{"description":"Risk & Control Self-Assessment (RCSA) Program as a modular, decision-aware workflow. Each wave runs on its own Audit item — created per wave (audit_type: operational; period_start/period_end = the wave window; report_date = the risk-committee date) — with the workflow instance attached to that item and the wave's questionnaires, attested returns, and calibration record kept inside the run. Each wave rebuilds the assessment universe from the existing Process, Risk, and Control items and their owners (enriching them, never recreating them), issues rating questionnaires to named control and process owners, collects attested self-assessments with structured exception capture, chases completeness, subjects the results to second-line challenge and calibration, aggregates a residual-risk view across units, updates the risk register's residual ratings, and routes self-identified issues to remediation and exceptions to time-bound acceptance before the results reach the risk committee. In scope: first-line self-assessment of in-scope business units and shared functions against their own risks and controls. Out of scope: independent testing/audit of those controls, and the remediation and formal risk-acceptance of what the wave surfaces, which are handed off downstream to the Finding Remediation & Action-Plan Monitoring (deficiencies), Policy Exception & Risk Acceptance (risk-acceptances/waivers), and Quarterly Board & Audit-Committee GRC Reporting (the wave report) workflows.","edges":[{"id":"e-prepare-assessment-questionnaires-owners-rate-and-attest","source":"prepare-assessment-questionnaires","target":"owners-rate-and-attest"},{"id":"e-owners-rate-and-attest-verify-returns-complete","source":"owners-rate-and-attest","target":"verify-returns-complete"},{"id":"e-verify-returns-complete-challenge-and-calibrate-results","label":"All returned","source":"verify-returns-complete","target":"challenge-and-calibrate-results","whenValue":"all_returned"},{"id":"e-verify-returns-complete-escalate-outstanding-units","label":"Escalate outstanding","source":"verify-returns-complete","target":"escalate-outstanding-units","whenValue":"escalation_required"},{"id":"e-escalate-outstanding-units-challenge-and-calibrate-results","source":"escalate-outstanding-units","target":"challenge-and-calibrate-results"},{"id":"e-challenge-and-calibrate-results-route-issues-and-exceptions","label":"Results credible","source":"challenge-and-calibrate-results","target":"route-issues-and-exceptions","whenValue":"results_credible"},{"id":"e-challenge-and-calibrate-results-rework-unit-assessments","label":"Rework required","source":"challenge-and-calibrate-results","target":"rework-unit-assessments","whenValue":"rework_required"},{"id":"e-rework-unit-assessments-route-issues-and-exceptions","source":"rework-unit-assessments","target":"route-issues-and-exceptions"},{"id":"e-route-issues-and-exceptions-report-to-risk-committee","source":"route-issues-and-exceptions","target":"report-to-risk-committee"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-RISK-07","UC-RISK-08","UC-RISK-10","UC-RISK-13","UC-RISK-14","UC-GOV-21"],"department":"operations","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-rcsa-program","contentDigest":"sha256:4a08a203b0f96f2087dae903e17246c4717f06bcf1767da2153cf0f3c9dcb894","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:4a08a203b0f96f2087dae903e17246c4717f06bcf1767da2153cf0f3c9dcb894","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-rcsa-program"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-rcsa-program","source":"coworkcanvas-gallery","standards":["coso-ic","coso-erm","iso-31000"],"teams":["operations","risk-management"]},"name":"Risk & Control Self-Assessment (RCSA) Program","nodes":[{"data":{"description":"Program lead and second-line risk team: Approve complete current ownership, achievable wave scope and the evidence-primed assessment workpaper’s exact methodology/scales before owners assess.","instructions":"**Objective** — Rebuild and reconcile the wave universe, resolve conflicting ownership, and approve the evidence-primed assessment workpapers and methodology before distribution.\n\n**Inputs**\n- Wave scope (from this workflow's definition): first-line self-assessment of in-scope business units and shared functions against their own risks and controls. Independent testing/audit of those controls, and the remediation and formal acceptance of what the wave surfaces, are out of scope and handled by downstream workflows.\n- Current org structure / org chart, plus any reorganization, acquisition, or new-product change since the prior wave.\n- Process inventory, risk register, and control inventory — the existing Process, Risk, and Control items with their owner fields (Process.process_owner, Risk.risk_owner, Control.control_owner) and their Control↔Risk / Control↔Process relationships. Business units have no native item type; the 'unit' half of the universe is carried in the universe-and-schedule document and via each unit's Process items.