Skip to content

Inspection Items

An examination report is prose. An inspection item is one confirmed, authoritative observation from it, with an owner, a due date and a link to whatever will fix it.


Candidates and items

CandidateItem
What it isA proposed observation extracted from a documentA confirmed authoritative observation
Created byExtraction, AI-assistedA person confirming a candidate, or creating one manually
AuthorityNoneFull
Can be rejectedYesClosed rather than rejected

A candidate is not an observation until a person confirms it

AI extracts and suggests with complete provenance. It never silently creates authoritative records. An authorised person must explicitly confirm each candidate.


Candidate extraction

Uploading an examination report and running extraction produces candidates, each carrying:

FieldPurpose
Source document and locationWhere in the report it came from
Extracted textWhat the extractor read
Original wordingThe authority's exact words
ClassificationA suggested category
ConfidenceThe extractor's assessed confidence
ProvenanceWhich model, which pass
StatusPending, confirmed or rejected

Requires inspection.extract.


Confirming a candidate

Confirming a candidate creates an item and, at the same time, canonicalises it into the platform's ordinary GRC objects:

Canonical recordWhen it is created or linked
Finding (FND-YYYY-NNNN)Where the observation identifies a deficiency
Action Plan (ACT-YYYY-NNNN)Where remediation is committed
Control (CTL-...)Where a new or amended control is required
RequirementWhere the observation reflects an obligation you should be tracking
EvidenceWhere evidence is linked to demonstrate the position

This is the point of the module. A regulator's observation becomes a tracked finding with an owner and a due date, in the same register as everything else — not a row in a separate remediation spreadsheet.

Requires inspection.canonicalize.


What an item carries

FieldPurpose
OrdinalIts number in the report
Verbatim wordingThe authority's exact words
Internal interpretationYour technical reading
ClassificationThe observation category
Department and ownerWho is accountable
Due dateWhen remediation is committed
Linked finding, actions, control, requirementThe canonical records
Validation stateunvalidated, internally_validated or independent_validated
Closure notesThe governed closure record

Dual wording

The verbatim wording and the internal interpretation are separate fields and stay separate.

This is more useful than it sounds. Internal interpretations drift — an observation about "inadequate oversight of material outsourcing" gets internally translated into "update the outsourcing register", and six months later the remediation addresses the translation rather than the observation. Keeping both visible prevents that.


Governed item closure

Completing an action does not close an inspection item

An item closes only through explicit governed closure with a recorded validation state. Completing the linked action plan is necessary and not sufficient.

Equally: a submitted formal response may legitimately coexist with open findings and actions still in progress. Responding is not remediating.

Validation states

StateMeaning
unvalidatedRemediation reported, not validated
internally_validatedValidated by a second line function
independent_validatedValidated by internal audit or another independent party

Requires inspection.canonicalize for item management, and the closure action to record the validation state.


Manual items

Not every observation arrives in a document. Items raised in a meeting, in a phone call or in a supervisory letter can be created manually with the same fields and the same governance.


Permissions

ActionPermission
View candidates, items and responsesinspection.read
Manage inspections and create manual itemsinspection.manage
Ingest reports and run extractioninspection.extract
Confirm candidates and canonicaliseinspection.canonicalize
Generate AI advisory extractionsinspection.ai_assist

Example

Inspection INS-2026-0002, draft observations received 3 April: 9 observations.

Extraction proposes 14 candidates from the letter. Review:

OutcomeCountReason
Confirmed as items9Match the authority's numbered observations
Rejected4Contextual narrative, not observations
Merged1Restated an observation already captured

Item 4:

FieldValue
Verbatim wording"The firm's register of material outsourcing arrangements did not include three arrangements identified during the review which, in the supervisor's assessment, meet the materiality threshold."
Internal interpretation"Three arrangements classified internally as non-material meet the supervisor's threshold. The gap is in our materiality assessment criteria, not in register maintenance."
ClassificationGovernance and record-keeping
OwnerHead of Third-Party Risk
Due date90 days
Linked findingFND-2026-0134
Linked actionsACT-2026-0241 reclassify the three arrangements; ACT-2026-0242 revise materiality criteria

The internal interpretation is doing real work here. The observation reads as a register maintenance failure; the internal analysis identifies it as a criteria problem. Both are on the record, and the two action plans address the criteria rather than only the three arrangements.

Closure: both actions completed and verified at day 71. The item closed at day 84 with internally_validated after the second line confirmed the revised criteria had been applied across the whole engagement population — not just the three arrangements named.


Troubleshooting

"Extraction produced nothing." The document could not be converted to text, or the AI entitlement is unavailable. Items can always be created manually.

"A candidate has the wrong wording." Correct it during confirmation. The verbatim field should match the authority's document exactly.

"An item will not close." Governed closure requires a validation state to be recorded. Completing the actions is not sufficient.

"I cannot confirm a candidate." Requires inspection.canonicalize.


OrviQ Enterprise Governance, Risk & Compliance Platform