{"description":"ESG-Related Risk Materiality & Integration as a decision-aware workflow. Each cycle runs on the existing portfolio-level ESG Risk item (a Risk with category: esg — e.g. \"ESG / sustainability risk — enterprise\"): it enriches that umbrella entry and the ESG-tagged slice of the Risk register (Risk items tagged category: esg / taxonomies: esg_sustainability) rather than recreating them, and fans per-topic detail out onto the individual Risk items it creates or updates for each impact, risk, and opportunity (IRO). In scope: assessing ESG-related risks across the confirmed environmental, social, and governance topics, entities, and value-chain boundary for this cycle — defining the ESG risk universe (impacts, risks, opportunities), engaging affected stakeholders and information users, assessing double materiality and prioritizing the material topics, mapping controls and management responses, defining KRIs and disclosure metrics, and assembling disclosure inputs. Its named deliverables are the double-materiality assessment (the ranked material topic set with a materiality matrix), the control/response and assurance mapping, the disclosure metrics and leading KRIs, and the framework-mapped disclosure index (ESRS/CSRD, ISSB S1/S2, GRI, SEC climate). Out of scope: any ESG topic, entity, or business unit not named in this cycle's confirmed scope, and the drafting of the external sustainability report itself. It consumes the enterprise risk portfolio and residual positions from the upstream Enterprise Risk Assessment & Portfolio Oversight Cycle and hands its material ESG topics, KRIs, and disclosure inputs to the downstream Quarterly Board & Audit-Committee GRC Reporting workflow rather than duplicating repeated work.","edges":[{"id":"e-prioritize-esg-risks-classify-disposition","source":"prioritize-esg-risks","target":"classify-disposition"},{"id":"e-classify-disposition-create-action-plan","label":"Action","source":"classify-disposition","target":"create-action-plan","whenValue":"gaps"},{"id":"e-classify-disposition-handoff-to-related-workflow","label":"Clear","source":"classify-disposition","target":"handoff-to-related-workflow","whenValue":"complete"},{"id":"e-classify-disposition-escalate-or-accept-risk","label":"Escalate","source":"classify-disposition","target":"escalate-or-accept-risk","whenValue":"monitor"},{"id":"e-create-action-plan-handoff-to-related-workflow","source":"create-action-plan","target":"handoff-to-related-workflow"},{"id":"e-escalate-or-accept-risk-handoff-to-related-workflow","source":"escalate-or-accept-risk","target":"handoff-to-related-workflow"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-RISK-02","UC-RISK-05","UC-RISK-07","UC-RISK-08","UC-RISK-09","UC-GOV-21"],"department":"risk-management","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-esg-risk-materiality-integration","contentDigest":"sha256:31ccdbcde94fb4d63b0cdda9a37195c04fe27dc6b59391d2db4d785f34b57409","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:31ccdbcde94fb4d63b0cdda9a37195c04fe27dc6b59391d2db4d785f34b57409","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-esg-risk-materiality-integration"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-esg-risk-materiality-integration","source":"coworkcanvas-gallery","standards":["coso-erm"],"teams":["risk-management","executive"]},"name":"ESG-Related Risk Materiality & Integration","nodes":[{"data":{"description":"ESG assessment lead and accountable topic owners: Judge materiality using the fixed lens, both applicable axes and stakeholder severity evidence; preserve dissent and validate the ranked topic set that scopes disclosure work.","formData":{"fields":[{"key":"stakeholder_segment","label":"Which group are you answering as?","options":[{"label":"Own workforce","value":"own_workforce"},{"label":"Value-chain worker or supplier","value":"value_chain_worker"},{"label":"Affected community","value":"community"},{"label":"Consumer or end user","value":"consumer"},{"label":"Investor or lender","value":"investor_lender"},{"label":"Regulator or other user of the information","value":"regulator_other_user"}],"required":true,"type":"select"},{"key":"topic_reference","label":"Topic you are rating (topic ID or name from the list sent to you)","required":true,"type":"text"},{"key":"topic_significance","label":"How significant is this topic to you or those you represent?","options":[{"label":"Critical","value":"critical"},{"label":"High","value":"high"},{"label":"Moderate","value":"moderate"},{"label":"Low","value":"low"},{"label":"Not relevant to me","value":"not_relevant"}],"required":true,"type":"select"},{"key":"impact_scale_scope_irremediability","label":"For a negative impact: how widespread is it, how severe, and can the harm be put right?","required":true,"type":"textarea"},{"key":"evidence_or_experience","label":"What experience, incident, or evidence supports your rating?","required":true,"type":"textarea"},{"key":"missing_topic","label":"Any topic missing from the list that you consider material","required":false,"type":"textarea"},{"key":"dissent_flag","label":"My view differs from the consensus in my group and should be recorded separately","required":false,"type":"checkbox"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Fix the ESG assessment basis, build the IRO universe and gather missing stakeholder perspectives, then validate the material topic set using the applicable materiality lens.