{"schema":"https://ver.cy/schemas/card/1.0.0","id":"EM-RSK-02","code":"em-rsk-02","url":"https://ver.cy/models/em-rsk-02/","name":"Audit, review and finding","alternateNames":[],"kind":"enterprise-contour","status":"research-draft","version":"research-checkpoint","language":"en","classifiers":{"family":"Enterprise profiles","category":"Enterprise subject","entryKind":"subject","plane":"","domain":["Enterprise","RSK"],"industry":["Cross-industry"],"navPath":"","tags":["EM-RSK-02","W2","subject","Audit","AuditProcedure","AuditFinding","AssuranceOpinion","CorrectiveAction"],"facets":{}},"whatItIs":"Review plan, criteria, sample, evidence, finding and corrective action. An audit opinion has a scope and limitations.","purpose":"Review plan, criteria, sample, evidence, finding and corrective action. An audit opinion has a scope and limitations.","scope":{"in":[],"out":[],"boundaries":[]},"distinguishingFeatures":["Criteria are pinned","The conclusion is limited by the coverage","Completing a task does not close a finding without verification"],"structure":{"bundles":[]},"agentConduct":{"may":[],"mustNot":["Negative case: A review of one system proves compliance of the whole group."],"requiresHuman":[]},"ethics":{"considerations":[],"affectedParties":[]},"owners":{"steward":"Владелец рисков / CISO / внутренний аудит","roles":[],"masterSystems":["GRC","IAM","SIEM","сервис-деск"]},"relations":[{"target":"EM-RSK-01","type":"neighbor"},{"target":"EM-WRK-01","type":"neighbor"},{"target":"EM-WRK-02","type":"neighbor"},{"target":"WM-ACT-033","type":"references","note":"conceptual-candidate"},{"target":"WM-ECO-035","type":"references","note":"conceptual-candidate"},{"target":"WM-KNW-014","type":"references","note":"conceptual-candidate"}],"interaction":{"identity":{"applicability":"required","items":["Audit","AuditProcedure","AuditFinding","AssuranceOpinion","CorrectiveAction"]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"required","items":[]},"capabilities":{"applicability":"required","items":[]},"hazards":{"applicability":"required","items":[]},"interfaces":{"applicability":"required","items":[]},"context":{"applicability":"required","items":[]}},"sources":[{"title":"NIST CSF/AI RMF: governance and risk functions"},{"title":"ODRL/PROV: authority, grounds and evidence"},{"title":"GRC/IAM/BCM practice and NIST SP 800-34 for recovery"}],"openQuestions":["How to separate a finding from a risk and a task?","What does a sample prove?","How to close a finding after independent verification?","Установить границу и решение reuse/extend/new по действующим спецификациям.","Подтвердить semantic crosswalk, права и source mastership.","Выбрать immutable refs; провести проверки fixtures до заявления о публикационной готовности."],"resources":{"source":"https://ver.cy/enterprise/models/em-rsk-02/"},"provenance":{"origin":"enterprise research programme","builtFrom":["enterprise/models/em-rsk-02/brief.json"],"providers":[],"researchStatus":"published-partial","generatedAt":"","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"derived","structure":"missing","agentConduct":"derived","ethics":"missing","owners":"filled","relations":"filled","interaction.identity":"derived","interaction.properties":"not-applicable","interaction.recognition":"missing","interaction.capabilities":"missing","interaction.hazards":"missing","interaction.interfaces":"missing","interaction.context":"missing","sources":"filled"},"notes":{"agentConduct":"Negative case of the research brief, not yet a rule for agents.","interaction.properties":"Enterprise record contour: physical properties belong to referenced world models.","structure":"Research contour: bundles not designed yet; questions are listed as open questions.","language":"Still in Russian: suggested owner, blocking decisions, vercy candidates. Translate in research/enterprise/i18n/units.en.json."},"score":0.469}}