{"description":"Periodic review of selected COBIT 2019 governance and management objectives, run per cycle on an Audit item (audit_type: it_audit; scope = the in-scope objectives; period_start/period_end = the assessment cycle) that the workflow instance attaches to and archives at close. Each in-scope COBIT objective is a Process item (process_type: it_general_control) linked to that Audit, and the review produces named deliverables against it: an evidence register and pre-scored capability sheet, a signed capability profile, a gap table with the benchmark decision, a committed improvement roadmap of Issue initiatives, and the governance board report and dashboard. In scope: the COBIT 2019 objectives selected for this cycle, each with a justified 0-5 target capability level, a named accountable owner, and the review cadence; out of scope: objectives explicitly excluded with recorded rationale. Self-originating: its scope sheet and target profile are supplied as workflow inputs, and it hands off to no distinct downstream workflow — the carry-forward improvement Issues and the archived instance seed its own next cycle.","edges":[{"id":"e-benchmark-against-targets-report-to-board","label":"Targets met","source":"benchmark-against-targets","target":"report-to-board","whenValue":"targets_met"},{"id":"e-benchmark-against-targets-build-roadmap","label":"Improve","source":"benchmark-against-targets","target":"build-roadmap","whenValue":"improvement_needed"},{"id":"e-build-roadmap-report-to-board","source":"build-roadmap","target":"report-to-board"},{"id":"e-report-to-board-track-actions","source":"report-to-board","target":"track-actions"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-GOV-01","UC-AUDIT-22","UC-RISK-14","UC-BCDR-05","UC-GOV-10","UC-GOV-11","UC-GOV-12","UC-GOV-13","UC-GOV-20","UC-SDLC-02","UC-SDLC-08","UC-SDLC-09","UC-SDLC-12","UC-SDLC-13"],"department":"executive","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-it-governance-cobit-review","contentDigest":"sha256:10127d5f20ad531fc57130095f92fb97dcdcf60abc15a77096891474c8966351","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:10127d5f20ad531fc57130095f92fb97dcdcf60abc15a77096891474c8966351","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-it-governance-cobit-review"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-it-governance-cobit-review","source":"coworkcanvas-gallery","standards":["cobit-2019","coso-ic"],"teams":["executive","it"]},"name":"IT Governance Objective Review (COBIT)","nodes":[{"data":{"decisionField":"assessment_outcome","description":"Review lead and accountable review owner with objective owners/operators: Challenge source evidence and interview contradictions, sign supported capability scores and decide whether target shortfalls are material or explicitly acceptable.","formData":{"fields":[{"key":"assessment_outcome","label":"Benchmark against targets","options":[{"label":"Targets met","value":"targets_met"},{"label":"Improvement needed","value":"improvement_needed"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Gather and challenge evidence, validate operation with owners, sign the capability profile and decide whether it meets the approved targets.\n\n**Decision criteria**\nInputs for preparation: - The approved objective scope sheet and target capability profile — uploaded to this step as PBC/external documents. Set up each in-scope objective as a Process item (process_type: it_general_control) linked to the anchor Audit (item relationship Audit ↔ Process), mirror the scope summary to Audit.scope and each objective's named accountable owner to its Process.process_owner; the documented exclusions, the assessment cadence, and the justified 0–5 target per objective live in the scope-sheet/target-profile documents (there is no native capability-level field — see the record note below).\n- For each objective, its COBIT component set: the process (governance/management practices and their activities), organizational structures, information flows and items, people/skills/competencies, policies and procedures, culture and behavior, and services/infrastructure/applications — capability rests on the components, not the process alone. Uploaded as the COBIT reference/component-mapping document to this step (framework content, not native items).\n- Source systems and repositories: the policy library, committee charters and minutes, accountability/RACI charts, process metrics and management reports, tool and configuration exports, and incident/problem history — external systems outside AssureSwarm; evidence extracts are uploaded to this step and linked to the objective Process items. Prior audit and assessment results are existing Audit items (rating, opinion, report_date) and their open Issue items, queried here; the prior-cycle capability scores for trend come from the prior cycle's archived instance / score-sheet document on its Audit.\n- The released evidence register, the provisional capability scores, and the per-objective interview guides.\n- The accountable owner and the key operators for each objective — the people who run the practices day to day, not only their managers.\n- The prior-cycle scores, for movement context during the interview.\n\n*Autonomous preparation incorporates Gather evidence and pre-score; Validate with process owners; Review lead and accountable review owner with objective owners/operators reviews the combined evidence.*\n1. Gather evidence per objective and map each item to a specific practice or activity. For a management objective like DSS02 (managed service requests and incidents), that means the incident policy, the ITSM tool configuration, MTTR/SLA metrics, and a sample of incident records — not just the existence of a policy. Build an evidence register: one row per practice/activity, the evidence item, its source, and its date.