{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:3674467114ba7d272775885cfbb2dc7591c579950a0bdad5f8e7d49a90cba04e","slug":"grc-soc2-reporting-management-assertion","url":"/assets/agent_workflow-grc-soc2-reporting-management-assertion-03bbd6a5.ee27a024e750ba4e.json"},"kind":"record","record":{"attributes":{"department":"compliance-legal","domain":"grc","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-soc2-reporting-management-assertion","description":"Reporting close for the Type II examination: drafting and validating the system description under the carve-out method, preparing the management assertion, reviewing complementary user entity controls and subservice reliance, and the dual-approval close of the examination file at the agreed period end. Management-owned SOC 2 Type II reporting support: system description, management assertion, CUECs, subservice reliance, and auditee file closure. The independent service auditor retains responsibility for examination conclusions and the CPA opinion. Attach this workflow to the existing SOC 2 evidence or reporting process item; retain evidence and conclusions on its workflow steps.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-soc2-reporting-management-assertion","capabilities":[],"controls":["UC-AUDIT-25","UC-GOV-21","UC-TPRM-04","UC-TPRM-08"],"domains":["grc"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:3674467114ba7d272775885cfbb2dc7591c579950a0bdad5f8e7d49a90cba04e","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-soc2-reporting-management-assertion","standards":["soc2"],"teams":["compliance-legal","executive"]},"id":"wf:D54","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AD54","slug":"grc-soc2-reporting-management-assertion","sourceIds":["cobit-2019","coso-erm","coso-ic","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"SOC 2 Reporting and Management Assertion","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c10648fc2d053fa77d405cc4d5dec3c727f2b7f0573a819a30fb3d69b6b6919","properties":{},"sourceDetailPath":"/data/v1/records/wf-d54-eba5e14e.json","sourceId":"wf:D54","targetDetailPath":"/data/v1/records/uc-uc-gov-21-8c5d79f9.json","targetId":"uc:UC-GOV-21","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aa06f45cc04e8657e99ec7ec38bd257206833472fd0984721ba3b07562dd4016","properties":{},"sourceDetailPath":"/data/v1/records/wf-d54-eba5e14e.json","sourceId":"wf:D54","targetDetailPath":"/data/v1/records/uc-uc-audit-25-e23c8618.json","targetId":"uc:UC-AUDIT-25","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be7be015b760fa1f75849f34d7565aeaa8520546de834ef74aa7b0c24e119b58","properties":{},"sourceDetailPath":"/data/v1/records/wf-d54-eba5e14e.json","sourceId":"wf:D54","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c180bf11c6883fb71e0998cf0a537c72b2bb6cc5f236fcc7a29c500f4c8a4fc1","properties":{},"sourceDetailPath":"/data/v1/records/wf-d54-eba5e14e.json","sourceId":"wf:D54","targetDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","targetId":"uc:UC-TPRM-08","type":"operates"}],"schemaVersion":1}
