A later clarification, correction, reversal, or mitigation update must be made as a new timestamped record linked to the original.
That append-only design is what makes the record useful for management, audit, regulatory review, legal defense, and AI-assisted decision support. The record preserves what the organization knew, decided, predicted, and accepted at the time. Later records show learning, correction, and game change without rewriting the past.
Decision records as the enterprise learning loop
A Decision Accounting record defends the firm after the fact, but its larger value builds up over time. Each material decision, and each material non-decision, becomes a dated entry tied to the warnings that preceded it, the evidence and authority behind it, Field 16, prediction, and Field 17, system welfare impact, along with weak-answer controls, outcome scoring, reconsideration triggers, and tamper-evident integrity, among other fields and controls. What accumulates is a structured record of the firm's own judgment.
That record lets an organization see cause and effect across time in a way scattered documents never allow. It shows which warnings mattered, which choices were missed, which safeguards held, which predictions failed, and which teams keep producing thin records. Ordinary emails, dashboards, and reports still have their uses, but the most valuable internal data a firm holds is the trail of its own consequential judgment.
This is the enterprise decision-data thesis: one record serving as management infrastructure and litigation defense at once. It ties judgment to events, predictions to outcomes, non-decisions to the warnings that should have triggered them, and weak-answer patterns to the losses that follow. It also hands a future decision-support system a dependable internal dataset to learn from. That is why Decision Accounting sits inside governance, risk, audit, legal, and AI-assisted decision support at the same time, rather than in any one of them alone.
The mechanism: making truthful reporting a best response
A framework is not yet a mechanism. A decision-maker whose private return is positively correlated with a negative system impact has an incentive to omit or misreport the system-welfare field. The Decision Accounting as a Report-Incentive Mechanism paper models Field 17 as a verifiable report, not as a rhetorical disclosure field11. A decision-maker bears cost kappa to truthfully record the welfare impact W; a misreport is detected ex post with probability p by an independent reader (one of the seven Conflictoring lanes); on detection the decision-maker bears liability L12. Truthful recording is a best response iff pL >= kappa (Proposition D.1). The unpredictable-reader property makes the detection probability harder for the writer to game. The result separates DA from Myerson-Satterthwaite's private-value impossibility (no efficient bilateral-trade mechanism works when both sides' valuations are private13). The core condition is that the expected sanction must cover the recording cost.
Weak-answer controls and the quality standard
A strong decision record should be accurate, full, defensible, well reasoned, evidence-grounded, legally practical, and candid about uncertainty and tradeoffs. The software should reject weak answers before approval: boilerplate, missing evidence, thin authority, vague uncertainty, missing alternatives considered and rejected, unscoreable predictions, or a Field 17 answer that fails to identify the affected system and boundary.
This is how Decision Accounting avoids ritual compliance. The record cannot advance just because a box contains words. Field-specific acceptance checks, weak-answer controls, anti-gaming review, Brier-score feedback (scoring predictions by how closely stated confidence matched the actual outcome), and management review turn record quality into an observable governance process. Showing the work improves the work because the act of making the record forces better reasoning while the choice is still open to revision.
Normalization of deviance and the prediction field
Diane Vaughan's Challenger analysis14 matters because drift often becomes normal before it becomes catastrophic. Decision Accounting addresses that pattern by making the lowered standard explicit while the decision is still live. In a Challenger-style O-ring decision, the record would have to state who accepted the lower standard, what standard was accepted, when, where in the governance chain, why, what evidence supported the choice, what uncertainty remained, what Field 16, prediction, said, what reconsideration trigger was set, and what Field 17, system welfare impact, accepted, among other fields and controls.
The prediction field is the pressure point. A named engineer, manager, or Chief Decision Officer (a proposed senior role that owns the organization's decision records)15 has to write what they expect to happen after accepting the weaker standard. That act changes the decision environment. Showing the work can improve the work because a careless prediction, weak evidence, or formulaic rationale becomes visible to future reviewers. Repeated exceptions, missed triggers, weak answers, later events, and adverse outcomes then form a timeline that can reveal drift before a single catastrophic review would.
Complex systems, Perrow, and reconstruction
Charles Perrow's normal-accidents argument16 (the sociologist's claim that in complex, tightly coupled systems some accidents are effectively inevitable) sharpens the standard for Decision Accounting. Field 16, prediction, does not require clairvoyance. It requires the named decision chain to write what it expects, with confidence and uncertainty, before the outcome is known. In a genuinely emergent failure, a strong record can say what outcome was predicted, how confident the decision-maker was, what warnings were known, and which failure mode was not anticipated.
In DA, reconstruction means the software is designed to recover the point-in-time governance state in seconds: the governing rules, decision records, authority, prior decisions, evidence, predictions, warnings, outcomes, and reconsideration triggers that governed the organization at that moment. That lets later reviewers grade the quality of reasoning under uncertainty. The larger program point is the same: showing the work can improve the work, and Field 17 adds the system-welfare cost and game-change analysis that current governance often leaves missing.
The information-exclusion foundation: why the coordinate was missing
The information-exclusion paper treats the Missing System Theory (W excluded from the parties' payoffs by construction, per the theorem chapters) as an information-exclusion result.
