{"description":"Runs on an Audit item created for this assessment cycle (audit_type = readiness) — the CSF assessment engagement the workflow instance attaches to and enriches as it progresses (scope, period, rating, and report fields are written on that Audit item; every in-scope Control is linked to it so the controls-scoped profile is queryable). Build, against that boundary, a NIST CSF 2.0 Current Profile, a Target Profile, an organizational Tier rating, a subcategory gap analysis, and a CISO-ready remediation roadmap. The workflow originates on its own — scoping ingests prior CSF profiles and open POA&M (Issue) items as data, not as a named upstream handoff. In scope: rating the in-scope control set against the CSF 2.0 Core, setting target outcomes, assigning a Tier, and producing a prioritized roadmap. Out of scope: executing the remediation projects themselves and re-performing independent assurance testing. The named deliverable is the assessment package (profiles, gap analysis, Tier, posture report, roadmap, closure artifact), handed off to TWO downstream workflows that consume it rather than repeat the profiling: the Cybersecurity Assurance Review (always) and the AI Governance & Risk/Impact Assessment (only when AI systems fall inside the boundary).","edges":[{"id":"e-define-target-profile-classify-disposition","source":"define-target-profile","target":"classify-disposition"},{"id":"e-classify-disposition-create-action-plan","label":"Action","source":"classify-disposition","target":"create-action-plan","whenValue":"gaps"},{"id":"e-classify-disposition-handoff-to-related-workflow","label":"Clear","source":"classify-disposition","target":"handoff-to-related-workflow","whenValue":"complete"},{"id":"e-classify-disposition-escalate-or-accept-risk","label":"Escalate","source":"classify-disposition","target":"escalate-or-accept-risk","whenValue":"monitor"},{"id":"e-create-action-plan-handoff-to-related-workflow","source":"create-action-plan","target":"handoff-to-related-workflow"},{"id":"e-escalate-or-accept-risk-handoff-to-related-workflow","source":"escalate-or-accept-risk","target":"handoff-to-related-workflow"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-AUDIT-22","UC-RISK-13","UC-RISK-14","UC-GOV-02","UC-GOV-04","UC-GOV-06","UC-GOV-09","UC-GOV-10","UC-GOV-11","UC-GOV-12","UC-TPRM-01","UC-RISK-15"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-csf-profile-maturity-assessment","contentDigest":"sha256:27c45a606d72b2ab411434c5a4c54d39fbe813777b3075321f79ec72cf5de5a8","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:27c45a606d72b2ab411434c5a4c54d39fbe813777b3075321f79ec72cf5de5a8","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-csf-profile-maturity-assessment"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"controls-csf-profile-maturity-assessment","source":"coworkcanvas-gallery","standards":["nist-csf-2"],"teams":["it","executive"]},"name":"CSF 2.0 Profile & Maturity Assessment","nodes":[{"data":{"description":"Set the assessment boundary, fixed scale and desired CSF outcomes from obligations, risk appetite and business criticality before current-state conclusions influence the targets.","instructions":"**Objective** — Set the assessment boundary, fixed scale and desired CSF outcomes from obligations, risk appetite and business criticality before current-state conclusions influence the targets.\n\n**Inputs**\n- The anchor Audit item created for this cycle (audit_type = readiness): the authorization/system boundary (organization, mission, system, or business unit being profiled) is captured in `Audit.scope`, its criticality context in `Audit.description`. The in-scope systems/business units are the Process items linked to it (Audit ↔ Process).\n- The applicable control baseline / unified control set — the existing Control items whose `framework` includes `nist-csf-2` (`control_owner` names the evidence owner per area); these are linked Audit ↔ Control at this step.\n- Any prior CSF profile, assessment, or POA&M on record — the prior cycle's archived Audit item (with its attached profile documents) and its open Issue items (`source: self_assessment`). This workflow originates on its own: these enter as data, not as a named upstream handoff.\n- The assessment objective (board-requested posture baseline, pre-certification readiness, post-incident re-baseline) recorded in `Audit.description`, and the triggering risk linked as Audit ↔ Risk (an existing Risk register item).\n- The NIST CSF 2.0 Core (Functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER) and the fixed maturity scale — carried in the locked workplan document on this step, since neither has a native field.\n- The locked workplan and in-scope Subcategory list from the Scope assessment step. This step depends only on scope, not on the Current Profile — target maturity is set from where the organization needs to be, so it is developed in parallel with the current rating.\n- The organizational risk register — existing Risk items (`residual_rating`, `treatment`, `risk_owner`) linked to the anchor Audit. Risk appetite / tolerance statements and board or executive priorities have no native Policy/Obligation type, so they enter as uploads (PBC/external) on this step.