{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:bbc320670d4d8c85ce55c4b291867eb62b89ddc4c7b8c7aacd8355d71a632125","slug":"grc-enterprise-risk-assessment-treatment-cycle","url":"/assets/agent_workflow-grc-enterprise-risk-assessment-treatment-cycle-2a22f4b7.0136e97d81afbaf4.json"},"kind":"record","record":{"attributes":{"department":"operations","domain":"grc","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-enterprise-risk-assessment-treatment-cycle","description":"Enterprise Risk Treatment Operations Cycle as a decision-aware workflow: it runs the documented risk methodology each cycle - identification and analysis of risks and opportunities, evaluation and prioritization against risk criteria, treatment selection and tracking for risks exceeding tolerance with residual re-evaluation, and risk-register and portfolio reporting to management and the board - triggering dynamic reassessment when internal or external change shifts the risk profile. This cycle has no anchor item of its own: the enterprise risk register it maintains IS the Risk item population, and the workflow instance is the cycle record and durable audit trail. In scope: entity-level and process-level risk across the enterprise, explicitly including cybersecurity, privacy, and financial-reporting risk alongside operational and strategic risk and opportunity. Out of scope: detailed control design and testing, which downstream control workflows own - a mitigate or share/transfer plan that creates or strengthens a control hands that work off to those workflows, which anchor on the affected Control items. This cycle has no upstream workflow feeding it; its starting inputs are the documented methodology, the consistent likelihood/impact scoring scales, the board-approved risk criteria and appetite/tolerance statements, and the risk-acceptance delegation matrix - all carried as Policy items - plus the existing control, insurance and transfer information (Control items and step documents) and the prior cycle's Risk register. Named deliverables: the maintained enterprise risk register (the Risk items), the prioritized risk heat-map dashboard, and the management and board portfolio report package.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-enterprise-risk-assessment-treatment-cycle","capabilities":[],"controls":["UC-RISK-06","UC-RISK-07","UC-RISK-08","UC-RISK-09","UC-RISK-10","UC-RISK-11"],"domains":["grc"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:bbc320670d4d8c85ce55c4b291867eb62b89ddc4c7b8c7aacd8355d71a632125","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-enterprise-risk-assessment-treatment-cycle","standards":["iso-31000","coso-erm","nist-csf-2","nist-800-53"],"teams":["operations","risk-management"]},"id":"wf:G22","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG22","slug":"grc-enterprise-risk-assessment-treatment-cycle","sourceIds":["coso-erm","coso-ic","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"sourceUrl":null,"title":"Enterprise Risk Treatment Operations Cycle","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01ce8ae1ab49976e0742f5ce7d0bf3b50631a0265d24712d5fbea9da3da2f2eb","properties":{},"sourceDetailPath":"/data/v1/records/wf-g22-87bce2d6.json","sourceId":"wf:G22","targetDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","targetId":"uc:UC-RISK-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:57702ef5e30ad07f33e36fec45854fda67abedb1a4c657f08a11ef16ea7b7a6f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g22-87bce2d6.json","sourceId":"wf:G22","targetDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","targetId":"uc:UC-RISK-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9190c372e946c8a006341905f80ee84a71a9ed49295c6f66b4cd0743a2b71981","properties":{},"sourceDetailPath":"/data/v1/records/wf-g22-87bce2d6.json","sourceId":"wf:G22","targetDetailPath":"/data/v1/records/uc-uc-risk-09-06ffdff1.json","targetId":"uc:UC-RISK-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a0cfec379b936dd4a1cdba28e0e0f8e8f197f3e6f74d85de5cc26de6cd98e1c3","properties":{},"sourceDetailPath":"/data/v1/records/wf-g22-87bce2d6.json","sourceId":"wf:G22","targetDetailPath":"/data/v1/records/uc-uc-risk-10-6d44f690.json","targetId":"uc:UC-RISK-10","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb351c3b24136aa98f03bea4acd4d268242071a75cb3f4c476abb5739aed57ed","properties":{},"sourceDetailPath":"/data/v1/records/wf-g22-87bce2d6.json","sourceId":"wf:G22","targetDetailPath":"/data/v1/records/uc-uc-risk-07-b86de728.json","targetId":"uc:UC-RISK-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cc1a7329e4d403890a2da42a07dd82ad51d7989bf88fe8dedf422a690071438b","properties":{},"sourceDetailPath":"/data/v1/records/wf-g22-87bce2d6.json","sourceId":"wf:G22","targetDetailPath":"/data/v1/records/uc-uc-risk-08-5f27bebc.json","targetId":"uc:UC-RISK-08","type":"operates"}],"schemaVersion":1}
