{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:access-excess-privilege","risk:access-privilege-abuse-repudiation","risk:access-provisioning-review-gap","risk:access-unauthorized-use-equipment","risk:ai-emergent-integration-risk","risk:aware-no-acceptable-use-policy","risk:bcdr-it-resilience-outage","risk:bcdr-no-tested-continuity-plan","risk:config-poor-baseline-drift","risk:config-weak-change-control","risk:cyber-adversary-threat-sources","risk:fin-accuracy-measurement-errors","risk:fin-completeness-understatement","risk:fin-cutoff-period-errors","risk:fin-data-quality-reporting-integrity","risk:fin-existence-overstatement","risk:fin-financial-statement-fraud","risk:fin-icfr-material-weakness","risk:fin-journal-entry-management-override"],"directIds":["ctrl:sox:ELC-CA","ctrl:sox:ELC-CE","ctrl:sox:ELC-IC","ctrl:sox:ELC-MGMT-OVR","ctrl:sox:ELC-MON","ctrl:sox:ELC-PERFR","ctrl:sox:ELC-RA","ctrl:sox:ITGC-AC","ctrl:sox:ITGC-CM","ctrl:sox:ITGC-DEV","ctrl:sox:ITGC-OPS","ctrl:sox:PLC-AUTH","ctrl:sox:PLC-CALC","ctrl:sox:PLC-EXCEPTION","ctrl:sox:PLC-INPUT","ctrl:sox:PLC-INTF","ctrl:sox:PLC-IPE","ctrl:sox:PLC-MRC","ctrl:sox:PLC-PHYS","ctrl:sox:PLC-RECON","ctrl:sox:PLC-SOD"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"SOX / PCAOB (ICFR)","next":"/assets/agent_sources-sox-2.417d41a9221df573.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Control Activities (entity-level) — policies and procedures, period-end financial reporting process oversight, and entity-wide control activities including technology general controls policies.","details":{"automation":"manual","control_category":"administrative","control_id":"ELC-CA","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Risk Assessment & Management","Compliance, Audit & Assurance"],"framework":"sox","group":"Entity-Level Controls (COSO-aligned)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-elc-ca-3faabd89.html","id":"ctrl:sox:ELC-CA","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AELC-CA","sourceIds":["sox"],"sourceUrl":null,"title":"ELC-CA — Control Activities (entity-level) — policies and procedures, period-end financial reporting process oversight, and entity-wide control activities including technology general controls policies.","type":"control","url":"/assets/agent_record-ctrl-sox-elc-ca-3faabd89.b7a7e482e50996dc.json"},{"attributes":{"category":"administrative","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Control Environment — tone at the top, integrity and ethical values, code of conduct, board/audit committee oversight, organizational structure, assignment of authority and responsibility, commitment to competence, HR policies.","details":{"automation":"manual","control_category":"administrative","control_id":"ELC-CE","control_type":"preventive","domains":["Awareness & Training","Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Human Resources / Personnel Security"],"framework":"sox","group":"Entity-Level Controls (COSO-aligned)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-elc-ce-91bb92d0.html","id":"ctrl:sox:ELC-CE","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AELC-CE","sourceIds":["sox"],"sourceUrl":null,"title":"ELC-CE — Control Environment — tone at the top, integrity and ethical values, code of conduct, board/audit committee oversight, organizational structure, assignment of authority and responsibility, commitment to competence, HR policies.","type":"control","url":"/assets/agent_record-ctrl-sox-elc-ce-91bb92d0.6f5105526b774269.json"},{"attributes":{"category":"administrative","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Information & Communication — quality of financial reporting information, internal communication of control responsibilities, and external communication channels (including whistleblower/ethics hotline).","details":{"automation":"manual","control_category":"administrative","control_id":"ELC-IC","control_type":"preventive","domains":["Awareness & Training"],"framework":"sox","group":"Entity-Level Controls (COSO-aligned)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-elc-ic-7f185e29.html","id":"ctrl:sox:ELC-IC","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AELC-IC","sourceIds":["sox"],"sourceUrl":null,"title":"ELC-IC — Information & Communication — quality of financial reporting information, internal communication of control responsibilities, and external communication channels (including whistleblower/ethics hotline).","type":"control","url":"/assets/agent_record-ctrl-sox-elc-ic-7f185e29.23b223f547b6d178.json"},{"attributes":{"category":"administrative","framework":"sox","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Anti-fraud and management override controls — controls addressing the risk of management override of controls, including journal-entry review and review of significant estimates.","details":{"automation":"manual","control_category":"administrative","control_id":"ELC-MGMT-OVR","control_type":"detective","domains":["Risk Assessment & Management"],"framework":"sox","group":"Entity-Level Controls (COSO-aligned)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-elc-mgmt-ovr-cd342100.html","id":"ctrl:sox:ELC-MGMT-OVR","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AELC-MGMT-OVR","sourceIds":["sox"],"sourceUrl":null,"title":"ELC-MGMT-OVR — Anti-fraud and management override controls — controls addressing the risk of management override of controls, including journal-entry review and review of significant estimates.","type":"control","url":"/assets/agent_record-ctrl-sox-elc-mgmt-ovr-cd342100.f42c7079639dc4bf.json"},{"attributes":{"category":"administrative","framework":"sox","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Monitoring Activities — ongoing and separate evaluations (internal audit, management self-assessment, disclosure committee), and evaluation/communication of control deficiencies.","details":{"automation":"manual","control_category":"administrative","control_id":"ELC-MON","control_type":"detective","domains":["Compliance, Audit & Assurance"],"framework":"sox","group":"Entity-Level Controls (COSO-aligned)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-elc-mon-ad9d73ce.html","id":"ctrl:sox:ELC-MON","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AELC-MON","sourceIds":["sox"],"sourceUrl":null,"title":"ELC-MON — Monitoring Activities — ongoing and separate evaluations (internal audit, management self-assessment, disclosure committee), and evaluation/communication of control deficiencies.","type":"control","url":"/assets/agent_record-ctrl-sox-elc-mon-ad9d73ce.963bcde690bc28c7.json"},{"attributes":{"category":"administrative","framework":"sox","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Period-End Financial Reporting Process — controls over the close process, consolidation, journal entries, estimates, and preparation of financial statements and disclosures.","details":{"automation":"manual","control_category":"administrative","control_id":"ELC-PERFR","control_type":"detective","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Risk Assessment & Management","Compliance, Audit & Assurance"],"framework":"sox","group":"Entity-Level Controls (COSO-aligned)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-elc-perfr-3841aaac.html","id":"ctrl:sox:ELC-PERFR","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AELC-PERFR","sourceIds":["sox"],"sourceUrl":null,"title":"ELC-PERFR — Period-End Financial Reporting Process — controls over the close process, consolidation, journal entries, estimates, and preparation of financial statements and disclosures.","type":"control","url":"/assets/agent_record-ctrl-sox-elc-perfr-3841aaac.1d9561012f453b21.json"},{"attributes":{"category":"administrative","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Risk Assessment — entity objective-setting, identification and analysis of risks to financial reporting, fraud risk assessment, and assessment of changes affecting internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"ELC-RA","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"sox","group":"Entity-Level Controls (COSO-aligned)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-elc-ra-413d9faf.html","id":"ctrl:sox:ELC-RA","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AELC-RA","sourceIds":["sox"],"sourceUrl":null,"title":"ELC-RA — Risk Assessment — entity objective-setting, identification and analysis of risks to financial reporting, fraud risk assessment, and assessment of changes affecting internal control.","type":"control","url":"/assets/agent_record-ctrl-sox-elc-ra-413d9faf.3cb8f63c58e6be29.json"},{"attributes":{"category":"technical","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Access to programs and data — logical and physical access security: authentication, authorization, user provisioning/deprovisioning, periodic access recertification, privileged/administrative access, and segregation of duties enforced via access.","details":{"automation":"hybrid","control_category":"technical","control_id":"ITGC-AC","control_type":"preventive","domains":["Access Control & Identity Management","Financial Reporting Controls (SOX)","Human Resources / Personnel Security","Logging, Monitoring & Detection"],"framework":"sox","group":"IT General Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-itgc-ac-2b64f901.html","id":"ctrl:sox:ITGC-AC","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AITGC-AC","sourceIds":["sox"],"sourceUrl":null,"title":"ITGC-AC — Access to programs and data — logical and physical access security: authentication, authorization, user provisioning/deprovisioning, periodic access recertification, privileged/administrative access, and segregation of duties enforced via access.","type":"control","url":"/assets/agent_record-ctrl-sox-itgc-ac-2b64f901.7d67a91f89b7ab81.json"},{"attributes":{"category":"technical","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Program change management — changes to applications, databases, and infrastructure are requested, authorized, tested, approved, and migrated to production by appropriate personnel with segregation between development and production.","details":{"automation":"hybrid","control_category":"technical","control_id":"ITGC-CM","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Vulnerability & Patch Management"],"framework":"sox","group":"IT General Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-itgc-cm-5d415c42.html","id":"ctrl:sox:ITGC-CM","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AITGC-CM","sourceIds":["sox"],"sourceUrl":null,"title":"ITGC-CM — Program change management — changes to applications, databases, and infrastructure are requested, authorized, tested, approved, and migrated to production by appropriate personnel with segregation between development and production.","type":"control","url":"/assets/agent_record-ctrl-sox-itgc-cm-5d415c42.ff8d9dcb1873753f.json"},{"attributes":{"category":"technical","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Program development / SDLC — new systems and significant implementations are designed, developed, tested, approved, and converted/migrated in accordance with management's specifications.","details":{"automation":"hybrid","control_category":"technical","control_id":"ITGC-DEV","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Secure Development (SDLC) & Application Security"],"framework":"sox","group":"IT General Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-itgc-dev-b45239b7.html","id":"ctrl:sox:ITGC-DEV","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AITGC-DEV","sourceIds":["sox"],"sourceUrl":null,"title":"ITGC-DEV — Program development / SDLC — new systems and significant implementations are designed, developed, tested, approved, and converted/migrated in accordance with management's specifications.","type":"control","url":"/assets/agent_record-ctrl-sox-itgc-dev-b45239b7.8f7606610af9dd22.json"},{"attributes":{"category":"technical","framework":"sox","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Computer operations — job scheduling and batch processing, backup and recovery, incident/problem management, and monitoring of system processing and availability.","details":{"automation":"hybrid","control_category":"technical","control_id":"ITGC-OPS","control_type":"detective","domains":["Asset Management & Inventory","Business Continuity & Disaster Recovery","Cryptography & Key Management","Data Protection & Privacy","Financial Reporting Controls (SOX)","Incident Management & Response","Logging, Monitoring & Detection","Network & Communications Security","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Vulnerability & Patch Management"],"framework":"sox","group":"IT General Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-itgc-ops-68266a51.html","id":"ctrl:sox:ITGC-OPS","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3AITGC-OPS","sourceIds":["sox"],"sourceUrl":null,"title":"ITGC-OPS — Computer operations — job scheduling and batch processing, backup and recovery, incident/problem management, and monitoring of system processing and availability.","type":"control","url":"/assets/agent_record-ctrl-sox-itgc-ops-68266a51.f1607aaf0c2e0b81.json"},{"attributes":{"category":"administrative","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Authorization and approval — transactions, journal entries, and changes are reviewed and approved by authorized personnel in accordance with delegation-of-authority policies before being recorded or executed.","details":{"automation":"manual","control_category":"administrative","control_id":"PLC-AUTH","control_type":"preventive","domains":["Financial Reporting Controls (SOX)"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-auth-85c1f61f.html","id":"ctrl:sox:PLC-AUTH","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-AUTH","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-AUTH — Authorization and approval — transactions, journal entries, and changes are reviewed and approved by authorized personnel in accordance with delegation-of-authority policies before being recorded or executed.","type":"control","url":"/assets/agent_record-ctrl-sox-plc-auth-85c1f61f.be0f6264f8ad18bf.json"},{"attributes":{"category":"technical","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Automated processing / configurable controls — system-enforced calculations, three-way matches, tolerance checks, and configurable application controls operating as designed.","details":{"automation":"automated","control_category":"technical","control_id":"PLC-CALC","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Compliance, Audit & Assurance"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-calc-f1e136b6.html","id":"ctrl:sox:PLC-CALC","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-CALC","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-CALC — Automated processing / configurable controls — system-enforced calculations, three-way matches, tolerance checks, and configurable application controls operating as designed.","type":"control","url":"/assets/agent_record-ctrl-sox-plc-calc-f1e136b6.342b528adc7e2eb1.json"},{"attributes":{"category":"administrative","framework":"sox","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Exception and edit-report controls — review and timely resolution of system-generated exception, error, and edit reports.","details":{"automation":"hybrid","control_category":"administrative","control_id":"PLC-EXCEPTION","control_type":"detective","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Compliance, Audit & Assurance"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-exception-13d1131e.html","id":"ctrl:sox:PLC-EXCEPTION","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-EXCEPTION","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-EXCEPTION — Exception and edit-report controls — review and timely resolution of system-generated exception, error, and edit reports.","type":"control","url":"/assets/agent_record-ctrl-sox-plc-exception-13d1131e.fa180f284aa673dd.json"},{"attributes":{"category":"technical","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Input controls — edit/validation checks, completeness checks, and field/format controls that ensure data entered into systems is complete, accurate, and valid.","details":{"automation":"automated","control_category":"technical","control_id":"PLC-INPUT","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Compliance, Audit & Assurance"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-input-9cfe3c64.html","id":"ctrl:sox:PLC-INPUT","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-INPUT","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-INPUT — Input controls — edit/validation checks, completeness checks, and field/format controls that ensure data entered into systems is complete, accurate, and valid.","type":"control","url":"/assets/agent_record-ctrl-sox-plc-input-9cfe3c64.174ef9b3e259e928.json"},{"attributes":{"category":"technical","framework":"sox","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Interface controls — controls ensuring data transferred between systems and across interfaces is complete, accurate, and processed only once (reconciliation of record counts/control totals, error handling).","details":{"automation":"hybrid","control_category":"technical","control_id":"PLC-INTF","control_type":"detective","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Compliance, Audit & Assurance"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-intf-5eca8436.html","id":"ctrl:sox:PLC-INTF","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-INTF","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-INTF — Interface controls — controls ensuring data transferred between systems and across interfaces is complete, accurate, and processed only once (reconciliation of record counts/control totals, error handling).","type":"control","url":"/assets/agent_record-ctrl-sox-plc-intf-5eca8436.d3f713f1b31a93b2.json"},{"attributes":{"category":"administrative","framework":"sox","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Information Produced by the Entity (IPE) / completeness and accuracy — controls over the completeness and accuracy of system-generated reports, queries, and spreadsheets used in the operation of controls or in financial reporting.","details":{"automation":"manual","control_category":"administrative","control_id":"PLC-IPE","control_type":"detective","domains":["Financial Reporting