Your main gap — is not detection. It is evidence. You almost certainly have controls covering some of what's described here — what you don't have is a signed, timestamped claim that survives being asked about a year later.
What's happening now — you attest to a boundary drawn at the sandbox, while the data crosses one drawn at the device. Both statements are true, and only one is documented.
Why it matters — the gap is invisible until someone asks you to evidence it. Then it is the only thing anyone talks about.
Fix first — decide where a trust field would live on your existing record — first-class attribute or metadata. That single decision determines whether the audit story is native or bolted on, and it costs nothing to answer.
What can wait — enforcement. The first phase is read-only throughout. Nothing gates, nothing blocks, no user sees a change.
Likely benefit — an answer to the one question you can't answer today, in a form an auditor accepts and an engineer can verify without calling you.