{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp09_archetype_breadth150_20260804","cell_id":"authority_legitimacy_and_consent_foundations__accounting_auditing","arm":"BREADTH_PROBE_ONE_SHOT","candidate_id":"authority_legitimacy_and_consent_foundations__accounting_auditing__P1","proposal_index":1,"version":0,"title":"Finding Mandate Compact for Contested Internal-Audit Remediation","problem":"Internal auditors can identify a control deficiency and demand remediation, but process owners may contest whether audit may set the finding’s severity, prescribe corrective action, or impose a deadline. When the mandate and its boundaries are unclear, finding closure becomes a negotiation over the auditor’s standing rather than a review of evidence, while management may treat resistance as acceptance of control risk without invoking the authorized risk-acceptance process.","actors":["Audit committee","Chief audit executive","Internal-audit engagement team","Business-unit process owners","Management control owners","Designated risk-acceptance executives","Employees or customers exposed to the affected control failure","Independent finding-review forum"],"observable_state":"Audit findings are repeatedly rerated, reopened, extended, or marked resolved through undocumented bargaining; similar findings receive different treatment across business units; process owners challenge who may bind them to deadlines or remediation designs; and the audit committee cannot distinguish evidentiary disagreement, jurisdictional objection, remediation choice, and formal risk acceptance in the issue record.","consequence":"Control weaknesses can remain unresolved or be closed without a legible basis, management accountability becomes ambiguous, and the audit committee receives assurance that is difficult to interpret or defend.","affected_objective":"Credible and timely assurance that identified internal-control deficiencies are either remediated, validly disputed, or explicitly accepted by the authorized risk owner.","intervention":"Create a Finding Mandate Compact that grounds and limits authority over audit findings. The audit committee charters internal audit to decide whether documented evidence satisfies published finding criteria and to propose severity; management retains authority over remediation design; only named executives may accept residual risk; and an independent review forum may affirm, modify, or remand contested classifications. Process-owner representatives participate in defining the taxonomy, evidence standards, response periods, and review rules without receiving a veto over mandated assurance. Every binding decision carries a public-to-participants reason record, competence disclosure, conflict check, and appeal route.","structural_mapping":[{"archetype_element":"Authority Mandate","domain_realization":"An audit-committee-approved compact states which finding decisions internal audit, management, risk owners, and the review forum may make."},{"archetype_element":"Authority Boundary","domain_realization":"Internal audit may judge evidence against criteria but may not choose operational remediation, silently accept risk, or extend its mandate beyond the audited control domain."},{"archetype_element":"Legitimacy Basis Map","domain_realization":"Each decision right is tied to its basis: committee delegation for assurance, domain competence for technical classification, operational ownership for remediation design, and executive delegation for risk acceptance."},{"archetype_element":"Affected Party Recognition","domain_realization":"The case record identifies process owners, control owners, authorized risk acceptors, and people materially exposed to the control deficiency."},{"archetype_element":"Consent Scope","domain_realization":"Process-owner representatives assent to consultation and review procedures, while the compact explicitly states that participation does not create a right to withdraw from audit oversight."},{"archetype_element":"Competence Evidence","domain_realization":"Finding decision-makers disclose relevant accounting, audit, systems, or operational qualifications; cases outside that competence require a qualified reviewer."},{"archetype_element":"Public Reason Record","domain_realization":"Each finding classification, deadline, extension, risk acceptance, and appeal outcome records criteria, evidence, authority source, conflicts, and review options."},{"archetype_element":"Accountability and Review Path","domain_realization":"A time-bounded forum independent of the original engagement hears challenges concerning evidence, classification, conflicts, procedure, or mandate overreach."},{"archetype_element":"Legitimacy Health Indicator","domain_realization":"The audit committee reviews rates of jurisdictional challenges, undocumented extensions, remands, conflict recusals, and findings bypassing formal risk acceptance."}],"mechanism_mapping":[{"mechanism_slug":"charter_or_mandate_document","role":"Codifies the source, scope, duration, revision rules, and limits of authority over findings.","counterfactual_removal":"Without it, participants can continue asserting incompatible decision rights even if templates and appeals exist."},{"mechanism_slug":"decision_rights_matrix","role":"Separates authority to identify evidence gaps, classify findings, design remediation, accept risk, grant extensions, and decide appeals.","counterfactual_removal":"Without it, the charter remains too general to prevent auditors or managers from crossing authority boundaries in individual cases."},{"mechanism_slug":"participatory_consultation_process","role":"Allows represented process owners and control owners to test the proposed taxonomy, evidence rules, and response periods before approval.","counterfactual_removal":"Without it, affected parties lack a structured connection to the operating rules and may reasonably treat them as one-sided audit preferences."},{"mechanism_slug":"public_reason_giving_protocol","role":"Requires every binding finding decision to identify criteria, evidence, mandate, conflicts, and the available review path.","counterfactual_removal":"Without it, formally authorized decisions remain opaque and objections cannot be separated into evidence, jurisdiction, or fairness claims."},{"mechanism_slug":"credentialing_and_peer_review_process","role":"Matches reviewers’ demonstrated competence to the accounting, technology, or operational subject of the finding.","counterfactual_removal":"Without it, delegated power may remain formally valid while its competence basis is untestable."},{"mechanism_slug":"appeal_or_review_forum","role":"Provides a corrigible path for error, conflict of interest, procedural defect, and boundary drift.","counterfactual_removal":"Without it, affected parties must either comply, bargain privately, or escalate politically, weakening the compact’s accountability basis."