IIA 2024 Standards
147 records. Direct records match this source; context records explain their connections.
Read the first JSON page · Data retrieval guide
Mappings may provide partial coverage. Read mapping properties, residual requirements and source notes before relying on a connection.
control · Direct
Principle 1 — Demonstrate Integrity
Demonstrate Integrity
control · Direct
Principle 10 — Manage Resources
Manage Resources
control · Direct
Principle 11 — Communicate Effectively
Communicate Effectively
control · Direct
Principle 12 — Enhance Quality
Enhance Quality
control · Direct
Principle 13 — Plan Engagements Effectively
Plan Engagements Effectively
control · Direct
Principle 14 — Conduct Engagement Work
Conduct Engagement Work
control · Direct
Principle 15 — Communicate Engagement Results and Monitor Action Plans
Communicate Engagement Results and Monitor Action Plans
control · Direct
Principle 2 — Maintain Objectivity
Maintain Objectivity
control · Direct
Principle 3 — Demonstrate Competency
Demonstrate Competency
control · Direct
Principle 4 — Exercise Due Professional Care
Exercise Due Professional Care
control · Direct
Principle 5 — Maintain Confidentiality
Maintain Confidentiality
control · Direct
Principle 6 — Authorized by the Board
Authorized by the Board
control · Direct
Principle 7 — Positioned Independently
Positioned Independently
control · Direct
Principle 8 — Overseen by the Board
Overseen by the Board
control · Direct
Principle 9 — Plan Strategically
Plan Strategically
control · Direct
Purpose — Purpose of Internal Auditing — Internal auditing strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight.
Purpose of Internal Auditing — Internal auditing strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight.
control · Direct
Std 1.1 — Honesty and Professional Courage
Honesty and Professional Courage
control · Direct
Std 1.2 — Organization's Ethical Expectations
Organization's Ethical Expectations
control · Direct
Std 1.3 — Legal and Ethical Behavior
Legal and Ethical Behavior
control · Direct
Std 10.1 — Financial Resource Management
Financial Resource Management
control · Direct
Std 10.2 — Human Resources Management
Human Resources Management
control · Direct
Std 10.3 — Technological Resources
Technological Resources
control · Direct
Std 11.1 — Building Relationships and Communicating with Stakeholders
Building Relationships and Communicating with Stakeholders
control · Direct
Std 11.2 — Effective Communication
Effective Communication
control · Direct
Std 11.3 — Communicating Results
Communicating Results
control · Direct
Std 11.4 — Errors and Omissions
Errors and Omissions
control · Direct
Std 11.5 — Communicating the Acceptance of Risks
Communicating the Acceptance of Risks
control · Direct
Std 12.1 — Internal Quality Assessment
Internal Quality Assessment
control · Direct
Std 12.2 — Performance Measurement
Performance Measurement
control · Direct
Std 12.3 — Oversee and Improve Engagement Performance
Oversee and Improve Engagement Performance
control · Direct
Std 13.1 — Engagement Communication
Engagement Communication
control · Direct
Std 13.2 — Engagement Risk Assessment
Engagement Risk Assessment
control · Direct
Std 13.3 — Engagement Objectives and Scope
Engagement Objectives and Scope
control · Direct
Std 13.4 — Evaluation Criteria
Evaluation Criteria
control · Direct
Std 13.5 — Engagement Resources
Engagement Resources
control · Direct
Std 13.6 — Work Program
Work Program
control · Direct
Std 14.1 — Gathering Information for Analyses and Evaluation
Gathering Information for Analyses and Evaluation
control · Direct
Std 14.2 — Analyses and Potential Engagement Findings
Analyses and Potential Engagement Findings
control · Direct
Std 14.3 — Evaluation of Findings
Evaluation of Findings
control · Direct
Std 14.4 — Recommendations and Action Plans
Recommendations and Action Plans
control · Direct
Std 14.5 — Engagement Conclusions
Engagement Conclusions
control · Direct
Std 14.6 — Engagement Documentation
Engagement Documentation
control · Direct
Std 15.1 — Final Engagement Communication
Final Engagement Communication
control · Direct
Std 15.2 — Confirming the Implementation of Recommendations or Action Plans
Confirming the Implementation of Recommendations or Action Plans
control · Direct
Std 2.1 — Individual Objectivity
Individual Objectivity
control · Direct
Std 2.2 — Safeguarding Objectivity
Safeguarding Objectivity
control · Direct
Std 2.3 — Disclosing Impairments to Objectivity
Disclosing Impairments to Objectivity
control · Direct
Std 3.1 — Competency
Competency
control · Direct
Std 3.2 — Continuing Professional Development
Continuing Professional Development
control · Direct
Std 4.1 — Conformance with the Global Internal Audit Standards
Conformance with the Global Internal Audit Standards
control · Direct
Std 4.2 — Due Professional Care
Due Professional Care
control · Direct
Std 4.3 — Professional Skepticism
Professional Skepticism
control · Direct
Std 5.1 — Use of Information
Use of Information
control · Direct
Std 5.2 — Protection of Information
Protection of Information
control · Direct
Std 6.1 — Internal Audit Mandate
Internal Audit Mandate
control · Direct
Std 6.2 — Internal Audit Charter
Internal Audit Charter
control · Direct
Std 6.3 — Board and Senior Management Support
Board and Senior Management Support
control · Direct
Std 7.1 — Organizational Independence
Organizational Independence
control · Direct
Std 7.2 — Chief Audit Executive Qualifications
Chief Audit Executive Qualifications
control · Direct
Std 8.1 — Board Interaction
Board Interaction
control · Direct
Std 8.2 — Resources
Resources
control · Direct
Std 8.3 — Quality
Quality
control · Direct
Std 8.4 — External Quality Assessment
External Quality Assessment
control · Direct
Std 9.1 — Understanding Governance, Risk Management, and Control Processes
Understanding Governance, Risk Management, and Control Processes
control · Direct
Std 9.2 — Internal Audit Strategy
Internal Audit Strategy
control · Direct
Std 9.3 — Methodologies
Methodologies
control · Direct
Std 9.4 — Internal Audit Plan
Internal Audit Plan
control · Direct
Std 9.5 — Coordination and Reliance
Coordination and Reliance
risk · Context
Public-safety harm from AI in critical infrastructure
Because AI acting as a safety component in critical digital infrastructure, road traffic, or utilities (Annex III(2)) operates without the required risk management, robustness, and human oversight, it can fail or behave unsafely, resulting in service disruption and threats to public safety and continuity.
