{"description":"Board Risk & Internal Control Oversight Cycle as a decision-aware workflow: the governance office verifies board independence and expertise, compiles the board risk & internal-control oversight pack, routes the at-least-annual governance-framework effectiveness evaluation, facilitates the independent board's approval of the risk strategy and material policies, captures and minutes the directed adjustments, and launches and tracks them as an owned open directives register. It is standalone: the governing body and the governance framework are not Studio item types, so there is no natural item anchor — each cycle runs as a fresh recurring workflow instance and its deliverables attach to the run's own steps. The named deliverables are the composition-and-independence summary, the board risk & internal-control oversight pack, the annual governance-and-management-framework effectiveness evaluation when in scope, the adopted board/committee minutes, and the board directives-and-adjustments register (one Issue item per directive, linked across cycles). The risk strategy and material policies the board approves are Policy items (approved_by, version, next_review_date); board directives, approval conditions, and framework adjustments are Issue items (issue_type: observation, source: management_identified). In scope: a single named governing body's quarterly (or specially convened) risk and internal-control oversight meeting and, where the annual clock or a substantial-change trigger applies, that cycle's enterprise governance and management framework effectiveness evaluation. Out of scope: the day-to-day first- and second-line control operation, testing, and assurance that feed the pack — no workflow hands into this cycle, and the board's directives flow onward into control-remediation and policy-update execution as prose, not a wired downstream template.","edges":[{"id":"e-determine-cycle-scope-evaluate-governance-and-management-framework","label":"Annual framework evaluation due","source":"determine-cycle-scope","target":"evaluate-governance-and-management-framework","whenValue":"annual_framework_due"},{"id":"e-determine-cycle-scope-convene-board-review-and-approve-strategy","label":"Quarterly oversight only","source":"determine-cycle-scope","target":"convene-board-review-and-approve-strategy","whenValue":"quarterly_only"},{"id":"e-evaluate-governance-and-management-framework-convene-board-review-and-approve-strategy","source":"evaluate-governance-and-management-framework","target":"convene-board-review-and-approve-strategy"},{"id":"e-convene-board-review-and-approve-strategy-record-oversight-minutes-and-materials","label":"Approved","source":"convene-board-review-and-approve-strategy","target":"record-oversight-minutes-and-materials","whenValue":"approved"},{"id":"e-convene-board-review-and-approve-strategy-return-to-management-for-revision","label":"Revisions required","source":"convene-board-review-and-approve-strategy","target":"return-to-management-for-revision","whenValue":"revisions_required"},{"id":"e-return-to-management-for-revision-record-oversight-minutes-and-materials","source":"return-to-management-for-revision","target":"record-oversight-minutes-and-materials"},{"id":"e-verify-board-independence-and-expertise-record-oversight-minutes-and-materials","source":"verify-board-independence-and-expertise","target":"record-oversight-minutes-and-materials"},{"id":"e-record-oversight-minutes-and-materials-implement-and-track-framework-adjustments","source":"record-oversight-minutes-and-materials","target":"implement-and-track-framework-adjustments"},{"id":"e-verify-board-independence-and-expertise-convene-board-review-and-approve-strategy","source":"verify-board-independence-and-expertise","target":"convene-board-review-and-approve-strategy"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-GOV-01","UC-GOV-05"],"department":"executive","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-board-risk-internal-control-oversight-cycle","contentDigest":"sha256:699bb8f921e61282509d797631e22c865a0c1b254195bbc6798e50947f563a0f","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:699bb8f921e61282509d797631e22c865a0c1b254195bbc6798e50947f563a0f","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-board-risk-internal-control-oversight-cycle"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-board-risk-internal-control-oversight-cycle","source":"coworkcanvas-gallery","standards":["cobit-2019","coso-ic","coso-erm","soc2"],"teams":["executive","risk-management"]},"name":"Board Risk & Internal Control Oversight Cycle","nodes":[{"data":{"description":"Agent compiles director independence attestations and the expertise and skills matrix for the governing body; human confirms the board demonstrates independence from management and appropriate expertise to oversee the program","formData":{"fields":[{"key":"independence","label":"I confirm I am independent of the organization's management and hold no financial interest that would impair my objectivity","required":true,"type":"checkbox"},{"helperText":"Enter \"None\" if you have nothing to disclose.","key":"relationships","label":"Relationships with the organization, its personnel, customers or vendors to disclose","required":true,"type":"textarea"},{"key":"expertise","label":"Relevant governance, security or audit expertise applied to this engagement","required":true,"type":"textarea"},{"key":"hours_available","label":"Hours committed to oversight this quarter","required":true,"type":"number"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Establish and evidence that the governing body is independent of management and appropriately expert to oversee the risk and internal-control program, so this cycle's approvals rest on a body qualified to give them (COSO IC Principle 2 / SOC 2 CC1.2).