{"description":"Runs one ISO 27001 clause 9.2 internal audit and clause 9.3 management review cycle — including clause 10.1 corrective actions — against the existing Audit item for this cycle (audit_type=internal), whose scope, lead_auditor, and period dates already carry the ISMS audit-programme entry: the workflow enriches that Audit item and its findings, never creates a duplicate audit. Upstream it consumes the Annex A control population (Control items, framework iso-27001) and the applicability decisions in the Statement of Applicability, the risk register (Risk items) and treatment plan, the prior-cycle Audit and open Issue records, and the org's ISMS policies and procedures (Policy items) as audit criteria. Named deliverables: the internal audit findings report, the clause 10.1 corrective-action records (recorded on the finding Issue items), the management review pack, and the approved clause 9.3 minutes and action register. Out of scope: the certification-body external audit and day-to-day control operation. No upstream workflow feeds this cycle and no single downstream workflow consumes its output; at close the cycle is archived on the Audit item as retained ISMS documented information, and carry-forward items re-enter the audit programme (the next PLANNED Audit item), the risk register, or the next review's inputs.","edges":[{"id":"e-prepare-fieldwork-conduct-audit-and-document","source":"prepare-fieldwork","target":"conduct-audit-and-document"},{"id":"e-conduct-audit-and-document-assemble-management-review","label":"Clean audit","source":"conduct-audit-and-document","target":"assemble-management-review","whenValue":"clean"},{"id":"e-conduct-audit-and-document-corrective-actions","label":"Nonconformities","source":"conduct-audit-and-document","target":"corrective-actions","whenValue":"nonconformities_found"},{"id":"e-corrective-actions-assemble-management-review","source":"corrective-actions","target":"assemble-management-review"},{"id":"e-assemble-management-review-hold-review-and-record","source":"assemble-management-review","target":"hold-review-and-record"},{"id":"e-hold-review-and-record-track-actions-to-closure","source":"hold-review-and-record","target":"track-actions-to-closure"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{"UC-AUDIT-17":"operates","UC-AUDIT-22":"operates","UC-AUDIT-23":"operates"},"controls":["UC-AUDIT-23","UC-AUDIT-22","UC-GOV-15","UC-AUDIT-17"],"department":"internal-audit","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-isms-internal-audit-management-review","contentDigest":"sha256:742d77471fcfb9e129cd8c2c7bf4a77d76efc0dc9e0982900aaa8c182a577076","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:742d77471fcfb9e129cd8c2c7bf4a77d76efc0dc9e0982900aaa8c182a577076","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-isms-internal-audit-management-review"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"controls-isms-internal-audit-management-review","source":"coworkcanvas-gallery","standards":["iso-27001"],"teams":["internal-audit","it","executive"]},"name":"ISMS Internal Audit & Management Review","nodes":[{"data":{"description":"Agent drafts the clause 9.2 audit plan and the fieldwork evidence and working-paper package; the lead auditor approves scope, criteria, independence, and readiness","instructions":"**Objective** — Produce an approved clause 9.2 audit plan and a fieldwork-ready evidence and working-paper package so the audit can begin with agreed scope, criteria, independence, and coverage.\n\n**Inputs**\n- This cycle's entry in the ISMS audit programme — the anchor Audit item (audit_type=internal, status PLANNED) carrying `scope` (the clause 9.2 area), `period_start`/`period_end`, and `lead_auditor`. The programme entry IS this Audit item and is the workflow's trigger; no upstream workflow feeds it, and the audit already exists — enrich it, do not create a duplicate.\n- The ISMS scope statement (a step upload — no native item type) and the Statement of Applicability (SoA): the Annex A control selection lives as Control items (framework contains iso-27001); the SoA document itself is a step upload. Every in-scope process and control must trace to these.\n- Prior-cycle context: the previous cycle's Audit item (rating, opinion, report_date) with its findings report, the register of open corrective actions (Issue items, source internal_audit, linked to that prior Audit item), and the last management review minutes (document on the prior instance's hold-review step, or re-uploaded here).\n- The certification / surveillance calendar (external CB scheduling system; an evidence copy uploaded here) whose dates constrain timing.