{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:compliance-no-independent-audit","risk:gov-oversight-failure","risk:hr-employment-practices-disputes","risk:ops-regulatory-reporting-failure","risk:reputational-stakeholder-trust","risk:strategic-misalignment-execution","uc:UC-AUDIT-05","uc:UC-AUDIT-09","uc:UC-AUDIT-27","uc:UC-GOV-38","wf:A10","wf:A11","wf:A5","wf:A8","wf:A9","wf:D10","wf:G2","wf:G4"],"directIds":["ctrl:iia-pos-2026-erm:IIA-POS-ERM-01","ctrl:iia-pos-2026-erm:IIA-POS-ERM-02","ctrl:iia-pos-2026-erm:IIA-POS-ERM-03","ctrl:iia-pos-2026-erm:IIA-POS-ERM-04","std:iia-pos-2026-erm"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"The Role of the Internal Audit Function in Enterprise Risk Management","next":null,"page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"iia-pos-2026-erm","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-pos-2026-erm/","description":"The board oversees risk, management owns and manages risk, and internal audit provides independent assurance and advice without assuming management responsibility.","details":{"automation":"manual","control_category":"administrative","control_id":"IIA-POS-ERM-01","control_type":"preventive","domains":[],"framework":"iia-pos-2026-erm","group":"Enterprise Risk Management Role Integrity","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":"ERM pp. 3, 7–9","source_url":null,"statement":"The board oversees risk, management owns and manages risk, and internal audit provides independent assurance and advice without assuming management responsibility."},"direct":true,"htmlUrl":"/agents/records/ctrl-iia-pos-2026-erm-iia-pos-erm-01-6f73f46d.html","id":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-01","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-pos-2026-erm%3AIIA-POS-ERM-01","sourceIds":["iia-pos-2026-erm"],"sourceUrl":null,"title":"IIA-POS-ERM-01 — Board, Management, and Internal Audit Accountabilities","type":"control","url":"/assets/agent_record-ctrl-iia-pos-2026-erm-iia-pos-erm-01-6f73f46d.81fc1751c7af4f97.json"},{"attributes":{"category":"administrative","framework":"iia-pos-2026-erm","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-pos-2026-erm/","description":"ERM activities operate through Identify, Assess, Manage, Monitor, and Report, with internal-audit assurance, advisory, and administrative boundaries defined for each phase.","details":{"automation":"manual","control_category":"administrative","control_id":"IIA-POS-ERM-02","control_type":"preventive","domains":[],"framework":"iia-pos-2026-erm","group":"Enterprise Risk Management Role Integrity","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":"ERM pp. 8, 11","source_url":null,"statement":"ERM activities operate through Identify, Assess, Manage, Monitor, and Report, with internal-audit assurance, advisory, and administrative boundaries defined for each phase."},"direct":true,"htmlUrl":"/agents/records/ctrl-iia-pos-2026-erm-iia-pos-erm-02-1e6dc74e.html","id":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-pos-2026-erm%3AIIA-POS-ERM-02","sourceIds":["iia-pos-2026-erm"],"sourceUrl":null,"title":"IIA-POS-ERM-02 — ERM Activity and Service Boundaries","type":"control","url":"/assets/agent_record-ctrl-iia-pos-2026-erm-iia-pos-erm-02-1e6dc74e.c1f2f7d0fb74bbb7.json"},{"attributes":{"category":"administrative","framework":"iia-pos-2026-erm","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-pos-2026-erm/","description":"Expanded internal-audit ERM responsibility requires documented allocation, board approval, separation, disclosure, independent assurance, cooling-off, periodic review, and transition where temporary.","details":{"automation":"manual","control_category":"administrative","control_id":"IIA-POS-ERM-03","control_type":"preventive","domains":[],"framework":"iia-pos-2026-erm","group":"Enterprise Risk Management Role Integrity","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":"ERM pp. 12–13, 15–20","source_url":null,"statement":"Expanded internal-audit ERM responsibility requires documented allocation, board approval, separation, disclosure, independent assurance, cooling-off, periodic review, and transition where temporary."},"direct":true,"htmlUrl":"/agents/records/ctrl-iia-pos-2026-erm-iia-pos-erm-03-2ed09a44.html","id":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-pos-2026-erm%3AIIA-POS-ERM-03","sourceIds":["iia-pos-2026-erm"],"sourceUrl":null,"title":"IIA-POS-ERM-03 — Safeguards for Expanded ERM Responsibility","type":"control","url":"/assets/agent_record-ctrl-iia-pos-2026-erm-iia-pos-erm-03-2ed09a44.8f5208a0589ea451.json"},{"attributes":{"category":"administrative","framework":"iia-pos-2026-erm","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-pos-2026-erm/","description":"The assurance/advisory mix is calibrated to ERM maturity and resources, strategic and risk context, other-provider strength, and board direction.","details":{"automation":"manual","control_category":"administrative","control_id":"IIA-POS-ERM-04","control_type":"preventive","domains":[],"framework":"iia-pos-2026-erm","group":"Enterprise Risk Management Role Integrity","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":"ERM p. 14","source_url":null,"statement":"The assurance/advisory mix is calibrated to ERM maturity and resources, strategic and risk context, other-provider strength, and board direction."},"direct":true,"htmlUrl":"/agents/records/ctrl-iia-pos-2026-erm-iia-pos-erm-04-592b59ae.html","id":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-04","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-pos-2026-erm%3AIIA-POS-ERM-04","sourceIds":["iia-pos-2026-erm"],"sourceUrl":null,"title":"IIA-POS-ERM-04 — Assurance and Advisory Portfolio Calibration","type":"control","url":"/assets/agent_record-ctrl-iia-pos-2026-erm-iia-pos-erm-04-592b59ae.4404b8d7a64e4a71.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-no-independent-audit","description":"Because independent internal and external audit and review of information security are not performed, control deficiencies and non-conformities are neither detected nor challenged, so weaknesses persist unremediated and management and the board lose reliable assurance over control effectiveness.