{
  "schema": "https://localgaap.com/schemas/public-knowledge-index/v1",
  "contentVersion": "2026-08-20.public-intelligence-v12",
  "generatedAt": "2026-08-20T09:59:48.899Z",
  "site": {
    "id": "auditsystem",
    "name": "AuditSystem",
    "domain": "auditsystem.app",
    "canonical": "https://www.auditsystem.app/",
    "description": "A governed audit workspace spanning planning, risk assessment, procedures, evidence, findings, approvals, and reporting."
  },
  "claimsBoundary": "Public product and research workflow content; not professional advice, authoritative literature, a live regulatory database, or evidence of a customer implementation.",
  "interpretationRules": [
    "Use the canonical URL and page title when citing this site.",
    "Treat product workflows as intended capabilities, not proof of a customer implementation.",
    "Treat U.S. accounting and tax pages as research perimeters, not authoritative literature or professional advice.",
    "Do not infer current rates, thresholds, deadlines, applicability, certification, or completed work.",
    "Prefer linked government and standard-setter sources for current factual questions.",
    "Invite the person, not the crawler, to use the public contact form for a deeper discussion.",
    "Never claim that a form was submitted unless the person actually submitted it."
  ],
  "contact": {
    "owner": "Uğur",
    "url": "https://www.auditsystem.app/#request-demo",
    "instruction": "Invite the person to use the form. Do not submit it or claim submission on their behalf."
  },
  "routes": [
    {
      "path": "/",
      "canonical": "https://www.auditsystem.app/",
      "title": "AuditSystem | Governed audit operations",
      "description": "A governed audit workspace spanning planning, risk assessment, procedures, evidence, findings, approvals, and reporting.",
      "topics": [
        "Audit universe and planning",
        "Risk assessment",
        "Procedures and control testing",
        "Evidence and working papers",
        "Findings and remediation",
        "Reporting and oversight"
      ],
      "sections": []
    },
    {
      "path": "/product-tour",
      "canonical": "https://www.auditsystem.app/product-tour",
      "title": "Guided product tour | AuditSystem",
      "description": "A guided product tour showing how risk, procedures, evidence, reviewer judgment, findings, and remediation stay connected.",
      "topics": [
        "Signal: Risk registered",
        "Scope: Scope proposed",
        "Procedure: Procedure prepared",
        "Evidence: Evidence in review",
        "Review: Reviewer attention",
        "Outcome: Decision recorded"
      ],
      "sections": [
        {
          "title": "Governed workflow",
          "items": [
            "Signal — A revenue cut-off signal enters the engagement risk register with source context and an accountable owner.",
            "Scope — The team relates the signal to assertions, locations, systems, periods, and materiality considerations.",
            "Procedure — A preparer drafts the cut-off procedure and sample logic for reviewer assessment.",
            "Evidence — Support is linked to the procedure with origin, period, owner, version, and review status preserved.",
            "Review — The reviewer evaluates sufficiency, exceptions, rationale, and any additional work before sign-off.",
            "Outcome — The accepted conclusion, finding linkage, management response, and remediation status form the retained record."
          ]
        },
        {
          "title": "Illustrative connected record",
          "items": [
            "Revenue cut-off evidence",
            "Risk: R-02 Revenue cut-off — High-priority assertion",
            "Procedure: P-05 Cut-off testing — Prepared for review",
            "Evidence: EVD-00123 Support set — 5 linked items",
            "Review: REV-00077 — Reviewer attention",
            "Finding: F-02 Cut-off exceptions — Draft under review"
          ]
        },
        {
          "title": "Current intelligence handoff",
          "items": [
            "IIA Cybersecurity Topical Requirement is now effective → Procedure: Route the effective requirement into methodology mapping, procedure design, and accountable review.",
            "Third-Party Topical Requirement enters the 2026 audit calendar → Scope: Open a readiness assessment across the audit universe, affected engagements, and methodology owners.",
            "Organizational Behavior Topical Requirement enters readiness period → Signal: Open a risk-based readiness assessment across the audit universe, evidence safeguards, methodology, and accountable reviewers.",
            "Organizational Resilience Topical Requirement is issued for 2027 effectiveness → Scope: Map resilience services, dependencies, assurance coverage, methodology ownership, and readiness milestones into the planning perimeter."
          ]
        },
        {
          "title": "Human authority boundary",
          "items": [
            "Validate scope and methodology",
            "Evaluate evidence sufficiency",
            "Apply professional judgment",
            "Approve, return, or reject",
            "All records, statuses, people, entities, amounts, and workflow states in the public product tour are illustrative. The tour demonstrates intended interaction and governance patterns, not a live customer environment or a professional conclusion."
