Manifesto_Vol3_AppC_RedFlagCatalog_v1.0_c0626.docx
This Appendix is the Karnataka Procurement Audit Cell’s working catalogue of red flags — named, defined, threshold-bound patterns that warrant…
Read this chapter in the interactive reader, or download the full 601-page manifesto (PDF).
The People’s Model
Manifesto v2026
Volume III — Implementation Handbook
Appendix C
Procurement & Works Red-Flag Catalog
Named detection rules. The Procurement Audit Cell’s working catalogue.
C.1 Purpose
This Appendix is the Karnataka Procurement Audit Cell’s working catalogue of red flags — named, defined, threshold-bound patterns that warrant investigation when they appear in procurement or works data on the Open Ledger. The Catalog is consumed continuously by automated checks (Vol I Ch 3 Sec. 3.7) and by the Audit Cell’s human reviewers.
A red flag is not a finding of wrongdoing. It is a pattern that warrants review. Every red flag has a defined threshold, a defined remedy pathway, and a published disposition. Repeated false positives are themselves an input to refining the Catalog.
C.2 Catalog structure
Every entry below carries: a code, a name, a definition with a quantitative threshold where applicable, the data source from Vol III App D, the response pathway, and the cross-reference to the Vol I Sec. 1.7 safeguard.
C.3 Tender-stage red flags
C.4 Execution-stage red flags
C.5 Payment-stage red flags
C.6 Cross-stage and pattern red flags
C.7 Operating discipline
- Automation first. The runtime engine continuously screens new records against the Catalog. The Audit Cell’s queue is fed by the screen, not the other way around.
- Publication of dispositions. Every red flag raised and its disposition (FALSE_POSITIVE / WARRANTED_REVIEW / VIOLATION_CONFIRMED) is published in aggregate on the Open Ledger Bulletin.
- Refinement of thresholds. False-positive rates above an agreed level trigger Catalog refinement; new categories of red flags emerging from audits are added with versioned amendments.
- Independence. The Audit Cell reports to the Lokayukta and to the Citizen Data Trust on aggregate findings; it does not report to the departments it audits.
C.8 Cross-references
- Volume I Chapter 1 — the eight named anti-capture safeguards that this Catalog operationalises.
- Volume I Chapter 3 — the workflow engine that screens records against the Catalog.
- Volume I Chapter 4 — Open Ledger publication that produces the data this Catalog acts on.
- Volume III Appendix B — Project Lifecycle SOP. The Catalog is applied at Steps 3, 4, 6 of the SOP.
- Volume III Appendix D — Open Ledger Data Dictionary. Every red flag references App D field names.
Architecture cross-reference
New red flags from the cryptographic floor
The architecture rewrite introduces new categories of red flags that auditors should monitor for: (1) KSSL anchor cadence failures — a state system that stops generating anchors on schedule. (2) Open Ledger publication gaps — a financial transaction in the operating system that did not propagate to the Open Ledger within the publication window. (3) Citizen Consent Ledger revocation non-propagation — a data flow that continued past a citizen’s revocation. (4) AI-Use Register entry missing — a state AI decision without a corresponding Register entry. (5) CSOC compel-patching non-compliance — a department refusing or delaying a compel-patching order. (6) Threshold-cryptography quorum bypass attempts — a high-impact operation attempted with insufficient quorum. (7) Open-source mandate violation — proprietary code commissioned without open-licence release.
Cross-references
Each of these red flags surfaces in different operational dashboards. KSSL events at App H sheet H.230. CSOC events at sheet H.231. Consent Ledger events at sheet H.232. Open Data Portal coverage at sheet H.233. Statutory backing for all of these red flags is in App I (Karnataka State Digital Infrastructure Act + Karnataka Cyber Security and Citizen Consent Act).
Code — Red flag — Definition + response
RF-T-01 — Single-bid tender — DEF: number of qualified bidders < 3 on a tender above KTPP threshold. SRC: contract.bidders_count. RESP: Procurement Audit Cell review before award; reason recorded. SAFEGUARD: Vol I Sec. 1.7 #6.
RF-T-02 — Identical bid prices — DEF: two or more bids within ±0.5% of each other on the same tender. SRC: tender response analytics on KPPP. RESP: Audit Cell review; potential cartel referral. SAFEGUARD: Vol I Sec. 1.7 #6.
RF-T-03 — Same-supplier pattern — DEF: same supplier wins ≥ 3 consecutive tenders of a category in a district within 12 months. SRC: awards.suppliers.id × dept_id × scheme. RESP: Audit Cell review; conflict-of-interest check (Vol I Sec. 1.7 #7).
RF-T-04 — Repeat short-notice tender — DEF: tender publication-to-deadline window < 14 days where standard window applies, repeated within 6 months by the same department. SRC: tender.publicationDate, tender.tenderPeriod.endDate. RESP: Audit Cell review.
