Cross-cutting operational guidance
Roles and Responsibilities
This guidance establishes how person, role, mandate, competence, authorisation, decision power, and responsibility are to remain distinct and traceable throughout a Reality Audit.
Abstract
A Reality Audit may involve a commissioning body, auditors, experts, sources, affected parties, reviewers, decision-makers, publication officers, and oversight bodies. These roles may be performed by more or fewer persons, but the functions must remain visible.
The guidance gives no actor new legal or institutional authority. It organises the chain of responsibility so that it can be documented who initiated, bounded, examined, interpreted, reviewed, decided, implemented, published, and controlled the work.
Mandate and function
The guidance is designed to make the chain of responsibility visible in audits involving several persons, bodies, suppliers, or technical systems. It prevents titles, software, procedures, or collective wording from replacing identifiable actions and decisions.
It does not require every audit to have a large organisational structure. A simple or independent audit may be conducted by one person, but that person must identify which roles are combined, which limitations result, and which external control may be required.
Decisive distinctions
Clarifying roles and responsibility requires person, office, task, and authority not to be used as synonyms. The same person may hold several functions, and the same title may carry different mandates in different matters.
| Term | Function | Must not automatically be read as |
|---|---|---|
| Person or body | The concrete human or legal actor. | The role, mandate, or conclusion. |
| Office or title | A formal or social designation. | Relevant competence in every question. |
| Role | The function held in the particular audit. | The whole person or office beyond the matter. |
| Task | The concrete work to be performed. | Decision power or final responsibility. |
| Mandate | The bounded commission and field of action. | Unlimited authority. |
| Competence | Professional, technical, legal, or experiential ability and authority. | Authority beyond the field of competence. |
| Authorisation | Express authority to act on behalf of another. | Transfer of every duty and responsibility. |
| Decision power | Authority to determine a formal outcome. | Professional omniscience or immunity from correction. |
| Responsibility | The duty to answer for action, decision, and effect. | Guilt before the matter has been examined. |
| Impartiality | Whether the actor can perform the role without a relevant conflict of interest. | A guarantee that the assessment is correct. |
Mandate and appointment of roles
Every formal audit should document who initiated it, who set the mandate, who finances or facilitates the work, who audits, who reviews quality, who makes any decisions, and who implements and verifies correction.
A role must not be inferred only from a job title. A manager is not automatically an expert auditor, data steward, impartial reviewer, legal decision-maker, or publication officer.
Initiation
Record who raised the question and the grounds on which the initiative rested.
Mandate owner
Record who set or approved the audit's purpose, questions, scope, and limitations.
Performing roles
Name who collects material, analyses, advises, reviews, and writes.
Decision path
Identify who can turn findings into decisions, measures, publication, or other actual effects.
Control path
Show who can examine the work, receive objections, and alter the outcome.
Principal operational roles
The roles below are functions. They do not always require separate offices or persons, but every function that is actually present in the matter must be identifiable.
| Role | Principal function | Cannot automatically |
|---|---|---|
| Initiator | Raises the question and presents possible grounds. | Predetermine the finding. |
| Commissioning or mandate owner | Sets or approves the mandate, resources, and decision path. | Direct the analysis towards a commissioned outcome. |
| Audit lead | Secures planning, method, impartiality, documentation, and coherence. | Exceed mandate or professional competence. |
| Auditor or analyst | Examines material and builds visible inferential chains. | Create formal decision power through the audit role alone. |
| Expert adviser | Provides a bounded assessment within documented competence. | Assume overall decision responsibility. |
| Material or records steward | Secures provenance, access, version, retention, and correction. | Determine what the material proves. |
| Party or directly affected actor | Provides relevant material, corrects errors, and answers claims. | Hold a veto over a responsible finding. |
| Source or witness | Provides observation, experience, or documentation. | Carry responsibility for the auditor's final interpretation. |
| Quality reviewer | Examines method, sources, inference, version, and correspondence. | Merely sign without substantive review. |
| Decision-maker | Determines a formal outcome within competence and mandate. | Merge the audit finding and the decision into the same act. |
| Correction owner | Implements measures and documents actual effects. | Treat the decision itself as proof of effect. |
| Publication officer | Assesses law, privacy, harm, reply, status, and release. | Be equated with substantive authorship. |
| Oversight, appeal, or review role | Examines grounds, process, or outcome within its own mandate. | Constitute real control without access or power to alter. |
Roles and responsibility matrix
The matrix below must be adapted to the particular audit. It is a control instrument, not a requirement that every field be filled by a different person.