\n\n**Inputs**\n- The board and committee rosters with tenure, roles, and committee assignments, plus the charters and their quorum and independence requirements.\n- Each director's most recent independence attestation and conflict-of-interest / D&O questionnaire disclosure.\n- The applicable independence and expertise standards: listing-rule tests (NYSE 303A / Nasdaq 5605), SOX §301 audit-committee independence and §407 audit-committee-financial-expert disclosure, and, for regulated entities, any risk-committee risk-management-expert requirement.\n- The agenda's matters under oversight, to test whether the body's expertise fits what it must judge.\n\n**Procedure**\n1. Compile composition: members, tenure, roles, and committee assignments for the board and its risk and audit committees, checked against the charters and quorum requirements. Where listing rules apply, confirm the majority-independent board and the fully independent audit committee.\n2. Test independence per director against the applicable standard — no material relationship with management, disqualifying compensation, family or interlocking-directorship ties, or recent employment. Flag any member whose independence is impaired or simply unconfirmed for this cycle; an expired or missing attestation is a gap, not a pass. Note any recusals required for specific agenda items.\n3. Build or refresh the expertise-and-skills matrix mapping directors against the competencies this oversight demands: risk management, internal control and financial reporting, cybersecurity, and industry or domain knowledge. Confirm the audit-committee financial expert and, where required, the risk-committee risk expert, and identify any competency the matters under oversight need but the body lacks.\n4. Where a gap exists — an independence lapse, a missing competency, or a quorum shortfall — record it with a remediation path (a fresh attestation, an executive session, an external advisor, a recusal, or a composition change) rather than proceeding silently.\n5. Draft the composition summary that evidences independence and appropriate expertise for the meeting record.\n\n**Record in AssureSwarm**\n- The form on this step, answered by the independent governance advisor, captures their independence confirmation, relationships to disclose, relevant governance/security/audit expertise, hours committed to oversight this quarter; send it as a form assignment and record the returned attestations and skills-matrix competency ratings as this step's form responses (coach-form-fill), bound to the named assignment; attach any existing signed memo as a source document — there is no Governance Body item type, so the roster, attestations, and skills matrix live as this step's forms and linked documents.\n- Where the board and committee charters are maintained as governed documents, they are Policy items (policy_type: charter, policy_owner, approved_by) the composition review reads against; query the roster, tenure, and prior-cycle attestations to build the composition view (coach-query-data), and attach the composition-and-independence summary with the flags and each remediation path as a document on this step (coach-document-upload).\n\n**Exit criteria** — The Corporate Secretary and committee chair have confirmed the body demonstrates independence from management and holds the expertise to oversee the development and performance of the internal-control and cybersecurity risk-management program; every independence or expertise gap is recorded with a remediation path; required recusals are noted; and the composition summary is ready to accompany the pack.\n\n**Form recipient** — this step's form is answered by the independent governance advisor, outside the board, Corporate Secretary, governance owner and management executors of this workflow. Send it with a form assignment; the owner's own work goes in the step result.","label":"Verify board independence and expertise","performedBy":{"primitives":["coach-query-data","coach-form-fill","coach-document-upload"]}},"id":"verify-board-independence-and-expertise"},{"data":{"decisionField":"cycle_scope","description":"Agent determines whether this cycle is a standard quarterly oversight review or the cycle that also carries the annual enterprise governance and management framework effectiveness evaluation; human decides the routing","formData":{"fields":[{"key":"cycle_scope","label":"Cycle scope routing","options":[{"label":"Annual framework evaluation due this cycle","value":"annual_framework_due"},{"label":"Quarterly oversight review only","value":"quarterly_only"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve whether this cycle also carries the at-least-annual effectiveness evaluation of the enterprise governance and management framework, or runs as quarterly oversight only. The governance owner (Chief Governance Officer or Corporate Secretary) owns the call.