BackThe List Of The Undeserving
This chapter is saved on your device for offline reading
Chapter 16

The Rule Test

Eight people sat in the IT lab.

Grace, Karanja, the IT lead, Wema, Zuri, a legal officer, a monitoring analyst, and a vendor representative on video.

“We cannot expose source code,” the vendor representative said.

“We are not asking for source code,” Grace replied. “We are asking for reproducible outcomes from agreed synthetic inputs.”

The control case ran first.

Stable declared need. Ordinary food spending. No peer signal.

Outcome: green.

Then the helmet case ran.

The synthetic student’s declared need was unchanged. The purchase category was *equipment*. No field existed for a course requirement.

The simulator returned:

**HIGH RISK — AUTO SUSPEND PENDING REVIEW.**

Zuri leaned forward. “But the helmet is mandatory.”

The IT lead pointed to the schema. “There is no course-context field.”

Karanja said, “Human review can correct that.”

“Before or after suspension?” Grace asked.

No one answered immediately.

The vendor representative clarified that the current configuration applied a provisional hold before contextual review.

“For a student,” Wema said, “a provisional meal hold is still missing food.”

“And if fraud is real?” Karanja asked.

“That is why I am not asking you to remove review. I am asking why punishment arrives before context.”

The funeral-travel case ran.

It received a medium-risk classification and restrictions on selected aid modules.

“Gift context?” Grace asked.

“Not represented in the current schema,” the vendor representative said.

Karanja leaned toward the table. “We cannot demand an explanation for every anomaly. The whole point was faster fraud control.”

Wema looked at the policy criteria beside the simulator output.

“Then the model cannot actually implement your policy of holistic need with the data it has.”

The room went still.

The vendor representative proposed adding a manual override field and running the test again.

Grace refused.

“That override is not part of the current pre-sanction workflow. We test the implementation that exists.”

The IT lead showed a configuration log. Red-band cases triggered automated adverse action. Service propagation was controlled by a separate configuration.

“Can essential services be separated without changing the risk model?” Wema asked.

“Yes.”

That opened a practical path.

The interim remedy would do two things: preserve fraud-review flags but disable automated sanctions, and stop those flags from automatically propagating into unrelated essential services. Human review would receive context before a final adverse decision.

Karanja shook his head. “Your backlog will explode.”

The IT lead agreed that manual queues would grow.

Grace asked whether donor reserve funding could support temporary review staff. The monitoring analyst confirmed that it could.

Wema did not demand that the entire model be deleted.

“Pause automated sanctions. Keep flags. Protect emergency access. Measure the backlog honestly.”

The IT lead disabled the sanction toggle.

They ran the helmet case again.

The risk label remained.

The result changed to:

**REVIEW REQUIRED — NO SERVICE SUSPENSION.**

They ran the funeral case again. Same principle.

The control case remained green.

The IT lead opened a change ticket containing the approver, timestamp, affected modules, rollback plan, and review period. Grace required follow-up monitoring so the setting could not quietly revert.

She also added two measures to the redesign: median review time and wrongful service interruption.

Success would no longer be measured only by reduced misuse.

Karanja looked exhausted.

“I wanted turnaround.”

“And students wanted explanations,” Wema said.

“You cannot have everything.”

“Maybe not. But you can show the tradeoff instead of hiding it inside a success metric.”

For the first time, Karanja did not argue.

Grace signed the interim finding:

**Control objective valid; implementation materially unfair.**

At 17:26, automated sanctions were formally halted pending redesign.

The fraud-control objective survived.

The change ticket also included a rollback plan and a scheduled monitoring review. Wema liked that detail more than the room’s moment of relief. Reform itself had to be auditable. If the sanction toggle was quietly restored later, the timestamp and authorization record would show it. Grace required a follow-up check after one week and requested two metrics for the interim period: median manual-review time and the number of wrongful essential-service interruptions. The cost of fairness would now be visible too. Backlogs might rise, and temporary staffing might be necessary. Wema accepted that tradeoff because hiding the cost would simply create a new misleading success story.

The unexplained punishment did not.

Reading settings
Line spacing
Theme