risk · Context
Discriminatory outcomes from AI in employment
Because AI used for recruitment, selection, promotion, task allocation, or worker monitoring (Annex III(4)) operates without bias mitigation, worker transparency, human oversight, or a data-protection impact assessment, it can decide about workers on biased or opaque grounds, resulting in discriminatory or unfair employment outcomes.
risk · Context
Unlawful denial of essential services by AI
Because AI evaluating eligibility for public benefits, creditworthiness, or insurance risk and pricing (Annex III(5)) operates without fairness, explainability, human oversight, or the required conformity controls, it can wrongly deny or misprice essential services, resulting in unlawful exclusion and consumer harm.
risk · Context
Wrongful denial by AI in migration and border control
Because AI for migration, asylum, or visa risk assessment and border-control screening (Annex III(7)) operates without the required accuracy, human oversight, and fundamental-rights protections, it can misjudge individuals, resulting in wrongful denial of entry or status and discrimination.
risk · Context
Environmental regulatory non-compliance
Unauthorized emissions or discharges, improper hazardous-waste handling, missing permits, or non-compliance with PFAS/chemical-reporting rules under EPA/RCRA/Clean Air & Water Acts — driving penalties and remediation.
risk · Context
Lack of independent audit and compliance review
Because independent internal and external audit and review of information security are not performed, control deficiencies and non-conformities are neither detected nor challenged, so weaknesses persist unremediated and management and the board lose reliable assurance over control effectiveness.
risk · Context
Client selection, sponsorship and exposure-limit breaches
Failure to investigate clients per guidelines, exceeding single-counterparty exposure limits without approval, and sponsoring transactions without adequate counterparty-risk assessment or AML/CTF screening.
risk · Context
ESG disclosure gaps and greenwashing
Public ESG commitments (carbon neutrality, DEI, supply-chain ethics) unsubstantiated by verifiable data, and non-compliant or inaccurate mandatory sustainability disclosures (CSRD, California SB 253/261, SEC climate rule) — inviting enforcement, investor backlash, and NGO campaigns.
risk · Context
Social and human-rights failures in operations and supply chain
Failure to respect human rights — forced or child labour, discrimination, unsafe conditions — in operations and supply chains, resulting in legal liability, boycotts, and ESG rating downgrades.
risk · Context
Financial-statement fraud and management override
Intentional misstatement through fictitious revenue, phantom inventory/assets, ghost-employee payroll, or management override of controls — inflating results and deceiving investors and regulators.
risk · Context
Ineffective ICFR / undisclosed material weakness
Because internal control over financial reporting is not maintained effectively - material weaknesses undetected or undisclosed and certifications signed despite known deficiencies - financial statements may be materially misstated and filings delayed or restated, resulting in SEC enforcement, delisting, securities-fraud liability, and loss of investor confidence.
risk · Context
Presentation and disclosure deficiencies
Debt misclassified as long-term, gross/net revenue errors, operating/non-operating misclassification, faulty segment reporting, undisclosed related-party transactions, unstated accounting-policy changes, going-concern and contingent-liability disclosure failures.
risk · Context
Inadequate board and management oversight of risk and control
Because board and management oversight of risk and control is weak - unclear tone at the top, ineffective board composition or independence, poor committee structure, and limited senior-management commitment - control priorities are not enforced and resources are withheld, so risks accumulate unmanaged and control failures go uncorrected across the entity.
risk · Context
Weak internal control environment enabling fraud and error
Because the internal control environment is weak - segregation of duties absent, authorization frameworks inadequate, and tone at the top poor - fraudulent and erroneous transactions can be initiated and concealed, resulting in material misstatement and financial, regulatory, and reputational loss.
risk · Context
Employment-practice and labor-law violations
Wrongful termination, wage-and-hour and overtime violations, benefit disputes, worker misclassification, whistleblower-protection breaches, and labor grievances/strike action causing litigation and operational loss.
risk · Context
Negligent advisory activities and breach of duty of care
Losses from disputes over M&A, structuring, financial-planning, or hedging advice where the firm has a duty of care — including failure to advise clients of material risks in recommended transactions.
risk · Context
Failed or inaccurate mandatory regulatory reporting
Late or inaccurate regulatory transaction reporting, missed regulatory-return deadlines, inaccurate risk reporting to management, and errors in suspicious-activity reporting — breaching disclosure obligations to regulators and stakeholders.
risk · Context
Securities-law and SEC-reporting non-compliance
Public-company reporting failures: late or restated SEC filings, disclosure-control deficiencies, and securities-fraud exposure distinct from the underlying ICFR weakness — triggering enforcement and delisting risk.
standard · Direct
IIA 2024 Standards
IIA 2024 Global Internal Audit Standards
unified · Context
UC-AUDIT-01 — Maintain an independent internal audit function
The organization maintains an internal audit function that provides the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight to protect and sustain organizational value. The function is positioned independently of management activities it audits: the chief audit executive reports functionally to the board, holds the qualifications and competencies the role requires, and has unrestricted access to the board. Independence is affirmed to the board at least annually.
unified · Context
UC-AUDIT-02 — Establish a board-approved internal audit mandate and charter
The board establishes and approves the internal audit mandate - the function's authority, role, and responsibilities - and documents it in an internal audit charter that is reviewed and reapproved periodically. The charter grants unrestricted access to the records, personnel, and physical property relevant to engagements, and the board and senior management visibly champion and support the mandate. The approved charter and review records are retained.
unified · Context
UC-AUDIT-03 — Ensure board oversight and support of internal audit
The board oversees the internal audit function through regular interaction with the chief audit executive, including executive sessions without management present, and approves the CAE's appointment, remuneration, evaluation, and removal. The board reviews and approves the internal audit plan and budget and ensures the function has sufficient resources to fulfill its mandate. Board meeting minutes and approvals evidence oversight.
