{"description":"Technology Investment & Project Risk Governance as a decision-aware checkpoint graph, run as a recurring workflow instance attached to the existing Process item for the technology-investment / portfolio-governance process (process_type: business_process) — each quarterly board cycle enriches that standing process record rather than creating a new one. In the cycle the investment board refreshes its criteria, scores and prioritizes the technology and innovation portfolio, routes the annual capital-planning leg that allocates security funding to the risk strategy, monitors in-flight value and reprioritizes or terminates where value is not realized, and enforces security-risk sections in every project gate with ERM-linked artifacts. In scope: the quarterly technology investment-board review (always), the annual capital-planning and security-budget leg (when the funding and staffing envelope must be set or re-planned this cycle), and every project stage gate falling due. Out of scope: individual project execution and delivery mechanics and day-to-day security operations. The cycle consumes the ERM cyber-risk register (Risk items, category: cyber_security) and the approved program business cases as standing inputs, and produces a board decision record and evidence pack as its named deliverable. There is no downstream workflow hand-off, so cross-references are recorded as linked records (Issue ↔ Risk) rather than routed onward; the scored portfolio, in-flight programs, and stage-gated projects have no native item type and live as step documents.","edges":[{"id":"e-refresh-investment-and-security-criteria-decide-portfolio-disposition","source":"refresh-investment-and-security-criteria","target":"decide-portfolio-disposition"},{"id":"e-decide-portfolio-disposition-compile-board-decision-record-and-evidence","source":"decide-portfolio-disposition","target":"compile-board-decision-record-and-evidence"},{"id":"e-set-capital-planning-scope-allocate-and-verify-security-funding","label":"Annual leg","source":"set-capital-planning-scope","target":"allocate-and-verify-security-funding","whenValue":"annual_leg_in_scope"},{"id":"e-set-capital-planning-scope-compile-board-decision-record-and-evidence","label":"Quarterly only","source":"set-capital-planning-scope","target":"compile-board-decision-record-and-evidence","whenValue":"quarterly_only"},{"id":"e-allocate-and-verify-security-funding-compile-board-decision-record-and-evidence","source":"allocate-and-verify-security-funding","target":"compile-board-decision-record-and-evidence"},{"id":"e-decide-portfolio-disposition-compile-board-decision-record-and-evidence","label":"Continue","source":"decide-portfolio-disposition","target":"compile-board-decision-record-and-evidence","whenValue":"continue_as_planned"},{"id":"e-decide-portfolio-disposition-apply-corrective-actions","label":"Corrective action","source":"decide-portfolio-disposition","target":"apply-corrective-actions","whenValue":"corrective_action_required"},{"id":"e-apply-corrective-actions-compile-board-decision-record-and-evidence","source":"apply-corrective-actions","target":"compile-board-decision-record-and-evidence"},{"id":"e-run-project-gate-reviews-compile-board-decision-record-and-evidence","source":"run-project-gate-reviews","target":"compile-board-decision-record-and-evidence"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-GOV-13","UC-GOV-11","UC-RISK-02"],"department":"executive","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-technology-investment-project-risk-governance","contentDigest":"sha256:bce9657225cd01598d10e901416f1aedcc06fe22a5b2aa418dc3d393cc8c3dfd","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:bce9657225cd01598d10e901416f1aedcc06fe22a5b2aa418dc3d393cc8c3dfd","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-technology-investment-project-risk-governance"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-technology-investment-project-risk-governance","source":"coworkcanvas-gallery","standards":["cobit-2019","nist-csf-2","iso-31000","nist-800-53"],"teams":["executive","it"]},"name":"Technology Investment & Project Risk Governance","nodes":[{"data":{"description":"Agent refreshes the defined investment criteria and the security and privacy requirements every investment must address; human EPMO and CISO confirm the criteria are current and gating","instructions":"**Objective** — Produce a ratified investment-criteria pack whose benefit, cost, and risk factors reflect current strategy and risk appetite, with security and privacy embedded as mandatory, gating evaluation dimensions.\n\n**Inputs**\n- The standing Process item for the technology-investment / portfolio-governance process (process_type: business_process) this cycle attaches to and enriches.\n- The defined technology-investment criteria in force: benefit / cost / risk factors, scoring weights, hurdle thresholds, and the separate lane and risk tolerance for innovation and emerging-technology bets — held as the standing investment-criteria Policy item (policy_type: standard, policy_owner: EPMO / CISO, framework: cobit-2019, review_frequency: quarterly) with its ratified criteria document attached; this cycle enriches that Policy rather than starting a fresh copy.