{"description":"Code of Conduct & Workforce Accountability Cycle as a decision-aware workflow that runs on an existing ethics Process item (\"Ethics & Code of Conduct Program\", process_type: business_process, frequency: annual): each annual cycle is a workflow instance attached to that Process, and the archived instances on it ARE the ethics register - version history plus the open-deviation log. The code of conduct and the rules of behavior are Policy items (policy_type: policy and procedure) enriched each cycle - never recreated - and the tone-at-the-top and acknowledgment Controls (UC-GOV-04, UC-GOV-07) are linked to the Process via item relationships. The cycle reissues the code and rules of behavior, secures leadership adoption, communicates expectations to personnel and business partners, gates access on acknowledgment, and evaluates adherence - routing violations through the documented disciplinary process and remediating deviations timely, with deviations and violations recorded as Issue items carrying the full remediation lifecycle. Named deliverables: the reissued code of conduct and rules of behavior (Policy items plus redline/change summary), the leadership adoption decision, the acknowledgment coverage report with access-gating evidence, the deviation and violation inventory (Issues), the disciplinary and remediation outcomes, and the archived self-contained cycle evidence package. In scope: one annual accountability cycle (a full reissue or an update-driven re-acknowledgment) covering all in-scope personnel and the business-partner populations bound by the code. Out of scope: the ethics-hotline intake that feeds reported concerns - an input, not a step here. No upstream workflow is required to start the cycle; it is triggered by its annual cadence or by a material change to the code or rules of behavior. Downstream, the operational access-provisioning system consumes this cycle's acknowledgment gate - the workflow's terminal handoff - before it grants access.","edges":[{"id":"e-secure-leadership-review-and-adoption-run-acknowledgment-campaign-and-access-gating","label":"Adopted","source":"secure-leadership-review-and-adoption","target":"run-acknowledgment-campaign-and-access-gating","whenValue":"adopted"},{"id":"e-secure-leadership-review-and-adoption-resolve-leadership-revisions","label":"Revise","source":"secure-leadership-review-and-adoption","target":"resolve-leadership-revisions","whenValue":"revise"},{"id":"e-resolve-leadership-revisions-run-acknowledgment-campaign-and-access-gating","source":"resolve-leadership-revisions","target":"run-acknowledgment-campaign-and-access-gating"},{"id":"e-run-acknowledgment-campaign-and-access-gating-determine-disciplinary-and-remediation-response","source":"run-acknowledgment-campaign-and-access-gating","target":"determine-disciplinary-and-remediation-response"},{"id":"e-determine-disciplinary-and-remediation-response-execute-disciplinary-actions","label":"Disciplinary action","source":"determine-disciplinary-and-remediation-response","target":"execute-disciplinary-actions","whenValue":"disciplinary_action_required"},{"id":"e-determine-disciplinary-and-remediation-response-verify-timely-deviation-remediation","label":"Remediation only","source":"determine-disciplinary-and-remediation-response","target":"verify-timely-deviation-remediation","whenValue":"remediation_without_discipline"},{"id":"e-execute-disciplinary-actions-verify-timely-deviation-remediation","source":"execute-disciplinary-actions","target":"verify-timely-deviation-remediation"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-GOV-04","UC-GOV-07"],"department":"hr","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-code-of-conduct-workforce-accountability-cycle","contentDigest":"sha256:297e477eb945b39af22edd0a8fe11617b292c0bd8882d2eaaa9eeb9d06a03f41","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:297e477eb945b39af22edd0a8fe11617b292c0bd8882d2eaaa9eeb9d06a03f41","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-code-of-conduct-workforce-accountability-cycle"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-code-of-conduct-workforce-accountability-cycle","source":"coworkcanvas-gallery","standards":["soc2","coso-ic","coso-erm","nist-csf-2"],"teams":["hr","compliance-legal"]},"name":"Code of Conduct & Workforce Accountability Cycle","nodes":[{"data":{"decisionField":"adoption_decision","description":"Accountable leadership body with HR and ethics subject-matter input: Reconcile the refreshed code with enforceable performance, incentive and disciplinary mechanisms and adopt it with visible sponsorship or require changes.","formData":{"fields":[{"key":"adoption_decision","label":"Leadership adoption decision","options":[{"label":"Adopted by leadership","value":"adopted"},{"label":"Revision required before adoption","value":"revise"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Refresh and reconcile the code, rules of behavior and accountability mechanisms, then obtain leadership adoption or a specific revision request.