Ask Osolix — instant answers

Compliance · Standards · Evidence

Every standard, mapped.
Every claim, evidenced.

Osolix is purpose-built for groups whose finance team has to sleep at night. Every standard your auditor will test — mapped to the specific platform capability that satisfies each control.

Foundational control · Segregation of duties

Maker-Checker — every asset addition reviewed before it hits the FAR

Whether added through mobile, bulk import, or ERP sync — every asset goes through a dedicated review queue before it appears on the live Fixed Asset Register.

Lifecycle states
  • · Pending — awaiting checker review (default)
  • · Approved — live on the FAR
  • · Rejected — returned with reason for resubmission
  • · Bypassed — ERP-direct, governed in source
  • · AutoApproved — low-value threshold (configurable)
Server-enforced rules
  • · Submitter ≠ approver (SOX 404 / ISO 27001 A.5.15)
  • · Reject requires a non-empty reason (control evidence)
  • · Bulk approve up to 5,000 in one action
  • · Edit-during-review captured as separate timeline event
  • · FAR-default view excludes pending records — auditors see only approved data
Source-aware routing
  • · Mobile audit → Department asset manager
  • · Bulk import → CSV uploader's manager
  • · Manual web → Default Asset Manager
  • · ERP sync → Bypassed (no human review needed)
  • · API direct → Configurable per integration
Where evidence appears
  • · FAR — Submitted By + Approved By + Approved Date columns
  • · Asset Detail — Audit & Provenance panel (gold-bordered)
  • · Review Queue — full timeline + bulk-batch IDs
  • · Auditor-Ask AI — answers governance questions instantly

Foundational control

Server-stamped audit trail — who, what, when on every record

Every state change is stamped server-side with the actor's identity (from JWT), a server-clock timestamp, and the field delta. Immutable — no code path writes without logging.

Where it surfaces
  • · FAR — Created By + Created Date columns
  • · Asset Detail — Audit & Provenance panel
  • · Asset history timeline — every event tagged with actor
  • · Auditor-Ask AI — answers 'who added asset X?' instantly
How it works under the hood
  • · EF Core SaveChanges interceptor (server-side)
  • · User ID pulled from JWT (not request body)
  • · Timestamp from server clock (not client clock)
  • · Same code path for every save — no opt-out

ISO/IEC 27001

Security

Information Security Management Systems

Issuer: ISO/IECEdition: 2022Jurisdiction: GlobalAudience: CISO · Procurement · Big-4 IT auditor

The international benchmark for an ISMS — risk-based, continuously improved, evidence-backed. Osolix is built and operated in alignment with ISO/IEC 27001, and maps Annex A controls (A.5 – A.8) to platform features so an auditor can walk down the list without leaving the product.

Requirement

Clauses 4–10 — the management system itself: policy, risk register, SoA, internal audit

How Osolix delivers

A complete, version-controlled ISMS document suite: Information Security Policy with seven measurable objectives, a populated 5×5 risk register with named treatments, a Statement of Applicability covering all 93 Annex A controls with per-control evidence pointers, and a formalised internal-audit and access-review programme.

Statement of Applicability v1.0
Requirement

A.5.15 Access control — role-based, least-privilege, segregation of duties

How Osolix delivers

Every screen and API is gated by a tenant-scoped RBAC matrix with delegation-of-authority chains, four-eyes approvals, and SoD checks at the schema layer (not just the UI). Cross-kind protection prevents client admins from modifying internal staff and vice-versa.

RBAC test matrix
Requirement

A.5.31 Compliance with legal, statutory, regulatory, contractual requirements

How Osolix delivers

Standards-mapping registry (this page) plus a per-tenant compliance configuration that toggles IFRS / US GAAP / GASB books per entity. Privacy requests, data-subject rights, and breach-notification timers are baked into the workflow engine.

Trust Center
Requirement

A.8.5 Secure authentication — MFA, password complexity, session timeouts

How Osolix delivers

Email-verified accounts (EmailVerifiedAt stamp), failed-login lockouts, JWT-based sessions with refresh tokens, optional SSO / OIDC, time-boxed sensitive-action re-auth.

Requirement

A.8.15 Logging — tamper-evident audit log of access + state changes

How Osolix delivers

AuditInterceptor (SaveChanges hook) records who/what/when/why on every entity write. CreatedBy + CreatedDate are server-stamped from the JWT subject claim — never user-typed — and surfaced on the Fixed Asset Register and every asset detail page.

