{"description":"Runs on the existing standing \"Board & Audit-Committee GRC Reporting\" governance Process item (process_type=business_process, frequency=quarterly): one workflow instance per quarter attaches to that Process and enriches it (the Process is not created here), and each closed instance is the prior-quarter baseline for the next run. The named deliverable is the quarterly board & audit-committee GRC pack (six-domain narrative deck, Word + PDF, redaction-cleared). It compiles that pack across six domains — risk profile, control health, open issues, regulatory deadlines, audit-plan progress, and SOX posture — computed over one quarter window. In scope: aggregating and synthesizing existing GRC records (Risk, Control, Issue, Audit, and Control-hosted SOX testing workflows) into a board-level narrative, obtaining executive and committee approval, and archiving the decision and action register. Out of scope: performing the underlying risk assessments, audits, or control tests themselves. Consumes two upstream handoff packages: the Enterprise Risk Assessment & Portfolio Oversight Cycle package (risk register, residual scores, appetite positions) and the Audit Report Drafting & Regulatory Compliance Attestation Cycle package (audit-plan status, issued reports, attestation status); there is no downstream workflow — the closed package feeds the next quarterly run of this workflow.","edges":[{"id":"e-draft-board-deck-obtain-executive-review","source":"draft-board-deck","target":"obtain-executive-review"},{"id":"e-obtain-executive-review-present-and-capture-decisions","source":"obtain-executive-review","target":"present-and-capture-decisions"},{"id":"e-present-and-capture-decisions-approve-or-revise-package","source":"present-and-capture-decisions","target":"approve-or-revise-package"},{"id":"e-approve-or-revise-package-resolve-approval-conditions","label":"Revise","source":"approve-or-revise-package","target":"resolve-approval-conditions","whenValue":"revise"},{"id":"e-approve-or-revise-package-record-approval-decision","label":"Approved","source":"approve-or-revise-package","target":"record-approval-decision","whenValue":"approved"},{"id":"e-resolve-approval-conditions-record-approval-decision","source":"resolve-approval-conditions","target":"record-approval-decision"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-GOV-05","UC-GOV-21","UC-AUDIT-22","UC-AUDIT-18","UC-RISK-10","UC-RISK-14"],"department":"risk-management","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-quarterly-board-audit-committee-reporting","contentDigest":"sha256:6d75ecb22ff2f49635ee533d71e7f61e415ea80adf9c9b1366b87543baf635a9","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:6d75ecb22ff2f49635ee533d71e7f61e415ea80adf9c9b1366b87543baf635a9","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-quarterly-board-audit-committee-reporting"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-quarterly-board-audit-committee-reporting","source":"coworkcanvas-gallery","standards":["coso-erm","iia-2024"],"teams":["risk-management","internal-audit","executive"]},"name":"Quarterly Board & Audit-Committee GRC Reporting","nodes":[{"data":{"description":"Chief Audit Executive: Frame the independently reported six-domain narrative and resolve every hard-stop redaction flag against the source-reconciled, quarter-locked pack.","instructions":"**Objective** — Prepare the quarter-locked, source-reconciled six-domain and assurance-governance pack, resolve every redaction flag and retain the CAE’s independent narrative.\n\n**Inputs**\n- The standing Board & Audit-Committee GRC Reporting governance Process item (process_type=business_process, frequency=quarterly) that this quarter's instance attaches to and enriches; it already exists and is not created by this workflow.\n- The reporting quarter (e.g., FY26-Q2) with its start and end dates, plus the prior-quarter baseline used for quarter-over-quarter (QoQ) comparison.\n- The handoff package from the Enterprise Risk Assessment & Portfolio Oversight Cycle (current risk register, residual scores, appetite positions) and the handoff package from the Audit Report Drafting & Regulatory Compliance Attestation Cycle (audit-plan status, issued reports, attestation status). These arrive as linked items and documents on the workflow; if a package is missing or stale, log it as an open constraint rather than blocking.\n- The audit-committee charter and the standing board reporting calendar (meeting date, materials-due date, pre-read distribution date).\n- The prior-quarter board-question log (questions the committee asked last cycle that require a follow-up answer this cycle).\n- Whether SOX is in scope this quarter (drives inclusion of the SOX posture section).\n- The locked quarter window, baseline, SOX flag, and per-domain workplan from the locked workplan.