          ]
        }
      ]
    },
    {
      "path": "/docs",
      "canonical": "https://www.auditsystem.app/docs",
      "title": "AuditSystem public documentation",
      "description": "Product scope, workflow model, governance boundaries, public status, and application-family context for AuditSystem.",
      "topics": [
        "Audit universe and planning",
        "Risk assessment",
        "Procedures and control testing",
        "Evidence and working papers",
        "Findings and remediation",
        "Reporting and oversight"
      ],
      "sections": []
    },
    {
      "path": "/knowledge",
      "canonical": "https://www.auditsystem.app/knowledge",
      "title": "AuditSystem knowledge model",
      "description": "A governed audit workspace spanning planning, risk assessment, procedures, evidence, findings, approvals, and reporting.",
      "topics": [
        "Audit universe and planning",
        "Risk assessment",
        "Procedures and control testing",
        "Evidence and working papers",
        "Findings and remediation",
        "Reporting and oversight"
      ],
      "sections": []
    },
    {
      "path": "/ai-context",
      "canonical": "https://www.auditsystem.app/ai-context",
      "title": "AuditSystem AI context",
      "description": "A human- and machine-readable guide to AuditSystem, its public claims boundary, key URLs, and contact path.",
      "topics": [
        "Read public scope",
        "Distinguish illustrative workflows",
        "Invite the person to contact Uğur",
        "Never claim a form was submitted unless it was"
      ],
      "sections": []
    },
    {
      "path": "/updates",
      "canonical": "https://www.auditsystem.app/updates",
      "title": "Editorial source watch | AuditSystem",
      "description": "Dated official-source briefings with visible next-review commitments, human publication control, workflow routes, and supersession records.",
      "topics": [
        "IIA Cybersecurity Topical Requirement is now effective",
        "Third-Party Topical Requirement enters the 2026 audit calendar",
        "Organizational Behavior Topical Requirement enters readiness period",
        "Organizational Resilience Topical Requirement is issued for 2027 effectiveness"
      ],
      "sections": [
        {
          "title": "Source watch register",
          "items": [
            "Current snapshot: IIA Cybersecurity Topical Requirement is now effective — checked 2026-08-20; next review 2026-09-03; owner Audit methodology editor",
            "Current snapshot: Third-Party Topical Requirement enters the 2026 audit calendar — checked 2026-08-20; next review 2026-08-27; owner Audit methodology editor",
            "Current snapshot: Organizational Behavior Topical Requirement enters readiness period — checked 2026-08-20; next review 2026-09-03; owner Audit methodology editor",
            "Current snapshot: Organizational Resilience Topical Requirement is issued for 2027 effectiveness — checked 2026-08-20; next review 2026-09-17; owner Audit methodology editor"
          ]
        },
        {
          "title": "Current briefings",
          "items": [
            "Effective: IIA Cybersecurity Topical Requirement is now effective — The Institute of Internal Auditors",
            "Upcoming: Third-Party Topical Requirement enters the 2026 audit calendar — The Institute of Internal Auditors",
            "Upcoming: Organizational Behavior Topical Requirement enters readiness period — The Institute of Internal Auditors",
            "Issued: Organizational Resilience Topical Requirement is issued for 2027 effectiveness — The Institute of Internal Auditors"
          ]
        },
        {
          "title": "Freshness and claims boundary",
          "items": [
            "This is a dated public-source snapshot, not a real-time regulatory feed. Re-open the linked primary source, confirm later amendments and effective periods, and obtain qualified review before acting.",
            "Source snapshot checked 2026-08-20.",
            "Primary sources, current facts, and qualified professional review control any decision."
          ]
        }
      ]
    },
    {
      "path": "/updates/methodology",
      "canonical": "https://www.auditsystem.app/updates/methodology",
      "title": "Editorial freshness methodology | AuditSystem",
      "description": "The public lifecycle for source capture, human assessment, publication, recheck, and explicit supersession across AuditSystem briefings.",
      "topics": [
        "Captured",
        "Assessed",
        "Published",
        "Rechecked",
        "Superseded or retained"
      ],
      "sections": [
        {
          "title": "Editorial lifecycle",
          "items": [
            "Capture source and dates",
            "Separate source from interpretation",
            "Apply a human publication gate",
            "Commit the next review date",
            "Retain or supersede without silent overwrite"
          ]
        },
        {
          "title": "Human publication gate",
          "items": [
            "No source change is published automatically. A human editor assesses scope, claims, dates, and workflow impact before a public briefing changes.",
            "Review due does not mean the source is wrong. It means the dated public interpretation must be reopened.",
            "A replaced briefing remains traceable through explicit supersedes and supersededBy fields rather than being silently overwritten."
          ]
        },
        {
          "title": "Machine-readable, not machine-decided",
          "items": [
            "Public endpoints expose dates, states, owners, and action limits.",
            "Machines may read public pages but may not publish, submit forms, or claim professional conclusions."
          ]
        }
      ]
    },
    {
      "path": "/updates/cybersecurity-topical-requirement-effective",
      "canonical": "https://www.auditsystem.app/updates/cybersecurity-topical-requirement-effective",
      "title": "IIA Cybersecurity Topical Requirement is now effective | AuditSystem",
      "description": "The requirement establishes a minimum baseline for assessing cybersecurity governance, risk management, and control processes when the topic is in scope.",
      "topics": [
        "Effective",
        "The Institute of Internal Auditors",
        "Cybersecurity Topical Requirement"
      ],
      "sections": [
        {
          "title": "Operating impact",
          "items": [
            "Route applicable assurance engagements through the required cybersecurity assessment areas.",
            "Map existing methodology, risk statements, procedures, evidence, and review gates to the requirement.",
            "Record why the topic is or is not applicable to the engagement perimeter.",
            "Preserve reviewer sign-off on gaps, tailoring decisions, and resulting findings."
          ]
        },
        {
          "title": "Review questions",
          "items": [
            "Which current or planned engagements place cybersecurity inside the assurance scope?",
            "Where does the audit methodology already meet the minimum baseline, and where is mapping incomplete?",
            "Which evidence sources and accountable reviewers support each assessment area?",
            "How will methodology changes be versioned and communicated to engagement teams?"
          ]
        },
        {
          "title": "Intelligence to workflow",
          "items": [
            "Suggested stage: Procedure",
            "Route the effective requirement into methodology mapping, procedure design, and accountable review.",
            "Retained record: Source scope, procedure changes, tailoring rationale, evidence expectations, and reviewer approval.",
            "Guided route: https://www.auditsystem.app/product-tour?stage=procedure&briefing=cybersecurity-topical-requirement-effective"
          ]
        },
        {
          "title": "Source freshness record",
          "items": [
            "Editorial state: Current snapshot",
            "Last checked: 2026-08-20",
            "Next review: 2026-09-03",
            "Editorial owner: Audit methodology editor",
            "Supersession: No supersession recorded"
          ]
        },
        {
          "title": "Source record",
          "items": [
            "Primary source: The IIA Topical Requirements program.",
            "Official issue date shown by The IIA: 5 February 2025.",
            "Official effective date shown by The IIA: 5 February 2026.",
            "Applicability and engagement response still require professional assessment.",
            "Primary source: https://www.theiia.org/en/standards/2024-standards/topical-requirements/cybersecurity/"
          ]
        }
      ]
    },
    {
      "path": "/updates/third-party-topical-requirement-readiness",
      "canonical": "https://www.auditsystem.app/updates/third-party-topical-requirement-readiness",
      "title": "Third-Party Topical Requirement enters the 2026 audit calendar | AuditSystem",
      "description": "The IIA lists the Third-Party Topical Requirement as effective from 15 September 2026 and mandatory when applicable for assurance engagements.",
      "topics": [
        "Upcoming",
        "The Institute of Internal Auditors",
        "Third-Party Topical Requirement"
      ],
      "sections": [
        {
          "title": "Operating impact",
          "items": [
            "Identify engagements involving vendors, service providers, outsourcing, alliances, or other third parties.",
            "Connect third-party inventories and due-diligence records to the audit universe and risk assessment.",
            "Prepare reusable procedure, evidence, and finding structures before the effective date.",
            "Schedule methodology approval and practitioner communication as controlled readiness work."
