{"description":"Runs on one Audit item created per governance cycle (audit_type: internal; scope set to the internal-audit charter/independence/board-governance cycle for the period) — the workflow instance attaches to that cycle item and writes to it throughout. The internal audit function and its board-approved charter — a Policy item (policy_type: charter) with its own version lineage — already exist and are reviewed, reaffirmed, or amended here, never recreated. The cycle as a decision-aware procedure: the CAE delivers functional reporting to the audit committee, affirms organizational independence in writing and treats any impairment, reviews and reapproves the board mandate and charter with its unrestricted-access provisions, runs the executive session and committee action on the CAE and the plan and budget, executes the stakeholder communication plan, and retains the governance evidence. Consumes upstream: closed assurance-engagement records (Audit items with their linked Issue findings) produced by the individual engagement workflows, the recommendation-tracking register (Issue items), and the prior cycle's carry-forward (open Issue items plus the prior run's carry-forward list). Named deliverables: the CAE functional reporting pack, the written organizational-independence affirmation, the reaffirmed or reapproved audit charter, the audit-committee minutes and resolution records, the stakeholder communication log, and the control-linked governance evidence set. In scope: the board-governance cycle for the internal audit function itself — charter, independence, committee reporting, and stakeholder communication; out of scope: the individual assurance engagements whose results feed the committee report, which run under their own workflows. Terminal by design: no downstream workflow is chained from this cycle; open threads carry forward to seed the next run of this same cycle.","edges":[{"id":"e-inventory-expanded-erm-responsibilities-affirm-organizational-independence","source":"inventory-expanded-erm-responsibilities","target":"affirm-organizational-independence"},{"id":"e-affirm-organizational-independence-disclose-and-treat-independence-impairment","label":"Impairment identified","source":"affirm-organizational-independence","target":"disclose-and-treat-independence-impairment","whenValue":"impairment_identified"},{"id":"e-affirm-organizational-independence-record-committee-governance-actions","label":"Independence affirmed","source":"affirm-organizational-independence","target":"record-committee-governance-actions","whenValue":"affirmed"},{"id":"e-disclose-and-treat-independence-impairment-perform-independent-assurance","source":"disclose-and-treat-independence-impairment","target":"perform-independent-assurance"},{"id":"e-perform-independent-assurance-record-committee-governance-actions","source":"perform-independent-assurance","target":"record-committee-governance-actions"},{"id":"e-review-and-reapprove-charter-revise-charter-for-board-approval","label":"Amend and reapprove","source":"review-and-reapprove-charter","target":"revise-charter-for-board-approval","whenValue":"amend_and_reapprove"},{"id":"e-review-and-reapprove-charter-record-committee-governance-actions","label":"Reaffirm charter as-is","source":"review-and-reapprove-charter","target":"record-committee-governance-actions","whenValue":"reaffirm_as_is"},{"id":"e-revise-charter-for-board-approval-record-committee-governance-actions","source":"revise-charter-for-board-approval","target":"record-committee-governance-actions"},{"id":"e-inventory-expanded-erm-responsibilities-record-committee-governance-actions","source":"inventory-expanded-erm-responsibilities","target":"record-committee-governance-actions"},{"id":"e-record-committee-governance-actions-execute-stakeholder-communication-plan","source":"record-committee-governance-actions","target":"execute-stakeholder-communication-plan"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-AUDIT-01","UC-AUDIT-02","UC-AUDIT-03","UC-AUDIT-05","UC-AUDIT-18","UC-AUDIT-27"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-charter-independence-board-governance","contentDigest":"sha256:d0ac12a0fd4a357279d21a76e1ed578eebdbb7f2fbf7bdc0dc9bdb8487e44c53","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:d0ac12a0fd4a357279d21a76e1ed578eebdbb7f2fbf7bdc0dc9bdb8487e44c53","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-internal-audit-charter-independence-board-governance"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"audit-internal-audit-charter-independence-board-governance","source":"coworkcanvas-gallery","standards":["iia-2024","coso-ic"],"teams":["internal-audit","executive"]},"name":"Internal Audit Charter, Independence & Board Governance Cycle","nodes":[{"data":{"controls":["UC-AUDIT-27"],"description":"Classify expanded ERM services and affected assurance, resolve charter/transition gaps, and attest the material completeness of the functional reporting pack.","instructions":"**Objective** — Classify expanded ERM services and affected assurance, resolve charter/transition gaps, and attest the material completeness of the functional reporting pack.\n\n**Inputs**\nEngagement records closed since the last committee meeting — the Audit items completed this period (rating, opinion, report_date) and their linked Issue findings (severity, issue_type: finding), produced by the individual engagement workflows.\n- The approved audit plan and its delivery status, plus any plan changes since approval — plan progress is derived from the portfolio of Audit items (status, fieldwork_start/fieldwork_end, period dates); the board-approved plan document itself is a step document on the prior cycle's committee-actions step.\n- The recommendation-tracking register — Issue items filtered on status, issue_owner, target_remediation_date, and actual_remediation_date (open, overdue, closed in the period).\n- Budget consumed against approved, staffing and vacancy position, co-source usage, and the function's performance metrics (Standard 12.2) — finance/HR extracts uploaded at this step (XLSX); AssureSwarm has no native budget/resource type.\n- The scope-limitation and access-restriction log for the period — uploaded at this step; any restriction escalated during the period should already exist as an Issue (issue_type: exception, source: internal_audit).