\n\n**Inputs**\n- The existing portfolio-level ESG **Risk item** (category: esg — e.g. \"ESG / sustainability risk — enterprise\") this cycle runs on, plus the ESG-tagged slice of the Risk register (Risk items with category: esg / taxonomies: esg_sustainability) — the subject already exists; this cycle enriches it rather than creating it.\n- Consumes the handoff package from the upstream **Enterprise Risk Assessment & Portfolio Oversight Cycle** — the enterprise risk portfolio, residual positions, and any ESG-tagged entries — rather than re-deriving them.\n- The confirmed in-scope population for this cycle: the environmental, social, and governance topic areas, the legal entities and business units, and the value-chain boundary (own operations, upstream, downstream) to assess.\n- The applicable reporting frameworks that set the disclosure obligations (for example CSRD/ESRS double materiality, ISSB IFRS S1/S2, GRI, SEC climate rules) and the reporting or assurance reliance for this cycle.\n- The owner registers for first, second, and third-line assignment, and the materiality criteria basis — the impact and financial materiality scales and thresholds.\n- The locked workplan: in-scope topics, entities, value-chain boundary, and the materiality lens.\n- ESG topic taxonomies to anchor completeness (for example the ESRS topical standards E1-E5, S1-S4, G1; SASB industry topics; disclosed topics of sector peers).\n- Internal sources: the enterprise risk register (ESG-tagged entries from the upstream package), incident and grievance logs, prior sustainability reports, and operational/emissions data.\n- External sources: regulatory horizon scans, rating-agency ESG assessments, and sector materiality benchmarks.\n- The ESG risk universe (IROs with value-chain locus and horizon) from the universe-definition stage in this checkpoint — engagement is run against this identified topic set.\n- The locked workplan's materiality lens (double materiality makes stakeholder input mandatory, not optional).\n- The stakeholder map: affected stakeholders (own workforce, value-chain workers, communities, consumers) and users of the information (investors, lenders, regulators), with named representatives or channels.\n- Existing engagement evidence: employee surveys, grievance mechanisms, investor ESG queries, community consultations, customer feedback.\n- The IRO universe from the universe-definition stage with value-chain locus and horizon.\n- The stakeholder input from stakeholder engagement in this checkpoint with impact-severity dimensions and user (financial) signals — the topic and stakeholder evidence are considered together.\n- The materiality lens and thresholds from the locked workplan, and the financial impact scale (magnitude × likelihood) consistent with the enterprise risk criteria.\n\n**Procedure**\n*Autonomous preparation incorporates Lock executable workplan; Define ESG risk universe; Engage stakeholders; ESG assessment lead and accountable topic owners reviews the combined evidence.*\n1. Confirm the final in-scope population — ESG topic areas, entities, business units, and the value-chain boundary — and that each in-scope topic has a named accountable owner.\n2. Fix the materiality lens: state whether the cycle applies double materiality (impact materiality + financial materiality, per ESRS) or single financial-only materiality (per ISSB), because the lens determines what evidence and stakeholder input the later steps must gather. Record the chosen lens and its framework basis.\n3. Assign owners and due dates per activity: risk-universe definition, stakeholder engagement, materiality prioritization, control mapping, KRI/metric definition, and disclosure inputs. Set the review cadence per material topic (default 365-day refresh, tightened for topics near or above appetite or subject to a fast-moving regulation).\n4. State evidence requirements: what each materiality score must cite (data source, stakeholder input, benchmark), where assessment support lives, and the sign-off expected at escalation and closure.\n5. Lock the plan and record it as the baseline so later changes are tracked as dated deltas rather than silent edits.\n6. Enumerate candidate topics against the taxonomy so nothing structurally required is missed: Environmental (climate mitigation and adaptation, pollution, water, biodiversity, circular economy), Social (own workforce, value-chain workers, affected communities, consumers), Governance (business conduct, corruption, political engagement).\n7. For each topic, express the IROs as concrete statements, not labels: the impact (how the company affects people/environment — inside-out) and the risk and opportunity (how the topic affects the company — outside-in). \"Climate\" is a topic; \"physical flood risk to the Gulf Coast plant disrupting output\" is an IRO.\n8. Set the value-chain locus for each IRO (own operations, upstream, downstream) and the time horizon (short/medium/long), because ESRS and ISSB both require horizon-tagged assessment.