workflow

Board Risk & Internal Control Oversight Cycle

Board Risk & Internal Control Oversight Cycle as a decision-aware workflow: the governance office verifies board independence and expertise, compiles the board risk & internal-control oversight pack, routes the at-least-annual governance-framework effectiveness evaluation, facilitates the independent board's approval of the risk strategy and material policies, captures and minutes the directed adjustments, and launches and tracks them as an owned open directives register. It is standalone: the governing body and the governance framework are not Studio item types, so there is no natural item anchor — each cycle runs as a fresh recurring workflow instance and its deliverables attach to the run's own steps. The named deliverables are the composition-and-independence summary, the board risk & internal-control oversight pack, the annual governance-and-management-framework effectiveness evaluation when in scope, the adopted board/committee minutes, and the board directives-and-adjustments register (one Issue item per directive, linked across cycles). The risk strategy and material policies the board approves are Policy items (approved_by, version, next_review_date); board directives, approval conditions, and framework adjustments are Issue items (issue_type: observation, source: management_identified). In scope: a single named governing body's quarterly (or specially convened) risk and internal-control oversight meeting and, where the annual clock or a substantial-change trigger applies, that cycle's enterprise governance and management framework effectiveness evaluation. Out of scope: the day-to-day first- and second-line control operation, testing, and assurance that feed the pack — no workflow hands into this cycle, and the board's directives flow onward into control-remediation and policy-update execution as prose, not a wired downstream template.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
executive
lineOfDefense
operate

Details

teams
  • executive
  • risk-management
domains
  • grc
standards
  • cobit-2019
  • coso-ic
  • coso-erm
  • soc2
sourceTemplateId
workflow-library:grc-board-risk-internal-control-oversight-cycle
releaseId
sha256:699bb8f921e61282509d797631e22c865a0c1b254195bbc6798e50947f563a0f
canonicalUrl
https://workflow-library.com/all/?w=grc-board-risk-internal-control-oversight-cycle
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-GOV-01
    • UC-GOV-05
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:699bb8f921e61282509d797631e22c865a0c1b254195bbc6798e50947f563a0f

            Connections