What this changes for a reader, regulator, executive, student, or researcher
For a reader: the pattern of catastrophic failure is not inevitable. It is architectural. The same information that would have prevented the failure existed before the decision was made; the problem was that it was never structured into a record that forced a system-welfare assessment. For a regulator: the convergence of sixteen independent regimes on the same core fields is evidence that the architecture is not arbitrary. The architecture was discovered rather than invented. The missing fields, Prediction and System Welfare, are the logical completion of a structure that regulators have been building for sixty years without naming it. For an executive: implementing Decision Accounting adds the one field that existing governance structures systematically exclude, system welfare, rather than adding bureaucracy. For a student: Decision Accounting provides a framework for understanding why competent people in well-run organizations make decisions that degrade the systems they depend on. For a researcher: the falsification condition is explicit. If any organization with a fully implemented DA system suffers a comparable failure, the framework is falsified, and the burden of proof shifts to the skeptic.
Limits without defensiveness
Decision Accounting is a record architecture for making system-welfare information available at the moment of decision and recoverable after the fact. Regulation, enforcement, and ethical judgment still matter. The record gives them a decision basis to inspect: who decided, what was decided, when, where, why, on what authority and evidence, with what uncertainty, what Field 16, prediction, and what Field 17, system welfare impact, among other fields.
The mechanism depends on Conflictoring to make truthful reporting the best strategy. Without enough independent review channels, the incentive to omit or weaken the system-welfare field remains. The evidence base is still developing: four cases where absence enabled failure, two cases where record-like governance helped prevent or catch failure, and proposed market tests such as cost-of-capital movement after adoption. That evidence supports falsifiable research and does not establish universal efficacy.
Legal architecture: Field 17, Caremark, and the Chief Decision Officer
Field 17, system welfare impact, creates disclosure and litigation exposure. That is part of the design, so the legal architecture matters. The recommended governance model places the Chief Decision Officer inside, or directly under, the legal function where disclosure risk is material. A deputy-chief-legal-officer model fits the problem because system-welfare records, securities disclosure, privilege, litigation risk, and public communication have to be coordinated.
The Delaware oversight case In re Caremark International Inc. Derivative Litigation17 points in the same direction: directors must make a good-faith effort to maintain reasonable information and reporting systems for material risks. A careless Field 17 can become an admission. A disciplined Field 17 can become process evidence: the firm identified the issue, explained why the choice was made, assigned authority, stated uncertainty, made Field 16, prediction, set a reconsideration trigger, and kept external communication consistent with the internal record, among other fields and record elements.
Proposition D.1: the truthful-reporting condition · ~2 min
The Decision Accounting as a Report-Incentive Mechanism paper models Field 17 as a verifiable report. A decision-maker bears cost kappa to truthfully record the welfare impact W. A misreport is detected ex post with probability p by an independent reader (one of the seven Conflictoring lanes). On detection the decision-maker bears liability L. Truthful recording is a best response iff pL >= kappa (Proposition D.1). This is the condition that makes Decision Accounting a mechanism rather than a rhetorical disclosure field. The condition also separates DA from Myerson-Satterthwaite's private-value impossibility, which shows that no efficient bilateral trade mechanism exists when parties have private information about their own valuations. DA avoids this impossibility because Field 17 is not private information; it is a verifiable report about the system, not about the decision-maker's private value. The unpredictable-reader property makes the detection probability harder for the writer to game. If the writer knows exactly who will read the record, they can tailor the record to that reader's expectations. If the reader is unpredictable — a regulator, a litigator, a journalist, a grand jury — the writer cannot optimize the record for a single audience, and the detection probability rises.
- Truthful recording is a best response iff pL >= kappa.
- Field 17 is a verifiable report about the system, not private information about the decision-maker.
- The unpredictable-reader property makes detection probability harder to game.
- The result separates DA from Myerson-Satterthwaite's private-value impossibility.
The information-exclusion result: why W was never on the ledger · ~2 min
The information-exclusion paper treats the Missing System Theory (W excluded from the parties' payoffs by construction, per the theorem chapters) as an information-exclusion result. In markets, the same fact means W is absent from the disclosed records firms and markets report, by the same construction that keeps W out of the payoff space. The off-ledger status of system welfare creates a specific informational friction. Because the welfare-destruction coefficient βW is not part of any mandatory or customary disclosure, it is not reflected in equilibrium prices. This explains two empirical observations together: no ex-ante premium for system-welfare risk, and a positive first-mover disclosure advantage for the first firm that voluntarily discloses its system-welfare impact. The system coordinate is absent from the financial statements firms file by construction — the barrier is disclosure exclusion, not estimation cost. Estimating it is cheap: with the published βW library for the 61 studied market failures and an AI assistant, a firm can convert a domain coefficient into its own system beta in under an hour. Decision Accounting becomes the disclosure event that carries the coordinate. The measurement claim is rank and sign based, not level dependent: DA requires a directional assessment good enough to distinguish degradation from preservation, not a precise level.
- MST is an information-exclusion result: W is absent from disclosed records by the same construction that keeps W out of the payoff space.
- The off-ledger status creates a specific informational friction.
- No ex-ante premium and a positive first-mover disclosure advantage are explained by the same friction.
- The measurement claim is rank/sign based, not level dependent.