\n- The current enterprise strategy and the board-approved risk appetite statement — uploaded here as PBC / external documents; authoritative copies live outside AssureSwarm.\n- The ERM cyber-risk register (Risk items, category: cyber_security) and current control posture (Control items — control_owner, frequency, framework) that feed the risk-scoring inputs.\n- Any criteria change requests raised since the last cycle — assembled with the prior criteria pack as the standing criteria baseline at cycle start.\n\n**Procedure**\n1. Retrieve the criteria in force with coach-query-data and diff them against the current strategy and risk appetite; list every factor, weight, and threshold that has moved or gone stale since the last cycle.\n2. Refresh weights and thresholds where strategy or appetite has shifted; where nothing moved, record an explicit \"no change\" with the reviewer's initials so the ratification is affirmative rather than silent.\n3. Make security and privacy a mandatory scored dimension, not a tie-breaker: give it a defined weight and a hard floor below which an initiative is flagged regardless of benefit, so nothing can clear the hurdle while ignoring its security and privacy obligations.\n4. Confirm the cyber-risk scoring inputs the criteria draw on — the ERM register entries and current threat / control posture — are current, so risk is weighed on the same footing as benefit and cost.\n5. Keep the innovation and emerging-technology lane's separate risk tolerance explicit so early bets are judged on their own risk-and-return basis rather than the business-as-usual hurdle.\n6. Compile the refreshed factors, weights, thresholds, and the security / privacy gating floor into a single criteria pack for board ratification.\n\n**Record in AssureSwarm**\n- Enrich the standing investment-criteria Policy item (policy_type: standard, policy_owner, approved_by, version, framework: cobit-2019, review_frequency: quarterly, effective_date, next_review_date) with coach-item-update — bumping version and next_review_date on ratification; create it with coach-item-create on the first cycle if it does not yet exist.\n- Attach the ratified criteria pack document — factors, weights, thresholds, and the mandatory security / privacy gating floor — to that Policy item as the governed PDF/DOCX with coach-document-upload.\n- Query and cite the source criteria Policy, strategy, and ERM Risk / Control inputs used with coach-query-data.\n\n**Exit criteria** — EPMO and CISO have confirmed the criteria are current, the weightings reflect the approved strategy and risk appetite, and security and privacy are embedded as mandatory gating criteria with a defined floor; the criteria pack is attached to the investment-criteria Policy item and ready to score against.","label":"Refresh investment and security criteria","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-item-update","coach-document-upload"]}},"id":"refresh-investment-and-security-criteria"},{"data":{"decisionField":"capital_planning_scope","description":"Agent determines whether the annual capital-planning and security-budget leg runs this cycle and drafts the routing rationale; human decides the routing","formData":{"fields":[{"key":"capital_planning_scope","label":"Capital-planning scope for this cycle","options":[{"label":"Annual capital-planning and security-budget leg in scope","value":"annual_leg_in_scope"},{"label":"Quarterly portfolio review only","value":"quarterly_only"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Decide whether the annual capital-planning and security-budget leg runs this cycle, or the cycle is a quarterly portfolio review inside an already-approved budget. Owned by the investment board (CIO as chair, finance, and the CISO).\n\n**Decision criteria**\n- Select **Annual capital-planning and security-budget leg in scope** (`annual_leg_in_scope`) when this cycle coincides with the annual capital-planning calendar that sets the security funding and staffing envelope, OR when an off-calendar trigger forces a re-plan: a material risk-strategy change, a security funding shortfall surfaced in monitoring, or new security or privacy obligations that change the budget.\n- Select **Quarterly portfolio review only** (`quarterly_only`) when the approved security funding and staffing envelope still holds and no forcing trigger is present — the cycle scores and dispositions the portfolio within the standing budget.\n\n**Record in AssureSwarm**\n- Submit the `capital_planning_scope` SELECT with one of the two values.\n- Record the decision rationale and evidence in the step result — the cycle's position in the planning calendar, the security budget's adequacy and utilization to date, and any forcing trigger with its evidence linked via coach-document-link (gathered with coach-query-data) — and name the owner in the step's approver record.\n\n**Exit criteria** — The SELECT is submitted with a documented rationale and evidence references, and the branch not selected is prunable.","kind":"decision","label":"Set capital-planning scope","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"set-capital-planning-scope"},{"data":{"description":"Agent allocates security funding and personnel to the risk strategy, verifies security and privacy requirements are addressed in budgeting, and reviews prior-period allocation adequacy and utilization; human CISO and finance confirm","instructions":"**Objective** — Produce an approved security-funding memo that allocates funding and personnel to the cyber-risk strategy, verifies security and privacy costs are budgeted, and reviews prior-period allocation adequacy and utilization.