{"description":"Risk Communication, Reporting & Performance Review as a decision-aware workflow that runs each quarter or on an out-of-cycle significant matter. Because none of the eight Studio item types represents the ERM reporting cycle itself, the workflow instance IS the durable record: its named deliverables - the tiered internal and external risk, control and performance reporting package, the event-driven report on a significant matter, the management-signed risk-and-control performance-review pack, and the tracked improvement actions - attach to its steps, its item-level writes land on the existing Risk, Control, and Issue items (improvement actions are tracked as Issues with source: self_assessment); control-testing results are read from SOX testing workflows hosted directly on the relevant Controls; and the risk-management framework is read as its Policy item (policy_type: charter) for the evaluation baseline and the suppliers and third parties consulted as their Vendor items. In scope: stakeholder consultation across every risk-process step (identification, assessment, response, monitoring) including suppliers and third parties; the cadenced internal and external reporting package; event-driven reporting on significant matters; the periodic review of risk-management and internal-control performance against the framework's design intent with accountable management; and converting lessons into owned, tracked improvement actions. Out of scope: running the underlying risk assessments, control testing, or business-performance measurement themselves - this workflow consumes their results as inputs. It starts on its own trigger (the quarterly cadence or a significant event) and has no upstream feeder workflow and no named downstream handoff workflow; each run's close-and-archive leaves the stakeholder, risk, and improvement registers current - the informal handoff both to the next cycle of this workflow and to the downstream risk-assessment and control-testing workflows whose results this cycle consumes.","edges":[{"id":"e-assess-event-driven-reporting-need-issue-event-driven-report","label":"Significant matter","source":"assess-event-driven-reporting-need","target":"issue-event-driven-report","whenValue":"significant_matter"},{"id":"e-assess-event-driven-reporting-need-deliver-reporting-package","label":"Routine cycle","source":"assess-event-driven-reporting-need","target":"deliver-reporting-package","whenValue":"routine_cycle"},{"id":"e-issue-event-driven-report-deliver-reporting-package","source":"issue-event-driven-report","target":"deliver-reporting-package"},{"id":"e-deliver-reporting-package-close-and-archive","source":"deliver-reporting-package","target":"close-and-archive"},{"id":"e-plan-stakeholder-consultation-identify-and-decide-improvement-actions","source":"plan-stakeholder-consultation","target":"identify-and-decide-improvement-actions"},{"id":"e-review-risk-and-control-performance-identify-and-decide-improvement-actions","source":"review-risk-and-control-performance","target":"identify-and-decide-improvement-actions"},{"id":"e-identify-and-decide-improvement-actions-track-improvement-actions-to-closure","label":"Action required","source":"identify-and-decide-improvement-actions","target":"track-improvement-actions-to-closure","whenValue":"action_required"},{"id":"e-identify-and-decide-improvement-actions-close-and-archive","label":"Monitor only","source":"identify-and-decide-improvement-actions","target":"close-and-archive","whenValue":"monitor_only"},{"id":"e-track-improvement-actions-to-closure-close-and-archive","source":"track-improvement-actions-to-closure","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-RISK-05","UC-GOV-21","UC-RISK-13","UC-RISK-15"],"department":"risk-management","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-communication-reporting-performance-review","contentDigest":"sha256:a9b7771d4a349b09631c9de418215f6f44afa4c44bd3c01f6e11d5431aa862d8","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:a9b7771d4a349b09631c9de418215f6f44afa4c44bd3c01f6e11d5431aa862d8","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-risk-communication-reporting-performance-review"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-risk-communication-reporting-performance-review","source":"coworkcanvas-gallery","standards":["iso-31000","coso-erm","soc2","nist-csf-2"],"teams":["risk-management"]},"name":"Risk Communication, Reporting & Performance Review","nodes":[{"data":{"description":"Risk owner with consultation lead: Approve an inclusive stakeholder-to-risk-process plan with cultural accommodations, then retain actual two-way consultation, dissent and updated risk evidence under that plan.","instructions":"**Objective** — Approve the inclusive consultation plan and carry out its scheduled two-way engagement, retaining dissent, unmet-contact follow-ups and resulting risk updates.\n\n**Inputs**\n- The cycle trigger and reporting period for this run — the scheduled quarterly cadence, or an out-of-cycle significant matter. The workflow instance's start IS the trigger; record the period and trigger in this step's notes. This workflow has no upstream feeder workflow.