\n- Binding external drivers: regulatory obligations, contractual security commitments, sector threat profile, and any framework the organization must map to (e.g. ISO 27001, NIST 800-53, SOC 2). Framework mappings live on `Control.framework` of the linked Control items; the obligation/commitment source documents enter as uploads on this step (no native Obligation type). These drivers shape targets but are not governing standards of this workflow, which is scoped to nist-csf-2.\n\n**Procedure**\n_This checkpoint absorbs “Scope assessment”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Scope assessment: Confirm the boundary explicitly: name what is inside (systems, business units, third parties in scope) and what is deliberately excluded, so downstream ratings are unambiguous. Record the boundary statement and its owner.\n2. Select the CSF 2.0 outcomes in scope. Default to all six Functions; where a Function is not applicable, record the concrete reason (e.g. no in-house recovery obligation) rather than silently dropping it. Enumerate the Categories and Subcategories that will be rated.\n3. Map each in-scope Subcategory to the organization's unified controls / control baseline and to the specific evidence sources (policy, ticketing, config exports, prior audit workpapers) that will support a rating. Flag any Subcategory with no identified evidence owner as an early risk.\n4. Assign an accountable owner and a due date to every evidence pull, and set review expectations (who signs off the Current Profile, the Target Profile, the Tier, and the roadmap).\n5. Lock the workplan: freeze the in-scope Subcategory list, owners, due dates, evidence requirements, and the maturity scale to be used, so that rating work does not renegotiate scope mid-stream. Capture any open constraints (access gaps, data readiness).\n6. Define Target Profile: For each in-scope Subcategory, set a target level on the same fixed maturity scale used for the Current Profile, so the two profiles are directly comparable.\n7. Justify each target from a driver: cite the obligation, risk-appetite statement, or threat rationale that makes that level (not higher, not lower) the right aim. Over-targeting every Subcategory to the maximum is a red flag — reserve top maturity for outcomes tied to the highest-impact risks.\n8. Differentiate targets by criticality: crown-jewel systems and GOVERN/IDENTIFY outcomes that underpin the whole program typically warrant higher targets than peripheral ones.\n9. Capture target dependencies and sequencing constraints (e.g. an identity outcome that must reach target before a detection outcome can be credibly raised).\n10. Confirm the Target Profile with the accountable owner named at scoping; unresolved disagreements are logged as open decisions, not silently averaged.\n\n**Record in AssureSwarm**\nAttach the locked workplan (XLSX) as a step document on this step (it carries the in-scope Subcategory list, maturity scale, owners, due dates, and open constraints — none of which have native fields). Write the anchor Audit item: `Audit.scope` = boundary statement, `Audit.description` = objective/criticality, `Audit.period_start`/`Audit.period_end` = assessment window, `Audit.fieldwork_start` = rating start. Link each in-scope Control (Audit ↔ Control), each in-scope system/business unit (Audit ↔ Process), and the triggering risk (Audit ↔ Risk).\nAttach the Target Profile (XLSX: per-Subcategory target level, driver rationale, sequencing dependencies, and owner sign-off) as a step document on this step — same no-per-Subcategory-type constraint as the Current Profile. Link the source Risk register items to the anchor (Audit ↔ Risk) as driver references; upload the obligation/risk-appetite source documents (PBC/external) to this step, as they have no native item home.\n\n**Exit criteria**\n- Boundary statement and in/out-of-scope list documented; in-scope Subcategories enumerated and mapped to controls and evidence owners; workplan locked with owners, due dates, and the maturity scale fixed; open constraints recorded.\n- Every in-scope Subcategory has a target level on the fixed scale with a cited driver; targets are differentiated by criticality rather than uniformly maxed; dependencies captured; owner has confirmed the Target Profile.","label":"Define Target Profile"},"id":"define-target-profile"},{"data":{"decisionField":"disposition_path","description":"Judge evidence-backed Current Profile ratings, reconcile the two Tier dimensions and current-to-target gaps, and choose whether the risk-ranked roadmap needs action or formal acceptance.","formData":{"fields":[{"key":"disposition_path","label":"Classify disposition","options":[{"label":"Complete","value":"complete"},{"label":"Gaps require action","value":"gaps"},{"label":"Monitor without immediate action","value":"monitor"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge evidence-backed Current Profile ratings, reconcile the two Tier dimensions and current-to-target gaps, and choose whether the risk-ranked roadmap needs action or formal acceptance.