Ontology audits · fixed scope · reasoner-verified
A reasoner reporting no inconsistency tells you your axioms admit a model. It does not tell you they admit the one you meant. The graphs that decide payment, eligibility, and liability usually pass every check their teams run, because the checks look for contradictions and the defects are somewhere else: in what the model says a status, a licence, or a diagnosis is. I find those, and I show you the axioms that prove it.
§ 07 — The Defects
Each of these is a modeling choice any competent engineer would make. None produces a warning in Protégé, a SHACL violation, or an inconsistency under HermiT. All four turn out to be the same underlying error, which has a name and a repair.
The board revokes the license, backdated to 3 March. You retract the triple. Every referral, sign-off, and prescription derived in the intervening six months was validly derived under an authority that has since been withdrawn. Your model has nowhere to put that. You can rewrite history or keep a false assertion, and neither is defensible to an auditor who asks which one you did.
A diagnosis is an assertion by someone with standing to make it. A disorder is what the assertion is about. Collapse them and a misdiagnosis becomes a disorder the patient has, and you can no longer ask who made the call, on what basis, or whether it was later withdrawn. That question arrives in every audit and most litigation.
Two payers assign different statuses to the same claim, each correct under its own rules. Keep functionality and the reasoner reports an inconsistency you cannot repair, because neither assertion is wrong. Drop it and you lose the constraint that made the property worth having. Both exits are bad, and the reason is upstream: the status was modeled as a fact about the claim rather than as the outcome of an act by a party.
If you imported a trimmed upper ontology, or none, no reasoner objects. The class quietly inherits both. A disposition has no onset and no end; a process has both. Any query that reaches the class through one parent returns rows the other drops, and nothing at runtime tells you which reading you got. The Tester found Force, Weight, Drag, and Lift in exactly this state in a published aerospace ontology.
What all four have in common
None is a missing class or a syntax error, which is why ordinary tooling passes them. Each takes something that exists because an authority recognized it, a license, a diagnosis, a coverage determination, an episode, and models it as a property of an object. Once the recognizing act is in the model, the conflicts become representable rather than fatal, and the questions an auditor asks become queryable.
Three or more of those and there is almost certainly something to find. Three business days and $2,500 establishes whether it is worth more than that.
§ 08 — Case Study
Two classification systems govern how mental disorders are named, coded, billed, and litigated. Clinicians and payers treat them as interchangeable, and the mappings between them are maintained as though the only question were which label corresponds to which.
I formalized both as OWL ontologies anchored in a common upper ontology, resolved every term to its top-level category by walking its subsumption chain, and compared the resulting types pair by pair.
The disagreements are not about severity or criteria. They are about what sort of entity is being classified at all. One system reads episodes and intoxications as things that unfold and have temporal parts. The other reads them as standing tendencies that may never manifest. Those are not variant descriptions of one thing.
More striking, the root term for mental disorder itself inverts between the two. The disagreement sits at the top, and everything beneath inherits it.
The last figure is the one worth pausing on. Across all 138 shared terms, the count that both systems independently type as a process is zero. Not few. Zero. Wherever one authority reads a condition as something that happens, the other reads it as something someone has.
What this generalizes to
Most organizations run on more than one classification scheme and assume they reconcile. A vendor taxonomy and an internal one. A regulatory coding system and an operational one. A legacy schema and its replacement. An acquired company's model and yours. The assumption is rarely tested, because testing it means formalizing both and putting a reasoner to the result. Finding the defects takes about three weeks. Discovering them through a denied claim takes longer and costs more.
§ 09 — Why These Domains
A license, a diagnosis, a coverage determination, a clearance, a charter, a tariff classification, a title, an accreditation. Each is real and enforceable, and none of them exists independently of the act that granted it. These are the load-bearing objects in health, finance, defense, and every regulated domain, and they are what most enterprise graphs are actually about.
Formal ontology was developed on physical and biological reality, where it works very well. A cell, a bearing, a reaction: these exist whether or not anyone recognized them, and their categories hold still. Nothing in that tradition prepares you for an object whose existence is the residue of a decision, which is why models of these domains pass every ordinary check and still produce results nobody can defend.
