Auditing
Verne maintains audit logs of all activities that take place within the system. Verne creates audit trails covering business activities as well as system and security events.
Verne’s audit log is a standard facility that requires no customisation or configuration to enable. Verne stores details about all new, altered or deleted data. Verne also stores “before images” of all data before it is updated or deleted. This allows authorised users to view a complete change history of all data within the system.
Verne provides three distinct product features which facilitate the monitoring and auditing of activity within a register:
- Audit logging – Verne maintains audit logs of all activities that take place within the system. Verne creates audit trails covering business activities as well as system and security events. Verne’s audit log is a standard facility that requires no customisation or configuration to enable.
- Versioning & Snapshots – Verne stores details about all new, altered or deleted data. Verne also stores “before images” of all data before it is updated or deleted. This allows authorised users to view a complete change history of all data within the system.
Audit Logging
Verne maintains audit logs of all updates that take place within the system. Verne creates audit trails covering business activities as well as system and security events. Verne’s audit log is a standard facility that requires no customisation or configuration to enable.
The Verne audit log captures all activities undertaken within the systems including data updates, task, job and process completion, system generated activity (such as correspondence generation) and user activity (both internal and external). Four essential properties are captured for every auditable event; what was done, when it was done, what was done to and who did it.
Verne stores details about all new, altered or deleted data. Verne also stores “before images” of all data before it is updated or deleted. This allows authorised users to view a complete change history of all data within the system.
Audit Log Detail
The data capture ensures that the following attributes are stored as a minimum:
- The user that triggered the event (in the event that the activity is a manual user-initiated process);
- The date and time that the activity commenced;
- The IP address that the activity came from;
- The activity that was carried out – such activities must be defined according to a controlled structure so that it is explicitly understood what the activity represents;
- The success or otherwise of the activity, if such a concept is applicable;
- The entity that the activity was based on (if applicable);
- The entity component that the activity was based on – for example, an entity address;
- Any specific business data that was directly associated with the activity – for example, a specific document that was uploaded, or a specific record that was changed.
Evidential Acknowledgement Detail
The system also records evidential acknowledgment for all prompts or warnings confirmed by a user during their activities. This becomes increasingly important as more and more functionality is assigned to external users. The system records a user’s response to a message informing them that the action they are about to take is subject to law, and identifying the ramifications if they continue with the process in an illegal or inappropriate way.
When such an activity is recorded, Verne captures the following:
- The nature of the advice/warning;
- Any relevant legislation that the user was advised of;
- The date and time that the user acknowledged the advice/warning;
- The user associated with the activity.
The following table presents Verne’s audit capabilities:
| Log Type | Verne Compliance |
|---|---|
| System Operation | The Verne audit log records system start and stop events. Data within the Verne audit log is available for viewing only, and only to authorised users. |
| Security | The Verne audit log records the identified security events including successful and unsuccessful login attempts, session timeouts, configuration changes, user profile maintenance, access control changes and authorisation decisions. Note that authorisation decisions made outside of Verne will not be visible to Verne and therefore not logged in the Verne audit log. |
| User Operations | Manually initiated user operations are logged in the Verne audit log. The following data is captured: • Timestamp • User ID • Name of the incoming request (Activity) • Session ID (to link events) • Name of sub-system (Verne business service) |
| Application Activity | Application initiated activity is logged in the Verne audit log. The following data is captured: • User ID • Time & Date (not duration) • Action/event data including the entity and entity component (e.g. address) and the specific data associated with the activity. Before and after data is also retained within Verne. • The success or otherwise of the activity • Result status • Any error messages |
Versioning & Snapshots
The Verne data layer employs versioning, whereby a history of all new, altered or deleted data is retained. This is achieved through a unique Verne – specific versioning process that avoids the two major pitfalls associated with historical data, namely the proliferation of duplicated data, and the process intensive cost of deriving data from timestamps. Refer to versioning for more details.
The Verne versioning system is incorporated into the filing history service. Verne is typically configured to generate one or more filings to represent the business activity associated with the Business Service. These are used to satisfy legislative requirements which mandate the Audit of the all historic activity related to an entity, and the details of an entity at the date of filing. Filings are stored and displayed in the filing history for each entity. Subsequently, the filing history can show the history of an entity on the register and provide a snapshot of the entity at a particular point of time.