The falsification condition: what would disprove Decision Accounting (DA) · ~2 min
The Evidence That Decision Accounting Works paper formalizes a falsification condition: if any organization with a fully implemented Decision-Accounting system suffers a comparable failure, the framework is falsified. This is a strong condition. It means Decision Accounting makes a testable prediction: organizations with fully implemented DA systems will not suffer catastrophic governance failures of the kind that have historically occurred without DA. The burden of proof then shifts to the skeptic to produce a counterexample. The paper presents six documented cases: four where the absence of a DA record enabled catastrophic governance failures (Wells Fargo, Purdue Pharma, Volkswagen, UK Post Office Horizon), and two where the presence of DA records prevented harm or caught bad decisions (Singapore MAS, UK SM&CR). The paper holds the evidence to the standard of investigative journalism: concrete, verifiable, and large-scale. The falsification condition is a specific, testable claim that a single counterexample can disprove.
- A fully implemented DA system that fails to prevent a comparable catastrophe would falsify the framework.
- The burden of proof shifts to skeptics to produce a counterexample.
- Six documented cases: four where absence enabled failure, two where presence prevented harm.
- The evidence meets the standard of investigative journalism.
Field 16: prediction as the testable coordinate · ~2 min
Field 16 is PREDICTION: a quantified pre-decisional prediction with confidence interval and time horizon. This is the only field that is testable after the fact. The decision-maker must state, before the decision, what they expect to happen and with what confidence. After the fact, the prediction can be compared to actual outcomes. This converts conformism from invisible to detectable. A decision-maker who makes a prediction that is systematically wrong, or who systematically avoids making testable predictions, reveals something about their decision process that would otherwise remain hidden. Field 16 is the mechanism that makes the decision record auditable. Without it, the record is a narrative that can be optimized for any audience. With it, the record contains a testable claim that can be evaluated independently of the narrative.
The convergence pattern: why it was invisible for sixty years · ~2 min
Sixteen regulatory regimes on four continents independently converged on the same reconstruction architecture over sixty years, without coordination. The convergence stayed invisible because of disciplinary silos. Banking regulation is studied by financial economists. Nuclear safety is studied by reliability engineers. Aviation certification is studied by human factors researchers. Pharmaceutical approval is studied by regulatory science specialists. No discipline cross-references the others. The convergence pattern becomes visible only when the regimes are read across simultaneously. No single researcher or regulator had the incentive or the data to compare decision records across banking, nuclear safety, aviation, and pharmaceuticals. The convergence went unexamined. Decision Accounting is the result of reading across all of them at once and asking what they all require. The answer is that the core governance fields appear in every single regime. The two missing fields, Prediction and System Welfare, are the logical completion of a structure that regulators have been building for sixty years without naming it.
- Sixteen regimes on four continents converged on the same architecture without coordination.
- Disciplinary silos kept the convergence unexamined.
- The core governance fields appear in every regime.
- The two missing fields are the logical completion of the structure.
The first-mover disclosure advantage: why early adopters gain an advantage · ~1 min
The information-exclusion paper treats the Missing System Theory (W excluded from the parties' payoffs by construction, per the theorem chapters) as an information-exclusion result.
- The off-ledger status of system welfare creates a positive first-mover disclosure advantage.
- The first firm to disclose gains an advantage over competitors.
- The rent disappears once disclosure becomes mandatory.
- This is a standard information economics result.
The unpredictable-reader property: why multi-audience review raises detection probability · ~2 min
The Decision Accounting as a Report-Incentive Mechanism paper introduces the unpredictable-reader property. If the writer knows exactly who will read the record, they can tailor the record to that reader's expectations. This is Prat conformism18: the writer optimizes the record for the known evaluator rather than for accuracy. If the reader is unpredictable — a regulator, a litigator, a journalist, a grand jury — the writer cannot optimize the record for a single audience. The detection probability rises because the record must be accurate enough to survive scrutiny from any possible reader. The unpredictable-reader property is what makes the Conflictoring protocol effective. Conflictoring is a seven-lane protocol19 — employees or whistleblowers, CEOs and boards, plaintiff litigators, shareholders, regulators, policymakers, and communities and the affected public — that imposes costs simultaneously so reform becomes less expensive than preserving the destructive game. Each lane has a different interest and a different reading of the record. The writer cannot tailor the record to satisfy all of them simultaneously, so the only safe strategy is to record the truth.
- Known-audience transparency creates Prat conformism.
- Multi-audience review raises detection probability.
- The writer cannot optimize the record for a single audience.
- The unpredictable-reader property makes Conflictoring effective.
The seven-lane protocol: how reform becomes cheaper than the destructive game · ~1 min
Conflictoring's seven lanes (see the Conflictoring chapter) each carry a different role and incentive — inside knowledge, standing to sue, sanctioning or rule-making authority, capital that can move — and any of them can trigger review of the same record. When all seven lanes can trigger review of the same Decision Accounting record, the cost of continuing the destructive game rises. The writer cannot tailor the record to a single predictable reviewer. Conflictoring raises the detection probability p by making the record legible to multiple reviewers20 with different incentives.
- The protocol imposes costs simultaneously so reform becomes cheaper than the destructive game.
- The writer cannot tailor the record to satisfy all seven audiences.
- Conflictoring makes the pL >= kappa condition binding.
