{"description":"Runs on an Audit item created for the cycle (audit_type internal or sox_testing; scope = \"Annual fraud risk assessment & anti-override review FYxx\"; period_start/period_end = the assessed period). The workflow instance attaches to that Audit, which is the cycle's durable record - a fresh Audit per cycle keeps successive years separable; the workflow enriches it, it does not create a duplicate. Covers the fraud triangle across fraudulent reporting, asset misappropriation, and corruption, the explicit assessment of management override risk, anti-override control recalibration (journal-entry review criteria and significant-estimates scrutiny), and audit committee reporting. Consumes upstream: the prior-period fraud risk register (Risk items, category financial_reporting, with their inherent_rating/residual_rating/treatment and dispositions) as the baseline; the SOX-scoped Process population; in-period Issue signals (deficiencies, findings); and the existing Control inventory - specifically the journal-entry-review and significant-estimates-challenge Control items whose description/frequency/control_owner hold the current criteria. In scope: the current SOX-scoped entity and process population, judged against the prior-period baseline; an event-triggered refresh scopes to the affected entities and fraud vectors, not automatically the whole map. No upstream workflow feeds this cycle - it originates from the prior-period assessment and interim events since. Named deliverable: the fraud risk assessment report and the audit committee package (fraud risk register, heat map, the explicit management-override determination, and the recalibrated anti-override control specification). Hands off to the journal-entry-review and significant-estimates control operators, who run the recalibrated anti-override controls; accepted residual risks persist as Risk items (treatment accept) that seed the next annual cycle's baseline.","edges":[{"id":"e-evaluate-management-override-risk-expand-anti-override-testing-scope","label":"Elevated risk","source":"evaluate-management-override-risk","target":"expand-anti-override-testing-scope","whenValue":"elevated_risk"},{"id":"e-evaluate-management-override-risk-calibrate-anti-override-controls","label":"Standard risk","source":"evaluate-management-override-risk","target":"calibrate-anti-override-controls","whenValue":"standard_risk"},{"id":"e-expand-anti-override-testing-scope-calibrate-anti-override-controls","source":"expand-anti-override-testing-scope","target":"calibrate-anti-override-controls"},{"id":"e-calibrate-anti-override-controls-report-to-audit-committee","source":"calibrate-anti-override-controls","target":"report-to-audit-committee"},{"id":"e-report-to-audit-committee-close-and-archive","label":"Accepted","source":"report-to-audit-committee","target":"close-and-archive","whenValue":"accepted"},{"id":"e-report-to-audit-committee-strengthen-mitigations-and-resubmit","label":"Additional mitigation required","source":"report-to-audit-committee","target":"strengthen-mitigations-and-resubmit","whenValue":"additional_mitigation_required"},{"id":"e-strengthen-mitigations-and-resubmit-close-and-archive","source":"strengthen-mitigations-and-resubmit","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-RISK-12"],"department":"finance","domains":["sox"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=sox-fraud-risk-assessment-anti-override-control-review","contentDigest":"sha256:daf2307624b2d1e52a35c50bcb6da717b62f88d54bb41beff571bb9a29757587","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:daf2307624b2d1e52a35c50bcb6da717b62f88d54bb41beff571bb9a29757587","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-fraud-risk-assessment-anti-override-control-review"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"sox-fraud-risk-assessment-anti-override-control-review","source":"coworkcanvas-gallery","standards":["sox","coso-ic","soc2"],"teams":["finance","executive"]},"name":"Fraud Risk Assessment & Anti-Override Control Review","nodes":[{"data":{"decisionField":"override_risk_rating","description":"Resolve the question SOX Section 404 and COSO Principle 8 require answering explicitly: is the risk of management override of controls elevated this period, and does it warrant expanded journal-entry and estimates testing before the anti-override controls are recalibrated? The Corporate Controller owns the call — with the standing caveat that management rating its own override risk is inherently conflicted, which is why the rationale must be evidence-cited and the audit committee reviews it later in this workflow.","formData":{"fields":[{"key":"override_risk_rating","label":"Management override risk rating","options":[{"label":"Elevated override risk","value":"elevated_risk"},{"label":"Standard override risk","value":"standard_risk"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nResolve the question SOX Section 404 and COSO Principle 8 require answering explicitly: is the risk of management override of controls elevated this period, and does it warrant expanded journal-entry and estimates testing before the anti-override controls are recalibrated? The Corporate Controller owns the call — with the standing caveat that management rating its own override risk is inherently conflicted, which is why the rationale must be evidence-cited and the audit committee reviews it later in this workflow.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe current SOX-scoped in-scope process population — Process items (process_type: financial_reporting, ACTIVE) — and the cycle scope (annual, or an event-triggered refresh) recorded on the anchor Audit item's scope field. There is no legal-entity type; entity names ride inside the register descriptions and the memos below.\n- The prior-period fraud risk register — the prior cycle's Risk items (category: financial_reporting) with their inherent_rating, residual_rating, and treatment, plus the prior cycle's archived report document.