{"description":"Year-End Deficiency Aggregation & Severity Evaluation as a modular, decision-aware workflow. The instance runs against the existing fiscal-year ICFR assessment engagement — the Audit item with audit_type=sox_testing whose period_end is fiscal year end — enriching it rather than creating a duplicate: the frozen register snapshot and the full evaluation memo trail attach to its steps, and the overall ICFR conclusion lands on that Audit item (rating/opinion/report_date). It closes the gap between per-deficiency handling and the portfolio view: it freezes the register, reconciles it to every failed test, aggregates related deficiencies, concludes control deficiency versus significant deficiency versus material weakness, and hands conclusions to certification support, remediation, and audit-committee reporting instead of duplicating their work. The named deliverables are the year-end deficiency-evaluation memo (carrying the overall ICFR conclusion) and the countersigned final severity schedule. In scope: freezing and severity-evaluating the year-end deficiency population as of the fiscal-year-end assessment date, kept live through the 10-K filing date under a late-arrival rule. Out of scope, handed off rather than duplicated: fixing the deficiencies (SOX Deficiency Remediation) and reporting them to the board (Quarterly Board & Audit-Committee GRC Reporting). Severity thresholds and the contributing-test population are consumed from the Annual ICFR Scoping & Risk Assessment, SOX Key Control TOD/TOE Test, and SOX ITGC Testing runs — the deficiency register itself is the Issue population (issue_type deficiency, escalating to significant_deficiency and material_weakness as this workflow finalizes).","edges":[{"id":"e-is-register-complete-remediate-register-gaps","label":"Close register gaps","source":"is-register-complete","target":"remediate-register-gaps","whenValue":"gaps_found"},{"id":"e-is-register-complete-aggregate-or-standalone","label":"Register complete","source":"is-register-complete","target":"aggregate-or-standalone","whenValue":"complete"},{"id":"e-remediate-register-gaps-aggregate-or-standalone","source":"remediate-register-gaps","target":"aggregate-or-standalone"},{"id":"e-aggregate-or-standalone-form-aggregation-groups","label":"Aggregate","source":"aggregate-or-standalone","target":"form-aggregation-groups","whenValue":"aggregate_groups"},{"id":"e-aggregate-or-standalone-compensating-control-effective","label":"Standalone","source":"aggregate-or-standalone","target":"compensating-control-effective","whenValue":"standalone_only"},{"id":"e-form-aggregation-groups-compensating-control-effective","source":"form-aggregation-groups","target":"compensating-control-effective"},{"id":"e-compensating-control-effective-document-compensating-mitigation","label":"Mitigated","source":"compensating-control-effective","target":"document-compensating-mitigation","whenValue":"effective"},{"id":"e-compensating-control-effective-apply-prudent-official-test","label":"Not mitigated","source":"compensating-control-effective","target":"apply-prudent-official-test","whenValue":"not_effective"},{"id":"e-document-compensating-mitigation-apply-prudent-official-test","source":"document-compensating-mitigation","target":"apply-prudent-official-test"},{"id":"e-apply-prudent-official-test-walk-through-with-disclosure-committee-and-auditor","source":"apply-prudent-official-test","target":"walk-through-with-disclosure-committee-and-auditor"},{"id":"e-walk-through-with-disclosure-committee-and-auditor-feed-302-404-conclusions","source":"walk-through-with-disclosure-committee-and-auditor","target":"feed-302-404-conclusions"},{"id":"e-walk-through-with-disclosure-committee-and-auditor-handoff-to-related-workflow","source":"walk-through-with-disclosure-committee-and-auditor","target":"handoff-to-related-workflow"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-RISK-14","UC-AUDIT-14","UC-AUDIT-17","UC-AUDIT-21","UC-GOV-21"],"department":"finance","domains":["sox"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=sox-deficiency-aggregation-evaluation","contentDigest":"sha256:e44e2152e93d96eb220e7ce001a04754f0a770e2bac48d1e711e634c9ff66c45","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:e44e2152e93d96eb220e7ce001a04754f0a770e2bac48d1e711e634c9ff66c45","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-deficiency-aggregation-evaluation"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"sox-deficiency-aggregation-evaluation","source":"coworkcanvas-gallery","standards":["sox","coso-ic"],"teams":["finance"]},"name":"Year-End Deficiency Aggregation & Severity Evaluation","nodes":[{"data":{"decisionField":"register_complete","description":"Reconcile every failed test and known control gap for the period to the frozen register, then gate the severity evaluation on the result: decide whether the deficiency population is complete or missing records must be created first. The completeness reviewer (SOX PMO lead or delegate) owns the call, made on the reconciliation evidence — an unproven register is how a material weakness goes missing.","formData":{"fields":[{"key":"register_complete","label":"Is the deficiency register complete?","options":[{"label":"Register complete","value":"complete"},{"label":"Gaps found - create missing records","value":"gaps_found"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nReconcile every failed test and known control gap for the period to the frozen register, then gate the severity evaluation on the result: decide whether the deficiency population is complete or missing records must be created first. The completeness reviewer (SOX PMO lead or delegate) owns the call, made on the reconciliation evidence — an unproven register is how a material weakness goes missing.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe fiscal-year ICFR assessment engagement this instance runs against and enriches — the existing Audit item with audit_type=sox_testing whose period_end fixes the evaluation as-of date. This already-existing subject is an input, not something this workflow creates.\n- The live deficiency register, which IS the Issue population: Issue items with issue_type=deficiency (and issue_type=exception for SOX test exceptions) in open statuses, including prior-year uncorrected Issues carrying identified_date, each linked to its affected Control; record the source workflow/Test-step reference on the Issue and keep the Issue as a linked item on that source Test step. Export access to these Issues with full record attributes.\n- The year-end severity framework — overall and performance materiality plus the significant-deficiency screening threshold — consumed from the current Annual ICFR Scoping & Risk Assessment run's handoff document. No native field holds materiality, so it arrives as a reference document, not an item field.\n- The contributing-source inventory: completed SOX Key Control TOD/TOE Test and SOX ITGC Testing runs (Control-hosted SOX testing workflows for the Workflow.customFields.sox.fiscalYear with the workflow Test-step conclusion of exceptions_noted or not_operating_effectively), plus the secondary sources distinguished by Issue.source (internal_audit / external_audit / self_assessment / management_identified) — walkthrough design gaps, internal-audit and external-auditor observations, and management self-identified items.\n- The evaluation-boundaries document — evaluation panel roster, decision owners, and the filing calendar (302 dates, the 404 assessment date at fiscal year end, and the 10-K filing date) — uploaded at this step and folded into the freeze memo.\n\nThe frozen register snapshot and its control totals.