workflow

Regulatory Exam & External Audit Management

Manage a live regulator examination or external audit end to end — from notification intake through request fulfillment, QC’d evidence release, fieldwork support, preliminary-findings response, and commitment closure. Runs on an Audit engagement item created per exam (audit_type = regulatory_exam, or external_attestation for an external audit); the workflow instance attaches to that Audit anchor, and preliminary findings and their corrective-action commitments become linked Issue items. No upstream workflow feeds this — it is triggered by the exam or audit notification itself. In scope: coordinating examiner requests, controlled evidence release, and management responses for a single exam or audit engagement. Out of scope: remediating the underlying control gaps — the findings and committed corrective actions hand off to Finding Remediation & Action-Plan Monitoring — and standing up new obligations surfaced by the exam, which hand off to Regulatory Horizon Scanning & Triage and Regulatory Obligation Implementation.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
compliance-legal
lineOfDefense
monitor

Details

teams
  • compliance-legal
domains
  • grc
  • reg
standards
  • nydfs-500
  • dora
  • soc1
  • soc2
sourceTemplateId
workflow-library:grc-regulatory-exam-management
releaseId
sha256:f6435e4199020b25d9143bcab2ab97b3aebb9f4c636df19a252b35f46f085c74
canonicalUrl
https://workflow-library.com/all/?w=grc-regulatory-exam-management
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-GOV-23
    • UC-AUDIT-17
    • UC-AUDIT-23
    • UC-AUDIT-24
    • UC-ACCESS-14
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings
          • code
            reliance-basis-incomplete
            title
            Reliance basis is incomplete
            message
            Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
            missing
            • independence
            • competence
            • evidence
            • recency
            • reliance rationale
            nodeIds

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:f6435e4199020b25d9143bcab2ab97b3aebb9f4c636df19a252b35f46f085c74

            Connections