← Back to catalogue
Published

Review / Inspection / Audit

vr.wm-act-033 · wm-act-033-review-inspection-audit

Provide the format-neutral context an agent needs to commission, plan, execute, evidence, conclude, report and govern a bounded review, inspection, audit or assessment engagement: who is mandated to examine what, against which criteria, by which methods, on what evidence, yielding which findings, conclusion, assurance level, redress path and record governance.

World Models Activities and processes ACT.REV

Bundle → Layer → Finding → Questions Filled

6 bundles · 13 layers · 26 findings · 107 questions

Engagement identity and mandate Establishes what this engagement is, how it is classified, under what authority it is performed, and who occupies which role with what impartiality safeguards.

Identity and typing

Stable identification of the engagement occurrence and the classification that selects which requirement regime, assurance level and reporting form apply.

Engagement identifier and registration

How a single engagement occurrence is uniquely identified, by which issuing system, and how that identity survives re-issue, merger, split and cross-organisation exchange.

  1. Which system of record issues the engagement identifier, and what is its issuing authority and scope of uniqueness? identity
  2. When no master-system or governed global identifier exists, which surrogate is minted and by whom? provenance
  3. How is identity preserved when an engagement is split, merged, re-opened or superseded by a re-inspection? relationship
  4. Which additional external references identify this engagement to counterparties and authorities? interoperability

Engagement type and assurance classification

Classification of the engagement along the dimensions that change its normative obligations: discipline, engagement form, assurance level and reporting model.

  1. Which engagement type applies, and which requirement standard governs that type? classification
  2. Is the engagement an attestation or a direct-reporting engagement, and what level of assurance is intended? decision
  3. What triggered this engagement, and is it routine, risk-based, complaint-driven, follow-up or unannounced? event
  4. Is the examining body internal, first-party, second-party or third-party relative to the subject? classification

Mandate, authority and parties

The legal, regulatory or contractual basis for examining the subject, the terms agreed, and the appointment and impartiality of the people and bodies involved.

Mandate, authority and terms of engagement

The instrument that authorises the examination, the powers it confers, its limits, and the agreed terms and conditions or rules of engagement.

  1. On what legal, regulatory or contractual basis is this engagement authorised, and which instrument evidences it? authority
  2. Which specific powers are conferred, such as entry to premises, unannounced inspection, sampling, document demand or acquisition under cover of identity? authority
  3. What terms and conditions, rules of engagement, liability limits and safety constraints govern the work? constraint
  4. What does this mandate explicitly not authorise, and where does it hand over to an enforcement or certification decision? exception

Party appointment and impartiality safeguards

Who acts as auditor or inspector, responsible party and intended user; how roles are appointed; and what impartiality, independence and conflict-of-interest safeguards apply to this engagement.

  1. Which parties occupy the auditor, responsible-party and intended-user roles for this engagement? ownership
  2. Which individuals are assigned to the engagement team, in which engagement roles, and for which periods? composition
  3. What threats to impartiality or independence were identified, and which safeguards were applied? constraint
  4. Who declared absence or presence of conflicts of interest, when, and to whom was it disclosed? evidence
Subject matter, criteria and decision basis Fixes what is examined, the boundary and period of examination, the criteria the subject is measured against, and the documented rules by which measured or observed states become conformity determinations.

Subject matter and scope

What is being examined, in what representation, within which boundary, over which period, and with what declared exclusions.

Subject matter and subject-matter information

Distinguishes the underlying subject matter from the subject-matter information presented about it, and identifies the concrete assessment subjects examined.

  1. What is the underlying subject matter, and what subject-matter information about it is being examined? definition
  2. Which concrete assessment subjects fall within the examination, such as locations, components, inventory items, users, batches or processes? composition
  3. How does each assessment subject link to the master record for that entity in its owning model? relationship
  4. What was the state or configuration of the subject at the moment of examination, and how was that state captured? state

Scope boundary, period and exclusions

The declared limits of the examination in organisational, geographic, temporal and topical terms, including what was deliberately excluded and why.

  1. What organisational, contractual and topical boundary is claimed for this engagement? composition
  2. Which period does the examination cover, and how does it relate to the fieldwork dates? temporal
  3. Which physical or logical locations, sites, borders or jurisdictions are within the examination boundary? spatial
  4. What was excluded from scope, on whose decision, and what effect does the exclusion have on the conclusion? exception

Criteria and decision basis

The requirements the subject is measured against and the documented rules that convert observed or measured states into conformity determinations.

Criteria selection and authoritative binding

Which criteria apply, from which authoritative source and version, how they were selected or tailored, and how each is interpreted for this engagement.