RF-T-05 — Award above estimate — DEF: award value > 110% of the published estimate without published reason. SRC: awards.value.amount vs tender.estimate.amount. RESP: written reason required; Audit Cell review beyond 125%.
RF-T-06 — Vendor blacklist breach — DEF: award to a vendor on the active Karnataka blacklist. SRC: awards.suppliers.id vs blacklist registry. RESP: award void; investigation; officer accountability.
Code — Red flag — Definition + response
RF-E-01 — Change-order frequency — DEF: ≥ 3 change orders on a contract within 6 months of award; or any single change order > 15% of contract value. SRC: contract amendments × value. RESP: Sponsor + Audit Cell review; cumulative cap rule.
RF-E-02 — Time overrun — DEF: actual milestone delivery > 125% of scheduled time, without published reason. SRC: milestones.dueDate vs milestones.actualDate. RESP: Risk Manager triggered escalation; engine L2 (Vol I Sec. 3.3).
RF-E-03 — Cost overrun — DEF: cumulative cost > 110% of award value without published reason. SRC: sum(transactions.value) vs awards.value. RESP: Audit Cell review beyond 125%.
RF-E-04 — Geo-tag mismatch — DEF: milestone evidence geo-tag outside the contract location boundary. SRC: milestones.evidence_uri.geo_tag vs contracts.geo. RESP: inspection re-run by an independent inspector.
RF-E-05 — Same-vendor inspection — DEF: same inspector certifies ≥ 5 consecutive milestones for the same vendor. SRC: inspections.inspector_id × awards.suppliers.id. RESP: rotation rule enforced (Vol I Sec. 1.7 #5); historical sample audit.
RF-E-06 — Repeat repairs — DEF: same asset receives ≥ 3 repair work orders for the same defect category within defect-liability period. SRC: asset_id × workorder.defect_category. RESP: contractor performance review; defect-liability claim.
Code — Red flag — Definition + response
RF-P-01 — Stop-the-line override — DEF: payment release with exception_code != NONE without Sponsor sign-off. SRC: transactions.exception_code × authorisation log. RESP: automatic Audit Cell case; officer accountability.
RF-P-02 — Advance pattern — DEF: same officer authorises ≥ 3 ADVANCE-coded payments within 12 months. SRC: transactions.exception_code = ADVANCE × payer_id. RESP: investigation (Vol I Sec. 4.7 safeguard 4).
RF-P-03 — Beneficiary bank-account change — DEF: bank-account change without multi-factor authentication + supervisor approval. SRC: spine.audit_log on beneficiary records. RESP: payment blocked; investigation.
RF-P-04 — Payment-delay anomaly — DEF: vendor payment delay > 90 days against a milestone with PASS certificate, without published reason. SRC: milestones.passDate vs transactions.payment_date. RESP: Risk Manager escalation; investigation if delay-rent pattern emerges.
RF-P-05 — Round-tripping pattern — DEF: payments to a vendor where ownership chains show ≥ 50% common-beneficial-ownership with another receiving vendor within the same scheme/district. SRC: Karnataka Supplier Registry beneficial-ownership filings. RESP: full investigation.
Code — Red flag — Definition + response
RF-X-01 — District unit-cost anomaly — DEF: same work-category unit cost in a district > 125% of the statewide median, or < 75%, sustained for two quarters. SRC: published unit-cost benchmarks (Vol I Sec. 4.4). RESP: Audit Cell review; correction or accepted variance with reason.
RF-X-02 — Concentration risk — DEF: > 30% of a department’s annual procurement value with a single vendor. SRC: awards aggregated by buyer.id × suppliers.id. RESP: Audit Cell review; diversification plan.
RF-X-03 — Officer COI mismatch — DEF: contract awarded to a vendor with disclosed beneficial overlap with an officer in the awarding chain. SRC: COI register × awards. RESP: automatic audit (Vol I Sec. 1.7 safeguard 7); award reviewable.
RF-X-04 — Citizen-rating triggered audit — DEF: average citizen rating for a service category in a district falls below the published threshold for two consecutive quarters. SRC: spine.ratings aggregated. RESP: structural audit; redesign or accountability action (Vol I Sec. 1.7 safeguard 8).
RF-X-05 — Grievance cluster — DEF: ≥ 20 grievances of the same category in the same block within a quarter. SRC: grievance engine aggregation. RESP: L4 structural escalation (Vol I Sec. 3.3); Grievance Justice Authority pattern audit.
← Manifesto_Vol3_AppB_ProjectLifecycleSOP_v1.0_c0626.docx · Manifesto_Vol3_AppD_OpenLedgerDataDict_v1.0_c0626.docx →
This is a chapter of The People's Model manifesto for Karnataka — published in full for public review. Every claim may be challenged: write to [email protected].