{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:ai-highrisk-critical-infra","risk:compliance-no-independent-audit","risk:hr-employment-practices-disputes","risk:reputational-stakeholder-trust","risk:strategic-misalignment-execution","uc:UC-AUDIT-05","uc:UC-AUDIT-23","uc:UC-AUDIT-27","uc:UC-GOV-38","wf:A1","wf:A10","wf:A11","wf:A5","wf:A8","wf:C16","wf:C17","wf:D05","wf:D06","wf:D10","wf:G2","wf:G33","wf:G4"],"directIds":["ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-01","ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-02","ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-03","std:iia-pos-2026-three-lines"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"Three Lines Model: Assurance and Advice in Support of Effective Governance","next":null,"page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"iia-pos-2026-three-lines","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-pos-2026-three-lines/","description":"First, second, and third lines have distinct but complementary responsibilities; roles are classified by the activity performed, and outsourcing does not transfer accountability.","details":{"automation":"manual","control_category":"administrative","control_id":"IIA-POS-TLM-01","control_type":"preventive","domains":[],"framework":"iia-pos-2026-three-lines","group":"Three Lines Role Integrity","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":"Three Lines pp. 3–5, 13–19","source_url":null,"statement":"First, second, and third lines have distinct but complementary responsibilities; roles are classified by the activity performed, and outsourcing does not transfer accountability."},"direct":true,"htmlUrl":"/agents/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-01-2ee41e40.html","id":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-01","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-pos-2026-three-lines%3AIIA-POS-TLM-01","sourceIds":["iia-pos-2026-three-lines"],"sourceUrl":null,"title":"IIA-POS-TLM-01 — Activity-Level Three Lines Responsibilities","type":"control","url":"/assets/agent_record-ctrl-iia-pos-2026-three-lines-iia-pos-tlm-01-2ee41e40.659f242f428300c5.json"},{"attributes":{"category":"administrative","framework":"iia-pos-2026-three-lines","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-pos-2026-three-lines/","description":"Independence requires structural safeguards, board-approved expanded remit, protection against self-review, and at least 12 months between operational responsibility and assurance.","details":{"automation":"manual","control_category":"administrative","control_id":"IIA-POS-TLM-02","control_type":"preventive","domains":[],"framework":"iia-pos-2026-three-lines","group":"Three Lines Role Integrity","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":"Three Lines pp. 9–11, 20–22","source_url":null,"statement":"Independence requires structural safeguards, board-approved expanded remit, protection against self-review, and at least 12 months between operational responsibility and assurance."},"direct":true,"htmlUrl":"/agents/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-02-c2f0d9a7.html","id":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-pos-2026-three-lines%3AIIA-POS-TLM-02","sourceIds":["iia-pos-2026-three-lines"],"sourceUrl":null,"title":"IIA-POS-TLM-02 — Independence and Self-Review Safeguards","type":"control","url":"/assets/agent_record-ctrl-iia-pos-2026-three-lines-iia-pos-tlm-02-c2f0d9a7.873cc5fc729e256b.json"},{"attributes":{"category":"administrative","framework":"iia-pos-2026-three-lines","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-pos-2026-three-lines/","description":"Assurance providers coordinate and rely on one another only where independence, competence, evidence, and coverage support reliance; gaps and duplication remain visible to the board.","details":{"automation":"manual","control_category":"administrative","control_id":"IIA-POS-TLM-03","control_type":"detective","domains":[],"framework":"iia-pos-2026-three-lines","group":"Three Lines Role Integrity","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":"Three Lines pp. 15–16, 18–19","source_url":null,"statement":"Assurance providers coordinate and rely on one another only where independence, competence, evidence, and coverage support reliance; gaps and duplication remain visible to the board."},"direct":true,"htmlUrl":"/agents/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-03-95334e6e.html","id":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-pos-2026-three-lines%3AIIA-POS-TLM-03","sourceIds":["iia-pos-2026-three-lines"],"sourceUrl":null,"title":"IIA-POS-TLM-03 — Assurance Coordination and Reliance","type":"control","url":"/assets/agent_record-ctrl-iia-pos-2026-three-lines-iia-pos-tlm-03-95334e6e.efbc41e7c5cdc1d5.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Business Continuity & Disaster Recovery","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["eu-ai-act-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-highrisk-critical-infra","description":"Because AI acting as a safety component in critical digital infrastructure, road traffic, or utilities (Annex III(2)) operates without the required risk management, robustness, and human oversight, it can fail or behave unsafely, resulting in service disruption and threats to public safety and continuity.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-highrisk-critical-infra","taxonomies":["eu-ai-act-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-highrisk-critical-infra-a7a37365.html","id":"risk:ai-highrisk-critical-infra","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-highrisk-critical-infra","sourceIds":["aiuc-1","ccpa","cobit-2019","eu-ai-act","iia-2024","iia-pos-2026-three-lines","iso-27001","iso-42001"],"sourceUrl":null,"title":"Public-safety harm from AI in critical infrastructure","type":"risk","url":"/assets/agent_record-risk-ai-highrisk-critical-infra-a7a37365.188d0210ccd8c746.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-no-independent-audit","description":"Because independent internal and external audit and review of information security are not performed, control deficiencies and non-conformities are neither detected nor challenged, so weaknesses persist unremediated and management and the board lose reliable assurance over control effectiveness.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"compliance-no-independent-audit","taxonomies":["iso-27005-vulnerability","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-compliance-no-independent-audit-9e1acf0f.html","id":"risk:compliance-no-independent-audit","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-no-independent-audit","sourceIds":["ccpa","cobit-2019","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001","nis2","nist-800-53"],"sourceUrl":null,"title":"Lack of independent audit and compliance review","type":"risk","url":"/assets/agent_record-risk-compliance-no-independent-audit-9e1acf0f.8a44783c74772a6f.json"},{"attributes":{"category":"people_hr","domain":["Human Resources / Personnel Security","Compliance, Audit & Assurance"],"inherent_rating":"medium","taxonomy":["basel-operational-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-employment-practices-disputes","description":"Wrongful termination, wage-and-hour and overtime violations, benefit disputes, worker misclassification, whistleblower-protection breaches, and labor grievances/strike action causing litigation and operational loss.","details":{"category":"people_hr","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"hr-employment-practices-disputes","taxonomies":["basel-operational-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-hr-employment-practices-disputes-2a788e39.html","id":"risk:hr-employment-practices-disputes","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-employment-practices-disputes","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Employment-practice