\n\nThe internal audit charter, board minutes and approvals, organization charts, and the ERM responsibility register.\n- Current and prior service assignments for the CAE and audit staff.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive owns the stated judgments and authorizations.*\n\n*Assemble the audit-committee reporting pack.* Build the CAE's functional report to the audit committee — assurance results, plan progress, significant matters, and the resource position — stated so the committee can discharge its oversight under IIA Standards 7.1, 8.1, and 8.2 and act on the specific approvals requested.\n\n1. Compile the assurance results: engagements completed since the last meeting with their conclusions, plus the matters that meet the function's defined significance criteria for board attention — typically unresolved high-risk findings, findings open more than 90 days past their agreed date, suspected fraud or management override, and repeat findings that show remediation is not sticking. Report themes across engagements, not just a list.\n2. State plan progress against the approved plan: percent delivered, engagements deferred or added with reasons, and the forecast to plan-year end. Separate cosmetic schedule shifts from material changes — a material change to the approved plan requires committee approval under Standard 7.1, so present it as a decision, not a footnote.\n3. Build the resource section for the board's sufficiency determination (Standard 8.2): budget consumed versus approved, vacancies and time-to-fill, competency and capacity gaps, and — where a shortfall exists — the specific coverage that will not be delivered because of it. \"We are stretched\" is not reportable; \"the two deferred engagements are X and Y and the risk they cover goes unassured this year\" is.\n4. Surface every scope limitation or access restriction encountered during the period as its own section, even when the answer is \"none.\" Standard 7.1 has the board inquire about inappropriate scope or resource limitations; a pack that buries a restriction in an appendix defeats that inquiry.\n5. Add the quality view: quality-program status, internal-assessment results, and position in the external-quality-assessment cycle (Standard 8.4 requires an EQA at least every five years).\n6. Close with the decisions-requested list: each approval the committee will be asked to record this cycle, phrased as the resolution sought. Verify every assertion in the pack traces to an engagement record or register — this pack enters the committee's file and will be read by regulators and external auditors.\n\n*Inventory expanded ERM responsibilities.* Maintain an inventory of internal audit's expanded ERM responsibilities before the CAE and board evaluate organizational independence, so temporary support, advisory work, and operating responsibility cannot be mistaken for independent assurance.\n\n7. Inventory each expanded responsibility and classify the service as assurance, advisory, administrative, supervisory, or operational.\n8. Record the board approval, rationale, start date, permanency or transition status, transition owner and date, and every affected assurance area.\n9. Reconcile each responsibility to the charter and identify where a role creates self-review, management responsibility, reporting-line, or objectivity concerns.\n10. Record the cooling-off status, including whether the 12-month cooling-off period applies before the function can provide independent assurance over the affected area.\n11. Escalate unresolved charter conflicts or expired transition arrangements to the audit committee for the independence affirmation.\n\n**Record in AssureSwarm**\nAttach the assembled CAE functional reporting pack to this step (step document, PDF/DOCX) and add Item relationships from the cycle Audit item to the Audit and Issue items the pack summarizes.\n- Record the decisions-requested list on the cycle Audit item (in its `description`) so the minutes step can reconcile against it.\n- Capture the CAE's accuracy-and-completeness attestation as the step approval.\n\nAttach the expanded-responsibility inventory and its board approvals to this step; list the service classification as assurance, advisory, administrative, supervisory, or operational, plus charter reconciliation, safeguards, owners, dates, and affected assurance areas.\n\n**Exit criteria**\nPack covers assurance results, plan progress, resources with a stated sufficiency conclusion, restrictions (explicitly, even if none), quality, and an enumerated decisions-requested list; every figure traces to a linked record; the CAE has attested that nothing material is omitted.\n\nEvery expanded responsibility is classified as assurance, advisory, administrative, supervisory, or operational; approved or escalated; reconciled to the charter; and assigned a transition or cooling-off disposition before the independence affirmation.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the linked engagement results, plan status, and registers into the distributable committee pack; `/coach-query-data` pulls the plan-progress and recommendation-status figures it summarizes.","label":"Inventory expanded ERM responsibilities","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-render-package"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive","ermPhase":"cross_cutting","independenceRequired":false,"lineRole":"third","serviceMode":"advisory"}},"id":"inventory-expanded-erm-responsibilities"},{"data":{"decisionField":"independence_status","description":"Agent drafts the written independence affirmation covering the functional reporting line, CAE qualifications, unrestricted board access, and the expanded-responsibility inventory; the Chief Audit Executive owns this third-line administrative governance call and documents any impairment for the board.","formData":{"fields":[{"key":"independence_status","label":"Affirm organizational independence","options":[{"label":"Independence affirmed","value":"affirmed"},{"label":"Impairment identified","value":"impairment_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve whether the CAE can affirm the function's organizational independence to the board in writing without qualification, or whether an impairment — in fact or in appearance — must be disclosed and treated. The CAE owns the call; IIA Standard 7.1 requires the confirmation to the board at least annually and the disclosure of any impairment.