{"description":"Runs on an existing Audit engagement (`audit`) already scoped to one or more significant FSLIs; enriches it, never re-creates it. Inputs: the scoped FSLI(s) (`fsli.balance`, `fsli.assertions`, `fsli.significant`) and a source-system extract per population under test. Named deliverables: the validated population record, the reproducible sample draw, the whole-population analytics results, and the FSLI assertion conclusion (`fsli.rationale`). Handoff: fraud risk and journal-entry testing (the fraud-risk-je-testing workflow) once every exception is dispositioned and the assertion conclusion is recorded.","edges":[{"id":"e-choose-method-conclude","source":"choose-method","target":"conclude"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":["audit-testing"],"controlVerbs":{"UC-AUDIT-11":"operates","UC-AUDIT-13":"operates","UC-AUDIT-14":"operates"},"controls":["UC-AUDIT-11","UC-AUDIT-13","UC-AUDIT-14"],"department":"internal-audit","domains":["audit"],"kind":"substantive-testing-data-analytics","library":{"aliases":[{"source":"assureplugin","sourceTemplateId":"substantive-testing-data-analytics"}],"canonicalUrl":"https://workflow-library.com/all/?w=substantive-testing-data-analytics","contentDigest":"sha256:f305df7947a3a4ed799b3666887edd77425586ee8543d0b2be515df6e862b700","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Restricted step documents and native step results retaining source files, review notes and final conclusions.","id":"workpapers"}],"roles":[{"contribution":"expertise","description":"Approves the procedure, scope and precommitted testing or monitoring criteria.","id":"audit-supervisor","nodeIds":["choose-method"]},{"contribution":"approval","description":"A reviewer other than the preparer; ITGC reviewers must also be independent of control operation.","id":"independent-reviewer","nodeIds":["conclude"]}],"status":"declared"},"provenance":[{"source":"assureplugin/skills/audit-sampling/workflows/substantive-testing-data-analytics.json","sourceTemplateId":"substantive-testing-data-analytics"}],"releaseId":"sha256:f305df7947a3a4ed799b3666887edd77425586ee8543d0b2be515df6e862b700","schemaVersion":1,"sourceTemplateId":"workflow-library:substantive-testing-data-analytics"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"substantive-testing-data-analytics","source":"coworkcanvas-gallery","standards":["iia-2024","sox"],"teams":["internal-audit"]},"name":"Substantive Testing & Data Analytics","nodes":[{"data":{"controls":["UC-AUDIT-11","UC-AUDIT-13"],"instructions":"**Objective** — Fix the assertion, population, materiality and sampling decision before testing.\n\n**Inputs** — Existing Audit engagement and scoped FSLIs with balances, assertions, significant status, assessed and fraud risk; source extracts and related matching populations.\n\n**Procedure**\n1. Freeze the source extract with source system, extraction query and parameters, entity, period and timestamp. Reconcile row counts or value to an independent source; inspect query filters and report completeness and accuracy, or cite approved current-period reliance on the same report and parameters. Profile columns, date boundaries, nulls, numeric ranges and totals. Validate an empty population and record not applicable/no occurrences; draw no sample and make no effectiveness claim.\n2. Use the engagement-approved sampling methodology. The source method uses this nonstatistical baseline for occurrence populations: at most 50 items, round up 10% with a floor of 5 capped at the population; 51–250 items, round up 15%; above 250, 25/40/60 for low/moderate/high risk. Increase for prior deficiencies, changed controls, sole safeguards, elevated risk or external reliance. This baseline does not establish statistical assurance; document the assurance objective, materiality, tolerable error and any statistical design separately. Choose random for homogeneous populations, systematic for temporal coverage, monetary-unit sampling for positive monetary exposure, and documented targeted strata as a supplement. Record the algorithm/version, input row order, seed, population SHA-256, size and date so another tester can reproduce the draw.\n3. Set tolerable misstatement for each population before drawing; use the higher relevant assessed/fraud risk when they differ and document qualitative risks. Declare sample expansion policy and methods for projected misstatement and sampling uncertainty before results exist.\n4. For zero occurrences record the validated empty population and its limitation; retain this as an explicit no-testing outcome in the reviewed conclusion. Execute no draw or analytics that assume observations.\n\n**Record in AssureSwarm** — Record the plan, risk, thresholds, sizing basis and exception policy in the step result; attach frozen populations and independent reconciliation evidence.\n\n**Exit criteria** — The engagement lead provides expertise and approval: the sampling basis supports the assertion and the planned conclusion distinguishes nonstatistical screening from statistical estimation.","label":"Approve substantive population and test plan","requiredApprovals":1},"id":"choose-method"},{"data":{"controls":["UC-AUDIT-13","UC-AUDIT-14"],"instructions":"**Objective** — Review substantive findings and issue the assertion-level conclusion.\n\n**Inputs** — Approved plan, frozen extracts, source documents and any invoice/receipt/purchase-order match files.\n\n**Procedure**\n1. Draw the approved sample and verify its row count and SHA-256 against the validated population. Record selected keys and any authorized replacements. Test each sample item against the assertion criteria and retain supporting evidence.\n2. Run whole-population duplicate key-plus-amount detection, sequence gaps where keys are sequential, and three-way match where relevant. Identify missing matches and amount differences above the approved currency tolerance (the source procedure uses 0.005 currency units). Recompute totals against FSLI balance and quantity-times-price calculations where columns permit; document unavailable inputs or inapplicable procedures explicitly.\n3. Precommit an exception policy before seeing results: expand once by a stated increment or stop and evaluate. Preserve the original exception after expansion. Replace only demonstrably out-of-scope, voided or duplicate rows using the same method and seed lineage; missing evidence is an exception. Prefer reperformance and inspection to observation and inquiry; investigate contrary evidence and distinguish an observed failure from an unsupported representation.\n4. Disposition every sample and analytics-flagged item individually. For approved count-based projections record the exception rate and the population count/value to which it is applied, distinguishing deviation counts from monetary misstatement. For monetary-unit sampling compute each applicable tainting percentage times sampling interval, treating high-value items and sampling uncertainty under the approved method. Do not use either simplified estimate as a statistical upper bound.\n5. Compare known/projected misstatement, uncertainty and qualitative exceptions with tolerable misstatement. Raise linked Issues with issue_type exception and source internal_audit; record root cause only where supported. Update fsli.rationale if that field exists with population, method, sample, analytics, exceptions, limitations and assertion conclusion. A substantive test does not update a control operating-effectiveness result.\n6. Hand off fraud or override indicators to the fraud/JE procedure and the reviewed assertion package to engagement reporting.\n\n**Record in AssureSwarm** — Attach the draw, algorithm/version, analytics and support; record every disposition and projection in the result. Link Issues to the FSLI and Audit and capture independent review in native approvals.\n\n**Exit criteria** — An audit reviewer independent of preparation provides expertise and approval: every selected and flagged item has a disposition, projection assumptions are stated, and the assertion conclusion follows the evidence.","label":"Evaluate sample, analytics and assertion evidence","requiredApprovals":1},"id":"conclude"}],"sourceTemplateId":"workflow-library:substantive-testing-data-analytics"}
