{"description":"Combined Assurance Mapping as a decision-aware workflow. Each cycle runs as one workflow instance attached to an Audit item created for the cycle (audit_type: advisory, scope = the combined-assurance mapping scope for the period, period_start/period_end = the cycle period) — no other Studio type represents an assurance-coordination cycle, so the workflow enriches that Audit item rather than any pre-existing engagement. In scope: mapping assurance coverage across the Three Lines of Defense for the confirmed risk universe and entities this cycle — cataloging assurance providers, mapping their coverage onto the risk universe, assessing reliance, identifying gaps and duplication, coordinating coverage plans, publishing the combined assurance map, and preparing audit-committee reporting inputs. Out of scope: performing the underlying assurance engagements themselves (owned by internal audit, second-line functions, and external providers) and any risk, entity, or provider not named in this cycle's confirmed scope. It consumes the risk universe and residual positions (Risk items with their residual_rating and treatment) from the upstream Enterprise Risk Assessment & Portfolio Oversight Cycle and hands its named deliverables — the published combined assurance map, the reliance conclusions, and the gap action plans — to the downstream Quarterly Board & Audit-Committee GRC Reporting workflow rather than duplicating repeated work.","edges":[{"id":"e-screen-role-collisions-and-self-review-assess-reliance","source":"screen-role-collisions-and-self-review","target":"assess-reliance"},{"id":"e-assess-reliance-coordinate-coverage-plans","source":"assess-reliance","target":"coordinate-coverage-plans"},{"id":"e-coordinate-coverage-plans-classify-disposition","source":"coordinate-coverage-plans","target":"classify-disposition"},{"id":"e-classify-disposition-create-action-plan","label":"Action","source":"classify-disposition","target":"create-action-plan","whenValue":"gaps"},{"id":"e-classify-disposition-handoff-to-related-workflow","label":"Clear","source":"classify-disposition","target":"handoff-to-related-workflow","whenValue":"complete"},{"id":"e-classify-disposition-escalate-or-accept-risk","label":"Escalate","source":"classify-disposition","target":"escalate-or-accept-risk","whenValue":"monitor"},{"id":"e-create-action-plan-handoff-to-related-workflow","source":"create-action-plan","target":"handoff-to-related-workflow"},{"id":"e-escalate-or-accept-risk-handoff-to-related-workflow","source":"escalate-or-accept-risk","target":"handoff-to-related-workflow"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{"UC-AUDIT-27":"tests","UC-GOV-38":"tests"},"controls":["UC-AUDIT-23","UC-AUDIT-18","UC-AUDIT-27","UC-GOV-38"],"department":"internal-audit","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-combined-assurance-mapping","contentDigest":"sha256:f0ae775a3a86f082f6bcc1a2383a15f8e0219c50577d82600fbd8fa89c947e8e","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:f0ae775a3a86f082f6bcc1a2383a15f8e0219c50577d82600fbd8fa89c947e8e","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-combined-assurance-mapping"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"grc-combined-assurance-mapping","source":"coworkcanvas-gallery","standards":["iia-2024"],"teams":["internal-audit","risk-management"]},"name":"Combined Assurance Mapping","nodes":[{"data":{"controls":["UC-GOV-38","UC-AUDIT-27"],"description":"Chief Risk Officer: Resolve provider-risk role collisions, cooling-off requirements and safeguards against a frozen scope and evidenced provider catalog.","instructions":"**Objective** — Freeze the assurance scope, map providers and coverage, and disposition self-review and role-collision gates before independent reliance is assessed.\n\n**Inputs**\n- Consumes the handoff package from the upstream **Enterprise Risk Assessment & Portfolio Oversight Cycle** — the confirmed risk universe as Risk items (residual_rating, treatment, category, taxonomies), with top or above-appetite risks flagged by residual_rating high or critical — rather than re-deriving it; the handoff document itself is re-attached as an upload on this step.\n- The confirmed in-scope population for this cycle: the entities and business units (which have no native item type — their scope statement lives in the locked workplan document on this step) and the risk-taxonomy categories (Risk.taxonomies values) whose assurance coverage will be mapped.\n- The register of assurance providers across the Three Lines (first-line self-assessment and QC, second-line risk, compliance, security and privacy monitoring, third-line internal audit) plus external audit, regulators, and outsourced specialists — supplied as a PBC/external upload on this step (there is no native provider item type).\n- The control inventory and the control-to-risk mapping — Control items and their existing Control ↔ Risk relationships — named up front here because the cataloging stage relies on them to trace provider activity to the risks it touches.\n- The assurance-mapping criteria: the reliance framework, the coverage-rating scale, and provider independence/competence attributes (uploaded as part of the locked workplan document — methodology has no item home).