  1. Which authoritative source and version supplies each criterion, and how is that binding resolved at read time? provenance
  2. How were criteria selected, tailored or narrowed to control objectives for this engagement, and who approved the selection? decision
  3. Are the criteria suitable, relevant, complete, reliable, neutral and understandable for the intended users? quality
  4. What engagement-local interpretation or acceptance guidance is applied to an ambiguous criterion, and does it conflict with the source? constraint

Materiality, tolerance and decision rules

The thresholds and documented decision rules that determine when a deviation is reportable and when a measured value counts as conforming, including guard bands and uncertainty treatment.

  1. What materiality or significance thresholds apply, quantitatively and qualitatively, and how were they set? measurement
  2. What documented decision rule converts a measured value plus its uncertainty into a conformity determination? decision
  3. How is measurement uncertainty obtained and whose responsibility is it to evaluate it? measurement
  4. How does the risk-based prioritisation of checks influence thresholds, sample intensity and reporting? requirement
Planning and fieldwork Converts the mandate and criteria into an executable plan with methods, sampling and coverage, and records what was actually done, where, when and by whom, including departures from plan.

Engagement planning

Objectives, schedule, methods, sampling, depth and coverage, and the assets and tooling used to perform the work.

Engagement objectives, plan and schedule

The stated objectives of the engagement, the tasks and milestones planned to meet them, and the resources committed.

  1. What are the engagement objectives, and how does each trace to a criterion or control objective? requirement
  2. What tasks, activities and milestones are planned, in what sequence, and with which dependencies? process
  3. Who approved the plan, when, and what changes require re-approval? authority
  4. What communication with the responsible party is planned before, during and after fieldwork? process

Methods, sampling, depth and coverage

Which examination methods are applied to which subjects, how samples are drawn from populations, and what depth and coverage are claimed.

  1. Which examination methods are used per objective, such as document examination, interview, observation, test, physical check or laboratory analysis? process
  2. How is the sample drawn from the population, and is the approach judgement-based or statistical? measurement
  3. What depth and coverage are claimed, and what does that imply about the extrapolation of results to the population? validation
  4. Which tools, platforms and automated analysers are used, at which versions and configurations? provenance

Fieldwork execution

The record of what was actually performed, under what conditions and access, by whom, and how execution departed from plan.

Fieldwork execution log, conditions and deviations

Chronological record of performed actions with actor, time and location, the site and access conditions that constrained them, and any departures from the approved plan.

  1. Which assessment actions were performed, by whom, and at what start and end times? event
  2. Where was each action performed, and was it on-site, remote or at a border or testing facility? spatial
  3. What access, availability, safety or security conditions constrained execution? constraint
  4. Where did execution deviate from the approved plan, why, who authorised it, and what is the consequence for coverage? exception
Evidence and observation How raw observations are captured with their collection method and subject, how evidence items are identified, held and kept intact, and how their relevance, reliability and sufficiency are appraised.

Evidence acquisition

Capture of observations and the identification, custody and integrity of the evidence items that support them.

Observation record and collection method

An atomic recorded observation: what was seen or measured, by which method, about which subject, when collected and when it ceases to be current.

  1. What exactly was observed, expressed independently of any judgement about conformity? definition
  2. By which collection method was the observation obtained, and by which actor or tool? process
  3. When was the observation collected, when did the observed condition occur, and when does the observation expire? temporal
  4. Which evidence items support this observation, and are they sufficient on their own? evidence

Evidence item identity, custody and integrity

Identification of each evidence item, where it came from, who held it, and how its integrity is demonstrable to a challenging party.

  1. How is each evidence item identified, and what is its authoritative source location? identity
  2. What integrity mechanism demonstrates that the item has not changed since acquisition? security
  3. Who has held the item since acquisition, in which transfers, and under what storage conditions? provenance
  4. Does the item contain personal, commercially confidential or classified material, and what handling class applies? privacy
  5. Under what conditions may the item be reused or shared with another authority or engagement? access

Evidence appraisal

Judgement about whether the evidence obtained is relevant, reliable, sufficient and appropriate, and what limitations qualify it.

Relevance, reliability, sufficiency and limitations

The recorded appraisal of evidence quality against the objectives, together with scope restrictions, unavailable evidence and their effect on the conclusion.

  1. Is each item of evidence relevant to the objective and criterion it is used to support? quality
  2. How reliable is the evidence given its source, generation method and susceptibility to manipulation? quality
  3. Is the accumulated evidence sufficient and appropriate to support the intended level of assurance? validation
  4. What evidence could not be obtained, why, and how does that limit the finding or conclusion? exception
Findings, conclusion and reporting How evidence becomes a structured finding with a conformity determination and severity, how findings retain identity across engagements, and how the engagement reaches and communicates a conclusion.