\n- The stakeholder / consultation register. The suppliers and other third parties in scope ARE the Vendor items (category, tier, data_classification, business_owner, risk_owner, reassessment_cadence, monitoring_status) — query them for the third-party parties to consult. The internal-stakeholder mapping (internal functions by organizational level, with each party's prior engagement history) has no single native item type, so that portion is a document carried forward from the prior cycle's close-and-archive step.\n- The current risk register — the Risk items (category, likelihood, impact, residual_rating, treatment, risk_owner) — and the risk-process steps in scope this cycle (identification, assessment, response, monitoring).\n- The risk-owner-approved consultation plan and session schedule from the approved consultation planning stage.\n- The current risk register content to be discussed at each session.\n- The records template pre-populated during planning.\n\n**Procedure**\n*Autonomous preparation incorporates Conduct consultation and retain records; Risk owner with consultation lead reviews the combined evidence.*\n1. For each in-scope risk-process step, list the stakeholders whose input is genuinely required at that step — e.g. process owners and second-line risk for assessment, suppliers and third parties for outsourced or shared risks, control owners for response and monitoring. Do not carry forward last cycle's list unchanged; add parties newly in scope and drop any no longer relevant.\n2. Identify the human and cultural factors that change how consultation should run for each group — language, geography, time zone, organizational culture, and prior engagement friction — and note the accommodation for each (e.g. translated materials, local facilitator, asynchronous input for a distant partner).\n3. Draft the consultation plan: for every stakeholder group specify the channel (workshop, interview, survey, structured questionnaire), format, timing within the cycle, and the specific supplier and third-party risk input to be solicited (concentration, sub-processor, resilience, and contractual-control questions).\n4. Schedule the sessions against the reporting-period deadline and pre-populate the records template that will later capture minutes, attendance, and distribution logs.\n5. Conduct or document each scheduled session at its designated risk-process step, capturing stakeholder input on risk identification, assessment, response, and monitoring — and explicitly the supplier and third-party risk input (concentration, resilience, sub-processor, and shared-control concerns).\n6. Record meeting minutes, attendance, and the substance of the two-way communication for each group; note any dissent, unresolved concern, or new/changed risk raised so it can flow to the risk register and to the improvement-action review later in the cycle.\n7. Compile the risk-communication distribution log evidencing which stakeholders received which risk information and when, so the consultation is demonstrable to an assessor.\n8. Reconcile against the plan: confirm every planned group was engaged; for any group not reached, record why and the remediation (reschedule or documented waiver).\n\n**Record in AssureSwarm**\n- Attach the consultation plan — the stakeholder-to-step mapping and session schedule — as an XLSX document on this step; there is no native consultation-plan item type, so the plan and the internal-stakeholder mapping live as step documents (document upload).\n- Query the Risk items the plan draws on (category, likelihood, impact, residual_rating, risk_owner) and the Vendor items for the suppliers and third parties to consult (tier, data_classification, business_owner, risk_owner, reassessment_cadence); carry the internal-stakeholder mapping forward from the prior cycle's close-and-archive step (query data).\n- Attach the consultation records, minutes, and distribution log as documents on this step — this cycle's consultation evidence set (document upload).\n- For any new or changed risk raised in consultation, create or update the Risk item (description, category, likelihood, impact, residual_rating, risk_owner) so the risk register reflects it, and link that Risk item to this step's records (item create/update, items link). The consultation plan and stakeholder register have no native item type — they stay as the step documents from the approved planning stage.\n\n**Exit criteria**\nApprove an inclusive stakeholder-to-risk-process plan with cultural accommodations, then retain actual two-way consultation, dissent and updated risk evidence under that plan.\nThe risk owner has confirmed the plan is inclusive of all required internal and external stakeholders (including suppliers and third parties), that human and cultural factors are addressed for each group, and has approved the plan; sessions are scheduled and the records template is ready.\nThe consultation lead confirms every planned stakeholder group — internal and external, including suppliers and third parties — was engaged (or a gap is documented and remediated), human and cultural factors were respected, and the records, minutes, and distribution log are complete and retained as evidence.","label":"Plan stakeholder consultation","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-items-link","coach-item-create"]}},"id":"plan-stakeholder-consultation"},{"data":{"decisionField":"reporting_trigger_type","description":"Agent compiles the tiered internal and external risk, control, and performance reporting editions and screens the period's events against the significant-matter criteria; human reporting owner reviews the editions for accuracy and decides whether an event-driven report must be issued alongside the cadenced package.","formData":{"fields":[{"key":"reporting_trigger_type","label":"Event-driven reporting routing","options":[{"label":"Significant matter requires event-driven report","value":"significant_matter"},{"label":"Routine cadence only","value":"routine_cycle"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Compile the cadenced internal and external reporting editions for the period and decide, owned by the reporting owner, whether a significant matter must also be reported outside the regular cadence via an event-driven report, or whether the cadenced package alone is sufficient.