# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T18:45:51Z", "synthesisSha256": "c979bcd81b5c06de37e995c66be33a90f2b5049b2d697d10de99b641fb572b88", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ECO-035", "registryId": "vr.wm-eco-035", "name": "Audit / Assurance Engagement", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Society, people and institutions", "industry": [ "Cross-industry" ], "domain": [ "SOC.ECO.AUD" ], "tags": [ "audit", "assurance", "engagement", "soc.eco.aud" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-eco-035-audit-assurance-engagement/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-eco-035", "model": { "registry_id": "vr.wm-eco-035", "model_id": "WM-ECO-035", "name": "Audit / Assurance Engagement", "entry_kind": "aggregate", "purpose": "Represent a governed professional engagement and its evidence-to-conclusion chain so agents can manage terms, independence, risks, procedures, evidence, findings, reporting and follow-up without confusing an audit with a review or related service, evidence with truth, management response with remediation, or an unmodified opinion with a guarantee.", "scope_statement": "Owns engagement and version identity; financial audit, review, other assurance, sustainability assurance, agreed-upon procedures, internal, public-sector, management-system, statutory, performance and compliance profiles; appointment, mandate, engagement letter, objective, scope, period, deadline and fee terms; responsible party, measurer or evaluator, practitioner, client, governance body and intended-user roles; integrity, objectivity, competence, due care, confidentiality, professional behavior, independence threats, safeguards, breaches and resolutions; partner, team, component practitioner, internal auditor, expert, resources, direction, supervision, review, consultation, quality review and differences of opinion; underlying subject, subject-matter information, assertions, criteria, frameworks and benchmarks; materiality, performance materiality and aggregation; inherent, control, detection, engagement, fraud, noncompliance and significant risks; audit strategy, plan, program, procedures, timing, extent, population, sampling and deviations; evidence items, sources, relevance, reliability, sufficiency, appropriateness, contradictions and workpaper provenance; condition, criterion, cause, effect, findings, misstatements, deviations, noncompliance, deficiencies, management responses, recommendations and action references; overall evaluation, unresolved matters, reasonable, limited or no assurance, conclusions, unmodified, qualified, adverse and disclaimer opinions, emphasis and other matters; report drafting, approval, signature, issuance, distribution, restriction, withdrawal, governance communications, follow-up and closure; archive, provenance, clocks, confidentiality, privilege, access, retention and loss-aware projections. External client, subject, criteria, statement, disclosure, control, risk, evidence source, issue, action, regulator case and records masters remain authoritative.", "in_scope": [ "Engagement identity, terms, parties, ethics, independence, competence, quality, subject, criteria, materiality, risks and controls", "Planning, procedures, sampling, evidence, workpapers, findings, responses, evaluation, conclusion, report, communication, follow-up, archive, access and projections" ], "out_of_scope": [ "Owning Organization, Person, Subject Matter, Criteria, Legal Norm, Statement, Disclosure, Control, Risk, Evidence Source, Issue, Remediation Action, Regulator Case, Decision, Sanction or Records masters", "Treating a review as audit, agreed-upon factual findings as assurance, management assertion as practitioner conclusion, approval as independence, or unmodified opinion as guarantee", "Autonomous appointment, engagement acceptance, independence attestation, evidence waiver, workpaper sign-off, opinion issuance, privileged disclosure or record destruction" ], "boundary_notes": [ { "neighbor": "WM-ACT-036", "distinction": "The registry supplies Research Study as a provisional parent signal, which is semantically suspect for audit and assurance; no containment or cascade authority is inferred.", "source_refs": [ "SRC-001", "SRC-005", "SRC-015" ] }, { "neighbor": "WM-ACT-033 and WM-ACT-034", "distinction": "Generic review, inspection, audit, assessment and evaluation processes may be referenced, but this aggregate owns professional terms, ethics, evidence-to-conclusion and report semantics.", "source_refs": [ "SRC-001", "SRC-010", "SRC-014", "SRC-015", "SRC-016" ] }, { "neighbor": "Audit, review, assurance and agreed-upon procedures", "distinction": "Each class has different objectives, work effort, evidence, wording and assurance level; factual findings are not an assurance conclusion.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-014", "SRC-015" ] }, { "neighbor": "Subject matter, assertion, criteria, evidence and conclusion", "distinction": "The engagement binds an external subject to suitable criteria, gathers source-qualified evidence and issues a scoped conclusion without making the underlying master its own.", "source_refs": [ "SRC-005", "SRC-006", "SRC-012", "SRC-015", "SRC-022" ] }, { "neighbor": "Finding, response, action and regulator decision", "distinction": "A practitioner finding, responsible-party response, promised or completed action, verification and regulator outcome remain separately owned assertions.", "source_refs": [ "SRC-010", "SRC-014", "SRC-015", "SRC-017" ] }, { "neighbor": "Professional and jurisdiction profiles", "distinction": "IAASB, IESBA, IIA, PCAOB, GAO, INTOSAI, ISO and EU rules are versioned scoped profiles and do not establish universal conformance.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020" ] } ] }, "sources": [ { "id": "SRC-001", "title": "2025 Handbook of International Quality Management, Auditing, Review, Other Assurance, and Related Services Pronouncements", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/2025-handbook-international-quality-management-auditing-review-other-assurance-and-related-services", "version_or_date": "Current edition published 17 September 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Provides the current IAASB family for quality management, audit, review, sustainability assurance, other assurance and related services." }, { "id": "SRC-002", "title": "ISA 220 Revised: Quality Management for an Audit of Financial Statements", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/international-standard-auditing-220-revised-quality-management-audit-financial-statements", "version_or_date": "Issued 17 December 2020; effective 15 December 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines engagement-partner and team responsibilities for managing and achieving audit quality." }, { "id": "SRC-003", "title": "ISA 315 Revised 2019: Identifying and Assessing the Risks of Material Misstatement", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/isa-315-revised-2019-identifying-and-assessing-risks-material-misstatement", "version_or_date": "Issued 19 December 2019", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines robust risk identification and assessment that drives responses and evidence work." }, { "id": "SRC-004", "title": "ISA 700 Revised: Forming an Opinion and Reporting on Financial Statements", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/international-standard-auditing-isa-700-revised-forming-opinion-and-reporting-financial-statements", "version_or_date": "Revised standard effective 15 December 2016", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines forming an opinion and the form and content of the auditor report." }, { "id": "SRC-005", "title": "ISAE 3000 Revised: Assurance Engagements Other than Audits or Reviews of Historical Financial Information", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits-or", "version_or_date": "Issued 9 December 2013; effective 15 December 2015", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines attestation and adaptable direct-engagement concepts for reasonable and limited assurance across subject matters." }, { "id": "SRC-006", "title": "ISSA 5000 General Requirements for Sustainability Assurance Engagements", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/international-standard-sustainability-assurance-5000-general-requirements-sustainability-assurance", "version_or_date": "Final standard 12 November 2024; effective 15 December 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines framework-neutral sustainability assurance engagements, evidence, reporting and limited or reasonable assurance." }, { "id": "SRC-007", "title": "ISRE 2400 Revised: Engagements to Review Historical Financial Statements", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/international-standard-review-engagements-2400-revised-engagements-review-historical-financial", "version_or_date": "Issued 27 September 2012; effective 31 December 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Distinguishes a limited-assurance review and its report from an audit." }, { "id": "SRC-008", "title": "ISRS 4400 Revised: Agreed-Upon Procedures Engagements", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/international-standard-related-services-isrs-4400-revised-agreed-upon-procedures-engagements", "version_or_date": "Revised standard effective 1 January 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Distinguishes factual findings from an assurance conclusion and requires agreed procedures and intended users." }, { "id": "SRC-009", "title": "International Code of Ethics for Professional Accountants", "organization": "International Ethics Standards Board for Accountants", "url": "https://www.ethicsboard.org/iesba-code", "version_or_date": "2025 Code overview and current edition", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines integrity, objectivity, competence, confidentiality, professional behavior and independence threat safeguards." }, { "id": "SRC-010", "title": "2024 Global Internal Audit Standards", "organization": "The Institute of Internal Auditors", "url": "https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/", "version_or_date": "2024 edition, effective for quality assessments 9 January 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines internal audit purpose, ethics, governance, management, engagement planning, performance, communication and action-plan monitoring." }, { "id": "SRC-011", "title": "AS 1000: General Responsibilities of the Auditor in Conducting an Audit", "organization": "Public Company Accounting Oversight Board", "url": "https://pcaobus.org/oversight/standards/auditing-standards/details/as-1000--general-responsibilities-of-the-auditor-in-conducting-an-audit", "version_or_date": "PCAOB Release 2024-004", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines auditor objectives, qualifications, due professional care, skepticism, judgment and general responsibilities." }, { "id": "SRC-012", "title": "AS 1105: Audit Evidence", "organization": "Public Company Accounting Oversight Board", "url": "https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105", "version_or_date": "Current standard and amendments accessed 6 September 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines sufficient appropriate evidence, relevance, reliability, procedures, sampling and contradictory evidence." }, { "id": "SRC-013", "title": "AS 3101: The Auditor's Report", "organization": "Public Company Accounting Oversight Board", "url": "https://pcaobus.org/oversight/standards/auditing-standards/details/AS3101", "version_or_date": "Current standard and amendments accessed 6 September 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines unqualified reporting, critical audit matters and links to qualified, adverse and disclaimer outcomes." }, { "id": "SRC-014", "title": "Government Auditing Standards 2024 Revision", "organization": "United States Government Accountability Office", "url": "https://www.gao.gov/yellowbook", "version_or_date": "2024 Yellow Book, effective 15 December 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Covers financial audits, attestation engagements, reviews, performance audits, ethics, independence and quality management." }, { "id": "SRC-015", "title": "ISSAI 100 Fundamental Principles of Public-Sector Auditing", "organization": "International Organization of Supreme Audit Institutions", "url": "https://www.issai.org/pronouncements/issai-100-fundamental-principles-of-public-sector-auditing/issai-100/", "version_or_date": "Endorsement version", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines mandate, three parties, subject matter, criteria, subject-matter information, engagement types and confidence in public-sector auditing." }, { "id": "SRC-016", "title": "ISO 19011:2026 Guidelines for Auditing Management Systems", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/19011", "version_or_date": "Edition 4, May 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Provides public metadata for audit principles, audit-program management, conducting audits and auditor competence; normative text is licensed." }, { "id": "SRC-017", "title": "Directive 2006/43/EC on Statutory Audits", "organization": "European Union", "url": "https://eur-lex.europa.eu/eli/dir/2006/43/2024-01-09/eng", "version_or_date": "Consolidated 9 January 2024; current version link available", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines statutory auditor approval, independence, professional ethics, standards, reporting, oversight and audit