\n\n**Inputs**\n- The locked workplan and in-scope Subcategory list from the Scope assessment step (which controls, which evidence sources, which owners).\n- The maturity scale fixed at scoping (e.g. a 0-4 or Not Implemented / Partial / Largely / Fully scale, or CMMI-style 1-5) applied consistently across Subcategories.\n- Actual evidence: policies, standards, configuration exports, ticket samples, monitoring output, prior audit/assessment results, and interviews.\n- The completed Current Profile scores (from Rate Current Profile) and the completed Target Profile levels (from Define Target Profile). This step is a join: it cannot start until both profiles exist, because a gap is the delta between them.\n- The fixed maturity scale and the CSF 2.0 Tier definitions (Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable, Tier 4 Adaptive) across the Cybersecurity Risk Governance and Cybersecurity Risk Management dimensions.\n- The gap table and assigned Tier from the Gap-analyze and assign Tier step (per-Subcategory gaps, residual-risk notes, Tier rationale).\n- The Current and Target Profiles (for the posture heatmap) and the risk register / obligation deadlines that drive urgency.\n- Cost, effort, and dependency information for candidate remediations (from owners named at scoping).\n\n**Procedure**\n_This checkpoint absorbs “Rate Current Profile”, “Gap-analyze and assign Tier”, “Report posture and roadmap”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Rate Current Profile: For each in-scope Subcategory, gather the mapped evidence and confirm it actually addresses that outcome — do not credit a policy that is not operationalized. Where evidence is missing, score conservatively and flag the evidence gap.\n2. Score each Subcategory on the fixed scale, capturing both design (is a control defined) and operating state (is it performed consistently). Record a one-line determination statement per Subcategory citing the evidence reference.\n3. Distinguish partial implementations: note which parts of a Subcategory are met and which are not, so the later gap analysis is precise rather than binary.\n4. Roll Subcategory scores up to Category and Function summaries (e.g. average or weakest-link, per the scale convention chosen at scoping) to give a readable posture heatmap.\n5. Record cross-cutting observations (systemic weaknesses, single points of failure, strong practices worth preserving) that the roadmap should reflect.\n6. Gap-analyze and assign Tier: For each in-scope Subcategory, subtract current from target to get the gap magnitude and direction. A zero or negative gap (already at or above target) is recorded as met; positive gaps are the remediation candidates.\n7. Classify each gap by size and by the risk it leaves open, so later prioritization has both effort and exposure signals. Note Subcategories where the gap is driven by design absence versus by inconsistent operation — these remediate differently.\n8. Assess the organization against the Tier characteristics, focusing on the GOVERN and IDENTIFY outcomes that describe how risk decisions are made, resourced, and integrated. Assign a Tier to the Cybersecurity Risk Governance dimension and to the Cybersecurity Risk Management dimension; if they diverge, record both rather than forcing one number.\n9. Write the Tier rationale: cite the specific evidence and Subcategory patterns (e.g. ad hoc risk decisions and no program-level metrics => Tier 1-2) that justify the assignment. The Tier is an aspirational management characterization, not a score average — state it as such.\n10. Sanity-check: the assigned Tier should be consistent with the Current Profile heatmap. A Tier 4 claim over a Current Profile full of Partial ratings is a contradiction to resolve before proceeding.\n11. Report posture and roadmap: Prioritize the gaps. Score each remediation candidate on risk reduction (how much residual exposure it removes), effort/cost, dependency (what must precede it), and any hard obligation deadline. Rank into priority bands (e.g. P0 critical, P1 high, P2 planned).\n12. Sequence the ranked gaps into roadmap horizons: near-term (0-90 days, quick wins and highest-risk fixes), mid-term (3-12 months), and strategic (beyond 12 months). Respect the dependency ordering captured in the Target Profile so prerequisites land first.\n13. Assign each roadmap item an owner, an effort/cost estimate, a target completion window, and the specific CSF Subcategory outcome it moves from current toward target, so progress is measurable against the profiles.\n14. Build the posture report: an executive summary of the assigned Tier and overall posture, the Current-vs-Target heatmap by Function, the top gaps and their residual risk, and the sequenced roadmap with owners and horizons. Write it for an executive audience — decisions and trade-offs, not raw Subcategory dumps.\n15. Include a measurement view: how re-rating at the next cycle will show movement, and which few metrics the CISO should track between cycles.