\n\n**Inputs**\n- Current risk, control, and performance data pulled through the organization's information systems: the risk register, control-testing results, and KRI/KPI performance sources. This step starts from these inputs and does not wait on the consultation stream.\n- The prior cycle's package as a template for structure and continuity, and the distribution list of internal levels and external parties.\n- The period's control-failure and exception Issue items and any incident log for the significant-matter screen.\n\n**Procedure**\n_Items 1–4 are agent-run (folded from the former \"Compile cadenced reporting package\" step); the human moment is the routing decision in item 5._\n1. Pull the current risk register status, control-testing / effectiveness results, and performance (KRI/KPI) data; reconcile figures to their source system so the package ties out, and flag any data as of a stale date.\n2. Compile the internal package in tiers matched to audience: a management-body / board summary (risk posture, tolerance breaches, culture and performance signals, key control-effectiveness conclusions), a management-detail tier, and a first-line operating-detail tier covering control responsibilities.\n3. Compile the external edition for business partners and external stakeholders, applying the appropriate confidentiality, redaction, and disclosure treatment so nothing non-public or contractually restricted leaks.\n4. Attach the data-source references to both editions so the reporting owner can trace any figure, and screen the period's risk events, incidents, and control failures against the significant-matter criteria.\n5. Review both editions for accuracy and completeness against the underlying data, then select the routing below.\n\n**Decision criteria**\n- Select **Significant matter requires event-driven report** (`significant_matter`) when a risk event, incident, or control failure this period meets the organization's significant-matter criteria — severity above the reporting threshold, a risk-tolerance breach, a regulatory or contractual notification trigger, or a matter of management-body interest — such that waiting for the next cadenced package would be too slow.\n- Select **Routine cadence only** (`routine_cycle`) when no matter this period meets those criteria and the cadenced package compiled above fully covers what stakeholders need to know now.\n- Base the decision on a screen of the period's control-failure and exception Issue items (issue_type: exception | deficiency, identified_date in the period) plus any incident log attached as a document on this step (incidents beyond control-failure Issues have no native item type), read against the compiled cadenced package, so you can see what the routine package already covers versus what needs urgent, out-of-cadence escalation.\n\n**Record in AssureSwarm**\n- Query the source items the package ties out to: the Risk items (residual_rating, treatment, risk_owner) for risk posture, the Control items and the SOX testing workflows hosted directly on those Controls (using the workflow Test-step conclusion) for control-effectiveness results; upload the KRI/KPI and business-performance extract pulled from the information systems as a document on this step (there is no native Metric/KPI item type) (query data, document upload).\n- Render the tiered internal edition and the external edition as DOCX/PDF documents on this step — these reporting-package editions are step documents (there is no native Report item type) (render package, document upload).\n- Submit the `reporting_trigger_type` SELECT field. In the step result note, cite the specific Issue items and incident-log entries screened and the criteria each did or did not meet with evidence references (query data, document link), and name the decision owner in the step's approver record.\n\n**Exit criteria** — Both editions are attached, accurate against the underlying data, and complete for their intended audiences; the form is submitted with a documented rationale and evidence references, the decision owner is named, and the unselected branch is prunable.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the tiered internal and external reporting editions from the risk, control, and performance data into a review-ready package.","kind":"decision","label":"Assess event-driven reporting need","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-render-package"]}},"id":"assess-event-driven-reporting-need"},{"data":{"description":"Agent drafts and distributes the event-driven report on the significant matter to accountable management, the board, and affected external stakeholders ahead of the regular cadence; human executive sponsor confirms timely, accurate issuance.","instructions":"**Objective** — Draft and distribute a timely, accurate event-driven report on the significant matter to the recipients who must be notified ahead of the regular cadence.\n\n**Inputs**\n- The significant-matter routing decision and the matter summary produced in the assess-event-driven-reporting-need step (the `significant_matter` branch).\n- The affected risk-register entry and any regulatory or partner notification obligations attached to it.\n\n**Procedure**\n1. Draft the event-driven report detailing the significant matter, its risk and control implications, the recommended management response, and the required decisions or acknowledgements — reusing the summary prepared during screening.\n2. Identify who must receive it outside the regular cadence: accountable management, the management body/board, and affected external stakeholders, including any regulator or business partner with a contractual or legal notification deadline. Record each deadline.\n3. Distribute the report through the appropriate channel and log the distribution with recipient, channel, and timestamp so timeliness against each deadline is evidenced.\n4. Link the event-driven report to the significant matter's record in the risk register for traceability, and flag the matter for the performance-review and improvement-action review later in the cycle.\n\n**Record in AssureSwarm**\n- Attach the event-driven report (PDF) and its timestamped distribution log (CSV) as documents on this step (document upload).\n- Link this step's report to the affected significant matter's Risk item so the event-driven communication is traceable to the risk register (items link); issue the notification to recipients (notify).\n\n**Exit criteria** — The executive sponsor confirms the report was issued to the correct recipients, within every applicable deadline, with an accurate account of the matter; the distribution is logged and linked.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` distributes the event-driven report to the escalation recipients and captures the timestamped delivery log.","label":"Issue event-driven report","performedBy":{"primitives":["coach-document-upload","coach-items-link","coach-notify"]}},"id":"issue-event-driven-report"},{"data":{"description":"Automatically deliver the previously reviewed audience-specific editions after the selected reporting path, retain required acknowledgements and resolve or record delivery exceptions.","instructions":"**Objective** — Distribute the cadenced internal package to every organizational level and the external edition to business partners and external stakeholders, with delivery logged so the reporting cadence is evidenced.\n\n**Inputs**\n- The accuracy-reviewed internal and external package editions compiled on the assess-event-driven-reporting-need step.\n- The event-driven-reporting routing outcome from that same decision; on the significant-matter path, confirmation that the event-driven report was already issued so the cadenced delivery does not contradict or duplicate it.\n- The distribution list of internal recipients (board, management, first line) and external stakeholders / business partners, drawn from the stakeholder register.\n\n**Procedure**\n1. Distribute the internal package to the board, management, and first-line recipients on the distribution list, and the external edition to business partners and external stakeholders, through the defined channels and cadence.\n2. Log each delivery — recipient, channel, and timestamp — in the information system of record so the reporting cadence is evidenced end to end.\n3. Confirm receipt or acknowledgement where required; flag any recipient who did not receive their package and resolve the gap (resend or documented exception).\n4. File the delivered editions and the delivery log to the evidence register for this cycle.\n\n**Record in AssureSwarm**\n- Attach the delivered internal and external editions and the delivery-log CSV (recipient, channel, timestamp, acknowledgements) as documents on this step (document upload, item export).\n- Issue the package to each recipient tier and capture acknowledgements (notify).\n\n**Exit criteria** — Delivery records show every internal level and every external stakeholder/partner on the distribution list received the previously approved appropriate edition, delivery is logged, and any delivery gap is resolved.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` fans the cadenced package out to each recipient tier and records the delivery log and acknowledgements.","label":"Deliver reporting package","performedBy":{"primitives":["coach-document-upload","coach-export-package","coach-notify"]},"requiredApprovals":0},"id":"deliver-reporting-package"},{"data":{"description":"Agent compiles the periodic evaluation of risk-management and internal-control performance against the framework's design and intended outcomes, pairing it with business performance for the same period; human accountable management reviews and signs off.","instructions":"**Objective** — Produce accountable management's periodic evaluation of risk-management and internal-control performance against the framework's design and intended outcomes, reviewed together with business performance for the same period.\n\n**Inputs**\n- The framework's design intent and intended outcomes (the evaluation baseline) — the risk-management framework's Policy item (policy_type: charter, framework: iso-31000 / coso-erm), whose review_frequency and next_review_date carry the evaluation schedule — plus evidence that ongoing and separate evaluations ran as planned.