{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Financial Reporting Controls (SOX)","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-FIN-04","description":"Require transactions, journal entries, and master-data or configuration changes to be reviewed and approved by authorized personnel in accordance with the delegation-of-authority matrix before they are recorded or executed. Capture approvals in systems under unique authenticated user accounts with tamper-evident audit trails that irrefutably bind each approval to the individual who performed it, so that approval actions cannot be repudiated. Evidence includes the delegation-of-authority matrix, approval workflow configurations, and approval audit trails.","details":{"control_category":"administrative","control_type":"preventive","domain":"Financial Reporting Controls (SOX)","guidance":[],"members":[{"control_id":"PLC-AUTH","coverage":"full","framework":"sox","relationship":"superset_of"},{"control_id":"AU-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Require transactions, journal entries, and master-data or configuration changes to be reviewed and approved by authorized personnel in accordance with the delegation-of-authority matrix before they are recorded or executed. Capture approvals in systems under unique authenticated user accounts with tamper-evident audit trails that irrefutably bind each approval to the individual who performed it, so that approval actions cannot be repudiated. Evidence includes the delegation-of-authority matrix, approval workflow configurations, and approval audit trails.","title":"Authorize transactions with attributable approvals","unified_id":"UC-FIN-04"},"id":"uc:UC-FIN-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-FIN-04","sourceIds":["nist-800-53","sox"],"sourceUrl":null,"title":"UC-FIN-04 — Authorize transactions with attributable approvals","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0c26894d9a1db6597423b59878d14dd153b59218801fa92ad511d821036eca01","properties":{},"sourceDetailPath":"/data/v1/records/wf-s6-7962d7b6.json","sourceId":"wf:S6","targetDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","targetId":"uc:UC-FIN-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5e0502f03666ac57581692e83755a316a66434139093b3a4ca5d20ba699ea432","properties":{},"sourceDetailPath":"/data/v1/records/wf-s9-feb4a0f4.json","sourceId":"wf:S9","targetDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","targetId":"uc:UC-FIN-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:61c3659e40b022738d95781c0ab6ed22d5af66f49a40a068a8650d578c545ea9","properties":{"rationale":"Journal entries require authorized approval bound to the individual, controlling top-side override entries.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/risk-fin-journal-entry-management-override-b0c0ed68.json","targetId":"risk:fin-journal-entry-management-override","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:74a90d774e2c69425b083c4545a4c9227ee5937951e4236d687fccf4cad357d2","properties":{"rationale":"Approval per delegation-of-authority before recording prevents unauthorized/fictitious transactions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7cf868d19e732d1b5a6d883c2cf48ca90660fc61f6e6e6b72439cb7eaf2e9d4a","properties":{"rationale":"Authorization before execution prevents unauthorized disbursements and forgery.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/risk-fraud-internal-misappropriation-d235cd10.json","targetId":"risk:fraud-internal-misappropriation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:81ea46c24685d506652127b90741eaa1479fd8ec33249d4cac4a31af051754c9","properties":{"control_id":"AU-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-10-71482204.json","targetId":"ctrl:nist-800-53:AU-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:82f09dc0d1998db16eb313a371bb57aa03bedb773f44fcac37980166b3ca25a3","properties":{"rationale":"Authorization plus tamper-evident, attributable approval trails deter and expose fraudulent entries and override.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/risk-fin-financial-statement-fraud-1dd35d5a.json","targetId":"risk:fin-financial-statement-fraud","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a8b435dca563a57e72adbdadeabbe05b3d377d6d22184541cd8f2323364bf5bc","properties":{"rationale":"Approval workflows enforce that authorizers differ from recorders, supporting SoD.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/risk-fin-segregation-of-duties-eb7ee015.json","targetId":"risk:fin-segregation-of-duties","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b37c770c18f24eef3f1646bd2d33533966a017133c4090481de500edf5fb81e5","properties":{"control_id":"PLC-AUTH","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/ctrl-sox-plc-auth-85c1f61f.json","targetId":"ctrl:sox:PLC-AUTH","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b5225b9b6447d6ba5bc05cee49b5e04c5a571f789dcb0da47abd0d7c730a9cbf","properties":{"rationale":"Requiring authorization of revenue transactions/credit memos reduces fictitious or channel-stuffed revenue.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/risk-fin-revenue-recognition-misstatement-5e181e17.json","targetId":"risk:fin-revenue-recognition-misstatement","type":"mitigates"}],"schemaVersion":1}