unified · Context
UC-AUDIT-04 — Uphold integrity and ethical conduct in internal auditing
Internal auditors demonstrate integrity in their work and professional relationships: they act honestly, exhibit professional courage by communicating truthfully even when uncomfortable, comply with applicable laws and the organization's ethical expectations, and encourage ethical behavior across the organization. Ethics expectations are acknowledged by audit staff annually and deviations are addressed and documented.
unified · Context
UC-AUDIT-05 — Maintain auditor objectivity and disclose impairments
Internal auditors maintain individual objectivity - an unbiased professional attitude free from conflicts of interest - in all engagements. The chief audit executive implements safeguards such as conflict screening, assignment rotation, and recusal to protect objectivity, and auditors promptly disclose actual or perceived impairments so they can be managed and, where necessary, communicated to affected stakeholders. A complete prior-responsibility register is maintained and used for every engagement assignment. An auditor who held operational, design, management, or supervisory responsibility for an activity during the preceding 12 months is subject to a 12-month cooling-off period; if that requirement is not met, the engagement is reassigned or a suitably qualified independent party provides assurance. Portfolio-level reporting to senior management and the board identifies actual and perceived self-review threats and their safeguards. Conflict declarations, prior-responsibility screening, reassignment or independent-assurance results, and safeguard records are retained.
unified · Context
UC-AUDIT-06 — Ensure auditor competency and continuing development
The internal audit function collectively possesses, and individual auditors apply, the knowledge, skills, and abilities required for their responsibilities, engaging qualified assistance where gaps exist. Auditors maintain and enhance their competency through continuing professional development, which is planned, tracked, and reviewed at least annually. Training records and competency assessments evidence operation.
unified · Context
UC-AUDIT-07 — Exercise due professional care and professional skepticism
Internal auditors exercise due professional care by conforming with applicable professional internal auditing standards and by assessing the nature, circumstances, and requirements of each engagement, including the interests of stakeholders and the relative complexity and significance of the work. Auditors apply professional skepticism, critically assessing the reliability and sufficiency of information before relying on it. Conformance is confirmed through supervisory and quality reviews.
unified · Context
UC-AUDIT-08 — Protect confidential information obtained in audit work
Internal auditors use information obtained during their work only for legitimate professional purposes and in conformance with applicable laws, regulations, and organizational policies. Information is protected against unauthorized access, use, or disclosure during and after engagements, and confidentiality obligations extend to parties assisting the internal audit function. Confidentiality acknowledgments and access controls over audit files evidence operation.
unified · Context
UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan
The chief audit executive develops an internal audit strategy aligned with organizational objectives and stakeholder expectations, grounded in a documented understanding of the organization's governance, risk management, and control processes. The strategy includes a documented assurance, advisory, and administrative capacity mix calibrated against ERM maturity and resourcing; strategic change and the current risk environment; the strength and reliability of other assurance providers; and board direction and stakeholder expectations. A risk-based internal audit plan covering the audit universe is created at least annually, approved by the board, and adjusted as the risk landscape changes. The capacity mix is reconsidered whenever the plan is refreshed, and material changes are communicated to senior management and the board with their coverage impact. The strategy, plan, capacity mix, board approvals, refresh decisions, and communications are retained.
unified · Context
UC-AUDIT-10 — Manage internal audit financial, human, and technology resources
The chief audit executive manages the function's resources to deliver the approved audit plan: a sufficient budget, recruitment, development, and deployment of qualified personnel, and technology that supports the audit process. Resource sufficiency is reassessed against the plan on a defined cadence, and the impact of any constraints on audit coverage is communicated to senior management and the board.
unified · Context
UC-AUDIT-11 — Establish audit methodologies and engagement work programs
The chief audit executive establishes documented methodologies that govern how engagements are planned, performed, and reported. For each engagement, auditors communicate with relevant stakeholders during planning, allocate appropriate and sufficient engagement resources, and develop a work program specifying the procedures for achieving the engagement objectives, which is approved before fieldwork begins. Methodology documents and approved work programs evidence operation.
unified · Context
UC-AUDIT-12 — Plan engagements with risk-based objectives, scope, and criteria
Each internal audit engagement is planned effectively: auditors perform an engagement-level risk assessment of the activity under review, define engagement objectives and scope that address the assessed risks, and establish evaluation criteria against which the subject matter will be assessed. Planning decisions and their rationale are documented in the engagement file and approved by engagement supervision.
unified · Context
UC-AUDIT-13 — Gather and analyze evidence to develop engagement findings
Auditors gather information that is relevant, reliable, and sufficient to support analyses and evaluations, applying appropriate analytical methods and tools. Deviations between the established criteria and the observed condition are analyzed and assessed for significance and developed into potential findings documenting condition, criteria, cause, and effect. Evidence and analyses are captured in workpapers.
unified · Context
UC-AUDIT-14 — Evaluate findings and develop recommendations and action plans
Engagement findings are evaluated individually and collectively to formulate engagement conclusions relative to the engagement objectives, considering the significance of the findings. Recommendations and/or management action plans addressing root causes are developed, collaboratively where appropriate, and are supported by documented evidence. Conclusions and recommendations are reviewed before communication.
unified · Context
UC-AUDIT-15 — Document and supervise engagement work
Engagement work is documented in workpapers sufficient for an experienced internal auditor to understand the work performed and the support for results and conclusions, and is retained according to defined retention requirements. Engagement performance is supervised and reviewed throughout the engagement, with review notes resolved before results are communicated, to ensure quality and conformance with methodologies.
unified · Context
UC-AUDIT-16 — Communicate final engagement results to stakeholders
A final engagement communication is issued to appropriate parties for every engagement, presenting the objectives, scope, conclusions, findings, and recommendations or management action plans. Communications meet the quality expectations of being accurate, objective, clear, concise, constructive, complete, and timely. If a final communication contains a significant error or omission, corrected information is communicated to all recipients of the original.
unified · Context
UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
Findings, recommendations, and management action plans - including improvements identified from security tests and exercises, and those coordinated with suppliers and third parties - are tracked in a follow-up process, and implementation is confirmed through evidence-based verification before closure. When management has accepted a level of risk that may exceed the organization's risk appetite, the matter is discussed with senior management and, if unresolved, escalated to the board. Follow-up logs and escalation records are retained.
