{"description":"Operate the Quality Assurance & Improvement Program (QAIP) cycle: ongoing-monitoring evidence, periodic self-assessment, external quality assessment (EQA) support, improvement planning, and board reporting. This cycle runs on an Audit item created per cycle (audit_type = internal — the schema has no quality_assessment option; scope = \"QAIP cycle FYxx\"; period_start/period_end span the period under assessment); the workflow instance attaches to that Audit item and every cycle output — the per-standard conformance ratings matrix, the below-GC finding Issue items, the improvement and action plan, and the QAIP results report — links back to it. It consumes the period's existing engagement Audit items and their completed engagement-workflow runs as the population and test evidence, plus the standing QAIP framework, charter, and methodology-manual Policy items. In scope: assessing the internal audit function's conformance with the Global Internal Audit Standards for the period. Out of scope: engagement-level rework — this cycle assesses quality, it does not redo fieldwork, which belongs to the engagement workflows. There is no upstream feeder; this workflow starts the quality chain and hands its approved results — overall conclusion, per-domain ratings, and conformance-statement wording — to Quarterly Board & Audit-Committee GRC Reporting.","edges":[{"id":"e-lock-executable-workplan-run-internal-assessment","source":"lock-executable-workplan","target":"run-internal-assessment"},{"id":"e-run-internal-assessment-support-external-assessment","source":"run-internal-assessment","target":"support-external-assessment"},{"id":"e-support-external-assessment-classify-disposition","source":"support-external-assessment","target":"classify-disposition"},{"id":"e-classify-disposition-create-action-plan","label":"Action","source":"classify-disposition","target":"create-action-plan","whenValue":"gaps"},{"id":"e-classify-disposition-approve-or-revise-package","label":"Clear","source":"classify-disposition","target":"approve-or-revise-package","whenValue":"complete"},{"id":"e-classify-disposition-escalate-or-accept-risk","label":"Escalate","source":"classify-disposition","target":"escalate-or-accept-risk","whenValue":"monitor"},{"id":"e-create-action-plan-approve-or-revise-package","source":"create-action-plan","target":"approve-or-revise-package"},{"id":"e-escalate-or-accept-risk-approve-or-revise-package","source":"escalate-or-accept-risk","target":"approve-or-revise-package"},{"id":"e-approve-or-revise-package-handoff-to-related-workflow","label":"Approved","source":"approve-or-revise-package","target":"handoff-to-related-workflow","whenValue":"approved"},{"id":"e-approve-or-revise-package-resolve-approval-conditions","label":"Revise","source":"approve-or-revise-package","target":"resolve-approval-conditions","whenValue":"revise"},{"id":"e-resolve-approval-conditions-handoff-to-related-workflow","source":"resolve-approval-conditions","target":"handoff-to-related-workflow"},{"id":"e-run-internal-assessment-update-methodology-and-training-backlog","source":"run-internal-assessment","target":"update-methodology-and-training-backlog"},{"id":"e-update-methodology-and-training-backlog-handoff-to-related-workflow","source":"update-methodology-and-training-backlog","target":"handoff-to-related-workflow"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{"UC-AUDIT-19":"operates","UC-AUDIT-20":"operates"},"controls":["UC-AUDIT-19","UC-AUDIT-20","UC-AUDIT-03","UC-AUDIT-02","UC-AUDIT-04","UC-AUDIT-05","UC-AUDIT-06","UC-AUDIT-07","UC-AUDIT-08","UC-AUDIT-10","UC-AUDIT-01","UC-AUDIT-09"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-qaip-cycle","contentDigest":"sha256:a154310aaad6e60914859edbbf54493e6a822745667977c77e5400e90fa4a26a","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:a154310aaad6e60914859edbbf54493e6a822745667977c77e5400e90fa4a26a","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-qaip-cycle"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"audit-qaip-cycle","source":"coworkcanvas-gallery","standards":["iia-2024"],"teams":["internal-audit"]},"name":"Quality Assurance & Improvement Program Cycle","nodes":[{"data":{"description":"Approve the criteria, reproducible sample, independent reviewer allocation and assessment timetable before fieldwork.","instructions":"**Objective** — Approve the criteria, reproducible sample, independent reviewer allocation and assessment timetable before fieldwork.\n\n**Inputs**\nThe internal audit charter and the methodology manual — existing Policy items (`policy_type: charter` / `procedure`) at their current versions.\n- The prior QAIP framework — an existing Policy item — and prior-cycle observations about it.\n- The Global Internal Audit Standards text (Domains I–V) — external to AssureSwarm — and any regulator expectations for documented quality programs.\n\nThe engagement register — the period's existing Audit items (every engagement with a final communication issued in the period, all statuses, including cancelled or materially descoped); these carry `lead_auditor` and `audit_type` natively.\n- The audit-plan tracker for the completeness reconciliation — uploaded as a document on this step.\n- Stakeholder list (auditees, senior management, audit-committee members) for surveys and interviews — the survey-recipient list is fixed and attached here.\n- Staff roster with certifications, CPE records, and annual conflict-of-interest attestations — a PBC upload on this step (there is no Staff/HR item type).\n\nFinal sample list; QA-lead and reviewer availability.\n- The board/audit-committee calendar — specifically the meeting where results will be reported.\n- Prior-cycle lessons learned and any EQA recommendations that change how assessments are run.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive and QA lead owns the stated judgments and authorizations.*\n\n*Confirm and version QAIP framework.* Re-confirm and version the existing QAIP framework — components, criteria mapping, rating scale, KPIs, and roles — so every later procedure executes against a current written standard instead of habit. In a mature program the framework, charter, and methodology manual already exist as Policy items and are an INPUT; this step enriches and re-versions them, it does not build them from scratch.\n\n1. Confirm the program covers all aspects of the function and both required components: ongoing monitoring plus periodic self-assessment (Standard 12.1), and an external quality assessment at least once every five years (Standard 8.4). Re-confirm the calendar — annual self-assessment, with standard-by-standard rotation acceptable only if every standard is covered within each five-year EQA window.