\n\n**Decision criteria**\n\nTwo tests drive the routing — the annual clock and substantial change — and either is sufficient on its own.\n\n- **Annual framework evaluation due (`annual_framework_due`)** — pick this when the framework effectiveness evaluation is due: the last completed evaluation is twelve months or more back (COBIT 2019 expects the governance system to be monitored and periodically evaluated, and the at-least-annual cadence is the floor), OR an out-of-cycle trigger forces it regardless of calendar — a material change in enterprise strategy, structure, or context; a significant regulatory change; or a governance failure or incident (COSO ERM Principle 15, Assesses Substantial Change). Cite the specific date or event.\n- **Quarterly oversight review only (`quarterly_only`)** — pick this when the last completed evaluation is under twelve months old AND no substantial-change trigger applies, so the standard quarterly risk and internal-control oversight review suffices. Record the date of the last completed evaluation to evidence that the clock has not run out.\n\n**Record in AssureSwarm**\n- Submit the decision form: `cycle_scope` (the branch), the step result stating the last-evaluation date and resolving each substantial-change trigger as present or absent with evidence references, and the step's approver record.\n- Query the prior cycle's archived run and evaluation history to establish the clock (coach-query-data), and link the evidence — the oversight-calendar entry, the last evaluation's completion record, and any change, regulatory, or incident trigger — as documents on this step (coach-document-link); there is no native calendar/scheduling object, so the clock is evidenced by these linked records.\n\n**Exit criteria** — The form is submitted with a rationale that states the last-evaluation date and resolves every substantial-change trigger; the routing follows the criteria above; and the not-taken branch is prunable.","kind":"decision","label":"Determine cycle scope","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"determine-cycle-scope"},{"data":{"description":"Agent runs the annual effectiveness evaluation of the enterprise governance and management framework and drafts recommended adjustments to reflect context, strategy, and regulatory change; human governance owner confirms the evaluation and adjustments","instructions":"**Objective** — Perform the at-least-annual effectiveness evaluation of the enterprise governance system and its supporting management framework, and draft evidence-based adjustments wherever either no longer fits current context, strategy, or regulation — ready for the board to approve alongside the quarterly pack.\n\n**Inputs**\n- The current governance-framework documentation: direction and strategy artifacts, decision-rights maps (RACI or authority matrices), accountability structures, the policy inventory — Policy items (policy_owner, review_frequency, next_review_date) — and defined processes as Process items (process_owner, process_type); RACI/authority maps have no native type and are read as linked documents.\n- The year's evidence base: oversight-cycle records, assurance and internal-audit findings, incidents and loss events, KRI trends, and stakeholder input.\n- The reference models: COBIT 2019 (governance objectives EDM01–EDM05 versus management objectives APO/BAI/DSS/MEA, and capability levels) and COSO (IC, and ERM Review and Revision, Principles 15–17).\n- The current enterprise strategy, operating context, and regulatory environment, to test fit for purpose.\n\n**Procedure**\n1. Evaluate the governance system — the evaluate/direct/monitor (EDM) layer: does it still set clear direction, allocate decision rights, and enforce accountability? Test against the year's evidence; where oversight, assurance, incidents, or stakeholder input show direction unclear or accountability diffuse, the system is not operating. Rate against a capability scale rather than a binary pass or fail.\n2. Evaluate the supporting management framework that operationalizes that direction: organizational structures, policies, processes, and culture. Assess each for fit for purpose — a policy no one follows, a process without an owner, or a culture signal that contradicts stated values is a live weakness.\n3. Compare both layers against current strategy, context, and the regulatory environment (COSO ERM Principle 15, substantial change). Pinpoint where direction, decision rights, accountability structures, policies, or culture no longer fit; the gap between designed and needed is the adjustment.