{"description":"Runs on the existing SOX Audit using approved Control-hosted TOD/TOE results and the interim scope. Produces the program coverage and exception register, remaining-period commitments, all-controls auditor handoff and management status communications for year-end roll-forward.","edges":[{"id":"e-conclusion-coordinate-interim-results","source":"conclusion","target":"coordinate-interim-results"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":[],"controlVerbs":{"UC-AUDIT-13":"operates","UC-AUDIT-21":"tests","UC-AUDIT-25":"operates"},"controls":["UC-AUDIT-13","UC-AUDIT-21","UC-AUDIT-25"],"department":"internal-audit","domains":["sox"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=sox-interim-operating-effectiveness-testing","contentDigest":"sha256:5bd155c018ab3cb785e6499512fb5c53848286349c16be8d9ce1b3a52651c824","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:5bd155c018ab3cb785e6499512fb5c53848286349c16be8d9ce1b3a52651c824","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-interim-operating-effectiveness-testing"},"lifecycleContract":{"absorbedNodeIds":{"attributes":"conclusion","exceptions":"conclusion","population":"conclusion","sample":"conclusion"},"approvalPolicy":"Independent reviewers cannot be the preparer, tester or control owner for the reviewed work. Required approval counts alone do not establish actor independence; verify assignments and exact versions at execution.","bindingRequirements":["Resolve named human roles to actual users and configure native step approvals before execution.","Workstream and Narrative Module are tenant communication/document destinations; verify a supported connector or record manual dispatch by the authorized sender.","EY is the tenant-bound external auditor; preserve its independent methodology and reliance judgments."],"bindingStatus":"requires-tenant-configuration","checkpoints":[{"contribution":"Judge program coverage and aggregate exposure; commit priorities and remaining-period work.","interventions":["expertise","approval"],"nodeId":"conclusion","requiredApprovals":1,"role":"IA/SOX program lead"},{"contribution":"Resolve reliance questions and approve management actions and escalation for interim slippage.","interventions":["expertise","approval"],"nodeId":"coordinate-interim-results","requiredApprovals":1,"role":"IA/SOX lead with external-auditor counterpart"}],"version":1},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"sox-interim-operating-effectiveness-testing","source":"coworkcanvas-gallery","standards":["coso-ic","iia-2024","iso-27001","nist-800-53","soc2","sox"],"teams":["internal-audit","finance"]},"name":"Interim Operating Effectiveness Testing","nodes":[{"data":{"instructions":"**Objective** — Approve interim program coverage, aggregate exceptions and remaining-period commitments from the Control-hosted test results.\n\n**Human contribution** — IA/SOX program lead (expertise, approval): Judge whether completed controls cover the approved program and commit corrective priorities for gaps and aggregate exposure. Assign this role to native approval and record the reviewed register version; detailed independent test approval remains at sox-key-control-tod-toe-test/reviewer-sign-off.\n\n**Inputs** — The approved in-scope control list and annual calendar; exact-version TOD approvals at sox-key-control-tod-toe-test/confirm-design-effectiveness; published results, workpapers, Control Impact Assessments and management responses at sox-key-control-tod-toe-test/execute-attribute-testing; independent approvals at sox-key-control-tod-toe-test/reviewer-sign-off. Missing or pending packages remain visible in the register and prevent a claim of completed control coverage.\n\n**Procedure**\n*Program preparation absorbs “Select and Document Sample” and “Test Control Attributes”; the Control-hosted workflow owns the detailed procedures and their approvals.*\n1. Build the Interim Program Results Register: one row for every in-scope control/version/period, with links to its test instance, published results, TOD and reviewer approvals, clean or exception conclusion, completion status and interim cutoff. Reconcile planned, completed and reviewed totals. Keep incomplete, failed-design, version-mismatched and unapproved controls explicit.\n2. Consume the approved sample/population basis and attribute conclusions by reference. Sampling, IPE validation, attribute execution, expansion and independent evidence review occur only in the detailed Control workflow. Route missing or unsupported results to that producer for correction; this checkpoint does not select samples, retest attributes or reapprove individual control conclusions.