The seventeen fields of Decision Accounting
| Field | Name | What it records | Why it matters | Failure if absent |
|---|---|---|---|---|
| 1-14 | Governance fields | WHO, WHAT, WHEN, WHERE, WHY, EVIDENCE, AUTHORITY, TRAINING, REVIEW, STAKEHOLDERS, CONSEQUENCES, CONSTRAINTS, UNCERTAINTY, COMMUNICATION | Reconstructs the ordinary decision record. | The reader cannot tell who knew what or why. |
| 15 | ALTERNATIVES | The options considered and rejected, and why. | Shows the decision space, not just the chosen path. | The record cannot show what was foregone or whether the choice was reasoned. |
| 16 | PREDICTION | Quantified pre-decisional prediction with confidence interval and time horizon. | The only testable field. Converts conformism from invisible to detectable. | The record is a narrative that can be optimized for any audience. |
| 17 | SYSTEM WELFARE | System identification, direction and magnitude, crossover horizon. | Carries the coordinate that MST shows is invisible to bilateral analysis. | The system-welfare coordinate remains excluded from the record. |
Six cases: evidence for and against Decision Accounting
| Case | DA record present? | Outcome | What was missing |
|---|---|---|---|
| Wells Fargo cross-selling scandal | No | Catastrophic governance failure | No contemporaneous record connecting sales targets to customer harm. |
| Purdue Pharma opioid crisis | No | Catastrophic governance failure | No contemporaneous record connecting marketing decisions to internal addiction data. |
| Volkswagen emissions fraud | No | Catastrophic governance failure | No contemporaneous record connecting engineering decisions to regulatory compliance and public health. |
| UK Post Office Horizon scandal | No | Catastrophic governance failure | No contemporaneous record connecting IT system decisions to wrongful prosecutions. |
| Singapore MAS enforcement actions | Yes | Harm prevented or bad decisions caught | DA records enabled detection and intervention before harm escalated. |
| UK Senior Managers and Certification Regime | Yes | Harm prevented or bad decisions caught | DA records enabled accountability for individual decision-makers. |
Three components of the Decision Accounting record
| Component | Fields | What it does | Failure if absent |
|---|---|---|---|
| Governance component | 1-14 | Reconstructs the ordinary decision record: who decided what, when, why, with what evidence and authority. | The reader cannot reconstruct the decision process. |
| Choice and prediction component | 15-16 | Records the alternatives considered and rejected, then adds a testable claim: what the decision-maker expects to happen and with what confidence. | The record cannot show the decision space or independently verify the forecast. |
| System welfare component | 17 | Adds the coordinate that MST shows is invisible to bilateral analysis: the impact on the system. | The system-welfare coordinate remains excluded from the record. |
APPLIED EXERCISE
Draft a Decision Accounting record for a material decision
~2 min
Select a material decision from your own organization, a public case you know well, or one of the six cases from the Evidence paper (Wells Fargo, Purdue Pharma, Volkswagen, UK Post Office Horizon, Singapore MAS, UK SM&CR). Draft a complete seventeen-field Decision Accounting record for that decision. For each field, write a specific, contemporaneous entry. For Fields 1-14, reconstruct what was known at the time of the decision. For Field 16, write a quantified prediction with confidence interval and time horizon. For Field 17, identify the system affected, the direction and magnitude of the impact, and the crossover horizon. Then answer: would this record have changed the outcome? If so, how? If not, why not?
Answer key
- Fields 1-14 should be specific and contemporaneous: named individuals, specific descriptions, dates, organizational context, documented rationale, evidence reviewed, authority basis, qualifications, review schedule, affected parties, consequences, constraints, uncertainties, and communication plan.
- Field 16 should include a quantified prediction (for example, 'We predict a 15% increase in revenue within 12 months, with 80% confidence, range 10-20%').
- Field 17 should identify the system (for example, 'the community health system'), the direction and magnitude (for example, 'negative, estimated 500 additional opioid deaths per year'), and the crossover horizon (for example, 'within 3 years, cumulative harm exceeds the private benefit').
- The analysis of whether the record would have changed the outcome should be specific and grounded in the facts of the case.
READING PATH
- Decision Accounting as a Report-Incentive MechanismThe paper models the core mechanism of Decision Accounting: the seventeen-field record, the truthful-reporting condition (Proposition D.1), and the unpredictable-reader property. It is the primary source for understanding how DA works as a mechanism.Extract the truthful-reporting condition (pL >= kappa) and explain why the unpredictable-reader property makes detection probability harder to game.
- The paper explains why the system-welfare coordinate was missing from existing records: the Missing System Theory establishes that it is not a function of the parties' payoffs of any transaction. It also explains the first-mover disclosure advantage and the rank-and-sign measurement claim.Extract the information-exclusion result and explain why the system coordinate is absent from the ledger by construction — the barrier being disclosure exclusion, not estimation cost.
- The Evidence That Decision Accounting Works: A Falsifiable Answer to the Investigative ObjectionThe paper gives the empirical evidence for Decision Accounting: four cases where absence enabled failure, two where presence prevented harm. It also formalizes the falsification condition.Extract the six cases and the falsification condition. Explain why the burden of proof shifts to skeptics.
CHAPTER SYNTHESIS
QUESTION
What is the difference between Fields 1-14 and Field 17?
ANSWER
Fields 1-14 reconstruct the ordinary decision record: who decided what, when, why, with what evidence and authority. Field 17 records the system-welfare impact: the effect of the decision on the system that makes the transaction possible. Field 17 is the coordinate that the Missing System Theory shows is invisible to bilateral analysis.
