Book page

BP12D - Governance Authority audits data space Participants

Default profile image
Yevheniia Tkachova • 24 April 2026

 

 

Overview

This business process outlines the activities that enable the Governance Authority to monitor compliance with established audit rules. The Governance Authority publishes audit rules that operationalise compliance requirements and specify the logs and metrics that Participants must provide as evidence of adherence

The required audit data is formally defined within the published audit rules for each Participant type, which state which logs and/or metrics must be supplied, along with the required format and level of aggregation. In exceptional cases, the Governance Authority may request additional audit data for ad‑hoc audits.

Audit logs and metrics are generated from the logs and metrics in the central log repository of each Participant’s Simpl‑Open agent based on aggregations and provided to the Governance Authority.

Audit dashboards and reports are used to generate insights actions of audited Participants related to the audit rules. This workflow applies to all Participants, namely Consumers, Providers, and the Governance Authority.

It includes the following main steps:

  • Manage audit rules: Create, update and delete of audit rules and the required logs and metrics (and the required aggregations) to check the audit rules. The audit rules are published for all data space Participants and they are notified in case of changes to audit rules;
  • Request audit logs and metrics from Participants for ad-hoc audits: Exchange of information follows the Governance Authority requests for ad-hoc audit data to Participants;
  • Create and use audit dashboards: Compile audit logs and metrics into the custom dashboards for the purpose of standard auditing and ad-hoc audits;
  • Participants provide audit logs & metrics to the Governance Authority: Define aggregations for sharing audit data and provide them to the Governance Authority through their Simpl-Open agent;
     
  • Create and use audit reports: Compile the audit data into reports to provide insights;
  • Generate audit alerts: Alerts are generated based on the configured specific conditions for the logs and metrics from the audit log repository.                          

Actors

The following actors are involved:

  • Governance Authority
  • Provider
  • Consumer

In the diagrams, they will be described as Participant.

Assumptions

The following assumptions are made:

  • The Simpl-Open agent is configured to capture all types of logs and metrics in the central log repository of each Participant.
  • The Simpl-Open agent is configured to persist audit data in the audit logs repository.
  • A solution is in place to exchange the logs and metrics between the Governance Authority and the Participants.
  • A solution is in place for monitoring, alerting and visualising of the data from the audit logs repository.

Prerequisites

The prerequisites for this workflow are outlined below. These prerequisites must be met to enable the process to occur:

  • Data space is configured: The Governance Authority has configured the data space catalogue with the corresponding vocabulary and schemas to have the general structure of a resource description, contract clauses, and other vital components (Business Process 2).
  • Participant onboarded: Before the Participant can log & monitor its Simpl-Agent, they should have successfully completed the onboarding business process (Business Process 3A).

Details

The following shows the detailed business process diagram and gives the step descriptions.

Trigger audit of a Participant

 

BP12D.01 Manage audit rules 

The Governance Authority establishes the audit rules and the audit data requirements, that specify the data that must be provided to verify compliance with those rules. At this step, the audit rules are created, updated and deleted, when the required logs and metrics together with the required aggregations, are no longer needed to check the audit rules.

BP12D.02 Notify all Participants about changes to audit rules

The Governance Authority notifies all Participants about the new and updated audit rules and audit data requirements in case of changes to the audit rules. These are published for Participants and data space applicants. 

BP12D.03 Request audit logs and metrics from Participants for ad-hoc audits

The Governance Authority requests additional audit data (including the audit data requirements) for ad-hoc audits from the Participants and Participants can reply to ask for clarifications.

BP12D.04 Provide requested audit logs and metrics

Based on the established audit rules and ad-hoc request, a Participant defines the required audit data aggregations for providing audit data to the Governance Authority through their Simpl-Open agent.

BP12D.05 Persist audit logs & metrics

The Governance Authority persists the audit data provided by the Participants in their audit repository.

BP12D.06 Create and use audit dashboards

The Governance Authority creates and configures custom dashboards by compiling the audit logs and metrics for the purpose of standard auditing and ad-hoc audits.

BP12D.07 Create and use audit reports                   

The Governance Authority creates reports to audit Participants of the data space regarding their actions related to both the standard audit rules and the ad-hoc audits. The audit reports are created via UI based on the logs and metrics from the audit repository.

BP12D.08 Generate audit alerts

The Governance Authority creates and configures audit alerts based on logs and metrics from the audit repository in accordance with the standard audit rules. When an anomaly related to these audit rules is detected in a Participant’s actions, the corresponding alert is automatically sent to the configured recipient and stored in the alert repository of the Governance Authority’s Simpl-Open agent.

Outcomes

  • Visualise and analyse audit dashboards: Audit custom dashboards are created exclusively for standard audits and ad‑hoc audits, with separate dashboards for each type of data collected based on the predefined and agreed audit rules.
  • Visualise and analyse audit alerts: Audit alerts are shared with the assigned recipients as they occur and stored in the alert repository of the Simpl-Open agent. Logs and metrics are stored in a consistent and accessible format in the audit repository, making them available for further investigation of the raised alerts. 
  • Visualise and analyse audit reports: Logs and metrics are stored in a consistent and accessible format in the audit repository for performing ad-hoc analysis supported by queries and aggregated views (e.g., table, diagrams, etc.) of the collected logs to identify patterns, trends, and anomalies (example of who is doing this: IT admin of the Simpl-Open agent).

    Business ProcessStatus: Proposed

    Detailed Requirements

  • 12D.1 - The Governance Authority manages audit rules
    Simpl-Open shall allow the Governance Authority to create: ...
    See more details

  • 12D.2 - A Participant consults audit rules
    Simpl-Open shall allow a Participant to consult the audit rules ...
    See more details

  • 12D.3 - The Governance Authority initiates an ad-hoc audit
    Simpl-Open shall allow the Governance Authority to initiate: ...
    See more details

  • 12D.4 - A Participant provides logs and metrics to the Governance Authority for audit purposes
    Simpl-Open shall allow a Participant to provide logs: ...
    See more details

  • 12D.5 - The Governance Authority persists audit logs and metrics from Participants
    Simpl-Open shall allow the Governance Authority to persist: ...
    See more details

  • 12D.6 - The Governance Authority audits the actions of Participants related to audit rules
    Simpl-Open shall allow the Governance Authority to use custom: ...
    See more details

  • 12D.7 - The Governance Authority generates audit alerts about the actions of Participants related to audit rules
    Simpl-Open shall support the Governance Authority to generate alerts: ...
    See more details

  • 12D.8 - The Governance Authority creates audit reports about the actions of Participants related to audit rules
    Simpl-Open shall support the Governance Authority to create ...
    See more details

Be the first one to comment


Please log in or sign up to comment.