\n\n**Decision criteria**\nInputs for preparation: - The current in-force code of conduct and documented rules of behavior - the Policy items on the anchor Process (policy_type: policy for the code, procedure for the rules of behavior), enriched each cycle rather than recreated. These are the workflow's own starting inputs; no upstream workflow feeds this cycle - it is triggered by annual cadence or a material change.\n- The prior published version, for a line-by-line redline (the prior value/attached document on those Policy items), and the ethics register - the prior archived workflow instances on the anchor Process (version history) plus the open Issue items linked to it (the open-deviation log).\n- Applicable frameworks to check content against, carried on the linked Control items' framework multiselect (soc2, coso-ic, coso-erm, nist-csf-2): SOC 2 CC1.1 (commitment to integrity and ethical values) and CC1.4/CC1.5 (accountability), COSO Internal Control principles 1 and 5, COSO ERM governance-and-culture components, and NIST CSF 2.0 Govern (GV.RR, GV.OC) for leadership's cyber-risk accountability.\n- Any regulatory change, incident finding (an Issue item on the anchor Process), or new business-partner obligation that must be reflected this cycle - regulatory/partner changes attached as notes/documents on this step.\n- The documented disciplinary process - a Policy item (policy_type: procedure) carrying its severity tiers, decision rights, and timeliness expectations - together with the current performance-measure and evaluation artifacts and the incentive and compensation structures, which have no native item type and arrive as documents on this step (PBC/HR uploads).\n- The in-force code and rules of behavior - the Policy items on the anchor Process. (This step maps the accountability mechanisms against the code framework and is prepared alongside the code refresh; the two are reconciled together when leadership adopts the package, so this step does not wait on the refreshed text to begin.)\n- The ethics register (prior archived instances on the anchor Process) and any prior misalignment findings between incentives and the code - open Issue items linked to the Process.\n\n*Autonomous preparation incorporates Refresh code of conduct and rules of behavior; Link performance, incentives, and disciplinary process; Accountable leadership body with HR and ethics subject-matter input reviews the combined evidence.*\n1. Draft the reissued code so it explicitly states the organization's commitment to integrity, its core ethical values, and the desired risk-aware, continually improving culture, and names leadership's responsibility and accountability for cybersecurity and internal-control risk.\n2. Refresh the documented rules of behavior every person must follow, and the defined expectations that require everyone to apply information security in accordance with established policies and procedures and to meet their internal-control responsibilities.\n3. Reconcile the draft against the prior version and the frameworks above, producing a redline plus a change summary that flags every substantive change; mark each flagged change as material (requires re-acknowledgment by existing personnel) or non-material (informational).\n4. Capture the version identifier, an effective-date placeholder, and the acknowledgment scope - who must acknowledge, and whether existing personnel must re-acknowledge because a material change was flagged during the redline materiality review.\n5. Retrieve the performance-measure, incentive, and disciplinary-process artifacts and map how each one reinforces the code and the rules of behavior, so accountability is carried by the surrounding mechanisms and not by the code text alone.\n6. Update and link the documented disciplinary process for violations - severity tiers, decision rights, and timeliness expectations - to the code and rules of behavior so the consequences for violations are explicit and consistently applied.\n7. Confirm performance measures and incentives reward adherence to the code and do not inadvertently reward behavior that conflicts with it; record any misalignment as an item for HR to resolve.\n8. Establish the linked relationships so the code, the rules of behavior, the performance and incentive measures, and the disciplinary process are traceable to one another as one accountability system.\n9. Assemble the leadership adoption package - the refreshed code and rules of behavior from the code refresh in this checkpoint, the change summary, the accountability linkage to performance, incentives, and the disciplinary process from the accountability mapping in this checkpoint, and the communication and acknowledgment plan.\n10. Cross-check that every tone-at-the-top element is present: the statement of integrity and ethical values, the risk-aware-culture expectations, leadership's accountability for cybersecurity and internal-control risk, and the periodic-evaluation commitment.\n11. Draft the leadership review brief asking leadership to review the code, demonstrate visible commitment, and formally adopt it as the standard of conduct for the organization; route it to the accountable body and capture the deliberation record.\n\n- Select **Adopted by leadership** (`adopted`) when leadership has reviewed the package, every tone-at-the-top element in the cross-check is present, and the body formally adopts the code and commits visible sponsorship. This routes the cycle to communication.