\n- The organization's own ISMS policies and procedures — Policy items (policy_type policy / procedure, framework iso-27001) — as audit criteria beyond the ISO 27001 clauses themselves.\n\n**Procedure**\n1. Draft the clause 9.2 audit plan: objective, scope and stated exclusions, audit criteria (ISO 27001 clauses 4–10 plus the org's ISMS policies/procedures), the fieldwork and closing-meeting schedule, and the auditee list per area.\n2. Trace scope to authority: cross-check every in-scope location, process, and selected control against the ISMS scope statement and the SoA. Flag any gap, or any exclusion that lacks a stated justification.\n3. Run the independence check: compare each proposed auditor against the areas they own or operate. No auditor may audit their own work — annotate every conflicting assignment and reassign before approval.\n4. Build the prior-cycle appendix: previous-report findings, open corrective actions to follow up, last review minutes, and the certification-calendar dates the plan must respect.\n5. Compile the per-auditee evidence request list, each item mapped to the clause requirement and Annex A control it supports, stating the record or configuration wanted, the period covered, and a due date ahead of fieldwork.\n6. Pre-populate one working paper per audit area: the criterion, the planned method (interview, document/record review, or technical sampling), sample selections sized to the area's risk, and prior findings to re-test.\n7. Draft the interview schedule and opening-meeting agenda (interviewees matched to areas), then circulate the approved plan, evidence requests, and schedule to auditees and management.\n\n**Record in AssureSwarm**\n- Step documents: attach the approved audit plan (DOCX/PDF), the evidence request list, and the pre-populated working papers (XLSX) to this step.\n- Item field update: enrich the anchor Audit item — confirm `Audit.scope` (the clause 9.2 area), set `Audit.fieldwork_start` / `Audit.fieldwork_end` to the approved schedule, and confirm `Audit.lead_auditor`.\n- Item relationship: link the anchor Audit item to the in-scope Annex A Control items (framework iso-27001) and to the org's ISMS Policy items used as audit criteria; link the prior-cycle Audit item and its open Issue items (source internal_audit) as carry-forward to follow up.\n- The ISMS scope statement, the SoA document, and the certification-body calendar copy have no queryable item home — attach them as step documents (evidence only). Record the independence-check outcome and any reassignment in the audit plan document (no native field).\n\n**Exit criteria** — The lead auditor has approved the plan; every in-scope requirement maps to at least one planned activity with higher-risk areas covered more deeply; all independence conflicts are resolved; sample selections are defensible; and auditees have confirmed the schedule and evidence due dates.","label":"Plan the audit and prepare fieldwork"},"id":"prepare-fieldwork"},{"data":{"decisionField":"audit_result","description":"Auditors run interviews and testing; agent drafts findings with clause references and evidence links; the lead auditor validates and classifies the result","formData":{"fields":[{"key":"audit_result","label":"Classify audit result","options":[{"label":"No nonconformities raised","value":"clean"},{"label":"Nonconformities require corrective action","value":"nonconformities_found"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Convert completed fieldwork into a validated, evidence-linked findings report and classify whether the cycle raised any nonconformity requiring clause 10.1 corrective action; the lead auditor owns the call.\n\n**Decision criteria**\nThe agent prepares the decision packet: (1) transcribe the auditors' interview and testing notes into the working papers as fieldwork proceeds, logging each evidence item with what was examined, who provided it, and when; (2) draft a candidate finding from each issue — the clause or Annex A control criterion, links to the supporting evidence, a plain statement of the gap, and a proposed classification of conformity, observation, or nonconformity graded major or minor; (3) assemble the draft findings report and closing-meeting summary, cross-referencing every finding to its criterion and evidence and listing any planned activity not completed with the reason. Auditors run the interviews, walkthroughs, and testing and exercise all audit judgment; the lead auditor validates each drafted finding against the evidence, corrects classifications, confirms the report with auditees at the closing meeting, then picks:\n- `clean` — no nonconformity survived validation. Every tested criterion conforms; any residual issues are observations or improvement opportunities only, with no gap against an ISO 27001 clause or Annex A control that a competent auditor would grade as a nonconformity. Route directly to the management review pack.