and labor-law violations","type":"risk","url":"/assets/agent_record-risk-hr-employment-practices-disputes-2a788e39.ad61d1925d1d36a4.json"},{"attributes":{"category":"reputational","domain":["Governance, Policy & Oversight","Risk Assessment & Management"],"inherent_rating":"medium","taxonomy":["coso-erm-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Areputational-stakeholder-trust","description":"Gradual loss of trust and social license among customers, employees, investors, regulators, and communities — from perceived values misalignment, poor ESG/governance conduct, or repeated service failures — weakening stakeholder relationships and long-term enterprise value even absent a single acute crisis.","details":{"category":"reputational","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"reputational-stakeholder-trust","taxonomies":["coso-erm-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-reputational-stakeholder-trust-23d21e70.html","id":"risk:reputational-stakeholder-trust","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Areputational-stakeholder-trust","sourceIds":["cobit-2019","coso-erm","coso-ic","gdpr","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-31000","nist-800-53","nist-csf-2","soc2","sox"],"sourceUrl":null,"title":"Stakeholder trust and social-license erosion","type":"risk","url":"/assets/agent_record-risk-reputational-stakeholder-trust-23d21e70.cc84ea3ea3c8507a.json"},{"attributes":{"category":"strategic","domain":["Governance, Policy & Oversight","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Astrategic-misalignment-execution","description":"Because strategic objectives are poorly defined, internally inconsistent, or misaligned with mission and stakeholders, approved strategies cannot be executed - resource gaps and weak governance of change compound the shortfall - resulting in resource misallocation, missed objectives, and value destruction.","details":{"category":"strategic","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"strategic-misalignment-execution","taxonomies":["coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-strategic-misalignment-execution-d9c0675b.html","id":"risk:strategic-misalignment-execution","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Astrategic-misalignment-execution","sourceIds":["cobit-2019","coso-erm","coso-ic","iia-pos-2026-erm","iia-pos-2026-three-lines","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Strategic misalignment and execution failure","type":"risk","url":"/assets/agent_record-risk-strategic-misalignment-execution-d9c0675b.d1ac0ae48868389a.json"},{"attributes":{"authority":"guidance","category":"iia-pos-2026-three-lines"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-pos-2026-three-lines/","description":"Three Lines Model: Assurance and Advice in Support of Effective Governance","details":{"amendmentState":"none","authority":"guidance","effectiveDate":null,"note":"Local reviewed paper: Three Lines Model: Assurance and Advice in Support of Effective Governance","propositions":[{"id":"IIA-POS-TLM-01","sourcePages":"Three Lines pp. 3–5, 13–19","title":"Activity-Level Three Lines Responsibilities"},{"id":"IIA-POS-TLM-02","sourcePages":"Three Lines pp. 9–11, 20–22","title":"Independence and Self-Review Safeguards"},{"id":"IIA-POS-TLM-03","sourcePages":"Three Lines pp. 15–16, 18–19","title":"Assurance Coordination and Reliance"}],"publicationDate":"2026","reviewed_at":null,"source_url":null,"version":"2026"},"direct":true,"htmlUrl":"/agents/records/std-iia-pos-2026-three-lines-1138e7ab.html","id":"std:iia-pos-2026-three-lines","mapUrl":"https://controlsmap.com/?v=1&node=std%3Aiia-pos-2026-three-lines","sourceIds":["iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Three Lines Model: Assurance and Advice in Support of Effective Governance","type":"standard","url":"/assets/agent_record-std-iia-pos-2026-three-lines-1138e7ab.dc7e1f3c5766bbff.json"},{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-05","description":"Internal auditors maintain individual objectivity - an unbiased professional attitude free from conflicts of interest - in all engagements. The chief audit executive implements safeguards such as conflict screening, assignment rotation, and recusal to protect objectivity, and auditors promptly disclose actual or perceived impairments so they can be managed and, where necessary, communicated to affected stakeholders. A complete prior-responsibility register is maintained and used for every engagement assignment. An auditor who held operational, design, management, or supervisory responsibility for an activity during the preceding 12 months is subject to a 12-month cooling-off period; if that requirement is not met, the engagement is reassigned or a suitably qualified independent party provides assurance. Portfolio-level reporting to senior management and the board identifies actual and perceived self-review threats and their safeguards. Conflict declarations, prior-responsibility screening, reassignment or independent-assurance results, and safeguard records are retained.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-ERM-03","propositionTitle":"Safeguards for Expanded ERM Responsibility","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 12–13, 15–20","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-TLM-02","propositionTitle":"Independence and Self-Review Safeguards","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 9–11, 20–22","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[{"control_id":"Principle 2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 2.1","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 2.2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 2.3","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"Internal auditors maintain individual objectivity - an unbiased professional attitude free from conflicts of interest - in all engagements. The chief audit executive implements safeguards such as conflict screening, assignment rotation, and recusal to protect objectivity, and auditors promptly disclose actual or perceived impairments so they can be managed and, where necessary, communicated to affected stakeholders. A complete prior-responsibility register is maintained and used for every engagement assignment. An auditor who held operational, design, management, or supervisory responsibility for an activity during the preceding 12 months is subject to a 12-month cooling-off period; if that requirement is not met, the engagement is reassigned or a suitably qualified independent party provides assurance. Portfolio-level reporting to senior management and the board identifies actual and perceived self-review threats and their safeguards. Conflict declarations, prior-responsibility screening, reassignment or independent-assurance results, and safeguard records are retained.","title":"Maintain auditor objectivity and disclose impairments","unified_id":"UC-AUDIT-05"},"direct":false,"htmlUrl":"/agents/records/uc-uc-audit-05-3332a81f.html","id":"uc:UC-AUDIT-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-05","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"UC-AUDIT-05 — Maintain auditor objectivity and disclose impairments","type":"unified","url":"/assets/agent_record-uc-uc-audit-05-3332a81f.e0f66febc0dfd61b.json"},{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-23","description":"The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.","details":{"control_category":"administrative","control_type":"detective","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-TLM-03","propositionTitle":"Assurance Coordination and Reliance","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 15–16, 