{"description":"Runs on the existing policy item. Canonical annual policy review: establish scope, obtain the policy owner and policy team sign-offs, record any required change path, and approve a documented review outcome and next review date. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-owner-signoff-policy-team-signoff","source":"owner-signoff","target":"policy-team-signoff"}],"isPublic":true,"itemTypeSlug":"policy","metadata":{"capabilities":["policy-annual-review"],"controlVerbs":{"UC-GOV-14":"operates"},"controls":["UC-GOV-14"],"department":"compliance-legal","domains":["grc"],"kind":"policy-annual-review","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:policy-annual-review"}],"canonicalUrl":"https://workflow-library.com/all/?w=grc-annual-policy-review","contentDigest":"sha256:ccc74893e9e25bfb5a02f79364bdc1997c132196bc534949164c09e48738a227","prerequisites":{"anchorItemType":{"slug":"policy"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-policy-lifecycle-management"}],"roles":[{"contribution":"expertise","description":"Policy owner. Policy owner review & sign-off.","id":"reviewer-1","nodeIds":["owner-signoff"]},{"contribution":"approval","description":"Policy governance approval authority. Approve annual review record.","id":"reviewer-2","nodeIds":["policy-team-signoff"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:policy-annual-review"}],"releaseId":"sha256:ccc74893e9e25bfb5a02f79364bdc1997c132196bc534949164c09e48738a227","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-annual-policy-review"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-annual-policy-review","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53","soc2"],"teams":["compliance-legal"]},"name":"Annual Policy Review","nodes":[{"data":{"controls":[],"instructions":"**Objective**\nPolicy owner review & sign-off. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current policy document, Policy item metadata, prior review, open policy changes, mapped requirements and controls, exceptions, incidents, audit findings, and organization changes.\n2. Use the scoped policy, current operating procedures, organization and system changes, incidents, exceptions, control and requirement mappings, stakeholder feedback, and prior commitments.\n\n**Procedure**\n1. Verify the authoritative version and review population, identify stakeholders and legal or subject-matter input, reconcile outstanding changes, and define which updates belong in this review versus a separate Policy Change workflow.\n2. Read the policy end to end, verify scope, roles, statements, links, and procedures, compare documented requirements to observed practice, correct purely editorial issues, and route substantive revisions through Policy Change.\n\n**Record in AssureSwarm**\n1. Document the version, effective and next-review dates, scope, participants, sources to be consulted, linked changes or issues, and any limitations that could prevent a complete review. Also record review period.\n2. Complete the preserved outcome, summary, and attestation fields; list sources and stakeholders reviewed, editorial corrections, gaps, affected sections, and the source ID of any required Policy Change.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `outcome` (Review outcome; values: current, updated, revision_required) in Step.result markdown.\n\nRecord `summary` (Review summary) in Step.result markdown.\n\nRecord `attestation` (I attest this policy is accurate, current, and aligned to practice) in Step.result markdown.\n\n**Exit criteria**\nPolicy owner provides expertise: The document of record and review boundary are unambiguous, required stakeholders are identified, open change work is visible, and the owner can begin substantive review. The owner outcome is supported by a specific review summary, substantive changes are not hidden as editorial edits, and any required revision has a defined owner and next action.","kind":"task","label":"Policy owner review & sign-off","requiredApprovals":1},"id":"owner-signoff"},{"data":{"controls":["UC-GOV-14"],"instructions":"**Objective**\nApprove annual review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the authoritative policy and metadata, intake scope, owner outcome and evidence, editorial updates, linked Policy Change, mapped requirements and controls, and applicable review cadence.\n2. Use the intake record, the policy owner’s upstream markdown result and native approval, the policy team’s current review result, supporting evidence, approved editorial updates, linked substantive change work, Policy item metadata, and unresolved conditions.\n\n**Procedure**\n1. Verify the owner considered relevant change signals, inspect changes against document-control rules, challenge stale or unsupported statements, confirm required approvers and audiences, and calculate the next review date consistently.\n2. Trace each sign-off to its evidence, verify the decision and dates agree across records, confirm substantive revisions have not been published without approval, and return incomplete or inconsistent work with explicit comments.\n\n**Record in AssureSwarm**\n1. Complete the preserved decision, next-review-date, and comments fields; capture review notes, owner resolutions, related change references, and any conditions that must be met before approval.\n2. Record the policy owner’s upstream review and the independent policy authority’s native approval, closure summary, date, final review outcome, mirrored next review date, open Policy Change or other follow-up, owner, and due date. Also record annual review closure summary.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `decision` (Decision; values: approve, return) in Step.result markdown.\n\nRecord `next_review_date` (Next review date) in Policy.fields.next_review_date.\n\nRecord `comments` (Policy team comments) in Step.result markdown.\n\n**Exit criteria**\nPolicy governance approval authority provides approval: The policy-team decision is supported, returned items are specific and assigned, the next review date is accurate, and the final closure reviewer has a complete governance record. The authorized reviewer accepts a coherent review record, Policy metadata can be updated without ambiguity, all substantive follow-up remains trackable, and closure is not represented as certification.","kind":"task","label":"Approve annual review record","requiredApprovals":1},"id":"policy-team-signoff"}],"sourceTemplateId":"workflow-library:grc-annual-policy-review"}