\n- Control-testing results, risk-tolerance breach history, and audit/assurance findings for the period. This step starts from these inputs; it does not wait on the reporting-delivery stream.\n- Business-performance results for the same period, so risk and control performance are reviewed against business outcomes, not in isolation.\n\n**Procedure**\n1. Compile the ongoing- and separate-evaluation evidence and confirm evaluations ran on schedule; measure the framework's effectiveness against its design and intended outcomes, noting where an intended outcome was not achieved.\n2. Pull the business-performance results for the same period and pair them against risk and control performance so trade-offs (e.g. a performance gain that raised residual risk) are visible.\n3. Draft the review pack summarizing framework effectiveness, risk-adjusted business performance, tolerance breaches, and any deviations from intended outcomes, with root-cause notes for accountable management.\n4. Schedule the review session with accountable management and prepare the review-minutes template.\n\n**Record in AssureSwarm**\n- Query the control-testing evidence — the SOX testing workflows hosted directly on their Control items (using the workflow Test-step conclusion) — and the affected Risk items (residual_rating, treatment); read the risk-management framework as its Policy item (policy_type: charter, framework: iso-31000 / coso-erm, policy_owner, with review_frequency and next_review_date carrying the evaluation schedule) as the design-intent evaluation baseline. The tolerance-breach history and business-performance extract have no native item type and are attached as documents on this step (query data, document upload).\n- Scan the workflow/control estate for evaluation completeness and attach the management-signed performance-review pack (PDF) and the review minutes as documents on this step (workflow scan, document upload).\n\n**Exit criteria** — Accountable management reviews the pack, confirms risk-management and internal-control performance was genuinely assessed against the framework's design and intended outcomes with business performance considered together, and signs off; the evaluation schedule, results, and review minutes are retained as evidence.","label":"Review risk and control performance","performedBy":{"primitives":["coach-query-data","coach-workflow-scan","coach-document-upload"]}},"id":"review-risk-and-control-performance"},{"data":{"decisionField":"improvement_action_decision","description":"Agent extracts candidate lessons from the performance review, evaluations, and consultation feedback, and drafts proposed improvement actions; human accountable owner decides whether a tracked improvement action is warranted.","formData":{"fields":[{"key":"improvement_action_decision","label":"Improvement action decision","options":[{"label":"Improvement action(s) required","value":"action_required"},{"label":"Monitor only - no tracked action this cycle","value":"monitor_only"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Decide, owned by the accountable improvement owner, whether this cycle's lessons must become owned, tracked improvement actions, or whether no lesson rises to a tracked action this cycle.\n\n**Decision criteria**\n- Select **Improvement action(s) required** (`action_required`) when one or more candidate lessons point to a genuine framework or process gap — a repeated tolerance breach, an evaluation finding of design or operating weakness, a stakeholder-consultation concern about how risk is managed or communicated, or an intended outcome not achieved — that needs an owned, dated corrective action.\n- Select **Monitor only** (`monitor_only`) when the candidate lessons are observations worth noting but none reflects a gap warranting a tracked action this cycle (e.g. a one-off explained by a known transient cause).\n- Draw the candidate lessons from two upstream sources that both feed this decision: the accountable-management performance-review pack (its evaluation findings and deviations, plus any finding already logged as an Issue item) and the stakeholder-consultation records (feedback, dissent, and newly raised concerns). Weigh recurrence, severity, and whether the framework's design is implicated.\n\n**Record in AssureSwarm** — Submit the `improvement_action_decision` SELECT field. In the step result note, list the candidate lessons considered, cite the performance-review finding, source Issue item, or consultation-record document behind each, state the routing chosen, and name the decision owner in the step's approver record (query data).\n\n**Exit criteria** — The form is submitted with the candidate lessons and rationale recorded, the decision owner is named, and the unselected branch is prunable.","kind":"decision","label":"Identify and decide improvement actions","performedBy":{"primitives":["coach-query-data","coach-item-create"]}},"id":"identify-and-decide-improvement-actions"},{"data":{"description":"Agent creates the owned, tracked improvement actions from the approved lessons, links them to their source evidence and target dates, and updates the improvement-action dashboard; human improvement owner confirms actions are progressing to closure.","instructions":"**Objective** — Turn the approved lessons into owned, tracked improvement actions linked to their source evidence, and keep the backlog reflecting real progress toward closure.