{"description":"Runs the compliance office's recurring register-evaluation cycle as a compliance-review engagement: the workflow instance attaches to an Audit item created per cycle (audit_type: compliance, period_start/period_end bounding the evaluation period, lead_auditor = the compliance officer), and every gap, management directive, and result produced this cycle links back to that Audit. A decision-aware cycle that refreshes the register of applicable legal, regulatory, and contractual requirements — including intellectual-property and software-licensing obligations — confirms ownership, schedules and performs documented compliance evaluations on each requirement's defined cadence, remediates non-compliance, reports status to management, and retains the register and results as evidence. Consumes upstream: between-cycle regulatory change flows in as a data feed from the Regulatory Horizon Scanning & Triage workflow, swept at the register-refresh entry point (a feed, not a formal handoff package). Named deliverables: the dated register of record, the period evaluation schedule, the evaluation results register, the compliance determination, the exposure-ranked remediation set (Issues linked to the cycle Audit), the compliance status report and dashboard, and the retained cycle evidence set. Hands off downstream: obligations that need standing up route to the Regulatory Obligation Implementation workflow — named in prose at close-and-archive, with no handoff package produced here. In scope: the legal, regulatory, and contractual requirements already in the compliance register that fall due for evaluation this period — cadence-due, overdue, or event-triggered. Out of scope: standing up brand-new obligations. The cycle scope — register population, the due subset including overdue catch-ups, and the period boundaries — is set at the register-refresh entry point.","edges":[{"id":"e-refresh-requirements-register-resolve-applicability-with-counsel","label":"Counsel determination required","source":"refresh-requirements-register","target":"resolve-applicability-with-counsel","whenValue":"counsel_determination_required"},{"id":"e-refresh-requirements-register-schedule-evaluations-by-cadence","label":"Applicability confirmed","source":"refresh-requirements-register","target":"schedule-evaluations-by-cadence","whenValue":"applicability_confirmed"},{"id":"e-resolve-applicability-with-counsel-schedule-evaluations-by-cadence","source":"resolve-applicability-with-counsel","target":"schedule-evaluations-by-cadence"},{"id":"e-schedule-evaluations-by-cadence-evaluate-compliance-status","source":"schedule-evaluations-by-cadence","target":"evaluate-compliance-status"},{"id":"e-evaluate-compliance-status-remediate-noncompliance","label":"Non-compliance identified","source":"evaluate-compliance-status","target":"remediate-noncompliance","whenValue":"non_compliance_identified"},{"id":"e-evaluate-compliance-status-report-to-management","label":"Compliant","source":"evaluate-compliance-status","target":"report-to-management","whenValue":"compliant"},{"id":"e-remediate-noncompliance-report-to-management","source":"remediate-noncompliance","target":"report-to-management"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-AUDIT-24"],"department":"compliance-legal","domains":["reg"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=reg-legal-regulatory-compliance-register-evaluation","contentDigest":"sha256:f66b649a8d2dd843ce3e4056421808ddaf88d95e9299e98194e32b19a040db10","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:f66b649a8d2dd843ce3e4056421808ddaf88d95e9299e98194e32b19a040db10","schemaVersion":1,"sourceTemplateId":"workflow-library:reg-legal-regulatory-compliance-register-evaluation"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"reg-legal-regulatory-compliance-register-evaluation","source":"coworkcanvas-gallery","standards":["cobit-2019","iso-27001"],"teams":["compliance-legal"]},"name":"Legal & Regulatory Compliance Register Evaluation","nodes":[{"data":{"decisionField":"register_applicability","description":"Agent rebuilds the register of applicable legal, regulatory, and contractual requirements — including intellectual-property and software-licensing obligations — and flags what changed; human decides whether every applicable requirement is confirmed or a new obligation needs a legal applicability determination","formData":{"fields":[{"key":"register_applicability","label":"Refresh the compliance requirements register","options":[{"label":"Applicability confirmed","value":"applicability_confirmed"},{"label":"Counsel determination required","value":"counsel_determination_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Bring the register of applicable legal, regulatory, and contractual requirements current with everything that changed since last cycle, and decide whether every entry's applicability is settled or an obligation with genuinely uncertain reach needs a counsel determination before it enters the register of record. The compliance officer owns the call.