{"description":"Quarterly 302/906 sub-certification as a modular, decision-aware workflow: it maintains the certifier hierarchy, refreshes the questionnaire for new systems, reorgs, known control issues, and pending deficiencies, launches the tiered cascade, tracks completion and cures gaps at the cutoff, triages exceptions and qualifications with escalation to the disclosure committee where material, summarizes the population for principal-officer 302/906 sign-off, and archives the certification evidence with the period's support. The instance runs against a campaign-record Audit item created for the quarter (audit_type: compliance; period_start/period_end = the quarter; scope = the in-scope entity and process population), enriching that one record — every questionnaire form, certification register, decision form, dashboard, and attestation package hangs off it and the run's own instance is the audit trail. It consumes the in-scope Process items (each carrying its process_owner) and the open deficiency Issue log, originates on its own recurring quarterly cadence with no upstream handoff, and hands its deficiencies downstream as linked Issue items into the SOX Deficiency Remediation, Year-End Deficiency Aggregation & Severity Evaluation, and Quarterly Board & Audit-Committee GRC Reporting workflows. In scope: the quarter's in-scope entities and processes per the current consolidation scope, from process-owner sub-certification through principal-officer 302/906 sign-off and archival, back-planned from the SEC filing date. Out of scope: the officers' external SEC filing mechanics, and the deficiency, year-end aggregation, and board reporting handled by the downstream SOX Deficiency Remediation, Year-End Deficiency Aggregation & Severity Evaluation, and Quarterly Board & Audit-Committee GRC Reporting workflows this cascade routes into.","edges":[{"id":"e-launch-certification-cascade-assess-completion-at-cutoff","source":"launch-certification-cascade","target":"assess-completion-at-cutoff"},{"id":"e-assess-completion-at-cutoff-evaluate-exception-materiality","label":"All returned by cutoff","source":"assess-completion-at-cutoff","target":"evaluate-exception-materiality","whenValue":"all_returned"},{"id":"e-assess-completion-at-cutoff-resolve-certification-gaps","label":"Gaps remain","source":"assess-completion-at-cutoff","target":"resolve-certification-gaps","whenValue":"gaps_remain"},{"id":"e-resolve-certification-gaps-evaluate-exception-materiality","source":"resolve-certification-gaps","target":"evaluate-exception-materiality"},{"id":"e-evaluate-exception-materiality-brief-disclosure-committee","label":"Escalate to disclosure committee","source":"evaluate-exception-materiality","target":"brief-disclosure-committee","whenValue":"escalate_disclosure_committee"},{"id":"e-evaluate-exception-materiality-summarize-for-principal-officer-signoff","label":"Handle below committee","source":"evaluate-exception-materiality","target":"summarize-for-principal-officer-signoff","whenValue":"handle_below_committee"},{"id":"e-brief-disclosure-committee-summarize-for-principal-officer-signoff","source":"brief-disclosure-committee","target":"summarize-for-principal-officer-signoff"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-GOV-07","UC-GOV-21"],"department":"finance","domains":["sox"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=sox-subcertification-cascade","contentDigest":"sha256:76943fa4fdeeb5deb71fbefc885cc9ef49c56ea1487e95d3fa44d89f1c8b0bd4","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:76943fa4fdeeb5deb71fbefc885cc9ef49c56ea1487e95d3fa44d89f1c8b0bd4","schemaVersion":1,"sourceTemplateId":"workflow-library:sox-subcertification-cascade"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"sox-subcertification-cascade","source":"coworkcanvas-gallery","standards":["sox","coso-ic"],"teams":["finance","executive"]},"name":"Quarterly 302/906 Sub-Certification Cascade","nodes":[{"data":{"description":"Issue the questionnaire down the tiers in dependency order and frame the attestation-package skeleton the campaign will fill, so each tier certifies with the tier below already in hand and everything collected traces forward into what the principal officers ultimately sign, per UC-GOV-07.","instructions":"**Objective**\nIssue the questionnaire down the tiers in dependency order and frame the attestation-package skeleton the campaign will fill, so each tier certifies with the tier below already in hand and everything collected traces forward into what the principal officers ultimately sign, per UC-GOV-07.\n\n**Inputs**\nLast quarter's approved hierarchy version — the XLSX hierarchy document on the prior quarter's archived instance, retrieved from that campaign's Audit item.\n- The org directory and HR mover-leaver feed covering every change since last quarter's hierarchy approval: departures, role changes, new controllers, reorganized reporting lines — uploaded at this step as an HRIS/directory extract (no native item home).\n- The in-scope process list from the current consolidation scope — the existing Process items (status ACTIVE), each carrying the process_owner who certifies it — plus the in-scope entity/segment list (acquisitions, disposals, newly consolidated entities, discontinued operations), which has no native item type and is uploaded at this step as a consolidation-scope extract. Every change that alters who must certify matters here (an acquisition may certify on an abbreviated basis in its transition quarter; any exclusion must be an explicit documented decision, and discontinued operations still certify through the disposal date).\n- The standing delegation register, where one exists — uploaded at this step (no native register type).\n\nLast quarter's questionnaire version and its change summary — the versioned representation document and change-summary document on the prior quarter's archived instance.\n- The period-change inventory sources, uploaded at this step as a PBC from IT and controllership: system go-lives and conversions affecting financial data, reorganizations and acquisitions, accounting policy changes and newly adopted standards, significant or unusual transactions recorded in the quarter.