# SILENT EXPIRY — THE CANONICAL DEFINITION
## Single Source of Truth · Rev3 · Public edition (sections 1–9)

**Status**: Constitutional document of the Silent Expiry discipline. Current revision.
**Issued**: 5 September 2026. **Supersedes**: Rev2 (2 September 2026), Rev1 and Rev0 (2 September 2026), all retained.
**Language of record**: English. **Author of record**: Dan Bleigh.
**Citation**: *Silent Expiry — Canonical Definition, Rev3, silent-expiry.pages.dev, 2026.*
The definition may be quoted freely with attribution. It costs nothing to use. That is
deliberate.
**Online**: https://silent-expiry.pages.dev/definition/ — revision history at https://silent-expiry.pages.dev/revision-history/

---

## 1. Definition

**Silent Expiry** is the state of a control that remains documented, in force and
verified as compliant while at least one condition its protective effect depends on has
ceased to be true — and whose failure produces no signal. A control in this state
continues to behave exactly as specified. It no longer protects anything.

The canonical short form:

> **Silent Expiry** — the quiet death of a control that stays documented, accepted and
> signed after the conditions it was built on have gone. Nothing fails. Nothing alarms.
> The paperwork remains correct — and the protection is no longer there.

Throughout this document, a **control** means any deliberate arrangement instituted to
keep an outcome within bounds: a rule, a check, an interval, a sample size, a threshold,
an approval, a device setting, a qualification, a review. The definition is therefore
not specific to manufacturing, to quality management, or to any standard. It applies
wherever controls exist.

Silent Expiry is present when, and only when, three conditions hold together:

1. **A reason existed.** The control was instituted because of a state of the world
   that justified it, and that state was real at the time. Whether anyone articulated
   that reason is immaterial: an inherited or copied number that was right for the
   conditions then holding has a premise like any other — and is a common case. What
   condition 1 excludes is the control that was wrong from the start.
2. **The premise lies outside the control's verification.** What persists is the
   control and its documentation. The premise may be recorded elsewhere — in a standard,
   a design basis, a footnote to a schedule, an engineer's memory — and the organization
   may know it perfectly well. What defines the condition is that no artefact the
   control's own verification consults, and no question that verification asks, tests
   whether the premise is still true. The separation is structural: between the control
   that persists and the condition that makes that control protective. Whether the
   premise was ever written down is immaterial. A premise recorded where the verification
   never looks is separated as completely as one never recorded at all — and in practice
   it is the commoner case.
3. **The failure is mute.** When the premise ceases to be true, the control does not
   break, stop, or alarm, and no signal attributable to that premise's failure reaches
   the verification loop of that control before its next relevant verification point.
   Signals may well exist elsewhere in the organization — a drifting scrap rate, an
   operator's remark, a line in a monthly report — and typically do. Muteness is a
   property of the *routing*, not of the universe: nothing carries the signal to
   anything that could act on this control. It is therefore **not** Silent Expiry if a
   warning about the premise was received and not acted on; if a regulator was informed;
   if engineers identified the changed premise; if a deviation report reached the
   verifying function; or if the premise was considered and action was decided against.
   Those are failures of response, and they are excluded. The concept covers what was
   never asked, not what was asked and answered badly. A control whose premise announces
   its own failure (an expiry date that flags, a licence that blocks) is
   **self-revealing** and is out of scope.

**Compliant non-execution.** For interval, threshold and trigger-based controls,
Silent Expiry commonly appears not as a control that fails while running, but as one
that never arrives. The control stays in force; the compliance check correctly returns
*not due*; and the trigger has stopped tracking the condition that drives the hazard. An
interval counted in operating hours, on an asset used at half the rate assumed when the
interval was set, passes every audit while the period it actually delivers has quietly
doubled in calendar terms — which is the period that matters if the mechanism it guards
against runs on the calendar. In this form the evidence is not a missed task. It is a
task that was never owed.

