Schedule audits around risk
Run them before compaction, after a long interruption, before commit, before publish, and after switching tasks. These are the moments where unverified assumptions cost the most. A drift audit catches when the model is silently following an older plan, mixing source versions, or about to cross an authority boundary.
Audit the model AND the human
Mature workflows audit both sides. The model audit asks: what do you think you know, with sources? The human audit asks: have I changed any rule that the model should know about, and have I said it explicitly? Drift is bilateral; audits should be too.
Output of the audit is action
An audit is not a status report. It produces a concrete next step: continue, checkpoint, restart, ask, escalate. If the audit ends with 'looks fine, carrying on' every single time, the audit is theater.