\n- The escalation/acceptance authority matrix (who can accept a coverage deficiency at which level) — named up front here, consumed later at the escalate-or-accept-risk step.\n- The audit-committee reporting template, cadence, and distribution list for this cycle — named up front here; cadence and distribution are recorded during publication in the disposition checkpoint.\n- The frozen risk-universe baseline and assurance-provider population from the locked workplan.\n- Each provider's scope documents: the internal audit plan and coverage, second-line monitoring programs, first-line control self-assessments, external audit scope, regulatory exam coverage, and outsourced assurance (SOC reports, penetration tests, certifications).\n- The control inventory and the control-to-risk mapping — Control items and their existing Control ↔ Risk relationships — so provider activity can be traced to the risks it touches.\n- The coverage-rating scale from the criteria basis.\n- The provider catalog and coverage matrix, including each provider's current and prior ERM responsibilities.\n- The applicable cooling-off, independence, and reliance criteria.\n\n**Procedure**\n*Autonomous preparation incorporates Lock executable workplan; Catalog providers and map coverage; Chief Risk Officer reviews the combined evidence.*\n1. Confirm the risk-universe baseline from the upstream package — which risks are in scope for coverage mapping, their residual ratings, and which are top or above-appetite (these get the deepest coverage scrutiny). Freeze this list as the mapping baseline.\n2. Confirm the assurance-provider population: list every party that performs assurance or control activity over the in-scope risks, across all three lines plus external and regulatory sources. A provider omitted here is invisible to the whole map — cross-check against prior-cycle maps and the current audit plan.\n3. Assign owners and due dates per activity: provider cataloging, coverage mapping, reliance assessment, gap analysis, coordination, and publication. Name a single accountable owner (typically the combined-assurance or GRC lead) plus contributors.\n4. State evidence requirements: what each coverage assertion must cite (an assurance report, a test result, a monitoring dashboard) and where the supporting artifacts live.\n5. Set the review points and the audit-committee reporting cadence this cycle feeds, and the review cadence for refreshing the map.\n6. Lock the plan and record it as the baseline, so later scope changes are tracked as dated deltas rather than silent edits.\n7. List every assurance provider and classify it to a line of defense: first line (management self-assessment, QC, operational control monitoring), second line (risk, compliance, security, and privacy oversight and monitoring), third line (internal audit), and external or independent (external audit, regulators, outsourced specialists, certification bodies). Some functions blur lines — record the line by the role played over each risk, not by the org chart.\n8. For each provider capture: scope of work, frequency and timing, methodology (audit, review, monitoring, testing, self-assessment), independence and objectivity, and the evidence it produces.\n9. Overlay each provider's activities onto the risk universe: for every in-scope risk, record which providers cover it and with what type of activity. Build the matrix with risks as rows and providers, grouped by line, as columns.\n10. Rate the depth of coverage in each risk-provider cell on the coverage scale (for example none, monitoring-only, detective testing, or full independent assurance), not a binary covered-versus-uncovered — a compliance dashboard and a full internal audit are not the same coverage.\n11. Flag over-coverage: risks where three or more providers perform overlapping activity (candidate duplication for the gap and coordination steps) and single-point coverage: top or above-appetite risks resting on one provider only.\n12. Tie every coverage assertion to evidence (the report, test, or monitoring artifact) so the matrix is defensible and re-performable, not merely asserted.\n13. Create a role-collision register for each material provider-risk cell. Record the provider, ERM phase, role, service mode, prior responsibility, safeguard, owner, due date, and disposition.\n14. Identify whether the provider designed, owned, operated, advised on, approved, or previously assured the activity now proposed for reliance; distinguish a temporary advisory role from continuing operational responsibility.\n15. Apply explicit pre-reliance gates to internal audit and the CAE: identify involvement in selecting or owning management risk decisions or responses; require 12-month separation after design, operation, management, or supervision; identify CAE supervision or expanded-remit arrangements; and require board-approved safeguards or separately performed independent coverage.\n16. Assess safeguards, including separate reviewers, external validation, cooling-off periods, changed reporting lines, or a replacement provider; record the accountable owner and due date for every safeguard.