unified · Context
UC-AUDIT-18 — Communicate with stakeholders on assurance matters
The internal audit function builds relationships and communicates regularly with its stakeholders - the board, management, and relevant external parties such as regulators and external auditors - to develop trust and mutual understanding on internal control and assurance matters. Communication approaches are tailored to stakeholder needs and delivered through defined channels, and significant control matters are shared with external parties as appropriate. Communication plans and records evidence operation.
unified · Context
UC-AUDIT-19 — Operate an audit quality assurance and improvement program
The chief audit executive develops, implements, and maintains a quality assurance and improvement program covering all aspects of the internal audit function, including ongoing monitoring and periodic internal quality assessments of conformance with applicable professional internal auditing standards. Performance objectives and measures for the function are established and tracked, and results, action plans, and progress are reported to senior management and the board, which oversee audit quality.
unified · Context
UC-AUDIT-20 — Obtain external quality assessments of internal audit
An external quality assessment of the internal audit function is obtained at the frequency mandated by applicable professional standards from a qualified, independent assessor or assessment team, evaluating conformance with applicable professional internal auditing standards. The board participates in determining the assessment scope and assessor selection and receives the results directly, and resulting improvement actions are planned and tracked to completion.
unified · Context
UC-AUDIT-23 — Coordinate independent assurance reviews across providers
The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.
workflow · Context
Cybersecurity Assurance Review
Cybersecurity Assurance Review — a CAE-owned assurance engagement that runs on the EXISTING Audit item opened from the audit plan (audit_type=it_audit, status PLANNED, lead_auditor and scope already set): the workflow instance attaches to that item and enriches it end to end, never creating a duplicate engagement record. It covers the three IIA Cybersecurity Topical Requirement domains (governance, risk management, and control activities) over the cyber estate bounded in the engagement memo (in scope: named legal entities, networks, cloud tenants, and OT/ICS where included; out of scope: areas whose assurance is documented as delivered by other engagements), testing against the NIST 800-53 Rev 5 catalog with CSF 2.0 / ISO 27001 as the aggregation frame. It originates from the audit plan (no upstream workflow) and produces the findings register (one four-Cs Issue per finding), the cyber posture summary carrying the per-domain and overall Standard 14.5 conclusions, and the approved engagement package — which it hands to the downstream Audit Report Drafting workflow.
workflow · Context
Internal Audit Ethics, Objectivity & Competency Program
Runs on an Audit item created per cycle as the anchor — audit_type=internal, scope set to the IA professional-practice program for the period, period_start/period_end = the cycle window (a program cycle, not an engagement, so this is a documented reuse of the Audit type; it is the "cycle item" every stream links its evidence to and closes at the end). A decision-aware annual cycle that attests the ethics and professional-courage expectations and documents deviations, screens per-engagement conflicts and manages objectivity impairments, collects confidentiality acknowledgments and restricts audit-file access, and assesses competency against role requirements with approved, tracked continuing-professional-development plans for each auditor. It consumes no upstream workflow: prior-cycle carryover (unresolved-deviation and monitored-impairment Issue items still open against the prior cycle's Audit item, plus in-progress development plans) is its own input, and the population is confirmed against the HR roster, engagement staffing, and the audit-file access list before measurement begins. Named deliverables: the professional-practice requirements memo, the ethics attestation register, the conflict-of-interest declarations and impairment register, the confidentiality acknowledgment register and before/after audit-file access review, the competency assessments with coverage matrix and CPD plans, and the signed CAE conformance report to the audit committee — assembled into an indexed cycle evidence file on the anchor Audit item. Downstream is self-feeding: the carry-forward list produced at close hands off to the next run of this same workflow; there is no distinct downstream workflow. In scope: every auditor and assisting party (employees plus co-source, outsourced, and guest auditors) who performed internal audit work or holds audit-file access during the period, across all four expectation streams (ethics, objectivity, confidentiality, competency); out of scope: the audit engagements' own subject-matter conclusions and any HR, legal, or ethics-office investigation a disclosed concern is referred into.
workflow · Context
Fraud & Forensic Investigation Engagement
Fraud & Forensic Investigation Engagement as a decision-aware workflow. It runs on a dedicated Audit item (audit_type: investigation) created for this allegation at intake — the confidential case record — with the workflow instance attached to that item and its visibility restricted to the named investigation team. In scope: one specific fraud allegation, worked predication-gated and confidentially from intake through evidence preservation, forensic procedures, interviews, loss quantification, and audit-committee reporting; the named deliverables are the chain-of-custody register, the findings memorandum with its loss-quantification schedule, and the privilege-marked audit-committee fraud report. Out of scope: the enterprise fraud risk profile (owned by Fraud Risk Assessment & Anti-Override Control Review, which receives scheme intelligence from this case rather than being rerun here) and any unrelated conduct discovered in passing (which gets its own intake record). It consumes the hotline intake package from Control Responsibility Communications & Ethics Hotline when so routed, and hands each control breakdown off as an Issue item — control-gap findings to Finding Remediation & Action-Plan Monitoring and ICFR-affecting deficiencies to SOX Deficiency Remediation — rather than duplicating that work.
workflow · Context
Audit Fieldwork, Findings & Reporting
Runs on the existing audit item. Execute approved audit procedures, evaluate and clear observations, issue a supported report, and close the engagement record with tracked actions. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
ISO 27001 Certification Readiness
Runs on the existing audit item. Assess ISO/IEC 27001 certification readiness across ISMS scope, clauses, risk treatment, Annex A applicability, internal assurance, gaps, and audit-entry governance. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
Process Narrative & Walkthrough
Runs on the existing process item. Document an end-to-end process, corroborate the narrative through a representative walkthrough, and approve a traceable current-state record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
SOC 2 Trust Services Readiness
Runs on the existing Audit engagement with its system description, service commitments, review period, control and risk registers, and available evidence; assesses CC1–CC9 design readiness and consumes reviewed companion assessments for selected optional Trust Services categories. Delivers the criterion-to-control mapping, criterion-level evidence and design conclusions, owned gap register, and approved SOC 2 readiness disposition to management for remediation and examination planning; Type II testing, management-owned PBC preparation and management assertion remain separate workflows.
