Skip to content

Audit and assurance workflows

Gamut separates six assurance records so evidence, testing, deficiencies, reporting and system activity are not collapsed into a single score.

AreaPrimary question
Evidence TrackerWhat proof has been requested, received, reviewed and linked?
Testing CentreDid the control operate as designed for the sampled period and scope?
Findings RegisterWhat deficiency, exception or uncertainty remains?
Workpaper PacksCan another reviewer reproduce the assurance conclusion?
Board DashboardWhat exposure, trend and decision requires leadership attention?
Audit TrailWho changed which governed record, and when?

Define the exact claim, framework item, system, owner, requested artifact and period. Record source, version, receipt date, reviewer and sufficiency decision. An attachment alone is not sufficient: explain what it proves, what it does not prove and whether it is current.

Reject or qualify evidence that is generic, self-authored without corroboration, outside the assessment period, scoped to another system or contradicted by tests.

A control test should identify objective, population, sample, procedure, expected result, actual result, exceptions and reviewer. Distinguish design adequacy from operating effectiveness. A policy can demonstrate design but usually cannot prove repeated operation.

Failed or inconclusive tests should create or update a finding and, where material, a risk. Retests must preserve the original result and show the corrective action assessed.

State the condition, expected criterion, cause, consequence, affected scope and supporting evidence. Assign severity, owner, due date and status. Management response, remediation and closure evidence remain separate decisions. Closing a task is not the same as validating the finding.

Select the correct system, framework, period and purpose. Before export, confirm scope, evidence links, reviewer sign-off, open limitations and generation metadata. Packs are point-in-time artifacts; regenerate after material source changes.

Use it to communicate exposure, trends, overdue high-severity work, material exceptions and decisions. Avoid presenting coverage or maturity as legal compliance. Drill into source records before acting on an aggregate.

Use the Audit Trail to investigate state changes and decision history. It supports accountability but does not prove the substantive correctness of the decision. Restrict access, export only what is needed and preserve retention requirements.

  1. Assessment identifies a claim or gap.
  2. Evidence is requested and reviewed.
  3. A test evaluates operation.
  4. Exceptions become findings and risks where appropriate.
  5. Remediation is completed and retested.
  6. A reviewer closes or qualifies the finding.
  7. Workpapers and board reporting preserve the relevant conclusion and limitations.