\n2. Re-confirm the criteria mapping: each standard mapped to the manual sections and artifacts that evidence it (engagement risk assessment → planning memo section; supervision → workpaper sign-off convention; communication quality → report template and review trail). This mapping is the self-assessment's testing skeleton — without it, ratings float on opinion. Update it only where the manual or the Standards changed.\n3. Confirm the rating scale with definitions — generally conforms, partially conforms, does not conform (the IIA Quality Assessment Manual scale) — and the aggregation rule that produces the overall opinion from per-standard ratings.\n4. Re-confirm the performance-measurement set under Standard 12.2, each KPI with a source, an owner, and a target. A workable core: percent of annual plan completed (≥ 90%), report cycle time from fieldwork end to issuance (≤ 30 days), engagements with documented supervisory review before issuance (100%), stakeholder survey mean (≥ 4.0 of 5), certified-staff CPE compliance (100%), corrective-action on-time closure (≥ 85%).\n5. Confirm roles and independence rules in the framework: the CAE owns the program; a QA lead executes it; no one rates their own engagements; results reach senior management and the board at least annually.\n6. Refresh the QAIP dashboard so KPI actuals trend continuously instead of being reconstructed at cycle end.\n\n*Select QAIP sample population.* Establish the complete population of the period's audit work and quality evidence, and draw a reproducible engagement sample that will carry the cycle's conformance conclusions.\n\n7. Build the engagement population and prove it complete: tie the count to the audit-plan tracker and reconcile every difference before sampling. Include cancelled and descoped engagements — how work gets dropped is a quality signal.\n8. Apply coverage rules before any random draw: each auditor-in-charge appears at least once per cycle; every engagement type is represented; at least one engagement with high-severity reported findings is included; any engagement that drew a stakeholder complaint or is subject to external reliance is auto-selected.\n9. Size the sample: 10–25% of issued reports, minimum 3–5 engagements for small functions; push toward the top of the range in the year before an EQA so the self-assessment predicts the external rating instead of being embarrassed by it.\n10. Fill remaining slots randomly with a recorded seed or documented picker so the draw is reproducible by a reviewer or a future external assessor.\n11. Fix the non-engagement populations now: survey recipients (auditees of sampled engagements plus audit-committee members and key senior management), and the staff-records slice for CPE and attestation checks (certified staff meet certification CPE requirements; the annual attestation round is complete).\n\n*Lock executable workplan.* Freeze scope, reviewer assignments, evidence expectations, and dates into a baselined workplan so the cycle executes against a fixed standard rather than a moving one.\n\n12. Pin criteria versions in writing: the Standards edition (Global Internal Audit Standards, effective January 2025), the QAIP framework version, and the rating scale — generally conforms, partially conforms, does not conform (GC/PC/DNC). Mid-cycle criteria drift becomes visible only if the baseline names versions.\n13. Assign every sampled engagement and every assessment domain to a named reviewer, and verify independence: no one reviews an engagement they performed or supervised. Document the check itself, not just the intent.\n14. Define what a completed procedure looks like — rating sheet, evidence references, exceptions log — so results are comparable across reviewers instead of stylistic.\n15. Back-plan from the audit-committee date: the results memo needs CAE approval at least two weeks before the meeting; assessment fieldwork must end at least four weeks before it, leaving room for improvement-plan drafting and the approval loop.\n16. Baseline the plan: any subsequent scope change requires documented CAE approval recorded on the cycle item.\n\n**Record in AssureSwarm**\n**Item field update** — re-version the QAIP framework Policy item: set `version`, `effective_date`, `next_review_date`, `review_frequency`, `policy_owner` (the CAE), and `framework: iia-2024`, and attach the framework document as the governed file on that Policy item (`Item document attach`); confirm the charter and methodology-manual Policy items are current and referenced.\n- **Step document** — attach the standard-to-evidence criteria mapping and the rating-scale definitions as documents on this step (they have no native per-standard field).\n- **Dashboard** — create or refresh the QAIP KPI dashboard and link it to the anchor Audit item.\n\n**Step document** — attach the population extract, the sample list, and the draw parameters (population count, sample size, coverage rules applied, seed or picker reference) as an XLSX on this step; Audit has no sample-population fields, so the numbers live in the document, not item fields.\n- **Item relationship** — link each sampled engagement Audit item to the anchor QAIP-cycle Audit item.\n- **Step document** — attach the fixed survey-recipient list and the staff-records slice (CPE, attestations) as uploads on this step (no Staff/HR item type).\n\n**Step document** — attach the locked, versioned workplan (per-reviewer assignments, back-planned milestone dates, pinned criteria versions, reviewer-independence check) as a document on this step.\n- **Item field update** — set `Audit.fieldwork_start` and `Audit.fieldwork_end` on the anchor to the assessment window; the back-planned CAE-approval and audit-committee milestone dates have no native field and stay in the workplan document.\n- **Step document** — attach the pinned criteria documents (Standards-to-evidence mapping, rating-scale definitions).\n\n**Exit criteria**\nFramework Policy item current, versioned, and CAE-approved; every in-scope standard mapped to evidence; each KPI has a source, target, and owner; dashboard live.\n\nPopulation reconciled to the plan tracker; sample satisfies all coverage rules; draw reproducible from recorded parameters; survey and staff-record populations fixed and linked.\n\nWorkplan approved and versioned; every procedure has an owner and a date; criteria versions pinned; reviewer independence verified and documented.\n\n> **⚡ Audit Artist accelerator:** `/coach-dashboard-create` — builds the QAIP KPI dashboard from the performance-measurement set so actuals trend continuously between cycles.","label":"Lock executable workplan","performedBy":{"primitives":["coach-item-update","coach-dashboard-create","coach-document-upload"]}},"id":"lock-executable-workplan"},{"data":{"description":"Rate conformance using independently corroborated evidence and determine root causes, interim protections and verifiable improvement proposals.","instructions":"**Objective** — Rate conformance using independently corroborated evidence and determine root causes, interim protections and verifiable improvement proposals.