workflow
Risk & Resilience Framework Governance
Risk & Resilience Framework Governance as a decision-aware workflow. The instance runs on the "Enterprise Risk Management Framework" Process item (process_type: business_process, process_owner = the framework owner, frequency: annual) - created on the first cycle at "Design core ERM framework" and enriched every cycle thereafter, never duplicated; that Process item is the governance register entry, and each governance cycle runs as a workflow instance attached to it, so the at-least-annual cadence is provable from one item's instance history. Working from the organization's context and the ISO 31000 / COSO ERM / DORA reference models - no upstream workflow package feeds it, because this workflow establishes the governance layer - it establishes or refreshes the enterprise risk management framework, extends it for ICT operational resilience and regulated technologies, secures management-body approval and budget, drives implementation across the organization, and runs the at-least-annual review, filling the governance layer the risk-cycle workflows run inside but never establish. The named deliverable is the approved risk & resilience framework package (core ERM design + ICT operational-resilience (DORA) extension + any regulated-technology lifecycle extension), archived at close as durable governance evidence. In scope: the enterprise risk framework, its always-in-scope ICT operational-resilience (DORA) extension, and any regulated-technology (e.g. high-risk AI) extensions to be evaluated. Out of scope: executing the individual risk-cycle workflows (identify / assess / treat / monitor) that run inside this framework - this workflow governs them but does not perform them, and consumes no upstream workflow package. Downstream, the archived framework enables those risk-cycle workflows, which reference it as their governing baseline (the relationship is real but not modeled as a node).
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- risk-management
- lineOfDefense
- operate
Details
- teams
- risk-management
- executive
- domains
- grc
- standards
- iso-31000
- coso-erm
- dora
- sourceTemplateId
- workflow-library:grc-risk-resilience-framework-governance
- releaseId
- sha256:2eaeb9c8bb2b20a89e69ff15a7f08852a99129d1bad280b4e70a722a18fef665
- canonicalUrl
- https://workflow-library.com/all/?w=grc-risk-resilience-framework-governance
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-RISK-01
- UC-BCDR-02
- UC-GOV-17
- UC-RISK-03
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:2eaeb9c8bb2b20a89e69ff15a7f08852a99129d1bad280b4e70a722a18fef665
Connections
- Risk & Resilience Framework Governance operates UC-GOV-17 — Establish enterprise risk management strategy and appetite
- Risk & Resilience Framework Governance operates UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- Risk & Resilience Framework Governance operates UC-BCDR-02 — Establish and govern an ICT operational resilience framework
- Risk & Resilience Framework Governance operates UC-RISK-01 — Establish and maintain a tailored risk management framework