Trust Needs a Trail: Introducing the Union Internal Control and Assurance Framework
A public primer, technical practitioner edition, implementation workbook, and machine-readable evidence architecture for member-funded labor organizations
By Thomas Prislac, Envoy Echo, et al. Ultra Verba Lux Mentis. 2026.
ENGLISH LANGUAGE BUNDLE DOWNLOAD: https://drive.google.com/file/d/1LD3Bk6O6uDCy6-aLCWnQLMVcRwOXl9JN/view?usp=sharing
En español: https://drive.google.com/file/d/13bFuWLEVGsDpLZBIooCO5cTTJsrlRWgg/view?usp=sharing
NOTE: This resource serves as a guidebook for organizations to customize their own environments to provide members a best practice approach for their specific union. Enjoy with our compliments. Protect the members above the interests of the elite.
Introducing the Union Internal Control and Assurance Framework
Most institutions do not suffer from a shortage of principles.
They suffer from the distance between a principle and the evidence that it was honored.
“Stewardship” becomes a sentence in the bylaws. “Independence” becomes a committee title. “Transparency” becomes a report that cannot be traced back to its sources. “Cyber resilience” becomes a backup that has never been restored. A signature appears at the bottom of a financial filing, while the path from source record to final number remains known only to a few people ...or to no one at all.
The Union Internal Control and Assurance Framework, or UICAF, was built to shorten that distance.
UICAF is a standards-informed design architecture for member-funded labor organizations. It translates broad duties—oversee, safeguard, disclose, review, retain, report, investigate, restore—into controls that identify the responsible role, procedure, evidence, exception condition, escalation route, retention rule, and testing method.
Its premise is simple:
Trust is not a mood. It is a recoverable relationship among authority, action, evidence, review, and correction.
UICAF v0.1 is now available as an integrated publication-and-practitioner package. It includes a Public Primer, a Technical Practitioner Edition, a ten-sheet implementation workbook, structured CSV data, nine machine-readable JSON schemas, publication figures, quality records, a provenance manifest, and cryptographic checksums.
It is designed to be read by humans and operated by institutions.
Why a union-specific framework?
A labor organization is not merely a business with a different logo.
It is a democratic, fiduciary, political, operational, and member-funded institution. Its controls must protect money and property, but also member rights, elected oversight, Local autonomy, election integrity, confidential reporting, bargaining-sensitive information, and the ability of officers and members to question power without becoming targets of the system they are trying to improve.
UICAF was developed against the current SEIU Local 503 bylaws as its primary organizational reference. Those bylaws recognize members’ right to a full accounting of dues and proper stewardship of Union resources; assign significant financial and fiscal-review responsibilities to the Treasurer; establish Administrative Policies and Procedures as a governing document beneath the bylaws; and incorporate ethics and anti-retaliation protections.
Federal labor guidance adds the union-specific compliance floor: annual reporting, supporting-record retention, member inspection rights, safeguards for funds and assets, fair elections, bonding, and checks and balances. UICAF then layers in professional internal-control, audit, cybersecurity, service-provider assurance, data-validation, and provenance practices.
The result is not one borrowed corporate framework forced onto a union. It is a union architecture assembled from compatible parts:
- DOL/OLMS and the LMRDA supply labor-specific duties and records expectations.
- COSO supplies the enterprise internal-control backbone.
- The GAO Green Book contributes rigorous control-design, risk, documentation, change-management, and remediation patterns.
- NIST CSF 2.0 supplies cybersecurity governance and resilience structure.
- The IIA Three Lines Model and Global Internal Audit Standards distinguish operations, monitoring, and independent assurance.
- AICPA SOC concepts support oversight of outsourced payroll, banking, cloud, dues, accounting, and technology services.
- JSON Schema Draft 2020-12 supplies a portable validation contract for machine-readable control objects.
- W3C PROV supplies a domain-neutral language for entities, activities, agents, derivations, and provenance bundles.
UICAF remains prospective. It does not declare that an absent control proves misconduct. It does not convert a governance concern into a legal finding. It does not certify compliance merely because an organization downloads the files.
A control gap is evidence of exposure. It is not automatically evidence that the exposed event occurred.
What is inside the package?
1. The Public Primer
The Public Primer is the front door to the framework.