\n\n**Inputs**\nThe standard-to-evidence criteria mapping from the framework step, and the locked workplan's sample.\n- Sampled engagement workpapers and their AssureSwarm workflows with step approvals.\n- The manual's supervision and sign-off conventions; engagement planning and completion checklists.\n- Post-engagement survey returns and the interview schedule; KPI actuals from the QAIP dashboard.\n- Staff records (CPE, conflict-of-interest attestations); charter and plan approvals.\n\nThe ratings matrix and finding items; themed exceptions from supervision testing.\n- Prior-cycle improvement actions still open, with their history.\n- Training budget and the methodology-release calendar.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Independent QA lead and assessors owns the stated judgments and authorizations.*\n\n*Run internal assessment.* Prove the ongoing-monitoring half of Standard 12.1 operated through the period and execute the periodic self-assessment on that evidence: rate conformance with each in-scope standard, producing per-standard ratings that will survive external re-performance at the next EQA.\n\n*Supervision-evidence assembly supports the assessor’s subsequent conformance judgment.*\n\n1. For each sampled engagement, test the supervision chain in date order: planning approved before fieldwork began; workpaper reviewer sign-offs dated before report issuance; review notes raised and cleared, not deleted; the final communication approved by the CAE or a named delegate. Every date-sequence violation is an exception — log it, do not average it away.\n2. Verify embedded routines operated: completion checklists actually filled (not blank templates), findings carry the full elements (condition, criteria, cause, effect, recommendation), and any second-review requirement in the manual was performed on the engagements that triggered it.\n3. Reconcile KPI actuals to source on a spot basis — recompute report cycle time for two or three engagements straight from workflow timestamps. A dashboard nobody reconciles is decoration, not monitoring.\n4. Pull survey results for the sampled engagements; a response rate under roughly 40% weakens this evidence line — note it and compensate with extra interviews at item 8.\n5. Theme the exceptions (late sign-off, missing checklist, evidence gaps) with counts per theme. Themes with frequency become rating inputs; isolated slips become coaching notes.\n6. Work the standard-to-evidence mapping standard by standard across the domains: ethics and professionalism (attestations, independence declarations, impairment handling); governance (charter content, board interactions, positioning and budget); managing the function (risk-based plan and its approvals, resourcing, performance measurement); and engagement performance (planning, evidence sufficiency, supervision, communication), using the sampled engagements and the supervision-testing results as the test items.\n7. For each standard record four things: evidence examined with references, what conformance would look like, what was actually found, and the rating. Rating discipline: generally conforms = requirement in policy and consistently evidenced in practice; partially conforms = policy exists but practice is inconsistent (supervision sign-offs missing on two of six sampled engagements is PC, not GC-with-a-note); does not conform = requirement absent or systematically inoperative.\n8. Corroborate with people: structured interviews (CAE, staff, audit-committee chair, two or three principal auditees) plus survey scores. A GC rating contradicted by consistent stakeholder testimony gets re-examined, not explained away.\n9. Rate hard. The self-assessment is itself assessed at the next EQA — self-ratings an external assessor later downgrades cost more credibility than an honest PC today.\n10. Aggregate to the overall conclusion using the framework's rule; draft an observation for everything below GC, plus improvement opportunities that do not affect ratings but earn a place in the backlog.\n\n*Build improvement plan.* Convert every below-GC rating and accepted observation into owned, dated, verifiable improvement actions — the improvement half that makes the QAIP a program rather than a scorecard.\n\n11. Root-cause each finding before writing any action: methodology gap (the manual is silent or wrong), competency gap, capacity overload, tooling, or supervision discipline. An action that does not name its cause treats the symptom and reappears next cycle.\n12. Write actions to a verification standard: the action, one accountable owner, a due date, and the evidence that will prove closure — \"supervision sign-off exceptions = 0 across the next two quarterly monitoring checks\", not \"remind the team\".\n13. Sequence by severity and exposure: does-not-conform items get an interim mitigation now (for example, mandatory second review of every report until the fix lands) plus the durable fix on a date.\n14. Fold in prior-cycle actions still open. Re-dating requires a written reason; chronic slippage is itself a finding about the QAIP and belongs in the results report.\n15. Set the tracking cadence: owner updates monthly; audit-committee status quarterly until every action driven by a PC or DNC rating closes.\n\n**Record in AssureSwarm**\n**Step document** — attach the supervision-testing matrix and the themed exceptions log (with counts per theme); the per-standard ratings matrix (evidence examined, expected conformance, actual finding, rating) as an XLSX; and the interview and survey summaries, all as documents on this step. Test-coverage counts live in the matrix, and Audit has no per-standard rating field, so the matrices stay documents.\n- **Item relationship** — link each tested engagement Audit item to the anchor QAIP-cycle Audit item.\n- **Item create + relationship** — create one Issue per below-GC rating (`issue_type: finding` or `observation`, `severity`, `source: self_assessment`, `identified_date`), each linked to the anchor Audit item.\n- **Item field update** — record the drafted overall conclusion on `Audit.rating` (GC → satisfactory, PC → needs_improvement, DNC → unsatisfactory — a lossy roll-up; the precise per-standard ratings stay in the matrix document).\n- **Workflow instance** — record the KPI spot-reconciliation results as a comment on the anchor Audit item, with a link to the QAIP KPI dashboard.