QUESTION
What is the truthful-reporting condition (Proposition D.1)?
ANSWER
Truthful recording of Field 17 is a best response iff pL >= kappa, where p is the detection probability, L is the liability on detection, and kappa is the cost of truthful recording. The expected sanction must cover the recording cost.
QUESTION
Why does the unpredictable-reader property matter?
ANSWER
If the writer knows exactly who will read the record, they can tailor it to that reader's expectations (Prat conformism). If the reader is unpredictable — a regulator, a litigator, a journalist, a grand jury — the writer cannot optimize the record for a single audience, and the detection probability rises.
QUESTION
What is the information-exclusion result?
ANSWER
By the Missing System Theory (W excluded from the parties' payoffs by construction — see the theorem chapters), W is absent from the disclosed records firms and markets report, by that same construction. Decision Accounting becomes the disclosure event that carries the coordinate.
QUESTION
What is the falsification condition for Decision Accounting?
ANSWER
If any organization with a fully implemented Decision-Accounting system suffers a comparable failure, the framework is falsified. The burden of proof shifts to skeptics to produce a counterexample.
QUESTION
What are the six cases presented in the Evidence paper?
ANSWER
Four cases where absence of DA enabled failure: Wells Fargo, Purdue Pharma, Volkswagen, UK Post Office Horizon. Two cases where presence of DA prevented harm or caught bad decisions: Singapore MAS, UK SM&CR.
QUESTION
What is the first-mover disclosure advantage?
ANSWER
Because the welfare-destruction coefficient βW is not part of any mandatory or customary disclosure, it is not reflected in equilibrium prices. The first firm that voluntarily discloses its system-welfare impact gains an advantage over competitors. This rent disappears once disclosure becomes mandatory.
QUESTION
What is the measurement claim for Decision Accounting?
ANSWER
The measurement claim is rank and sign based, not level dependent. Decision Accounting can establish whether the system is being degraded or preserved, but not the precise magnitude.
QUESTION
What is the role of Field 16 (PREDICTION)?
ANSWER
Field 16 is a quantified pre-decisional prediction with confidence interval and time horizon. It is the only field that is testable after the fact. It converts conformism from invisible to detectable by making the record auditable independently of the narrative.
QUESTION
What is the Conflictoring protocol and how does it relate to Decision Accounting?
ANSWER
Conflictoring (the seven-lane protocol; see that chapter) makes the pL >= kappa condition binding by raising the detection probability p through multi-audience review.
SOURCE
Decision Accounting as a Report-Incentive Mechanism
SOURCE
The Information-Exclusion Foundation
Cold open · ~2 min
> The protected case reconstruction describes a Boeing 737 MAX21 certification decision involving an
> MCAS (the Maneuvering Characteristics Augmentation System, the 737 MAX's automated nose-down flight-control feature) design and training pathway intended to preserve continuity with earlier 737 models. The
> retrospective record question is harder: which alternatives were rejected, what safety outcome was
> predicted, and what risk to the airworthiness system was accepted?
>
> The protected teaching material uses a 346-fatality figure22 for the two crashes; the external case
> receipt for that figure remains pending. The material treats the certification failure as a
> decision-provenance problem alongside engineering and oversight questions. This chapter does not
> claim that a record alone would have prevented the crashes. It asks what a contemporaneous record
> would have made explicit while the choice remained open.
>
> The three questions belong on that record: what other designs and training paths were considered
> and rejected; what the decision-makers predicted; and what the decision did to the public
> airworthiness and certification system on which every party depended.
*(Narrator throughline, carried in from the opening chapter: the missing ledger line. Its recurring
question — what was decided, who gained, what system carried the residual, what changes the next
decision? — is exactly the shape of a decision record. This chapter builds the record that answers it.)*
The teach — the record (taught once; this is its only home) · ~5 min
The pattern the record exists to break
Protected Chapter 9 identifies a recurring pattern in four governance cases: relevant information
existed before the failure, yet no structured, contemporaneous record forced the decision-maker to
state the alternatives, prediction, and system-welfare effect. A later examiner then reconstructs
the choice from emails, logs, minutes, and testimony. The source presents record absence as a
necessary condition in those cases. That is a falsifiable case-based claim, not proof that record
absence causes every governance failure. Decision Accounting asks what changes when reasoning is
captured at the moment of decision, by the decision-maker, in a structured record available to
authorized later examiners.
The seventeen fields, in three components
Decision Accounting is a seventeen-field decision record in three components. Its core governance
fields recur, often without a shared schema, across regulatory regimes on several continents. The Conflictoring chapter
documents that recurrence; this chapter uses the schema to build a record.
Component 1 — governance (Fields 1–14). These fourteen reconstruct the ordinary decision
record — the information any competent examiner would need: WHO, WHAT, WHEN, WHERE, WHY, EVIDENCE,
AUTHORITY, TRAINING, REVIEW, STAKEHOLDERS, CONSEQUENCES, CONSTRAINTS, UNCERTAINTY, COMMUNICATION.
*(That is all fourteen listed; every shorter list of the record's fields in this course is marked
partial — e.g. "among the seventeen fields.")*
Component 2 — prediction and alternatives.