\n- Select **Revision required before adoption** (`revise`) when leadership attaches conditions or any required element is missing, weak, or inconsistent - e.g., an absent risk-aware-culture statement, an incomplete accountability linkage, or a disputed disciplinary consequence. This routes to \"Resolve leadership revisions\" before communication.\n\n**Record in AssureSwarm**\n- Upload the reissued code, the rules of behavior, and the redline/change summary to this step as DOCX/PDF documents (step document).\n- Enrich the two Policy items - the code-of-conduct Policy (policy_type: policy) and the rules-of-behavior Policy (policy_type: procedure): set version, effective_date (placeholder until adoption), policy_owner, review_frequency: annual, next_review_date, framework (soc2, coso-ic, coso-erm, nist-csf-2), and domains (governance_policy_oversight, awareness_training) (item field update). On the first-ever cycle these Policy items are created (item create).\n- The material-vs-non-material change list and the acknowledgment scope have no native Policy field, so record them on the redline/change-summary document attached above (step document - honest fallback).\n- Link the code-of-conduct and rules-of-behavior Policy items, the disciplinary-process Policy item, and the UC-GOV-04/UC-GOV-07 Control items to the anchor Process as one traceable relationship set (item relationships - Policy ↔ Control, Policy ↔ Process).\n- Attach the performance-measure, incentive/compensation, and disciplinary-process artifacts to this step; performance and incentive structures have no native item type (step document; document link).\n- Record any incentive-vs-code misalignment as an Issue (issue_type: observation, source: management_identified, issue_owner) linked to the anchor Process, for HR to resolve (item create).\n- Submit the `adoption_decision` SELECT (adopted | revise) on the step form.\n- Record the rationale, any conditions, and evidence references in the step result, and name the adopting leader or body in the step's approver record (step form).\n- Upload the adoption package and link it to the code-of-conduct and rules-of-behavior Policy items and the anchor Process (document upload; item relationship).\n- On `adopted`, stamp `approved_by` and confirm `effective_date` on the code-of-conduct and rules-of-behavior Policy items (item field update).\n\n**Exit criteria**\nReconcile the refreshed code with enforceable performance, incentive and disciplinary mechanisms and adopt it with visible sponsorship or require changes.\nThe ethics owner confirms the refreshed code and rules of behavior are complete and that integrity, ethical-values, risk-aware-culture, and control-responsibility expectations are all present and clearly stated; the change summary correctly classifies each change as material or non-material; the code-of-conduct and rules-of-behavior Policy items are versioned and the documents are attached.\nThe HR partner and ethics owner confirm the disciplinary process is documented, current, and enforceable; performance measures and incentives are aligned to the code with any misalignment logged for resolution; and the accountability linkage is complete and traceable.\nThe `adoption_decision` form is submitted with a rationale and a named decision owner, and the branch not selected is prunable.","kind":"decision","label":"Secure leadership review and adoption","performedBy":{"primitives":["coach-document-upload","coach-item-create","coach-item-update","coach-items-link"]}},"id":"secure-leadership-review-and-adoption"},{"data":{"description":"Agent applies leadership's revisions to the code and accountability system and re-secures adoption; human sponsor confirms the conditions are resolved","instructions":"**Objective** — Apply leadership's revisions to the code and accountability system, re-run the completeness check, and re-secure formal adoption so the cycle can proceed to communication with a clean, adopted version.\n\n**Inputs**\n- The `revise` decision record from \"Secure leadership review and adoption\" - leadership's comments, conditions, and the specific elements they flagged (the step result on that step's form).\n- The exact version of the code and rules-of-behavior Policy items, and the accountability linkage, that leadership reviewed - the Policy items' reviewed `version`, so changes are tracked against a known baseline.\n\n**Procedure**\n1. Translate each leadership comment and condition into a specific revision to the code, the rules of behavior, the expectations, or the linkage to performance, incentives, and discipline.\n2. Apply the revisions and record a change log showing what changed and why, against the version leadership reviewed.\n3. Re-run the tone-at-the-top completeness check (integrity and ethical values, risk-aware-culture expectations, leadership cyber/internal-control accountability, periodic-evaluation commitment) to confirm no required element was dropped or reopened.\n4. Re-circulate the revised code to the sponsor and, where required, back to the leadership body for formal adoption; capture the confirmation.