\n\n**Decision criteria**\n- **Complete** — Current Profile meets or exceeds Target across in-scope Subcategories, or all gaps are already covered by an accepted existing plan; no new remediation is warranted from this cycle. Proceed straight to packaging.\n- **Gaps require action** — One or more prioritized gaps need a new, owned remediation plan (open POA&M items) before the posture is acceptable. This is the common outcome when the roadmap contains P0/P1 items without existing owners and dates.\n- **Monitor without immediate action** — Gaps exist but are within risk appetite for now, or fixing them is deferred pending a decision/resource — the residual risk must be formally escalated or accepted and monitored rather than remediated this cycle.\n\n**Record in AssureSwarm**\nAttach the Current Profile (XLSX profile table with per-Subcategory score, determination statement, evidence reference, and Function/Category rollups) plus the evidence index as step documents on this step — there is no per-Subcategory item type, so scores live in the document, not as queryable items. Upload the pulled evidence samples (PBC/external) here too. Log each evidence gap in the profile document; where a gap is a real control weakness worth tracking, open it as an Issue (`issue_type: observation`, `source: self_assessment`) linked Issue ↔ anchor Audit.\nAttach the gap analysis (XLSX gap table: per-Subcategory magnitude, type, residual-risk note) and the Tier rationale memo (the Governance-dimension and Management-dimension Tier, 1–4, with cited rationale) as step documents on this step — the full Tier has no native field, so it lives in the memo. Write the coarse rollup to the anchor: `Audit.rating` (satisfactory | needs_improvement | unsatisfactory) as a 3-level proxy for the Tier. Note any Tier/profile inconsistency in the memo for resolution before proceeding.\nAttach the CISO-ready posture report (DOCX/PDF) and the prioritized remediation roadmap (XLSX: per-item priority band, owner, estimate, horizon, and target Subcategory) as step documents on this step. Optionally publish a posture-tracking Dashboard from the profile and roadmap tables for ongoing monitoring between cycles.\nSubmit the `disposition_path` SELECT with the chosen value; record the decision rationale and evidence references in the step result and the approver in the native approval record.\n\n**Exit criteria**\n- Every in-scope Subcategory carries a score on the fixed scale with a cited determination; partial implementations are itemized; Function/Category rollups computed; evidence gaps logged.\n- Every in-scope Subcategory carries a computed gap classified by size and residual risk; a Tier is assigned to each dimension with evidence-cited rationale; Tier is reconciled against the Current Profile with no unresolved contradiction.\n- Every actionable gap is priority-banded and placed in a roadmap horizon with owner, estimate, and target Subcategory; the posture report presents Tier, Function heatmap, top gaps, and roadmap in executive-ready form; the measurement view names the metrics to track.\n- The form is submitted with one disposition selected and a rationale captured; the two unchosen branches are prunable because each branch edge value matches the submitted value.\n\n> **⚡ Audit Artist accelerator:** `/coach-query-data` pulls the evidence samples (tickets, config exports, prior results) that support each Subcategory rating; `/coach-item-update` writes the scores and determinations back to the Current Profile record. `/coach-render-package` assembles the posture report and roadmap into a CISO-ready deliverable; `/coach-dashboard-create` stands up the posture-tracking dashboard from the profile and roadmap tables.","kind":"decision","label":"Classify disposition","performedBy":{"agent":"grc-artist","primitives":["coach-query-data","coach-item-update","coach-render-package","coach-dashboard-create"]}},"id":"classify-disposition"},{"data":{"description":"Create an owned POA&M action plan for the gaps requiring action","instructions":"**Objective** — Convert the prioritized gaps that require action into owned, dated, trackable remediation items (POA&M) ready for the final package.\n\n**Inputs**\n- The prioritized roadmap and gap table from the Report posture and roadmap step (priority bands, target Subcategories, owners, estimates).\n- The disposition rationale from Classify disposition explaining why action is required.\n- Existing POA&M / issue-tracking records so new items link to, and do not duplicate, open remediation.\n\n**Procedure**\n1. For each gap requiring action, write a discrete remediation item: root cause (design absence vs inconsistent operation), the CSF Subcategory outcome it closes, and the current-to-target movement it delivers.\n2. Assign an accountable owner, a due date consistent with the roadmap horizon, and any interim mitigation to hold residual risk down until the fix lands.\n3. Define the validation evidence that will prove the gap closed (what will be re-rated and how) and the reporting cadence to the CISO.\n4. Assign a POA&M identifier to each item and link it to the source gap, the affected control, and any existing issue record, so nothing is orphaned or duplicated.