{"description":"Runs on the existing audit item. Evaluate SOX control deficiencies individually and in aggregate, obtain management challenge, and govern committee communication and disposition. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-severity-aggregation-deficiency-evaluation-closure","source":"severity-aggregation","target":"deficiency-evaluation-closure"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":["sox-deficiency-eval"],"controlVerbs":{"UC-GOV-21":"operates","UC-RISK-14":"operates"},"controls":["UC-RISK-14","UC-GOV-21"],"department":"finance","domains":["sox"],"framework":"sox","kind":"sox-deficiency-eval","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:sox-deficiency-eval"}],"canonicalUrl":"https://workflow-library.com/all/?w=sox-program-deficiency-committee-review","contentDigest":"sha256:20b0f1a39cb19973e76827f07005d4b06432a3f32ff85b840339bcdbe906b7d9","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-deficiency-aggregation-evaluation"}],"roles":[{"contribution":"expertise","description":"SOX technical evaluator. Assess severity and aggregation.","id":"reviewer-1","nodeIds":["severity-aggregation"]},{"contribution":"approval","description":"Management and audit committee. Approve deficiency evaluation.","id":"reviewer-2","nodeIds":["deficiency-evaluation-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:sox-deficiency-eval"}],"releaseId":"sha256:20b0f1a39cb19973e76827f07005d4b06432a3f32ff85b840339bcdbe906b7d9","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-program-deficiency-committee-review"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"sox-program-deficiency-committee-review","source":"coworkcanvas-gallery","standards":[],"teams":["finance"]},"name":"Deficiency Evaluation & Committee","nodes":[{"data":{"instructions":"**Objective**\nAssess severity and aggregation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review failed test or monitoring work, control description, exceptions and population, risk and assertion mappings, process walkthrough, owner response, prior issues, compensating activities, and supporting evidence.\n2. Use validated facts, materiality, affected accounts and assertions, transaction volume, exposure period, compensating controls, possible misstatement scenarios, related deficiencies, prior errors, and auditor observations.\n\n**Procedure**\n1. Reperform the fact pattern, separate evidence gaps from control failures, quantify known exceptions and affected periods, confirm whether the issue is isolated or systemic, identify root cause, and search for related deficiencies.\n2. Develop reasonably possible misstatement scenarios, evaluate magnitude and likelihood, assess precision and evidence for compensating controls, consider aggregation by cause and assertion, compare indicators, and document contrary factors.\n\n**Record in AssureSwarm**\n1. Capture the deficiency reference, validated condition, criteria, cause, affected controls and assertions, population and exceptions, period, locations, systems, owner response, limitations, and immediate actions. Also record validated fact summary.\n2. Document proposed severity, scenario calculations, likelihood and magnitude rationale, compensating-control analysis, aggregation set, indicators considered, differences of view, and additional evidence needed.\n\n**Exit criteria**\nSOX technical evaluator provides expertise: The factual record is supported and complete enough for severity analysis, disputed facts remain explicit, and related or recurring matters are identified for aggregation. The proposed severity is reproducible from evidence and applicable criteria, aggregation has been explicitly addressed, and unresolved judgments are ready for management challenge.","kind":"task","label":"Assess severity and aggregation","requiredApprovals":1},"id":"severity-aggregation"},{"data":{"controls":["UC-RISK-14","UC-GOV-21"],"instructions":"**Objective**\nApprove deficiency evaluation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the fact record, severity analysis, aggregation inventory, management response, remediation plan, disclosure considerations, external auditor view where available, and draft governance materials.\n2. Review all stage evidence, final calculations and criteria, committee disposition, management response, auditor communication, remediation plan, disclosures, related deficiencies, and outstanding limitations.\n\n**Procedure**\n1. Present evidence and judgments, record questions and dissent, challenge optimistic assumptions and unsupported compensating controls, confirm communication requirements and timing, and route material changes back through evaluation.\n2. Verify the final severity follows supported facts, aggregation and dissent are addressed, required communications occurred, linked issue and remediation records agree, and return any unsupported or inconsistent disposition.\n\n**Record in AssureSwarm**\n1. Capture attendees, date, materials, questions, management and committee views, disposition, revised severity or conditions, disclosure and auditor communications, remediation commitments, owners, and due dates.\n2. Document the authorized reviewer, final severity and rationale, aggregation set, committee date and decision, communications, disclosure impact, remediation owner and due date, reassessment triggers, and links. Also record final evaluation summary.\n\n**Exit criteria**\nManagement and audit committee provides approval: An approver confirms required governance review is evidenced, the accepted or revised evaluation is clear, and dissent or unresolved reporting implications remain visible. The authorized reviewer accepts the documented management evaluation and governance record; workflow completion alone does not constitute management assertion or an auditor conclusion.","kind":"task","label":"Approve deficiency evaluation","requiredApprovals":1},"id":"deficiency-evaluation-closure"}],"sourceTemplateId":"workflow-library:sox-program-deficiency-committee-review"}