\n\n**Decision criteria**\n\nThe branch rests on evidence assembled in this step: the functional reporting line (does the board actually approve the charter, plan, budget, and the CAE's appointment, evaluation, and remuneration — check the minutes, not the org chart); the administrative reporting line and whether it introduces pressure; the record of direct board access, including executive sessions actually held in the period; the CAE's qualifications against Standard 7.2; and a threat scan of the period — management pressure on scope, findings, or reporting; the CAE or auditors holding operational responsibility for areas the function audits; self-review of areas an auditor managed within the last twelve months; scope or budget restrictions imposed by management; and personal or financial conflicts. Log each threat with the safeguard applied to it.\n\n- **Independence affirmed (`affirmed`)** — every structural element is intact and evidenced: functional reporting to the board operating in practice, unrestricted and exercised board access including at least one executive session in the affirmation period, a qualified CAE, and every identified threat fully mitigated by a documented safeguard (reassignment, independent review of the affected engagement, a cooling-off period, co-sourced coverage). Residual threats at the level of appearance count against this branch unless the safeguard genuinely neutralizes the appearance, not just the fact.\n- **Impairment identified (`impairment_identified`)** — any threat is not fully mitigated: an imposed scope or budget restriction; blocked access to records, personnel, or property; the CAE carrying operational or second-line duties without an independent-review safeguard; an audit of an area the responsible auditor recently managed with no compensating review; a reporting-line change that removed a functional-oversight element; or pressure that altered a finding, rating, or report. Standard 7.1 treats impairment in appearance the same as in fact — when a reasonable third party would doubt objectivity, select this branch and let the board weigh the disclosure. A disclosed and treated impairment costs less than a clean affirmation later shown to be qualified.\n\n**Record in AssureSwarm**\n- Submit the decision form on this step: `independence_status` (the branch), the step result citing the threats-and-safeguards log entries and the reporting-line evidence, and the step's approver record (the CAE).\n- Attach the written organizational-independence affirmation addressed to the board — a positive statement that the function is positioned independently of the activities it audits, with functional reporting, unrestricted board access, and CAE qualifications intact — plus the reporting-line evidence (board minutes), the qualifications record, and the threats-and-safeguards log, as step documents (signed affirmation PDF, log XLSX).\n\n**Exit criteria** — Form submitted with a rationale that disposes every identified threat as safeguarded or impairing; the draft affirmation and its evidence pack are attached; the branch not selected is prunable. On `impairment_identified`, the affirmation text already flags the impairment rather than omitting it.","kind":"decision","label":"Affirm organizational independence","performedBy":{"primitives":["coach-document-upload","coach-query-data"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive","ermPhase":"report","independenceRequired":true,"lineRole":"third","serviceMode":"administrative"}},"id":"affirm-organizational-independence"},{"data":{"description":"Agent documents the impairment, its effect on engagements, and safeguards or disclosures for the board; the treatment names independent assurance, a transition owner and date, periodic board re-evaluation, and an explicit non-reliance statement for every affected engagement.","instructions":"**Objective** — Document the independence impairment in full, apply a treatment proportional to its significance, and put a plain-language disclosure in front of the board so no impaired assurance is presented as independent.\n\n**Inputs**\n- The impairment description and rationale from the independence decision, with the threats-and-safeguards log.\n- The engagement register for the affirmation period, to map which engagements the impairment touches.\n- The charter and reporting-line record, to test whether the impairment contradicts a board-approved provision.\n- Prior impairment disclosures, if any — a recurring impairment is a structural condition, not an event.\n\n**Procedure**\n1. Characterize the impairment: its nature (self-review, management interference, scope or budget restriction, operational responsibility, personal or financial conflict, reporting-line defect); whether it exists in fact, in appearance, or both; and whether it is a period-specific event or a structural condition. A structural condition — say, the CAE permanently owning a second-line function — needs a governance fix the board must decide, not an engagement-level safeguard.\n2. Map the blast radius: every engagement, opinion, or advisory output in the period the impairment touches. Disposition each — conclusions stand as issued, require independent re-review, or must be re-performed — and record who made that call.\n3. Select the treatment scaled to significance: reassign affected engagements; add independent supervisory review or external assurance over the affected area; restore the compromised reporting line or access right (the only real fix for structural interference); or, for low-significance appearance-level residue, a documented board acknowledgment that the residual threat is accepted. Acceptance is the board's decision to make, never the CAE's own.\n4. Draft the board disclosure in plain terms: what the impairment is, how it arose, which assurance it affects, the treatment applied, and what the board should discount or re-source as a result. No euphemism — \"a limitation was encountered\" hides exactly what Standard 7.1 requires the board to see.