How audit trail works (this page)
Requirement

A.8.24 Use of cryptography — encryption at rest and in transit

How Osolix delivers

TLS 1.2+ for every transport. Database encryption at rest. Sensitive credentials (ERP integrations, SMTP, OAuth secrets) sealed with column-level encryption.

SOX 404

Security

Sarbanes-Oxley Act §404 — Management Assessment of Internal Controls

Issuer: U.S. CongressEdition: 2002 (active)Jurisdiction: United States (extraterritorial for SEC registrants)Audience: Controller · Internal Audit · External Auditor

Public-company management must attest to the effectiveness of internal control over financial reporting. Osolix supplies the IT General Controls (ITGC), application controls, and audit evidence an external auditor will test.

Requirement

ITGC: change management, access management, computer operations, program development

How Osolix delivers

Branch-protected source control with mandatory PR review. Access changes flow through approval workflow. Backup + restore drills run on a published cadence (RTO 1h / RPO 5min). Every release is reproducible from a tagged commit.

Restore-drill runbook
Requirement

Application controls: completeness, accuracy, validity, restricted access

How Osolix delivers

Server-side validation on every monetary field, three-way matching (PO → GRN → invoice) for additions, mandatory tag-uniqueness enforcement at the database constraint level, and tenant-scoped query filters that no API path can bypass.

Requirement

Segregation of duties — preparer ≠ approver ≠ payer

How Osolix delivers

Workflow templates for additions, transfers, retirements, and write-offs each enforce a four-eyes (or six-eyes for high-value) approval chain. SoD violations are flagged at submission, not after the fact.

Requirement

Audit trail: who, what, when, why for every financial event

How Osolix delivers

Every Asset, Lease, Capex, Maintenance, Verification, Transfer, Retirement, and Insurance record carries CreatedBy / CreatedAt / UpdatedBy / UpdatedAt — populated by the AuditInterceptor on every save path with no opt-out. The Asset Detail page surfaces this in a dedicated "Audit & Provenance" panel for auditor walkthroughs.

Audit charter v1
Requirement

Evidence retention — 7 years for SEC registrants

How Osolix delivers

Soft-delete semantics across the entire schema (no hard deletes from the UI). Long-term archive policies configurable per entity. Deleted records remain auditable and indexable.

SOC 2

Security

Trust Services Criteria — Security, Availability, Confidentiality, Processing Integrity, Privacy

Issuer: AICPAEdition: 2017 TSC (revised 2022)Jurisdiction: Global (de-facto standard for SaaS procurement)Audience: CISO · Vendor security review

The de-facto SaaS-procurement bar. Osolix is engineered in alignment with the AICPA Trust Services Criteria — our SOC 2 control matrix maps each criterion to a platform feature.

Requirement

CC6 Logical & physical access — provisioning, MFA, periodic re-certification

How Osolix delivers

Joiner-Mover-Leaver workflow with quarterly access review, MFA enforced for admin roles, automatic disablement on user termination event (HRIS webhook).

SOC 2 control matrix
Requirement

CC7 System operations — change, incident, vulnerability, monitoring

How Osolix delivers

Versioned migrations, blue-green deploys, SLO + error-budget telemetry, public status page, incident runbook with named on-call rotation.

Incident response playbook
Requirement

A1 Availability — capacity, environmental, recovery

How Osolix delivers

Multi-AZ deployments, autoscaling, scheduled DR drills, cross-region failover documented and tested.

Cross-region failover drill
Requirement

C1 Confidentiality — data classification + handling

How Osolix delivers

Tenant isolation is enforced server-side through global query filters, tenant-scoped authorization claims, and strict data partitioning across all query and API paths.

IAS 16

Accounting

Property, Plant and Equipment

Issuer: IFRS Foundation / IASBEdition: Active (with subsequent amendments)Jurisdiction: IFRS jurisdictions (UAE, KSA, EU, UK, India, …)Audience: CFO · Group Controller · External Auditor

The base IFRS standard for capitalised tangibles. Osolix supports componentisation, dual-policy depreciation (Straight-Line, DDB, SYD, UoP), revaluation model with OCI flow, and full disposal accounting.

Requirement

§9 Recognition criteria — future economic benefits, cost reliably measurable

How Osolix delivers

Capex Project workflow funnels every spend item through gating (Approve → Order → Receive → Capitalise) before an Asset record is created. The Asset Detail page links back to the originating Capex project for full audit drilldown.

Requirement

§43 Componentisation — significant parts depreciated separately

How Osolix delivers

Asset hierarchy (Master / Sub-asset) plus parallel valuation books let you depreciate the chassis on one schedule and the engine on another, while reporting both as a single asset on the FAR.