\n5. Confirm every P0/P1 gap from the roadmap has a corresponding action item — no high-priority gap may exit this step without an owner and a date.\n\n**Record in AssureSwarm** — Create one Issue item per action-requiring gap (the studio POA&M convention): `issue_type: deficiency` (or `finding`), `source: self_assessment`, `severity` from the priority band, `root_cause` (design absence vs inconsistent operation), `remediation_plan` (interim mitigation, validation evidence, and reporting cadence), `issue_owner`, `identified_date`, and `target_remediation_date` matching the roadmap horizon. Link each Issue to the affected Control (Issue ↔ Control) and to the anchor Audit (Issue ↔ Audit), and to any existing open issue so nothing duplicates.\n\n**Exit criteria** — Every action-requiring gap has an owned, dated POA&M item with root cause, validation evidence, and a POA&M ID; all P0/P1 gaps are covered; items are linked to source gaps and controls with no duplication.\n\n> **⚡ Audit Artist accelerator:** `/coach-item-create` opens the POA&M items with owners and dates; `/coach-items-link` wires each to its source gap, control, and existing issue record.","label":"Create action plan","performedBy":{"agent":"grc-artist","primitives":["coach-item-create","coach-items-link"]}},"id":"create-action-plan"},{"data":{"description":"Escalate residual risk or document formal risk acceptance for the monitor path","instructions":"**Objective** — For the monitor-without-immediate-action disposition, formally escalate the residual risk or document its acceptance, with conditions and a monitoring trigger.\n\n**Inputs**\n- The gap table, residual-risk notes, and assigned Tier from the Gap-analyze and Report steps.\n- The disposition rationale from Classify disposition explaining why remediation is deferred.\n- The organization's risk-acceptance authority matrix (who may accept risk at what level) and the risk register.\n\n**Procedure**\n1. Quantify the residual risk being carried: which Subcategory outcomes stay below target, the exposure this leaves, and the plausible impact if it materializes.\n2. Prepare the decision memo for the appropriate authority — control owner, assessor lead, system owner, or authorizing official — matched to the severity per the acceptance matrix. Do not let a lower authority accept a risk reserved for a higher one.\n3. State the acceptance conditions and expiry: the time-box, the compensating monitoring, and the specific trigger (metric threshold, incident, obligation change) that re-opens the gap for action.\n4. Define follow-up ownership and the monitoring cadence so the accepted risk is revisited rather than forgotten.\n5. If the authority declines acceptance, route the gap back to remediation by opening an owned action item instead.\n\n**Record in AssureSwarm** — Attach the risk-acceptance / escalation memo (DOCX/PDF: accepting authority, conditions, expiry, monitoring trigger, follow-up owner) as a step document on this step. Record the acceptance on the affected Risk item(s): `treatment: accept`, `residual_rating`, `risk_owner` (create the Risk item if the residual risk is not yet on the register), and link Risk ↔ anchor Audit. The acceptance memo carries the expiry and trigger, which have no native Risk field.\n\n**Exit criteria** — Residual risk is quantified and either formally accepted by the correct authority with conditions, expiry, and a monitoring trigger, or escalated/returned to remediation; follow-up ownership and cadence are recorded.","label":"Escalate or accept risk"},"id":"escalate-or-accept-risk"},{"data":{"description":"Sign off the internally consistent assessment conclusion and accept its handoff boundary, live remediation trackers and re-rating schedule.","instructions":"**Objective** — Sign off the internally consistent assessment conclusion and accept its handoff boundary, live remediation trackers and re-rating schedule.\n\n**Inputs**\n- The Current Profile, Target Profile, gap table, and assigned Tier.\n- The posture report and prioritized roadmap.\n- Whichever closure artifact applies: the POA&M action plan (gaps path), the risk-acceptance/escalation memo (monitor path), or the clean disposition rationale (complete path).\n- The evidence index and any open constraints logged along the way.\n- The signed-off final package from the Prepare final package step (profiles, Tier, gaps, roadmap, closure artifact).\n- The entry points for the downstream workflows: the Cybersecurity Assurance Review workflow (which uses the profile and gaps to scope assurance testing) and the AI Governance & Risk/Impact Assessment workflow (which consumes the governance-related outcomes).\n- Any POA&M items or accepted-risk records that remain open and must stay tracked after closure.\n- The organization's records-retention requirement for assessment artifacts.\n\n**Procedure**\n_This checkpoint absorbs “Prepare final package”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Prepare final package: Assemble the package: profiles, gap analysis, Tier with rationale, posture report, roadmap, and the closure artifact from the disposition branch that executed.