{"description":"Control Responsibility Communications & Ethics Hotline as a decision-aware workflow that runs on the existing Control item for control-responsibility communications and the whistleblower/ethics hotline (framework sox + coso-ic, quarterly frequency, control_owner = Ethics & Compliance Officer) — each instance is one quarterly operating cycle of that control, enriching it rather than creating a duplicate. Within the cycle it inventories what changed in control responsibilities this quarter, drafts and distributes tailored communications with tracked acknowledgment, verifies internal and external concern-raising channels including the whistleblower hotline are operating, tests intake-to-routing end to end, and confirms this quarter's real reported matters reached the people responsible for acting on them. The named deliverable is the archived quarterly evidence package — the responsibility-change delta list, the approved tailored communications, the distribution and acknowledgment records, the internal-channel and hotline health summaries, the intake-to-routing test trace, and the real-matter routing review — retained on the anchor Control as durable audit evidence. In scope: this quarter's control-responsibility communications and the operation and intake-to-routing reliability of the internal and external concern-raising channels including the anonymous whistleblower/ethics hotline. Out of scope: investigating or adjudicating the substance of individual reported matters (owned by each case's responsible function) and designing new controls. This cycle consumes no other workflow's handoff package and hands off to no downstream workflow; the quarterly cadence (or an interim trigger such as a reorganization, new policy, control-ownership change, or M&A) is its own trigger.","edges":[{"id":"e-verify-external-whistleblower-hotline-distribute-and-track-acknowledgment","source":"verify-external-whistleblower-hotline","target":"distribute-and-track-acknowledgment"},{"id":"e-distribute-and-track-acknowledgment-remediate-communication-gaps","label":"Gap identified","source":"distribute-and-track-acknowledgment","target":"remediate-communication-gaps","whenValue":"gap_identified"},{"id":"e-distribute-and-track-acknowledgment-review-quarter-reported-matters-routing","label":"Coverage confirmed","source":"distribute-and-track-acknowledgment","target":"review-quarter-reported-matters-routing","whenValue":"coverage_confirmed"},{"id":"e-remediate-communication-gaps-review-quarter-reported-matters-routing","source":"remediate-communication-gaps","target":"review-quarter-reported-matters-routing"},{"id":"e-verify-external-whistleblower-hotline-test-intake-to-routing-end-to-end","source":"verify-external-whistleblower-hotline","target":"test-intake-to-routing-end-to-end"},{"id":"e-test-intake-to-routing-end-to-end-remediate-routing-gap","label":"Routing gap","source":"test-intake-to-routing-end-to-end","target":"remediate-routing-gap","whenValue":"routing_gap"},{"id":"e-test-intake-to-routing-end-to-end-review-quarter-reported-matters-routing","label":"Routing confirmed","source":"test-intake-to-routing-end-to-end","target":"review-quarter-reported-matters-routing","whenValue":"routing_confirmed"},{"id":"e-remediate-routing-gap-review-quarter-reported-matters-routing","source":"remediate-routing-gap","target":"review-quarter-reported-matters-routing"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-TRAIN-04"],"department":"compliance-legal","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-control-responsibility-communications-ethics-hotline","contentDigest":"sha256:46c33e7957451f219f05cbf24352132b607a2602b1935d359cd89256b4630baa","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:46c33e7957451f219f05cbf24352132b607a2602b1935d359cd89256b4630baa","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-control-responsibility-communications-ethics-hotline"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-control-responsibility-communications-ethics-hotline","source":"coworkcanvas-gallery","standards":["sox"],"teams":["compliance-legal","hr"]},"name":"Control Responsibility Communications & Ethics Hotline","nodes":[{"data":{"description":"Ethics & Compliance Officer: Approve accurate duty-change communications and judge vendor anonymity, reachability and evidence discrepancies before distribution and controlled routing tests.","formData":{"fields":[{"key":"anonymity_controls_status","label":"Status of the anonymity and non-retaliation controls for the period","options":[{"label":"Intact and unchanged","value":"intact_unchanged"},{"label":"Intact, but the controls changed - detail below","value":"intact_but_changed"},{"label":"An anonymity incident occurred","value":"incident_occurred"}],"required":true,"type":"select"},{"key":"service_changes","label":"Changes to supported languages, subprocessors, data location, or routing configuration","required":false,"type":"textarea"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Prepare and approve role-specific responsibility communications and assess the hotline’s availability and protections before executing distribution and routing tests.