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"compliance-no-independent-audit","taxonomies":["iso-27005-vulnerability","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-compliance-no-independent-audit-9e1acf0f.html","id":"risk:compliance-no-independent-audit","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-no-independent-audit","sourceIds":["ccpa","cobit-2019","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001","nis2","nist-800-53"],"sourceUrl":null,"title":"Lack of independent audit and compliance review","type":"risk","url":"/assets/agent_record-risk-compliance-no-independent-audit-9e1acf0f.8a44783c74772a6f.json"},{"attributes":{"category":"strategic","domain":["Governance, Policy & Oversight","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["coso-erm-risk","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-oversight-failure","description":"Because board and management oversight of risk and control is weak - unclear tone at the top, ineffective board composition or independence, poor committee structure, and limited senior-management commitment - control priorities are not enforced and resources are withheld, so risks accumulate unmanaged and control failures go uncorrected across the entity.","details":{"category":"strategic","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"gov-oversight-failure","taxonomies":["coso-erm-risk","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-gov-oversight-failure-d98ffc12.html","id":"risk:gov-oversight-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-oversight-failure","sourceIds":["cobit-2019","coso-erm","coso-ic","iia-2024","iia-pos-2026-erm","nis2","nist-csf-2","soc2","sox"],"sourceUrl":null,"title":"Inadequate board and management oversight of risk and control","type":"risk","url":"/assets/agent_record-risk-gov-oversight-failure-d98ffc12.e05fa5d3e4686a7a.json"},{"attributes":{"category":"people_hr","domain":["Human Resources / Personnel Security","Compliance, Audit & Assurance"],"inherent_rating":"medium","taxonomy":["basel-operational-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-employment-practices-disputes","description":"Wrongful termination, wage-and-hour and overtime violations, benefit disputes, worker misclassification, whistleblower-protection breaches, and labor grievances/strike action causing litigation and operational loss.","details":{"category":"people_hr","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"hr-employment-practices-disputes","taxonomies":["basel-operational-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-hr-employment-practices-disputes-2a788e39.html","id":"risk:hr-employment-practices-disputes","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-employment-practices-disputes","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Employment-practice and labor-law violations","type":"risk","url":"/assets/agent_record-risk-hr-employment-practices-disputes-2a788e39.ad61d1925d1d36a4.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Financial Reporting Controls (SOX)"],"inherent_rating":"medium","taxonomy":["basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aops-regulatory-reporting-failure","description":"Late or inaccurate regulatory transaction reporting, missed regulatory-return deadlines, inaccurate risk reporting to management, and errors in suspicious-activity reporting — breaching disclosure obligations to regulators and stakeholders.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"ops-regulatory-reporting-failure","taxonomies":["basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ops-regulatory-reporting-failure-d1dbc50a.html","id":"risk:ops-regulatory-reporting-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aops-regulatory-reporting-failure","sourceIds":["iia-2024","iia-pos-2026-erm"],"sourceUrl":null,"title":"Failed or inaccurate mandatory regulatory reporting","type":"risk","url":"/assets/agent_record-risk-ops-regulatory-reporting-failure-d1dbc50a.2e12d66424f07883.json"},{"attributes":{"category":"reputational","domain":["Governance, Policy & Oversight","Risk Assessment & Management"],"inherent_rating":"medium","taxonomy":["coso-erm-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Areputational-stakeholder-trust","description":"Gradual loss of trust and social license among customers, employees, investors, regulators, and communities — from perceived values misalignment, poor ESG/governance conduct, or repeated service failures — weakening stakeholder relationships and long-term enterprise value even absent a single acute crisis.","details":{"category":"reputational","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"reputational-stakeholder-trust","taxonomies":["coso-erm-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-reputational-stakeholder-trust-23d21e70.html","id":"risk:reputational-stakeholder-trust","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Areputational-stakeholder-trust","sourceIds":["cobit-2019","coso-erm","coso-ic","gdpr","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-31000","nist-800-53","nist-csf-2","soc2","sox"],"sourceUrl":null,"title":"Stakeholder trust and social-license erosion","type":"risk","url":"/assets/agent_record-risk-reputational-stakeholder-trust-23d21e70.cc84ea3ea3c8507a.json"},{"attributes":{"category":"strategic","domain":["Governance, Policy & Oversight","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Astrategic-misalignment-execution","description":"Because strategic objectives are poorly defined, internally inconsistent, or misaligned with mission and stakeholders, approved strategies cannot be executed - resource gaps and weak governance of change compound the shortfall - resulting in resource misallocation, missed objectives, and value destruction.","details":{"category":"strategic","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"strategic-misalignment-execution","taxonomies":["coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-strategic-misalignment-execution-d9c0675b.html","id":"risk:strategic-misalignment-execution","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Astrategic-misalignment-execution","sourceIds":["cobit-2019","coso-erm","coso-ic","iia-pos-2026-erm","iia-pos-2026-three-lines","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Strategic misalignment and execution failure","type":"risk","url":"/assets/agent_record-risk-strategic-misalignment-execution-d9c0675b.d1ac0ae48868389a.json"},{"attributes":{"authority":"guidance","category":"iia-pos-2026-erm"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-pos-2026-erm/","description":"The Role of the Internal Audit Function in Enterprise Risk Management","details":{"amendmentState":"none","authority":"guidance","effectiveDate":null,"note":"Local reviewed paper: The Role of the Internal Audit Function in Enterprise Risk Management","propositions":[{"id":"IIA-POS-ERM-01","sourcePages":"ERM pp. 3, 7–9","title":"Board, Management, and Internal Audit Accountabilities"},{"id":"IIA-POS-ERM-02","sourcePages":"ERM pp. 8, 11","title":"ERM Activity and Service Boundaries"},{"id":"IIA-POS-ERM-03","sourcePages":"ERM