\n9. Assign a unique ID per IRO and classify to the E/S/G taxonomy; capture the source and date so provenance is auditable.\n10. Deduplicate and relate: merge true duplicates (preserving both source references), and model parent-child where one IRO is a specific manifestation of a broader topic. Never silently delete — record which entry survived and why.\n11. Flag data gaps — topics where the company lacks the data to assess an IRO — as an explicit finding for the disclosure and action steps, rather than scoring them blind.\n12. Segment stakeholders into the two ESRS categories and cover both: affected stakeholders (evidence for impact materiality) and users of sustainability information (evidence for financial materiality). Omitting affected stakeholders is the most common double-materiality defect.\n13. Choose a proportionate method per segment: this step's form for breadth, structured interviews or panels for depth, and existing channels (grievance logs, investor letters) as documentary evidence. Record why each method fits the segment.\n14. Run the engagement against the ESG risk universe: send the identified topic set with the form so each respondent rates the significance of the topics and can surface any topic the universe missed. Capture severity dimensions for impacts — scale, scope, and irremediability — because ESRS scores impact severity on these, not on a single 1-5 feel.\n15. Distinguish signal from volume: a small number of severely affected stakeholders can make a topic material even if few respondents raise it. Do not let response counts override severity.\n16. Log dissent and conflicting views rather than averaging them away, and capture the provenance (who, when, method) for each input so it is auditable.\n17. Feed any newly surfaced topic back to the risk-universe owner as an addition rather than scoring it informally here.\n18. Score impact materiality per IRO on severity (scale, scope, irremediability) and likelihood, using the stakeholder evidence — inside-out. For actual (already occurring) impacts, likelihood is not scored; severity governs.\n19. Score financial materiality per IRO on the magnitude of the potential financial effect (on cash flows, access to finance, cost of capital) and its likelihood over the short/medium/long horizons — outside-in.\n20. Apply the double-materiality rule: a topic is material if it clears the threshold on EITHER axis. Do not require both — a severe human-rights impact with no near-term financial effect is still material under ESRS.\n21. Set and document the threshold before scoring, place each IRO on the materiality matrix, and record the driver behind each score, not just the number.\n22. Rank the material topics and flag concentration/correlation (topics sharing a common driver, e.g. climate transition affecting both stranded-asset risk and workforce reskilling) for portfolio oversight.\n23. Compare each material topic's exposure to appetite and flag above-appetite topics for the disposition step. Have the accountable owners validate the material set — a materiality assessment the business disowns will not survive assurance.\n\n**Record in AssureSwarm**\n- Link this workflow instance to the existing portfolio-level ESG Risk item (category: esg) it runs on, so the cycle is anchored to that register entry (workflow attach).\n- Build the workflow steps with owners and due dates, and assign them (workflow build/assign).\n- Attach the locked workplan (scope, value-chain boundary, materiality lens, owners, dates, evidence requirements, review points) to the step (step document, PDF/DOCX).\n- Create a **Risk item per IRO** — category: esg (or the specific driver category, e.g. compliance_regulatory), taxonomies including esg_sustainability, risk_owner — carrying the IRO statement, its ID, value-chain locus, time horizon, and source reference in description (Risk has no native locus/horizon fields, so they live in the description) (item create).\n- Link each IRO Risk item to the portfolio-level ESG Risk item this cycle runs on, and model parent-child by linking a specific IRO to its broader-topic Risk (items link).\n- Record dedup decisions — the surviving entry and the merge/parent-child rationale — on the step (step document).\n- The form on this step, answered by the engaged stakeholder respondent, captures their segment, the topic they are rating, their significance rating, the impact's scale/scope/irremediability in their own words, the experience or evidence behind the rating, any missing topic, and a dissent flag. Bind the response to the named assignment, collection method and native submission timestamp.\n- Log each stakeholder input against its IRO **Risk item** — segment, method, impact-severity dimensions (scale, scope, irremediability), and provenance — in the Risk item's description/comments (there is no Stakeholder or stakeholder-input item type — this is the honest fallback) (item update).\n- Attach the engagement evidence (form responses, interview notes, consultation records) and the stakeholder map to the step (step document).\n- Update each IRO **Risk item**: set likelihood, impact, and inherent_rating to the governing-axis materiality score (Risk has single likelihood/impact/inherent fields — there are no separate impact-materiality vs financial-materiality fields) (item update).