\n\n**Item field update** — on each finding Issue set `root_cause`, `remediation_plan` (the action, its accountable owner, and the pre-defined closure evidence, plus any interim mitigation), `issue_owner`, and `target_remediation_date`; there is no standalone Action type, so the action-plan governance set lives in the Issue fields, and `target_remediation_date` is the filterable due-date index that feeds the watchlist.\n- **Item relationship** — link the interim mitigations noted on each Issue to the engagement Audit items or methodology they protect.\n- **Workflow instance** — record the reporting cadence on the anchor Audit item as a comment.\n\n**Exit criteria**\nEvery sampled engagement has a completed, dated supervision test with exceptions logged and themed; KPI spot-reconciliation documented and survey coverage assessed; every in-scope standard rated with evidence references; below-GC ratings exist as linked finding items; interview corroboration documented; the overall conclusion is drafted.\n\nEvery below-GC finding carries at least one action with an owner, a date, and pre-defined closure evidence; interim mitigations live for DNC items; cadence recorded.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-scan` — sweeps the sampled engagement workflows for approval sign-offs, dates, and missing steps, producing the supervision-evidence matrix mechanically.","label":"Run internal assessment","performedBy":{"primitives":["coach-workflow-scan","coach-document-upload"]}},"id":"run-internal-assessment"},{"data":{"description":"Complete Support external assessment","formData":{"fields":[{"key":"assessment_form_offered","label":"Form of assessment you would perform","options":[{"label":"Full external assessment","value":"full_external"},{"label":"Self-assessment with independent validation","value":"self_assessment_with_validation"}],"required":false,"type":"select"},{"key":"independence_declaration","label":"Every relationship you or your firm has had with the organization in the last three years, including any financial-statement audit, consulting, or staffing role","required":false,"type":"textarea"},{"key":"reciprocal_arrangement","label":"Reciprocal peer-assessment arrangement with this organization","options":[{"label":"None","value":"none"},{"label":"Round-robin of three or more organizations","value":"round_robin"},{"label":"Two-way peer arrangement","value":"two_way_peer"}],"required":false,"type":"select"},{"key":"eqa_experience","label":"External quality assessments led in the last five years — how many, what sectors, what function sizes","required":false,"type":"textarea"},{"key":"certifications_and_training","label":"Relevant certifications (e.g. CIA), quality-assessment training, and how you maintain currency with the Global Internal Audit Standards","required":false,"type":"textarea"},{"key":"references","label":"References from comparable organizations, with contact details","required":false,"type":"textarea"},{"key":"conflicts_or_limitations","label":"Any conflict, limitation, or condition that would affect the engagement","required":false,"type":"textarea"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Run the function's side of the Standard 8.4 external quality assessment — form selection, assessor vetting, evidence readiness, fieldwork logistics, and factual-accuracy review — so the EQA lands inside the five-year deadline and on evidence rather than improvisation.\n\n**Inputs**\n- The prior EQA report and its date (the five-year clock) — a document on the prior cycle's archived Audit item, re-attached here; board input on scope and assessor. Note the dual role: the prior EQA report is an INPUT here, and in an EQA year the final EQA report this step receives is itself a cycle OUTPUT.\n- Current self-assessment results and QAIP records.\n- Budget and procurement constraints.\n\n**Procedure**\n1. Choose the form with the board: a full external assessment (an independent team performs everything) or a self-assessment with independent validation (SAIV — the function self-assesses and a qualified external validator tests and opines on that work; materially cheaper and common for smaller functions, but the validator must meet the same independence bar).\n2. Vet the assessor on two axes and document both — send this step’s form only for missing declarations to candidate providers who execute none of this workflow’s checkpoints, supplying the known firm and lead in the request context. Independence: from outside the organization; no reciprocal two-way peer arrangement (round-robins of three or more organizations are acceptable); weigh the conflict carefully if the candidate is the organization's financial-statement auditor. Competence: demonstrated EQA experience, current knowledge of the Global Internal Audit Standards, relevant certification such as the CIA, quality-assessment training, and references from comparable organizations. Standard 8.4 expects the board to discuss scope, frequency, and assessor qualifications and independence — get that discussion minuted.\n3. Assemble the advance-request package from QAIP records: charter, risk-based plan with approvals, methodology manual, self-assessment ratings and improvement plan, KPI dashboards, sampled engagement files, and the prior EQA report with closure evidence. Every gap found while assembling is a cheap pre-EQA fix; the same gap found by the assessor is a finding.\n4. Schedule interviews (audit-committee chair, CEO or CFO, principal auditees, CAE, engagement staff) and the fieldwork window; brief interviewees to be candid — scripted interviews are transparent to experienced assessors and taint the result.\n5. Review the draft report for factual accuracy only: challenge errors with evidence; do not negotiate ratings. Draft management responses with owners and dates for every recommendation.\n6. In a non-EQA year this step still executes, thin: verify the clock position in months, record readiness status and the planned EQA window, and skip procurement — explicitly, so the step shows a decision rather than a blank.\n\n**Record in AssureSwarm**\n- The form on this step, answered by each candidate external quality assessor, uses the firm and named lead from the identified assignment and captures the form of assessment offered, the three-year relationship and independence declaration, any reciprocal peer arrangement, EQA experience, certifications and Standards currency, references, and any conflict or limitation; the selection judgment and the board discussion go in the step result.\n- **Step document** — attach the assessor-selection documentation and board-minute reference, the advance-package index, the draft and final EQA reports, and management responses as documents on this step.\n- **Item create + relationship** — create one Issue per EQA recommendation (`issue_type: finding` or `observation`, `source: external_audit`), each linked to the anchor Audit item.