\n- The prior wave's universe, ratings, and open items — the prior wave's archived workflow instance (attached to its Audit item), the prior residual_rating values on Risk items, and open Issue items with source: self_assessment; carried as context. If none, record that this is the inaugural wave.\n- The approved RCSA methodology and its rating scales + exception thresholds — held as a Policy item (policy_type: standard) with the methodology document attached; it is the reference every later step applies, so confirm you hold the currently approved version, not a stale copy.\n- The confirmed assessment universe and per-unit risk/control lists (from the universe refresh stage) — the refreshed Process/Risk/Control items and the universe document.\n- The approved RCSA methodology (the Policy item): the control design scale, the control performance scale, and the risk likelihood/impact scales, each scale point's plain-language definition, and the exception threshold.\n- Each unit's incident, loss, audit-finding, and key-risk-indicator history since the last wave — the audit-finding half is Issue items (source: internal_audit/external_audit); incidents, losses, and KRIs have no native type, so pull them as a history-extract document attached to this step.\n\n**Procedure**\n*Autonomous preparation incorporates Refresh assessment universe and schedule; Program lead and second-line risk team reviews the combined evidence.*\n1. Rebuild the universe from the org structure, process inventory, risk register, and control inventory so every in-scope unit and process is listed with the specific risks and controls it will self-assess and a named control or process owner for each.\n2. Diff against the prior wave: add units/processes created by reorganizations, acquisitions, or new products; retire entries that no longer exist, recording a rationale for each retirement; and carry each surviving unit's prior ratings and open items forward as context.\n3. Flag stale ownership — owners who have left, changed roles, or hold conflicting duties (e.g., an owner assessing a control they also perform without compensating review) — and route each for reassignment to a current accountable person before anything is distributed.\n4. Draft the wave schedule with per-unit dates: distribution, return deadline, the chase-and-escalation window, calibration sessions, and the committee reporting date. Back-plan from the fixed committee date; if the window is infeasible, narrow scope or move the date now, not mid-wave.\n5. Generate an assessment workpaper per unit, pre-populated with the unit's risks and controls, their descriptions, the prior wave's ratings, open issues, and the unit's incident/loss/audit-finding history since the last wave — so owners rate from evidence, not memory.\n6. Apply the standard scales to every control: a design rating (e.g., designed effectively / partially designed / design deficient) and a performance rating (operating effectively / operating with exceptions / not operating), plus likelihood and impact for each risk. Print each scale point’s definition in the assessment workpaper.\n7. Build structured exception capture: any rating at or below the exception threshold forces a description, the actual/potential impact, the affected risk or control, and the owner's proposed action — so self-identified issues arrive as routable records, not free text.\n8. Pilot the assessment workpaper against one representative unit; fix ambiguous wording, wrong pre-populated data, or scale points owners misread before the full run.\n\n**Record in AssureSwarm**\n- Create the wave anchor: one Audit item (audit_type: operational; period_start/period_end = the wave window; report_date = the committee date; lead_auditor = the program lead) that the workflow instance attaches to (coach-item-create).\n- Refresh the existing Process, Risk, and Control items and their owner fields (Process.process_owner, Risk.risk_owner, Control.control_owner) and re-link the Control↔Risk and Control↔Process relationships so each unit's population is correctly connected (coach-item-update, coach-items-link). Business units have no native type — carry the unit list in the universe document.\n- Attach the assessment-universe and wave-schedule document (XLSX) to this step (coach-item-document-attach); it is the system of record for the per-unit distribution, return, chase, and calibration dates, which have no native item field. The committee date lives on Audit.report_date.\n- Pull the registers to rebuild the universe (coach-query-data).\n- Build the per-unit assessment workpapers as documents with the scale definitions and exception requirements; owners record their judgments in native results and personally attest through native approvals.