\n- Every completed SOX Key Control TOD/TOE Test and SOX ITGC Testing run for the period, with per-control conclusions.\n- The secondary deficiency sources named in the evaluation boundaries: walkthrough design gaps, internal audit findings, external-auditor observations, management self-identified items.\n\n*Agent retrieval, preparation and filing absorb “Freeze the deficiency register”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Freeze the deficiency register: Fix the deficiency population as of the evaluation date in a version-stamped snapshot, so every downstream reconciliation, cluster, and classification runs against one stable, reperformable population.\n\n2. Export the full register as of the evaluation date (item export), one row per deficiency with: deficiency ID, source test reference, control ID, process, FSLI(s), assertion(s), status, identified date, and remediation status. Flag records missing a source reference or control ID now — they will fail normalization later.\n3. Version-stamp the snapshot: cutoff date and time, who ran it, total record count, and control totals per status (open / remediation-in-progress / remediated-pending-retest / closed). The totals are the tamper-evidence — any later drift between the live register and the freeze is detectable by re-running the counts.\n4. Verify the snapshot is the population the evaluation boundaries describe: interim carryovers present, prior-year uncorrected items present, approved exclusions absent with their documented rationale referenced.\n5. Write the late-arrival rule into the freeze memo: a deficiency identified after cutoff is logged as a subsequent item, flagged to the evaluation panel, and evaluated in a dated addendum — never silently merged into the frozen population. The rule stays in force through the 10-K filing date, because 404 speaks as of year end but a subsequent item can still change the conclusion when the condition it reveals existed at year end.\n6. Attach the snapshot file and the freeze memo to this step.\n\n7. Assessment scope for Is the deficiency register complete?: Reconcile every failed test and known control gap for the period to the frozen register, then gate the severity evaluation on the result: decide whether the deficiency population is complete or missing records must be created first. The completeness reviewer (SOX PMO lead or delegate) owns the call, made on the reconciliation evidence — an unproven register is how a material weakness goes missing.\n\n8. Build the should-exist population from the testing side, not the register side: query every completed test run and extract each control concluding in a design gap, an operating exception, or an ineffective conclusion, with control ID and conclusion reference. Direction matters — starting from the register only proves what is already there.\n9. Include partial failures: a test that passed after sample expansion still generated exceptions, and whether those exceptions were dispositioned as deficiencies must be traceable, not assumed. Likewise an ITGC failure judged tolerable because dependent application controls were tested direct — the ITGC deficiency itself still belongs in the population.\n10. Reconcile each failed test to a frozen-register record, matching on control ID plus source reference; matches made on description alone need human confirmation. List every unmatched failure with its source run.\n11. Sweep the secondary sources the same way: each walkthrough design gap, IA finding rated as a control issue, auditor-communicated deficiency, and self-identified item either matches a register record or lands on the unmatched list.\n12. Reverse-check the register: any frozen record with no surviving source reference is investigated — a duplicate, a mis-keyed reference, or evidence the source inventory itself was incomplete.\n13. Draft the completeness reconciliation memo: population counts by source, matched counts, the unmatched list with detail, and the reverse-check result. Attach it with the reconciliation worksheet, and spot-check a sample of matched pairs back to their source test conclusions.\n\nJudge from the completeness memo, not from confidence in the process: (1) every contributing source in the evaluation boundaries was actually swept — a source never queried is an unknown, not a pass; (2) the unmatched list is literally empty, or every remaining item is demonstrably out of population (duplicate of a matched record, an exclusion approved in the evaluation boundaries, or a test exception formally dispositioned as no-deficiency with the disposition referenced); (3) the reverse-check found no register record without a source; (4) the spot-check of matched pairs tied back to source test conclusions without mismatch.\n\n- **Register complete (`complete`)** — all four hold. A dispositioned-as-no-deficiency claim must cite where the disposition is documented; a verbal disposition keeps the item unmatched. State the reconciled count per source in the rationale.\n- **Gaps found - create missing records (`gaps_found`)** — any unmatched failure, un-swept source, or unexplained register orphan remains. Name each gap and its source run in the rationale — the gap step works from that list, and the reconciliation re-runs to zero afterward. Taking this branch is the control operating as designed; the expensive error is evaluating severity on a hole.\n\nDo not rationalize a gap away by pre-judging its severity (\"that one would only be a control deficiency anyway\") — severity belongs to the panel, judged on the whole population, and aggregation can make small items matter.\n\n**Record in AssureSwarm**\nAttach the register snapshot and the freeze memo (document upload).\n- Record the cutoff timestamp, record count, and per-status control totals on the step.\n\nAttach the completeness memo and reconciliation worksheet (document upload), and record the counts on the step: failed tests by source, matched, unmatched.\n- Submit the decision form: `register_complete` (the branch), the step result citing per-source reconciliation counts and where the evidence lives, and the step's approver record.\n- Comment on this step with the references for any dispositioned-as-no-deficiency items relied on.\n\n**Exit criteria**\nSnapshot attached with cutoff timestamp and control totals the SOX PMO lead verified against the live register; late-arrival rule documented and in force through the filing date; every downstream step works from this snapshot, not the live register. Every contributing source in the evaluation boundaries swept and every failed test matched to a register record or on the unmatched list with detail; reverse-check dispositioned and the reviewer's spot-check documented; form submitted with rationale counts that reconcile to the memo; every unmatched item is either on the gap branch's work list or evidenced out of population; the unused branch is prunable.\n\n> **⚡ Audit Artist accelerator:** `/sox-python` runs the two-direction reconciliation as a reproducible procedure — joining test conclusions to register records and emitting the matched and unmatched lists deterministically.","kind":"decision","label":"Is the deficiency register complete?","performedBy":{"note":"","primitives":["coach-query-data","coach-document-upload","sox-python","coach-export-package"]}},"id":"is-register-complete"},{"data":{"description":"Agent creates a deficiency record for each unmatched failed test and re-runs the reconciliation; human approves the amended population","instructions":"**Objective** — Create a properly attributed deficiency record for every unmatched item and re-prove completeness to zero, so the amended frozen population is whole before any severity work begins.