\n17. Treat each unresolved role collision as an assurance limitation: downgrade reliance, record the rationale, and carry the cell forward as an assurance gap for coordination.\n18. Escalate any unresolved collision affecting material reliance to the risk and audit leaders. No reliance is finalized until all gates are dispositioned.\n\n**Record in AssureSwarm**\n- Create the anchor Audit item for this cycle (audit_type: advisory, scope = the combined-assurance mapping scope, period_start/period_end = the cycle period); the workflow instance attaches to it and every gap Issue links back to it.\n- Build the workflow steps with owners and due dates, and assign them.\n- Attach the locked workplan (scope, risk-universe baseline, provider population, control-to-risk mapping, reliance/coverage criteria, escalation/acceptance authority matrix, audit-committee reporting template, owners, dates, evidence requirements, review points) to the step (document upload).\n- Record the assurance-provider register — each provider's line of defense, scope, frequency, methodology, and independence — as a document on this step; there is no native AssuranceProvider item type, so the register and the provider-to-risk coverage live in the step documents, not as queryable items.\n- Build the combined assurance coverage matrix (in-scope risks as rows, providers grouped by line as columns, a depth rating per cell) and attach it to the step (document upload, XLSX); flag the duplication and single-point-coverage cells. Read the Control ↔ Risk relationships to trace provider activity to risks.\n- Attach the role-collision register to this step and link each material collision to its provider-risk coverage cell in the assurance matrix.\n- For internal audit and the CAE, record whether they were involved in selecting or owning management risk decisions or responses; the 12-month separation after design, operation, management, or supervision; any CAE supervision or expanded-remit arrangements; and the board-approved safeguards or separately performed independent coverage. Record the disposition, safeguard owner, and due date; flag unresolved collisions as assurance gaps. No reliance is finalized until all gates are dispositioned.\n\n**Exit criteria**\nResolve provider-risk role collisions, cooling-off requirements and safeguards against a frozen scope and evidenced provider catalog.\nRisk-universe baseline and assurance-provider population confirmed and frozen; owners and due dates assigned per activity; evidence requirements and audit-committee reporting points stated; the baseline recorded so downstream changes are tracked as deltas.\nEvery provider cataloged and classified to a line, with scope, frequency, methodology, and independence recorded; the coverage matrix maps each in-scope risk to its providers with a depth rating tied to evidence; duplication and single-point-coverage cells flagged; nothing in scope left unmapped.\nFor internal audit and the CAE, involvement in selecting or owning management risk decisions or responses is dispositioned; 12-month separation after design, operation, management, or supervision is confirmed; CAE supervision or expanded-remit arrangements are dispositioned; and board-approved safeguards or separately performed independent coverage is evidenced. No reliance is finalized until all gates are dispositioned; unresolved collisions are downgraded into assurance gaps.","label":"Screen role collisions and self-review","performedBy":{"primitives":["coach-item-create","coach-workflow-build","coach-workflow-assign","coach-document-upload","coach-items-link","coach-query-data"]},"roleIntegrity":{"decisionOwner":"Chief Risk Officer","ermPhase":"assess","independenceRequired":false,"lineRole":"second","serviceMode":"assurance"}},"id":"screen-role-collisions-and-self-review"},{"data":{"controls":["UC-AUDIT-23"],"description":"Assess reliance after role-collision screening and retain UC-AUDIT-23 as the reliance-assessment control.","instructions":"**Objective** — Judge, for each provider's assurance over each risk, whether the combined-assurance function can actually rely on that work — its independence, competence, objectivity, and evidence quality — so the coverage matrix reflects effective, reliable coverage rather than nominal activity.\n\n**Inputs**\n- The coverage matrix from the completed role-collision package, with provider activities mapped to risks and depth ratings.\n- Each provider's independence and competence attributes, methodology, and recent quality history (peer reviews, external assessments, prior reliance experience).\n- The reliance framework and criteria (for example IIA guidance on using the work of others, and the standards external audit applies when relying on internal auditors).\n\n**Procedure**\n1. For each provider, assess objectivity and independence: how far removed is the provider from the risk owner and the activity being assured? First-line self-assessment is the least independent; third-line internal audit and external audit the most. Reliance weight scales with independence.