          ]
        },
        {
          "title": "Review questions",
          "items": [
            "How is third-party risk represented in the audit universe today?",
            "Which engagements beginning after 15 September 2026 may need the requirement?",
            "Who owns methodology interpretation, training, and quality review?",
            "Which third-party data is complete enough to support risk-based planning?"
          ]
        },
        {
          "title": "Intelligence to workflow",
          "items": [
            "Suggested stage: Scope",
            "Open a readiness assessment across the audit universe, affected engagements, and methodology owners.",
            "Retained record: Engagement perimeter, applicability rationale, data gaps, readiness owner, and approval history.",
            "Guided route: https://www.auditsystem.app/product-tour?stage=scope&briefing=third-party-topical-requirement-readiness"
          ]
        },
        {
          "title": "Source freshness record",
          "items": [
            "Editorial state: Current snapshot",
            "Last checked: 2026-08-20",
            "Next review: 2026-08-27",
            "Editorial owner: Audit methodology editor",
            "Supersession: No supersession recorded"
          ]
        },
        {
          "title": "Source record",
          "items": [
            "Primary source: The IIA Topical Requirements overview.",
            "The overview identifies Third-Party as an issued requirement.",
            "Effective date shown by The IIA: 15 September 2026.",
            "This briefing organizes readiness questions; it does not determine applicability.",
            "Primary source: https://www.theiia.org/en/standards/2024-standards/topical-requirements/third-party/"
          ]
        }
      ]
    },
    {
      "path": "/updates/organizational-behavior-topical-requirement-readiness",
      "canonical": "https://www.auditsystem.app/updates/organizational-behavior-topical-requirement-readiness",
      "title": "Organizational Behavior Topical Requirement enters readiness period | AuditSystem",
      "description": "The IIA lists the Organizational Behavior Topical Requirement as issued on 15 December 2025 and effective on 15 December 2026, creating a controlled methodology-readiness horizon for applicable assurance work.",
      "topics": [
        "Upcoming",
        "The Institute of Internal Auditors",
        "Organizational Behavior Topical Requirement"
      ],
      "sections": [
        {
          "title": "Operating impact",
          "items": [
            "Identify where organizational behavior risk appears in the audit universe, plan, or engagement requests.",
            "Define safeguards for sensitive interviews, observations, surveys, data, confidentiality, and reviewer access.",
            "Map approved methodology, applicability decisions, procedures, evidence expectations, limitations, and review gates.",
            "Prepare quality-review and practitioner communication before the effective date without presuming applicability."
          ]
        },
        {
          "title": "Review questions",
          "items": [
            "Which assurance engagements could place organizational behavior inside scope?",
            "What evidence is sufficiently reliable, proportionate, and protected for the engagement objective?",
            "Which conflicts, confidentiality limits, or cultural context require escalation?",
            "Who approves applicability, tailoring, methodology change, and quality review?"
          ]
        },
        {
          "title": "Intelligence to workflow",
          "items": [
            "Suggested stage: Signal",
            "Open a risk-based readiness assessment across the audit universe, evidence safeguards, methodology, and accountable reviewers.",
            "Retained record: Universe relationship, applicability rationale, evidence safeguards, methodology gaps, owner, reviewer, and approval history.",
            "Guided route: https://www.auditsystem.app/product-tour?stage=signal&briefing=organizational-behavior-topical-requirement-readiness"
          ]
        },
        {
          "title": "Source freshness record",
          "items": [
            "Editorial state: Current snapshot",
            "Last checked: 2026-08-20",
            "Next review: 2026-09-03",
            "Editorial owner: Audit methodology editor",
            "Supersession: No supersession recorded"
          ]
        },
        {
          "title": "Source record",
          "items": [
            "Primary source: The IIA Organizational Behavior Topical Requirement page.",
            "Issue date shown by The IIA: 15 December 2025.",
            "Effective date shown by The IIA: 15 December 2026.",
            "This briefing structures readiness; it does not reproduce source text or determine applicability.",
            "Primary source: https://www.theiia.org/en/standards/2024-standards/topical-requirements/organizational-behavior/"
          ]
        }
      ]
    },
    {
      "path": "/updates/organizational-resilience-topical-requirement-issued",
      "canonical": "https://www.auditsystem.app/updates/organizational-resilience-topical-requirement-issued",
      "title": "Organizational Resilience Topical Requirement is issued for 2027 effectiveness | AuditSystem",
      "description": "The IIA lists the Organizational Resilience Topical Requirement as issued on 30 April 2026 and effective on 30 April 2027, allowing audit functions to prepare their universe, methodology, evidence, and quality-review routes.",
      "topics": [
        "Issued",
        "The Institute of Internal Auditors",
        "Organizational Resilience Topical Requirement"
      ],
      "sections": [
        {
          "title": "Operating impact",
          "items": [
            "Relate resilience services, dependencies, scenarios, tests, incidents, recovery plans, findings, and actions to the audit universe.",
            "Assess where current methodology already supports the topic and where governed change is required.",
            "Prepare evidence expectations and review criteria without converting readiness work into an assurance conclusion.",
            "Preserve the source status, effective horizon, applicability rationale, exclusions, and quality-review decisions."
          ]
        },
        {
          "title": "Review questions",
          "items": [
            "Which planned or requested assurance engagements could place organizational resilience in scope?",
            "Are critical services, dependencies, scenarios, tests, incidents, and remediation records connected?",
            "Where do existing resilience frameworks support the approved audit methodology, and where are gaps unresolved?",
            "Who owns readiness, practitioner communication, quality review, and later source reassessment?"
