Definition
A periodic, methodical review of provenance records, fixity logs, access and operation logs, and associated metadata to assess, document, and increase confidence in the authenticity and integrity of a digital collection or subset.
Principle
Principle
Multiple independent evidentiary signals (provenance metadata, fixity history, access logs) evaluated together produce stronger, actionable confidence judgments about an object's integrity than any single signal alone.
Demonstration
Demonstration
Illustrative scenario → During a quarterly audit, reviewers compare ingest manifests, fixity histories, and access logs for a collection. Recognition: they find a gap in fixity checks overlapping with an unusual external access pattern. Action: they perform targeted integrity checks, restore from verified backups where needed, and update ingestion controls. Consequence: the institution documents the incident and reduces risk of undetected compromise.
Misapplication
Misapplication
Mistaken interpretation: treating auditing as purely retrospective evidence that guarantees irreversibility or legal authenticity. Error: an audit can reveal gaps or anomalies and support response but does not retroactively prove origin or prevent prior unseen compromise.
Consequence
Consequence
Integrity auditing surfaces systemic weaknesses, supports incident response and legal defensibility by documenting chains of evidence, and informs process improvements; it requires retained logs, reproducible procedures, and allocation of personnel and tooling.
Reversal
Reversal
Where real‑time monitoring and continuous verification at scale are implemented, periodic audits may detect issues later than automated alerts; conversely, in small or static collections, periodic audits may be sufficient and more resource‑efficient than continuous monitoring.
Boundary
Boundary
Clearly within: archival repositories, trusted digital repositories, or curated collections retaining provenance and operational logs. Boundary case: large-scale distributed datasets where log retention policies vary across nodes. Clearly outside: ephemeral transactional systems without preserved logs or scenarios where provenance cannot be reconstructed.
Semantic Tension
Semantic Tension
Transparency ↔ Privacy — comprehensive auditing improves integrity assurance but may require retaining or exposing access and provenance data that implicate user privacy or confidentiality.
Synthesis
Synthesis
Integrity auditing transforms dispersed operational signals into documented judgments about collection integrity: it is a governance practice that combines technical, procedural, and evidentiary controls to detect, explain, and remediate integrity risks.