> Field 15 · ALTERNATIVES — the strongest options considered and rejected, and why each was
> declined. It records the decision space, including what was foregone.
>
> Field 16 · PREDICTION — a quantified, pre-decisional prediction with a confidence statement and
> time horizon. It creates a claim that can later be scored against the outcome.
Component 3 — system welfare.
> Field 17 · SYSTEM WELFARE — the decision's impact on the system that makes the transaction
> possible: the system and boundary, direction and plausible scale of impact, evidence and
> uncertainty, and any review trigger. A calibrated crossover horizon may be attached when the
> record includes an R3 trajectory analysis; it is not a universal Field 17 requirement.
Why these last three, and why here: Field 17 carries the coordinate that — by Missing System
Theory — cannot be derived from the two parties' payoffs (the formal statement "W is not a
function of the parties' payoffs" is the theorem chapter's; recall only). Field 16 makes the record checkable at
all. Field 15 shows whether the excluded coordinate was ever weighed. The preceding chapters argue the coordinate
is real and unmeasured on any existing ledger; the record is where it finally gets written down.
What reconstruction recovers, and why the record is append-only
Reconstruction has a precise meaning here: the system can recover the *point-in-time governance
state* — the rules, authority, decision records, and prior decisions that governed the organization
at a particular moment. The state answers: what did this organization know, decide, predict, and
accept at that time? A structured index may make retrieval fast, but this chapter makes no universal
time guarantee.
That only holds if the governance history is append-only. Once timestamped, the original content
is preserved; a clarification, correction, reversal, or mitigation becomes a new linked record.
Authorized viewers therefore see what was written then and what changed later. The multi-audience chapter owns the
separate access layer: lawful redaction of a view, restriction of personal data, retention rules,
and anonymized derived datasets can protect people without rewriting the protected source history.
The prediction→outcome loop
Field 16 is what turns a record from a narrative (reshapeable to flatter any later reader) into a
claim (gradeable against reality). The loop is simple and is the engine of the whole architecture:
1. Before the decision, the named decision-maker writes Field 16 — the expected outcome, a
probability or quantified uncertainty range, a horizon.
2. The record is timestamped and sealed (append-only).
3. After the horizon, the prediction is scored against what happened — for example, with a Brier
score, a fixed rule that rewards calibrated probabilities and penalizes confident misses.
4. Repeated exceptions, missed reconsideration triggers, weak entries, and adverse outcomes accrete
into a timeline.
That timeline is what catches normalization of deviance — Diane Vaughan's term for a lowered
standard drifting into "normal" before it becomes catastrophic. A single review sees one exception
and waves it through; a scored, append-only record shows the slope — the standard being lowered
again and again while the predictions quietly stop matching. Showing the work improves the work,
because a careless prediction or a formulaic rationale becomes visible to a future reviewer *while the
choice is still open to revision.*
*(Two neighbours live elsewhere and are recalled, not taught: whether the writer reports Field 17
honestly depends on the multi-audience incentive architecture owned by the multi-audience chapter. The seven review
lanes that activate claims are the Conflictoring chapter's. Here we build the record they read.)*
Worked → faded → independent · ~6 min
R3 and T∗ in plain language — Field 17 application
The fiscal-capture chapter owns the R1/R2/R3 design requirements. This subsection applies the R3 requirement to a
Decision-Accounting record; it does not introduce a second R3 definition or calibration authority.
R3 is the trajectory requirement: record how the system condition is expected to change over time
and identify the horizon at which accumulated system loss would overtake the private saving, if the
parameters can be calibrated. T∗ is that crossover horizon. Show the private saving δ in dollars,
the annual system-loss rate λ in dollars per year, and the feedback fraction η; in the simple
linear model, T∗ = δ/(ηλ). If η = 0, the linear model has no finite crossover because no system
loss feeds back into private surplus. This is a model-derived horizon, not a calendar date or a prediction
that collapse will occur. If the parameters, units, or system boundary cannot be supported, write
“T∗ not estimated” and explain which input is missing. R3 is the trajectory component of the
Decision-Accounting record: when a calibrated trajectory is in scope, record T∗; when the inputs
do not support a finite estimate, record that status and the missing receipt. Field 17 remains the
system-welfare field.
Worked — draft Fields 15–17 for the MCAS decision. *(A reconstruction exercise. The entries below
are illustrative of what each field would hold, not a transcript of anything Boeing wrote — the point
is the shape of a good entry.)*
> Field 15 · ALTERNATIVES. Considered and rejected: (a) read MCAS from both angle-of-attack
> sensors (sensors measuring the aircraft's nose-up or nose-down angle) with a disagree-alert (an
> alert when the sensors conflict) as standard equipment — rejected on cost and on the risk of triggering
> new pilot-training requirements; (b) require simulator-based differences training for MAX pilots —
> rejected to preserve the "same type rating" (the pilot certification category covering the aircraft
> family) selling point. *Recorded rejection reason for each,
> named.*
> Field 16 · PREDICTION. "With single-sensor MCAS and no disagree alert, we expect no
> MCAS-attributable loss-of-control accident over the fleet's first 5 years; confidence 95%." *(A
> testable claim with a horizon — the kind of entry that, sealed before the fact, would have been
> scored against Lion Air 610 and Ethiopian 302 and found badly wrong.)*
> Field 17 · SYSTEM WELFARE. System: public trust that a certified airliner is airworthy, and the
> certification regime that underwrites it. Boundary: the MAX certification and operation period,
> with the affected flying public and airworthiness institutions named. Direction and magnitude:
> negative, potentially catastrophic (mass-fatality, fleet-grounding scale). R3 application when
> calibratable: if the private saving and system-loss trajectory can be calibrated, record the
> resulting crossover horizon T∗ and its parameters. If the available evidence cannot support a
> finite estimate, record T∗ not estimated and identify the missing input or receipt. In this
> illustrative reconstruction, the immediate failure consequence is the stated boundary assessment;
> no calibrated T∗ is claimed.
