Foundational control · Segregation of duties
Maker-Checker — every asset addition reviewed before it hits the FAR
Whether added through mobile, bulk import, or ERP sync — every asset goes through a dedicated review queue before it appears on the live Fixed Asset Register.
- · Pending — awaiting checker review (default)
- · Approved — live on the FAR
- · Rejected — returned with reason for resubmission
- · Bypassed — ERP-direct, governed in source
- · AutoApproved — low-value threshold (configurable)
- · Submitter ≠ approver (SOX 404 / ISO 27001 A.5.15)
- · Reject requires a non-empty reason (control evidence)
- · Bulk approve up to 5,000 in one action
- · Edit-during-review captured as separate timeline event
- · FAR-default view excludes pending records — auditors see only approved data
- · Mobile audit → Department asset manager
- · Bulk import → CSV uploader's manager
- · Manual web → Default Asset Manager
- · ERP sync → Bypassed (no human review needed)
- · API direct → Configurable per integration
- · FAR — Submitted By + Approved By + Approved Date columns
- · Asset Detail — Audit & Provenance panel (gold-bordered)
- · Review Queue — full timeline + bulk-batch IDs
- · Auditor-Ask AI — answers governance questions instantly
Foundational control
Server-stamped audit trail — who, what, when on every record
Every state change is stamped server-side with the actor's identity (from JWT), a server-clock timestamp, and the field delta. Immutable — no code path writes without logging.
- · FAR — Created By + Created Date columns
- · Asset Detail — Audit & Provenance panel
- · Asset history timeline — every event tagged with actor
- · Auditor-Ask AI — answers 'who added asset X?' instantly
- · EF Core SaveChanges interceptor (server-side)
- · User ID pulled from JWT (not request body)
- · Timestamp from server clock (not client clock)
- · Same code path for every save — no opt-out
ISO/IEC 27001
SecurityInformation Security Management Systems
The international benchmark for an ISMS — risk-based, continuously improved, evidence-backed. Osolix is built and operated in alignment with ISO/IEC 27001, and maps Annex A controls (A.5 – A.8) to platform features so an auditor can walk down the list without leaving the product.
Clauses 4–10 — the management system itself: policy, risk register, SoA, internal audit
A complete, version-controlled ISMS document suite: Information Security Policy with seven measurable objectives, a populated 5×5 risk register with named treatments, a Statement of Applicability covering all 93 Annex A controls with per-control evidence pointers, and a formalised internal-audit and access-review programme.
Statement of Applicability v1.0A.5.15 Access control — role-based, least-privilege, segregation of duties
Every screen and API is gated by a tenant-scoped RBAC matrix with delegation-of-authority chains, four-eyes approvals, and SoD checks at the schema layer (not just the UI). Cross-kind protection prevents client admins from modifying internal staff and vice-versa.
RBAC test matrixA.5.31 Compliance with legal, statutory, regulatory, contractual requirements
Standards-mapping registry (this page) plus a per-tenant compliance configuration that toggles IFRS / US GAAP / GASB books per entity. Privacy requests, data-subject rights, and breach-notification timers are baked into the workflow engine.
Trust CenterA.8.5 Secure authentication — MFA, password complexity, session timeouts
Email-verified accounts (EmailVerifiedAt stamp), failed-login lockouts, JWT-based sessions with refresh tokens, optional SSO / OIDC, time-boxed sensitive-action re-auth.
A.8.15 Logging — tamper-evident audit log of access + state changes
AuditInterceptor (SaveChanges hook) records who/what/when/why on every entity write. CreatedBy + CreatedDate are server-stamped from the JWT subject claim — never user-typed — and surfaced on the Fixed Asset Register and every asset detail page.
How audit trail works (this page)A.8.24 Use of cryptography — encryption at rest and in transit
TLS 1.2+ for every transport. Database encryption at rest. Sensitive credentials (ERP integrations, SMTP, OAuth secrets) sealed with column-level encryption.
SOX 404
SecuritySarbanes-Oxley Act §404 — Management Assessment of Internal Controls
Public-company management must attest to the effectiveness of internal control over financial reporting. Osolix supplies the IT General Controls (ITGC), application controls, and audit evidence an external auditor will test.
ITGC: change management, access management, computer operations, program development
Branch-protected source control with mandatory PR review. Access changes flow through approval workflow. Backup + restore drills run on a published cadence (RTO 1h / RPO 5min). Every release is reproducible from a tagged commit.