| Field | What must be documented | Control question |
|---|---|---|
| Role | The operational function in this matter. | Is the function described precisely? |
| Person or body | Name or identifiable organisational unit. | Who actually performed the action? |
| Mandate basis | Commission, law, delegation, agreement, or independent initiative. | What gave the role its field of action? |
| Field of competence | Relevant professional, technical, legal, or experiential competence. | Where does competence end? |
| Tasks | Concrete responsibility and deliverable. | What was actually done? |
| Decision power | What the role may determine, approve, or cannot alter. | Are advice and decision distinguished? |
| Access | Which material and systems the role may view or alter. | Was meaningful control possible? |
| Impartiality status | Connections, conflicts, and safeguards. | What protects the assessment? |
| Documentation duty | Which trace, note, version, or approval the role owns. | Can the action be reconstructed? |
| Period | Start, end, and any changes of role. | Who held the role when the action occurred? |
| Control or appeal path | Who may examine the action and what they may change. | Does effective review exist? |
Combining roles
The same person may hold several roles, especially in small organisations or independent audits. The combination is not automatically defective, but it must be assessed for concentration of power, impartiality, competence, self-review, and effects on the affected party.
The greater the potential harm, irreversibility, or public effect, the stronger the case for organisational separation or independent control.
Incompatible roles
In some matters, combining roles may be practically or in principle incompatible with a responsible audit. The audited actor should not alone decide the audit. The original decision-maker should not be the sole reviewer of the appeal. An actor with a substantial financial interest should not alone provide quality assurance.
Incompatibility must be assessed concretely. This document creates no universal legal rule of impartiality; applicable law and professional standards must be identified.
Chain of responsibility
The chain of responsibility must show who initiated, bounded, collected, interpreted, reviewed, decided, implemented, and controlled. Passive and collective formulations must be traced back to identifiable actions.
Advice and decision
An expert opinion may carry substantial weight without being binding. The audit must show what constitutes information, professional advice, recommendation, approval, formal decision, implementation, and control.
The decision-maker must show which assessment was independent, which material was relied upon, and how advice was used or departed from.
| Act | Function | Responsible limitation |
|---|---|---|
| Information | Provides material or factual information. | Does not alone establish a finding. |
| Professional advice | Provides an assessment within a field of competence. | Is not automatically binding. |
| Recommendation | Proposes an outcome or measure. | Must show reasons and alternatives. |
| Approval | Confirms that a defined requirement or checkpoint has been met. | Must specify what was reviewed. |
| Decision | Determines a formal outcome. | Requires competence, grounds, and responsibility. |
| Implementation | Puts the decision into effect. | Must document actual action and effect. |
| Control | Examines grounds, process, or result. | Requires real access and capacity for correction. |
Signature and approval
A signature or digital approval must not automatically be taken to mean that the person wrote the whole document, reviewed every source, endorsed every assessment, or approved public release.
The approval function should be specified, for example: substantively reviewed, methodologically reviewed, legally assessed, administratively approved, approved for publication, or decided within the stated mandate.
Impartiality and conflicts of interest
Central roles must be assessed for financial interests, personal relationships, organisational ties, earlier participation, prior public positions, outcome-dependent remuneration, and dependence on the commissioning body.
A conflict does not always require automatic withdrawal. Measures may include disclosure, a bounded role, a co-auditor, independent review, a separate decision-maker, or withdrawal.
Competence and limitation
The role must correspond to actual competence. Methodological, professional, legal, technical, experiential, and decision competence must not be inferred automatically from a single title.
In high-risk domains, the competence boundary and need for external professional or legal assessment must be stated expressly.
Adversarial participation and party rights
A directly affected party should, where relevant and responsible, be told what claim the matter concerns, which material is material, what time limit applies, and how the response was assessed.
Adversarial participation is not a veto. It must not be used to pressure sources, disclose personal data without grounds, or delay the audit indefinitely.
Publication and privacy
Substantive responsibility for an internal assessment is not automatically authority to publish it. Before release, it must be clear who owns the document, who may approve publication, who assessed privacy and harm, and who may correct, replace, or unpublish it.
