Explainer

Verification and audit: what each one establishes.

An audit records that a process was completed against a standard at a point in time, by a party the audited organisation engages. Verification determines whether a specific claim is true, binds the result to the policy version in force, and states what it could not determine. The 2 work in sequence: an audit report is evidence, and a verification consumes it.

Side by side

PropertyAuditVerification
Question answeredWas the process completed against the standard?Is this claim true?
SubjectAn organisation's processA specific claim and its evidence
Who engages the reviewerUsually the organisation under reviewA party with no hand in the subject, under a conflict-of-interest gate
OutputA reportA sealed, policy-versioned determination
ReproducibleBy the same auditor, on the same engagementBy anyone, from the record: same evidence and policy version give the same result
GapsRecorded as scope and limitations in the reportStated per claim as could not determine, with coverage denominators
Time behaviourA point in timeA point in time, with monitoring that withdraws the seal on drift
ReaderThe organisation and its stakeholdersAny relying party, including a counterparty the subject has never met

Why the policy version matters

A determination made under one rule set can be misread under another. Certisyn binds every determination to the exact policy version in force at issuance, so a later reader replays it under the rules that applied and can tell whether the standard moved afterwards.

Why the gaps matter

A statement that something was not observed is routinely recorded in a form that reads as a claim about the world. The Coverage Attestation Profile (CAP-1), published at the IETF, specifies how to declare the examined population with denominators and how to enumerate every unexamined unit with a reason. Certisyn determinations carry that discipline.

How they combine

An institution holds an ISO certificate, a SOC 2 report or an Essential Eight assessment. Each is an input. A verification takes the claim the certificate supports, examines the evidence behind it and issues a determination the institution's counterparties can check.

Frequently asked

What is the difference between verification and audit?

An audit records that a process was completed against a standard at a point in time by a party the audited organisation engages. Verification determines whether a specific claim is true, binds the result to the policy version in force, and states what it could not determine.

Does verification replace an audit?

No. An audit report is evidence, and verification consumes audit reports as inputs. The 2 answer different questions for different readers.

Why does the policy version matter?

A determination made under one rule set can be misread under another. The policy version travels with the determination, so a later reader replays it under the rules that applied.

Related