workflow
Combined Assurance Mapping
Combined Assurance Mapping as a decision-aware workflow. Each cycle runs as one workflow instance attached to an Audit item created for the cycle (audit_type: advisory, scope = the combined-assurance mapping scope for the period, period_start/period_end = the cycle period) — no other Studio type represents an assurance-coordination cycle, so the workflow enriches that Audit item rather than any pre-existing engagement. In scope: mapping assurance coverage across the Three Lines of Defense for the confirmed risk universe and entities this cycle — cataloging assurance providers, mapping their coverage onto the risk universe, assessing reliance, identifying gaps and duplication, coordinating coverage plans, publishing the combined assurance map, and preparing audit-committee reporting inputs. Out of scope: performing the underlying assurance engagements themselves (owned by internal audit, second-line functions, and external providers) and any risk, entity, or provider not named in this cycle's confirmed scope. It consumes the risk universe and residual positions (Risk items with their residual_rating and treatment) from the upstream Enterprise Risk Assessment & Portfolio Oversight Cycle and hands its named deliverables — the published combined assurance map, the reliance conclusions, and the gap action plans — to the downstream Quarterly Board & Audit-Committee GRC Reporting workflow rather than duplicating repeated work.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- internal-audit
- lineOfDefense
- assure
Details
- teams
- internal-audit
- risk-management
- domains
- grc
- standards
- iia-2024
- sourceTemplateId
- workflow-library:grc-combined-assurance-mapping
- releaseId
- sha256:f0ae775a3a86f082f6bcc1a2383a15f8e0219c50577d82600fbd8fa89c947e8e
- canonicalUrl
- https://workflow-library.com/all/?w=grc-combined-assurance-mapping
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-AUDIT-23
- UC-AUDIT-18
- UC-AUDIT-27
- UC-GOV-38
- roleIntegrity
- activityCount
- 2
- ermPhases
- assess
- lineRoles
- second
- third
- serviceModes
- assurance
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:f0ae775a3a86f082f6bcc1a2383a15f8e0219c50577d82600fbd8fa89c947e8e
Connections
- Combined Assurance Mapping tests UC-AUDIT-18 — Communicate with stakeholders on assurance matters
- Combined Assurance Mapping tests UC-AUDIT-27 — Govern expanded internal audit ERM responsibilities
- Combined Assurance Mapping tests UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity
- Combined Assurance Mapping tests UC-AUDIT-23 — Coordinate independent assurance reviews across providers