\n- The open deficiency log — the existing open Issue items (issue_type in deficiency | significant_deficiency | material_weakness), each linked to the Control it implicates: known control issues, pending deficiencies awaiting severity evaluation, remediation in flight.\n- The draft Section 302 certification text the principal officers will sign (Exhibit 31) and the Section 906 statement (Exhibit 32), uploaded at this step from disclosure counsel.\n\nThe approved certifier hierarchy version with tier assignments and scopes.\n- The approved, version-stamped questionnaire(s) per tier.\n- The campaign milestone calendar: tier due dates, cutoff, disclosure committee date.\n- The prior quarter's attestation package as the structural precedent.\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Maintain certifier hierarchy”, “Refresh certification questionnaire”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Maintain certifier hierarchy: Rebuild and approve the tiered certifier hierarchy so every in-scope entity and process has exactly one accountable certifier and individual accountability for control responsibilities never lapses between quarters, per UC-GOV-07.\n\n2. Query the mover-leaver feed for every change touching the certifier population since the prior hierarchy was approved — not merely since quarter end; the gap between approval and launch is where vacancies hide.\n3. Rebuild the tiered map: process owners certify their business processes; entity controllers roll up the processes and accounts of their entity; segment CFOs roll up their entities. Apply the line-of-sight test at each tier: a certifier must actually supervise or review what they certify — a controller still listed for an entity they stopped managing two months ago fails the test even though the directory has not caught up.\n4. Flag three defect classes: (a) an in-scope entity or process with no named certifier; (b) a named certifier who has left the role; (c) a certifier whose assigned scope no longer matches their responsibilities after a reorg.\n5. Diff the rebuilt hierarchy against last quarter's version and propose a successor for each vacated assignment from the equivalent current role. Record every delegation with its approver — delegation shifts performance of the questionnaire, never accountability for the representation, and a certifier may not push scope carrying a known open issue down to a subordinate to distance themselves from it.\n6. Link the campaign-record Audit item to the in-scope Process items so the process axis of coverage is traceable as items from either direction at launch; capture the certifier-to-entity assignments in the hierarchy document, since the entity/segment axis has no item type.\n7. Human checkpoint: the corporate controller reviews the diff and the vacancy list, confirms or corrects each proposed successor, and approves the hierarchy only when every in-scope entity and process has exactly one accountable certifier and every delegation is documented.\n\n8. Assessment scope for Refresh certification questionnaire: Refresh the sub-certification questionnaire so this period's representations cover what actually changed, and certifiers with known issues in scope receive targeted questions instead of stale statements they could sign cleanly over a problem, per UC-FIN-02 and UC-GOV-21.\n\n9. Compile the period-change inventory and decide item by item what the questionnaire must ask: an ERP go-live needs a targeted question on conversion controls and data integrity; a newly adopted accounting standard needs a representation on its application; a one-off unusual transaction needs a question only for the certifiers whose scope recorded it.\n10. Map each open deficiency and known control issue to the certifiers whose scope it touches, and write those certifiers targeted questions requiring a current-status confirmation. The design rule: no certifier should be able to certify cleanly over a known issue in their scope — the representation package must require acknowledgment or an update before personal approval.\n11. Draft the standing representations in parallel with the officers' certification text: disclosure controls and procedures effectiveness, changes in ICFR during the period, knowledge of fraud — whether or not material — involving management or employees with a significant role in ICFR, and subsequent events, plus the fair-presentation representation supporting Section 906. Parallelism is the point: a representation the officers make that no sub-certifier supports is a gap in the officers' evidential basis for signing.\n12. Version-stamp the questionnaire and write the change summary against last quarter's representation document, so reviewers and certifiers see exactly what changed and why.\n13. Build the versioned representation document so each tier receives the correct scope-tailored version at launch — process owners answer at process level; entity controllers and segment CFOs additionally represent over their roll-up and their sub-certifiers' returns.\n14. Human checkpoint: the SOX PMO lead and disclosure counsel confirm the questionnaire covers every item in the period-change inventory and the known-issue map, and that the representation wording stays aligned with the certification text the principal officers will sign.\n\n15. Assessment scope for Launch certification cascade: Issue the questionnaire down the tiers in dependency order and frame the attestation-package skeleton the campaign will fill, so each tier certifies with the tier below already in hand and everything collected traces forward into what the principal officers ultimately sign, per UC-GOV-07.\n\n16. Frame the attestation-package skeleton before anything is issued, so the cascade collects into the package rather than the package being reassembled around the cascade at sign-off: a cover letter carrying the standard Section 302/906 certification language; an executive-summary section reserved for the ICFR position and key changes since the prior cycle; a deficiency summary table structured by severity, remediation status, and FSLI impact; a coverage matrix that will reconcile certifications returned against the population issued; and placeholders for management responses and remediation plans. Every claim the officers will read must trace to an artifact the cascade produces — framing the skeleton now is what makes that cite-every-claim discipline achievable rather than aspirational.