Auditor Visibility · Controlled Governance Access

Give auditors controlled access to the governance record.

Auditors need a clear, scoped, read-only view of relevant governance records — not uncontrolled system access, not manually assembled evidence folders.

EAB provides structured auditor visibility: scoped to the review, read-only by design, and connected to the live governance record — not a static export.

Read-only access Scoped to review No evidence assembly
Auditor Visibility · Governance Access Layer
Scoped read-only access per review engagement
AI system records, screening results, obligation status
Evidence readiness and uploaded artefacts
Supervisor approval records and decision trail
Audit trail — timestamped, attributed, immutable
No operational control — no modification rights
The audit access problem

Too little access creates gaps. Too much access creates governance risk.

Manual evidence exports have version issues and missing context. Broad system access creates confidentiality and governance concerns. Controlled visibility is the right model.

Access control

Scoped per Review Engagement

Auditor access is scoped to the systems, periods, and obligation areas relevant to the review. Access is granted by the mandanten_admin and expires. Auditors cannot navigate outside the defined scope.

Read-only

No Modification Rights

Auditors can view governance records, screening results, evidence artefacts, and approval decisions. They cannot create, edit, or delete records. The governance record is protected.

Live record

Connected to the Live Governance Record

Auditors see the actual governance record — not a static export assembled for the review. Evidence is in context. Approval decisions show the reasoning. The audit trail is complete.

Evidence

Evidence in Context

Uploaded evidence artefacts are visible with their metadata — upload date, uploader, linked obligation area, and review status. Evidence is not a file list — it is a structured governance record.

Decisions

Approval Records and Decision Trail

Supervisor approval decisions are visible with their context — the screening record, the evidence present at approval time, and the decision justification. Approvals cannot be retroactively altered.

Traceability

Timestamped, Attributed Audit Trail

Every governance action is timestamped and attributed to the person who took it. The audit trail is immutable. Auditors can reconstruct the governance history of any system from registration to current state.

From governance record to controlled auditor review

Audit access that matches the review scope.

Auditor visibility is provisioned, scoped, and time-limited — so organizations can provide evidence without creating uncontrolled access.

1
Mandanten Admin

Define scope and provision auditor access

The admin creates an auditor account, scoped to the relevant systems and time period. Access is provisioned for the duration of the review engagement — not permanent.

2
Auditor

Review governance records in read-only mode

The auditor logs in and sees the governance records within their scope — AI systems, screening results, obligation coverage, evidence artefacts, and supervisor approval decisions. No evidence assembly required.

3
Auditor

Navigate the audit trail and decision record

The auditor can trace every governance action — who screened the system, when, what the result was, what evidence was present at approval, and what the supervisor decided. The reconstruction is complete and timestamped.

4
Mandanten Admin

Access expires after the review

Auditor access is time-limited. After the engagement, access expires without manual revocation. The organisation's governance record is protected. The access event itself is logged in the audit trail.

Auditor Visibility

Provide audit evidence without losing governance control.

Controlled visibility is stronger than exporting audit folders. The governance record stays intact. Auditors see exactly what the review requires.

EU-hosted · Anchored to CELEX 32024R1689

Get in Touch
Request More Information

Tell us about your organization and what you’re looking to address. We’ll follow up with the relevant information.