Post-Decision Conflict Audit¶
Retrospective audit — instantiates Conflict-of-Interest Mitigation
Risk-based retrospective testing of past decisions — disclosures, access, communications, and outcomes — to catch undisclosed conflicts, control failures, and institutional patterns after the fact, and to trigger remedy.
Every control before this one acts before or during a decision. Post-Decision Conflict Audit is the mechanism that looks backward: it samples decisions that have already been made and tests whether the conflict controls actually held — whether disclosures were complete, access boundaries respected, recusals real, and outcomes untainted. Its defining orientation is retrospective and evidentiary: it does not gate anything, it checks what happened against what should have, and where it finds a broken control it triggers remedy — reopening a decision, replacing a reviewer, referring suspected corruption. It is the system's feedback loop, catching the conflicts that slipped past every forward control and, by aggregating findings across many cases, surfacing the institutional patterns (a recurring counterparty, a favored vendor, an over-used exception) that no single-case review can see.
Example¶
A city's inspector general runs an annual audit of the transit agency's largest contract awards. The audit does not re-decide the contracts; it tests them. Using a risk-based sample — the highest-value awards, any with a single bidder, and a random tail of routine ones — it pulls the disclosure records, evaluator rosters, email metadata, and award justifications. In one award it finds that an evaluator had failed to disclose that his brother-in-law was a subcontractor on the winning bid; the pre-decision screen missed it because the relationship was never in the register. The audit classifies this as a control failure with a possible tainted outcome, refers the non-disclosure for investigation, and — because the scores show that evaluator's marks were decisive — recommends the award be re-scored by an independent panel. Across the full sample it also notices that the same three firms won 80% of sole-source awards, a pattern it flags for policy review.
The audit's value is twofold: it repaired one specific tainted decision that every forward control had let through, and it detected a systemic concentration that only a backward, aggregate look could reveal.
How it works¶
- Risk-based sampling. Prioritize high-consequence, anomalous, exception-laden, and repeat-counterparty cases while retaining a random tail so the sample cannot be gamed.
- Test controls against evidence. Compare disclosures, access logs, recusal records, and communications with what the decision actually required.
- Classify findings and remedy. Distinguish honest error from negligence, concealment, and corruption; where a breach could have changed the outcome, trigger reconsideration, not just a sanction.
- Aggregate for patterns and feed policy review. Roll findings up to reveal institutional dependencies and control gaps, informing the next recertification cycle.
Tuning parameters¶
- Sampling rate and risk weighting — how much of the population is tested and how heavily toward high-risk cases. Heavier weighting finds more per hour but can miss diffuse low-level problems.
- Evidence depth — how far the audit reaches (records only vs. communications and access logs). Deeper review detects subtler breaches but raises privacy and surveillance concerns.
- Decision-remedy threshold — how strong the evidence of taint must be before a past decision is reopened. A low bar disrupts settled matters; a high one lets tainted outcomes stand.
- Lookback window — how far back the audit reaches. Longer windows catch slow patterns but strain records and fade memory.
When it helps, and when it misleads¶
Its strength is that it is the only control that catches what the forward controls missed and the only one positioned to see patterns — the recurring vendor, the captured reviewer, the exception that quietly became standing — because it looks across many decisions at once.
Its central failure mode is hindsight bias: judging a reasonable in-the-moment decision as culpable because a bad outcome is now visible, which punishes judgment rather than misconduct and teaches people to hide uncertainty.[n1] A second failure is the punitive fishing expedition that produces sanctions but never actually remedies the tainted decision. The classic misuse is auditing to assign blame while leaving the corrupted outcome — the awarded contract, the published paper — untouched. The guarding discipline is to judge decisions against the information available at the time, to separate uncertainty and error from concealment and corruption, and to make decision remedy, not just personnel punishment, the required output of a finding.
How it implements the components¶
compliance_monitoring_enforcement_and_remedy— its core: retrospective testing of whether controls held, graduated consequences for breaches, and repair of tainted decisions.periodic_recertification_and_policy_review— by aggregating findings into patterns, it feeds the periodic review that revalidates thresholds, controls, and policy.
It does not implement information_firewall_and_access_control — installing and live-monitoring the access barrier is Information Firewall; this audit tests, after the fact, whether that barrier and other controls actually held, rather than maintaining them in real time.
Related¶
- Instantiates: Conflict-of-Interest Mitigation — it closes the loop with retrospective assurance, remedy, and pattern detection.
- Consumes: Conflict-of-Interest Disclosure Register — audits the disclosures, records, and decisions the register and its downstream controls produced.
- Sibling mechanisms: Information Firewall · Independent Conflict Review Panel · Pre-Decision Conflict Screen · Conflict-of-Interest Disclosure Register
Editorial Notes¶
Form Classification¶
Form family: Assessment, Review & Assurance
Rationale: Post-Decision Conflict Audit operates as a bounded evaluation of existing evidence or work that produces a finding or disposition because it risk-based retrospective testing of past decisions — disclosures, access, communications, and outcomes — to catch undisclosed conflicts, control failures, and institutional patterns after the fact, and to trigger remedy.
Independent corroboration: The frozen evidence defines Post-Decision Conflict Audit as 'Risk-based retrospective testing of past decisions — disclosures, access, communications, and outcomes — to catch undisclosed conflicts, control failures, and institutional patterns after the fact, and to trigger remedy', so its operative form is Assessment, Review & Assurance.
Review outcome: Independent reviewer agreement; high confidence.
Origin Attribution¶
Primary origin: Accounting & Auditing
Origin pattern: Convergent development
Present-day reach: Multi-domain
Rationale: Risk-based retrospective sampling of decisions for undisclosed conflicts and control failures is an internal-audit practice.
Related originating lineages:
- Law & Governance — Law contributes fiduciary duties, disclosure standards, and remedies for conflicted decisions.
Review resolution: Light authoritative-source research resolves the primary-origin disagreement in favor of accounting auditing. U.S. GAO: Conflict of Interest Abuses and Internal Audit directly documents the defining practice or theory described in the selected origin rationale. Other domains are retained only where the blind reviews identify material co-development or translation; broad application is recorded separately as domain_reach=multi_domain, while origin_mode=convergent describes the relationship among origin lineages.
Attribution caveat: The boundary with law governance is substantive because that tradition materially developed or translated part of the mechanism; the cited provenance places the defining form in accounting auditing.
Review outcome: Researched adjudication after independent review; high confidence.
Sources consulted:
Notes¶
[n1] Hindsight bias, studied by psychologist Baruch Fischhoff, is the tendency to see an outcome as having been predictable once it is known, which makes past decisions look more culpable than they were at the time. In audit it is the standing trap: the discipline is to evaluate a decision against the facts and controls available when it was made, not against what later came to light. ↩