\n2. Flag evidence that is missing, stale (older than the review period or superseded), or contradictory (the policy asserts one thing, the metrics show another). Assign each objective’s participating process owner the outstanding evidence items with a due date; have them supply source documents and their explanation in the native result; an unfilled evidence gap is itself a finding about the objective's documentation and monitoring discipline.\n3. Pre-score each practice on the COBIT Performance Management rating scale: Not (0–15%), Partially (>15–50%), Largely (>50–85%), Fully (>85–100%) achieved. Under CPM a capability level is reached only when the activities assigned to that level are Largely or Fully achieved and every lower level is satisfied — so one Not-achieved activity at level 2 caps the objective at level 1 no matter how mature its level-4 activities look. Roll practice ratings up to a provisional capability level (0–5) per objective.\n4. Cite the specific evidence behind every rating (register row references), and mark any rating resting on incomplete or single-source evidence as low confidence — those are what the interviews must resolve.\n5. Draft an interview guide per objective targeting the low-confidence ratings, the evidence gaps, and the contradictions; open-ended \"tell me about your process\" questions waste the session.\n6. Review before release: spot-check that each citation actually supports its rating, challenge any score that moved sharply from the prior cycle or sits exactly on an achievement threshold (86% Fully vs. 85% Largely flips a level), and confirm the guides cover the flagged questions before owner validation in this checkpoint.\n7. Schedule the interviews and send each attendee their objective's guide, pre-scores, and open questions ahead of the session so owners arrive prepared; an ambush interview yields defensiveness, not evidence.\n8. In the session, walk through how each practice operates — not \"do you have a policy\" but \"show me the last time this ran.\" Capture responses with attendees, roles, and date. Distinguish fact from opinion, and specifically log the exceptions, workarounds, informal steps, and recent failures owners describe. A practice that works only because one person heroically patches it is not Established (level 3); it is Performed and fragile.\n9. Reconcile what you heard against the evidence register. Where testimony and evidence agree, confirm the rating; where they diverge, documented evidence generally outranks assertion unless the owner produces new evidence on the spot. Adjust the affected practice ratings and the provisional capability level accordingly.\n10. Document a rationale for every adjustment with an interview or evidence citation — an unexplained score change is the first thing an independent reviewer challenges. A rating still resting on incomplete evidence after the interview is flagged as such, not quietly upgraded to close the gap.\n11. Produce the final capability score sheet per objective: the pre-score, the adjusted score, what changed and why, and any residual low-confidence rating with the reason it could not be resolved.\n12. The review lead confirms every in-scope objective had at least one owner interview, that each adjustment traces to a citation, and signs the final scores as the assessed capability profile.\n\nBuild the gap table first: for each in-scope objective, the signed capability level minus the approved target, giving gap size and direction (at or above target, or short by N levels). Classify each shortfall by materiality — a function of the gap size and the risk relevance of the objective. A one-level gap on a high-risk objective (EDM03 ensured risk optimization, DSS05 managed security services, or a SOX-relevant SDLC objective) is material; the same gap on a low-priority objective may be an acceptable variance. Add prior-cycle trend so a gap that is closing reads differently from one that is widening.\n\n- **Targets met (`targets_met`)** — every in-scope objective is at or above its target, or the only shortfalls are immaterial variances on low-risk objectives that the review owner explicitly accepts and documents. No material gap remains to remediate, so the review proceeds straight to board reporting on a targets-met conclusion. A gap parked as \"we will accept it\" still needs the acceptance recorded here, not left silent.\n- **Improvement needed (`improvement_needed`)** — one or more material gaps exist: a capability shortfall on a high-risk or high-priority objective, or a cluster of gaps that together pull a focus area's maturity below target. Name each material gap in the rationale — which objective, current versus target level, and why it is material — because the roadmap step builds initiatives directly from this list.\n\n**Record in AssureSwarm**\n- Attach the evidence register and the pre-scored capability sheet to this step as documents (XLSX).\n- The objective’s accountable process owner records their evidence response in the native result: the objective and practice, the item requested, whether evidence is attached, held elsewhere, not maintained, or not applicable, the file itself, its system of record and coverage date, how the practice actually runs day to day including workarounds, and who answered when.\n- Ensure each in-scope objective exists as a Process item (process_type: it_general_control, process_owner) linked to the anchor Audit (item relationship Audit ↔ Process), and link each evidence document to the objective's Process item it supports (item relationship). The per-practice CPM ratings and the provisional 0–5 capability level live in the register document — there is no capability-level field on Process, so cross-cycle trend is read from these documents.