\n2. Assess competence and rigor: does the provider have the skills, methodology, and evidence standards to support reliance? A checklist-based self-assessment supports less reliance than an evidenced, sampled test.\n3. Assess evidence quality and recency: is the underlying work documented, reperformable, and current within the risk's review cadence? Stale assurance (older than the risk's cadence) is downgraded.\n4. Assign a reliance level to each risk-provider cell (for example full reliance, partial reliance, awareness only, or no reliance) and record the rationale. Downgrade nominal coverage that fails these tests — this is what converts the raw activity matrix into an effective-coverage view.\n5. Flag reliance conflicts: cells where the matrix assumed coverage that the reliance assessment now discounts, so the gap step treats those as effective gaps.\n\n**Record in AssureSwarm**\n- Record the reliance level and rationale per material coverage cell in a reliance-adjusted revision of the coverage matrix, re-attached as a document on this step (document upload, XLSX) — reliance levels have no per-cell item structure, so they live in the matrix document, versioned at this step.\n- Flag the downgraded cells (nominal coverage, low reliance) in that revision as the inputs to the gap analysis.\n\n**Exit criteria** — Every material coverage cell has a reliance level with a documented rationale grounded in independence, competence, and evidence quality; nominal-but-unreliable coverage is downgraded; the effective-coverage view is distinct from the raw activity map.","label":"Assess reliance","performedBy":{"primitives":["coach-item-update","coach-query-data","coach-document-upload"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive","ermPhase":"assess","independenceRequired":true,"lineRole":"third","serviceMode":"assurance"}},"id":"assess-reliance"},{"data":{"description":"Combined-assurance lead and accountable assurance provider owners: Rank effective gaps and duplication, settle resource and independence trade-offs, and personally accept or decline each provider coverage commitment.","instructions":"**Objective** — Analyze effective gaps and duplication and agree a coordinated coverage plan with each provider’s own commitments and constraints.\n\n**Inputs**\n- The reliance-adjusted coverage matrix (effective coverage), with downgraded cells flagged.\n- The risk residual ratings and above-appetite flags from the risk universe.\n- The duplication flags (three or more overlapping providers) from the coverage step.\n- The ranked gap and duplication findings.\n- Each provider's forward plan and capacity (the internal audit plan, the second-line monitoring calendar, external audit timing).\n- The reliance levels, so coordination can shift reliance where it is defensible.\n\n**Procedure**\n*Autonomous preparation incorporates Identify assurance gaps; Combined-assurance lead and accountable assurance provider owners reviews the combined evidence.*\n1. Identify coverage gaps: risks with no reliable assurance (every cell rated no reliance or awareness only) and risks with only partial reliable coverage relative to their significance. A top or above-appetite risk carrying only first-line self-assessment is a gap even though a cell is filled.\n2. Rank gaps by risk significance against coverage deficit: an above-appetite risk with no independent assurance ranks above a low-residual risk with thin coverage. This ranking drives the action plan.\n3. Identify duplication and inefficiency: risks where multiple independent providers perform overlapping full assurance with no reliance benefit — a candidate to reallocate assurance effort toward gap areas rather than to cut blindly (a second reviewer may be deliberate for a critical risk).\n4. Distinguish true gaps from acceptable design: some low risks are intentionally lightly assured. Confirm each gap is a real deficiency against the assurance strategy, not a deliberate, appetite-consistent choice — flag which is which.\n5. Quantify the picture: counts of risks by coverage status (well-assured, partially assured, gap, or over-assured) and the share of top risks with independent assurance — the headline metrics for the audit committee.\n6. Convene or engage the assurance providers (the combined-assurance forum: the chief audit executive, the CRO and compliance lead, the external audit liaison, and key first-line owners) and walk them through the gap and duplication findings.\n7. For each priority gap, agree who will extend coverage and when: assign the gap to the best-placed provider (independence and competence matching the risk), or agree a new assurance activity. Record the owner and target period.\n8. For each duplication, agree the rationalization: consolidate to one provider and let others rely, stagger timing, or retain deliberate redundancy for a critical risk with a documented reason.\n9. Align timing and reliance protocols: sequence activities so later providers can rely on earlier work, and agree how evidence will be shared across lines to enable that reliance.