\n- **Item field update** — in an EQA year set `Audit.report_date` on the anchor to the EQA completion date; Audit has no five-year-clock field, so the next-EQA-due date is recorded in this step's document and the anchor `description`.\n\n**Exit criteria** — EQA year: final report received, every recommendation has an owned and dated response, clock reset. Non-EQA year: clock position and readiness status recorded, with the planned window visible to the board.\n\n**Form recipient** — Candidate external quality-assessment providers not assigned any checkpoint in this internal QAIP workflow. Check the complete preparation, execution, review and approval roster first: anyone assigned a role anywhere in this workflow contributes through native results, documents and approvals instead. Read current evidence and declarations before requesting anything. Select only unresolved questions for the identified scope and period; known facts remain linked context, and no request is needed if nothing is missing. The catalog fields are optional so known or unasked facts need not be repeated; every question actually required by the assignment must have an attributable response or a recorded unresolved gap before the dependent judgment. A negative or declined affirmation remains visible; it must never be converted to a positive statement. This workflow runs the internal function’s procurement and support. Candidate providers supply declarations; the selected assessor performs a separate EQA engagement. Anyone assigned as an executor here uses native evidence/results instead of this form.","label":"Support external assessment"},"id":"support-external-assessment"},{"data":{"decisionField":"disposition_path","description":"Review the proposed conformance communication and classify supported results as clear, gaps requiring action or bounded monitoring.","formData":{"fields":[{"key":"disposition_path","label":"Classify disposition","options":[{"label":"Complete","value":"complete"},{"label":"Gaps require action","value":"gaps"},{"label":"Monitor without immediate action","value":"monitor"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Review the proposed conformance communication and classify supported results as clear, gaps requiring action or bounded monitoring.\n\n**Inputs**\nRatings matrix, overall conclusion, and finding items; the improvement plan with status.\n- KPI dashboard actuals versus targets; the EQA report and responses if this cycle carried one.\n- The prior results report, for trend.\n\n**Decision criteria**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive with QA lead input owns the stated judgments and authorizations.*\n\n*Report QAIP results.* Prepare the cycle’s results for senior management and the board with enough candor to support or withhold the conformance statement. Release the exact approved communication at the final handoff; this preparation does not authorize issuance.\n\n1. Respect the required cadence: internal-assessment results at least annually; EQA results on completion; performance measures per the framework calendar. Board oversight of quality (Standard 8.3) only works if reporting actually reaches the board, not just management.\n2. Build the content in this order: overall conclusion with per-domain ratings and trend versus prior cycle; the evidence basis (sample sizes, survey response rates) so the audience can weigh it; improvement-plan status with chronic slippage named; KPI actuals versus targets, explaining only real variances; EQA results and responses when applicable.\n3. Apply the conformance-statement rule strictly: the function may state that it conforms with the Global Internal Audit Standards only when QAIP results support it — and internal assessments alone cannot carry that statement past an overdue five-year EQA deadline.\n4. Disclose nonconformance that affects the function's overall scope or operation to senior management and the board — including an EQA that did not happen on time. Softening this disclosure is an ethics failure, not a communication choice.\n5. Prepare the CAE and audit-committee chair pre-brief on any PC or DNC message before the meeting; stage it for authorized release after approval; committee surprises destroy more credibility than the ratings themselves.\n\n*Classify disposition.* Classify what the cycle found so only the relevant closure path survives. Owner: CAE, with QA-lead input.\n\n\n\n`complete` (Complete) — every in-scope standard rated generally conforms; KPI actuals at or above target, or variances explained and accepted; no new improvement actions beyond routine refinements; prior-cycle actions closed with verification evidence. Proceed directly to the final package.\n- `gaps` (Gaps require action) — one or more partially-conforms or does-not-conform ratings; systemic engagement-quality defects (supervision sign-off failures or evidence-standard misses recurring across engagements); an overdue EQA or unaddressed EQA recommendations; KPI misses that trace to capability rather than noise. Route to action planning.\n- `monitor` (Monitor without immediate action) — observations are real but isolated, change no rating, and are either already covered by in-flight actions or fall below the cost-benefit line for new ones; or the CAE proposes to accept a bounded risk temporarily (for example, a weak survey response rate pending next cycle's redesign). Route to the escalate-or-accept-risk step — this path documents the acceptance; it never just parks the observation.\n\n**Record in AssureSwarm**\n**Step document** — attach the proposed QAIP results memo or deck (PDF/DOCX), clearly marked draft; attach the issued version and dispatch evidence at the approved handoff.\n- **Item field update** — stage the proposed audience and exact conformance wording in the draft memo. Set `Audit.report_date` to the actual delivery date only when the approved results are issued at handoff.\n- **Item relationship** — link this step's report to the finding Issue items whose improvement actions it commits to.\n\n**Step form**: submit `disposition_path` on this step's form; the step result cites the specific ratings-matrix lines and KPI variances that drive the classification, and the step's approver record records the decision owner.\n\n**Exit criteria**\nResults and any nonconformance disclosure are staged for approval and delivery within cadence; proposed wording matches the evidence and EQA clock.\n\nForm submitted with an evidence-referenced rationale; unused branches prunable.","kind":"decision","label":"Classify disposition"},"id":"classify-disposition"},{"data":{"description":"Create an owned action plan for gaps","instructions":"**Objective** — Turn the gaps classified at disposition into a formally owned action plan the audit committee can track to verified closure.