\n17. Issue the process-owner tier first as versioned representation documents — one per certifier, each scoped to that owner's processes and carrying the campaign cutoff dates. Link each package and its eventual personal native approval to its register row; these participants do not receive a data-collection form. Record each issued certification as a row in a version-stamped XLSX certification register on the campaign record — certifier, tier, entity or process scope, questionnaire version, and due date. There is no native Certification item type, so the register (not per-certification items) is the unit everything downstream — chasing, screening, reconciliation — operates on.\n18. Stage the upper tiers as dependent: each entity controller's questionnaire falls due only after their process owners' certifications are returned, and each segment CFO's only after their controllers'. The sequencing is substantive, not administrative — an upper-tier certifier signing before the tier below has returned is certifying blind, which defeats the cascade's purpose.\n19. Reconcile issuance against the approved hierarchy: every certifier in the population received the correct scope and questionnaire version, with zero unissued packages. Fix any mismatch before declaring launch, not at the cutoff.\n20. Record the launch evidence on the campaign record: issuance list, tier due dates, and the reconciliation result.\n21. Human checkpoint: the SOX PMO lead confirms the launch reached the full population, the tier sequencing is correct, and the due dates leave the final tier enough runway before the cutoff and the disclosure committee meeting.\n\n**Record in AssureSwarm**\nRecord the rebuilt hierarchy, the diff against last quarter, and each vacancy's resolution as a version-stamped XLSX hierarchy document on this step, attached to the campaign-record Audit item — the certifier-to-scope map (and its legal-entity/segment axis) has no native item type, so the document is its home.\n- Link the campaign-record Audit item to the in-scope Process items (Audit ↔ Process relationship) so the process axis of the scope is traceable as items from either direction at launch.\n- Record delegations with their approver and reason in the hierarchy document against the affected assignments, and capture the corporate controller's approval on this step.\n\nBuild the version-stamped representation package per tier as documents, with answers and source links in the package and step results. Reuse known scope, changes and issues as cited context; each certifier supplies current answers and corrections and personally approves their exact scoped package through native approval.\n- Record the change summary and the known-issue-to-certifier map (keyed to the open deficiency Issue items) as documents on this step.\n- Record PMO and disclosure counsel approval on the step.\n\nRecord the certification register as a version-stamped XLSX on the campaign-record Audit item — one row per certification (certifier, tier, scope, questionnaire version, due date); there is no Certification item type, so the register is the tracking surface.\n- Bind each representation document and its approval record to the approved certifier, scope, tier, period and questionnaire version. Known issues remain visible and require acknowledgment or correction in the representation; a supplied source is context, never the certifier’s current assertion. Preserve the PMO’s issuance reconciliation in the step result.\n- Attach the attestation-package skeleton and the issuance reconciliation as documents on the campaign record.\n- Set the anchor Audit's period_start, period_end, and report_date (the target filing-support date); attach the full tier due-date schedule as a document on this step, since the per-tier dates have no native field.\n\n**Exit criteria**\nApproved hierarchy version recorded; zero in-scope entities or processes without a certifier; zero departed certifiers still assigned; every delegation documented with an approver; corporate controller approval captured. Representation documents built and version-stamped; every period-change item and every mapped known issue traces to a question or representation; wording reconciled to the draft 302/906 texts; SOX PMO and disclosure counsel approval recorded. Every certifier in the approved hierarchy has a register row with correct scope, version, and due date; upper tiers are staged dependent on lower-tier returns; the issuance reconciliation shows zero gaps; the attestation-package skeleton is attached to the campaign record.\n\n**Scoped representation record**\nEach certifier answers the following statements in their versioned representation document and linked step result. These are required representation contents, not form fields. Preserve the named keys for reconciliation.\n- `certifier_scope` — Entity, process, or segment you are certifying. Must match the scope on your register row; certify only what you are accountable for. Bind the approved register scope without re-entry; a scope mismatch must be resolved before sign-off.\n- `certification_tier` — Your tier in the cascade. Allowed values: `process_owner` (Process owner); `entity_controller` (Entity controller); `segment_cfo` (Segment or divisional CFO). Bind the approved hierarchy tier without re-entry.\n- `information_accuracy` — To my knowledge the financial information and disclosures for my scope are accurate and complete for the period. The certifier personally makes this representation through native approval; do not infer assent from a prepared document or another person’s approval. If they cannot make it, record the qualification and withhold acceptance until the gap or exception route resolves it.\n- `control_operation` — Did the controls in your scope operate as designed during the period?. Allowed values: `operated_as_designed` (Yes — operated as designed throughout); `operated_with_exceptions` (Operated with exceptions (described below)); `did_not_operate` (One or more controls did not operate). The certifier selects one of these three values for the current period. Both adverse values require the associated exceptions and remain visible to triage.