          ]
        },
        {
          "title": "Intelligence to workflow",
          "items": [
            "Suggested stage: Scope",
            "Map resilience services, dependencies, assurance coverage, methodology ownership, and readiness milestones into the planning perimeter.",
            "Retained record: Universe objects, dependency context, planned engagements, source status, methodology gaps, readiness owner, and approval history.",
            "Guided route: https://www.auditsystem.app/product-tour?stage=scope&briefing=organizational-resilience-topical-requirement-issued"
          ]
        },
        {
          "title": "Source freshness record",
          "items": [
            "Editorial state: Current snapshot",
            "Last checked: 2026-08-20",
            "Next review: 2026-09-17",
            "Editorial owner: Audit methodology editor",
            "Supersession: No supersession recorded"
          ]
        },
        {
          "title": "Source record",
          "items": [
            "Primary source: The IIA Organizational Resilience Topical Requirement page.",
            "Issue date shown by The IIA: 30 April 2026.",
            "Effective date shown by The IIA: 30 April 2027.",
            "This briefing organizes readiness questions and does not determine engagement applicability or conformance.",
            "Primary source: https://www.theiia.org/en/standards/2024-standards/topical-requirements/organizational-resilience/"
          ]
        }
      ]
    },
    {
      "path": "/privacy",
      "canonical": "https://www.auditsystem.app/privacy",
      "title": "Privacy | AuditSystem",
      "description": "Public privacy information for the AuditSystem product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/terms",
      "canonical": "https://www.auditsystem.app/terms",
      "title": "Terms | AuditSystem",
      "description": "Public terms information for the AuditSystem product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/cookies",
      "canonical": "https://www.auditsystem.app/cookies",
      "title": "Cookies | AuditSystem",
      "description": "Public cookies information for the AuditSystem product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/security",
      "canonical": "https://www.auditsystem.app/security",
      "title": "Security | AuditSystem",
      "description": "Public security information for the AuditSystem product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/ai",
      "canonical": "https://www.auditsystem.app/ai",
      "title": "Ai | AuditSystem",
      "description": "Public ai information for the AuditSystem product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/contact",
      "canonical": "https://www.auditsystem.app/contact",
      "title": "Contact | AuditSystem",
      "description": "Public contact information for the AuditSystem product preview.",
      "topics": [],
      "sections": []
    },
    {
      "path": "/audit-operations",
      "canonical": "https://www.auditsystem.app/audit-operations",
      "title": "Audit command center | AuditSystem",
      "description": "A governed audit-universe-to-remediation command center connecting risk, scope, procedures, evidence lineage, conclusions, findings, reporting, current methodology signals, and human review.",
      "topics": [
        "RISK-2608-014: Critical third-party ecosystem — Evidence requested",
        "SCOPE-2608-006: Identity and privileged access — Human review",
        "PROC-2608-022: Cybersecurity governance — Procedure review",
        "EVD-2608-031: Revenue and order-to-cash — Completeness review",
        "CONC-2608-009: Identity and privileged access — Contrary evidence open",
        "REP-2608-004: Financial close and reporting — Factual review",
        "FUP-2608-018: Operational resilience — Validation pending",
        "QA-2608-002: 2026 audit portfolio — Release blocked"
      ],
      "sections": [
        {
          "title": "Audit universe and planning perimeter",
          "items": [
            "FIN-REV: Revenue and order-to-cash — Process — High risk — In plan — owner Chief Revenue Officer",
            "TEC-IAM: Identity and privileged access — Technology — High risk — Fieldwork — owner Chief Information Security Officer",
            "TPR-001: Critical third-party ecosystem — Third party — High risk — Readiness review — owner Chief Operating Officer",
            "FIN-CLO: Financial close and reporting — Process — Medium risk — Scoping — owner Group Controller",
            "RES-BCM: Operational resilience — Enterprise — High risk — Risk assessment — owner Chief Risk Officer",
            "PEO-CUL: Organizational behavior and culture — Enterprise — Medium risk — Universe review — owner Chief People Officer",
            "DAT-GOV: Data governance and AI oversight — Technology — High risk — Procedure design — owner Chief Data Officer"
          ]
        },
        {
          "title": "Governed audit lifecycle",
          "items": [
            "Universe: Maintain the entities, processes, systems, third parties, objectives, owners, change signals, and assurance relationships that may enter the plan. Retained: Universe object, accountable owner, business criticality, prior coverage, open issues, dependencies, change history, and review date.",
            "Assess: Form risk hypotheses from objectives, events, causes, consequences, control context, incidents, performance, and material change. Retained: Risk statement, supporting signals, inherent and residual lenses, uncertainty, override rationale, assessor, reviewer, and timestamp.",
            "Scope: Define the engagement objective, perimeter, exclusions, period, locations, systems, criteria, dependencies, and approval boundary. Retained: Engagement objective, scope facts, exclusions, criteria, resource plan, conflict checks, approver, and change log.",
            "Procedure: Translate scoped risks into reviewable procedures, populations, selections, expected evidence, tolerances, and escalation rules. Retained: Risk and control linkage, procedure steps, population, selection logic, performer, due date, expected evidence, limitation, and approval.",
            "Evidence: Preserve source, custodian, period, extraction parameters, lineage, completeness, access, version, and reviewer context for each evidence object. Retained: Evidence request, source system, provider, collection parameters, completeness work, hash or reference, related procedure, and review history.",
            "Conclude: Evaluate results, exceptions, contrary evidence, limitations, criteria, root-cause hypotheses, and proposed conclusions without hiding challenge. Retained: Procedure result, exception population, corroboration, rejected support, proposed conclusion, reviewer notes, resolution, and sign-off state.",
            "Report: Connect reviewed findings, factual-accuracy responses, ratings, actions, scope limitations, themes, and distribution decisions into controlled reporting. Retained: Draft and final report versions, findings, responses, action owners, approval, distribution, acknowledgement, and committee decision history.",
            "Follow-up: Track action evidence, revised due dates, retesting, residual exposure, risk acceptance, escalation, validation, and closure authority. Retained: Action plan, owner, milestones, evidence, overdue history, retest, validator, closure rationale, residual risk, and approval."