\n- The current and prior-quarter risk register — Risk items (residual_rating, inherent_rating, treatment, risk_owner) — reconciled against the Enterprise Risk Assessment handoff package for residual exposure, appetite position, and movement drivers.\n- Control library (Control items: control_id, key_control, control_owner, framework) with test status read from the linked Control-hosted SOX testing workflows (the workflow Test-step conclusion) via the Control-hosted SOX workflow binding; the open-issue register (Issue items: severity, issue_owner, root_cause, identified_date, target_remediation_date); the regulatory obligation calendar with due dates and attestation status (kept as a step document — no native Obligation type); audit-plan progress from Audit items (audit_type, rating, opinion, report_date; completed vs. planned, in-flight, slipped); and SOX deficiency posture — Control-hosted SOX testing workflows (cycle from Workflow.customFields.sox.fiscalYear; Test-step conclusion) plus Issue items with issue_type deficiency/significant_deficiency/material_weakness and source sox_testing — only if SOX is flagged in scope.\n- The reconciled six-section dataset with QoQ deltas from the reconciled baseline stage, plus the locked quarter window and SOX-in-scope flag.\n- The board-question log, so prior-quarter questions are answered in the pack.\n- The organization's board-deck template and the recipient distribution list.\n\n**Procedure**\n*Autonomous preparation incorporates Lock executable workplan; Baseline board pack; Chief Audit Executive reviews the combined evidence.*\n1. Set the quarter window: record quarter start, quarter end, and the prior-quarter comparison baseline. Every domain figure and QoQ delta downstream must be computed over exactly this window — a mismatched window is the most common source of an unreconcilable board number.\n2. Lock the reporting calendar: back-schedule from the audit-committee meeting date — materials-due date (typically meeting minus 5 business days), executive-review date, and internal data-freeze date. Confirm each date against the board calendar and the charter's notice requirements.\n3. Rebuild the board-question log: carry forward every unanswered question from the prior quarter, assign each an owner and the target section of this quarter's pack, and add any new standing items the committee expects.\n4. Confirm scope and set the SOX-section flag: list the six domains in scope (risk profile, control health, open issues, regulatory obligations, audit-plan progress, and SOX posture) and mark SOX in or out for the quarter.\n5. Reconcile upstream inputs: confirm the two upstream handoff packages are current (dated inside or immediately before this window) and approved. Log any gap (missing, stale, or unapproved) as an open constraint with an owner and a resolve-by date.\n6. Lock the executable workplan: for each domain section name the owner, the source system or records to pull, the due date, and the evidence expected. Freeze scope for the quarter here.\n7. Baseline the board-pack skeleton: create the six section shells matched to the locked scope, each tagged with the quarter window so figures cannot be pulled from the wrong period.\n8. Risk section: rank the top risks by residual exposure; identify material QoQ moves — new, escalated, de-escalated, retired — and record the driver behind each move and its appetite position.\n9. Control section: list controls added and retired this quarter; compute current test-coverage status (tested-passed, tested-failed, not-yet-tested) and flag any failed test that maps to a top risk.\n10. Aggregate the issue register: pull all open issues, bucket by severity, compute aging buckets for overdue items (for example 0-30, 31-90, and 90-plus days past target), and cluster the top systemic root-cause themes cutting across issues.\n11. Regulatory section: list new and upcoming obligations with due dates and mark attestations completed vs. outstanding this quarter.\n12. Audit-plan section: tabulate engagements completed vs. planned, work in flight, and any slipped or deferred audits with rationale.\n13. SOX section (only if in scope): summarize open-deficiency count and severity and management attestation readiness. If out of scope, record that explicitly so the drafter omits the section.\n14. Reconcile every figure to its source: each section number must tie back to the underlying records; note any figure that will not reconcile as an open data gap with an owner.\n15. Add an assurance-governance subsection that states the current capacity mix and material changes since the prior period; captures material reliance decisions and judgments with their basis, provider, coverage effect, limitations, and source trace; and covers top-risk independent coverage, open role collisions and safeguards, expanded remit, transition status, and objectivity implications. Reconcile every statement to its source and identify the board action requested.