workflow · Context
Continuous Monitoring & Agent Evaluation
Runs on the existing standing Audit item for a monitoring cycle. Inputs are the approved KRI definitions, current Issue, Remediation, Control, System and Personnel records, and the agent-drafted suggestions and step results produced since the previous cycle. Deliver the monitoring dashboard, breach triage and quality scorecard to the engagement lead, with owned corrective actions and the next run date.
workflow · Context
Fraud Risk Assessment & JE Testing
Runs ON an audit item (an existing engagement). Assesses fraud risks across the fraud triangle and management override, maps anti-fraud controls to those risks, validates and characterizes the journal-entry population for the period, selects entries by pattern flag plus a reproducible random draw from the unflagged remainder, tests every selected entry for support, approval and business purpose, and raises every unsupported anomaly as an issue linked to its FSLI and control. Hands off to engagement reporting for issue disposition and reporting.
workflow · Context
Substantive Testing & Data Analytics
Runs on an existing Audit engagement (`audit`) already scoped to one or more significant FSLIs; enriches it, never re-creates it. Inputs: the scoped FSLI(s) (`fsli.balance`, `fsli.assertions`, `fsli.significant`) and a source-system extract per population under test. Named deliverables: the validated population record, the reproducible sample draw, the whole-population analytics results, and the FSLI assertion conclusion (`fsli.rationale`). Handoff: fraud risk and journal-entry testing (the fraud-risk-je-testing workflow) once every exception is dispositioned and the assertion conclusion is recorded.
workflow · Context
Internal Audit Engagement Lifecycle
Internal Audit Engagement Lifecycle: run an IIA-aligned engagement on the existing Audit item (audit_type=internal) created by Audit Engagement Planning — it enriches that item and never creates a duplicate; the workflow instance attaches to the Audit item and is archived on it at close. In scope: evidence requests, fieldwork, finding evaluation, supervisory QA, conclusions per objective, and action-plan registration for the auditable entity and period fixed at planning (Audit.scope, Audit.period_start/period_end). Named deliverables: the evaluated findings register (one Issue item per finding), conclusions per objective (recorded on the Audit item as rating/opinion), and the report-ready handoff package. Out of scope: report wording (owned by Audit Report Drafting) and remediation validation (owned by Finding Remediation & Action-Plan Monitoring). It consumes the approved planning handoff package from Audit Engagement Planning and hands off to BOTH downstream workflows — Audit Report Drafting (the findings register and conclusions) and Finding Remediation & Action-Plan Monitoring (the registered action records) — rather than duplicating their work.
workflow · Context
Audit Engagement Planning
Audit Engagement Planning runs ON an already-opened Audit item — the engagement record the annual audit plan created. The audit is an INPUT: this workflow enriches that item, it never creates a duplicate. In scope: producing the planning package — scope, the engagement risk assessment and mapped control population (Risk and Control items linked to the Audit; together the engagement Risk & Control Matrix, the RCM), the sampling plan, the planning memos, and the enriched audit record. Out of scope: fieldwork, findings, and reporting, which belong to the downstream Internal Audit Engagement Lifecycle workflow that consumes this workflow's handoff package (the RCM travels with it). There is no upstream workflow; planning starts from the audit-plan entry itself.
workflow · Context
Finding Remediation & Action-Plan Monitoring
Finding Remediation & Action-Plan Monitoring runs on the EXISTING parent Audit item — the issued engagement whose report findings are being followed up — enriching that Audit and its linked findings rather than creating a new engagement; the workflow instance attaches to that Audit item, and each report finding is an Issue item linked to it. It tracks issued-report findings and their agreed management actions from registration through evidence validation, closure, extension, risk acceptance, escalation, and committee reporting, and produces a verified disposition register and a signed final evidence-and-decision package. In scope: all open findings from the engagement plus any prior-cycle findings still open against the same auditee. Out of scope: re-performing engagement fieldwork and re-wording report findings (both belong to the upstream Audit Report Drafting workflow) and assembling the board pack (the downstream Quarterly Board & Audit-Committee GRC Reporting workflow consumes this cycle's outputs). It consumes the issued final report and findings register handed off from Audit Report Drafting and hands its verified outputs to Quarterly Board & Audit-Committee GRC Reporting.
workflow · Context
Quality Assurance & Improvement Program Cycle
Operate the Quality Assurance & Improvement Program (QAIP) cycle: ongoing-monitoring evidence, periodic self-assessment, external quality assessment (EQA) support, improvement planning, and board reporting. This cycle runs on an Audit item created per cycle (audit_type = internal — the schema has no quality_assessment option; scope = "QAIP cycle FYxx"; period_start/period_end span the period under assessment); the workflow instance attaches to that Audit item and every cycle output — the per-standard conformance ratings matrix, the below-GC finding Issue items, the improvement and action plan, and the QAIP results report — links back to it. It consumes the period's existing engagement Audit items and their completed engagement-workflow runs as the population and test evidence, plus the standing QAIP framework, charter, and methodology-manual Policy items. In scope: assessing the internal audit function's conformance with the Global Internal Audit Standards for the period. Out of scope: engagement-level rework — this cycle assesses quality, it does not redo fieldwork, which belongs to the engagement workflows. There is no upstream feeder; this workflow starts the quality chain and hands its approved results — overall conclusion, per-domain ratings, and conformance-statement wording — to Quarterly Board & Audit-Committee GRC Reporting.
workflow · Context
Audit Report Drafting
Runs on the existing Audit using approved fieldwork conclusions, findings and management responses. Produces the audit report after management factual confirmation and independent IA management approval of the exact draft, then the issued report, completion announcement and tenant-bound MAR survey dispatch record for remediation monitoring and QAIP.