\n\n**Inputs**\n- The cycle trigger and target completion date — the scheduled quarterly cadence, or an interim trigger such as a reorganization, new/amended policy, control-ownership change, or M&A. This is the workflow instance's own starting trigger (a recurring run on the anchor Control); no upstream workflow feeds it.\n- The current control inventory (control objectives and owners of record) — the Control items (control_id, description, control_owner, frequency), queried here.\n- The policy library and source objective documents — the Policy items (policy_owner, next_review_date, framework/domains) with the governed documents attached, plus any objective documents uploaded to this step.\n- The org/HR roster — role changes, new hires, and moves as a change extract from the HRIS, uploaded to this step (no native item type for roster data).\n- The internal and external concern-raising channel inventory — one Process item per intake channel (process_type=operational, process_owner, frequency) — and the whistleblower/ethics hotline Vendor item, including the anonymity assurance and the non-retaliation policy.\n- The prior quarter's communications, distribution list, and channel-testing evidence — the prior archived instance's evidence package on the same anchor Control — or a note that this is the first cycle.\n- Any approved communication templates or house style, uploaded to this step.\n- The hotline vendor — the Vendor item (category, tier, data_classification, business_owner, risk_owner, reassessment_cadence, last_assessment_date, next_reassessment_date, monitoring_status, contract_end_date) — with the contract, availability commitment, supported languages, and the anonymity and non-retaliation controls attached to it.\n- The vendor’s missing control/change confirmation through the form, plus its period service report and uptime/intake logs attached as source documents.\n- The advertised access channels (phone, web form, app) and the vendor status page or account console.\n\n**Procedure**\n*Autonomous preparation incorporates Draft tailored responsibility communications; Ethics & Compliance Officer reviews the combined evidence.*\n1. Record why the cycle is running now and fix its scope: log the trigger with its date and source; confirm the in-scope audiences (new hires, role changes, and teams affected by policy or objective changes) and the in-scope internal and external channels; set the target completion date for the quarter.\n2. Query the control inventory, policy library, and organizational data changed since the last communication cycle to identify new or amended internal-control objectives, updated policies, and changes to duties — role changes, new hires, org moves, and control-ownership reassignments.\n3. Cross-reference the changes against the prior quarter's distribution list to flag people whose responsibilities changed but who have not yet received updated communication.\n4. Compile a per-person or per-role delta list stating what changed, which objective or policy it maps to, and why it affects that person's duties. Worked example: \"AP Manager — now owns the manual-journal-entry review control (was Controller); maps to Financial Close Policy §4; must acknowledge new review + hotline escalation duty.\"\n5. Flag any control that changed without a current owner of record (orphaned control) and set an owner before drafting — an unowned control cannot be communicated to anyone.\n6. Draft the communication content per audience segment, stating each person's internal-control and reporting responsibilities, the objectives and policies that apply, and what specifically changed since the last cycle, in plain role-specific language (avoid generic all-staff boilerplate for people whose duties actually changed).\n7. Embed the reporting-channel information in every communication — how and where to raise a concern internally, plus the external and anonymous whistleblower/ethics hotline details, including the anonymity assurance and the non-retaliation policy.\n8. Link each communication to its source policy and objective documents so every stated responsibility is traceable to an authoritative source, and assemble the distribution list mapping each tailored communication to its recipients and planned delivery channel.\n9. The Ethics & Compliance Officer reviews the delta list against known organizational changes and samples the tailored communications for accuracy, tone, and completeness, then approves them for distribution.\n10. Obtain the period’s service report and uptime/intake logs as source documents. Ask the vendor’s account or assurance contact only for missing anonymity/non-retaliation control status and service changes using the form; derive availability, outages and intake volume from the logs and existing commitment, and inspect advertised channels independently. The vendor's own confirmation is what makes the anonymity assertion evidence rather than assumption.\n11. Confirm the vendor contract, availability commitment, supported languages, and anonymity and non-retaliation controls are current and published where employees and external parties can find them, and reconcile them to the vendor's answers.\n12. Confirm the hotline is reachable through every advertised channel — phone, web form, and app — by validating the vendor status page or account console independently of the vendor's answer (place a tagged reachability check where the protocol allows).