18–19","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[{"control_id":"A.5.35","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CCPA-1798.185","coverage":"partial","delta":"risk-assessment submission obligations handled under risk management controls","framework":"ccpa","relationship":"intersects_with"},{"control_id":"MEA04","coverage":"full","framework":"cobit-2019","relationship":"superset_of"},{"control_id":"Std 9.5","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.","title":"Coordinate independent assurance reviews across providers","unified_id":"UC-AUDIT-23"},"direct":false,"htmlUrl":"/agents/records/uc-uc-audit-23-124d94d5.html","id":"uc:UC-AUDIT-23","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-23","sourceIds":["ccpa","cobit-2019","iia-2024","iia-pos-2026-three-lines","iso-27001"],"sourceUrl":null,"title":"UC-AUDIT-23 — Coordinate independent assurance reviews across providers","type":"unified","url":"/assets/agent_record-uc-uc-audit-23-124d94d5.9beb44d85e6248c7.json"},{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-27","description":"Any ERM, compliance, risk-management, or other second-line responsibility assigned to the internal audit function or chief audit executive is classified as assurance, advisory, administrative, supervisory, or operational; justified and documented in the internal audit charter or a board-approved appendix; and approved by the board with the associated independence and objectivity risks. Internal audit does not select or own risk responses or other management decisions. Expanded responsibilities are time-bounded with a transition plan when intended to be temporary, and actual or perceived impairments are disclosed to the board. Internal auditors do not provide assurance over an activity they designed, operated, managed, or supervised during the preceding 12 months; another suitably qualified and independent party provides assurance for affected areas. Safeguards, alternative assurance, and transition status are reviewed periodically.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-ERM-01","propositionTitle":"Board, Management, and Internal Audit Accountabilities","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 3, 7–9","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-ERM-03","propositionTitle":"Safeguards for Expanded ERM Responsibility","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 12–13, 15–20","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-TLM-02","propositionTitle":"Independence and Self-Review Safeguards","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 9–11, 20–22","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[],"statement":"Any ERM, compliance, risk-management, or other second-line responsibility assigned to the internal audit function or chief audit executive is classified as assurance, advisory, administrative, supervisory, or operational; justified and documented in the internal audit charter or a board-approved appendix; and approved by the board with the associated independence and objectivity risks. Internal audit does not select or own risk responses or other management decisions. Expanded responsibilities are time-bounded with a transition plan when intended to be temporary, and actual or perceived impairments are disclosed to the board. Internal auditors do not provide assurance over an activity they designed, operated, managed, or supervised during the preceding 12 months; another suitably qualified and independent party provides assurance for affected areas. Safeguards, alternative assurance, and transition status are reviewed periodically.","title":"Govern expanded internal audit ERM responsibilities","unified_id":"UC-AUDIT-27"},"direct":false,"htmlUrl":"/agents/records/uc-uc-audit-27-b7e48974.html","id":"uc:UC-AUDIT-27","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-27","sourceIds":["iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"UC-AUDIT-27 — Govern expanded internal audit ERM responsibilities","type":"unified","url":"/assets/agent_record-uc-uc-audit-27-b7e48974.99d46a06afc6330e.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-38","description":"For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[{"propositionId":"IIA-POS-ERM-01","propositionTitle":"Board, Management, and Internal Audit Accountabilities","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 3, 7–9","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-ERM-02","propositionTitle":"ERM Activity and Service Boundaries","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 8, 11","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-TLM-01","propositionTitle":"Activity-Level Three Lines Responsibilities","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 3–5, 13–19","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[],"statement":"For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.","title":"Assign and maintain Three Lines accountability by risk activity","unified_id":"UC-GOV-38"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-38-0167bec0.html","id":"uc:UC-GOV-38","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-38","sourceIds":["iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity","type":"unified","url":"/assets/agent_record-uc-uc-gov-38-0167bec0.951040fdf083d485.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-cybersecurity-assurance-review","description":"Cybersecurity Assurance Review — a CAE-owned assurance engagement that runs on the EXISTING Audit item opened from the audit plan (audit_type=it_audit, status PLANNED, lead_auditor and scope already set): the workflow instance attaches to that item and enriches it end to end, never creating a duplicate engagement record. It covers the three IIA Cybersecurity Topical Requirement domains (governance, risk management, and control activities) over the cyber estate bounded in the engagement memo (in scope: named legal entities, networks, cloud tenants, and OT/ICS where included; out of scope: areas whose assurance is documented as delivered by other engagements), testing against the NIST 800-53 Rev 5 catalog with CSF 2.0 / ISO 27001 as the aggregation frame. It originates from the audit plan (no upstream workflow) and produces the findings register (one four-Cs Issue per finding), the cyber posture summary carrying the per-domain and overall Standard 14.5 conclusions, and the approved engagement package — which it hands to the downstream Audit Report Drafting workflow.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-cybersecurity-assurance-review","capabilities":[],"controls":["UC-AUDIT-12","UC-AUDIT-13","UC-AUDIT-16","UC-AUDIT-23","UC-GOV-15","UC-VULN-01","UC-LOG-04","UC-IR-01","UC-BCDR-13","UC-LOG-01","UC-LOG-03","UC-LOG-05","UC-LOG-08","UC-VULN-05","UC-AUDIT-14"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:b1b1849f755b1bd298e35c5fe4919ba4e021cf217f67943330cb40b47b726828","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[{"code":"reliance-basis-incomplete","message":"Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.","missing":["independence","competence","evidence","recency","reliance rationale"],"nodeIds":[],"title":"Reliance basis is incomplete"}]},"sourceTemplateId":"workflow-library:audit-cybersecurity-assurance-review","standards":["iia-2024","nist-800-53"],"teams":["internal-audit","it"]},"direct":false,"htmlUrl":"/agents/records/wf-a1-f09c8201.html","id":"wf:A1","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA1","slug":"audit-cybersecurity-assurance-review","sourceIds":["ccpa","cobit-2019","hipaa","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Cybersecurity Assurance Review","type":"workflow","url":"/assets/agent_record-wf-a1-f09c8201.bcf6d3e5957c24c1.