Requirement

§50 Depreciation — systematic basis, residual + useful life reviewed annually

How Osolix delivers

Five depreciation methods built-in (Straight-Line, Declining Balance, Sum-of-Years, Units-of-Production, Manual). Useful life and salvage value are first-class fields with audit-logged change history. Recompute is a one-click operation.

Requirement

§31 Revaluation model with periodic appraisal + OCI movement

How Osolix delivers

AssetValuationEvent records each fair-value adjustment with method (Cost / Market / Income), level (1/2/3), before/after amounts, and gain/loss split. The journal posts revaluation surplus to OCI automatically.

Requirement

§67 Derecognition on disposal or when no further benefit expected

How Osolix delivers

Retirement workflow (FA Retirement Form V2.3) captures method (Sale / Donation / Scrap / Write-off), proceeds, gain/loss, and journals the disposal in one approved transaction.

IFRS 16

Accounting

Leases

Issuer: IFRS Foundation / IASBEdition: 2019Jurisdiction: IFRS jurisdictionsAudience: CFO · Lease Accountant

On-balance-sheet lessee accounting for almost every lease. Osolix delivers right-of-use asset recognition, lease-liability amortisation, modification re-measurement, and short-term / low-value exemptions.

Requirement

§22 Right-of-use asset + lease liability at commencement

How Osolix delivers

A new Lease record auto-computes the present value of fixed payments at the discount rate, books the ROU asset on one side and the liability on the other, and emits the opening journal.

Requirement

§32 Subsequent measurement — interest unwind + ROU depreciation

How Osolix delivers

Monthly amortisation schedule pre-computed for the entire lease term. Interest expense and depreciation post automatically every period close. LeaseLiabilityOpeningBalance is a reportable field on the asset detail.

Requirement

§44 Modification — re-measure liability, adjust ROU

How Osolix delivers

Lease modification workflow re-presents the new payment schedule, recomputes the discount unwind, and posts the adjustment to the ROU asset — all in one approved transaction.

Requirement

§5 Short-term + low-value exemption

How Osolix delivers

Per-lease toggle for short-term (≤12 months) or low-value treatment — those leases skip the on-balance-sheet flow and post to P&L straight-line.

ASC 842

Accounting

Leases (FASB Codification)

Issuer: FASBEdition: 2018Jurisdiction: United States (US GAAP)Audience: US Controller · External Auditor

The US-GAAP counterpart to IFRS 16. Most mechanics overlap, but ASC 842 retains the operating-vs-finance lease distinction. Osolix supports both classifications side-by-side via the parallel valuation books framework.

Requirement

Lease classification test — finance vs. operating

How Osolix delivers

Lease wizard runs the five classification tests (transfer of ownership, bargain purchase, lease term, present value, specialised use) at commencement and stamps the resulting class on the record.

Requirement

Operating lease — single straight-line lease cost

How Osolix delivers

For operating leases, Osolix booked one straight-line lease cost per period, while still maintaining the underlying ROU and liability for disclosure.

Requirement

Finance lease — interest expense + ROU amortisation reported separately

How Osolix delivers

Finance-lease records post interest and amortisation as two distinct lines, matching the ASC 842 income-statement geography.

IAS 36

Accounting

Impairment of Assets

Issuer: IFRS Foundation / IASBEdition: ActiveJurisdiction: IFRS jurisdictionsAudience: CFO · Valuation specialist

When an asset's carrying amount may exceed its recoverable amount, you must test and book an impairment. Osolix runs trigger detection continuously — RUL drift, market-value drift, sum-insured drift — and lets you book the loss inline.

Requirement

§9 Indicators of impairment — internal + external

How Osolix delivers

Drift Watcher Hub aggregates external (market price), internal (technical-obsolescence flag, RUL prediction), and macro (interest-rate change) indicators. Each indicator drives a configurable alert threshold.

Requirement

§59 Recognition + measurement of impairment loss

How Osolix delivers

When recoverable amount falls below carrying amount, the platform proposes an impairment journal (debit P&L, credit accumulated impairment). One-click approval posts the entry and stamps the asset with ImpairmentAmount + ImpairmentDate.

Requirement

§110 Reversal of impairment loss

How Osolix delivers

Impairment reversal is a first-class workflow: re-test → propose reversal up to original carrying amount → post entry → audit-log the change.

IFRS 13

Accounting

Fair Value Measurement

Issuer: IFRS Foundation / IASBEdition: ActiveJurisdiction: IFRS jurisdictionsAudience: CFO · Valuation specialist

A consistent framework for fair-value measurement and disclosure across IFRS standards. Osolix records the valuation level (1 / 2 / 3), method, inputs, and date for every revaluation event.