\n- Record both-axis scores (impact materiality and financial materiality), the drivers, the horizon effect, the threshold basis, and each topic's material/not-material status in the step's materiality workpaper (XLSX) — the honest home for the dual-axis detail (step document).\n- Build or refresh the **materiality matrix as a Dashboard** over the IRO Risk items, and record the ranked material topic set on the step (dashboard).\n\n**Exit criteria**\nJudge materiality using the fixed lens, both applicable axes and stakeholder severity evidence; preserve dissent and validate the ranked topic set that scopes disclosure work.\nFinal scope, value-chain boundary, materiality lens, owners, due dates, evidence requirements, and review expectations confirmed and locked; review cadence set per topic; the baseline recorded so downstream changes are tracked as deltas.\nEvery in-scope topic is represented by structured IRO entries with IDs, categories, value-chain locus, and horizon; duplicates resolved with rationale; data gaps flagged; the universe traces to a recognized topic taxonomy for completeness.\nBoth affected stakeholders and information users are engaged with a proportionate, recorded method; input is captured against the topic universe with impact-severity dimensions and provenance; dissent is preserved; newly surfaced topics are routed back to the universe.\nEvery IRO scored on both axes with recorded drivers; the threshold is documented and applied; the material topic set is ranked, matrix-placed, owner-validated, and above-appetite topics flagged; concentration/correlation captured for oversight.\n\n**Form recipient** — this step's form is answered by the engaged stakeholder respondent — an affected stakeholder or a user of the sustainability information, outside this workflow’s assessment, topic-owner, remediation and approval roles. Those executors record their own contributions in native results. Send it with a form assignment; the owner's own work goes in the step result.","label":"Prioritize ESG risks","performedBy":{"primitives":["coach-workflow-build","coach-workflow-assign","coach-workflow-attach","coach-document-upload","coach-item-create","coach-form-fill","coach-query-data","coach-items-link","coach-item-update","coach-notify","coach-dashboard-create"]}},"id":"prioritize-esg-risks"},{"data":{"decisionField":"disposition_path","description":"GRC/ESG-function owner with accountable topic owners: Judge evidenced response effectiveness, residual exposure, metric quality and framework disclosure gaps to select complete, action or formal acceptance.","formData":{"fields":[{"key":"disposition_path","label":"Classify disposition","options":[{"label":"Complete","value":"complete"},{"label":"Gaps require action","value":"gaps"},{"label":"Monitor without immediate action","value":"monitor"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Map responses and assurance, define metrics and KRIs, compile traced disclosure inputs and determine the assessment’s required action or acceptance path.\n\n**Decision criteria**\nInputs for preparation: - The ranked material topic set from **Prioritize ESG risks** with impact/financial scores and appetite positions.\n- The control inventory and existing management responses (policies, targets, transition plans, supplier codes) and their effectiveness evidence.\n- Assurance sources: internal audit ESG coverage, external limited/reasonable assurance on prior metrics, and second-line monitoring.\n- The ranked material topic set from **Prioritize ESG risks** with appetite positions.\n- The framework's required datapoints for the material topics (for example ESRS topical datapoints, ISSB S2 cross-industry and industry metrics, GHG Protocol scopes 1-3).\n- Available data sources and their reliability, and the appetite/tolerance thresholds to anchor KRI limits.\n- The material topic set with scores and appetite positions (**Prioritize ESG risks**).\n- The control/response mapping and residual positions (**Map controls and responses**) — prepared in this checkpoint.\n- The metrics and KRIs with data-quality basis (**Define ESG KRIs and metrics**) — prepared in this checkpoint.\n- The applicable framework's disclosure structure (ESRS datapoints per material topic, ISSB S1/S2, GRI) and the prior period's disclosures for comparability.\n\n*Autonomous preparation incorporates Map controls and responses; Define ESG KRIs and metrics; Report disclosure inputs; GRC/ESG-function owner with accountable topic owners reviews the combined evidence.*\n1. Link each material topic to the controls and responses that mitigate it — preventive (supplier due-diligence, emissions caps) and detective (monitoring, grievance mechanisms) — and identify material topics with no mapped response (a bare exposure) and responses mapped to no material topic (candidate redundancy).\n2. Judge each response against the topic: design (would it, operating as intended, address the impact or the financial risk?) and operating effectiveness (does evidence show it works — targets met, actions on track?). Do not credit an unevidenced target or an aspirational transition plan as an effective control.