{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Financial Reporting Controls (SOX)","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-FIN-01","description":"Deploy control activities over financial reporting through formally approved policies and procedures that state what is expected and how it is performed, including entity-wide policies for technology general controls and oversight of the period-end financial reporting process. Assign owners, communicate the policies to responsible personnel, and review and reapprove them periodically. Evidence includes the approved policy set, periodic review sign-offs, and communication records.","details":{"control_category":"administrative","control_type":"preventive","domain":"Financial Reporting Controls (SOX)","guidance":[],"members":[{"control_id":"ELC-CA","coverage":"full","framework":"sox","relationship":"equal"}],"statement":"Deploy control activities over financial reporting through formally approved policies and procedures that state what is expected and how it is performed, including entity-wide policies for technology general controls and oversight of the period-end financial reporting process. Assign owners, communicate the policies to responsible personnel, and review and reapprove them periodically. Evidence includes the approved policy set, periodic review sign-offs, and communication records.","title":"Deploy financial control activities through policies","unified_id":"UC-FIN-01"},"id":"uc:UC-FIN-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-FIN-01","sourceIds":["sox"],"sourceUrl":null,"title":"UC-FIN-01 — Deploy financial control activities through policies","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:369284a22c0fd47c9dea73df206e5f417b9f06508a2f3a67ff4c7d101c234d04","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/risk-fin-rights-obligations-relatedparty-60258f56.json","targetId":"risk:fin-rights-obligations-relatedparty","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4ecd34db9d097564c7fb32f8cb286427a3dfa36e883c8d44cf608543775467d8","properties":{"rationale":"Deploying control activities via approved, owned, periodically-reviewed policies is a core structural defense of ICFR effectiveness.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/risk-fin-icfr-material-weakness-cdd66323.json","targetId":"risk:fin-icfr-material-weakness","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:76b7d7300105f707950a83a7aa3571ceadfd49617eae856615b8ecc13f521cf6","properties":{},"sourceDetailPath":"/data/v1/records/wf-s8-45ab5a56.json","sourceId":"wf:S8","targetDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","targetId":"uc:UC-FIN-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:92c166528433d4ccfc30ca9994e04b7a10b1934598d096f9144c302388cbe0f2","properties":{},"sourceDetailPath":"/data/v1/records/wf-s11-1dc58397.json","sourceId":"wf:S11","targetDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","targetId":"uc:UC-FIN-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b1f4741ce2d6a0d316875fa449b489a075da04aced37ae5635d1d20824bf667","properties":{"rationale":"Policy-based control activities and period-end oversight raise the barrier to management override and fraud.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/risk-fin-financial-statement-fraud-1dd35d5a.json","targetId":"risk:fin-financial-statement-fraud","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a9955cbb71be92d1dccb2728b3240b6e12c801f1828db98df7faad84876278f2","properties":{"control_id":"ELC-CA","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/ctrl-sox-elc-ca-3faabd89.json","targetId":"ctrl:sox:ELC-CA","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ee9a8a0658c7d5bfae3dd3d332929ba269a38b70a8b88a17fd688a899e7dde08","properties":{},"sourceDetailPath":"/data/v1/records/wf-g34-1b925ad7.json","sourceId":"wf:G34","targetDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","targetId":"uc:UC-FIN-01","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f29bdec3d0a1cca38f2780fd2a441b2318391923443b088ae20dbd62eb33c293","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/risk-fin-valuation-impairment-07037c02.json","targetId":"risk:fin-valuation-impairment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f5b43883746d220554d0183dc6d26d938826b9d85875d2289b3f2c69534a689f","properties":{"rationale":"Formally approved control-activity policies with assigned owners strengthen the control environment against weakness.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"}],"schemaVersion":1}
