{"description":"Design-readiness review of the SOC 2 processing integrity series: processing definitions and specifications, input controls, processing controls, output delivery, and storage integrity (PI1.1–PI1.5). Design-readiness assessment limited to the listed SOC 2 criteria. Evidence may include operating examples to assess the design; this module does not provide a SOC 2 Type II opinion. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.","edges":[],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":[],"configuration":["engagement_scope","applicable_criteria","review_period","responsible_roles","resource_reference_index"],"controlMappingQualification":"Links reflect the procedures and scoped criteria in this module; other requirements sharing a unified control remain outside its conclusion.","controlVerbs":{},"controls":["UC-FIN-06","UC-FIN-07","UC-FIN-08","UC-FIN-09","UC-FIN-10"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-processing-integrity-assessment","contentDigest":"sha256:57d4dce4e6d411751ff2482a79f9545f465586d447cab37498bd8d777237d19d","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:57d4dce4e6d411751ff2482a79f9545f465586d447cab37498bd8d777237d19d","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-soc2-processing-integrity-assessment"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"scope":"Design-readiness assessment limited to the listed SOC 2 criteria. Evidence may include operating examples to assess the design; this module does not provide a SOC 2 Type II opinion.","slug":"audit-soc2-processing-integrity-assessment","source":"coworkcanvas-gallery","standards":["soc2"],"teams":["internal-audit"]},"name":"SOC 2 Processing Integrity Assessment","nodes":[{"data":{"controls":["UC-FIN-07","UC-FIN-08","UC-FIN-10","UC-FIN-06","UC-FIN-09"],"description":"Evaluate PI1.1–PI1.5 specifications, inputs, processing, outputs and stored-data integrity and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.","instructions":"**Objective**\nEvaluate PI1.1–PI1.5 specifications, inputs, processing, outputs and stored-data integrity and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\n- The linked consolidated controls for input validation and reporting information quality\n- Data definitions and product specifications for the processing the platform performs\n- Input validation design: form validation, import checks, and API contract enforcement\n- Rejected-input handling records for the window\n\nThe linked consolidated controls for processing exceptions, output delivery, and stored-data safeguarding\n- Processing exception records: failed jobs, stuck workflows, and their resolution\n- Output surfaces: exports, notifications, and report generation with delivery checks\n- Storage integrity measures: transactional guarantees, backup verification, and audit-trail immutability\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Assess Processing Definitions & Input Controls”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Assess Processing Definitions & Input Controls: Assess PI1.1 and PI1.2: the entity obtains, generates, uses, and communicates quality information about processing objectives - including definitions of data processed and product specifications - and implements policies and procedures over system inputs for completeness and accuracy. Define the scoped processing flows and their inputs, outputs, approvals, and audit trails, including forms, imports, and APIs where applicable.\n\n2. Verify definitions of processed data exist and are communicated to users where they need them, so inputs arrive in the expected shape.\n3. Confirm the input surfaces validate completeness and accuracy: required fields, type checks, referential checks on imports, and API schema enforcement.\n4. Inspect how rejected or failed inputs are surfaced to the submitter and tracked to resolution rather than silently dropped.\n5. Check specification changes flow through the change process so validations and documentation stay aligned.\n6. Record a design conclusion per criterion and log gaps as candidate findings.\n\n7. Assessment scope for Evaluate Processing, Output & Stored-Item Integrity: Evaluate PI1.3, PI1.4, and PI1.5: policies and procedures govern system processing, outputs are delivered completely, accurately, and timely per specifications, and inputs, items in processing, and outputs are stored completely and accurately. In product terms: workflow state transitions execute as specified, exports and notifications deliver what the record shows, and stored data survives round-trips intact.\n\n8. Verify processing exceptions surface to an owner with resolution tracking, and that error handling fails safe rather than corrupting state.\n9. Sample exports or generated reports and reconcile them against the source records for completeness and accuracy.\n10. Confirm delivery timeliness expectations are defined and monitored for the output surfaces customers rely on.\n11. Check stored items are protected against loss and tampering: transactional writes, verified backups, and append-only audit history.\n12. Record a design conclusion per criterion and log gaps as candidate findings.\n\n**Record in AssureSwarm**\nAttach the specification extract and validation design evidence to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach exception samples, reconciliation results, and storage-integrity evidence to this step. Raise gaps as issues linked to the readiness audit and record the three conclusions; single sign-off closes the series.\n\n**Exit criteria**\nPI1.1 and PI1.2 each carry a documented design conclusion supported by attached evidence, and every input-control gap has a named owner and a target date. PI1.3, PI1.4, and PI1.5 each carry a documented design conclusion supported by attached evidence, and every processing-integrity gap has a named owner and a target date.","kind":"task","label":"Evaluate Processing, Output & Stored-Item Integrity","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]}},"id":"step-2"}],"sourceTemplateId":"workflow-library:audit-soc2-processing-integrity-assessment"}