Controls (SOX)"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-ipe-f81a8f21.html","id":"ctrl:sox:PLC-IPE","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-IPE","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-IPE — Information Produced by the Entity (IPE) / completeness and accuracy — controls over the completeness and accuracy of system-generated reports, queries, and spreadsheets used in the operation of controls or in financial reporting.","type":"control","url":"/assets/agent_record-ctrl-sox-plc-ipe-f81a8f21.ae15b9f2f3ab4189.json"},{"attributes":{"category":"administrative","framework":"sox","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Management review controls — reviews of financial information, account analyses, budget-to-actual variances, estimates, and reconciliations performed at an appropriate level of precision with documented investigation and resolution of items.","details":{"automation":"manual","control_category":"administrative","control_id":"PLC-MRC","control_type":"detective","domains":["Financial Reporting Controls (SOX)"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-mrc-14e10ed1.html","id":"ctrl:sox:PLC-MRC","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-MRC","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-MRC — Management review controls — reviews of financial information, account analyses, budget-to-actual variances, estimates, and reconciliations performed at an appropriate level of precision with documented investigation and resolution of items.","type":"control","url":"/assets/agent_record-ctrl-sox-plc-mrc-14e10ed1.9e3d5d11ae7b0e17.json"},{"attributes":{"category":"physical","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Physical safeguards / custody controls — controls over physical custody of assets, inventory counts, and safeguarding of negotiable instruments and records.","details":{"automation":"manual","control_category":"physical","control_id":"PLC-PHYS","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Compliance, Audit & Assurance"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-phys-1087f5d3.html","id":"ctrl:sox:PLC-PHYS","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-PHYS","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-PHYS — Physical safeguards / custody controls — controls over physical custody of assets, inventory counts, and safeguarding of negotiable instruments and records.","type":"control","url":"/assets/agent_record-ctrl-sox-plc-phys-1087f5d3.e36b15dcca769691.json"},{"attributes":{"category":"administrative","framework":"sox","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Reconciliations — account and subledger-to-general-ledger reconciliations performed completely and accurately, with timely review, approval, and resolution of reconciling items.","details":{"automation":"manual","control_category":"administrative","control_id":"PLC-RECON","control_type":"detective","domains":["Financial Reporting Controls (SOX)"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-recon-58a9d629.html","id":"ctrl:sox:PLC-RECON","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-RECON","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-RECON — Reconciliations — account and subledger-to-general-ledger reconciliations performed completely and accurately, with timely review, approval, and resolution of reconciling items.","type":"control","url":"/assets/agent_record-ctrl-sox-plc-recon-58a9d629.2f0bb76d347ece1d.json"},{"attributes":{"category":"administrative","framework":"sox","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/sox/","description":"Segregation of duties — incompatible duties (authorization, recording, custody, reconciliation) are divided among different people to reduce the risk of error or fraud.","details":{"automation":"manual","control_category":"administrative","control_id":"PLC-SOD","control_type":"preventive","domains":["Financial Reporting Controls (SOX)"],"framework":"sox","group":"Process-Level / Business-Process Controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-sox-plc-sod-4bef3b4c.html","id":"ctrl:sox:PLC-SOD","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asox%3APLC-SOD","sourceIds":["sox"],"sourceUrl":null,"title":"PLC-SOD — Segregation of duties — incompatible duties (authorization, recording, custody, reconciliation) are divided among different people to reduce the risk of error or fraud.","type":"control","url":"/assets/agent_record-ctrl-sox-plc-sod-4bef3b4c.66d1f5a120adcaac.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-excess-privilege","description":"Overly broad or wrongly assigned access rights, applications/services running with excessive privileges, and failure to enforce least privilege — a compromise or insider then gains broad access to systems and data.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"access-excess-privilege","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-excess-privilege-cd8adadc.html","id":"risk:access-excess-privilege","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-excess-privilege","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Excessive privilege and wrong assignment of access rights","type":"risk","url":"/assets/agent_record-risk-access-excess-privilege-cd8adadc.c154ceb8157b770a.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","description":"Authorized users or administrators exploit legitimate access beyond permitted scope, fabricate or forge credentials/rights to gain privileges, and repudiate performed actions — undermining accountability and audit-trail integrity.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"access-privilege-abuse-repudiation","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-privilege-abuse-repudiation-343a8917.html","id":"risk:access-privilege-abuse-repudiation","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Abuse of rights, forged rights, and repudiation of actions","type":"risk","url":"/assets/agent_record-risk-access-privilege-abuse-repudiation-343a8917.5dfe55c5d06b0530.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-provisioning-review-gap","description":"No formal user registration/de-registration procedure and no periodic access-rights review, so orphaned or excessive accounts accumulate and access is not revoked when roles change or personnel leave.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"access-provisioning-review-gap","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-provisioning-review-gap-dc152038.html","id":"risk:access-provisioning-review-gap","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-provisioning-review-gap","sourceIds":["iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Weak account provisioning/de-registration and access review","type":"risk","url":"/assets/agent_record-risk-access-provisioning-review-gap-dc152038.95f8a2aeb24acc6e.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","description":"Use of systems, networks, or devices without authorization, and users with authorized access reaching resources that exceed their authorization, potentially to exfiltrate data or conduct attacks.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"access-unauthorized-use-equipment","taxonomies":["iso-27005-threat","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-unauthorized-use-equipment-d2082944.html","id":"risk:access-unauthorized-use-equipment","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Unauthorized use of equipment and unauthorized access escalation","type":"risk","url":"/assets/agent_record-risk-access-unauthorized-use-equipment-d2082944.659ef798ce61ee67.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Secure Development (SDLC) & Application Security"],"inherent_rating":"medium","taxonomy":["iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-emergent-integration-risk","description":"Large-scale or multi-model pipelines exhibit emergent capabilities/failures not present in any component and not predictable from component testing; integration with legacy systems introduces interface mismatches and configuration errors.","details":{"category":"ai_governance","impact":"high","inherent_rating":"medium","likelihood":"medium","risk_id":"ai-emergent-integration-risk","taxonomies":["iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-emergent-integration-risk-8490271c.html","id":"risk:ai-emergent-integration-risk","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-emergent-integration-risk","sourceIds":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc1","soc2","sox"],"sourceUrl":null,"title":"Emergent behaviour and unsafe AI system integration","type":"risk","url":"/assets/agent_record-risk-ai-emergent-integration-risk-8490271c.7c427d5d71af8a3d.json"},{"attributes":{"category":"cyber_security","domain":["Awareness & Training","Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-no-acceptable-use-policy","description":"Because acceptable-use policies for email, messaging, and telecommunication services are absent, personnel use insecure channels without guidance, so sensitive information is inadvertently or deliberately disclosed through unsanctioned communications.