Audit Recommendation & Evidence Assurance Manager (AREA)
Make audit-recommendation follow-through a live, connected model — from the audited entity and the audit report, through the recommendation and management response, to implementation actions, the evidence that proves them, independent validation of that evidence, the exceptions and risks when it falls short, and the authorised decision to close.
Its central question:
For each audit recommendation, what did management commit to, what actions and evidence deliver it, has that evidence been independently validated as sufficient — and is there a clean, authorised basis to close it (or a blocking exception that says not yet)?
It sits beside the audit office's report register and the agency's own project and document systems — it owns the recommendation → evidence → validation → closure lifecycle and the assurance relationships around their records.
The assurance spine
Entity / Audit Report → Recommendation → Management Response → Implementation Action → (Milestone) → Evidence Requirement → Evidence Submission → Evidence Validation → Exception → Risk → Assurance Decision → Closure Request → Closure Approval, with a Status History trail across the top.
The documents
| Page | What's in it |
|---|---|
| 00 — Overview | What the app is, the domain, the 16 models by area, the demo scenario |
| 01 — Quick Reference | Menu map, every model, key status vocabularies, the demo data set |
| 02 — System Diagram | The assurance data model as a diagram (+ interactive viewer) |
| 03 — Phase 2 Scope | The runtime not yet built: the recommendation state machine, closure guards, evidence/validation gates and the DomainEvents outbox |
Status
Phase 1 (built): all 16 models render as an AI-Safe CRUD register with a dashboard, seeded with one coherent QAO-style performance-audit scenario (35 rows) — one recommendation carried all the way to CLOSED, one held at an open blocking exception.
Phase 2 (scoped, not built): the recommendation lifecycle state machine, the closure
guard rules (evidence validated, no blocking exceptions, completion declared), response
versioning, and the DomainEvent outbox that would notify downstream systems — see
page 03.
Prototype system; draft. All entities, people, reports, recommendations, evidence and decisions in the demo data are fictional; values demonstrate structure only and are not real audit findings.