\n13. Compile the hotline-health summary, reconciling the vendor's reported outages and intake volume to the logs supplied, and raise any discrepancy with the vendor before the summary is relied on.\n\n**Record in AssureSwarm**\n- Attach the delta list as an XLSX document on this step, capturing the trigger, scope, in-scope audiences/channels, and target date — there is no delta-list item type, so it lives as a step document on the anchor Control's run (coach-document-upload) — with the query artifacts and prior-cycle comparison behind it (coach-query-data).\n- For each orphaned control, set its owner of record — item field update Control.control_owner on the affected Control item (coach-item-update).\n- Upload each drafted tailored communication as a DOCX/PDF document on this step, one per audience segment, and attach the distribution list (XLSX) mapping each communication to its recipients and delivery channel (coach-document-upload).\n- Link each affected Control item to its governing Policy items so every stated responsibility traces to an authoritative source — item relationship Control ↔ Policy (coach-items-link).\n- The form on this step, answered by the hotline vendor's account or assurance contact, captures only missing anonymity/non-retaliation control status and service changes. Bind it to the fixed reporting quarter and named vendor assignment. The attached source logs and independent channel checks supply availability, outages, intake counts and operational status.\n- Enrich the hotline Vendor item — set monitoring_status, last_assessment_date and next_reassessment_date, tier, and data_classification; contract_end_date confirmed current (create the Vendor item on the first cycle) (coach-item-update, coach-item-create).\n- Attach the vendor logs and the contract extract as documents on the Vendor item / this step (coach-query-data, coach-document-upload), and upload the hotline-health summary (with the anonymity and non-retaliation confirmation) as a document on this step (coach-document-upload).\n\n**Exit criteria**\nApprove accurate duty-change communications and judge vendor anonymity, reachability and evidence discrepancies before distribution and controlled routing tests.\nScope, trigger, and target date recorded; the delta list is complete and accurate against known organizational changes with every orphaned-control flag resolved; every communication is linked to its sources; the distribution list is complete; the Ethics & Compliance Officer has approved the communications for distribution.\nThe vendor’s missing-input form is submitted and source logs are attached as documents; the Ethics & Compliance Officer confirms the hotline is operating through every advertised channel, anonymity and non-retaliation protections are intact, discrepancies between the vendor's answers and the logs are resolved, and the vendor evidence is sufficient to serve as audit evidence.\n\n**Form recipient** — this step's form is answered by the hotline vendor's account or assurance contact, outside the Officer, HR/manager escalation contacts and internal system/channel executors in this workflow. Send it with a form assignment; the owner's own work goes in the step result.","label":"Verify external and whistleblower hotline channel","performedBy":{"primitives":["coach-document-upload","coach-items-link","coach-query-data","coach-item-create","coach-item-update"]}},"id":"verify-external-whistleblower-hotline"},{"data":{"decisionField":"communication_coverage","description":"Agent distributes approved communications and tracks acknowledgment against the distribution list; human decides whether coverage is sufficient to close distribution","formData":{"fields":[{"key":"communication_coverage","label":"Communication coverage decision","options":[{"label":"Coverage confirmed","value":"coverage_confirmed"},{"label":"Gap identified - follow-up required","value":"gap_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve whether this quarter's control-responsibility communications reached and were acknowledged by enough of the in-scope population to close distribution, or whether a material gap requires follow-up. Owned by the Ethics & Compliance Officer.\n\nBefore the decision the agent: (1) distributes the approved tailored communications to each audience segment through its assigned channel and timestamps each send; (2) tracks acknowledgment, read-receipt, or attestation completion per recipient against the distribution list; (3) calculates the coverage rate — the share of in-scope people who received and acknowledged — and lists any recipients or segments below the completion threshold; (4) compiles the coverage summary with the outstanding list for the decision.\n\n**Decision criteria**\n- Select **Coverage confirmed** (`coverage_confirmed`) when every in-scope person has acknowledged, or the residual shortfall is immaterial and formally accepted with rationale — typically at or above the organization's acknowledgment threshold (commonly 95–100%) with no critical control owner or newly-assigned individual outstanding.\n- Select **Gap identified — follow-up required** (`gap_identified`) when a material gap remains: a whole segment below threshold, or any critical control owner or new hire not yet acknowledged, so remediation must run before distribution can close.