\n10. Have each participating provider owner record their commitment in the native result and accept or decline through native approvals, in their own words — activity, scope, period, accountable owner, evidence-sharing terms, and constraints. An unacknowledged coverage commitment is not a plan, and a commitment recorded on the provider's behalf is not an acceptance.\n11. Capture disagreements and declined commitments, and route any unresolved coverage decision to the disposition step.\n\n**Record in AssureSwarm**\n- Create an Issue item per gap or duplication finding (issue_type: deficiency for a true coverage gap, observation for a duplication or an accepted-design finding; source: self_assessment; severity set to the significance rank; identified_date set), and link each Issue to the Risk it concerns and to the anchor Audit item.\n- Record the coverage-status counts (well-assured, partially assured, gap, over-assured) and the top-risk independent-assurance metric on the step.\n- Update each gap/duplication Issue with the coordinated commitment: remediation_plan (the agreed provider and action), issue_owner (the accountable provider owner), and target_remediation_date (the target period); each Issue stays linked to its Risk.\n- Each assurance provider owner’s native result and approval capture their function and line, acceptance of the commitment, the committed activity and scope, the committed period, the accountable owner, the evidence they will make available for reliance, and any capacity constraints — those responses are the acknowledgment evidence.\n- Attach the coordinated coverage plan and the consolidated provider acknowledgments as a document on this step (document upload).\n\nRecord in the native step result or attached source documents: Your assurance function and the line of defense it operates in (provider_function_and_line); Do you accept the coordinated coverage commitment assigned to your function? (commitment_accepted); Assurance activity, methodology, and scope you commit to over the assigned risks (committed_activity_and_scope); Period in which the committed work will complete (committed_period); Named owner accountable for delivering this commitment (accountable_owner); Working papers or evidence you will make available so other lines can place reliance (evidence_sharing_terms); Capacity, budget, independence, or timing constraints that could put the commitment at risk (capacity_constraints). Use native approvals for sign-off.\n\n**Exit criteria**\nRank effective gaps and duplication, settle resource and independence trade-offs, and personally accept or decline each provider coverage commitment.\nCoverage gaps and duplication identified and linked to their risks; gaps ranked by significance against deficit; true deficiencies separated from appetite-consistent light coverage; the headline coverage metrics quantified.\nPriority gaps assigned to named providers with target periods; duplications rationalized with documented rationale; timing and reliance protocols aligned; each provider has acknowledged its commitments in native results and approvals; unresolved coverage decisions flagged for disposition.","label":"Coordinate coverage plans","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-item-update","coach-notify","coach-document-upload"]}},"id":"coordinate-coverage-plans"},{"data":{"decisionField":"disposition_path","description":"Combined-assurance or GRC lead with accountable risk and assurance owners: Judge whether the published effective-coverage posture is adequate, needs gap actions or requires formal acceptance of carried deficiencies.","formData":{"fields":[{"key":"disposition_path","label":"Classify disposition","options":[{"label":"Complete","value":"complete"},{"label":"Gaps require action","value":"gaps"},{"label":"Monitor without immediate action","value":"monitor"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Publish the evidenced coverage map and determine the action, clean or acceptance path for its overall posture.\n\n**Decision criteria**\nInputs for preparation: - The reliance-adjusted coverage matrix, the gap and duplication findings, and the coordinated coverage plan.\n- The headline coverage metrics.\n- The audit-committee reporting template and the distribution list.\n\n*Autonomous preparation incorporates Publish assurance map; Combined-assurance or GRC lead with accountable risk and assurance owners reviews the combined evidence.*\n1. Assemble the map into a reviewable form: a heat-mapped risk-by-line-of-defense matrix (coverage depth and reliance color-coded), with top and above-appetite risks surfaced first.\n2. Add the narrative layer: the headline metrics (share of top risks with independent assurance, count of gaps, duplication reduced), the priority gaps and their coordinated remediation, and the material reliance judgments.\n3. Reconcile every figure to source before publishing — the matrix, the provider items, the gap findings — so no published number is unsupported.\n4. Version and date the map, mark the prior version superseded, and record what changed since the last cycle (gaps closed, gaps opened, coverage shifts).\n5. Publish to the agreed audience and confirm access; queue the disposition decision on the overall coverage posture.