\n- Internal audit findings and control deficiencies — Issue items (source: internal_audit / sox_testing / management_identified; issue_type: deficiency / finding). Hotline case themes and any actual fraud or near-miss since the prior assessment have no native type — upload them as PBC evidence at this step.\n- A scheme reference taxonomy — the ACFE occupational fraud tree and the COSO/ACFE Fraud Risk Management Guide scheme libraries are the standard starting points (external reference, cited in the memo).\n\nthe source data below lives in external systems (HR/comp, treasury, FP&A) and is uploaded as PBC evidence at this step; the AssureSwarm record is the memo built from it.\n- Compensation plan structures for executives and finance leadership: bonus metrics, equity vesting conditions, and which reported figures they key on (EPS, revenue, EBITDA, covenant ratios).\n- Debt agreements with covenant computation sheets; analyst guidance and public earnings commitments; budget-versus-actual by entity for the period.\n- The fraud-scheme register — the Risk items created at evaluate-management-override-risk; pressure is scored against concrete schemes, not in the abstract.\n- Prior-period incentive ratings from the prior cycle's memo for movement comparison.\n\nThe segregation-of-duties matrix and current system access listings for the GL and sub-ledgers (journal-entry posting, approval-limit maintenance, vendor/customer master changes, period open/close authority) — these come from external systems (ERP/IAM) and are uploaded as PBC evidence at this step.\n- The fraud-scheme register — the Risk items from evaluate-management-override-risk with their Process links.\n- Prior audit findings and SOD exceptions — Issue items (source: internal_audit / sox_testing) — and reconciliation exception history.\n- The close calendar and estimate governance: who prepares and who challenges each significant estimate (from the estimates register PBC upload).\n\nthe culture signals below come from external systems (hotline vendor, HR) and are uploaded as PBC evidence at this step.\n- Whistleblower hotline statistics for the period: volume, category mix, substantiation rate, and financial-reporting themes, with prior-period comparison (under SOX Section 301 the hotline is the audit committee's own instrument — its data is first-order evidence here).\n- Ethics and engagement survey results, exit-interview themes, code-of-conduct violation and discipline records.\n- Management's track record on prior findings — remediation velocity, tone of pushback, any past override instance and its consequence — traceable to the prior cycle's Issue items and memos.\n- Turnover in fiduciary and oversight roles: controllers, internal audit, compliance.\n\n*Agent retrieval, preparation and filing absorb “Compile fraud scheme inventory”, “Assess incentives and pressures”, “Assess opportunities and override capability”, “Assess rationalizations and culture”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Compile fraud scheme inventory: Build an entity-mapped inventory of plausible fraud schemes across all three categories — fraudulent financial reporting, asset misappropriation, and corruption — so the fraud-triangle assessment scores concrete schemes rather than abstract categories.\n\n2. Seed the library from the taxonomy, then localize. Fraudulent reporting: revenue manipulation (bill-and-hold, channel stuffing, side agreements), improper reserves and cookie-jar releases, biased estimates, improper capitalization of expenses, disclosure omission. Asset misappropriation: billing schemes and fictitious vendors, ghost employees, expense-reimbursement abuse, cash skimming and larceny, inventory theft. Corruption: bribery and kickbacks in vendor or customer relationships, undisclosed conflicts of interest, related-party arrangements.\n3. Map every scheme to the specific entities, processes, accounts, and financial-statement assertions it would touch. A scheme with no plausible mechanism at an entity is dropped with a written reason — COSO Principle 8's points of focus require considering all types of fraud, then documenting why any is implausible, not skipping it silently.\n4. Weight by base rates: per the ACFE Report to the Nations, asset misappropriation appears in roughly nine of ten occupational fraud cases but carries the smallest median loss, while financial statement fraud appears in about one in twenty with a median loss an order of magnitude larger. So reporting schemes get depth of analysis; misappropriation gets breadth of coverage; corruption (about half of cases) rides on procurement and sales relationships.\n5. Add what no taxonomy can know: schemes enabled by this organization's specific system gaps, manual workarounds, and recent reorganizations, plus any pattern from in-period incidents, hotline cases, or prior internal audit findings.\n6. Run the completeness cross-check: every in-scope entity and process has at least one mapped scheme or a documented no-plausible-scheme rationale. Flag uncovered entities and processes for the Controller — silence is the failure mode, not over-inclusion.\n\n7. Assessment scope for Assess incentives and pressures: Score the incentive-and-pressure leg of the fraud triangle for each in-scope entity, identifying where compensation design, financial targets, and external commitments concentrate motive on people who can influence reported results.\n\n8. Trace each compensation metric to the accounts and estimates that feed it, and to the individuals who both carry the metric and can influence those accounts. The classic flag is an executive whose bonus vests on a figure they can move with a late journal entry or an assumption change. Note cliff structures: all-or-nothing vesting at a threshold generates sharper pressure than a linear payout curve.\n9. Compute covenant headroom: a ratio within roughly 10–15% of its limit at a measurement date is a live pressure point on exactly the accounts inside the ratio — EBITDA add-backs, working-capital classifications, reserve levels. Apply the same logic to guidance: a quarter tracking just below consensus is pressure on revenue cutoff and reserve releases.