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"aware-no-acceptable-use-policy","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-aware-no-acceptable-use-policy-e874ca5c.html","id":"risk:aware-no-acceptable-use-policy","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-no-acceptable-use-policy","sourceIds":["iso-27001","nist-800-53","nist-csf-2","nydfs-500","sox"],"sourceUrl":null,"title":"No acceptable-use policy for messaging and telecoms","type":"risk","url":"/assets/agent_record-risk-aware-no-acceptable-use-policy-e874ca5c.3ed302d2568a687a.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["coso-erm-risk","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-it-resilience-outage","description":"Critical technology infrastructure or applications experience unplanned outages, data loss, or prolonged recovery times — including failure of DR systems to activate — disrupting operations and harming stakeholders.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"bcdr-it-resilience-outage","taxonomies":["coso-erm-risk","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-bcdr-it-resilience-outage-18dfc108.html","id":"risk:bcdr-it-resilience-outage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-it-resilience-outage","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"IT resilience failure — unplanned outage, data loss, slow recovery","type":"risk","url":"/assets/agent_record-risk-bcdr-it-resilience-outage-18dfc108.676c731632e2a885.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-no-tested-continuity-plan","description":"No BCP/DR plan, or plans that exist but have never been exercised end-to-end, so a natural disaster, pandemic, civil unrest, or infrastructure failure disables critical processes with no tested recovery path.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"bcdr-no-tested-continuity-plan","taxonomies":["enterprise-risk","coso-erm-risk","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.html","id":"risk:bcdr-no-tested-continuity-plan","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-no-tested-continuity-plan","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Absent or untested business continuity / disaster recovery plan","type":"risk","url":"/assets/agent_record-risk-bcdr-no-tested-continuity-plan-d4d9e7a9.2e628816044d5241.json"},{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Vulnerability & Patch Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-poor-baseline-drift","description":"Without documented, enforced baseline configurations and change control, systems drift into insecure states, contain unauthorized changes, or expose unnecessary network services, expanding attack surface.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"config-poor-baseline-drift","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-config-poor-baseline-drift-2dd66324.html","id":"risk:config-poor-baseline-drift","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-poor-baseline-drift","sourceIds":["coso-ic","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Poor configuration management and insecure baseline drift","type":"risk","url":"/assets/agent_record-risk-config-poor-baseline-drift-2dd66324.de11f6b9169c61ac.json"},{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-weak-change-control","description":"Changes to systems, software, hardware, or configurations without formal approval and testing (including unauthorized or poorly tested hardware/config changes) introduce new vulnerabilities, instability, or failed releases.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"config-weak-change-control","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-config-weak-change-control-e7d90eaf.html","id":"risk:config-weak-change-control","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-weak-change-control","sourceIds":["cobit-2019","coso-ic","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Absent or weak change-control procedures","type":"risk","url":"/assets/agent_record-risk-config-weak-change-control-e7d90eaf.0118c76865b2782b.json"},{"attributes":{"category":"cyber_security","domain":["Risk Assessment & Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-source"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acyber-adversary-threat-sources","description":"Because capable, motivated threat actors - outsiders, privileged and non-privileged insiders, organized groups, competitors, malicious partners or suppliers, and nation-states - actively target the organization's cyber resources, deliberate attacks are attempted against its systems and data, resulting in compromise, disruption, or theft when defenses are outmatched.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"cyber-adversary-threat-sources","taxonomies":["nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-cyber-adversary-threat-sources-fa9e3003.html","id":"risk:cyber-adversary-threat-sources","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acyber-adversary-threat-sources","sourceIds":["aiuc-1","cobit-2019","coso-ic","gdpr","iso-27001","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Attacks by capable, motivated threat actors","type":"risk","url":"/assets/agent_record-risk-cyber-adversary-threat-sources-fa9e3003.8ace32770a775a42.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"medium","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-accuracy-measurement-errors","description":"Errors in revenue recognition amounts, cost of goods sold, depreciation/amortization, payroll calculations, fair-value measurement, journal-entry posting, tax provision, and foreign-currency translation misstating the financial statements.","details":{"category":"financial_reporting","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"fin-accuracy-measurement-errors","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-accuracy-measurement-errors-fd727255.html","id":"risk:fin-accuracy-measurement-errors","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-accuracy-measurement-errors","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Measurement and calculation errors (accuracy)","type":"risk","url":"/assets/agent_record-risk-fin-accuracy-measurement-errors-fd727255.4628396b1fcc6cf6.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-completeness-understatement","description":"Unrecorded payables (cut-off failure), accrued expenses, unrecorded revenue for delivered goods, off-balance-sheet obligations, uncaptured inventory write-downs, and understated payroll/tax liabilities — understating obligations and overstating income.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-completeness-understatement","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-completeness-understatement-4b9388d1.html","id":"risk:fin-completeness-understatement","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-completeness-understatement","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Understatement of liabilities/expenses (completeness)","type":"risk","url":"/assets/agent_record-risk-fin-completeness-understatement-4b9388d1.ae76e179265f879b.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"medium","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-cutoff-period-errors","description":"Revenue, vendor invoices, payroll, capital expenditure, treasury transactions, or tax provisions recorded in the wrong period — deliberately shifted to meet targets or erroneously mis-timed — distorting period results.","details":{"category":"financial_reporting","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"fin-cutoff-period-errors","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-cutoff-period-errors-180e8bcf.html","id":"risk:fin-cutoff-period-errors","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-cutoff-period-errors","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Period cut-off errors","type":"risk","url":"/assets/agent_record-risk-fin-cutoff-period-errors-180e8bcf.3601f2d8b43b607f.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-data-quality-reporting-integrity","description":"Poor data lineage, inconsistent master-data definitions, or uncontrolled data transformation (weak IPE completeness/accuracy) cause management decisions and regulatory reports to rest on inaccurate or incomplete data.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-data-quality-reporting-integrity","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-data-quality-reporting-integrity-276baaa6.html","id":"risk:fin-data-quality-reporting-integrity","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-data-quality-reporting-integrity","sourceIds":["cobit-2019","iso-27001","soc1","soc2","sox"],"sourceUrl":null,"title":"Data-quality and IPE integrity failures in reporting","type":"risk","url":"/assets/agent_record-risk-fin-data-quality-reporting-integrity-276baaa6.94785b86a662b514.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-existence-overstatement","description":"Revenue, receivables, inventory, capitalized assets, prepaid expenses, treasury investments, or tax assets recorded without underlying existence or occurrence — inflating the balance sheet and income statement.