Audit Log
Review of organizational policy and conformance.
Role
Audit steps back from a single merge or deploy: it reviews whether the programme is operating—strengths, observations, gaps and findings against policy and control criteria, citing prior evaluation and enforcement evidence.
It is an efficacy review of the operating governance system.
Examples
Q2 FOSS contribution programme audit
Internal Audit reviews the FOSS contribution programme against policy and the control catalog: "Strengths include effective pre-publication data-leakage controls: PR #417’s failed secret scan was blocked and enforcement recorded. IP review dispositions are present for sampled engagements. Gaps remain in annual recertification coverage and contributor training completion—findings that feed the next policy and control revision."
Source: Q2 2026 FOSS Contribution Programme Audit (foss-audit-q2-2026).
Criteria drawn from policy and guidance
The audit cites policy criteria and guidance expectations explicitly, so findings are not free-floating opinions. Evaluation and enforcement logs for sampled PRs are attached as evidence.
Source: criteria and mapped evaluation/enforcement evidence in the Q2 2026 Audit Log.
Links upstream
- Evaluation Log — inspection evidence
- Enforcement Log — action evidence
Links downstream
Audit closes the measurement loop: findings feed programme remediation and later definition updates rather than another log type.
Anti-patterns
Audit as screenshot week
Assembling evidence only when the auditor arrives. If evaluation and enforcement were not emitted continuously, Layer 7 cannot review them.
Findings without criteria
Observations that never cite which policy or control failed. Remediation cannot target a definition.
Unactioned audit recommendation
A finding or recommendation is recorded—and then sits. Audit without remediation is a report, not a control loop.