\n\n**Inputs**\n- The gap list from the decision rationale: each unmatched failed test or finding with its source run.\n- The source test conclusions and evidence references behind each gap.\n- The frozen snapshot and freeze memo, for the addendum.\n\n**Procedure**\n1. Create one deficiency record per unmatched item (item create), populated from the source rather than from memory: source test reference, control ID, process, FSLI(s), assertion(s), and a failure description lifted from the test conclusion — what the control failed to do, over what window, and what the exception evidence showed. Do not pre-classify severity on new records; classification belongs to the panel downstream.\n2. Where an unmatched failure evidences the same defect as an existing record (same control, same failure mode), do not create a duplicate — add the second source reference to the existing record and flag it as multi-source for normalization.\n3. Link each new record to its source test result and to the affected control record (items link), so traceability runs both directions: register to evidence, and control to its deficiencies.\n4. Re-run the full completeness reconciliation — both directions — to a zero-unmatched result. A partial re-run over only the new records misses knock-on effects of the merge calls in step 2.\n5. Issue a dated addendum to the freeze memo: which records were added after cutoff, why each was missed (source not queried, mis-keyed control ID, disposition never recorded), and the amended control totals. The miss reasons are monitoring evidence in their own right — a systematically missed source suggests a deficiency in the deficiency-management control itself.\n\n**Record in AssureSwarm**\n- Item create — one Issue per unmatched item (issue_type=deficiency, source set per origin, identified_date, description lifted from the source test conclusion), linked by item relationship to the affected Control and added as a linked item on the source workflow's Test step.\n- Attach the re-run reconciliation and the freeze-memo addendum to this step (document upload).\n\n**Exit criteria** — Reconciliation shows zero unmatched in both directions; every added record carries its source reference, control ID, and dimensions; addendum records the amended control totals; the reviewer approves the amended population as the evaluation basis.","label":"Create missing deficiency records","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"remediate-register-gaps"},{"data":{"decisionField":"aggregation_path","description":"Fix the unit of severity evaluation: which candidate clusters are evaluated as combined aggregation groups, and which deficiencies stand alone. The evaluation panel owns the call; it determines whether severity is judged on individual exposures or combined ones.","formData":{"fields":[{"key":"aggregation_path","label":"Aggregate as groups or evaluate standalone?","options":[{"label":"Form aggregation groups","value":"aggregate_groups"},{"label":"Evaluate all standalone","value":"standalone_only"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nFix the unit of severity evaluation: which candidate clusters are evaluated as combined aggregation groups, and which deficiencies stand alone. The evaluation panel owns the call; it determines whether severity is judged on individual exposures or combined ones.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe approved frozen population (amended, if the gap branch ran).\n- The RCM and control records, for dimension lookups: process, FSLI, assertion, COSO mapping, control attributes.\n- Trial-balance or FSLI balances and transaction volumes for the period, for magnitude quantification.\n- The prior-year evaluation memo, for recurrence flags.\n\nThe normalized, merged population with dimensions, magnitude fields, and likelihood flags.\n- The severity thresholds from the evaluation boundaries: overall materiality and the significant-deficiency threshold.\n- Prior-year uncorrected deficiencies and interim items open at year end (already in the frozen population — verify, do not assume).\n\n*Agent retrieval, preparation and filing absorb “Normalize by process, FSLI, and assertion”, “Identify related deficiencies”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Normalize by process, FSLI, and assertion: Standardize every deficiency onto common dimensions and quantified magnitude fields, so related items can be clustered mechanically and combined exposures computed — aggregation is only as good as this coding.\n\n2. Code each record on the aggregation dimensions: business process; affected FSLI(s); relevant assertion(s) (existence/occurrence, completeness, accuracy, valuation, rights and obligations, presentation); COSO component and principle; root-cause category (design gap, competency, capacity, change management, judgment/estimate, override); and control attributes — preventive or detective, manual or automated, entity-level, process-level, or ITGC. Take dimensions from the linked control record; deviate only where the failure touched something narrower or broader than the control's mapping, and say so.\n3. Quantify magnitude on two lines that must never be conflated: actual misstatement detected (often zero — a deficiency does not require a misstatement) and potential magnitude — the gross exposure of transactions or balances flowing through the failed control during its ineffective window. For a detective control down four months over a revenue stream booking $30M per quarter, potential exposure is the roughly $40M that passed unreviewed. Redundant or compensating controls do not reduce this number here; that analysis comes later, with evidence.\n4. Flag likelihood factors per record: recurrence from the prior year, duration ineffective, transaction volume and complexity, the degree of estimation or judgment in the amounts, and fraud susceptibility (assets convertible to cash, management-override exposure).\n5. Give ITGC records a dependency footprint instead of direct FSLI exposure: list the application controls and system-generated reports relying on the failed layer — their FSLIs define the deficiency's reach.\n6. Merge duplicates describing the same defect observed by different sources (the same failed access control found by testing and by the external auditor), retaining every source reference on the surviving record.\n\n7. Assessment scope for Identify related deficiencies: Surface every combination of deficiencies that could be more severe together than any member is alone — the in-combination evaluation AS 2201 and the SEC guidance require, and the thing per-deficiency handling structurally misses.\n\n8. Cluster the population once per aggregation dimension, letting a record appear in several candidate groups: (a) same FSLI and assertion — the primary lens, because misstatement risk concentrates where multiple failed controls guard the same assertion; (b) same business process — end-to-end coverage loss even across FSLIs; (c) same root cause — e.g., every deficiency tracing to an under-resourced close team, which may indicate a COSO control-environment failure rather than isolated process defects; (d) same ITGC layer — one failed change-management or access layer supporting multiple application controls aggregates through its full dependency footprint.\n9. Verify the uncorrected past is in the clustering: prior-year deficiencies not yet remediated-and-retested and interim items still open combine with current-year findings — severity is evaluated on the uncorrected whole as of year end.\n10. Compute combined actual and combined potential magnitude per candidate cluster. Combined potential is not naive addition where exposures overlap — two failed controls over the same $10M population expose $10M, not $20M. Document the overlap treatment per cluster.