workflow
Enterprise Risk Assessment & Portfolio Oversight Cycle
Second-line ERM oversight cycle. Each run is anchored to a cycle Audit item created for the period (audit_type: operational, scope = the assessment boundary, period_start/period_end = the cycle window, report_date = the approval date); the workflow instance attaches to it as the durable audit trail, and the enterprise Risk items are the register it assesses and updates in place. Establish the assessment context (scope, criteria, appetite, scoring calibration), identify risks, score inherent and residual severity, select responses, publish the portfolio view, and route the package through disposition and governance approval. In scope: enterprise-level risk identification, assessment, response selection, and portfolio reporting for the current cycle. Out of scope: defining the board-approved risk appetite statement itself and preparing the board reporting deck, which are handled by downstream workflows. Consumes the prior-cycle risk-register handoff package (the existing Risk items plus the linked register document) from the Enterprise Risk Register Lifecycle workflow, and hands its named deliverables — the residual portfolio view (dashboard), the risk-movement narrative, and the approved assessment package — to the Risk Appetite Definition & Board Reporting and Quarterly Board & Audit-Committee GRC Reporting workflows.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- risk-management
- lineOfDefense
- monitor
Details
- teams
- risk-management
- domains
- grc
- standards
- coso-erm
- iso-31000
- sourceTemplateId
- workflow-library:grc-enterprise-risk-assessment-cycle
- releaseId
- sha256:c0b55c9a7fc920d14f3d9ae8b3d77d431a7fa57d1bdb0cd025c63ae86e94f2e9
- canonicalUrl
- https://workflow-library.com/all/?w=grc-enterprise-risk-assessment-cycle
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-RISK-03
- UC-RISK-06
- UC-RISK-07
- UC-RISK-08
- UC-RISK-09
- UC-RISK-10
- UC-RISK-04
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:c0b55c9a7fc920d14f3d9ae8b3d77d431a7fa57d1bdb0cd025c63ae86e94f2e9
Connections
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-04 — Define objectives and business context for risk assessment
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-06 — Perform periodic enterprise risk assessments
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-09 — Select, plan, and implement risk treatments