**The structural condition.** These three describe the state. A fourth fact explains
why the state persists: every standard verification instrument — audit, closure review,
management review — interrogates the record or the execution, and none interrogates the
premise. This is a property of the instruments, not of the state. An organization that
has installed premise-keeping still *has* expired premises; what it has changed is that
it now finds them. **Detection changes the exposure, not the phenomenon.**

All three conditions are individually testable. A situation that fails any one of them
is not Silent Expiry, and this document says so plainly in Section 4 — the concept's
usefulness depends on its narrowness.

**Expiry is graded, not binary.** Protective effect degrades continuously as a premise
departs from truth; the short-form phrase "the protection is no longer there" names the
end state of that degradation, not an instantaneous switch. In practice a premise is
recorded as fallen when the change in the world is **material** — when the control's
protective effect has degraded enough that, had the current conditions been known at
institution, a different control would have been chosen. Materiality is set locally,
recorded with the premise, and is itself subject to review. Practitioners are warned
against the characteristic overclaim: a 20% erosion of margin is a degraded control, not
an absent one, and describing it as absent discredits the finding and the term.

**"Protection" means the control's own.** The protective effect at issue is that of the
control under test, on its own terms. A second, uncoordinated control that happens to
cover the same outcome does not restore it — any more than an audit would credit a
compensating control nobody has identified, tested or decided to rely on — and a
register that quietly leaned on such coincidences would be recording its own next
expiry.

## 2. Why a New Term Is Needed

The existing vocabulary of management is built around three kinds of object: **events**
(failures, nonconformities, incidents), **causes** (why an event happened), and
**conformance** (whether practice matches its documentation). Each of the established
disciplines serves one of these objects well, and none of them owns the object at the
center of Silent Expiry — which is not an event, not a cause, and not a conformance gap,
but a **state**: a truth about the world that has quietly stopped holding.

The relationships, stated with respect:

**Root cause analysis and CAPA** operate after an event, and operate well. Silent
Expiry describes what exists *before* the event — often for years before. A fallen
premise frequently becomes the root cause an investigation later finds; the concept
names the interval during which it was findable and nothing was looking.

**Audit** verifies that a system conforms to its own declarations. It does this
correctly. The conditions a control was built on were never declared, so they sit
structurally outside every audit's evidence base (Section 6).

**ISO 9001's own context and change machinery** is the objection this document's first
readers will raise, and it deserves the most precise answer in this section. The
context clause (4.1) requires the organization to determine the external and internal
issues relevant to its purpose and to monitor and review them; management review takes
changes in those issues as an input (9.3); planning and control of changes (6.3, 8.5.6)
govern the changes the organization makes. All three are real, and a mature system runs
all three. They operate at the level of the organization — market, regulation,
technology, capability — and are reviewed by the people who run the organization, on
the cadence at which they meet. A premise operates at the level of the control: one
supplier's reject rate, one machine's duty cycle, one person's continued tenure in a
post. Nothing in the context clause links an issue to the specific controls that stand
on it, so a context review can faithfully record "supplier base changing" while the
sampling plan built on the old supplier keeps its number. Change control governs
changes the organization decides to make; a premise falls without anyone deciding
anything (property 2), and most often because of a change somebody else made. The
clauses supply the level above and the process beside. Neither supplies the
per-control record, and neither asks the per-control question. (Clause numbers follow
the harmonized structure in use since the 2015 edition; the argument does not depend
on them.)

**Risk management** registers uncertain future events and their consequences. A premise
ceasing to be true is not an event — nothing happens, nothing arrives, nothing can be
dated by observation at the time. Risk registers hold what might occur; Silent Expiry
concerns what has already silently stopped being true.

**FMEA** rates the failure modes of a product or process, including how detectable each
failure is. Its detection rankings score the escape of defects — not the decay of the
assumptions under the controls it recommends. An FMEA's own recommended actions become,
once implemented, precisely the kind of control that can silently expire.

**Lessons learned** capture what happened; **knowledge management** preserves what is
known. Both preserve artifacts. Preservation is not the missing function — preservation
of the *control* while the *reason* evaporates is part of the mechanism itself
(Section 3).