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-existence-overstatement","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-existence-overstatement-0e009631.html","id":"risk:fin-existence-overstatement","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-existence-overstatement","sourceIds":["cobit-2019","nist-800-53","soc1","soc2","sox"],"sourceUrl":null,"title":"Overstatement of assets/revenue (existence & occurrence)","type":"risk","url":"/assets/agent_record-risk-fin-existence-overstatement-0e009631.e106ea3635dc71b6.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-financial-statement-fraud","description":"Intentional misstatement through fictitious revenue, phantom inventory/assets, ghost-employee payroll, or management override of controls — inflating results and deceiving investors and regulators.","details":{"category":"financial_reporting","impact":"critical","inherent_rating":"high","likelihood":"low","risk_id":"fin-financial-statement-fraud","taxonomies":["sox-rmm-assertion","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-financial-statement-fraud-1dd35d5a.html","id":"risk:fin-financial-statement-fraud","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-financial-statement-fraud","sourceIds":["cobit-2019","coso-ic","iia-2024","iso-27001","nist-800-53","soc2","sox"],"sourceUrl":null,"title":"Financial-statement fraud and management override","type":"risk","url":"/assets/agent_record-risk-fin-financial-statement-fraud-1dd35d5a.0b3cf75ecebe244f.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"critical","taxonomy":["enterprise-risk","coso-erm-risk","sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-icfr-material-weakness","description":"Because internal control over financial reporting is not maintained effectively - material weaknesses undetected or undisclosed and certifications signed despite known deficiencies - financial statements may be materially misstated and filings delayed or restated, resulting in SEC enforcement, delisting, securities-fraud liability, and loss of investor confidence.","details":{"category":"financial_reporting","impact":"critical","inherent_rating":"critical","likelihood":"medium","risk_id":"fin-icfr-material-weakness","taxonomies":["enterprise-risk","coso-erm-risk","sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-icfr-material-weakness-cdd66323.html","id":"risk:fin-icfr-material-weakness","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-icfr-material-weakness","sourceIds":["cobit-2019","coso-erm","coso-ic","iia-2024","iso-27001","nis2","nist-800-53","nist-csf-2","soc2","sox"],"sourceUrl":null,"title":"Ineffective ICFR / undisclosed material weakness","type":"risk","url":"/assets/agent_record-risk-fin-icfr-material-weakness-cdd66323.c752785baa39846a.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-journal-entry-management-override","description":"Manual/automated journal entries posted with transposition errors, wrong account codes, or amounts; recurring entries not updated; and top-side entries used to override controls and manage earnings at period-end.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-journal-entry-management-override","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-journal-entry-management-override-b0c0ed68.html","id":"risk:fin-journal-entry-management-override","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-journal-entry-management-override","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Manual journal entries and management-override risk","type":"risk","url":"/assets/agent_record-risk-fin-journal-entry-management-override-b0c0ed68.9d5e8f3457283361.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:082ce7de28fdc456c8e68f7bf2b6f2f2af4a25425c80e8e87c82e9d347e259f9","properties":{"rationale":"Auto-disabling dormant accounts and prompt termination removal close the orphaned-account vector for unauthorized access.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:09382bcceec855e05ba63bae60745ad7ba04e455a53d7670e9ca079451bfd058","properties":{"rationale":"Input validation improves source-data quality feeding downstream reporting.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-06-ccd6f7dc.json","sourceId":"uc:UC-FIN-06","targetDetailPath":"/data/v1/records/risk-fin-data-quality-reporting-integrity-276baaa6.json","targetId":"risk:fin-data-quality-reporting-integrity","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0b12f962c7cc946d84a55d30bfc4421c097d291249fa8b3bfdfd1fc507fb4729","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-train-04-48d1a2b1.json","sourceId":"uc:UC-TRAIN-04","targetDetailPath":"/data/v1/records/risk-aware-no-acceptable-use-policy-e874ca5c.json","targetId":"risk:aware-no-acceptable-use-policy","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0f85c7f54d399fc6018fdd4f507fcd4dd899fc979a6b03137629b6643d782679","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-itgc-cm-5d415c42.json","sourceId":"ctrl:sox:ITGC-CM","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1448b5981f0f84eae0edf17bdeddb04df6bb1bab4d08fb48d84c2c8e23575315","properties":{"rationale":"Owner-approved provisioning with role-based entitlements and 1-business-day deprovisioning on termination directly eliminates orphaned accounts and un-revoked access.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-provisioning-review-gap-dc152038.json","targetId":"risk:access-provisioning-review-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1632e74bd02edd66cad05bb212cde9846176de3a7edf29cbca25141253cc0bd1","properties":{"rationale":"Reconciliation verifies accuracy of recorded balances against supporting detail.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-03-a90abe13.json","sourceId":"uc:UC-FIN-03","targetDetailPath":"/data/v1/records/risk-fin-accuracy-measurement-errors-fd727255.json","targetId":"risk:fin-accuracy-measurement-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:18b58ca85027d94d8496e3d1471222bdde9fa639d67644ff65a5c486f7960b56","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-phys-1087f5d3.json","sourceId":"ctrl:sox:PLC-PHYS","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a5f1f259980515eddc80f69e703a658b57433541647a1ff7f90b57f670714d7","properties":{"control_id":"ELC-PERFR","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-02-9127de7b.json","sourceId":"uc:UC-FIN-02","targetDetailPath":"/data/v1/records/ctrl-sox-elc-perfr-3841aaac.json","targetId":"ctrl:sox:ELC-PERFR","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a8ef53959bd64c17025de4be4c12ce726630dd619dcfc49af8a1f550d63cb29","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-ipe-f81a8f21.json","sourceId":"ctrl:sox:PLC-IPE","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b96f0765a2dfb4e5c76bdcb09eb295102be82d719a3b7bd233ebba82e04a84b","properties":{"control_id":"ELC-RA","coverage":"partial","delta":"objective-setting, fraud, and change aspects covered by dedicated unified controls","framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/ctrl-sox-elc-ra-413d9faf.json","targetId":"ctrl:sox:ELC-RA","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:21ad7cc38e9b6bf95acaa09c9adfc05dddf8e76f8d5db73ef0506aba33916062","properties":{"rationale":"Control-total/hash reconciliation catches data corruption altering amounts in transit.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-08-8e7468dd.json","sourceId":"uc:UC-FIN-08","targetDetailPath":"/data/v1/records/risk-fin-accuracy-measurement-errors-fd727255.json","targetId":"risk:fin-accuracy-measurement-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:269f3acba42579a6bc73c0dd88c43231111049eb12fa94cb7ac24dc8038a554c","properties":{"rationale":"Counts reconciled to records can surface unrecorded or missing assets.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-10-f87a53c1.json","sourceId":"uc:UC-FIN-10","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e73b4aa73b6fdc90e315da6690ced6a6609712d01299eeb106236c9d41049ad","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-sod-4bef3b4c.json","sourceId":"ctrl:sox:PLC-SOD","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:30d160b6febe5fe4c87f741657300759414cd0ee4d903d5cdbc207e56c0389a3","properties":{"control_id":"ITGC-AC","coverage":"partial","delta":"authentication, recertification, privileged access, segregation of duties, and physical access security satisfied by companion controls","framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/ctrl-sox-itgc-ac-2b64f901.json","targetId":"ctrl:sox:ITGC-AC","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:31ea77b7876a0049f03ed5af95891c225ceb782737684b01042355db3abb5d47","properties":{"rationale":"Periodic counts reconciled to records verify asset/inventory existence, catching overstatement.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-10-f87a53c1.json","sourceId":"uc:UC-FIN-10","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:324ccbae279d97d8a37c53405dd25eec8f98a302325ba1ed10eeba22baad7059","properties":{"rationale":"Input completeness checks ensure entered transactions are complete but cannot capture never-entered items like unrecorded payables; population completeness rests on reconciliations, interface totals, and three-way match.