{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:8b3fcc0e9ec08f3b44dfc9cfbb44cf2d57ce6a0729c257e1de8142822e4212df","slug":"sox-deficiency-remediation","url":"/assets/agent_workflow-sox-deficiency-remediation-3ab06039.16ede68c3a8dfa7a.json"},"kind":"record","record":{"attributes":{"department":"finance","domain":"sox","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=sox-deficiency-remediation","description":"SOX Deficiency Remediation carries one control deficiency's full lifecycle — grade, root cause, remediation, validation, and closure. The workflow runs on the deficiency **Issue item** it opens at grading — `issue_type` set to the exact SOX grade (deficiency / significant_deficiency / material_weakness) and `severity` on the mapped AssureSwarm scale — linked to the affected Control(s), the source Control-hosted SOX testing workflow (template kind: sox-testing), and the current-year SOX audit (Audit, `audit_type: sox_testing`); the remediation actions and the validation retest live as steps on this Issue's own workflow. In scope: a single deficiency triggered by a failed test or unresolved exception. It **consumes** the concluded, reviewed failed-test workpaper handoff package owned upstream (SOX Key Control TOD/TOE Test and SOX ITGC Testing) and **hands off** the closed-or-carried deficiency outcome — with its intact severity history and any triggered communication obligations — to Quarterly Board & Audit-Committee GRC Reporting, which aggregates the full deficiency population into the period's ICFR conclusion and audit-committee materials. It exchanges handoff packages with those related workflows rather than duplicating their work.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=sox-deficiency-remediation","capabilities":[],"controls":["UC-RISK-14","UC-AUDIT-17"],"domains":["sox"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:8b3fcc0e9ec08f3b44dfc9cfbb44cf2d57ce6a0729c257e1de8142822e4212df","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:sox-deficiency-remediation","standards":["sox","coso-ic"],"teams":["finance"]},"id":"wf:S3","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AS3","slug":"sox-deficiency-remediation","sourceIds":["iia-2024","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"SOX Deficiency Remediation","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1d91d30656aa69c195e6359265a95d445cc7626eb4b45a349e69b6eab0da234c","properties":{},"sourceDetailPath":"/data/v1/records/wf-s3-0d4673bb.json","sourceId":"wf:S3","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:807d133d67b44710c9c60794b198d6f6060299b5fc2befcabd673a3263ce7197","properties":{},"sourceDetailPath":"/data/v1/records/wf-s3-0d4673bb.json","sourceId":"wf:S3","targetDetailPath":"/data/v1/records/uc-uc-risk-14-a5d6281b.json","targetId":"uc:UC-RISK-14","type":"oversees"}],"schemaVersion":1}