\n5. Open a tracked item per treatment with an owner and a due date; treatments that persist beyond this cycle carry an expiry or re-review date so they surface in the next cycle's intake.\n6. For every impaired engagement, obtain or arrange independent assurance, name a transition owner and date, schedule periodic board re-evaluation, and state an explicit non-reliance position until the safeguard is effective.\n\n**Record in AssureSwarm**\n- Create the impairment as an Issue — `issue_type: deficiency` (or `significant_deficiency` where the impairment is structural or affects issued assurance), `source: internal_audit`, `severity` scaled to significance, `issue_owner` the CAE, `identified_date` — with the nature (self-review, management interference, scope/budget restriction, operational responsibility, personal/financial conflict, reporting-line defect), the fact-vs-appearance call, and the event-vs-structural call captured in `description` and `root_cause`.\n- Add Item relationships from the impairment Issue to the affected Audit items and to the independence affirmation artifact; attach the plain-language board disclosure and the treatment plan as step documents.\n- Create one Issue per treatment (`issue_owner`, `target_remediation_date`; expiry or re-review date in `remediation_plan`), linked to the impairment Issue.\n- Attach the independent assurance arrangement, named transition owner and date, periodic board re-evaluation schedule, and explicit non-reliance statement to the impairment record.\n\n**Exit criteria** — The CAE and the board or committee chair have approved the disclosure and treatment; every affected engagement carries a recorded disposition; no impaired engagement is presented to the board as independent; treatment items are open with owners, dates, and expiries where they persist; periodic board re-evaluation and the non-reliance statement remain in force until independent assurance is restored.","label":"Disclose and treat the independence impairment","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive","ermPhase":"monitor","independenceRequired":false,"lineRole":"third","serviceMode":"administrative"}},"id":"disclose-and-treat-independence-impairment"},{"data":{"controls":["UC-AUDIT-27","UC-AUDIT-05"],"description":"The board or audit committee appoints a separately qualified independent provider to perform or re-perform assurance affected by an independence impairment and report its conclusion directly to the board.","instructions":"**Objective** — Obtain genuine independent assurance over every area affected by the disclosed impairment before the committee relies on the result.\n\n**Inputs**\n- The approved impairment disclosure and treatment, affected engagement list, prior assurance work, and explicit non-reliance statement.\n- The board or audit committee's provider-selection and approval criteria.\n\n**Procedure**\n1. A separately qualified independent provider is appointed and approved by the board or audit committee, confirms its independence and competence, performs or re-performs the affected assurance, retains its work and evidence, issues its result and conclusion directly to the board, and dispositions prior impaired assurance. The CAE supplies records but does not supervise the provider, approve scope or conclusion, or serve as the provider.\n2. Give the provider unrestricted access to the affected records, people, systems, and prior work while preserving its independent judgment.\n3. Reconcile the provider's scope to every affected engagement and require an explicit conclusion for each prior result: confirmed, modified, withdrawn, or replaced.\n4. Route the provider's report directly to the board or audit committee and update the non-reliance statement only for work the independent conclusion resolves.\n\n**Record in AssureSwarm**\n- Retain evidence that a separately qualified independent provider was appointed and approved by the board or audit committee, confirms its independence and competence, performs or re-performs the affected assurance, retains its work and evidence, issues its result and conclusion directly to the board, and dispositions prior impaired assurance. Record that the CAE supplies records but does not supervise the provider, approve scope or conclusion, or serve as the provider.\n- Attach the appointment approval, independence and competence confirmation, scope, workpapers or evidence index, direct board report, and prior-assurance disposition register to this step.\n\n**Exit criteria** — A separately qualified independent provider is appointed and approved by the board or audit committee, confirms its independence and competence, performs or re-performs the affected assurance, retains its work and evidence, issues its result and conclusion directly to the board, and dispositions prior impaired assurance; the CAE supplies records but does not supervise the provider, approve scope or conclusion, or serve as the provider. No prior impaired assurance is relied upon without that disposition.","label":"Perform independent assurance","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-items-link"]},"roleIntegrity":{"decisionOwner":"Audit Committee Chair","ermPhase":"monitor","independenceRequired":true,"lineRole":"external","serviceMode":"assurance"}},"id":"perform-independent-assurance"},{"data":{"decisionField":"charter_disposition","description":"Agent reviews the internal audit mandate and charter against the required authorities and unrestricted-access provisions and drafts a redline; human decides whether to reaffirm the charter as-is or amend it and take it to the board for reapproval","formData":{"fields":[{"key":"charter_disposition","label":"Review and reapprove the audit charter","options":[{"label":"Reaffirm charter as-is","value":"reaffirm_as_is"},{"label":"Amend and reapprove","value":"amend_and_reapprove"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Decide whether the board-approved internal audit mandate and charter remain complete, current, and consistent with practice (reaffirm as-is) or must be amended and taken back to the board for reapproval. The CAE owns the recommendation; the board owns the charter (IIA Standards 6.1 and 6.2).