\n- `exceptions_and_qualifications` — Every exception, control failure, or qualification to this certification. Enter \"none\" if there are none. A qualification disclosed here is credible; a clean certification over a known issue is not. Retain every qualification and all known issues, plus the certifier’s additions or corrections; a clean answer cannot erase an open issue.\n- `changes_in_controls` — Material changes to processes, systems, personnel, or controls in your scope during the period. Enter \"none\" if there were none — this feeds the changes-in-ICFR representation. State the current-period position explicitly, including an affirmative none where applicable; carry this into the changes-in-ICFR representation.\n- `fraud_or_misconduct` — Any known or suspected fraud, misconduct, or complaint touching financial reporting in your scope. Enter \"none\" if you are aware of none, including matters raised to you by others. State current knowledge explicitly, including matters raised by others and an affirmative none where applicable; preserve every allegation for triage, regardless of materiality.\n- `certification_date` — Date of this certification. Record the actual native personal approval date and timestamp, never document creation, dispatch or PMO reconciliation time.\n\nEvery answer is the certifier’s personal, current statement for the assigned period as of sign-off. Previously supplied evidence may be linked or quoted but cannot substitute for that statement. Record qualifications explicitly; blank text, silence, a prepared document, or PMO approval never means none, accurate, complete or returned. Bind personal native approval to the exact document version, scope and period. A substantive correction invalidates the prior approval and requires the same accountable certifier’s renewed approval (or a documented authorized successor), with the prior version retained. An upper-tier approval waits for accepted lower-tier returns or a Controller-authorized gap resolution explicitly disclosed in its package. The launch authorization approves issuance only and cannot stand in for any certifier’s personal representation.\n","label":"Launch certification cascade","performedBy":{"agent":"sox-artist","note":"frames the 302/906 attestation-package skeleton and stages the tiered issuance","primitives":["coach-item-create","coach-query-data","coach-document-upload","coach-items-link","coach-form-create"]}},"id":"launch-certification-cascade"},{"data":{"decisionField":"completion_status","description":"Decide at the cutoff timestamp whether the certification population is complete, so the campaign proceeds to exception triage on a whole population or first cures its gaps. The corporate controller owns the call, per UC-GOV-07.","formData":{"fields":[{"key":"completion_status","label":"Certification population at cutoff","options":[{"label":"All certifications returned by cutoff","value":"all_returned"},{"label":"Gaps remain at cutoff","value":"gaps_remain"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nDecide at the cutoff timestamp whether the certification population is complete, so the campaign proceeds to exception triage on a whole population or first cures its gaps. The corporate controller owns the call, per UC-GOV-07.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe certification register from launch (the XLSX on the campaign record): one row per certification with certifier, tier, scope, version, and due date.\n- The approved hierarchy with each certifier's tier-above escalation contact — the hierarchy document from launch-certification-cascade.\n- The cutoff date (the anchor Audit's period_end / target filing-support date) and the questionnaire version stamp.\n- The known-issue-to-certifier map from the questionnaire refresh (keyed to the open deficiency Issue items), for the quality screen.\n\n*Agent retrieval, preparation and filing absorb “Track completion and chase stragglers”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Track completion and chase stragglers: Drive returns toward a complete, quality-screened population by the cutoff, so no certification is silently missing or defective when the cutoff reconciliation runs, per UC-GOV-07 and UC-GOV-21.\n\n2. Build the completion dashboard: returned, in-progress, and outstanding certifications by tier, segment, and entity, with aging against the cutoff. Watch the tier dependencies specifically — a late process owner blocks their entity controller, who blocks their segment CFO; the dashboard should expose that chain before it compresses the final tier's window.\n3. Screen every return for completeness defects: unanswered representation statements, missing personal native approval bound to the exact package version, an outdated questionnaire version, or scope narrower than assigned. Route defective returns back to the certifier with the specific gap named. A certification is not \"returned\" until it passes the screen.\n4. Apply the quality screen for reflex sign-offs: an all-clean certification returned minutes after issuance, or a clean response from a certifier whose scope carries a mapped known issue the targeted question was written to surface, gets a follow-up before acceptance. A clean answer over a known open deficiency is itself an exception candidate, not a relief.\n5. Chase stragglers through the accountability chain — the entity controller chases their process owners, the segment CFO chases their controllers — and log every chase with its date and response against the affected certification's register row and as comments on the campaign record, so the escalation trail is evidence, not folklore.\n6. Snapshot the completion position ahead of the cutoff: every certification still outstanding, its certifier, its scope, and the tier-dependency impact of its absence.\n7. Human checkpoint: the SOX PMO lead reviews the dashboard and chase log, confirms escalations are running through the right tier, and flags certifiers at risk of missing the cutoff to the corporate controller while there is still time to intervene.\n\n8. Assessment scope for Assess completion at cutoff: Decide at the cutoff timestamp whether the certification population is complete, so the campaign proceeds to exception triage on a whole population or first cures its gaps. The corporate controller owns the call, per UC-GOV-07.