Restore-drill runbookApplication controls: completeness, accuracy, validity, restricted access
Server-side validation on every monetary field, three-way matching (PO → GRN → invoice) for additions, mandatory tag-uniqueness enforcement at the database constraint level, and tenant-scoped query filters that no API path can bypass.
Segregation of duties — preparer ≠ approver ≠ payer
Workflow templates for additions, transfers, retirements, and write-offs each enforce a four-eyes (or six-eyes for high-value) approval chain. SoD violations are flagged at submission, not after the fact.
Audit trail: who, what, when, why for every financial event
Every Asset, Lease, Capex, Maintenance, Verification, Transfer, Retirement, and Insurance record carries CreatedBy / CreatedAt / UpdatedBy / UpdatedAt — populated by the AuditInterceptor on every save path with no opt-out. The Asset Detail page surfaces this in a dedicated "Audit & Provenance" panel for auditor walkthroughs.
Audit charter v1Evidence retention — 7 years for SEC registrants
Soft-delete semantics across the entire schema (no hard deletes from the UI). Long-term archive policies configurable per entity. Deleted records remain auditable and indexable.
SOC 2
SecurityTrust Services Criteria — Security, Availability, Confidentiality, Processing Integrity, Privacy
The de-facto SaaS-procurement bar. Osolix is engineered in alignment with the AICPA Trust Services Criteria — our SOC 2 control matrix maps each criterion to a platform feature.
CC6 Logical & physical access — provisioning, MFA, periodic re-certification
Joiner-Mover-Leaver workflow with quarterly access review, MFA enforced for admin roles, automatic disablement on user termination event (HRIS webhook).
SOC 2 control matrixCC7 System operations — change, incident, vulnerability, monitoring
Versioned migrations, blue-green deploys, SLO + error-budget telemetry, public status page, incident runbook with named on-call rotation.
Incident response playbookA1 Availability — capacity, environmental, recovery
Multi-AZ deployments, autoscaling, scheduled DR drills, cross-region failover documented and tested.
Cross-region failover drillC1 Confidentiality — data classification + handling
Tenant isolation is enforced server-side through global query filters, tenant-scoped authorization claims, and strict data partitioning across all query and API paths.
IAS 16
AccountingProperty, Plant and Equipment
The base IFRS standard for capitalised tangibles. Osolix supports componentisation, dual-policy depreciation (Straight-Line, DDB, SYD, UoP), revaluation model with OCI flow, and full disposal accounting.
§9 Recognition criteria — future economic benefits, cost reliably measurable
Capex Project workflow funnels every spend item through gating (Approve → Order → Receive → Capitalise) before an Asset record is created. The Asset Detail page links back to the originating Capex project for full audit drilldown.
§43 Componentisation — significant parts depreciated separately
Asset hierarchy (Master / Sub-asset) plus parallel valuation books let you depreciate the chassis on one schedule and the engine on another, while reporting both as a single asset on the FAR.
§50 Depreciation — systematic basis, residual + useful life reviewed annually
Five depreciation methods built-in (Straight-Line, Declining Balance, Sum-of-Years, Units-of-Production, Manual). Useful life and salvage value are first-class fields with audit-logged change history. Recompute is a one-click operation.
§31 Revaluation model with periodic appraisal + OCI movement
AssetValuationEvent records each fair-value adjustment with method (Cost / Market / Income), level (1/2/3), before/after amounts, and gain/loss split. The journal posts revaluation surplus to OCI automatically.
§67 Derecognition on disposal or when no further benefit expected
Retirement workflow (FA Retirement Form V2.3) captures method (Sale / Donation / Scrap / Write-off), proceeds, gain/loss, and journals the disposal in one approved transaction.
IFRS 16
AccountingLeases
On-balance-sheet lessee accounting for almost every lease. Osolix delivers right-of-use asset recognition, lease-liability amortisation, modification re-measurement, and short-term / low-value exemptions.
§22 Right-of-use asset + lease liability at commencement
A new Lease record auto-computes the present value of fixed payments at the discount rate, books the ROU asset on one side and the liability on the other, and emits the opening journal.
§32 Subsequent measurement — interest unwind + ROU depreciation
Monthly amortisation schedule pre-computed for the entire lease term. Interest expense and depreciation post automatically every period close. LeaseLiabilityOpeningBalance is a reportable field on the asset detail.
§44 Modification — re-measure liability, adjust ROU
Lease modification workflow re-presents the new payment schedule, recomputes the discount unwind, and posts the adjustment to the ROU asset — all in one approved transaction.
