Audit Finding Reporting & Management
Consolidated 45+ audit categories from IS, management, inspection and branch audits into one repository with event-driven notifications and granular access control.
- Context
- Awash Bank · Core Systems
- My role
- Backend engineer — repository design, RBAC & reporting
- Primary stack
- Spring Framework · Spring Security · Angular
Measured impact
- Audit categories
- 45+
- IS, management, inspection and branch audit types unified
- Rectification rate
- +45%
- Improvement in discrepancy resolution
- Roles
- 20+
- Granular RBAC across compliance and governance functions
The problem
Operational challenge
Audit findings were fragmented across more than 45 categories and as many spreadsheets. Nobody could answer 'what is outstanding, and who owns it' without a manual reconciliation, so rectification slipped and compliance response was slow.
The approach
Implementation strategy
I designed a centralised repository with category-aware ingestion, event-driven notifications that escalate ageing findings automatically, and a 20+ role RBAC model so each function sees exactly its own scope. Reviewers compile findings into summary reports directly in the system.
Engineering trade-offs
Compliance requirements meant data integrity outranked feature velocity. I kept the schema strict and the write paths narrow, accepting slower iteration in exchange for records that survive an external audit.
What I built
Delivery highlights
- Modelled 45+ heterogeneous audit categories into one schema without losing category-specific fields.
- Built event-driven notification and escalation so ageing findings surface before they breach SLA.
- Implemented 20+ role RBAC with field-level scoping on top of Spring Security.
- Delivered compilation and review workflows that turn raw findings into board-ready summary reports.
How it fits together
System architecture
Interface
System screens
7 captures from the live system. Select any image to view it full size.