\n\n**Decision criteria**\n\nThe branch rests on a documented three-part test performed in this step. Content: the charter must state the function's purpose; the mandate — authority, role, and responsibilities (Standard 6.1); unrestricted access to the data, records, information, personnel, and physical property relevant to engagements; the CAE's organizational position and functional reporting line to the board; the commitment to conform with the Global Internal Audit Standards; the types of services provided; the board's and senior management's support responsibilities (Standard 6.3); and its own periodic-review clause. Currency: check the standards citation — a charter still referencing the 2017 IPPF attribute standards (1000, 1100, 1110) needs re-pointing to the Global Internal Audit Standards effective January 2025 — and confirm the review interval in the charter's own clause is being met. Practice: diff the charter against the period's events — reporting-line changes, organizational restructures, new regulatory expectations, scope expansions such as fraud investigation or new subsidiaries, and above all any access restriction actually encountered during an engagement that the charter's access provision should have prevented.\n\n- **Reaffirm charter as-is (`reaffirm_as_is`)** — every required provision is present and current, the standards citation is right, and nothing that happened in the period contradicts the text. Reaffirmation is still a recorded governance outcome: minute the review with the date, what was tested, and the conclusion that no amendment is needed. A skipped review and a recorded no-change review are entirely different pieces of evidence.\n- **Amend and reapprove (`amend_and_reapprove`)** — any provision is missing, outdated, or contradicted by practice. Materiality does not excuse the trip to the board: even a minor reporting-line correction requires board reapproval, because the board — not the CAE — owns the charter. An access restriction encountered in practice forces this branch or an explicit board discussion; leaving the provision unamended while practice contradicts it makes the charter aspirational, which is worse than either fixing the text or escalating the restriction.\n\n**Record in AssureSwarm**\n- Submit the decision form on this step: `charter_disposition` (the branch), the step result citing the redline items or the clean three-part test, and the step's approver record.\n- Attach the charter review record — what was tested, against what, and the conclusion — and the redline where one exists, as step documents (DOCX/PDF).\n- Add an Item relationship from the cycle Audit item to the existing charter Policy item (`policy_type: charter`) under review, and confirm the board-approved version tested is reflected in the Policy item's `version` and `next_review_date`.\n\n**Exit criteria** — Form submitted; the review record is attached regardless of branch, so the periodic review is evidenced even on reaffirmation; every redline item traces to a content gap, a currency gap, or a practice contradiction; the branch not selected is prunable.","kind":"decision","label":"Review and reapprove the audit charter","performedBy":{"primitives":["coach-document-upload","coach-query-data","coach-items-link"]}},"id":"review-and-reapprove-charter"},{"data":{"description":"Agent applies the charter amendments, version-stamps the revised mandate, and prepares the board approval memo; human CAE and committee chair approve the revised text for tabling","instructions":"**Objective** — Produce the amended, version-stamped charter text and the board approval memo, ready to table at the committee for reapproval.\n\n**Inputs**\n- The redline and review record from the charter-review decision.\n- The current board-approved charter version and its version history.\n- The committee's terms of reference and any corporate-secretariat drafting conventions that govern board-owned documents.\n\n**Procedure**\n1. Apply each redline item to the charter text — the authority, role, and responsibilities; the unrestricted-access provision covering records, personnel, and physical property; the functional reporting line; the standards-conformance commitment; and the statement of board and senior-management support. Then re-run the full content test from the review step on the finished text: amendments have a way of orphaning cross-references and definitions, and a charter that fixed one gap while opening another goes back to the board twice.\n2. Version-stamp the revision: new version number, revision date, and a change log stating what changed and why for each amendment. Preserve the prior board-approved version in the dated history — the lineage must show unbroken board approval, because a charter version in circulation that never went to the board is itself a governance gap.\n3. Run a consistency pass against adjacent governance documents: the audit-committee terms of reference and any board governance manual that cross-references the audit charter. A charter amended in isolation drifts from the documents that cite it; flag conflicts to the corporate secretary rather than silently editing documents the CAE does not own.\n4. Draft the board approval memo: the changes summarized with rationale, the conformance statement to the current Standards, and the exact resolution the committee is asked to pass. Committees approve resolutions, not diffs — write the resolution text for them.\n5. Compile the tabling pack — redline, clean version, change log, approval memo — and link it to the charter review record so the board's eventual decision traces to the assessment that prompted it.\n\n**Record in AssureSwarm**\n- Attach the redlined and clean charter versions, the change log, and the board approval memo as step documents (DOCX).\n- Add Item relationships from the tabling pack to the charter Policy item (`policy_type: charter`) and the cycle Audit item — the Policy item's `version`, `approved_by`, and `next_review_date` are drafted here but only updated once the committee reapproves at the committee-actions step, keeping board ownership intact.\n- Capture the CAE's and the committee chair's approval-for-tabling as the step approval.