\n10. Layer external pressure where visible: industry downturn against entity growth targets, refinancing needs, liquidity constraints, and earn-out measurement periods (an earn-out is direct pressure on whoever controls the measured results).\n11. Score each entity on the organization's scale (low/moderate/high or 1–5) with evidence cited. The score reflects proximity of motive to capability: high pressure on someone who cannot touch the ledger scores lower than moderate pressure on the person who closes it.\n12. Compare to the prior period and explain every movement — an unexplained rating drop is the first thing a reviewer or external auditor challenges.\n\n13. Assessment scope for Assess opportunities and override capability: Score the opportunity leg of the fraud triangle per entity and name, specifically, every role with the practical ability to override a control — the structural map both the override-risk determination and the anti-override calibration consume.\n\n14. Pull conflicting-duty combinations from the SOD matrix — initiate+approve, record+reconcile, custody+record — then verify against actual provisioned access, not role design; provisioning drifts from the matrix. Prioritize combinations that enable a mapped scheme: an SOD conflict with no scheme attached is an access finding, not a fraud opportunity.\n15. Build the override-capability roster — the people who can defeat a control with authority rather than evade it: direct GL posting outside workflow approval, ability to raise or bypass approval limits, unilateral authority over significant estimates and judgmental accruals, super-user or firefighter access to financial systems, authority to open or close ledger periods, and authority to instruct subordinates to post entries (capability by hierarchy, which never appears in access data). This roster is why COSO Principle 8 and the external auditor's AS 2401 presumption exist: senior management can usually override whatever the design says.\n16. Map the thin-oversight terrain: significant estimates and judgmental accruals, one-off and non-routine transactions, related-party arrangements, top-side consolidation entries, and any process where the preparer's work receives no independent challenge. Cross-reference to prior audit and reconciliation exceptions in the same terrain — repeat exceptions mark real gaps, not hypothetical ones.\n17. Rank exposures by capability breadth times the severity of the schemes enabled, and score opportunity per entity. An entity with clean SOD but one person holding all estimate authority can still score high.\n18. Compare to prior period: access remediation completed since the last assessment should show as movement, or the remediation claim is suspect.\n\n19. Assessment scope for Assess rationalizations and culture: Score the rationalization leg of the fraud triangle per entity from observable culture signals, and pinpoint where all three legs converge on the same roles — the convergence map that drives the override-risk determination next.\n\n20. Read hotline data in both directions: rising volume can mean rising misconduct or rising trust, but a near-zero report rate in a sizeable entity is itself a red flag — ACFE data consistently shows tips as the leading fraud detection method, so silence usually means fear or futility, not purity. Weight substantiated financial-reporting allegations heaviest.\n21. Score tone-at-the-top from behavior, not policy text: were control breaches by senior people sanctioned like junior ones; did management remediate findings or negotiate them down; has anyone been promoted or paid out shortly after cutting a corner. A single unsanctioned override in the record moves rationalization up a notch by itself — it teaches the organization that overrides are survivable.\n22. Mine attrition: clustered departures in finance and accounting, exit-interview themes of pressure to make numbers, and oversight roles left vacant or downgraded for extended periods.\n23. Overlay the triangle: cross-reference these signals against the incentive and opportunity maps and mark every role and entity where all three legs are elevated. Those convergence entries are what the override decision will cite.\n24. Score per entity with citations, and state the data's limits explicitly — culture scored from artifacts alone understates risk, which is exactly why the Controller's qualitative judgment is recorded as a distinct input rather than silently blended in.\n\n25. Assessment scope for Evaluate management override risk: Resolve the question SOX Section 404 and COSO Principle 8 require answering explicitly: is the risk of management override of controls elevated this period, and does it warrant expanded journal-entry and estimates testing before the anti-override controls are recalibrated? The Corporate Controller owns the call — with the standing caveat that management rating its own override risk is inherently conflicted, which is why the rationale must be evidence-cited and the audit committee reviews it later in this workflow.\n\n\n\nThe call rests on the synthesis built in this step: combine the incentive, opportunity, and rationalization ratings per entity, flagging every entity where all three legs are individually elevated; evaluate the two vectors SOX and COSO treat as primary — journal entries and significant estimates — citing current journal-entry approval thresholds, estimate governance, and any override instance in the prior period (these are the same vectors AS 2401 presumes and obliges the external auditor to test, so the external audit will re-perform this logic); and compare against the prior-period rating, naming the driver of any movement. The Controller weighs the synthesis together with what the data cannot show — recent governance changes, board composition, known pressure events — and the synthesis memo recommending a rating is attached before the form is submitted.