workflow
Risk Communication, Reporting & Performance Review
Risk Communication, Reporting & Performance Review as a decision-aware workflow that runs each quarter or on an out-of-cycle significant matter. Because none of the eight Studio item types represents the ERM reporting cycle itself, the workflow instance IS the durable record: its named deliverables - the tiered internal and external risk, control and performance reporting package, the event-driven report on a significant matter, the management-signed risk-and-control performance-review pack, and the tracked improvement actions - attach to its steps, its item-level writes land on the existing Risk, Control, and Issue items (improvement actions are tracked as Issues with source: self_assessment); control-testing results are read from SOX testing workflows hosted directly on the relevant Controls; and the risk-management framework is read as its Policy item (policy_type: charter) for the evaluation baseline and the suppliers and third parties consulted as their Vendor items. In scope: stakeholder consultation across every risk-process step (identification, assessment, response, monitoring) including suppliers and third parties; the cadenced internal and external reporting package; event-driven reporting on significant matters; the periodic review of risk-management and internal-control performance against the framework's design intent with accountable management; and converting lessons into owned, tracked improvement actions. Out of scope: running the underlying risk assessments, control testing, or business-performance measurement themselves - this workflow consumes their results as inputs. It starts on its own trigger (the quarterly cadence or a significant event) and has no upstream feeder workflow and no named downstream handoff workflow; each run's close-and-archive leaves the stakeholder, risk, and improvement registers current - the informal handoff both to the next cycle of this workflow and to the downstream risk-assessment and control-testing workflows whose results this cycle consumes.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- risk-management
- lineOfDefense
- operate
Details
- teams
- risk-management
- domains
- grc
- standards
- iso-31000
- coso-erm
- soc2
- nist-csf-2
- sourceTemplateId
- workflow-library:grc-risk-communication-reporting-performance-review
- releaseId
- sha256:a9b7771d4a349b09631c9de418215f6f44afa4c44bd3c01f6e11d5431aa862d8
- canonicalUrl
- https://workflow-library.com/all/?w=grc-risk-communication-reporting-performance-review
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-RISK-05
- UC-GOV-21
- UC-RISK-13
- UC-RISK-15
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:a9b7771d4a349b09631c9de418215f6f44afa4c44bd3c01f6e11d5431aa862d8
Connections
- Risk Communication, Reporting & Performance Review operates UC-RISK-15 — Continually improve the risk management program
- Risk Communication, Reporting & Performance Review operates UC-RISK-13 — Monitor and review risk management performance
- Risk Communication, Reporting & Performance Review operates UC-GOV-21 — Communicate and report risk and control information
- Risk Communication, Reporting & Performance Review operates UC-RISK-05 — Communicate and consult with stakeholders on risk