workflow
Quarterly Board & Audit-Committee GRC Reporting
Runs on the existing standing "Board & Audit-Committee GRC Reporting" governance Process item (process_type=business_process, frequency=quarterly): one workflow instance per quarter attaches to that Process and enriches it (the Process is not created here), and each closed instance is the prior-quarter baseline for the next run. The named deliverable is the quarterly board & audit-committee GRC pack (six-domain narrative deck, Word + PDF, redaction-cleared). It compiles that pack across six domains — risk profile, control health, open issues, regulatory deadlines, audit-plan progress, and SOX posture — computed over one quarter window. In scope: aggregating and synthesizing existing GRC records (Risk, Control, Issue, Audit, and Control-hosted SOX testing workflows) into a board-level narrative, obtaining executive and committee approval, and archiving the decision and action register. Out of scope: performing the underlying risk assessments, audits, or control tests themselves. Consumes two upstream handoff packages: the Enterprise Risk Assessment & Portfolio Oversight Cycle package (risk register, residual scores, appetite positions) and the Audit Report Drafting & Regulatory Compliance Attestation Cycle package (audit-plan status, issued reports, attestation status); there is no downstream workflow — the closed package feeds the next quarterly run of this workflow.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- risk-management
- lineOfDefense
- monitor
Details
- teams
- risk-management
- internal-audit
- executive
- domains
- grc
- standards
- coso-erm
- iia-2024
- sourceTemplateId
- workflow-library:grc-quarterly-board-audit-committee-reporting
- releaseId
- sha256:6d75ecb22ff2f49635ee533d71e7f61e415ea80adf9c9b1366b87543baf635a9
- canonicalUrl
- https://workflow-library.com/all/?w=grc-quarterly-board-audit-committee-reporting
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-GOV-05
- UC-GOV-21
- UC-AUDIT-22
- UC-AUDIT-18
- UC-RISK-10
- UC-RISK-14
- roleIntegrity
- activityCount
- 2
- ermPhases
- report
- lineRoles
- third
- board
- serviceModes
- advisory
- decision
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:6d75ecb22ff2f49635ee533d71e7f61e415ea80adf9c9b1366b87543baf635a9
Connections
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-GOV-05 — Ensure board-level oversight of risk and internal control
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-AUDIT-18 — Communicate with stakeholders on assurance matters
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-GOV-21 — Communicate and report risk and control information
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-AUDIT-22 — Review risk strategy and performance with leadership
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-RISK-14 — Track deficiencies to closure with remediation action plans