Skip to main content

Governance artifact

Gemara Layer 7

AuditLog

Audit Log

Purpose

Review of organizational policy and conformance.

Role

Audit steps back from a single merge or deploy: it reviews whether the programme is operating—strengths, observations, gaps and findings against policy and control criteria, citing prior evaluation and enforcement evidence.

It is an efficacy review of the operating governance system.

Examples

Q2 FOSS contribution programme audit

Internal Audit reviews the FOSS contribution programme against policy and the control catalog: "Strengths include effective pre-publication data-leakage controls: PR #417’s failed secret scan was blocked and enforcement recorded. IP review dispositions are present for sampled engagements. Gaps remain in annual recertification coverage and contributor training completion—findings that feed the next policy and control revision."

Source: Q2 2026 FOSS Contribution Programme Audit (foss-audit-q2-2026).

Criteria drawn from policy and guidance

The audit cites policy criteria and guidance expectations explicitly, so findings are not free-floating opinions. Evaluation and enforcement logs for sampled PRs are attached as evidence.

Source: criteria and mapped evaluation/enforcement evidence in the Q2 2026 Audit Log.

Anti-patterns

Audit as screenshot week

Assembling evidence only when the auditor arrives. If evaluation and enforcement were not emitted continuously, Layer 7 cannot review them.

Findings without criteria

Observations that never cite which policy or control failed. Remediation cannot target a definition.

Unactioned audit recommendation

A finding or recommendation is recorded—and then sits. Audit without remediation is a report, not a control loop.

References