This checklist implements the four fault-line framework for auditing documents in the Oraculus Decimus Intellect Analyst system. Use this checklist to systematically review documents for compliance and identify potential issues.
The four fault lines represent critical areas of legal, ethical, and policy compliance:
- DOJ Certification - Department of Justice certification and law enforcement compliance
- IRB Consent (28 C.F.R. Part 46) - Institutional Review Board and human subjects protections
- Infrastructure Policy - Facility, procurement, and contractor compliance
- Federal Grant Incentives - Grant funding mechanisms and conflict of interest
- DOJ Certification Present: Document includes explicit DOJ certification or reference
- Law Enforcement Authority: Proper law enforcement authority and jurisdiction established
- Criminal Investigation Standards: Compliance with criminal investigation procedures
- Evidence Chain of Custody: Proper evidence handling and chain-of-custody procedures documented
- Legal Process Compliance: Warrants, subpoenas, or court orders properly obtained
- Information Sharing Protocols: Appropriate information sharing agreements in place
- Privacy Act Compliance: Compliance with Privacy Act requirements for law enforcement records
- FOIA Exemptions: Proper application of Freedom of Information Act exemptions
- Missing DOJ certification where required
- Unauthorized law enforcement activities
- Improper evidence handling
- Information sharing without legal basis
- Privacy Act violations
- Verify DOJ certification requirements for all law enforcement documents
- Flag documents with missing certifications for legal review
- Ensure proper chain-of-custody documentation for all evidence
- Review information sharing agreements for legal compliance
- IRB Approval Present: Research has valid Institutional Review Board approval
- Informed Consent Documented: Proper informed consent obtained from subjects
- Consent Form Adequate: Consent forms meet regulatory requirements
- Subject Protections: Adequate protections for human research subjects
- Vulnerable Population Protections: Special protections for children, prisoners, pregnant women
- Risk Assessment: Proper assessment and minimization of risks to subjects
- Confidentiality Measures: Adequate measures to protect subject confidentiality
- Continuing Review: Evidence of ongoing IRB continuing review
- Adverse Event Reporting: Procedures for reporting adverse events to IRB
- HIPAA Compliance: Health Insurance Portability and Accountability Act compliance where applicable
- Research conducted without IRB approval
- Missing or inadequate informed consent
- Lack of protections for vulnerable populations
- Confidentiality breaches
- Failure to report adverse events
- Verify IRB approval status for all research documents
- Review informed consent procedures and documentation
- Identify documents involving vulnerable populations requiring special protections
- Flag any research activities without proper IRB oversight
- Consult with IRB and legal counsel on compliance issues
- Facility Compliance: Facilities meet applicable safety and regulatory standards
- Procurement Compliance: Procurement follows federal acquisition regulations (FAR)
- Contractor Oversight: Proper contractor selection and oversight procedures
- Conflict of Interest Checks: Conflicts of interest identified and managed
- Security Requirements: Facility and information security requirements met
- Environmental Compliance: Environmental regulations and permits in place
- Accessibility Standards: ADA and accessibility requirements met
- Quality Assurance: Quality control and assurance programs operational
- Record Keeping: Proper infrastructure documentation and record keeping
- Audit Trail: Complete audit trail for infrastructure decisions
- Facility non-compliance or safety violations
- Procurement irregularities or FAR violations
- Inadequate contractor oversight
- Unmanaged conflicts of interest
- Security deficiencies
- Environmental violations
- Review all facility compliance documentation
- Audit procurement processes for FAR compliance
- Verify contractor oversight and performance monitoring
- Identify and document conflicts of interest
- Ensure security requirements are met
- Flag infrastructure policy violations for immediate remediation
- Grant Authorization: Proper authorization for federal grant funding
- Grant Compliance: Compliance with all grant terms and conditions
- Budget Alignment: Expenditures align with approved grant budget
- Matching Funds: Required matching funds or cost-sharing documented
- Performance Metrics: Grant performance metrics and milestones tracked
- Financial Reporting: Timely and accurate financial reporting to grantor
- Audit Requirements: Grant audit requirements satisfied
- Conflict of Interest Policy: Grant-specific conflict of interest policies in place
- Indirect Cost Compliance: Indirect costs properly calculated and approved
- Close-out Procedures: Grant close-out procedures followed
- Unauthorized use of grant funds
- Failure to meet grant conditions
- Budget violations or cost overruns
- Missing matching funds
- Incomplete financial reporting
- Conflicts of interest involving grant funding
- Improper indirect cost rates
- Verify grant authorization and terms for all federally funded activities
- Review financial reports for accuracy and compliance
- Ensure matching funds and cost-sharing requirements are met
- Identify conflicts of interest related to grant funding
- Flag grant compliance issues for financial review
- Coordinate with grants management office on remediation
- PII Handling: Personally identifiable information properly protected
- Data Security: Appropriate data security measures in place
- Access Controls: Proper access controls and authorization
- Encryption: Sensitive data encrypted in transit and at rest
- Data Retention: Data retention policies followed
- Breach Response: Data breach response plan in place
- Legal Counsel Review: Documents reviewed by qualified legal counsel where required
- Litigation Holds: Documents subject to litigation hold properly preserved
- Privilege Review: Attorney-client privilege properly asserted
- Regulatory Compliance: Compliance with all applicable regulations verified
For each document under audit, complete this checklist:
- Document ID: _______________
- Document Title: _______________
- Date Reviewed: _______________
- Reviewer: _______________
| Fault Line | Applicable | Compliant | Issues Identified | Severity |
|---|---|---|---|---|
| DOJ Certification | ☐ Yes ☐ No | ☐ Yes ☐ No | ☐ Low ☐ Med ☐ High ☐ Critical | |
| IRB Consent | ☐ Yes ☐ No | ☐ Yes ☐ No | ☐ Low ☐ Med ☐ High ☐ Critical | |
| Infrastructure | ☐ Yes ☐ No | ☐ Yes ☐ No | ☐ Low ☐ Med ☐ High ☐ Critical | |
| Grant Incentives | ☐ Yes ☐ No | ☐ Yes ☐ No | ☐ Low ☐ Med ☐ High ☐ Critical |
Total Issues: _______________
Critical Issues: _______________
High Severity Issues: _______________
Requires Legal Review: ☐ Yes ☐ No
Requires Immediate Action: ☐ Yes ☐ No
The Oraculus Decimus Intellect Analyst provides automated support for this checklist:
- Manifest Flags: Use
scripts/triage.pyto add flags with categories matching fault lines - Report Generation: Use
scripts/render_report.pyto generate compliance reports - Query Evaluation: Use
scripts/eval_harness.pywith IRB and compliance queries
python scripts/triage.py --doc-id DOC123 \
--flag "Missing IRB approval documentation" \
--severity critical \
--category irb_consent \
--author "Compliance Officer"- 28 C.F.R. Part 46 - Protection of Human Subjects
- Department of Justice Certification Requirements
- Federal Acquisition Regulation (FAR)
- OMB Uniform Guidance (2 C.F.R. Part 200)
- Privacy Act of 1974
- HIPAA Privacy Rule
- Freedom of Information Act (FOIA)
Version: 1.0.0
Last Updated: 2024
Maintained by: Oraculus Decimus Intellect Analyst Project