\n\n**Record in AssureSwarm** — Submit the `communication_coverage` SELECT. Record the coverage rate, the outstanding list, and the decision rationale/evidence references in the step result, and the decision owner or approver in the step's approver record (coach-form-fill). Attach the per-recipient send/acknowledgment log as a document on this step — there is no Person/recipient item type, so acknowledgment tracking is a spreadsheet rather than item-level data (coach-document-upload). Publish the coverage summary (acknowledgment rate by segment) as a dashboard (coach-dashboard-create).\n\n**Exit criteria** — The form is submitted with a rationale and the coverage summary attached; the unused branch is prunable.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` distributes the approved communications to each segment's channel and records the per-recipient send and acknowledgment timestamps that feed the coverage rate.","kind":"decision","label":"Distribute communications and confirm coverage","performedBy":{"primitives":["coach-form-fill","coach-document-upload","coach-dashboard-create","coach-notify"]}},"id":"distribute-and-track-acknowledgment"},{"data":{"description":"Agent escalates outstanding communications to flagged recipients and tracks re-acknowledgment; human confirms gaps are closed or accepts residual risk","instructions":"**Objective** — Close the flagged communication gaps by escalating the outstanding communications and tracking re-acknowledgment, or document an accepted residual risk with an accountable owner.\n\n**Inputs**\n- The outstanding recipient/segment list and coverage summary from the coverage decision.\n- Recipient manager and HR contacts for secondary-channel escalation.\n- The organization's follow-up deadline and escalation policy.\n\n**Procedure**\n1. Re-send or escalate the outstanding communications to the flagged recipients or segments through a secondary channel — direct manager or HR — with a short follow-up deadline.\n2. Track re-acknowledgment against the deadline and update the coverage summary as acknowledgments land.\n3. For any recipient who still has not acknowledged by the deadline, escalate to their manager and the Ethics & Compliance Officer for direct follow-up and log the escalation with a timestamp.\n4. Update the register with the remediation actions taken and the final coverage achieved.\n\n**Record in AssureSwarm**\n- Attach the escalation and re-acknowledgment log (with the final coverage achieved) as a document on this step (coach-document-upload).\n- Record any material unresolved gap or formally accepted residual as an Issue — issue_type: exception, source: compliance_review, severity, issue_owner, target_remediation_date — linked to the anchor Control (coach-item-create, coach-items-link).\n\n**Exit criteria** — The Ethics & Compliance Officer confirms the material gaps are closed, or documents the accepted residual risk with an accountable owner; the final coverage achieved is recorded.","label":"Remediate communication gaps","performedBy":{"primitives":["coach-form-fill","coach-document-upload","coach-item-create","coach-items-link"]}},"id":"remediate-communication-gaps"},{"data":{"decisionField":"routing_test_result","description":"Agent checks the internal channels are staffed and within SLA, then submits tagged test reports through an internal channel and the anonymous hotline and traces each to its responsible recipient; the Ethics & Compliance Officer decides whether channel health and routing passed","formData":{"fields":[{"key":"routing_test_result","label":"Intake-to-routing test result","options":[{"label":"Routing confirmed","value":"routing_confirmed"},{"label":"Routing gap identified","value":"routing_gap"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve whether the internal concern-raising channels are genuinely open and whether controlled test reports submitted through an internal channel and through the anonymous hotline both route to the function responsible for acting on that category of concern, within SLA and with hotline anonymity preserved. Owned by the Ethics & Compliance Officer.\n\n**Inputs**\n- The internal channel inventory — one Process item per channel (process_type=operational, process_owner, frequency): manager escalation, compliance mailbox, internal reporting portal, and the audit-committee line — each with its policy response-time commitment (SLA) noted on the Process item description.\n- The quarter's intake volume and response-time metrics/logs for each channel — query artifacts (CSV extracts) attached to this step.\n- The hotline-health summary and vendor evidence from the combined communications and hotline preparation checkpoint.\n- The documented test protocol for tagged controlled submissions.\n\n**Procedure**\n_Items 1–4 are agent-run (folded from the former \"Verify internal concern-raising channels\" step); items 5–8 prepare the test; the human moment is the routing decision below._\n1. Inventory each internal channel through which people can raise a control or compliance concern and confirm each is currently staffed, monitored, and reachable (send or trace a live probe where feasible).