\n\n- **Elevated override risk (`elevated_risk`)** — select when any of the following holds: the convergence table has entries (an entity with all three fraud-triangle legs elevated over override-capable processes); an actual override instance, substantiated financial-reporting allegation, or unexplained top-side entry occurred in-period; an executive with direct posting or estimate authority has compensation or covenant compliance keyed to a metric they can move; estimate history shows one-directional bias toward targets; or a prior-period elevated rating whose driving conditions are not demonstrably resolved. Routes to expanded journal-entry and estimates testing before calibration.\n- **Standard override risk (`standard_risk`)** — select when the convergence table is empty, no in-period override instance or substantiated allegation exists, journal-entry approval and estimate challenge operated without exception, and any movement from prior period is toward lower exposure with documented drivers. Standard is not zero: AS 2401 treats override as a presumed risk precisely because it can never be ruled out — this branch sets testing depth only, and the baseline anti-override controls still proceed to recalibration.\n\n**Record in AssureSwarm**\nItem create — one Risk item per scheme (this is the fraud-scheme register): category: financial_reporting, description carrying the scheme narrative plus its affected accounts, assertions, and entity names, and risk_owner where known. Leg ratings and the combined risk are set later at report-to-audit-committee.\n- Item relationship — link each Risk item to the Process items it touches (Risk ↔ Process). Entities not modelled as Process items are named in the description and the inventory summary.\n- Step document — attach the inventory summary with the coverage cross-check and the dropped-scheme rationale list (PDF/XLSX on this step).\n\nStep document — attach the incentives-and-pressures memo (DOCX/PDF on this step): per-entity incentive/pressure scores, the metric-to-account trace, covenant and guidance headroom calculations, and data citations. Risk carries no per-leg fraud-triangle field, so the leg score lives in this memo and in Risk.description, not a native field.\n- Step document — the Controller's qualitative adjustments — management-team dynamics, recent compensation changes, informal targets the data cannot surface — are recorded in the same memo's rating table as attributed inputs, with the final rating per entity.\n\nStep document — attach the opportunity-and-override-capability memo (on this step): the ranked override-capability roster, the thin-oversight map, and per-entity opportunity scores. The roster has no native type, so it lives in this memo; each roster line names the scheme(s) it enables by reference to their Risk items.\n- Item relationship — link each mapped scheme's Risk item to the Process items whose override exposure enables it (Risk ↔ Process); role-level capability that is not a Process item is cross-referenced in the memo, not linked.\n- Step document — the Controller's corrections — manual workarounds and system gaps known from experience but absent from access data — are added to the memo before scores are finalized.\n\nStep document — attach the rationalization-and-culture memo (on this step): per-entity scores, hotline/survey/discipline/attrition citations, and the three-leg convergence table. This leg score, like the other two, has no native Risk field and lives in the memo and Risk.description.\n- Step document — the Controller's tone-at-the-top judgment is documented in the same memo as an attributed input alongside the data-derived score.\n\nStep form — submit the decision form: `override_risk_rating` (the branch), the step result citing the deciding entities, convergence entries, and evidence documents, and the step's approver record.\n- Step document — attach the override-risk synthesis memo — per-entity leg ratings, the journal-entry and estimates vector evaluation, and the prior-period comparison with movement drivers — before submitting.\n\n**Exit criteria**\nEvery in-scope entity and process is covered by mapped schemes or a documented exclusion; all three fraud categories represented; schemes from in-period incidents and prior findings incorporated; the Controller has confirmed completeness — including entity-specific and emerging schemes the library missed — before triangle scoring begins. Every in-scope entity has an incentive/pressure rating tied to cited evidence; every compensation metric is traced to the accounts it can be moved through; covenant and guidance headroom quantified; period-over-period movement explained; ratings ready to overlay against opportunity and rationalization. Override-capability roster complete with named roles and the mechanism for each (system access, hierarchy, or estimate authority); every roster line linked to the schemes it enables; per-entity opportunity ratings recorded with evidence; access verified against provisioned reality, not role design alone. Every in-scope entity has a rationalization rating with cited evidence; hotline, survey, discipline, and attrition signals each dispositioned; the convergence table names every role and entity where all three triangle legs are elevated; the fraud-triangle evaluation is complete and ready for the override determination. Form submitted with a rationale that names the deciding entities and evidence rather than restating the label; synthesis memo attached; movement versus prior period explained; the unused branch is prunable.","kind":"decision","label":"Evaluate management override risk","performedBy":{"note":"","primitives":["coach-query-data","coach-document-upload","coach-item-create","coach-items-link"]}},"id":"evaluate-management-override-risk"},{"data":{"description":"Agent extends journal-entry and significant-estimates testing depth for elevated-risk entities with lowered thresholds and broader sampling; human reviews expanded findings","instructions":"**Objective** — For the entities behind the elevated rating, deepen journal-entry and significant-estimates scrutiny beyond the baseline so the anti-override recalibration responds to observed behavior, not ratings alone — and surface anything that must escalate before the cycle's normal reporting date.