\n\nJudge the published map against the risk universe and state counts in the rationale (how many risks fall to each path and which top risks drive them) so the downstream step sizes its work:\n\n- **Complete (`complete`)** — assurance coverage is adequate across the in-scope risks: every top and above-appetite risk has reliable, appropriately-independent coverage, duplication is rationalized, and the coordinated plan needs no new remediation action this cycle. Route straight to the final package.\n- **Gaps require action (`gaps`)** — one or more priority coverage gaps need a remediation action: a significant risk with no reliable independent assurance, or a coordinated commitment that needs a tracked plan with an owner and date. Route to create the action plan.\n- **Monitor without immediate action (`monitor`)** — a coverage gap on a notable risk exists but no cost-justified assurance can be added this period, so the residual assurance deficiency is knowingly carried and needs a formal acceptance or an escalation to the authority that can accept it — not a remediation plan. Route to escalate or accept the risk.\n\n**Record in AssureSwarm**\n- Build or refresh the combined-assurance dashboard and attach the published, versioned combined assurance map to the step (document upload, XLSX/PDF).\n- Record the version, the change-since-last-cycle note, and the distribution list on the step.\n- Submit the decision form: `disposition_path` (the branch), the step result with the coverage-status counts and the driving top risks, and the step's approver record.\n\n**Exit criteria**\nJudge whether the published effective-coverage posture is adequate, needs gap actions or requires formal acceptance of carried deficiencies.\nThe combined assurance map published as a versioned, dated, heat-mapped artifact with narrative and headline metrics; every figure reconciled to source; the change-since-last-cycle recorded; distributed to the agreed audience.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` compiles the coverage matrix, reliance levels, gap findings, and coordinated plan into the published, self-contained assurance map with source cross-references.\nForm submitted; the rationale reconciles the coverage-status counts to the chosen path and names the driving risks; the unused branches are prunable because branch edge values match the selected form value.","kind":"decision","label":"Classify disposition","performedBy":{"primitives":["coach-dashboard-create","coach-render-package","coach-document-upload","coach-query-data"]}},"id":"classify-disposition"},{"data":{"description":"Create an owned action plan for gaps","instructions":"**Objective** — Turn each priority coverage gap into an owned, dated action plan — the assurance to be added, by whom, by when, with the evidence that will confirm the gap closed — so under-assured significant risks have a credible path to adequate coverage rather than an open flag.\n\n**Inputs**\n- The gap findings from the disposition decision, ranked by significance, with their coordinated-plan commitments.\n- The provider capacity and the reliance framework.\n- The risk owners and the assurance-provider owners.\n\n**Procedure**\n1. For each gap, establish the root cause: no provider in scope, a provider that exists but cannot be relied on, or a timing or capacity constraint. The remedy differs — adding a provider versus strengthening one versus rescheduling.\n2. Define the assurance action: which provider will add or deepen coverage, the activity type (independent audit, second-line testing, external assurance), and the reliance level it must reach for the risk.\n3. Name a single accountable owner and a due date; where the risk is live and unassured now, record an interim measure (heightened monitoring, a management attestation) that holds until the coverage lands.\n4. Define validation evidence up front: what will prove the gap closed — the completed assurance report, a coverage cell moving to reliable — decided before work starts, not chosen after.\n5. Set a reporting cadence to the audit committee and link each action to its risk and to the coordinated coverage plan.\n\n**Record in AssureSwarm**\n- Update each existing gap Issue with its action plan (these Issues were created during gap analysis in the coordination checkpoint, so enrich rather than duplicate): root_cause, remediation_plan (the assurance action and any interim measure), recommendation (the target reliance level and validation evidence), issue_owner, and target_remediation_date; each Issue is already linked to its Risk.\n- Record the reporting cadence on the step.\n\n**Exit criteria** — Every priority gap has an owned, dated action plan with root cause, the assurance action and target reliance level, an interim measure where needed, and pre-defined validation evidence; each links to its risk; the reporting cadence is set.","label":"Create action plan","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-item-update"]}},"id":"create-action-plan"},{"data":{"description":"Escalate to risk owner, GRC lead, executive sponsor, or board delegate or document risk acceptance","instructions":"**Objective** — For each monitor-path coverage deficiency, prepare a decision memo that either escalates the un-assured exposure to the authority that can accept it or documents a formal, time-bound acceptance of the assurance gap with conditions and follow-up ownership, so a knowingly-carried assurance deficiency is a governed choice and not a silent one.