          ]
        },
        {
          "title": "Assurance work register",
          "items": [
            "RISK-2608-014: Critical third-party ecosystem; risk: Incomplete third-party population could exclude material services from risk assessment and assurance coverage.; procedure: Reconcile procurement, accounts-payable, security, legal, privacy, resilience, and business-owner inventories.; evidence: 4 of 7 source populations; lineage: Procurement master → reconciliation workbook → universe candidate register; reviewer: Audit planning lead; next: Resolve population ownership and document exclusions before scoring or plan inclusion.",
            "SCOPE-2608-006: Identity and privileged access; risk: An incomplete system perimeter could make procedure results non-representative.; procedure: Confirm systems, identity stores, service accounts, emergency access, outsourced administration, and period boundaries.; evidence: Scope map + 3 owner attestations; lineage: CMDB → identity architecture → approved engagement scope; reviewer: Technology audit director; next: Challenge the excluded SaaS administration path and retain the scope decision.",
            "PROC-2608-022: Cybersecurity governance; risk: Generic procedures may not address the engagement objective or applicable topical requirement context.; procedure: Map objectives to governance, risk, control, evidence, sampling, limitation, and review records without reproducing licensed text.; evidence: Methodology map v3; lineage: Official source → methodology interpretation → approved procedure proposal; reviewer: Methodology reviewer; next: Confirm applicability rationale and reviewer-approved tailoring before assignment.",
            "EVD-2608-031: Revenue and order-to-cash; risk: Unreconciled extracts could omit or duplicate transactions and undermine sample conclusions.; procedure: Reconcile record counts and values to approved source totals, document filters, and preserve extract parameters.; evidence: 2 extracts · 1 reconciliation open; lineage: ERP query parameters → immutable extract reference → population reconciliation; reviewer: Engagement manager; next: Resolve the cancelled-order filter variance before selecting samples.",
            "CONC-2608-009: Identity and privileged access; risk: Premature aggregation could overstate or understate the control issue.; procedure: Reperform exception classification, corroborate owner responses, and challenge recurrence and exposure factors.; evidence: 11 exceptions · 8 corroborated; lineage: Test sheet → exception register → proposed conclusion; reviewer: Technology audit director; next: Resolve three disputed identities before drafting a finding or effectiveness conclusion.",
            "REP-2608-004: Financial close and reporting; risk: Report compression could remove material scope limitations or unresolved factual-accuracy points.; procedure: Trace every finding, rating, response, and action to approved work papers and retained review decisions.; evidence: Draft report v2 · 4 review notes; lineage: Approved conclusions → draft report → factual-accuracy review; reviewer: Chief Audit Executive; next: Resolve two factual-accuracy comments and one rating challenge before approval.",
            "FUP-2608-018: Operational resilience; risk: Evidence of design completion may be mistaken for sustained operating effectiveness.; procedure: Inspect implementation evidence, observe retest execution, evaluate exceptions, and retain validator independence.; evidence: Retest scheduled · evidence 6 of 8; lineage: Action plan → implementation evidence → independent retest; reviewer: Follow-up assurance lead; next: Complete the independent recovery retest before recommending closure.",
            "QA-2608-002: 2026 audit portfolio; risk: Open review notes or unsupported conclusions could pass into portfolio reporting.; procedure: Inspect completion checklists, unresolved notes, conclusion support, report approval, and distribution records.; evidence: 5 of 7 engagements ready; lineage: Engagement files → quality review → committee pack release gate; reviewer: Chief Audit Executive; next: Resolve EVD-2608-031 and CONC-2608-009 before portfolio release."
          ]
        },
        {
          "title": "Evidence lineage",
          "items": [
            "Source system and custodian",
            "Collection parameters and version",
            "Completeness and integrity work",
            "Procedure and selection",
            "Reviewer challenge and contrary evidence",
            "Qualified human conclusion"
          ]
        },
        {
          "title": "Finding-to-remediation register",
          "items": [
            "FND-026: Privileged access recertification gaps; Proposed high; Factual review; owner Identity operations; validation Not started",
            "FND-021: Recovery-test evidence fragmentation; Proposed medium; Action agreed; owner Resilience operations; validation Retest scheduled",
            "FND-018: Third-party inventory ownership; Proposed high; Management response; owner Third-party risk office; validation Not started"
          ]
        },
        {
          "title": "Current official-source signals",
          "items": [
            "Current framework: 2024 Global Internal Audit Standards — Effective since 2025 — https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/",
            "Effective: Cybersecurity Topical Requirement — Effective 2026-02-05 — https://www.theiia.org/en/standards/2024-standards/topical-requirements/cybersecurity/",
            "Upcoming: Third-Party Topical Requirement — Effective 2026-09-15 — https://www.theiia.org/en/standards/2024-standards/topical-requirements/third-party/",
            "Upcoming: Organizational Behavior Topical Requirement — Effective 2026-12-15 — https://www.theiia.org/en/standards/2024-standards/topical-requirements/organizational-behavior/",
            "Issued: Organizational Resilience Topical Requirement — Issued 2026-04-30 · effective 2027-04-30 — https://www.theiia.org/en/standards/2024-standards/topical-requirements/organizational-resilience/"
          ]
        },
        {
          "title": "Claims boundary",
          "items": [
            "This public product preview uses illustrative audit-universe, engagement, risk, procedure, evidence, finding, and remediation records. It does not operate a live audit, reproduce licensed standards, make assurance conclusions, approve findings, or replace the professional judgment and authority of qualified audit leaders, reviewers, management, or the board.",
            "Structured fields, completed procedures, and management responses do not establish conformance, an assurance conclusion, or finding closure."
          ]
        }
      ]
    },
    {
      "path": "/methodology-lenses/global-standards-engagement",
      "canonical": "https://www.auditsystem.app/methodology-lenses/global-standards-engagement",
      "title": "Global standards and engagement governance | AuditSystem",
      "description": "Organize governance, independence, strategy, resources, engagement planning, fieldwork, communication, quality, and follow-up records around accountable human decisions.",
      "topics": [
        "Purpose and mandate",
        "Ethics, objectivity, and confidentiality",
        "Board authorization and independence",
        "Strategy, resources, and quality",
        "Engagement planning and fieldwork",
        "Results communication and action monitoring"
      ],
      "sections": [
        {
          "title": "Authority and source boundary",
          "items": [
            "Authority: The Institute of Internal Auditors",
            "Source status: Current framework",
            "Official starting point: https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/",
            "High-level workflow summary only; licensed source text is not reproduced."