\n- Pull the pre-population data from the registers and the incident-history document (coach-query-data) and include it in each assessment workpaper.\n- Link each assessment workpaper to its unit's Process item (the unit has no native item; the Process record carries it).\n\n**Exit criteria**\nApprove complete current ownership, achievable wave scope and the evidence-primed assessment workpaper’s exact methodology/scales before owners assess.\nEvery in-scope unit/process appears with its risks, controls, and a current accountable owner; no unit present in the prior wave or the current org chart is silently missing; every retirement carries a rationale; the schedule is linked and achievable against the committee date; the program lead and second-line risk team have confirmed completeness before assessment workpapers are built.\nEvery in-scope unit has an assessment workpaper pre-populated with accurate risk/control/history data; scales and definitions match the approved methodology verbatim; exception capture is mandatory below threshold; the pilot ambiguities are resolved; the second-line risk team has approved the content and scales.","label":"Prepare assessment questionnaires","performedBy":{"primitives":["coach-item-create","coach-item-update","coach-items-link","coach-document-upload","coach-query-data","coach-form-create"]}},"id":"prepare-assessment-questionnaires"},{"data":{"description":"Named first-line control and process owners: Personally rate design, performance and likelihood/impact against actual evidence, expose every threshold exception and attest their own assessment.","instructions":"**Objective** — Distribute each approved unit workpaper and obtain the accountable owner’s evidence-backed ratings, structured exceptions and personal native attestation.\n\n**Inputs**\n- The approved per-unit assessment workpapers (from the assessment workpaper-prep step).\n- The universe's owner assignments and the wave schedule's per-unit due dates.\n- The scale definitions, exception threshold, and the attestation-obligation wording from the methodology.\n- The distributed assessment workpapers and the distribution ledger (from the distribution stage).\n- Each unit's objective signals since the last wave: incidents, losses, audit findings, key-risk-indicator breaches.\n- The methodology's completeness rules and exception threshold.\n\n**Procedure**\n*Autonomous preparation incorporates Distribute to control owners; Named first-line control and process owners reviews the combined evidence.*\n1. Issue each unit's assessment workpaper to its named control or process owner with the return deadline, the scale definitions, the exception threshold, and a plain statement of the attestation obligation — that the owner personally attests their unit's ratings and exceptions.\n2. Stage briefing materials and an office-hours schedule for first-time owners and for units whose prior returns needed heavy calibration: how to rate against the scales and what a well-documented exception looks like.\n3. Record the distribution ledger — unit, recipient, distribution date, due date — as the completeness baseline the chase will run against.\n4. Set reminder triggers ahead of each unit's deadline so no owner first learns of the deadline by missing it.\n5. As owners record assessments in native results with supporting workpapers, validate completeness: every control rated on design and performance, every risk rated for likelihood and impact, every at-or-below-threshold rating carrying a structured exception, no mandatory field blank. Return incomplete submissions the same day with the specific gaps listed.\n6. Cross-check each unit's ratings against its objective signals; tag any return that rates a control effective despite contradicting evidence (an incident, breach, or audit finding on that control) as input to second-line challenge.\n7. Capture every self-identified exception as a draft issue record: unit, affected risk or control, severity per the methodology, description, and the owner's proposed action.\n8. Log each attestation — owner name, role, attestation date — against the unit's return so the record shows who stood behind each assessment.\n\n**Record in AssureSwarm**\n- Link/deliver each assessment workpaper document to its owner (coach-document-link) and record the distribution ledger — unit, recipient, distribution date, due date — as a CSV/XLSX document on this step (there is no native ledger field).\n- Run the workflow scan to confirm every unit has an assigned, reachable recipient (coach-workflow-scan).\n- Schedule the deadline reminders (coach-notify).\n- Each named control/process owner records the unit and control/risk reference, design/performance ratings, likelihood/impact, all threshold exceptions and proposed action/date in the native result with its assessment workpaper attached. Record personal attestation in native approvals, retaining the attestor identity, role and timestamp.