{"description":"Runs on the existing remediation item. Plan and deliver corrective action, independently validate it against agreed closure criteria, and approve a traceable remediation record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-remediation-plan-remediation-delivery","source":"remediation-plan","target":"remediation-delivery"},{"id":"e-remediation-delivery-remediation-review-closure","source":"remediation-delivery","target":"remediation-review-closure"}],"isPublic":true,"itemTypeSlug":"remediation","metadata":{"capabilities":["remediation-delivery-validation"],"controlVerbs":{"UC-RISK-14":"operates"},"controls":["UC-RISK-14"],"department":"operations","domains":["controls"],"kind":"remediation-delivery-validation","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:remediation-delivery-validation"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-remediation-delivery-validation","contentDigest":"sha256:1d968c8acfc2bd6f39974fb0b8bf73fbe438470b6211d849af0502405e11076d","prerequisites":{"anchorItemType":{"slug":"remediation"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-remediation-delivery"}],"roles":[{"contribution":"expertise","description":"Remediation sponsor. Define remediation plan and criteria.","id":"reviewer-1","nodeIds":["remediation-plan"]},{"contribution":"expertise","description":"Action owner. Deliver corrective action.","id":"reviewer-2","nodeIds":["remediation-delivery"]},{"contribution":"approval","description":"Independent remediation validator. Approve remediation record.","id":"reviewer-3","nodeIds":["remediation-review-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:remediation-delivery-validation"}],"releaseId":"sha256:1d968c8acfc2bd6f39974fb0b8bf73fbe438470b6211d849af0502405e11076d","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-remediation-delivery-validation"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-remediation-delivery-validation","source":"coworkcanvas-gallery","standards":[],"teams":["operations"]},"name":"Remediation Delivery & Validation","nodes":[{"data":{"instructions":"**Objective**\nDefine remediation plan and criteria. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Remediation item, linked issue and root cause, risk treatment, management response, relevant controls and requirements, target dates, approved exceptions, resource constraints, and prior attempts.\n\n**Procedure**\n1. Confirm the plan addresses documented cause rather than symptoms, decompose delivery into measurable milestones, define design and operating criteria, identify affected processes and systems, assess change risk, and agree evidence required for validation.\n\n**Record in AssureSwarm**\n1. Capture the delivery plan, closure criteria, action owner, milestones, target and contingency dates, dependencies, resources, change and rollback approach, expected evidence, validator independence, and escalation triggers.\n\n**Exit criteria**\nRemediation sponsor provides expertise: The plan is actionable, criteria are observable and aligned to the underlying issue, ownership and dependencies are accepted, and validation requirements are defined before delivery.","kind":"task","label":"Define remediation plan and criteria","requiredApprovals":1},"id":"remediation-plan"},{"data":{"instructions":"**Objective**\nDeliver corrective action. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved plan, design specifications, change tickets, configurations, procedures, training, communications, approvals, deployment records, reconciliations, affected populations, and rollback or contingency arrangements.\n\n**Procedure**\n1. Perform each milestone, verify authorized change and segregation, reconcile deployed scope to the plan, preserve before-and-after evidence, document deviations and failed steps, update affected documentation, and escalate blockers or date changes.\n\n**Record in AssureSwarm**\n1. Document delivery status, completed milestones, change identifiers, dates, performers and reviewers, scope deployed, evidence links, deviations, incidents, rollback decisions, revised dates, and residual open actions. Also record delivery evidence summary.\n\n**Exit criteria**\nAction owner provides expertise: Delivered work is traceable to the approved plan, deviations and incomplete scope remain visible, implementation evidence is assembled, and the package is ready for validation.","kind":"task","label":"Deliver corrective action","requiredApprovals":1},"id":"remediation-delivery"},{"data":{"controls":["UC-RISK-14"],"instructions":"**Objective**\nApprove remediation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use closure criteria, delivery evidence, configurations, updated documentation, populations, transaction samples, monitoring results, interviews, linked issue evidence, deviations, and validator independence requirements.\n2. Review all stage records, linked issue and risk information, approved plan, change evidence, validation work, exceptions, monitoring commitments, revised dates, and stakeholder responses.\n\n**Procedure**\n1. Verify the delivered scope, inspect or reperform evidence for every criterion, test data completeness and relevant operation period, investigate exceptions, compare residual exposure to the intended response, and avoid relying solely on owner attestation.\n2. Trace each closure criterion to validation support, verify the validator and approval chain, reconcile owners and dates, confirm failed or partial results remain open, and return incomplete or inconsistent evidence for correction.\n\n**Record in AssureSwarm**\n1. Record the validation method, period and population, selections, results by criterion, exceptions, evidence references, residual exposure, validator identity, independence considerations, and required follow-up. Also record validation summary.\n2. Capture the authorized reviewer, closure summary, delivery and validation dates, final result, linked issue and risk references, residual actions, monitoring owner, due dates, and evidence package location. Also record remediation record summary.\n\n**Exit criteria**\nIndependent remediation validator provides approval: An approver accepts that the validation result follows from sufficient cited work, unmet criteria remain open, and the result is not inferred merely from delivery or workflow completion. The authorized reviewer accepts the remediation record as a traceable account of delivery and validation, linked records can be updated consistently, and closure itself is not an assurance conclusion.","kind":"task","label":"Approve remediation record","requiredApprovals":1},"id":"remediation-review-closure"}],"sourceTemplateId":"workflow-library:controls-remediation-delivery-validation"}