§5 Short-term + low-value exemption
Per-lease toggle for short-term (≤12 months) or low-value treatment — those leases skip the on-balance-sheet flow and post to P&L straight-line.
ASC 842
AccountingLeases (FASB Codification)
The US-GAAP counterpart to IFRS 16. Most mechanics overlap, but ASC 842 retains the operating-vs-finance lease distinction. Osolix supports both classifications side-by-side via the parallel valuation books framework.
Lease classification test — finance vs. operating
Lease wizard runs the five classification tests (transfer of ownership, bargain purchase, lease term, present value, specialised use) at commencement and stamps the resulting class on the record.
Operating lease — single straight-line lease cost
For operating leases, Osolix booked one straight-line lease cost per period, while still maintaining the underlying ROU and liability for disclosure.
Finance lease — interest expense + ROU amortisation reported separately
Finance-lease records post interest and amortisation as two distinct lines, matching the ASC 842 income-statement geography.
IAS 36
AccountingImpairment of Assets
When an asset's carrying amount may exceed its recoverable amount, you must test and book an impairment. Osolix runs trigger detection continuously — RUL drift, market-value drift, sum-insured drift — and lets you book the loss inline.
§9 Indicators of impairment — internal + external
Drift Watcher Hub aggregates external (market price), internal (technical-obsolescence flag, RUL prediction), and macro (interest-rate change) indicators. Each indicator drives a configurable alert threshold.
§59 Recognition + measurement of impairment loss
When recoverable amount falls below carrying amount, the platform proposes an impairment journal (debit P&L, credit accumulated impairment). One-click approval posts the entry and stamps the asset with ImpairmentAmount + ImpairmentDate.
§110 Reversal of impairment loss
Impairment reversal is a first-class workflow: re-test → propose reversal up to original carrying amount → post entry → audit-log the change.
IFRS 13
AccountingFair Value Measurement
A consistent framework for fair-value measurement and disclosure across IFRS standards. Osolix records the valuation level (1 / 2 / 3), method, inputs, and date for every revaluation event.
§72 Fair value hierarchy — Level 1 / 2 / 3
AssetValuationEvent.Level is a required field on every revaluation record. The Investment Property tab and Lease tab both expose level + method side-by-side for disclosure-note generation.
§91 Disclosure of valuation technique + significant unobservable inputs
Each valuation event captures method (Cost / Market / Income), input description (free-text + structured), and the responsible appraiser. The audit committee report template renders this directly.
US GAAP
AccountingGenerally Accepted Accounting Principles (US)
The full FASB codification is supported via parallel valuation books — run an IFRS book and a US-GAAP book on the same asset, with their own depreciation policies, salvage values, and lives.
ASC 360 Property, Plant and Equipment — capitalisation, depreciation, impairment
AssetBook records each book's policy independently — Corporate (book) for IFRS, Tax (alternate) for US-GAAP MACRS, Local for jurisdictional overrides. Reports filter by book.
ASC 350 Intangibles — goodwill + other intangibles
Asset classification supports Intangible items with their own amortisation rules, indefinite-life flagging, and annual impairment-test reminders.
ASC 410 Asset Retirement Obligations
Per-asset AroAmount field, with discount-unwind schedule and journal posting. The retirement workflow trues-up the actual disposal cost against the booked ARO.
GASB 34
AccountingBasic Financial Statements—and Management's Discussion and Analysis—for State and Local Governments
Government accounting standards for capital assets — including infrastructure, modified approach, and required network-level reporting. Osolix supports the modified approach via condition-assessment records on the asset detail.
§19 Capitalisation of infrastructure assets
Infrastructure-class assets get the same lifecycle as standard PPE plus a condition-assessment workflow that drives the modified-approach disclosure.
§23 Modified approach — preserve at established condition level
Per-asset condition score with target threshold; a deviation triggers a maintenance project recommendation rather than depreciation.
Required Supplementary Information — condition + preservation costs
GASB-34 RSI report renders the condition assessment by asset class, the preservation expenditure, and the comparison to the established condition level.
ISO 55000 series
AssetAsset Management — Overview, Principles and Terminology
The international management-system standard for asset management — strategy, policy, objectives, risk, and continuous improvement. Osolix is structured around the ISO 55000 lifecycle (Plan → Acquire → Operate → Maintain → Renew / Dispose). ISO 55001 certification applies to an organisation's management system, not to software — Osolix supplies the records, workflows, and reports customers present as evidence in their own certification audit.