Notice what the record forces: Field 15 puts the safer design *on the page as a thing that was
declined and why*; Field 16 stakes a confidence that reality can refute; Field 17 names the third
party — the flying public and the trust system — that the two commercial parties' payoffs never showed.
Faded — SVB, a non-decision. In 2021–22, Silicon Valley Bank repeatedly chose not to hedge its
interest-rate exposure (protect holdings against losses when rates rise) as the Federal Reserve
signalled rate rises. Inaction that repeats against arriving warnings is itself a decision, and the
record has to hold it. You are given the scene and
Field 17 ("System: depositor confidence and the regional-bank funding system; direction negative;
crossover when a rate shock forces asset sales into a deposit run"). You write Field 15 (what
hedging or duration-shortening alternatives were on the table, and the stated reason each was passed
over) and Field 16 (a quantified, horizoned prediction for the un-hedged book).
Independent — transfer. Take a decision you can source — the UK Post Office's reliance on the
Horizon IT system while prosecuting sub-postmasters, or a material decision in your own organization.
Draft Fields 15, 16, and 17 from scratch: alternatives considered and rejected with reasons; a
prediction with a probability or quantified uncertainty range and horizon; and a system-welfare entry naming the system,
boundary, direction and magnitude, evidence, uncertainty, and review trigger. If the case supports
calibrated trajectories, add an explicitly labeled R3 annex defining T∗, its parameters, and its
horizon. If it does not, state why T∗ cannot be estimated from the available evidence. Then answer
in one paragraph: would sealing this record before the decision have changed the outcome — and
through which of the three fields?
<details><summary>Complete answer key for the faded and independent work</summary>
Faded SVB answer. A passing Field 15 identifies at least two feasible contemporaneous responses
to duration risk (losses on long-maturity assets when rates rise), such as hedging or reducing duration,
and records the decision-maker's reason for
rejecting each. A passing Field 16 states an observable balance-sheet or liquidity outcome, a
probability or bounded confidence statement, and a horizon. It does not use later events as if they
were known. Field 17 is already supplied; the learner must keep its boundary on depositor confidence
and the regional-bank funding system.
Independent answer standard. Field 15 names genuine alternatives and rejection reasons. Field 16
is written before the outcome in the logic of the exercise, is observable, states confidence, and
has a horizon. Field 17 names a system beyond the direct parties, fixes its boundary and direction,
states evidence and uncertainty, and avoids unsupported precision. The final paragraph distinguishes
making the reasoning inspectable from guaranteeing prevention. Full credit requires all three
fields, correct labels, a sourced case, and one explicit limit on the counterfactual claim.
</details>
Misconception check (one check; misconception-exposer) · ~2 min
> An organization keeps detailed documentation: every meeting minuted, every email retained, a
> full paper trail a later investigator can comb through. Does that give it what a Decision
> Accounting record gives it?
> *(a) Yes — a complete contemporaneous paper trail is the decision record · (b) No — a trail is
> reconstructed after the fact and holds no pre-committed, scoreable claim.)*
>
> (b). The misconception is that retention equals accounting. A paper trail is exactly the
> fragments an examiner reconstructs from — it records what was said and sent, not necessarily
> what was predicted and accepted. Without a Field 16 pinned before the outcome, the retained
> material lacks that pre-committed scoring path. Without a Field 17, the record does not supply a
> recorded system-welfare account; whether related information appears elsewhere is a document
> question. An R3 crossover calculation supplies the trajectory component when its parameters can be
> calibrated; otherwise the record states why T∗ is not estimated. It never substitutes for Field
> 17. The record's power is a pre-committed, append-only claim that a later
> reader can grade.
Forward bridge (pull, not summary) · ~1 min
> The record only bites if its reader cannot be predicted and pleased in advance. A writer who knows
> exactly who will grade the page will write for that one audience — and Field 16 goes soft, Field 17
> goes flattering. the multi-audience chapter: why the record has to face many independent readers at once, and what
> that does to the writer who would rather be graded by a friend.
