An audit records that a process was completed against a standard at a point in time, by a party the audited organisation engages. Verification determines whether a specific claim is true, binds the result to the policy version in force, and states what it could not determine. The 2 work in sequence: an audit report is evidence, and a verification consumes it.
| Property | Audit | Verification |
|---|---|---|
| Question answered | Was the process completed against the standard? | Is this claim true? |
| Subject | An organisation's process | A specific claim and its evidence |
| Who engages the reviewer | Usually the organisation under review | A party with no hand in the subject, under a conflict-of-interest gate |
| Output | A report | A sealed, policy-versioned determination |
| Reproducible | By the same auditor, on the same engagement | By anyone, from the record: same evidence and policy version give the same result |
| Gaps | Recorded as scope and limitations in the report | Stated per claim as could not determine, with coverage denominators |
| Time behaviour | A point in time | A point in time, with monitoring that withdraws the seal on drift |
| Reader | The organisation and its stakeholders | Any relying party, including a counterparty the subject has never met |
A determination made under one rule set can be misread under another. Certisyn binds every determination to the exact policy version in force at issuance, so a later reader replays it under the rules that applied and can tell whether the standard moved afterwards.
A statement that something was not observed is routinely recorded in a form that reads as a claim about the world. The Coverage Attestation Profile (CAP-1), published at the IETF, specifies how to declare the examined population with denominators and how to enumerate every unexamined unit with a reason. Certisyn determinations carry that discipline.
An institution holds an ISO certificate, a SOC 2 report or an Essential Eight assessment. Each is an input. A verification takes the claim the certificate supports, examines the evidence behind it and issues a determination the institution's counterparties can check.
An audit records that a process was completed against a standard at a point in time by a party the audited organisation engages. Verification determines whether a specific claim is true, binds the result to the policy version in force, and states what it could not determine.
No. An audit report is evidence, and verification consumes audit reports as inputs. The 2 answer different questions for different readers.
A determination made under one rule set can be misread under another. The policy version travels with the determination, so a later reader replays it under the rules that applied.