\n\n**Record in AssureSwarm**\n- Upload the revised code and the change log to this step as DOCX/PDF documents (step document).\n- Bump the code-of-conduct and rules-of-behavior Policy items' `version` and refresh `effective_date`/`approved_by` on re-adoption (item field update).\n- Record each condition’s resolution in the native result and re-adoption in native approvals.\n\n**Exit criteria** — The leadership sponsor confirms every condition and comment is resolved, the change log is complete against the reviewed baseline, and the revised code is adopted and cleared to be communicated across the organization.","label":"Resolve leadership revisions","performedBy":{"primitives":["coach-document-upload","coach-form-fill","coach-item-update"]}},"id":"resolve-leadership-revisions"},{"data":{"description":"Ethics owner with accountable access and personnel managers: Resolve nonresponse and access-granted-without-acknowledgment exceptions against the approved population and material-change scope.","formData":{"fields":[{"key":"acknowledgment","label":"I have read the Code of Conduct and agree to abide by it","required":true,"type":"checkbox"},{"helperText":"Enter \"None\" if you have nothing to disclose.","key":"conflicts","label":"Conflicts of interest to disclose (outside employment, financial or family interest in a customer, vendor or competitor)","required":true,"type":"textarea"},{"key":"understood_reporting","label":"I know how to report a suspected violation, including one involving senior leadership","required":true,"type":"checkbox"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Communicate the adopted expectations, collect required acknowledgments and resolve exceptions while enforcing acknowledgment before access.\n\n**Inputs**\n- The adopted code and rules-of-behavior Policy items with their stamped `effective_date` - either the `adopted` output of \"Secure leadership review and adoption\" or the re-adopted version from \"Resolve leadership revisions\".\n- The in-scope personnel roster - a CSV/XLSX upload on this step, since there is no native Personnel type - and the business-partner populations bound by the code, drawn from the Vendor items where third parties are maintained as a vendor register, each with their distribution channels.\n- The change summary (the redline document from the code refresh in this checkpoint), so the message can highlight what changed for existing personnel.\n- The communicated, adopted code-of-conduct Policy item published in this checkpoint, with its stamped `effective_date` and `version`.\n- The change summary's material-change list (on the redline document), which determines who must re-acknowledge.\n- The in-scope population roster (CSV upload - no native Personnel type), the new-joiner and role-change feed (an extract uploaded as evidence on this step), and the operational access-provisioning system - an external system that consumes this cycle's acknowledgment gate downstream.\n\n**Procedure**\n*Autonomous preparation incorporates Communicate expectations to personnel and partners; Ethics owner with accountable access and personnel managers reviews the combined evidence.*\n1. Publish the adopted code and rules of behavior with their effective date, and prepare the tone-at-the-top communication conveying leadership's expectations for integrity, ethical behavior, and a risk-aware, continually improving culture.\n2. Communicate those expectations to all personnel and to the in-scope business partners, tailoring the partner message to the code-of-conduct and rules-of-behavior obligations that apply to third parties.\n3. Route the communication through leaders so the message is visibly owned at the top rather than issued only by the ethics function, reinforcing consistent leadership behavior.\n4. Track distribution reach against the in-scope personnel and business-partner populations and log the communication as evidence.\n5. Create and issue the acknowledgment of the code and rules of behavior to every in-scope person, requiring the documented rules of behavior to be acknowledged before access to systems and information is granted.\n6. Drive re-acknowledgment from existing personnel wherever the change summary flagged a material update, recording each acknowledgment with its person, code version, and timestamp.\n7. Enforce the access gate: identify new joiners and role changes whose access must not be granted until acknowledgment is captured, and flag any granted-without-acknowledgment exception for remediation.\n8. Track completion against the in-scope population, escalate non-responders through their managers, and compile the acknowledgment coverage report.\n\n**Record in AssureSwarm**\n- Link the published code-of-conduct Policy item and the communication to the cycle record - the anchor Process and this workflow instance (document link; item relationship).\n- Record the communication-evidence - audience, channel, and reach vs. the in-scope population - as a document on this step; there is no native communications-evidence item type (step document - honest fallback).\n- Log any distribution gap (a segment the communication did not reach) as an Issue (issue_type: observation, source: management_identified) linked to the anchor Process for follow-up (item create).