\n\n\n\n**all_returned** (All certifications returned by cutoff) — every certification in the approved hierarchy is returned AND accepted by the completeness screen as of the cutoff timestamp: current questionnaire version, all representation statements answered, personal native approval bound to the exact package version and assigned period present, full assigned scope covered. A return sitting in rejected-pending-rework status counts as outstanding, not returned. On this branch the population closes and the campaign proceeds directly to exception triage.\n- **gaps_remain** (Gaps remain at cutoff) — any certification is missing, rejected by the screen and not yet re-returned, or covers less than its assigned scope. Even one gap forces this branch: an undocumented hole in the population silently weakens the officers' basis for certifying, so each gap must be escalated and either cured with a late certification or converted into a documented exception with an alternate procedure before triage.\n\nPresent the gap list with significance, not just a count — an outstanding segment-CFO roll-up leaves an entire segment unsupported, while a single small process leaves a narrow slice. The controller should see exactly what the population would omit on each path before choosing.\n\n**Record in AssureSwarm**\nBuild the completion dashboard over the campaign record and its certification register (returned / in-progress / outstanding by tier, with aging against the cutoff).\n- Log chases and responses against each certification's register row and as comments on the campaign record; update each certification's screen status in the register as returns pass or fail the screen — with no Certification item type, the register carries the per-certification status and chase trail.\n- Record the pre-cutoff snapshot — the outstanding list with certifier and scope — as a document on this step.\n\nSubmit this step's form: `completion_status` = the chosen branch; the step result = the reconciliation reference (returned-and-accepted count against the approved population as of the cutoff timestamp) plus the outstanding list with scope significance; the step's approver record = the corporate controller making the call.\n\n**Exit criteria**\nEvery return screened, with defects routed back and re-returns tracked; the chase log is current on every outstanding certification; the pre-cutoff snapshot is recorded; the at-risk list is in front of the corporate controller before the cutoff, not after it. Form submitted; the rationale cites the cutoff reconciliation and names every outstanding certification, or states there are none; the unused branch is prunable because the recorded value matches one branch edge.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` sends the tier-routed chase and escalation notices with a logged trail; `/coach-workflow-scan` surfaces per-certifier status and aging against the cutoff.","kind":"decision","label":"Assess completion at cutoff","performedBy":{"note":"","primitives":["coach-query-data","coach-dashboard-create","coach-workflow-scan","coach-notify"]}},"id":"assess-completion-at-cutoff"},{"data":{"description":"Agent escalates every outstanding certification and drafts alternate procedures where none can be obtained; human corporate controller confirms each gap is cured or documented as an exception","instructions":"**Objective** — Convert every gap standing at the cutoff into either a cured, screened certification or an explicit, owned exception with an alternate procedure, so the principal officers never sign over a silent hole in the population, per UC-GOV-07.\n\n**Inputs**\n- The cutoff reconciliation and its outstanding list: certifier, scope, tier, aging.\n- The approved hierarchy with escalation contacts.\n- The filing calendar — every day of continued delay compresses the disclosure committee's and the officers' review windows.\n- The chase log showing what escalation has already been attempted.\n\n**Procedure**\n1. Escalate each outstanding certification to the responsible segment CFO and the corporate controller, recording the escalation against the certification's register row and as a tracked entry in the escalation-log document on this step — stating the certifier, the uncovered scope, and the filing-calendar impact of continued delay (there is no native task/action item type, so the escalation trail lives in the register and the step document). Escalation above the certifier's own chain is warranted now — tier-level chasing already ran during tracking and did not produce a return.\n2. Record each late certification as it arrives with its return date and the escalation that produced it, and re-run the completeness and quality screens before acceptance — late does not mean unscreened.\n3. Where no certification can be obtained — a departed certifier with no successor in place, or an entity issue preventing sign-off — draft the alternate procedure: either a delegate certifier with documented authority over the scope, or a direct review by the controller organization covering the entity's close package, account reconciliations, and known-issue list. Record the residual scope gap as an Issue (issue_type: exception, source: management_identified, issue_owner, identified_date) linked to the campaign-record Audit and routed to exception triage, with the alternate procedure captured on the Issue, so it reaches principal-officer visibility rather than dying here.\n4. Update the population reconciliation so the final record shows every gap and how it resolved: cured, with return date and screen result, or excepted, with alternate procedure and owner. There is no third state.\n5. Human checkpoint: the corporate controller confirms every gap is now either a returned, accepted certification or a documented exception with an accountable owner and an alternate procedure, and releases the population to exception triage.\n\n**Record in AssureSwarm**\n- For each residual gap that cannot be cured, create an Issue (issue_type: exception, source: management_identified, issue_owner, identified_date) and link it to the campaign-record Audit (Issue ↔ Audit); record the alternate procedure on the Issue's remediation_plan.\n- Record late returns and their screen results against the certification register rows; log the per-gap escalation trail in the escalation-log document on this step (no native task item type).