\n3. Compare Control Impact Assessments across controls for common causes, shared systems, affected accounts/assertions, uncovered periods and compensating-control dependencies. Hand related deficiency packages to sox-deficiency-aggregation-evaluation/evaluate-severity-by-group. Record whether that downstream assessment is pending or available; do not describe unassessed aggregate exposure as cleared.\n4. Carry management feedback and disputed facts from the detailed test records into the program register. Link sox-deficiency-remediation action commitments where available. The program lead decides escalation and corrective priorities for incomplete controls, aggregate exposure and overdue evidence/reviews.\n5. Set remaining-period coverage by control/version, including changed controls, annual occurrences, remediation retests, dates and accountable owners. Preserve all limitations. Approve the exact program register and commitments through native approval before the external-auditor handoff.\n\n**Record in AssureSwarm** — Attach the Interim Program Results Register and aggregate exposure/remaining-period plan to conclusion; put source instance/version links, reconciliation, priorities, owners and unresolved dependencies in the step result. Keep test results and test approvals on their producing Control steps.\n\n**Exit criteria** — Every in-scope control is represented with an approved source conclusion or an explicit incomplete status; counts reconcile, aggregate exposure is assessed or assigned, and the program lead has approved coverage gaps, corrective priorities and dated remaining-period commitments.\n","kind":"task","label":"Record Interim Testing Conclusion","requiredApprovals":1},"id":"conclusion"},{"data":{"instructions":"**Objective** — Agree external-auditor reliance and management actions from the complete interim results.\n\n**Human contribution** — IA/SOX lead with external-auditor counterpart (expertise, approval): Resolve reliance questions and approve management actions and escalation for interim slippage. Assign the named role to this step’s native approval before execution; the executor cannot satisfy an independent review role. Record the reviewed version and decision in the native approval and step result.\n\n**Inputs** — The approved Interim Program Results Register from conclusion, all in-scope controls, exception/deficiency register, PBC aging and the annual reliance strategy.\n\n**Procedure**\n1. Prepare the all-controls interim-results handoff for the external auditor, including clean results, exceptions, tests not complete or not approved, control/version/period coverage, population/sample basis, workpaper links, open questions and planned year-end work. Reconcile totals to the in-scope control list so clean results cannot disappear from a deficiency-only report.\n2. The IA/SOX lead and external-auditor counterpart discuss the package. Record the exact version, authorized dispatch date, recipients, receipt, reliance decisions per area, requests for further work, disagreements and open questions with owners/dates. EY identifies a tenant-bound auditor, not an assumed integration or guaranteed reliance.\n3. Communicate interim status to management at the cadence agreed in the annual workplan and when a milestone or escalation trigger changes. Name business leaders, process/control owners and the SOX steering recipients. Include controls planned/completed/reviewed, clean and exception counts, overdue PBC requests, overdue reviews, significant issues, blockers, decisions required and forecast year-end coverage.\n4. Record actual messages, dispatch and receipt evidence in step documents and dates in the result. If sending is not authorized or the Workstream/email binding is unavailable, prepare the exact recipient package for the authorized sender and keep dispatch pending. The SOX lead approves corrective priorities and escalation for slippage; hand the approved remaining-period plan to sox-period-end-roll-forward-testing.\n\n**Record in AssureSwarm** — Put the analysis, exact document version, evidence references, recipients, actual dates, open questions and owners in this step's result. Attach the package and received evidence as step documents. Capture sign-off through native approval.\n\n**Exit criteria** — The SOX lead resolves or assigns reliance and delivery issues, approves management escalation/actions, and records actual auditor and management handoffs with any pending dispatch or responses visible.","kind":"task","label":"Coordinate interim results and status","requiredApprovals":1},"id":"coordinate-interim-results"}],"sourceTemplateId":"workflow-library:sox-interim-operating-effectiveness-testing"}