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-06-ccd6f7dc.json","sourceId":"uc:UC-FIN-06","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3939d5dee5215ede55fc2775d65265e2fc5e6c9a29250b8396a7b2272900ba88","properties":{"control_id":"PLC-PHYS","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-10-f87a53c1.json","sourceId":"uc:UC-FIN-10","targetDetailPath":"/data/v1/records/ctrl-sox-plc-phys-1087f5d3.json","targetId":"ctrl:sox:PLC-PHYS","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3a451515a0a5739efa3c20cd0bb1769f0ff38442f9cf0e1266455cfd1a5fa6b8","properties":{"rationale":"IPE completeness validation confirms reports capture all underlying records.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-09-05f62d2c.json","sourceId":"uc:UC-FIN-09","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3da62b4bb08a7c22e051089e91059598038a2e06565244f281c3643839af753c","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-intf-5eca8436.json","sourceId":"ctrl:sox:PLC-INTF","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3dc83163693fc5df12cfa9f8089d93cdf357122f4f06b3271e1dba5c8be3c6ab","properties":{"rationale":"Protecting stored records against loss/unauthorized alteration preserves data integrity and retention.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-10-f87a53c1.json","sourceId":"uc:UC-FIN-10","targetDetailPath":"/data/v1/records/risk-fin-data-quality-reporting-integrity-276baaa6.json","targetId":"risk:fin-data-quality-reporting-integrity","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3e7ccbb70e8989477cb9d31b58375e3c0af28c2c69935c5b5f128c50e17b8ced","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-exception-13d1131e.json","sourceId":"ctrl:sox:PLC-EXCEPTION","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:40602c949ab347d876ec0daac4bf4648a96f26b1e954b9e0c4418d7b6c413d25","properties":{"rationale":"Subledger-to-GL reconciliation enforces data consistency across systems.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-03-a90abe13.json","sourceId":"uc:UC-FIN-03","targetDetailPath":"/data/v1/records/risk-fin-data-quality-reporting-integrity-276baaa6.json","targetId":"risk:fin-data-quality-reporting-integrity","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:43f1567b5887d1fa8d9380a632faafe3d4edf31d1160d3b278bdd6e23944dc3c","properties":{"rationale":"Gating changes through authorization and impact analysis prevents unauthorized changes that cause drift, though baseline monitoring is the operative control.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-02-175d55b0.json","sourceId":"uc:UC-CONFIG-02","targetDetailPath":"/data/v1/records/risk-config-poor-baseline-drift-2dd66324.json","targetId":"risk:config-poor-baseline-drift","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:441f58b0c5473cca79133c40d6c7b615132e02469c56f7c2fad0b9857993e2a0","properties":{"control_id":"ELC-MON","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-21-6406caa4.json","sourceId":"uc:UC-AUDIT-21","targetDetailPath":"/data/v1/records/ctrl-sox-elc-mon-ad9d73ce.json","targetId":"ctrl:sox:ELC-MON","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:44d020fec45fd9e556c9f8bdb1cc1c2e0dbeace4d4dec22b3303ff1fe1182c3b","properties":{"rationale":"Monitoring that assesses control design/operating effectiveness and evaluates and communicates deficiencies (SOX ELC-MON, COSO P16) detects undetected ICFR weaknesses.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-21-6406caa4.json","sourceId":"uc:UC-AUDIT-21","targetDetailPath":"/data/v1/records/risk-fin-icfr-material-weakness-cdd66323.json","targetId":"risk:fin-icfr-material-weakness","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:47b9cf23fed9101fa9fe22188f873bf2c719d4e3fd1e59f5eadccd3644933184","properties":{"rationale":"This is the IPE control: validating source data, logic and totals of reports/spreadsheets before reliance.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-09-05f62d2c.json","sourceId":"uc:UC-FIN-09","targetDetailPath":"/data/v1/records/risk-fin-data-quality-reporting-integrity-276baaa6.json","targetId":"risk:fin-data-quality-reporting-integrity","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:48ef8eaf62abab1c557ac2b3bfaee8584bccae3849d633ef8c4bb4f7ac40715c","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-elc-mon-ad9d73ce.json","sourceId":"ctrl:sox:ELC-MON","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4aac43fcdf1236c87bd6db5409d48c01861b0e6e8514f7d69e770de2dcd1cd46","properties":{"rationale":"Subledger-to-GL reconciliation reveals unrecorded items and missing entries.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-03-a90abe13.json","sourceId":"uc:UC-FIN-03","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4dbaf2da2cbca31ff53a56655afe89fb9f89e1773ba80acd02261d82f5d17f77","properties":{"control_id":"ITGC-OPS","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-12-32fbbd73.json","sourceId":"uc:UC-ASSET-12","targetDetailPath":"/data/v1/records/ctrl-sox-itgc-ops-68266a51.json","targetId":"ctrl:sox:ITGC-OPS","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4ecd34db9d097564c7fb32f8cb286427a3dfa36e883c8d44cf608543775467d8","properties":{"rationale":"Deploying control activities via approved, owned, periodically-reviewed policies is a core structural defense of ICFR effectiveness.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/risk-fin-icfr-material-weakness-cdd66323.json","targetId":"risk:fin-icfr-material-weakness","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:51ad6eb18b35c3f0f1df1dcdd85ddef6ca37bd593855c436fa4399cb5295f231","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-itgc-ops-68266a51.json","sourceId":"ctrl:sox:ITGC-OPS","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5545b35b6fd0a270714ad640e985999d25ea9214313ea7571880695cbd52b78a","properties":{"rationale":"Interface reconciliation controls data-transfer integrity and lineage across systems.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-08-8e7468dd.json","sourceId":"uc:UC-FIN-08","targetDetailPath":"/data/v1/records/risk-fin-data-quality-reporting-integrity-276baaa6.json","targetId":"risk:fin-data-quality-reporting-integrity","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:563746acabae85520e2d7b371f07cccb9916908aa8ea80febb9566083e8e76e1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-input-9cfe3c64.json","sourceId":"ctrl:sox:PLC-INPUT","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:574c71c3d81d81c1c2234444fa051732d44ba4f1e9d6f9f9fb3f0849a1f28169","properties":{"control_id":"PLC-EXCEPTION","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-07-880ee951.json","sourceId":"uc:UC-FIN-07","targetDetailPath":"/data/v1/records/ctrl-sox-plc-exception-13d1131e.json","targetId":"ctrl:sox:PLC-EXCEPTION","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5974d4cd9e0f85803af4e83dc3f83aec26d099458a30e4b85d6e1aed72f56f51","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-recon-58a9d629.json","sourceId":"ctrl:sox:PLC-RECON","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ffb88ce652506ecf84fb88b264d0eb42d61ca1f72fd14d38745d836f4be9592","properties":{"rationale":"NYDFS 500.9 member and explicit cyber scope make the assessment periodically surface evolving cyber threats for treatment, enabling context not the operative defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:61c3659e40b022738d95781c0ab6ed22d5af66f49a40a068a8650d578c545ea9","properties":{"rationale":"Journal entries require authorized approval bound to the individual, controlling top-side override entries.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/risk-fin-journal-entry-management-override-b0c0ed68.json","targetId":"risk:fin-journal-entry-management-override","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64ea51facc02eefd0dbddc8d69cec6c321fd3df66cdc42f67cb99220261fb99c","properties":{"rationale":"Separating authorization/recording/custody/reconciliation stops one person perpetrating and concealing fraud or override.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-05-52738635.json","sourceId":"uc:UC-FIN-05","targetDetailPath":"/data/v1/records/risk-fin-financial-statement-fraud-1dd35d5a.json","targetId":"risk:fin-financial-statement-fraud","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:69a86660352c0428300d7c01318e4d8c9ad99e0d7dd07a7730813b40a5ff2c81","properties":{"rationale":"Reliable IPE underpins control operation; weak IPE is a common material-weakness root cause.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-09-05f62d2c.json","sourceId":"uc:UC-FIN-09","targetDetailPath":"/data/v1/records/risk-fin-icfr-material-weakness-cdd66323.json","targetId":"risk:fin-icfr-material-weakness","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:69aed65b14884c901ee3b2d59e7adee21605f4218b44330c80ad00d1873c3ce7","properties":{"rationale":"Separating recording from independent reconciliation ensures unrecorded liabilities/expenses are detected.