\n11. Compare each cluster's combined magnitude to the significant-deficiency threshold and to materiality, and flag every cluster that crosses a threshold only in combination — those clusters are why this step exists.\n12. Build the candidate-group worksheet: cluster ID, shared dimension, member deficiency IDs, combined actual and potential magnitude with the overlap treatment, and the threshold comparison. Attach it for the panel.\n\n13. Assessment scope for Aggregate as groups or evaluate standalone?: Fix the unit of severity evaluation: which candidate clusters are evaluated as combined aggregation groups, and which deficiencies stand alone. The evaluation panel owns the call; it determines whether severity is judged on individual exposures or combined ones.\n\n\n\nTest each candidate cluster against the aggregation logic, not against a preference for a smaller problem: deficiencies are related when a single misstatement scenario could pass through them together — same FSLI and assertion, same process, common root cause, or a shared ITGC layer. Per cluster, ask three things: (1) is the shared dimension substantive at the assertion level, or a coincidence of labels — two \"revenue\" deficiencies touching different assertions (occurrence versus cutoff) may not combine; (2) does the combined potential magnitude change the threshold picture relative to any member alone; (3) would the failure modes plausibly compound — a failed preventive control plus the failed detective control behind it is the classic compounding pair.\n\n- **Form aggregation groups (`aggregate_groups`)** — at least one cluster holds: its shared dimension is substantive and evaluating members separately would understate combined exposure. Any cluster that crosses the significant-deficiency threshold or materiality only in combination belongs on this branch almost by definition. Name the approved clusters in the rationale; unrelated leftovers still evaluate standalone alongside the groups.\n- **Evaluate all standalone (`standalone_only`)** — no candidate survives scrutiny: shared dimensions are superficial, exposures do not join into a common misstatement scenario, and no combination changes any threshold comparison. Argue this cluster by cluster in the rationale — \"aggregation was evaluated and no related deficiencies exist\" with per-cluster reasoning is precisely what the external auditor will ask to see. A blanket none-related over a population with multiple same-FSLI failures is a red flag, not a finding.\n\n**Record in AssureSwarm**\nItem field update — enrich each Issue's native fields (Issue.description with the coded dimensions in narrative, Issue.root_cause with the root-cause category). FSLI, assertion, COSO component/principle, actual and potential magnitude, and the likelihood flags have no native Issue fields, so the full coding master lives in the normalization worksheet — not on the item.\n- Step document — attach the normalization coding worksheet (document upload); it is the system of record for the dimension, magnitude, and likelihood columns.\n- Record the merge log on the step: records combined, surviving Issue ID, retained source references.\n\nAttach the candidate-group worksheet (document upload).\n- Record cluster counts on the step, including how many cross a threshold only in combination.\n\nSubmit the decision form: `aggregation_path` (the branch), the step result with per-cluster accept/reject reasoning and worksheet references, and the step's approver record.\n\n**Exit criteria**\nEvery record fully coded, with actual and potential magnitude quantified or explicitly justified as non-quantifiable; ITGC records carry their dependency footprint; duplicates merged with all sources retained; the reviewer's sample-check against source test evidence documented with corrections applied. All four dimensions clustered over the full population including carryovers; combined magnitudes computed with documented overlap treatment; worksheet attached; the evaluation panel has curated the list — added combinations the mechanical pass missed, struck spurious ones — and settled the candidates for the aggregation decision. Form submitted; every candidate cluster explicitly accepted or rejected with reasons; the unused branch is prunable — the standalone path proceeds straight to severity evaluation with every deficiency its own unit.","kind":"decision","label":"Aggregate as groups or evaluate standalone?","performedBy":{"note":"","primitives":["coach-query-data","coach-item-update","coach-document-upload"]}},"id":"aggregate-or-standalone"},{"data":{"description":"Agent documents each approved group with members, rationale, and combined magnitude; human signs off group composition","instructions":"**Objective** — Establish each approved cluster as a documented aggregation group — the unit the severity framework is applied to — with reperformable combined magnitudes and bidirectional links from every member.\n\n**Inputs**\n- The approved cluster list and per-cluster rationale from the aggregation decision.\n- The candidate-group worksheet with combined-magnitude computations.\n- The normalized member deficiency records.\n\n**Procedure**\n1. Designate each approved cluster as a documented aggregation group with a stable group ID in the group worksheet — there is no native group item type, so the worksheet is the group's system of record; record its members, the shared dimension, and the panel's aggregation rationale verbatim — that rationale travels with the group into the memo and the auditor walkthrough.\n2. Finalize the combined-magnitude computation per group: combined actual misstatement, combined potential exposure with the overlap treatment stated, and the comparison against the significant-deficiency threshold and overall materiality. Show the arithmetic — member exposures, overlap deduction, result — so a reviewer can reperform it from the worksheet alone.\n3. Link every member deficiency Issue to the other members of its group (items link) so group membership is navigable from any member — there is no group item to point at, so the members' mutual Issue↔Issue links plus the worksheet roster together define the unit. A member left unlinked and off the roster silently evaluates standalone and understates the group.\n4. Handle multi-membership deliberately: where one deficiency sits in two approved groups (clustered by FSLI and again by root cause), keep it in both for evaluation but flag it so no portfolio total double-counts its exposure.\n5. Sweep the remainder: every deficiency in no approved group is explicitly carried forward as a standalone evaluation unit. Reconcile the complete unit list — groups plus standalones — to the frozen population count: every deficiency in at least one unit, none dropped.\n\n**Record in AssureSwarm**\n- Item relationship — member Issue↔Issue links marking each group's membership.\n- Step document — the group worksheet (document upload) carries each group's members, shared dimension, panel rationale, and combined magnitudes; no native group item type exists, so the worksheet is the group's system of record.\n- Record the unit reconciliation on the step: frozen-population count versus unit coverage.