unified
UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
Management operates a monitoring program over the system of internal control that combines ongoing evaluations with separate assessments, including management self-assessments and internal audit evaluations. Controls are assessed for design and operating effectiveness on a defined frequency by assessors with a level of independence appropriate to the assessment, under documented assessment plans, and plans for security testing, training exercises, and monitoring are developed, maintained, and executed. Identified deficiencies are evaluated and communicated to those responsible for corrective action, including senior management and the board as appropriate.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Compliance, Audit & Assurance
- type
- detective
- category
- administrative
Details
- unified_id
- UC-AUDIT-21
- title
- Assess control effectiveness through testing and monitoring
- statement
- Management operates a monitoring program over the system of internal control that combines ongoing evaluations with separate assessments, including management self-assessments and internal audit evaluations. Controls are assessed for design and operating effectiveness on a defined frequency by assessors with a level of independence appropriate to the assessment, under documented assessment plans, and plans for security testing, training exercises, and monitoring are developed, maintained, and executed. Identified deficiencies are evaluated and communicated to those responsible for corrective action, including senior management and the board as appropriate.
- domain
- Compliance, Audit & Assurance
- control_type
- detective
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- CA-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-14
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- MEA02
- coverage
- full
- relationship
- superset_of
- framework
- sox
- control_id
- ELC-MON
- coverage
- full
- relationship
- superset_of
- framework
- coso-ic
- control_id
- P16
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-AUDIT-21 — Assess control effectiveness through testing and monitoring maps_to PM-14 — Testing, Training, and Monitoring
- framework
- nist-800-53
- control_id
- PM-14
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- UC-AUDIT-21 — Assess control effectiveness through testing and monitoring maps_to MEA02 — Managed System of Internal Control
- framework
- cobit-2019
- control_id
- MEA02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-21 — Assess control effectiveness through testing and monitoring maps_to P16 — The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
- framework
- coso-ic
- control_id
- P16
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-21 — Assess control effectiveness through testing and monitoring mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Ongoing and separate assessments of controls, with deficiencies routed for corrective action, directly detect and remediate a weak control environment.
- Process Walkthrough & Design Assessment tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- UC-AUDIT-21 — Assess control effectiveness through testing and monitoring maps_to ELC-MON — Monitoring Activities — ongoing and separate evaluations (internal audit, management self-assessment, disclosure committee), and evaluation/communication of control deficiencies.
- framework
- sox
- control_id
- ELC-MON
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- SOX §302/§404 (2002), PCAOB AS 2201
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-21 — Assess control effectiveness through testing and monitoring mitigates Ineffective ICFR / undisclosed material weakness
- strength
- primary
- rationale
- Monitoring that assesses control design/operating effectiveness and evaluates and communicates deficiencies (SOX ELC-MON, COSO P16) detects undetected ICFR weaknesses.
- Control Remediation Retest and Closure tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- SOX Control Testing tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- ISO 27001 SoA Review & Controls Assessment oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- Period-End Roll-Forward / Rollover Testing tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- Control Walkthrough tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- Period-End Roll-Forward Testing tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- SOX ITGC Testing operates UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- Security Control Assessment & POA&M Remediation operates UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- ISO/IEC 42001 AI Management System Internal Audit tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- NIST RMF System Authorization (ATO) Cycle oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- Interim Operating Effectiveness Testing tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- Continuous Controls Monitoring (ISCM) Cycle oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- Control Design Assessment tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- SOX Key Control TOD/TOE Test operates UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- SOX Process Walkthrough operates UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- SOC 2 Readiness & Evidence Collection oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- UC-AUDIT-21 — Assess control effectiveness through testing and monitoring maps_to CA-2 — Control Assessments
- framework
- nist-800-53
- control_id
- CA-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-21 — Assess control effectiveness through testing and monitoring mitigates Financial-statement fraud and management override
- strength
- related
- rationale
- Independent testing of control operating effectiveness can detect management override and fraudulent transactions.
- Control Interim Testing Record tests UC-AUDIT-21 — Assess control effectiveness through testing and monitoring