{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-14","description":"Engagement findings are evaluated individually and collectively to formulate engagement conclusions relative to the engagement objectives, considering the significance of the findings. Recommendations and/or management action plans addressing root causes are developed, collaboratively where appropriate, and are supported by documented evidence. Conclusions and recommendations are reviewed before communication.","details":{"control_category":"administrative","control_type":"detective","domain":"Compliance, Audit & Assurance","guidance":[],"members":[{"control_id":"Std 14.3","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 14.4","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 14.5","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"Engagement findings are evaluated individually and collectively to formulate engagement conclusions relative to the engagement objectives, considering the significance of the findings. Recommendations and/or management action plans addressing root causes are developed, collaboratively where appropriate, and are supported by documented evidence. Conclusions and recommendations are reviewed before communication.","title":"Evaluate findings and develop recommendations and action plans","unified_id":"UC-AUDIT-14"},"id":"uc:UC-AUDIT-14","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-14","sourceIds":["iia-2024"],"sourceUrl":null,"title":"UC-AUDIT-14 — Evaluate findings and develop recommendations and action plans","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a632fc67be2947e0352961ac5fedad6171a9a5c30fdba5d58bfe79a8b97b6df","properties":{},"sourceDetailPath":"/data/v1/records/wf-a17-a4afb609.json","sourceId":"wf:A17","targetDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","targetId":"uc:UC-AUDIT-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5bc74f6b251b9d2c0f6f41dac796967208362afd9bc11f3c4a8952374ade5bf4","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","sourceId":"uc:UC-AUDIT-14","targetDetailPath":"/data/v1/records/risk-risk-securities-law-noncompliance-a155942c.json","targetId":"risk:risk-securities-law-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:62037741fc42cd5c073145e03ea36570266ea858da6f8f4d1612637bec14a138","properties":{},"sourceDetailPath":"/data/v1/records/wf-a6-92070208.json","sourceId":"wf:A6","targetDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","targetId":"uc:UC-AUDIT-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6c8568d03145ca48d81aed0426ed8c06d5c1e490e9356c1d0464322d5a791055","properties":{"control_id":"Std 14.3","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","sourceId":"uc:UC-AUDIT-14","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-14-3-c92edb96.json","targetId":"ctrl:iia-2024:Std 14.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:86035f91c13e958aa66f1cfa79dbe35b3fe0d6859a1b031536d28c57726b3b7d","properties":{},"sourceDetailPath":"/data/v1/records/wf-a11-0924c009.json","sourceId":"wf:A11","targetDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","targetId":"uc:UC-AUDIT-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8ba742e7ffc46f304a251823a8f168f237265c0f27f2dff163eee1e2fda0f16c","properties":{},"sourceDetailPath":"/data/v1/records/wf-a19-c8784b53.json","sourceId":"wf:A19","targetDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","targetId":"uc:UC-AUDIT-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8bb7ca3b01b21d2349240ca0fab3996ea3a3f66527b82a3f9ecfdf72478aac46","properties":{},"sourceDetailPath":"/data/v1/records/wf-d02-28b5b7ac.json","sourceId":"wf:D02","targetDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","targetId":"uc:UC-AUDIT-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:983dcd739e234a8cf188f7bfe3733af7ed7bf39508f7f595166e6ca542d27020","properties":{"control_id":"Std 14.4","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","sourceId":"uc:UC-AUDIT-14","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-14-4-64e64b21.json","targetId":"ctrl:iia-2024:Std 14.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4172bf537c1d97b457873b123638286ca9ff745475af298eb505c84e7ee2207","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","targetId":"uc:UC-AUDIT-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6cd128d84a93da436a2d4259532ce4a17f15663edc42ecafe7d5265a74d1293","properties":{"control_id":"Std 14.5","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","sourceId":"uc:UC-AUDIT-14","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-14-5-8eb1fda0.json","targetId":"ctrl:iia-2024:Std 14.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e69d4fb1c971517a5151e848a39ca9beeda0616d7f5afe2f211e4995b05a4b6f","properties":{},"sourceDetailPath":"/data/v1/records/wf-a12-a338c67f.json","sourceId":"wf:A12","targetDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","targetId":"uc:UC-AUDIT-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e77e2d007dd6d76f1adb7e48413736eeee510041bac2cb0cab3c19c64d4729d1","properties":{},"sourceDetailPath":"/data/v1/records/wf-s16-ff1d0766.json","sourceId":"wf:S16","targetDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","targetId":"uc:UC-AUDIT-14","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f179950d0a4965a393fcf2173db2ed4fdf20e35ba2bb4f5842bffededb3f232c","properties":{"rationale":"Evaluating findings into conclusions and root-cause recommendations/action plans is core independent-audit output.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","sourceId":"uc:UC-AUDIT-14","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb39d74b86bb6e5cc5537712ce583aae41c173c95cd10c8f4f03c5f8dd598f42","properties":{},"sourceDetailPath":"/data/v1/records/wf-a2-163f5a6d.json","sourceId":"wf:A2","targetDetailPath":"/data/v1/records/uc-uc-audit-14-5c0dbe8f.json","targetId":"uc:UC-AUDIT-14","type":"tests"}],"schemaVersion":1}