\n\n**Exit criteria** — Every approved group documented with a reperformable combined magnitude; all members linked; multi-membership flagged against double-counting; the unit list reconciles to the frozen population; panel sign-off on every group's composition and rationale recorded before classification begins.","label":"Form aggregation groups","performedBy":{"primitives":["coach-items-link"]}},"id":"form-aggregation-groups"},{"data":{"decisionField":"compensating_effective","description":"Decide, on test evidence rather than assertion, whether compensating controls reduce the severity of any evaluation unit. The evaluation panel owns the call; it separates classifications that get mitigated from those that stand as drafted.","formData":{"fields":[{"key":"compensating_effective","label":"Compensating control effective?","options":[{"label":"Effective - severity mitigated","value":"effective"},{"label":"Not effective - classifications stand","value":"not_effective"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nDecide, on test evidence rather than assertion, whether compensating controls reduce the severity of any evaluation unit. The evaluation panel owns the call; it separates classifications that get mitigated from those that stand as drafted.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe complete unit list: signed-off groups with combined magnitudes, plus standalone units.\n- The severity thresholds: overall materiality and the significant-deficiency threshold from the evaluation boundaries.\n- Magnitude fields and likelihood flags from normalization; prior-year classifications for recurring items.\n\n*Agent retrieval, preparation and filing absorb “Evaluate severity per evaluation unit”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Evaluate severity per evaluation unit: Apply the severity framework to every evaluation unit — each aggregation group and each standalone deficiency — and draft a defensible preliminary classification of control deficiency, significant deficiency, or material weakness for panel challenge.\n\n2. Assess magnitude per unit: actual misstatement plus the potential misstatement of the transactions and balances the failed controls address, compared to materiality and the significant-deficiency threshold. Severity turns on what could occur, not what did — an actual misstatement of zero does not cap potential magnitude, and the exposure is bounded by the amounts flowing through the control during its ineffective window (the \"could\" factors: FSLI amounts exposed, plus current and expected future transaction volume).\n3. Assess likelihood per unit: is there a reasonable possibility — more than remote; it need not be probable — that a misstatement of that magnitude would not be prevented or detected on a timely basis? Weigh the normalization flags: recurrence from the prior year, duration the control was ineffective, transaction volume and complexity, subjectivity of the amounts involved, fraud susceptibility, and — within a group — the interaction of the deficiencies with each other.\n4. Draft the preliminary classification per unit: material weakness where a reasonable possibility of a material misstatement exists; significant deficiency where less severe than a material weakness yet important enough to merit audit-committee attention (combined magnitude above the significant-deficiency threshold is the working screen); control deficiency otherwise.\n5. Check every unit — regardless of its quantitative screen — against the indicators of material weakness, any one of which presumptively points to that classification: (a) identified fraud, whether or not material, involving senior management; (b) restatement of previously issued financial statements to correct a material misstatement; (c) a material misstatement identified by the external auditor in the current period that internal control would not have caught; (d) ineffective oversight of external financial reporting and internal control by the audit committee. Overcoming an indicator takes explicit documented reasoning, never silence.\n6. For each unit at or above significant-deficiency severity, identify candidate compensating controls — controls addressing the same misstatement risk by a different mechanism — and record whether each was tested this period. These feed the next decision; naming untested compensating controls just to soften a classification is the pattern external auditors reject fastest.\n7. Attach the severity worksheet: every unit, its magnitude and likelihood assessment, the indicator check, the draft classification, and the rationale chain from evidence to conclusion.\n\n8. Assessment scope for Compensating control effective?: Decide, on test evidence rather than assertion, whether compensating controls reduce the severity of any evaluation unit. The evaluation panel owns the call; it separates classifications that get mitigated from those that stand as drafted.\n\n\n\nFor every candidate compensating control named on the severity worksheet, two tests must both pass for each unit it is claimed to compensate:\n\n1. *Tested effective* — the control has design and operating effectiveness conclusions from this period's SOX Key Control TOD/TOE Test runs, covering the deficiency's ineffective window. An untested control compensates nothing — reliance without evidence merely relocates the deficiency. A compensating control that itself failed testing is disqualified outright, and should already be in this register as a deficiency.\n2. *Sufficient precision* — the control operates at a level of precision that would prevent or detect a misstatement of the magnitude that matters for the unit's draft classification: material, for a draft material weakness; important-to-oversight, for a draft significant deficiency. Precision is concrete: investigation threshold relative to the exposure (a variance review triggered at $5M cannot compensate a $2M risk), aggregation level (entity-wide analytics rarely catch process-level errors), operating frequency versus the timing of potential misstatement, and population coverage of the deficient flow.\n\n- **Effective - severity mitigated (`effective`)** — at least one relied-on compensating control passes both tests for at least one unit. Name in the rationale which control mitigates which unit and which test runs evidence it; the next step documents each reduction in full.\n- **Not effective - classifications stand (`not_effective`)** — no candidate survives both tests: untested, failed, or imprecise relative to the exposure. Draft classifications proceed unmitigated to the prudent-official test. Record per candidate why it failed — the auditor will probe exactly these rejections, and documented rigor here supports the overall conclusion.\n\nOne trap cuts both ways: a single review control cannot compensate every deficiency in its process at once — judge its precision against the combined exposure of all units leaning on it, not each unit separately.\n\n**Record in AssureSwarm**\nAttach the severity worksheet with the complete per-unit rationale chain (document upload).\n- Record the draft classification counts on the step — material weaknesses, significant deficiencies, control deficiencies — and which units proceed to compensating-control assessment.\n\nSubmit the decision form: `compensating_effective` (the branch), the step result mapping each candidate to pass/fail on both tests with test-run references, and the step's approver record.\n\n**Exit criteria**\nEvery unit carries a draft classification with magnitude, likelihood, and indicator analysis; units near the significant-deficiency and materiality thresholds flagged for extra panel scrutiny; candidate compensating controls listed with tested status; the panel challenge session held, with its marks recorded on which units proceed to compensating-control assessment. Form submitted; every candidate compensating control dispositioned on both tests with evidence references; the unused branch is prunable.","kind":"decision","label":"Compensating control effective?","performedBy":{"agent":"sox-artist","note":"drafts the per-unit severity classification and rationale for evaluation-panel challenge and sign-off","primitives":[]}},"id":"compensating-control-effective"},{"data":{"description":"Agent substantiates each severity reduction with the compensating control's test evidence and precision analysis; human confirms the support","instructions":"**Objective** — Substantiate every severity reduction taken on a compensating control with cited test evidence and a written precision analysis, so each mitigated classification survives auditor reperformance.