{"description":"Runs on the existing risk item. Scan the forward horizon for signals of an emerging exposure, assess plausibility and velocity, and decide whether it enters the register or stays on the watchlist. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[],"isPublic":true,"itemTypeSlug":"risk","metadata":{"capabilities":["emerging-risk-horizon-scan"],"controlVerbs":{"UC-RISK-07":"operates","UC-RISK-11":"operates"},"controls":["UC-RISK-07","UC-RISK-11"],"department":"risk-management","domains":["grc"],"kind":"emerging-risk-horizon-scan","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:emerging-risk-horizon-scan"}],"canonicalUrl":"https://workflow-library.com/all/?w=grc-emerging-risk-horizon-scan","contentDigest":"sha256:83efcfa5d3fb60eaa22ea6b249b2a86fe028af2f318a41e7613ed1982c4db22a","prerequisites":{"anchorItemType":{"slug":"risk"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:reg-horizon-scanning-triage"}],"roles":[{"contribution":"variance","description":"Risk horizon review panel. Approve scan record and watchlist disposition.","id":"reviewer-1","nodeIds":["horizon-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:emerging-risk-horizon-scan"}],"releaseId":"sha256:83efcfa5d3fb60eaa22ea6b249b2a86fe028af2f318a41e7613ed1982c4db22a","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-emerging-risk-horizon-scan"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-emerging-risk-horizon-scan","source":"coworkcanvas-gallery","standards":[],"teams":["risk-management"]},"name":"Emerging Risk & Horizon Scan","nodes":[{"data":{"controls":["UC-RISK-07","UC-RISK-11"],"instructions":"**Objective**\nApprove scan record and watchlist disposition. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, strategy and objective statements, prior scan output and watchlist, regulatory and technology intelligence, peer and industry reporting, threat feeds, scenario libraries, and the risk taxonomy.\n2. Use the agreed source list, published intelligence and reporting, internal incident and near-miss data, stakeholder observations, prior watchlist entries and their status, and the qualification criteria.\n3. Use the screened watchlist, scenario analysis, existing control and continuity capability, exposure and dependency maps, expert input, comparable events elsewhere, and the approved risk criteria.\n4. Review all stage records, the signal inventory and its attribution, screening rejections, plausibility and velocity reasoning, dispositions, trigger conditions, dissenting views, and declared blind spots.\n\n**Procedure**\n1. Fix the horizon window, select the domains and objectives in scope, enumerate the sources to be consulted with their reliability, define the signal qualification criteria, and document sources deliberately excluded.\n2. Record each signal with its source and date, apply the qualification criteria consistently, retain signals that fail screening with the reason, look for convergence between weak signals, and challenge confirmation bias in retained selections.\n3. Evaluate plausibility against evidence rather than vividness, rate velocity, estimate impact ranges under stated assumptions, assess current preparedness, define observable trigger conditions, and challenge both dismissal and alarm.\n4. Trace promotions and closures to their evidence, verify trigger conditions have named observers and a cadence, confirm dissent remains visible, reconcile promotions with register entries, and return unsupported dispositions with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the scan horizon, domains and objectives covered, source list with reliability notes, qualification criteria, exclusions and their rationale, accountable scanner, and known blind spots. Also record scan sources.\n2. Document the signal inventory with source and date attribution, screening basis and criteria applied, retained and rejected signals with reasons, convergence observations, and source coverage that returned nothing.\n3. Document plausibility reasoning, velocity rating, impact range with assumptions, preparedness assessment, disposition, trigger conditions with named observers, and dissenting views retained. Also record watchlist disposition.\n4. Capture the authorized reviewer, the scan summary, accepted dispositions, effective scan date, next scan cadence, promoted register references, retained watchlist entries, blind spots, owners, and due dates. Also record horizon scan summary.\n\n**Exit criteria**\nRisk horizon review panel provides variance: The horizon and source coverage are explicit, qualification criteria are stated in advance of screening, and blind spots are visible rather than implied. Every retained signal is traceable to a dated source, rejections are reasoned rather than silent, and the candidate watchlist is ready for assessment. An approver accepts that each disposition follows from the assessed evidence, trigger conditions are observable and owned, and uncertainty is expressed rather than resolved by assertion. The authorized reviewer accepts the scan as a traceable record of forward-looking analysis, watchlist and register stay reconciled, and closure implies no assurance that unscanned exposures do not exist.","kind":"task","label":"Approve scan record and watchlist disposition","requiredApprovals":1},"id":"horizon-closure"}],"sourceTemplateId":"workflow-library:grc-emerging-risk-horizon-scan"}