\n- Issue the tone-at-the-top notification to personnel and partners (notify).\n- Create the acknowledgment form keyed to the code-of-conduct Policy item's `version` (form create).\n- The form on this step, answered by every employee, contractor and staffing-provider-supplied individual, captures their acknowledgment that they have read and will abide by the code, any conflicts of interest to disclose, their confirmation that they know how to report a suspected violation including one involving senior leadership, ; bind each response to its named assignment, code version and native submission timestamp, then export the acknowledgment coverage report as an XLSX/CSV document on this step (form fill; step document).\n- Record each granted-without-acknowledgment exception and non-responder disposition as an Issue (issue_type: exception, source: management_identified, severity, issue_owner, identified_date) linked to the anchor Process (item create).\n\n**Exit criteria**\nResolve nonresponse and access-granted-without-acknowledgment exceptions against the approved population and material-change scope.\nConfirm the adopted code and the integrity and risk-aware-culture expectations reached all in-scope personnel and business partners, leadership visibly owns the message, and distribution reach is evidenced before acknowledgment begins.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` — issues the tone-at-the-top communication to the in-scope personnel and business-partner audiences and records delivery as reach evidence.\nAcknowledgments and required re-acknowledgments are captured with access gated before it is granted; the coverage report is complete; and every non-responder and every granted-without-acknowledgment exception has a disposition and an owner.\n\n**Form recipient** — Send the form to in-scope employees, contractors and staffing-provider personnel outside all ethics, HR, leadership, disciplinary and remediation executors in this workflow. Participating executors record their own acknowledgment and disclosures in native results.","label":"Run acknowledgment campaign and access gating","performedBy":{"primitives":["coach-document-upload","coach-item-create","coach-notify","coach-form-create","coach-form-fill"]}},"id":"run-acknowledgment-campaign-and-access-gating"},{"data":{"decisionField":"disciplinary_response","description":"HR or ethics decision authority: Substantiate deviations, compare prior cases and choose proportionate disciplinary or remediation responses under the documented severity and decision-rights rules.","formData":{"fields":[{"key":"disciplinary_response","label":"Disciplinary and remediation response","options":[{"label":"Disciplinary action required per process","value":"disciplinary_action_required"},{"label":"Remediation without formal discipline","value":"remediation_without_discipline"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Evaluate adherence and determine the evidenced, consistent disciplinary or remediation response to each substantiated deviation.\n\n**Decision criteria**\nInputs for preparation: - The acknowledgment coverage report (step document) and the exception Issues from \"Run acknowledgment campaign and access gating\" - the acknowledgment- and re-acknowledgment-gap signal.\n- Reported ethics concerns and hotline cases (the hotline is an external system; its case export is uploaded on this step), policy-violation reports, and control-responsibility failures attributable to individuals; already-substantiated prior items are open Issue items on the anchor Process.\n- The code-of-conduct and rules-of-behavior Policy items and the linked disciplinary-process Policy item, so each signal is assessed against a defined standard.\n\n*Autonomous preparation incorporates Evaluate adherence and detect deviations; HR or ethics decision authority reviews the combined evidence.*\n1. Compile adherence signals for the period: acknowledgment and re-acknowledgment gaps, reported ethics concerns and hotline cases, policy-violation reports, and individual control-responsibility failures.\n2. Assess each signal to hold individuals accountable for their internal-control and code responsibilities, separating substantiated deviations and violations from unsubstantiated or already-resolved items.\n3. Build the deviation and violation inventory with severity, the individuals or partners involved, the code or rule breached, and the supporting evidence; flag any item whose remediation timeliness clock has started.\n4. Prepare the routing recommendation and rationale for each item to support the disciplinary and remediation decision.\n5. Apply the documented disciplinary process to each substantiated item from the adherence evaluation in the response checkpoint - mapping severity to the process's tiers, decision rights, and timeliness expectations - and draft the proportionate response.\n6. For items warranting formal action, draft the disciplinary recommendation and its paired remediation actions; for items warranting correction only, draft the coaching and remediation plan.\n7. Assemble the evidence, the code or rule breached, and a consistency check against how comparable prior cases were handled, so consequences are applied evenly.