\n\n**Inputs**\n- The decision rationale: which compensating control mitigates which evaluation unit.\n- The compensating controls' period test evidence from the SOX Key Control TOD/TOE Test runs.\n- The severity worksheet with the pre-mitigation draft classifications.\n\n**Procedure**\n1. For each relied-on compensating control, pull the period test evidence and cite the specific design and operating conclusions relied on — run reference, sample coverage, conclusion date. Reliance must cover the deficiency's ineffective window: a control tested effective only in Q4 does not compensate a Q1–Q3 gap.\n2. Write the precision analysis per pairing: the misstatement size the compensating control would detect (its threshold and aggregation level), the deficiency's potential magnitude it is set against, and the margin between them. State coverage gaps honestly — period not covered, population slices outside the control's view, exception types it would not surface.\n3. Conclude residual severity per unit: the mitigated classification plus the rationale for what the compensating control does and does not absorb. Partial mitigation is the norm — a monthly detective review may reduce a draft material weakness to a significant deficiency by capping undetected exposure at one month's flow, without eliminating the deficiency. A one-level reduction with reasoning is credible; a draft material weakness quietly becoming a control deficiency should draw the panel's hardest look.\n4. Link each compensating control record to the deficiency unit it mitigates (items link), so the reliance is navigable from both sides.\n5. Update the severity worksheet to show pre-mitigation and post-mitigation classifications side by side with the evidence trail — the memo and the auditor walkthrough need both visible. Overwriting the draft hides the judgment.\n\n**Record in AssureSwarm**\n- Item relationship — link each compensating Control item to the deficiency Issue unit(s) it mitigates (items link), so the reliance is navigable from both sides.\n- Attach the updated severity worksheet with both pre- and post-mitigation classification columns and evidence references (document upload).\n\n**Exit criteria** — Every reduction rests on cited test evidence covering the ineffective window plus a written precision analysis; residual severity recorded per unit; the worksheet shows pre- and post-mitigation states; panel confirmation recorded, with any rejected reliance reverted to the unmitigated draft.","label":"Document compensating mitigation","performedBy":{"primitives":["coach-query-data","coach-items-link","coach-document-upload"]}},"id":"document-compensating-mitigation"},{"data":{"description":"Finalize every classification through the prudent-official standard — the qualitative backstop that keeps quantitatively defensible conclusions from failing external challenge — and produce the countersigned final severity schedule.","instructions":"**Objective**\nFinalize every classification through the prudent-official standard — the qualitative backstop that keeps quantitatively defensible conclusions from failing external challenge — and produce the countersigned final severity schedule.\n\n**Inputs**\nThe severity worksheet with post-mitigation (or unmitigated) classifications per unit.\n- The full rationale chains: magnitude, likelihood, aggregation effect, compensating reliance.\n- The material-weakness indicator checks from the severity evaluation.\n\nThe countersigned final severity schedule and the full worksheet trail.\n- The freeze memo (with any addendum), completeness reconciliation, candidate-group and group worksheets, and compensating-mitigation documentation.\n- The subsequent-items log accumulated under the late-arrival rule since cutoff.\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Draft the year-end evaluation memo”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Apply the prudent-official test: Finalize every classification through the prudent-official standard — the qualitative backstop that keeps quantitatively defensible conclusions from failing external challenge — and produce the countersigned final severity schedule.\n\n2. Apply the test to each unit, hardest where the quantitative analysis lands just below a threshold: would a prudent official in the conduct of their own affairs, having the same knowledge of the deficiency, its duration, and its mitigation, conclude that the annual and interim financial statements remain assured against material misstatement? This is the check on classification-by-arithmetic — a unit can sit below every quantitative screen and still be a material weakness when qualitative factors (fraud exposure, management override, estimate subjectivity, second-year recurrence) would trouble a prudent official.\n3. Interrogate the pattern, not only the units: several significant deficiencies concentrated in one COSO component, or a deficiency management failed to remediate for a second consecutive year, can elevate the conclusion beyond what any single unit supports.\n4. Finalize each unit's classification — control deficiency, significant deficiency, or material weakness — with the complete rationale chain assembled in one place: magnitude, likelihood, aggregation effect, compensating mitigation with its evidence, and the prudent-official reasoning. Any unit whose final class differs from its quantitative screen carries the overriding reasoning explicitly.\n5. Compile the final severity schedule sorted by classification: each unit, its member deficiencies, final class, and rationale references back to the worksheet. This schedule is the source of truth the memo, the certifications, and committee reporting all transcribe from.\n6. Flag every significant deficiency and material weakness for the disclosure path — 302/404 support and audit-committee reporting — in the following steps.\n7. Obtain countersignatures from the SOX PMO lead and the controller on each final classification, resolving residual disagreement now — a split position surfacing during the auditor walkthrough costs far more than settling it here.\n\n8. Assessment scope for Draft the year-end evaluation memo: Produce the single year-end memo documenting the deficiency evaluation end to end and stating the overall ICFR conclusion management will certify against — the workpaper the external auditor and the disclosure committee read first.\n\n9. Write the population section: freeze metadata (cutoff, counts, control totals), the completeness reconciliation results by source with the zero-unmatched proof, and every subsequent item received after cutoff with its addendum disposition. A reader must be able to conclude the evaluation ran on a complete, fixed population.\n10. Write the evaluation section: aggregation groups with the panel's rationale, the final severity schedule, compensating-control reliance with its test evidence and precision analysis, and the prudent-official conclusions — including any classification that overrode its quantitative screen and why.