\n16. Synthesize, do not list: write one short, board-readable narrative per domain, but connect them into a board-level story — for example, a residual-risk increase tied to a failed control test tied to an open high-severity issue. Lead each section with what changed and what the board must decide; keep it at board altitude, not operational detail.\n17. Risk narrative: top residual risks and the material QoQ moves with drivers and appetite position.\n18. Control narrative: controls added and retired and test-coverage status, calling out failed tests on top risks.\n19. Issues narrative: open issues by severity, overdue aging, and the systemic root-cause themes.\n20. Regulatory narrative: new and upcoming obligations with due dates and attestation completion.\n21. Audit-plan narrative: completed vs. planned, in-flight, and slipped audits with rationale.\n22. SOX narrative (only when in scope): deficiency posture and management attestation readiness.\n23. Close the board-question log: ensure every carried-forward question has an answer located in the pack.\n24. Render: produce distributable Word and PDF versions of the assembled narrative.\n25. Outbound-safety redaction (hard gate): run a strict block-policy redaction pass over the staged package — the board pack is the highest-stakes outbound artifact the GRC function produces. Any item the pass flags for human review is a hard stop: the package build halts and does not proceed to distribution until a person resolves every flagged item. This gate is non-negotiable.\n26. Package and record distribution: after the redaction pass clears, package the deck, produce the distribution summary (recipient list and delivery record), and attach the rendered deck to this step.\n27. Add an assurance-governance subsection covering capacity mix, top-risk independent coverage, reliance limitations, open role collisions and safeguards, expanded remit, transition status, and objectivity implications; reconcile every statement to its source and identify the board action requested.\n28. Within that subsection, state the current capacity mix and material changes since the prior period; list material reliance decisions and judgments with their basis, provider, coverage effect, limitations, and source trace.\n\n**Record in AssureSwarm**\n- Attach this quarter's workflow instance to the standing Board & Audit-Committee GRC Reporting Process item (the anchor); there are no item fields for the reporting window, so record the quarter label, window start and end, prior-quarter baseline, and the SOX-in-scope flag as metadata in this step's record.\n- Attach the locked reporting calendar and the board-question log as documents on this step.\n- Link the two upstream handoff packages (the Enterprise Risk Assessment and the Audit Report Drafting & Regulatory Compliance Attestation cycles' close-step documents) to the workflow; log any input gap as an open-constraint note on this step with owner and resolve-by date.\n- Record the per-domain owner, source, due-date, and evidence table on the step.\n- Attach the assembled six-section source dataset (with QoQ deltas) as a document on this step.\n- Link the underlying Risk, Control, Issue, and Audit source items to this workflow; cite Control-hosted SOX testing workflow results through their direct Control hosts, and attach the regulatory obligation calendar as a step document (no native Obligation type).\n- Log any unreconciled figure as an open data-gap item with owner and resolve-by date.\n- Include the assurance-governance subsection in the retained source dataset, with the current capacity mix and material changes since the prior period; material reliance decisions and judgments with basis, provider, coverage effect, limitations, and source trace; and the coverage, collision, remit, transition, and objectivity evidence behind it.\n- Attach the rendered, redacted deck (Word and PDF) via document upload.\n- Record the quarter and window, the source records behind each section, the redaction disposition (cleared, or each flagged item and how it was resolved), and the distribution summary.\n- Include the assurance-governance subsection in the rendered deck, with the current capacity mix and material changes since the prior period; material reliance decisions and judgments with basis, provider, coverage effect, limitations, and source trace; and the coverage, collision, remit, transition, and objectivity evidence behind it.\n\n**Exit criteria**\nFrame the independently reported six-domain narrative and resolve every hard-stop redaction flag against the source-reconciled, quarter-locked pack.\nQuarter window and baseline set; calendar and board-question log attached; SOX flag set; both upstream packages linked or their absence logged as a constraint; the per-domain workplan (owner, source, due date, evidence) is frozen.