workflow
Year-End Deficiency Aggregation & Severity Evaluation
Year-End Deficiency Aggregation & Severity Evaluation as a modular, decision-aware workflow. The instance runs against the existing fiscal-year ICFR assessment engagement — the Audit item with audit_type=sox_testing whose period_end is fiscal year end — enriching it rather than creating a duplicate: the frozen register snapshot and the full evaluation memo trail attach to its steps, and the overall ICFR conclusion lands on that Audit item (rating/opinion/report_date). It closes the gap between per-deficiency handling and the portfolio view: it freezes the register, reconciles it to every failed test, aggregates related deficiencies, concludes control deficiency versus significant deficiency versus material weakness, and hands conclusions to certification support, remediation, and audit-committee reporting instead of duplicating their work. The named deliverables are the year-end deficiency-evaluation memo (carrying the overall ICFR conclusion) and the countersigned final severity schedule. In scope: freezing and severity-evaluating the year-end deficiency population as of the fiscal-year-end assessment date, kept live through the 10-K filing date under a late-arrival rule. Out of scope, handed off rather than duplicated: fixing the deficiencies (SOX Deficiency Remediation) and reporting them to the board (Quarterly Board & Audit-Committee GRC Reporting). Severity thresholds and the contributing-test population are consumed from the Annual ICFR Scoping & Risk Assessment, SOX Key Control TOD/TOE Test, and SOX ITGC Testing runs — the deficiency register itself is the Issue population (issue_type deficiency, escalating to significant_deficiency and material_weakness as this workflow finalizes).
Record JSON · Open in map · Data retrieval guide
Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.
Attributes
- domain
- sox
- department
- finance
- lineOfDefense
- monitor
Details
- teams
- finance
- domains
- sox
- standards
- sox
- coso-ic
- sourceTemplateId
- workflow-library:sox-deficiency-aggregation-evaluation
- releaseId
- sha256:9b4a1c1e81a2665c85165fa8a26c94debca482f1af27a23a4898507907cce79c
- canonicalUrl
- https://assureswarm.com/workflows/all/?w=sox-deficiency-aggregation-evaluation
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-RISK-14
- UC-AUDIT-14
- UC-AUDIT-17
- UC-AUDIT-21
- UC-GOV-21
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:9b4a1c1e81a2665c85165fa8a26c94debca482f1af27a23a4898507907cce79c
Connections
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-RISK-14 — Track deficiencies to closure with remediation action plans
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-GOV-21 — Communicate and report risk and control information
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-AUDIT-14 — Evaluate findings and develop recommendations and action plans