{"description":"Runs on an existing SOX-applicable Control under a sox-testing template. SAMPLE reviews history, attributes and reproducible selection; TEST reviews evidence, exceptions and the approved result artifact. Keep fiscal year on Workflow.customFields.sox.fiscalYear and hand the published result to the SOX program.","edges":[{"id":"e-sample-test","source":"sample","target":"test"}],"isPublic":true,"itemTypeSlug":"control","metadata":{"capabilities":["sox-control-testing","audit-testing"],"controlVerbs":{"UC-AUDIT-21":"tests"},"controls":["UC-AUDIT-21"],"department":"internal-audit","domains":["sox"],"framework":"sox","kind":"sox-testing","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:sox-control-testing"}],"canonicalUrl":"https://workflow-library.com/all/?w=sox-control-testing-publication","contentDigest":"sha256:6a9a2b6740664366edac822192a3264e04a764e662b3a0277aba2229cc0360af","prerequisites":{"anchorItemType":{"slug":"control"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-key-control-tod-toe-test"}],"roles":[{"contribution":"approval","description":"Test supervisor independent of the operator. SAMPLE.","id":"reviewer-1","nodeIds":["sample"]},{"contribution":"approval","description":"Independent audit reviewer. Approve SOX testing record.","id":"reviewer-2","nodeIds":["test"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:sox-control-testing"}],"releaseId":"sha256:6a9a2b6740664366edac822192a3264e04a764e662b3a0277aba2229cc0360af","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-control-testing-publication"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"sox-control-testing-publication","source":"coworkcanvas-gallery","standards":[],"teams":["internal-audit"]},"name":"SOX Control Testing","nodes":[{"data":{"instructions":"**Objective**\nSAMPLE. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, SOX applicability, walkthrough and design work, risk and FSLI mappings, control frequency and the approved test plan, with prior approved workpapers, previous exceptions and remediation, change assessments and program reliance guidance.\n2. Review the approved control design, risk and assertion mapping, walkthrough, policy or procedure, reviewer precision, thresholds, system dependencies, the approved history and reliance decision, and prior attribute definitions.\n3. Use the native population extract, report parameters, control frequency, expected occurrence count, the approved attribute plan and its population applicability, sampling guidance, prior-period considerations, and approved targeted strata.\n\n**Procedure**\n1. Verify the control was in scope for the period, reconcile its description to program documentation, identify design or ownership changes and define reliance boundaries. Then confirm prior work relates to the same control and attributes, compare performers, systems, frequency and evidence, identify recurring conditions, and document whether history informs expectations or qualifies for approved reliance.\n2. Translate each essential control feature into an observable pass/fail criterion, define not-applicable handling, specify expected evidence and timing, and distinguish design, performance, and review attributes.\n3. Validate completeness and accuracy, reconcile counts and date coverage, preserve the original population, execute the approved random, systematic, targeted, or full-population selection, and document replacements.\n\n**Record in AssureSwarm**\n1. Document the fiscal period, scope, control version, assertions, preparer and reviewer roles, known changes and limitations; attach or link the prior workpaper and record its period, conclusion, exceptions, remediation status, the reliance decision and the procedure it affects. Also record testing scope summary; history and reliance assessment.\n2. List each numbered attribute, its expected value or evidence, population applicability, source, failure condition, and approved treatment for missing or conflicting support. Also record attribute plan.\n3. Record the period and test kind in the native sample result, attach the frozen population and sample listing, and record extraction logic, reconciliation, sample size, selection method, seed or interval, and substitutions. Also record test of design; test of operating effectiveness.\nStep.result is markdown. Include exactly one versioned JSON block with the actual period and kind (tod or toe):\n```json\n{\"soxSample\":{\"schemaVersion\":1,\"period\":\"2026-Q2\",\"kind\":\"toe\"}}\n```\nReplace the example period for this run. Keep fiscal year in Workflow.customFields.sox.fiscalYear.\n\nRecord `period` (Testing period) in Step.result fenced json soxSample.period.\n\nRecord `kind` (Test kind; values: tod, toe) in Step.result fenced json soxSample.kind.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The test objective and period are unambiguous under an approved scope, history is considered without replacing current-period evidence, recurring matters are carried forward visibly, any reliance is approved, bounded and supported, and its effect on attribute scope and sample extent is stated. Attributes cover the relevant control features without ambiguity, can be applied consistently by another tester, and changes after testing starts require documented approval and rework assessment. The population is suitable, every selected item traces to it, the method can be reproduced, and the sample covers the period and risk characteristics required by the plan.","kind":"task","label":"SAMPLE","requiredApprovals":1},"id":"sample"},{"data":{"controls":["UC-AUDIT-21"],"instructions":"**Objective**\nApprove SOX testing record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved sample and attributes, original source documents, system records, report outputs, approvals, reviewer annotations, population support, and authorized owner responses.\n2. Use the frozen sample, approved attribute plan, indexed evidence, relevant history, control and risk context, exception criteria, owner responses, and required result schema.\n3. Review the scope, population and sample, attributes, evidence index, history assessment, workpaper, results artifact, proposed conclusion, exceptions, limitations, and linked follow-up records.\n\n**Procedure**\n1. Obtain evidence for each sample and attribute, verify dates and identifiers, retain native or authoritative formats where practical, name files consistently, and flag missing, altered, late, or owner-created-after-selection support.\n2. Test every item and attribute, retain per-cell results and support, distinguish control exceptions from documentation issues, investigate contradictory evidence, reconcile counts, and route confirmed exceptions for evaluation.\n3. Trace selected results to evidence, recalculate counts, challenge contrary evidence and scope limitations, verify published-result compatibility, and return incomplete or inconsistent work with specific review notes.\n\n**Record in AssureSwarm**\n1. Attach evidence to this CAPS stage, maintain a sample-to-file index, record source and receipt date, identify confidentiality restrictions, and cross-reference evidence that legitimately supports multiple attributes. Also record evidence index and gaps.\n2. Upload the annotated workpaper and required results artifact, record the conclusion, exception count and workpaper reference in the markdown step result, and link exception or remediation records without hiding limitations. Also record operating Effectively; exceptions Noted; not Operating Effectively; exceptions count.\n3. Document reviewer comments and resolutions, the approved or returned status, the authorized reviewer, date, remaining limitations, exception handoffs, and the exact workpaper and results references reviewed. Also record final review summary.\nRetain conclusion, exceptions_count and workpaper_reference in the markdown step result. Publish the supported SOX results JSON document and annotated workpaper on TEST using the existing publication schema. Native approval and validated result documents drive publication; narrative alone is not publication.\n\nRecord `conclusion` (Testing conclusion; values: operating_effectively, exceptions_noted, not_operating_effectively) in Step.result markdown.\n\nRecord `exceptions_count` (Exceptions) in Step.result markdown.\n\nRecord `workpaper_reference` (Workpaper reference) in Step.result markdown.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: Each selected item has indexed support or a documented evidence gap, identifiers agree to the sample, source and timing are clear, and testing can begin without relying on undocumented explanations. Results reconcile to the sample and attributes, the proposed conclusion follows the evidence, every exception is traceable, and reviewer approval evaluates the work rather than inferring effectiveness from completion. The authorized reviewer can support the explicit conclusion from the complete record, review notes are resolved or retained, follow-up is assigned, and closure does not create an audit opinion by itself.","kind":"task","label":"TEST","requiredApprovals":1},"id":"test"}],"sourceTemplateId":"workflow-library:sox-control-testing-publication"}