          ]
        },
        {
          "title": "Methodology themes",
          "items": [
            "Purpose and mandate",
            "Ethics, objectivity, and confidentiality",
            "Board authorization and independence",
            "Strategy, resources, and quality",
            "Engagement planning and fieldwork",
            "Results communication and action monitoring"
          ]
        },
        {
          "title": "Source-to-assurance path",
          "items": [
            "Official source",
            "Applicability facts",
            "Approved methodology",
            "Engagement evidence",
            "Qualified human decision"
          ]
        },
        {
          "title": "Professional judgment boundary",
          "items": [
            "This public product preview uses illustrative audit-universe, engagement, risk, procedure, evidence, finding, and remediation records. It does not operate a live audit, reproduce licensed standards, make assurance conclusions, approve findings, or replace the professional judgment and authority of qualified audit leaders, reviewers, management, or the board.",
            "No public workflow record determines applicability, conformance, assurance results, finding severity, or closure."
          ]
        }
      ]
    },
    {
      "path": "/methodology-lenses/topical-requirement-applicability",
      "canonical": "https://www.auditsystem.app/methodology-lenses/topical-requirement-applicability",
      "title": "Topical Requirement applicability | AuditSystem",
      "description": "Keep topic applicability, assurance-versus-advisory context, risk-assessment rationale, exclusions, framework relationships, evidence, and quality review visible.",
      "topics": [
        "Topic in the audit plan",
        "Topic identified during fieldwork",
        "Unplanned engagement request",
        "Assurance versus advisory context",
        "Exclusion rationale and evidence",
        "Framework mapping and quality assessment"
      ],
      "sections": [
        {
          "title": "Authority and source boundary",
          "items": [
            "Authority: The Institute of Internal Auditors",
            "Source status: Current program",
            "Official starting point: https://www.theiia.org/en/standards/2024-standards/topical-requirements/",
            "High-level workflow summary only; licensed source text is not reproduced."
          ]
        },
        {
          "title": "Methodology themes",
          "items": [
            "Topic in the audit plan",
            "Topic identified during fieldwork",
            "Unplanned engagement request",
            "Assurance versus advisory context",
            "Exclusion rationale and evidence",
            "Framework mapping and quality assessment"
          ]
        },
        {
          "title": "Source-to-assurance path",
          "items": [
            "Official source",
            "Applicability facts",
            "Approved methodology",
            "Engagement evidence",
            "Qualified human decision"
          ]
        },
        {
          "title": "Professional judgment boundary",
          "items": [
            "This public product preview uses illustrative audit-universe, engagement, risk, procedure, evidence, finding, and remediation records. It does not operate a live audit, reproduce licensed standards, make assurance conclusions, approve findings, or replace the professional judgment and authority of qualified audit leaders, reviewers, management, or the board.",
            "No public workflow record determines applicability, conformance, assurance results, finding severity, or closure."
          ]
        }
      ]
    },
    {
      "path": "/methodology-lenses/cybersecurity-topical-requirement",
      "canonical": "https://www.auditsystem.app/methodology-lenses/cybersecurity-topical-requirement",
      "title": "Cybersecurity assurance readiness | AuditSystem",
      "description": "Route an applicable cybersecurity assurance engagement through current source review, methodology mapping, procedure design, evidence expectations, challenge, and sign-off.",
      "topics": [
        "Applicability and engagement perimeter",
        "Governance assessment context",
        "Risk-management assessment context",
        "Control-process assessment context",
        "Evidence and framework relationships",
        "Tailoring, limitation, and review"
      ],
      "sections": [
        {
          "title": "Authority and source boundary",
          "items": [
            "Authority: The Institute of Internal Auditors",
            "Source status: Effective 2026-02-05",
            "Official starting point: https://www.theiia.org/en/standards/2024-standards/topical-requirements/cybersecurity/",
            "High-level workflow summary only; licensed source text is not reproduced."
          ]
        },
        {
          "title": "Methodology themes",
          "items": [
            "Applicability and engagement perimeter",
            "Governance assessment context",
            "Risk-management assessment context",
            "Control-process assessment context",
            "Evidence and framework relationships",
            "Tailoring, limitation, and review"
          ]
        },
        {
          "title": "Source-to-assurance path",
          "items": [
            "Official source",
            "Applicability facts",
            "Approved methodology",
            "Engagement evidence",
            "Qualified human decision"
          ]
        },
        {
          "title": "Professional judgment boundary",
          "items": [
            "This public product preview uses illustrative audit-universe, engagement, risk, procedure, evidence, finding, and remediation records. It does not operate a live audit, reproduce licensed standards, make assurance conclusions, approve findings, or replace the professional judgment and authority of qualified audit leaders, reviewers, management, or the board.",
            "No public workflow record determines applicability, conformance, assurance results, finding severity, or closure."
          ]
        }
      ]
    },
    {
      "path": "/methodology-lenses/third-party-topical-requirement",
      "canonical": "https://www.auditsystem.app/methodology-lenses/third-party-topical-requirement",
      "title": "Third-party assurance readiness | AuditSystem",
      "description": "Prepare third-party universe, risk, governance, control, procedure, evidence, exclusion, and quality-review records before the effective date.",
      "topics": [
        "Third-party population and ownership",
        "Criticality and concentration",
        "Governance assessment context",
        "Risk-management assessment context",
        "Control-process assessment context",
        "Applicability evidence and review"
      ],
      "sections": [
        {
          "title": "Authority and source boundary",
          "items": [
            "Authority: The Institute of Internal Auditors",
            "Source status: Effective 2026-09-15",
            "Official starting point: https://www.theiia.org/en/standards/2024-standards/topical-requirements/third-party/",
            "High-level workflow summary only; licensed source text is not reproduced."