\n3. Derive residual exposure from inherent minus demonstrated response effect; residual should move only as far as the evidence supports. A \"within appetite\" resting on unmet targets is false comfort — flag it.\n4. Map assurance: which line or party last tested each key response or metric and when, so gaps (a material topic feeding disclosure with no independent assurance) are visible — this matters because ESRS moves from limited toward reasonable assurance over time.\n5. Compare residual to appetite and flag topics above appetite or tolerance for the disposition step.\n6. Map each material topic to its required disclosure metrics first (the framework datapoints), then to leading KRIs for internal monitoring — the two overlap but are not identical.\n7. Prefer leading indicators over lagging counts where possible: a KRI should move before the risk materializes (supplier audit failure rate ahead of a value-chain incident; emissions trajectory vs. target ahead of a transition-plan miss). Tie each KRI to the topic's impact or financial driver.\n8. Set thresholds calibrated to appetite: green/amber/red bands where red aligns to the tolerance limit and amber gives lead time to act. State the measurement, source, formula, boundary (organizational and value-chain), and the owner responsible.\n9. Address data quality explicitly: for each metric state whether the figure is measured, calculated, or estimated, and its assurance-readiness — because a disclosed metric will be assured. Flag Scope 3 and value-chain metrics where estimation is unavoidable.\n10. Set the monitoring cadence per KRI to the indicator's volatility, and define the breach response: who is notified and what happens at amber/red, so a breach triggers action, not just a color change.\n11. Map each material topic to its required disclosures under the applicable framework and produce a disclosure index showing, per datapoint, the source evidence and its location — this index is what an assurance provider and the board will trace against.\n12. Draft the per-topic narrative to the framework's structure: the IRO, its governance and the management response/policy, the targets and actions, and the metrics with methodology and boundary. Keep methodology footnotes with each figure.\n13. Apply the phase-in and comparability rules: mark datapoints subject to phase-in, and reconcile any restated prior-period figure with a stated reason — an unexplained restatement is an audit flag.\n14. Run a completeness and consistency check: every material topic has its mandatory datapoints (or a documented data-gap explanation), and the numbers in the narrative tie to the metric items and the KRI dashboard.\n15. Compile the open data gaps and assurance gaps as explicit findings for the disposition step, rather than papering over them.\n\nJudge the material topic set against appetite, response effectiveness, and disclosure readiness, and state counts in the rationale (how many topics fall to each path, in which E/S/G categories, and how many are above appetite) so the downstream step sizes its work:\n\n- **Complete (`complete`)** — the assessment is current and within appetite: residual ESG exposures sit within tolerance, responses on material topics are effective with assurance coverage, KRIs are green, and disclosure inputs are complete with no material data gap. Route straight to the final package.\n- **Gaps require action (`gaps`)** — one or more material topics need treatment: residual above appetite with a viable response, an unmitigated material topic, a material data or assurance gap that blocks disclosure, or a red KRI with a fixable cause. These need an owned action plan with root cause and dates. Route to create the action plan.\n- **Monitor without immediate action (`monitor`)** — a material topic is above appetite or otherwise notable but no cost-justified treatment exists this period, so it is knowingly carried: it needs a formal risk acceptance or an escalation to the authority that can accept it, plus monitoring — not a remediation plan. Route to escalate or accept the risk.\n\n**Record in AssureSwarm**\n- Link each material topic **Risk item** to the **Control items** that mitigate it and to any governing **Policy items** (ESG policies, supplier codes of conduct); targets and transition plans that are neither Control nor Policy attach as step documents (no native type) (items link, step document).\n- Link each topic Risk to the **Audit items** and **Controls** that are its assurance sources; where a Control-hosted SOX testing workflow last tested the response or metric, cite that workflow result through its direct Control host (items link).\n- Update each topic Risk: set residual_rating from demonstrated response effectiveness, and treatment (mitigate) where a response is credited (item update).\n- Record the effectiveness basis and the appetite position (within or above appetite) on the step — Risk has no appetite field (step document).\n- Record the metrics and KRIs — thresholds (green/amber/red bands), source, formula, boundary, data-quality basis (measured/calculated/estimated), cadence, and owner — in a metric/KRI definition register (XLSX) on this step; there is no Metric or KRI item type, so this register plus the dashboard are the ground truth (step document).