{"description":"Physical-asset custody and count program as a decision-aware workflow that operates control UC-FIN-10 (physical asset custody & count) each cycle. The instance attaches to the EXISTING UC-FIN-10 Control item — a preventive, physical control run on the standing count calendar — enriching that control's operating history each cycle rather than creating a new record; every variance, custody exception, storage gap, deficiency, and carry-forward it raises is an Issue linked back to that Control. It covers count-package preparation, blind physical count and inspection, book reconciliation, custody-log authorization review, storage and retention verification, and certified, audit-ready evidence archival. In scope each cycle: cash funds (petty cash, tills, vault), negotiable instruments on hand, and physical accounting records under retention, counted against the standing count calendar. It consumes no upstream workflow and hands off to none; cross-cycle continuity is item-based — this cycle's carry-forward Issue items become the next cycle's scoping inputs — so there is no handoff package.","edges":[{"id":"e-compile-book-records-and-count-package-execute-physical-count-and-inspection","source":"compile-book-records-and-count-package","target":"execute-physical-count-and-inspection"},{"id":"e-execute-physical-count-and-inspection-reconcile-count-to-book-balances","source":"execute-physical-count-and-inspection","target":"reconcile-count-to-book-balances"},{"id":"e-execute-physical-count-and-inspection-certify-count-results-and-escalate-deficiencies","source":"execute-physical-count-and-inspection","target":"certify-count-results-and-escalate-deficiencies"},{"id":"e-reconcile-count-to-book-balances-investigate-and-resolve-variances","label":"Variances noted","source":"reconcile-count-to-book-balances","target":"investigate-and-resolve-variances","whenValue":"variances_noted"},{"id":"e-reconcile-count-to-book-balances-certify-count-results-and-escalate-deficiencies","label":"Clean","source":"reconcile-count-to-book-balances","target":"certify-count-results-and-escalate-deficiencies","whenValue":"clean"},{"id":"e-investigate-and-resolve-variances-certify-count-results-and-escalate-deficiencies","source":"investigate-and-resolve-variances","target":"certify-count-results-and-escalate-deficiencies"},{"id":"e-review-custody-log-authorization-remediate-custody-access-exceptions","label":"Exceptions noted","source":"review-custody-log-authorization","target":"remediate-custody-access-exceptions","whenValue":"exceptions_noted"},{"id":"e-review-custody-log-authorization-certify-count-results-and-escalate-deficiencies","label":"No exceptions","source":"review-custody-log-authorization","target":"certify-count-results-and-escalate-deficiencies","whenValue":"no_exceptions"},{"id":"e-remediate-custody-access-exceptions-certify-count-results-and-escalate-deficiencies","source":"remediate-custody-access-exceptions","target":"certify-count-results-and-escalate-deficiencies"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-FIN-10"],"department":"finance","domains":["sox"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=sox-physical-asset-custody-count-program","contentDigest":"sha256:726b59341fce0a43fd2afaf59a183ec7403481ce70c1016f6e16704fa5e7efe6","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:726b59341fce0a43fd2afaf59a183ec7403481ce70c1016f6e16704fa5e7efe6","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-physical-asset-custody-count-program"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"sox-physical-asset-custody-count-program","source":"coworkcanvas-gallery","standards":["sox","soc2"],"teams":["finance","facilities"]},"name":"Physical Asset Custody & Count Program","nodes":[{"data":{"description":"Agent pulls book balances and prepares blind count sheets for every asset class and location; human verifies the count package before counting begins","instructions":"**Objective** — Fix an independent, time-stamped book baseline for every in-scope population and issue blind count sheets, so counting starts from a reconcilable baseline the counters cannot see.\n\n**Inputs**\n- The UC-FIN-10 Control item this cycle operates — the anchor; its `control_id`, `key_control`, and `frequency` fix the population and cadence. Prior-cycle carryovers arrive as existing Issue items (uncleared variances, custody exceptions, storage or retention fixes) linked to this Control, queried in from the last cycle's certification step, which carried them forward as it closed.\n- General ledger and subledger balances for each cash fund as of the count cutoff (external GL/ERP; baseline extracts uploaded as documents on this step); the negotiable-instrument register with instrument detail (external register; document copy on this step); the accounting-records retention index with box and folder counts by record class (document on this step — no native record/asset item type).\n- The count calendar, custodian roster, and location register that define the in-scope populations, locations, and custodian assignments for this cycle (documents on this step — no native Location/Asset item type).\n- The count policy — the existing Policy item (`policy_type: procedure`) that governs the blind-count requirement, dual-count thresholds, and denomination detail expected per fund type. Reference the existing Policy record; do not recreate it here.