workflow · Context
Third-Party Vendor Assurance Engagement
Runs on the existing Audit item for this engagement (audit_type=vendor_review) — the workflow enriches that already-planned engagement record, it never creates a duplicate — consuming the confirmed scope, criteria, and calendar handed off from Audit Engagement Planning. An IA-led third-party vendor assurance engagement that concludes on the design and operating effectiveness of the organization’s TPRM program — governance, risk tiering, vendor control-environment reliance, monitoring, exclusions, and reporting. Vendors under test are the existing Vendor items, each finding is an Issue item, and the named deliverable is a reperformable engagement workpaper package. In scope: assuring the program (IA evaluates management’s third-party risk management; it does not operate it). Out of scope: operating the vendor lifecycle (onboarding, tier refresh, remediation), which belongs to the second-line Third-Party Vendor Risk Lifecycle workflow; deep single-report SOC work, which can be delegated to the reusable Vendor SOC 1/SOC 2 Report Review & CUEC Mapping workflow; and ICT arrangements caught by regulatory regimes, which route to Third-Party ICT Vendor Regulatory Assurance. Findings and the engagement conclusion exit through Audit Report Drafting, and action plans route to Finding Remediation & Action-Plan Monitoring.
workflow · Context
Internal Audit Charter, Independence & Board Governance Cycle
Runs on one Audit item created per governance cycle (audit_type: internal; scope set to the internal-audit charter/independence/board-governance cycle for the period) — the workflow instance attaches to that cycle item and writes to it throughout. The internal audit function and its board-approved charter — a Policy item (policy_type: charter) with its own version lineage — already exist and are reviewed, reaffirmed, or amended here, never recreated. The cycle as a decision-aware procedure: the CAE delivers functional reporting to the audit committee, affirms organizational independence in writing and treats any impairment, reviews and reapproves the board mandate and charter with its unrestricted-access provisions, runs the executive session and committee action on the CAE and the plan and budget, executes the stakeholder communication plan, and retains the governance evidence. Consumes upstream: closed assurance-engagement records (Audit items with their linked Issue findings) produced by the individual engagement workflows, the recommendation-tracking register (Issue items), and the prior cycle's carry-forward (open Issue items plus the prior run's carry-forward list). Named deliverables: the CAE functional reporting pack, the written organizational-independence affirmation, the reaffirmed or reapproved audit charter, the audit-committee minutes and resolution records, the stakeholder communication log, and the control-linked governance evidence set. In scope: the board-governance cycle for the internal audit function itself — charter, independence, committee reporting, and stakeholder communication; out of scope: the individual assurance engagements whose results feed the committee report, which run under their own workflows. Terminal by design: no downstream workflow is chained from this cycle; open threads carry forward to seed the next run of this same cycle.
workflow · Context
Annual Internal Audit Planning & Resource Management
Runs the chief audit executive's annual internal audit planning cycle on a per-cycle Audit item created for the year (audit_type=internal, e.g. "Annual IA Planning Cycle FY20XX", status PLANNED→COMPLETE, period_start/period_end = the plan year) — the anchor the workflow instance and every cycle document and link hang off, since no native plan/cycle type exists. It consumes the standing (prior-year) audit universe carried in as Process items plus the prior cycle's archived instance and universe memo, and enriches rather than recreates it: it refreshes the audit universe and the documented understanding of governance, risk, and control processes, ranks the universe by residual risk, develops the internal audit strategy and the risk-based audit plan, resources it with a budget, staffing, and technology plan, tests resource sufficiency, obtains board approval, and reassesses the plan and resources on the quarterly refresh. In scope is the enterprise-level planning cycle from audit-universe refresh through board approval, plus the quarterly plan-and-resource reassessment; delivering the individual engagements is out of scope — the approved engagement list (the created engagement Audit items) hands off to each engagement's own audit engagement planning workflow.
workflow · Context
ISMS Internal Audit & Management Review
Runs one ISO 27001 clause 9.2 internal audit and clause 9.3 management review cycle — including clause 10.1 corrective actions — against the existing Audit item for this cycle (audit_type=internal), whose scope, lead_auditor, and period dates already carry the ISMS audit-programme entry: the workflow enriches that Audit item and its findings, never creates a duplicate audit. Upstream it consumes the Annex A control population (Control items, framework iso-27001) and the applicability decisions in the Statement of Applicability, the risk register (Risk items) and treatment plan, the prior-cycle Audit and open Issue records, and the org's ISMS policies and procedures (Policy items) as audit criteria. Named deliverables: the internal audit findings report, the clause 10.1 corrective-action records (recorded on the finding Issue items), the management review pack, and the approved clause 9.3 minutes and action register. Out of scope: the certification-body external audit and day-to-day control operation. No upstream workflow feeds this cycle and no single downstream workflow consumes its output; at close the cycle is archived on the Audit item as retained ISMS documented information, and carry-forward items re-enter the audit programme (the next PLANNED Audit item), the risk register, or the next review's inputs.
workflow · Context
SOC 2 Readiness & Evidence Collection
SOC 2 Readiness & Evidence Collection runs ON an already-opened Audit item — the SOC examination engagement record (audit_type readiness, or external_attestation) whose scope (report type and Type 1/Type 2), examination period (period_start/period_end), and CPA firm (external_firm) are already set. That Audit item is an INPUT: this workflow enriches it and attaches its run to it, never creating a duplicate engagement. It consumes the organization's own Control library — the Control items, framework tagged soc2/soc1 — and no upstream workflow feeds it. In scope: one SOC examination cycle end to end — map the Control library to each in-scope Trust Services criterion (Security always; Availability, Confidentiality, Processing Integrity, or Privacy only where a customer commitment requires it) and SOC 1 control objective, close readiness gaps, run the provided-by-client (PBC) evidence request list with QA, and coordinate the CPA firm through fieldwork and follow-ups. Named deliverables: the criteria-to-control mapping matrix and graded gap matrix, the owned PBC evidence request list, the QA'd evidence set, and the cross-referenced PBC response package — all attached to the anchor Audit and its workflow instance. Out of scope: the SOC report the CPA firm drafts and continuous control monitoring between examinations. No downstream workflow is declared; this run's next-cycle seed artifacts (the PBC list and control calendar) stay on the close step as the de facto handoff to the next examination.