**Continuous improvement** optimizes what is measured. A premise with no signal is not
measured, so improvement systems route around it indefinitely.

**Systems thinking** supplies the worldview — everything connected, delays everywhere —
but no unit of record. It tells you assumptions decay somewhere; it does not tell you
which ones, where they are written, or who would know.

**Model risk management** — the validation and periodic revalidation of quantitative
models, as practiced in banking, and its machine-learning cousin *concept drift* —
deserves specific mention: it is one of several established disciplines that treat
expired assumptions as a first-class object, each inside its own narrow domain. Silent
Expiry generalizes that shared insight from models, plans, and safety designs to
controls of every kind. The fuller lineage — what is owed to whom — is given at the
close of this section.

**Lineage and contribution.** The ideas assembled here are not new, and this document
does not claim they are. That controls and systems embed assumptions which were valid
when adopted and silently cease to be is Lehman's observation for software
(1980–1996) and Rasmussen's for socio-technical systems (1997). That an organization
can spend years in a state where its accepted beliefs about its own protections are
false and nothing signals it is Turner's *incubation period* (1978); that a dormant
weakness in a defense waits for a trigger is Reason's *latent condition* (1990). That
the reasons for a decision are lost while the decision persists is the founding problem
of the design-rationale and organizational-memory literatures. That the load-bearing
assumptions under a plan can be identified, signposted and watched is Dewar's
*Assumption-Based Planning* (1993); that the same can be done for the assumptions under
a safety design, checked during operations, is Leveson's assumption-based leading
indicators (2015). That a protective function can fail hidden, discoverable only on
demand, and must be found by scheduled tasks is the hidden-function doctrine of
Reliability-Centered Maintenance (1978). Model risk management (SR 11-7, 2011) and the
project assumption log (PMBOK, 2017) practice assumption review by mandate in their own
domains.

What Silent Expiry contributes is the **configuration** these sources enclose without
naming: a control that was *right when built*, whose premise fell *with no decision and
no drift in practice*, whose loss of protection is *hidden but not a failure of the
device*, in the *routine controls of an operating management system* — where there is
no hazard analysis to mine, no model output to back-test, no project to close. For that
region it supplies a deliberately narrow object (the premise, five properties), a
filter transposed from RCM's evident/hidden partition to premises rather than devices,
and a name. It replaces none of the disciplines above. It is what they would have
written for this domain if any of them had been working in it.

Stated as a claim, so that it can be held to: Silent Expiry is offered as a
**diagnostic state with a unit of record** — a named, testable configuration and the
object it is tested on — not as a newly discovered phenomenon. The phenomenon is old.
The state had no test, and the unit had no record.

## 3. The Core Mechanism

### 3.1 What actually expires

Not the document. Not the practice. What expires is a **premise**: a statement about
the world that had to be true for the control to protect, and that was true when the
control was instituted.

A premise has five properties, all required:

1. It is a **proposition** — true or false, not a thing or a value judgment.
2. It is **contingent** — it can stop being true without anyone deciding anything.
3. It was **true at institution** — otherwise the control was a design error, which is
   a different and better-understood problem.
4. **The protection depends on it; the execution does not.** If it falls, the control
   still runs — and no longer protects.
5. It is **external to the control** — a control cannot verify its own premise, any
   more than a thermometer can certify the room it was calibrated for.

The essential distinction: a **requirement** states what the control must do; a
**premise** states what the world must be for that to be enough. Organizations manage
requirements with great discipline. Premises, as a class, are managed by no one.

Property 5 says the control cannot *verify* its premise, not that it cannot *influence*
it. A barrier that changes how closely people approach the edge it guards has altered
the very behaviour it was sized for — and still cannot check it. The premise is
external in the sense that matters, and such a control is a candidate for the state
like any other, with one added instruction: its witness watches for the control's own
side effects. The property holds only approximately where a rule's reason is partly
constituted by the rule's own text — a statute and its legislative purpose — and the
definition is applied there with that said.

