{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","download":{"releaseId":"sha256:bc6cf5860fdb27f325962c466df236c9c4a31f63c44be4a365cd49f1343cfb2c","slug":"sox-financial-controls-policy-segregation-of-duties","url":"/assets/agent_workflow-sox-financial-controls-policy-segregation-of-duties-d991d599.0cd7102b2875b0c0.json"},"kind":"record","record":{"attributes":{"department":"finance","domain":"sox","lineOfDefense":"operate"},"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=sox-financial-controls-policy-segregation-of-duties","description":"Financial controls policy and segregation-of-duties governance as a decision-aware workflow covering annual policy-suite reapproval and communication, quarterly SoD conflict-matrix refresh, role and system-access conflict screening, mitigating-control documentation, and owner-assignment confirmation, closed out with a control-indexed certified evidence package. Each run is one workflow instance on the existing Process item \"Financial Controls Policy & SoD Governance\" (process_type: financial_reporting, quarterly cadence), enriching — never recreating — the financial-control Policy suite (entity-wide ITGC and period-end financial reporting oversight policies held as Policy items) and the existing Control items UC-FIN-01 and UC-FIN-05 that the cycle operates. In scope: reapproval and communication of the Policy suite and segregation-of-duties screening across the in-scope entities, finance systems, and personnel, with the cycle running either annual policy reapproval plus the quarterly SoD review or the quarterly SoD review alone; out of scope: access provisioning and remediation execution themselves. As a standing governance control it takes no upstream workflow feed and runs on its own annual/quarterly cadence, but it hands off the remediation and deficiency Issues it raises — elimination-path access conflicts and recorded deficiencies — to the access-management and deficiency-evaluation processes that execute them.","details":{"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=sox-financial-controls-policy-segregation-of-duties","capabilities":[],"controls":["UC-FIN-01","UC-FIN-05"],"domains":["sox"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:bc6cf5860fdb27f325962c466df236c9c4a31f63c44be4a365cd49f1343cfb2c","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:sox-financial-controls-policy-segregation-of-duties","standards":["sox"],"teams":["finance"]},"download":{"releaseId":"sha256:bc6cf5860fdb27f325962c466df236c9c4a31f63c44be4a365cd49f1343cfb2c"},"history":{"digest":"9026a15e9d5b4bba45b674d31416bd76f7102c55e304ff7e94ca99a739f3f564","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-10-04T21:48:26Z","updatedRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4"},"id":"wf:S11","mapUrl":"https://evidenceflows.com/?v=1&node=wf%3AS11","slug":"sox-financial-controls-policy-segregation-of-duties","sourceIds":["sox"],"sourceUrl":null,"title":"Financial Controls Policy & Segregation-of-Duties Governance","type":"workflow"},"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:0efdcd77b91054b91bb1a3ca9f941d649d275efea96e232be81bda388373eedd","properties":{},"sourceDetailPath":"/data/v1/records/wf-s11-1dc58397.json","sourceId":"wf:S11","targetDetailPath":"/data/v1/records/uc-uc-fin-05-52738635.json","targetId":"uc:UC-FIN-05","type":"operates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:92c166528433d4ccfc30ca9994e04b7a10b1934598d096f9144c302388cbe0f2","properties":{},"sourceDetailPath":"/data/v1/records/wf-s11-1dc58397.json","sourceId":"wf:S11","targetDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","targetId":"uc:UC-FIN-01","type":"operates"}],"schemaVersion":1}
