RMAP audit readiness
Audit readiness is an evidence consistency problem, not a document count problem
When an assessor samples and traces a transaction, policy, records, interviews and site practice must describe the same management fact.
The first response to an upcoming RMAP assessment is often to inventory documents: is the policy in place, is the procedure set complete, and is every field filled in? Three months later, a well-bound package is handed over and the assessment still runs into trouble.
The problem is rarely “do you have this document?” It is “how was this conclusion reached?”
What an assessor is actually doing
The core activity in a third-party assessment is sampling and tracing back, not simply checking boxes. An assessor may select material lots and work backwards: which supplier, when screening was performed, what information was used, who approved the risk rating, what followed if it was high risk, and whether anyone later verified that mitigation worked.
Break any link in that chain and the documents in front of it stop functioning as evidence. Documents describe what a company intends to do. An assessment tests what actually happened and what proves it.
The four-column evidence test
| Evidence source | The assessment question |
|---|---|
| Policy | What does the documented system require? |
| Records | What trace was actually left? |
| Interview | How do the people doing the work describe it? |
| Site practice | What does the control look like in operation? |
When all four point to the same management fact, the requirement holds. When one diverges, there is a gap—and more documentation rarely closes a divergence in practice.
For example, policy requires quarterly reassessment of high-risk suppliers and four dated forms exist. In interview, however, the buyer explains that all four were completed at year end and there is no quarterly trigger in the workflow. Policy and records look complete, but interviews and actual cadence do not agree. The issue can move from a missed action to unreliable records, prompting wider sampling.
Why risk identification exposes evidence gaps
In my audit-readiness work, risk identification and assessment are often where evidence gaps concentrate. Policies are easy to write and disclosures have visible outputs. A risk conclusion, however, is a professional judgement, and a judgement needs a reviewable reasoning trail.
- Conclusions without sources. A report says a region is not a CAHRA without identifying the source, version or query date.
- Ratings without rules. Suppliers are classified high, medium or low, but recalculating a sample does not reproduce the register.
- Decisions without approval. A material risk conclusion has no approver or date, or the signatory cannot explain what was approved.
The screening may genuinely have happened. The gap is often not intent; it is a process with no step for capturing how the conclusion was reached.
Work backwards from the assessment question
- Decompose the requirements. Go below chapter headings and identify discrete, verifiable facts.
- Write the fact and the evidence. State what happens in one sentence, then identify the record, system location and accountable role. Anything that cannot be filled in is a gap.
- Sample your own material. Select three to five lots and trace the chain from receipt to supplier, origin, risk decision and response.
- Verify through interviews. The aim is not to script answers. It is to confirm that staff can explain responsibilities, triggers and escalation paths in their own words.
The result is an evidence matrix: requirements down the side and policy, records, interviews and site practice across the top. Every cell contains specific evidence or a marked gap. It is first and foremost the company’s own risk map.
Completed is not the same as closed
A complete corrective-action closure has three parts:
- Correction: fix this instance;
- Corrective action: fix the mechanism that produced it;
- Effectiveness verification: return after an appropriate interval and confirm that the problem has not recurred.
Effectiveness verification requires elapsed time. Completing and “verifying” on the same day rarely demonstrates that a control now works. Close only the first part and the issue is likely to return.
If the assessment is eight weeks away
- Weeks 1–2: build the evidence matrix and identify gaps; resist the urge to write new documents.
- Weeks 3–5: sample material and trace the highest-risk chains. Where a historical gap cannot be recreated honestly, document the cause and improvement plan.
- Weeks 6–7: verify interviews across procurement, quality, warehousing, compliance and management.
- Final week: index evidence and test retrieval. If a record cannot be found within two minutes, its practical value on site is close to zero.
Mapping first and writing second is deliberate. Otherwise teams often fill the wrong gaps and make policy and practice harder to reconcile.
Important note and sources
This article offers management guidance based on audit-readiness practice. It does not replace the applicable RMAP standard, assessment procedure or legal advice. Look-back periods, finding classifications, closure deadlines and verification methods vary by mineral, standard and version.
Alex Xue has focused on responsible-minerals due diligence since 2018, prepared for and attended 25+ audits, and worked hands-on with upstream traceability across China, DR Congo and Indonesia.