### 3.2 Why the premise gets lost

The separation of condition 2 is not an accident of sloppy practice; it is a structural
product of documentation itself. Writing a control down preserves the decision and
discards the world that made it right — three times over. *Spatially*: the record lives
in a system the justifying conditions never entered. *Temporally*: the record outlives
the conditions by design; retention is what records are for. *Personally*: the record
outlives the tenure of the person who knew why. Often there was nothing to sever: the
reason was never written anywhere, lived in one person, and left with them — condition
2 covers that case in its first words, *were not recorded*. Ten years later the
organization holds a perfectly maintained instruction and no surviving trace of its
reason. Better
document control does not repair this; better document control preserves the severed
record longer.

### 3.3 Why nothing notices

Because of properties 4 and 5, the failure is mute by construction. Controls whose
premises announce their own death — a certificate that flags its expiry date, a licence
that blocks at renewal — are *self-revealing* and largely take care of themselves;
engineering builds alarms where it knows how. Silent Expiry lives exactly where no
alarm was built: in the sample size resting on a supplier's old defect rate, in the
interval computed from a retired production tempo, in the qualification that assumes a
person still holds a post. The world moves; the control does not; no instrument watches
the gap between them. Organizations do not fail to notice out of negligence. There is,
in the ordinary architecture of management systems, nothing whose job it is to notice.

## 4. What Silent Expiry Is Not

The concept is narrow on purpose. The following exclusions are part of the definition.

- **Not poor execution.** Silent Expiry presupposes faithful execution — that is what
  makes it invisible to conformance audits in the first place. If practice deviates
  from the document, that is nonconformance — visible to any audit — and not this.
- **Not incompetence or negligence.** By property 3, the premise was true and the
  control was right when instituted. Everyone involved did their job. That is what
  makes the state invisible to blame-seeking instruments: there is no defendant.
- **Not technical failure.** Nothing breaks. A broken control produces symptoms;
  an expired one produces records.
- **Not simple obsolescence — though the two overlap, and the overlap is worth
  naming.** An obsolete artifact is stale against a **currently known requirement**:
  the standard was revised, the customer specification changed, the regulation was
  updated. Someone comparing the artifact to the requirement register finds it, because
  both sides of that comparison exist inside the document system. An expired premise is
  stale against a **condition of the world that was never recorded anywhere**: no
  register holds it, so no comparison inside the document system can find it. Where a
  premise happens to have been recorded in a public artifact — a flood-plain map, a
  model validation report — the case sits on the boundary: obsolescence in form, Silent
  Expiry in effect, because nothing connects the stale artifact to the controls that
  depend on it. The useful question is never "is this obsolete or expired?" but "**is
  there any comparison, anywhere in this organization, that would catch it?**"
- **Not a synonym for root cause.** Root cause is what an investigation names after an
  event. Silent Expiry is a state that exists before any event, and may persist for
  years without one. When the event finally comes, the fallen premise may well be the
  root cause found — the concept covers the years during which finding it required no
  incident, only a question nobody's method asked.
- **Not normalization of deviance, and not drift.** In normalization of deviance, a
  visible anomaly is progressively tolerated. In practical drift, practice migrates
  away from procedure under real-world pressure. Both involve something observable
  moving. In Silent Expiry, nothing observable moves: practice matches procedure
  exactly, no anomaly exists to tolerate — the *world* moved. This boundary is what
  keeps the term from absorbing every famous disaster; most celebrated accidents fail
  the three-condition test, and honest use of the term refuses them.
- **Not a rival to latent conditions or the incubation period, but a species of
  both.** A fallen premise *is* a latent condition (Reason) and the years it goes
  unnoticed *are* an incubation period (Turner). Silent Expiry names the subset in
  which the defense was correct when built and no practice moved — the subset for
  which neither tradition proposed a per-control record.

