workflow
Year-End Deficiency Aggregation & Severity Evaluation
Year-End Deficiency Aggregation & Severity Evaluation as a modular, decision-aware workflow. The instance runs against the existing fiscal-year ICFR assessment engagement — the Audit item with audit_type=sox_testing whose period_end is fiscal year end — enriching it rather than creating a duplicate: the frozen register snapshot and the full evaluation memo trail attach to its steps, and the overall ICFR conclusion lands on that Audit item (rating/opinion/report_date). It closes the gap between per-deficiency handling and the portfolio view: it freezes the register, reconciles it to every failed test, aggregates related deficiencies, concludes control deficiency versus significant deficiency versus material weakness, and hands conclusions to certification support, remediation, and audit-committee reporting instead of duplicating their work. The named deliverables are the year-end deficiency-evaluation memo (carrying the overall ICFR conclusion) and the countersigned final severity schedule. In scope: freezing and severity-evaluating the year-end deficiency population as of the fiscal-year-end assessment date, kept live through the 10-K filing date under a late-arrival rule. Out of scope, handed off rather than duplicated: fixing the deficiencies (SOX Deficiency Remediation) and reporting them to the board (Quarterly Board & Audit-Committee GRC Reporting). Severity thresholds and the contributing-test population are consumed from the Annual ICFR Scoping & Risk Assessment, SOX Key Control TOD/TOE Test, and SOX ITGC Testing runs — the deficiency register itself is the Issue population (issue_type deficiency, escalating to significant_deficiency and material_weakness as this workflow finalizes).
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- sox
- department
- finance
- lineOfDefense
- monitor
Details
- teams
- finance
- domains
- sox
- standards
- sox
- coso-ic
- sourceTemplateId
- workflow-library:sox-deficiency-aggregation-evaluation
- releaseId
- sha256:e44e2152e93d96eb220e7ce001a04754f0a770e2bac48d1e711e634c9ff66c45
- canonicalUrl
- https://workflow-library.com/all/?w=sox-deficiency-aggregation-evaluation
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-RISK-14
- UC-AUDIT-14
- UC-AUDIT-17
- UC-AUDIT-21
- UC-GOV-21
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:e44e2152e93d96eb220e7ce001a04754f0a770e2bac48d1e711e634c9ff66c45
Connections
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-RISK-14 — Track deficiencies to closure with remediation action plans
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-GOV-21 — Communicate and report risk and control information
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-AUDIT-14 — Evaluate findings and develop recommendations and action plans