workflow · Context
Security Control Assessment & POA&M Remediation
Run this assessment on the EXISTING Audit item for the engagement (audit_type: it_audit or compliance) — enrich that record, never create a duplicate: Audit.scope carries the authorization boundary and Audit.period_start/period_end the assessment window. Consumes, from the upstream SSP-development / system-categorization effort, the approved System Security Plan (SSP), the FIPS 199 system categorization, and the tailored NIST 800-53 baseline (existing Control items, framework: nist-800-53). Assess each in-scope control with 800-53A examine/interview/test methods, record satisfied / other-than-satisfied determinations, open a POA&M Issue for every gap, re-validate remediation, and issue the Security Assessment Report (SAR). In scope: control assessment, determinations, the POA&M lifecycle, and the SAR for the authorization boundary agreed at kickoff. Out of scope: the authorization (ATO) decision itself and the steady-state continuous-monitoring cadence. On completion, the frozen SAR and POA&M package are handed to the NIST RMF System Authorization (ATO) Cycle.
workflow · Context
Control Design Assessment
Runs on the existing control item. Assess whether a control is clearly specified and designed to address its stated risk before deciding what follow-up or testing is appropriate. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
Control Exception Evaluation and Remediation
Runs on the existing control item. Validate a control-test exception, evaluate its scope and implications, determine disposition, and establish accountable remediation where needed. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
Control Remediation Retest and Closure
Runs on the existing control item. Verify remediation readiness, independently retest the changed control, evaluate sustained results, and approve a supported closure decision. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
Control Walkthrough
Runs on the existing control item. Walk one representative transaction or event through the control to understand actual execution, evidence, handoffs, and changes. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
ISO 27001 Stage 1 ISMS Documentation Review
Certification-body Stage 1 review of the ISMS against ISO/IEC 27001:2022 clauses 4–10: context and leadership, planning and support, operation, and performance evaluation with improvement - walking each clause group against the governing documents and the operating processes that carry it, and concluding Stage 2 readiness with dual sign-off. Stage 1 documentation and readiness review for ISO/IEC 27001:2022 clauses 4–10, conducted under the engagement methodology. It informs Stage 2 planning and does not issue a certification decision. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.
workflow · Context
ISO 27001 Stage 2 Annex A Controls Audit
Attach to the existing Audit engagement, owned by Internal Audit, using its approved Statement of Applicability, risk treatment plan, scope, review period and operating evidence; produce the Stage 2 Annex A Controls Audit report, four signed theme conclusions and finding register for the engagement and remediation owners. Apply the approved Statement of Applicability to ISO/IEC 27001:2022 Annex A.5.1–A.5.37, A.6.1–A.6.8, A.7.1–A.7.14 and A.8.1–A.8.34; document each exclusion and assess direct and inherited responsibilities. This Annex A assessment contributes to the engagement and does not independently establish full ISMS conformity or issue certification. Stage 1 and readiness remain separate workflows; any certification decision remains with the authorized certification body.
workflow · Context
Audit Planning and Scoping
Runs on the existing audit item. Plan an audit engagement from four independent starting points — management self-identified issues, the external threat and regulatory landscape, prior audit history, and the in-scope risk and control set — which converge into the walkthrough question set, the walkthrough, and the approved risk and control matrix that governs fieldwork. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
Interim Operating Effectiveness Testing
Runs on the existing SOX Audit using approved Control-hosted TOD/TOE results and the interim scope. Produces the program coverage and exception register, remaining-period commitments, all-controls auditor handoff and management status communications for year-end roll-forward.
workflow · Context
Quarterly Board & Audit-Committee GRC Reporting
Runs on the existing standing "Board & Audit-Committee GRC Reporting" governance Process item (process_type=business_process, frequency=quarterly): one workflow instance per quarter attaches to that Process and enriches it (the Process is not created here), and each closed instance is the prior-quarter baseline for the next run. The named deliverable is the quarterly board & audit-committee GRC pack (six-domain narrative deck, Word + PDF, redaction-cleared). It compiles that pack across six domains — risk profile, control health, open issues, regulatory deadlines, audit-plan progress, and SOX posture — computed over one quarter window. In scope: aggregating and synthesizing existing GRC records (Risk, Control, Issue, Audit, and Control-hosted SOX testing workflows) into a board-level narrative, obtaining executive and committee approval, and archiving the decision and action register. Out of scope: performing the underlying risk assessments, audits, or control tests themselves. Consumes two upstream handoff packages: the Enterprise Risk Assessment & Portfolio Oversight Cycle package (risk register, residual scores, appetite positions) and the Audit Report Drafting & Regulatory Compliance Attestation Cycle package (audit-plan status, issued reports, attestation status); there is no downstream workflow — the closed package feeds the next quarterly run of this workflow.
workflow · Context
Policy Exception & Risk Acceptance
Policy Exception & Risk Acceptance as a decision-aware workflow. It carries a waiver from request and justification through risk assessment, compensating controls, time-bound approval, registration with expiry, and re-review so no exception outlives its rationale. The exception IS an Issue item (issue_type: policy_exception) — the workflow runs on it, and the exception register is simply the set of those Issues, queryable by their filterable exception_expiry_date. The affected policy is a Policy item the Issue links to; a granted acceptance also sets treatment: accept on the linked Risk item. In scope: time-bound exceptions/waivers to an existing policy that are risk-accepted for a bounded window. Out of scope: permanent policy-change proposals, which route to the Policy Lifecycle Management workflow (the Policy item's revision process) rather than this waiver workflow. No upstream or downstream workflow feeds or consumes this one; the exception request is the initial input, and recurring-exception patterns are compiled as feedback onto the affected Policy items at close.
workflow · Context
Combined Assurance Mapping
Combined Assurance Mapping as a decision-aware workflow. Each cycle runs as one workflow instance attached to an Audit item created for the cycle (audit_type: advisory, scope = the combined-assurance mapping scope for the period, period_start/period_end = the cycle period) — no other Studio type represents an assurance-coordination cycle, so the workflow enriches that Audit item rather than any pre-existing engagement. In scope: mapping assurance coverage across the Three Lines of Defense for the confirmed risk universe and entities this cycle — cataloging assurance providers, mapping their coverage onto the risk universe, assessing reliance, identifying gaps and duplication, coordinating coverage plans, publishing the combined assurance map, and preparing audit-committee reporting inputs. Out of scope: performing the underlying assurance engagements themselves (owned by internal audit, second-line functions, and external providers) and any risk, entity, or provider not named in this cycle's confirmed scope. It consumes the risk universe and residual positions (Risk items with their residual_rating and treatment) from the upstream Enterprise Risk Assessment & Portfolio Oversight Cycle and hands its named deliverables — the published combined assurance map, the reliance conclusions, and the gap action plans — to the downstream Quarterly Board & Audit-Committee GRC Reporting workflow rather than duplicating repeated work.