committees." }, { "id": "SRC-018", "title": "PCAOB Auditing Standards Index", "organization": "Public Company Accounting Oversight Board", "url": "https://pcaobus.org/oversight/standards/auditing-standards", "version_or_date": "Current index accessed 6 September 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Supplies versioned general, risk, evidence, communication, documentation and reporting standards and archived applicability dates." }, { "id": "SRC-019", "title": "ISA 610 Revised 2013: Using the Work of Internal Auditors", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/isa-610-revised-2013-using-work-internal-auditors", "version_or_date": "Revised standard published 19 March 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines evaluation and use of internal-audit work while preserving external auditor responsibility." }, { "id": "SRC-020", "title": "ISA 600 Revised: Special Considerations in Group Audits", "organization": "International Auditing and Assurance Standards Board", "url": "https://www.iaasb.org/publications/international-standard-auditing-600-revised-special-considerations-audits-group-financial-statements", "version_or_date": "Revised standard effective 15 December 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Defines group engagement, components, component auditors, direction, supervision, review and evidence aggregation." }, { "id": "SRC-021", "title": "RFC 3339: Date and Time on the Internet", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339.html", "version_or_date": "July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Provides interoperable timestamps with seconds and explicit UTC offset." }, { "id": "SRC-022", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "Recommendation 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Provides entity, activity, agent, derivation and attribution semantics for workpapers and evidence." }, { "id": "SRC-023", "title": "Data Quality Vocabulary", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vocab-dqv/", "version_or_date": "Working Group Note 15 December 2016", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Provides explicit quality measurements, annotations and policies for evidence and conclusions." }, { "id": "SRC-024", "title": "ODRL Information Model 2.2", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/odrl-model/", "version_or_date": "Recommendation 15 February 2018", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T18:41:00Z", "relevance": "Provides permission, prohibition, duty and constraint semantics for confidential workpapers and reports." } ], "structure": { "bundles": [ { "id": "engagement-identity-terms-and-parties", "name": "Engagement identity, terms and parties", "description": "Establish one engagement, its kind, mandate, terms, subject and accountable participants", "rationale": "Establish one engagement, its kind, mandate, terms, subject and accountable participants", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-014", "SRC-015", "SRC-006", "SRC-010", "SRC-017" ], "layers": [ { "id": "engagement-identity-class-and-terms", "name": "Engagement identity, class and terms", "description": "Groups governed assertions about engagement identity, class and terms for the engagement.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-014", "SRC-015" ], "findings": [ { "id": "engagement-version-kind-status-predecessor-successor-and-master-system", "name": "Engagement, version, kind, status, predecessor, successor and master system", "description": "Records engagement, version, kind, status, predecessor, successor and master system as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-014", "SRC-015" ], "questions": [ { "id": "engagement-version-kind-status-predecessor-successor-and-master-system-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish engagement, version, kind, status, predecessor, successor and master system?", "kind": "identity", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "engagement-version-kind-status-predecessor-successor-and-master-system-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on engagement, version, kind, status, predecessor, successor and master system, under what ethics and authority?", "kind": "authority", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "engagement-version-kind-status-predecessor-successor-and-master-system-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify engagement, version, kind, status, predecessor, successor and master system?", "kind": "validation", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "engagement-version-kind-status-predecessor-successor-and-master-system-data", "name": "Engagement, version, kind, status, predecessor, successor and master system data", "description": "Typed engagement data for engagement, version, kind, status, predecessor, successor and master system, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "engagement-version-kind-status-predecessor-successor-and-master-system-record", "name": "Engagement, version, kind, status, predecessor, successor and master system record", "description": "Immutable or versioned evidence for engagement, version, kind, status, predecessor, successor and master system with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "audit-review-assurance-agreed-upon-procedures-internal-performance-and-compliance-class", "name": "Audit, review, assurance, agreed-upon procedures, internal, performance and compliance class", "description": "Records audit, review, assurance, agreed-upon procedures, internal, performance and compliance class as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-014", "SRC-015" ], "questions": [ { "id": "audit-review-assurance-agreed-upon-procedures-internal-performance-and-compliance-class-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish audit, review, assurance, agreed-upon procedures, internal, performance and compliance class?", "kind": "classification", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "audit-review-assurance-agreed-upon-procedures-internal-performance-and-compliance-class-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on audit, review, assurance, agreed-upon procedures, internal, performance and compliance class, under what ethics and authority?", "kind": "requirement", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "audit-review-assurance-agreed-upon-procedures-internal-performance-and-compliance-class-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify audit, review, assurance, agreed-upon procedures, internal, performance and compliance class?", "kind": "security", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "audit-review-assurance-agreed-upon-procedures-internal-performance-and-compliance-class-data", "name": "Audit, review, assurance, agreed-upon procedures, internal, performance and compliance class data", "description": "Typed engagement data for audit, review, assurance, agreed-upon procedures, internal, performance and compliance class, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "audit-review-assurance-agreed-upon-procedures-internal-performance-and-compliance-class-record", "name": "Audit, review, assurance, agreed-upon procedures, internal, performance and compliance class record", "description": "Immutable or versioned evidence for audit, review, assurance, agreed-upon procedures, internal, performance and compliance class with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-008", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "mandate-terms-subject-and-parties", "name": "Mandate, terms, subject and parties", "description": "Groups governed assertions about mandate, terms, subject and parties for the engagement.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-010", "SRC-014", "SRC-015", "SRC-017" ], "findings": [ { "id": "appointment-mandate-engagement-letter-objective-scope-period-deadline-and-fee", "name": "Appointment, mandate, engagement letter, objective, scope, period, deadline and fee", "description": "Records appointment, mandate, engagement letter, objective, scope, period, deadline and fee as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-010", "SRC-014", "SRC-015", "SRC-017" ], "questions": [ { "id": "appointment-mandate-engagement-letter-objective-scope-period-deadline-and-fee-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish appointment, mandate, engagement letter, objective, scope, period, deadline and fee?", "kind": "requirement", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "appointment-mandate-engagement-letter-objective-scope-period-deadline-and-fee-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on appointment, mandate, engagement letter, objective, scope, period, deadline and fee, under what ethics and authority?", "kind": "constraint", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "appointment-mandate-engagement-letter-objective-scope-period-deadline-and-fee-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify appointment, mandate, engagement letter, objective, scope, period, deadline and fee?", "kind": "privacy", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "appointment-mandate-engagement-letter-objective-scope-period-deadline-and-fee-data", "name": "Appointment, mandate, engagement letter, objective, scope, period, deadline and fee data", "description": "Typed engagement data for appointment, mandate, engagement letter, objective, scope, period, deadline and fee, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-010", "SRC-014", "SRC-015", "SRC-017" ] } ], "artifacts": [ { "id": "appointment-mandate-engagement-letter-objective-scope-period-deadline-and-fee-record", "name": "Appointment, mandate, engagement letter, objective, scope, period, deadline and fee record", "description": "Immutable or versioned evidence for appointment, mandate, engagement letter, objective, scope, period, deadline and fee with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-010", "SRC-014", "SRC-015", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "responsible-party-measurer-evaluator-practitioner-client-governance-body-and-intended-user", "name": "Responsible party, measurer or evaluator, practitioner, client, governance body and intended user", "description": "Records responsible party, measurer or evaluator, practitioner, client, governance body and intended user as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-010", "SRC-014", "SRC-015", "SRC-017" ], "questions": [ { "id": "responsible-party-measurer-evaluator-practitioner-client-governance-body-and-intended-user-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish responsible party, measurer or evaluator, practitioner, client, governance body and intended user?", "kind": "relationship", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "responsible-party-measurer-evaluator-practitioner-client-governance-body-and-intended-user-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on responsible party, measurer or evaluator, practitioner, client, governance body and intended user, under what ethics and authority?", "kind": "process", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "responsible-party-measurer-evaluator-practitioner-client-governance-body-and-intended-user-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify responsible party, measurer or evaluator, practitioner, client, governance body and intended user?", "kind": "retention", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "responsible-party-measurer-evaluator-practitioner-client-governance-body-and-intended-user-data", "name": "Responsible party, measurer or evaluator, practitioner, client, governance body and intended user data", "description": "Typed engagement data for responsible party, measurer or evaluator, practitioner, client, governance body and intended user, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-010", "SRC-014", "SRC-015", "SRC-017" ] } ], "artifacts": [ { "id": "responsible-party-measurer-evaluator-practitioner-client-governance-body-and-intended-user-record", "name": "Responsible party, measurer or evaluator, practitioner, client, governance body and intended user record", "description": "Immutable or versioned evidence for responsible party, measurer or evaluator, practitioner, client, governance body and intended user with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-010", "SRC-014", "SRC-015", "SRC-017" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "ethics-independence-competence-and-quality", "name": "Ethics, independence, competence and quality", "description": "Preserve professional standing, threat evaluation, team capability and quality responsibilities", "rationale": "Preserve professional standing, threat evaluation, team capability and quality responsibilities", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-017", "SRC-019", "SRC-020" ], "layers": [ { "id": "ethics-independence-objectivity-and-confidentiality", "name": "Ethics, independence, objectivity and confidentiality", "description": "Groups governed assertions about ethics, independence, objectivity and confidentiality for the engagement.