\n\n**Procedure**\n1. Pull each population's baseline as of the cutoff, capturing source system, as-of timestamp, and record count: for imprest funds the authorized fund amount (an imprest fund reconciles to its authorized amount, not to a floating ledger balance); for vaults and tills the book balance; for negotiables the register with serial or certificate numbers; for records the index by retention class.\n2. List the known reconciling items at cutoff — deposits in transit, replenishment checks issued but not yet received — so the reconciler can separate legitimate timing differences from real variances instead of discovering them mid-investigation.\n3. Build one count sheet per location and asset class, blind: pre-populate custodian of record, location, and the structure expected (denomination rows for cash; payee, date, amount, and endorsement columns for checks; certificate number and registered owner for securities; box, seal, condition, and label fields for records) — but never the book quantity. A count sheet that shows the expected balance invites counting to the number.\n4. Add one row per count location to the count-package index and attach its count sheet, so each location's progress, exceptions, and eventual reconciliation trace through one index — there is no native Location/Asset item type to hold a per-location tracker.\n5. Assemble the count-package index: every location with its count sheet and a baseline reference. The baseline extracts stay with the reconciler — they are not distributed to counting teams.\n6. Tie the package to scope: the package's location count equals the in-scope population from the count calendar, with nothing dropped or added. The control owner verifies the package — baselines current, every location covered — and releases it to the counting teams.\n\n**Record in AssureSwarm**\n- Attach the count-package index and the book baseline extracts as documents on this step (XLSX index, one row per in-scope location and asset class). There is no native Location/Asset item type, so per-location tracking lives in this index document and the per-location tabs of the later workpapers, not as separate items.\n- Stage the blank blind count-sheet forms on this step for on-site completion.\n- Confirm the prior-cycle carry-forward Issue items (linked to the UC-FIN-10 Control) are pulled in as this cycle's scoping inputs.\n\n**Exit criteria** — Every in-scope location has a blind count sheet and a time-stamped book baseline; known reconciling items are listed; the package ties to the in-scope population; the control owner's release is recorded.","label":"Compile book records and count package","performedBy":{"primitives":["coach-query-data","coach-form-create","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"compile-book-records-and-count-package"},{"data":{"description":"Agent stages counting logistics and blind count sheets; human counting teams perform the physical count and inspection at every location","formData":{"fields":[{"key":"returned_intact","label":"All assets counted were returned to my custody intact at the end of the count","required":true,"type":"checkbox"},{"key":"items_not_presented","label":"Assets in my custody not presented for counting, and why","required":false,"type":"textarea"},{"key":"custodian_observations","label":"Any disagreement, exception, or condition issue I want recorded","required":false,"type":"textarea"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Physically count and inspect every in-scope population so existence, completeness, and condition are verified first-hand by counters independent of custody — with irregularities escalated before teams leave the location.\n\n**Inputs**\n- The released count package: blind count sheets and inspection checklists per location.\n- The count-team roster paired against locations for independence.\n- The count policy: dual-count thresholds, custodian-presence rule, escalation contacts.\n\n**Procedure**\n1. Enforce independence and presence: no counter counts a fund they hold, supervise custody of, or administer; the custodian is present for the entire count of their fund and signs that it was returned intact — this protects the custodian from later shortage claims and the counters from substitution claims. A counter is never left alone with cash.\n2. Control simultaneity: count all funds at a location in one session, or seal uncounted funds until their turn — an unsealed, uncounted fund is the classic source for borrowing to cover a shortage in the fund being counted.\n3. Count cash by denomination and list every check individually (payee, date, amount, endorsement). IOUs, employee personal checks held as cash, and unreplenished paid-out vouchers are not cash — list them separately as policy exceptions unless the imprest policy explicitly allows receipts pending replenishment. Flag undeposited checks older than the deposit-timeliness threshold (typically one to three business days): they indicate a deposit-control failure independent of the count result.\n4. Dual-count where policy requires — vault counts and funds above the policy value threshold: two counters count independently and must agree before the sheet is signed.\n5. For securities and other negotiables, sight each instrument and record certificate or serial number, registered owner, and condition; a photocopy in the file is not the instrument.