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-05-52738635.json","sourceId":"uc:UC-FIN-05","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6aa5aaf3c70ecd866104c451499beb1ce461ef1c390996613f6f0bd53c186099","properties":{"control_id":"PLC-SOD","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-05-52738635.json","sourceId":"uc:UC-FIN-05","targetDetailPath":"/data/v1/records/ctrl-sox-plc-sod-4bef3b4c.json","targetId":"ctrl:sox:PLC-SOD","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6bf5cf187be38ee1a9647174d9f81144cce499353785b0a20070e9d238cd67e2","properties":{"control_id":"PLC-INPUT","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-06-ccd6f7dc.json","sourceId":"uc:UC-FIN-06","targetDetailPath":"/data/v1/records/ctrl-sox-plc-input-9cfe3c64.json","targetId":"ctrl:sox:PLC-INPUT","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:74a90d774e2c69425b083c4545a4c9227ee5937951e4236d687fccf4cad357d2","properties":{"rationale":"Approval per delegation-of-authority before recording prevents unauthorized/fictitious transactions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7602e9e128eb62424718cbc8cf526d493b7abc77813bba8f60dea1776af06cb4","properties":{"control_id":"ELC-CE","coverage":"partial","delta":"also spans board oversight, organizational structure, competence, and HR policy elements","framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-sox-elc-ce-91bb92d0.json","targetId":"ctrl:sox:ELC-CE","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:765227456a7ab6efabf21383ae9a1160c75f32d2fa13f7bb850f9cc75e9b27c2","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-elc-ic-7f185e29.json","sourceId":"ctrl:sox:ELC-IC","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7be0e231a3ad78e91d8b9ef46aa54df87aff784cc540febfe7812f13a0a32145","properties":{"rationale":"Budget-to-actual and period-over-period variance review surfaces unrecorded liabilities/expenses.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-02-9127de7b.json","sourceId":"uc:UC-FIN-02","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:82f09dc0d1998db16eb313a371bb57aa03bedb773f44fcac37980166b3ca25a3","properties":{"rationale":"Authorization plus tamper-evident, attributable approval trails deter and expose fraudulent entries and override.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/risk-fin-financial-statement-fraud-1dd35d5a.json","targetId":"risk:fin-financial-statement-fraud","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:83083cd0c8860f905e8ef04a7d61156318fcaf5e3807ba83754000b3e3bc2999","properties":{"rationale":"Input edit checks catch journal-entry transposition and wrong-account errors.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-06-ccd6f7dc.json","sourceId":"uc:UC-FIN-06","targetDetailPath":"/data/v1/records/risk-fin-journal-entry-management-override-b0c0ed68.json","targetId":"risk:fin-journal-entry-management-override","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:86e9d0ba4c2d71dcd122ddf867dccc7264fd408042503f03a45a19a142214ed9","properties":{"rationale":"Three-way match prevents recording purchases/payables without underlying receipt.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-07-880ee951.json","sourceId":"uc:UC-FIN-07","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8a92d659a5b5ae0f6f15cda4bc6d93f26e39a076f34c617931f2e8a22444146b","properties":{"control_id":"PLC-CALC","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-07-880ee951.json","sourceId":"uc:UC-FIN-07","targetDetailPath":"/data/v1/records/ctrl-sox-plc-calc-f1e136b6.json","targetId":"ctrl:sox:PLC-CALC","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8d09bed430ac28b30f60bb6ea9ccd37bf349e41772da11fc7e4f96ec98784afe","properties":{"rationale":"Analytical review of balances and reconciliations detects overstated or non-existent assets and revenue.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-02-9127de7b.json","sourceId":"uc:UC-FIN-02","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8f57527b3cce8428686cdd269d36bf4322357292c8f776e13325d0d55867c9fd","properties":{"rationale":"Reconciliation identifies recorded balances lacking support, catching overstatement.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-03-a90abe13.json","sourceId":"uc:UC-FIN-03","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:91f8b904816ac650ed850c2a24deae14d930a3542c56602d1b25d3e816f3de7c","properties":{"rationale":"Separating authorization from recording reduces unauthorized/fictitious entries inflating balances.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-05-52738635.json","sourceId":"uc:UC-FIN-05","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:971e4534c3033febf99472ef870f6943be2deeeb4f4e8cfa3196ec930ee1f523","properties":{"rationale":"verified backups plus periodic recovery tests and availability monitoring directly reduce data loss and slow recovery","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-12-32fbbd73.json","sourceId":"uc:UC-ASSET-12","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9a2dd113f43050cd25f72fd6dd5f4123ced3610ac943a4b9f8f3372301e66f51","properties":{"control_id":"ITGC-DEV","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/ctrl-sox-itgc-dev-b45239b7.json","targetId":"ctrl:sox:ITGC-DEV","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b1f4741ce2d6a0d316875fa449b489a075da04aced37ae5635d1d20824bf667","properties":{"rationale":"Policy-based control activities and period-end oversight raise the barrier to management override and fraud.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/risk-fin-financial-statement-fraud-1dd35d5a.json","targetId":"risk:fin-financial-statement-fraud","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9c5d51b3b12fe145f66e8e52f4fca2c356e187e231c0eaf665986fedd3066c7e","properties":{"rationale":"periodic recovery-capability testing exercises the restore path","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-12-32fbbd73.json","sourceId":"uc:UC-ASSET-12","targetDetailPath":"/data/v1/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.json","targetId":"risk:bcdr-no-tested-continuity-plan","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9ee77884cb417d7ca873c1da9e61a1e7501681b6b60ada17838b345b9b5ed71b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-itgc-ac-2b64f901.json","sourceId":"ctrl:sox:ITGC-AC","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9eed5d03f9c4036beec66a273d2a9bd532df159ea00be6cc7cb3f62989a99883","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-elc-mgmt-ovr-cd342100.json","sourceId":"ctrl:sox:ELC-MGMT-OVR","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a40476f4487da7de49d2d0686dd0e64b771a74626c4f5b046cd267cdfde82d79","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-elc-perfr-3841aaac.json","sourceId":"ctrl:sox:ELC-PERFR","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a5fa4d164b3098becc07c88536314926d852e5f5d6aa48d5b1ff7f762d6bd148","properties":{"control_id":"PLC-INTF","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-08-8e7468dd.json","sourceId":"uc:UC-FIN-08","targetDetailPath":"/data/v1/records/ctrl-sox-plc-intf-5eca8436.json","targetId":"ctrl:sox:PLC-INTF","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a7375c877a52d49ed615c130197e681ba77301ea4a5f496583dd499f996e262c","properties":{"control_id":"PLC-RECON","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-03-a90abe13.json","sourceId":"uc:UC-FIN-03","targetDetailPath":"/data/v1/records/ctrl-sox-plc-recon-58a9d629.json","targetId":"ctrl:sox:PLC-RECON","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a9955cbb71be92d1dccb2728b3240b6e12c801f1828db98df7faad84876278f2","properties":{"control_id":"ELC-CA","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/ctrl-sox-elc-ca-3faabd89.json","targetId":"ctrl:sox:ELC-CA","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a99f0290556f4481fa55872b021e247f553a2c3616269cb118deed745ec459bd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-elc-ra-413d9faf.json","sourceId":"ctrl:sox:ELC-RA","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad0b29143ccf0380ec4626d576bd9304f4f57f800f12549a87110c291370e89b","properties":{"rationale":"Edit/validation and format checks reject inaccurate input data at entry.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-06-ccd6f7dc.json","sourceId":"uc:UC-FIN-06","targetDetailPath":"/data/v1/records/risk-fin-accuracy-measurement-errors-fd727255.json","targetId":"risk:fin-accuracy-measurement-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:af12745220c783bc0f6e205c5c3af8e0c7c85b58780c0404fae059129efd34d9","properties":{"rationale":"Three-way match ensures liabilities are recorded for goods/services received.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-07-880ee951.json","sourceId":"uc:UC-FIN-07","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:affecc614a1b80fdb212b049f43344096e245c8ea10fa66c59900ef298f451e3","properties":{"control_id":"ELC-IC","coverage":"partial","delta":"quality financial-reporting information prong and general external communication only partially addressed","framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-train-04-48d1a2b1.json","sourceId":"uc:UC-TRAIN-04","targetDetailPath":"/data/v1/records/ctrl-sox-elc-ic-7f185e29.json","targetId":"ctrl:sox:ELC-IC","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b37c770c18f24eef3f1646bd2d33533966a017133c4090481de500edf5fb81e5","properties":{"control_id":"PLC-AUTH","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-04-70e42862.json","sourceId":"uc:UC-FIN-04","targetDetailPath":"/data/v1/records/ctrl-sox-plc-auth-85c1f61f.json","targetId":"ctrl:sox:PLC-AUTH","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9d622e2f67556f55261ae4f5e988085968ccaa506b795e041dec12b6e43453d","properties":{"rationale":"Physical counts detect phantom inventory/assets used in statement fraud.