\n\n**Inputs**\n- The compliance requirements register of record from last cycle — the final dated register XLSX retained on the prior cycle's *Close and archive* step, where the register of record is finalized and retained. There is no native Requirement/Obligation item type, so the register is a document, and refreshing it (adds/changes/retirements) — never recreating it — is the whole job of this step.\n- The upstream regulatory-change feed — horizon-scanning output, regulatory-change subscriptions, and legal bulletins per jurisdiction and sector — from the Regulatory Horizon Scanning & Triage workflow, linked as documents at this step (a data feed swept here, not a formal handoff package).\n- Newly executed or amended contracts, licenses, and permits (customer agreements, vendor terms, IP/open-source terms) — uploaded here as PBC/external documents.\n- The software and IP asset inventory — SAM/discovery deployment and entitlement extracts uploaded here (CSV/XLSX).\n- The per-cycle anchor is an Audit item (`audit_type: compliance`, `period_start`/`period_end`, `lead_auditor` = compliance officer) created for this evaluation cycle; every downstream gap, directive, and result links to it.\n\n**Decision criteria**\n\nThe branch rests on the delta work done in this step: sweep the horizon-scanning feed, regulatory-change subscriptions, and legal bulletins for every jurisdiction and sector of operation, plus newly executed or amended contracts (customer agreements, vendor terms, licenses, permits) and the software and IP asset inventory; reconcile into the register as adds (new laws and amendments now in force, new contractual and licensing obligations including open-source and IP-usage terms), changes, and retirements (superseded or expired entries retire with a supersession reference, never a bare deletion); then diff against the prior cycle into a delta list with effective dates, the processes and assets each requirement governs, and a proposed owner per new or changed entry.\n\n- **Applicability confirmed (`applicability_confirmed`)** — every entry's applicability is determinable from the source text and known facts: the obligation names the organization's activity, jurisdiction, or thresholds plainly — an amended data-protection rule in a jurisdiction where the organization demonstrably processes in-scope data, a signed clause with unambiguous scope, a license whose terms map directly to deployed software. Every delta carries an effective date and a mapped scope. Choose this branch even when the delta list is long — volume of change is not uncertainty.\n- **Counsel determination required (`counsel_determination_required`)** — at least one obligation's applicability cannot be settled without legal judgment: extraterritorial-reach questions (does a foreign statute reach this activity), threshold ambiguity (revenue, headcount, or data-volume triggers near the line), an ambiguous contract clause or flow-down obligation, an open-source license whose copyleft reach over shipped product is unclear, or overlapping regimes in conflict. Name each uncertain obligation and its specific question in the rationale — the counsel step executes from that list, and settled entries do not wait for it.\n\nThe screening test: would a reasonable regulator or counterparty dispute the applicability call? If yes for any entry, route it to counsel. A wrong \"not applicable\" is the costliest register failure — the obligation vanishes from every future evaluation cycle.\n\n**Record in AssureSwarm**\n- Submit the decision form: `register_applicability` (the branch), the step result summarizing the delta and naming each uncertain obligation with its framed question and citation, and the step's approver record.\n- Attach the register update memo — delta list, effective dates, process-and-asset mapping, proposed owners — as a document on this step (XLSX/DOCX), and link the source documents (bulletins, contracts, license terms) to the same step. There is no native Requirement/Obligation item type, so the register of record lives as this dated document, not as individual items.\n\n**Exit criteria** — Form submitted; every delta dispositioned as add, change, or retire with an effective date; uncertain obligations named with framed questions, or the rationale states none exist; the unselected branch is prunable.","kind":"decision","label":"Refresh the compliance requirements register","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-document-upload"]}},"id":"refresh-requirements-register"},{"data":{"description":"Agent packages each uncertain obligation with the applicability question framed; human counsel determines applicability and scope for the register of record","instructions":"**Objective** — Obtain a documented, signed legal determination of applicability and scope for each uncertain obligation, so it enters — or is excluded from — the register of record on legal authority rather than compliance-team guesswork.