\n\n**Exit criteria** — Revised text passes the full content test, with the unrestricted-access provisions intact; the version history preserves the prior approved version with an unbroken lineage; the approval memo states the exact resolution sought; the CAE and the committee chair have approved the pack for tabling.","label":"Revise the charter for board approval","performedBy":{"primitives":["coach-document-upload","coach-items-link"]}},"id":"revise-charter-for-board-approval"},{"data":{"description":"Exercise board authority over charter, CAE, plan, budget and resources, hold the confidential executive session and confirm exact resolutions and accountable actions.","instructions":"**Objective** — Exercise board authority over charter, CAE, plan, budget and resources, hold the confidential executive session and confirm exact resolutions and accountable actions.\n\n**Inputs**\nThe list of governance actions due this run, drawn from the governance calendar and the prior cycle's carry-forward (audit-committee dates, executive-session slots, standing functional-reporting decisions due, and carried-forward items with owners).\n- The reporting pack, the independence affirmation with any impairment disclosure, and the charter materials from whichever branch ran — the tabling pack, or the recorded reaffirmation.\n- The committee terms of reference: quorum rules, standing invitees, pre-read lead time.\n\nThe meeting file: agenda with outcome types, linked artifacts, attendance.\n- The decisions-requested list from the reporting pack.\n- The recording secretary's meeting notes and, for the executive session, the chair's note.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Audit committee, committee chair and Chief Audit Executive with corporate secretary owns the stated judgments and authorizations.*\n\n*Convene the audit-committee session.* Put the committee in a position to act: an agenda that carries every governance decision due this cycle, a scheduled executive session without management present, and materials circulated far enough ahead to be read.\n\n1. Build the agenda from the governance actions due this cycle, item by item: the CAE's functional report; the charter item (the reapproval resolution if the amend branch ran, the recorded reaffirmation if not); audit plan and budget approval or progress; the resource-sufficiency determination (Standard 8.2); the CAE appointment, evaluation, and remuneration actions due — and removal, where applicable; and the written independence affirmation, including any impairment disclosure. Reconcile agenda to the governance actions due: a governance decision due this cycle but absent from the agenda is exactly the failure this workflow exists to prevent.\n2. Type each agenda item with the outcome the minutes must record — approve, note, or direct. An item without a defined outcome type produces minutes that evidence discussion but not oversight.\n3. Schedule the executive session: the CAE and the committee only, no management present (Standard 8.1). Keep it standing at every regular meeting rather than exceptional, so convening one signals nothing; reserve it for independence, access, management conduct, and anything that cannot be raised with management in the room. The CAE steps out in turn when the committee discusses the CAE's own remuneration or evaluation.\n4. Pre-circulate the pack, the affirmation, and the charter materials with the committee's lead time — five to seven business days is the working norm; less converts the meeting from decision-making into a first reading. Confirm quorum against the terms of reference and set per-item invitees: management present for their items, excluded from the executive session.\n5. Compile the meeting file: the agenda linked to each supporting artifact and to the decision each item must produce, so the minutes step can reconcile one-to-one.\n\n*Record committee governance actions and minutes.* Convert the committee meeting into oversight evidence: minutes and approval records that capture each governance decision in resolution language, an executive-session record calibrated to preserve candor, and a tracked action for everything the committee assigned.\n\n6. Capture each decision with the exact resolution language and the vote or consensus outcome: the committee's action on the CAE's appointment, evaluation, remuneration, or removal; approval of the audit plan and budget, including any modification the committee imposed; the resource-sufficiency determination (Standard 8.2 — record the conclusion, not just that resources were \"discussed\"); and the charter reapproval with the version number approved, where tabled.\n7. Record the executive session at the right altitude: that it occurred, who attended, the matters raised at headline level — independence, access, management conduct — and any direction the committee issued. Verbatim notes defeat the session's purpose; no record defeats the evidence. Standing practice is a separate confidential minute or chair's note, referenced — not reproduced — in the main minutes.\n8. Reconcile agenda to outcome one-to-one: every tabled item ends in a resolution, a noting, or a deferral with a target date. An agenda item with no recorded outcome is a reconciliation failure to chase now, while memories are fresh, not at the evidence-retention step.\n9. Open a tracked item for every action the committee assigned to the CAE or management: owner, due date, and the minute reference it traces to. These feed the recommendation-tracking register and the next cycle's carry-forward.\n10. Route the draft minutes to the committee chair for review and record their status honestly — draft, chair-reviewed, or formally approved (formal approval typically lands at the next meeting). The resolution records for individual decisions stand as evidence even while the minutes remain in draft.\n\n**Record in AssureSwarm**\nAttach the agenda as a step document (PDF) and record the meeting metadata — date, quorum confirmation, executive-session slot, circulation date and recipients — on this step and on the cycle Audit item; AssureSwarm has no native Meeting type, so the session is evidenced on the step and the cycle item rather than a dedicated record.\n- Add Item relationships from the cycle Audit item to each agenda item's supporting artifact — reporting pack, affirmation, charter materials.