Finding construction

The internal structure of a finding, the determination and grading applied to it, and how it is identified and matched over time.

Finding statement structure

The elements that make a finding intelligible and contestable: the criterion, the condition observed, the cause and the actual or potential effect, with traceability to observations.

  1. For this finding, what are the criterion, the observed condition, the cause and the effect or potential effect? definition
  2. Which observations and evidence items support each element of the finding? evidence
  3. What reasoning connects the evidence to the claim that the criterion is or is not met? validation
  4. Are the grounds stated precisely enough to support a proportionate measure or a contested response? requirement

Conformity determination and severity grading

The verdict attached to a finding against its criterion and the severity or significance grade assigned, with the scheme that defines the permitted values.

  1. What determination is recorded against the criterion, and from which controlled value set? decision
  2. What severity, significance or risk grade is assigned, under which grading scheme? classification
  3. Which decision rule and uncertainty treatment produced the determination for a measured characteristic? measurement
  4. On what basis is a criterion recorded as not applicable, not tested or inconclusive rather than passed or failed? exception

Finding identity, recurrence and baseline comparison

How a finding keeps a stable identity across engagements and report revisions so that new, unchanged, updated and closed findings can be distinguished and trends measured.

  1. What stable key identifies the same underlying issue across engagements even when the artifact or wording changes? identity
  2. Against which baseline engagement is this finding compared, and what is its baseline state? relationship
  3. Is this a repeat finding, and how many consecutive engagements has it persisted through? state
  4. Has the finding been suppressed, accepted or excluded from reporting, on whose authority and with what justification? authority

Conclusion and reporting

Aggregation of findings into an engagement-level conclusion at a stated assurance level, and the issuance of the report or certificate with responsible-party views and use restrictions.

Engagement conclusion and assurance statement

How individual findings aggregate into an overall conclusion or opinion, at what assurance level, with what modifications and emphases.

  1. What is the overall conclusion or opinion, and how does it follow from the findings and their severity? decision
  2. What level of assurance is expressed, and does it match the level planned? quality
  3. Is the conclusion modified, qualified, adverse or a disclaimer, and on what grounds? exception
  4. Which assertions does the examining party itself attest to, and who signs them? authority

Report issuance, responsible-party views and use restrictions

Issuance of the engagement report or certificate, incorporation of the responsible party's views, and the restrictions on distribution, reliance and publication attached to it.

  1. Who issues the report or certificate, to which addressees, and on what date does it take effect? event
  2. How were the responsible party's views obtained and represented, including any disagreement? process
  3. What restrictions govern reliance, onward distribution, publication and use of the report or certificate? access
  4. Which mandatory content and statements must the report carry under the governing standard or law? requirement
Lifecycle, record governance and exchange The engagement state machine and closure, redress and follow-up, the provenance, retention and quality governance of the engagement record set, and its exchange with other systems and standards.

Engagement lifecycle and redress

States the engagement passes through, the recommendations it leaves behind and their verification, and the routes by which its results can be contested.

Engagement state model and closure

The permitted states of an engagement, the transitions between them, who may effect each transition, and the conditions for closure or abandonment.

  1. Which states may an engagement occupy, and which transitions are permitted between them? state
  2. Who is authorised to effect each transition, and what evidence must exist before it is allowed? authority
  3. What conditions must hold for the engagement to be closed, and what remains open after closure? lifecycle
  4. How is an engagement suspended, withdrawn or abandoned, and how is partial work disclosed? exception

Recommendation issuance and follow-up verification

Recommendations or required actions arising from findings, and the later verification that claimed remediation is evidenced, without owning the remediation work itself.

  1. What recommendation or required action does each finding carry, addressed to whom and by when? requirement
  2. Which model owns the planning, execution and closure of the resulting action, and what is referenced from here? ownership
  3. How and when is implementation verified, by which procedure, and with what evidence? validation
  4. What happens when verification fails or the deadline passes, and to whom is it escalated? process

Right to be heard, appeals and complaints

Procedural rights of the responsible party before and after a result is recorded, and the handling of appeals against a determination or complaints about the conduct of the engagement.

  1. Was the affected party given the opportunity to be heard before the result was acted on, with what notice period? process
  2. Who may appeal which determination, to which body, and within what time limit? authority
  3. How is the appeal or complaint reviewed independently of the individuals who produced the original result? constraint
  4. What outcomes can an appeal produce, and how are they reflected in the engagement record and any issued output? lifecycle

Record governance and quality

Provenance and amendment of the engagement record set, its retention classification and disposition, and the quality review that supports reliance on it.

Record provenance, versioning and amendment

How every change to the engagement record set is attributed, timestamped and versioned, and how an issued output is corrected without rewriting history.

