Appearance
Auditor Playbook
This playbook defines the operational workflows, key workspaces, verification tools, and governance principles for Internal and External Auditors (auditor) inspecting records in OrviQ.
1. What This Role Does in OrviQ
The Auditor conducts independent, objective evaluations of the organization's governance, risk, and control operations.
In OrviQ, the audit experience is designed around defensibility and end-to-end lineage:
- Auditors inspect immutable registers across regulations, policies, controls, risks, and evidence.
- They validate complete forward traceability (from high-level statutory circulars down to individual evidence files) and reverse traceability (from operational controls back to governing mandates).
- They verify cryptographic data integrity (SHA-256 evidence hashes and immutable change logs).
- They formulate audit workpapers, manage audit engagements, and record formal audit findings (
AUD-YYYY-NNNN).
2. Primary Workspaces
Auditors operate primarily within independent inspection modules:
| Workspace | Route | Key Activities |
|---|---|---|
| Audit Management | /audit | Plan audit engagements, manage fieldwork workpapers, sample records, and record audit findings. |
| Regulatory Inspections | /inspections | Manage regulatory exam requests, coordinate response packages, and track regulator inquiries. |
| Control Register & Crosswalk | /controls, /crosswalk | Inspect internal control charters, frequencies, owner assignments, and crosswalk linkages. |
| Evidence Register | /evidence | Inspect uploaded artifacts, examine SHA-256 hashes, review observation periods, and check approvals. |
| Policy Library & Lineage | /governance/library | Inspect published policy versions, atomic statements, and forward lineage graphs. |
| Enterprise Audit Log | /admin/audit-log | Review tenant-wide immutable decision histories, login events, and workflow transitions. |
3. Typical Operating Workflow
Engagement Planning & Scoping
- Define Audit Scope: In Audit & Inspection > Audit Management (
/audit), create a new audit engagement. Specify the target scope, business entities, governing frameworks, and testing periods. - Review Scoping & Applicability: Inspect Scope & Applicability (
/scope-applicability) to verify that the entity's declared Statement of Applicability aligns with organizational mandates.
Fieldwork & Substantive Testing
- Trace Lineage from Mandate to Control: Open Regulatory Compliance > Requirements (
/requirements) or Control Crosswalk (/crosswalk). Select a sampled requirement. Examine the forward lineage drawer: $$\text{Regulation} \longrightarrow \text{Requirement} \longrightarrow \text{Policy Statement} \longrightarrow \text{Control} \longrightarrow \text{Evidence}$$ - Execute Reverse Traceability: Open the reverse traceability lookup (
/api/policies/traceability/reverseor through the control drawer). For a sampled operational control, verify which exact published policy statements and regulatory obligations mandate its execution. - Inspect Evidence Integrity: Open Controls & Assurance > Evidence Register (
/evidence). For sampled evidence files:- Verify the cryptographic SHA-256 hash against source systems.
- Verify that the artifact's observation period covers the audited timeframe.
- Inspect the approval timestamp and confirm that the approver was independent of the uploader (maker-checker validation).
- Inspect Decision & Workflow History: Open the Audit Trail tab on any sampled record. Review point-in-time transitions, stage approvals, rationale entries, and return-for-rework notes.
Reporting & Finding Issuance
- Record Audit Findings: When an audit test reveals an unmitigated deficiency or missing evidence, record an official finding directly in Audit Management (
/audit). - Classify Finding Severity: Assign finding severity (Low, Medium, High, Critical) and attribute the root cause (design deficiency vs operating failure).
- Track Management Remediation: Monitor management action plans and milestone delivery in
/action-plans.
4. Approvals & Segregation-of-Duties (SoD) Boundaries
OrviQ enforces strict independence boundaries for auditors:
- Strict Read-Only Operational Authority: The
auditorrole has read-only visibility across operational registers (policies, controls, risks, crosswalks, evidence). Auditors cannot edit controls, approve evidence, mutate risk scores, or grant exceptions. - Audit Workpaper Autonomy: Audit workpapers and audit finding records are managed independently within the Audit domain, ensuring management cannot alter auditor observations.
- SoD Ledger Defensibility: All segregation-of-duties decisions (who submitted, who reviewed, who approved) are immutably logged and cannot be purged or overwritten by tenant administrators.
5. What the System Does NOT Imply
Auditors must preserve semantic distinctions in their working papers:
Semantic Guardrails
- Traceability $\neq$ Effectiveness: Demonstrating complete lineage from a regulatory mandate to an operational control proves structural design; it does not prove the control operated effectively.
- System Determination $\neq$ Audit Opinion: System status indicators (such as "Assessed" or "Coverage 100%") reflect software tracking calculations; they do not substitute for an independent audit opinion.
- Evidence Uploaded $\neq$ Evidence Sufficient: The presence of an artifact in the register indicates collection; audit testing must independently evaluate whether the evidence is substantively sufficient.
- Audit Access $\neq$ Audit Sign-Off: Reviewing records in the audit workspace does not constitute formal audit certification until the audit engagement is officially signed off.