\nIs the control designed to address the risk?: effective = Effective; partially_effective = Partially effective; ineffective = Ineffective; not_applicable = Not applicable to my unit.\nDid the control operate as designed through the period?: effective = Effective - operated every time; partially_effective = Partially effective - operated with gaps; ineffective = Ineffective - did not operate; not_applicable = Not applicable to my unit.\nLikelihood of the risk occurring in your unit over the next period: 1_rare = 1 - Rare; 2_unlikely = 2 - Unlikely; 3_possible = 3 - Possible; 4_likely = 4 - Likely; 5_almost_certain = 5 - Almost certain.\nImpact on your unit if it occurred: 1_insignificant = 1 - Insignificant; 2_minor = 2 - Minor; 3_moderate = 3 - Moderate; 4_major = 4 - Major; 5_severe = 5 - Severe.\n- Create a draft Issue for each self-identified exception (issue_type: deficiency or observation per severity; source: self_assessment; severity; description; issue_owner; identified_date), linked to the affected Risk and Control (coach-item-create, coach-items-link).\n- Log the attestation metadata — owner name, role, attestation date — as an attestation-log document on this step (no native attestation field), attached to the unit's return.\n\nRecord in the native step result or attached source documents: Unit and the control or risk id this response covers (assessment_scope_reference); Is the control designed to address the risk? (control_design_rating); Did the control operate as designed through the period? (control_performance_rating); Likelihood of the risk occurring in your unit over the next period (risk_likelihood); Impact on your unit if it occurred (risk_impact); Exception detail - required for any rating at or below the methodology threshold: what failed, when, and how it was detected (exception_detail); Your proposed action and target date for any exception raised above (proposed_action); I personally attest that these ratings and exceptions reflect how my unit's controls actually operated in the period (owner_attestation). Use native approvals for sign-off.\n\n**Exit criteria**\nPersonally rate design, performance and likelihood/impact against actual evidence, expose every threshold exception and attest their own assessment.\nEvery in-scope unit has an accountable recipient who actually received the assessment workpaper; no orphaned units (owner on leave, departed, or disputing ownership); every disputed assignment resolved to a named person; the distribution ledger and reminders are set before the window opens.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` — issues each assessment workpaper to its owner and schedules the pre-deadline reminders from the distribution ledger.\nEach control/process owner has completed honest, evidence-based ratings, documented (not smoothed) exceptions, and formally attested the return; the program lead has spot-checked a sample of early returns for quality while the window is still open; every exception exists as a draft issue record.","label":"Owners rate and attest","performedBy":{"primitives":["coach-document-upload","coach-workflow-scan","coach-notify","coach-form-fill","coach-item-create","coach-items-link"]}},"id":"owners-rate-and-attest"},{"data":{"decisionField":"returns_status","description":"Agent reconciles attested returns against the universe ledger and pre-stages escalations; human program lead decides whether the wave is complete or outstanding units must be escalated","formData":{"fields":[{"key":"returns_status","label":"Completeness status","options":[{"label":"All units returned and attested","value":"all_returned"},{"label":"Outstanding units - escalation required","value":"escalation_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve whether the wave has a complete, attested population or outstanding units must be escalated before calibration. Owned by the RCSA program lead.\n\n**Decision criteria**\n- Choose **all_returned** (All units returned and attested) when every unit in the assessment universe is marked returned-and-attested against the distribution ledger — no unit outstanding, none returned-but-unattested. Calibration can begin on a complete population.\n- Choose **escalation_required** (Outstanding units - escalation required) when one or more units are still outstanding or unattested after the chase window, such that calibrating now would silently exclude part of the population. These units must be escalated to their leadership first.