# TE_AUDIT v0.1 — Organizational Analysis and Documentary Audit

**Version**: 0.1
**Date**: 2026-09-17
**Status**: Pre-pilot; governed by TE_CASEWORK and the TE stack.

## 1. Invocation

Trigger on a comprehensive review of company/organisation records, including an unstructured pile of documents. The audit is part of that mandate from the first wave. A narrow task, such as summarising one invoice, keeps its scope. The report names the scope as mandated.

The sequence is mandate/access → SVP and first documentary wave → relevance decisions → domain analysis → mandatory systematic audit → counterverification → bounded report. Flag provisional urgent issues to the authorised case owner as they arise. The second analytical pass runs in every case, a reassuring first analysis included.

## 2. First wave and analysis

Apply CASEWORK §§2–4. Identify versions, potential duplicates, dates, parties, obligations, authorisations, transactions, communications and missing expected material. Build a provisional chronology and map of roles, processes and resources. Select documents by the mandate and the §3 coverage areas; record the first persuasive narrative as one hypothesis among the competing ones.

After the wave, explain all exclusions; preserve excluded originals. Maintain uncertainty for inaccessible items. Use LEXX for contractual/policy/delegation questions, SCIMS for organisational functioning, VERI for effects and OBSERVER to integrate. SCIMS and VERI vectors describe the organisation; a person's motives are established from acts, authority and benefit (CASEWORK §1).

## 3. Mandatory risk/control coverage

For each baseline area, record a procedure, source population, actual tested scope, evidence and result, or the status `not_testable` or `not_applicable` with its reason:

| Area | Example questions |
|---|---|
| Source integrity | Conflicting versions, gaps, altered narratives, authenticity limits? |
| Finance | Do invoicing, settlement and ledger records reconcile? Duplicate documents versus actual duplicate payments? |
| Procurement | Services/deliveries supported? Exceptions, splitting patterns or conflicts requiring verification? |
| Authorisations | Who could approve, execute and review? Unsupported overrides or self-approval? |
| Governance | Delegations, related-party disclosures and decisions consistent with the applicable instruments? |
| People and internal abuse | Documentary indications of coercion, retaliation, discriminatory practices or improper use of position? Alternative explanations and affected-party evidence? |
| Assets and resources | Are custody, use and transfers supported? Possible diversion versus ordinary accounting error? |
| Information and reporting | Access, changes, reporting chains, missing logs and unsupported external/internal representations? |

Extend these areas for the actual organisation. Documentary coverage measures what was read; operational control tests and substantive tests are recorded separately, each with its own scope. Record the sample and the populations outside it.

## 4. Findings and escalation

Use the common finding schema. Investigate indicators of abuse, fraud, corruption and other possible violations when evidenced. Success is a complete, bounded and reviewed report, with zero or more findings. Verify actor identity, acts, authority and potential benefit independently; surname matches, relationships and opportunity are leads for that verification.

Look for both intentional and emergent causes. Two payments require two transaction records (bank, ledger); invoice copies form one origin group. Missing minutes go to the gap register (CASEWORK §3). A control weakness and a loss are separate findings; a formally correct document and the execution it records are verified separately.

An audit escalates by recommending targeted investigation and evidence preservation to the authorised owner; the procedural acts that follow are those of the persons the mandate names, after the competent determination of applicable duties (CASEWORK §2). Contact with a potentially implicated person is a decision of the authorised owner, recorded in the case.

## 5. Closure

Deliver a linked analytical report and audit ledger, coverage/limitations, gap register, exclusion-reconsideration record, alternative explanations, unresolved matters and proposed checks. Reassess excluded documents before closure. Significant findings are reviewed by a second person. Reopening produces a new case revision and invalidates old review receipts.

Use bounded statements: no exception identified in specified tests; exception supported at a specified confidence; unresolved; not testable. Zero findings is reported as `no exception identified in specified tests`, with the tested scope and the coverage gaps beside it; a `not_testable` area is reported as a limitation in the coverage section; closing a wave with unreadable or restricted records certifies the accessible pass, and those records stay open in the gap register.

External professional reference: [IIA, Internal Auditing and Fraud, third edition](https://www.theiia.org/en/content/guidance/recommended/supplemental/practice-guides/global-practice-guide-internal-auditing-and-fraud). The public overview, consulted 2026-09-17, identifies organisational fraud-risk assessment as an audit concern; the coverage table in §3 is this protocol's own.