pp. 12–13, 15–20","title":"Safeguards for Expanded ERM Responsibility"},{"id":"IIA-POS-ERM-04","sourcePages":"ERM p. 14","title":"Assurance and Advisory Portfolio Calibration"}],"publicationDate":"2026","reviewed_at":null,"source_url":null,"version":"2026"},"direct":true,"htmlUrl":"/agents/records/std-iia-pos-2026-erm-d24e4aa8.html","id":"std:iia-pos-2026-erm","mapUrl":"https://controlsmap.com/?v=1&node=std%3Aiia-pos-2026-erm","sourceIds":["iia-pos-2026-erm"],"sourceUrl":null,"title":"The Role of the Internal Audit Function in Enterprise Risk Management","type":"standard","url":"/assets/agent_record-std-iia-pos-2026-erm-d24e4aa8.2dcc33e3d52512af.json"},{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-05","description":"Internal auditors maintain individual objectivity - an unbiased professional attitude free from conflicts of interest - in all engagements. The chief audit executive implements safeguards such as conflict screening, assignment rotation, and recusal to protect objectivity, and auditors promptly disclose actual or perceived impairments so they can be managed and, where necessary, communicated to affected stakeholders. A complete prior-responsibility register is maintained and used for every engagement assignment. An auditor who held operational, design, management, or supervisory responsibility for an activity during the preceding 12 months is subject to a 12-month cooling-off period; if that requirement is not met, the engagement is reassigned or a suitably qualified independent party provides assurance. Portfolio-level reporting to senior management and the board identifies actual and perceived self-review threats and their safeguards. Conflict declarations, prior-responsibility screening, reassignment or independent-assurance results, and safeguard records are retained.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-ERM-03","propositionTitle":"Safeguards for Expanded ERM Responsibility","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 12–13, 15–20","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-TLM-02","propositionTitle":"Independence and Self-Review Safeguards","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 9–11, 20–22","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[{"control_id":"Principle 2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 2.1","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 2.2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 2.3","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"Internal auditors maintain individual objectivity - an unbiased professional attitude free from conflicts of interest - in all engagements. The chief audit executive implements safeguards such as conflict screening, assignment rotation, and recusal to protect objectivity, and auditors promptly disclose actual or perceived impairments so they can be managed and, where necessary, communicated to affected stakeholders. A complete prior-responsibility register is maintained and used for every engagement assignment. An auditor who held operational, design, management, or supervisory responsibility for an activity during the preceding 12 months is subject to a 12-month cooling-off period; if that requirement is not met, the engagement is reassigned or a suitably qualified independent party provides assurance. Portfolio-level reporting to senior management and the board identifies actual and perceived self-review threats and their safeguards. Conflict declarations, prior-responsibility screening, reassignment or independent-assurance results, and safeguard records are retained.","title":"Maintain auditor objectivity and disclose impairments","unified_id":"UC-AUDIT-05"},"direct":false,"htmlUrl":"/agents/records/uc-uc-audit-05-3332a81f.html","id":"uc:UC-AUDIT-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-05","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"UC-AUDIT-05 — Maintain auditor objectivity and disclose impairments","type":"unified","url":"/assets/agent_record-uc-uc-audit-05-3332a81f.e0f66febc0dfd61b.json"},{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-09","description":"The chief audit executive develops an internal audit strategy aligned with organizational objectives and stakeholder expectations, grounded in a documented understanding of the organization's governance, risk management, and control processes. The strategy includes a documented assurance, advisory, and administrative capacity mix calibrated against ERM maturity and resourcing; strategic change and the current risk environment; the strength and reliability of other assurance providers; and board direction and stakeholder expectations. A risk-based internal audit plan covering the audit universe is created at least annually, approved by the board, and adjusted as the risk landscape changes. The capacity mix is reconsidered whenever the plan is refreshed, and material changes are communicated to senior management and the board with their coverage impact. The strategy, plan, capacity mix, board approvals, refresh decisions, and communications are retained.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-ERM-04","propositionTitle":"Assurance and Advisory Portfolio Calibration","source":"iia-pos-2026-erm","sourcePages":"ERM p. 14","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"}],"members":[{"control_id":"Principle 9","coverage":"partial","delta":"Principle 9 also spans methodologies (9.3) and assurance coordination/reliance (9.5)","framework":"iia-2024","relationship":"intersects_with"},{"control_id":"Std 9.1","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 9.2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 9.4","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"The chief audit executive develops an internal audit strategy aligned with organizational objectives and stakeholder expectations, grounded in a documented understanding of the organization's governance, risk management, and control processes. The strategy includes a documented assurance, advisory, and administrative capacity mix calibrated against ERM maturity and resourcing; strategic change and the current risk environment; the strength and reliability of other assurance providers; and board direction and stakeholder expectations. A risk-based internal audit plan covering the audit universe is created at least annually, approved by the board, and adjusted as the risk landscape changes. The capacity mix is reconsidered whenever the plan is refreshed, and material changes are communicated to senior management and the board with their coverage impact. The strategy, plan, capacity mix, board approvals, refresh