\n6. Inspect records storage against the index: box or folder present, seal intact, physical condition (water, pest, or fire damage), retention label legible.\n7. Escalate immediately on a missing asset, broken seal, or evidence of unauthorized access: secure the location, stop the count, and notify the control owner before the team leaves — do not confront the custodian or attempt on-the-spot reconciliation.\n8. Have counters and custodian sign and timestamp every count sheet before the team leaves, and collect the custodian's confirmation on this step's form at the same time; then consolidate the returns into the count-and-inspection log.\n\n**Record in AssureSwarm**\n- Attach each location's completed count sheet with counted quantities, timestamps, and counter names, and record the counters' results in the step result — the counting team's own work is never a form.\n- The custodian form asks only whether assets were returned intact, which assets in their custody were not presented and why, and any disagreement or condition observations. Bind the assignment to the known custody record and signed count sheet; retain respondent identity and the native submission timestamp. The counters record presence and counted quantities in their results and signed sheets. Collect the response at count completion.\n- Record condition exceptions as rows on the count-and-inspection log and against their location in the count-package index — there is no Location item to hold them; genuine findings are raised as Issues at the reconciliation and storage steps.\n- Attach the consolidated count-and-inspection log as a document (XLSX) on this step.\n\n**Exit criteria** — Every location's count sheet is complete, signed by counters and custodian, and time-stamped, with a submitted custodian confirmation for every custody assignment counted; dual counts performed where required; condition exceptions logged against their locations; any immediate irregularity escalated in real time rather than discovered later in the file.\n\n**Form recipient** — this step's form is answered by *the custodian of record for the fund or location counted*, not by the step owner. Send it with a form assignment; the owner's own work goes in the step result.","label":"Execute physical count and inspection","performedBy":{"primitives":["coach-query-data","coach-form-fill","coach-document-upload"]}},"id":"execute-physical-count-and-inspection"},{"data":{"decisionField":"variance_result","description":"Agent auto-matches counted quantities to book balances and computes variances by location; human investigates and records the reconciliation result","formData":{"fields":[{"key":"variance_result","label":"Reconciliation result","options":[{"label":"Clean — ties to book","value":"clean"},{"label":"Variances noted","value":"variances_noted"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Tie every counted quantity back to its book baseline and decide whether the cycle proceeds straight to custody review or routes through variance investigation first. The Corporate Controller owns the call.\n\n**Decision criteria**\n- **clean** (Clean — ties to book) — every location reconciles within the count policy tolerance: imprest funds tie exactly (cash on hand + approved replenishment vouchers + replenishment in transit = the authorized fund amount — imprest tolerance is zero by construction); operational tills sit within the cumulative over/short tolerance the policy sets; every negotiable instrument on the register was sighted with matching serial or certificate numbers; the records index is complete with no missing or misfiled boxes. Every reconciling item is an identified timing difference — deposit in transit, replenishment in transit — with documentary support (deposit slip, check copy), not a verbal explanation.\n- **variances_noted** (Variances noted) — any of: an unexplained shortage or overage of any amount (overages are not good news — they mean the fund is not controlled and can mask lapping or substitution); an above-tolerance variance at any location; a missing or unexpected instrument; a records-index gap; or a recurring over/short pattern at the same location or custodian across cycles even when each instance is individually within tolerance — the SAB 99 qualitative lens applies, and small amounts with fraud indicia are never clean.\n\nA variance \"explained\" only by the custodian's assertion is unexplained. When in doubt between branches, route to investigation — a clean call that later unravels impeaches the whole cycle's certification.\n\n**Record in AssureSwarm** — Submit this step's form: `variance_result` = the chosen branch; the step result = the per-location tie-out summary with references into the attached workpaper; the step's approver record = the Controller making the call. Attach the reconciliation workpaper and variance detail as a document (XLSX) on this step, and refresh the variance dashboard by location and asset class so the reviewer sees exactly which locations breach threshold.