\n\n**Inputs**\n- The disposition rationale and the finding items behind it.\n- The existing improvement plan from the assessment phase, to avoid duplication.\n- Resource constraints and the methodology-release calendar.\n\n**Procedure**\n1. Reconcile against the improvement plan first: gaps already carrying actions get linked, not rewritten; net-new gaps (typically surfaced by external-assessment support or EQA recommendations) get new actions.\n2. Build each action with the full governance set: root cause, one accountable owner, a due date proportionate to severity (a does-not-conform driver gets an interim mitigation inside 90 days), validation evidence defined up front, and the interim mitigation itself where current engagements are exposed — for example, second review of every report touching the affected methodology until the fix lands.\n3. Guard the conformance statement while gaps are open: state explicitly how the function will describe itself in reports and to external parties until the DNC-driving items close.\n4. Set the cadence: owner updates monthly; audit-committee status quarterly until closure. Closure requires the pre-defined validation evidence, reviewed by someone other than the action owner.\n5. Load everything into tracking with watchlist dates — an action plan that lives only in a memo is already stale.\n\n**Record in AssureSwarm**\n- **Item create / field update** — for net-new gaps create an Issue (`issue_type: finding`/`observation`, `source: self_assessment` or `external_audit`); on every gap's Issue set `root_cause`, `remediation_plan` (action + owner + validation evidence + interim mitigation), `issue_owner`, and `target_remediation_date`. Gaps already carrying an action from the improvement plan are linked, not rewritten. No standalone Action type — the governance set lives in Issue fields; `target_remediation_date` feeds the watchlist.\n- **Item relationship** — link each Issue to the anchor Audit item, and link interim mitigations to the engagement Audit items or methodology they protect.\n\n**Exit criteria** — Every disposition gap maps to a linked action with owner, date, and closure evidence defined; interim mitigations live where needed; cadence recorded.","label":"Create action plan"},"id":"create-action-plan"},{"data":{"description":"Escalate to engagement lead, CAE delegate, or audit committee delegate or document risk acceptance","instructions":"**Objective** — Close the monitor path with a real decision: escalate the observation or accept the risk explicitly — time-bound and owned, never silently parked.\n\n**Inputs**\n- The disposition rationale and the observations behind it.\n- Affected ratings and KPI lines; related in-flight actions.\n- The function's exposure to external reliance (regulators, external auditor).\n\n**Procedure**\n1. Draft the decision memo: the observation, the standards and KPIs it touches, why no immediate action (cost-benefit, in-flight coverage, timing), and the impact if it persists — the rating it would degrade at the next cycle, EQA exposure, and consequences where external parties rely on internal audit's work.\n2. Quantify where possible: \"supervision exceptions at the current rate would push the supervision standard to partially conforms next cycle\" is decidable; \"minor process observations\" is not.\n3. Route by authority: matters touching board oversight — EQA timing, the conformance statement — require audit-committee chair concurrence, not just CAE sign-off; function-internal items the CAE may accept alone. Record which rule applied.\n4. Time-bound every acceptance with an expiry date or re-evaluation trigger; an open-ended acceptance is a policy change wearing a memo.\n5. Name the follow-up owner who re-checks at expiry and the evidence they will look at.\n\n**Record in AssureSwarm**\n- **Item create** — record a risk acceptance as an Issue with `issue_type: policy_exception`, `exception_approver` (the CAE or, for board-oversight matters, the audit-committee chair), and `exception_expiry_date` (the time-bound expiry / re-evaluation trigger — the filterable acceptance index); attach the decision memo as a document on this step.\n- **Item relationship** — link the acceptance Issue to the affected finding Issue items; where an underlying Risk item exists, set `Risk.treatment: accept` on it.\n- **Workflow instance** — name the follow-up owner and the expiry re-check in a comment on the anchor Audit item.\n\n**Exit criteria** — Memo approved at the correct authority level; expiry and follow-up owner set; linkage to affected ratings recorded.","label":"Escalate or accept risk"},"id":"escalate-or-accept-risk"},{"data":{"description":"Complete Update methodology and training backlog","instructions":"**Objective** — Institutionalize the cycle's lessons: methodology text, templates, and the training backlog change so the same findings do not recur next cycle.\n\n**Inputs**\n- Improvement and action plans; ratings-matrix observations.\n- The audit manual at its current version, with its change log.\n- The training plan, CPE records, and competency framework.\n\n**Procedure**\n1. Split lessons into manual changes versus behavior changes: manual changes get drafted edits (section, old text, new text, reason traced to a finding); behavior changes get training items. A finding that produces neither is either accepted risk or not really a finding.\n2. Version the manual properly: change-log entry, effective date, communication to all staff, and a transition rule for in-flight engagements stating which version applies to them.\n3. Build training items with specificity: audience, competency addressed, format, target quarter — and tie them into CPE planning so they actually land; certified-staff CPE compliance is itself a QAIP KPI.\n4. Update the templates and checklists named in findings within the same release, not \"later\" — template drift is the most common repeat finding at the next assessment.\n5. Record which findings these changes fully address; everything else stays an open action with its owner and date intact.\n\n**Record in AssureSwarm**\n- **Item field update** — bump the methodology-manual Policy item: set `version`, `effective_date`, and `next_review_date`, and attach the updated manual and its change log as the governed document on that Policy item.\n- **Step document** — capture the training-backlog items (audience, competency, format, target quarter) as a document on this step; there is no Training/Task item type.\n- **Item relationship** — link each methodology change to its source finding Issue item, and mark the findings these changes fully address.