decisions, and communications are retained.","title":"Develop a risk-based internal audit strategy and plan","unified_id":"UC-AUDIT-09"},"direct":false,"htmlUrl":"/agents/records/uc-uc-audit-09-f23ecfe4.html","id":"uc:UC-AUDIT-09","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-09","sourceIds":["iia-2024","iia-pos-2026-erm"],"sourceUrl":null,"title":"UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan","type":"unified","url":"/assets/agent_record-uc-uc-audit-09-f23ecfe4.100ca5d1f5dd78b5.json"},{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-27","description":"Any ERM, compliance, risk-management, or other second-line responsibility assigned to the internal audit function or chief audit executive is classified as assurance, advisory, administrative, supervisory, or operational; justified and documented in the internal audit charter or a board-approved appendix; and approved by the board with the associated independence and objectivity risks. Internal audit does not select or own risk responses or other management decisions. Expanded responsibilities are time-bounded with a transition plan when intended to be temporary, and actual or perceived impairments are disclosed to the board. Internal auditors do not provide assurance over an activity they designed, operated, managed, or supervised during the preceding 12 months; another suitably qualified and independent party provides assurance for affected areas. Safeguards, alternative assurance, and transition status are reviewed periodically.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-ERM-01","propositionTitle":"Board, Management, and Internal Audit Accountabilities","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 3, 7–9","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-ERM-03","propositionTitle":"Safeguards for Expanded ERM Responsibility","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 12–13, 15–20","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-TLM-02","propositionTitle":"Independence and Self-Review Safeguards","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 9–11, 20–22","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[],"statement":"Any ERM, compliance, risk-management, or other second-line responsibility assigned to the internal audit function or chief audit executive is classified as assurance, advisory, administrative, supervisory, or operational; justified and documented in the internal audit charter or a board-approved appendix; and approved by the board with the associated independence and objectivity risks. Internal audit does not select or own risk responses or other management decisions. Expanded responsibilities are time-bounded with a transition plan when intended to be temporary, and actual or perceived impairments are disclosed to the board. Internal auditors do not provide assurance over an activity they designed, operated, managed, or supervised during the preceding 12 months; another suitably qualified and independent party provides assurance for affected areas. Safeguards, alternative assurance, and transition status are reviewed periodically.","title":"Govern expanded internal audit ERM responsibilities","unified_id":"UC-AUDIT-27"},"direct":false,"htmlUrl":"/agents/records/uc-uc-audit-27-b7e48974.html","id":"uc:UC-AUDIT-27","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-27","sourceIds":["iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"UC-AUDIT-27 — Govern expanded internal audit ERM responsibilities","type":"unified","url":"/assets/agent_record-uc-uc-audit-27-b7e48974.99d46a06afc6330e.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-38","description":"For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[{"propositionId":"IIA-POS-ERM-01","propositionTitle":"Board, Management, and Internal Audit Accountabilities","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 3, 7–9","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-ERM-02","propositionTitle":"ERM Activity and Service Boundaries","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 8, 11","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-TLM-01","propositionTitle":"Activity-Level Three Lines Responsibilities","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 3–5, 13–19","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[],"statement":"For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.","title":"Assign and maintain Three Lines accountability by risk activity","unified_id":"UC-GOV-38"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-38-0167bec0.html","id":"uc:UC-GOV-38","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-38","sourceIds":["iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity","type":"unified","url":"/assets/agent_record-uc-uc-gov-38-0167bec0.951040fdf083d485.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-ethics-objectivity-competency-program","description":"Runs on an Audit item created per cycle as the anchor — audit_type=internal, scope set to the IA professional-practice program for the period, period_start/period_end = the cycle window (a program cycle, not an engagement, so this is a documented reuse of the Audit type; it is the \"cycle item\" every stream links its evidence to and closes at the end). A decision-aware annual cycle that attests the ethics and professional-courage expectations and documents deviations, screens per-engagement conflicts and manages objectivity impairments, collects confidentiality acknowledgments and restricts audit-file access, and assesses competency against role requirements with approved, tracked continuing-professional-development plans for each auditor. It consumes no upstream workflow: prior-cycle carryover (unresolved-deviation and monitored-impairment Issue items still open against the prior cycle's Audit item, plus in-progress development plans) is its own input, and the population is confirmed against the HR roster, engagement staffing, and the audit-file access list before measurement begins. Named deliverables: the professional-practice requirements memo, the ethics attestation register, the conflict-of-interest declarations and impairment register, the confidentiality acknowledgment register and before/after audit-file access review, the competency assessments with coverage matrix and CPD plans, and the signed CAE conformance report to the audit committee — assembled into an indexed cycle evidence file on the anchor Audit item. Downstream is self-feeding: the carry-forward list produced at close hands off to the next run of this same workflow; there is no distinct downstream workflow. In scope: every auditor and assisting party (employees plus co-source, outsourced, and guest auditors) who performed internal audit work or holds audit-file access during the period, across all four expectation streams (ethics, objectivity, confidentiality, competency); out of scope: the audit engagements' own subject-matter conclusions and any HR, legal, or ethics-office investigation a disclosed concern is referred into.