\n4. Draft each recommended adjustment with its rationale and evidence, the layer it touches, and the expected effect — so the board approves specific changes, not a general sentiment.\n5. Assemble the framework-evaluation summary and the proposed adjustments, packaged for board approval alongside the quarterly pack.\n\n**Record in AssureSwarm**\n- Attach the governance-and-management-framework effectiveness-evaluation summary and the proposed-adjustments schedule as documents on this step (coach-document-upload).\n- Create each recommended adjustment as an Issue item — issue_type: observation, source: management_identified, issue_owner (the accountable layer owner), target_remediation_date, with the layer it touches, its rationale, evidence reference, and expected effect in description (coach-item-create) — so it can be tracked from board approval through implementation.\n\n**Exit criteria** — The Chief Governance Officer has confirmed the evaluation genuinely assesses both the governance system and the management framework against current context, strategy, and the regulatory environment; every recommended adjustment is evidence-based, specific, and traceable; and the summary and adjustments are ready to present to the board for approval.","label":"Evaluate governance and management framework","performedBy":{"primitives":["coach-document-upload","coach-item-create"]}},"id":"evaluate-governance-and-management-framework"},{"data":{"decisionField":"board_approval_decision","description":"Independent board through its chair: Challenge program performance and management recommendations, deliberate on appetite and policy terms, and approve or return the exact strategy and policy package.","formData":{"fields":[{"key":"board_approval_decision","label":"Board approval decision","options":[{"label":"Risk strategy and material policies approved","value":"approved"},{"label":"Revisions required before approval","value":"revisions_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Assemble the risk and control oversight pack and obtain the independent board’s evidenced approval or return of strategy, material policies and any framework adjustments.\n\n**Decision criteria**\nInputs for preparation: - The risk register — Risk items (category, likelihood, impact, inherent_rating, residual_rating, treatment, risk_owner) — plus the KRI/appetite dashboard: top and emerging risks, appetite and tolerance status, and movement since the last meeting.\n- The status of prior board risk decisions and open directives — Issue items from earlier cycles (issue_owner, target_remediation_date, status) — and the incident and loss register, which has no native item type and is carried as documents in the prior pack.\n- Control and program results: Control-hosted SOX testing workflows (Test-step conclusion, cycle from Workflow.customFields.sox.fiscalYear) per control under test, Control items (key_control, control_owner), Audit items (rating, opinion, report_date) for internal/external results, and Issue items graded by issue_type (deficiency | significant_deficiency | material_weakness) with remediation status — plus program maturity against plan.\n- Assurance across the three lines (management, risk and compliance, internal audit) and external audit where relevant.\n- Management's submissions: the risk strategy and the material policies presented for approval — Policy items (policy_owner, version, next_review_date), uploaded here where not yet in the library — and regulatory and context changes.\n\n*Autonomous preparation incorporates Compile risk and internal-control oversight pack; Independent board through its chair reviews the combined evidence.*\n1. Compile risk-management outcomes since the last meeting: top and emerging risks; every risk-appetite or tolerance breach and any KRI trending through its threshold; incident, loss, and near-miss events; and the status of each prior board risk decision. Movement and breaches are the signal — a static heat map with no trend tells the board nothing.\n2. Compile program-effectiveness reporting on internal control and the cybersecurity risk-management program: control performance and testing results, key-control failures with remediation status and dates, assurance and audit findings, and program maturity against plan. Grade deficiencies consistently — deficiency versus significant deficiency versus material weakness — because severity, not count, drives the board's attention.\n3. Assemble management's reporting and asks: the risk strategy and any proposed changes, the material policies submitted for approval, regulatory and context changes, and management's recommendations. Separate what is for information from what is for decision.\n4. Build the pack: an executive summary that leads with the decisions requested; the supporting sections above; a cross-reference from every assertion to its underlying material so a director can drill down; and an explicit decision register listing each approval and decision the board must make, with management's recommendation on each.\n5. Test for fair presentation: known bad news is surfaced rather than buried, every figure traces to a source, and no requested approval is missing from the decision register.