\n- Record the outstanding-evidence requests with owners and due dates on this step, and mark the low-confidence ratings for the interview stage.\n- Attach the interview notes and the final signed capability score sheet to this step as documents (XLSX score sheet + interview notes).\n- Link the interview evidence to the affected objectives' Process items (item relationship). Mirror the overall assessed conclusion to Audit.rating (satisfactory | needs_improvement | unsatisfactory); the per-objective 0–5 levels stay in the score-sheet document (no capability-level field).\n- Record the sign-off (review lead and date) in native approvals before benchmarking the signed profile within this checkpoint.\n- Submit the decision form: `assessment_outcome` (the branch), the step result citing the specific objectives and gaps with their materiality classification and trend, and the step's approver record.\n- Attach the gap table (signed score vs. target, gap size and direction, materiality, trend) to this step as the decision evidence (document upload).\n\nRecord in the native step result or attached source documents: COBIT objective and practice the request relates to (objective_reference); Requested evidence item, as listed on the request (evidence_item_requested); Your response to this request (response_status); Evidence file or export (evidence_file); System of record it came from and the date it covers (evidence_source_and_date); How this practice actually runs day to day, including any workaround or exception (how_the_practice_operates); Your name and role for this objective (responder_role); Date submitted (response_date). Use native approvals for sign-off.\n\n**Exit criteria**\nChallenge source evidence and interview contradictions, sign supported capability scores and decide whether target shortfalls are material or explicitly acceptable.\nEvery in-scope objective has an evidence register mapped to its practices, a provisional capability level with per-rating citations, and an interview guide targeting its gaps and low-confidence scores; outstanding evidence requests are issued with owners and dates; the register is ready for owner validation within this checkpoint.\nEvery in-scope objective was interviewed with at least one owner; each score adjustment carries an interview or evidence citation; residual low-confidence ratings are flagged rather than hidden; the review lead has signed the final capability profile.\nThe form is submitted with a rationale that dispositions every objective as at-target or gapped and every gap as material or acceptable; the gap table is attached; the not-selected branch is prunable because the rationale fully states whether remediation work remains.","kind":"decision","label":"Benchmark against targets","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-items-link"]}},"id":"benchmark-against-targets"},{"data":{"description":"Agent drafts the improvement roadmap with owners, milestones, and dependencies; human sponsors and owners commit to it","instructions":"**Objective** — Turn the material capability gaps into a sequenced, owned, and funded improvement roadmap that owners have accepted and sponsors have committed, so the board sees a plan rather than a wish list.\n\n**Inputs**\n- The gap table and the step result naming each material gap (objective, current versus target level, why material).\n- The affected objectives' components — a capability uplift usually needs more than a process tweak; it touches organizational structures, skills, policies, and tooling.\n- The in-flight program/project portfolio, resource capacity, and budget calendar, for realistic sequencing and funding.\n\n**Procedure**\n1. Define one or more initiatives per material gap. For each, state which practices/activities it strengthens and the specific capability uplift targeted — e.g., \"raise APO12 (managed risk) from level 2 to level 3 by establishing a defined, repeatable risk-analysis procedure and a maintained risk register.\" A vague \"improve governance\" initiative cannot be tested closed.\n2. Attach a planning-level effort and cost estimate to each initiative, then prioritize by risk reduction and business value — the highest-risk gaps first, not the easiest wins.\n3. Sequence initiatives to respect dependencies. Some objectives are prerequisites: you cannot reach APO13 (managed security) maturity without the APO01 management-framework and EDM03 risk foundations beneath it, and initiatives compete for the same scarce people and change windows. Call out resource collisions explicitly instead of assuming everything runs in parallel.\n4. Give each initiative an accountable owner, milestone dates, and a success measure tied to the target capability level, so completion is tested rather than asserted. Package the budget and resourcing asks that need sponsor or board approval.\n5. Flag any material gap left uncovered and any initiative proposed for deferral, each with the residual capability gap that will persist if it does not proceed.\n6. Sponsors and proposed owners commit: owners explicitly accept their initiatives and milestones, sponsors adjust priorities and commit funding (or record asks deferred to the board), and sign an explicit risk acceptance for every deferred or dropped initiative that names the capability gap it leaves open. The committed roadmap is the version reported to the board.\n\n**Record in AssureSwarm**\n- Create an Issue per initiative (item create — issue_type: opportunity, or deficiency for a material control shortfall; source: self_assessment; severity from the gap's materiality; issue_owner; target_remediation_date for the milestone; recommendation = the capability uplift and its success measure; remediation_plan for the sequenced steps). The effort/cost estimate lives in the initiative's remediation_plan or an attached planning sheet (no native cost field).