Skip to main content
Failure protocol

When we are wrong

A score is a measurement, and measurements can be overtaken by events. A brand we rated highly can still halt withdrawals, disclose a breach, or be found insolvent. This page sets out — in advance — exactly what we do when that happens, so our response is a procedure we already committed to, not a decision we make under pressure.

§1

We never delete or rewrite a score

Our score history is append-only. When a brand fails, we do not quietly remove its page, and we do not change a past number. The score is shown frozen — struck through, but still visible, with the value it held at the moment we froze it and a timestamp. The strike-through is the record: it shows what we published and when, rather than hiding it.

§2

What we do, and by when

These are the targets we hold ourselves to. They are targets, not warranties — a genuinely novel situation may take longer, and we would rather be accurate slightly later than fast and wrong.

§3

We do not change the rules in reaction

We do not make an unscheduled change to our methodology inside the review window, or while a related legal threat is live. Overfitting our method to the last failure is its own kind of error. A methodology release whose plan, scope, and date were recorded before the event proceeds on its own schedule, and we disclose it in the post-mortem rather than letting it look like a quiet reaction. “No change” is a legitimate, and often correct, outcome: some failure modes are outside what our published evidence can see, and our methodology says so.

§4

What we will not do

§5

Two kinds of wrong: theirs and ours

A different case is when the fault is ours: a bug in our pipeline, an input we should have caught, or a weight applied incorrectly. We call this a computation error, and it gets a different remedy — the score was never right, even at the moment we published it.

Public correction-note template

On [date] we found that the score published for [brand] between [date A] and [date B] was computed in error. Cause: [description of the bug, bad input, or mis-weight]. Corrected score: [X], effective [date]. The erroneous prior value, [Y], remains in our public record, marked as an error — it is not deleted.

Both invariants hold at once. The ledger keeps every value we ever published — a miscalculation is never deleted, only labelled. The number showing today is always the one we currently believe is correct — a miscalculation is never left standing in public. A brand failure preserves an accurate historical value; a computation error disowns an inaccurate one while still keeping the record of it.


For how a score is computed in the first place, see /methodology. Every published score and every change to it is recorded in our audit trail.