Furries PH Docs
Dashboard
Asset Management System docs

Lifecycles

Audit and Reconciliation

Run blind counts, investigate differences, post corrections, and close an AMS audit without erasing evidence.

First created Last updated

amsauditsreconciliationlifecycle

AMS audits reconcile what the system says should exist with what an independent counter can physically prove. They do not rewrite history. A posted variance creates a new, actor-attributed movement linked to the audit and leaves the original custody, transit, and count evidence intact.

Choose the audit scope

Use a wall-to-wall audit for a full facility or register closeout. Use cycle, spot, zero-bin, or critical-asset audits for targeted control work. Record the partner, locations, ownership register, categories, assets or containers, cutoff time, count mode, tolerance, and responsible reviewer before counting begins.

Keep Owned Assets and Loaned Assets distinguishable throughout the audit. A Loaned Asset discrepancy also requires agreement, owner, condition, evidence, and return-obligation review; it never becomes an FPH-owned adjustment merely because it is present or missing.

Freeze and preserve the cutoff

  1. Record the audit reference and cutoff time.
  2. Finish or explicitly suspend open checkouts, transfers, shipments, dock work, and maintenance movements in scope.
  3. Export the versioned pre-count snapshot and retain its hash.
  4. Assign counters who did not perform the movement being verified where practical.
  5. Use blind counting when prior quantities could bias the result.

Operations may continue outside the scope. If emergency movement must occur inside it, scan and record that movement against the cutoff instead of editing a count.

Count and investigate

Scan the canonical QR, barcode, NFC, or approved identifier, then record quantity, condition, quality status, location, container, and evidence. Duplicate reads are suppressed; a tag is only a pointer to the canonical record. When an item has no registered match, record its readable physical identifier as an unregistered observation instead of making up an asset ID. The service persists that observation as an unexpected result, keeps assetId empty, safely replays a lost-response retry with the same idempotency key, and requires the same independent review before the audit can be posted.

Investigate every difference against:

  • movements after the cutoff;
  • active checkout and accountable custodian;
  • container membership and partial receipts;
  • quarantine, maintenance, staging, dock, or virtual-transit locations;
  • tag replacement, suspected clone, or unreadable-label history;
  • unit-of-measure or serialized-versus-quantity mistakes;
  • Loaned Asset agreement and owner-return records.

The first counter must not silently replace a disputed result. Record a recount by a different actor and preserve both observations. Large, sensitive, or policy-threshold variances require an independent approver and recent step-up authentication.

Post and close

Only a clean, reviewed audit can be posted. Each non-matching result requires a separate independent review that records root cause, remediation, audit-capable remediation owner, due date, and review reason; the original counter cannot perform that review. The server rejects posting while any non-matching result remains unreviewed. Posting creates compensating quantity/location/condition events, updates the derived current state atomically, and records the signed-in actor and server time. It must never backdate, delete, or mutate the original movement.

Before closeout, verify:

  • expected quantity = counted quantity + approved unresolved exceptions;
  • no asset has negative availability or conflicting custody/container state;
  • all discrepancy, damage, missing, and excess findings have evidence and disposition;
  • Loaned Asset owner notification, claim, renewal, or return action is recorded where required;
  • operational totals reconcile to the AMS subledger without treating custody as accounting recognition;
  • posted economic corrections, if any, use the applicable open period and maker-checker workflow;
  • the post-count snapshot validates and its hash is retained with the audit pack.

The audit pack contains scope and cutoff, pre/post snapshots, count observations, recounts, variance approvals, compensating events, attachments, unresolved exceptions, reconciliation totals, and closeout actor/time. Retain it under the configured policy; restricted evidence remains private and short-lived download links must not be copied into permanent records.

Failure and recovery

Retry a timed-out count or post with the same idempotency key. Do not create a replacement audit merely because the response was lost. If scanning is unavailable, use the controlled continuity worksheet, preserve device/operator/time and source references, then import through dry-run validation and reconcile before posting.

After restoration, compare the checkpoint fingerprint, asset/movement counts, open-audit state, and last accepted idempotency keys before reopening movement. Record achieved RTO/RPO and any loss or replay as continuity evidence. The current local certification verifies zero-row-loss checkpoint copy/restore and no-oversell contention, but production backup restoration remains an operator-controlled platform exercise.

This control model follows the lifecycle, traceability, reconciliation, and continual-improvement intent of ISO 55001:2024, the financial/non-financial alignment of ISO/TS 55010:2024, and continuity evidence principles from ISO 22301:2019. These references guide the workflow; they are not claims of ISO certification.

All docs