# pc-expired-exception-blocks-build.policy-card.yaml: Policy Card pc-expired-exception-blocks-build version 1.0.0.
# Validates against https://aigovernanceengineer.com/schemas/policy-card.v1.json
# Generated by the Policy Card builder, https://aigovernanceengineer.com/toolkit/policy-card
# Illustrative, review before use. Indicative, not legal advice and not a conformity claim.
"$schema": "https://aigovernanceengineer.com/schemas/policy-card.v1.json"
card_id: pc-expired-exception-blocks-build
version: "1.0.0"
title: "Expired exceptions block the build"
owner: ai-governance-engineering
applies_to:
  - "repo:*"
source_policy: "ai-policy.yaml#exceptions"
rules:
  - rule_id: exceptions.no-expired.v1
    description: "The build fails while any policy exception it relies on has expired, has no grant or expiry date, or runs longer than 90 days."
    effect: deny
    condition: "an exception has expired, has no grant or expiry date, or runs longer than 90 days"
    failure_mode: "A temporary exception quietly becomes permanent and the rule it waived stops applying."
    enforcement_points:
      - pre_merge
    implementation:
      engine: opa_rego
      module: policies/pc-expired-exception-blocks-build.rego
      entrypoint: data.aige.cards.pc_expired_exception_blocks_build.verdict
    maps_to:
      - AIGE-OBL-ISO42001-A2
      - AIGE-OBL-EUAIA-ART17
      - AIGE-OBL-NISTRMF-GOVERN
exceptions: "Requested by the system owner, approved by the AI governance committee for at most 90 days, and recorded as a signed verdict override with an expiry."
effective_from: "2026-10-01"
review_by: "2027-04-01"
extensions:
  generated_by: "https://aigovernanceengineer.com/toolkit/policy-card"
  template: expired-exception-blocks-build
  notice: "Illustrative, review before use. Indicative, not legal advice and not a conformity claim."
  cedar_module: policies/pc-expired-exception-blocks-build.cedar
  ci_hook: ".github/workflows/policy-card-pc-expired-exception-blocks-build.yml"
  approval_pending_from: ai-governance-committee
