{"description":"Runs on the existing system item. Evaluate a service-organization report, subservice coverage, exceptions, and complementary user-entity controls for a governed reliance decision. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-soc-report-evaluation-soc-review-closure","source":"soc-report-evaluation","target":"soc-review-closure"}],"isPublic":true,"itemTypeSlug":"system","metadata":{"capabilities":["system-soc-report-cuec-review"],"controlVerbs":{"UC-ACCESS-21":"operates"},"controls":["UC-ACCESS-21"],"department":"risk-management","domains":["grc"],"kind":"system-soc-report-cuec-review","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:system-soc-report-cuec-review"}],"canonicalUrl":"https://workflow-library.com/all/?w=grc-system-soc-cuec-review","contentDigest":"sha256:df3671c86f949c17c967daba333b4b646ed00fc63fc113d19f8a950279dbbfe6","prerequisites":{"anchorItemType":{"slug":"system"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-vendor-soc-cuec-review"}],"roles":[{"contribution":"expertise","description":"System owner and technical specialist. Evaluate opinion, controls, and exceptions.","id":"reviewer-1","nodeIds":["soc-report-evaluation"]},{"contribution":"approval","description":"Independent system-risk reviewer. Approve SOC review record.","id":"reviewer-2","nodeIds":["soc-review-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:system-soc-report-cuec-review"}],"releaseId":"sha256:df3671c86f949c17c967daba333b4b646ed00fc63fc113d19f8a950279dbbfe6","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-system-soc-cuec-review"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-system-soc-cuec-review","source":"coworkcanvas-gallery","standards":[],"teams":["risk-management"]},"name":"SOC Report, Subservice & CUEC Review","nodes":[{"data":{"instructions":"**Objective**\nEvaluate opinion, controls, and exceptions. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, current SOC report and bridge letter, contract and service description, architecture and data flows, relevant processes and controls, user population, prior review, and reporting period.\n2. Use the scoped report, independent auditor opinion, system description, control matrix, test procedures and results, exceptions, management responses, subsequent-event disclosure, bridge letter, and customer risk-control mapping.\n\n**Procedure**\n1. Verify report authenticity and period, compare covered services and locations to actual use, identify scope exclusions and boundary differences, determine bridge-period needs, map business dependencies, and flag stale or missing reports.\n2. Read the opinion and basis, map relevant controls to dependencies, analyze exception populations and impact, evaluate testing periods and methods, assess subsequent changes, challenge unsupported remediation claims, and identify reliance limitations.\n\n**Record in AssureSwarm**\n1. Capture report type, auditor, opinion date and period, criteria, services, locations, actual-use alignment, boundary differences, bridge coverage, excluded components, reliance purpose, and information gaps. Also record scope alignment.\n2. Document the opinion result, relevant controls and criteria, exceptions and affected populations, management responses, period limitations, subsequent events, mapping references, reliance implications, and follow-up requests. Also record report evaluation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The report is identified and aligned to actual service use, scope and period gaps are explicit, and the evidence package is sufficient for detailed evaluation. The opinion and testing results are evaluated against actual reliance needs, material exceptions and limitations remain visible, and subservice and CUEC analysis can proceed.","kind":"task","label":"Evaluate opinion, controls, and exceptions","requiredApprovals":1},"id":"soc-report-evaluation"},{"data":{"controls":["UC-ACCESS-21"],"instructions":"**Objective**\nApprove SOC review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the report evaluation, subservice disclosures, carve-out or inclusive method, complementary subservice controls, CUEC list, customer policies and controls, test results, contracts, architecture, and open exceptions.\n2. Review all stage records, report and bridge evidence, mappings, exception analysis, subservice and CUEC conclusions, customer control support, linked issues, and monitoring commitments.\n\n**Procedure**\n1. Map each relevant CUEC to an owned control and evidence, assess operating support, trace subservice dependencies, evaluate uncovered responsibilities, determine compensating measures, define reliance limits, and create linked issues for material gaps.\n2. Trace each reliance conclusion to report and customer evidence, verify gaps and exceptions are routed, reconcile owners and dates, confirm report-period limitations remain visible, and return unsupported analysis for correction.\n\n**Record in AssureSwarm**\n1. Record CUEC status and mappings, control owners and evidence, subservice method and dependencies, gaps, compensating controls, reliance response, linked issues, monitoring requirements, owners, and due dates.\n2. Capture the authorized reviewer, review summary, report period and opinion, reliance response, material exceptions, CUEC and subservice status, linked issues, monitoring dates, owners, and evidence references.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts the documented responsibility and reliance response, all relevant CUECs and subservices are addressed, and unsupported coverage remains an explicit gap. The authorized reviewer accepts the SOC review as a traceable analysis record, related system and control records can be updated consistently, and closure does not establish assurance.","kind":"task","label":"Approve SOC review record","requiredApprovals":1},"id":"soc-review-closure"}],"sourceTemplateId":"workflow-library:grc-system-soc-cuec-review"}
