4,675 audit findings extracted from 1,554 public Office of the Auditor-General reports, mapped to the S.I.N.S. Framework™ and aligned to ISO 27005 / NIST CSF. The empirical backbone of RETACH's Cyber Risk Quantification Engine — built from real, cited government audit evidence, not survey data.
Every finding is tagged multi-label against RETACH's four pillars using curated, word-boundary-matched keyword sets. Most OAG findings are financial/governance in nature — the IT-relevant subset is smaller but consistent, and is exactly the layer RETACH's S.I.N.S. Framework™ is built to fix.
We built this the RETACH way: keep it simple, and be honest about what you don't know. The extraction tool looks for clear structural signals in each report — numbered findings, standard section headings — rather than an AI trying to interpret meaning. When a report doesn't give a clean signal, it gets flagged for a person to check by hand, instead of guessing. And before any change went live across all 1,554 reports, it was tested against a set we'd already verified ourselves.
| Update | What we fixed | Result |
|---|---|---|
| v3.6 | A handful of report titles were unreadable because of a formatting quirk in a few PDFs. | 6 reports that had failed to process were recovered. |
| v3.7 | The tool didn't recognize every way audit reports word their standard legal disclaimers. | 6 rows that were just boilerplate text, not real findings, were removed. |
| v3.8 | Real findings were sometimes getting cut off by the standard disclaimer text sitting in front of them. | 534 rows fixed (11% of the dataset): 234 real findings were recovered in full, and 300 rows that weren't real findings were correctly removed. |
We also map every pillar back to two global standards — ISO 27005 and the NIST Cybersecurity Framework — so the findings aren't just RETACH's opinion. It's how the wider security industry already talks about these risks.
| S.I.N.S. Pillar | ISO 27005 Domain | NIST CSF Function |
|---|---|---|
| Systems | Asset & Vulnerability Management | Protect |
| Infrastructure | Physical & Operational Security | Protect, Recover |
| Network | Communications Security | Protect, Detect |
| Security | Risk Treatment & Organisational Controls | Identify, Govern |
Most recurring threads sit in the general financial/governance category — expected, since OAG audits are financial-statement audits, not IT audits. The slice that matters for RETACH's thesis is the smaller one that ties directly to a S.I.N.S. pillar: 18 of the 458 recurring threads. Here's what that looks like in practice — the same digital-risk issue, named the same way, audit cycle after audit cycle:
| Entity | S.I.N.S. Pillar | Recurring issue | Unbroken since |
|---|---|---|---|
| Kenya Veterinary Board | Infrastructure | Lack of Disaster Recovery & Business Continuity Plan | 2 audits running (2021/22–2022/23) |
| Tourism Regulatory Authority | Infrastructure | Lack of a Disaster Recovery Plan | 2 audits running (2017/18–2018/19) |
| Child Welfare Society of Kenya | Security | Inadequate IT Governance & Security Policy | 2 audits running (2018/19–2019/20) |
| Anti-Counterfeit Authority | Infrastructure | ICT Strategy Objectives Not Implemented | 2 audits running (2018/19–2019/20) |
| Privatization Commission | Systems | E-Procurement System Not Implemented | 2 audits running (2021/22–2022/23) |
| Kenya Universities and Colleges Central Placement Service | Infrastructure | Unsupported ICT Server Procurement | 2 audits running (2018/19–2019/20) |
Smaller n by design — S.I.N.S.-taggable findings are 4.8% of the corpus overall. The pattern (unresolved digital-risk gaps persisting audit after audit) is the point, not the count.
Raw finding count, not severity-weighted. High counts partly reflect audit history length and entity complexity, not necessarily worse governance — read alongside the full register.
| Entity | Findings |
|---|---|
| National Social Security Fund | 50 |
| Kenya Pipeline Company Limited | 44 |
| Western Kenya Rice Mills Limited | 43 |
| Kenya School of Government | 42 |
| Tana and Athi Rivers Development Authority | 41 |
| School Equipment Production Unit | 39 |
| Water Services Regulatory Board | 39 |
| Kenya Forest Service | 38 |
| Kenya Water Institute | 36 |
| South Nyanza Sugar Company Limited | 36 |
| Kenya National Shipping Line Limited | 35 |
| National Museums of Kenya | 35 |
| Kenyatta International Convention Centre | 34 |
| Child Welfare Society of Kenya | 33 |
| Kenyatta National Hospital | 33 |
RETACH counter-checks its own claims against empirical data before publishing them. These are documented, unresolved gaps — flagged rather than hidden.
Keyword matches on "network"/"internet" can echo non-IT findings (e.g. a marketing finding mentioning a company's internet presence). Confirmed in manual review at roughly 1-in-3 in a small sample. Network-pillar counts should not be used in public claims without a manual pass.
178 files (11.6% of the corpus) are image-only/scanned PDFs with no extractable text. They are excluded from the register entirely — not represented as empty or "clean" rows — because an unknown is not a zero. OCR recovery is deferred as a phase-2 enhancement.
17.6% of real findings show a filename-tagged financial year that doesn't match the year stated in the report's own text, versus a 15.0% baseline from earlier sampling — a modest, unexplained +2.6pp drift, not yet root-caused.
Un-numbered findings are stored up to 900 characters; ~14% of these are cut mid-sentence. The underlying extracted text is correct — only the stored excerpt is capped.
RETACH doesn't sell frameworks — we quantify risk against them, with cited, auditable evidence. This index is the measurement layer behind every Digital Resilience Assessment we deliver.
Talk to RETACH → Visit retach.tech