The acceptance audit: one hour, five risks
The free thing that opens the door. It needs no system access, only the client's register and the people who own it.
Before the meeting
Ask for the register export and pick five material risks: two the board has seen, two from technology, one from a business unit.
The four questions, per risk
- Who accepted it? A named person, not a function or a committee.
- Until when? A date on which the acceptance ends and something happens.
- On what evidence? The facts that make it true, with where each came from.
- What happens when it expires? Accept again, escalate, fund or fix, or nothing.
Scoring
For each risk, one point per question answered with a name, a date, a source or an action. Five risks, twenty points.
What to hand over
A one-page table: the five risks, the four answers, the score, and one sentence per risk on what the loop would change. In most first audits the common answers are "the technology function", "never", "a paragraph" and "nothing".
What not to do
Do not criticise the register. It was built to answer different questions. The audit shows which questions it cannot answer yet.