\n\n- Select **Disciplinary action required per process** (`disciplinary_action_required`) when the documented disciplinary process calls for formal consequences for the violation - severity, repetition, or willfulness crosses the tier threshold that mandates discipline. This routes to \"Execute disciplinary actions\".\n- Select **Remediation without formal discipline** (`remediation_without_discipline`) when the deviation warrants timely correction and coaching but not formal discipline under the process. This routes directly to \"Verify timely deviation remediation\".\n\n**Record in AssureSwarm**\n- Scan the workflow and monitoring surface for adherence signals (workflow scan) and query the acknowledgment coverage, hotline case export, and violation data (query data).\n- Record the deviation and violation inventory as Issue items (issue_type: finding or exception, severity, source: management_identified, description = party involved + rule breached, root_cause, issue_owner, identified_date) (item create).\n- Link each Issue to the Control it breaches and to the anchor Process (item relationship - Issue ↔ Control).\n- Submit the `disciplinary_response` SELECT (disciplinary_action_required | remediation_without_discipline) on the step form.\n- Record the rationale with evidence references in the step result, including the consistency check against prior cases, and name the HR or ethics decision owner in the step's approver record (step form).\n- Stamp the routing decision onto each substantiated deviation Issue's `management_response` so the response is traceable per item (item field update).\n\n**Exit criteria**\nSubstantiate deviations, compare prior cases and choose proportionate disciplinary or remediation responses under the documented severity and decision-rights rules.\nThe ethics owner and HR partner confirm the adherence evaluation is complete for the period, the inventory is accurate and evidenced, and each item is ready for a disciplinary and remediation decision.\nThe `disciplinary_response` form is submitted with a rationale and named owner, and the branch not selected is prunable.","kind":"decision","label":"Determine disciplinary and remediation response","performedBy":{"primitives":["coach-workflow-scan","coach-query-data","coach-item-create","coach-items-link","coach-item-update"]}},"id":"determine-disciplinary-and-remediation-response"},{"data":{"description":"Agent packages the disciplinary actions for HR execution and records the consequences applied; human HR partner confirms the actions were carried out per the documented process","instructions":"**Objective** — Execute the approved disciplinary actions and record the consequences applied, so violations demonstrably carry real consequences and accountability is enforced per the documented process.\n\n**Inputs**\n- The `disciplinary_action_required` decision record and the approved disciplinary recommendations from \"Determine disciplinary and remediation response\".\n- The documented disciplinary-process Policy item (policy_type: procedure) - severity tiers, decision rights, approvals, confidentiality requirements - and the accountable managers.\n- The paired remediation actions drafted alongside each disciplinary recommendation.\n\n**Procedure**\n1. Package each approved disciplinary action for HR execution - the violation, the severity tier, the consequence, and the accountable manager - in line with the documented disciplinary process.\n2. Record the disciplinary consequences applied to each individual, with dates and approvals, as evidence that violations carry consequences and accountability is enforced.\n3. Capture the paired remediation actions that must accompany the discipline so the underlying control or behavior gap is corrected, not just penalized.\n4. Update the individuals' accountability records, respecting the confidentiality the disciplinary process requires.\n\n**Record in AssureSwarm**\n- Enrich each substantiated deviation Issue: set `management_response` (the consequence applied), `remediation_plan` (the paired remediation), `target_remediation_date`, and `issue_owner` (item field update); create a new Issue for any violation not already inventoried (item create).\n- Attach the confidential disciplinary record - tier, consequence, dates, and approvals - as an access-restricted document on this step; there is no native HR-case type, so it is kept access-restricted here (step document).\n- Record execution status per action in the native step result, with sign-off in native approvals.