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-ethics-objectivity-competency-program","description":"Runs on an Audit item created per cycle as the anchor — audit_type=internal, scope set to the IA professional-practice program for the period, period_start/period_end = the cycle window (a program cycle, not an engagement, so this is a documented reuse of the Audit type; it is the \"cycle item\" every stream links its evidence to and closes at the end). A decision-aware annual cycle that attests the ethics and professional-courage expectations and documents deviations, screens per-engagement conflicts and manages objectivity impairments, collects confidentiality acknowledgments and restricts audit-file access, and assesses competency against role requirements with approved, tracked continuing-professional-development plans for each auditor. It consumes no upstream workflow: prior-cycle carryover (unresolved-deviation and monitored-impairment Issue items still open against the prior cycle's Audit item, plus in-progress development plans) is its own input, and the population is confirmed against the HR roster, engagement staffing, and the audit-file access list before measurement begins. Named deliverables: the professional-practice requirements memo, the ethics attestation register, the conflict-of-interest declarations and impairment register, the confidentiality acknowledgment register and before/after audit-file access review, the competency assessments with coverage matrix and CPD plans, and the signed CAE conformance report to the audit committee — assembled into an indexed cycle evidence file on the anchor Audit item. Downstream is self-feeding: the carry-forward list produced at close hands off to the next run of this same workflow; there is no distinct downstream workflow. In scope: every auditor and assisting party (employees plus co-source, outsourced, and guest auditors) who performed internal audit work or holds audit-file access during the period, across all four expectation streams (ethics, objectivity, confidentiality, competency); out of scope: the audit engagements' own subject-matter conclusions and any HR, legal, or ethics-office investigation a disclosed concern is referred into.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-ethics-objectivity-competency-program","capabilities":[],"controls":["UC-AUDIT-04","UC-AUDIT-05","UC-AUDIT-06","UC-AUDIT-08"],"domains":["audit"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:12fca28d6d3a7fe7190b7ac924cfb3b588fd0ceaa1afc3769dc1f7303c2c1f8f","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-internal-audit-ethics-objectivity-competency-program","standards":["iia-2024"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-a10-c454863e.html","id":"wf:A10","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA10","slug":"audit-internal-audit-ethics-objectivity-competency-program","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Internal Audit Ethics, Objectivity & Competency Program","type":"workflow","url":"/assets/agent_record-wf-a10-c454863e.5b80756b536cc72d.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-fraud-investigation","description":"Fraud & Forensic Investigation Engagement as a decision-aware workflow. It runs on a dedicated Audit item (audit_type: investigation) created for this allegation at intake — the confidential case record — with the workflow instance attached to that item and its visibility restricted to the named investigation team. In scope: one specific fraud allegation, worked predication-gated and confidentially from intake through evidence preservation, forensic procedures, interviews, loss quantification, and audit-committee reporting; the named deliverables are the chain-of-custody register, the findings memorandum with its loss-quantification schedule, and the privilege-marked audit-committee fraud report. Out of scope: the enterprise fraud risk profile (owned by Fraud Risk Assessment & Anti-Override Control Review, which receives scheme intelligence from this case rather than being rerun here) and any unrelated conduct discovered in passing (which gets its own intake record). It consumes the hotline intake package from Control Responsibility Communications & Ethics Hotline when so routed, and hands each control breakdown off as an Issue item — control-gap findings to Finding Remediation & Action-Plan Monitoring and ICFR-affecting deficiencies to SOX Deficiency Remediation — rather than duplicating that work.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-fraud-investigation","capabilities":[],"controls":["UC-AUDIT-05","UC-AUDIT-08","UC-AUDIT-12","UC-AUDIT-13","UC-AUDIT-14","UC-AUDIT-15","UC-AUDIT-16","UC-AUDIT-18","UC-IR-07"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:b5fe4ec3e78e34833795d4e184e8ffaddf20825dd6fd5fa09a4a661495cc0862","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-fraud-investigation","standards":["iia-2024"],"teams":["internal-audit","compliance-legal"]},"direct":false,"htmlUrl":"/agents/records/wf-a11-0924c009.html","id":"wf:A11","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA11","slug":"audit-fraud-investigation","sourceIds":["coso-ic","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"Fraud & Forensic Investigation Engagement","type":"workflow","url":"/assets/agent_record-wf-a11-0924c009.c336e97e36aab989.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-qaip-cycle","description":"Operate the Quality Assurance & Improvement Program (QAIP) cycle: ongoing-monitoring evidence, periodic self-assessment, external quality assessment (EQA) support, improvement planning, and board reporting. This cycle runs on an Audit item created per cycle (audit_type = internal — the schema has no quality_assessment option; scope = \"QAIP cycle FYxx\"; period_start/period_end span the period under assessment); the workflow instance attaches to that Audit item and every cycle output — the per-standard conformance ratings matrix, the below-GC finding Issue items, the improvement and action plan, and the QAIP results report — links back to it. It consumes the period's existing engagement Audit items and their completed engagement-workflow runs as the population and test evidence, plus the standing QAIP framework, charter, and methodology-manual Policy items. In scope: assessing the internal audit function's conformance with the Global Internal Audit Standards for the period. Out of scope: engagement-level rework — this cycle assesses quality, it does not redo fieldwork, which belongs to the engagement workflows. There is no upstream feeder; this workflow starts the quality chain and hands its approved results — overall conclusion, per-domain ratings, and conformance-statement wording — to Quarterly Board & Audit-Committee GRC Reporting.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-qaip-cycle","capabilities":[],"controls":["UC-AUDIT-19","UC-AUDIT-20","UC-AUDIT-03","UC-AUDIT-02","UC-AUDIT-04","UC-AUDIT-05","UC-AUDIT-06","UC-AUDIT-07","UC-AUDIT-08","UC-AUDIT-10","UC-AUDIT-01","UC-AUDIT-09"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:a154310aaad6e60914859edbbf54493e6a822745667977c77e5400e90fa4a26a","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-qaip-cycle","standards":["iia-2024"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-a5-cb7fa618.html","id":"wf:A5","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA5","slug":"audit-qaip-cycle","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Quality Assurance & Improvement Program Cycle","type":"workflow","url":"/assets/agent_record-wf-a5-cb7fa618.630571d876c00aca.