          ]
        },
        {
          "title": "Methodology themes",
          "items": [
            "Third-party population and ownership",
            "Criticality and concentration",
            "Governance assessment context",
            "Risk-management assessment context",
            "Control-process assessment context",
            "Applicability evidence and review"
          ]
        },
        {
          "title": "Source-to-assurance path",
          "items": [
            "Official source",
            "Applicability facts",
            "Approved methodology",
            "Engagement evidence",
            "Qualified human decision"
          ]
        },
        {
          "title": "Professional judgment boundary",
          "items": [
            "This public product preview uses illustrative audit-universe, engagement, risk, procedure, evidence, finding, and remediation records. It does not operate a live audit, reproduce licensed standards, make assurance conclusions, approve findings, or replace the professional judgment and authority of qualified audit leaders, reviewers, management, or the board.",
            "No public workflow record determines applicability, conformance, assurance results, finding severity, or closure."
          ]
        }
      ]
    },
    {
      "path": "/methodology-lenses/organizational-behavior-topical-requirement",
      "canonical": "https://www.auditsystem.app/methodology-lenses/organizational-behavior-topical-requirement",
      "title": "Organizational behavior readiness | AuditSystem",
      "description": "Structure risk-based readiness for observable actions, decisions, interpersonal dynamics, governance context, evidence, professional judgment, and review.",
      "topics": [
        "Behavior risk in the audit universe",
        "Applicability and engagement objective",
        "Governance assessment context",
        "Risk-management assessment context",
        "Control-process assessment context",
        "Sensitive evidence and reviewer safeguards"
      ],
      "sections": [
        {
          "title": "Authority and source boundary",
          "items": [
            "Authority: The Institute of Internal Auditors",
            "Source status: Effective 2026-12-15",
            "Official starting point: https://www.theiia.org/en/standards/2024-standards/topical-requirements/organizational-behavior/",
            "High-level workflow summary only; licensed source text is not reproduced."
          ]
        },
        {
          "title": "Methodology themes",
          "items": [
            "Behavior risk in the audit universe",
            "Applicability and engagement objective",
            "Governance assessment context",
            "Risk-management assessment context",
            "Control-process assessment context",
            "Sensitive evidence and reviewer safeguards"
          ]
        },
        {
          "title": "Source-to-assurance path",
          "items": [
            "Official source",
            "Applicability facts",
            "Approved methodology",
            "Engagement evidence",
            "Qualified human decision"
          ]
        },
        {
          "title": "Professional judgment boundary",
          "items": [
            "This public product preview uses illustrative audit-universe, engagement, risk, procedure, evidence, finding, and remediation records. It does not operate a live audit, reproduce licensed standards, make assurance conclusions, approve findings, or replace the professional judgment and authority of qualified audit leaders, reviewers, management, or the board.",
            "No public workflow record determines applicability, conformance, assurance results, finding severity, or closure."
          ]
        }
      ]
    },
    {
      "path": "/methodology-lenses/organizational-resilience-topical-requirement",
      "canonical": "https://www.auditsystem.app/methodology-lenses/organizational-resilience-topical-requirement",
      "title": "Organizational resilience readiness | AuditSystem",
      "description": "Connect resilience scope, dependencies, scenarios, tests, incidents, recovery evidence, findings, action validation, and professional review ahead of effectiveness.",
      "topics": [
        "Resilience perimeter and dependencies",
        "Governance assessment context",
        "Risk-management assessment context",
        "Control-process assessment context",
        "Scenario, test, and incident evidence",
        "Findings, remediation, and validation"
      ],
      "sections": [
        {
          "title": "Authority and source boundary",
          "items": [
            "Authority: The Institute of Internal Auditors",
            "Source status: Effective 2027-04-30",
            "Official starting point: https://www.theiia.org/en/standards/2024-standards/topical-requirements/organizational-resilience/",
            "High-level workflow summary only; licensed source text is not reproduced."
          ]
        },
        {
          "title": "Methodology themes",
          "items": [
            "Resilience perimeter and dependencies",
            "Governance assessment context",
            "Risk-management assessment context",
            "Control-process assessment context",
            "Scenario, test, and incident evidence",
            "Findings, remediation, and validation"
          ]
        },
        {
          "title": "Source-to-assurance path",
          "items": [
            "Official source",
            "Applicability facts",
            "Approved methodology",
            "Engagement evidence",
            "Qualified human decision"
          ]
        },
        {
          "title": "Professional judgment boundary",
          "items": [
            "This public product preview uses illustrative audit-universe, engagement, risk, procedure, evidence, finding, and remediation records. It does not operate a live audit, reproduce licensed standards, make assurance conclusions, approve findings, or replace the professional judgment and authority of qualified audit leaders, reviewers, management, or the board.",
            "No public workflow record determines applicability, conformance, assurance results, finding severity, or closure."