\n- `nonconformities_found` — at least one validated nonconformity remains (major = an ISO 27001 requirement is absent or systemically failing; minor = an isolated lapse needing a fix). Any major, or any minor requiring a fix, selects this branch and routes to clause 10.1 corrective action before the management review.\n\n**Record in AssureSwarm**\n- Step form: submit the `audit_result` SELECT (`clean` | `nonconformities_found`), with the step result (rationale + evidence references) and the step's approver record (the lead auditor).\n- Step document: attach the validated internal audit findings report and the closing-meeting summary (DOCX/PDF) to this step.\n- Item create: one Issue per validated finding — `issue_type: finding` (or `observation` for lesser items), `severity` graded (minor lapse → medium/high, major → high/critical), `source: internal_audit`, `identified_date`, and `description` stating the gap against its clause / Annex A criterion.\n- Item relationship: link each finding Issue ↔ the anchor Audit item, and Issue ↔ the Annex A Control or the Process it hit.\n- Item field update: on the anchor Audit set `rating` (satisfactory | needs_improvement | unsatisfactory) and confirm `fieldwork_start` / `fieldwork_end`.\n\n**Exit criteria** — The findings report is validated and confirmed with auditees, the `audit_result` form is submitted with rationale, and the unused branch is pruned.","kind":"decision","label":"Conduct audit and document findings"},"id":"conduct-audit-and-document"},{"data":{"description":"Agent drafts clause 10.1 nonconformity records and corrective action plans; owners fix root causes and the lead auditor verifies effectiveness","instructions":"**Objective** — Raise, resolve, and verify clause 10.1 corrective actions for every nonconformity so root causes are eliminated and a signed corrective-action status feeds the management review.\n\n**Inputs**\n- The validated findings report and the finding Issue items (issue_type finding, source internal_audit) created on the `nonconformities_found` branch — the corrective actions are recorded on these existing Issues, not on new items.\n- The affected process owners and, for the effectiveness sign-off, the lead auditor or CISO.\n- The current risk register (Risk items) and the Annex A control population (Control items, framework iso-27001) — a root cause may require updating a Risk or a Control.\n\n**Procedure**\n1. Draft a clause 10.1 record per nonconformity: the immediate correction taken to contain it, root-cause analysis prompts tailored to the finding for the process owner (e.g., 5-whys or cause categories), and a scan of the ISMS for similar actual or potential nonconformities elsewhere.\n2. Draft a corrective action plan per record: proposed owner, due date, and a measurable success criterion, plus any consequential update where the root cause changes the risk assessment or the SoA.\n3. Track implementation, chasing owners as due dates approach; log status and escalate stalled items.\n4. Compile implementation and re-test evidence for each completed action into a closure package, and roll the status of all records into a single corrective-action status summary for the management review.\n\n**Record in AssureSwarm**\n- Item field update: on each finding Issue from the audit decision (enrich it — do not create a second item) set `issue_owner`, `root_cause`, `remediation_plan` (the corrective action + measurable success criterion), `management_response`, and `target_remediation_date`; on effectiveness sign-off set `actual_remediation_date` and `verified_date`.\n- Item field update / relationship: where a root cause changes risk, update the linked Risk item (`residual_rating`, `treatment`) or the affected Control item, and link that change to the finding Issue.\n- Step documents: attach the root-cause analysis, the re-test evidence, and the signed corrective-action status summary (PDF) to this step.\n\n**Exit criteria** — Process owners have confirmed root causes and committed to plans; the lead auditor or CISO has verified effectiveness on the evidence (root cause eliminated, not just the symptom corrected); ineffective actions are returned to owners with a revised plan and date; and the status summary is signed for the review.","label":"Raise and verify corrective actions"},"id":"corrective-actions"},{"data":{"description":"Agent assembles all clause 9.3 inputs and drafts the review pack; the CISO reviews it for completeness and releases it","instructions":"**Objective** — Assemble every clause 9.3 review input into a complete, decision-ready management review pack and release it to top management.