{"description":"Deliver one corrective action against a finding and capture the evidence it produces. Validation and closure approval happen on the finding’s own workflow, where every action raised against it is judged together.","edges":[],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-RISK-14"],"department":"operations","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-remediation-delivery","contentDigest":"sha256:4d8c5f2ce3e264ed1116540f0195c8bad3d0b12f1d421e2ff3e6930cf127b3bc","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:4d8c5f2ce3e264ed1116540f0195c8bad3d0b12f1d421e2ff3e6930cf127b3bc","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-remediation-delivery"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-remediation-delivery","source":"coworkcanvas-gallery","standards":["nist-800-53","soc2"],"teams":["operations"]},"name":"Remediation Delivery","nodes":[{"data":{"description":"Agree observable root-cause criteria and feasible commitments, then deliver the action with evidence and visible blockers for parent-finding validation.","instructions":"**Objective** — Agree observable root-cause criteria and feasible commitments, then deliver the action with evidence and visible blockers for parent-finding validation.\n\n**Inputs**\nThe linked Issue and its root cause, the remediation plan and closure criteria on this record, and the operating template that will carry the corrective action once it is in place.\nThe plan confirmed in this checkpoint, the systems, documents or counterparties the action touches, and the evidence format the closure criteria call for.\n\n**Procedure**\n_This checkpoint absorbs “Confirm the plan, owner and closure criteria”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Confirm the plan, owner and closure criteria: Confirm what will actually clear the finding, who owns it, and what evidence will prove it closed.\n2. Read the linked finding and confirm the plan on this record addresses its root cause rather than its symptom.\n3. Confirm the named action owner has the authority and access to perform the work.\n4. Confirm the closure criteria are observable - a reviewer must be able to tell from the evidence alone whether the action succeeded.\n5. Set or confirm the target date. Where the original commitment has moved, record the revised target date rather than overwriting the original.\n6. Perform the corrective action: Do the work the plan describes and capture the evidence it produces.\n7. Perform the action as planned. Where it depends on an outside party - a signature, a vendor response, a regulator - record the request and the date it was made, so a delay is visible rather than silent.\n8. Capture the evidence as the work proceeds rather than reconstructing it afterwards.\n9. Where the action cannot be completed as planned, stop and record why, then revisit the planning activities in this checkpoint rather than closing on a partial result.\n\n**Record in AssureSwarm**\nRecord the confirmed plan, owner and closure criteria on this step, and note any change to the target date with its reason.\nAttach the evidence the action produced and record the completion date on this record.\n\n**Exit criteria**\n- The plan addresses the root cause, the owner is named and able, the closure criteria are observable, and the target date reflects the current commitment.\n- The action is performed, the completion date is recorded, and the evidence is attached and legible to someone who was not present. Validation and closure are NOT performed here - they belong to the linked finding’s own workflow, which judges this action alongside every other action raised against that finding.","kind":"task","label":"Perform the corrective action"},"id":"deliver"}],"sourceTemplateId":"workflow-library:controls-remediation-delivery"}