\n- Record the updated population reconciliation showing each gap's resolution — cured (return date, screen result) or excepted (alternate procedure, owner) — as a document on this step.\n\n**Exit criteria** — Zero unresolved gaps: each is a returned-and-accepted certification or an exception Issue with an owner and an alternate procedure; the final reconciliation accounts for the full population; the corporate controller's release to triage is recorded.","label":"Resolve certification gaps","performedBy":{"primitives":["coach-item-create","coach-query-data"]}},"id":"resolve-certification-gaps"},{"data":{"decisionField":"exception_escalation","description":"Decide whether anything the cascade surfaced is material enough to put in front of the disclosure committee before the principal officers sign. The corporate controller and disclosure counsel own the call jointly, per UC-GOV-21 and UC-FIN-02.","formData":{"fields":[{"key":"exception_escalation","label":"Exception escalation disposition","options":[{"label":"Escalate to disclosure committee","value":"escalate_disclosure_committee"},{"label":"Handle below committee level","value":"handle_below_committee"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nDecide whether anything the cascade surfaced is material enough to put in front of the disclosure committee before the principal officers sign. The corporate controller and disclosure counsel own the call jointly, per UC-GOV-21 and UC-FIN-02.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe returned certifications: flagged exceptions, qualifications, and yes-with-comments responses.\n- Scope-gap exceptions carried in from gap resolution, where that path ran.\n- The open deficiency log, for duplicate matching.\n- The period's materiality thresholds, for early context on significance.\n\n*Agent retrieval, preparation and filing absorb “Triage exceptions and qualifications”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Triage exceptions and qualifications: Normalize everything the cascade surfaced into a triaged exceptions log where every item carries a classification, an owner, and a downstream route, per UC-GOV-21.\n\n2. Extract every exception, qualification, and yes-with-comments response into the period exceptions log with certifier, entity or process, and a plain-language description of what was raised. Read every free-text comment field, not just the flagged answers — certifiers routinely qualify in prose (\"clean, except for…\") while ticking the clean box.\n3. Classify each item: control-deficiency implication, disclosure implication, or clarification requiring no further action, and record the rationale. The classification test: could this, alone or aggregated with similar items, indicate a control failed to operate or that a disclosure is needed? When in doubt, classify as control-implicating — a misfiled clarification silently escapes the deficiency process, and that is the worse error.\n4. De-duplicate against the open deficiency log: an exception restating a known open deficiency links to the existing record and evidences that the certifier acknowledged it; a genuinely new fact pattern gets a new record.\n5. For each control-implicating item, create a deficiency Issue (issue_type: deficiency, source: management_identified, severity, issue_owner, identified_date) and link it to the campaign-record Audit (Issue ↔ Audit) and to the implicated Control (Issue ↔ Control), then route it twice: into the SOX Deficiency Remediation workflow for root-cause analysis and corrective action, and onto the period's deficiency log consumed by the Year-End Deficiency Aggregation & Severity Evaluation workflow — nothing raised in a sub-certification may escape the year-end aggregation and severity call. These linked deficiency Issues are the handoff package both downstream workflows anchor on.\n6. Compile the triaged exceptions log, with classifications and both routings, on the campaign record.\n7. Human checkpoint: the SOX PMO lead reviews each classification, corrects any exception misfiled as a clarification, and confirms every control-implicating item now has a linked deficiency record with a named owner and both downstream routes recorded.\n\n8. Assessment scope for Evaluate exception materiality: Decide whether anything the cascade surfaced is material enough to put in front of the disclosure committee before the principal officers sign. The corporate controller and disclosure counsel own the call jointly, per UC-GOV-21 and UC-FIN-02.\n\n\n\n**escalate_disclosure_committee** (Escalate to disclosure committee) — any exception meets one or more of: (a) quantitative magnitude at or approaching the period's materiality thresholds — escalate well below the bright line when qualitative factors compound; (b) qualitative significance under SAB 99-style factors: indications of fraud or management override, restatement risk, masking a trend or affecting covenant compliance, or touching a segment the market watches; (c) it evidences a change in ICFR during the period that may itself require disclosure in the filing; (d) left unescalated, it would make a drafted Section 302 representation inaccurate as written; or (e) recurrence or a worsening trend across quarters raises its significance beyond the single item.\n- **handle_below_committee** (Handle below committee level) — every item is quantitatively immaterial, free of the qualitative flags above, fully handled by the deficiency and remediation routes already recorded, and consistent with the drafted representations as written. Below-committee handling is a routing choice, not suppression: every item stays on the exceptions log the officers see at sign-off.\n\nScore item by item — a single escalating exception forces the committee branch for the campaign even when everything else on the log is a clarification.\n\n**Record in AssureSwarm**\nCreate a deficiency Issue (issue_type: deficiency, source: management_identified, severity, issue_owner, identified_date) per control-implicating item; link it to the campaign-record Audit (Issue ↔ Audit) and the implicated Control (Issue ↔ Control), and to the existing deficiency Issue when the exception restates a known one.\n- Record the triaged exceptions log — every exception, qualification, and commented response with classification, rationale, and both downstream routings — as an XLSX document on the campaign record.