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-charter-independence-board-governance","description":"Runs on one Audit item created per governance cycle (audit_type: internal; scope set to the internal-audit charter/independence/board-governance cycle for the period) — the workflow instance attaches to that cycle item and writes to it throughout. The internal audit function and its board-approved charter — a Policy item (policy_type: charter) with its own version lineage — already exist and are reviewed, reaffirmed, or amended here, never recreated. The cycle as a decision-aware procedure: the CAE delivers functional reporting to the audit committee, affirms organizational independence in writing and treats any impairment, reviews and reapproves the board mandate and charter with its unrestricted-access provisions, runs the executive session and committee action on the CAE and the plan and budget, executes the stakeholder communication plan, and retains the governance evidence. Consumes upstream: closed assurance-engagement records (Audit items with their linked Issue findings) produced by the individual engagement workflows, the recommendation-tracking register (Issue items), and the prior cycle's carry-forward (open Issue items plus the prior run's carry-forward list). Named deliverables: the CAE functional reporting pack, the written organizational-independence affirmation, the reaffirmed or reapproved audit charter, the audit-committee minutes and resolution records, the stakeholder communication log, and the control-linked governance evidence set. In scope: the board-governance cycle for the internal audit function itself — charter, independence, committee reporting, and stakeholder communication; out of scope: the individual assurance engagements whose results feed the committee report, which run under their own workflows. Terminal by design: no downstream workflow is chained from this cycle; open threads carry forward to seed the next run of this same cycle.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-charter-independence-board-governance","capabilities":[],"controls":["UC-AUDIT-01","UC-AUDIT-02","UC-AUDIT-03","UC-AUDIT-05","UC-AUDIT-18","UC-AUDIT-27"],"domains":["audit"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:d0ac12a0fd4a357279d21a76e1ed578eebdbb7f2fbf7bdc0dc9bdb8487e44c53","roleIntegrity":{"activityCount":4,"ermPhases":["monitor","report","cross_cutting"],"lineRoles":["third","external"],"serviceModes":["assurance","advisory","administrative"],"warnings":[]},"sourceTemplateId":"workflow-library:audit-internal-audit-charter-independence-board-governance","standards":["iia-2024","coso-ic"],"teams":["internal-audit","executive"]},"direct":false,"htmlUrl":"/agents/records/wf-a8-414556d8.html","id":"wf:A8","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA8","slug":"audit-internal-audit-charter-independence-board-governance","sourceIds":["coso-ic","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Internal Audit Charter, Independence & Board Governance Cycle","type":"workflow","url":"/assets/agent_record-wf-a8-414556d8.d1cb0879ca235797.json"},{"attributes":{"department":"internal-audit","domain":"controls","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-isms-internal-audit-management-review","description":"Runs one ISO 27001 clause 9.2 internal audit and clause 9.3 management review cycle — including clause 10.1 corrective actions — against the existing Audit item for this cycle (audit_type=internal), whose scope, lead_auditor, and period dates already carry the ISMS audit-programme entry: the workflow enriches that Audit item and its findings, never creates a duplicate audit. Upstream it consumes the Annex A control population (Control items, framework iso-27001) and the applicability decisions in the Statement of Applicability, the risk register (Risk items) and treatment plan, the prior-cycle Audit and open Issue records, and the org's ISMS policies and procedures (Policy items) as audit criteria. Named deliverables: the internal audit findings report, the clause 10.1 corrective-action records (recorded on the finding Issue items), the management review pack, and the approved clause 9.3 minutes and action register. Out of scope: the certification-body external audit and day-to-day control operation. No upstream workflow feeds this cycle and no single downstream workflow consumes its output; at close the cycle is archived on the Audit item as retained ISMS documented information, and carry-forward items re-enter the audit programme (the next PLANNED Audit item), the risk register, or the next review's inputs.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-isms-internal-audit-management-review","capabilities":[],"controls":["UC-AUDIT-23","UC-AUDIT-22","UC-GOV-15","UC-AUDIT-17"],"domains":["controls"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:742d77471fcfb9e129cd8c2c7bf4a77d76efc0dc9e0982900aaa8c182a577076","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[{"code":"reliance-basis-incomplete","message":"Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.","missing":["independence","competence","evidence","recency","reliance rationale"],"nodeIds":[],"title":"Reliance basis is incomplete"}]},"sourceTemplateId":"workflow-library:controls-isms-internal-audit-management-review","standards":["iso-27001"],"teams":["internal-audit","it","executive"]},"direct":false,"htmlUrl":"/agents/records/wf-c16-5cfe940e.html","id":"wf:C16","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC16","slug":"controls-isms-internal-audit-management-review","sourceIds":["ccpa","cobit-2019","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-csf-2","nydfs-500"],"sourceUrl":null,"title":"ISMS Internal Audit & Management Review","type":"workflow","url":"/assets/agent_record-wf-c16-5cfe940e.b4554998fd4e48e4.json"},{"attributes":{"department":"it","domain":"controls","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-soc2-readiness-evidence-cycle","description":"SOC 2 Readiness & Evidence Collection runs ON an already-opened Audit item — the SOC examination engagement record (audit_type readiness, or external_attestation) whose scope (report type and Type 1/Type 2), examination period (period_start/period_end), and CPA firm (external_firm) are already set. That Audit item is an INPUT: this workflow enriches it and attaches its run to it, never creating a duplicate engagement. It consumes the organization's own Control library — the Control items, framework tagged soc2/soc1 — and no upstream workflow feeds it. In scope: one SOC examination cycle end to end — map the Control library to each in-scope Trust Services criterion (Security always; Availability, Confidentiality, Processing Integrity, or Privacy only where a customer commitment requires it) and SOC 1 control objective, close readiness gaps, run the provided-by-client (PBC) evidence request list with QA, and coordinate the CPA firm through fieldwork and follow-ups. Named deliverables: the criteria-to-control mapping matrix and graded gap matrix, the owned PBC evidence request list, the QA'd evidence set, and the cross-referenced PBC response package — all attached to the anchor Audit and its workflow instance. Out of scope: the SOC report the CPA firm drafts and continuous control monitoring between examinations. No downstream workflow is declared; this run's next-cycle seed artifacts (the PBC list and control calendar) stay on the close step as the de facto handoff to the next examination.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-soc2-readiness-evidence-cycle","capabilities":[],"controls":["UC-AUDIT-21","UC-AUDIT-23","UC-AUDIT-25","UC-RISK-14"],"domains":["controls"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:a75a8829641f824e14de4a3ac834eb857327b7536a5954b8f5b887df61305df4","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[{"code":"reliance-basis-incomplete","message":"Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.","missing":["independence","competence","evidence","recency","reliance rationale"],"nodeIds":[],"title":"Reliance basis is incomplete"}]},"sourceTemplateId":"workflow-library:controls-soc2-readiness-evidence-cycle","standards":["soc2","soc1"],"teams":["it","compliance-legal"]},"direct":false,"htmlUrl":"/agents/records/wf-c17-334c380f.html","id":"wf:C17","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC17","slug":"controls-soc2-readiness-evidence-cycle","sourceIds":["ccpa","cobit-2019","coso-ic","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","soc2","sox"],"sourceUrl":null,"title":"SOC 2 Readiness & Evidence Collection","type":"workflow","url":"/assets/agent_record-wf-c17-334c380f.d9519829e4f191bc.