\n\n**Inputs**\n- The `annual_leg_in_scope` routing decision and its rationale from \"Set capital-planning scope\".\n- The cybersecurity risk strategy, roles, responsibilities, and policies (uploaded as PBC / external documents); the ERM cyber-risk register (Risk items, category: cyber_security; risk-strategy linkage via risk_owner, treatment).\n- The current security budget, prior-period actuals and utilization, and the funded and candidate initiative set with their security / privacy cost lines — uploaded here; there is no native Budget or Funding item type.\n\n**Procedure**\n1. Allocate and adjust funding, personnel, and other resources commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies, mapping each budget line to the risk or capability it resources with coach-query-data.\n2. Verify security and privacy requirements are explicitly funded across the capital plan, the budgeting, and each investment decision — funded initiatives carry their own security and privacy costs, and cross-cutting security capabilities are funded rather than assumed.\n3. Evaluate the prior period's allocation and utilization for adequacy and optimization: where security funding was under- or over-utilized, where risk grew faster than the budget, and where reallocation is warranted; adjust the budgets as priorities and risks have changed.\n4. Reconcile the allocation against the ERM register so no material risk is left unresourced and no line funds a retired capability.\n5. Compile the allocation, the adequacy-and-utilization review, and the budget adjustments into a funding memo.\n\n**Record in AssureSwarm**\n- Attach the approved security-funding and staffing memo — the allocation, the adequacy-and-utilization review, and the budget adjustments — as a DOCX/PDF document on this step with coach-document-upload; there is no native Budget or Funding item type, so the envelope lives as the funding-memo document.\n- Query and cite the budget, prior-period utilization, risk-strategy, and ERM Risk inputs with coach-query-data.\n\n**Exit criteria** — The CISO and finance confirm the security funding and staffing are commensurate with the risk strategy, security and privacy requirements are addressed across the budgeting and investment decisions, and the allocation adequacy-and-utilization review is complete with approved adjustments.","label":"Allocate and verify security funding","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"allocate-and-verify-security-funding"},{"data":{"decisionField":"portfolio_disposition","description":"Build the portfolio value-realization view for the in-flight programs and decide, owned by the investment board, whether the portfolio continues as planned or corrective action is required because expected value is not being realized.","formData":{"fields":[{"key":"portfolio_disposition","label":"Portfolio disposition decision","options":[{"label":"Continue in-flight programs as planned","value":"continue_as_planned"},{"label":"Corrective action required (reprioritize or terminate)","value":"corrective_action_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nBuild the portfolio value-realization view for the in-flight programs and decide, owned by the investment board, whether the portfolio continues as planned or corrective action is required because expected value is not being realized.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe ratified criteria pack — the investment-criteria Policy item (policy_type: standard) and its attached criteria document — from \"Refresh investment and security criteria\": weights, thresholds, and the security / privacy floor to score against.\n- The full candidate and in-flight initiative set — candidate proposals, in-flight programs, and the innovation and emerging-technology pipeline — uploaded here as the EPMO pipeline extract (CSV/XLSX); there is no native Initiative or Program item type, so the population arrives as a step upload, not items.\n- Per-initiative business cases, total-cost-of-ownership estimates, and security / privacy assessments — uploaded as one pack per initiative; ERM cyber-risk entries (Risk items, category: cyber_security) for delivery and cyber risk.\n\nEach in-flight program's approved business case — expected benefit, cost, schedule, and target risk / security posture — carried as the per-initiative pack uploaded at \"Assemble and score the portfolio\" and re-used here as the program baseline; there is no native Program item type.\n- Current status, actuals, and variance data per program (uploaded here); ERM cyber-risk entries (Risk items, category: cyber_security) for programs carrying security risk.\n\n*Agent retrieval, preparation and filing absorb “Assemble and score the portfolio”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Assemble and score the portfolio: Produce a complete, traceable scored and prioritized portfolio — business-as-usual investments and the innovation pipeline — ranked by benefit, cost, and risk against the ratified criteria.