workflow · Context
Regulatory Exam & External Audit Management
Manage a live regulator examination or external audit end to end — from notification intake through request fulfillment, QC’d evidence release, fieldwork support, preliminary-findings response, and commitment closure. Runs on an Audit engagement item created per exam (audit_type = regulatory_exam, or external_attestation for an external audit); the workflow instance attaches to that Audit anchor, and preliminary findings and their corrective-action commitments become linked Issue items. No upstream workflow feeds this — it is triggered by the exam or audit notification itself. In scope: coordinating examiner requests, controlled evidence release, and management responses for a single exam or audit engagement. Out of scope: remediating the underlying control gaps — the findings and committed corrective actions hand off to Finding Remediation & Action-Plan Monitoring — and standing up new obligations surfaced by the exam, which hand off to Regulatory Horizon Scanning & Triage and Regulatory Obligation Implementation.
workflow · Context
Year-End Deficiency Aggregation & Severity Evaluation
Year-End Deficiency Aggregation & Severity Evaluation as a modular, decision-aware workflow. The instance runs against the existing fiscal-year ICFR assessment engagement — the Audit item with audit_type=sox_testing whose period_end is fiscal year end — enriching it rather than creating a duplicate: the frozen register snapshot and the full evaluation memo trail attach to its steps, and the overall ICFR conclusion lands on that Audit item (rating/opinion/report_date). It closes the gap between per-deficiency handling and the portfolio view: it freezes the register, reconciles it to every failed test, aggregates related deficiencies, concludes control deficiency versus significant deficiency versus material weakness, and hands conclusions to certification support, remediation, and audit-committee reporting instead of duplicating their work. The named deliverables are the year-end deficiency-evaluation memo (carrying the overall ICFR conclusion) and the countersigned final severity schedule. In scope: freezing and severity-evaluating the year-end deficiency population as of the fiscal-year-end assessment date, kept live through the 10-K filing date under a late-arrival rule. Out of scope, handed off rather than duplicated: fixing the deficiencies (SOX Deficiency Remediation) and reporting them to the board (Quarterly Board & Audit-Committee GRC Reporting). Severity thresholds and the contributing-test population are consumed from the Annual ICFR Scoping & Risk Assessment, SOX Key Control TOD/TOE Test, and SOX ITGC Testing runs — the deficiency register itself is the Issue population (issue_type deficiency, escalating to significant_deficiency and material_weakness as this workflow finalizes).
workflow · Context
SOX Annual Planning & Risk Assessment
Runs on the existing audit item. Plan the annual SOX program through materiality, entity and account scoping, risk and control mapping, reliance strategy, calendar, and governance approval. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
Year-End Planning & Roll-Forward
Runs on the existing audit item. Plan and govern SOX year-end and roll-forward coverage based on interim results, changes, deficiencies, remaining populations, and reporting deadlines. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.
workflow · Context
SOX Deficiency Remediation
SOX Deficiency Remediation carries one control deficiency's full lifecycle — grade, root cause, remediation, validation, and closure. The workflow runs on the deficiency **Issue item** it opens at grading — `issue_type` set to the exact SOX grade (deficiency / significant_deficiency / material_weakness) and `severity` on the mapped AssureSwarm scale — linked to the affected Control(s), the source Control-hosted SOX testing workflow (template kind: sox-testing), and the current-year SOX audit (Audit, `audit_type: sox_testing`); the remediation actions and the validation retest live as steps on this Issue's own workflow. In scope: a single deficiency triggered by a failed test or unresolved exception. It **consumes** the concluded, reviewed failed-test workpaper handoff package owned upstream (SOX Key Control TOD/TOE Test and SOX ITGC Testing) and **hands off** the closed-or-carried deficiency outcome — with its intact severity history and any triggered communication obligations — to Quarterly Board & Audit-Committee GRC Reporting, which aggregates the full deficiency population into the period's ICFR conclusion and audit-committee materials. It exchanges handoff packages with those related workflows rather than duplicating their work.
workflow · Context
SOX IPE Validation
SOX IPE Validation as a modular, decision-aware workflow that runs on — and enriches — the existing relying Control item (a key control, framework⊇sox) whose evidence depends on an Information Produced by the Entity (IPE) report: the report's identity, test history, and C&A test date are recorded onto that control rather than into a separate record. In scope: the completeness-and-accuracy conclusion for one IPE report for one period. It consumes its starting key-control population from the upstream SOX scoping / RCM build — the Control library with its Control ↔ Risk links. Its named deliverables are a reperformable completeness-and-accuracy (C&A) memo attached to the control and a validated-IPE evidence-and-decision package. Out of scope: testing the relying control's own operation — that belongs to the downstream SOX Key Control TOD/TOE Test, which anchors on the control's fiscal-year Control-hosted SOX testing workflow and cites this workflow's C&A package instead of re-validating. It can stand alone, but hands its validated-IPE package to SOX Key Control TOD/TOE Test instead of duplicating repeated work.
workflow · Context
SOX Process Walkthrough
Runs on the existing Process item being walked (process_type=financial_reporting) — one workflow instance per walkthrough unit (process × location × variant), with the SOX program's Audit item (audit_type=sox_testing) linked as engagement context. It enriches that Process item and seeds its controls; it never creates a duplicate process. Consumes upstream: the significant-account and location scoping baseline, which it takes as a handoff package from the SOX Scoping Decision workflow rather than re-deriving. Produces the named deliverables: the documented process understanding, the identified key controls and their attributes, the control-to-risk mapping (the Risk & Control Matrix, RCM), the walkthrough memo (which doubles as the process's standing narrative), and draft Control records seeded into the register. Out of scope, owned downstream: design-effectiveness conclusions, sampling, and control testing — the handoff splits the control population so confirmed-design controls go to the SOX Key Control TOD/TOE Test workflow and open-design-gap controls go to the Control Design workflow first. It can stand alone but is designed to exchange handoff packages with these related workflows instead of duplicating repeated work.