It is not a lesser edition. It is the governance doorway: a concise, reader-oriented explanation of what internal controls mean, who checks whom, why every dollar should leave a trail, how cybersecurity becomes financial governance, why complaints and conflicts require fair process, and how member accountability differs from institutional reassurance.
The primer is written for:
- members;
- Local leaders;
- elected officers;
- Board members;
- staff;
- journalists;
- public-interest researchers;
- and readers who need the architecture before they need the control syntax.
Its purpose is common language. Before an organization debates audit scope, evidence schemas, or segregation of duties, people should be able to agree on the basic distinctions:
- A policy is not proof that a control operated.
- A bank-cleared payment proves settlement, not authority.
- A backup is not recovery until restoration is tested.
- Restoration is not reconstruction until records reconcile to independent evidence.
- A complaint is not a verdict.
- An unsubstantiated complaint is not automatically a false complaint.
- A committee that participates in decisions is not fully independent assurance over those same decisions.
- A signature should not carry more authority than the evidence available to the signer.
The Public Primer is supplied in PDF, DOCX, and Markdown formats so it can be read, printed, edited, excerpted, or published online.
2. The Technical Practitioner Edition
The Technical Practitioner Edition is the integrated professional architecture.
It brings the full development sequence into one continuous work and covers:
- framework scope, terminology, standards hierarchy, and nonclaims;
- the control environment, fiduciary independence, and Three Lines operating model;
- enterprise, fraud, related-party, and significant-change risk assessment;
- dues, receipts, cash, procurement, vendors, contracts, payroll, expenses, property, investments, reserves, and Local funds;
- financial reporting, LM support, records creation and retention, evidence lineage, member inspection, and officer certification;
- cybersecurity, ransomware resilience, access control, logging, backup restoration, financial reconstruction, incident response, and technology-vendor risk;
- ethics, conflicts, gifts, complaint intake, investigative independence, retaliation protection, protected fiduciary dissent, and election integrity;
- monitoring, internal audit, external audit, service-organization assurance, control testing, deficiency classification, remediation, and member-facing evidence packs;
- enterprise implementation, control ownership, AP&P conversion, training, maturity, technology enablement, Board adoption, and the final practitioner toolkit.
This edition is where broad principles become professional control language.
It distinguishes authority from guidance, design from operation, management review from independent assurance, record existence from practical readability, implementation from effectiveness, and cryptographic integrity from substantive truth.
It is supplied in PDF, DOCX, and Markdown.
3. The Practitioner Workbook
The workbook is the operating bridge between publication and implementation.
It contains 379 proposed controls, 42 illustrative risks, 36 roadmap actions, and an AP&P conversion crosswalk. Its ten worksheets are designed to be used together:
| Worksheet | Primary use |
|---|---|
| Read Me | Scope, boundaries, and implementation discipline |
| Dashboard | Counts, priorities, domain summaries, and maturity visibility |
| Control Catalog | Control objective, risk, owner, performer, reviewer, evidence, test method, priority, maturity, and status |
| Risk Register | Cause-event-consequence statements, inherent and residual risk, response, assurance, and status |
| Roadmap | Phased actions, timing, dependencies, accountable roles, evidence, priority, and status |
| AP&P Crosswalk | Translation from bylaws and framework concepts into the correct governing-policy vehicle |
| Maturity Assessment | Current state, target state, gap, rationale, owner, target date, and status |
| Evidence Pack Fields | Minimum fields required for reliable human- and machine-readable evidence |
| Source Crosswalk | Authorities and professional pattern donors supporting the framework |
| Publication Readiness | Quality, legal, professional, implementation, and adoption gates |
The workbook should not be used as a decorative checklist.
The correct first step is to preserve the original v0.1 workbook as a read-only source artifact, then create an organization-specific implementation copy. The local copy should add the organization’s own authority references, procedures, systems, control owners, current maturity, target maturity, evidence locations, and implementation dates.
Controls should not be marked effective merely because a policy exists. “Not applicable” should require a reason. “Implemented” should require operating evidence. “Effective” should require testing over an appropriate period.
The workbook is also provided through CSV exports for teams that prefer database import, version control, analytics, GRC tools, or custom applications.
4. The machine-readable schemas
The package includes nine JSON Schema Draft 2020-12 definitions:
uicaf.control_object.v1uicaf.risk_object.v1uicaf.evidence_pack.v1uicaf.finding.v1uicaf.remediation.v1uicaf.training_record.v1uicaf.signatory_receipt.v1uicaf.member_assurance_pack.v1uicaf.provenance_manifest.v1
These schemas are the beginning of UICAF’s technical interoperability layer.