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-017" ], "findings": [ { "id": "integrity-objectivity-competence-due-care-confidentiality-and-professional-behavior", "name": "Integrity, objectivity, competence, due care, confidentiality and professional behavior", "description": "Records integrity, objectivity, competence, due care, confidentiality and professional behavior as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-017" ], "questions": [ { "id": "integrity-objectivity-competence-due-care-confidentiality-and-professional-behavior-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish integrity, objectivity, competence, due care, confidentiality and professional behavior?", "kind": "constraint", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "integrity-objectivity-competence-due-care-confidentiality-and-professional-behavior-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on integrity, objectivity, competence, due care, confidentiality and professional behavior, under what ethics and authority?", "kind": "event", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "integrity-objectivity-competence-due-care-confidentiality-and-professional-behavior-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify integrity, objectivity, competence, due care, confidentiality and professional behavior?", "kind": "access", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "integrity-objectivity-competence-due-care-confidentiality-and-professional-behavior-data", "name": "Integrity, objectivity, competence, due care, confidentiality and professional behavior data", "description": "Typed engagement data for integrity, objectivity, competence, due care, confidentiality and professional behavior, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-017" ] } ], "artifacts": [ { "id": "integrity-objectivity-competence-due-care-confidentiality-and-professional-behavior-record", "name": "Integrity, objectivity, competence, due care, confidentiality and professional behavior record", "description": "Immutable or versioned evidence for integrity, objectivity, competence, due care, confidentiality and professional behavior with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "independence-threat-interest-relationship-safeguard-breach-and-resolution", "name": "Independence threat, interest, relationship, safeguard, breach and resolution", "description": "Records independence threat, interest, relationship, safeguard, breach and resolution as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-017" ], "questions": [ { "id": "independence-threat-interest-relationship-safeguard-breach-and-resolution-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish independence threat, interest, relationship, safeguard, breach and resolution?", "kind": "validation", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "independence-threat-interest-relationship-safeguard-breach-and-resolution-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on independence threat, interest, relationship, safeguard, breach and resolution, under what ethics and authority?", "kind": "measurement", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "independence-threat-interest-relationship-safeguard-breach-and-resolution-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify independence threat, interest, relationship, safeguard, breach and resolution?", "kind": "exception", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "independence-threat-interest-relationship-safeguard-breach-and-resolution-data", "name": "Independence threat, interest, relationship, safeguard, breach and resolution data", "description": "Typed engagement data for independence threat, interest, relationship, safeguard, breach and resolution, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-017" ] } ], "artifacts": [ { "id": "independence-threat-interest-relationship-safeguard-breach-and-resolution-record", "name": "Independence threat, interest, relationship, safeguard, breach and resolution record", "description": "Immutable or versioned evidence for independence threat, interest, relationship, safeguard, breach and resolution with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-014", "SRC-017" ] } ], "inline_only_rationale": null } ] }, { "id": "team-experts-resources-supervision-and-review", "name": "Team, experts, resources, supervision and review", "description": "Groups governed assertions about team, experts, resources, supervision and review for the engagement.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011", "SRC-019", "SRC-020" ], "findings": [ { "id": "partner-team-component-auditor-internal-auditor-expert-competence-and-availability", "name": "Partner, team, component auditor, internal auditor, expert, competence and availability", "description": "Records partner, team, component auditor, internal auditor, expert, competence and availability as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011", "SRC-019", "SRC-020" ], "questions": [ { "id": "partner-team-component-auditor-internal-auditor-expert-competence-and-availability-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish partner, team, component auditor, internal auditor, expert, competence and availability?", "kind": "composition", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "partner-team-component-auditor-internal-auditor-expert-competence-and-availability-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on partner, team, component auditor, internal auditor, expert, competence and availability, under what ethics and authority?", "kind": "evidence", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "partner-team-component-auditor-internal-auditor-expert-competence-and-availability-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify partner, team, component auditor, internal auditor, expert, competence and availability?", "kind": "interoperability", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "partner-team-component-auditor-internal-auditor-expert-competence-and-availability-data", "name": "Partner, team, component auditor, internal auditor, expert, competence and availability data", "description": "Typed engagement data for partner, team, component auditor, internal auditor, expert, competence and availability, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011", "SRC-019", "SRC-020" ] } ], "artifacts": [ { "id": "partner-team-component-auditor-internal-auditor-expert-competence-and-availability-record", "name": "Partner, team, component auditor, internal auditor, expert, competence and availability record", "description": "Immutable or versioned evidence for partner, team, component auditor, internal auditor, expert, competence and availability with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011", "SRC-019", "SRC-020" ] } ], "inline_only_rationale": null }, { "id": "direction-supervision-review-consultation-quality-review-and-difference-of-opinion", "name": "Direction, supervision, review, consultation, quality review and difference of opinion", "description": "Records direction, supervision, review, consultation, quality review and difference of opinion as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011", "SRC-019", "SRC-020" ], "questions": [ { "id": "direction-supervision-review-consultation-quality-review-and-difference-of-opinion-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish direction, supervision, review, consultation, quality review and difference of opinion?", "kind": "process", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "direction-supervision-review-consultation-quality-review-and-difference-of-opinion-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on direction, supervision, review, consultation, quality review and difference of opinion, under what ethics and authority?", "kind": "quality", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "direction-supervision-review-consultation-quality-review-and-difference-of-opinion-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify direction, supervision, review, consultation, quality review and difference of opinion?", "kind": "decision", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "direction-supervision-review-consultation-quality-review-and-difference-of-opinion-data", "name": "Direction, supervision, review, consultation, quality review and difference of opinion data", "description": "Typed engagement data for direction, supervision, review, consultation, quality review and difference of opinion, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011", "SRC-019", "SRC-020" ] } ], "artifacts": [ { "id": "direction-supervision-review-consultation-quality-review-and-difference-of-opinion-record", "name": "Direction, supervision, review, consultation, quality review and difference of opinion record", "description": "Immutable or versioned evidence for direction, supervision, review, consultation, quality review and difference of opinion with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010", "SRC-011", "SRC-019", "SRC-020" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "subject-matter-criteria-materiality-and-risk", "name": "Subject matter, criteria, materiality and risk", "description": "Bind the exact subject and suitable criteria, then qualify materiality and risk without absorbing their masters", "rationale": "Bind the exact subject and suitable criteria, then qualify materiality and risk without absorbing their masters", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-012", "SRC-015", "SRC-003", "SRC-011", "SRC-014", "SRC-018" ], "layers": [ { "id": "subject-matter-information-criteria-and-assertions", "name": "Subject matter, information, criteria and assertions", "description": "Groups governed assertions about subject matter, information, criteria and assertions for the engagement.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-012", "SRC-015" ], "findings": [ { "id": "underlying-subject-subject-matter-information-assertion-criterion-framework-and-benchmark", "name": "Underlying subject, subject-matter information, assertion, criterion, framework and benchmark", "description": "Records underlying subject, subject-matter information, assertion, criterion, framework and benchmark as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-012", "SRC-015" ], "questions": [ { "id": "underlying-subject-subject-matter-information-assertion-criterion-framework-and-benchmark-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish underlying subject, subject-matter information, assertion, criterion, framework and benchmark?", "kind": "other", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "underlying-subject-subject-matter-information-assertion-criterion-framework-and-benchmark-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on underlying subject, subject-matter information, assertion, criterion, framework and benchmark, under what ethics and authority?", "kind": "validation", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "underlying-subject-subject-matter-information-assertion-criterion-framework-and-benchmark-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify underlying subject, subject-matter information, assertion, criterion, framework and benchmark?", "kind": "identity", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "underlying-subject-subject-matter-information-assertion-criterion-framework-and-benchmark-data", "name": "Underlying subject, subject-matter information, assertion, criterion, framework and benchmark data", "description": "Typed engagement data for underlying subject, subject-matter information, assertion, criterion, framework and benchmark, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-012", "SRC-015" ] } ], "artifacts": [ { "id": "underlying-subject-subject-matter-information-assertion-criterion-framework-and-benchmark-record", "name": "Underlying subject, subject-matter information, assertion, criterion, framework and benchmark record", "description": "Immutable or versioned evidence for underlying subject, subject-matter information, assertion, criterion, framework and benchmark with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-012", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "criterion-relevance-completeness-reliability-neutrality-understandability-and-availability", "name": "Criterion relevance, completeness, reliability, neutrality, understandability and availability", "description": "Records criterion relevance, completeness, reliability, neutrality, understandability and availability as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-012", "SRC-015" ], "questions": [ { "id": "criterion-relevance-completeness-reliability-neutrality-understandability-and-availability-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish criterion relevance, completeness, reliability, neutrality, understandability and availability?", "kind": "quality", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "criterion-relevance-completeness-reliability-neutrality-understandability-and-availability-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on criterion relevance, completeness, reliability, neutrality, understandability and availability, under what ethics and authority?", "kind": "security", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "criterion-relevance-completeness-reliability-neutrality-understandability-and-availability-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify criterion relevance, completeness, reliability, neutrality, understandability and availability?", "kind": "classification", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "criterion-relevance-completeness-reliability-neutrality-understandability-and-availability-data", "name": "Criterion relevance, completeness, reliability, neutrality, understandability and availability data", "description": "Typed engagement data for criterion relevance, completeness, reliability, neutrality, understandability and availability, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-012", "SRC-015" ] } ], "artifacts": [ { "id": "criterion-relevance-completeness-reliability-neutrality-understandability-and-availability-record", "name": "Criterion relevance, completeness, reliability, neutrality, understandability and availability record", "description": "Immutable or versioned evidence for criterion relevance, completeness, reliability, neutrality, understandability and availability with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-012", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "materiality-risk-controls-and-fraud", "name": "Materiality, risk, controls and fraud", "description": "Groups governed assertions about materiality, risk, controls and fraud for the engagement.", "source_refs": [ "SRC-003", "SRC-011", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ], "findings": [ { "id": "materiality-threshold-performance-materiality-tolerable-misstatement-and-aggregation", "name": "Materiality, threshold, performance materiality, tolerable misstatement and aggregation", "description": "Records materiality, threshold, performance materiality, tolerable misstatement and aggregation as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-003", "SRC-011", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ], "questions": [ { "id": "materiality-threshold-performance-materiality-tolerable-misstatement-and-aggregation-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish materiality, threshold, performance materiality, tolerable misstatement and aggregation?", "kind": "decision", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "materiality-threshold-performance-materiality-tolerable-misstatement-and-aggregation-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on materiality, threshold, performance materiality, tolerable misstatement and aggregation, under what ethics and authority?", "kind": "privacy", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "materiality-threshold-performance-materiality-tolerable-misstatement-and-aggregation-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify materiality, threshold, performance materiality, tolerable misstatement and aggregation?", "kind": "composition", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "materiality-threshold-performance-materiality-tolerable-misstatement-and-aggregation-data", "name": "Materiality, threshold, performance materiality, tolerable misstatement and aggregation data", "description": "Typed engagement data for materiality, threshold, performance materiality, tolerable misstatement and aggregation, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-011", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ] } ], "artifacts": [ { "id": "materiality-threshold-performance-materiality-tolerable-misstatement-and-aggregation-record", "name": "Materiality, threshold, performance materiality, tolerable misstatement and aggregation record", "description": "Immutable or versioned evidence for materiality, threshold, performance materiality, tolerable misstatement and aggregation with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-003", "SRC-011", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ] } ], "inline_only_rationale": null }, { "id": "inherent-control-detection-engagement-fraud-noncompliance-and-significant-risk", "name": "Inherent, control, detection, engagement, fraud, noncompliance and significant risk", "description": "Records inherent, control, detection, engagement, fraud, noncompliance and significant risk as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-003", "SRC-011", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ], "questions": [ { "id": "inherent-control-detection-engagement-fraud-noncompliance-and-significant-risk-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish inherent, control, detection, engagement, fraud, noncompliance and significant risk?", "kind": "other", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "inherent-control-detection-engagement-fraud-noncompliance-and-significant-risk-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on inherent, control, detection, engagement, fraud, noncompliance and significant risk, under what ethics and authority?", "kind": "retention", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "inherent-control-detection-engagement-fraud-noncompliance-and-significant-risk-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify inherent, control, detection, engagement, fraud, noncompliance and significant risk?", "kind": "relationship", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "inherent-control-detection-engagement-fraud-noncompliance-and-significant-risk-data", "name": "Inherent, control, detection, engagement, fraud, noncompliance and significant risk data", "description": "Typed engagement data for inherent, control, detection, engagement, fraud, noncompliance and significant risk, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-011", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ] } ], "artifacts": [ { "id": "inherent-control-detection-engagement-fraud-noncompliance-and-significant-risk-record", "name": "Inherent, control, detection, engagement, fraud, noncompliance and significant risk record", "description": "Immutable or versioned evidence for inherent, control, detection, engagement, fraud, noncompliance and significant risk with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-003", "SRC-011", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "planning-procedures-evidence-and-documentation", "name": "Planning, procedures, evidence and documentation", "description": "Connect risk-responsive work to sufficient appropriate evidence and an immutable workpaper trail", "rationale": "Connect risk-responsive work to sufficient appropriate evidence and an immutable workpaper trail", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-016", "SRC-018", "SRC-005", "SRC-006", "SRC-021", "SRC-022", "SRC-023" ], "layers": [ { "id": "strategy-plan-program-procedure-and-sampling", "name": "Strategy, plan, program, procedure and sampling", "description": "Groups governed assertions about strategy, plan, program, procedure and sampling for the engagement.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-016", "SRC-018" ], "findings": [ { "id": "strategy-plan-milestone-procedure-nature-timing-extent-owner-and-status", "name": "Strategy, plan, milestone, procedure, nature, timing, extent, owner and status", "description": "Records strategy, plan, milestone, procedure, nature, timing, extent, owner and status as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-016", "SRC-018" ], "questions": [ { "id": "strategy-plan-milestone-procedure-nature-timing-extent-owner-and-status-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish strategy, plan, milestone, procedure, nature, timing, extent, owner and status?", "kind": "process", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "strategy-plan-milestone-procedure-nature-timing-extent-owner-and-status-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on strategy, plan, milestone, procedure, nature, timing, extent, owner and status, under what ethics and authority?", "kind": "access", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "strategy-plan-milestone-procedure-nature-timing-extent-owner-and-status-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify strategy, plan, milestone, procedure, nature, timing, extent, owner and status?", "kind": "state", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "strategy-plan-milestone-procedure-nature-timing-extent-owner-and-status-data", "name": "Strategy, plan, milestone, procedure, nature, timing, extent, owner and status data", "description": "Typed engagement data for strategy, plan, milestone, procedure, nature, timing, extent, owner and status, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-016", "SRC-018" ] } ], "artifacts": [ { "id": "strategy-plan-milestone-procedure-nature-timing-extent-owner-and-status-record", "name": "Strategy, plan, milestone, procedure, nature, timing, extent, owner and status record", "description": "Immutable or versioned evidence for strategy, plan, milestone, procedure, nature, timing, extent, owner and status with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-016", "SRC-018" ] } ], "inline_only_rationale": null }, { "id": "population-sampling-frame-unit-selection-method-size-deviation-and-projection", "name": "Population, sampling frame, unit, selection method, size, deviation and projection", "description": "Records population, sampling frame, unit, selection method, size, deviation and projection as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-016", "SRC-018" ], "questions": [ { "id": "population-sampling-frame-unit-selection-method-size-deviation-and-projection-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish population, sampling frame, unit, selection method, size, deviation and projection?", "kind": "measurement", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "population-sampling-frame-unit-selection-method-size-deviation-and-projection-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on population, sampling frame, unit, selection method, size, deviation and projection, under what ethics and authority?", "kind": "exception", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "population-sampling-frame-unit-selection-method-size-deviation-and-projection-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify population, sampling frame, unit, selection method, size, deviation and projection?", "kind": "lifecycle", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "population-sampling-frame-unit-selection-method-size-deviation-and-projection-data", "name": "Population, sampling frame, unit, selection method, size, deviation and projection data", "description": "Typed engagement data for population, sampling frame, unit, selection method, size, deviation and projection, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-016", "SRC-018" ] } ], "artifacts": [ { "id": "population-sampling-frame-unit-selection-method-size-deviation-and-projection-record", "name": "Population, sampling frame, unit, selection method, size, deviation and projection record", "description": "Immutable or versioned evidence for population, sampling frame, unit, selection method, size, deviation and projection with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-016", "SRC-018" ] } ], "inline_only_rationale": null } ] }, { "id": "evidence-source-procedure-and-workpaper", "name": "Evidence, source, procedure and workpaper", "description": "Groups governed assertions about evidence, source, procedure and workpaper for the engagement.", "source_refs": [ "SRC-005", "SRC-006", "SRC-012", "SRC-018", "SRC-021", "SRC-022", "SRC-023" ], "findings": [ { "id": "evidence-item-source-assertion-procedure-relevance-reliability-and-contradiction", "name": "Evidence item, source, assertion, procedure, relevance, reliability and contradiction", "description": "Records evidence item, source, assertion, procedure, relevance, reliability and contradiction as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-005", "SRC-006", "SRC-012", "SRC-018", "SRC-021", "SRC-022", "SRC-023" ], "questions": [ { "id": "evidence-item-source-assertion-procedure-relevance-reliability-and-contradiction-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish evidence item, source, assertion, procedure, relevance, reliability and contradiction?", "kind": "evidence", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "evidence-item-source-assertion-procedure-relevance-reliability-and-contradiction-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on evidence item, source, assertion, procedure, relevance, reliability and contradiction, under what ethics and authority?", "kind": "interoperability", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "evidence-item-source-assertion-procedure-relevance-reliability-and-contradiction-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify evidence item, source, assertion, procedure, relevance, reliability and contradiction?", "kind": "temporal", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "evidence-item-source-assertion-procedure-relevance-reliability-and-contradiction-data", "name": "Evidence item, source, assertion, procedure, relevance, reliability and contradiction data", "description": "Typed engagement data for evidence item, source, assertion, procedure, relevance, reliability and contradiction, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006", "SRC-012", "SRC-018", "SRC-021", "SRC-022", "SRC-023" ] } ], "artifacts": [ { "id": "evidence-item-source-assertion-procedure-relevance-reliability-and-contradiction-record", "name": "Evidence item, source, assertion, procedure, relevance, reliability and contradiction record", "description": "Immutable or versioned evidence for evidence item, source, assertion, procedure, relevance, reliability and contradiction with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-005", "SRC-006", "SRC-012", "SRC-018", "SRC-021", "SRC-022", "SRC-023" ] } ], "inline_only_rationale": null }, { "id": "workpaper-index-preparer-reviewer-cross-reference-digest-sign-off-and-lock", "name": "Workpaper index, preparer, reviewer, cross-reference, digest, sign-off and lock", "description": "Records workpaper index, preparer, reviewer, cross-reference, digest, sign-off and lock as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-005", "SRC-006", "SRC-012", "SRC-018", "SRC-021", "SRC-022", "SRC-023" ], "questions": [ { "id": "workpaper-index-preparer-reviewer-cross-reference-digest-sign-off-and-lock-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish workpaper index, preparer, reviewer, cross-reference, digest, sign-off and lock?", "kind": "provenance", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "workpaper-index-preparer-reviewer-cross-reference-digest-sign-off-and-lock-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on workpaper index, preparer, reviewer, cross-reference, digest, sign-off and lock, under what ethics and authority?", "kind": "decision", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "workpaper-index-preparer-reviewer-cross-reference-digest-sign-off-and-lock-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify workpaper index, preparer, reviewer, cross-reference, digest, sign-off and lock?", "kind": "provenance", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "workpaper-index-preparer-reviewer-cross-reference-digest-sign-off-and-lock-data", "name": "Workpaper index, preparer, reviewer, cross-reference, digest, sign-off and lock data", "description": "Typed engagement data for workpaper index, preparer, reviewer, cross-reference, digest, sign-off and lock, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006", "SRC-012", "SRC-018", "SRC-021", "SRC-022", "SRC-023" ] } ], "artifacts": [ { "id": "workpaper-index-preparer-reviewer-cross-reference-digest-sign-off-and-lock-record", "name": "Workpaper index, preparer, reviewer, cross-reference, digest, sign-off and lock record", "description": "Immutable or versioned evidence for workpaper index, preparer, reviewer, cross-reference, digest, sign-off and lock with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-005", "SRC-006", "SRC-012", "SRC-018", "SRC-021", "SRC-022", "SRC-023" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "findings-evaluation-conclusion-and-reporting", "name": "Findings, evaluation, conclusion and reporting", "description": "Preserve observations, management responses and criteria-scoped conclusions without overstating assurance", "rationale": "Preserve observations, management responses and criteria-scoped conclusions without overstating assurance", "source_refs": [ "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-018", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-013" ], "layers": [ { "id": "findings-misstatements-deficiencies-and-responses", "name": "Findings, misstatements, deficiencies and responses", "description": "Groups governed assertions about findings, misstatements, deficiencies and responses for the engagement.", "source_refs": [ "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ], "findings": [ { "id": "condition-criterion-cause-effect-finding-misstatement-deviation-and-noncompliance", "name": "Condition, criterion, cause, effect, finding, misstatement, deviation and noncompliance", "description": "Records condition, criterion, cause, effect, finding, misstatement, deviation and noncompliance as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ], "questions": [ { "id": "condition-criterion-cause-effect-finding-misstatement-deviation-and-noncompliance-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish condition, criterion, cause, effect, finding, misstatement, deviation and noncompliance?", "kind": "evidence", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "condition-criterion-cause-effect-finding-misstatement-deviation-and-noncompliance-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on condition, criterion, cause, effect, finding, misstatement, deviation and noncompliance, under what ethics and authority?", "kind": "identity", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "condition-criterion-cause-effect-finding-misstatement-deviation-and-noncompliance-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify condition, criterion, cause, effect, finding, misstatement, deviation and noncompliance?", "kind": "ownership", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "condition-criterion-cause-effect-finding-misstatement-deviation-and-noncompliance-data", "name": "Condition, criterion, cause, effect, finding, misstatement, deviation and noncompliance data", "description": "Typed engagement data for condition, criterion, cause, effect, finding, misstatement, deviation and noncompliance, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ] } ], "artifacts": [ { "id": "condition-criterion-cause-effect-finding-misstatement-deviation-and-noncompliance-record", "name": "Condition, criterion, cause, effect, finding, misstatement, deviation and noncompliance record", "description": "Immutable or versioned evidence for condition, criterion, cause, effect, finding, misstatement, deviation and noncompliance with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ] } ], "inline_only_rationale": null }, { "id": "corrected-uncorrected-deficiency-significant-deficiency-material-weakness-response-and-action", "name": "Corrected, uncorrected, deficiency, significant deficiency, material weakness, response and action", "description": "Records corrected, uncorrected, deficiency, significant deficiency, material weakness, response and action as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ], "questions": [ { "id": "corrected-uncorrected-deficiency-significant-deficiency-material-weakness-response-and-action-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish corrected, uncorrected, deficiency, significant deficiency, material weakness, response and action?", "kind": "state", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "corrected-uncorrected-deficiency-significant-deficiency-material-weakness-response-and-action-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on corrected, uncorrected, deficiency, significant deficiency, material weakness, response and action, under what ethics and authority?", "kind": "classification", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "corrected-uncorrected-deficiency-significant-deficiency-material-weakness-response-and-action-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify corrected, uncorrected, deficiency, significant deficiency, material weakness, response and action?", "kind": "authority", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "corrected-uncorrected-deficiency-significant-deficiency-material-weakness-response-and-action-data", "name": "Corrected, uncorrected, deficiency, significant deficiency, material weakness, response and action data", "description": "Typed engagement data for corrected, uncorrected, deficiency, significant deficiency, material weakness, response and action, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ] } ], "artifacts": [ { "id": "corrected-uncorrected-deficiency-significant-deficiency-material-weakness-response-and-action-record", "name": "Corrected, uncorrected, deficiency, significant deficiency, material weakness, response and action record", "description": "Immutable or versioned evidence for corrected, uncorrected, deficiency, significant deficiency, material weakness, response and action with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-003", "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ] } ], "inline_only_rationale": null } ] }, { "id": "evaluation-conclusion-opinion-report-and-communication", "name": "Evaluation, conclusion, opinion, report and communication", "description": "Groups governed assertions about evaluation, conclusion, opinion, report and communication for the engagement.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-010", "SRC-013", "SRC-014", "SRC-015" ], "findings": [ { "id": "sufficiency-appropriateness-materiality-aggregation-unresolved-matter-and-overall-evaluation", "name": "Sufficiency, appropriateness, materiality, aggregation, unresolved matter and overall evaluation", "description": "Records sufficiency, appropriateness, materiality, aggregation, unresolved matter and overall evaluation as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-010", "SRC-013", "SRC-014", "SRC-015" ], "questions": [ { "id": "sufficiency-appropriateness-materiality-aggregation-unresolved-matter-and-overall-evaluation-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish sufficiency, appropriateness, materiality, aggregation, unresolved matter and overall evaluation?", "kind": "decision", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "sufficiency-appropriateness-materiality-aggregation-unresolved-matter-and-overall-evaluation-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on sufficiency, appropriateness, materiality, aggregation, unresolved matter and overall evaluation, under what ethics and authority?", "kind": "composition", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "sufficiency-appropriateness-materiality-aggregation-unresolved-matter-and-overall-evaluation-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify sufficiency, appropriateness, materiality, aggregation, unresolved matter and overall evaluation?", "kind": "requirement", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "sufficiency-appropriateness-materiality-aggregation-unresolved-matter-and-overall-evaluation-data", "name": "Sufficiency, appropriateness, materiality, aggregation, unresolved matter and overall evaluation data", "description": "Typed engagement data for sufficiency, appropriateness, materiality, aggregation, unresolved matter and overall evaluation, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-010", "SRC-013", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "sufficiency-appropriateness-materiality-aggregation-unresolved-matter-and-overall-evaluation-record", "name": "Sufficiency, appropriateness, materiality, aggregation, unresolved matter and overall evaluation record", "description": "Immutable or versioned evidence for sufficiency, appropriateness, materiality, aggregation, unresolved matter and overall evaluation with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-010", "SRC-013", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "reasonable-limited-none-unmodified-qualified-adverse-disclaimer-emphasis-and-other-matter", "name": "Reasonable, limited, none, unmodified, qualified, adverse, disclaimer, emphasis and other matter", "description": "Records reasonable, limited, none, unmodified, qualified, adverse, disclaimer, emphasis and other matter as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-010", "SRC-013", "SRC-014", "SRC-015" ], "questions": [ { "id": "reasonable-limited-none-unmodified-qualified-adverse-disclaimer-emphasis-and-other-matter-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish reasonable, limited, none, unmodified, qualified, adverse, disclaimer, emphasis and other matter?", "kind": "classification", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "reasonable-limited-none-unmodified-qualified-adverse-disclaimer-emphasis-and-other-matter-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on reasonable, limited, none, unmodified, qualified, adverse, disclaimer, emphasis and other matter, under what ethics and authority?", "kind": "relationship", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "reasonable-limited-none-unmodified-qualified-adverse-disclaimer-emphasis-and-other-matter-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify reasonable, limited, none, unmodified, qualified, adverse, disclaimer, emphasis and other matter?", "kind": "constraint", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "reasonable-limited-none-unmodified-qualified-adverse-disclaimer-emphasis-and-other-matter-data", "name": "Reasonable, limited, none, unmodified, qualified, adverse, disclaimer, emphasis and other matter data", "description": "Typed engagement data for reasonable, limited, none, unmodified, qualified, adverse, disclaimer, emphasis and other matter, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-010", "SRC-013", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "reasonable-limited-none-unmodified-qualified-adverse-disclaimer-emphasis-and-other-matter-record", "name": "Reasonable, limited, none, unmodified, qualified, adverse, disclaimer, emphasis and other matter record", "description": "Immutable or versioned evidence for reasonable, limited, none, unmodified, qualified, adverse, disclaimer, emphasis and other matter with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-010", "SRC-013", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "lifecycle-follow-up-governance-and-interoperability", "name": "Lifecycle, follow-up, governance and interoperability", "description": "Issue, communicate, archive and follow up with qualified provenance, access and loss-aware projections", "rationale": "Issue, communicate, archive and follow up with qualified provenance, access and loss-aware projections", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-010", "SRC-013", "SRC-014", "SRC-017", "SRC-018", "SRC-009", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ], "layers": [ { "id": "issuance-communication-follow-up-and-archive", "name": "Issuance, communication, follow-up and archive", "description": "Groups governed assertions about issuance, communication, follow-up and archive for the engagement.