An audit asks for dated documents and a credible audit trail. Here is what Illizeo keeps, where to find it, and what has to come from elsewhere.
What an audit asks for, and where to find it #
An audit does not ask for a report: it asks for documents, and for evidence that they were not produced for the occasion. Illizeo has no “prepare an audit” feature, but it keeps what you need to answer.
| Typical request | Where to find it |
|---|---|
| Contracts and amendments | The employee’s document space, by category |
| Pay history | The employee record, by effective date |
| Working time and work rate | Approved attendance and the rate history |
| Absences and their supporting documents | The Absences module and attached documents |
| What was sent to payroll, and when | Each period’s files, dated and versioned |
| Who changed what | The audit log — cryptographically chained for immutable entries |
Step by step #
-
Bound the period and the people #
An audit covers a defined scope. Bounding it first avoids producing documents nobody asked for — and which open other questions.
-
Gather documents, not extracts #
Prefer the original document to a screenshot or a reconstructed table. A signed contract beats a line in an export.
-
Explain differences with versions #
Where a period was redone, comparing two versions shows exactly what changed, and the audit log shows who did it. That is more convincing than a recollection.
-
Verify the audit trail’s integrity #
The log’s immutable entries are chained: a server-side verification returns an integrity verdict over the whole chain, with no dependence on a third party.
-
Do not reopen a period without reason #
A revoked approval leaves a trace. During an audit, better to explain a mistake than to have it discovered that you quietly corrected it.
What does not exist #
No “audit” screen and no automatically generated audit pack. No checklist per authority or per country. No temporary access to create for an external auditor: if you want to open read access, it goes through a role — preferably a temporary one, with an end date.
FAQ #
Can we give an auditor read access?
Yes, through a role scoped to strictly what is needed. A temporary role with an end date stops having effect on its own — better than access someone forgets to remove.
Is the audit trail tamper-proof?
No, and nobody should claim it is. It is tamper-evident: any alteration of a chained entry is caught when the chain is recomputed. That is what holds up in front of an auditor.
How long is data kept?
According to your retention policy. Check it before an audit covers a period already purged.
What about items not held in Illizeo?
Payslips, declarations and payment evidence come from the payroll producer. Warn them as soon as the audit notice arrives: they are often the slowest link.