\n\n**Inputs**\n- The uncertain-obligation list from the register refresh, each with its source text and framed question.\n- The facts counsel needs: entities and jurisdictions, activities and products, data types and volumes, threshold metrics (headcount, revenue, processing scale), and the relevant contracts.\n- Prior determinations on related obligations, for consistency.\n\n**Procedure**\n1. Package each obligation for counsel: the exact source text — statute section, regulation cite, contract clause, or license term — the organizational activities and assets it may reach, the jurisdictions involved, and the specific question: whether it applies at all, which entities, processes, or assets it reaches, what the compliance obligation entails operationally, and the effective date with any transition period.\n2. Frame each question narrowly enough to be answerable — \"does Article X's extraterritorial provision reach our processing of EU-resident data absent an EU establishment\" gets a determination; \"does this regulation apply to us\" gets a memo. Supply facts, not conclusions.\n3. Have reviewing counsel record the determination per obligation in the native result and signed determination document using that package: applicable or not; the precise scope; the obligation in operational terms; the recommended owner; the evaluation cadence it warrants; and the dependent obligations the determination surfaces — a statute ruled applicable typically pulls registration, reporting, and record-keeping duties in with it.\n4. Handle privilege deliberately: the register records the operative conclusion — applicable or not, scope, owner, cadence — while the full privileged analysis stays under legal privilege with access restricted to legal, and the register notes where it resides.\n5. Update the register for each obligation counsel confirmed, and record the disposition of each obligation ruled out of scope with the determination reference. The out-of-scope record is evidence too — it is what the organization produces when a regulator asks why an obligation is absent from its register.\n6. Have counsel sign the determination record. Conditional or time-boxed determinations (\"not applicable until headcount exceeds N\") get a monitoring trigger on the register entry so the condition is watched, not remembered.\n\n**Record in AssureSwarm**\n- The native result and signed legal determination document capture per obligation the applicability determination, the scope reached, the requirement in operational terms, the effective date, the recommended owner and cadence, and any condition to monitor or dependent obligations it pulls in — the operative conclusion for the register, never the privileged analysis.\n- Attach the signed determination record per obligation to this step (document upload); the full privileged analysis stays outside AssureSwarm in legal's privileged store, and the register notes where it resides.\n- Record each newly confirmed obligation — counsel's scope, owner, and cadence — as a row in the register-of-record document (there is no native Requirement item type), and link its signed determination document to that register and to the cycle's anchor Audit item.\n- Record excluded obligations in the register with the determination reference and any re-review trigger.\n\n**Exit criteria** — Every obligation packaged for counsel carries a signed determination — entered in the register with scope, owner, and cadence, or excluded with the reasoning referenced and any re-review trigger set; conditional determinations carry monitoring triggers.\n\n","label":"Resolve applicability with legal counsel","performedBy":{"primitives":["coach-document-upload","coach-items-link","coach-item-create"]}},"id":"resolve-applicability-with-counsel"},{"data":{"description":"Turn the approved register into an executable evaluation schedule for the period: every due requirement scheduled with a method, reviewer, evidence expectation, and due date, and every overdue evaluation caught up.","instructions":"**Objective**\nTurn the approved register into an executable evaluation schedule for the period: every due requirement scheduled with a method, reviewer, evidence expectation, and due date, and every overdue evaluation caught up.\n\n**Inputs**\nThe register of record, including the newly added and counsel-confirmed entries.\n- The current organization roster or HR feed — movers and leavers since last cycle.\n- The RACI conventions used where responsibility spans legal, compliance, IT, and the business.\n\nThe approved register with per-requirement cadence and next-due dates.\n- The prior cycle's schedule and completion record, to catch missed evaluations.\n- The reviewer roster and availability across compliance, legal, IT, and the business.\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Confirm register ownership”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Confirm register ownership: Verify a named, current, accountable owner for every register entry — an unowned requirement is unevaluated by default, and ownership gaps are where compliance programs quietly rot.