  1. Which agent generated or modified each record, acting on behalf of which organisation? provenance
  2. How is a content change signalled, and what identifier and modification timestamp must change with it? validation
  3. How is an issued report or finding corrected, withdrawn or re-issued, and how is the original preserved? lifecycle
  4. From which prior records is this record derived, including imported plans and prior engagements? relationship

Retention, disposition and legal hold

Classification of engagement records for retention, the trigger and period that govern disposition, and holds that suspend it, without asserting ownership of disposal execution.

  1. Which retention class applies to each record type in this engagement, and which schedule authority defines it? retention
  2. What event starts the retention clock, and when does the disposition become due? temporal
  3. Is a legal, regulatory or appeal-related hold in force, who placed it and when may it be released? exception
  4. Which model or Dimension policy executes disposition, and what tombstone remains here afterwards? ownership
  5. How are personal-data minimisation and erasure obligations reconciled with evidentiary retention duties? privacy

Engagement quality review and competence evidence

The review performed on the engagement itself before issuance and the evidence that assigned personnel were competent for it, as required by a risk-based system of quality management.

  1. Was an engagement quality review performed, by whom, and what was its scope and conclusion? quality
  2. Under which risk-based criteria is an engagement quality review required rather than optional? requirement
  3. What evidence shows that each assigned individual was competent for their engagement role? evidence
  4. How was the work supervised and reviewed within the engagement team before conclusions were formed? process

Exchange and alignment

How engagement records are projected onto external exchange standards without asserting conformance, and where those mappings lose information.

Exchange binding and standard crosswalk

Declared mappings between this model's concepts and external exchange formats and ontologies, with explicit statements of lossiness, direction and version dependence.

  1. Which external standard and version is each binding declared against, and in which direction is it valid? interoperability
  2. Which local concept maps to which target construct, and which local concepts have no target equivalent? composition
  3. Where is the mapping lossy or semantically approximate, and what is the effect on a consumer? quality
  4. What conformance is claimed, and what evidence supports the claim? validation
  5. Under what conditions may an engagement record be transmitted to another authority or system, and what must accompany it? access

Classifiers Filled

Family
World Models
Category
Activities and processes
Entry kind
aggregate
Navigation path
NAV.ACT.REV
Domain
ACT.REV
Industry
Cross-industry
Tags
reviewinspectionauditact.rev

What it is Filled

The model is rooted on one engagement occurrence (audit, inspection, review, assessment or attestation engagement) treated as an aggregate: engagement identity governs its plan, execution log, observations, evidence appraisals, findings, conclusion, issued report or certificate, recommendations, appeals and record provenance, which share the engagement lifecycle. It is storage- and interface-neutral; JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are projections, not semantics. It carries references to the examined subject, the criteria sources, the responsible party and any remediation actions, but never reproduces those models' lifecycles. 'Audit' here means an assurance or examination activity, not IT audit-trail logging, which is a homonym.

In scope

  • Engagement identity, registration and typing (audit, inspection, review, assessment, attestation, direct-reporting, surveillance, follow-up)
  • Mandate, statutory or contractual authority, terms of engagement, and appointment of the three parties
  • Impartiality, independence and conflict-of-interest declarations scoped to this engagement
  • Subject matter, subject-matter information, scope boundary, period covered and declared exclusions
  • Selection and binding of criteria to authoritative external requirement sources
  • Materiality, tolerance, acceptance limits and documented decision rules including measurement-uncertainty handling
  • Engagement plan, objectives, schedule, methods, sampling strategy, depth and coverage
  • Fieldwork execution log, site and access conditions, and deviations from plan
  • Observations, evidence items, custody and integrity, and appraisal of relevance, reliability and sufficiency
  • Findings with criteria/condition/cause/effect structure, conformity determination and severity grading
  • Finding identity, recurrence and baseline comparison across engagements
  • Engagement conclusion, opinion, assurance level and report or certificate issuance with use restrictions
  • Responsible-party views, right to be heard, appeals and complaints about this engagement
  • Recommendation issuance and follow-up verification of claimed remediation
  • Engagement record provenance, versioning, amendment, retention classification and quality review

Out of scope

  • The examined subject itself (product, asset, system, process, person, programme) and its own lifecycle
  • Requirement, regulation and control-catalogue texts; only references, selections and engagement-local interpretations are held here
  • Corrective and preventive action execution, remediation project management and action closure
  • Enterprise risk register ownership, risk treatment decisions and residual-risk acceptance
  • Enforcement measures, sanctions, withdrawal, recall, prosecution and administrative penalties
  • Certification, approval and accreditation decision lifecycles, including suspension and withdrawal of certificates held by the subject or the body
  • Laboratory test method definition, measurement execution and uncertainty computation
  • Auditor qualification, training, certification and competence-registry lifecycle
  • IT system audit trails, security event logs and continuous telemetry pipelines (homonym boundary)
  • The multi-engagement audit programme or annual assurance plan and its own prioritisation lifecycle
  • Runtime policy evaluation, access-control enforcement and the platform audit trail that records who read these records
  • Physical execution of records disposal, destruction certificates and archival transfer
  • Commercial terms, fee arrangements and invoicing

