workflow

Enterprise Risk Assessment & Portfolio Oversight Cycle

Second-line ERM oversight cycle. Each run is anchored to a cycle Audit item created for the period (audit_type: operational, scope = the assessment boundary, period_start/period_end = the cycle window, report_date = the approval date); the workflow instance attaches to it as the durable audit trail, and the enterprise Risk items are the register it assesses and updates in place. Establish the assessment context (scope, criteria, appetite, scoring calibration), identify risks, score inherent and residual severity, select responses, publish the portfolio view, and route the package through disposition and governance approval. In scope: enterprise-level risk identification, assessment, response selection, and portfolio reporting for the current cycle. Out of scope: defining the board-approved risk appetite statement itself and preparing the board reporting deck, which are handled by downstream workflows. Consumes the prior-cycle risk-register handoff package (the existing Risk items plus the linked register document) from the Enterprise Risk Register Lifecycle workflow, and hands its named deliverables — the residual portfolio view (dashboard), the risk-movement narrative, and the approved assessment package — to the Risk Appetite Definition & Board Reporting and Quarterly Board & Audit-Committee GRC Reporting workflows.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
risk-management
lineOfDefense
monitor

Details

teams
  • risk-management
domains
  • grc
standards
  • coso-erm
  • iso-31000
sourceTemplateId
workflow-library:grc-enterprise-risk-assessment-cycle
releaseId
sha256:c0b55c9a7fc920d14f3d9ae8b3d77d431a7fa57d1bdb0cd025c63ae86e94f2e9
canonicalUrl
https://workflow-library.com/all/?w=grc-enterprise-risk-assessment-cycle
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-RISK-03
    • UC-RISK-06
    • UC-RISK-07
    • UC-RISK-08
    • UC-RISK-09
    • UC-RISK-10
    • UC-RISK-04
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:c0b55c9a7fc920d14f3d9ae8b3d77d431a7fa57d1bdb0cd025c63ae86e94f2e9

            Connections