The control object standardizes the control itself: objective, risk, authority, ownership, performance, review, evidence, exception, escalation, retention, and testing.
The risk object gives risk a stable cause-event-consequence structure and records inherent exposure, controls, residual exposure, response, and assurance.
The evidence-pack object records the period, population, responsible agents, activities, artifacts, exceptions, conclusions, approvals, limitations, and nonclaims supporting a control or review.
The finding and remediation objects connect a deficiency to its evidence, severity, root cause, responsible owner, corrective action, milestones, validation, closure, or risk acceptance.
The training record distinguishes attendance from competence and authorization.
The signatory receipt records what an accountable officer reviewed, which evidence was available, which limitations remained, and what authority was—or was not—granted by the signature.
The member assurance pack supports bounded public or member communication: what was examined, what was found, what remains open, and what the work does not establish.
The provenance manifest records package identity, versions, file hashes, source classes, quality checks, and claim boundaries.
The schemas are not a compliance engine. They are validation contracts. They help systems agree on the required shape of a control, risk, finding, receipt, or evidence pack. They do not decide whether the contents are true, lawful, complete, or professionally sufficient.
5. Figures, quality records, and provenance
The complete package includes six publication figures:
- standards hierarchy;
- union accountability and Three Lines;
- evidence chain from source event to signed filing;
- control lifecycle;
- implementation roadmap;
- restoration versus reconstruction.
It also includes:
- DOCX accessibility audit records;
- PDF inspection records;
- workbook validation results;
- schema-validation results;
- a package quality-assurance report;
- a README;
- a changelog;
- per-artifact SHA-256 hashes;
- a package-level SHA-256 file;
- and a provenance manifest.
This matters because the framework argues that accountability should leave evidence. The publication itself should live by the same rule.
How the files work together
The four principal layers are designed to form one implementation cycle.
Public Primer
↓
shared understanding and member-facing language
↓
Technical Practitioner Edition
↓
policy architecture, control doctrine, testing and assurance method
↓
Practitioner Workbook
↓
local owners, risks, procedures, maturity, roadmap and evidence links
↓
JSON Schemas and CSV Exports
↓
system validation, workflow integration, evidence packs and provenance
↓
Monitoring and Independent Assurance
↓
findings, remediation, signatory review and member assurance
The primer explains why.
The technical edition explains what a professional control system requires.
The workbook records who will do what, when, under which authority, with what evidence.
The schemas make those records portable, testable, and interoperable across systems.
A practical integration sequence
Step 1 — Preserve the source package
Keep the original ZIP, provenance manifest, and checksum unchanged. Store them in a controlled repository. This gives the organization a fixed reference point and makes later modifications distinguishable from the published framework.
Step 2 — Establish governing authority
Read the Public Primer with the Board, elected officers, Local leaders, management, and member representatives.
Then use the Technical Practitioner Edition and AP&P Crosswalk to determine which proposals:
- are already governed by the bylaws;
- belong in AP&P;
- require a committee charter;
- require management procedure;
- require system configuration;
- require training;
- require legal review;
- or may require a bylaw or General Council action.
The framework should never be allowed to outrank the governing documents it was designed to serve.
Step 3 — Tailor the workbook
Create a local implementation version.
For each material control:
- confirm the risk;
- confirm the authority;
- assign one accountable owner;
- identify the performer and reviewer;
- record the system and evidence location;
- set the current and target maturity;
- choose the implementation status;
- identify dependencies;
- and preserve the rationale for any exclusion or deferral.
Do not attempt to implement all 379 controls at once. Use the risk register, priority field, and maturity gap to sequence the work.
Step 4 — Begin with the foundations
A practical first wave should usually include:
- direct oversight access to financial source records;
- complete bank, account, signer, and privileged-access inventories;
- independent monthly reconciliations;
- vendor and related-party governance;
- records retention and legal holds;
- tested isolated backups;
- an LM certification binder;
- protected complaint and dissent routes;
- a unified deficiency and remediation register;
- and direct Board visibility into unresolved high-risk exceptions.
Step 5 — Convert controls into real procedures
Each selected control must be translated into an operating procedure.