\n\n**Inputs**\n- The override-risk decision, its rationale, and the named elevated entities and roles.\n- The complete journal-entry population for those entities for the period — every entry, not post-threshold survivors — with poster, approver, timestamps, source, and line detail.\n- The significant-estimates register: methodology, assumptions, preparer and challenger, prior-period values and actual outcomes.\n- The override-capability roster from the opportunity step (the screens target those roles).\n\n**Procedure**\n1. Screen the complete journal-entry population at lowered thresholds using the AS 2401 characteristics: entries to seldom-used, unrelated, or suspense/intercompany accounts; entries by people who rarely post or by override-capable roles; period-end and post-close entries with thin or missing description or support; round-dollar amounts; amounts just below approval thresholds (threshold-shaving); weekend and after-hours postings; and top-side entries recorded outside the GL. Run every screen over the whole population — screens are cheap and completeness is the point; record each screen's parameters and hit count.\n2. Run the estimates retrospective: compare each significant estimate's prior-period assumptions to actual outcomes. One-directional misses that consistently favored targets indicate bias, not imprecision — the same look-back AS 2401 requires of the external auditor. Flag any in-period methodology or assumption change lacking a documented business reason, especially one that moved results favorably.\n3. Select the targeted review set judgmentally from the hits: highest-severity flags first, every multi-flag entry, and everything posted by or at the direction of the roles named in the override decision. For each item pull full support: business rationale, approver identity and independence (the approver must not be the poster or report to the poster), timing relative to period-end, and whether the entry reversed after close.\n4. Disposition every reviewed item explicitly: supported, error, or override-characteristics. Override-characteristics means a control's intent was defeated by authority rather than by mistake — and an authority-based explanation (\"the CFO said to book it\") is a finding attribute, not support.\n5. Escalate immediately — to the audit committee chair and, where warranted, General Counsel — any item with override characteristics or intentional-misstatement indicia. AS 2401 and SOX Section 301 both assume fraud indications move at once, not at the scheduled reporting step.\n\n**Record in AssureSwarm**\n- Item create — for each item dispositioned override-characteristics, create an Issue: issue_type: finding, severity: high or critical, source: sox_testing, identified_date, issue_owner, and a description naming the control defeated and the authority used. Link it to the anchor Audit and the affected Control (Issue ↔ Audit, Issue ↔ Control).\n- Step document — attach the screen definitions and parameters, hit counts per screen, the targeted review set with per-item dispositions, and the estimates retrospective (XLSX/PDF on this step).\n- Step document — record any immediate escalation in the findings memo with date, recipient, and item.\n\n**Exit criteria** — Every screen run over the complete elevated-entity population with parameters recorded; estimates retrospective complete with a bias conclusion per estimate; every targeted item dispositioned supported/error/override-characteristics; escalations actioned same-day and documented; findings packaged for the calibration step.\n\n> **⚡ Audit Artist accelerator:** `/sox-python` — runs the lowered-threshold journal-entry screens (after-hours, round-dollar, threshold-shaving, seldom-used accounts) deterministically over the full population, reproducible in a Procedure tab.","label":"Expand anti-override testing scope","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload","sox-python"]}},"id":"expand-anti-override-testing-scope"},{"data":{"description":"Agent proposes updated journal-entry review criteria and significant-estimates review precision based on the current risk rating; human sets the final thresholds","instructions":"**Objective** — Reset the two anti-override controls — journal-entry review criteria and the significant-estimates challenge protocol — to a precision proportionate to this cycle's override-risk rating, with the capture-rate impact of every threshold change quantified before it is set.\n\n**Inputs**\n- The current journal-entry review policy: materiality thresholds, mandatory-review criteria, approver-independence rules.\n- The current significant-estimates review protocol: which estimates require independent challenge, the challenger's required independence, and the documentation precision expected.\n- The override-risk rating and rationale, plus the expanded-scope findings if the elevated branch ran.\n- A recent representative period's journal-entry and estimates population for impact modeling.\n\n**Procedure**\n1. Rebase journal-entry criteria on evidence: if expanded testing flagged entries below the current mandatory-review threshold, that threshold is demonstrably too high — set the new one below the observed pattern, not marginally under the old line. Where risk concentrates in behavior rather than size, add criteria instead of lowering thresholds: mandatory review for post-close entries, for entries by override-capable roles regardless of amount, and for all top-side entries (top-side entries warrant a 100% review rule at any rating — they are the canonical override vehicle).\n2. Verify approver independence structurally: the reviewer of an entry posted by or at the direction of a senior officer cannot report to that officer. Where the hierarchy makes that impossible — CFO-directed entries — route the review to internal audit or the audit committee's designee. This is the one calibration decision a threshold cannot solve.