\n\n2. Extract the assigned owner per requirement; where responsibility is shared, extract the RACI and verify exactly one Accountable per entry — split ownership with no single accountable name is an exception to fix, not an operating model.\n3. Reconcile against the current organization: is each owner still in role? Flag departures and transfers; flag new entries carrying only proposed owners not yet confirmed.\n4. Run the exception hunts that experience says pay off: software-license and IP obligations with no named steward (classically orphaned between IT asset management and legal); requirements owned by a vacant role rather than a person; and concentration — one owner carrying dozens of obligations is a paper owner who cannot credibly evaluate them all on cadence.\n5. Propose reassignments — successor-in-role by default — each naming the manager who must confirm. Confirmed ownership means accepting the evaluation duty and its cadence, not being informed of it.\n6. Draft the ownership memo: the per-requirement owner map, the exception list with dispositions, and the proposed reassignments with their confirming managers.\n7. Human checkpoint: accept or correct each reassignment, close every orphaned-requirement exception, and approve the register with its ownership as the authoritative obligation set for the cycle.\n\n8. Assessment scope for Schedule evaluations by defined cadence: Turn the approved register into an executable evaluation schedule for the period: every due requirement scheduled with a method, reviewer, evidence expectation, and due date, and every overdue evaluation caught up.\n\n9. Confirm each requirement's cadence is still right — cadence scales with penalty exposure, enforcement activity, and rate of change. Working heuristics: high-penalty or fast-moving regimes (privacy, sanctions, sector-regulator rules) quarterly; moderate-exposure obligations semiannual; stable contractual and licensing obligations annual. Any requirement whose underlying law or contract changed this cycle is due now, regardless of cadence.\n10. Build the period schedule: per due requirement, the evaluation method (document inspection, control-output review, license reconciliation, filing verification, attestation), the evidence the method must produce, the assigned reviewer, and a due date inside the period. Match method to obligation type — a filing obligation is evidenced by the filed artifact and its acknowledgment, not by someone attesting the filing happened.\n11. Check reviewer independence: the reviewer should not be the requirement owner where the evaluation judges the owner's own performance. Where team size forces self-review, note it on the schedule and route that evaluation for compliance-officer countersign.\n12. Sweep for overdue evaluations — due in a prior period, never performed. Schedule them first and record the miss: an overdue evaluation is itself a finding about the compliance process and belongs in the management report, not quietly absorbed.\n13. Cross-check schedule against register both ways: no due requirement omitted, no retired requirement still scheduled. Flag cadence adjustments where risk or change rate shifted — a cadence change is a register change, dated, attributed, and approved by the requirement owner.\n14. Human checkpoint: approve the schedule for execution — complete, correctly cadenced, right methods and reviewers, overdue items caught up.\n\n**Record in AssureSwarm**\nRecord the confirmed accountable owner for every register entry in the owner column of the register-of-record document — there is no native Requirement item, so ownership lives in the register document, not as an item field.\n- Attach the ownership memo with the exception dispositions to this step.\n- Record the approval on the step.\n\nRecord each scheduled evaluation as a row in the period evaluation schedule document (XLSX) — requirement, method, reviewer, evidence expectation, and due date; there is no native evaluation or Requirement item type, so the schedule is the surface, keyed back to the register-of-record.\n- Attach the schedule and the overdue catch-up plan to this step.\n\n**Exit criteria**\nEvery register entry carries a named accountable owner confirmed in role; every exception dispositioned; each reassignment confirmed by the named manager; register-plus-ownership approved as authoritative for the cycle. Every requirement due this period, including overdue catch-ups, has a scheduled evaluation with method, reviewer, and due date; zero retired requirements scheduled; cadence changes recorded with rationale and owner approval; schedule approved.","label":"Schedule evaluations by defined cadence","performedBy":{"note":"","primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"schedule-evaluations-by-cadence"},{"data":{"decisionField":"compliance_status","description":"Agent executes each scheduled review, gathers the evidence, scores every requirement and characterizes the exposure each gap creates; human decides whether the population is compliant or non-compliance requires a remediation track","formData":{"fields":[{"key":"compliance_status","label":"Evaluate compliance status","options":[{"label":"Compliant","value":"compliant"},{"label":"Non-compliance identified","value":"non_compliance_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Execute every scheduled evaluation, consolidate the results into one compliance determination, and decide whether the population stands compliant or material non-compliance requires the remediation track. The compliance officer owns the call, on documented review evidence rather than assertion.