Why it exists Filled

Provide the format-neutral context an agent needs to commission, plan, execute, evidence, conclude, report and govern a bounded review, inspection, audit or assessment engagement: who is mandated to examine what, against which criteria, by which methods, on what evidence, yielding which findings, conclusion, assurance level, redress path and record governance.

Distinguishing features Filled

  • Rooted on one bounded engagement with a mandate, criteria and three parties, not on the examined subject itself.
  • Records findings, conclusions and assurance levels but never imposes sanctions, which belong to an enforcement model.
  • Differs from a certification model: the engagement report feeds a certification decision but is not that decision.
  • Differs from an audit trail or security log, which records system events rather than an examination by a mandated party.

What robots and AI may and may not do Filled

Must not

  • Create a finding against a criterion that has no bound external source.
  • Issue a conclusion before evidence sufficiency has been concluded by the responsible person.
  • Start fieldwork before independence and conflict-of-interest declarations are recorded.
  • Alter or delete an issued report or finding instead of issuing a correction.
  • Present an alignment to an audit standard as certified conformance.

Only with a human decision

  • Signing the conclusion, opinion or assurance statement of an engagement.
  • Deciding on an appeal or complaint against a finding.
  • Accepting a declared conflict of interest and allowing the auditor to proceed.

May

  • Register an engagement and bind it to a versioned criteria set from an external source.
  • Record observations and attach evidence references with their provenance.
  • Draft findings that cite the criterion, the evidence and the condition observed.
  • Track follow-up verification of agreed actions against the original findings.

Moral aspects Filled

  • Findings can harm the reputation and livelihood of the audited party, so they must rest on stated evidence and criteria.
  • Interviews and observations collect personal data about staff; collect only what the criteria need.
  • Independence protects everyone who relies on the result; a captured auditor misleads the public.

Who is affected

  • The audited organisation and its staff
  • Users of the report such as regulators, investors and customers
  • Auditors and inspectors whose judgement is recorded

Owners Filled

Steward

The adopting Dimension must designate a named accountable owner for the engagement record set who is organisationally separate from the engagement team, and record that owner in the package manifest alongside the escalation route.

Roles

Engagement record owner
Hold accountability for the completeness, integrity and retention classification of the engagement record set independently of the engagement team.; Approve identity scheme use, value-set versions and the escalation route recorded in the owner package.
Model steward
Maintain this model's structure, value sets, boundary notes and composition links, and keep them consistent with the registry entry vr.wm-act-033.; Version exchange binding profiles when a target standard is revised, and record lossiness and conformance claims with their validation evidence.
Engagement lead (lead auditor or inspector)
Plan and direct the engagement, bind criteria, supervise fieldwork and construct findings against the documented decision rules.; Declare impartiality threats and safeguards, and form and sign the engagement conclusion within the mandated authority.
Engagement quality reviewer
Review significant judgements, evidence sufficiency and the draft conclusion before issuance, independently of the engagement team.; Record the review scope, matters raised and conclusion, and clear a specific report version for issue or withhold clearance.
Responsible-party liaison
Receive notices and requests for comment, coordinate the responsible party's views and disagreements, and confirm receipt of the issued output.; Exercise or waive the right to be heard within the notice period and initiate appeals where the regime allows.
Records custodian
Maintain custody chains, integrity digests and sensitivity classifications for evidence items and issued outputs.; Apply and release holds, present records for disposition to the owning records-management process, and record the disposition confirmation and tombstone.

Links to other meta-models Filled

child

  • WM-ACT-009 (registered parent activity model) - Inherit generic activity semantics - occurrence identity, actor participation, temporal bounds and lifecycle - and specialise them for evidence-against-criteria examination. Generic activity machinery is not redefined here.