\n3. Reset the estimates protocol: every estimate whose retrospective showed bias, or whose methodology changed in-period, gets independent challenge at the next close, not next year. Challenge documentation must state the challenger's own expectation and the tolerance around it — \"reviewed, agreed\" is not evidence of challenge.\n4. Model each proposed change against the recent period's population: entries and estimates captured now versus proposed, and incremental review hours at realistic minutes-per-item. Precision the review team cannot execute produces checkbox review — worse than an honestly wider threshold, because it manufactures false assurance. Present two or three calibration options with the capture-versus-burden trade-off quantified.\n5. Write the specification: thresholds and criteria, effective date, entities in scope, the named control owners for journal-entry review and estimates challenge, and a standing rule that mid-period threshold changes require documented approval — the anti-override control must itself resist quiet loosening.\n\n**Record in AssureSwarm**\n- Item field update — update the two anti-override Control items (journal-entry review, significant-estimates challenge): Control.description with the new thresholds/criteria and effective date, Control.frequency, and Control.control_owner, so the live control record carries the calibration.\n- Step document — attach the updated anti-override control specification and the capture-rate impact model (DOCX + XLSX on this step).\n- Step document — record prior-versus-new thresholds and criteria in the specification's change table so the audit committee and the external auditor can see exactly what moved and why.\n\n**Exit criteria** — Final thresholds and criteria set by the Controller with the impact model attached; approver-independence routing resolved including the senior-officer case; biased or changed estimates assigned independent challenge at the next close; effective date and named control owners recorded; the change table complete.\n\n> **⚡ Audit Artist accelerator:** `/sox-python` — models each proposed threshold change against the recent period's journal-entry and estimates population, quantifying capture-rate and review-burden impact reproducibly.","label":"Calibrate anti-override controls","performedBy":{"primitives":["coach-query-data","coach-item-update","coach-document-upload","sox-python"]}},"id":"calibrate-anti-override-controls"},{"data":{"decisionField":"audit_committee_outcome","description":"Put the refreshed fraud risk assessment and anti-override calibration in front of the audit committee for the oversight decision only it can make — the committee is the one control positioned above the executives the override analysis is about — and record whether it accepts the assessment or directs further mitigation. The Controller presents; the committee owns the outcome.","formData":{"fields":[{"key":"audit_committee_outcome","label":"Audit committee outcome","options":[{"label":"Accepted","value":"accepted"},{"label":"Additional mitigation required","value":"additional_mitigation_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nPut the refreshed fraud risk assessment and anti-override calibration in front of the audit committee for the oversight decision only it can make — the committee is the one control positioned above the executives the override analysis is about — and record whether it accepts the assessment or directs further mitigation. The Controller presents; the committee owns the outcome.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe fraud-scheme register items and the three leg-rating memos.\n- The override-risk determination and, if the elevated branch ran, the expanded-testing dispositions.\n- The recalibrated anti-override control specification with its change table.\n- The control inventory — the preventive and detective controls available to map as mitigations.\n- The prior-period register for the movement comparison.\n\n*Agent retrieval, preparation and filing absorb “Document fraud risk register”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Document fraud risk register: Produce the documented fraud risk assessment record that SOX Section 404 and COSO Principle 8 require: every scheme rated on all three triangle legs, tied to named mitigating controls, with residual risk computed and movement from the prior period explained.\n\n2. Complete the register entry for each scheme: fraud category, affected entities and processes, the incentive, opportunity, and rationalization ratings, and combined inherent risk scored as likelihood times significance per the COSO/ACFE Fraud Risk Management Guide convention — significance includes legal and reputational exposure, not just misstatement size.\n3. Map mitigating controls per scheme as specific named controls, never control families. \"Management review\" cannot mitigate a scheme whose actor is management: schemes tied to the override-capability roster may cite only controls that operate independently of the actor — audit committee oversight, internal audit procedures, the recalibrated journal-entry review with independent approver routing.\n4. Compute residual risk from control strength honestly: a control with open deficiencies or in-period exceptions mitigates less than its design says. Every high-residual scheme needs an explicit disposition — accept (named acceptor plus interim monitoring), mitigate further (tracked action), or transfer where insurance genuinely responds.\n5. Build the heat-map dashboard plotting inherent and residual risk by entity and fraud category, so concentration is visible at a glance.\n6. Run the prior-period diff: new schemes, retired schemes (retired because the mechanism is gone — never because nothing happened), and every rating movement with its driver.