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-ethics-objectivity-competency-program","capabilities":[],"controls":["UC-AUDIT-04","UC-AUDIT-05","UC-AUDIT-06","UC-AUDIT-08"],"domains":["audit"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:12fca28d6d3a7fe7190b7ac924cfb3b588fd0ceaa1afc3769dc1f7303c2c1f8f","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-internal-audit-ethics-objectivity-competency-program","standards":["iia-2024"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-a10-c454863e.html","id":"wf:A10","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA10","slug":"audit-internal-audit-ethics-objectivity-competency-program","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Internal Audit Ethics, Objectivity & Competency Program","type":"workflow","url":"/assets/agent_record-wf-a10-c454863e.5b80756b536cc72d.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-fraud-investigation","description":"Fraud & Forensic Investigation Engagement as a decision-aware workflow. It runs on a dedicated Audit item (audit_type: investigation) created for this allegation at intake — the confidential case record — with the workflow instance attached to that item and its visibility restricted to the named investigation team. In scope: one specific fraud allegation, worked predication-gated and confidentially from intake through evidence preservation, forensic procedures, interviews, loss quantification, and audit-committee reporting; the named deliverables are the chain-of-custody register, the findings memorandum with its loss-quantification schedule, and the privilege-marked audit-committee fraud report. Out of scope: the enterprise fraud risk profile (owned by Fraud Risk Assessment & Anti-Override Control Review, which receives scheme intelligence from this case rather than being rerun here) and any unrelated conduct discovered in passing (which gets its own intake record). It consumes the hotline intake package from Control Responsibility Communications & Ethics Hotline when so routed, and hands each control breakdown off as an Issue item — control-gap findings to Finding Remediation & Action-Plan Monitoring and ICFR-affecting deficiencies to SOX Deficiency Remediation — rather than duplicating that work.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-fraud-investigation","capabilities":[],"controls":["UC-AUDIT-05","UC-AUDIT-08","UC-AUDIT-12","UC-AUDIT-13","UC-AUDIT-14","UC-AUDIT-15","UC-AUDIT-16","UC-AUDIT-18","UC-IR-07"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:b5fe4ec3e78e34833795d4e184e8ffaddf20825dd6fd5fa09a4a661495cc0862","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-fraud-investigation","standards":["iia-2024"],"teams":["internal-audit","compliance-legal"]},"direct":false,"htmlUrl":"/agents/records/wf-a11-0924c009.html","id":"wf:A11","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA11","slug":"audit-fraud-investigation","sourceIds":["coso-ic","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"Fraud & Forensic Investigation Engagement","type":"workflow","url":"/assets/agent_record-wf-a11-0924c009.c336e97e36aab989.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-qaip-cycle","description":"Operate the Quality Assurance & Improvement Program (QAIP) cycle: ongoing-monitoring evidence, periodic self-assessment, external quality assessment (EQA) support, improvement planning, and board reporting. This cycle runs on an Audit item created per cycle (audit_type = internal — the schema has no quality_assessment option; scope = \"QAIP cycle FYxx\"; period_start/period_end span the period under assessment); the workflow instance attaches to that Audit item and every cycle output — the per-standard conformance ratings matrix, the below-GC finding Issue items, the improvement and action plan, and the QAIP results report — links back to it. It consumes the period's existing engagement Audit items and their completed engagement-workflow runs as the population and test evidence, plus the standing QAIP framework, charter, and methodology-manual Policy items. In scope: assessing the internal audit function's conformance with the Global Internal Audit Standards for the period. Out of scope: engagement-level rework — this cycle assesses quality, it does not redo fieldwork, which belongs to the engagement workflows. There is no upstream feeder; this workflow starts the quality chain and hands its approved results — overall conclusion, per-domain ratings, and conformance-statement wording — to Quarterly Board & Audit-Committee GRC Reporting.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-qaip-cycle","capabilities":[],"controls":["UC-AUDIT-19","UC-AUDIT-20","UC-AUDIT-03","UC-AUDIT-02","UC-AUDIT-04","UC-AUDIT-05","UC-AUDIT-06","UC-AUDIT-07","UC-AUDIT-08","UC-AUDIT-10","UC-AUDIT-01","UC-AUDIT-09"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:a154310aaad6e60914859edbbf54493e6a822745667977c77e5400e90fa4a26a","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-qaip-cycle","standards":["iia-2024"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-a5-cb7fa618.html","id":"wf:A5","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA5","slug":"audit-qaip-cycle","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Quality Assurance & Improvement Program Cycle","type":"workflow","url":"/assets/agent_record-wf-a5-cb7fa618.630571d876c00aca.