{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:699bb8f921e61282509d797631e22c865a0c1b254195bbc6798e50947f563a0f","slug":"grc-board-risk-internal-control-oversight-cycle","url":"/assets/agent_workflow-grc-board-risk-internal-control-oversight-cycle-c88a811e.0fa126b56e48780a.json"},"kind":"record","record":{"attributes":{"department":"executive","domain":"grc","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-board-risk-internal-control-oversight-cycle","description":"Board Risk & Internal Control Oversight Cycle as a decision-aware workflow: the governance office verifies board independence and expertise, compiles the board risk & internal-control oversight pack, routes the at-least-annual governance-framework effectiveness evaluation, facilitates the independent board's approval of the risk strategy and material policies, captures and minutes the directed adjustments, and launches and tracks them as an owned open directives register. It is standalone: the governing body and the governance framework are not Studio item types, so there is no natural item anchor — each cycle runs as a fresh recurring workflow instance and its deliverables attach to the run's own steps. The named deliverables are the composition-and-independence summary, the board risk & internal-control oversight pack, the annual governance-and-management-framework effectiveness evaluation when in scope, the adopted board/committee minutes, and the board directives-and-adjustments register (one Issue item per directive, linked across cycles). The risk strategy and material policies the board approves are Policy items (approved_by, version, next_review_date); board directives, approval conditions, and framework adjustments are Issue items (issue_type: observation, source: management_identified). In scope: a single named governing body's quarterly (or specially convened) risk and internal-control oversight meeting and, where the annual clock or a substantial-change trigger applies, that cycle's enterprise governance and management framework effectiveness evaluation. Out of scope: the day-to-day first- and second-line control operation, testing, and assurance that feed the pack — no workflow hands into this cycle, and the board's directives flow onward into control-remediation and policy-update execution as prose, not a wired downstream template.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-board-risk-internal-control-oversight-cycle","capabilities":[],"controls":["UC-GOV-01","UC-GOV-05"],"domains":["grc"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:699bb8f921e61282509d797631e22c865a0c1b254195bbc6798e50947f563a0f","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-board-risk-internal-control-oversight-cycle","standards":["cobit-2019","coso-ic","coso-erm","soc2"],"teams":["executive","risk-management"]},"id":"wf:G17","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG17","slug":"grc-board-risk-internal-control-oversight-cycle","sourceIds":["cobit-2019","coso-erm","coso-ic","nis2","nist-csf-2","soc2"],"sourceUrl":null,"title":"Board Risk & Internal Control Oversight Cycle","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2770ad147e9dca5a110bba4fdbf8c7f0be504d8a089c29248c01d717687aa543","properties":{},"sourceDetailPath":"/data/v1/records/wf-g17-8c15d035.json","sourceId":"wf:G17","targetDetailPath":"/data/v1/records/uc-uc-gov-01-e1e2136d.json","targetId":"uc:UC-GOV-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f4777178aeb214339656c564928a20972f6832c6cbe980d78b1a8b0a2ddcc311","properties":{},"sourceDetailPath":"/data/v1/records/wf-g17-8c15d035.json","sourceId":"wf:G17","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"operates"}],"schemaVersion":1}
