This page defines how audits are planned, executed, evidenced, rated, reported, and followed up within AuditFlow OS.

It sets a consistent operating model for assurance work across cyber, AI, data, governance, third-party, and IS4-style reviews.

The rulebook helps users run audit activity in a structured, repeatable, risk-based way.


Purpose

The purpose of this rulebook is to:

This rulebook applies to audits managed through AuditFlow OS.


Principles

All audits should follow these principles.

1. Risk-based

Audit activity should focus on areas with higher risk, greater exposure, weaker control confidence, or known evidence gaps.

2. Evidence-based

Audit conclusions should be supported by relevant and sufficient evidence. Opinion alone should not drive findings or assurance ratings.