Certify

External review

Prepare for and support external audit, address findings

Hats
2
Review
External
Unit Types
Audit Prep, Finding Resolution
Inputs
Document

Dependencies

Documentevidence-package

Hat Sequence

1

Audit Liaison

Focus: Prepare the organization for external audit by organizing evidence per the auditor's request format, verifying completeness, and anticipating auditor questions. Serve as the bridge between internal compliance work and external audit expectations.

Produces: Audit readiness checklist, organized evidence submission per auditor request list, and pre-audit self-assessment.

Reads: Evidence package from document stage via the unit's ## References section.

Anti-patterns:

  • Submitting evidence without verifying it matches the auditor's specific requests
  • Not anticipating follow-up questions for complex or unusual controls
  • Presenting evidence in a disorganized format that wastes auditor time
  • Failing to verify that all evidence is current as of the audit period
  • Not preparing stakeholders for potential auditor interviews
2

Finding Resolver

Focus: Address auditor findings with documented responses that include root cause analysis, remediation evidence, or justified risk acceptance. Every finding must have a clear resolution path — fix, mitigate, or accept with rationale.

Produces: Finding response documents with root cause analysis, remediation evidence or risk acceptance justification, and preventive measures.

Reads: Auditor findings, evidence package, and remediation log via the unit's ## References section.

Anti-patterns:

  • Responding to findings without root cause analysis
  • Fixing the symptom without addressing why the gap existed
  • Accepting risk without documenting the business justification
  • Not providing evidence that the remediation actually resolves the finding
  • Treating findings as personal criticism rather than improvement opportunities

Certify

Criteria Guidance

Good criteria examples:

  • "Audit readiness checklist confirms all evidence is current, accessible, and mapped to the auditor's request list"
  • "Each auditor finding has a documented response with remediation evidence or a justified exception"
  • "Finding resolution includes root cause analysis to prevent recurrence, not just a fix for the immediate gap"

Bad criteria examples:

  • "Audit is prepared for"
  • "Findings are resolved"
  • "Certification is obtained"

Completion Signal

Audit preparation package is complete with all evidence organized per the auditor's request format. Any auditor findings have documented responses with remediation evidence or accepted risk justification. All finding resolutions include root cause analysis. The compliance posture is audit-ready with no unaddressed critical findings.