{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:daf2307624b2d1e52a35c50bcb6da717b62f88d54bb41beff571bb9a29757587","slug":"sox-fraud-risk-assessment-anti-override-control-review","url":"/assets/agent_workflow-sox-fraud-risk-assessment-anti-override-control-review-63384be6.7f431c01814395d7.json"},"kind":"record","record":{"attributes":{"department":"finance","domain":"sox","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=sox-fraud-risk-assessment-anti-override-control-review","description":"Runs on an Audit item created for the cycle (audit_type internal or sox_testing; scope = \"Annual fraud risk assessment & anti-override review FYxx\"; period_start/period_end = the assessed period). The workflow instance attaches to that Audit, which is the cycle's durable record - a fresh Audit per cycle keeps successive years separable; the workflow enriches it, it does not create a duplicate. Covers the fraud triangle across fraudulent reporting, asset misappropriation, and corruption, the explicit assessment of management override risk, anti-override control recalibration (journal-entry review criteria and significant-estimates scrutiny), and audit committee reporting. Consumes upstream: the prior-period fraud risk register (Risk items, category financial_reporting, with their inherent_rating/residual_rating/treatment and dispositions) as the baseline; the SOX-scoped Process population; in-period Issue signals (deficiencies, findings); and the existing Control inventory - specifically the journal-entry-review and significant-estimates-challenge Control items whose description/frequency/control_owner hold the current criteria. In scope: the current SOX-scoped entity and process population, judged against the prior-period baseline; an event-triggered refresh scopes to the affected entities and fraud vectors, not automatically the whole map. No upstream workflow feeds this cycle - it originates from the prior-period assessment and interim events since. Named deliverable: the fraud risk assessment report and the audit committee package (fraud risk register, heat map, the explicit management-override determination, and the recalibrated anti-override control specification). Hands off to the journal-entry-review and significant-estimates control operators, who run the recalibrated anti-override controls; accepted residual risks persist as Risk items (treatment accept) that seed the next annual cycle's baseline.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=sox-fraud-risk-assessment-anti-override-control-review","capabilities":[],"controls":["UC-RISK-12"],"domains":["sox"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:daf2307624b2d1e52a35c50bcb6da717b62f88d54bb41beff571bb9a29757587","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:sox-fraud-risk-assessment-anti-override-control-review","standards":["sox","coso-ic","soc2"],"teams":["finance","executive"]},"id":"wf:S10","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AS10","slug":"sox-fraud-risk-assessment-anti-override-control-review","sourceIds":["coso-ic","soc2","sox"],"sourceUrl":null,"title":"Fraud Risk Assessment & Anti-Override Control Review","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c7cf1c0bf23d8d13177655b0fbe3a61a49f27bd89e1ea10b86c89d71117aa063","properties":{},"sourceDetailPath":"/data/v1/records/wf-s10-d9231db2.json","sourceId":"wf:S10","targetDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","targetId":"uc:UC-RISK-12","type":"operates"}],"schemaVersion":1}