\nSix section datasets assembled over the locked window with QoQ deltas; every figure traced to source or flagged as a data gap; SOX section built or explicitly marked out of scope; source records linked; the assurance-governance subsection states the current capacity mix and material changes since the prior period and material reliance decisions and judgments with basis, provider, coverage effect, limitations, and source trace, and is otherwise complete and traceable.\nRendered, redacted deck attached; board-question log fully answered; distribution summary produced; the outbound-safety gate is recorded as cleared with all flags resolved; the assurance-governance subsection states the current capacity mix and material changes since the prior period and material reliance decisions and judgments with basis, provider, coverage effect, limitations, and source trace, and is otherwise complete and traceable.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` renders the assembled narrative to Word and PDF, and `/coach-redact` runs the strict block-policy outbound-safety pass that halts the build on any flagged item until a human resolves it.","label":"Draft board deck","performedBy":{"agent":"grc-artist","note":"board-deck render, redact, and distribute engine","primitives":["coach-query-data","coach-document-upload","coach-render-package","coach-redact"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive","ermPhase":"report","independenceRequired":false,"lineRole":"third","serviceMode":"advisory"}},"id":"draft-board-deck"},{"data":{"description":"Secure executive sign-off on the drafted board deck before it goes to the audit committee","instructions":"**Objective** — Secure sign-off from the executive team (typically CRO, CFO, General Counsel, and CAE) on the drafted board deck before it goes to the audit committee, so the executives own the narrative and figures presented.\n\n**Inputs**\n- The rendered, redacted board deck and distribution summary from the draft step.\n- The executive reviewer roster and any charter-mandated pre-approvers.\n- The board-question log and the source dataset for reference during review.\n\n**Procedure**\n1. Route the deck to each named executive reviewer with the review-due date from the locked calendar.\n2. Capture each reviewer's disposition: approve, approve-with-edits, or reject-with-reasons; record who reviewed and when.\n3. Triage edits: apply non-substantive edits directly; for a substantive change to a figure or conclusion, correct the source baseline or deck drafting stage and note the change so the audit trail shows what moved and why.\n4. Confirm consistency after edits: any changed figure still ties to source, and the board-question log answers remain accurate.\n5. Confirm all mandated pre-approvers have signed before release to the committee.\n\n**Record in AssureSwarm**\n- Attach the reviewed deck version and record each reviewer, disposition, date, and comments.\n- Log substantive edits with a before-and-after note and link to the step where the change was made.\n\n**Exit criteria** — Every mandated executive reviewer has recorded a disposition; all are approve or approve-with-edits with edits applied; the released deck version is attached and consistent with source.","label":"Obtain executive review"},"id":"obtain-executive-review"},{"data":{"description":"Audit Committee Chair and board members: Challenge the risk/assurance posture and material reliance judgments, decide directions and acceptance, and confirm the read-back wording before publishing owned actions.","instructions":"**Objective** — Present the approved pack, capture and read back the committee’s decisions and challenges, then publish its exact directions as an owned action register.\n\n**Inputs**\n- The executive-approved board deck and distribution summary.\n- The meeting agenda and the attendee and quorum list.\n- The board-question log, to confirm prior questions were addressed.\n- The captured decisions and actions from the present-and-capture-decisions step.\n- The organization's action-tracking register and owner directory.\n\n**Procedure**\n*Autonomous preparation incorporates Publish decision and action register; Audit Committee Chair and board members reviews the combined evidence.*\n1. Distribute the pre-read by the calendar's distribution date and confirm receipt.\n2. Present each domain section; record attendance and quorum.\n3. Capture every decision the committee makes: the motion, who moved and seconded (if formal), the outcome, and any conditions.\n4. Capture directions and new questions: for each, record the exact ask, the owner assigned, and the due date — these seed the next-quarter board-question log.\n5. Note any risk-acceptance or appetite breach the committee explicitly accepts, with rationale, as a governance decision.