Overview
This business process outlines the activities that enable the Governance Authority to monitor compliance with established audit rules. The Governance Authority publishes audit rules that operationalise compliance requirements and specify the logs and metrics that Participants must provide as evidence of adherence
The required audit data is formally defined within the published audit rules for each Participant type, which state which logs and/or metrics must be supplied, along with the required format and level of aggregation. In exceptional cases, the Governance Authority may request additional audit data for ad‑hoc audits.
Audit logs and metrics are generated from the logs and metrics in the central log repository of each Participant’s Simpl‑Open agent based on aggregations and provided to the Governance Authority.
Audit dashboards and reports are used to generate insights actions of audited Participants related to the audit rules. This workflow applies to all Participants, namely Consumers, Providers, and the Governance Authority.
It includes the following main steps:
- Manage audit rules: Create, update and delete of audit rules and the required logs and metrics (and the required aggregations) to check the audit rules. The audit rules are published for all data space Participants and they are notified in case of changes to audit rules;
- Request audit logs and metrics from Participants for ad-hoc audits: Exchange of information follows the Governance Authority requests for ad-hoc audit data to Participants;
- Create and use audit dashboards: Compile audit logs and metrics into the custom dashboards for the purpose of standard auditing and ad-hoc audits;
- Participants provide audit logs & metrics to the Governance Authority: Define aggregations for sharing audit data and provide them to the Governance Authority through their Simpl-Open agent;
- Create and use audit reports: Compile the audit data into reports to provide insights;
- Generate audit alerts: Alerts are generated based on the configured specific conditions for the logs and metrics from the audit log repository.
Actors
The following actors are involved:
- Governance Authority
- Provider
- Consumer
In the diagrams, they will be described as Participant.
Assumptions
The following assumptions are made:
- The Simpl-Open agent is configured to capture all types of logs and metrics in the central log repository of each Participant.
- The Simpl-Open agent is configured to persist audit data in the audit logs repository.
- A solution is in place to exchange the logs and metrics between the Governance Authority and the Participants.
- A solution is in place for monitoring, alerting and visualising of the data from the audit logs repository.
Prerequisites
The prerequisites for this workflow are outlined below. These prerequisites must be met to enable the process to occur:
- Data space is configured: The Governance Authority has configured the data space catalogue with the corresponding vocabulary and schemas to have the general structure of a resource description, contract clauses, and other vital components (Business Process 2).
- Participant onboarded: Before the Participant can log & monitor its Simpl-Agent, they should have successfully completed the onboarding business process (Business Process 3A).
Details
The following shows the detailed business process diagram and gives the step descriptions.

Trigger audit of a Participant
BP12D.01 Manage audit rules
The Governance Authority establishes the audit rules and the audit data requirements, that specify the data that must be provided to verify compliance with those rules. At this step, the audit rules are created, updated and deleted, when the required logs and metrics together with the required aggregations, are no longer needed to check the audit rules.
BP12D.02 Notify all Participants about changes to audit rules
The Governance Authority notifies all Participants about the new and updated audit rules and audit data requirements in case of changes to the audit rules. These are published for Participants and data space applicants.
BP12D.03 Request audit logs and metrics from Participants for ad-hoc audits
The Governance Authority requests additional audit data (including the audit data requirements) for ad-hoc audits from the Participants and Participants can reply to ask for clarifications.
BP12D.04 Provide requested audit logs and metrics
Based on the established audit rules and ad-hoc request, a Participant defines the required audit data aggregations for providing audit data to the Governance Authority through their Simpl-Open agent.
BP12D.05 Persist audit logs & metrics
The Governance Authority persists the audit data provided by the Participants in their audit repository.
BP12D.06 Create and use audit dashboards
The Governance Authority creates and configures custom dashboards by compiling the audit logs and metrics for the purpose of standard auditing and ad-hoc audits.
BP12D.07 Create and use audit reports
The Governance Authority creates reports to audit Participants of the data space regarding their actions related to both the standard audit rules and the ad-hoc audits. The audit reports are created via UI based on the logs and metrics from the audit repository.
BP12D.08 Generate audit alerts
The Governance Authority creates and configures audit alerts based on logs and metrics from the audit repository in accordance with the standard audit rules. When an anomaly related to these audit rules is detected in a Participant’s actions, the corresponding alert is automatically sent to the configured recipient and stored in the alert repository of the Governance Authority’s Simpl-Open agent.
Outcomes
- Visualise and analyse audit dashboards: Audit custom dashboards are created exclusively for standard audits and ad‑hoc audits, with separate dashboards for each type of data collected based on the predefined and agreed audit rules.
- Visualise and analyse audit alerts: Audit alerts are shared with the assigned recipients as they occur and stored in the alert repository of the Simpl-Open agent. Logs and metrics are stored in a consistent and accessible format in the audit repository, making them available for further investigation of the raised alerts.
Visualise and analyse audit reports: Logs and metrics are stored in a consistent and accessible format in the audit repository for performing ad-hoc analysis supported by queries and aggregated views (e.g., table, diagrams, etc.) of the collected logs to identify patterns, trends, and anomalies (example of who is doing this: IT admin of the Simpl-Open agent).
Business Process Status: Proposed Detailed Requirements
12D.1 - The Governance Authority manages audit rules
Simpl-Open shall allow the Governance Authority to create: ...
See more details12D.2 - A Participant consults audit rules
Simpl-Open shall allow a Participant to consult the audit rules ...
See more details12D.3 - The Governance Authority initiates an ad-hoc audit
Simpl-Open shall allow the Governance Authority to initiate: ...
See more details12D.4 - A Participant provides logs and metrics to the Governance Authority for audit purposes
Simpl-Open shall allow a Participant to provide logs: ...
See more details12D.5 - The Governance Authority persists audit logs and metrics from Participants
Simpl-Open shall allow the Governance Authority to persist: ...
See more details12D.6 - The Governance Authority audits the actions of Participants related to audit rules
Simpl-Open shall allow the Governance Authority to use custom: ...
See more details12D.7 - The Governance Authority generates audit alerts about the actions of Participants related to audit rules
Simpl-Open shall support the Governance Authority to generate alerts: ...
See more details12D.8 - The Governance Authority creates audit reports about the actions of Participants related to audit rules
Simpl-Open shall support the Governance Authority to create ...
See more details
Please log in or sign up to comment.