{"description":"Runs on the existing audit item. Assemble and govern management’s annual ICFR assessment record, including scope, test results, deficiencies, certifications, disclosures, and assertion approval. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-assessment-synthesis-management-assessment-closure","source":"assessment-synthesis","target":"management-assessment-closure"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":["sox-mgmt-assessment"],"controlVerbs":{"UC-GOV-21":"operates"},"controls":["UC-GOV-21"],"department":"finance","domains":["sox"],"framework":"sox","kind":"sox-mgmt-assessment","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:sox-mgmt-assessment"}],"canonicalUrl":"https://workflow-library.com/all/?w=sox-management-assessment-assertion","contentDigest":"sha256:32b1feec1a1316d8be4799202977bff12a5ed7f20f205ae62f4abe2a98b6d6fd","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-subcertification-cascade"}],"roles":[{"contribution":"expertise","description":"SOX assessment reviewer. Synthesize ICFR results.","id":"reviewer-1","nodeIds":["assessment-synthesis"]},{"contribution":"approval","description":"Authorized management signatory. Approve management assessment record.","id":"reviewer-2","nodeIds":["management-assessment-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:sox-mgmt-assessment"}],"releaseId":"sha256:32b1feec1a1316d8be4799202977bff12a5ed7f20f205ae62f4abe2a98b6d6fd","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-management-assessment-assertion"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"sox-management-assessment-assertion","source":"coworkcanvas-gallery","standards":[],"teams":["finance"]},"name":"Management Assessment & Assertion","nodes":[{"data":{"instructions":"**Objective**\nSynthesize ICFR results. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review approved SOX scope and plans, risk-control matrices, walkthroughs, testing trackers and workpapers, entity and IT coverage, service-auditor reports, sub-certifications, changes, and deficiency inventory.\n2. Use reviewed testing results, exceptions, deficiency evaluations, remediation and retests, entity-level and IT results, service-auditor reports, certifications, close controls, subsequent events, and disclosure drafts.\n\n**Procedure**\n1. Reconcile scoped controls to completed testing, identify missing reviews and evidence, validate entity and period coverage, confirm changes are reflected, inventory open deficiencies, and establish the assessment calendar and decision owners.\n2. Aggregate results by process and assertion, verify unresolved exceptions are captured, evaluate scope and evidence limitations, reconcile deficiency severity, consider subsequent changes, and draft conclusions tied to specific supporting records.\n\n**Record in AssureSwarm**\n1. Capture assessment period, scope reference, control and testing reconciliation, certifications, service-provider coverage, changes, deficiencies, missing work, reporting criteria, owners, and due dates. Also record approved scope reference.\n2. Link the results memorandum, summarize coverage and outcomes, list exceptions and deficiencies, limitations, remediation status, contradictory evidence, disclosure considerations, and remaining management judgments. Also record results memorandum reference.\n\n**Exit criteria**\nSOX assessment reviewer provides expertise: The assessment population reconciles to approved scope, incomplete evidence and review are visible, and management has a supportable basis for result synthesis. The synthesis is traceable to reviewed evidence, does not hide gaps or dissent, and all judgments requiring certification or disclosure review are explicit.","kind":"task","label":"Synthesize ICFR results","requiredApprovals":1},"id":"assessment-synthesis"},{"data":{"controls":["UC-GOV-21"],"instructions":"**Objective**\nApprove management assessment record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the population reconciliation, results memorandum, final deficiency evaluations, certifications, disclosure drafts, remediation status, external auditor communications, legal input, and proposed assertion wording.\n2. Review all stage records, final results memorandum, signed certifications, approved assertion and disclosures, deficiency and remediation status, committee materials, auditor communications, and unresolved limitations.\n\n**Procedure**\n1. Challenge evidence sufficiency and scope, verify assertion language matches the evaluated criteria and period, reconcile material weakness determinations and disclosures, record dissent and conditions, and prohibit approval while material support remains incomplete.\n2. Trace material statements to evidence, verify approved versions and dates, confirm required governance and disclosures, reconcile linked records, and return the package if results, deficiencies, or assertion language conflict.\n\n**Record in AssureSwarm**\n1. Capture the decision, approvers, assertion and disclosure versions reviewed, evidence and criteria considered, conditions, dissent, unresolved items, communications, owners, and due dates. Also record assertion package decision.\n2. Document the authorized reviewer, final assessment and assertion references, period, criteria, scope, deficiencies, disclosure outcome, certifications, committee and auditor communications, limitations, and archive index. Also record management assessment summary.\n\n**Exit criteria**\nAuthorized management signatory provides approval: An approver accepts the package for final governance or records precise revisions and blockers; the workflow does not itself issue management’s formal assertion. The authorized reviewer accepts the support and governance record; only the separately approved management assertion carries its stated meaning, not workflow completion.","kind":"task","label":"Approve management assessment record","requiredApprovals":1},"id":"management-assessment-closure"}],"sourceTemplateId":"workflow-library:sox-management-assessment-assertion"}