\n2. Reconcile internal consistency: the Tier matches the Current Profile, every P0/P1 gap has either an action item or a documented acceptance, and the roadmap owners match the POA&M owners.\n3. Attach the evidence index and note any assumptions and unresolved constraints so a downstream reader knows the package's limits.\n4. Draft the proposed overall conclusion (posture statement, Tier, headline gaps, and the disposition) for owner sign-off.\n5. Verify completeness against the workplan locked at scoping — every in-scope Subcategory is represented and no scoped item was silently dropped.\n6. Handoff to related workflow: Confirm which downstream workflows apply this cycle: the Cybersecurity Assurance Review always; the AI Governance & Risk/Impact Assessment when AI systems fall inside the boundary.\n7. Create or locate the downstream workflow instance and attach the final package as its declared input, so the receiving team starts from the profile and gaps rather than re-scoping.\n8. Write a short handoff note stating the assessment boundary, the assigned Tier, the top gaps, key assumptions, and explicitly what the downstream workflow should NOT repeat (the profiling and Tier rating are done).\n9. Confirm receipt/ownership on the downstream side so the handoff is not left dangling.\n10. Archive the final package, profiles, gap analysis, Tier rationale, report, roadmap, and closure artifacts as a read-only record under the applicable retention period.\n11. Update linked records: mark the workflow complete, ensure open POA&M and accepted-risk items are carried on their own trackers with owners intact, and update the control/risk register with the new posture.\n12. Schedule the follow-up: the next full re-profiling cycle and any interim monitoring checkpoints tied to the roadmap horizons and accepted-risk expiries.\n13. Communicate closure to the CISO and stakeholders with the final posture statement, Tier, and where the roadmap now lives.\n14. Confirm nothing actionable is left only inside this closed workflow — every open item has an external home.\n\n**Record in AssureSwarm**\nAttach the assembled assessment package (PDF/ZIP bundling profiles, gap analysis, Tier memo, posture report, roadmap, and the closure artifact) as a step document on this step; the constituent step documents from prior steps remain linked through the workflow instance. Write the conclusion to the anchor: `Audit.opinion` = na (a maturity assessment issues no assurance opinion), `Audit.report_date` = package date. List assumptions and open constraints in the package document.\nAttach the final assessment package to the entry step of each applicable downstream workflow instance as its declared input — the Cybersecurity Assurance Review (always) and, when AI systems are in the boundary, the AI Governance & Risk/Impact Assessment (each anchored on its own Audit item). Link those instances to this one, attach the handoff note (boundary, Tier, top gaps, non-repeat scope), and record the receiving owner and handoff date on this step. Then mark this workflow instance complete/archived against the anchor Audit item and attach the read-only package export as the retained record; confirm the open POA&M Issue items and any accepted-risk Risk items (`treatment: accept`) stay live on their own trackers outside the closed instance, update the control/risk register with the new posture, and log the next re-rating date and the closure communication on this step.\n\n**Exit criteria**\n- A single package links profiles, gap analysis, Tier, report, roadmap, and the applicable closure artifact; internal consistency is reconciled; assumptions and constraints are stated; the proposed conclusion is ready for sign-off.\n- Each applicable downstream workflow instance is linked with the final package attached as its input; the handoff note names boundary, Tier, top gaps, and non-repeat scope; downstream receipt is confirmed, and that confirmation closes the assessment. Package archived read-only under retention; the instance is marked closed with all open items rehomed on live trackers; next re-rating and monitoring checkpoints scheduled; closure communicated to the CISO.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` compiles the profiles, gap analysis, report, roadmap, and closure artifact into one review-ready package; `/coach-document-upload` files it against the workflow item. `/coach-workflow-attach` links the package into the downstream workflow instance as its declared input, `/coach-notify` alerts the receiving owner with the handoff note and the closure statement, and `/coach-workflow-export` produces the read-only archive of the closed assessment for retention.","label":"Handoff to related workflow","performedBy":{"agent":"grc-artist","primitives":["coach-render-package","coach-document-upload","coach-workflow-attach","coach-notify","coach-workflow-export"]}},"id":"handoff-to-related-workflow"}],"sourceTemplateId":"workflow-library:controls-csf-profile-maturity-assessment"}