\n11. State the overall ICFR conclusion as of fiscal year end that the evidence supports: effective only if no material weakness exists at the assessment date. One open material weakness at year end forces not-effective regardless of remediation momentum; a weakness remediated before year end supports effective only if the remediated control operated long enough to be retested and concluded effective. Include the remediation status of every open significant deficiency and material weakness.\n12. Run a deliberate internal-consistency check before release: every number in the memo traces to an exhibit, classification counts match the schedule, and the conclusion sentence matches the material-weakness count. Transcription drift between schedule and memo is the most common walkthrough finding.\n13. Assemble the exhibit package — severity worksheet (pre- and post-mitigation), completeness reconciliation, group worksheet, countersigned schedule — and attach the complete memo package to this step.\n\n**Record in AssureSwarm**\nAttach the final severity schedule (document upload), with the SOX PMO lead and controller countersignatures captured as step approvals.\n- Item field update — set Issue.issue_type to deficiency | significant_deficiency | material_weakness (and Issue.severity) on every register Issue. Group-level final classifications live in the group worksheet and the schedule — there is no native group item type to update.\n\nAttach the memo and exhibit package (document upload), rendered as one cross-referenced package for review.\n- Item field update — write the overall ICFR conclusion to the anchor Audit item: Audit.rating, Audit.opinion, and Audit.report_date. Record the classification counts on the workflow run.\n\n**Exit criteria**\nEvery unit holds a final classification with a complete rationale chain; below-screen overrides reasoned explicitly; the schedule compiled and countersigned by the SOX PMO lead and the controller; all significant deficiencies and material weaknesses flagged for disclosure. Memo complete with population, evaluation, and conclusion sections; every exhibit attached and cross-referenced; the internal-consistency check documented; SOX PMO lead approval recorded, releasing the draft for the disclosure-committee and external-auditor walkthrough.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the memo and its exhibits into one paginated, cross-referenced review package for the walkthrough.","label":"Apply the prudent-official test","performedBy":{"note":"","primitives":["coach-item-update","coach-document-upload","coach-render-package"]}},"id":"apply-prudent-official-test"},{"data":{"description":"Agent prepares the walkthrough pack and logs challenges and dispositions; human records concurrence or escalates divergence","instructions":"**Objective** — Put every classification and the overall conclusion through disclosure-committee and external-auditor challenge, so concurrence is documented and any severity disagreement surfaces and routes to the audit committee before certification support is issued.\n\n**Inputs**\n- The approved memo draft and exhibit package.\n- The final severity schedule with near-threshold items flagged.\n- The walkthrough dates and attendee lists from the evaluation boundaries.\n\n**Procedure**\n1. Prepare the walkthrough pack: the memo, the final severity schedule, the open-questions list, and — separately flagged — the items nearest the significant-deficiency and materiality thresholds plus any classification that overrode a material-weakness indicator or a quantitative screen. Leading with the judgment calls, rather than letting reviewers hunt for them, is what makes concurrence meaningful.\n2. Run the disclosure-committee session first: record every challenge and its disposition. Where the committee changes a conclusion, update the memo and the severity schedule as a documented amendment flowing back to the countersigned record — never an untracked edit.\n3. Walk the external auditor through the schedule item by item, capturing their severity view per unit. The auditor evaluates independently for the ICFR opinion; document each divergence, the discussion, and its resolution — or the agree-to-disagree rationale where management maintains its position on its own evidence. Management's assessment is its own, not an adoption of the auditor's, but an unexplained gap between the two positions in the same filing is untenable.\n4. Issue the final memo with a change log showing exactly what moved during the walkthroughs and why. The delta between released draft and final is evidence of governance operating; its absence invites the question of whether real review occurred.\n5. Escalate before proceeding: any unresolved divergence with the auditor over a significant deficiency or material weakness goes to the audit committee now — it bears on the 404 conclusion, the auditor's ICFR opinion, or both, and cannot be discovered at filing.\n\n**Record in AssureSwarm**\n- Attach the walkthrough pack, the committee minutes, the auditor divergence-and-resolution log, and the final memo with change log (document upload).\n- Record concurrence status and any audit-committee escalation on the step.\n\n**Exit criteria** — Disclosure-committee concurrence minuted; auditor views captured per unit with every divergence resolved or escalated to the audit committee; final memo issued with its change log; no open severity disagreement on a significant deficiency or material weakness proceeding silently.","label":"Walk through with disclosure committee and external auditor","performedBy":{"primitives":["coach-document-upload"]}},"id":"walk-through-with-disclosure-committee-and-auditor"},{"data":{"description":"Agent converts the final evaluation into 302 and 404 certification support with full traceability; certifying officers' delegates verify","instructions":"**Objective** — Convert the concluded evaluation into exact-match certification support for the Section 302 and 404 processes, with traceability from every disclosed statement back to the underlying deficiency records.\n\n**Inputs**\n- The final memo with change log and the countersigned severity schedule.\n- The scoped certification packages and native sign-off requirements for certifying officers and process owners.\n- The filing calendar: the 10-K assessment-language deadline and the 302 certification dates.\n\n**Procedure**\n1. Prepare the Section 404 management-assessment input: the overall ICFR conclusion as of fiscal year end in the memo's exact terms, and — for any material weakness — draft disclosure language covering what failed, its potential effect, and remediation status. Material-weakness disclosure must be specific enough that a reader understands the failure and its reach; boilerplate about \"certain controls over financial reporting\" draws comment letters.\n2. Prepare the Section 302 support: the formal communication of all significant deficiencies and material weaknesses to the audit committee and the external auditor (the certification's underlying representation), and the statement of material changes in ICFR during the period — remediation completed this quarter belongs here even where the underlying deficiency itself is not disclosable.\n3. Populate the scoped downstream certification packages with the approved concluded items, their evidence references and the exact representations relevant to each certifying officer and process owner. Route those packages through the downstream workflow’s native review and sign-off. Reuse the concluded schedule and existing evidence; obtain only genuinely unresolved facts from a named respondent outside every preparation, execution, review and approval role in the complete certification workflow. Participants record their own certification judgments in native results and approvals, without a questionnaire. A process owner certifying no known deficiencies while the schedule lists their process's significant deficiency is a contradiction the support package must make impossible.