# Business operations audit checklist

DutyGraph working worksheet. Educational scoping aid, not a financial audit or compliance opinion. Fill this in for ONE workflow. Blank means unknown, not a failure.

## 1. Set a useful boundary

Workflow name:
Starts when:
Ends when:
Business question:
Sponsor:
Day-to-day work owner:
Participants and receiving teams:
Information approved for collection:
Review date:

## 2. Ask about actual work

- What arrives at the start? Who provides it?
- What information is required before anyone can act?
- Who performs each meaningful step?
- What system or document is used, and for which purpose?
- Who decides whether the result is acceptable?
- Which exceptions change the normal sequence?
- What waits for another person, decision or input?
- What is passed to the next team? How do they accept it?
- Which workaround is routine but not documented?
- What happens when the usual owner is unavailable?

## 3. Keep evidence and interpretation separate

| Observation | Source and date | Reported or observed? | Who reviewed it? | Open question |
|---|---|---|---|---|
| | | | | |
| | | | | |
| | | | | |

Do not put personal, confidential or restricted data into an unapproved shared copy. A report that something takes too long is not a measured duration until evidence supports it.

## 4. Decide what deserves follow-up

Candidate issue:
Why it matters:
Supporting evidence:
Alternative explanation:
Who can clarify:
Smallest useful test:
Baseline needed:
Decision owner:
Review date:

## 5. Close the review

Record findings, unanswered questions and proposed actions separately. Obtain the appropriate owner review. A completed checklist is not authorization to change access, deploy an agent or remove a human checkpoint.

More guidance: https://dutygraph.com/learn/business-operations-audit-checklist/
Discuss a scoped review: https://dutygraph.com/business-operations-audit/