\n\n2. Compile the full population with coach-query-data so nothing competing for funding is left off the board table — reconcile the candidate list against the EPMO pipeline and the prior cycle's carry-forward items; a missing initiative silently defunds it.\n3. Score each initiative against the ratified criteria — expected benefit, total cost of ownership, and risk (cyber and delivery) — and apply the security / privacy floor: an initiative missing a security or privacy assessment scores incomplete, never zero-risk.\n4. Capture each initiative's score and its benefit, cost, and risk inputs as a row in the scoring-and-ranking workbook so the ranking is traceable back to its inputs — there is no native Initiative or Program item type to create one item per initiative.\n5. Rank and prioritize by the criteria; place innovation and emerging-technology bets in their defined lane and rank them within it, so early bets are not crowded out by incremental spend.\n6. Flag for board attention any initiative with a thin business case, a missing security or privacy assessment, or a score below the hurdle threshold.\n\n7. Assessment scope for Decide portfolio disposition: Build the portfolio value-realization view for the in-flight programs and decide, owned by the investment board, whether the portfolio continues as planned or corrective action is required because expected value is not being realized.\n\n8. Pull each in-flight program's current status against its approved business case with coach-query-data: benefit realized to date versus expected, cost and schedule variance, and change in its risk and security posture.\n9. Compute value-realization signals per program — tracking to plan, slipping, or unlikely to be realized — against defined thresholds (for example a benefit shortfall beyond a set percentage, a schedule slip past one gate, or unresolved high cyber risk).\n10. Flag programs breaching cost, schedule, or benefit thresholds or carrying unresolved security risk, and assemble the evidence pack behind each flag so any disposition decision rests on verifiable data.\n11. Build a portfolio value-realization dashboard with coach-dashboard-create showing benefit realization, variance, and risk status across the in-flight portfolio, so the board sees where value is and is not being delivered.\n12. Put the value-realization view to the board, which satisfies itself that the benefit and variance data are reliable and the flagged programs are correctly identified, then selects the disposition below.\n\nSelect **Continue in-flight programs as planned** (`continue_as_planned`) when value realization is acceptable across the portfolio — no program breaches its cost, schedule, or benefit thresholds beyond tolerance and no unresolved high cyber risk demands intervention this cycle.\n- Select **Corrective action required (reprioritize or terminate)** (`corrective_action_required`) when any program must be reprioritized, rebaselined, or terminated because expected value is not being realized — a sustained benefit shortfall, an unrecoverable schedule or cost breach, or unresolved security risk that outweighs the program's value.\n\n**Record in AssureSwarm**\nAttach the scored, prioritized portfolio — business-as-usual investments and the innovation lane, each with its benefit, cost, and risk inputs and rank — as an XLSX scoring-and-ranking workbook on this step with coach-document-upload; there is no native Initiative or Program item type, so the scored population lives as a step document rather than one item per initiative.\n- Query and cite the criteria pack and initiative population used with coach-query-data.\n\nBuild the portfolio value-realization dashboard — benefit realization, variance, and risk status across the in-flight portfolio — with coach-dashboard-create.\n- Attach the underlying evidence pack behind each flag as an XLSX document on this step with coach-document-upload; the in-flight programs have no native item type.\n- Submit the `portfolio_disposition` SELECT with one of the two values.\n- Record in the step result the specific programs, the recommended action per program, and the evidence references — drawn from the business-case and variance data with coach-query-data and the quantified consequence of each option (funding freed by termination and its candidate reallocation, staged in a board decision brief attached with coach-document-upload); name the owner in the step's approver record.\n\n**Exit criteria**\nThe board confirms the initiative population is complete, each score is supported by its benefit, cost, and risk inputs, and the prioritized ranking — including the innovation lane — is ready for funding and disposition decisions. The value-realization view is complete and its benefit and variance data confirmed reliable; the SELECT is submitted with per-program rationale and evidence, and the branch not selected is prunable.\n\n> **⚡ Audit Artist accelerator:** `/coach-dashboard-create` assembles the portfolio value-realization dashboard from the per-program benefit, variance, and risk data.","kind":"decision","label":"Decide portfolio disposition","performedBy":{"note":"","primitives":["coach-query-data","coach-document-upload","coach-dashboard-create","coach-item-create"]}},"id":"decide-portfolio-disposition"},{"data":{"description":"Agent executes the board's reprioritization, rebaselining, or termination decisions and reallocates freed funding; human program sponsor confirms the actions are executed","instructions":"**Objective** — Execute the board's reprioritization, rebaselining, or termination decisions and reallocate the freed funding and personnel, keeping the portfolio and ERM records current.