\n\nThe board weighs the pack's risk-management outcomes and program effectiveness, management's recommendation, and the key risk-appetite and tolerance decisions, plus any framework adjustments in scope, then chooses one:\n\n- **Risk strategy and material policies approved (`approved`)** — pick this when the board is satisfied the risk strategy and material policies are sound and fit the enterprise's risk appetite and context, and approves them. Conditions are compatible with approval: record each condition, but the strategy and policies stand approved and flow forward. Genuine oversight leaves a trail — questions, dissent, and conditions belong in the record even on an approval.\n- **Revisions required before approval (`revisions_required`)** — pick this when the strategy, policies, or framework adjustments cannot be approved as presented and management must rework them first: an appetite or tolerance the board rejects, a policy gap, insufficient support in the pack, or an adjustment the board is unwilling to direct as drafted. State specifically what must change so management is not left guessing.\n\n**Record in AssureSwarm**\n- Query the reporting sources to populate the pack (coach-query-data): Risk and Control items, Control-hosted SOX testing workflow results, Audit items, and Issue items by issue_type, plus the Policy items presented for approval; the incident/loss register has no native type and is attached as a document.\n- Assemble and attach the board risk & internal-control oversight pack — executive summary, sectioned reporting, cross-references, and decision register — as a document on this step (coach-render-package / coach-document-upload); the pack is a point-in-time snapshot of those items, which the workflow reads but does not own.\n- Submit the decision form: `board_approval_decision` (the branch), the step result capturing the deliberation substance, any conditions, and evidence references, and the step's approver record (the approving body or chair).\n- Attach the deliberation record — questions, dissent, and conditions — as the basis for the minutes (coach-document-upload). The risk strategy and material policies are Policy items: on an approval, set Policy.approved_by (the approving body or chair), Policy.version, Policy.effective_date, and Policy.next_review_date on each (coach-item-update) and link them to the decision (coach-items-link); on a return, leave them un-approved and link them as returned.\n\n**Exit criteria**\nChallenge program performance and management recommendations, deliberate on appetite and policy terms, and approve or return the exact strategy and policy package.\nThe Corporate Secretary has confirmed the pack fairly presents risk-management outcomes, program effectiveness, and management's reporting; supporting materials are complete and traceable from every assertion; and the decisions and approvals requested of the board are stated unambiguously in the decision register.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the board pack — executive summary, sectioned reporting, cross-references, and decision register — into a single distribution-ready document from the linked source material.\nThe form is submitted; the rationale records the deliberation, any conditions, and the approving body or chair; the risk strategy and material policies are marked approved-with-conditions or returned for revision; and the not-taken branch is prunable.","kind":"decision","label":"Convene board review and approve risk strategy","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-render-package","coach-item-update","coach-items-link"]}},"id":"convene-board-review-and-approve-strategy"},{"data":{"description":"Agent packages the board's requested revisions to the risk strategy, material policies, or framework adjustments, routes them to management, and re-secures the updates; human sponsor confirms the revisions are addressed and the deferral is recorded as a board directive","instructions":"**Objective** — Turn the board's revision comments and conditions into a specific, tracked rework package, and record the board's return-for-revision as an open directive for re-presentation at a future session — so every board condition is addressed and the deferral is minuted, without the strategy being treated as approved.\n\n**Inputs**\n- the step result and conditions from the convene decision — the specific reasons for the return.\n- The exact version of the risk strategy, material policies, and framework adjustments the board reviewed (the baseline for the change log).\n- The accountable management owners for each item and the date of the next scheduled or specially convened session.\n\n**Procedure**\n1. Translate the board's comments and conditions into specific, assignable revisions — not \"strengthen the appetite statement\" but the exact clause, threshold, or policy section to change and the outcome required. Ambiguous returns come back wrong.\n2. Route each revision to its accountable management owner with the board's rationale and a required response date, and track each to completion. Ownership sits with management (first and second line), not the governance office — the office facilitates and tracks.