{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:6d75ecb22ff2f49635ee533d71e7f61e415ea80adf9c9b1366b87543baf635a9","slug":"grc-quarterly-board-audit-committee-reporting","url":"/assets/agent_workflow-grc-quarterly-board-audit-committee-reporting-5961162f.3e6d2da161b79c19.json"},"kind":"record","record":{"attributes":{"department":"risk-management","domain":"grc","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-quarterly-board-audit-committee-reporting","description":"Runs on the existing standing \"Board & Audit-Committee GRC Reporting\" governance Process item (process_type=business_process, frequency=quarterly): one workflow instance per quarter attaches to that Process and enriches it (the Process is not created here), and each closed instance is the prior-quarter baseline for the next run. The named deliverable is the quarterly board & audit-committee GRC pack (six-domain narrative deck, Word + PDF, redaction-cleared). It compiles that pack across six domains — risk profile, control health, open issues, regulatory deadlines, audit-plan progress, and SOX posture — computed over one quarter window. In scope: aggregating and synthesizing existing GRC records (Risk, Control, Issue, Audit, and Control-hosted SOX testing workflows) into a board-level narrative, obtaining executive and committee approval, and archiving the decision and action register. Out of scope: performing the underlying risk assessments, audits, or control tests themselves. Consumes two upstream handoff packages: the Enterprise Risk Assessment & Portfolio Oversight Cycle package (risk register, residual scores, appetite positions) and the Audit Report Drafting & Regulatory Compliance Attestation Cycle package (audit-plan status, issued reports, attestation status); there is no downstream workflow — the closed package feeds the next quarterly run of this workflow.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-quarterly-board-audit-committee-reporting","capabilities":[],"controls":["UC-GOV-05","UC-GOV-21","UC-AUDIT-22","UC-AUDIT-18","UC-RISK-10","UC-RISK-14"],"domains":["grc"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:6d75ecb22ff2f49635ee533d71e7f61e415ea80adf9c9b1366b87543baf635a9","roleIntegrity":{"activityCount":2,"ermPhases":["report"],"lineRoles":["third","board"],"serviceModes":["advisory","decision"],"warnings":[]},"sourceTemplateId":"workflow-library:grc-quarterly-board-audit-committee-reporting","standards":["coso-erm","iia-2024"],"teams":["risk-management","internal-audit","executive"]},"id":"wf:G10","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG10","slug":"grc-quarterly-board-audit-committee-reporting","sourceIds":["cobit-2019","coso-erm","coso-ic","iia-2024","iso-31000","nis2","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Quarterly Board & Audit-Committee GRC Reporting","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:09fed3546986fe04fdec9059b5f846d64b5f3de14be1d43fc8e4e13b53da8c3f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g10-3ef59294.json","sourceId":"wf:G10","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6f9ef4dea11e082079fb5833586ca0e528f227f9baafb0b4f3a5919f9325ef8c","properties":{},"sourceDetailPath":"/data/v1/records/wf-g10-3ef59294.json","sourceId":"wf:G10","targetDetailPath":"/data/v1/records/uc-uc-audit-18-7ab55995.json","targetId":"uc:UC-AUDIT-18","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:992d4a2b68122b00a3263d70934f1236bb6a38fa2d31c2a28eecc5d107aceaad","properties":{},"sourceDetailPath":"/data/v1/records/wf-g10-3ef59294.json","sourceId":"wf:G10","targetDetailPath":"/data/v1/records/uc-uc-gov-21-8c5d79f9.json","targetId":"uc:UC-GOV-21","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a87e86719e6abed7d0f71894b5c4d412c134e7b3b3bfaddb94afbdfab8b91c1e","properties":{},"sourceDetailPath":"/data/v1/records/wf-g10-3ef59294.json","sourceId":"wf:G10","targetDetailPath":"/data/v1/records/uc-uc-risk-10-6d44f690.json","targetId":"uc:UC-RISK-10","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f12b59f934696db4cc3fd528ef9ee0ce74a16bff27fb09bb754fa758d3beef67","properties":{},"sourceDetailPath":"/data/v1/records/wf-g10-3ef59294.json","sourceId":"wf:G10","targetDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","targetId":"uc:UC-AUDIT-22","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f758511bd9a9d0bd988c97e5bc60869498358fec759ad9d659772cfcce08bfea","properties":{},"sourceDetailPath":"/data/v1/records/wf-g10-3ef59294.json","sourceId":"wf:G10","targetDetailPath":"/data/v1/records/uc-uc-risk-14-a5d6281b.json","targetId":"uc:UC-RISK-14","type":"oversees"}],"schemaVersion":1}