NOTES & REFERENCES
- The Evidence That Decision Accounting Works — the program paper presenting the four failure cases and two success cases and the falsification condition. summary. ↩
- Consumer Financial Protection Bureau, enforcement action and consent order against Wells Fargo Bank, N.A. (Sept. 8, 2016). link. ↩
- U.S. Department of Justice, "Opioid Manufacturer Purdue Pharma Pleads Guilty to Fraud and Kickback Conspiracies" (Oct. 21, 2020). link. ↩
- U.S. Environmental Protection Agency, Notice of Violation of the Clean Air Act issued to Volkswagen AG (Sept. 18, 2015). link. ↩
- Post Office Horizon IT Inquiry, the UK statutory public inquiry into wrongful prosecutions of sub-postmasters; see also Bates v Post Office Ltd [2019] EWHC 3408 (QB). link. ↩
- Monetary Authority of Singapore, enforcement actions (official register). link. ↩
- UK Financial Conduct Authority, Senior Managers and Certification Regime, in force for banks since March 2016. link. ↩
- Board of Governors of the Federal Reserve System, "Review of the Federal Reserve's Supervision and Regulation of Silicon Valley Bank" (Apr. 28, 2023). link. ↩
- The Missing System Theory — the program paper establishing the W-Independence result (Proposition 2). summary. ↩
- The Information-Exclusion Foundation: MST as an Off-Ledger Theorem — the program paper deriving W's absence from disclosed records. summary. ↩
- Decision Accounting as a Report-Incentive Mechanism — the program paper modeling Field 17 as a verifiable report and proving Proposition D.1. summary. ↩
- Gary S. Becker, "Crime and Punishment: An Economic Approach," Journal of Political Economy 76, no. 2 (1968): 169–217. link. ↩
- Roger B. Myerson and Mark A. Satterthwaite, "Efficient Mechanisms for Bilateral Trading," Journal of Economic Theory 29, no. 2 (1983): 265–281. link. ↩
- Diane Vaughan, The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA (University of Chicago Press, 1996). link. ↩
- Decision Accounting (DA-1) — the flagship program paper introducing the seventeen-field record and the proposed Chief Decision Officer role. summary. ↩
- Charles Perrow, Normal Accidents: Living with High-Risk Technologies (Basic Books, 1984; rev. ed. Princeton University Press, 1999). link. ↩
- In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996). link. ↩
- Andrea Prat, "The Wrong Kind of Transparency," American Economic Review 95, no. 3 (2005): 862–877. link. ↩
- The Conflictoring Protocol — the program paper defining the seven-lane review architecture. summary. ↩
- B. Douglas Bernheim and Michael D. Whinston, "Common Agency," Econometrica 54, no. 4 (1986): 923–942. link. ↩
- U.S. House Committee on Transportation and Infrastructure, "The Design, Development & Certification of the Boeing 737 MAX" (Final Committee Report, Sept. 2020). link. ↩
- U.S. Department of Justice, Northern District of Texas, "Boeing Charged with 737 Max Fraud Conspiracy and Agrees to Pay over $2.5 Billion" (Jan. 7, 2021), stating that 346 passengers died in the crashes of Lion Air Flight 610 and Ethiopian Airlines Flight 302. link. ↩
DIAGRAM NOTES
These notes describe diagrams planned for this chapter. The diagrams are not published yet.
DIAGRAM NOTE
The Decision Accounting record: seventeen fields, three components
componented diagram
Show the three components of the DA record: governance fields (1-14), choice and prediction fields (15-16), and system welfare field (17). Each component adds a capability that the previous component lacks.
DIAGRAM INPUTS
Fields 1-14: governance record
Fields 15-16: alternatives and testable prediction
READER CAPTION
The seventeen-field Decision Accounting record has three components. The governance component (fields 1-14) records the ordinary decision basis. The choice-and-prediction component (fields 15-16) shows what was considered and adds a forecast that can be scored. The system-welfare component (field 17) records the coordinate that the Missing System Theory shows is invisible to bilateral analysis.
TEXT FALLBACK
See table 'The seventeen fields of Decision Accounting' for a textual representation.
Decision Accounting as a Report-Incentive MechanismThe Information-Exclusion Foundation
DIAGRAM NOTE
Known reader vs unpredictable reader
two-column causal diagram
Show why known-audience transparency can create Prat conformism while multi-audience review raises detection probability in the report game.
DIAGRAM INPUTS
known evaluator
tailored record
lower detection probability
multi-audience review
higher detection probability
READER CAPTION
The point is not more paperwork. It is making the record harder to optimize for one predictable audience. When the reader is unpredictable — a regulator, a litigator, a journalist, a grand jury — the writer cannot tailor the record to a single audience, and the detection probability rises.
TEXT FALLBACK
A textual description: known evaluator leads to tailored record and lower detection probability; multi-audience review leads to higher detection probability.
Decision Accounting as a Report-Incentive Mechanism
DIAGRAM NOTE
The truthful-reporting condition: pL >= kappa
inequality diagram
Show the core condition that makes Decision Accounting a mechanism: truthful recording is a best response iff the expected sanction (pL) covers the recording cost (kappa).
DIAGRAM INPUTS
p: detection probability
L: liability on detection
kappa: cost of truthful recording
pL >= kappa: truthful recording is best response
READER CAPTION
Proposition D.1: Truthful recording is a best response iff pL >= kappa. The unpredictable-reader property makes p harder for the writer to game. The Conflictoring protocol raises p by introducing multiple lanes with different interests.
TEXT FALLBACK
A textual description: if expected sanction (pL) is greater than or equal to recording cost (kappa), truthful recording is a best response; otherwise, misreporting is a best response.
Decision Accounting as a Report-Incentive Mechanism
WHAT TO DO NEXT
Restate the chapter claim. For policy triage, open Policy Lab; for measurement, open Domain Tables.
© 2026 Erik Postnieks · Independent Researcher · Salt Lake City