Audit Management

Regulation, evidence, findings and CAP in one governed system

Designed for authorities that oversee aviation security.

Findings & CAP Tracker — open findings, overdue CAPs and evidence
Findings & CAP Tracker — open findings, overdue CAPs and evidence

Evidence, deadlines and corrective actions in one governed workspace

Explore the platform
PLAN // ASSIGN // EXECUTE // REVIEW // REMEDIATE // CLOSE // MONITOR_
Governed data model

A governed operational chain. Not a checklist app.

Oditrix binds regulation to field work, findings to corrective action, and monitoring back into the next plan.

RegulationQuestionEvidenceFindingCorrective ActionReportingMonitoring
Audit lifecycle

Closure is a control point. Not the end.

Seven governed stages keep regulation, evidence, ownership and authority attached to the work.

Plan

Activity, site, team, duration, question set

Assign

Commitment text accepted

Execute

Hints, evidence, levels, due dates

Review

Lead Auditor + AI-assisted report

Remediate

CAP submitted and reviewed

Close

Super Admin approval

Monitor

Deadlines, repeats, scores

Human-in-the-loop AI

AI assists. People decide.

AI proposes finding, recommendation and CAP language in standard AVSEC terminology. Auditors review, authorised users approve, Super Admin closes.

01 / Assist

AI proposes

Finding, recommendation and CAP language.

02 / Judgement

Auditor reviews and edits

Context and professional judgement remain human.

03 / Authority

Authorised user approves

AI cannot close findings or approve audits.

Modules

Eight modules. Four operating layers.

Plan and execute. Govern and remediate. Monitor and analyse. Keep people and closed records under control.

01 / Plan & Execute

Audit Management

Plan audits, inspections, tests & surveys; assign teams; track status.

  • 01

    Audit, inspection, test and survey planning

  • 02

    Team assignment and status tracking

  • 03

    Super Admin sign-off for opening and closure

  • 04

    System-captured timing and completion checks

02 / Plan & Execute

Question & Regulation Library

Sections, question banks and legal articles — versioned and controlled.

  • 01

    Controlled question banks and sections

  • 02

    Question–article references

  • 03

    Customer-authorised regulatory content

  • 04

    Audit records tied to the regulation in force at the time

03 / Plan & Execute

Field Application

Offline-capable mobile workspace with the full question screen.

  • 01

    Offline-capable mobile and tablet work

  • 02

    Regulation hints at the point of work

  • 03

    Photo evidence attached to findings

  • 04

    Device data cleared after transmission

04 / Govern & Remediate

AI Report Assistant

Finding → Recommendation → CAP drafts in standard AVSEC terminology.

  • 01

    Finding, recommendation and CAP draft language

  • 02

    Standard AVSEC terminology

  • 03

    Auditor review and editing

  • 04

    No autonomous closure or audit approval

05 / Govern & Remediate

Findings & CAP Tracker

Deadlines, follow-up audits, repeated findings and corrective-action review.

  • 01

    Due dates and named ownership

  • 02

    CAP submission and review

  • 03

    Repeated-finding detection

  • 04

    Follow-up and verification workflow

06 / Monitor & Analyse

Reports & Analytics

30+ reports, airport security scores, hotspots and trend views — Admin / Super Admin.

  • 01

    30+ management reports

  • 02

    Airport security scores and trend views

  • 03

    Severity hotspots by section and site

  • 04

    People, sites, sections and findings reporting

07 / People & Assurance

Personnel & Certification

Personnel files, certificates, validity dates, assignment gates and 90-day warnings.

  • 01

    Personnel files and certificates

  • 02

    Validity date monitoring

  • 03

    Assignment gates

  • 04

    90-day expiry warnings

08 / People & Assurance

Secure Archive

Closed audits, final reports and CAPs — UIDN-stamped, Admin-controlled.

  • 01

    Closed audits, final reports and CAPs

  • 02

    UIDN-watermarked downloads

  • 03

    Admin-controlled access

  • 04

    Accountable audit trail

Continuous assurance

Oversight as a standing state.

Open findings, deadlines and repeat signals are watched continuously — inspired by continuous-monitoring principles of USAP-CMA.

  • 01

    Audit completed

  • 02

    Findings remain live

  • 03

    CAP deadlines monitored

  • 04

    Repeated findings detected

  • 05

    Security score updated

  • 06

    Management alerted

  • 07

    Follow-up / verification

  • 08

    Risk profile updated

Data sovereignty

Your infrastructure. Your control.

Built for decision-makers who need ownership, access discipline and auditability.

Your infrastructure

Internal-network deployment on customer infrastructure — your staff install, engineers guide remotely.

Field to centre, controlled

Offline-capable field work; sync when linked; device data cleared after transmission.

Named accountability

Role-based access, dual-control approvals, UIDN-watermarked archive downloads.

Configurable controls

Encryption, MFA and directory integration per the customer’s approved architecture.

Architecture

Field to centre. Controlled.

A high-level architecture for decision-makers who need to understand ownership, data movement and operational boundaries.

01 / Field zone

Mobile / tablet

Offline work · evidence capture · data cleared after sync

02 / Customer security perimeter

Application · database · archive

Regulation library · analytics · AI layer*

03 / Management layer

Web console

Planning · approvals · reporting · archive

* AI processing per approved deployment architecture. Operational audit data remains within the customer’s controlled infrastructure.

Governance

Authority remains named.

Super Admin

Final authority on closure and location removals

Admin

Plans audits, tracks findings, reviews CAPs

Lead Auditor

Distributes sections, signs the final report

Auditor

Field execution, findings, severity

Observer

View-only training role with structured feedback

The workflow itself enforces discipline.

Completion checks, two-step confirmations, enforced question–article references, system-captured timing and consent before access.

  • 01

    Opening and closing audits requires Super Admin sign-off.

  • 02

    Customer-authorised content is versioned and linked.

  • 03

    AI cannot close findings or approve audits.

  • 04

    Every audit stays tied to the regulation in force at the time.

Next step

From audit activity to continuous AVSEC oversight.

Demonstrate Oditrix on a representative AVSEC workflow within your operational environment.