\n\n**Inputs**\n- This cycle's audit results (from the audit decision) and, when nonconformities were raised, the signed corrective-action status summary.\n- Status of actions from previous management reviews.\n- Changes in external and internal issues and interested-party needs; monitoring and measurement results; nonconformity and corrective-action trends; fulfilment of information security objectives; risk assessment results and risk treatment plan status; interested-party feedback; and continual-improvement opportunities.\n\n**Procedure**\n1. Gather each clause 9.3(a)–(f) input from its owning source: status of prior-review actions; changes in issues and interested-party needs; information security performance and effectiveness feedback (including nonconformity/corrective-action trends, monitoring-and-measurement results, and objective fulfilment); interested-party feedback; risk assessment and treatment-plan status; and continual-improvement opportunities.\n2. Summarize each input against its target over one consistent reporting period; flag every item that requires a management decision.\n3. Draft the agenda mapping each clause 9.3 input to a slot, and prepare the pack for distribution ahead of the meeting.\n\n**Record in AssureSwarm**\n- Step document: attach the assembled management review pack and agenda (PDF/DOCX) to this step. The clause 9.3 monitoring-and-measurement results, objective-fulfilment data, and interested-party feedback have no native item type — attach them as step uploads (PBC) here.\n- Item relationship: link the anchor Audit item (carrying this cycle's `rating` and result) and the finding Issue items with their corrective-action status; the corrective-action status summary is the document from the corrective-actions step.\n- Record the reporting period and the decision-required flags in the pack itself (no native reporting-period or decision-item field).\n\n**Exit criteria** — The CISO has confirmed every clause 9.3 input category is present or its absence justified, decision items are flagged, and the pack is released to top management with enough lead time for meaningful review.","label":"Assemble management review pack"},"id":"assemble-management-review"},{"data":{"description":"Top management holds the clause 9.3 review; agent drafts the minutes and action register; the review chair approves them","instructions":"**Objective** — Hold the clause 9.3 management review and capture approved minutes and an action register recording every decision on ISMS suitability, change, and resources.\n\n**Inputs**\n- The released management review pack and agenda.\n- The confirmed attendee list (top management) and the follow-up status of decisions from previous reviews.\n\n**Procedure**\n1. Prepare meeting support: confirmed attendees, the walk-through order for the pack, and the status of prior-review decisions to close the loop.\n2. After the meeting, draft the minutes from the discussion notes: attendees, each input reviewed, discussion highlights, and every decision on continual-improvement opportunities, needs for change to the ISMS, and resource needs.\n3. Draft the action register from those decisions — each action with a proposed owner, due date, and success measure — and trace each output back to the reviewed input that prompted it.\n\n**Record in AssureSwarm**\n- Step documents: attach the approved clause 9.3 minutes (PDF) and the action register (XLSX) to this step, retained as documented information.\n- Item create: one Issue per review action — `issue_type: opportunity` (or `observation`), `source: management_identified`, `issue_owner`, `target_remediation_date`, with the success measure stated in `description` / `remediation_plan`; link each to the anchor Audit item and, in the register, trace it back to the clause 9.3 input that prompted it.\n- Record the explicit ISMS suitability / adequacy / effectiveness assessment in the minutes document (no native outcome field).