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-charter-independence-board-governance","description":"Runs on one Audit item created per governance cycle (audit_type: internal; scope set to the internal-audit charter/independence/board-governance cycle for the period) — the workflow instance attaches to that cycle item and writes to it throughout. The internal audit function and its board-approved charter — a Policy item (policy_type: charter) with its own version lineage — already exist and are reviewed, reaffirmed, or amended here, never recreated. The cycle as a decision-aware procedure: the CAE delivers functional reporting to the audit committee, affirms organizational independence in writing and treats any impairment, reviews and reapproves the board mandate and charter with its unrestricted-access provisions, runs the executive session and committee action on the CAE and the plan and budget, executes the stakeholder communication plan, and retains the governance evidence. Consumes upstream: closed assurance-engagement records (Audit items with their linked Issue findings) produced by the individual engagement workflows, the recommendation-tracking register (Issue items), and the prior cycle's carry-forward (open Issue items plus the prior run's carry-forward list). Named deliverables: the CAE functional reporting pack, the written organizational-independence affirmation, the reaffirmed or reapproved audit charter, the audit-committee minutes and resolution records, the stakeholder communication log, and the control-linked governance evidence set. In scope: the board-governance cycle for the internal audit function itself — charter, independence, committee reporting, and stakeholder communication; out of scope: the individual assurance engagements whose results feed the committee report, which run under their own workflows. Terminal by design: no downstream workflow is chained from this cycle; open threads carry forward to seed the next run of this same cycle.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-charter-independence-board-governance","capabilities":[],"controls":["UC-AUDIT-01","UC-AUDIT-02","UC-AUDIT-03","UC-AUDIT-05","UC-AUDIT-18","UC-AUDIT-27"],"domains":["audit"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:d0ac12a0fd4a357279d21a76e1ed578eebdbb7f2fbf7bdc0dc9bdb8487e44c53","roleIntegrity":{"activityCount":4,"ermPhases":["monitor","report","cross_cutting"],"lineRoles":["third","external"],"serviceModes":["assurance","advisory","administrative"],"warnings":[]},"sourceTemplateId":"workflow-library:audit-internal-audit-charter-independence-board-governance","standards":["iia-2024","coso-ic"],"teams":["internal-audit","executive"]},"direct":false,"htmlUrl":"/agents/records/wf-a8-414556d8.html","id":"wf:A8","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA8","slug":"audit-internal-audit-charter-independence-board-governance","sourceIds":["coso-ic","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Internal Audit Charter, Independence & Board Governance Cycle","type":"workflow","url":"/assets/agent_record-wf-a8-414556d8.d1cb0879ca235797.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-annual-internal-audit-planning-resource-management","description":"Runs the chief audit executive's annual internal audit planning cycle on a per-cycle Audit item created for the year (audit_type=internal, e.g. \"Annual IA Planning Cycle FY20XX\", status PLANNED→COMPLETE, period_start/period_end = the plan year) — the anchor the workflow instance and every cycle document and link hang off, since no native plan/cycle type exists. It consumes the standing (prior-year) audit universe carried in as Process items plus the prior cycle's archived instance and universe memo, and enriches rather than recreates it: it refreshes the audit universe and the documented understanding of governance, risk, and control processes, ranks the universe by residual risk, develops the internal audit strategy and the risk-based audit plan, resources it with a budget, staffing, and technology plan, tests resource sufficiency, obtains board approval, and reassesses the plan and resources on the quarterly refresh. In scope is the enterprise-level planning cycle from audit-universe refresh through board approval, plus the quarterly plan-and-resource reassessment; delivering the individual engagements is out of scope — the approved engagement list (the created engagement Audit items) hands off to each engagement's own audit engagement planning workflow.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-annual-internal-audit-planning-resource-management","capabilities":[],"controls":["UC-AUDIT-09","UC-AUDIT-10"],"domains":["audit"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:2e25e6b33c874dbffd18cd204117039793dba7390af3d1956eb91cbbd82141f7","roleIntegrity":{"activityCount":3,"ermPhases":["manage","monitor"],"lineRoles":["third"],"serviceModes":["advisory"],"warnings":[]},"sourceTemplateId":"workflow-library:audit-annual-internal-audit-planning-resource-management","standards":["iia-2024"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-a9-8040386c.html","id":"wf:A9","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA9","slug":"audit-annual-internal-audit-planning-resource-management","sourceIds":["iia-2024","iia-pos-2026-erm"],"sourceUrl":null,"title":"Annual Internal Audit Planning & Resource Management","type":"workflow","url":"/assets/agent_record-wf-a9-8040386c.5194d800d207dd20.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-planning-scoping","description":"Runs on the existing audit item. Plan an audit engagement from four independent starting points — management self-identified issues, the external threat and regulatory landscape, prior audit history, and the in-scope risk and control set — which converge into the walkthrough question set, the walkthrough, and the approved risk and control matrix that governs fieldwork. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-planning-scoping","capabilities":["audit-planning-scoping"],"controls":["UC-AUDIT-05","UC-AUDIT-11","UC-AUDIT-12"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:b129f9b9eac5c2e11573cd10f14c1314472067164b8f97a66dcff8c708730543","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-planning-scoping","standards":["iia-2024"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-d10-392b8e6b.html","id":"wf:D10","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AD10","slug":"audit-planning-scoping","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Audit Planning and Scoping","type":"workflow","url":"/assets/agent_record-wf-d10-392b8e6b.f8104bc7674a4ad6.json"},{"attributes":{"department":"internal-audit","domain":"grc","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-combined-assurance-mapping","description":"Combined Assurance Mapping as a decision-aware workflow. Each cycle runs as one workflow instance attached to an Audit item created for the cycle (audit_type: advisory, scope = the combined-assurance mapping scope for the period, period_start/period_end = the cycle period) — no other Studio type represents an assurance-coordination cycle, so the workflow enriches that Audit item rather than any pre-existing engagement. In scope: mapping assurance coverage across the Three Lines of Defense for the confirmed risk universe and entities this cycle — cataloging assurance providers, mapping their coverage onto the risk universe, assessing reliance, identifying gaps and duplication, coordinating coverage plans, publishing the combined assurance map, and preparing audit-committee reporting inputs. Out of scope: performing the underlying assurance engagements themselves (owned by internal audit, second-line functions, and external providers) and any risk, entity, or provider not named in this cycle's confirmed scope. It consumes the risk universe and residual positions (Risk items with their residual_rating and treatment) from the upstream Enterprise Risk Assessment & Portfolio Oversight Cycle and hands its named deliverables — the published combined assurance map, the reliance conclusions, and the gap action plans — to the downstream Quarterly Board & Audit-Committee GRC Reporting workflow rather than duplicating repeated work.