Certify
External reviewPrepare for and support external audit, address findings
Dependencies
Hat Sequence
Audit Liaison
Focus: Prepare the organization for external audit by organizing evidence per the auditor's request format, verifying completeness, and anticipating auditor questions. Serve as the bridge between internal compliance work and external audit expectations.
Produces: Audit readiness checklist, organized evidence submission per auditor request list, and pre-audit self-assessment.
Reads: Evidence package from document stage via the unit's ## References section.
Anti-patterns:
- Submitting evidence without verifying it matches the auditor's specific requests
- Not anticipating follow-up questions for complex or unusual controls
- Presenting evidence in a disorganized format that wastes auditor time
- Failing to verify that all evidence is current as of the audit period
- Not preparing stakeholders for potential auditor interviews
Finding Resolver
Focus: Address auditor findings with documented responses that include root cause analysis, remediation evidence, or justified risk acceptance. Every finding must have a clear resolution path — fix, mitigate, or accept with rationale.
Produces: Finding response documents with root cause analysis, remediation evidence or risk acceptance justification, and preventive measures.
Reads: Auditor findings, evidence package, and remediation log via the unit's ## References section.
Anti-patterns:
- Responding to findings without root cause analysis
- Fixing the symptom without addressing why the gap existed
- Accepting risk without documenting the business justification
- Not providing evidence that the remediation actually resolves the finding
- Treating findings as personal criticism rather than improvement opportunities
Certify
Criteria Guidance
Good criteria examples:
- "Audit readiness checklist confirms all evidence is current, accessible, and mapped to the auditor's request list"
- "Each auditor finding has a documented response with remediation evidence or a justified exception"
- "Finding resolution includes root cause analysis to prevent recurrence, not just a fix for the immediate gap"
Bad criteria examples:
- "Audit is prepared for"
- "Findings are resolved"
- "Certification is obtained"
Completion Signal
Audit preparation package is complete with all evidence organized per the auditor's request format. Any auditor findings have documented responses with remediation evidence or accepted risk justification. All finding resolutions include root cause analysis. The compliance posture is audit-ready with no unaddressed critical findings.