\n\n**Exit criteria** — Manual changes versioned with effective dates and communicated; training items scheduled; every change traces to a finding; addressed findings marked.","label":"Update methodology and training backlog"},"id":"update-methodology-and-training-backlog"},{"data":{"decisionField":"approval_path","description":"Approve the exact evidence-traceable package, conclusion and disclosures or specify the defects requiring revision.","formData":{"fields":[{"key":"approval_path","label":"Approve or revise package","options":[{"label":"Approved","value":"approved"},{"label":"Revision required","value":"revise"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Approve the exact evidence-traceable package, conclusion and disclosures or specify the defects requiring revision.\n\n**Inputs**\nRatings matrix and finding items; supervision-testing results.\n- Improvement and action plans; EQA materials if in cycle.\n- All routing submissions with their native-result rationales; the KPI dashboard export.\n\n**Decision criteria**\n*The agent prepares the combined evidence and performs the recordkeeping below. Authorized engagement lead, Chief Audit Executive delegate or audit-committee delegate owns the stated judgments and authorizations.*\n\n*Prepare final package.* Assemble the single reviewable package that carries the cycle's evidence, ratings, decisions, and proposed conclusion into approval.\n\n1. Compile in a fixed order: (1) cycle scope and trigger, (2) sample and coverage basis, (3) supervision-evidence results, (4) per-standard ratings with evidence references, (5) overall conclusion and proposed conformance-statement wording, (6) improvement and action plan, (7) EQA status or results, (8) the decision log — every routing submission with its native-result rationale, (9) open constraints and assumptions.\n2. Spot-check traceability both ways: pick three ratings and walk each to its evidence; pick three evidence documents and confirm a rating references each. Fix breaks before review, not during it.\n3. State unresolved constraints honestly (survey response rate, scope-outs) — reviewers approve a package, not a mood.\n4. Confirm the proposed conclusion sentence matches the ratings arithmetic and the conformance-statement rule; a conclusion more optimistic than its matrix will bounce at approval or, worse, pass.\n5. Freeze the package version that goes to approval; later edits create a new version — never a silent replacement.\n\n*Approve or revise package.* Capture the accountable sign-off on the cycle package: the engagement lead, CAE delegate, or audit-committee delegate decides whether the package stands or returns for rework.\n\n\n\n`approved` (Approved) — every rating is supported by referenced evidence; the conclusion and conformance-statement wording are consistent with the ratings arithmetic and the EQA clock; improvement and action items carry owners, dates, and validation evidence; required disclosures (nonconformance, accepted risks) are present; the package version is frozen. Conditions may accompany approval only where they do not change ratings or conclusions — anything that would is a revision, not a condition.\n- `revise` (Revision required) — any rating without evidence references; a conclusion overstating conformance (for example, claiming the statement with the EQA overdue); actions missing owner, date, or closure evidence; unexplained KPI variances; traceability spot-check failures; a material constraint left undisclosed. Return with a specific defect list — \"tighten this up\" is not a review comment.\n\n**Record in AssureSwarm**\n**Step document** — attach the rendered final package document plus an index of linked items on this step; the frozen package-version identifier is stamped in the document (Audit has no package-version field).\n- **Item relationship** — link every source Issue item (findings, and through them the ratings and actions) to the anchor Audit item; the decision-form submissions are already captured on their steps.\n\n**Step form**: submit `approval_path` on this step's form; the step result lists what was checked (and on revision enumerates the specific defects), and the step's approver record records the approver.\n\n**Exit criteria**\nPackage complete in the fixed order; two-way traceability spot-check passed; version frozen and linked to all sources.\n\nForm submitted; on revision, defects enumerated specifically enough to action; unused branch prunable.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` — compiles the linked evidence, ratings matrix, and decision log into the versioned review package.","kind":"decision","label":"Approve or revise package","performedBy":{"primitives":["coach-render-package","coach-document-upload"]}},"id":"approve-or-revise-package"},{"data":{"description":"Resolve reviewer comments or approval conditions","instructions":"**Objective** — Clear every reviewer comment with evidence and show exactly what changed, so re-approval reviews a delta rather than the whole package again.\n\n**Inputs**\n- The reviewer's defect list from the approval decision.\n- The frozen package version under review and its source items.\n\n**Procedure**\n1. Log each comment with a resolution type: evidence added, rating changed, wording corrected, action plan strengthened, or rebutted-with-evidence. Rebuttals require the reviewer's concurrence, not the author's confidence.\n2. Where a rating changes, cascade the change everywhere it lands: the overall conclusion, the conformance-statement wording, the improvement plan, and the report draft must move together — a rating change that only edits the matrix creates an internally contradictory package.\n3. Re-run the traceability spot-check on every changed section.\n4. Produce the delta note: comment → change → location, attached to the new package version.\n5. Do not reopen closed scope: new issues discovered during revision go to the improvement plan or the next cycle unless they invalidate a rating in this one.\n\n**Record in AssureSwarm**\n- **Step document** — attach the new package version, the comment-resolution log, and the delta note (comment → change → location) on this step, superseding the prior version rather than overwriting it.\n- **Item relationship** — re-link any Issue items whose content (rating, action, owner) changed to the anchor Audit item.\n\n**Exit criteria** — Every comment resolved or explicitly rebutted with reviewer concurrence; the original independent approver has approved the exact revised package before handoff; delta note complete and new version supersedes the old.","label":"Resolve approval conditions"},"id":"resolve-approval-conditions"},{"data":{"description":"Release only the approved results, resolve freshness and reliance boundaries with the recipient, and confirm receipt before retaining the cycle record.","instructions":"**Objective** — Release only the approved results, resolve freshness and reliance boundaries with the recipient, and confirm receipt before retaining the cycle record.