references

  • Requirement, regulation and control-catalogue model - Resolve each criterion to an external source identifier and version. This model carries the binding, the selection or tailoring decision and any engagement-local interpretation; it never holds requirement text or the catalogue's own version lifecycle.
  • Examined subject model (product, asset, system, process, organisation) - Identify assessment subjects by their master identifiers so that findings attach to the authoritative record. Subject state, configuration history and lifecycle remain with the owning model.
  • Party, role and competence model - Resolve auditors, inspectors, responsible parties and intended users, and point to competence evidence. Qualification, training and competence-registry lifecycle stay with the party model; only engagement-scoped appointment and impartiality declarations are held here.
  • Corrective action and remediation model - Link a recommendation to the action record that will be planned, executed and closed elsewhere. This model records issuance and verification observations only, never action state, ownership or closure.
  • Risk register and risk treatment model - Hand over engagement-scoped risk statements for treatment and residual-risk acceptance. Risk scoring policy, treatment decisions and register lifecycle are not owned here.
  • Test, measurement and laboratory result model - Consume measured values with their stated uncertainty as evidence. Method validation, calibration traceability and uncertainty evaluation remain with the measurement model; only the decision rule application is local.
  • Certification, approval and accreditation model - Carry the reference from an issued certificate or attestation to the certification decision it feeds, and from the examining body to its accreditation scope. Grant, suspension and withdrawal lifecycles are not owned here.
  • Enforcement, measure and sanction model - Supply the evidenced determination and stated grounds that an enforcement measure may cite. Deciding, imposing, appealing at law and executing measures such as withdrawal or recall are entirely outside this model.
  • Audit programme and assurance plan model - Place the engagement within a multi-engagement programme for prioritisation and coverage reporting. Programme risk assessment, resourcing and its own lifecycle are not modelled here.
  • Records management, retention schedule and disposition model - Resolve retention classes and hand disposition execution to the owning records model or adopting-Dimension policy. This model holds classification, trigger, hold state and tombstone specification only.

aligned

  • W3C PROV-O provenance ontology - Express the engagement as prov:Activity, evidence and reports as prov:Entity, and auditors and bodies as prov:Agent, using wasGeneratedBy, used, wasAttributedTo and actedOnBehalfOf. Alignment only; provenance reasoning semantics are not reproduced.
  • NIST OSCAL assessment-plan and assessment-results models - Map plan, observation, finding, risk, reviewed-controls, attestation and assessment-log constructs for exchange in control-assessment contexts. Alignment is versioned separately and no conformance is claimed without validation evidence.
  • OASIS SARIF v2.1.0 result interchange format - Map findings onto result objects with ruleId, level, kind, locations, fingerprints and baselineState for tool-generated inspection results. The mapping is lossy for pass-type results and is annotated as such.
  • OMG Structured Assurance Case Metamodel (SACM) 2.3 - Express the criteria-to-evidence reasoning of a conclusion as claims, argument and evidence when a structured assurance case is required by the recipient. Argumentation semantics remain owned by SACM.

composes

  • Record provenance and versioning mix-in - Apply a common attribution, version-identifier and last-modified pattern to every record in the aggregate so that any content change is signalled uniformly, as OSCAL requires of its root elements.

neighbor

  • Requirement / control-catalogue model - This model records which criteria were selected, their version binding and any engagement-local interpretation; the catalogue model owns requirement text, hierarchy and its own version lifecycle. OSCAL keeps controls in the catalogue and profile layers and only references them from assessment results.
  • Corrective action / remediation model - This model issues recommendations and records follow-up verification observations. Deciding, planning, executing and closing corrective action belongs elsewhere: Regulation (EU) 2019/1020 places corrective action on the economic operator and enforcement on the authority, while the market-surveillance authority verifies follow-up.
  • Risk register model - OSCAL lets an assessment result carry engagement-scoped risk characterizations, but risk-treatment decisions and residual-risk acceptance migrate to the POA&M or risk model. This model therefore carries risk statements produced by the engagement, not the risk register lifecycle.
  • Test and measurement result model - Measurement values, method validation and uncertainty evaluation are produced by testing or laboratory models. This model consumes them as evidence and applies a documented decision rule, in the JCGM 106 sense, to reach a conformity determination.
  • Certification / accreditation model - Inspection certificates and attestations issued as engagement outputs are in scope as artifacts, but the decision lifecycle of a certification or of a body's accreditation scope is owned by the certification and accreditation models, per the EU accreditation framework.
  • Enforcement / sanction / case model - Article 16 measures, Article 19 serious-risk withdrawal or recall, and any penalty are enforcement acts owned by an enforcement model. This model supplies the evidenced non-compliance determination that such measures may cite.
  • IT audit-trail and security logging model - Homonym boundary. System audit logs are potential evidence sources referenced by observations; this model never owns log-record semantics, log retention or log integrity enforcement.
  • Party, role and competence model - This model records appointment to an engagement role and the engagement-scoped impartiality declaration; qualification, training and competence-registry lifecycle belong to the party model, as separated in the IIA and INTOSAI frameworks.
  • Audit programme / assurance plan model - Programme-level risk-based prioritisation, coverage across many engagements and resourcing span multiple engagements and have their own lifecycle. This model holds only a reference from the engagement to its programme.
  • Provenance model (W3C PROV) - PROV-O is an alignment target for expressing engagement-as-Activity, evidence-as-Entity and auditor-as-Agent. This model does not redefine provenance semantics and does not own generic provenance reasoning.