\n3. Apply the returned updates and record a change log against the exact version the board reviewed: what changed, why, and which board condition it answers. An unmapped condition is an open item, not a closed one.\n4. Re-circulate the revised strategy, policies, and adjustments to the executive sponsor and prepare them for re-presentation at the next scheduled or specially convened session. Approval is not re-secured here; it happens when the board next sits.\n5. Record the board's return-for-revision as an open directive so it flows into the directives register and the minutes and remains open until a future board approves.\n\n**Record in AssureSwarm**\n- Route each revision to its accountable owner with the board's rationale and response date (coach-notify), and capture each participating owner’s returned revision in the native step result and attached revised document; use native approval for ownership acceptance.\n- Attach the change log mapped to the reviewed baseline version and to each board condition as a document (coach-document-upload). The return-for-revision is itself a board directive: it is created as an open Issue item during directive capture in the minutes checkpoint (issue_type: observation, source: management_identified) so it enters the directives register and stays open until a future board approves — this step records it so capture picks it up.\n\n**Exit criteria** — The executive sponsor has confirmed every board condition and comment is resolved and the change log is complete; the revised strategy, policies, and adjustments are ready to return to the board; and the return-for-revision is recorded as an open directive for re-presentation that remains open until the board approves.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` routes each revision to its accountable management owner with the board's rationale and response date and keeps a logged chase trail to completion.","label":"Return to management for revision","performedBy":{"primitives":["coach-document-upload","coach-form-fill","coach-notify"]}},"id":"return-to-management-for-revision"},{"data":{"description":"Chair and Corporate Secretary: Adopt the accurate deliberation, qualification and decision record with every directive assigned and linked to its authority.","instructions":"**Objective** — Capture every board directive and adjustment and adopt minutes that link each decision, condition and deferral to the supporting evidence.\n\n**Inputs**\n- The board's decision record and conditions from the convene step (approval-with-conditions or return-for-revision) and, where in scope, the approved framework adjustments from the evaluation step.\n- The open directives register from prior cycles, for linkage and cumulative visibility.\n- The supporting materials that authorize each directive: pack sections, policy versions, and minute references.\n- The deliberation record from the convene step (questions, dissent, conditions), the decisions, and the directives captured in this checkpoint.\n- The attendance and composition/independence evidence from the qualification review, and the charter's quorum requirement.\n- The supporting materials: the oversight pack, management reports, the risk strategy and material policies, and the framework evaluation where in scope.\n\n**Procedure**\n*Autonomous preparation incorporates Capture board directives and adjustments; Chair and Corporate Secretary reviews the combined evidence.*\n1. Record each adjustment the board directed: changes to risk strategy and direction; conditions attached to approved material policies; remediation the board required of the internal-control or cybersecurity program; and any deferral or return-for-revision directive from the review. A condition on an approval is itself a directive — capture it, do not fold it silently into the policy.\n2. Where the annual framework evaluation was in scope, record each governance-and-management-framework adjustment the board approved — to direction, decision rights, accountability structures, policies, or culture — as its own tracked change.\n3. Create each directive and adjustment as an action item carrying an accountable owner, a due date, a status, and a link to the minute reference and the supporting material that authorizes it. An owner-less or date-less directive is how board direction quietly dies.\n4. Link the new directives to the open items from prior cycles so the board's cumulative directions are visible in one register — repeat directives and chronic slippage should be obvious at a glance.\n5. Reconcile the captured set back against the decision record and conditions: every item the board directed appears exactly once, and nothing directed is missing.\n6. Draft the minutes to document the oversight activities and decisions: the pack reviewed; the risk-management-outcomes and program-effectiveness discussion; the risk-strategy and material-policy approval or deferral with conditions; the directed adjustments; and, where in scope, the framework evaluation and approved adjustments. Minute the decisions and the basis for them — enough to show the board engaged, without a verbatim transcript that creates needless discovery risk.