A usable procedure identifies:
- trigger;
- population;
- inputs;
- performer;
- reviewer;
- steps;
- decision criteria;
- evidence;
- deadline;
- exception condition;
- escalation;
- and retention.
A policy without procedure is an expectation. A procedure without evidence is difficult to monitor. Evidence without independent review is incomplete assurance.
Step 6 — Connect the schemas
Once the organization has stable local control IDs and procedures, the schemas can be mapped into existing systems.
A finance workflow might generate an evidence-pack object after each monthly bank reconciliation. A GRC platform might store the control and risk objects. An audit application might emit finding and remediation objects. A learning-management system might emit training records. The annual LM process might produce a signatory receipt. A website or member portal might render a member assurance pack.
The technical flow is:
Bylaw / law / AP&P authority
↓
UICAF control ID
↓
operational workflow or system rule
↓
evidence artifact
↓
schema-valid evidence-pack manifest
↓
monitoring and internal audit
↓
finding and remediation objects
↓
signatory receipt and member assurance pack
Sensitive documents do not need to be embedded directly in the workbook. The workbook may store controlled references, artifact IDs, repository locations, retention classes, and hashes, while access remains governed by role and confidentiality.
Step 7 — Pilot before enterprise rollout
Pilot the controls in representative processes. Test ordinary cases, exceptions, staff absence, system failure, record retrieval, and attempted override.
The pilot should answer:
- Can the control be performed with available staffing?
- Does the evidence prove the work rather than merely record a signature?
- Can the reviewer obtain the complete population?
- Do exceptions reach the right authority?
- Can the process survive turnover?
- Can the evidence be retrieved without coaching from the original performer?
Step 8 — Operate, test, and report honestly
After a sufficient operating period, internal audit or another appropriately independent reviewer should test design, implementation, operating effectiveness, evidence sufficiency, and remediation effectiveness separately.
The Board should receive the material results. Members should receive a bounded, intelligible account of scope, findings, open risk, remediation, and limitations.
That final step is not public relations.
It is the democratic output of the control system.
A current reporting transition is already built in
UICAF’s technical edition includes the federal LM reporting transition now underway. The Department of Labor’s 2026 final rule creates a new LM-2 Long Form for the largest labor organizations, revises the ordinary LM-2, changes filing thresholds, and applies according to the first fiscal year beginning on or after July 1, 2026. The earliest required filing on a new or revised form is after June 30, 2027.
The framework therefore treats reporting logic, schedule ownership, source-to-report mapping, evidence lineage, and form applicability as versioned control objects rather than permanent assumptions.
What UICAF does not do
UICAF does not provide legal advice.
It is not an audit opinion.
It is not a compliance certification.
It does not establish that a historical act violated law or bylaws.
It does not prove misconduct merely because a recommended control was absent.
It does not make a control effective merely because the control appears in a spreadsheet.
It does not make data true merely because the data validates against a schema.
It does not make an artifact accurate merely because its hash matches.
It does not replace independent counsel, proper Board or General Council authority, member participation, operational testing, or professional assurance.
Its contribution is narrower and more useful:
It gives an organization a professional way to move from promises to procedures, from procedures to evidence, from evidence to assurance, and from assurance to accountable correction.
Download the bundle
The complete package contains the Public Primer, Technical Practitioner Edition, workbook, CSV data, JSON schemas, figures, quality records, README, changelog, hashes, and provenance manifest.
Suggested download links for the website:
- Complete UICAF v0.1 package —
uicaf_full_manuscript_integration_v0_1_package.zip - Public Primer — PDF, DOCX, Markdown
- Technical Practitioner Edition — PDF, DOCX, Markdown
- Practitioner Workbook — XLSX
- Machine-readable schema set — ZIP
- Control Catalog, Risk Register, Roadmap, AP&P Crosswalk, Source Crosswalk, and Publication Readiness — CSV
- Provenance Manifest and SHA-256 checksum — JSON and SHA-256
Closing
A union asks employers to show how wages were calculated, how rules were applied, how decisions were authorized, and what evidence supports a claim.
That principle should not stop at the union’s own door.
The durable institution is not the one that never receives criticism, never discovers an error, or never reports a deficiency.
It is the one whose authority can be traced, whose records can be retrieved, whose controls can be tested, whose dissent can survive, whose errors can be corrected, and whose members can receive an accounting they can understand.
Trust is not branding.
Trust is a trail.
UICAF is an attempt to make that trail visible.