}],"causal_chain":["Ambiguous finding authority makes disputes about standing indistinguishable from disputes about evidence or remediation.","The mandate document and decision-rights matrix assign each binding decision to a specified role and legitimacy basis.","Representative consultation makes affected parties’ objections available before the rules bind cases, without fictionalizing consent to mandatory oversight.","Competence checks and reason-giving connect each exercise of authority to domain-relevant evidence and disclosed criteria.","The review forum can correct evidentiary error, conflict, procedural defect, or mandate overreach while routing risk acceptance to the authorized executive.","A structured case record then distinguishes remediation, valid disagreement, authorized risk acceptance, and unresolved noncompliance for audit-committee oversight."],"baseline":"Internal audit relies on a broad charter, professional judgment, standard finding templates, and ad hoc escalation. Process owners negotiate ratings, deadlines, and closure evidence with the engagement team or its management chain, while responsibility for final classification, remediation choice, and risk acceptance is not consistently separated in the case record.","nearest_rivals":["A broader internal-audit charter: clarifies general access and reporting authority but may not allocate the distinct binding decisions inside a contested finding.","A RACI matrix for issue management: assigns participation and execution roles but does not establish why a decision is legitimate, what competence supports it, or how it can be appealed.","A standardized finding template and quality review: improves documentation and consistency but leaves affected-party representation, mandate boundaries, and independent challenge optional.","Executive escalation of disputed findings: can force resolution but concentrates authority without necessarily separating evidence review from risk acceptance or recording reasons."],"remaining_contrastive_claim":"The candidate’s distinguishing proposition is that contested audit remediation is partly an authority-foundation failure: combining a scoped mandate, represented rule formation, domain-matched competence, reason-giving, and outcome-capable review should make the basis of each binding finding decision more legible than role assignment, documentation standardization, or escalation alone.","authority_safety":{"decision_authority":"The audit committee approves and may revoke the compact; the chief audit executive administers it; internal audit evaluates evidence within the charter; management chooses remediation; designated executives accept residual risk within delegated thresholds; and the independent review forum decides only properly filed contests within its mandate.","authorized_first_step":"Conduct a read-only shadow review of historical finding records and draft a hypothetical rights-and-reasons record without changing ratings, deadlines, closures, risk acceptances, personnel evaluations, or audit opinions.","excluded_actions":["Unilaterally expanding internal audit’s charter","Treating consultation as consent to mandatory oversight","Allowing auditors to prescribe operational remediation unless separately authorized","Allowing process owners to erase findings through withdrawal or silence","Changing live findings during the first evidence step","Disclosing protected audit evidence beyond existing access permissions","Using appeal participation or disagreement in employee performance decisions"],"halt_rollback":"Stop the shadow review if protected information would leave its authorized audience, if role participation could affect a live case, or if reviewers cannot remain independent. Delete working extracts under the organization’s approved retention process, preserve source records unchanged, and report only de-identified observations to the charter sponsor."},"negative_tests":{"strongest_counterevidence":"Contested cases already contain clear, consistently understood decision rights, qualified decision-makers, reasoned records, independent review, and formal risk acceptance, yet the observed bargaining and relitigation persist for reasons unrelated to authority legitimacy.","problem_falsifier":"Interviews and case reconstruction show that process owners accept internal audit’s standing and boundaries; disputes arise solely from missing evidence, remediation capacity, or incompatible technical interpretations.","intervention_falsifier":"In shadow-coded cases, the compact cannot assign disputed decisions to a legitimate role without duplicating existing rules, or independent reviewers cannot distinguish evidence disputes, mandate objections, remediation choices, and risk acceptance more consistently than under the baseline record.","risks":["The compact becomes legitimacy theater while informal bargaining continues.","Consultation is misrepresented as voluntary consent to unavoidable audit authority.","Review delays urgent remediation or creates procedural overload.","Management or audit leadership captures representative selection or the review forum.","Published reasons expose confidential, privileged, security-sensitive, or personal information.","Narrow boundaries create gaps between audit, compliance, finance, and operational jurisdictions.","Competence requirements privilege credentials over relevant practical knowledge.","Formal authority encourages overconfidence in findings whose evidence remains uncertain."]},"next_evidence_step":"Over four weeks, select up to 12 closed, previously contested findings from one completed audit cycle. Two reviewers who were not on the original engagements independently code the disputed decision, asserted authority basis, affected parties, competence evidence, reasons, conflicts, review path, and final disposition using the proposed compact. Compare coding agreement and identify cases the compact cannot route without ambiguity; interview no more than six original participants to test whether the reconstruction matches their dispute. Do not alter any source record or live decision.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Not assessed because runtime isolation prohibits inspecting or comparing other proposals; this candidate was derived solely from the supplied archetype and domain card.","revision_record":{"parent_version":null,"progress_targets_addressed":["Initial one-shot construction of a complete domain-specific candidate","Explicit preservation of mandate, boundary, representation, competence, reason-giving, and review structure","Operationally bounded and non-binding first evidence step"],"conceptual_changes":["None; this is the initial version."],"operational_changes":["None; this is the initial version."],"evidence_changes":["None; prior art and empirical performance remain unsearched and untested."],"claim_changes":["None; no novelty, prevalence, demand, or effect-size claim is made."]}}