\n\n**Exit criteria** — Form submitted with a rationale that references the attached workpaper; every in-scope location shows a computed variance in units and value (zero or otherwise); the unused branch is prunable because the recorded value matches one branch edge.","kind":"decision","label":"Reconcile counts to book balances","performedBy":{"primitives":["coach-query-data","coach-dashboard-create","coach-document-upload"]}},"id":"reconcile-count-to-book-balances"},{"data":{"description":"Agent logs each variance with root-cause prompts and tracks corrective action to completion; human approves each resolution before recount or sign-off","instructions":"**Objective** — Drive every noted variance to a root-caused disposition — corrected and re-verified, or escalated as potential loss — without restarting the full count, so the cycle proceeds to custody review on a defensible reconciliation.\n\n**Inputs**\n- The variance detail and reconciliation workpaper from the decision step, with each flagged location's count sheet and baseline.\n- Prior-cycle variance dispositions for recurrence checks.\n- The count policy: recount rules, adjustment approval path, loss-escalation thresholds.\n\n**Procedure**\n1. Open one variance item per flagged location and population: asset class, direction (short or over), size in units and value, custodian, and the count-sheet reference.\n2. Investigate in cost order: (a) recount first, by a different counter than the original — count error is the most common cause and the cheapest to eliminate; (b) then search transactions: unrecorded receipts or disbursements, replenishments posted to the wrong fund, deposits in transit missed in the baseline; (c) then physically search for misplacement — adjacent safe compartments, unlogged transfers between locations; (d) only after those fail, classify the variance as unexplained.\n3. Match the corrective action to the root cause: count error → corrected count sheet signed by both counters; unrecorded transaction → book adjustment through the standard journal-entry approval path, never a plug to the fund; misplacement → relocation plus custody-log correction. An unexplained shortage or overage escalates as potential loss or theft: secure the fund, notify security and internal audit, preserve the original count sheets and custody logs unaltered as evidence, and check the fidelity-bond or insurer notification threshold. Never allow the custodian to make good a shortage from personal funds — it destroys the evidence trail and is itself a fraud indicator.\n4. Run the recurrence check: the same location or custodian trending short or over in one direction across three cycles is elevated regardless of individual size.\n5. Re-run the affected count-to-book tie after each correction and confirm the variance clears without introducing a new discrepancy.\n6. Maintain the variance resolution log — variance, root cause, corrective action, performer and date, re-check result — and obtain the Controller's approval on each resolution individually, not as a batch.\n\n**Record in AssureSwarm**\n- Create one Issue per variance — `issue_type: exception`, `source: management_identified`, `severity`, `root_cause`, `identified_date`, and `actual_remediation_date` once cleared — linked to the UC-FIN-10 Control item (Issue ↔ Control), with the count-sheet reference recorded in the Issue (there is no Location item to link to).\n- Track each corrective action to completion, recording the performer and `actual_remediation_date` on the variance Issue.\n- Attach the variance resolution log as a document (XLSX) on this step with the Controller's per-item approvals.\n\n**Exit criteria** — Every variance item closed with root cause, completed corrective action, and a clean re-run of the tie — or escalated to security and internal audit with the escalation recorded; the Controller's approval sits on each resolution; the cycle is released to custody-log review.\n\n> **⚡ Audit Artist accelerator:** `/sox-python` re-runs the count-to-book tie deterministically after each correction, so every cleared variance is re-checkable from recorded inputs rather than hand-recomputed.","label":"Investigate and resolve variances","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-workflow-scan","coach-query-data","coach-document-upload","sox-python"]}},"id":"investigate-and-resolve-variances"},{"data":{"decisionField":"custody_result","description":"Agent compares custody logs and access records to the authorized-custodian list; human reviews and records whether custody exceptions exist","formData":{"fields":[{"key":"custody_result","label":"Custody-authorization review result","options":[{"label":"No exceptions","value":"no_exceptions"},{"label":"Exceptions noted","value":"exceptions_noted"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Confirm that only authorized custodians held or accessed cash, negotiable instruments, and accounting records during the period, and decide whether custody exceptions must be remediated before storage verification. The Corporate Controller owns the call.\n\n**Decision criteria**\n- **no_exceptions** (No exceptions) — every individual on every custody log, vault register, and physical or system access record for the period maps to the authorized-custodian list as of the access date; every custodian change — handoff, temporary coverage, new assignment — carries a documented approval, and cash-fund handoffs include a joint transfer count signed by outgoing and incoming custodians; the key and combination population equals the authorized population (no unreturned keys, no combination left unchanged after a custodian departed); no access after a termination or transfer effective date; dual-control requirements (two keys, split combination) observed wherever policy requires them; and where a custodian also records the related transactions, a documented compensating check — dual control or an independent reconciliation — exists for that segregation-of-duties overlap.