\n- Build or refresh a **KRI monitoring Dashboard** over the material-topic Risk items and link it to the workflow (dashboard).\n- Compile the **disclosure index** (XLSX) mapping each framework datapoint to its source evidence and location, and link the supporting artifacts to it (document link).\n- Create an **Issue item** for each data or assurance gap that blocks disclosure — issue_type: deficiency (or observation), source: self_assessment, issue_owner, identified_date — linked to its topic Risk item (item create, items link).\n- Attach the drafted per-topic disclosure narratives (DOCX) and the completeness/gap log to the step (step document).\n- Submit the decision form: `disposition_path` (the branch), the step result with the counts and the appetite/disclosure-readiness basis, and the step's approver record.\n\n**Exit criteria**\nJudge evidenced response effectiveness, residual exposure, metric quality and framework disclosure gaps to select complete, action or formal acceptance.\nEvery material topic is mapped to its responses (or flagged as unmitigated) and to its assurance; residual exposure is evidence-based, not assumed; above-appetite topics flagged; assurance gaps on disclosed topics are visible.\nEach material topic has its required disclosure metrics and leading KRIs with appetite-calibrated thresholds, named sources, boundaries, owners, and cadence; data-quality/assurance-readiness recorded per metric; breach-response routing defined; the dashboard reflects current status.\nDisclosure index complete for every material topic with each datapoint traced to source; per-topic narratives drafted to the framework structure with methodology footnotes; phase-in and restatements marked and reconciled; figures tie to the metric items and dashboard; data and assurance gaps logged as findings.\nForm submitted; the rationale reconciles topic counts to the chosen path and names above-appetite and gap topics; the unused branches are prunable because branch edge values match the selected form value.","kind":"decision","label":"Classify disposition","performedBy":{"primitives":["coach-items-link","coach-item-update","coach-query-data","coach-item-create","coach-dashboard-create","coach-document-upload"]}},"id":"classify-disposition"},{"data":{"description":"Create an owned action plan for gaps","instructions":"**Objective** — Turn each ESG gap into an owned, dated action plan with root cause, interim mitigation, and validation evidence, so above-appetite topics, unmitigated impacts, and disclosure data gaps have a credible path to resolution rather than an open flag.\n\n**Inputs**\n- The gap topics from the disposition decision, with residual positions and appetite.\n- The mapped responses and the assurance/data gaps per topic, and the required disclosure datapoints still missing.\n- The first-line topic owners and the treatment options (mitigate, transfer, avoid) plus data-remediation options for measurement gaps.\n\n**Procedure**\n1. Establish root cause for each gap — why residual sits above appetite, why the response is absent or ineffective, or why the data cannot be measured/assured. Fixing a missing metric without the underlying data process rebuilds the gap next cycle.\n2. Choose the treatment: mitigate (a new/strengthened response, target, or transition action), transfer, avoid, or — for measurement gaps — a data-remediation action (new data source, boundary fix, methodology). Acceptance is not an action-plan outcome; that path is the monitor branch.\n3. Name a single accountable owner and a due date per action; where the exposure is live now, record an interim mitigation or interim disclosure treatment (estimated with a stated basis) that holds until the fix lands.\n4. Define validation evidence up front: what will prove the gap closed (a passing assurance test, a KRI returning to green, a measured datapoint replacing an estimate) — decided before work starts, not chosen after.\n5. Set a reporting cadence so progress is visible to the ESG/risk committee, and link each action to its topic.\n\n**Record in AssureSwarm**\n- Create an **Issue item per gap** — issue_type: deficiency (or finding), source: self_assessment, root_cause, remediation_plan (the treatment, interim mitigation, and the validation evidence that will close it), issue_owner, identified_date, target_remediation_date — and link each to its topic Risk item (item create, items link).\n- Record the reporting cadence on the step (step document).\n\n**Exit criteria** — Every gap has an owned, dated plan with root cause, treatment (including data-remediation where relevant), an interim mitigation where needed, and pre-defined validation evidence; each plan links to its topic; the reporting cadence is set.","label":"Create action plan","performedBy":{"primitives":["coach-item-create","coach-items-link"]}},"id":"create-action-plan"},{"data":{"description":"Escalate to risk owner, GRC lead, executive sponsor, or board delegate or document risk acceptance","instructions":"**Objective** — For each monitor-path ESG topic, prepare a decision memo that either escalates the above-appetite exposure to the authority that can accept it or documents a formal, time-bound risk acceptance with conditions and follow-up ownership, so carried ESG risk is a governed choice and not a silent one.