Control Intelligence

AI Analysis Results

Obligation Tracking & PerformanceContract & Legal Management

Back to Sub-Process
38
/ 100
Deficient
Overall Sub-Process Rating
DeficientControl is missing, ineffective, or materially gapped.
1 control evaluated3 strengths identified4 gaps identified
Executive Summary

The Obligation Tracking & Performance process has material control deficiencies that require immediate management attention. Key controls are either absent, not operating effectively, or lack sufficient evidence of design and execution. The current state exposes the organization to significant financial reporting and compliance risk.

Strengths
  • Contractual obligations (milestones, SLAs, penalties) are tracked and... has been partially implemented
  • Exception reporting is generated and reviewed timely
  • Management review is performed on a regular cadence
Gaps
  • Access recertification cadence does not meet policy requirements
  • Monitoring controls are not formally documented or tested
  • Evidence of review lacks timestamp and reviewer identity
  • No automated alerting for control threshold breaches
Recommendations
  1. 1Conduct an annual control design assessment aligned with framework updates
  2. 2Develop a remediation tracker with defined SLAs and escalation paths
  3. 3Implement a workflow tool that captures reviewer identity and timestamp for all approvals
  4. 4Automate exception detection and route alerts to control owners within 24 hours
Framework Mapping
COSO 2013
Principle P16
SOX 404
ICFR.CM.OT.01
IIA Standards 2024
IV.9.3

Control-Level Breakdown (1)

CM-OT-01Needs ImprovementScore: 43/100
Contractual obligations (milestones, SLAs, penalties) are tracked and reported to management.
Key Finding

The control is partially implemented but operates inconsistently. Contractual obligations (milestones, SLAs, penalties) are tracked and reported to management. Gaps in execution or evidence retention reduce assurance over this area.

Recommendation

Redesign the control to address inconsistencies. Specifically: contractual obligations (milestones, slas, penalties) are tracked and reported to management. Assign a control owner and establish a testing cadence.

Framework Tags
COSO P16ICFR.CM.OT.01IIA IV.9.3