EM-RSK-02 · Subject model · W2
Audit, review and finding
Review plan, criteria, sample, evidence, finding and corrective action. An audit opinion has a scope and limitations.
Queued for research
Claude: not-started; Grok: not-started.
Research note, in Russian: Entire research brief pending
Subject boundary and candidate types
- Audit
- AuditProcedure
- AuditFinding
- AssuranceOpinion
- CorrectiveAction
Deep research questions
- How to separate a finding from a risk and a task?
- What does a sample prove?
- How to close a finding after independent verification?
Verifiable invariants
- Criteria are pinned
- The conclusion is limited by the coverage
- Completing a task does not close a finding without verification
End-to-end acceptance scenario
An audit of two processes with an excluded site and a re-verification of a finding preserves the boundaries of the opinion.
Negative case
A review of one system proves compliance of the whole group.
Approaches to compare
- NIST CSF/AI RMF: governance and risk functions
- ODRL/PROV: authority, grounds and evidence
- GRC/IAM/BCM practice and NIST SP 800-34 for recovery
Candidates in the live catalogue
- WM-ACT-033 · Review / Inspection / Audit · 0.3.0-research.1 · installable
Semantic fit requires boundary research; a published model does not by itself complete this card. - WM-ECO-035 · Audit / Assurance Engagement · 0.3.0-research.1 · installable
Semantic fit requires boundary research; a published model does not by itself complete this card. - WM-KNW-014 · Issue / Problem · 0.3.0-research.1 · installable
Semantic fit requires boundary research; a published model does not by itself complete this card.
Result requirements
Every card is executed together with the full research contract: definitions, fields and cardinalities, lifecycle, sources, data mastership, rights, the five object facets, at least eight invariants, positive and negative examples, dependencies, migration and applicability limits.