{"description":"Runs on the existing control item. Walk one representative transaction or event through the control to understand actual execution, evidence, handoffs, and changes. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[],"isPublic":true,"itemTypeSlug":"control","metadata":{"capabilities":["control-walkthrough"],"controlVerbs":{"UC-AUDIT-13":"tests","UC-AUDIT-21":"tests"},"controls":["UC-AUDIT-13","UC-AUDIT-21"],"department":"internal-audit","domains":["audit"],"kind":"control-walkthrough","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:control-walkthrough"}],"canonicalUrl":"https://workflow-library.com/all/?w=audit-control-walkthrough","contentDigest":"sha256:aad79d3a209a28e35932add90167fe72340b4e937a9b43d97d71a986d998cd4f","prerequisites":{"anchorItemType":{"slug":"control"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-walkthrough"}],"roles":[{"contribution":"approval","description":"Test supervisor independent of the operator. Approve walkthrough conclusion.","id":"reviewer-1","nodeIds":["walkthrough-conclusion"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:control-walkthrough"}],"releaseId":"sha256:aad79d3a209a28e35932add90167fe72340b4e937a9b43d97d71a986d998cd4f","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-control-walkthrough"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"audit-control-walkthrough","source":"coworkcanvas-gallery","standards":["coso-ic","iia-2024","nist-800-53","sox"],"teams":["internal-audit"]},"name":"Control Walkthrough","nodes":[{"data":{"controls":["UC-AUDIT-13","UC-AUDIT-21"],"instructions":"**Objective**\nApprove walkthrough conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current control description, process narrative, system flow, prior walkthrough, open changes, linked risks, and the population from which an occurrence can be selected.\n2. Use the selected occurrence, control procedure, role assignments, screen or report access, expected evidence, and the preparer questions derived during planning.\n3. Use source documents, system timestamps, report parameters, approvals, exception logs, downstream records, and the execution sequence established through inquiry.\n4. Review the plan, inquiry notes, complete evidence trace, deviations, owner explanations, system changes, and any open documentation questions.\n\n**Procedure**\n1. Select a recent representative occurrence without allowing the owner to substitute a polished example; schedule the preparer, performer, reviewer, and system contacts needed to explain each handoff.\n2. Ask the performer to demonstrate the activity in sequence, explain decision points and exceptions, identify reports and parameters used, and show how reviewer challenge differs from routine preparation.\n3. Agree identifiers and amounts across each handoff, inspect the timing and authority of approvals, reproduce key report filters where feasible, and investigate missing links or post-dated evidence.\n4. Reconcile observed practice to the control and process narratives, assess whether deviations require documentation or design changes, and separate walkthrough observations from any later population-based testing conclusion.\n\nAdditional canonical requirements reviewed with this package:\nSelect a Real Control Occurrence: Select a representative occurrence and document the date, population context, operator, and source records used for the walkthrough.\nInterview the Control Operator: Interview the operator about trigger, decision points, exceptions, tools, handoffs, and evidence retention; capture any practice variation.\nTrace Inputs, Actions and Outputs: Trace the occurrence from complete inputs through performed actions and resulting output, checking that each documented control activity occurred.\nInspect Retained Evidence: Inspect retained evidence for completeness, integrity, timing, and retrievability; link the source records sufficient for reperformance.\nRecord Practice-versus-Documentation Conclusion: Record whether observed practice matches the approved procedure, list deviations, and route material gaps to exception remediation.\n\n**Record in AssureSwarm**\n1. Record the occurrence identifier, date, participants, systems, planned route, known changes, and any confidentiality or access constraints affecting evidence capture. Also record walkthrough date.\n2. Capture who performed each action, what was observed, the systems and reports used, key judgments, deviations from the documented design, and evidence references for the occurrence. Also record inquiry and observation summary.\n3. Map the evidence chain, note agreements and deviations at each point, identify system-generated dependencies, and record whether the occurrence is representative of normal execution. Also record trace result.\n4. Document the conclusion, changes required, evidence limitations, responsible owners, target dates, and links to any issue, design assessment, or planned test prompted by the walkthrough. Also record changes and follow-up.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: A traceable occurrence and knowledgeable participants are confirmed, the route covers initiation through evidence retention, and known changes are in scope. The actual execution sequence and reviewer involvement are understood, unsupported explanations are flagged, and each key claim has observable or documentary support. The occurrence is traceable end to end or the precise break is documented, observed deviations are supported, and the trace result is ready for independent review. The authorized reviewer can follow the occurrence and rationale, documentation changes are assigned, and the record does not overstate what a single walkthrough demonstrates.","kind":"task","label":"Approve walkthrough conclusion","requiredApprovals":1},"id":"walkthrough-conclusion"}],"sourceTemplateId":"workflow-library:audit-control-walkthrough"}