Requirement

§72 Fair value hierarchy — Level 1 / 2 / 3

How Osolix delivers

AssetValuationEvent.Level is a required field on every revaluation record. The Investment Property tab and Lease tab both expose level + method side-by-side for disclosure-note generation.

Requirement

§91 Disclosure of valuation technique + significant unobservable inputs

How Osolix delivers

Each valuation event captures method (Cost / Market / Income), input description (free-text + structured), and the responsible appraiser. The audit committee report template renders this directly.

US GAAP

Accounting

Generally Accepted Accounting Principles (US)

Issuer: FASBEdition: Codification (continuously updated)Jurisdiction: United StatesAudience: US Controller

The full FASB codification is supported via parallel valuation books — run an IFRS book and a US-GAAP book on the same asset, with their own depreciation policies, salvage values, and lives.

Requirement

ASC 360 Property, Plant and Equipment — capitalisation, depreciation, impairment

How Osolix delivers

AssetBook records each book's policy independently — Corporate (book) for IFRS, Tax (alternate) for US-GAAP MACRS, Local for jurisdictional overrides. Reports filter by book.

Requirement

ASC 350 Intangibles — goodwill + other intangibles

How Osolix delivers

Asset classification supports Intangible items with their own amortisation rules, indefinite-life flagging, and annual impairment-test reminders.

Requirement

ASC 410 Asset Retirement Obligations

How Osolix delivers

Per-asset AroAmount field, with discount-unwind schedule and journal posting. The retirement workflow trues-up the actual disposal cost against the booked ARO.

GASB 34

Accounting

Basic Financial Statements—and Management's Discussion and Analysis—for State and Local Governments

Issuer: GASBEdition: ActiveJurisdiction: United States — public-sectorAudience: Public-sector controller · Auditor

Government accounting standards for capital assets — including infrastructure, modified approach, and required network-level reporting. Osolix supports the modified approach via condition-assessment records on the asset detail.

Requirement

§19 Capitalisation of infrastructure assets

How Osolix delivers

Infrastructure-class assets get the same lifecycle as standard PPE plus a condition-assessment workflow that drives the modified-approach disclosure.

Requirement

§23 Modified approach — preserve at established condition level

How Osolix delivers

Per-asset condition score with target threshold; a deviation triggers a maintenance project recommendation rather than depreciation.

Requirement

Required Supplementary Information — condition + preservation costs

How Osolix delivers

GASB-34 RSI report renders the condition assessment by asset class, the preservation expenditure, and the comparison to the established condition level.

ISO 55000 series

Asset

Asset Management — Overview, Principles and Terminology

Issuer: ISOEdition: 2024 (ISO 55000:2024 / 55001:2024; 55002:2018 guidance)Jurisdiction: GlobalAudience: Head of Asset Management · Maintenance Director

The international management-system standard for asset management — strategy, policy, objectives, risk, and continuous improvement. Osolix is structured around the ISO 55000 lifecycle (Plan → Acquire → Operate → Maintain → Renew / Dispose). ISO 55001 certification applies to an organisation's management system, not to software — Osolix supplies the records, workflows, and reports customers present as evidence in their own certification audit.

Requirement

Strategic Asset Management Plan (SAMP) — line-of-sight from org strategy to asset action

How Osolix delivers

Capex Project module ties spend to a strategic objective; Maintenance Plans tie work-orders to availability targets; the Reporting hub rolls them up into a single SAMP narrative.

ISO 55001 shared-responsibility matrix
Requirement

Risk-based decision-making across the lifecycle

How Osolix delivers

Risk score on every asset, RUL prediction in the Maintenance hub, repair-vs-replace banner on the asset detail, and a cost-of-failure heatmap in the Maintenance hub.

Clause 6 — risk-based planning mapping
Requirement

Performance + condition monitoring with continuous improvement loop

How Osolix delivers

Verification cycles, IoT-fed anomaly alerts (RUL heatmap), and a quarterly review board template — all instrumented so every cycle's outcome feeds the next plan.

Clause 9 — performance evaluation mapping

GDPR

Privacy

General Data Protection Regulation (EU) 2016/679

Issuer: European Parliament & CouncilEdition: 2018Jurisdiction: European Union (extraterritorial)Audience: DPO · Legal · Procurement

Europe's privacy bedrock — applies to anyone processing EU residents' data. Osolix delivers data-subject rights, Records of Processing (Art. 30), and a published DPIA.