\n- **exceptions_noted** (Exceptions noted) — any of: access by someone outside the authorized roster; access by a terminated or transferred employee after their effective date; an undocumented handoff, or a handoff without a transfer count; one individual holding both keys or a full combination where dual control is required; a combination not changed after custodian turnover; a custody-plus-recording overlap with no documented compensating check; or gaps in the log itself — missing pages, unsigned entries, a required location with no log. An unreliable log is an exception even when no bad access is observed: a control that cannot demonstrate operation did not operate.\n\nCompare the access population against HR effective dates, not just names, and check delegation-of-authority records before flagging temporary coverage as unauthorized.\n\n**Record in AssureSwarm** — Submit this step's form: `custody_result` = the chosen branch; the step result = the per-location authorized-versus-observed summary with references into the attached workpaper; the step's approver record = the Controller. Attach the custody-authorization workpaper listing every location, its authorized custodians, actual access observed, and each flag's disposition as a document (XLSX) on this step.\n\n**Exit criteria** — Form submitted; every location has an authorized-versus-observed comparison in the attached workpaper; every flag is either cleared with evidence or carried into the exceptions branch; the unused branch is prunable.","kind":"decision","label":"Review custody log authorization","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"review-custody-log-authorization"},{"data":{"description":"Agent logs each custody exception and drafts corrective access changes; human approves remediation and re-verifies authorization before storage review","instructions":"**Objective** — Close every unauthorized-access and undocumented-handoff finding with a completed, physically verified corrective action and a re-verified custodian population, so storage verification starts from a trustworthy access baseline.\n\n**Inputs**\n- The custody exceptions and workpaper from the review step.\n- The authorized-custodian list, delegation-of-authority records, and HR effective dates.\n- The key and combination register, including combination-change history and sealed-envelope escrow records.\n\n**Procedure**\n1. Open one exception item per finding: location, individual, access type (key, combination, badge, log entry), the exposure window, and the root-cause bucket — offboarding gap, undocumented temporary coverage, stale credential, unmaintained roster, or log-keeping failure.\n2. Apply the corrective action the cause demands: revoke physical and system access — revoking a combination means changing it and re-escrowing the new one in a sealed envelope, not editing a list; formalize an undocumented handoff only with both parties' attestation plus a fresh verification count of the affected fund; route authorized-custodian list changes through their approval path; fix log-keeping at locations whose logs were unreliable, whether by new log discipline or a replaced custodian.\n3. Assess exposure for each exception: for the window an unauthorized person had access, confirm the asset population survived it — tie the most recent clean count and reconciliation across the window; if the window predates the last clean count, order a targeted recount of the affected location now rather than waiting for next cycle.\n4. Escalate control-override indicators to internal audit — management directing off-roster access, altered or backfilled log entries. These are fraud-risk signals, not hygiene items, and their severity evaluation belongs outside the count program.\n5. Verify each revocation physically, not by assertion: the collected key, the combination-change record with new escrow, the disabled badge. An email saying access was removed is not evidence that it was.\n6. Re-run the custody-log comparison after corrections land: every location shows only authorized custodians and documented handoffs. The Controller approves each corrective action individually.\n\n**Record in AssureSwarm**\n- Create one Issue per custody finding — `issue_type: exception`, `source: management_identified`, `severity`, `root_cause`, `actual_remediation_date` — linked to the UC-FIN-10 Control item (Issue ↔ Control), referencing the custody-authorization workpaper.\n- Track each corrective action to completion, recording the performer and `actual_remediation_date` on the exception Issue.\n- Attach the exception log, the updated authorized-custodian list, and the re-run comparison result as documents on this step.