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-010", "SRC-013", "SRC-014", "SRC-017", "SRC-018" ], "findings": [ { "id": "draft-review-approval-signature-issue-release-distribution-restriction-and-withdrawal", "name": "Draft, review, approval, signature, issue, release, distribution, restriction and withdrawal", "description": "Records draft, review, approval, signature, issue, release, distribution, restriction and withdrawal as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-010", "SRC-013", "SRC-014", "SRC-017", "SRC-018" ], "questions": [ { "id": "draft-review-approval-signature-issue-release-distribution-restriction-and-withdrawal-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish draft, review, approval, signature, issue, release, distribution, restriction and withdrawal?", "kind": "lifecycle", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "draft-review-approval-signature-issue-release-distribution-restriction-and-withdrawal-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on draft, review, approval, signature, issue, release, distribution, restriction and withdrawal, under what ethics and authority?", "kind": "state", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "draft-review-approval-signature-issue-release-distribution-restriction-and-withdrawal-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify draft, review, approval, signature, issue, release, distribution, restriction and withdrawal?", "kind": "process", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "draft-review-approval-signature-issue-release-distribution-restriction-and-withdrawal-data", "name": "Draft, review, approval, signature, issue, release, distribution, restriction and withdrawal data", "description": "Typed engagement data for draft, review, approval, signature, issue, release, distribution, restriction and withdrawal, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-010", "SRC-013", "SRC-014", "SRC-017", "SRC-018" ] } ], "artifacts": [ { "id": "draft-review-approval-signature-issue-release-distribution-restriction-and-withdrawal-record", "name": "Draft, review, approval, signature, issue, release, distribution, restriction and withdrawal record", "description": "Immutable or versioned evidence for draft, review, approval, signature, issue, release, distribution, restriction and withdrawal with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-010", "SRC-013", "SRC-014", "SRC-017", "SRC-018" ] } ], "inline_only_rationale": null }, { "id": "governance-communication-recommendation-action-owner-due-status-verification-and-closure", "name": "Governance communication, recommendation, action, owner, due, status, verification and closure", "description": "Records governance communication, recommendation, action, owner, due, status, verification and closure as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-010", "SRC-013", "SRC-014", "SRC-017", "SRC-018" ], "questions": [ { "id": "governance-communication-recommendation-action-owner-due-status-verification-and-closure-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish governance communication, recommendation, action, owner, due, status, verification and closure?", "kind": "relationship", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "governance-communication-recommendation-action-owner-due-status-verification-and-closure-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on governance communication, recommendation, action, owner, due, status, verification and closure, under what ethics and authority?", "kind": "lifecycle", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "governance-communication-recommendation-action-owner-due-status-verification-and-closure-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify governance communication, recommendation, action, owner, due, status, verification and closure?", "kind": "event", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "governance-communication-recommendation-action-owner-due-status-verification-and-closure-data", "name": "Governance communication, recommendation, action, owner, due, status, verification and closure data", "description": "Typed engagement data for governance communication, recommendation, action, owner, due, status, verification and closure, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-010", "SRC-013", "SRC-014", "SRC-017", "SRC-018" ] } ], "artifacts": [ { "id": "governance-communication-recommendation-action-owner-due-status-verification-and-closure-record", "name": "Governance communication, recommendation, action, owner, due, status, verification and closure record", "description": "Immutable or versioned evidence for governance communication, recommendation, action, owner, due, status, verification and closure with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-010", "SRC-013", "SRC-014", "SRC-017", "SRC-018" ] } ], "inline_only_rationale": null } ] }, { "id": "provenance-access-retention-and-projection", "name": "Provenance, access, retention and projection", "description": "Groups governed assertions about provenance, access, retention and projection for the engagement.", "source_refs": [ "SRC-009", "SRC-014", "SRC-017", "SRC-018", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ], "findings": [ { "id": "source-actor-derivation-quality-confidence-conflict-event-time-and-knowledge-time", "name": "Source, actor, derivation, quality, confidence, conflict, event time and knowledge time", "description": "Records source, actor, derivation, quality, confidence, conflict, event time and knowledge time as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-009", "SRC-014", "SRC-017", "SRC-018", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ], "questions": [ { "id": "source-actor-derivation-quality-confidence-conflict-event-time-and-knowledge-time-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish source, actor, derivation, quality, confidence, conflict, event time and knowledge time?", "kind": "quality", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "source-actor-derivation-quality-confidence-conflict-event-time-and-knowledge-time-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on source, actor, derivation, quality, confidence, conflict, event time and knowledge time, under what ethics and authority?", "kind": "temporal", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "source-actor-derivation-quality-confidence-conflict-event-time-and-knowledge-time-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify source, actor, derivation, quality, confidence, conflict, event time and knowledge time?", "kind": "measurement", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "source-actor-derivation-quality-confidence-conflict-event-time-and-knowledge-time-data", "name": "Source, actor, derivation, quality, confidence, conflict, event time and knowledge time data", "description": "Typed engagement data for source, actor, derivation, quality, confidence, conflict, event time and knowledge time, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-014", "SRC-017", "SRC-018", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ] } ], "artifacts": [ { "id": "source-actor-derivation-quality-confidence-conflict-event-time-and-knowledge-time-record", "name": "Source, actor, derivation, quality, confidence, conflict, event time and knowledge time record", "description": "Immutable or versioned evidence for source, actor, derivation, quality, confidence, conflict, event time and knowledge time with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-009", "SRC-014", "SRC-017", "SRC-018", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ] } ], "inline_only_rationale": null }, { "id": "owner-custodian-purpose-confidentiality-privilege-access-legal-hold-retention-and-mapping-loss", "name": "Owner, custodian, purpose, confidentiality, privilege, access, legal hold, retention and mapping loss", "description": "Records owner, custodian, purpose, confidentiality, privilege, access, legal hold, retention and mapping loss as source-qualified Audit / Assurance Engagement context while client, subject matter, criteria, statements, disclosures, controls, risks, issues, actions, regulator cases and records masters remain external.", "source_refs": [ "SRC-009", "SRC-014", "SRC-017", "SRC-018", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ], "questions": [ { "id": "owner-custodian-purpose-confidentiality-privilege-access-legal-hold-retention-and-mapping-loss-q01", "text": "Which stable engagement, version, kind, mandate, subject, criteria, scope, period and external-master identities establish owner, custodian, purpose, confidentiality, privilege, access, legal hold, retention and mapping loss?", "kind": "access", "answer_data": [ "engagement, version, appointment, engagement letter, subject, criteria, scope, period and master-system identifiers", "audit, review, assurance, agreed-upon procedures, internal, statutory, performance, compliance and sustainability classes", "proposed, accepted, planned, active, reviewed, completed, reported, archived, withdrawn and superseded states" ] }, { "id": "owner-custodian-purpose-confidentiality-privilege-access-legal-hold-retention-and-mapping-loss-q02", "text": "Who appoints, prepares, performs, supervises, reviews, evaluates, concludes, communicates or may rely on owner, custodian, purpose, confidentiality, privilege, access, legal hold, retention and mapping loss, under what ethics and authority?", "kind": "provenance", "answer_data": [ "appointing party, responsible party, measurer or evaluator, practitioner, partner, team, expert, reviewer, governance body and intended user", "mandate, professional standard, law, engagement terms, independence, competence, authorization, access and segregation of duties", "purpose, responsibility, confidentiality, restriction, limitation, exception, escalation and contestability" ] }, { "id": "owner-custodian-purpose-confidentiality-privilege-access-legal-hold-retention-and-mapping-loss-q03", "text": "Which assertion, criterion, risk, procedure, evidence, materiality, source, event time, knowledge time, uncertainty and successor lineage qualify owner, custodian, purpose, confidentiality, privilege, access, legal hold, retention and mapping loss?", "kind": "evidence", "answer_data": [ "subject-matter information, assertion, criterion, benchmark, materiality, risk, control, procedure, finding, conclusion and opinion", "evidence source, relevance, reliability, sufficiency, appropriateness, contradiction, limitation, representation and review", "period, procedure, review, report, issuance, observation, ingestion and knowledge times, predecessor, successor, retention and mapping loss" ] } ], "data_elements": [ { "id": "owner-custodian-purpose-confidentiality-privilege-access-legal-hold-retention-and-mapping-loss-data", "name": "Owner, custodian, purpose, confidentiality, privilege, access, legal hold, retention and mapping loss data", "description": "Typed engagement data for owner, custodian, purpose, confidentiality, privilege, access, legal hold, retention and mapping loss, qualified by source, criteria, authority, risk, materiality, procedure, evidence, time, access and provenance.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-009", "SRC-014", "SRC-017", "SRC-018", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ] } ], "artifacts": [ { "id": "owner-custodian-purpose-confidentiality-privilege-access-legal-hold-retention-and-mapping-loss-record", "name": "Owner, custodian, purpose, confidentiality, privilege, access, legal hold, retention and mapping loss record", "description": "Immutable or versioned evidence for owner, custodian, purpose, confidentiality, privilege, access, legal hold, retention and mapping loss with engagement identity, digest, source, professional-standard version, event and knowledge times, access marking and successor lineage.", "media_or_form": [ "application/yaml", "application/json", "application/pdf", "text/csv", "text/markdown", "text/html" ], "serial": true, "identity_strategy": "Prefer the authoritative firm, practitioner, client, regulator, repository or records identifier; otherwise use a governed IRI, then a Dimension UUID or ULID.", "source_refs": [ "SRC-009", "SRC-014", "SRC-017", "SRC-018", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "initialize-engagement", "name": "Initialize engagement", "description": "Governed operation to initialize engagement without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "appointment or mandate", "engagement-kind, subject, criteria, scope and period profile" ], "outputs": [ "bounded proposed engagement identity" ], "preconditions": [ "parties, authority, intended users and subject are known" ], "effects": [ "creates a proposed engagement without implying acceptance, independence or assurance" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-010", "SRC-014", "SRC-015" ] }, { "id": "accept-or-continue-engagement", "name": "Accept or continue engagement", "description": "Governed operation to accept or continue engagement without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "terms, competence, resources and integrity information", "ethics and independence evaluation" ], "outputs": [ "acceptance, continuation, decline or withdrawal record" ], "preconditions": [ "threats, safeguards, preconditions and authority are documented" ], "effects": [ "preserves unresolved limitations and never fabricates independence" ], "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-009", "SRC-011", "SRC-017" ] }, { "id": "bind-subject-criteria-and-materiality", "name": "Bind subject, criteria and materiality", "description": "Governed operation to bind subject, criteria and materiality without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "subject matter and subject-matter information", "criteria, framework and intended-user needs" ], "outputs": [ "versioned subject, criteria, scope and materiality assertions" ], "preconditions": [ "criteria suitability, availability, purpose and evidence are known" ], "effects": [ "does not turn a benchmark or management assertion into authoritative