\n\n**Inputs**\n- The monitor-branch topics with residual positions and appetite.\n- The appetite statement and the escalation authority matrix (who can accept ESG risk at which level — topic owner, GRC/ESG lead, executive sponsor, board/committee delegate).\n- The rationale for carrying rather than treating (no cost-justified response this period) and any compensating measures.\n\n**Procedure**\n1. Quantify the exposure being carried: residual severity and financial effect, the amount over appetite, and the plausible impact and velocity — an acceptance without a quantified exposure is a blank cheque.\n2. Match the decision to authority: the higher the residual over appetite, the higher the acceptance authority. A topic materially above appetite is not accepted by its own first-line owner — it escalates to the executive sponsor or board/committee delegate per the matrix.\n3. Draft the decision memo: the topic, why treatment is deferred, the compensating measures, the exposure quantification, and the recommendation (escalate for decision, or accept).\n4. For acceptances, capture conditions and an expiry: what must stay true, the KRIs that would void the acceptance, and a re-decision date. A perpetual acceptance is permanent unmanaged risk — every acceptance is time-bound.\n5. Define follow-up ownership: who monitors the accepted or escalated topic and who re-opens it at expiry or on a breach.\n\n**Record in AssureSwarm**\n- For an accepted topic, record the acceptance as an **Issue item** — issue_type: policy_exception, exception_approver (the accepting authority), exception_expiry_date (the time-bound re-decision date — the filterable expiry index), issue_owner (the follow-up owner), with the conditions and the voiding KRIs in its description — linked to the topic **Risk item**, and set treatment: accept on that Risk (item create, items link, item update).\n- Attach the per-topic decision memo (DOCX/PDF) to the step (step document).\n- Notify the escalation authority and record the follow-up owner (notify).\n\n**Exit criteria** — Each monitor-path topic has a decision memo with quantified exposure; acceptances are approved at the authority matching the over-appetite level, time-bound, and conditioned; escalations are routed to the right authority; follow-up ownership and re-decision dates are set.","label":"Escalate or accept risk","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload","coach-item-update","coach-notify"]}},"id":"escalate-or-accept-risk"},{"data":{"description":"Quarterly Board Reporting receiving owner and ESG/risk-function owner: Accept the materiality/disclosure package and its limitations for board reporting, take ownership of the received output and obtain the ESG/risk-function owner’s formal handoff sign-off.","instructions":"**Objective** — Compile the validated materiality and decided gap/acceptance record, deliver it to board reporting and retain the archive and monitoring schedule.\n\n**Inputs**\n- The owner-validated material topic set with impact/financial scores and appetite positions.\n- The control-response and assurance mapping, the metrics/KRIs and their status, the disclosure index and gap log, the action plans (gaps branch), and the acceptance/escalation memos (monitor branch).\n- The linked outputs of any related workflow and the unresolved constraints logged along the way.\n- The final package: the material topic set, above-appetite topics, action plans, acceptances and escalations, metrics/KRIs, and the disclosure inputs and gaps, plus the governance decision it supports.\n- The named downstream workflow and its owner.\n- The assumptions and limitations logged during the cycle.\n- The records-retention schedule for ESG governance and disclosure records (aligned to the reporting/audit retention period).\n- Open threads: action plans in flight, risk acceptances with expiry dates, metrics/KRIs to keep monitoring, and scope changes for the next cycle; the review cadence and the next scheduled cycle date.\n\n**Procedure**\n*Autonomous preparation incorporates Prepare final package; Quarterly Board Reporting receiving owner and ESG/risk-function owner reviews the combined evidence.*\n1. Compile the package in the order a reviewer reads it: materiality summary (material topics by E/S/G, above-appetite topics, movement since the last cycle), then topic-level detail with scores and evidence, then responses and residual, then metrics/KRIs and disclosure readiness, then action plans, acceptances, and open constraints.\n2. Test against re-performance: could a reviewer holding only this package reconstruct each materiality score and its basis? Any \"see the assessment\" external reference fails — pull the artifact in.\n3. Spot-check every figure against source — the register, the metric items, the KRI dashboard, the disclosure index — before publishing; a summary count that does not tie undermines the whole package.