\n7. Record the governance facts that make the record defensible: attendance, quorum met per the charter, independence and conflict declarations, and any recusals on specific matters. These lines are what evidence that an independent and appropriately expert body — not management — exercised the oversight (COSO IC Principle 2 / SOC 2 CC1.2).\n8. Assemble and link the supporting materials as the evidentiary appendix — the pack, management reports, the approved risk strategy and material policies, and the framework evaluation — so each decision in the minutes points to the material it rested on.\n9. Route the draft minutes to the chair and Corporate Secretary for review, and capture formal adoption (at this meeting or the next), including the adoption date. Draft minutes are not yet the record; adoption makes them official.\n\n**Record in AssureSwarm**\n- Create each directive and adjustment — including any return-for-revision deferral — as an Issue item: issue_type: observation, source: management_identified, issue_owner (the accountable owner), target_remediation_date (the due date), with the directive text and the minute/authorization reference in description (coach-item-create).\n- Link each new directive Issue to the prior-cycle directive Issues to form the cumulative open register, and — where a directive changes a specific control, risk, or policy — to the Control, Risk, or Policy item it targets (coach-items-link).\n- Attach the draft and then the adopted board/committee minutes, with the adoption date, as documents on this step (coach-document-upload).\n- Link the supporting materials as the minutes' evidentiary appendix (coach-document-link): the oversight pack and management reports, the approved risk strategy and material policies (the Policy items), and the framework evaluation where in scope — so each decision in the minutes points to the material it rested on.\n\n**Exit criteria**\nAdopt the accurate deliberation, qualification and decision record with every directive assigned and linked to its authority.\nThe Corporate Secretary has confirmed every directed adjustment and approved framework change is a tracked item with an owner, a due date, and a traceable link to the board's decision; the new directives are linked into the cumulative register; and the captured set reconciles to the decision record with nothing dropped.\nThe chair and Corporate Secretary have confirmed the minutes and materials accurately and completely document the oversight activities and decisions and evidence the body's independence and expertise; attendance, quorum, declarations, and recusals are recorded; the supporting appendix is linked; and the minutes are adopted with a date as the official record.","label":"Record oversight minutes and materials","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"record-oversight-minutes-and-materials"},{"data":{"description":"Agent drives implementation of the approved framework adjustments and board directives across the organization, stands up the tracking dashboard, and assembles and archives the complete oversight record while scheduling the next cycle; human governance owner confirms implementation is on plan and the durable record is complete, which closes the cycle","instructions":"**Objective** — Launch implementation of the board-approved framework adjustments and directed strategy and direction changes across the accountable functions, stand up tracking that shows their true status, and close the cycle with a durable archived oversight record and the next meetings scheduled — the governance owner's confirmation recorded here is the closure.\n\n**Inputs**\n- The tracked directive and adjustment items from the directive-capture stage of the adopted minutes, each with an owner, a due date, and an authorization link.\n- The approved framework-adjustment schedule from the evaluation step — the layers to change: direction, decision rights, accountability structures, policies, processes, and culture.\n- The governance register, for logging progress and evidence.\n- Every other artifact from this cycle: the oversight pack; the composition and independence evidence; the framework evaluation where in scope; the adopted minutes and supporting materials; and the board's approvals and conditions.\n- The corporate records-retention schedule (board minutes are commonly retained permanently and SOX-relevant records seven years) and the designated evidence repository.\n- The board oversight calendar and the policy cadence for scheduling the next cycle.\n\n**Procedure**\n_After the accountable implementation commitments, items 5–9 retain the adopted record and schedule the next cycle._\n1. Launch implementation of the approved framework adjustments — updating direction, decision rights, accountability structures, policies, processes, and culture programs as the board approved and as context, strategy, and regulation require. Sequence dependencies: a decision-rights change usually precedes the policy edits that encode it.