The publication officer must distinguish public interest from curiosity, and the audit's documentation needs from authority to make the same material public.
Technology and artificial intelligence
Software and artificial intelligence may serve as recording tools, search tools, analytical assistance, classifiers, text generators, models, or decision support. Technical systems cannot stand as the finally responsible actor.
The record must show who selected the system, controlled inputs, assessed the output, could override it, made the decision, and corrects error. ‘The AI decided’ is not a complete account of responsibility.
Small organisations and independent auditors
The guidance must work without a large administration. Where one person performs several functions, the roles must be named separately, the combination declared, competence boundaries made visible, sources preserved, and counter-material actively sought.
External review should be used where potential harm, public release, irreversibility, or limited organisational independence makes self-review insufficient.
Common failure modes
The failure modes below are objects of audit, not automatic findings. They require concrete documentation of role, action, effect, and resistance to correction.
Title capture
Title or office replaces actual competence, mandate, or grounds.
Role conflation
An actor shifts between source, auditor, adviser, decision-maker, or reviewer without the change being visible.
Dissolution of responsibility
No actor answers because the action passed through many stages or was expressed in passive language.
Decision laundering
A professional or technical recommendation is presented as though it were itself the formal decision.
Signature laundering
A signature creates an appearance of review or approval that did not occur.
Delegation laundering
Responsibility is shifted to a subordinate, supplier, or software while the actor who selected and used the arrangement disappears.
Appeal convergence
The same actor or premises effectively review their own decision without independent examination.
Reduction of the party
The affected person is treated only as a source, category, or object of audit rather than a party with relevant rights and material.
Publication drift
Internal material is released without a separate assessment of mandate, privacy, harm, and status.
Critical objections and safeguards
Role clarification can itself become bureaucratic, symbolic, or protective of power. The objections below must therefore be used to examine the guidance itself, not only the audit at hand.
| Objection | Residual problem | Practical safeguard |
|---|---|---|
| Does the system become too bureaucratic? | Role records may consume more time than the matter warrants. | Use the minimum sufficient record and scale it to risk. |
| May the same person hold several roles? | Complete separation is often impossible. | Declare the combination and add control where the effect is greatest. |
| Who sets the mandate in independent criticism? | No formal commissioning body exists. | The auditor publishes the mandate, competence, limitations, and intended use. |
| Can full independence be achieved? | Every actor stands in relationships and institutions. | Document ties and assess functional independence rather than asserted neutrality. |
| Can party rights obstruct effective audit? | Participation may be used for pressure or delay. | Bound access and time limits proportionately and document necessary exceptions. |
| Who bears responsibility in distributed work? | No one controls the whole chain. | Map partial responsibility, system responsibility, and final decision or correction authority. |
| Can an organisation bear responsibility? | Collective and individual attribution overlap. | Distinguish institutional responsibility from concrete acts of identifiable persons. |
| Can AI become an independent decision-maker? | Technical autonomy may be substantial. | Keep human or legal responsibility visible while the system cannot bear duties, appeals, and repair. |
| Can formal roles conceal informal power? | Actual influence may lie outside the organisational chart. | Map actual access, pressure, resource control, and decision effect. |
| What if the responsible actor cannot correct? | Formal responsibility without real authority is weak. | Identify who holds resources and change authority and escalate correction accordingly. |
Use, documentation, and revision
The guidance should be used with R7.1 for mandate and scope, R7.7 for participation, decision, and revision, and R7.8 for publication, privacy, and safeguards. The roles and responsibility matrix may be maintained in the audit record and updated when persons, mandates, or decision paths change.
A new content version is required if roles, mandatory fields, the chain of responsibility, impartiality requirements, or decision logic are substantively altered. Pure design, print, link, or accessibility changes do not trigger a new content version.
Sources and grounds
- DET SOM ER: Eit sjølvstendig filosofisk grunnverk. Fyrste autoriserte utgåve. ISBN 978-82-694438-3-7.Especially the parts on the human being, systems, practice, responsibility, and corrigibility.
- Røyndalism — T6: Self, Identity and Role
- Røyndalism — T7: System, Authority and Institution
- Røyndalism — R1: Methodology of Reality Audit
- Røyndalism — R2: Audit Standard
- Røyndalism — R3: Procedure
- Røyndalism — R7: Resources and Worksheets
Revision history
- Document version
- 1.0
- First published
- 18 June 2026
First public edition.