parent

  • WM-ACT-009

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative master-system identifier issued by the system of record for the engagement or artifact - for example the audit or inspection management system's engagement number, a regulator's case reference, or an issuing body's certificate number - recorded together with its issuing system and scheme.
  • Governed global identifier or IRI where one exists, such as a persistent URI minted in the adopting Dimension's governed namespace or an identifier assigned by a recognised registry or accreditation body.
  • UUID or ULID minted by the adopting Dimension only when neither of the above exists, recorded explicitly as a surrogate with its minting agent, minting timestamp and the reason no authoritative identifier was available.
  • A date, report title, file name, sequence label, engagement year or subject name is never an identifier and must not be used as one, alone or in combination.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Filled

  • An engagement has a mandate, a named examiner independent of the subject, a criteria set, evidence and a dated report.
  • Often confused with a certification decision, a test result, an enforcement case and a system audit log.

Capabilities and actions required Filled

  • Register engagement: Create the engagement aggregate root with its identity, classification, mandate reference and party roles, making it addressable before any planning or fieldwork occurs.
  • Bind criteria set: Resolve and attach the criteria and control objectives in scope for the engagement, each bound to an external source identifier and version, with tailoring decisions and local interpretations recorded.
  • Record observation: Capture an atomic observation with its collection method, subject, origin actor or tool, supporting evidence references and separated event, collection and ingestion timestamps.
  • Appraise evidence: Record the judgement of relevance, reliability, sufficiency and appropriateness for evidence supporting an objective, together with limitations and unavailable evidence.
  • Construct finding and determine conformity: Assemble criterion, condition, cause and effect into a finding, attach the supporting observations, apply the documented decision rule and record the determination and severity grade.
  • Issue conclusion and report: Aggregate findings into an engagement conclusion at a stated assurance level, incorporate the responsible party's views, and issue the sealed report or certificate with its use restrictions.
  • Register appeal or complaint: Record a challenge to a determination or to the conduct of the engagement, assign an independent reviewer, and capture the outcome and any consequent amendment.
  • Record follow-up verification: Record a verification act testing whether claimed implementation of a recommendation is evidenced, and its outcome, without changing the state of the action in the owning remediation model.
  • Close engagement: Transition the engagement to a closed state once closure criteria are met, fixing open items, retention triggers and the record set that must be preserved.
  • Export engagement record to a binding target: Project the engagement record set onto a declared external exchange binding, applying the versioned crosswalk and emitting the lossiness notes and conformance level actually claimed.

Hazards and failure modes required Filled

  • A false clean opinion that hides a real nonconformity from those who rely on it.
  • Leakage of confidential evidence or interview notes about named staff.
  • Findings issued against outdated criteria versions.
  • Undeclared conflicts of interest that invalidate the engagement.

Standards and interfaces required Filled

  • ISO 19011 guidelines for auditing management systems.
  • ISO/IEC 17020 for inspection bodies and ISO/IEC 17021-1 for certification audits.
  • International Standards on Auditing (ISA) and ISAE 3000 for assurance engagements.
  • Institute of Internal Auditors standards for internal audit.

Context of use required Filled

  • The market-surveillance framing, including the right to be heard with a notice period of at least ten working days, proportionate measures stating exact grounds, and mutual assistance timelines, is specific to Regulation (EU) 2019/1020 and does not transfer to other jurisdictions without verification.
  • The public-sector engagement taxonomy and quality-management deadlines are specific to US GAGAS 2024; other supreme audit institutions apply INTOSAI principles through their own national frameworks.
  • The internal-audit domain and principle structure follows the IIA 2024 Global Internal Audit Standards, whose adoption and effective dates vary by jurisdiction and sector.
  • Control-assessment constructs follow NIST OSCAL and SP 800-53A, which are US federal in origin; other control regimes use different assessment vocabularies.
  • Retention periods, legal hold triggers and personal-data erasure obligations are entirely jurisdiction-specific and are deliberately left unfixed, with only the classification and trigger structure modelled.
  • Accreditation and notified-body concepts follow the EU framework under Regulation (EC) No 765/2008 as explained in the Blue Guide; equivalent but non-identical regimes exist elsewhere.

Sources Filled

  1. OSCAL Assessment Results Model v1.1.2 JSON Format Metaschema Reference - National Institute of Standards and Technology (NIST)
  2. Assessment Results Model (OSCAL concepts documentation) - National Institute of Standards and Technology (NIST)
  3. Assessment Plan Model (OSCAL concepts documentation) - National Institute of Standards and Technology (NIST)
  4. Static Analysis Results Interchange Format (SARIF) Version 2.1.0 Plus Errata 01 - OASIS
  5. PROV-O: The PROV Ontology - World Wide Web Consortium (W3C)
  6. Regulation (EU) 2019/1020 on market surveillance and compliance of products - European Union (European Parliament and Council)
  7. ISSAI 100 – Fundamental Principles of Public-Sector Auditing - International Organisation of Supreme Audit Institutions (INTOSAI)
  8. Global Internal Audit Standards - The Institute of Internal Auditors (IIA)
  9. NIST SP 800-53A Rev. 5, Assessing Security and Privacy Controls in Information Systems and Organizations - National Institute of Standards and Technology (NIST)
  10. Structured Assurance Case Metamodel (SACM), Version 2.3 - Object Management Group (OMG)
  11. JCGM publications, including JCGM 106:2012 'Evaluation of measurement data — The role of measurement uncertainty in conformity assessment' and JCGM 200:2012 (VIM) - Joint Committee for Guides in Metrology / Bureau International des Poids et Mesures (BIPM)
  12. Government Auditing Standards (Yellow Book) - U.S. Government Accountability Office (GAO)
  13. Commission Notice — The 'Blue Guide' on the implementation of EU product rules 2022 - European Commission
  14. ISO/IEC 17020:2012 Conformity Assessment — Requirements for the Operation of Various Types of Bodies Performing Inspection (OSAC Registry entry) - National Institute of Standards and Technology (NIST), Organization of Scientific Area Committees for Forensic Science
  15. GAO Issues 2024 'Yellow Book,' Updating the Standards for Government Auditing - U.S. Government Accountability Office (GAO)

Open questions

  • Re-test whether cross-engagement finding identity, recurrence and suppression justify a second aggregate, once predecessor, successor and repeat-finding links are frozen into the relationship contract.
  • Verify the audit-documentation requirements in GAGAS 2024 and the IIA 2024 Global Internal Audit Standards to decide whether an engagement working-paper or documentation artifact must exist rather than evidence appraisal remaining inline only.
  • Obtain ISO/IEC 17020, ISO 19011, ISO/IEC 17000 and ISO 9000 through a licensed channel to close the declared vocabulary-alignment omission and to replace the unverified inspection-body clause alignment currently resting on a third-party registry pointer.
  • Split SRC-011 into per-document pins for JCGM 106:2012, JCGM 100:2008 and JCGM 200:2012, then re-attach the decision-rule, guard-band and uncertainty source_refs to the correct document.
  • Model interviewee, whistleblower and anonymous-source protection, currently a declared omission, because it collides directly with the in-scope right to be heard, the responsible party's views in the report, and cross-authority evidence reuse.
  • Close the two declared coverage gaps by finding a verified source for a sensitivity-classification scheme for audit and inspection material, and for acceptance sampling plans, statistical confidence and extrapolation to a population.
  • Re-audit artifact serial flags as a whole against the distinction between serial instances and versions, starting with exchange-binding-profile, engagement-report, engagement-quality-review-record and engagement-authorization-instrument.
  • Re-run the function sweep to cover evidence-item registration and custody transfer, report amendment or withdrawal, legal-hold placement and release, plan approval and re-approval, and superseding impartiality declarations, once a second provider or a further single-provider pass is authorized.
  • Sector-specific inspection and audit schemes - food and feed, aviation, maritime, nuclear, clinical GxP, financial supervision, forensic and building control - are not enumerated; each adds mandatory content, qualification and reporting rules that an adopting Dimension must layer on.
  • Rules of evidence admissibility in judicial or administrative proceedings are not modelled; custody and integrity are captured, but admissibility is jurisdiction-specific and belongs to a legal-process model.
  • Acceptance sampling plans, statistical confidence computation and extrapolation methods are referenced but not specified.
  • Interviewee protection, whistleblower confidentiality and anonymous-source handling are acknowledged through sensitivity classification but not modelled as a distinct concern.
  • Machine-readable competence and qualification taxonomies for auditors and inspectors are referenced to the party model and not defined here.
  • Remote and continuous auditing modalities, including automated evidence collection cadence and expiry, are only partially represented through observation expiry and tool references.
  • ISO vocabulary alignment for the terms audit, inspection, review, verification, validation, nonconformity and objective evidence is not asserted, because the relevant ISO texts could not be retrieved.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-act-033-review-inspection-audit/spec.yaml, ver-cy/world-models/card-supplements/wm-act-033-review-inspection-audit.json