## 5. Observable Symptoms

Practitioners do not see Silent Expiry directly — mute is mute. They see its shadows:

- **The recurring nonconformity that survives "effective" corrective action.** The same
  defect returns after each closure, because each action rebuilt the control and none
  re-examined what the control assumes.
- **Investigations that end at "procedure was followed."** True, complete, and
  unhelpful — the signature of a premise problem being examined with conformance tools.
- **Numbers nobody can justify but everyone obeys.** Every chosen number in a
  management system — an interval, a sample size, a threshold — is a fossilized
  assumption. Ask who chose it and from what, and the trail usually ends at a person
  who has left or a condition that has changed.
- **Grammar that hides a count.** "The setter", "the machine", "is verified" — definite
  articles concealing that the answer is *one person*, passives concealing that no one
  in particular does it. Premises hide in chosen numbers, definite articles, and
  agentless passive verbs.
- **The veteran's aside.** "That was for the old line." The most reliable detector
  currently deployed in industry is an experienced employee three months from
  retirement.

The standard misinterpretations: treating these as training problems (retraining
executes a premise problem harder), as documentation problems (revising a document
re-severs it with fresher ink), or as discipline problems (there is no one to
discipline — see Section 4).

The strongest form of the objection is not that any one of these explanations is wrong
but that together they are sufficient — that an incident can always be explained as
poor document control, poor change management, an obsolete FMEA, a missed periodic
review or a training gap, and that nothing is left over for a new term. Run them
against the manufacturing example of Section 7. **Document control**: the sampling plan
is current, approved and controlled — it passes. **Change management**: the supplier
changed its sand source; that was the supplier's decision, outside the buyer's change
control, and nothing was notified or submitted for the buyer to manage — it passes
(where a contract requires supplier change notification and it is honoured, the premise
is self-revealing and the case is out of scope; here it was not). **The FMEA**: the
analysis that recommended eight per lot is current and its action is closed; its
occurrence rating was right when assigned, and nothing in the FMEA's review cycle
re-derives it from the supplier's live reject rate — it passes. **Periodic review**:
the plan was reviewed on schedule and found to conform — it passes. **Training**: every
inspector is qualified and follows the plan exactly — it passes. Five explanations, all
true, all satisfied, and the plan protects a supplier that no longer exists. That is the
test the term has to pass to earn its place: not that the standard explanations are
wrong, but that a case exists in which every one of them is satisfied and the exposure
remains.

## 6. Why Audits Rarely Detect It

An audit compares two things it can hold: the **record** and the **practice**. It asks
whether practice conforms to record (the execution gap) and whether the record is
current and controlled (the currency gap). Both comparisons are legitimate, necessary,
and performed billions of times a year.

A third comparison is often raised against this document, and it is real: the
**effectiveness audit** — standard in quality auditing for decades, and explicit in
ISO 9001's internal-audit clause, which asks whether the system is *effectively
implemented and maintained* — compares practice to its outcome: does the control
achieve what it is for? It is legitimate and it is valuable. It is also lagging. It can
see a fallen premise only once the fall has produced a measurable outcome — escapes at
the customer, a field-return rate that moved, an incident — which is to say, once the
exposure has already been paid for. Until then the outcome sits inside its historical
range, because the demand on the protection has not yet arrived: the hidden-function
structure Reliability-Centered Maintenance described for devices (Section 2), here for
premises. When the outcome finally moves, the effectiveness audit is one of the
channels through which muteness ends — usually after the harm, and usually without
naming the premise. The premise axis is leading where the effectiveness axis is
lagging: it asks whether the conditions the control was built for still hold, not
whether the consequences of their absence have arrived.

Silent Expiry lives on an axis none of these comparisons reach: record and practice
against the **world the control was designed for**. On this axis the audit has nothing
to compare, because the
premise was never written down. **You cannot sample what was never recorded.** The
evidence model of auditing requires an artifact to check against; the premise has no
artifact, no document number, no location. The audit is not failing at its job. Its
job has a boundary, and Silent Expiry lives entirely on the far side of it.

This is the structural blind spot, and it yields the discipline's central practical
consequence: the state becomes detectable only when the premise becomes a record —
written, dated, assigned to the person who would know, and asked about on a schedule.
Detection is not an analytical problem. It is a bookkeeping problem that nobody's books
were designed to hold.

## 7. Examples Across Domains

Each example passes the three-condition test; in each, note that every record involved
is correct.