\n- Record the classification rationale on each row of the triaged exceptions log (non-control-implicating items live only as log rows, with no item).\n\nSubmit this step's form: `exception_escalation` = the chosen branch; the step result = the per-item scoring — each exception's quantitative magnitude against threshold, its qualitative flags, and why it does or does not escalate; the step's approver record = the corporate controller and disclosure counsel making the call.\n\n**Exit criteria**\nEvery exception, qualification, and commented response is on the log with a classification and rationale; every control-implicating item has a linked deficiency record, a named owner, and both downstream routes recorded; the SOX PMO lead's review of the classifications is complete. Form submitted; the rationale covers every exception on the log individually, not as a batch; the unused branch is prunable because the recorded value matches one branch edge.","kind":"decision","label":"Evaluate exception materiality","performedBy":{"note":"","primitives":["coach-query-data","coach-item-create","coach-items-link"]}},"id":"evaluate-exception-materiality"},{"data":{"description":"Agent packages the escalated exceptions for the disclosure committee and records its conclusions; human committee chair approves the disposition of every escalated item","instructions":"**Objective** — Put every escalated exception in front of the disclosure committee and capture a documented conclusion per item — disclose, modify the representation, or no disclosure with rationale — before the principal officers certify, per UC-GOV-21.\n\n**Inputs**\n- The escalated exceptions with their materiality scoring from the prior step.\n- The linked deficiency records where control implications exist.\n- The draft Section 302 and 906 certification texts and the draft 10-Q or 10-K disclosure sections they attach to.\n- The committee meeting date from the campaign calendar.\n\n**Procedure**\n1. Draft the committee briefing, one section per escalated item: the facts as certified — in the certifier's own words, not paraphrased into blandness — quantification against the period's materiality thresholds, the linked deficiency record where one exists, and a recommended disclosure treatment. Attach it as the pre-read.\n2. Circulate the pre-read ahead of the scheduled meeting and log attendance and the materials version reviewed. The committee's review is itself part of the disclosure controls and procedures the officers certify — its operation must be evidenced, not assumed.\n3. Record the committee's conclusion per item, one of exactly three: disclose, with the location in the 10-Q or 10-K; modify the draft Section 302 representation or its supporting analysis; or no disclosure required, with the documented rationale. No item leaves the meeting without a disposition and an owner for any resulting filing change.\n4. Link each item needing board or audit-committee visibility into the Quarterly Board & Audit-Committee GRC Reporting workflow — significant deficiencies, material weaknesses, and any fraud involving management must reach the audit committee, as the Section 302 representations themselves require.\n5. Human checkpoint: the disclosure committee chair approves the minutes and the per-item conclusions, confirming no escalated exception leaves the meeting without a documented disposition.\n\n**Record in AssureSwarm**\n- Attach the pre-read and the chair-approved minutes as documents on this step.\n- Record each item's conclusion and rationale in the triaged exceptions log revision on this step — and on the item's deficiency Issue where one exists — with the owner of any resulting filing change.\n- Link the audit-committee-bound deficiency Issues to the campaign-record Audit (Issue ↔ Audit) so the Quarterly Board & Audit-Committee GRC Reporting workflow picks them up.\n\n**Exit criteria** — Every escalated exception carries a committee conclusion with rationale; chair-approved minutes are attached; every resulting filing change has a named owner; items requiring audit-committee visibility are linked into the reporting workflow.","label":"Brief disclosure committee","performedBy":{"primitives":["coach-document-upload","coach-items-link"]}},"id":"brief-disclosure-committee"},{"data":{"description":"Agent compiles the certification summary, population coverage, exceptions and dispositions and committee conclusions for the CEO and CFO, then archives the quarter's record with the period's filing support and seeds the next campaign; humans execute the Section 302 and 906 certifications and those signatures close the quarter","instructions":"**Objective** — Assemble the cited attestation package that gives the CEO and CFO a complete, honest basis for executing the Section 302 and 906 certifications filed with the period's report, then preserve the quarter's certification evidence with that filing support and seed the next campaign, per UC-FIN-02.\n\n**Inputs**\n- The full campaign record: the approved certifier hierarchy version, the questionnaire version and change summary, the issuance and chase logs, the population reconciliation (issued, returned, late, alternate-procedure), and the returned sub-certifications indexed by tier and entity.\n- The triaged exceptions log with classifications and dispositions; the disclosure committee pre-read, minutes, and per-item conclusions where the committee was convened.\n- The period deficiency log with severity and remediation status; the linked process narratives; the quarter's testing results where they inform the ICFR representations.\n- The draft Section 302 (Exhibit 31) and Section 906 (Exhibit 32) certification texts.\n- The SOX retention schedule governing filing support, and the carry-forward candidates noted during triage.