\n- Link each initiative Issue to the objective's Process item and to the anchor Audit (item relationship Issue ↔ Process, Issue ↔ Audit).\n- Record the sponsor and owner commitments on this step. For every deferred or dropped initiative, record the signed risk acceptance in that Issue's management_response, and where the residual gap warrants a register entry, create/update a Risk item with treatment: accept and risk_owner, linked to the objective's Process item.\n\n**Exit criteria** — Every material gap is covered by at least one owned initiative or a signed risk acceptance; each initiative has a testable success measure tied to a target level, a milestone plan, and a committed owner; funding asks are packaged for the board; the committed roadmap is fixed as the version to be reported.","label":"Build improvement roadmap","performedBy":{"primitives":["coach-item-create","coach-items-link"]}},"id":"build-roadmap"},{"data":{"description":"Agent drafts the governance report and dashboard; human presents to the board and records its decisions and directives","instructions":"**Objective** — Put the assessed capability profile, its movement, and either the committed roadmap or the targets-met conclusion in front of the governance board, and record the board's decisions precisely enough to drive the review records.\n\n**Inputs**\n- The signed capability profile and the gap table; the benchmark decision (`assessment_outcome`).\n- If improvement was needed, the committed roadmap with owners, milestones, and funding asks; if targets were met, the evidence supporting that conclusion.\n- Prior-cycle results for trend; the board/committee reporting calendar and its decision-request format.\n\n**Procedure**\n1. Draft the governance report for a board audience — decisions and business impact, not COBIT jargon. Lead with a current-versus-target capability view per objective, movement since the prior review, and the material gaps translated into business impact (the risk carried or the value missed). Then present either the committed roadmap summary (owners, milestones, funding asks, expected uplift) or, on a targets-met conclusion, the evidence that supports it.\n2. Build the governance dashboard: the capability profile against targets, the trend across cycles, and roadmap or sustainment status, so the board and its committees keep visibility between reviews rather than only at the meeting.\n3. Compile an evidence appendix so every statement in the report traces to assessment evidence or a recorded decision — a board challenge of \"how do you know\" must resolve to a citation, not an opinion. List the specific decisions requested from the board (roadmap approval, funding, target or scope changes), each with a recommended position.\n4. Distribute the pre-read package ahead of the session and log the questions it draws, so the meeting opens on substance rather than orientation.\n5. The sponsor and review owner present: walk the board through results, trends, and the roadmap or targets-met conclusion, and take challenge. Record each board decision (approved, amended, deferred, or rejected), any directed change to targets or scope with its rationale, and any new action the board assigns — captured precisely enough to update the target profile, scope, and tracking records without re-interviewing anyone.\n\n**Record in AssureSwarm**\n- Build or refresh the governance dashboard (dashboard create) linked to this step: capability versus target, cross-cycle trend, and roadmap/sustainment status.\n- Attach the governance report and the evidence appendix to this step as documents (DOCX/PDF); export the objective Process items and initiative Issue items into the reporting package (item export, CSV); set Audit.report_date to the reporting date.\n- Record the board decisions, the directed target/scope changes with rationale, and the newly assigned actions on this step (precise enough to update the target profile, scope, and tracking records without re-interviewing).\n\n**Exit criteria** — The report and dashboard present current-versus-target capability, trend, and the roadmap or targets-met conclusion, each statement traceable to the appendix; the pre-read was distributed; every board decision, directed change, and new action is recorded precisely enough to update the review records.","label":"Report to governance board","performedBy":{"primitives":["coach-dashboard-create","coach-document-upload","coach-export-package"]}},"id":"report-to-board"},{"data":{"description":"Agent tracks approved actions, flags slippage against objective metrics, and assembles the archive; the sponsor and review owner review progress at each cadence point and sign off at the closing review, which archives the cycle and carries open actions forward","instructions":"**Objective** — Keep the board-approved roadmap and directed actions moving between reviews — tracking each item to its milestones and surfacing slippage while it can still be corrected — and, at the cadence point where the cycle ends, close the review on a verified, re-performable archive with every open thread carried forward.\n\n**Inputs**\n- The committed roadmap and the board decisions/directed actions from the reporting step, each with owner, milestones, due dates, and success measure.\n- Any directed changes to the target profile and scope the board ordered.\n- The affected objectives' metrics, for confirming improvements actually land.\n- The approved review cadence and the next scheduled review date.\n- Every review artifact, for the closing archive: the approved scope sheet and target profile; the evidence register; interview notes; the signed capability scores; the gap table and benchmark decision record; the committed roadmap; the board minutes and directives; and the tracking register.