Strategic Asset Management Plan (SAMP) — line-of-sight from org strategy to asset action
Capex Project module ties spend to a strategic objective; Maintenance Plans tie work-orders to availability targets; the Reporting hub rolls them up into a single SAMP narrative.
ISO 55001 shared-responsibility matrixRisk-based decision-making across the lifecycle
Risk score on every asset, RUL prediction in the Maintenance hub, repair-vs-replace banner on the asset detail, and a cost-of-failure heatmap in the Maintenance hub.
Clause 6 — risk-based planning mappingPerformance + condition monitoring with continuous improvement loop
Verification cycles, IoT-fed anomaly alerts (RUL heatmap), and a quarterly review board template — all instrumented so every cycle's outcome feeds the next plan.
Clause 9 — performance evaluation mappingGDPR
PrivacyGeneral Data Protection Regulation (EU) 2016/679
Europe's privacy bedrock — applies to anyone processing EU residents' data. Osolix delivers data-subject rights, Records of Processing (Art. 30), and a published DPIA.
Art. 15 Right of access
Self-service Privacy Request portal at /privacy/request. The DSR queue routes the request to the DPO, the platform compiles the personal-data dossier, and delivery happens within the regulatory window.
Submit a privacy requestArt. 17 Right to erasure
Erasure workflow soft-redacts personal identifiers across all records while preserving aggregate financial entries (which are required for SOX retention). The redaction event is itself audited.
Art. 30 Records of processing activities
Published Records of Processing document on the Trust Center, kept current for every new sub-processor or processing purpose.
Records of ProcessingArt. 35 Data Protection Impact Assessment
Published DPIA covering processing inventory, risk assessment, and mitigation. Triggers re-assessment when a new high-risk feature ships (e.g. AI agents, biometrics).
PDPL DPIAArt. 33 Breach notification within 72 hours
Incident-response playbook with a built-in 72-hour timer that auto-escalates to the DPO and notifies affected tenants from the same console.
PDPL (UAE / KSA)
PrivacyPersonal Data Protection Law
Region-native privacy regulation that mirrors GDPR fundamentals but adds local data-residency and Arabic-language obligations. Osolix runs from a GCC region with Arabic UI and DPO contact in-region.
Data residency within the regulated jurisdiction
Per-tenant region selection at provisioning. Backups stay in-region. Cross-border transfers happen only via the customer's explicit configuration and with documented adequacy.
Arabic-language privacy notice + consent flows
Native Arabic UI across the entire product (RTL-aware), Arabic privacy notice, Arabic-language DSR portal.
Data Protection Officer designation + contact
The Trust Center explains how to send a data-subject request through our contact form, with a 30-day response commitment.
Trust CenterISO 9001
OperationalQuality Management Systems — Requirements
Process-discipline framework that customers in regulated industries (aviation, healthcare, energy) often require from their vendors. Osolix's engineering operating system follows the ISO 9001 plan-do-check-act cycle.
Documented procedures + records
Every workflow (additions, transfers, retirements, maintenance, audits) is governed by a configurable template stored in the Workflow Designer. Each execution leaves a record.
Continual improvement — corrective + preventive action
Anomaly detection feeds the maintenance backlog. Verification discrepancies become CAPA tasks. Quarterly review boards close the loop.
Document control with revision history
Every form (Transfer V2, Retirement V2.3, Verification, Capex) is versioned with a publish-date stamp. Superseded versions remain readable.
WCAG 2.2 AA
OperationalWeb Content Accessibility Guidelines
The international accessibility benchmark. Osolix tests every screen against WCAG 2.2 AA — keyboard navigation, screen-reader landmarks, contrast ratios, focus visibility, motion-reduction respect.
Perceivable — adequate contrast, alt text, captions
Brand palette tested for AA contrast across both light and dark themes. Every image carries alt text. Charts include a hidden summary table for non-visual access.
WCAG 2.2 AA conformance templateOperable — keyboard, no seizure-inducing motion
Full keyboard navigation across every screen. Motion respects prefers-reduced-motion. Focus indicators are gold-accented for high visibility.
Understandable — predictable, helpful errors
Consistent navigation patterns (canonical PageHero + PageTabs across every page). Inline error messages are specific, actionable, and announced to screen readers.
Robust — works with assistive technology
Semantic HTML, ARIA where it adds clarity, and tests against NVDA + VoiceOver before each release.
We'll happily walk your auditor through any of these.
Most procurement reviews close in two calls — one with your CISO, one with your Controller. Contact us through our contact form to schedule, or browse the full evidence library on the Trust Center.