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage1-documentation-review","description":"Certification-body Stage 1 review of the ISMS against ISO/IEC 27001:2022 clauses 4–10: context and leadership, planning and support, operation, and performance evaluation with improvement - walking each clause group against the governing documents and the operating processes that carry it, and concluding Stage 2 readiness with dual sign-off. Stage 1 documentation and readiness review for ISO/IEC 27001:2022 clauses 4–10, conducted under the engagement methodology. It informs Stage 2 planning and does not issue a certification decision. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage1-documentation-review","capabilities":[],"controls":["UC-AUDIT-21","UC-AUDIT-22","UC-AUDIT-23","UC-AUDIT-25","UC-CONFIG-02","UC-GOV-02","UC-GOV-06","UC-GOV-11","UC-GOV-12","UC-GOV-14","UC-GOV-15","UC-GOV-16","UC-HR-06","UC-RISK-03","UC-RISK-06","UC-RISK-09","UC-RISK-14","UC-RISK-15","UC-TRAIN-01"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:943b404cc0e12e6e267dfbc1f1d00c7877ba4169de0de517c4d7fb5e13899775","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[{"code":"reliance-basis-incomplete","message":"Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.","missing":["independence","competence","evidence","recency","reliance rationale"],"nodeIds":[],"title":"Reliance basis is incomplete"}]},"sourceTemplateId":"workflow-library:audit-iso27001-stage1-documentation-review","standards":["iso-27001"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-d05-2302db1f.html","id":"wf:D05","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AD05","slug":"audit-iso27001-stage1-documentation-review","sourceIds":["ccpa","cobit-2019","coso-erm","coso-ic","hipaa","iia-2024","iia-pos-2026-three-lines","iso-27001","iso-31000","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2","sox"],"sourceUrl":null,"title":"ISO 27001 Stage 1 ISMS Documentation Review","type":"workflow","url":"/assets/agent_record-wf-d05-2302db1f.1d673318680c60b2.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage2-controls-audit","description":"Attach to the existing Audit engagement, owned by Internal Audit, using its approved Statement of Applicability, risk treatment plan, scope, review period and operating evidence; produce the Stage 2 Annex A Controls Audit report, four signed theme conclusions and finding register for the engagement and remediation owners. Apply the approved Statement of Applicability to ISO/IEC 27001:2022 Annex A.5.1–A.5.37, A.6.1–A.6.8, A.7.1–A.7.14 and A.8.1–A.8.34; document each exclusion and assess direct and inherited responsibilities. This Annex A assessment contributes to the engagement and does not independently establish full ISMS conformity or issue certification. Stage 1 and readiness remain separate workflows; any certification decision remains with the authorized certification body.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage2-controls-audit","capabilities":[],"controls":["UC-ACCESS-02","UC-ACCESS-03","UC-ACCESS-04","UC-ACCESS-05","UC-ACCESS-06","UC-ACCESS-08","UC-ACCESS-09","UC-ACCESS-18","UC-ASSET-01","UC-ASSET-03","UC-ASSET-04","UC-ASSET-06","UC-ASSET-07","UC-ASSET-08","UC-AUDIT-23","UC-AUDIT-24","UC-AUDIT-25","UC-BCDR-01","UC-BCDR-03","UC-BCDR-04","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-03","UC-CONFIG-05","UC-CRYPTO-02","UC-DATA-09","UC-DATA-11","UC-DATA-12","UC-DATA-13","UC-GOV-03","UC-GOV-06","UC-GOV-07","UC-GOV-08","UC-GOV-14","UC-GOV-22","UC-GOV-23","UC-HR-01","UC-HR-02","UC-HR-03","UC-HR-04","UC-HR-05","UC-HR-07","UC-IR-01","UC-IR-03","UC-IR-04","UC-IR-06","UC-IR-07","UC-IR-10","UC-LOG-01","UC-LOG-02","UC-LOG-04","UC-LOG-08","UC-NET-01","UC-NET-13","UC-PHYS-01","UC-PHYS-02","UC-PHYS-03","UC-PHYS-04","UC-PHYS-05","UC-PHYS-06","UC-PHYS-08","UC-PHYS-09","UC-RISK-02","UC-RISK-17","UC-SDLC-01","UC-SDLC-03","UC-SDLC-04","UC-SDLC-05","UC-SDLC-10","UC-SDLC-14","UC-TPRM-01","UC-TPRM-04","UC-TPRM-07","UC-TPRM-08","UC-TRAIN-01","UC-VULN-03","UC-VULN-04","UC-VULN-05"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:b684ea2e0d1a9c1dea7abe73d94ca5e187127e4e8497cd066aaf3917023996ae","roleIntegrity":{"activityCount":5,"ermPhases":["assess","report"],"lineRoles":["third"],"serviceModes":["assurance"],"warnings":[{"code":"reliance-basis-incomplete","message":"Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.","missing":["competence","recency"],"nodeIds":["approve-annex-a-conclusion","assess-organizational-controls","assess-people-controls","assess-physical-controls","assess-technological-controls"],"title":"Reliance basis is incomplete"}]},"sourceTemplateId":"workflow-library:audit-iso27001-stage2-controls-audit","standards":["iso-27001"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-d06-c9616fb8.html","id":"wf:D06","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AD06","slug":"audit-iso27001-stage2-controls-audit","sourceIds":["aiuc-1","ccpa","cobit-2019","coso-erm","coso-ic","dora","eu-ai-act","gdpr","hipaa","iia-2024","iia-pos-2026-three-lines","iso-27001","iso-31000","nis2","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"ISO 27001 Stage 2 Annex A Controls Audit","type":"workflow","url":"/assets/agent_record-wf-d06-c9616fb8.602879df218362f9.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-planning-scoping","description":"Runs on the existing audit item. Plan an audit engagement from four independent starting points — management self-identified issues, the external threat and regulatory landscape, prior audit history, and the in-scope risk and control set — which converge into the walkthrough question set, the walkthrough, and the approved risk and control matrix that governs fieldwork. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-planning-scoping","capabilities":["audit-planning-scoping"],"controls":["UC-AUDIT-05","UC-AUDIT-11","UC-AUDIT-12"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:b129f9b9eac5c2e11573cd10f14c1314472067164b8f97a66dcff8c708730543","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-planning-scoping","standards":["iia-2024"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-d10-392b8e6b.html","id":"wf:D10","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AD10","slug":"audit-planning-scoping","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"Audit Planning and Scoping","type":"workflow","url":"/assets/agent_record-wf-d10-392b8e6b.f8104bc7674a4ad6.json"},{"attributes":{"department":"internal-audit","domain":"grc","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-combined-assurance-mapping","description":"Combined Assurance Mapping as a decision-aware workflow. Each cycle runs as one workflow instance attached to an Audit item created for the cycle (audit_type: advisory, scope = the combined-assurance mapping scope for the period, period_start/period_end = the cycle period) — no other Studio type represents an assurance-coordination cycle, so the workflow enriches that Audit item rather than any pre-existing engagement. In scope: mapping assurance coverage across the Three Lines of Defense for the confirmed risk universe and entities this cycle — cataloging assurance providers, mapping their coverage onto the risk universe, assessing reliance, identifying gaps and duplication, coordinating coverage plans, publishing the combined assurance map, and preparing audit-committee reporting inputs. Out of scope: performing the underlying assurance engagements themselves (owned by internal audit, second-line functions, and external providers) and any risk, entity, or provider not named in this cycle's confirmed scope. It consumes the risk universe and residual positions (Risk items with their residual_rating and treatment) from the upstream Enterprise Risk Assessment & Portfolio Oversight Cycle and hands its named deliverables — the published combined assurance map, the reliance conclusions, and the gap action plans — to the downstream Quarterly Board & Audit-Committee GRC Reporting workflow rather than duplicating repeated work.