{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","download":{"releaseId":"sha256:ed2a45e38c53e33cf5f928ceda0401b42ec8fd5969528156e4aaea79d5455ee7","slug":"sox-deficiency-remediation","url":"/assets/agent_workflow-sox-deficiency-remediation-3ab06039.76906c9c1644b8dd.json"},"kind":"record","record":{"attributes":{"department":"finance","domain":"sox","lineOfDefense":"monitor"},"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=sox-deficiency-remediation","description":"SOX Deficiency Remediation carries one control deficiency's full lifecycle — grade, root cause, remediation, validation, and closure. The workflow runs on the deficiency **Issue item** it opens at grading — `issue_type` set to the exact SOX grade (deficiency / significant_deficiency / material_weakness) and `severity` on the mapped AssureSwarm scale — linked to the affected Control(s), the source Control-hosted SOX testing workflow (template kind: sox-testing), and the current-year SOX audit (Audit, `audit_type: sox_testing`); the remediation actions and the validation retest live as steps on this Issue's own workflow. In scope: a single deficiency triggered by a failed test or unresolved exception. It **consumes** the concluded, reviewed failed-test workpaper handoff package owned upstream (SOX Key Control TOD/TOE Test and SOX ITGC Testing) and **hands off** the closed-or-carried deficiency outcome — with its intact severity history and any triggered communication obligations — to Quarterly Board & Audit-Committee GRC Reporting, which aggregates the full deficiency population into the period's ICFR conclusion and audit-committee materials. It exchanges handoff packages with those related workflows rather than duplicating their work.","details":{"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=sox-deficiency-remediation","capabilities":[],"controls":["UC-RISK-14","UC-AUDIT-17"],"domains":["sox"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:ed2a45e38c53e33cf5f928ceda0401b42ec8fd5969528156e4aaea79d5455ee7","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:sox-deficiency-remediation","standards":["sox","coso-ic"],"teams":["finance"]},"download":{"releaseId":"sha256:ed2a45e38c53e33cf5f928ceda0401b42ec8fd5969528156e4aaea79d5455ee7"},"history":{"digest":"fda43b314db47e951bfa8aa3d8bb9d79050d9abd7b30a2cbdc5b635471fb4862","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-10-04T21:48:26Z","updatedRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4"},"id":"wf:S3","mapUrl":"https://evidenceflows.com/?v=1&node=wf%3AS3","slug":"sox-deficiency-remediation","sourceIds":["iia-2024","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"SOX Deficiency Remediation","type":"workflow"},"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:1d91d30656aa69c195e6359265a95d445cc7626eb4b45a349e69b6eab0da234c","properties":{},"sourceDetailPath":"/data/v1/records/wf-s3-0d4673bb.json","sourceId":"wf:S3","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"oversees"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:807d133d67b44710c9c60794b198d6f6060299b5fc2befcabd673a3263ce7197","properties":{},"sourceDetailPath":"/data/v1/records/wf-s3-0d4673bb.json","sourceId":"wf:S3","targetDetailPath":"/data/v1/records/uc-uc-risk-14-a5d6281b.json","targetId":"uc:UC-RISK-14","type":"oversees"}],"schemaVersion":1}