\n4. State the proposed conclusion and the governance decision it supports (for example material set approved, escalations tabled for the committee), plus what remains open with named owners.\n5. Note explicitly what the downstream board-reporting workflow should consume and not re-derive, so the handoff is clean.\n6. Create or link the downstream **Quarterly Board & Audit-Committee GRC Reporting** workflow and attach the final package; it consumes the material topics, above-appetite exposures, escalations/acceptances, and disclosure-ready metrics for board-level reporting.\n7. State the handoff contract: what is authoritative here (materiality scores, ownership, response mapping, disclosure index) and therefore should not be re-derived, versus what the downstream workflow extends (board narrative, committee framing).\n8. Pass assumptions and limitations forward explicitly — provisional topics, deferred value-chain segments, estimated metrics, acceptances nearing expiry — so downstream work inherits them rather than rediscovering them.\n9. Confirm the receiving owner acknowledges the handoff so the package does not land unowned. Before treating the cycle as closable, check it is: the material set is owner-validated, escalations and acceptances are decided, action plans are owned and dated, and disclosure inputs are complete or their gaps are owned. An undecided escalation is not closable.\n10. Export the final workflow record and archive it with the package in the designated governance repository under retention and immutability controls; record the archive location and reference, and verify retrievability by opening the archived copy. Any post-archive correction is a new dated addendum, never an edit to the sealed record.\n11. Update the control execution log for UC-RISK-02, UC-RISK-05, UC-RISK-07, UC-RISK-08, UC-RISK-09, and UC-GOV-21 with the cycle period, completion date, and result — this is what demonstrates on-cadence ESG risk and governance execution when the control is sampled.\n12. Create carry-forward items, each with an owner and due date: action plans continuing past close, risk acceptances due for re-decision at expiry, metrics/KRIs to monitor, and scope changes for the next cycle. An acceptance that renews silently is how temporary risk becomes permanent.\n13. Communicate the outcome to stakeholders and confirm the next cycle is scheduled at the policy cadence; the ESG/risk-function owner's handoff sign-off on this step is the formal closure declaration.\n\n**Record in AssureSwarm**\n- Compile the package and link each evidence artifact (the IRO Risk items, the materiality workpaper, the disclosure index, and the action-plan Issues) back to its producing step (document link).\n- Attach the compiled evidence-and-decision package (PDF/DOCX) and the materiality summary to the step (step document).\n- Record each receiving owner’s actual acceptance in native approvals, with scope and limitations in the native result. Retain the source owner’s closure sign-off where the procedure requires it.\n- Link the downstream workflow and attach or link the final package (workflow attach, document link).\n- Record the handoff contract, the assumptions passed forward, and the acknowledging owner on the step.\n- Export the workflow record and attach the closure record with the archive location and reference to the step (workflow export, step document).\n- Create the carry-forward items as **Issue items** (issue_owner, target_remediation_date) — continuing action plans and acceptance re-decisions at expiry — and record the metric/KRI monitoring and next-cycle scope changes on the step (item create, step document).\n- Record the control execution log update (UC-RISK-02/05/07/08/09, UC-GOV-21) and the next cycle date on the step (step document).\n\n**Exit criteria**\nAccept the materiality/disclosure package and its limitations for board reporting, take ownership of the received output and obtain the ESG/risk-function owner’s formal handoff sign-off.\nPackage assembled in reviewer order and passes the re-performance test with no external references; every summary figure traces to source; the proposed conclusion and open items are stated with owners; ready for the governance decision and handoff.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` compiles the linked material topics, scores, evidence, metrics, disclosure index, and action plans into the ordered, self-contained package with source cross-references.\nThe downstream workflow is linked and holds the final package; the handoff contract names what not to re-derive; assumptions and limitations are passed forward; the receiving owner has acknowledged. The final record is archived, verified retrievable and immutable, with its reference recorded; the control execution log is updated for all linked controls; every open thread exists as a carry-forward item with an owner and due date; the next cycle is scheduled; and the ESG/risk-function owner's sign-off on this step closes the cycle.","label":"Handoff to related workflow","performedBy":{"primitives":["coach-render-package","coach-document-upload","coach-workflow-attach","coach-workflow-export","coach-item-create"]}},"id":"handoff-to-related-workflow"}],"sourceTemplateId":"workflow-library:grc-esg-risk-materiality-integration"}