\n2. Drive the board's directed strategy and direction changes into the accountable functions, and confirm each owner has accepted their action item and due date. Unaccepted ownership is not ownership — an item no one has agreed to owns nothing.\n3. Stand up or refresh a directives-and-adjustments tracking dashboard showing every open board directive and framework change with its owner, due date, and status, and surface slipping items with a proposed recovery path rather than just flagging them red.\n4. Log implementation progress and evidence in the governance register so the next cycle can confirm closure against a real trail — attach status updates and comments to the individual directive items, not to the dashboard.\n5. Confirm the cycle is closable: the minutes are adopted, the board's approvals and conditions are recorded, and every open directive has a tracked owner and due date. Open directives carry forward across cycles — they do not block closure, but each must be owned. This cycle produces an owned, OPEN register; an individual directive's own closure is confirmed in a later cycle, not here.\n6. Assemble the complete oversight record — composition and independence evidence, the pack, the framework evaluation where in scope, the adopted minutes and appendix, approvals and conditions, and the directives register — and test it against the no-oral-explanation bar: could an auditor or regulator reconstruct what the board reviewed and decided, and that the body was independent and expert, from this record alone?\n7. Archive the record to the retention location with its version, meeting date, adoption date, and applicable retention period, and verify retrievability by opening the archived copy rather than trusting the upload confirmation. Record the archive confirmation and reference; the archived minutes are the fixed record, so any later correction is a new, dated addendum approved by the chair — never a silent edit to the archived file.\n8. Update the downstream registers so work references the current board-approved versions: the risk strategy and material-policy library, the control inventory, and the governance-framework documentation.\n9. Update the oversight calendar and schedule the next quarterly board and committee meetings and the next at-least-annual framework effectiveness evaluation, carrying every open directive forward as an input to the next cycle.\n\n**Record in AssureSwarm**\n- Update each directive Issue as owners accept and progress is made — Issue.status, owner-acceptance, and progress notes, with evidence and comments attached to the item (coach-item-update); create any newly identified sub-task or progress-log Issue items (coach-item-create). Closure of an individual directive sets Issue.actual_remediation_date in a later cycle, not here.\n- Build or refresh the directives-and-adjustments tracking dashboard over the open directive Issues (coach-dashboard-create), and monitor due dates to surface slipping items with recovery paths (coach-workflow-monitor).\n- Export the full workflow instance into the archive package as the durable audit trail (coach-workflow-export), and record the archive confirmation, reference, and retention period on this step (coach-document-upload).\n- Repoint the downstream registers at the board-approved versions (coach-document-link): the risk-strategy and material-policy library is the approved Policy items (already carrying approved_by/version/next_review_date from the convene step), the control inventory is the Control items, and the governance-framework documentation and oversight calendar are linked documents (no native Policy home for RACI maps, no native calendar object); link the archived record to the governance register.\n\n**Exit criteria** — The Chief Governance Officer has confirmed the approved framework adjustments and board directives are being implemented across the organization on plan, every open item has an owner who has accepted it, the tracking dashboard reflects true status, and slipping items are owned and on a credible recovery path; the archived record is verified retrievable and self-contained — composition and independence, pack, minutes and materials, approvals, directives, and any framework evaluation and adjustments — and durable enough to serve as evidence without oral explanation; downstream registers reference the board-approved versions; open directives are carried forward; and the next quarterly meetings and annual framework evaluation are scheduled, which closes the cycle.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-scan` tracks the open directives and framework adjustments against their due dates and surfaces slipping items for the tracking dashboard.","label":"Implement and track directives and framework adjustments","performedBy":{"primitives":["coach-item-create","coach-dashboard-create","coach-item-update","coach-workflow-scan","coach-workflow-export","coach-document-upload"]}},"id":"implement-and-track-framework-adjustments"}],"sourceTemplateId":"workflow-library:grc-board-risk-internal-control-oversight-cycle"}
