unified
UC-FIN-04 — Authorize transactions with attributable approvals
Require transactions, journal entries, and master-data or configuration changes to be reviewed and approved by authorized personnel in accordance with the delegation-of-authority matrix before they are recorded or executed. Capture approvals in systems under unique authenticated user accounts with tamper-evident audit trails that irrefutably bind each approval to the individual who performed it, so that approval actions cannot be repudiated. Evidence includes the delegation-of-authority matrix, approval workflow configurations, and approval audit trails.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Financial Reporting Controls (SOX)
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-FIN-04
- title
- Authorize transactions with attributable approvals
- statement
- Require transactions, journal entries, and master-data or configuration changes to be reviewed and approved by authorized personnel in accordance with the delegation-of-authority matrix before they are recorded or executed. Capture approvals in systems under unique authenticated user accounts with tamper-evident audit trails that irrefutably bind each approval to the individual who performed it, so that approval actions cannot be repudiated. Evidence includes the delegation-of-authority matrix, approval workflow configurations, and approval audit trails.
- domain
- Financial Reporting Controls (SOX)
- control_type
- preventive
- control_category
- administrative
- members
- framework
- sox
- control_id
- PLC-AUTH
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AU-10
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- SOX Key Control TOD/TOE Test tests UC-FIN-04 — Authorize transactions with attributable approvals
- SOX Key Control Operation (Close Cycle) operates UC-FIN-04 — Authorize transactions with attributable approvals
- UC-FIN-04 — Authorize transactions with attributable approvals mitigates Manual journal entries and management-override risk
- strength
- primary
- rationale
- Journal entries require authorized approval bound to the individual, controlling top-side override entries.
- UC-FIN-04 — Authorize transactions with attributable approvals mitigates Overstatement of assets/revenue (existence & occurrence)
- strength
- primary
- rationale
- Approval per delegation-of-authority before recording prevents unauthorized/fictitious transactions.
- UC-FIN-04 — Authorize transactions with attributable approvals mitigates Internal fraud — asset misappropriation, embezzlement, forgery
- strength
- primary
- rationale
- Authorization before execution prevents unauthorized disbursements and forgery.
- UC-FIN-04 — Authorize transactions with attributable approvals maps_to AU-10 — Non-repudiation
- framework
- nist-800-53
- control_id
- AU-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-FIN-04 — Authorize transactions with attributable approvals mitigates Financial-statement fraud and management override
- strength
- primary
- rationale
- Authorization plus tamper-evident, attributable approval trails deter and expose fraudulent entries and override.
- UC-FIN-04 — Authorize transactions with attributable approvals mitigates Segregation-of-duties conflicts in financial processes
- strength
- related
- rationale
- Approval workflows enforce that authorizers differ from recorders, supporting SoD.
- UC-FIN-04 — Authorize transactions with attributable approvals maps_to PLC-AUTH — Authorization and approval — transactions, journal entries, and changes are reviewed and approved by authorized personnel in accordance with delegation-of-authority policies before being recorded or executed.
- framework
- sox
- control_id
- PLC-AUTH
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- SOX §302/§404 (2002), PCAOB AS 2201
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-FIN-04 — Authorize transactions with attributable approvals mitigates Revenue-recognition misstatement (fictitious, mis-timed, mis-measured)
- strength
- related
- rationale
- Requiring authorization of revenue transactions/credit memos reduces fictitious or channel-stuffed revenue.