They fail in three ways generic practice does not anticipate, and each is checkable.
Most teams meet BFO as a procurement requirement and treat it as overhead. The instrumental case is narrower and better. BFO ships one axiom that almost no in-house model has an equivalent of:
Import that and the fourth defect stops being a silent divergence and becomes an inconsistency the reasoner reports on the next build. You do not have to adopt the whole hierarchy to get it. Bringing in the top two levels and anchoring your own classes underneath is usually a day of work and converts a whole class of runtime surprise into a build failure.
The rest of the value is that your model then joins a shared backbone, which is what makes a crosswalk between two systems checkable at all rather than merely assertable. The case study above exists because both systems were resolved to the same anchor.
Where the theory comes from
This is worked out at length in the Recognition Layer and formalized at scale in A Structural Ontology of the Law, a 6,900-class model of legal structure with a typology of the ways a chain of authority can fail. You do not need any of that to commission an audit. It is where the checklist came from.
§ 10 — The Audit
I take your ontology, schema, or classification scheme, run it, and answer five questions. The first is binary and the reasoner answers it. The other four are where the work is.
What you receive
A consistency verdict, reproducible. A ranked defect inventory, each entry carrying the assertions that produce it. A conformance gap list by axiom. A prioritized remediation plan with effort estimates, written so your engineers can execute it without me. And a ninety-minute readout with your team. Everything machine-readable alongside the written report. You own all of it.
The checks are open. Run your own model through the FOL / OWL Tester first if you would rather see the shape of the output before commissioning anything.
§ 11 — Scope & Price
Fixed means fixed. If the work runs long, that is my problem rather than a change order.
Structural Coherence Audit
$12,500
Three weeks · fixed fee
The full engagement on one ontology or schema, or on two systems compared against each other.
Up to 5,000 classes. Machine-readable deliverables included.
Straddle Triage
$2,500
Three business days · fixed fee
A rapid read of a single artifact when you are not yet sure there is anything to find.
If it would find nothing, I will tell you so. Credited in full against a full audit booked within thirty days.
Included
One ontology or schema up to 5,000 classes, or two systems compared for crosswalk analysis. OWL, RDF, SKOS, or any documented schema I can parse.
Not included
Building the corrected model, integration, or ongoing maintenance. Those follow as separate engagements, and the audit tells you whether you need one.
You provide
The artifacts, any governing documentation, and one technical contact available for roughly two hours of questions.
Building a model from nothing rather than auditing one you have? That is custom ontology development, scoped separately.
§ 12 — Starting
Teams running a knowledge graph or semantic layer where the entities are statuses, entitlements, credentials, or classifications rather than physical things. Health systems, payers, and standards bodies whose classifications drive reimbursement, eligibility, or liability. Teams grounding a language model in a graph and finding the grounding does not hold. Defense and industrial programs required to conform to BFO or the Common Core Ontologies. Regulated organizations that will have to justify a classification to someone who does not accept that it has always been done this way.
Send the artifact, or a description of it if you cannot send it yet. I will tell you within a day whether there is likely anything worth finding, at no cost and with no obligation. If there is not, I will say so.
David R. Koepsell, J.D., Ph.D. I wrote the open-source validation toolchain these audits run on: the FOL / OWL Tester, which finds the faults editors pass over, and BFO-Agent, which populates an ontology from text and refuses 93.3% of unfounded assertions against a 10% ungated baseline. Both are public and you can run them against your own model before you talk to me.
Behind that: twenty-five years at the intersection of formal ontology, law, and emerging technology, trained in formal ontology under Barry Smith, one of the founders of BFO. Books with Wiley-Blackwell, Springer, Bloomsbury, Open Court, and Palgrave Macmillan, including a forthcoming monograph on the structural ontology of legal systems. Former chief legal officer of a genomic data company.
The combination that matters: I can tell you what your model asserts, whether a reasoner accepts it, and what happens to you legally if it is wrong.
Back to the underlying work
BFO-Agent, the FOL / OWL Tester, the Recognition Layer, a 6,900-class formalization of legal structure, and a public library of reasoner-validated ontologies. All of it open and browsable.