You forget process, especially "safety case" process rules all.
Maintained Build Standard > valid Safety Case > valid Release To Service.
A simple chain, and break any link or fail to demonstrate each is intact, and the RTS cannot be issued. That is the systemic and organisational failure that led to the Nimrod Review and cancellation of MRA4.
In the case of Rivet Joint, the mandated regulations imposed on DEC and procurers would require them to confirm the robustness of this audit trail before even seeking approval to proceed. The scrutineers must verify it before granting approval. And, throughout the entire procurement and in-service phases, it must be the subject of continuous assessment.
What can go wrong if you follow the regs? We know what goes wrong if you don't. ZD576. XV230. XV179. ZG710. MoD/MAA are on record as agreeing with the instructions not to.