\n6. Capture board challenge, approval, and direction on material mix changes and material reliance judgments, including any condition, requested alternative, or follow-up.\n7. Read back decisions and actions at the close of the session to confirm the committee agrees with the captured wording.\n8. Consolidate every decision and action into the register with a stable ID, description, owner, due date, and status set to open.\n9. Cross-link each action to the risk, issue, control, or obligation it relates to, so the follow-up is traceable to the underlying GRC record.\n10. Set escalation and monitoring triggers: for any risk-acceptance or appetite breach, record the review trigger and the next check date.\n11. Notify each action owner with their item or items, due date, and the linked context; confirm delivery.\n12. Publish the register to the governance repository and record its version and location.\n\n**Record in AssureSwarm**\n- Attach the meeting minutes and decision capture to this step.\n- Capture each direction or question as a dated, owned entry in the minutes/decision-capture document (there is no native Action item type; the register is published after the committee read-back in this checkpoint); record each formal decision with its conditions.\n- Record the board challenge, approval, and direction on material mix changes and material reliance judgments, with the supporting judgment, condition, owner, and due date.\n- Publish the consolidated decision-and-action register as a document (XLSX/CSV) on this step (no native Action type), each action carrying owner, due date, and status; cross-link each action to the Risk, Issue, Control, or Audit item it relates to via an item relationship; for any risk-acceptance the committee accepted, set Risk.treatment=accept on the affected Risk item with rationale in Risk.description.\n- Record the published register's location and the notification delivery.\n\n**Exit criteria**\nChallenge the risk/assurance posture and material reliance judgments, decide directions and acceptance, and confirm the read-back wording before publishing owned actions.\nAttendance and quorum recorded; every committee decision captured with conditions; every new direction or question logged as an owned, dated action; board challenge, approval, and direction on material mix changes and material reliance judgments are explicit; read-back confirmed.\nEvery decision and action published with owner, due date, and links; owners notified; escalation triggers set; register version recorded.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` sends each action owner their assigned follow-ups with due dates and linked context, and records delivery.","label":"Present and capture decisions","performedBy":{"agent":"grc-artist","note":"decision and action register publish and notify engine","primitives":["coach-item-update","coach-notify"]},"roleIntegrity":{"decisionOwner":"Audit Committee Chair","ermPhase":"report","independenceRequired":false,"lineRole":"board","serviceMode":"decision"}},"id":"present-and-capture-decisions"},{"data":{"decisionField":"approval_path","description":"Capture approval from risk owner, GRC lead, executive sponsor, or board delegate","formData":{"fields":[{"key":"approval_path","label":"Approve or revise package","options":[{"label":"Approved","value":"approved"},{"label":"Revision required","value":"revise"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve whether the final board-reporting package (deck, minutes, and decision-and-action register) is approved for archival close, or must be revised first. Owned by the GRC lead, executive sponsor, or board delegate.\n\n**Decision criteria**\n- **approved** — the deck was executive-approved and presented, all committee decisions and actions are captured and published with owners and due dates, the board-question log is closed, and no reviewer condition remains open. Pick this to proceed to record-approval-decision.\n- **revise** — a reviewer or approver condition is unmet: a figure needs correction, an action lacks an owner or due date, a committee direction was mis-captured, or an escalation trigger is missing. Pick this to route to resolve-approval-conditions before final recording.\n\n**Record in AssureSwarm**\n- Submit the `approval_path` SELECT field (approved or revise).\n- Record the decision owner or approver in the step's approver record and the rationale and evidence references in the step result.\n\n**Exit criteria** — The `approval_path` form is submitted with a rationale; the unselected branch is prunable because the branch edge values match the submitted value.","kind":"decision","label":"Approve or revise package"},"id":"approve-or-revise-package"},{"data":{"description":"Resolve reviewer comments or approval conditions","instructions":"**Objective** — Clear every reviewer comment or approval condition raised at the approve-or-revise-package decision so the package can be finalized.