{"description":"Runs on the existing risk item. Run a periodic enterprise risk identification cycle, consolidate candidate risks, and approve the resulting register changes. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[],"isPublic":true,"itemTypeSlug":"risk","metadata":{"capabilities":["erm-risk-identification-register-refresh"],"controlVerbs":{"UC-RISK-07":"operates","UC-RISK-10":"operates"},"controls":["UC-RISK-07","UC-RISK-10"],"department":"risk-management","domains":["grc"],"kind":"erm-risk-identification-register-refresh","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:erm-risk-identification-register-refresh"}],"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-register-refresh","contentDigest":"sha256:7833e463a292cf29cc68a8f0103621a5c7a32a0716bc1f98312c1724e186475d","prerequisites":{"anchorItemType":{"slug":"risk"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-enterprise-risk-register-lifecycle"}],"roles":[{"contribution":"approval","description":"Risk register owner. Approve register refresh record.","id":"reviewer-1","nodeIds":["erm-refresh-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:erm-risk-identification-register-refresh"}],"releaseId":"sha256:7833e463a292cf29cc68a8f0103621a5c7a32a0716bc1f98312c1724e186475d","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-risk-register-refresh"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-risk-register-refresh","source":"coworkcanvas-gallery","standards":[],"teams":["risk-management"]},"name":"ERM Risk Identification & Register Refresh","nodes":[{"data":{"controls":["UC-RISK-07","UC-RISK-10"],"instructions":"**Objective**\nApprove register refresh record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the enterprise risk taxonomy, prior cycle output, strategy and objective statements, organizational structure, incidents, issues, audit results, control failures, external environment reports, and the approved risk criteria.\n2. Use workshop output, interview notes, incident and loss data, audit and assurance findings, control testing results, external threat and regulatory intelligence, strategic initiatives, and the current register.\n3. Use the consolidated candidate set, the taxonomy and domain vocabulary, organizational accountability maps, existing register entries and their owners, and the qualification criteria from the scoping stage.\n4. Review all stage records, the candidate inventory and its source attribution, duplicate dispositions, taxonomy placements, ownership nominations, watchlist referrals, and open coverage gaps.\n\n**Procedure**\n1. Fix the cycle boundaries, confirm which units and domains participate, reconcile the taxonomy version against the register, identify data sources and workshop participants, and document coverage exclusions with rationale.\n2. Normalize each candidate into a cause-event-impact statement, compare it against existing register entries, merge genuine duplicates, keep materially distinct exposures separate, and record why each merge or split was chosen.\n3. Assign category and subcategory, map affected domains, nominate an accountable owner with the authority to act, choose the register action, and route contested ownership or classification to the accountable role before advancing.\n4. Trace material additions and merges to their evidence, confirm every new entry has an accountable owner and a next assessment date, verify excluded scope remains visible, and return incomplete classification with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the cycle period, identification scope, taxonomy version, participating units, data sources, qualification criteria, exclusions, accountable facilitator, and known coverage gaps.\n2. Document the candidate inventory, source attribution for each candidate, duplicate disposition, merge and split rationale, withdrawn candidates, and candidates deferred to the watchlist.\n3. Record the taxonomy placement, register action, nominated owner, affected domains, prior entry references for merges and updates, contested classifications, and items routed to the watchlist.\n4. Capture the authorized reviewer, the refresh summary, accepted register actions, effective cycle date, next cycle cadence, watchlist referrals, open coverage gaps, owners, and due dates.\n\n**Exit criteria**\nRisk register owner provides approval: The cycle scope is explicit, the taxonomy and qualification criteria are agreed, and exclusions that could hide exposure are visible and assigned. Every candidate is traceable to a source, duplicates are resolved with stated reasoning, and the surviving set is ready for taxonomy placement. An approver accepts that each classification and ownership assignment follows from the consolidation evidence, and unresolved ownership is escalated rather than defaulted. The authorized reviewer accepts the refresh as a traceable record of identification work, the register can be updated consistently, and no assurance over completeness of risk identification is implied by closure.","kind":"task","label":"Approve register refresh record","requiredApprovals":1},"id":"erm-refresh-closure"}],"sourceTemplateId":"workflow-library:grc-risk-register-refresh"}