\n7. Assemble the fraud risk assessment report: methodology and population, fraud-triangle findings, the explicit override determination and testing performed, the recalibrated anti-override set with its change table, the full register, and the residual-risk acceptance list. External audit tests management's Principle 8 conclusion against this document — write it to be tested.\n\n8. Assessment scope for Report to audit committee: Put the refreshed fraud risk assessment and anti-override calibration in front of the audit committee for the oversight decision only it can make — the committee is the one control positioned above the executives the override analysis is about — and record whether it accepts the assessment or directs further mitigation. The Controller presents; the committee owns the outcome.\n\n\n\nThe committee decides on the package assembled in this step: an executive summary of the fraud-triangle findings; the explicit override determination with its evidence and any expanded testing and dispositions; the recalibrated anti-override specification with the prior-versus-new change table and capture impact; the full register and heat map; the residual-risk acceptance list; and the comparison to the prior period including interim events already reported to the committee. Prepare discussion points for the committee's likely lines — the basis for the override rating, the adequacy of the recalibrated thresholds, items escalated during expanded testing, and hotline themes under its SOX Section 301 remit — and a minutes template to complete after the meeting. Anything escalated mid-cycle must already have reached the chair; the meeting confirms handling — it is never where the committee first learns of an override finding.\n\n- **Accepted (`accepted`)** — the committee concurs that the scope, the override rating and its basis, the recalibrated thresholds, and the residual-risk acceptances are adequate as presented. Questions answered in-meeting from existing evidence, or clarifications that change no rating, threshold, or acceptance, still land here — record them in the minutes as discussion, not directives.\n- **Additional mitigation required (`additional_mitigation_required`)** — the committee directs substantive change before it will accept: a rating it finds understated, thresholds it finds too loose, a residual acceptance it refuses, additional testing (for example extending the journal-entry screens to an entity rated standard), or a new mitigation or control. Capture each directive verbatim with owner and expected completion date — the strengthen-mitigations step executes from that list, and vague minutes make closure unverifiable.\n\n**Record in AssureSwarm**\nItem field update — complete each Risk item created at evaluate-management-override-risk (do not create duplicates): likelihood, impact, inherent_rating, residual_rating, treatment (mitigate / accept / transfer), and risk_owner. The per-leg incentive/opportunity/rationalization scores stay in the leg memos and Risk.description — there is no native per-leg field.\n- Item relationship — link every Risk item to its named mitigating Control items (Risk ↔ Control), and link the supporting evidence documents to the Risk items they support.\n- Dashboard — publish the fraud risk heat-map plotting inherent_rating × residual_rating by entity and fraud category.\n- Step document — attach the fraud risk assessment report (PDF on this step).\n\nStep form — submit the decision form: `audit_committee_outcome` (the branch), the step result summarizing the committee's basis with reference to the minutes, and the step's approver record (the committee chair or delegate).\n- Item export — export the fraud risk register extract (the Risk items, CSV/XLSX) for the package.\n- Step document — attach the issued committee package (the fraud risk assessment report and its exhibits) and the completed minutes capturing questions, responses, and each directive verbatim.\n\n**Exit criteria**\nEvery scheme carries three leg ratings, inherent and residual risk, and at least one named actor-independent mitigating control or an explicit acceptance with a named acceptor; heat map published; prior-period movement explained; the Controller has confirmed completeness and finalized the report for committee delivery. Presentation delivered; form submitted with the committee's actual basis rather than a restated label; issued package and minutes attached; if additional mitigation was directed, every directive is captured verbatim with owner and due date; the unused branch is prunable.","kind":"decision","label":"Report to audit committee","performedBy":{"note":"","primitives":["coach-export-package","coach-document-upload","coach-render-package","coach-item-create","coach-item-update","coach-items-link","coach-dashboard-create","coach-query-data"]}},"id":"report-to-audit-committee"},{"data":{"description":"Agent tracks each committee-directed action to completion and updates the risk register and control calibration; human confirms readiness before closure","instructions":"**Objective** — Convert every audit committee directive into a tracked, evidenced action and close all of them — the cycle cannot complete while any directive is open, and closure is confirmed by the committee chair or delegate, not by management alone.\n\n**Inputs**\n- The committee minutes with each directive verbatim, its owner, and its due date.\n- The decision-form rationale from the reporting step.\n- The current register, the anti-override specification, and — where directives touch testing — the expanded-scope method and outputs.\n\n**Procedure**\n1. Create one action item per directive, never bundled — bundled directives get partially closed and wholly reported as done. Each carries the directive text verbatim, the affected register entry or control, the owner, and the due date.\n2. Execute by directive type: threshold changes re-run the capture-impact model and re-issue the specification with a new change-table row; additional testing runs under the expanded-scope method (full-population screens, explicit per-item dispositions); rating changes update the register entry and recompute residual risk; a refused residual acceptance gets an actual mitigation, not a re-worded acceptance.