\n2. Check each channel's response-time performance against its policy commitment and pull the quarter's intake volume and response-time metrics.\n3. Identify any channel that is broken, unmonitored, or has stale or missing response-time data, and note the owning team.\n4. Compile the channel-health summary with supporting evidence — logs, metrics, or screenshots — for each channel.\n5. Submit a controlled test report through an internal channel and a separate controlled test report through the external and anonymous hotline, each tagged as a test per the documented test protocol.\n6. Trace each test report from intake through triage to confirm it reaches the person or function responsible for that category — HR, security, finance, or legal — within the committed timeframe.\n7. Verify the hotline test submission's anonymity was preserved throughout routing, with no identifying metadata leaked to the receiving function.\n8. Compile the end-to-end test trace with a timestamp at each handoff.\n\n**Decision criteria**\n- Select **Routing confirmed** (`routing_confirmed`) when every internal channel is open and monitored, both test reports were correctly routed to the responsible function within SLA, and the hotline test's anonymity was preserved end to end.\n- Select **Routing gap identified** (`routing_gap`) when a channel is broken or unmonitored, any handoff failed, a route was late against SLA, or the hotline test's anonymity was compromised at any point.\n\n**Record in AssureSwarm** — Submit the `routing_test_result` SELECT. Record the rationale and evidence references in the step result and the decision owner in the step's approver record (coach-form-fill). Attach the timestamped end-to-end trace and the channel-health summary as documents on this step (coach-document-upload) and publish the channel-health summary as a dashboard (coach-dashboard-create); pull and attach the per-channel intake and response-time metrics behind them (coach-query-data). Record any broken, unmonitored, or SLA-missing channel as an Issue — issue_type: deficiency, source: compliance_review, issue_owner, target_remediation_date — linked to that channel's Process item (coach-item-create, coach-items-link). This workflow's direct Control host supplies the control association; when that Control is literally SOX-applicable, its separate Control-hosted SOX testing workflow may consume this evidence rather than duplicating the routing test.\n\n**Exit criteria** — The form is submitted with rationale, the channel-health summary, and the timestamped end-to-end trace attached; every channel needing repair is flagged as a linked Issue; the unused branch is prunable.\n\n> **⚡ Audit Artist accelerator:** `/sox-testing` plans the intake-to-routing test, records the controlled submissions, and builds the reperformable end-to-end trace with per-handoff timestamps.","kind":"decision","label":"Test intake-to-routing pipeline end to end","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload","coach-form-fill","sox-testing","coach-query-data","coach-dashboard-create"]}},"id":"test-intake-to-routing-end-to-end"},{"data":{"description":"Agent diagnoses and coordinates a fix for the failed routing test and re-runs it; human confirms the gap is closed or escalates","instructions":"**Objective** — Diagnose the failed intake-to-routing test, coordinate the fix, and re-run the test to confirm the gap is closed, or escalate if it cannot be closed this cycle.\n\n**Inputs**\n- The timestamped end-to-end test trace and the specific gap detail from the routing test decision.\n- The owning team contacts — the hotline vendor and the internal system/triage owner.\n\n**Procedure**\n1. Diagnose where the routing test failed — a misconfigured triage rule, a missing recipient, a vendor handoff break, or an anonymity leak — and identify the owning team.\n2. Coordinate the fix with the hotline vendor or the internal system owner and document the corrective action and its target date.\n3. Re-run the end-to-end test through the fixed path to confirm the gap is closed, preserving the same test protocol and anonymity checks.\n4. Update the register with the finding, root cause, fix, and re-test result.\n\n**Record in AssureSwarm**\n- Record the finding as an Issue — issue_type: finding, source: compliance_review, root_cause, remediation_plan, issue_owner, target_remediation_date (actual_remediation_date on close) (coach-item-create).\n- Link the Issue to this source routing-test workflow and to the affected channel's Process item — item relationships Issue ↔ source testing workflow, Issue ↔ Process (coach-items-link).\n- Attach the re-test evidence as a document on this step and update this workflow's routing-test step result after a passing re-test (coach-document-upload, coach-item-update).\n\n**Exit criteria** — The Ethics & Compliance Officer confirms the re-test passed and the routing gap is closed, or escalates to the audit committee when it cannot be closed this cycle.","label":"Remediate routing gap","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload","coach-item-update"]}},"id":"remediate-routing-gap"},{"data":{"description":"Ethics & Compliance Officer: Judge whether real concerns reached responsible functions within time and assign exceptions, retaining the complete quarter’s communications and routing evidence.","instructions":"**Objective** — Review actual reported-matter routing and timely action, own every exception and retain the complete quarterly evidence record.