Definition
A periodic, methodical review of provenance records, fixity logs, access and operation logs, and associated metadata to assess, document, and increase confidence in the authenticity and integrity of a digital collection or subset.

Principle

Principle
Multiple independent evidentiary signals (provenance metadata, fixity history, access logs) evaluated together produce stronger, actionable confidence judgments about an object's integrity than any single signal alone.

Demonstration

Demonstration
Illustrative scenario → During a quarterly audit, reviewers compare ingest manifests, fixity histories, and access logs for a collection. Recognition: they find a gap in fixity checks overlapping with an unusual external access pattern. Action: they perform targeted integrity checks, restore from verified backups where needed, and update ingestion controls. Consequence: the institution documents the incident and reduces risk of undetected compromise.

Misapplication

Misapplication
Mistaken interpretation: treating auditing as purely retrospective evidence that guarantees irreversibility or legal authenticity. Error: an audit can reveal gaps or anomalies and support response but does not retroactively prove origin or prevent prior unseen compromise.

Consequence

Consequence
Integrity auditing surfaces systemic weaknesses, supports incident response and legal defensibility by documenting chains of evidence, and informs process improvements; it requires retained logs, reproducible procedures, and allocation of personnel and tooling.

Reversal

Reversal
Where real‑time monitoring and continuous verification at scale are implemented, periodic audits may detect issues later than automated alerts; conversely, in small or static collections, periodic audits may be sufficient and more resource‑efficient than continuous monitoring.

Boundary

Boundary
Clearly within: archival repositories, trusted digital repositories, or curated collections retaining provenance and operational logs. Boundary case: large-scale distributed datasets where log retention policies vary across nodes. Clearly outside: ephemeral transactional systems without preserved logs or scenarios where provenance cannot be reconstructed.

Semantic Tension

Semantic Tension
Transparency ↔ Privacy — comprehensive auditing improves integrity assurance but may require retaining or exposing access and provenance data that implicate user privacy or confidentiality.

Synthesis

Synthesis
Integrity auditing transforms dispersed operational signals into documented judgments about collection integrity: it is a governance practice that combines technical, procedural, and evidentiary controls to detect, explain, and remediate integrity risks.