\n\n**Inputs**\n- The approved evaluation schedule: method, reviewer, evidence expectation, and due date per requirement.\n- Access to the evidence sources: filings and acknowledgments, permits and licenses, control outputs and logs, attestations, contracts, and software deployment and entitlement data.\n- Prior-cycle results for the same requirements, to spot regressions and carry-forward gaps.\n\n**Procedure**\n_Items 1–6 are agent-run (folded from the former \"Conduct documented compliance reviews\" step); the human moment is the determination in item 7._\n1. Perform each review per its scheduled method and collect evidence that is dated, attributable, and specific to the obligation: the filed return plus its acknowledgment for filing obligations; the current permit for license-to-operate obligations; control outputs or logs for operational obligations; records of authorized acquisition for procured assets. \"We believe we comply\" is not evidence, and a bare attestation is minimum-grade — corroborate it for high-exposure requirements.\n2. Give software-licensing and IP obligations a reconciliation, not a testimonial: build the effective license position — deployed and in-use counts from discovery or SAM data against entitlements from proof-of-license records (invoices, license certificates, agreements), measured in the license's own metric (per-user, per-device, per-core, subscription seats). Record every usage-over-entitlement gap with counts. Where the organization distributes software, check open-source components' obligations — notice retention, copyleft terms — and confirm assets were acquired through authorized channels (ISO 27001 A.5.32 is the anchor).\n3. Score each requirement: compliant (evidence demonstrates the obligation met in full), partially compliant (met in material part, with specific bounded gaps), or non-compliant (not met, or no evidence it is met — absence of evidence scores as non-compliance for evaluation purposes, and the record says so). Write the specific gap, never \"issues noted\".\n4. Record reviewer, review date, and method on every evaluation so it is reperformable; where the reviewer deviated from the scheduled method, record why.\n5. Compile the evaluation results register: per-requirement status, evidence pointer, and gap; then the population summary — evaluated versus due, compliant count, and gap count with severity per gap.\n6. Do the exposure work the branch rests on, since the call is not gap counting: characterize each gap's exposure — statutory penalties (range, and whether they accrue per violation or per day), contractual remedies a counterparty could exercise (termination rights, indemnities, liquidated damages), software-license exposure (a vendor true-up at list price plus back maintenance is the standard audit outcome), IP infringement exposure, and time-sensitivity (self-disclosure duties, contractual cure periods already running). Cross-reference carry-forward gaps from prior cycles to mark recurrences and expired interim treatments, then rank the gap list by exposure with a proposed owner and due date per gap.\n7. Confirm the scoring is supportable against the retained evidence and pick the branch below.\n\n**Decision criteria**\n- **Compliant (`compliant`)** — every evaluated requirement scored compliant, or the only residual gaps are immaterial and already treated: no statutory penalty exposure, no counterparty remedy triggered, each gap bounded, documented, and covered by an in-date approved treatment. A partially-compliant score can ride this branch only on documented immateriality plus treatment — never because remediation is inconvenient this quarter. Zero recurring gaps, zero expired interim treatments.\n- **Non-compliance identified (`non_compliance_identified`)** — any requirement carries a material gap: penalty or enforcement exposure, a breach a counterparty could act on, usage over entitlement on software licenses, an unmet IP obligation, a recurring gap from a prior cycle, or an interim treatment that expired without its permanent fix. Materiality doubt routes here: the cost of this branch is a remediation plan; the cost of a wrong \"compliant\" is an untracked exposure carrying the compliance office's signature. Name every gap in the rationale.\n\n**Record in AssureSwarm**\n- Attach the per-requirement evidence files to this step, and record each result — status (compliant / partially compliant / non-compliant), reviewer, review date, method, and evidence pointer — as a row in the evaluation results register document (XLSX); there is no native evaluation item, so the results register is the surface. Attach the compiled register to this step.\n- Attach the compliance determination summary — the compliant population, the exposure-ranked gap list, the recurrences — to the step.\n- Submit the decision form: `compliance_status` (the branch), the step result citing the per-gap exposure basis and evidence references, and the step's approver record.\n\n**Exit criteria** — Every scheduled evaluation has a documented result with evidence, reviewer, date, and method, and every gap is described specifically with severity and exposure; form submitted; every evaluated requirement dispositioned as compliant or gap-listed; each gap carries an exposure characterization and, on the non-compliance branch, a proposed owner and due date — or, on the compliant branch, a documented immateriality-and-treatment basis; the unselected branch is prunable.","kind":"decision","label":"Evaluate compliance status","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-item-update"]}},"id":"evaluate-compliance-status"},{"data":{"description":"Agent opens and tracks a remediation item with an interim treatment for each non-compliance; human owners approve the remediation plan and the treatments","instructions":"**Objective** — Convert every material gap into an owned, dated remediation item, with an interim treatment wherever the permanent fix is not immediate — no high-exposure non-compliance sits untracked or untreated while the fix is built.\n\n**Inputs**\n- The exposure-ranked gap list from the compliance determination, with proposed owners and due dates.\n- The affected register requirements and their evaluation evidence.\n- Carry-forward remediation items still open, to catch duplicates and recurrences.\n\n**Procedure**\n1. Open one remediation item per gap carrying the requirement, the specific gap, the exposure characterization, the accountable owner, and a due date scaled to exposure. Ownership sits with the requirement owner or their first-line delegate — the compliance office tracks remediation; it does not own the fixes. Working scale: penalty-accruing or enforcement-active gaps get an interim treatment within days and a committed permanent-fix plan; contractual breaches align to the contract's cure period; license over-deployment gets trued up or de-deployed before the vendor's auditors find it.\n2. Draft an interim treatment for any gap that cannot close immediately: a compensating control, a tightened process, a license-entitlement true-up, a documented risk acceptance with an approver whose authority matches the exposure, or deliberate engagement with the regulator or counterparty — where a regime credits self-disclosure, that call is made with counsel, not by default or omission. Every interim treatment carries an expiry date; a treatment without one becomes the permanent state.\n3. Escalate recurrences: a gap returning from a prior cycle means the prior fix failed — the new plan must state what is different this time, and the item escalates one level of management.\n4. Link each remediation item to its evaluation finding, its register requirement, and its owner, and attach the closure-evidence definition — the artifact that will prove the fix in a later cycle — so closure is verifiable rather than asserted.\n5. Run the completeness check: every determination gap maps to a remediation item with owner and date, or to an approved interim treatment. The residual unplanned list must be empty — or explicitly risk-accepted — before status goes to management.\n6. Human checkpoint: the requirement owners and the compliance officer approve the remediation plan and every interim treatment or risk acceptance, and confirm no high-exposure gap is left untreated.\n\n**Record in AssureSwarm**\n- Create one Issue per material gap — `issue_type: finding` (or `deficiency` where it is a control-design or operating gap), `source: compliance_review`, `severity` from the exposure ranking, `issue_owner`, `identified_date`, `target_remediation_date` scaled to exposure, and `remediation_plan` carrying the interim treatment and its expiry. Link each Issue to the cycle's anchor Audit item; link a recurrence to the prior cycle's Issue.\n- Where a gap is dispositioned as a documented risk acceptance rather than a fix, record it as an Issue with `issue_type: policy_exception`, `exception_approver` (authority matched to the exposure), and `exception_expiry_date` (the filterable expiry index), and set `treatment: accept` on the linked Risk.\n- Attach the interim-treatment approvals and risk-acceptance records to this step.