truth" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-012", "SRC-015" ] }, { "id": "assess-risks-and-controls", "name": "Assess risks and controls", "description": "Governed operation to assess risks and controls without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "entity, environment, processes, controls and assertions", "fraud, noncompliance and engagement-risk signals" ], "outputs": [ "risk and control assessment records" ], "preconditions": [ "risk method, source, level, rationale and reviewer are known" ], "effects": [ "keeps inherent, control, detection, fraud and engagement risks distinct" ], "source_refs": [ "SRC-003", "SRC-011", "SRC-012", "SRC-014", "SRC-018" ] }, { "id": "plan-and-perform-procedures", "name": "Plan and perform procedures", "description": "Governed operation to plan and perform procedures without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "assessed risks, objectives and materiality", "team, timing, sampling and access plan" ], "outputs": [ "procedure execution and exception records" ], "preconditions": [ "authorized plan, competent team, evidence access and safety controls exist" ], "effects": [ "records actual work separately from planned work and flags deviations" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-010", "SRC-012", "SRC-016", "SRC-018" ] }, { "id": "obtain-and-evaluate-evidence", "name": "Obtain and evaluate evidence", "description": "Governed operation to obtain and evaluate evidence without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "procedure result and candidate evidence", "assertion, criteria, risk and reliability profile" ], "outputs": [ "qualified evidence and sufficiency evaluation" ], "preconditions": [ "source, provenance, relevance, reliability, completeness and contradiction checks run" ], "effects": [ "never lets evidence quantity compensate silently for poor quality" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-012", "SRC-015", "SRC-022", "SRC-023" ] }, { "id": "record-findings-and-responses", "name": "Record findings and responses", "description": "Governed operation to record findings and responses without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "condition, criteria, evidence and effect", "management or responsible-party response" ], "outputs": [ "finding, misstatement, deficiency, recommendation and action reference" ], "preconditions": [ "source, severity method, ownership and communication rights are known" ], "effects": [ "preserves disagreement and never closes a matter solely on a promised action" ], "source_refs": [ "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-018" ] }, { "id": "form-conclusion-and-issue-report", "name": "Form conclusion and issue report", "description": "Governed operation to form conclusion and issue report without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "evaluated evidence, findings and unresolved matters", "engagement kind, assurance level and reporting rules" ], "outputs": [ "criteria-scoped conclusion or factual-findings report and issuance event" ], "preconditions": [ "sufficiency, appropriateness, materiality, review, authority and report controls pass" ], "effects": [ "does not overstate assurance or infer absence of fraud, error, noncompliance or future failure" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-013", "SRC-014" ] }, { "id": "monitor-actions-and-close", "name": "Monitor actions and close", "description": "Governed operation to monitor actions and close without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "issued report, recommendations and action references", "follow-up mandate and verification evidence" ], "outputs": [ "follow-up, residual-risk and closure assertions" ], "preconditions": [ "ownership, deadlines, verification scope and continuing obligations are known" ], "effects": [ "keeps management implementation, practitioner verification and risk acceptance separate" ], "source_refs": [ "SRC-010", "SRC-014", "SRC-015", "SRC-018" ] }, { "id": "archive-project-retain-and-audit", "name": "Archive, project, retain and audit", "description": "Governed operation to archive, project, retain and audit without autonomous appointment, independence, conclusion, opinion, publication or destruction authority.", "inputs": [ "engagement aggregate and target purpose", "access, archive, retention and conformance policy" ], "outputs": [ "locked file, minimum view, loss declaration, retention result or audit event" ], "preconditions": [ "digest, authority, confidentiality, privilege, legal-hold, clock and conformance checks pass" ], "effects": [ "never exposes unnecessary workpapers or cascades deletion into subject, issue, action or regulator masters" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ] } ], "composition": [ { "target": "WM-ACT-036", "relation": "REFERENCE", "purpose": "Preserve the semantically suspect Research Study parent signal only as a review hold, not as containment.", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-015" ] }, { "target": "WM-ACT-033 Review / Inspection / Audit and WM-ACT-034 Assessment / Evaluation", "relation": "REFERENCE", "purpose": "Reference generic process patterns without duplicating professional engagement authority and evidence semantics.", "required": false, "source_refs": [ "SRC-010", "SRC-014", "SRC-015", "SRC-016" ] }, { "target": "Organization, Person, Subject Matter, Criteria, Legal Norm, Statement, Disclosure, Control, Risk, Issue, Action, Regulator Case and Records models", "relation": "REFERENCE", "purpose": "Resolve external identity, rule, source, response and governance records without duplicating their lifecycles.", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-010", "SRC-012", "SRC-014", "SRC-015", "SRC-017", "SRC-022" ] }, { "target": "IAASB, IESBA, IIA, PCAOB, GAO, INTOSAI, ISO 19011 and EU statutory-audit profiles", "relation": "ALIGN", "purpose": "Project version-pinned professional and jurisdiction profiles with declared scope and semantic loss.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015", "SRC-016", "SRC-017", "SRC-018", "SRC-019", "SRC-020" ] }, { "target": "RFC 3339, PROV-O, DQV and ODRL", "relation": "ALIGN", "purpose": "Project temporal, provenance, quality and policy views without claiming universal conformance.", "required": false, "source_refs": [ "SRC-021", "SRC-022", "SRC-023", "SRC-024" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension owner, namespace authority and delegated engagement, professional, legal, ethics, privacy, security and records authorities", "Authoritative Organization, Person, Subject Matter, Criteria, Legal Norm, Statement, Disclosure, Control, Risk, Evidence, Issue, Action, Regulator Case and Records registries", "Approved financial audit, review, other assurance, sustainability assurance, internal audit, public-sector, management-system, statutory, performance and compliance profiles", "Acceptance, independence, planning, evidence, review, reporting, confidentiality, privilege, archive, retention and agent-operation policies" ], "namespace_guidance": "Mint engagement, version, term, party-role, risk, materiality, procedure, sample, evidence, workpaper, finding, conclusion, report, communication, follow-up and projection IDs; preserve every external master identifier.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize an engagement by authoritative firm, practitioner, client, appointment or regulator identifier, engagement kind, subject, criteria, scope, period and version head, never by filename, report date or digest alone.", "Canonicalize evidence items, workpapers, findings, conclusions, reports, communications and follow-up assertions separately from the engagement head." ], "patch_rules": [ "Extensions declare jurisdiction, professional standard, engagement kind, subject, criteria, risk, materiality, procedure, evidence, opinion, confidentiality and interoperability effects.", "Accepted terms, signed-off workpapers and issued reports are immutable; revision, correction, withdrawal and reissuance create linked successors with reason, authority and downstream impact.", "Never silently change parties, independence, subject, criteria, scope, period, materiality, risk, procedure, evidence, finding, conclusion, opinion, report restriction, access or external reference." ], "compatibility_rules": [ "Ignore additive fields only when engagement and version identity, terms, subject, criteria, scope, evidence chain, conclusion, states, clocks, authority, access and provenance survive.", "Every projection pins professional-standard, jurisdiction, criteria, report, language and schema versions and declares loss in evidence, opinion, lifecycle, confidentiality and authority semantics." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier for an engagement, workpaper, evidence item, finding, report, communication or records object, qualified by namespace and record kind.", "Governed globally resolvable engagement or artifact IRI.", "Dimension UUID or ULID when neither preceding identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; distinguish subject period, appointment, acceptance, procedure, evidence collection, review, sign-off, report, issuance, communication, follow-up, observation, ingestion and knowledge times whenever they differ.", "serial_naming_rule": "Use {engagement-id}--{engagement-version-id}--{workstream-or-component-id}--{artifact-kind}--{record-revision-id}.", "integrity_rule": "Store digest, media type, engagement and version IDs, actor, purpose, source, professional-standard, criteria, method and policy versions, materiality, assertion, procedure, evidence time, knowledge time, confidentiality, privilege, retention and provenance." }, "policies": [ "This model owns the governed audit or assurance engagement and evidence-to-conclusion chain, not client, subject, criteria, statement, disclosure, control, risk, issue, action, regulator case or records masters.", "Audit, review, assurance and agreed-upon procedures retain distinct objectives, evidence work and report semantics; factual findings are not assurance conclusions.", "Responsible-party assertion, practitioner evidence, finding, management response, conclusion, opinion and regulator decision remain separately sourced and authority-qualified.", "A clean or unmodified report is reasonable or limited assurance in the stated scope, not a guarantee or proof of absence of fraud, error, noncompliance or future failure.", "Agents cannot autonomously accept an engagement, assert independence, waive evidence, sign off workpapers, form or issue an opinion, disclose privileged material or destroy records without explicit delegated authority." ], "crud": { "read": [ "Resolve engagement, versions, terms, parties, ethics, independence, team, subject, criteria, materiality, risks, controls, plan, procedures, sampling, evidence, workpapers, findings, responses, conclusion, report, communications, follow-up, archive, access and projection loss." ], "create": [ "Bind engagement kind, appointment, parties, subject, criteria, scope, period, intended users and initial unknown acceptance and independence states before planning work." ], "update": [ "Append successor terms, independence evaluations, plans, procedures, evidence, reviews, findings, responses, conclusions, reports and follow-up records with reason, authority, source, event time and knowledge time." ], "delete": [ "Apply professional, legal, contractual, privilege, audit, legal-hold and Dimension retention policy; tombstone only the catalogue view and never cascade deletion to external masters." ] }, "roles": [ { "name": "Appointing party and client", "responsibilities": [ "Authorize scoped terms and access while remaining separate from the practitioner's conclusion." ] }, { "name": "Responsible party and measurer or evaluator", "responsibilities": [ "Own subject-matter information, assertions and representations under the applicable criteria." ] }, { "name": "Engagement partner and practitioner", "responsibilities": [ "Own acceptance, direction, evidence judgments, conclusion, report and overall engagement quality." ] }, { "name": "Engagement team, component practitioner and expert", "responsibilities": [ "Perform authorized procedures, document evidence and communicate limits and contradictions." ] }, { "name": "Reviewer and engagement quality reviewer", "responsibilities": [ "Objectively review significant judgments, workpapers, conclusions and unresolved differences before release." ] }, { "name": "Governance body and intended user", "responsibilities": [ "Receive scoped communications and reports without altering practitioner-owned conclusions." ] }, { "name": "Ethics, legal, privacy, security and records authority", "responsibilities": [ "Own independence, confidentiality, privilege, access, exception, archive and retention controls." ] } ], "access": { "default_rule": "Deny workpapers, evidence, personal, commercial, financial, security, investigation, legal, privileged and pre-issuance material unless purpose-bound policy permits the minimum necessary view.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Declared engagement, regulator, legal, quality-review, peer-review, investigation or public-report access must cite authority, scope, purpose, recipient and time limit and be logged." ], "audit_requirements": [ "Log actor, agent, role, purpose, engagement and version IDs, operation, authority, policy, RFC 3339 time, affected assertions, source revision and outcome without duplicating protected values or credentials." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension namespace, engagement, professional, ethics, independence, legal, privacy, security, privilege, archive, retention and agent policies.", "Read this engagement and linked party, subject, criteria, statement, disclosure, control, risk, evidence, issue, action, regulator case and records models before mutation." ] } }, "coverage": { "claim": "WM-ECO-035 covers a governed Audit / Assurance Engagement aggregate through engagement identity, class, mandate, terms, parties, ethics, independence, competence, quality, subject matter, criteria, assertions, materiality, risks, controls, planning, procedures, sampling, evidence, workpapers, findings, responses, evaluation, conclusion, opinion, reporting, communications, follow-up, archive, provenance, access and loss-aware projections. Engagement-family, jurisdiction, profession, sector, licensing, implementation-conformance and independent-review questions remain deferred.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Identity is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "classification and direct properties", "status": "covered", "notes": "Classification and direct properties is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Recognition and observation is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Capabilities and possible actions is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "composition", "status": "covered", "notes": "Composition is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "lifecycle", "status": "covered", "notes": "Lifecycle is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "relationships", "status": "covered", "notes": "Relationships is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "temporal", "status": "covered", "notes": "Temporal is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "spatial", "status": "not-applicable", "notes": "No intrinsic geometry is owned; jurisdiction, client, subject, evidence and work locations are external references when material." }, { "dimension": "provenance", "status": "covered", "notes": "Provenance is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "ownership", "status": "covered", "notes": "Ownership is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "validation", "status": "covered", "notes": "Validation is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "access", "status": "covered", "notes": "Access is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention and deletion is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "interoperability", "status": "covered", "notes": "Interoperability is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." }, { "dimension": "authority and ethics", "status": "covered", "notes": "Authority and ethics is explicit; engagement-kind, jurisdiction, professional-standard, subject, criteria and independent-review profiles remain held where applicable." } ], "known_omissions": [ "Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.", "WM-ACT-036 is a semantically suspect provisional parent signal because the registry names it Research Study; no settled WM-ECO-035 edge exists.", "Financial audit, review, other assurance, sustainability assurance, internal audit, public-sector, management-system, statutory, performance, compliance, sector and jurisdiction profiles need separate validation.", "Client, subject matter, criteria, statements, disclosures, controls, risks, evidence sources, issues, actions, regulator cases and retention remain adopting-Dimension profiles.", "IAASB, IESBA, IIA and ISO normative text carries licensing or access conditions; this model records public metadata and links, not copied standards.", "Every IAASB, IESBA, IIA, PCAOB, GAO, INTOSAI, ISO, EU, RFC, PROV, DQV and ODRL mapping needs exact release pins and conformance tests." ], "conflicts": [ "Audit, review, other assurance, sustainability assurance, internal audit, performance audit, compliance audit and agreed-upon procedures have different objectives and report semantics.", "Responsible-party assertion, evidence, finding, misstatement, deficiency, management response, practitioner conclusion, opinion and regulator decision are distinct assertions.", "Reasonable assurance, limited assurance, no assurance, unmodified, qualified, adverse and disclaimer are not one lifecycle axis.", "Independence, objectivity, competence, authorization, access and confidentiality are related but separately evidenced conditions.", "Sufficiency is evidence quantity and appropriateness is relevance and reliability; one does not automatically compensate for the other." ], "regional_assumptions": [ "Appointment, independence, professional standards, audit rights, reporting, privilege, regulator access, archive and retention depend on jurisdiction and engagement type.", "IAASB, PCAOB, IIA, GAO, INTOSAI, ISO and EU sources are scoped profiles and not universally co-applicable." ], "adversarial_checks": [ "Reject an engagement without a discriminator for audit, review, assurance, related service, internal or public-sector work.", "Reject an engagement that treats WM-ACT-036 Research Study as a settled parent or absorbs client, subject, issue, action or regulator masters.", "Reject a conclusion without suitable criteria, scoped subject matter, sufficient appropriate evidence, materiality where applicable and review lineage.", "Reject agreed-upon factual findings represented as assurance or a limited-assurance review represented as an audit.", "Reject an unmodified report as proof of absence of fraud, error, noncompliance or future failure.", "Reject a report correction that overwrites the issued predecessor or conceals original users and restrictions.", "Reject autonomous acceptance, independence, sign-off, opinion issuance, privileged disclosure or destruction without delegated authority." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The model owns one professional engagement and its evidence-to-conclusion lineage. Client, responsible party, practitioner organization, person, subject matter, criteria, legal norm, statement, disclosure, control, risk, evidence source, issue, remediation action, regulator case, decision, sanction and records remain external masters." }, "decisions": [ { "concept": "Audit / Assurance Engagement boundary", "disposition": "accepted-as-discriminated-engagement-aggregate", "rationale": "The aggregate owns professional terms, execution and evidence-to-conclusion lineage but requires an explicit engagement-kind discriminator and does not absorb external subject, party, criteria, issue, action or regulator masters." }, { "concept": "WM-ACT-036 parent signal", "disposition": "held-as-semantically-suspect-reference", "rationale": "The registry names WM-ACT-036 Research Study, so its provisional parent signal grants no containment, lifecycle or cascade authority for audit and assurance." }, { "concept": "WM-ACT-033 and WM-ACT-034 neighbors", "disposition": "accepted-as-generic-process-references", "rationale": "Generic review, inspection, audit, assessment and evaluation patterns may be referenced, while this aggregate retains professional engagement, ethics, evidence and report semantics." }, { "concept": "Audit, review, other assurance and agreed-upon procedures", "disposition": "accepted-as-distinct-engagement-classes", "rationale": "They have different objectives, work effort, evidence duties, assurance levels and report wording; factual findings are not an assurance conclusion." }, { "concept": "Reasonable, limited and no assurance", "disposition": "accepted-as-distinct-assurance-levels", "rationale": "These levels cannot be inferred from procedure count, report state or one another and remain explicit engagement properties." }, { "concept": "Subject matter, subject-matter information, criteria, evidence and conclusion", "disposition": "accepted-as-distinct-linked-objects", "rationale": "The engagement binds an external subject to suitable criteria, evaluates source-qualified evidence and issues a scoped conclusion without making any one object proof of another." }, { "concept": "Independence, objectivity, competence, authorization and access", "disposition": "accepted-as-separate-evidenced-conditions", "rationale": "Related professional conditions require distinct actors, declarations, threats, safeguards, decisions, periods and review evidence." }, { "concept": "Inherent, control, detection, engagement, fraud and noncompliance risk", "disposition": "accepted-as-distinct-risk-classes", "rationale": "Each risk retains its subject, assertion, source, likelihood, consequence, response, owner and assessment lineage." }, { "concept": "Sufficiency and appropriateness of evidence", "disposition": "accepted-as-separate-evaluation-dimensions", "rationale": "Sufficiency concerns quantity while appropriateness concerns relevance and reliability; quantity cannot silently cure unsuitable evidence." }, { "concept": "Finding, misstatement, deficiency, response, action and regulator decision", "disposition": "accepted-as-distinct-assertions", "rationale": "Practitioner observations, responsible-party responses, promised or completed remediation, verification and regulator outcomes retain independent identity and authority." }, { "concept": "Conclusion, opinion and report modifiers", "disposition": "accepted-as-engagement-class-qualified", "rationale": "Unmodified, qualified, adverse, disclaimer, emphasis and other-matter semantics depend on the applicable engagement and reporting framework and do not establish truth or absence of fraud." }, { "concept": "Issued workpapers, reports, corrections and withdrawals", "disposition": "accepted-as-append-only-successor-semantics", "rationale": "Issued terms, workpapers and reports remain immutable; correction, reissuance and withdrawal preserve predecessors, users, scope and reasons." }, { "concept": "Single-provider waiver and local no-tools audit", "disposition": "accepted-with-mandatory-hold", "rationale": "One bounded Claude Sonnet and one bounded Grok attempt each timed out after 120 seconds. Codex separately audited the frozen validated result and comparison without acquiring new facts, so assurance remains reviewable-draft." } ], "publicationHolds": [ "Absence-of-external-review hold: one Claude Sonnet and one Grok attempt for WM-ECO-035 each timed out after 120 seconds; no external result was admitted.", "Boundary hold: this aggregate owns the engagement and its evidence-to-conclusion lineage while party, subject, criteria, statement, disclosure, control, risk, source, issue, action, regulator and records masters remain external.", "Relation hold: WM-ACT-036 Research Study is a semantically suspect provisional parent signal and no settled WM-ECO-035 registry edge exists.", "Engagement-class hold: financial audit, review, other assurance, sustainability assurance, agreed-upon procedures, internal audit, public-sector, management-system, statutory, performance and compliance profiles need separate validation.", "Assurance hold: reasonable, limited and no assurance and direct and attestation engagements remain explicit and cannot be inferred from procedure or report state.", "Ethics hold: independence, objectivity, competence, authorization, confidentiality, access, threats, safeguards and breaches remain separately evidenced and jurisdiction-qualified.", "Evidence hold: sufficiency and appropriateness, relevance and reliability, source and assertion, contradiction and resolution remain distinct and reviewable.", "Authority hold: responsible-party assertion, management representation, practitioner conclusion, opinion, approval and regulator decision do not prove one another.", "Lifecycle hold: appointment, acceptance, planning, execution, completion, reporting, issuance, follow-up and archive states remain separately timestamped and authorized.", "Outcome hold: an unmodified or clean report is not a guarantee and does not prove absence of fraud, error, noncompliance or future failure.", "Source-access hold: IAASB, IESBA, IIA and ISO normative text carries licensing or access conditions; public metadata and official links were used without redistributing standards.", "Interoperability hold: every professional, jurisdiction, temporal, provenance, quality and policy projection needs exact release pins, conformance evidence and loss declarations.", "Review hold: audit, assurance, ethics, legal, regulatory, privacy, security, records and independent external review are outstanding.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Canonically adjudicate the WM-ACT-036 parent signal and register relations to generic audit, assessment, party, subject, criteria, statement, disclosure, control, risk, source, issue, action, regulator and records models.", "Create independently validated financial audit, review, other assurance, sustainability assurance, agreed-upon procedures, internal audit, public-sector, management-system, statutory, performance, compliance, sector and jurisdiction profiles.", "Benchmark acceptance, independence, materiality, risk assessment, control reliance, sampling, evidence evaluation, workpaper review, findings, opinion modification, communications, follow-up and archive controls.", "Validate jurisdiction, profession, entity class, appointment, licensing, privilege, regulator access, reporting, distribution, external inspection and retention policies.", "Pin exact external releases and licensing conditions and obtain independent audit, assurance, ethics, legal, privacy, security and records review before promotion beyond reviewable-draft assurance." ] }, "statistics": { "sources": 24, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }