{"description":"Runs on the existing risk item. Assess a risk against current context and evidence, select a supported treatment response, and approve a traceable review record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-risk-assessment-risk-review-closure","source":"risk-assessment","target":"risk-review-closure"}],"isPublic":true,"itemTypeSlug":"risk","metadata":{"capabilities":["risk-assessment-treatment-review"],"controlVerbs":{"UC-RISK-04":"operates","UC-RISK-07":"operates","UC-RISK-08":"operates","UC-RISK-09":"operates","UC-RISK-13":"operates"},"controls":["UC-RISK-04","UC-RISK-07","UC-RISK-08","UC-RISK-09","UC-RISK-13"],"department":"risk-management","domains":["grc"],"kind":"risk-assessment-treatment-review","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:risk-assessment-treatment-review"}],"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-assessment-treatment-review","contentDigest":"sha256:be78b032b9dd7a006f5dcc70e2dfb3e6acad595c02e4813e28601c1b350ed90c","prerequisites":{"anchorItemType":{"slug":"risk"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-enterprise-risk-assessment-cycle"}],"roles":[{"contribution":"expertise","description":"Risk assessment specialist. Assess exposure and control response.","id":"reviewer-1","nodeIds":["risk-assessment"]},{"contribution":"approval","description":"Risk acceptance authority. Approve risk review record.","id":"reviewer-2","nodeIds":["risk-review-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:risk-assessment-treatment-review"}],"releaseId":"sha256:be78b032b9dd7a006f5dcc70e2dfb3e6acad595c02e4813e28601c1b350ed90c","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-risk-assessment-treatment-review"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-risk-assessment-treatment-review","source":"coworkcanvas-gallery","standards":["coso-erm","iso-31000","nist-800-53","soc2"],"teams":["risk-management"]},"name":"Risk Assessment & Treatment Review","nodes":[{"data":{"controls":[],"instructions":"**Objective**\nAssess exposure and control response. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, business objectives, process and system maps, incidents, issues, loss events, prior assessments, control results, external changes, and approved scoring criteria.\n2. Use the confirmed context, scoring rubric, control design and testing results, monitoring trends, incidents, issues, scenarios, threat information, financial data, and owner representations.\n\n**Procedure**\n1. Reframe the risk as a clear cause-event-impact statement, confirm affected assets and stakeholders, reconcile ownership, identify material assumptions and dependencies, and document scope changes since the prior review.\n2. Score each required dimension, test the rationale against cited facts, evaluate control coverage and limitations, compare current and prior results, perform scenario analysis where material, and challenge optimistic assumptions.\n\n**Record in AssureSwarm**\n1. Capture the assessment period, risk context, owner, affected objectives, boundaries, assumptions, dependencies, change triggers, source references, and information gaps.\n2. Document scores, rating direction, calculation or rubric applied, supporting and contrary evidence, control reliance, uncertainty, sensitivity, prior-period comparison, and unresolved data requests. Also record assessment result.\n\n**Exit criteria**\nRisk assessment specialist provides expertise: The risk statement is decision-useful, ownership and assessment criteria are confirmed, and gaps that could change the assessment are visible and assigned. The assessment is reproducible from the cited evidence, rating changes are explained, and material uncertainty or control limitations are carried into treatment analysis.","kind":"task","label":"Assess exposure and control response","requiredApprovals":1},"id":"risk-assessment"},{"data":{"controls":["UC-RISK-04","UC-RISK-07","UC-RISK-08","UC-RISK-09","UC-RISK-13"],"instructions":"**Objective**\nApprove risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, appetite and tolerance statements, existing initiatives, proposed controls, insurance or contractual terms, budget and resource constraints, dependencies, and stakeholder analysis.\n2. Review all stage records, scoring support, control evidence, treatment analysis, appetite exceptions, stakeholder responses, linked actions, monitoring measures, and open information gaps.\n\n**Procedure**\n1. Compare accept, mitigate, transfer, and avoid options; estimate risk reduction and secondary effects; define measurable actions and escalation triggers; identify owners and dates; and route appetite exceptions to authorized governance.\n2. Trace material ratings and decisions to evidence, verify action ownership and dates, confirm contrary evidence remains visible, reconcile linked records, and return incomplete or inconsistent analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the treatment decision, rationale, response plan, expected residual exposure, action owners, milestones, resources, dependencies, monitoring indicators, escalation thresholds, and linked remediation items.\n2. Capture the authorized reviewer, the review summary, accepted assessment and treatment references, effective review date, monitoring cadence, linked actions, open limitations, owners, and due dates. Also record risk review summary.\n\n**Exit criteria**\nRisk acceptance authority provides approval: An approver accepts that the selected response follows from the assessment and appetite criteria, while rejected options and any required exception approval remain traceable. The authorized reviewer accepts the risk review as a traceable record of analysis and decisions, linked records can be updated consistently, and no assurance claim is inferred from closure.","kind":"task","label":"Approve risk review record","requiredApprovals":1},"id":"risk-review-closure"}],"sourceTemplateId":"workflow-library:grc-risk-assessment-treatment-review"}
