Audit and assurance workflows
Gamut separates six assurance records so evidence, testing, deficiencies, reporting and system activity are not collapsed into a single score.
| Area | Primary question |
|---|---|
| Evidence Tracker | What proof has been requested, received, reviewed and linked? |
| Testing Centre | Did the control operate as designed for the sampled period and scope? |
| Findings Register | What deficiency, exception or uncertainty remains? |
| Workpaper Packs | Can another reviewer reproduce the assurance conclusion? |
| Board Dashboard | What exposure, trend and decision requires leadership attention? |
| Audit Trail | Who changed which governed record, and when? |
Evidence Tracker
Section titled “Evidence Tracker”Define the exact claim, framework item, system, owner, requested artifact and period. Record source, version, receipt date, reviewer and sufficiency decision. An attachment alone is not sufficient: explain what it proves, what it does not prove and whether it is current.
Reject or qualify evidence that is generic, self-authored without corroboration, outside the assessment period, scoped to another system or contradicted by tests.
Testing Centre
Section titled “Testing Centre”A control test should identify objective, population, sample, procedure, expected result, actual result, exceptions and reviewer. Distinguish design adequacy from operating effectiveness. A policy can demonstrate design but usually cannot prove repeated operation.
Failed or inconclusive tests should create or update a finding and, where material, a risk. Retests must preserve the original result and show the corrective action assessed.
Findings Register
Section titled “Findings Register”State the condition, expected criterion, cause, consequence, affected scope and supporting evidence. Assign severity, owner, due date and status. Management response, remediation and closure evidence remain separate decisions. Closing a task is not the same as validating the finding.
Workpaper Packs
Section titled “Workpaper Packs”Select the correct system, framework, period and purpose. Before export, confirm scope, evidence links, reviewer sign-off, open limitations and generation metadata. Packs are point-in-time artifacts; regenerate after material source changes.
Board Dashboard
Section titled “Board Dashboard”Use it to communicate exposure, trends, overdue high-severity work, material exceptions and decisions. Avoid presenting coverage or maturity as legal compliance. Drill into source records before acting on an aggregate.
Audit Trail
Section titled “Audit Trail”Use the Audit Trail to investigate state changes and decision history. It supports accountability but does not prove the substantive correctness of the decision. Restrict access, export only what is needed and preserve retention requirements.
End-to-end closure
Section titled “End-to-end closure”- Assessment identifies a claim or gap.
- Evidence is requested and reviewed.
- A test evaluates operation.
- Exceptions become findings and risks where appropriate.
- Remediation is completed and retested.
- A reviewer closes or qualifies the finding.
- Workpapers and board reporting preserve the relevant conclusion and limitations.