\n4. Build the traceability index: every disclosed item maps to its evaluation unit, member deficiency records, and evidence references. Archive the certification support package together with the index.\n5. Run the transcription verification: the certifying officers' delegates tie the support package to the approved memo line by line — same classifications, same counts, same conclusion, nothing reclassified or omitted in transcription. Any wording change made for disclosure style routes back to the disclosure committee rather than being silently accepted.\n\n**Record in AssureSwarm**\n- Step document — attach the certification support package and traceability index (document upload).\n- Handoff package — deliver the approved scoped support package and traceability index to the downstream Section 302/404 certification workflow. Each certifying officer and process owner receives the concluded items relevant to their representations before native sign-off; known conclusions and executor certifications are not collected again through form fills.\n\n**Exit criteria** — 404 and 302 support prepared in memo-exact terms; scoped certification packages reflect the concluded items before native signature; traceability index complete; the delegates' line-by-line verification documented with zero unexplained deltas.","label":"Feed 302/404 certification conclusions","performedBy":{"primitives":["coach-form-fill","coach-document-upload"]}},"id":"feed-302-404-conclusions"},{"data":{"description":"Agent seeds remediation runs, packages the audit-committee view, and archives the full evaluation trail with the subsequent-events watch; downstream owners acknowledge receipt and the SOX PMO lead closes on that acknowledgment","instructions":"**Objective** — Hand the concluded evaluation to SOX Deficiency Remediation and Quarterly Board & Audit-Committee GRC Reporting with everything each needs to proceed — an explicit statement of what neither may relitigate — and close the cycle on their acknowledgment with a reperformable archive and an armed subsequent-events watch.\n\n**Inputs**\n- The final severity schedule and memo references.\n- The current inventory of open remediation efforts (workflow scan).\n- Remediation owners and target dates from the classification records.\n- The full document trail: final memo with change log, severity worksheet, completeness reconciliation, group worksheet, walkthrough minutes, and the certification support package with its traceability index.\n- The frozen register and the concluded classification on every deficiency record.\n- The filing date, which bounds the subsequent-events watch.\n\n**Procedure**\n_Items 6–10 close the workflow (folded from the former \"Close and archive\" step); the acknowledged handoff recorded here is the closure — there is no separate confirmation._\n1. Scan for existing remediation runs so the handoff refreshes rather than duplicates: every open material weakness, significant deficiency, and control deficiency requiring action ends with exactly one SOX Deficiency Remediation run — created where none exists, re-seeded where one does.\n2. Seed each remediation run with the final classification, aggregation-group membership, the rationale reference into the memo, and target dates. Group membership matters downstream: remediating one member of an aggregated material weakness does not de-escalate the group — only a documented re-evaluation of the unit does — and material-weakness fixes need enough operating runway before next year end for retesting to conclude effective.\n3. Package the audit-committee view for Quarterly Board & Audit-Committee GRC Reporting: the final severity schedule, the material-weakness narrative and disclosure position, and remediation milestones with owners and dates. The committee package reports conclusions; it does not reopen them.\n4. State the non-repeat boundary in both packages: severity classifications are final per this evaluation and reopen only on new facts through a documented re-evaluation under the late-arrival rule; remediation validates fixes and retests controls — it does not re-argue classifications; committee reporting transcribes the schedule — it does not restate severity.\n5. Obtain acknowledgment from both downstream owners that the package contents are sufficient to proceed, and log any gap they identify back onto this workflow before closure.\n6. Assemble the archive: final memo and change log, severity worksheet (pre- and post-mitigation), completeness reconciliation with any freeze addendum, group worksheet, walkthrough minutes, and the certification support package. Reperformability is the test — a reviewer holding only the archive must be able to retrace every classification from frozen population to certified conclusion without asking anyone anything.\n7. Update every deficiency record with its final classification, evaluation-unit reference, and memo reference, so the register itself reflects the concluded state and next year's evaluation inherits clean carryover data.\n8. Arm the subsequent-events watch through the filing date: any deficiency identified between the evaluation date and filing is assessed as a subsequent item under the late-arrival rule — logged, flagged to the evaluation panel, and evaluated in a dated addendum. A documented re-evaluation of the concluded position triggers if the item could change any unit's classification or the overall ICFR conclusion; the dangerous case is a newly surfaced condition that existed at year end. A watchlist over new register entries makes the watch operational rather than aspirational.\n9. Communicate closure to the SOX PMO, the disclosure committee, and both downstream workflow owners, stating the archive location and the watch end date.\n10. Record the archive confirmation on the step. Post-archive corrections are new dated addenda referencing the archived version — the archived record itself is never edited.\n\n**Record in AssureSwarm**\n- Handoff package — attach both handoff documents (SOX Deficiency Remediation and Quarterly Board & Audit-Committee GRC Reporting) at this step; record the downstream owners' acknowledgments on the step.\n- Each actionable deficiency ends with exactly one SOX Deficiency Remediation workflow instance anchored on its deficiency Issue (or aggregation group), linked to that Issue — created where none exists, re-seeded where one does.\n- Workflow instance — the archived run is the reperformable audit trail; attach the complete archive package (document upload).\n- Item field update — confirm Issue.issue_type as the final classification on every register Issue and carry the evaluation-unit and memo references in Issue.description/root_cause (there is no native unit field).\n- Subsequent-events watch — a convention over new Issues with identified_date after the cutoff (no native scheduler), armed through the filing date.\n\n**Exit criteria** — Every actionable deficiency has exactly one seeded remediation run; the committee package delivered; the non-repeat boundary stated in both packages; both downstream owners' acknowledgments recorded; archive attached and confirmed reperformable by the SOX PMO lead; every register record reflects its concluded state; the subsequent-events watch armed through the filing date with its re-evaluation trigger stated; closure communicated and the workflow closed.","label":"Handoff to related workflows","performedBy":{"primitives":["coach-workflow-scan","coach-document-upload","coach-item-update"]}},"id":"handoff-to-related-workflow"}],"sourceTemplateId":"workflow-library:sox-deficiency-aggregation-evaluation"}
