workflow

Combined Assurance Mapping

Combined Assurance Mapping as a decision-aware workflow. Each cycle runs as one workflow instance attached to an Audit item created for the cycle (audit_type: advisory, scope = the combined-assurance mapping scope for the period, period_start/period_end = the cycle period) — no other Studio type represents an assurance-coordination cycle, so the workflow enriches that Audit item rather than any pre-existing engagement. In scope: mapping assurance coverage across the Three Lines of Defense for the confirmed risk universe and entities this cycle — cataloging assurance providers, mapping their coverage onto the risk universe, assessing reliance, identifying gaps and duplication, coordinating coverage plans, publishing the combined assurance map, and preparing audit-committee reporting inputs. Out of scope: performing the underlying assurance engagements themselves (owned by internal audit, second-line functions, and external providers) and any risk, entity, or provider not named in this cycle's confirmed scope. It consumes the risk universe and residual positions (Risk items with their residual_rating and treatment) from the upstream Enterprise Risk Assessment & Portfolio Oversight Cycle and hands its named deliverables — the published combined assurance map, the reliance conclusions, and the gap action plans — to the downstream Quarterly Board & Audit-Committee GRC Reporting workflow rather than duplicating repeated work.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
internal-audit
lineOfDefense
assure

Details

teams
  • internal-audit
  • risk-management
domains
  • grc
standards
  • iia-2024
sourceTemplateId
workflow-library:grc-combined-assurance-mapping
releaseId
sha256:f0ae775a3a86f082f6bcc1a2383a15f8e0219c50577d82600fbd8fa89c947e8e
canonicalUrl
https://workflow-library.com/all/?w=grc-combined-assurance-mapping
capabilities
    mappingStatus
    mapped
    lineOfDefense
    assure
    controls
    • UC-AUDIT-23
    • UC-AUDIT-18
    • UC-AUDIT-27
    • UC-GOV-38
    roleIntegrity
    activityCount
    2
    ermPhases
    • assess
    lineRoles
    • second
    • third
    serviceModes
    • assurance
    warnings

      Source

      No record-specific source URL is provided.

      Download workflow template · Release: sha256:f0ae775a3a86f082f6bcc1a2383a15f8e0219c50577d82600fbd8fa89c947e8e

      Connections