\n3. Chase to completion: dated reminders to owners before due dates, escalation to the CFO for stalled items. A committee directive aging past due is itself reportable to the chair.\n4. Evidence each closure — what changed, where the artifact lives, completion date — to the standard that the chair's delegate can verify closure from the evidence alone, without asking anyone.\n5. Assemble the resubmission summary, one row per directive (directive, action taken, evidence, date), and obtain the chair's or delegate's written confirmation that no open item remains. Whether that confirmation happens between meetings or at the next scheduled one is the chair's call, not management's.\n\n**Record in AssureSwarm**\n- Item create — one Issue per committee directive (never bundled): issue_type: observation, source: management_identified, issue_owner, target_remediation_date, and actual_remediation_date set on closure; description carrying the directive verbatim.\n- Item relationship — link each Issue to the Risk and/or Control items its directive modifies (Issue ↔ Risk, Issue ↔ Control).\n- Step document — record the reminder and escalation trail as it happens.\n- Step document — attach the re-issued specification or revised register extract for any directive that changed them, plus the resubmission summary and the chair/delegate confirmation.\n\n**Exit criteria** — Every directive has a closed action item with verifiable evidence; the register and specification reflect all directed changes; any committee-requested testing re-run and dispositioned; the chair's or delegate's confirmation attached; zero open items.","label":"Strengthen mitigations and resubmit","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-workflow-scan","coach-query-data","coach-document-upload","coach-notify"]}},"id":"strengthen-mitigations-and-resubmit"},{"data":{"description":"Hand the approved control specification to its operating owners, then archive the cycle and schedule its monitoring obligations.","instructions":"**Objective** — Freeze the completed cycle as the evidence record internal and external audit will test, hand the recalibrated anti-override controls to their operators, and set the baseline and tripwires that determine when the next assessment runs.\n\n**Inputs**\n- The finalized register, override determination, anti-override specification (as amended by any committee directives), committee package, minutes, and directive-closure evidence.\n- The accepted-residual-risk list with named acceptors and monitoring expectations.\n- The next annual assessment's scheduled date and the standing event-trigger list.\n\n**Procedure**\n1. Export the complete cycle record — register, determination and rationale, specification with change table, committee package and minutes, directive closures — and archive it in the designated evidence repository under the organization's SOX evidence retention schedule (seven years is the standard convention for audit-relevant workpapers). Verify the archive is retrievable by pulling one document back out; the archive confirmation is recorded, and post-archive corrections are new dated addenda — never edits to the archived set.\n2. Make the handoff operational, not an announcement: the journal-entry review and estimates-challenge control owners each acknowledge the new thresholds, criteria, and effective date, and the first close after the effective date is flagged for those owners to confirm the new criteria actually operated. Calibration that never reaches the close checklist is the classic silent failure.\n3. Update the fraud risk assessment log with the cycle's outcome, ratings, and calibration changes — the single line of history internal audit and the external auditor trace when testing control design and operating effectiveness against COSO Principle 8.\n4. Create the carry-forward items: one per accepted residual risk with its interim-monitoring metric, named owner, and check frequency; one for the next scheduled assessment with its date; and the standing event-trigger list (restatement, credible allegation, executive change, acquisition, new incentive plan) with the instruction that any trigger fires an off-cycle refresh — the trigger list is what makes \"annual or event-triggered\" real rather than aspirational.\n5. Send the closure notice to the CFO and audit committee chair: cycle closed, outcome, next assessment date, and where the archive lives.\n\n**Record in AssureSwarm**\n- Workflow instance — export the complete workflow record (the run is the audit trail) and attach the archived-package manifest with its repository location and the archive confirmation (step document).\n- Item field update — on the anchor Audit item, set rating, report_date, and close its status; the anchor Audit is the cycle's durable record.\n- Handoff (step document) — the accepted residual risks are already Risk items (treatment: accept) the next cycle reads directly as its baseline; the interim-monitoring metrics, the next-cycle schedule, and the standing event-trigger list have no native type, so record them as a step document — the handoff package the next annual run's evaluate-management-override-risk consumes — each carry-forward with a named owner.\n- Step document — record the closure notice with recipients and date.\n\n**Exit criteria** — Archive complete, retrievability verified, and confirmation recorded; control-owner acknowledgments of the new specification captured with the first-close check flagged; assessment log updated; carry-forward items created with owners; closure notice sent; the journal-entry and estimates-control owners have accepted the final execution requirements.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-item-update","coach-document-upload","coach-notify"]}},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:sox-fraud-risk-assessment-anti-override-control-review"}
