Audit Request & Investigation Manager (ARIM)

Make audit-request handling and investigation a governed, connected model — from intake and triage, through jurisdiction and conflict assessment, to the investigation, its evidence and chain of custody, the findings and procedural fairness, and the recommendations, referrals, decision and closure.

Its central question:

For each audit request, was it triaged and assessed for jurisdiction and conflict, did the investigation gather evidence with proper chain of custody, were findings tested by procedural fairness, and is there an authorised decision and complete, closable record?

It sits beside the audit office's case and records systems — it owns the request → triage → investigation → evidence → findings → outcomes → closure lifecycle and the integrity controls (custody, conflicts, fairness) around it.

The case spine

Entity / Audit Request → Request Issue / Triage / Jurisdiction / Conflict / Information Request → Investigation → Plan / Evidence (Issue Links, Chain of Custody) / Interview / Chronology → Finding (Evidence Links, Procedural Fairness) → Recommendation / Referral / Decision / Closure, with a Status History trail on the request.

The documents

Page What's in it
00 — Overview What the app is, the domain, the 22 models by area, the demo scenario
01 — Quick Reference Menu map, every model, key status vocabularies, the demo data set
02 — System Diagram The request-and-investigation data model as a diagram (+ interactive viewer)
03 — Phase 2 Scope The runtime not yet built: the request/investigation state machines, triage routing, closure guards and the DomainEvents outbox

Status

Phase 1 (built): all 22 models render as an AI-Safe CRUD register with a dashboard, seeded with one coherent QAO-style case (36 rows) — a protected-disclosure procurement allegation triaged, investigated (evidence with custody, interviews, chronology), one finding substantiated and one not, procedural fairness completed, a recommendation, a referral to the CCC, an approved decision and closure.

Phase 2 (scoped, not built): the request/investigation lifecycle state machines, triage routing, the closure guard rules (procedural fairness complete, conflicts resolved, evidence index complete), the procedural-fairness cycle, and the DomainEvent outbox — see page 03.

Prototype system; draft. All entities, requests, allegations, evidence, findings and decisions in the demo data are fictional; values demonstrate structure only and are not real audit findings.