\n\nAgent preparation before the human picks: (1) reconcile returned-and-attested vs returned-but-unattested vs outstanding against the ledger; (2) chase outstanding/unattested units within the chase window with escalating reminders, copying unit leadership as the deadline recedes; (3) compile the completeness report — response rate against the universe, each outstanding unit with days overdue and owner, prior-wave repeat late responders flagged; (4) pre-stage an escalation draft per outstanding unit (missed deadline, the wave dates it threatens, the leadership contact) so escalation costs one decision, not a drafting cycle.\n\n**Record in AssureSwarm** — Submit the `returns_status` SELECT (all_returned | escalation_required). In the step result, record the response rate, the outstanding units by name, and the evidence references; name the decision owner in the step's approver record. Pull the reconciliation via coach-query-data and coach-workflow-scan, and attach the completeness report (response rate, outstanding units) as a document on this step.\n\n**Exit criteria** — The `returns_status` form is submitted with a rationale and owner; the unselected branch is prunable.","kind":"decision","label":"Verify returns complete","performedBy":{"primitives":["coach-query-data","coach-workflow-scan"]}},"id":"verify-returns-complete"},{"data":{"description":"Agent escalates each outstanding unit to its leadership, validates late returns, and documents any leadership-acknowledged non-response; human program lead confirms no unit is silently missing","instructions":"**Objective** — Convert every outstanding unit into either a validated late return or a leadership-acknowledged non-response record, so the aggregate view can show unassessed units explicitly rather than silently dropping them.\n\n**Inputs**\n- The completeness report and the pre-staged escalation drafts (from the verify-returns decision).\n- Each outstanding unit's owner, leadership contact, and days overdue.\n- The calibration and committee dates now at risk.\n\n**Procedure**\n1. Send the pre-staged escalation for each outstanding unit to its leadership, stating the missed deadline, days overdue, and the calibration/committee dates the gap threatens, with a final return date.\n2. Validate late returns to the same bar as on-time returns — completeness, both rating scales, structured exceptions, attestation — so escalated units get no lower quality bar.\n3. Where a unit will not return within the wave, draft a non-response record acknowledged by that unit's leadership: the unit appears in the aggregate explicitly as unassessed, with the reason and the leadership sign-off — never silently omitted or carried forward at its old ratings.\n4. Update the completeness ledger and escalation log so the record shows exactly which returns arrived only under escalation.\n\n**Record in AssureSwarm**\n- Upload the escalation and any leadership-acknowledged non-response document (coach-document-upload).\n- Re-run the workflow scan to confirm the population is now fully accounted for (coach-workflow-scan).\n\n**Exit criteria** — Every unit is now returned-and-attested or carries a leadership-acknowledged non-response record; the ledger and escalation log are updated; the program lead has released the wave into challenge and calibration.","label":"Escalate outstanding units","performedBy":{"primitives":["coach-workflow-scan","coach-document-upload"]}},"id":"escalate-outstanding-units"},{"data":{"decisionField":"calibration_outcome","description":"Agent prepares the second-line challenge pack and supports the calibration session; human second-line risk lead decides whether the calibrated results are credible or units must rework","formData":{"fields":[{"key":"calibration_outcome","label":"Calibration outcome","options":[{"label":"Results credible - accept into aggregation","value":"results_credible"},{"label":"One or more units must rework their assessment","value":"rework_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve whether the second-line-calibrated results are credible and fit to aggregate, or one or more units must re-perform their assessment. Owned by the second-line risk lead.\n\n**Decision criteria**\n- Choose **results_credible** (Results credible - accept into aggregation) when the calibrated results are internally consistent, evidence-backed, and reconciled across peer units — every material challenge either upheld with owner-produced evidence or adjusted with owner concurrence — so the dataset can be aggregated as-is.\n- Choose **rework_required** (One or more units must rework their assessment) when at least one unit's return cannot be made credible within the session — ratings contradicted by evidence the owner cannot reconcile, or the all-effective / zero-exception under-reporting pattern the owner will not substantiate — so those units must re-perform against specific challenges before their results are used.\n\nAgent preparation before the human picks: (1) build the challenge pack per unit — ratings against objective signals (incidents, losses, audit findings, KRI breaches), rating distribution vs peers, movement vs prior wave, and an explicit flag on returns rating everything effective with zero exceptions; (2) schedule and support the calibration session, logging every challenged rating and its resolution (upheld with evidence, or adjusted with owner concurrence); (3) apply agreed adjustments to the wave dataset while preserving both the original owner rating and the calibrated rating; (4) compile the calibration memo — challenges, resolutions, cross-unit corrections, and any unit that could not be made credible in-session.\n\n**Record in AssureSwarm** — Submit the `calibration_outcome` SELECT (results_credible | rework_required). In the step result, record the challenges raised and resolved and the evidence references; name the decision owner in the step's approver record. Build the challenge/calibration views via coach-dashboard-create and coach-query-data, and attach the challenge pack and the calibration memo as documents on this step — the memo preserves both the original owner rating and the calibrated rating and is the system of record for pre-calibration values, since a Risk item holds only one residual_rating.\n\n**Exit criteria** — The `calibration_outcome` form is submitted with rationale and owner; the calibration memo preserves original vs calibrated ratings; the unselected branch is prunable.","kind":"decision","label":"Challenge and calibrate results","performedBy":{"primitives":["coach-query-data","coach-dashboard-create"]}},"id":"challenge-and-calibrate-results"},{"data":{"description":"Agent returns failed questionnaires with the specific calibration challenges to address and validates the re-returns; human second-line lead confirms each reworked return now stands up","instructions":"**Objective** — Turn each failed unit's return into a re-attested, challenge-answered assessment that stands up, without slipping the committee date.\n\n**Inputs**\n- The calibration memo and the specific challenges per failed unit (from the calibrate decision).\n- The contested ratings and the contradicting evidence the second line cited.\n- The remaining schedule margin to the committee date.\n\n**Procedure**\n1. Return each failed unit's assessment workpaper to its owner with the specific calibration challenges to address — the contested ratings, the contradicting evidence cited, and what a credible re-assessment must demonstrate — not a bare request to try again.\n2. Set a short rework deadline that protects the committee reporting date; track re-returns against it and escalate to unit leadership immediately on slippage, since the normal chase window is spent.\n3. Validate each re-return and re-run the challenge comparison on the reworked units: every contested rating is now either evidenced or adjusted, and the owner has re-attested the corrected assessment.\n4. Update the calibration memo with the rework outcomes so the record shows both what challenge found and how each unit answered it.\n\n**Record in AssureSwarm**\n- Capture the reworked returns in native results with corrected assessment workpapers and the owner’s new native attestation; the corrected residual ratings post to the Risk items at the aggregation step, not here.\n- Refresh the challenge comparison (coach-query-data) and append the rework outcomes to the calibration-memo document.\n\n**Exit criteria** — Each reworked return stands up to the original challenge — real evidence, concurred and re-attested adjustments, no contested rating slipping through unchanged; the second-line lead has released the corrected results into aggregation.","label":"Rework unit assessments","performedBy":{"primitives":["coach-form-fill","coach-query-data"]}},"id":"rework-unit-assessments"},{"data":{"description":"Program lead and second-line risk team: Approve a faithful cross-unit baseline with each breach and unassessed unit visible, and ensure every threshold exception has an acknowledged remediation or formal acceptance destination.","instructions":"**Objective** — Aggregate the calibrated returns without hiding individual breaches, update the risk register and reconcile every issue/exception to its acknowledged downstream disposition.\n\n**Inputs**\n- The calibrated wave dataset (credible returns plus any reworked returns) and the calibration memo.\n- The organization's risk appetite and tolerance thresholds by category/unit.\n- The prior wave's aggregate for trending, and the risk register entries to update.\n- The approved residual-risk baseline and the draft issue records from the attested returns.\n- The methodology's severity definitions and any existing issues from audits/prior waves (to dedupe against).\n- The two downstream handoff targets: the Finding Remediation & Action-Plan Monitoring workflow (for deficiencies to fix) and the Policy Exception & Risk Acceptance workflow (for exceptions to accept).\n\n**Procedure**\n*Autonomous preparation incorporates Aggregate residual-risk view; Program lead and second-line risk team reviews the combined evidence.*\n1. Aggregate across the universe: rating distributions by unit, process, and risk category; a control design-vs-performance heat map; exception density by unit; and unassessed units shown explicitly, never dropped.\n2. Compare aggregate exposure to appetite and tolerance, flagging every category or unit whose residual position breaches tolerance individually — do not let breaches average away inside portfolio totals.\n3. Trend against the prior wave: units that improved or deteriorated, repeat exceptions on the same controls, and chronic under-performers, so the movement story is explicit and traceable to underlying returns.\n4. Update the affected risk-register entries with this wave's residual ratings and build the portfolio dashboard the routing and reporting steps draw from.\n5. Triage every self-identified issue from the attested returns: confirm severity per the methodology, dedupe against issues already tracked from audits or prior waves, and give each a named owner and target date.\n6. For each confirmed deficiency requiring corrective action, package the finding — rating, exception narrative, evidence, owner, target date — and hand it off into the Finding Remediation & Action-Plan Monitoring workflow, so action plans are tracked to closure there rather than re-triaged or left in the assessment workpaper.\n7. For each exception the unit intends to live with rather than fix, package a waiver request — the control, the gap, the business rationale, and the exposure — into the Policy Exception & Risk Acceptance workflow, so acceptance is risk-assessed, time-bound, and approved at the right authority level rather than surviving as a silent RCSA footnote.\n8. Reconcile the routing: every at-or-below-threshold rating in the calibrated dataset maps to exactly one disposition — a remediation handoff, a formal acceptance handoff, or a documented calibration adjustment — with no unrouted residue.\n\n**Record in AssureSwarm**\n- Build the residual-risk dashboard (coach-dashboard-create) from the calibrated dataset (coach-query-data), and attach the baseline XLSX (distributions, heat map, tolerance breaches, unassessed units) as a document on this step.\n- Update the affected Risk items with this wave's residual ratings — Risk.residual_rating (and Risk.likelihood / Risk.impact where recalibrated) (coach-item-update).\n- For each deficiency to fix, create an Issue (issue_type: deficiency; source: self_assessment; severity; issue_owner; target_remediation_date) linked to its Control, Risk, and the wave Audit (coach-item-create, coach-items-link), and package it for the Finding Remediation & Action-Plan Monitoring workflow (coach-render-package), recording the tracking identifier.\n- For each exception the unit intends to accept rather than fix, create an Issue (issue_type: policy_exception; source: self_assessment; severity; exception_approver; exception_expiry_date) linked to the affected Risk (and any governing Policy), and set Risk.treatment = accept on that Risk only after the downstream authorized acceptance is actually granted; until then retain its prior treatment and label the request pending (coach-item-create, coach-items-link, coach-item-update); package the waiver for the Policy Exception & Risk Acceptance workflow (coach-render-package) and record its tracking identifier.\n\n**Exit criteria**\nApprove a faithful cross-unit baseline with each breach and unassessed unit visible, and ensure every threshold exception has an acknowledged remediation or formal acceptance destination.\nThe aggregate is faithful to the calibrated returns — every unit present or explicitly marked unassessed, tolerance breaches flagged individually, trend movements traceable; the program lead and second-line team have approved it as the wave's residual-risk baseline.\nEvery self-identified exception has left the RCSA as a tracked remediation item or a formal acceptance request with an owner and date; the routing reconciliation shows no unrouted residue; both downstream workflows have acknowledged the handoff packages; the program lead and second-line team have confirmed it complete.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` — assembles each finding and waiver into the handoff package its downstream workflow expects.","label":"Route issues and exceptions","performedBy":{"primitives":["coach-dashboard-create","coach-query-data","coach-item-update","coach-item-create","coach-items-link","coach-render-package"]}},"id":"route-issues-and-exceptions"},{"data":{"description":"Agent compiles the wave report from the approved baseline and assembles the standalone archive; the risk committee reviews the results and the program lead captures its directives, verifies every handoff landed downstream, and closes the wave on that record","instructions":"**Objective** — Compile the wave report from the approved baseline, stage it into the committee reporting cycle, capture the committee's directives as tracked follow-ups, and close the wave on that record with a standalone archive and every handoff verified.\n\n**Inputs**\n- The approved residual-risk baseline and dashboard (from the approved aggregation stage).\n- The routing reconciliation with issue/exception counts and their handoff status (from the approved routing stage), and the downstream tracking identifiers it produced.\n- The downstream reporting target: the Quarterly Board & Audit-Committee GRC Reporting workflow.\n- Every other wave artifact, for the archive: the confirmed assessment universe, scope, and schedule; assessment workpapers; attested returns; the completeness ledger with escalations and any non-response records; the challenge pack; the calibration memo and rework outcomes.\n- The retention period from the applicable evidence policy.\n\n**Procedure**\n\n_Items 5–8 close the workflow (folded from the former \"Close and archive\" step); the committee's review and the directives captured here are the closure._\n\n1. Compile the report from the baseline: universe coverage and response rate; calibrated rating distributions and the heat map; the appetite/tolerance position with each breach named; the top residual exposures; self-identified issue and exception counts with routing status; unassessed units with reasons; and movement against the prior wave.\n2. Draft a narrative the committee can act on: where control performance deteriorated, what second-line challenge changed and where under-reporting was found, and which exposures now sit outside tolerance awaiting treatment or acceptance.\n3. Stage the report package into the Quarterly Board & Audit-Committee GRC Reporting workflow for the committee cycle, and distribute unit-level results to each unit's leadership so owners see their position against peers.\n4. Log every committee question and directive from the session as a tracked follow-up with a named owner and due date.\n5. Assemble the complete wave record — the report and every artifact above — into one package, archive it to the designated evidence repository under the applicable retention period, and export the workflow record so the package stands alone.\n6. Verify every routed issue and exception actually landed in its downstream workflow with a live tracking identifier — no handoff accepted in principle but never opened.\n7. Compile lessons for the next wave — scale points owners misread, chronic late units, under-reporting patterns challenge kept finding — and record the next wave's scheduled date.\n8. Close the wave anchor on the committee's reviewed result: the rating and report date recorded here are the wave's formal closure, and no favorable post-committee edit is admissible.\n\n**Record in AssureSwarm**\n- Assemble and export the wave report package (PDF/XLSX) for the Quarterly Board & Audit-Committee GRC Reporting workflow (coach-render-package, coach-item-export) and build/refresh the committee dashboard (coach-dashboard-create).\n- Record each committee directive as an Issue (issue_type: observation; source: management_identified; issue_owner; target_remediation_date) linked to the wave Audit (coach-item-create).\n- Export the workflow instance as the standalone audit trail (coach-workflow-export) and upload the archive package to the evidence repository (coach-document-upload).\n- Close the wave anchor: set Audit.rating (satisfactory | needs_improvement | unsatisfactory) and confirm Audit.report_date on the wave Audit item (coach-item-update).\n- Record the next wave's scheduled date and the lessons-learned note as a document on this step.\n\n**Exit criteria** — The presented report matches the approved baseline without favorable edits; the package is staged into the reporting workflow; unit-level results are distributed; every committee directive is captured with an owner. The archive stands alone as evidence to auditors and regulators — who assessed each unit, what they attested, how the second line challenged it, and where every self-identified exception went; no handoff is orphaned; the next wave is scheduled; and the wave anchor is closed on the committee's reviewed result.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` — compiles the wave report and unit-level result packs from the approved baseline and routing reconciliation.","label":"Report to risk committee","performedBy":{"primitives":["coach-export-package","coach-dashboard-create","coach-render-package","coach-item-create","coach-workflow-export","coach-document-upload","coach-item-update"]}},"id":"report-to-risk-committee"}],"sourceTemplateId":"workflow-library:grc-rcsa-program"}