\n\n**Exit criteria** — Top management has explicitly assessed the continuing suitability, adequacy, and effectiveness of the ISMS and made every decision (none deferred without a revisit date); and the review chair has corrected and approved the minutes and action register.","label":"Hold review and record outcomes"},"id":"hold-review-and-record"},{"data":{"description":"Agent tracks review actions, chases owners, compiles closure evidence, and archives the full cycle package; the CISO confirms closure or carries items forward and that approval formally closes the cycle","instructions":"**Objective** — Drive every management review action to verified closure, carry any open item formally into the next cycle, and archive the complete audit-and-review cycle as retained ISMS documented information — the approval recorded here closes the cycle.\n\n**Inputs**\n- The approved action register and minutes from the review.\n- The destinations for carry-forward: the audit programme, the risk register, and the next review's inputs.\n- Every cycle artifact from the prior steps: the approved audit plan, working papers and evidence register, the findings report, corrective-action records with verification evidence, the review pack, and the approved minutes.\n- The retention and access rules for ISMS documented information, and the audit programme.\n\n**Procedure**\n\n_Items 1–4 are agent-run tracking, item 5 is the human moment, and items 6–8 close the cycle (folded from the former \"Close and archive\" step) — the closure approved on this step is the cycle's formal close, with no separate confirmation._\n\n1. Load every review action into the tracker with owner, due date, and success measure; confirm acceptance with each owner.\n2. Chase progress on a cadence proportionate to the due dates; log status and flag stalled items for escalation to the review chair.\n3. Compile completion evidence per action against its stated success measure into a closure summary.\n4. Draft carry-forward entries mapping each open item to its next-cycle destination (the audit programme, the risk register, or the next review inputs).\n5. The CISO confirms closure of each action on the evidence — the change operates in practice, not only on paper — returns inadequate items to their owners with reasons, decides which open items carry into the next cycle, and notifies each owner of the carried dates.\n6. Assemble the complete cycle package from all prior steps — audit plan, working papers and evidence register, findings report, corrective-action records with verification evidence, review pack, approved minutes, action register, and the closure/carry-forward summary — and confirm every listed artifact is present.\n7. Archive the package under the ISMS documented-information retention and access rules, and verify every artifact is retrievable from the archive reference.\n8. Update the audit programme with actual dates and results, schedule the trigger for the next cycle, and issue the closure notice to top management and the auditees.\n\n**Record in AssureSwarm**\n- Item field update: on each review-action Issue set `actual_remediation_date` and `verified_date` on CISO closure, with completion evidence and closure notes in `management_response` / `remediation_plan`.\n- Step documents: attach the closure summary, the carry-forward list (CSV/XLSX), and the archived cycle package (ZIP/PDF) or its archive reference to this step.\n- Materialize carry-forwards: create or update Risk items for risk-register entries and create the next-cycle Audit item (status PLANNED, audit_type internal) for programme entries; review-input carry-forwards stay on the list document for the next instance's assemble-management-review step, and revised dates are recorded on the carried Issue items (`target_remediation_date`).\n- Item field update: on the anchor Audit item set `report_date`, finalize `rating` and `opinion`, and move status to CLOSED; the workflow instance itself is the durable audit trail retained as ISMS documented information.\n- Item relationship: link the next-cycle Audit item created for the programme, and record the archive reference and next-cycle trigger date in the Audit item's `scope` / notes (no native archive-reference field).\n\n**Exit criteria** — The CISO has confirmed closure of each action on the evidence, returned inadequate items to owners with reasons, decided which open items carry into the next cycle, and notified each owner of the carried dates; the archived cycle package is verified complete and retrievable from its recorded reference; the next-cycle trigger sits on the audit programme with the next-cycle Audit item created; the closure notice is approved and issued; and the anchor Audit item is CLOSED, which is the cycle's formal close.","label":"Track actions to closure"},"id":"track-actions-to-closure"}],"sourceTemplateId":"workflow-library:controls-isms-internal-audit-management-review"}