\n\n**Inputs**\n- the step result note listing the unmet conditions from the approve-or-revise-package decision.\n- The affected deck, minutes, and action register.\n\n**Procedure**\n1. Itemize each condition into a checklist with an owner.\n2. For a figure correction: fix it at its source, re-tie it, and re-run the relevant deck section; note before and after.\n3. For a missing action owner or due date: assign and confirm with the owner.\n4. For a mis-captured direction: correct the minutes and re-confirm wording with the committee chair or secretary.\n5. For a missing escalation trigger: add it with a review date.\n6. Summarize what changed, evidence closure of each condition and obtain the final package approver’s approval of the corrected versions before recording them.\n\n**Record in AssureSwarm**\n- Attach the revised artifacts and a change log mapping each condition to its resolution.\n- Update the affected items and records.\n\n**Exit criteria** — Every condition from the decision rationale is closed and evidenced; revised artifacts attached; change log recorded.","label":"Resolve approval conditions"},"id":"resolve-approval-conditions"},{"data":{"description":"Automatically record the approval already granted to the exact versions, archive the quarter read-only, update committee-directed records and carry forward actions and questions.","instructions":"**Objective** — Record the final, authoritative approval of the board-reporting package with approver, date, and any residual conditions, and preserve the quarter's immutable audit trail behind it — the approval already granted to the exact versions authorizes automatic archival closure of the quarter’s cycle.\n\n**Inputs**\n- The approved package (direct approval) or the revised package with its change log (post-resolution) — deck (Word and PDF), minutes, and decision-and-action register.\n- The approver identity and the approval date.\n- The redaction disposition and the source dataset behind the pack.\n- The board-question log and the open-action list for carry-forward, and the governance repository's retention classes.\n\n**Procedure**\n_These recording and archive actions execute under the prior approval; the revised route requires actual approval of the corrected package first._\n1. Confirm the package state matches the approval basis: if it arrived via revision, confirm the change log shows every condition closed.\n2. Record the approver, role, approval date, and the exact scope approved (deck version, minutes, register version).\n3. Record any residual conditions accepted at approval and the owner and date for each.\n4. Set follow-up ownership: who tracks the published actions to closure next quarter.\n5. Assemble the archive set: final deck (Word and PDF), minutes, decision-and-action register, approval record, redaction disposition, and the source dataset.\n6. Archive to the governance repository with retention metadata (quarter, retention class, access scope) and mark records read-only.\n7. Update linked GRC records (risks, issues, controls, obligations) with the committee decisions and any accepted risk positions.\n8. Seed the next cycle: carry forward open actions and unanswered questions into the next-quarter board-question log and schedule the next reporting calendar. There is no downstream workflow — the closed package feeds the next quarterly run of this workflow.\n9. Communicate closure to stakeholders with the archive location.\n\n**Record in AssureSwarm**\n- Write the approval record: approver, date, approved versions, residual conditions, and follow-up owner, and link it to the final package artifacts.\n- Upload the archive set and record its location and retention metadata.\n- Export the closed Workflow instance as the immutable audit-trail record; update the linked GRC items with committee decisions — e.g. Risk.treatment=accept on accepted risks, Issue.target_remediation_date per committee direction — and link them to the anchor Process; record the carry-forward list (next-quarter board-question log + next calendar).\n\n**Exit criteria** — Approval record written with approver, date, and approved versions, residual conditions and follow-up ownership captured, and linked to the final artifacts; the archive set stored read-only with retention metadata; linked records updated; open items carried forward and the next reporting calendar scheduled; closure communicated.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-export` exports the closed workflow and its artifacts as the immutable audit-trail record for archival.","label":"Record approval decision","performedBy":{"agent":"grc-artist","note":"close-out archive and audit-trail export engine","primitives":["coach-document-upload","coach-workflow-export"]},"requiredApprovals":0},"id":"record-approval-decision"}],"sourceTemplateId":"workflow-library:grc-quarterly-board-audit-committee-reporting"}