\n\n**Inputs**\n- The monitor-branch gaps with their risk residual ratings and appetite positions.\n- The escalation authority matrix (who can accept an assurance or coverage deficiency at which level — risk owner, GRC lead, executive sponsor, board or audit-committee delegate).\n- The rationale for carrying rather than closing (no cost-justified assurance this period) and any compensating monitoring.\n\n**Procedure**\n1. Quantify the deficiency being carried: the risk's residual exposure, the coverage and reliance shortfall, and what could go undetected because assurance is absent — an acceptance without a quantified exposure is a blank cheque.\n2. Match the decision to authority: the more significant the un-assured risk, the higher the acceptance authority. A top or above-appetite risk with no independent assurance is not accepted by its first-line owner — it escalates to the executive sponsor or audit-committee delegate per the matrix.\n3. Draft the decision memo: the risk, why assurance is deferred, the compensating monitoring, the exposure quantification, and the recommendation (escalate for decision, or accept).\n4. For acceptances, capture conditions and an expiry: what must stay true, the indicators that would void the acceptance, and a re-decision date — every acceptance is time-bound so a temporary gap does not become permanent.\n5. Define follow-up ownership: who monitors the carried deficiency and who re-opens it at expiry or on a trigger.\n\n**Record in AssureSwarm**\n- For an accepted assurance deficiency, update the gap Issue to issue_type: policy_exception with exception_approver (the accepting authority) and exception_expiry_date (the re-decision date), capture the authority, conditions, and monitoring trigger in management_response, and set treatment: accept on the linked Risk item.\n- For an escalation, record the routing, authority, and pending decision in the gap Issue's management_response and keep the Issue open pending the authority's decision.\n- Attach the decision memo to the step (document upload, DOCX/PDF); notify the escalation authority and record the follow-up owner.\n\n**Exit criteria** — Each monitor-path deficiency has a decision memo with quantified exposure; acceptances are approved at the authority matching the risk's significance, time-bound, and conditioned; escalations are routed to the right authority; follow-up ownership and re-decision dates are set.","label":"Escalate or accept risk","performedBy":{"primitives":["coach-document-upload","coach-item-update","coach-notify"]}},"id":"escalate-or-accept-risk"},{"data":{"description":"Quarterly Board Reporting receiving owner and combined-assurance owner: Accept the effective assurance map, reliance limitations and carried gap obligations; the source owner signs closure only when all escalations are decided and work is owned.","instructions":"**Objective** — Compile and hand off the assurance record after its coverage and risk decisions, retain the immutable archive and carry open work into reporting and the next cycle.\n\n**Inputs**\n- The published combined assurance map and the headline coverage metrics.\n- The reliance-adjusted matrix, the gap and duplication findings, the coordinated coverage plan, the action plans (gaps branch), and the acceptance or escalation memos (monitor branch).\n- The open constraints logged during the cycle.\n- The final package: the published assurance map, the coverage metrics, the gap actions, the acceptances and escalations, and the open constraints.\n- The named downstream workflow and its owner.\n- The assumptions and limitations logged during the cycle.\n- The records-retention schedule for assurance and GRC governance records.\n- Open threads: gap action plans in flight, acceptances with expiry dates, coordinated coverage commitments to track, and scope changes for the next cycle; plus the review cadence and next scheduled cycle date.\n\n**Procedure**\n*Autonomous preparation incorporates Prepare final package; Quarterly Board Reporting receiving owner and combined-assurance owner reviews the combined evidence.*\n1. Compile the package in the order a reviewer reads it: coverage-posture summary (share of top risks with independent assurance, gaps opened and closed, duplication rationalized), then the assurance map, then the gap findings with their action plans and acceptances, then the open constraints.\n2. Test it against re-performance: could a reviewer holding only this package reconstruct each coverage and reliance conclusion? Any external reference (\"see the map\") fails — pull the artifact in.\n3. Spot-check every figure against source — the matrix, the provider items, the gap items — before publishing; a summary count that does not tie to the map undermines the whole package.\n4. State the proposed conclusion and the governance decision it supports (for example the assurance map accepted, gap actions tabled, escalations for audit-committee decision), plus what remains open with named owners.