**Manufacturing.** Incoming inspection samples eight castings per lot — a sound plan
when the supplier's reject rate sat below one percent. The supplier changes its sand
source; the rate quadruples. Sampling continues, correctly executed, and the plan
protects a supplier that no longer exists.

**Engineering.** A machine's calibration interval was computed from the duty cycle at
commissioning. Throughput has since doubled. Every calibration is on time, certified,
and scheduled for a machine that retired years ago without moving.

**Healthcare.** A deterioration-screening protocol was validated on the ward's 2019
patient population. The catchment has aged; acuity has shifted. The protocol is applied
to every patient, perfectly, with quietly degraded sensitivity — and every chart is
complete.

**Aviation.** A maintenance interval assumes the utilization profile the operator flew
when the program was approved — sector length, cycles per day. The route network
changes; compliance with the interval remains exact.

**Defense.** Spares provisioning for a land-vehicle fleet was computed from a training
tempo set years ago. The tempo changed; the inventory records reconcile to the unit;
readiness erodes with every accurate stock count.

**Software.** A firewall rule set enforces a network boundary designed in 2021. A later
integration bridged the segments. The rules are applied faithfully, audited annually,
and defend a perimeter that is no longer where they think it is. (The TLS certificate
that expires loudly at 2 a.m. is the self-revealing cousin — engineering alarms what it
can. The bridged segment alarms nothing.)

**Finance.** A credit model was validated under one interest-rate regime and borrower
mix. The regime turned. Model governance — where it exists and is honored — is the one
discipline that schedules the question; where revalidation lags, the model prices
faithfully in a world it was never shown.

**Government.** A flood-plain map encodes the storm statistics of the 1980s. Permits
are issued against it daily, each one correct to the map, the map correct to a climate
that has moved on.

## 8. Relationship to *The Norwood Files*

The phenomenon was first demonstrated at length in *The Norwood Files* (2026), a novel
that follows one fictional plant through four years of accumulating expiry, because the
state takes years to form and narrative is the only instrument that compresses years
while preserving causality. The novel is the concept's first demonstration, not its
source of validity. Nothing in this document depends on it, and everything in it
conforms to this document.

## 9. Future Development

The definition establishes what Silent Expiry *is*. The instrument descends directly
from Dewar's Assumption-Based Planning and Leveson's assumption-based leading
indicators, and borrows its cadence logic from the failure-finding intervals of
Reliability-Centered Maintenance; its contribution is to bring that machinery to
controls that have none of the analyses those methods start from. Managing it requires
an instrument: a way to write premises down, assign them to the people who would know,
ask about them on a schedule, retire them with the controls they belong to, and measure
the watching itself. That instrument — the
premise register and its operating discipline — is formalized in *Silent Expiry — A
Field Manual* (in preparation). Three diagnostic questions from that work are already
stable and free to use: **Date** — can you say when the premise would have stopped
being true? **Witness** — who, outside the control's owner, would actually know?
**Counterfactual** — if it were false today, would anything alarm, or would the
control keep running? The third question finds the ones that matter. For a premise
that erodes rather than breaks, the Date question is answered by the materiality rule
of Section 1: the point at which, had the conditions been known, a different control
would have been chosen.

Two boundaries keep the instrument tractable, and they belong in the definition,
because without them it reads as a demand to write down every assumption in the
building. The first bounds the premises: only a proposition whose falsity would leave
the control running and unprotective is load-bearing — the Counterfactual question is
the load test — and only load-bearing premises are recorded. "Gravity holds" fails it:
if gravity stopped, everything would alarm. A control may carry more than one
load-bearing premise; all that pass are recorded, and none has to be singled out as
*the* premise. The second bounds the controls: the Field Manual records premises only
for the controls the organization's own risk process has already marked as significant
— for a plant of ordinary size, tens of controls, not the procedure library. An
organization asked to show that it identifies Silent Expiry would show exactly that
record: its significant controls, their load-bearing premises, each dated, each with a
named witness, each asked on a cadence, and the count of those that nothing would
currently reveal if they fell.