\n\n**Inputs**\n- Every real matter reported through the internal channels and the whistleblower hotline during the quarter, excluding the controlled test cases — the quarter's extract from the external hotline case system / compliance mailbox (no Case/Matter item type in AssureSwarm).\n- Each channel's routing map and its committed action timeframe — from that channel's Process item.\n- The verified internal-channel and hotline health summaries and the routing-test step result and evidence package from this Control-hosted workflow, so this review reads against known-good channels.\n- The responsibility-change delta list.\n- The approved communications and the distribution and acknowledgment records, with any remediation of communication gaps.\n- The internal-channel and hotline health summaries.\n- The end-to-end routing test trace (and any routing-gap remediation and re-test).\n- The real-matter routing review.\n\n**Procedure**\n*Autonomous preparation incorporates Close and archive; Ethics & Compliance Officer reviews the combined evidence.*\n1. Pull every concern or matter actually reported through the internal channels and the whistleblower hotline during the quarter, excluding the controlled test cases.\n2. For each reported matter, confirm it was routed to and received by the function or person responsible for acting on it, and check whether it was acted on within the committed timeframe.\n3. Flag any real report that was mis-routed, delayed past its committed timeframe, or has no confirmed recipient of record.\n4. Summarize case counts by category, routing outcome, and time-to-first-action for the quarter.\n5. Assemble the full quarterly evidence package — the delta list, approved communications, distribution and acknowledgment records with any remediation, the internal-channel and hotline health summaries, the end-to-end routing test trace, and the real-matter routing review.\n6. Archive the package to the retention location with the quarter, date, and retention period, linked to the compliance and governance register.\n7. Update the linked records — the control inventory, the hotline vendor record, and the audit-committee reporting log — so the current quarter's status is reflected.\n8. Communicate a closure summary to the audit committee or relevant oversight body noting coverage achieved, channel health, and any open remediation items with owners and dates.\n\n**Record in AssureSwarm**\n- Attach the quarter's real reported-matters extract (excluding test cases) and its routing status as a document on this step — there is no Case/Matter item type, so the matters enter AssureSwarm only as this quarterly extract (coach-query-data, coach-document-upload).\n- Export the routing-review summary and register of routing exceptions as a CSV/XLSX (coach-item-export).\n- Record each mis-routed, late, or unowned matter as an Issue — issue_type: exception, source: compliance_review, issue_owner, target_remediation_date — linked to the affected channel's Process item (coach-item-create, coach-items-link).\n- Export the assembled quarterly evidence package — delta list, approved communications, distribution/acknowledgment records, internal-channel and hotline health summaries, the intake-to-routing test trace, and the real-matter routing review — via coach-workflow-export; the workflow instance itself, archived on the anchor Control, is the durable audit trail.\n- Update the linked records so the quarter's status is reflected — the anchor Control, the hotline Vendor item, and each channel's Process item (coach-item-update).\n- Attach the closure summary memo (PDF/DOCX) to the audit committee as a document on this step; open remediation items remain live as the Issue items created upstream (coach-document-upload).\n- Link the archived package to the compliance and governance register (coach-document-link).\n\n**Exit criteria**\nJudge whether real concerns reached responsible functions within time and assign exceptions, retaining the complete quarter’s communications and routing evidence.\nThe Ethics & Compliance Officer confirms the reviewed real matters were correctly routed and actioned, and that every flagged mis-routing has an owner and a remediation date.\nThe archived record is self-contained and durable enough to serve as audit or regulator evidence without oral explanation — communications, acknowledgment, channel health, routing tests, and real-matter review all present — and the quarterly cycle is formally closed.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the quarter's communications, acknowledgment records, channel-health summaries, routing test trace, and real-matter review into a single archived evidence package.","label":"Review this quarter's reported matters for correct routing","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-export-package","coach-item-create","coach-items-link","coach-workflow-export","coach-item-update","coach-render-package"]}},"id":"review-quarter-reported-matters-routing"}],"sourceTemplateId":"workflow-library:grc-control-responsibility-communications-ethics-hotline"}
