IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Documentation

Continuous assurance reference

Drift, evidence freshness and recurring assurance concepts in the packaged guide.

MSP4.1.0
All documentation / MSP / 4.1.0
This reference is bundled with the 4.1.0 engine and may retain earlier UI terminology. Use the current 4.1.0 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.

Continuous Assurance Foundation

ITAuditFactory ISO 27001 Audit Toolkit v4.1.0

Explicit conclusion states

ConclusionMeaning
PassThe declared technical condition was observed. Human scope and control review still apply.
FailThe declared technical condition was not met.
Needs ReviewThe result is ambiguous, informational, or needs a human conclusion.
Not ApplicableThe test was explicitly excluded from the evaluated scope.
Not CollectedEvidence was not obtained; this is not a pass.
Collection ErrorCollection failed because of a runtime, authorization, dependency, or data error.
Suppressed ExceptionAn approved, time-bounded exception suppresses operational action; it does not rewrite the observation.

Transparent Test Contract v2

Every exported result includes the purpose, expected and observed values, permissions, data source, collector and rule versions, ISO mapping rationale, evidence lineage, last successful collection, and evidence age. Existing 4.1.0 collectors remain compatible. Until a collector explicitly declares every required semantic field, its contract is marked PARTIAL and lists the gaps.

Collector preflight and health

Each selected module records READY, READY_WITH_LIMITATIONS, or BLOCKED before collection. The records are stored as 04-Logs\Collector-Preflight.csv and 04-Logs\Collector-Preflight.json and are included in the HTML report. Preflight does not probe or disclose passwords; authorization and connectivity are confirmed by the read-only collector.

Evidence Integrity v2

Each completed run contains:

  • Evidence-Integrity-v2.json — sorted package-relative path, size, and SHA-256 for every included file.
  • Evidence-Integrity-v2.sha256 — the SHA-256 of the manifest itself.
  • SHA256SUMS.txt — the legacy manifest retained for compatibility.

The v2 manifest is independently verifiable but is not claimed to be certificate-signed. Certificate-backed signing and trusted timestamp integration remain future controlled work.

Verify a package

powershell.exe -NoLogo -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files\ITAuditFactory\ITAuditFactory ISO 27001 Audit Toolkit\Scripts\Verify-ITAuditFactoryEvidencePackage.ps1" -PackageRoot "D:\Evidence\Run-20260904"

Exit code 0 means the manifest and every listed file hash match. Exit code 1 means verification failed. To save a JSON report, pass -ReportPath pointing outside the evidence package.

Review sequence

  1. Review collector preflight and resolve blocked or limited modules.
  2. Review explicit conclusion states; do not rely on the legacy status alone.
  3. Open each test contract and resolve partial-contract gaps.
  4. Review raw evidence, scope, mapping, remediation, and human governance records.
  5. Run the standalone verifier before auditor handoff and retain its result outside the package.