Who Assures the Verifier? An Executable Assurance-Locus Audit of the European Digital Identity Wallet
The European Digital Identity Wallet (EUDI Wallet) architecture places material duties on relying parties: they register services and intended uses, authenticate to Wallet Units, validate presentations and trust anchors, and make risk-based status decisions. Wallet certification and the emerging Functional Conformance Assessment Framework provide increasingly structured wallet-side evidence. A different question remains: what independently rerunnable evidence shows that the concrete relying-party verifier version used in a transaction enforced the applicable request, presentation and reliance-decision controls? We conduct an assurance-locus audit of current law, Architecture and Reference Framework (ARF) 3.0.0, ETSI metadata, FCAF scope and three pinned open-source verifier codebases. We then design a 17-rule research profile, a machine-readable evidence receipt and 36 frozen synthetic transactions. Three heterogeneous study-authored implementations (Python, JavaScript and jq) execute 108 cases with zero oracle mismatches and zero cross-path disagreements. The experiment establishes determinism and implementability of the proposed decision model, not product conformance or certification. Source inspection finds substantial protocol-verification mechanisms in all three public codebases but no single audited evidence object joining RP registration and purpose, exact verifier/policy version, transaction verdict and downstream attribute use. We therefore propose an RP-as-system-under-test evidence unit that complements, rather than displaces, wallet certification, registration and supervision. A preregistered census of 26 appointed experts is prepared to test content validity and governance feasibility; recruitment awaits the applicable ethics/data-protection determination.