\n\n**Inputs**\n- The `action_required` decision and the candidate lessons approved in the identify-and-decide-improvement-actions step.\n- The source evidence behind each lesson: the performance-review finding, evaluation result, or consultation feedback that prompted it.\n- The open improvement-action backlog carried from prior cycles — the open Issue items created by prior runs (source: self_assessment, issue_owner, target_remediation_date).\n\n**Procedure**\n1. Create an improvement-action record for each approved lesson, naming the accountable owner, the target closure date, and the specific framework or process element it will change; write a verifiable done-definition, not a vague intent.\n2. Link each action to its source evidence so the reason it exists is traceable to the review finding, evaluation result, or consultation feedback.\n3. Add or update the improvement-action backlog dashboard so status — open, in progress, closed — and ageing are visible across the program.\n4. Follow up on actions opened in prior cycles that remain open: record current status, re-baseline any slipped target date with a reason, and escalate actions overdue past tolerance.\n\n**Record in AssureSwarm**\n- Create one Issue item per approved lesson as the tracked improvement action — issue_type: opportunity | observation, source: self_assessment (distinguishing it from an audit finding), issue_owner (accountable owner), target_remediation_date (target closure date), remediation_plan (the verifiable done-definition) (item create).\n- Link each improvement-action Issue to the Risk or Control it improves and to its source evidence — the performance-review finding, evaluation result, or consultation record — so the reason it exists is traceable (items link).\n- Build or refresh the improvement-action backlog dashboard over the open and closed Issue items (source: self_assessment) so status and ageing are visible; for carryover actions that closed this cycle, set Issue.actual_remediation_date (dashboard create, item update).\n\n**Exit criteria** — The improvement owner confirms every action has a named owner, target date, and correct source-evidence linkage, and that the backlog realistically reflects progress toward closure, including carryover actions from prior cycles.","label":"Track improvement actions to closure","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-item-update","coach-dashboard-create"]}},"id":"track-improvement-actions-to-closure"},{"data":{"description":"Automatically retain the complete consultation, reporting and management/improvement record, refresh registers and communicate the authorized cycle outcome.","instructions":"**Objective** — Assemble and archive a self-contained, durable evidence record for the cycle and formally close it, leaving the registers current for the next cycle.\n\n**Inputs**\n- The consultation records, minutes, and distribution log from the consultation stream.\n- The internal and external reporting editions and delivery log, plus any event-driven report, from the reporting stream.\n- The performance-review pack and evaluation evidence, and the improvement-action backlog with its decision record (whether actions were tracked or the cycle was monitor-only), from the performance stream.\n\n**Procedure**\n1. Assemble the complete evidence record for the cycle: consultation records and minutes; the internal and external reporting editions and delivery logs; any event-driven report; the performance-review pack and evaluation evidence; and the improvement-action backlog with its decision record.\n2. Archive the record to the retention location tagged with the cycle date, reporting period, and applicable retention period, and link it to the governance register.\n3. Update the stakeholder register, risk register, and improvement backlog so the next cycle starts from current state (new/changed risks from consultation, carried-over improvement actions, refreshed stakeholder contacts).\n4. Communicate the cycle's close, the next quarterly reporting date, and any carried-over improvement actions to accountable management.\n\n**Record in AssureSwarm**\n- Export the assembled cycle evidence from this workflow instance to the retention location — the instance itself is the durable cycle record, with the assembled evidence attached as a document on this step (workflow export).\n- Leave the registers current for the next cycle: field-update the Risk items for new/changed risks from consultation (residual_rating, risk_owner) and the improvement-action Issue items for backlog status; refresh the stakeholder register document (no native type) and attach it here; and link the archived record to the governance register (item update, document link).\n\n**Exit criteria** — Verify that the archived record is self-contained and durable enough to serve as evidence to auditors and regulators without oral explanation — consultation, reporting, performance review, and improvement actions — and the cycle closes automatically under the prior review decisions with the registers updated.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-document-upload","coach-item-update"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:grc-risk-communication-reporting-performance-review"}