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-combined-assurance-mapping","capabilities":[],"controls":["UC-AUDIT-23","UC-AUDIT-18","UC-AUDIT-27","UC-GOV-38"],"domains":["grc"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:f0ae775a3a86f082f6bcc1a2383a15f8e0219c50577d82600fbd8fa89c947e8e","roleIntegrity":{"activityCount":2,"ermPhases":["assess"],"lineRoles":["second","third"],"serviceModes":["assurance"],"warnings":[]},"sourceTemplateId":"workflow-library:grc-combined-assurance-mapping","standards":["iia-2024"],"teams":["internal-audit","risk-management"]},"direct":false,"htmlUrl":"/agents/records/wf-g2-bd9bee15.html","id":"wf:G2","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG2","slug":"grc-combined-assurance-mapping","sourceIds":["ccpa","cobit-2019","coso-ic","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001"],"sourceUrl":null,"title":"Combined Assurance Mapping","type":"workflow","url":"/assets/agent_record-wf-g2-bd9bee15.87f19d0784457f79.json"},{"attributes":{"department":"compliance-legal","domain":"grc","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-regulatory-exam-management","description":"Manage a live regulator examination or external audit end to end — from notification intake through request fulfillment, QC’d evidence release, fieldwork support, preliminary-findings response, and commitment closure. Runs on an Audit engagement item created per exam (audit_type = regulatory_exam, or external_attestation for an external audit); the workflow instance attaches to that Audit anchor, and preliminary findings and their corrective-action commitments become linked Issue items. No upstream workflow feeds this — it is triggered by the exam or audit notification itself. In scope: coordinating examiner requests, controlled evidence release, and management responses for a single exam or audit engagement. Out of scope: remediating the underlying control gaps — the findings and committed corrective actions hand off to Finding Remediation & Action-Plan Monitoring — and standing up new obligations surfaced by the exam, which hand off to Regulatory Horizon Scanning & Triage and Regulatory Obligation Implementation.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-regulatory-exam-management","capabilities":[],"controls":["UC-GOV-23","UC-AUDIT-17","UC-AUDIT-23","UC-AUDIT-24","UC-ACCESS-14"],"domains":["grc","reg"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:f6435e4199020b25d9143bcab2ab97b3aebb9f4c636df19a252b35f46f085c74","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[{"code":"reliance-basis-incomplete","message":"Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.","missing":["independence","competence","evidence","recency","reliance rationale"],"nodeIds":[],"title":"Reliance basis is incomplete"}]},"sourceTemplateId":"workflow-library:grc-regulatory-exam-management","standards":["nydfs-500","dora","soc1","soc2"],"teams":["compliance-legal"]},"direct":false,"htmlUrl":"/agents/records/wf-g33-6008159c.html","id":"wf:G33","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG33","slug":"grc-regulatory-exam-management","sourceIds":["aiuc-1","ccpa","cobit-2019","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"Regulatory Exam & External Audit Management","type":"workflow","url":"/assets/agent_record-wf-g33-6008159c.13168981ead3556c.json"},{"attributes":{"department":"risk-management","domain":"grc","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-enterprise-risk-register-lifecycle","description":"Enterprise Risk Register Lifecycle as a decision-aware workflow. This is a standalone recurring instance (quarterly or annual) that runs against the existing Risk item population — the enterprise risk register itself — enriching those Risk items in place rather than recreating a register: per-risk results are written onto the individual Risk items, and cycle-level deliverables attach to the workflow instance's steps. In scope: maintaining the register across the confirmed entities, business units, and risk-taxonomy categories for this cycle — intake and deduplication of new risks, Three-Lines ownership, control and assurance mapping, KRIs, periodic review and escalation, and retirement. Out of scope: any entity, unit, or category not named in this cycle's confirmed scope. It consumes the candidate-risk handoff package from the upstream Risk Register Intake workflow and hands its maintained register, residual positions, and escalations to two downstream workflows — Enterprise Risk Assessment & Portfolio Oversight Cycle (the maintained register, the concentration and correlation flags, and the residual positions) and Risk Appetite Definition & Board Reporting (the above-appetite entries, the escalations, and the acceptances) — rather than duplicating repeated work.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-enterprise-risk-register-lifecycle","capabilities":[],"controls":["UC-RISK-10","UC-RISK-09","UC-RISK-13","UC-RISK-05","UC-GOV-38"],"domains":["grc"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:c93ca4af1ef0fb0829dc57626fed632b72751eed20f08bb8b59f66e7fa0ac457","roleIntegrity":{"activityCount":1,"ermPhases":["cross_cutting"],"lineRoles":["second"],"serviceModes":["administrative"],"warnings":[]},"sourceTemplateId":"workflow-library:grc-enterprise-risk-register-lifecycle","standards":["coso-erm","iso-31000"],"teams":["risk-management"]},"direct":false,"htmlUrl":"/agents/records/wf-g4-a265153d.html","id":"wf:G4","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG4","slug":"grc-enterprise-risk-register-lifecycle","sourceIds":["coso-erm","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-31000","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Enterprise Risk Register Lifecycle","type":"workflow","url":"/assets/agent_record-wf-g4-a265153d.991ad2704842d587.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:083eb07ca149e8112ed6cf7541a60e05026915716647852270d94d91d25914e5","properties":{"rationale":"Planning and obtaining independent reviews of information security at intervals and after change (ISO A.5.35) is the independent-review control this risk lacks.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0dbb135014fc23b5e9e783cdceff73a0dbe3290e67bee867d9f1144353fe09c6","properties":{"rationale":"Board-approved service boundaries, impairment disclosure, and independent coverage preserve assurance credibility for the stakeholders who rely on internal audit.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1084b9bd598ffa0e6391985bad5a84175d6b6c7e5bfb7baa1e6f7bdb61b9aa96","properties":{},"sourceDetailPath":"/data/v1/records/wf-a11-0924c009.json","sourceId":"wf:A11","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:10ab744fc2f05812744d0be837bb31e3211af44a5d3e5027b8455f310249bb3a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c16-5cfe940e.json","sourceId":"wf:C16","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1889e1064f89088e03dd6aa659e4c9423282a6569b34c5524edfd3940b55072b","properties":{"rationale":"Activity-level Three Lines accountability assigns named risk decision-makers, challenge, and independent assurance, directly countering execution drift caused by unclear role ownership.