workflow

SOX ITGC Testing

SOX ITGC Testing as a modular, decision-aware workflow. It runs on the existing Audit engagement item for this ITGC cycle (audit_type: sox_testing, period_start/period_end = the test period) — enrich that item, never create a duplicate — while per-control operating-effectiveness results live on Control-hosted SOX testing workflows, one created per in-scope ITGC control per Workflow.customFields.sox.fiscalYear, each hosted directly on the Control under test. It consumes the ICFR scoping handoff package from Annual ICFR Scoping & Risk Assessment, produces the reperformable final ITGC testing package as its named deliverable, and hands the deficiencies off to SOX Deficiency Remediation. In scope: the operating-effectiveness conclusion on the ITGCs protecting in-scope financial systems, reached by referencing the controls-owned NIST 800-53 catalog and its test scripts — not by rebuilding procedures. Out of scope, owned by related workflows: scoping of significant accounts and applications (Annual ICFR Scoping & Risk Assessment), deep completeness-and-accuracy validation of system-generated populations (SOX IPE Validation), and remediation of what fails (SOX Deficiency Remediation, the downstream handoff). It can stand alone, but is designed to exchange handoff packages with these related workflows instead of duplicating repeated work.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
sox
department
internal-audit
lineOfDefense
assure

Details

teams
  • internal-audit
  • it
  • finance
domains
  • sox
standards
  • sox
  • nist-800-53
sourceTemplateId
workflow-library:sox-itgc-testing
releaseId
sha256:eaebf4d5b6fbbc31ce2e6cc4908a6af39aeb6d2a3e5494135f364962e96fd19a
canonicalUrl
https://workflow-library.com/all/?w=sox-itgc-testing
capabilities
    mappingStatus
    mapped
    lineOfDefense
    assure
    controls
    • UC-AUDIT-21
    • UC-ACCESS-01
    • UC-ACCESS-02
    • UC-ACCESS-04
    • UC-CONFIG-02
    • UC-ACCESS-17
    • UC-ACCESS-05
    • UC-ACCESS-16
    • UC-ASSET-12
    • UC-BCDR-12
    • UC-CONFIG-03
    • UC-BCDR-03
    • UC-GOV-08
    • UC-SDLC-06
    • UC-SDLC-07
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:eaebf4d5b6fbbc31ce2e6cc4908a6af39aeb6d2a3e5494135f364962e96fd19a

            Connections