\n\n**Exit criteria** — Every exception closed with a completed and physically verified corrective action; exposure windows assessed, with targeted recounts done where required; the re-run comparison shows only authorized access; override indicators escalated; the Controller's approvals recorded.","label":"Remediate custody access exceptions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-workflow-scan","coach-query-data","coach-document-upload"]}},"id":"remediate-custody-access-exceptions"},{"data":{"description":"Assemble the self-contained, audit-ready evidence package for the cycle and secure the Controller's certification that physical custody was safeguarded — with every deficiency escalated for SOX severity evaluation, the certified package archived under retention, and every open thread seeded into the next cycle.","instructions":"**Objective**\nAssemble the self-contained, audit-ready evidence package for the cycle and secure the Controller's certification that physical custody was safeguarded — with every deficiency escalated for SOX severity evaluation, the certified package archived under retention, and every open thread seeded into the next cycle.\n\n**Inputs**\nThe storage and retention policy — the existing Policy item (`policy_type: policy`) setting safe and vault specifications, environmental requirements, and the retention schedule by record type. Referenced, not recreated.\n- The location register with each site's storage configuration; the records-retention index.\n- The legal-hold list and the pending-disposition queue.\n- Electronic-records configuration: write-protection or immutability settings, version history and edit logs, backup coverage.\n\nEvery cycle artifact: count sheets, consolidated count-and-inspection log, reconciliation workpaper, variance resolution log, custody-authorization workpaper, exception log, and storage-and-retention verification workpaper.\n- The cycle's in-scope population and prior-cycle metrics for trend comparison.\n- The SOX program's deficiency-evaluation criteria — the existing Policy item (`policy_type: standard`, owned by the SOX program) that defines how a count-program finding grades to deficiency, significant deficiency, or material weakness. Referenced, not recreated.\n- The count-cycle execution log, the count calendar, and the SOX retention policy.\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Verify storage and retention controls”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Verify storage and retention controls: Verify that cash, negotiable instruments, and accounting records are stored with the required protection against loss and unauthorized alteration and that retention and disposition operate per schedule — confirming protection where it exists and time-boxing a fix where it does not.\n\n2. Verify physical protection per location: fire rating of safes and cabinets appropriate to contents (paper records need fire-rated storage; magnetic and optical media fail at far lower temperatures and need media-rated containers); dual-key or split-combination mechanics actually functioning, not merely documented; environmental controls at records storage within range (temperature, humidity), cross-referenced to any water, pest, or fire-damage observations from the physical inspection step; the off-site facility's current contract and access-control attestation on file.\n3. Test retention-schedule compliance on a sample per record class: nothing disposed before its scheduled date; disposition after the date only with an approved certificate of destruction; SOX-relevant workpapers and financial records anchored at the seven-year retention standard. Check every legal hold against the pending-disposition queue — a hold overrides the schedule regardless of the record's age.\n4. Confirm completeness of the stored population: the period's expected inputs, in-process items, and outputs are present in storage or the index; misfiles found during the count are corrected; sequential record series show no unexplained gaps.\n5. Verify electronic protection against unauthorized alteration: immutability or write-protection on electronic accounting records; version history and edit logs enabled — and reviewed for the period for unexplained changes; backup coverage in place. A record editable in place with no edit trail fails this test even if nothing bad happened — the control's absence is the finding.\n6. Grade each gap: a missing required safeguard is remediated before the cycle certifies; a degraded safeguard with a documented compensating control gets an owner and a time-boxed fix. The Controller reviews the verification workpaper and directs immediate remediation for any certification-blocking gap.\n\n7. Assessment scope for Certify count results and escalate deficiencies: Assemble the self-contained, audit-ready evidence package for the cycle and secure the Controller's certification that physical custody was safeguarded — with every deficiency escalated for SOX severity evaluation, the certified package archived under retention, and every open thread seeded into the next cycle.\n\n8. Sweep completeness against scope: every in-scope location and asset class shows all four results — count, reconciliation, custody authorization, and storage-and-retention. A gap here is a scope failure to remediate before certification, not a footnote.\n9. Index the package so an external auditor can navigate it cold: organized by asset class and location, each conclusion tracing to its evidence — every count sheet signed, every variance traced to closure, every custody exception to a completed corrective action, every storage gap to its disposition.