{"description":"Runs on the existing system item. Inventory the spreadsheets and end-user tools feeding reporting for a system, and test their access, change, and integrity controls. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-euc-controls-euc-closure","source":"euc-controls","target":"euc-closure"}],"isPublic":true,"itemTypeSlug":"system","metadata":{"capabilities":["euc-inventory-validation"],"controlVerbs":{"UC-ACCESS-20":"operates"},"controls":["UC-ACCESS-20"],"department":"it","domains":["controls"],"kind":"euc-inventory-validation","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:euc-inventory-validation"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-euc-validation","contentDigest":"sha256:7d6a110101d46d36ef6125f2bb1ed4f193f88c88ef5753f5275ab3560291b33c","prerequisites":{"anchorItemType":{"slug":"system"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-ipe-validation"}],"roles":[{"contribution":"expertise","description":"System owner and technical specialist. Test access, change and integrity controls.","id":"reviewer-1","nodeIds":["euc-controls"]},{"contribution":"approval","description":"Independent system-risk reviewer. Approve EUC validation record.","id":"reviewer-2","nodeIds":["euc-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:euc-inventory-validation"}],"releaseId":"sha256:7d6a110101d46d36ef6125f2bb1ed4f193f88c88ef5753f5275ab3560291b33c","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-system-euc-validation"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-system-euc-validation","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"End-User Computing Inventory & Validation","nodes":[{"data":{"instructions":"**Objective**\nTest access, change and integrity controls. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, process narratives and reporting data flows, the prior EUC inventory, file share and collaboration locations, report preparer interviews, and the EUC policy criteria.\n2. Use file and folder permissions, version history and change logs, formula audit or comparison tooling, input source reconciliation, review evidence by someone other than the preparer, and prior error history.\n\n**Procedure**\n1. Trace reporting outputs back to their inputs so undeclared spreadsheets are found rather than self-reported, rate criticality by reliance and complexity, and record locations searched that returned nothing.\n2. Inspect actual permissions rather than intended ones, compare current formulas against a known-good baseline where one exists, reconcile inputs to their source system, and confirm review was performed by someone other than the preparer.\n\n**Record in AssureSwarm**\n1. Capture the inventory period, EUC population with location and owner, criticality rating with reliance basis, tools newly identified since the prior inventory, search coverage, and known blind spots.\n2. Document permissions inspected per EUC, version and change traceability, formula integrity testing and its method, input reconciliation results, independent review evidence, and controls found absent.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is derived by tracing reporting inputs rather than by self-declaration, criticality reflects reliance, and search blind spots are declared rather than implied complete. Access is tested as configured rather than as intended, formula integrity is tested by comparison rather than inspection alone, and independent review is evidenced by identity.","kind":"task","label":"Test access, change and integrity controls","requiredApprovals":1},"id":"euc-controls"},{"data":{"controls":["UC-ACCESS-20"],"instructions":"**Objective**\nApprove EUC validation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the control testing results, the reliance placed on each output, error history and downstream impact, available platform alternatives, and the materiality of the balances or decisions affected.\n2. Review all stage records, the inventory derivation and blind spots, control evidence per EUC, reliance conclusions and their materiality basis, conditions with expiry, and remediation owners.\n\n**Procedure**\n1. Weigh control weaknesses against the materiality of the reliance rather than treating all EUCs alike, identify EUCs whose function belongs in a controlled system, and record conditions of reliance with expiry rather than open-ended acceptance.\n2. Trace each reliance conclusion to tested control evidence, verify conditions carry expiry dates, confirm blind spots and migration candidates carry owners, and return self-declared inventories with precise comments.\n\n**Record in AssureSwarm**\n1. Record the reliance conclusion per EUC, control weaknesses weighed against materiality, conditions of reliance with expiry, migration candidates, remediation with owners and dates, and outputs that should not be relied upon. Also record remediation detail.\n2. Capture the authorized reviewer, the summary, accepted reliance conclusions, effective inventory date, next inventory cadence, conditions and remediation with owners and dates, blind spots, and linked issues raised. Also record eUC validation summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that reliance is weighed against materiality, conditions carry expiry rather than being open-ended, and outputs judged unreliable are named rather than qualified into acceptance. The authorized reviewer accepts the record as evidence the EUC control operated, and closure implies no assurance over end-user tools the inventory did not reach.","kind":"task","label":"Approve EUC validation record","requiredApprovals":1},"id":"euc-closure"}],"sourceTemplateId":"workflow-library:controls-system-euc-validation"}