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-combined-assurance-mapping","capabilities":[],"controls":["UC-AUDIT-23","UC-AUDIT-18","UC-AUDIT-27","UC-GOV-38"],"domains":["grc"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:f0ae775a3a86f082f6bcc1a2383a15f8e0219c50577d82600fbd8fa89c947e8e","roleIntegrity":{"activityCount":2,"ermPhases":["assess"],"lineRoles":["second","third"],"serviceModes":["assurance"],"warnings":[]},"sourceTemplateId":"workflow-library:grc-combined-assurance-mapping","standards":["iia-2024"],"teams":["internal-audit","risk-management"]},"direct":false,"htmlUrl":"/agents/records/wf-g2-bd9bee15.html","id":"wf:G2","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG2","slug":"grc-combined-assurance-mapping","sourceIds":["ccpa","cobit-2019","coso-ic","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001"],"sourceUrl":null,"title":"Combined Assurance Mapping","type":"workflow","url":"/assets/agent_record-wf-g2-bd9bee15.87f19d0784457f79.json"},{"attributes":{"department":"risk-management","domain":"grc","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-enterprise-risk-register-lifecycle","description":"Enterprise Risk Register Lifecycle as a decision-aware workflow. This is a standalone recurring instance (quarterly or annual) that runs against the existing Risk item population — the enterprise risk register itself — enriching those Risk items in place rather than recreating a register: per-risk results are written onto the individual Risk items, and cycle-level deliverables attach to the workflow instance's steps. In scope: maintaining the register across the confirmed entities, business units, and risk-taxonomy categories for this cycle — intake and deduplication of new risks, Three-Lines ownership, control and assurance mapping, KRIs, periodic review and escalation, and retirement. Out of scope: any entity, unit, or category not named in this cycle's confirmed scope. It consumes the candidate-risk handoff package from the upstream Risk Register Intake workflow and hands its maintained register, residual positions, and escalations to two downstream workflows — Enterprise Risk Assessment & Portfolio Oversight Cycle (the maintained register, the concentration and correlation flags, and the residual positions) and Risk Appetite Definition & Board Reporting (the above-appetite entries, the escalations, and the acceptances) — rather than duplicating repeated work.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-enterprise-risk-register-lifecycle","capabilities":[],"controls":["UC-RISK-10","UC-RISK-09","UC-RISK-13","UC-RISK-05","UC-GOV-38"],"domains":["grc"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:c93ca4af1ef0fb0829dc57626fed632b72751eed20f08bb8b59f66e7fa0ac457","roleIntegrity":{"activityCount":1,"ermPhases":["cross_cutting"],"lineRoles":["second"],"serviceModes":["administrative"],"warnings":[]},"sourceTemplateId":"workflow-library:grc-enterprise-risk-register-lifecycle","standards":["coso-erm","iso-31000"],"teams":["risk-management"]},"direct":false,"htmlUrl":"/agents/records/wf-g4-a265153d.html","id":"wf:G4","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG4","slug":"grc-enterprise-risk-register-lifecycle","sourceIds":["coso-erm","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-31000","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Enterprise Risk Register Lifecycle","type":"workflow","url":"/assets/agent_record-wf-g4-a265153d.991ad2704842d587.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0ab85b62605a0cc1d7fad0caaff344a503e50114cc7abbf9da035cb6d1000e78","properties":{},"sourceDetailPath":"/data/v1/records/wf-a5-cb7fa618.json","sourceId":"wf:A5","targetDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","targetId":"uc:UC-AUDIT-09","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0dbb135014fc23b5e9e783cdceff73a0dbe3290e67bee867d9f1144353fe09c6","properties":{"rationale":"Board-approved service boundaries, impairment disclosure, and independent coverage preserve assurance credibility for the stakeholders who rely on internal audit.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1084b9bd598ffa0e6391985bad5a84175d6b6c7e5bfb7baa1e6f7bdb61b9aa96","properties":{},"sourceDetailPath":"/data/v1/records/wf-a11-0924c009.json","sourceId":"wf:A11","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:13c15c39b720105320ae0c15edeef87c33dc872270c01113fc115be7c028447e","properties":{"control_id":"IIA-POS-ERM-01","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 3, 7–9","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-01-6f73f46d.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-01","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1889e1064f89088e03dd6aa659e4c9423282a6569b34c5524edfd3940b55072b","properties":{"rationale":"Activity-level Three Lines accountability assigns named risk decision-makers, challenge, and independent assurance, directly countering execution drift caused by unclear role ownership.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/risk-strategic-misalignment-execution-d9c0675b.json","targetId":"risk:strategic-misalignment-execution","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2da111153671b539bce20f369f30c67fcf7d08159a5a719b336629c3d2eb91ae","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-04-592b59ae.json","sourceId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-04","targetDetailPath":"/data/v1/records/std-iia-pos-2026-erm-d24e4aa8.json","targetId":"std:iia-pos-2026-erm","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:31aad85a41264a2f288f88465dff2361c9eedafac885731f96494a7a3e3b78d4","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-03-2ed09a44.json","sourceId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-03","targetDetailPath":"/data/v1/records/std-iia-pos-2026-erm-d24e4aa8.json","targetId":"std:iia-pos-2026-erm","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:37b061e56d22142ddc51e3b30a6612e15b06727b53790c237c770be9ccebc719","properties":{"rationale":"A board-approved risk-based plan directs independent assurance to the key risks the board must oversee.