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/risk-strategic-misalignment-execution-d9c0675b.json","targetId":"risk:strategic-misalignment-execution","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:424aa1d6be0feea8c3eff42b7f991ace14ed70b42933cf65e9c22040a2be720b","properties":{"control_id":"IIA-POS-TLM-01","coverage":"guidance","delta":null,"framework":"iia-pos-2026-three-lines","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Three Lines pp. 3–5, 13–19","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-01-2ee41e40.json","targetId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-01","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:48303bab97616f0e5f1342e26f5dd1bca6d01ba43e99eaa60d8ee32cec2458af","properties":{},"sourceDetailPath":"/data/v1/records/wf-g33-6008159c.json","sourceId":"wf:G33","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4926845441ec44ba26ca61f03aa59b3cc26fd9322b26be564e62c304d11488d3","properties":{},"sourceDetailPath":"/data/v1/records/wf-g4-a265153d.json","sourceId":"wf:G4","targetDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","targetId":"uc:UC-GOV-38","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5fceaa2dafcc802e8d6e37db2ad1e88f71871195dda76c9a02a17a6fa4776b55","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-03-95334e6e.json","sourceId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-03","targetDetailPath":"/data/v1/records/std-iia-pos-2026-three-lines-1138e7ab.json","targetId":"std:iia-pos-2026-three-lines","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:67abbb98674a60d1e311149a41268506b940f4b8ce615e56e53b8d61ee29fb76","properties":{},"sourceDetailPath":"/data/v1/records/wf-a5-cb7fa618.json","sourceId":"wf:A5","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:68c54ab14ccc33912e6227b99398a504ebcf0e728f632bbb0a7cf0da84f88b69","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/risk-hr-employment-practices-disputes-2a788e39.json","targetId":"risk:hr-employment-practices-disputes","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a3558ec7e9a10fd979fb2146dad124e9e35ecb0607b2fe082cd69dd44934bc9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c17-334c380f.json","sourceId":"wf:C17","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e8ccc435a5fcf927ce307de1a1e12e8921071d5f9e7484da8836b088cd51f71","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:747356fdac6fa018a60214212b3f0e42631af892f6eab2220b5e18bd69bb0d1c","properties":{"rationale":"Documented, governance-approved Three Lines accountability makes risk ownership and retained board and management responsibility transparent, supporting stakeholder trust.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7570c0c37de5d53d21740767fc8ea868bdbe27a8ca8b45beddf0b5ced8d127c2","properties":{"rationale":"Individual objectivity with conflict screening, rotation, and recusal is what makes the audit genuinely independent and its assurance reliable.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7935b88e335a1fb9072eb8a5457ddf3271eab7fd68665ced0fc14a5439796813","properties":{},"sourceDetailPath":"/data/v1/records/wf-g2-bd9bee15.json","sourceId":"wf:G2","targetDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","targetId":"uc:UC-AUDIT-27","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:806bf2cd1daca69abb1a4ae1ab016c6f590f9c99251a3cd266bea7c58307de2f","properties":{"control_id":"IIA-POS-TLM-02","coverage":"guidance","delta":null,"framework":"iia-pos-2026-three-lines","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Three Lines pp. 9–11, 20–22","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-02-c2f0d9a7.json","targetId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-02","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:85201cd31f0ee0e6db246c32a2fc40ce83139071e77d05dea752549461bcd912","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/risk-ai-highrisk-critical-infra-a7a37365.json","targetId":"risk:ai-highrisk-critical-infra","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8d8e9f9fedb91b03a998461590d29e0537db1686a82fa64c9d0f1ca4bc5e616d","properties":{},"sourceDetailPath":"/data/v1/records/wf-a8-414556d8.json","sourceId":"wf:A8","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9ae7358f763b8260c0f6fe9fa493cc2557b41b004c96ffa66e0f0b76d399a7dd","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9faf8a94071e8116b366bb45920bf621cc6c6119423787e39bfe5790e13c6009","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a1f433171b5aaf25af2d32fbfc47776014edc843e7c1f77d8dd25b39f4b867f4","properties":{"control_id":"IIA-POS-TLM-02","coverage":"guidance","delta":null,"framework":"iia-pos-2026-three-lines","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Three Lines pp. 9–11, 20–22","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-02-c2f0d9a7.json","targetId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-02","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c7e7cd6a2b9b5bf85a122d9970f37b1ec15b114f5b816136f898d82252b7ae92","properties":{"control_id":"IIA-POS-TLM-03","coverage":"guidance","delta":null,"framework":"iia-pos-2026-three-lines","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Three Lines pp. 15–16, 18–19","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-03-95334e6e.json","targetId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cb987e37171a9d9fbca514ecd492988fff1913a767ea997db1e4f516735a0e5a","properties":{},"sourceDetailPath":"/data/v1/records/wf-g2-bd9bee15.json","sourceId":"wf:G2","targetDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","targetId":"uc:UC-GOV-38","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d24407e00147961728306982a51e3cc72b1bb3edc653a3bde7863a093094d066","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-02-c2f0d9a7.json","sourceId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-02","targetDetailPath":"/data/v1/records/std-iia-pos-2026-three-lines-1138e7ab.json","targetId":"std:iia-pos-2026-three-lines","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e440dc99ef84dba28eab3f5113cdab754bbd2af30d33effae6aaa6846849553e","properties":{},"sourceDetailPath":"/data/v1/records/wf-a8-414556d8.json","sourceId":"wf:A8","targetDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","targetId":"uc:UC-AUDIT-27","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ec08a2873e334dc6214319db8a39cc09b8f0ad002710d7722b3fcb850f80ebc6","properties":{"rationale":"Separating management decisions from internal audit and requiring independent coverage preserve assurance credibility when governance evaluates strategic execution.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/risk-strategic-misalignment-execution-d9c0675b.json","targetId":"risk:strategic-misalignment-execution","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:edf89edb5d6d8bf07bc34ac2386e3eb74f9d169ebbc065ffc19d5228403c6a92","properties":{},"sourceDetailPath":"/data/v1/records/wf-d10-392b8e6b.json","sourceId":"wf:D10","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f601925a011412a5760ff5d13387a69f999643d139ee72d6afb659a36f3b1272","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-01-2ee41e40.json","sourceId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-01","targetDetailPath":"/data/v1/records/std-iia-pos-2026-three-lines-1138e7ab.json","targetId":"std:iia-pos-2026-three-lines","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f9caea0220c0f389ba0f63c3e49c48ade41cc55cfbf31a8af1df6c617bbedd4e","properties":{},"sourceDetailPath":"/data/v1/records/wf-g2-bd9bee15.json","sourceId":"wf:G2","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fee400d0d63f9fa16f1118bab34ec9c6ea10a200b514523920d84336df0655ea","properties":{},"sourceDetailPath":"/data/v1/records/wf-a10-c454863e.json","sourceId":"wf:A10","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"operates"}],"schemaVersion":1,"scope":"sources","total":26}
