{"description":"Runs on the existing audit item. Plan the annual SOX program through materiality, entity and account scoping, risk and control mapping, reliance strategy, calendar, and governance approval. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-sox-scope-risk-sox-planning-closure","source":"sox-scope-risk","target":"sox-planning-closure"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":["sox-annual-planning"],"controlVerbs":{"UC-AUDIT-12":"operates"},"controls":["UC-AUDIT-12"],"department":"finance","domains":["sox"],"framework":"sox","kind":"sox-annual-planning","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:sox-annual-planning"}],"canonicalUrl":"https://workflow-library.com/all/?w=sox-annual-program-planning","contentDigest":"sha256:b75bd14e0152fe649923987ad463dcbb0ac52c7904f707221db82b724a0b7c21","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-annual-icfr-scoping-risk-assessment"}],"roles":[{"contribution":"expertise","description":"Engagement lead. Assess ICFR scope and risks.","id":"reviewer-1","nodeIds":["sox-scope-risk"]},{"contribution":"approval","description":"Independent audit supervisor. Approve annual SOX plan.","id":"reviewer-2","nodeIds":["sox-planning-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:sox-annual-planning"}],"releaseId":"sha256:b75bd14e0152fe649923987ad463dcbb0ac52c7904f707221db82b724a0b7c21","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-annual-program-planning"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"sox-annual-program-planning","source":"coworkcanvas-gallery","standards":[],"teams":["finance"]},"name":"SOX Annual Planning & Risk Assessment","nodes":[{"data":{"instructions":"**Objective**\nAssess ICFR scope and risks. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review financial plans and statements, approved materiality, legal entities, locations, acquisitions and divestitures, systems, service organizations, prior scope, deficiencies, auditor strategy, and regulatory deadlines.\n2. Use reconciled financial data, FSLI significance assessments, quantitative coverage, qualitative factors, transaction classes, risk assessments, entity-level controls, IT landscape, prior errors, and deficiencies.\n\n**Procedure**\n1. Reconcile entity and reporting data, validate planning thresholds and ownership, identify significant changes, set the annual calendar and decision rights, and define how scope or risk changes will be approved.\n2. Calculate coverage, evaluate qualitative significance and aggregation, identify relevant assertions and reasonable misstatement risks, map processes and systems, consider fraud and management override, and explain all inclusions and exclusions.\n\n**Record in AssureSwarm**\n1. Capture fiscal year, reporting perimeter, materiality reference and thresholds, governance roles, methodology, milestones, changes, dependencies, assumptions, data limitations, and responsible owners.\n2. Document calculations, scoped entities, locations, FSLIs, disclosures, assertions, processes, systems, fraud risks, qualitative judgments, exclusions, coverage gaps, and reassessment triggers. Also record scope analysis reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The planning basis agrees to authoritative reporting information, roles and thresholds are approved inputs, and known changes or limitations are visible for scoping analysis. The proposed scope is reproducible and risk-based, material relationships and exclusions are explicit, and unresolved data or mapping gaps are assigned before program design.","kind":"task","label":"Assess ICFR scope and risks","requiredApprovals":1},"id":"sox-scope-risk"},{"data":{"controls":["UC-AUDIT-12"],"instructions":"**Objective**\nApprove annual SOX plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use proposed scope, risk-control matrices, control frequency and ownership, prior testing, deficiencies, internal audit and external auditor plans, service-auditor reports, resources, specialists, and reporting dates.\n2. Review materiality, scope calculations, risk assessments, program design, staffing, calendar, external auditor feedback, governance comments, limitations, and open data or mapping actions.\n\n**Procedure**\n1. Set testing timing and extent, allocate controls and locations, define roll-forward and year-end work, coordinate reliance and PBC needs, assign reviewers, plan deficiency escalation, and test feasibility against deadlines and capacity.\n2. Challenge risk-to-coverage alignment, confirm key changes and exclusions are addressed, reconcile populations and milestones, verify ownership and escalation, and return unsupported scope or reliance assumptions for correction.\n\n**Record in AssureSwarm**\n1. Capture the control universe, coverage plan, timing, reliance assumptions, owners, resources, milestones, quality reviews, committee calendar, auditor coordination, decision, and required revisions. Also record program decision.\n2. Document the authorized reviewer, final scope and coverage references, methodology, program calendar, resources, reliance, limitations, open actions, owners, due dates, and reassessment triggers. Also record annual SOX plan summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts a feasible program responsive to scoped risks, reliance and exclusions are supportable, and unresolved capacity or coverage gaps have explicit escalation. The authorized reviewer accepts the annual management plan and authorize its documented work; planning closure is not a management assertion, audit opinion, or operating-effectiveness conclusion.","kind":"task","label":"Approve annual SOX plan","requiredApprovals":1},"id":"sox-planning-closure"}],"sourceTemplateId":"workflow-library:sox-annual-program-planning"}