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/risk-gov-oversight-failure-d98ffc12.json","targetId":"risk:gov-oversight-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ae879825aa0923bdf383513123695da051588e837f4f6f10635b82f82e58d33","properties":{},"sourceDetailPath":"/data/v1/records/wf-a9-8040386c.json","sourceId":"wf:A9","targetDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","targetId":"uc:UC-AUDIT-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4926845441ec44ba26ca61f03aa59b3cc26fd9322b26be564e62c304d11488d3","properties":{},"sourceDetailPath":"/data/v1/records/wf-g4-a265153d.json","sourceId":"wf:G4","targetDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","targetId":"uc:UC-GOV-38","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5bf1a2fac198dab4ead40a95bfd8d7686593bddada69ca6f2fd2404551110b7f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-02-1e6dc74e.json","sourceId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-02","targetDetailPath":"/data/v1/records/std-iia-pos-2026-erm-d24e4aa8.json","targetId":"std:iia-pos-2026-erm","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:67abbb98674a60d1e311149a41268506b940f4b8ce615e56e53b8d61ee29fb76","properties":{},"sourceDetailPath":"/data/v1/records/wf-a5-cb7fa618.json","sourceId":"wf:A5","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:68c54ab14ccc33912e6227b99398a504ebcf0e728f632bbb0a7cf0da84f88b69","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/risk-hr-employment-practices-disputes-2a788e39.json","targetId":"risk:hr-employment-practices-disputes","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6d345a1c2d22a56c7395a702b683dfd5f0474b5d9fb0b05577f6bfaf04af9443","properties":{"control_id":"IIA-POS-ERM-01","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 3, 7–9","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-01-6f73f46d.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-01","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:747356fdac6fa018a60214212b3f0e42631af892f6eab2220b5e18bd69bb0d1c","properties":{"rationale":"Documented, governance-approved Three Lines accountability makes risk ownership and retained board and management responsibility transparent, supporting stakeholder trust.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7570c0c37de5d53d21740767fc8ea868bdbe27a8ca8b45beddf0b5ced8d127c2","properties":{"rationale":"Individual objectivity with conflict screening, rotation, and recusal is what makes the audit genuinely independent and its assurance reliable.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7935b88e335a1fb9072eb8a5457ddf3271eab7fd68665ced0fc14a5439796813","properties":{},"sourceDetailPath":"/data/v1/records/wf-g2-bd9bee15.json","sourceId":"wf:G2","targetDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","targetId":"uc:UC-AUDIT-27","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:849306d150f8dce43c53633a952eee38e5f54d3e62b4670ece7d83424cf70911","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-01-6f73f46d.json","sourceId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-01","targetDetailPath":"/data/v1/records/std-iia-pos-2026-erm-d24e4aa8.json","targetId":"std:iia-pos-2026-erm","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8d8e9f9fedb91b03a998461590d29e0537db1686a82fa64c9d0f1ca4bc5e616d","properties":{},"sourceDetailPath":"/data/v1/records/wf-a8-414556d8.json","sourceId":"wf:A8","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c522f6d83718a2d10d7fb32cfd1a6507f5a6bf9f81ac574ec79e964ff79599c3","properties":{"control_id":"IIA-POS-ERM-03","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 12–13, 15–20","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-03-2ed09a44.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cb987e37171a9d9fbca514ecd492988fff1913a767ea997db1e4f516735a0e5a","properties":{},"sourceDetailPath":"/data/v1/records/wf-g2-bd9bee15.json","sourceId":"wf:G2","targetDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","targetId":"uc:UC-GOV-38","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d972f93de535219262d85640e50744e0492fa413875d8b8eee0557274b978e30","properties":{"control_id":"IIA-POS-ERM-02","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 8, 11","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-02-1e6dc74e.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-02","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dff5fbe626f856a99fa964c901dc3e7176cdc5bf15dd37141519715437b6a3e5","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/risk-ops-regulatory-reporting-failure-d1dbc50a.json","targetId":"risk:ops-regulatory-reporting-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e440dc99ef84dba28eab3f5113cdab754bbd2af30d33effae6aaa6846849553e","properties":{},"sourceDetailPath":"/data/v1/records/wf-a8-414556d8.json","sourceId":"wf:A8","targetDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","targetId":"uc:UC-AUDIT-27","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ec08a2873e334dc6214319db8a39cc09b8f0ad002710d7722b3fcb850f80ebc6","properties":{"rationale":"Separating management decisions from internal audit and requiring independent coverage preserve assurance credibility when governance evaluates strategic execution.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/risk-strategic-misalignment-execution-d9c0675b.json","targetId":"risk:strategic-misalignment-execution","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ec8bea9ce78a6a49049aa07087e07adc5bc84be5cd0d5fc0b7dac5a4fdcceab6","properties":{"control_id":"IIA-POS-ERM-03","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 12–13, 15–20","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-03-2ed09a44.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:edf89edb5d6d8bf07bc34ac2386e3eb74f9d169ebbc065ffc19d5228403c6a92","properties":{},"sourceDetailPath":"/data/v1/records/wf-d10-392b8e6b.json","sourceId":"wf:D10","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f32821d0b84d82e1a105e55ab3563bf1af959c2a5f017cd896ba6e6c35dbd43e","properties":{"control_id":"IIA-POS-ERM-04","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM p. 14","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-04-592b59ae.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-04","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fee400d0d63f9fa16f1118bab34ec9c6ea10a200b514523920d84336df0655ea","properties":{},"sourceDetailPath":"/data/v1/records/wf-a10-c454863e.json","sourceId":"wf:A10","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"operates"}],"schemaVersion":1,"scope":"sources","total":23}
