{"description":"Quarterly management review of one process area - the process area's own oversight run. The domain owner reviews the registers the domain operates (systems, tenants, audits), the health and evidence of the operating-process runs, the domain's risks, issues and metrics, and the operation of its controls, then records direction and a dual sign-off. Instantiated once per process area; the operating processes keep their own runs.","edges":[],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-RISK-13","UC-RISK-14","UC-GOV-21"],"department":"risk-management","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-domain-oversight-management-review","contentDigest":"sha256:d61ea8f4d4988817a3771d780f21c98336cf07ac4f1b9cb318e7913dd738d1fa","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:d61ea8f4d4988817a3771d780f21c98336cf07ac4f1b9cb318e7913dd738d1fa","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-domain-oversight-management-review"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-domain-oversight-management-review","source":"coworkcanvas-gallery","standards":["coso-erm","iso-31000","nist-800-53","soc2"],"teams":["risk-management","executive"]},"name":"Domain Oversight and Management Review","nodes":[{"data":{"description":"Domain owner and independent reviewer: Review the complete domain evidence, challenge exceptions and high-tier risk treatments, and jointly approve next-quarter priorities and resource or policy direction.","instructions":"**Objective** — Review the domain’s inventory, operating evidence, risk and control posture and obtain the domain owner’s and independent reviewer’s separate approvals of management direction.\n\n**Inputs**\nThe linked request or system record, the approved procedure and configuration, and the reviewed outputs of prerequisite steps. Resolve the named operating and approving roles before execution.\n\n**Procedure**\n*Autonomous preparation incorporates Confirm Domain Scope and the Register; Review Operating Evidence and Run Health; Review Domain Risks, Issues and Metrics; Review Control Operation and Exceptions; Domain owner and independent reviewer reviews the combined evidence.*\n1. Confirm the domain's scope statement and operating-process inventory are current, then review the register items linked on this step - the systems, tenants, or audit engagements this domain operates. For each register item confirm the record is present, its owner and criticality are current, and nothing operated in the quarter is missing from the register. A register gap found here is recorded as an issue before the review proceeds.\n2. Review the quarter's operating evidence across the domain, including attached workflow runs, on-time completion, overdue steps, and evidence completeness. Sample one closed run per process and record exceptions.\n3. Review risk posture, open issues and their age, metric trends, and residual-rating changes. Confirm every open high-tier risk has a current treatment decision and accountable owner.\n4. Review failed or missed control executions, corrective actions, and compensating measures. Confirm each recorded control failure either closed or carries an owner, due date, and interim containment.\n5. Record the management review conclusion, next-quarter priorities, resource or policy changes, and escalations. The domain owner and independent reviewer provide the two required approvals.\n\n**Record in AssureSwarm**\nRecord the actions and evidence examined, their actual dates and source references, the responsible role, the human decision and unresolved exceptions in this step's result. Attach or link the evidence using the supported record and review path. Never record credentials or secret values.\n\n**Exit criteria**\nReview the complete domain evidence, challenge exceptions and high-tier risk treatments, and jointly approve next-quarter priorities and resource or policy direction.\nThe procedure's stated checks and authorized human decision are supported by evidence; failed checks or unresolved conditions remain visible with an owner and next action. Approval to execute and approval to close remain separate where the procedure requires them.","kind":"task","label":"Management Review Sign-off and Direction","requiredApprovals":2},"id":"signoff"}],"sourceTemplateId":"workflow-library:grc-domain-oversight-management-review"}
