Appearance
Audit Phase
Audit is where you validate the current state and package it for internal readiness review. The goal is not a last-minute scramble, but a confirmable snapshot backed by Evidence and audit trail.
ScopeDefine the system and governance scope
ImplementExecute Controls and attach Evidence
MonitorKeep governance continuously current
AuditPrepare internal review and exports
Outcome
You leave this phase with:
- a validated readiness snapshot (Requirements, Controls, Evidence)
- exports that represent the current state
- an audit trail that supports internal assurance review
Time to first value: 30–60 minutes
Prerequisites: governance work is underway and Evidence is attached to priority Controls
Internal audit focus
This phase focuses on internal readiness and internal audit review. It is about traceability, Evidence quality, and defensible status snapshots.
Path at a glance
1
Freeze scope
Confirm frameworks, versions, and project context
2
Validate statuses
Ensure fulfilled and executed reflect Evidence
3
Export the project
Generate the project PDF and gather Evidence downloads
4
Review the trail
Validate decisions and status changes
Step 1: Freeze scope for the review window
Goal: ensure you’re reviewing the right version of the truth.
Where in Modulos
Project → Settings → FrameworksProject → Settings → General settings
Do this
- Confirm frameworks and versions are correct for the review window.
- Confirm the AI system description and lifecycle stage match what is being reviewed.
You’re done when
- the scope is stable enough for internal review and sign-off
Step 2: Validate statuses against Evidence
Goal: ensure statuses match reality.
Where in Modulos
Project → RequirementsProject → ControlsProject → Evidence
Do this
- For fulfilled Requirements, spot-check mapped Controls and their Evidence.
- For executed Controls, verify Evidence demonstrates execution and is not stale or irrelevant.
You’re done when
- readiness claims are defensible from Evidence and mappings
Step 3: Export the project for internal review
Goal: produce a record that can be reviewed without live navigation.
Where in Modulos
Project → Dashboard → Export- per-file Evidence download from each Control's Control tab
Do this
- Generate the project-wide PDF from the Dashboard Export button.
- Download the underlying Evidence files an auditor needs to see directly, rather than relying on the PDF summary alone.
You’re done when
- you can hand off the project PDF and the Evidence files that support it
Step 4: Review the audit trail for key decisions
Goal: make decisions and status changes traceable.
Where in Modulos
Project → Controls → select a Control → Comments and Logsfor key events and status-change commentsProject → Requirementsfor each Requirement's review state
Do this
- Review key events in each Control's Comments and Logs: ownership changes, status changes, and Requirement fulfillments.
- Confirm that each Control's status changes carry a logged comment in its Comments and Logs panel.
- Confirm that each in-scope Requirement was reviewed and marked Fulfilled by its Requirement Owner.
- Resolve any inconsistencies before final sign-off.
You’re done when
- the Controls' Comments and Logs and the Requirements' review states support the story your status snapshot is telling
Next
Monitor phase
Keep governance continuously current between review windows
Internal Audit path
A role-based walkthrough for internal review and assurance