\n10. Compute cycle metrics against prior cycles: locations counted on schedule, variances raised and cleared, gross over and short value, custody exceptions found and remediated, storage gaps found and closed. Deteriorating trends — rising recurring variances, repeat exceptions at the same location — are deficiency indicators in their own right, even when each instance closed.\n11. Write up anything unresolved, or anything indicating the control failed to operate (a missed count, an unreliable custody log, an unexplained loss), neutrally — condition, criteria, cause, effect — and escalate it to the SOX program owner for severity evaluation. Severity (deficiency, significant deficiency, or material weakness) weighs likelihood and magnitude, compensating controls, and aggregation with other findings — the count program reports; it does not self-grade.\n12. Draft the certification statement: period, scope, results, metrics, and every open item disclosed with its owner and due date. Certifying clean while omitting a known open item is a worse failure than the item itself. Before signing, the Corporate Controller confirms every step of this cycle is finished or explicitly dispositioned, both decision forms are submitted, and no unresolved deficiency lacks an escalation record — then reviews the package, escalates unresolved deficiencies, and signs. Certifying over an open step is how audit trails grow holes; that signature closes the cycle and items 13–16 execute it.\n13. Export the certified package and archive it in the designated evidence repository under the SOX retention anchor (seven years is the standard), recording the archive location and reference against each location and asset class, and confirming the archived copy is retrievable. Post-archive corrections are new dated addenda — never edits to the archived set.\n14. Update the count-cycle execution log with the period result, completion dates, and key metrics. Internal audit, SOX testers, and the external auditor select samples from this log, so its accuracy is itself audit-relevant.\n15. Create carry-forward items for every aged variance, deferred remediation, and scheduled retention action — each with a named owner, a due date, and a link to its source artifact — so they arrive as explicit inputs to the next cycle's scoping step rather than as tribal memory.\n16. Confirm the next count is scheduled on the count calendar (preserving surprise-count confidentiality), and send the cycle-closure notice to the Controller and SOX program owner summarizing results and carryovers.\n\n**Record in AssureSwarm**\nAttach the storage-and-retention verification workpaper as a document (XLSX) on this step.\n- Create one Issue per gap — `issue_type: observation` (or `deficiency` for a certification-blocking gap), `source: self_assessment`, `issue_owner`, `target_remediation_date` — linked to the UC-FIN-10 Control item (Issue ↔ Control); the affected location is named in the Issue, since there is no Location item to link to.\n\nAttach the indexed evidence package and the signed certification statement as documents on this step (PDF/XLSX), linking every prior-step artifact into the package so each conclusion traces to its evidence.\n- Create one Issue per escalated deficiency — `issue_type: deficiency`, `source: self_assessment` (severity graded later by the SOX program owner) — linked to the UC-FIN-10 Control item and to this step (Issue ↔ Control).\n- Export the workflow instance and record the archive reference (workflow export plus a document upload confirming the archive location under the SOX seven-year retention anchor).\n- Create one carry-forward Issue per open thread — `issue_owner`, `target_remediation_date`, `source: self_assessment` — linked to the UC-FIN-10 Control item and to its source artifact (Issue ↔ Control), so the next cycle's compile step queries them as existing items.\n- Attach the cycle-closure notice as a document and set the workflow instance's final status.\n\n**Exit criteria**\nEvery location and system verified against the policy; each gap either remediated or documented with a compensating control, owner, and due date; the legal-hold check performed against the disposition queue; the Controller's review recorded. Package complete against scope with a navigable index; certification signed by the Controller with all open items disclosed with owners and due dates; every deficiency escalated with a linked item; the package archived with its reference recorded and retrievability confirmed; execution log updated; every open thread carried forward with an owner and due date; the next count scheduled and the closure notice attached.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the indexed, audit-ready evidence package from the linked artifacts so the certification traces to one navigable set, and renders the cycle-closure notice from the same records.","label":"Certify count results and escalate deficiencies","performedBy":{"note":"","primitives":["coach-document-upload","coach-item-create","coach-items-link","coach-query-data","coach-render-package","coach-workflow-export"]}},"id":"certify-count-results-and-escalate-deficiencies"}],"sourceTemplateId":"workflow-library:sox-physical-asset-custody-count-program"}
