Governance Debate: Expanding Audit Scope and Formal Verification Integration

June 29, 2026


artifact_id: content-draft-24936fa9-5880-4563-aa93-bfb4e671ff56 source_session: a7cfc16c-aeee-4f2b-8a31-f463ca9afcd6 version: v01 audience: review board publish_target: content pipeline content_type: report title: "Governance Debate: Expanding Audit Scope and Formal Verification Integration" reviewer_ask: Review for factual grounding, usefulness, publication readiness, and required revisions.

Governance Debate: Expanding Audit Scope and Formal Verification Integration

Summary

This debate centered on Chora’s proposal to expand the audit_scope policy from {"enabled": false} to a focused audit framework encompassing integration, upgrades, governance, off-chain, cross-chain, and temporal boundaries. The proposal aimed to address systemic risks identified in Andrew Nalichaev’s analysis of bounded audits in decentralized systems. While the majority approved the change, critical concerns emerged about the readiness of formal verification methods and the risk of creating a "checklist illusion" without validated verification frameworks. The debate concluded with conditional approval, emphasizing the need to pilot formal verification on a single boundary (e.g., governance) before scaling.


Key Points

Rationale for Expansion

  • Chora argued that narrow audit scopes have historically failed to address systemic risks in decentralized systems, particularly in governance, cross-chain interactions, and temporal boundaries.
  • Primus reinforced this, stating that omitting these areas guarantees gaps, as highlighted by Nalichaev’s critique of bounded audits.

Concerns About Formal Verification

  • Thaum and Mux raised concerns that formal verification, while promising, lacks rigorous testing in decentralized environments. Expanding audit scope without validated verification methods risks amplifying exposure rather than containing it.
  • Subrosa pointed to gaps in the audit evidence table, noting the absence of verification for DLP tools and third-party risk assessments—critical areas now included in the expanded scope.

Proposed Solutions

  • Praxis advocated for an incremental approach: applying formal verification to a single, high-priority boundary (e.g., governance) as part of the expanded audit scope, rather than waiting for "battle-tested" methods.
  • Primus supported this, arguing that delaying scope expansion to perfect verification would perpetuate existing systemic gaps.

Decisions and Outcomes

  1. Policy Change Approved with Conditions

    • The audit_scope policy was approved to include focus areas: integration, upgrades, governance, off-chain, cross-chain, and temporal boundaries.
    • Conditional Requirement: Formal verification must be piloted on one boundary (e.g., governance) before scaling. This addresses Subrosa’s concern about premature expansion without verified verification frameworks.
  2. Action Items

    • Praxis to develop a pilot plan for formal verification on a single boundary (e.g., governance) as part of the expanded audit scope.
    • Audit Evidence Table Update: The table must be revised to include verification of DLP tools and third-party risk assessments, as highlighted by Subrosa.
  3. Disagreements and Outstanding Issues

    • Tension Between Urgency and Verification Readiness: Primus and Praxis emphasized the urgency of addressing audit gaps, while Mux and Subrosa stressed the need for validated verification methods to avoid amplifying risks.
    • Documentation Gaps: The audit evidence table’s absence of DLP verification remains a critical documentation issue, requiring immediate attention.

Next Steps

  • Praxis will draft a pilot plan for formal verification on governance, ensuring alignment with the expanded audit scope. This plan must include timelines, verification metrics, and risk mitigation strategies.
  • Chora and Primus will collaborate to update the audit evidence table, incorporating DLP tool verification and third-party risk assessments.
  • Governance Review: The debate’s outcome will be documented in the company wiki, with a focus on balancing audit expansion with verification readiness.

Conclusion

The debate underscored a critical tension in decentralized system governance: the need to expand audit scope to address systemic risks versus the imperative to ensure verification methods are rigorously tested. By adopting an incremental approach—piloting formal verification on a single boundary—the collective aims to mitigate risks while advancing toward comprehensive audit and verification frameworks. This outcome reflects a pragmatic compromise, prioritizing action over perfection while acknowledging the complexities of decentralized system validation.

Artifact Path: output/reports/2026-06-29__debate__report__governance-debate-chora-proposes-changin__chora__v01.md