\n- Capture the CAE's and the committee chair's agenda approval as the step approval.\n\nAttach the draft audit-committee minutes, the resolution/approval records, and the executive-session reference note as step documents.\n- Where the committee reapproved an amended charter, update the charter Policy item (`policy_type: charter`) — `version`, `approved_by`, `effective_date`, `next_review_date` — to the reapproved version; this is the point at which board ownership lands. On a clean reaffirmation, refresh `next_review_date` to evidence the review with no text change.\n- Add Item relationships from the minutes to the reporting pack, the charter Policy item, and the independence affirmation artifact.\n- Create one Issue per committee-assigned action — `issue_owner`, `target_remediation_date`, minute reference in `description` — feeding the recommendation register and the next cycle's carry-forward.\n\n**Exit criteria**\nAgenda reconciles to the governance actions due with zero orphaned governance actions; every item carries an outcome type; the executive session is scheduled without management; materials circulated within the lead-time norm with the circulation logged; quorum confirmed.\n\nEvery agenda item reconciles to a recorded outcome; each committee decision carries resolution language, a date, and the approving body; the executive session is evidenced without breaching its confidentiality; every assigned action exists as a tracked item; the CAE has confirmed the minutes fairly reflect the committee's decisions.","label":"Record committee governance actions and minutes","performedBy":{"primitives":["coach-item-create","coach-query-data","coach-document-upload","coach-items-link","coach-item-update"]}},"id":"record-committee-governance-actions"},{"data":{"description":"Approve recipient-specific governance communications and confidentiality treatment, then deliver binding decisions and retain their evidence.","instructions":"**Objective** — Approve recipient-specific governance communications and confidentiality treatment, then deliver binding decisions and retain their evidence.\n\n**Inputs**\nThe stakeholder communication plan: the audience-by-message-by-channel matrix and each touchpoint's cadence.\n- The committee outcomes: approved plan and budget, assigned actions, governance decisions.\n- The significant-matters register and the confidentiality and redaction conventions for external sharing.\n- The external-audit coordination calendar and the organization's regulatory-relations protocol.\n\nEvery artifact the cycle produced: reporting pack; written independence affirmation, plus the impairment disclosure and treatment records if that branch ran; charter review record, plus the redline, clean version, change log, and approval memo if amended; agenda; minutes and resolution records; executive-session reference note; communication log.\n- The branch history of this run — which decision branches executed determines which conditional artifacts must exist.\n- The workflow's linked controls: UC-AUDIT-01 (independent internal audit function), UC-AUDIT-02 (board-approved mandate and charter), UC-AUDIT-03 (board oversight and support), UC-AUDIT-18 (stakeholder communication).\n- The records-retention schedule: board minutes and charter versions are commonly retained permanently; internal audit governance records typically seven to ten years, or per the regulated-industry schedule.\n- The open-thread list: impairment treatments with expiries, charter amendments awaiting later ratification, open committee-assigned actions, deferred communications.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive and authorized stakeholder liaisons owns the stated judgments and authorizations.*\n\n*Execute the stakeholder communication plan.* Deliver the cycle's tailored communications to the board, management, regulators, and external auditors through their defined channels, and log a trail that evidences the communication plan actually operated (IIA Standards 11.1 and 9.5).\n\n1. Work the plan matrix touchpoint by touchpoint: board and committee follow-ups; management briefings on the outcomes that affect them; regulator liaison through the designated regulatory-relations channel — never ad hoc, because internal audit reports are routinely examined material; and external-auditor coordination under Standard 9.5 — plan sharing, reliance discussions, and the significant control matters relevant to the financial-statement audit. Tailor each to the audience: the external auditor needs the control-relevant findings and testing coverage; the regulator gets responses through the protocol; management gets the actions that bind them.\n2. Have the CAE approve the audience, content and required redactions under the communication plan before dispatch; obtain counsel’s privilege review where required. Apply the external-sharing discipline before anything leaves: executive-session matters and unremediated vulnerabilities move on a need-to-know basis; investigation-related material gets a legal-privilege check first; distributed copies follow the redaction convention. Log what was withheld and why alongside what was shared.\n3. Deliver the committee outcomes to the parties they bind: the approved plan and budget to the functions affected, each assigned action to its owner with its due date, and the governance decisions to whoever must act on them. Delivery means confirmed receipt where the matter is binding, not fire-and-forget.\n4. Log every touchpoint as a communication record: audience, channel, date, matter communicated, artifact shared, and any redaction applied.\n5. Sweep the plan for gaps: any planned touchpoint not delivered is either completed now or explicitly deferred into the next cycle's carry-forward with a date. Silence against the plan is a finding against the function's own control.\n\n*Assemble and retain the governance evidence set.* Assemble the cycle's governance evidence into a complete, linked, audit-ready set that lets a reviewer trace each governance obligation to its artifact without oral explanation, archive it under the governance retention class, and complete the cycle after the authorized communications and evidence checklist, without a separate archival approval.