\n\n**Exit criteria** — The HR partner confirms each disciplinary action was executed per the documented process, consequences and approvals are recorded, and the paired remediation is assigned before remediation timeliness is verified.","label":"Execute disciplinary actions","performedBy":{"primitives":["coach-item-create","coach-form-fill","coach-item-update","coach-document-upload"]}},"id":"execute-disciplinary-actions"},{"data":{"description":"Agent tracks every deviation and violation to closure, confirms remediation was timely, and assembles and archives the self-contained cycle evidence package to the retention location; human confirms all items are remediated within the required timeframe and the record is durable, which closes the cycle","instructions":"**Objective** — Track every deviation and violation to remediation closure, confirm remediation was timely, and archive the complete cycle record — so the cycle evidences that deviations were remediated on a timely basis and the closure approval recorded here formally ends the accountability cycle. This step reconverges both response branches - items that went through formal discipline and items handled by remediation without discipline.\n\n**Inputs**\n- The deviation and violation inventory from the adherence evaluation in the response checkpoint - the Issue items with their remediation fields.\n- The executed disciplinary actions and their paired remediation from \"Execute disciplinary actions\" - the enriched Issues on the disciplinary branch.\n- The remediation-only items routed directly from \"Determine disciplinary and remediation response\" (the remediation-without-discipline branch).\n- The timeliness expectations defined in the disciplinary and remediation process.\n- The full cycle trail that drains through this checkpoint: the adopted code and rules of behavior, the leadership adoption decision, the communication evidence, the acknowledgment and re-acknowledgment coverage with access gating, the accountability linkage, and the adherence evaluation.\n- The retention schedule and the linked records to update: the policy library (the code-of-conduct and rules-of-behavior Policy items), the control inventory (the UC-GOV-04/UC-GOV-07 Control items), and the external access-provisioning process that depends on the acknowledgment gate.\n\n**Procedure**\n_Items 5–8 close the workflow (folded from the former \"Close and archive\" step); the approval recorded here is the closure._\n1. Track every inventory item - whether it went through formal discipline or remediation without discipline - to remediation closure, recording the action taken, the owner, and the completion date.\n2. Measure remediation timeliness against the process's timeliness expectations, and flag any overdue or at-risk item with a corrective escalation.\n3. Confirm recurring or systemic deviations are fed back into the code, the rules of behavior, the communication, or the training so the culture continually improves rather than repeating the same failures.\n4. Compile the remediation-closure dashboard and the evidence that deviations were remediated on a timely basis.\n5. Assemble the complete cycle record from the artifacts above into one package with version, adoption and effective dates, and the applicable retention period.\n6. Archive the record to the retention location as evidence and link it to the ethics register.\n7. Update linked records - the policy library, the access-provisioning process that depends on the acknowledgment gate, and the control inventory - so downstream work references the current adopted version and any open remediation items.\n8. Communicate the adopted code, its effective date, the acknowledgment status, and the next annual cycle date to stakeholders.\n\n**Record in AssureSwarm**\n- On each deviation and violation Issue, set `actual_remediation_date` and `verified_date` and advance status to closed/verified; record overdue-item escalations on the same Issues (item field update).\n- Build the remediation-closure dashboard over those Issues, tracking status, owner, and timeliness across both branches (dashboard create).\n- Query the deviation Issues to measure closure and timeliness and to surface overdue items (query data).\n- Export the assembled cycle record to the retention location; the archived workflow instance on the anchor Process IS the ethics-register entry for this cycle (workflow export).\n- Link the archived record to the anchor Process, the code-of-conduct and rules-of-behavior Policy items (policy library), and the UC-GOV-04/UC-GOV-07 Control items (control inventory), so downstream references the adopted version (document link; item relationship).\n\n**Exit criteria** — Every deviation and violation is remediated within the required timeframe, overdue items are escalated and owned, and systemic issues are routed back into the framework, so timely remediation of deviations is evidenced; and the archived record is self-contained and durable enough to serve as audit and regulatory evidence without oral explanation - adopted code and rules of behavior, leadership adoption, communication, acknowledgment coverage with access gating, accountability linkage, adherence evaluation, and disciplinary and remediation outcomes - which formally closes the accountability cycle.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-export` — packages the full cycle trail into a single retention-ready evidence export with versions and dates.","label":"Verify timely deviation remediation","performedBy":{"primitives":["coach-dashboard-create","coach-query-data","coach-item-update","coach-workflow-export","coach-document-upload","coach-items-link"]}},"id":"verify-timely-deviation-remediation"}],"sourceTemplateId":"workflow-library:grc-code-of-conduct-workforce-accountability-cycle"}