\n- The records-retention schedule and the designated governance-evidence repository.\n\n**Procedure**\n\n_Items 6–9 close the workflow (folded from the former \"Close and archive\" step); the sponsor and review owner's sign-off at the closing cadence review is the closure._\n\n1. Load every board-approved initiative and directed action into the tracking register with owner, milestones, due dates, and success measure, and apply the board's directed changes to the target profile and scope records now — an unapplied board direction is the first thing the next cycle trips over.\n2. Monitor milestone progress and the metrics of the affected objectives. Flag slipped milestones, stalled initiatives (no movement across a period), and the subtler failure — a milestone marked done while the objective's metric has not moved, meaning capability did not actually improve. A closed task is a claim; the metric is the evidence.\n3. Compile the progress pack at the agreed cadence: status per initiative against its milestones, slippage flags with aging (how long overdue), and any risk acceptances or deferrals approaching expiry — a deferral that lapses silently becomes permanent unremediated risk.\n4. Log escalations for items needing sponsor intervention, and keep the next periodic review scheduled at the approved cadence.\n5. At each cadence point the sponsor and review owner review the pack: confirm flagged slippage is real, direct corrective action or re-planning for stalled initiatives, decide what escalates to the board, and verify no board direction was left unapplied. Where the review concluded targets met, confirm the sustainment metrics still hold — a target reached once but not sustained is a gap re-opening. Between cadence points the step stays open: open initiatives remain tracked, not blocking.\n6. At the closing cadence review, verify every artifact is final and internally consistent — the signed scores match the gap table, the roadmap matches the board minutes, and directed changes are reflected in the target/scope records. No item may be left in an ambiguous or draft state.\n7. Archive the full package to the designated repository under the retention policy, indexed so an independent reviewer can reperform the trail: evidence → practice rating → capability level → gap → benchmark decision → board directive. Verify retrievability by opening the archived copy, not by trusting the upload confirmation. Once the archive reference is recorded it is the fixed record of the cycle; any later correction is a new, dated addendum linked to the package, never a silent edit.\n8. Link the archive to the affected objective records and the tracking register so the next cycle starts from this baseline, and compile the carry-forward package: open improvement actions (each with owner and due date) and directed changes to targets or scope for the next scoping brief. An action still open at close carries forward to routine tracking rather than vanishing.\n9. Confirm the next review date and its owner are locked in the assessment calendar at the approved cadence, record the closure timestamp and archive reference, and notify the sponsor, the accountable owners, and the board secretariat — the sign-off recorded on this step is the formal closure of the review.\n\n**Record in AssureSwarm**\n- Maintain the roadmap initiative Issues as they progress — update status, and set actual_remediation_date / verified_date as milestones land and the objective's metric confirms the uplift. Create an Issue for each board-directed action (item create — source: management_identified, issue_owner, target_remediation_date), linked to its objective's Process item.\n- Query the affected objectives' metrics to confirm the uplift is real (query data); apply the board's directed target/scope changes to the objective Process items (process_owner, description) and to Audit.scope / the scope document.\n- Attach each cadence progress pack (built from the workflow scan/monitor status) to this step as a document, and record the escalations raised on the step.\n- Export the workflow instance and archive it with the full package (workflow export); attach the closure record with the archive location and reference to this step as a document. Close the anchor Audit with its final report_date and rating.\n- Create a carry-forward Issue for each open action and directed change (item create — issue_owner, target_remediation_date), and link the archive to the objectives' Process items (item relationship).\n- Record the closure timestamp, the next review date and owner, and the archive reference on this step.\n\n**Exit criteria** — Every board-approved initiative and directed action is in the register with an owner and live status; directed target/scope changes are applied; each cadence's progress pack is compiled with slippage aged and expiring acceptances flagged; escalations are raised where needed. At the closing review every artifact is final and consistent; the package is archived and verified retrievable with its reference recorded under the addenda-only correction convention; the archive is linked to the objective and tracking records; carry-forward items exist with owners; the next review is scheduled; and the review owner's sign-off on this step closes the cycle.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-scan` surfaces per-initiative status, overdue milestones, and slipped or stalled improvement actions, so the cadence progress pack is built from live data rather than a manual sweep.","label":"Track improvement actions","performedBy":{"primitives":["coach-item-create","coach-query-data","coach-workflow-scan","coach-workflow-export","coach-document-upload","coach-items-link"]}},"id":"track-actions"}],"sourceTemplateId":"workflow-library:grc-it-governance-cobit-review"}
