{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:2eaeb9c8bb2b20a89e69ff15a7f08852a99129d1bad280b4e70a722a18fef665","slug":"grc-risk-resilience-framework-governance","url":"/assets/agent_workflow-grc-risk-resilience-framework-governance-9d751b7f.fd9505c7d6c6397a.json"},"kind":"record","record":{"attributes":{"department":"risk-management","domain":"grc","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-resilience-framework-governance","description":"Risk & Resilience Framework Governance as a decision-aware workflow. The instance runs on the \"Enterprise Risk Management Framework\" Process item (process_type: business_process, process_owner = the framework owner, frequency: annual) - created on the first cycle at \"Design core ERM framework\" and enriched every cycle thereafter, never duplicated; that Process item is the governance register entry, and each governance cycle runs as a workflow instance attached to it, so the at-least-annual cadence is provable from one item's instance history. Working from the organization's context and the ISO 31000 / COSO ERM / DORA reference models - no upstream workflow package feeds it, because this workflow establishes the governance layer - it establishes or refreshes the enterprise risk management framework, extends it for ICT operational resilience and regulated technologies, secures management-body approval and budget, drives implementation across the organization, and runs the at-least-annual review, filling the governance layer the risk-cycle workflows run inside but never establish. The named deliverable is the approved risk & resilience framework package (core ERM design + ICT operational-resilience (DORA) extension + any regulated-technology lifecycle extension), archived at close as durable governance evidence. In scope: the enterprise risk framework, its always-in-scope ICT operational-resilience (DORA) extension, and any regulated-technology (e.g. high-risk AI) extensions to be evaluated. Out of scope: executing the individual risk-cycle workflows (identify / assess / treat / monitor) that run inside this framework - this workflow governs them but does not perform them, and consumes no upstream workflow package. Downstream, the archived framework enables those risk-cycle workflows, which reference it as their governing baseline (the relationship is real but not modeled as a node).","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-resilience-framework-governance","capabilities":[],"controls":["UC-RISK-01","UC-BCDR-02","UC-GOV-17","UC-RISK-03"],"domains":["grc"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:2eaeb9c8bb2b20a89e69ff15a7f08852a99129d1bad280b4e70a722a18fef665","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-risk-resilience-framework-governance","standards":["iso-31000","coso-erm","dora"],"teams":["risk-management","executive"]},"id":"wf:G16","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG16","slug":"grc-risk-resilience-framework-governance","sourceIds":["cobit-2019","coso-erm","dora","eu-ai-act","iso-31000","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"Risk & Resilience Framework Governance","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d14a14475f8d603e7f0fa784835996afba75b4dafe5e224fef71e09ac5f2c5d","properties":{},"sourceDetailPath":"/data/v1/records/wf-g16-694f4e2b.json","sourceId":"wf:G16","targetDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","targetId":"uc:UC-GOV-17","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aae2adaa961ad38818a1f779929abea6a131364f57df2364c5fadcc346ae55ff","properties":{},"sourceDetailPath":"/data/v1/records/wf-g16-694f4e2b.json","sourceId":"wf:G16","targetDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","targetId":"uc:UC-RISK-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab09fdd190f6cccbc1b587f3d1c1f50feab2ec3ed9a3c01937de1dd3cf6522c0","properties":{},"sourceDetailPath":"/data/v1/records/wf-g16-694f4e2b.json","sourceId":"wf:G16","targetDetailPath":"/data/v1/records/uc-uc-bcdr-02-2a51c24c.json","targetId":"uc:UC-BCDR-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fdfff27500e0c780aba9597532b29312daa28ecd701cfd89faa25108e0f26396","properties":{},"sourceDetailPath":"/data/v1/records/wf-g16-694f4e2b.json","sourceId":"wf:G16","targetDetailPath":"/data/v1/records/uc-uc-risk-01-13d56297.json","targetId":"uc:UC-RISK-01","type":"operates"}],"schemaVersion":1}