\n\n**Inputs**\n- The `corrective_action_required` disposition, the named programs, and the per-program actions from \"Decide portfolio disposition\".\n- Each affected program's business case, scope / schedule / budget, and linked ERM cyber-risk entries; the prioritized portfolio ranking for reallocation targets.\n\n**Procedure**\n1. Translate each corrective-action decision into an Issue (issue_type: observation) with coach-item-create — capturing rebaselined scope, schedule, and budget for reprioritized programs in the remediation_plan, or an orderly stop-work, salvage, decommission, and knowledge-capture plan for terminated ones.\n2. Reallocate the funding and personnel freed by terminations or de-scoping to higher-priority initiatives per the board's direction, and update the portfolio ranking and the security-funding plan to reflect the moves.\n3. Link each corrective-action Issue to the related ERM cyber-risk Risk items (category: cyber_security) with coach-items-link — the program and its business case are step documents, referenced not linked — so the change is traceable and the enterprise risk picture stays current.\n4. Record owners and due dates for every action, and surface any action that cannot be executed within the cycle for escalation and carry-forward.\n\n**Record in AssureSwarm**\n- Create one Issue per corrective action (issue_type: observation, source: management_identified, remediation_plan, issue_owner, target_remediation_date) with coach-item-create.\n- Link each corrective-action Issue to its related ERM cyber-risk Risk items (category: cyber_security) with coach-items-link; the affected program and its business case are step documents, referenced rather than linked.\n\n**Exit criteria** — The affected program sponsors confirm the reprioritization, rebaselining, or termination actions are executed or scheduled with named owners and dates, freed funding is reallocated as the board directed, and the portfolio and risk records reflect the changes.","label":"Apply corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link"]}},"id":"apply-corrective-actions"},{"data":{"description":"Agent scans every project at its current gate for a completed security-risk section and ERM linkage, and holds gates on gaps; human confirms security-risk coverage from initiation through delivery","instructions":"**Objective** — Confirm every in-scope project, from initiation through delivery, carries a completed, substantive security-risk section in its stage-gate documentation with its cyber risks ERM-linked, and hold non-compliant gates.\n\n**Inputs**\n- Every in-scope project at its current stage gate and its gate documentation (the coach-workflow-scan target set).\n- The ERM cyber-risk register; the organization's gate / security-risk-section template defining what a substantive section requires.\n\n**Procedure**\n1. Scan every in-scope project at its current stage gate with coach-workflow-scan — from initiation through delivery — and check that each gate document carries a completed information-security-risk section, so security risk is addressed within project management for all projects rather than a subset.\n2. Verify each gate's security-risk section is substantive — risks identified, assessed, and assigned owners and treatments — not a boilerplate placeholder.\n3. Confirm the cyber risks each gate raises are reflected in the ERM register (Risk items, category: cyber_security), linking each held-gate Issue to its ERM Risk entries with coach-items-link, so risk management is integrated into enterprise decision-making rather than siloed in the project.\n4. Compile a gate-compliance register listing every project, its gate, and the status of its security-risk section, flagging missing or thin sections and any gate about to be passed without one.\n5. Hold non-compliant gates and route them back to the project for a completed security-risk section before the gate can clear.\n\n**Record in AssureSwarm**\n- Scan every in-scope project at its current gate with coach-workflow-scan.\n- Attach the gate-compliance register — every project, its gate, and its security-risk-section status — as an XLSX document on this step with coach-document-upload; projects have no native item type.\n- Record each non-compliant or held gate as an Issue (issue_type: exception, source: management_identified, issue_owner, target_remediation_date) with coach-item-create, and link it to its ERM cyber-risk Risk items (category: cyber_security) with coach-items-link.\n\n**Exit criteria** — The board and the CISO confirm every project from initiation through delivery carries a completed, substantive security-risk section, the cyber risks are ERM-linked, and non-compliant gates are held until remediated.