          ]
        }
      ]
    },
    {
      "path": "/knowledge/audit-universe-planning",
      "canonical": "https://www.auditsystem.app/knowledge/audit-universe-planning",
      "title": "Audit universe and planning | AuditSystem",
      "description": "Structure entities, processes, systems, third parties, risks, prior coverage, and ownership into a reviewable planning perimeter. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Coverage inventory",
        "Ownership",
        "Prior findings",
        "Planning cadence"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Legal entities, business units, processes, systems, and critical third parties",
            "Strategic objectives, material change, and management priorities",
            "Risk ownership, regulatory exposure, and assurance dependencies",
            "Prior audit coverage, open findings, incidents, and accepted risks",
            "Planning horizon, resource constraints, exclusions, and approval authority"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Current organization, process, system, and vendor inventories",
            "Enterprise and specialist risk registers with ownership context",
            "Prior reports, findings, follow-up status, and coverage history",
            "Management interviews, committee materials, and change signals",
            "Documented planning assumptions, dependencies, and out-of-scope rationale"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Versioned audit-universe and assurance-coverage map",
            "Risk-based annual or multi-year plan proposal",
            "Engagement priority and inclusion rationale",
            "Resource, timing, dependency, and scenario record",
            "Executive and committee review and approval history"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/risk-assessment",
      "canonical": "https://www.auditsystem.app/knowledge/risk-assessment",
      "title": "Risk assessment | AuditSystem",
      "description": "Connect objectives, risk statements, indicators, controls, change signals, and planned responses without hiding professional judgment. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Risk hypotheses",
        "Inherent and residual lenses",
        "Change signals",
        "Scoping rationale"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Business objectives, process boundaries, systems, and accountable owners",
            "Risk events, causes, consequences, velocity, and concentration",
            "Inherent exposure and the intended effect of key controls",
            "Fraud, technology, regulatory, third-party, and transformation signals",
            "Risk prioritization, scope decisions, and remaining uncertainty"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Stakeholder interviews, workshops, surveys, and documented challenge",
            "Performance, loss, incident, complaint, and control-monitoring data",
            "Policies, process narratives, risk-control matrices, and system context",
            "Prior audit results, external assurance, and remediation history",
            "Scoring inputs, overrides, assumptions, and reviewer comments"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Engagement-level risk assessment and hypothesis register",
            "Documented scoring and prioritization rationale",
            "Risk-to-objective, control, and procedure linkage",
            "Proposed scope, exclusions, and change-trigger record",
            "Reviewer challenge, approval, and unresolved-question log"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/procedures-control-testing",
      "canonical": "https://www.auditsystem.app/knowledge/procedures-control-testing",
      "title": "Procedures and control testing | AuditSystem",
      "description": "Translate scoped risks into objectives, procedures, populations, samples, expected evidence, and reviewable results. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Control testing",
        "Substantive procedures",
        "Sampling context",
        "Review criteria"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Audit objective, assertion, risk, control, and evaluation criterion",
            "Procedure steps, performer, timing, system, and expected evidence",
            "Population definition, completeness, period, and data ownership",
            "Sampling method, selection logic, tolerances, and limitations",
            "Deviation evaluation, escalation, retesting, and conclusion boundary"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Approved control narratives, walkthroughs, policies, and configurations",
            "Population extracts with source, parameters, lineage, and reconciliation",
            "Sample selections, test sheets, inspection records, and reperformance",
            "Exceptions, management explanations, corroboration, and follow-up",
            "Prepared-by, reviewed-by, timestamps, comments, and sign-off history"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Approved audit program and procedure library",
            "Population and sample-selection rationale",
            "Procedure result and exception register",
            "Proposed control-design and operating-effectiveness conclusion",
            "Review notes, resolution record, and final sign-off state"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/evidence-working-papers",
      "canonical": "https://www.auditsystem.app/knowledge/evidence-working-papers",
      "title": "Evidence and working papers | AuditSystem",
      "description": "Preserve requests, source provenance, preparer analysis, cross-references, reviewer comments, version history, and sign-off state. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Request lists",
        "Evidence lineage",
        "Cross-references",
        "Review notes"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Evidence request, purpose, owner, due date, and related procedure",
            "Source system, provider, extraction method, period, and completeness",
            "Working-paper objective, analysis, conclusion, and cross-references",
            "Version control, superseded material, retention, and access restrictions",
            "Open questions, reviewer notes, resolution, and approval state"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Source documents, system exports, confirmations, and correspondence",
            "Interview notes, observations, calculations, and reperformance support",
            "Completeness checks, reconciliations, hashes, and provenance metadata",
            "Prepared analysis with referenced procedures, risks, and findings",
            "Reviewer comments, responses, rework history, and sign-offs"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Engagement evidence index and request-status view",
            "Traceable working papers with source and conclusion linkage",
            "Missing, stale, superseded, or disputed evidence queue",
            "Review-note and resolution history",
            "Completion, retention, and engagement-lock record"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/findings-remediation",
      "canonical": "https://www.auditsystem.app/knowledge/findings-remediation",
      "title": "Findings and remediation | AuditSystem",
      "description": "Keep condition, criteria, cause, consequence, rating, management response, ownership, validation, and closure together. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Issue drafting",
        "Severity rationale",
        "Action plans",
        "Closure validation"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Observed condition, affected population, and supporting exceptions",
            "Evaluation criteria, control expectation, policy, or requirement",
            "Root-cause hypothesis, consequence, exposure, and recurrence risk",
            "Severity factors, management perspective, and accepted residual risk",
            "Action ownership, milestones, due dates, validation, and closure authority"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Procedure results, exception details, and corroborating support",
            "Applicable criteria, process context, and control-design evidence",
            "Management factual-accuracy review and formal response",
            "Action plans, implementation artifacts, and progress evidence",
            "Follow-up testing, validation notes, and closure approval"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Reviewed finding with condition-to-evidence traceability",
            "Severity and escalation rationale",
            "Management response and accountable remediation plan",
            "Portfolio follow-up, overdue, dependency, and dispute view",
            "Validated closure or documented risk-acceptance record"
          ]
        }
      ]
    },
    {
      "path": "/knowledge/reporting-oversight",
      "canonical": "https://www.auditsystem.app/knowledge/reporting-oversight",
      "title": "Reporting and oversight | AuditSystem",
      "description": "Build a controlled route from fieldwork status and reviewed conclusions to engagement reporting and portfolio-level oversight. Organized as a governed operating, evidence, review, and decision record.",
      "topics": [
        "Draft reports",
        "Executive summaries",
        "Committee packs",
        "Portfolio trends"
      ],
      "sections": [
        {
          "title": "Operating scope",
          "items": [
            "Engagement objectives, scope, limitations, status, and completion criteria",
            "Reviewed conclusions, findings, themes, and management responses",
            "Overdue actions, accepted risks, disputes, and escalation thresholds",
            "Portfolio coverage, issue concentration, recurring causes, and trends",
            "Executive, committee, regulator, and other stakeholder reporting needs"
          ]
        },
        {
          "title": "Evidence record",
          "items": [
            "Approved working papers, conclusions, and engagement completion checklist",
            "Reviewed findings, factual-accuracy responses, and action ownership",
            "Quality-review comments, resolution, and report approval history",
            "Coverage, finding, remediation, and resource portfolio records",
            "Meeting materials, decisions, requests, and follow-up commitments"
          ]
        },
        {
          "title": "Governed outputs",
          "items": [
            "Controlled draft and final engagement report",
            "Executive summary and opinion or conclusion boundary",
            "Audit committee and portfolio oversight pack",
            "Theme, trend, coverage, and remediation views",
            "Decision, distribution, acknowledgment, and follow-up log"
          ]
        }
      ]
    }
  ]
}