\n\n*Filing and cycle completion follow the authorized communication package after the evidence checklist passes.*\n\n6. Inventory against the expected-artifact checklist, branch-aware: the impairment disclosure exists if and only if the impairment branch ran; the tabling pack exists if and only if the amend branch ran. A conditional artifact missing on an executed branch is a gap; one absent on a branch that never ran is correct.\n7. Verify the load-bearing provisions are actually evidenced, not merely asserted: functional reporting shown by minutes in which the board approves the plan, budget, and CAE appointment, evaluation, and remuneration actions (Standard 7.1); the executive session shown to have occurred (Standard 8.1); the resource-sufficiency determination minuted (Standard 8.2); the written affirmation dated within twelve months of the prior one; and the charter's unrestricted access to records, personnel, and property matched against zero unresolved access restrictions in the period — or a restriction that was escalated and disclosed rather than absorbed.\n8. Run signature-and-date hygiene: an unsigned resolution, an undated affirmation, or a draft stamped \"final\" is not evidence. Route each defect back to its owner now — this is the last step with the leverage to get signatures.\n9. Link each artifact to the control it operates: the affirmation and impairment records to UC-AUDIT-01; the charter, review record, and reapproval to UC-AUDIT-02; the agenda, minutes, resolutions, and executive-session note to UC-AUDIT-03; the communication log to UC-AUDIT-18. Build to external-quality-assessment standard — this set is what an EQA (Standard 8.4, at least every five years) samples to test governance-domain conformance.\n10. Confirm the cycle is actually closable: the checklist closed, every committee decision recorded, and nothing remaining that only this cycle can resolve. Open items that legitimately outlive the cycle transfer forward; unresolved gaps in this cycle's own evidence do not — they block closure.\n11. Export the executed workflow — steps, approvals, forms, decision rationales, and attached documents — and archive it with the evidence set in the designated repository under the retention class and immutability controls, keeping the charter versions, minutes, and affirmations retrievable. Record the archive reference on the cycle item, then verify retrievability by opening the archived copy from the reference alone; an upload confirmation is not a retrieval test.\n12. Build the carry-forward: each impairment treatment with its expiry or re-review date, each charter amendment awaiting board ratification, each open committee action with owner and due date, each deferred stakeholder touchpoint. Seed them into the next cycle's intake — the intake step of this workflow's next run reads exactly this list — and verify nothing on the open-thread list lacks a destination.\n13. Update the cycle item to closed with the closure timestamp and archive references, and notify the committee chair and the stream owners that the cycle is closed and where its record lives. The governance register's closed-cycle history is the on-cadence evidence an EQA or regulator samples first.\n\n**Record in AssureSwarm**\nAttach the stakeholder communication log — audience, channel, date, matter, artifact shared, redaction applied — as a step document (XLSX/CSV) on the cycle, and add Item relationships from each shared artifact to its log entry.\n- Add Item relationships from deliveries that discharged a committee-assigned action to that tracked-action Issue item.\n- Record the CAE’s approval of the audience-specific communication package in the native approval record; retain delivery evidence against that approved scope.\n\nUpload any artifact still living outside the workflow (step document) and add Item relationships linking each governance artifact to its Control item: the affirmation and impairment Issues to UC-AUDIT-01; the charter Policy item, review record, and reapproval to UC-AUDIT-02; the agenda, minutes, resolutions, and executive-session note to UC-AUDIT-03; the communication log to UC-AUDIT-18.\n- Record the completeness-check result — checklist outcome, defects found, and their resolution — on the cycle Audit item (in its `description`).\n- Export the executed workflow instance (steps, forms, approvals, decision rationales, documents) as the self-contained archive artifact and record its retrieval reference on the cycle Audit item.\n- Update the cycle Audit item: `status` → COMPLETE, `report_date` = committee/closure date, retention class and archive reference in `description`; refresh each carry-forward Issue (`issue_owner`, `target_remediation_date`) so it lands in the next cycle's intake with its owner and due date intact.\n- The communication approval authorizes filing and cycle completion once the evidence checklist passes; record completion without a separate archival approval.\n\n**Exit criteria**\nEvery touchpoint in the plan is delivered-and-logged or explicitly deferred with a date; external sharing shows the confidentiality, privilege, and redaction checks; binding deliveries show confirmed receipt; the communication history reads as evidence that the plan operated, not as narrative.\n\nChecklist closes with every expected artifact present, signed, and dated; branch-conditional artifacts reconcile to the branches that ran; every artifact is linked to its unified control; defects are resolved, not waived; the archive is self-contained and retrievability-tested from its reference under the applied retention class; every open thread has an owner, a due date, and a destination in the next cycle; the cycle item is closed with the authorized communications and retained evidence traceable.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` delivers the planned briefings, action assignments, and follow-ups through their channels with a logged trail that doubles as the communication record.","label":"Execute the stakeholder communication plan","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-notify","coach-items-link","coach-workflow-export","coach-item-update"]}},"id":"execute-stakeholder-communication-plan"}],"sourceTemplateId":"workflow-library:audit-internal-audit-charter-independence-board-governance"}
