Skip to content

[M0-D01 follow-up] Record the first client engagement facts #348

Description

@smiggleworth

Note

Follow-up discovery issue created 2026-09-22 when M0-D01 #58 closed. It collects organization facts; it does not block building the program, boundary, or engagement records, which already represent unknown targets and unconfirmed dates.

Decision needed

Record the first client engagement's organization-specific facts that the product owner did not have on 2026-09-22.

Questions to answer

  • Name the first client organization (or record that the first program is internal dogfooding).
  • Record the target Type I as-of date and the intended Type II observation period (start and length).
  • Identify the audit firm and any dates it has confirmed, with the objective evidence (engagement letter or written communication).
  • List the client services in the first system boundary.
  • Set due dates on the R1, R2, and T1 milestones from an agreed plan. Until then the milestones stay undated.

Decided context

Trust Services categories are Security plus Availability, Confidentiality, Processing Integrity, and Privacy (all five). See decision record.

Involve

Product owner, compliance lead, readiness advisor, audit firm.

Done when

  • Each fact is recorded here with owner, date, and evidence, or explicitly recorded as still unknown.
  • Milestone due dates are set only from an agreed plan.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:auditReadiness, auditor collaboration, and exportpriority:P1Important after the critical path is usabletype:discoveryProduct or domain decision required before implementation

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions