{"description":"Manage a live regulator examination or external audit end to end — from notification intake through request fulfillment, QC’d evidence release, fieldwork support, preliminary-findings response, and commitment closure. Runs on an Audit engagement item created per exam (audit_type = regulatory_exam, or external_attestation for an external audit); the workflow instance attaches to that Audit anchor, and preliminary findings and their corrective-action commitments become linked Issue items. No upstream workflow feeds this — it is triggered by the exam or audit notification itself. In scope: coordinating examiner requests, controlled evidence release, and management responses for a single exam or audit engagement. Out of scope: remediating the underlying control gaps — the findings and committed corrective actions hand off to Finding Remediation & Action-Plan Monitoring — and standing up new obligations surfaced by the exam, which hand off to Regulatory Horizon Scanning & Triage and Regulatory Obligation Implementation.","edges":[{"id":"e-qc-responses-before-release-rework-flagged-responses","label":"Rework","source":"qc-responses-before-release","target":"rework-flagged-responses","whenValue":"rework"},{"id":"e-qc-responses-before-release-assess-preliminary-findings","label":"Release","source":"qc-responses-before-release","target":"assess-preliminary-findings","whenValue":"release"},{"id":"e-rework-flagged-responses-assess-preliminary-findings","source":"rework-flagged-responses","target":"assess-preliminary-findings"},{"id":"e-stand-up-exam-logistics-support-fieldwork-interactions","source":"stand-up-exam-logistics","target":"support-fieldwork-interactions"},{"id":"e-support-fieldwork-interactions-assess-preliminary-findings","source":"support-fieldwork-interactions","target":"assess-preliminary-findings"},{"id":"e-assess-preliminary-findings-compile-factual-accuracy-response","label":"Disputed","source":"assess-preliminary-findings","target":"compile-factual-accuracy-response","whenValue":"disputed"},{"id":"e-assess-preliminary-findings-draft-management-responses","label":"Accurate","source":"assess-preliminary-findings","target":"draft-management-responses","whenValue":"accurate"},{"id":"e-compile-factual-accuracy-response-draft-management-responses","source":"compile-factual-accuracy-response","target":"draft-management-responses"},{"id":"e-draft-management-responses-track-commitments-to-closure","source":"draft-management-responses","target":"track-commitments-to-closure"},{"id":"e-track-commitments-to-closure-handoff-to-related-workflow","source":"track-commitments-to-closure","target":"handoff-to-related-workflow"},{"id":"e-track-commitments-to-closure-conduct-lessons-learned","source":"track-commitments-to-closure","target":"conduct-lessons-learned"},{"id":"e-handoff-to-related-workflow-conduct-lessons-learned","source":"handoff-to-related-workflow","target":"conduct-lessons-learned"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-GOV-23","UC-AUDIT-17","UC-AUDIT-23","UC-AUDIT-24","UC-ACCESS-14"],"department":"compliance-legal","domains":["grc","reg"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-regulatory-exam-management","contentDigest":"sha256:f6435e4199020b25d9143bcab2ab97b3aebb9f4c636df19a252b35f46f085c74","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:f6435e4199020b25d9143bcab2ab97b3aebb9f4c636df19a252b35f46f085c74","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-regulatory-exam-management"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-regulatory-exam-management","source":"coworkcanvas-gallery","standards":["nydfs-500","dora","soc1","soc2"],"teams":["compliance-legal"]},"name":"Regulatory Exam & External Audit Management","nodes":[{"data":{"description":"Provision the secure data room, name the single point of contact, and set the communication protocol","instructions":"**Objective** — Provision the controlled examiner-interaction infrastructure — secure data room, single point of contact, and communication protocol — so every request, release, and interaction is traceable and privilege-safe.\n\n**Inputs**\n- Exam or audit notification letter; examiner or audit-firm contacts; exam type, review period, and the legal entities and functions in scope.\n- Data-room access roster and prior exam findings and open commitments (existing Issue items from the prior exam, source: regulatory_exam / external_audit, linked to the prior Audit item and its archived workflow instance).\n- Response due dates, escalation thresholds, and the named accountable executive and exam manager.\n- The exam playbook and standing evidence inventory carried into the engagement (documents referenced here and updated at lessons-learned; no native Playbook type).\n- Governing standards (NYDFS 500, DORA, SOC 1, SOC 2) as existing Control items whose framework tags contain nydfs-500 | dora | soc1 | soc2.\n- No upstream workflow feeds this; the trigger is the exam or audit notification itself.\n\n**Procedure**\n1. Log the notification: record the regulator or external audit firm, exam type, review period, entities and functions in scope, and the accountable executive and exam manager.\n2. Provision the secure data room or examiner portal and load the approved access roster; grant least-privilege access and record who can see what.\n3. Designate the single point of contact through whom all examiner communication flows; publish the communication protocol covering response channels, who may speak with examiners, meeting-note expectations, escalation paths, and the thresholds that trigger executive escalation.\n4. Hold an internal kickoff briefing for all in-scope teams so owners understand timelines, confidentiality expectations, and the no-side-channel rule (no one answers an examiner directly).\n5. Confirm accountability by naming the decision owner for evidence release and the owner for findings responses.\n\n**Record in AssureSwarm**\n- Create the Audit engagement item — the anchor: audit_type = regulatory_exam (or external_attestation for an external audit), external_firm = the regulator or audit firm, scope, period_start / period_end for the review period, lead_auditor = the exam manager; record the accountable executive, the single point of contact, and the evidence-release and findings-response decision owners in Audit.description.\n- Where in-scope functions exist as Process items, link Audit ↔ Process for each.\n- Attach the notification letter, the published communication protocol, and the data-room access roster + access-grant log as documents on this step (no native Contact/Roster type).\n\n**Exit criteria** — Data room provisioned with the approved roster; single point of contact named; communication protocol published and acknowledged by in-scope teams; engagement record created with accountable owners.","label":"Stand up exam logistics"},"id":"stand-up-exam-logistics"},{"data":{"decisionField":"release_path","description":"Named evidence-release decision owner: Judge each assigned, source-tagged package for request completeness, accuracy, privilege and data minimization before authorizing release or targeted rework.","formData":{"fields":[{"key":"release_path","label":"QC responses before release","options":[{"label":"Release to examiner","value":"release"},{"label":"Rework before release","value":"rework"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Decompose and assign the request population, retain source/coverage/sensitivity evidence in results and documents, and authorize each staged package for release or rework.\n\n**Decision criteria**\nInputs for preparation: - First-day letter or initial request list; response due dates; escalation thresholds.\n- The systems, document repositories, and business-owner directory that hold the evidence.\n- The single point of contact, for routing clarifying questions to the examiner.\n\n*Autonomous preparation incorporates Decompose and assign the request list; Named evidence-release decision owner reviews the combined evidence.*\n1. Log the first-day letter or initial request list on arrival and timestamp receipt.\n2. Assign each item a unique request ID; split compound requests into single answerable items so each has one deliverable and one owner.\n3. Flag ambiguous or over-broad items; draft clarifying questions and route them to the examiner through the single point of contact rather than guessing scope.\n4. Map each item to the systems, documents, and business owners that hold the evidence.\n5. Assign each request to an accountable owner with an internal due date buffered ahead of the examiner deadline (typically 3 to 5 business days), and confirm owner acceptance. Have the assigned owner record their response in the native result and attach the evidence, identifying its source, period, coverage caveats and any sensitive-content flag — the QC step reads those flags before anything reaches the examiner.\n6. Stand up the aging queue and monitor it daily: chase at-risk items, rebalance workload where owners are overloaded, and escalate slippage that threatens a committed delivery date to the exam manager.\n\n- Choose **Release to examiner** (`release`) when the response fully answers the request as asked, the evidence is accurate and current, and the privileged-content and confidentiality check passes: no legal privilege is waived, no confidential supervisory information is improperly included, and personal data is minimized to what the request requires.\n- Choose **Rework before release** (`rework`) when the response is incomplete or off-point, cites stale or wrong evidence, or the privilege and confidentiality check flags legal-privilege exposure, confidential supervisory information, or unminimized personal data that must be redacted or removed first.\n\n**Record in AssureSwarm**\n- Attach the first-day letter as an upload on this step.\n- The assigned owner’s native result records the request ID, source system, period, coverage limitations and sensitive-content classification (none, personal/customer data, legal privilege or third-party confidentiality); attach the actual evidence document. Retain preparer/reviewer identity and submission date from the auditable result/approval trail.\n- Maintain the per-request tracker as an XLSX workpaper on this step — one row per decomposed item: request ID, source-letter reference, owner, internal due date, examiner deadline, mapped evidence sources, and status (there is no native Exam-Request item type; this tracker is the operational record and carries through release and supplemental intake).\n- Log clarifying questions and examiner responses in the tracker against the parent request row.\nSubmit the `release_path` SELECT on this step's form (release or rework). Record the decision owner in the step's approver record and the rationale, request ID, and evidence references in the step result.\n\nRecord in the native step result or attached source documents: Request ID this response answers (request_id); Evidence file or export (evidence_file); System or repository the evidence came from (evidence_source_system); Period the evidence covers (period_covered); What this response does and does not cover, and anything the requester should know to read it correctly (completeness_statement); Sensitive content in this response (sensitive_content_flag); Who prepared this and who reviewed it before submission (preparer_and_reviewer); Date submitted (date_provided). Use native approvals for sign-off.\n\n**Exit criteria**\nJudge each assigned, source-tagged package for request completeness, accuracy, privilege and data minimization before authorizing release or targeted rework.\nEvery request has a unique ID, one owner, an internal due date ahead of the examiner deadline, and mapped evidence sources; ambiguous items carry logged clarifying questions; each owner's return carries its source, period, coverage statement, and sensitive-content flag; the aging queue is live and monitored.\nThe form is submitted with a rationale; the unused branch is prunable because the branch edge values (release, rework) match the selected form value.","kind":"decision","label":"QC responses before release"},"id":"qc-responses-before-release"},{"data":{"description":"Return flagged packages to owners and resolve QC, redaction, or privilege issues","instructions":"**Objective** — Resolve every issue that blocked a response package from release and re-QC the corrected package before it re-enters the release queue.\n\n**Inputs**\n- The flagged package and the specific QC comments, missing evidence, redaction requirements, or privilege concerns recorded on the release decision.\n- The examiner deadline for the underlying request.\n\n**Procedure**\n1. Return each flagged package to its owner with the specific defects to fix: missing evidence, QC comments, required redactions, or privilege concerns.\n2. Track rework turnaround against the examiner deadline; escalate to the exam manager if the fix cannot land in time.\n3. Apply required redactions and remove privileged or confidential supervisory content; minimize personal data to what the request requires.\n4. Re-run the completeness, accuracy and privileged-content check on the corrected package and obtain the named release owner’s approval of that exact corrected version.\n5. Record what changed between versions so the release log carries a clean version history.\n\n**Record in AssureSwarm**\n- Attach the corrected package version as a document on this step.\n- Set the request's status to reworked in the request-tracker XLSX and record the defects found and the changes applied in the version/change log on this step.\n\n**Exit criteria** — Every flagged package has its defects resolved, redactions applied, and a passing re-check; version differences are recorded; the package is ready for the release step.\n\n> **⚡ Audit Artist accelerator:** `/coach-redact` removes privileged and confidential supervisory content and minimizes personal data on the package before the re-check.","label":"Rework flagged responses","performedBy":{"agent":"grc-artist","primitives":["coach-redact"]}},"id":"rework-flagged-responses"},{"data":{"description":"Coordinate interview scheduling, observation support, and walkthrough logistics during fieldwork","instructions":"**Objective** — Support examiner fieldwork so every interview, walkthrough, and observation is prepared, in-scope, and debriefed under the communication protocol.\n\n**Inputs**\n- The communication protocol and single point of contact provisioned at logistics setup.\n- Examiner interview and walkthrough requests; the roster of personnel and system owners.\n\n**Procedure**\n1. Schedule examiner interviews with the right personnel; confirm attendees and scope in advance.\n2. Hold preparation briefings so interviewees answer accurately, within scope, and without volunteering out-of-scope material.\n3. Coordinate observation support and system demonstrations; manage walkthrough logistics including rooms, screen-share access, and attendee lists.\n4. Debrief after each session; log topics covered and any verbal concerns raised by examiners.\n5. Follow up on items promised during sessions and route them into the request tracker so nothing verbal is lost.\n\n**Record in AssureSwarm**\n- Attach each session debrief as a document on this step: attendees, topics, examiner concerns raised, and promised follow-ups; relate it to the Audit anchor.\n- Add any evidence promised in a session as new rows in the request-tracker XLSX.\n\n**Exit criteria** — Every scheduled interaction is prepped, run under the protocol, and debriefed; verbal concerns and promised follow-ups are logged and converted into tracked requests.","label":"Support fieldwork interactions"},"id":"support-fieldwork-interactions"},{"data":{"decisionField":"findings_accuracy","description":"Findings-response owner: Judge preliminary facts against controlled releases, supplemental responses and interview records, disputing only demonstrated factual errors.","formData":{"fields":[{"key":"findings_accuracy","label":"Assess preliminary findings","options":[{"label":"Factually accurate","value":"accurate"},{"label":"Factual accuracy disputed","value":"disputed"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Release only approved versions through the controlled channel, maintain supplemental-request discipline and decide whether preliminary findings are accurate or factually disputed.\n\n**Decision criteria**\nInputs for preparation: - Approved packages from the release decision, and reworked packages that passed re-check and obtained release approval.\n- The secure data room or examiner portal and the access roster provisioned at logistics setup.\n- The request tracker.\n- Supplemental or follow-up requests as they arrive; the parent request tracker and release log.\n- The accountable executive, for the concern-signal briefing.\n\n*Autonomous preparation incorporates Release responses and log delivery; Track supplemental requests; Findings-response owner reviews the combined evidence.*\n1. Confirm each package carries a release approval before touching the channel.\n2. Release each approved package through the secure data room or examiner portal only — never a side channel.\n3. Record a release-log entry per package: request ID, document versions, redactions applied, release date, approver, and recipient.\n4. Update the request tracker status to delivered.\n5. Reconcile the tracker against the release log so nothing is marked delivered without a logged release, and no logged release is missing from the tracker.\n6. Log each supplemental or follow-up request on arrival and link it to its parent request ID.\n7. Run it through the same loop as first-round items: decompose into answerable items, assign to an owner with an internal due date, review before release, and release through the data room with a logged entry.\n8. Track the volume and themes of follow-up requests; a cluster of follow-ups on one topic is an early signal of examiner concern.\n9. Brief the accountable executive on emerging focus areas so the organization is not surprised at the exit meeting.\n\n- Choose **Factually accurate** (`accurate`) when the finding's stated facts tie to the request tracker, the release log, and the interview debriefs — even where you disagree with the conclusion, the underlying facts are correct — and it should proceed to a management response.\n- Choose **Factual accuracy disputed** (`disputed`) when the finding rests on a factual error contradicted by released documents, data, or interview records (for example it cites evidence never requested, misstates a date or figure, or ignores evidence already delivered), warranting a factual-accuracy correction before the finding is finalized.\n\n**Record in AssureSwarm**\n- Attach the released document versions as documents on this step (the data room is an External system; AssureSwarm holds the released copies as the evidentiary mirror).\n- Write the release log as an XLSX/CSV on this step — one entry per package: request ID, document versions, redactions applied, release date, approver, recipient.\n- Set the request's status to delivered in the request-tracker XLSX.\n- Attach each supplemental letter as an upload on this step and add its decomposed items as new rows in the request-tracker XLSX, linked by parent request ID and carrying the same fields (owner, internal due date, examiner deadline, status).\n- Attach the examiner-concern-signal briefing as a document on this step, related to the Audit anchor.\nCreate one Issue per preliminary finding (issue_type: finding, source: regulatory_exam or external_audit, severity, identified_date) and link Issue ↔ Audit anchor — these Issues carry through response and become the commitment register. Submit the `findings_accuracy` SELECT (accurate or disputed) for the finding under review; record the decision owner in the step's approver record and the rationale with specific evidence references in the step result (this decision step stores one submission — per-finding outcomes live on the individual Issue items).\n\n**Exit criteria**\nJudge preliminary facts against controlled releases, supplemental responses and interview records, disputing only demonstrated factual errors.\nEvery approved package is released through the controlled channel with a matching release-log entry; the tracker and release log reconcile with zero unmatched rows.\n\n> **⚡ Audit Artist accelerator:** `/coach-document-upload` pushes each released version into the data room and records the release-log entry in one step.\nEvery supplemental request is logged, linked to its parent, and carried through review and logged release; emerging examiner focus areas are briefed to the accountable executive.\nThe form is submitted with a rationale; the unused branch is prunable because the branch edge values (accurate, disputed) match the selected form value.","kind":"decision","label":"Assess preliminary findings","performedBy":{"agent":"grc-artist","primitives":["coach-document-upload"]}},"id":"assess-preliminary-findings"},{"data":{"description":"Assemble the evidence-backed factual correction and deliver it through the single point of contact","instructions":"**Objective** — Correct the factual record on disputed findings before they are finalized, with an evidence-backed challenge delivered through the controlled channel.\n\n**Inputs**\n- The disputed preliminary finding and the rationale recorded at the assessment decision.\n- The release log, released documents and data, and interview debriefs that contradict the draft.\n- Legal review and the accountable executive.\n\n**Procedure**\n1. For each disputed finding, assemble an evidence-backed factual-accuracy response citing the specific released documents, data, and interview records that contradict the draft.\n2. Keep the response strictly factual — correct the record, do not argue the conclusion (that belongs in the management response).\n3. Route the response through legal review and the accountable executive for sign-off.\n4. Deliver it to the examiner through the single point of contact.\n5. Log the outcome of each dispute (accepted, partially accepted, or rejected) so the finding's final wording is traceable.\n\n**Record in AssureSwarm**\n- Attach the factual-accuracy response (DOCX/PDF) as a document on this step, related to the corresponding Issue item, and reference the cited released documents.\n- Log the legal and executive sign-off and the dispute outcome (accepted / partially accepted / rejected) on this step; fold the resolved wording into Issue.description.\n\n**Exit criteria** — Every disputed finding has an evidence-cited factual-accuracy response delivered and its outcome logged; legal and executive sign-offs are recorded.","label":"Compile factual-accuracy response"},"id":"compile-factual-accuracy-response"},{"data":{"description":"Draft management responses and corrective-action commitments with owners, dates, and feasibility confirmed","instructions":"**Objective** — Commit management to corrective actions the organization can actually deliver, with named owners and realistic dates, for every confirmed finding.\n\n**Inputs**\n- Confirmed findings from the accurate branch, and the resolved wording from any factual-accuracy corrections.\n- The owning teams for feasibility pressure-testing; the accountable executive.\n- The required response timeline stated in the notification.\n\n**Procedure**\n1. Draft the management response to each confirmed finding: acknowledge, contextualize where fair, and state the corrective action.\n2. Define corrective-action commitments with named owners and realistic target dates.\n3. Pressure-test feasibility with the owning teams before anything is promised to the regulator or audit firm — an over-promised date that slips is worse than a defensible longer one.\n4. Obtain accountable-executive approval on the full response package.\n5. Submit the response package within the required timeline through the single point of contact.\n\n**Record in AssureSwarm**\n- Attach the management response package (DOCX/PDF) as a document on this step, related to the Audit anchor.\n- On each confirmed finding's Issue, set management_response, remediation_plan, issue_owner, and target_remediation_date — these Issue fields ARE the commitment register (no separate record).\n- Log executive approval and the submission date on this step.\n\n**Exit criteria** — Every confirmed finding has an approved management response with feasibility-tested commitments (owner, date, closure evidence); the package is submitted within the required timeline.","label":"Draft management responses"},"id":"draft-management-responses"},{"data":{"description":"Register each commitment made to the examiner and verify closure evidence before reporting it complete","instructions":"**Objective** — Track every commitment made in the management response to verified closure, so nothing is reported complete to the regulator or audit firm without evidence.\n\n**Inputs**\n- The commitment register from the management responses (owner, due date, required closure evidence).\n- Progress evidence from commitment owners.\n\n**Procedure**\n1. Register every commitment with owner, due date, and the required closure evidence.\n2. Track progress on a defined cadence (for example weekly or monthly, set by criticality).\n3. Verify completion evidence against the required closure evidence before closure is reported — do not accept \"done\" without the artifact.\n4. Escalate at-risk commitments to the accountable executive before a committed date is missed.\n5. Report verified closures to the regulator or audit firm on the agreed reporting cadence.\n\n**Record in AssureSwarm**\n- On each commitment Issue, set actual_remediation_date and verified_date and move status → closed once the evidence is verified; attach the closure-evidence documents on this step.\n- Log escalations and the regulator/audit-firm status reports as documents on this step.\n\n**Exit criteria** — Every commitment is registered, tracked on cadence, and closed only with verified evidence; at-risk items are escalated before the due date; closures are reported.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-scan` watches the commitment register on cadence and surfaces at-risk items before their due dates.","label":"Track commitments to closure","performedBy":{"agent":"grc-artist","primitives":["coach-workflow-scan"]}},"id":"track-commitments-to-closure"},{"data":{"description":"Handoff outputs to Finding Remediation & Action-Plan Monitoring, Regulatory Horizon Scanning & Triage and Regulatory Obligation Implementation","instructions":"**Objective** — Route exam outputs to the downstream workflows that own the follow-on work, without duplicating it, and hand over a clean package.\n\n**Inputs**\n- The final exam package: findings, factual-accuracy responses, management responses, and the commitment register.\n- The downstream workflow owners.\n\n**Procedure**\n1. Route findings with control implications to Finding Remediation & Action-Plan Monitoring for remediation tracking; pass the finding, its evidence, and the committed corrective action.\n2. Route exam outcomes that imply new or changed regulatory obligations to Regulatory Horizon Scanning & Triage and Regulatory Obligation Implementation.\n3. Create or link the downstream workflow records; pass the final package and note assumptions and what the downstream should not repeat (for example evidence already gathered).\n4. Confirm the downstream owners have accepted the handoff.\n\n**Record in AssureSwarm**\n- Attach the handoff package (findings, factual-accuracy responses, management responses, commitment register, and do-not-repeat notes) as a document on this step; the shared records are the Issue items themselves, which the downstream remediation workflow anchors on.\n- Log acceptance by each downstream owner on this step.\n\n**Exit criteria** — Every finding and obligation with follow-on work is handed to its named downstream workflow with an accepted package; no follow-on work is left unowned.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-export` packages the exam outputs and `/coach-notify` alerts each downstream owner that their handoff is ready.","label":"Handoff to related workflow","performedBy":{"agent":"grc-artist","primitives":["coach-workflow-export","coach-notify"]}},"id":"handoff-to-related-workflow"},{"data":{"description":"Exam manager and readiness improvement owners: Judge the observed request/QC/fieldwork weaknesses and commit to owned readiness improvements; archive the final file and revoke obsolete access after both the review and accepted handoffs.","instructions":"**Objective** — Review the completed exam’s readiness lessons, assign improvements and retain the complete engagement archive with unneeded examiner access revoked.\n\n**Inputs**\n- The full engagement record: request-cycle timing, QC rework rates, data-room and protocol effectiveness, interview performance, and examiner feedback.\n- The exam playbook, standing evidence inventory, and authority contact protocols.\n- The complete exam file: correspondence, request tracker, release log, findings, factual-accuracy responses, management responses, and commitment register.\n- The data-room access roster.\n\n**Procedure**\n*Autonomous preparation incorporates Close and archive; Exam manager and readiness improvement owners reviews the combined evidence.*\n1. Run the post-exam lessons-learned review covering request-cycle timeliness, QC rework rates, data-room and protocol effectiveness, interview performance, and examiner feedback.\n2. Convert each weakness into an owned readiness improvement with a due date.\n3. Update the exam playbook, standing evidence inventory, and authority contact protocols.\n4. Share themes with compliance and audit leadership.\n5. Archive the complete exam file: correspondence, request tracker, release log, findings, factual-accuracy responses, management responses, and the commitment register.\n6. Update linked records; schedule the commitment follow-up cadence and any regulator status reporting that outlives the engagement.\n7. Revoke data-room access that is no longer needed.\n8. Communicate the final outcome to the accountable executive and in-scope teams.\n\n**Record in AssureSwarm**\n- Attach the lessons-learned memo as a document on this step, related to the Audit anchor; list each owned readiness improvement with owner and due date in the memo (no native Task type).\n- Attach the updated exam playbook and the standing evidence-inventory reference as documents on this step (no native Playbook type).\n- On the Audit anchor, set rating and report_date and move status → closed (set opinion only if the external audit issues a formal opinion).\n- The workflow instance is the archived, tamper-evident audit trail; attach the archived-file index and the access-revocation log as documents on this step, and note the scheduled follow-up cadence.\n\n**Exit criteria**\nJudge the observed request/QC/fieldwork weaknesses and commit to owned readiness improvements; archive the final file and revoke obsolete access after both the review and accepted handoffs.\nLessons-learned review complete; each weakness has an owned improvement; playbook, evidence inventory, and contact protocols updated; themes shared with leadership.\nFull exam file archived and indexed; residual commitment follow-ups scheduled; unneeded data-room access revoked; final outcome communicated; engagement marked closed.","label":"Conduct lessons learned"},"id":"conduct-lessons-learned"}],"sourceTemplateId":"workflow-library:grc-regulatory-exam-management"}
