Skip to content

Audit Phase

Audit is where you validate the current state and package it for internal readiness review. The goal is not a last-minute scramble, but a confirmable snapshot backed by Evidence and audit trail.

ScopeDefine the system and governance scope
ImplementExecute Controls and attach Evidence
MonitorKeep governance continuously current
AuditPrepare internal review and exports

Outcome

You leave this phase with:

  • a validated readiness snapshot (Requirements, Controls, Evidence)
  • exports that represent the current state
  • an audit trail that supports internal assurance review

Time to first value: 30–60 minutes
Prerequisites: governance work is underway and Evidence is attached to priority Controls

Internal audit focus

This phase focuses on internal readiness and internal audit review. It is about traceability, Evidence quality, and defensible status snapshots.

Path at a glance

Step 1: Freeze scope for the review window

Goal: ensure you’re reviewing the right version of the truth.

Where in Modulos

  • Project → Settings → Frameworks
  • Project → Settings → General settings

Do this

  • Confirm frameworks and versions are correct for the review window.
  • Confirm the AI system description and lifecycle stage match what is being reviewed.

You’re done when

  • the scope is stable enough for internal review and sign-off

Step 2: Validate statuses against Evidence

Goal: ensure statuses match reality.

Where in Modulos

  • Project → Requirements
  • Project → Controls
  • Project → Evidence

Do this

  • For fulfilled Requirements, spot-check mapped Controls and their Evidence.
  • For executed Controls, verify Evidence demonstrates execution and is not stale or irrelevant.

You’re done when

  • readiness claims are defensible from Evidence and mappings

Step 3: Export the project for internal review

Goal: produce a record that can be reviewed without live navigation.

Where in Modulos

  • Project → Dashboard → Export
  • per-file Evidence download from each Control's Control tab

Do this

  • Generate the project-wide PDF from the Dashboard Export button.
  • Download the underlying Evidence files an auditor needs to see directly, rather than relying on the PDF summary alone.

You’re done when

  • you can hand off the project PDF and the Evidence files that support it

Step 4: Review the audit trail for key decisions

Goal: make decisions and status changes traceable.

Where in Modulos

  • Project → Controls → select a Control → Comments and Logs for key events and status-change comments
  • Project → Requirements for each Requirement's review state

Do this

  • Review key events in each Control's Comments and Logs: ownership changes, status changes, and Requirement fulfillments.
  • Confirm that each Control's status changes carry a logged comment in its Comments and Logs panel.
  • Confirm that each in-scope Requirement was reviewed and marked Fulfilled by its Requirement Owner.
  • Resolve any inconsistencies before final sign-off.

You’re done when

  • the Controls' Comments and Logs and the Requirements' review states support the story your status snapshot is telling

Next