workflow

Year-End Deficiency Aggregation & Severity Evaluation

Year-End Deficiency Aggregation & Severity Evaluation as a modular, decision-aware workflow. The instance runs against the existing fiscal-year ICFR assessment engagement — the Audit item with audit_type=sox_testing whose period_end is fiscal year end — enriching it rather than creating a duplicate: the frozen register snapshot and the full evaluation memo trail attach to its steps, and the overall ICFR conclusion lands on that Audit item (rating/opinion/report_date). It closes the gap between per-deficiency handling and the portfolio view: it freezes the register, reconciles it to every failed test, aggregates related deficiencies, concludes control deficiency versus significant deficiency versus material weakness, and hands conclusions to certification support, remediation, and audit-committee reporting instead of duplicating their work. The named deliverables are the year-end deficiency-evaluation memo (carrying the overall ICFR conclusion) and the countersigned final severity schedule. In scope: freezing and severity-evaluating the year-end deficiency population as of the fiscal-year-end assessment date, kept live through the 10-K filing date under a late-arrival rule. Out of scope, handed off rather than duplicated: fixing the deficiencies (SOX Deficiency Remediation) and reporting them to the board (Quarterly Board & Audit-Committee GRC Reporting). Severity thresholds and the contributing-test population are consumed from the Annual ICFR Scoping & Risk Assessment, SOX Key Control TOD/TOE Test, and SOX ITGC Testing runs — the deficiency register itself is the Issue population (issue_type deficiency, escalating to significant_deficiency and material_weakness as this workflow finalizes).

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
sox
department
finance
lineOfDefense
monitor

Details

teams
  • finance
domains
  • sox
standards
  • sox
  • coso-ic
sourceTemplateId
workflow-library:sox-deficiency-aggregation-evaluation
releaseId
sha256:e44e2152e93d96eb220e7ce001a04754f0a770e2bac48d1e711e634c9ff66c45
canonicalUrl
https://workflow-library.com/all/?w=sox-deficiency-aggregation-evaluation
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-RISK-14
    • UC-AUDIT-14
    • UC-AUDIT-17
    • UC-AUDIT-21
    • UC-GOV-21
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:e44e2152e93d96eb220e7ce001a04754f0a770e2bac48d1e711e634c9ff66c45

            Connections