{"description":"Runs on the existing audit item. Govern external-audit PBC requests from intake and preparation through quality review, secure delivery, clarification, and complete request closure. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":["sox-pbc"],"controlVerbs":{"UC-AUDIT-25":"operates"},"controls":["UC-AUDIT-25"],"department":"finance","domains":["sox"],"framework":"sox","kind":"sox-pbc","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:sox-pbc"}],"canonicalUrl":"https://workflow-library.com/all/?w=sox-external-audit-pbc-request","contentDigest":"sha256:6d0a661e3761f8a35e5eabfafee0b91603106a4739bfef76aa1f1ece69e90de4","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed PBC package, delivery evidence and open clarifications for the auditor request owner and the company's approved PBC procedure"}],"roles":[{"contribution":"approval","description":"PBC release authority. Approve PBC request closure.","id":"reviewer-1","nodeIds":["pbc-request-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:sox-pbc"}],"releaseId":"sha256:6d0a661e3761f8a35e5eabfafee0b91603106a4739bfef76aa1f1ece69e90de4","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-external-audit-pbc-request"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"sox-external-audit-pbc-request","source":"coworkcanvas-gallery","standards":[],"teams":["finance"]},"name":"External Audit Support & PBC","nodes":[{"data":{"controls":["UC-AUDIT-25"],"instructions":"**Objective**\nApprove PBC request closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the auditor request list and correspondence, prior submissions, SOX scope, control and process records, data owners, retention requirements, confidentiality rules, and reporting calendar.\n2. Use the validated request, authoritative reports and documents, source-system extracts, report parameters, reconciliations, prior submissions, retention rules, and approved secure workspace.\n3. Review the request and clarification history, prepared package, reconciliation, source parameters, redactions, limitations, related submissions, legal or security restrictions, and delivery protocol.\n4. Review the released response, delivery evidence, auditor acknowledgment, follow-up questions, supplemental packages, dispute or restriction decisions, request tracker, and related SOX records.\n\n**Procedure**\n1. Clarify ambiguous wording and dates with the auditor, identify the authoritative source and preparer, detect duplicate or superseded requests, assess sensitive data, agree delivery format, and set preparation and review milestones.\n2. Generate or collect support with reproducible parameters, reconcile totals and populations, validate dates and identifiers, explain transformations, remove out-of-scope sensitive data, preserve source versions, and identify limitations.\n3. Reperform key reconciliations, inspect samples of source agreement, confirm no privileged or out-of-scope data is included, verify explanations are factual, approve the exact version, and transmit through the authorized channel.\n4. Confirm the tracker reflects the exact response and status, link all clarifications and supplements, ensure superseded versions cannot be mistaken for final, assign open questions, and preserve the secure audit trail.\n\n**Record in AssureSwarm**\n1. Capture request reference, exact scope, period, requested format, purpose, auditor contact, preparer, reviewer, source system, confidentiality, dependencies, due date, and clarification history. Also record requested population and period.\n2. Link the response package, source and query parameters, reconciliation, preparer and date, transformations, redactions, exceptions, limitations, version, and cross-references to related controls or workpapers. Also record prepared response reference.\n3. Capture the release decision, reviewer, approved version and hash or identifier, reconciliation checks, restrictions, delivery channel, recipient, timestamp, portal confirmation, and any required revision.\n4. Document the authorized reviewer, closure status, final package and delivery reference, auditor receipt, clarifications, supplemental versions, open items, owners, due dates, restrictions, and archive location. Also record request closure status.\n\n**Exit criteria**\nPBC release authority provides approval: The request is unambiguous and owned, sensitive handling is defined, duplicates are resolved, and the preparer can produce the requested support from an authoritative source. The response matches the request and authoritative records, reconciliation and handling are evidenced, and differences or limitations are explicit for quality review. An approver authorizes the exact package and secure delivery is evidenced, or the request remains held with specific revision or escalation requirements. The authorized reviewer accepts a complete request trail and accurate status; closure evidences request handling and does not imply auditor acceptance of management’s broader controls.","kind":"task","label":"Approve PBC request closure","requiredApprovals":1},"id":"pbc-request-closure"}],"sourceTemplateId":"workflow-library:sox-external-audit-pbc-request"}