\n\n**Exit criteria** — Every material gap has a remediation item with a named owner, an exposure-scaled due date, and a defined closure-evidence artifact, or an approved interim treatment with expiry; recurrences escalated with a changed plan; approvals recorded; zero untreated high-exposure gaps.","label":"Open and drive remediation","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"remediate-noncompliance"},{"data":{"description":"Put a complete and accurate compliance status in front of management — register health, evaluation coverage and results, exposure-ranked gaps, remediation state — and convert management's directives into tracked actions with owners and dates.","instructions":"**Objective**\nPut a complete and accurate compliance status in front of management — register health, evaluation coverage and results, exposure-ranked gaps, remediation state — and convert management's directives into tracked actions with owners and dates.\n\n**Inputs**\nThe cycle artifacts: register update memo, counsel determinations where made, ownership memo, evaluation schedule and results register, compliance determination, and remediation plan.\n- Prior directives and open-remediation aging from earlier cycles.\n- The audience map: compliance committee, executive management, and the audit committee or board where exposure warrants.\n\nThe final register with counsel determinations and ownership changes applied; the records-retention schedule for compliance evidence.\n- The evaluation results register and per-requirement evidence; the remediation plan with interim treatments; the management report with directives.\n- The complete cycle file: the register update memo, counsel determination record (if that branch ran), ownership memo, evaluation schedule, documented review results, compliance determination, remediation plan (if that branch ran), and management report.\n- The open items: unclosed remediation, interim treatments with expiries, applicability questions still with counsel, cadence adjustments to apply, and management directives in flight.\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Close and archive”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Report compliance status to management: Put a complete and accurate compliance status in front of management — register health, evaluation coverage and results, exposure-ranked gaps, remediation state — and convert management's directives into tracked actions with owners and dates.\n\n2. Compile the status report: register health (adds, changes, and retirements this cycle; ownership completeness; counsel determinations made), evaluation coverage (requirements due versus evaluated — anything under full coverage is explained by name, not footnoted), compliance results with trend against prior cycle, the exposure-ranked gap list, and remediation status including interim treatments with their expiries and carry-forward aging.\n3. Lead with what needs management, stated as the decision or resource each item requires: material non-compliance, high-penalty exposure, recurring gaps, license or IP infringement risk, and any applicability determination that changed the organization's compliance footprint. A report its audience can read without deciding anything is a status file, not a management report.\n4. Build the compliance status dashboard for between-cycle visibility — coverage, gap count by exposure band, remediation aging, upcoming evaluation due dates — and format the report per audience: the compliance committee gets register-level detail; the executive summary carries the exposure-ranked gaps and the asks; audit committee or board inclusion when exposure is organizationally material (an enforcement action, a self-disclosure decision, a material contract breach).\n5. Present, and capture management's acknowledgment and directives — accelerated remediation, resourcing, escalation, external disclosure — verbatim, converting each into a tracked action with an owner and a due date.\n6. Human checkpoint: confirm the report represents register health, results, and remediation accurately and completely; present it; record the acknowledgment and directives.\n\n7. Assessment scope for Close and archive: Finalize the dated register of record, lock the cycle's evaluation evidence into retrievable retention, and close the cycle behind a self-contained archive and a complete carry-forward, so any requirement traces to its review, evidence, and remediation without reconstruction and the next cycle opens from the full record.\n\n8. Finalize the register of record as the dated authoritative version, superseding but preserving the prior dated version. Point-in-time reconstruction — \"what did your register say last March\" — is a standard regulator ask; prior versions are preserved, never overwritten.\n9. Assemble the evidence set: the documented review results per requirement, the collected evidence, the compliance scoring, the non-compliance findings, the remediation plan with interim treatments, and the management report with its directives.