\n\n**Procedure**\n\n_Items 8–12 close the quarter (folded from the former \"Close and archive\" step); the officers' execution of the certifications at item 7 is the closure — no separate closure declaration follows._\n\n1. Assemble the package into the skeleton framed at launch:\n   - the cover letter carrying the standard Section 302/906 certification language the officers will execute;\n   - the executive summary stating the ICFR position and the key changes since the prior cycle — systems, reorganizations, policy changes — the direct basis for the changes-in-ICFR representation;\n   - the population coverage matrix reconciling certifications returned against the population issued: issued, returned, late, and alternate-procedure counts by tier and segment, tied to the approved hierarchy;\n   - the deficiency summary table by severity (deficiency, significant deficiency, material weakness), remediation status, and FSLI impact;\n   - the material-weakness assessment where any MW exists or is pending severity evaluation, with its disclosure consequence stated plainly;\n   - the process narratives linked, not inlined, and the controls × tests × results coverage view where the quarter's testing supports the ICFR representations;\n   - management responses and remediation plans for each significant item, and the full exceptions log with dispositions and committee conclusions.\n2. Apply cite-every-claim discipline: every statement in the memo traces to a named artifact — a returned certification, a deficiency record, committee minutes, the reconciliation. A claim with no citation does not go in front of the officers; this package becomes SEC filing support and is built to that grade.\n3. Reconcile the draft certification texts against what the cascade surfaced: any change in ICFR during the period is reflected; significant deficiencies, material weaknesses, and any fraud involving management have been communicated to the audit committee and the external auditor, as the Section 302 representations require; the Section 906 fair-presentation statement is consistent with the exceptions record.\n4. Scrub the package of internal review notes and unresolved drafting comments — the officers' copy must be clean. Anything unresolved moves to the open-questions list rather than lingering in the text.\n5. Surface every open question for the SOX lead to resolve before the officers see the package — nothing lands on the CEO's or CFO's desk unresolved. Then capture the officers' own questions and the resolutions provided, so the record shows the certifications were informed rather than pro forma.\n6. Stage the sign-off package — summary memo, draft certifications, and the underlying sub-certifications indexed by tier and entity — for the officers, and per policy for the external auditor and the audit committee.\n7. The CEO and CFO review the summary memo, satisfy themselves that the sub-certification population and exception dispositions support each representation, and execute the Section 302 and 906 certifications for filing with the 10-Q or 10-K. Those signatures close the quarter's campaign; items 8–12 execute the closure.\n8. Export the complete campaign record and archive it with the period's 10-Q or 10-K filing support under the SOX retention schedule — certification support conventionally follows the seven-year retention expectation applied to audit workpapers.\n9. Verify archive completeness before declaring it done: every artifact indexed and retrievable; every exception traceable from the raising certification through classification, routing, and disposition; the deficiency routings into the SOX Deficiency Remediation workflow and onto the year-end aggregation log recorded. Any post-archive correction is a new dated addendum referencing the archived artifact, never an edit to it.\n10. Carry forward what next quarter needs, each with an owner and a due date: exceptions still open stay as open Issue items carrying a target_remediation_date; the non-finding carry-forwards — certifiers who returned late and need earlier engagement, questionnaire updates promised during triage, and hierarchy changes already known to be coming — have no native task item type and are recorded in a carry-forward document on this step. This set seeds the next quarter's campaign at launch.\n11. Send the closure notice to the certifier population and finance leadership with the quarter's completion and exception metrics — return rate by tier, exceptions raised and their classifications, committee escalations. Keeping the reporting channel visible between campaigns is what UC-GOV-21 asks of the cadence.\n12. Set the anchor Audit's status to its closed/complete state with report_date at the close date.\n\n**Record in AssureSwarm**\n- Attach the assembled sign-off package and, once executed, the signed Section 302 and 906 certifications as documents.\n- Record the certification-text reconciliation, the open-questions list with resolutions, and the officers' questions and answers on this step, so the informed-certification trail is preserved.\n- Export the workflow instance (the run itself is the audit trail) and record the archive confirmation as a document on the campaign record; set the anchor Audit's status and report_date.\n- Keep still-open exceptions as open Issue items with a target_remediation_date; record the non-finding carry-forwards (early-engagement list, promised questionnaire updates, known hierarchy changes) in a carry-forward document on this step (no native task item type), linked to this campaign.\n- Record the closure notice and its distribution list as a document on this step.\n\n**Exit criteria** — Package complete with every section cited to underlying artifacts; the open-questions list resolved to zero before sign-off; the certification-text reconciliation documented; the executed 302 and 906 certifications attached; the archived package verified complete and retrievable with its confirmation recorded; every carry-forward item owned and dated; the closure notice sent to the certifier population and finance leadership.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles and renders the officer sign-off package — cover letter, executive summary, deficiency table, coverage matrix, indexed sub-certifications — directly from the campaign record, and `/coach-notify` sends the closure notice with a logged distribution trail.","label":"Summarize for principal-officer sign-off","performedBy":{"agent":"sox-artist","note":"compiles the cited 302/906 attestation package for officer sign-off","primitives":["coach-query-data","coach-document-upload","coach-render-package","coach-workflow-export","coach-item-create","coach-notify"]}},"id":"summarize-for-principal-officer-signoff"}],"sourceTemplateId":"workflow-library:sox-subcertification-cascade"}