Requirement

Art. 15 Right of access

How Osolix delivers

Self-service Privacy Request portal at /privacy/request. The DSR queue routes the request to the DPO, the platform compiles the personal-data dossier, and delivery happens within the regulatory window.

Submit a privacy request
Requirement

Art. 17 Right to erasure

How Osolix delivers

Erasure workflow soft-redacts personal identifiers across all records while preserving aggregate financial entries (which are required for SOX retention). The redaction event is itself audited.

Requirement

Art. 30 Records of processing activities

How Osolix delivers

Published Records of Processing document on the Trust Center, kept current for every new sub-processor or processing purpose.

Records of Processing
Requirement

Art. 35 Data Protection Impact Assessment

How Osolix delivers

Published DPIA covering processing inventory, risk assessment, and mitigation. Triggers re-assessment when a new high-risk feature ships (e.g. AI agents, biometrics).

PDPL DPIA
Requirement

Art. 33 Breach notification within 72 hours

How Osolix delivers

Incident-response playbook with a built-in 72-hour timer that auto-escalates to the DPO and notifies affected tenants from the same console.

PDPL (UAE / KSA)

Privacy

Personal Data Protection Law

Issuer: UAE Federal Decree-Law 45/2021 · KSA Royal Decree M/19Edition: 2022 (UAE) · 2023 (KSA)Jurisdiction: United Arab Emirates · Kingdom of Saudi ArabiaAudience: GCC DPO · GCC Procurement

Region-native privacy regulation that mirrors GDPR fundamentals but adds local data-residency and Arabic-language obligations. Osolix runs from a GCC region with Arabic UI and DPO contact in-region.

Requirement

Data residency within the regulated jurisdiction

How Osolix delivers

Per-tenant region selection at provisioning. Backups stay in-region. Cross-border transfers happen only via the customer's explicit configuration and with documented adequacy.

Requirement

Arabic-language privacy notice + consent flows

How Osolix delivers

Native Arabic UI across the entire product (RTL-aware), Arabic privacy notice, Arabic-language DSR portal.

Requirement

Data Protection Officer designation + contact

How Osolix delivers

The Trust Center explains how to send a data-subject request through our contact form, with a 30-day response commitment.

Trust Center

ISO 9001

Operational

Quality Management Systems — Requirements

Issuer: ISOEdition: 2015Jurisdiction: GlobalAudience: Quality manager · Operations director

Process-discipline framework that customers in regulated industries (aviation, healthcare, energy) often require from their vendors. Osolix's engineering operating system follows the ISO 9001 plan-do-check-act cycle.

Requirement

Documented procedures + records

How Osolix delivers

Every workflow (additions, transfers, retirements, maintenance, audits) is governed by a configurable template stored in the Workflow Designer. Each execution leaves a record.

Requirement

Continual improvement — corrective + preventive action

How Osolix delivers

Anomaly detection feeds the maintenance backlog. Verification discrepancies become CAPA tasks. Quarterly review boards close the loop.

Requirement

Document control with revision history

How Osolix delivers

Every form (Transfer V2, Retirement V2.3, Verification, Capex) is versioned with a publish-date stamp. Superseded versions remain readable.

WCAG 2.2 AA

Operational

Web Content Accessibility Guidelines

Issuer: W3CEdition: 2.2 (2023)Jurisdiction: Global (legally referenced in EU, UK, US Section 508)Audience: Accessibility · Procurement · Public-sector buyer

The international accessibility benchmark. Osolix tests every screen against WCAG 2.2 AA — keyboard navigation, screen-reader landmarks, contrast ratios, focus visibility, motion-reduction respect.

Requirement

Perceivable — adequate contrast, alt text, captions

How Osolix delivers

Brand palette tested for AA contrast across both light and dark themes. Every image carries alt text. Charts include a hidden summary table for non-visual access.

WCAG 2.2 AA conformance template
Requirement

Operable — keyboard, no seizure-inducing motion

How Osolix delivers

Full keyboard navigation across every screen. Motion respects prefers-reduced-motion. Focus indicators are gold-accented for high visibility.

Requirement

Understandable — predictable, helpful errors

How Osolix delivers

Consistent navigation patterns (canonical PageHero + PageTabs across every page). Inline error messages are specific, actionable, and announced to screen readers.

Requirement

Robust — works with assistive technology

How Osolix delivers

Semantic HTML, ARIA where it adds clarity, and tests against NVDA + VoiceOver before each release.

We'll happily walk your auditor through any of these.

Most procurement reviews close in two calls — one with your CISO, one with your Controller. Contact us through our contact form to schedule, or browse the full evidence library on the Trust Center.