{"description":"Runs on the existing control item. Assess whether a control is clearly specified and designed to address its stated risk before deciding what follow-up or testing is appropriate. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[],"isPublic":true,"itemTypeSlug":"control","metadata":{"capabilities":["control-design-assessment"],"controlVerbs":{"UC-AUDIT-13":"tests","UC-AUDIT-21":"tests"},"controls":["UC-AUDIT-13","UC-AUDIT-21"],"department":"internal-audit","domains":["audit"],"kind":"control-design-assessment","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:control-design-assessment"}],"canonicalUrl":"https://workflow-library.com/all/?w=audit-control-design-assessment","contentDigest":"sha256:19ed451f8831aa644571f5f565bd060230005406569c794b1ae5b463984f10c6","prerequisites":{"anchorItemType":{"slug":"control"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-design"}],"roles":[{"contribution":"approval","description":"Test supervisor independent of the operator. Approve design-assessment conclusion.","id":"reviewer-1","nodeIds":["design-conclusion"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:control-design-assessment"}],"releaseId":"sha256:19ed451f8831aa644571f5f565bd060230005406569c794b1ae5b463984f10c6","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-control-design-assessment"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"audit-control-design-assessment","source":"coworkcanvas-gallery","standards":["coso-ic","iia-2024","nist-800-53","sox"],"teams":["internal-audit"]},"name":"Control Design Assessment","nodes":[{"data":{"controls":["UC-AUDIT-13","UC-AUDIT-21"],"instructions":"**Objective**\nApprove design-assessment conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, linked risk and requirement records, owner, frequency, system dependencies, assertions, and current narrative or procedure.\n2. Use the approved risk statement, mapped compliance requirements, process objective, financial assertion where relevant, and the scoped control statement from intake.\n3. Consider performance criteria, thresholds, review precision, source-report reliability, segregation of duties, escalation rules, evidence retention, frequency, and the expected population.\n4. Use the approved scope, criterion-level assessment, linked evidence, owner responses, and all unresolved limitations or corrective actions.\n\n**Procedure**\n1. Reconcile the control title and description to the actual activity; identify who performs and reviews it, what population it covers, when it occurs, and which risk mechanism it is intended to interrupt.\n2. Trace each material risk cause and consequence to a specific preventive or detective feature; challenge vague monitoring language, unsupported mappings, and control objectives that merely restate the risk.\n3. Evaluate each design element against the risk and frequency; inspect how exceptions are identified and resolved, how reviewer challenge is shown, and how changes in systems or personnel affect execution.\n4. Confirm that the proposed conclusion matches the evidence, distinguish design observations from execution testing, and verify that gaps and dependencies are neither omitted nor described as tested operating results.\n\nAdditional canonical requirements reviewed with this package:\nDocument Control Objective and Risk Linkage: Identify the control objective, risk addressed, authoritative policy or process, and the consequence if the control does not operate.\nAssess Control Precision: Evaluate the trigger, population, threshold, criteria, performer competence, and review precision needed to prevent or detect the identified risk.\nAssess Evidence Design: Identify the evidence produced, source system, retention period, integrity attributes, and how an independent reviewer can reperform the control.\nConfirm Owner and Frequency: Confirm the accountable owner, operator, cadence, escalation path, and separation between preparation and review are explicit and current.\nRecord Design Conclusion: Record whether the design is adequate, each gap or compensating control, and the owner and due date for required remediation.\n\n**Record in AssureSwarm**\n1. Document the in-scope control statement, assessment period, stakeholders, dependencies, and any boundary exclusions that could change the conclusion. Also record scope notes.\n2. Capture the alignment result by risk or requirement, the rationale for each mapping, gaps in coverage, and any redundant or compensating activity considered. Also record risk-response alignment.\n3. Record criterion-level observations, supporting examples, information-produced-by-entity dependencies, identified design gaps, and the basis for the provisional design result.\n4. State the conclusion, rationale, scope limitations, design improvements, owners, and target dates; link any resulting Issue or remediation record rather than burying it in narrative. Also record design assessment conclusion; follow-up actions.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The control and risk boundary are unambiguous, the accountable participants are identified, and missing source material is either obtained or logged for follow-up. Every claimed risk response is supported by a concrete control feature and any uncovered exposure is described precisely enough to assign corrective action. The design result follows from documented criteria, material gaps are separated from editorial improvements, and necessary corrective actions have accountable owners. The authorized reviewer can trace the conclusion to the recorded criteria, limitations are explicit, and all follow-up work is assigned without implying effectiveness from workflow completion.","kind":"task","label":"Approve design-assessment conclusion","requiredApprovals":1},"id":"design-conclusion"}],"sourceTemplateId":"workflow-library:audit-control-design-assessment"}
