- Documentation
- /
- Iscrm
- /
- 00 — Overview
00 — Overview
Queensland Audit Office (QAO) reference application. This is a demonstration prototype modelled on the Queensland Audit Office's public-facing documentation, reports, guidance and activities. It is not an official QAO system and holds no real audit information — every entity, system, control, deficiency and decision in the demo data is fictional and illustrates the data model and workflow only.
What ISCRM is
The Information Systems Controls & Remediation Manager turns IT-controls assurance into a structured, evidence-backed register. A control isn't "fine" because it exists — it is assured when it has been assessed (design and operating effectiveness), and where the assessment finds a deficiency, that deficiency is remediated, independently retested as passed, has no open blocking gap, and an authorised approver has signed the closure. ISCRM holds every one of those links so the state of controls assurance is always demonstrable.
The domain
Auditors assess general IT controls (access, change, operations) over an agency's key systems — especially financial systems. When a control is ineffective, the fix is a remediation plan and actions; but the fix isn't trusted until a retest proves it, and a recurring or blocking deficiency can't simply be closed by assertion. The hard parts are effectiveness evidence, independent retest, and closure discipline (interim risk acceptance is not closure). ISCRM models all three.
The 18 models by area
Systems & Controls (5) - Entity — the audited organisation. - InformationSystem — a system in scope (criticality, lifecycle, is-financial). - ControlDomain — a grouping of objectives (e.g. Access, Change). - ControlObjective — what a set of controls must achieve. - Control — a specific control on a system, meeting an objective.
Assessment & Evidence (4) - AssessmentCycle — a testing cycle (e.g. FY2025-26). - ControlAssessment — a control tested in a cycle, with design/operating/overall effectiveness. - EvidenceRequirement — what evidence a control/assessment needs. - EvidenceSubmission — the evidence provided (URI, checksum, supersession).
Deficiencies & Remediation (4) - ControlDeficiency — a gap found by assessment (severity, closure-blocking, repeat-finding). - RemediationPlan — the plan to fix it, versioned with a current flag. - RemediationAction — a committed remediation action. - Retest — an independent retest of the control, with a pass/partial/fail outcome.
Assurance & Closure (5) - RiskAcceptance — a formally requested/approved interim acceptance of residual risk. - AssuranceDecision — an authorised decision (e.g. defer, accept, treat). - ClosureRequest — a request to close, declaring completion. - ClosureApproval — the authorised approve / reject / defer outcome. - StatusHistory — the lifecycle trail of a deficiency.
(The source pack's DomainEvent outbox is Phase 2 — see page 03.)
The demo scenario
A QAO-style IS-controls assessment of Queensland Health's finance system (SAP S/4HANA), cycle AC-2026, testing an access-management and a change-management control:
- Change control (CTL-CHG-01) — assessed EFFECTIVE; no deficiency.
- Access review control (CTL-ACC-01) — assessed INEFFECTIVE, raising two deficiencies:
- DEF-ACC-01 — Quarterly privileged access review not performed. Remediated (review scheduled and evidenced) → retest PASSED → closure APPROVED → CLOSED.
- DEF-ACC-02 — Terminated accounts not disabled promptly (a repeat finding). Automation in progress → retest FAILED → a pending risk acceptance and an assurance decision to defer → sits at REMEDIATION_IN_PROGRESS.
32 rows across all 18 models — the whole spine in both a "closed clean" and a "failed-retest / held-open" state.