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-scan` sweeps every in-scope project's current gate for a completed security-risk section and surfaces the gaps.","label":"Run project gate reviews","performedBy":{"primitives":["coach-workflow-scan","coach-items-link","coach-item-create","coach-document-upload"]}},"id":"run-project-gate-reviews"},{"data":{"description":"Agent assembles the board decision record and evidence pack spanning criteria, scoring, funding, dispositions, and gate compliance, then archives it and seeds the next cycle; human board chair approves and signs off, and that signature closes the cycle","instructions":"**Objective** — Assemble the cycle's decision record and evidence pack spanning criteria, scoring, funding, dispositions, corrective actions, and gate compliance, obtain board-chair sign-off, and close the cycle on that signature.\n\n**Inputs**\n- The ratified criteria pack and the scored, prioritized portfolio.\n- The security-funding allocation and utilization review when the annual leg ran — or the quarterly-scope decision and its rationale when it did not.\n- The disposition decision and any corrective actions; the project-gate compliance register.\n- The systems of record to update at close: the portfolio / EPMO tooling, the security-budget plan, and the ERM cyber-risk register; plus the open corrective actions, held gates, and budget adjustments to carry forward.\n\n**Procedure**\n_Items 1–5 assemble the record and obtain sign-off; items 6–9 close the cycle (folded from the former \"Close and archive\" step) — the board chair's signature recorded here is the closure, with no separate confirmation._\n1. Assemble the board decision record for the cycle — the ratified investment criteria, the scored and prioritized portfolio, the security-funding allocation and utilization review (or the quarterly-scope rationale where the annual leg did not run), the disposition decisions and corrective actions, and the project-gate compliance register — linking each artifact to its workflow step with coach-document-link.\n2. Draft the board minutes and decision memo stating what the board evaluated, prioritized, funded, reprioritized, or terminated, and why, cross-referencing every decision to its evidence.\n3. Confirm the record evidences all three governed outcomes — portfolio value governance, security resource adequacy, and risk integration across the enterprise and its projects — so the cycle stands as audit-ready evidence that needs no oral explanation.\n4. Attach the consolidated decision record and evidence pack with coach-document-upload.\n5. Put the record to the board chair, who reviews that it faithfully captures the board's decisions and their rationale with complete evidence, and signs it off.\n6. Export the complete signed cycle record with coach-workflow-export and archive it to the retention location with its version, approval date, and retention period as evidence.\n7. Update the linked systems of record with coach-document-link — the portfolio and EPMO tooling, the security-budget plan, and the ERM cyber-risk register — so downstream work references the current board decisions, funding, and risk picture; where the board's decisions change the enterprise risk picture, update residual_rating and treatment on the affected Risk items with coach-item-update.\n8. Create carry-forward Issues (issue_type: observation, source: management_identified) with coach-item-create for open corrective actions, held gates, and budget adjustments so they arrive as explicit inputs to the next cycle, each with a named owner (issue_owner) and due date (target_remediation_date).\n9. Schedule the next quarterly investment-board review, the next annual capital-planning leg, and the upcoming project gates, and communicate the board's decisions and their effective dates to stakeholders.\n\n**Record in AssureSwarm**\n- Link each source artifact to its workflow step, and update the linked systems of record — the portfolio / EPMO tooling, the security-budget plan, and the ERM register — with coach-document-link.\n- Attach the consolidated decision record and evidence pack with coach-document-upload.\n- Export the complete signed cycle record — the workflow instance is the cycle's audit trail — with coach-workflow-export and archive it to retention.\n- Create carry-forward Issues (issue_type: observation, source: management_identified, issue_owner, target_remediation_date) for open corrective actions, held gates, and budget adjustments with coach-item-create.\n- Where the board's decisions change the ERM picture, update residual_rating and treatment on the affected Risk items with coach-item-update.\n\n**Exit criteria** — The board chair has signed off the decision record as a faithful, fully evidenced capture of the board's decisions; the archived record is self-contained and durable enough to serve as evidence to auditors without oral explanation; nothing remains open without a tracked owner; the next quarterly review, annual capital-planning leg, and project gates are scheduled and the decisions communicated; the governance cycle is formally closed.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-export` exports the complete signed cycle record for archival to the retention location.","label":"Compile board decision record and evidence","performedBy":{"primitives":["coach-document-upload","coach-workflow-export","coach-item-create","coach-item-update"]}},"id":"compile-board-decision-record-and-evidence"}],"sourceTemplateId":"workflow-library:grc-technology-investment-project-risk-governance"}