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-10-f87a53c1.json","sourceId":"uc:UC-FIN-10","targetDetailPath":"/data/v1/records/risk-fin-financial-statement-fraud-1dd35d5a.json","targetId":"risk:fin-financial-statement-fraud","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb3c0c01cf11882d5a870e0ede1674c11fa44eb00bcfd9799807377ef1d2c8c5","properties":{"rationale":"Record counts and control totals reconciled at each interface ensure no records are dropped.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-08-8e7468dd.json","sourceId":"uc:UC-FIN-08","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb55a8ec6c93eeaf8bf819b1e064274f43b1f998131d9b00a8d67e61b7f8b2ee","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-mrc-14e10ed1.json","sourceId":"ctrl:sox:PLC-MRC","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bc7fee09d5235e76437b44f81717b2b4cf31f6ef9114448f4a5b4bb6a617b765","properties":{"control_id":"ELC-MGMT-OVR","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","sourceId":"uc:UC-RISK-12","targetDetailPath":"/data/v1/records/ctrl-sox-elc-mgmt-ovr-cd342100.json","targetId":"ctrl:sox:ELC-MGMT-OVR","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bca9506a16c42dad9a6c1fe955d3c973f5c1b3ccd45b1901696f0d8da676c081","properties":{"rationale":"SDLC approval gates requiring significant changes be tested/approved before production contribute to change discipline, but the operative change controls are the dedicated UC-07 and UC-06 (approved-changes-only).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bfbd1a9c22b1272fbdca122b8af1101f63e71cd97cce8cc39cc7bbab05dbea0f","properties":{"rationale":"Timeliness checks on interfaces support transfer within the correct period.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-08-8e7468dd.json","sourceId":"uc:UC-FIN-08","targetDetailPath":"/data/v1/records/risk-fin-cutoff-period-errors-180e8bcf.json","targetId":"risk:fin-cutoff-period-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c77b4322fdc38c552b3e68398feff534b5a64c6646c4a679aad9a06416ac2951","properties":{"rationale":"Account analyses and variance review at a precision threshold detect measurement/calculation errors.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-02-9127de7b.json","sourceId":"uc:UC-FIN-02","targetDetailPath":"/data/v1/records/risk-fin-accuracy-measurement-errors-fd727255.json","targetId":"risk:fin-accuracy-measurement-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c8ac9622b839a0a9e42d8af5c2cd5c9e1da7215b575505fc89292bab280e6c4e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-auth-85c1f61f.json","sourceId":"ctrl:sox:PLC-AUTH","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cbb9ad216c0bc5f9603b90f5e0f2cd55a748c19f6e0479987436772df72c6ae9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-elc-ce-91bb92d0.json","sourceId":"ctrl:sox:ELC-CE","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cc570a08bee56416db49486987295b96f1962d38ac6568378306eff9d4021753","properties":{"control_id":"PLC-MRC","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-02-9127de7b.json","sourceId":"uc:UC-FIN-02","targetDetailPath":"/data/v1/records/ctrl-sox-plc-mrc-14e10ed1.json","targetId":"ctrl:sox:PLC-MRC","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dbd69f416d26e446904bf1dedc40fc4a4141e437cc1108fb248a7083359bbe78","properties":{"control_id":"ITGC-CM","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-config-02-175d55b0.json","sourceId":"uc:UC-CONFIG-02","targetDetailPath":"/data/v1/records/ctrl-sox-itgc-cm-5d415c42.json","targetId":"ctrl:sox:ITGC-CM","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dc838e86f734bf7681a330907bc22964e0d1e63151b76dc06208ca64d24788e7","properties":{"rationale":"Validating report logic, parameters and totals catches calculation errors in reports and spreadsheets.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-09-05f62d2c.json","sourceId":"uc:UC-FIN-09","targetDetailPath":"/data/v1/records/risk-fin-accuracy-measurement-errors-fd727255.json","targetId":"risk:fin-accuracy-measurement-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfc315612c713723a50c9d8914f9a7dbc9a9d82d7da7ce0cca39ac67d98d100a","properties":{"rationale":"Role-based, owner-approved provisioning and modify-on-role-change help limit wrong assignment and accumulation, but the operative least-privilege defense is role design (UC-03) and periodic access review (UC-02).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-excess-privilege-cd8adadc.json","targetId":"risk:access-excess-privilege","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e0dbfa652a28597344c5b673499f836c66223b83a9f624f49fda24d735377c11","properties":{"rationale":"Security/risk impact analysis and pre-production testing catch integration interface/config errors, though emergent AI behaviour is not caught by change testing.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-02-175d55b0.json","sourceId":"uc:UC-CONFIG-02","targetDetailPath":"/data/v1/records/risk-ai-emergent-integration-risk-8490271c.json","targetId":"risk:ai-emergent-integration-risk","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e0ee5e557a0991377906103899e94396546f81fd7b5857ebeb83ca4c5c77ffbb","properties":{"rationale":"'Processed only once' controls prevent duplicate records inflating balances.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-08-8e7468dd.json","sourceId":"uc:UC-FIN-08","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e1940764bc9d5430e791fd5bdc5fe8e7811e38f4fdf403b2b517a22560685e02","properties":{"rationale":"Close calendar and period-over-period variance review detect mis-timed transactions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-02-9127de7b.json","sourceId":"uc:UC-FIN-02","targetDetailPath":"/data/v1/records/risk-fin-cutoff-period-errors-180e8bcf.json","targetId":"risk:fin-cutoff-period-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e2633cba254803415201d2f7e9b6560bdf242ffe4527a0f12c47c463d159aae0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-itgc-dev-b45239b7.json","sourceId":"ctrl:sox:ITGC-DEV","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e4b4c6250652aace5a96a742cd709c7ec59cc96043c8a1c66e4709d2c494a165","properties":{"rationale":"Automated processing enforces recording in the proper period.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-07-880ee951.json","sourceId":"uc:UC-FIN-07","targetDetailPath":"/data/v1/records/risk-fin-cutoff-period-errors-180e8bcf.json","targetId":"risk:fin-cutoff-period-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e79d9f1085a08b2c0078623a74f182c38115a275ebe83946bc0562b90d697b66","properties":{"rationale":"The documented request->impact-analysis->authorize->test->approve->independent-migration process is the change-control defense itself.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-02-175d55b0.json","sourceId":"uc:UC-CONFIG-02","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb4584970a3d10a43b8e6b52a71626665c9a47c8f2baca3126259e6676457b3c","properties":{"rationale":"Independent testing of control operating effectiveness can detect management override and fraudulent transactions.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-21-6406caa4.json","sourceId":"uc:UC-AUDIT-21","targetDetailPath":"/data/v1/records/risk-fin-financial-statement-fraud-1dd35d5a.json","targetId":"risk:fin-financial-statement-fraud","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ee41b85adbf6ad46ccd8a408d90fdbf11db2418f0cb5130c9d07f83fee98e02c","properties":{"control_id":"PLC-IPE","coverage":"full","delta":null,"framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-09-05f62d2c.json","sourceId":"uc:UC-FIN-09","targetDetailPath":"/data/v1/records/ctrl-sox-plc-ipe-f81a8f21.json","targetId":"ctrl:sox:PLC-IPE","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f67ff06fb773d0f1089d4819b048691037c347f94ad9b19a46047afa3f3ca5fb","properties":{"rationale":"Accounts uniquely attributable to individuals plus logged provisioning/modification events underpin the accountability that counters repudiation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f77fa8167d1cf995061ce6ec70e394ada9e94f0aca96f4e7eaa0d802a1f40710","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-plc-calc-f1e136b6.json","sourceId":"ctrl:sox:PLC-CALC","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb70fe178fef2e0561814dddb63237a2c37ad2b72c7a339dc22ecbfdd15149ef","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-sox-elc-ca-3faabd89.json","sourceId":"ctrl:sox:ELC-CA","targetDetailPath":"/data/v1/records/std-sox-baeb68e1.json","targetId":"std:sox","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ffc6a927f610eb20e3d93d7bf9b40a620fda0036188911dad4b0e6df30947a13","properties":{"rationale":"System-enforced calculations produce accurate amounts (depreciation, payroll, tolerances).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-07-880ee951.json","sourceId":"uc:UC-FIN-07","targetDetailPath":"/data/v1/records/risk-fin-accuracy-measurement-errors-fd727255.json","targetId":"risk:fin-accuracy-measurement-errors","type":"mitigates"}],"schemaVersion":1,"scope":"sources","total":131}