\n5. Note explicitly what the downstream audit-committee reporting workflow should consume and not re-derive.\n6. Create or link the downstream Quarterly Board & Audit-Committee GRC Reporting workflow and attach the final package: it consumes the coverage posture, the top-risk independent-assurance metric, the material gaps and their remediation, and the escalations requiring committee decision.\n7. State the handoff contract: what is authoritative here (the coverage map, the reliance conclusions, the gap findings) and should not be re-derived, versus what the downstream workflow extends (the board narrative and the committee decisions).\n8. Pass assumptions and limitations forward explicitly — provisional reliance judgments, deferred coverage, acceptances nearing expiry — so downstream work inherits them rather than rediscovering them.\n9. Confirm the receiving owner acknowledges the handoff so the package does not land unowned.\n10. Confirm the cycle is closable: the assurance map is published and accepted, escalations and acceptances are decided, and gap actions are owned and dated. An undecided escalation is not closable.\n11. Export the final workflow record and archive it with the package in the designated governance repository under retention and immutability controls; record the archive location and reference. Verify retrievability by opening the archived copy. Any post-archive correction is a new dated addendum, never an edit to the sealed record.\n12. Update the control execution log for UC-AUDIT-18 and UC-AUDIT-23 with the cycle period, completion date, and result — this is what demonstrates on-cadence combined-assurance coverage when the control is sampled.\n13. Create carry-forward items, each with an owner and due date: gap actions continuing past close, acceptances due for re-decision at expiry, coordinated coverage commitments to track, and scope changes for the next cycle. An acceptance that renews silently is how a temporary assurance gap becomes permanent.\n14. Communicate the outcome to stakeholders, confirm the next cycle is scheduled at the policy cadence, and have the combined-assurance owner declare the cycle closed on this step — that declaration, alongside the acknowledged handoff, is the closure.\n\n**Record in AssureSwarm**\n- Assemble the package and link each evidence artifact to its producing step (document link).\n- Attach the compiled package and the coverage-posture summary to the step (document upload).\n- Record each receiving owner’s actual acceptance in native approvals, with scope and limitations in the native result. Retain the source owner’s closure sign-off where the procedure requires it.\n- Link the downstream workflow and attach or link the final package to it (workflow attach, document link); record the handoff contract, the assumptions passed forward, and the acknowledging owner on the step.\n- Export the workflow instance as the audit trail; attach the closure record with the archive location and reference to the step (document upload).\n- Update the anchor Audit item: report_date = the map publish date and rating per the coverage posture; link the anchor Audit to the UC-AUDIT-18 and UC-AUDIT-23 Control items as combined-assurance execution evidence (there is no separate control execution log — the Audit ↔ Control relationship is what a sampled control cites).\n- Create the carry-forward items as Issue items — in-flight gap actions stay open; acceptance re-decisions at expiry and coverage commitments to track become new Issues — each with issue_owner and target_remediation_date; record the next cycle date on the step.\n\n**Exit criteria**\nAccept the effective assurance map, reliance limitations and carried gap obligations; the source owner signs closure only when all escalations are decided and work is owned.\nPackage assembled in reviewer order and passes the re-performance test with no external references; every figure traces to source; the proposed conclusion and open items are stated with owners; ready for the governance decision and handoff.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` compiles the assurance map, reliance conclusions, gap findings, action plans, and acceptances into the ordered, self-contained package with source cross-references.\nThe downstream reporting workflow is linked and holds the final package, the handoff contract names what not to re-derive, assumptions are passed forward, and the receiving owner has acknowledged; the final record is archived, verified retrievable and immutable, with its reference recorded; the control execution log is updated for UC-AUDIT-18 and UC-AUDIT-23; every open thread exists as a carry-forward item with an owner and due date; the next cycle is scheduled; closure declared by the combined-assurance owner.","label":"Handoff to related workflow","performedBy":{"primitives":["coach-render-package","coach-document-upload","coach-workflow-attach","coach-workflow-export","coach-item-create","coach-item-update","coach-items-link"]}},"id":"handoff-to-related-workflow"}],"sourceTemplateId":"workflow-library:grc-combined-assurance-mapping"}