\n\n**Inputs**\nThe approval-decision form submission and any condition list.\n- The final package version identifier.\n- Board or audit-committee minutes where the results were acknowledged.\n\nThe approved final package and the exact results memo authorized for issuance.\n- Improvement and action plan status as of the handoff date.\n- The EQA clock position and any accepted-risk expiries.\n\nThe approved, locked package and the handoff confirmation.\n- The open action, condition, and accepted-risk lists.\n- The workpaper retention policy.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive and receiving board-reporting owner owns the stated judgments and authorizations.*\n\n*Record approval decision.* Make the approval durable: who approved which package version, when, under what conditions, and who owns the follow-through.\n\n1. Record the approver's name and role, the decision date, and the exact package version approved — a version identifier, never \"latest\".\n2. Enumerate conditions with owners and due dates; a condition without an owner is a wish, and it will surface unmet at the next EQA.\n3. Where board-level acknowledgment applies — EQA results, the conformance statement — record the meeting and minute reference alongside the approval.\n4. Wire follow-up into existing tracking: conditions join the action-plan cadence; record the next cycle's start trigger (periodic self-assessment within 12 months; the EQA clock date).\n5. Lock the approved package against edits; subsequent changes belong to the next cycle or a formally versioned amendment.\n\n*Handoff to related workflow.* Hand the approved results to Quarterly Board & Audit-Committee GRC Reporting so board reporting reuses this cycle's conclusions instead of reconstructing them.\n\n6. Verify the exact results memo and conformance wording have final approval, including original-reviewer approval of any revised version. Release the results and required nonconformance disclosures to senior management and the board under the recorded sending authority, with dispatch evidence and actual delivery date on Audit.report_date. Complete the authorized CAE/chair pre-brief before the board meeting. Create or link the downstream Quarterly Board & Audit-Committee GRC Reporting workflow for the relevant quarter.\n7. Pass a defined handoff package: the overall conclusion with per-domain ratings, the approved conformance-statement wording, improvement-plan status summary, EQA status and date, the KPI dashboard reference, and a link to the locked package.\n8. State assumptions and freshness explicitly: the as-of date of the ratings and which actions were open at handoff — so the board deck cannot silently present stale status as current.\n9. Draw the do-not-repeat boundary: downstream formats and contextualizes; it does not re-rate, re-open findings, or re-litigate the conformance statement. Changes it wants come back through this workflow's approval path.\n10. Confirm receipt by the downstream owner before closing; an unacknowledged handoff is not a handoff.\n\n*Close and archive.* Close the cycle with a complete, immutable audit trail and the next cycle already scheduled — the QAIP is a standing program, not an annual event.\n\n11. Verify completeness before archiving: every step holds its records, every decision form is submitted, approval is recorded against a version, and the handoff is receipted. An archive with holes is a finding waiting for the next external assessor.\n12. Archive the final package and evidence index under the retention policy — align with workpaper retention (typically five years or more), because the next EQA will sample this cycle's records.\n13. Keep open items alive outside the archive: improvement actions, accepted-risk expiries, and approval conditions stay on active watchlists with owners. Closing the cycle never closes its actions.\n14. Schedule the next triggers now: the next periodic self-assessment within 12 months; and the EQA countdown (months remaining to the five-year deadline).\n15. Communicate closure to participants and the audit-committee secretary: the one-line conclusion, where the record lives, and what remains open.\n\n**Record in AssureSwarm**\n**Step document and native approval reference** — link the actual approval from Approve or revise package and any reapproval of the corrected version. Record the approving identity, role, actual decision date, exact package identifier and owned conditions in the retained approval record/document. The existing `approval_path` selector belongs to its original decision node; do not create or fill an approval form on this handoff step. Record the receiving owner’s own acceptance through native approval.\n- **Item field update** — capture the board-minute reference in a comment on the anchor Audit item; condition due dates ride on the condition-owner Issues' `target_remediation_date`.\n- **Step document** — mark the package document final and locked.\n\n**Handoff package** — attach the defined handoff package (overall conclusion + per-domain ratings, approved conformance-statement wording, improvement-plan status, EQA status/date, KPI-dashboard reference, and a link to the locked package) as a document on this step, for Quarterly Board & Audit-Committee GRC Reporting's first step to consume.\n- **Workflow instance** — link the downstream workflow instance to this run.\n- **Workflow instance** — record the recipient and receipt date, and keep handoff questions, in this step's comment thread (no native recipient/receipt field).\n\n**Item field update / workflow instance** — set the anchor Audit item to closed status and archive/lock this workflow run and its documents; the closure date is recorded in the closure comment (no native closure-date field beyond `report_date`).\n- **Item field update** — keep open Issue items live outside the archive on their `target_remediation_date` and, for accepted risks, `exception_expiry_date`, each with an owner; do not close the Issues when the cycle closes.\n- **Workflow instance** — post the closure comment on the anchor Audit item with the one-line conclusion and the record location, and note the next self-assessment (within 12 months) and EQA-clock triggers.\n\n**Exit criteria**\nApproval recorded against a specific version; conditions owned and dated; board reference captured where applicable; package locked.\n\nDownstream workflow linked; package passed with its as-of date; do-not-repeat boundaries stated; receipt confirmed by the downstream owner.\n\nRecord complete and locked; retention applied; open items on active watchlists with owners; next self-assessment and EQA triggers scheduled.","label":"Handoff to related workflow"},"id":"handoff-to-related-workflow"}],"sourceTemplateId":"workflow-library:audit-qaip-cycle"}