\n10. Apply retention dates per the records-retention schedule; where an individual regulation prescribes a record-keeping period longer than the default, the longer period wins and is noted on the artifact (ISO 27001 A.5.33, protection of records, is the control anchor).\n11. Verify retrievability by walking the chain both directions on a sample: pick a requirement and find its review and evidence; pick a remediation item and find its finding and requirement. Confirm the register links to the evaluation results that support it and each result links to its remediation where one exists.\n12. Run the gap check: no evaluated requirement without retained review evidence, no remediation item without its supporting record. Cure gaps now — an evidence gap found today costs a document upload; found by a regulator, it costs the program's credibility.\n13. Verify the cycle file against the artifact checklist above. Branch-dependent artifacts — the counsel determination, the remediation plan — are present when their branch ran and explicitly noted not-run otherwise, so a reviewer never wonders whether something is missing or was never required.\n14. Archive the full cycle file to the retention location with the retention date for compliance program records, keeping the dated register and evaluation results retrievable as evidence. The completeness test: a regulator or auditor could reconstruct the cycle from the archive alone — what was applicable, what was evaluated, what was found, what was done — without oral explanation.\n15. Carry the open items into the next cycle's intake with owners and due dates intact: open remediation with its aging, interim treatments with expiries (an expiry falling inside the next period is flagged due, not merely carried), counsel questions in flight, cadence adjustments, and management directives. Obligations that need building route to the Regulatory Obligation Implementation workflow; between-cycle regulatory change keeps flowing through Regulatory Horizon Scanning & Triage into the next refresh.\n16. Mark the cycle closed in the compliance program register with the archive references and the closure timestamp, and notify the requirement owners, the compliance committee, and management. Post-archive corrections are new dated addenda, not edits to archived artifacts.\n17. Under the recorded management-report approval and directives, automatically verify the dated requirement-to-review-to-remediation evidence chain and complete carry-forward, then record cycle closure.\n\n**Record in AssureSwarm**\nAttach the report (with the evaluation results and remediation register as supporting evidence) as a document on this step.\n- Create or refresh the recurring compliance-status dashboard driven by the Issue population and the anchor Audit's fields — coverage, gap count by exposure band, remediation aging, and upcoming evaluation due dates.\n- Create one Issue per management directive — `issue_type: observation`, `source: management_identified`, `issue_owner`, `target_remediation_date` — linked to the cycle's anchor Audit item.\n\nUpload the final dated register-of-record version and the assembled evaluation evidence set as documents on this step, preserving (not overwriting) the prior cycle's dated register.\n- Trace the chain through the cycle Audit: every gap and directive Issue links to the anchor Audit, while the register, results, and evidence documents sit on the cycle's steps — link the register document to the results-register document and each result to its remediation Issue.\n- Record the retention date applied to each artifact as a note on the document/step (no native retention field); where a regulation prescribes a longer record-keeping period, note the longer period on the artifact.\n- Export the workflow instance and attach the archive manifest as a document on this step — the workflow run itself is the cycle's audit trail.\n- Update the anchor Audit item to close the cycle: set `report_date`, set `rating` (`satisfactory` when the population was compliant, `needs_improvement` or `unsatisfactory` per the worst gap severity), and move its status to complete; carry-forward = the open `source: compliance_review` Issues still linked to the Audit, which the next cycle's refresh queries as intake.\n- Send the closure notification to owners, the compliance committee, and management.\n\n**Exit criteria**\nReport presented with coverage fully explained; management acknowledgment recorded; every directive exists as a tracked action with owner and due date; dashboard current as of this cycle. Dated register of record retained with the prior version preserved; every evaluated requirement traceable to retained evidence and every remediation item to its supporting record; retention dates applied with regulation-specific periods honored; archive complete and self-contained with branch artifacts accounted for; every open item present in the next cycle's intake with owner and due date; cycle marked closed with archive references and timestamp; closure notice sent.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the management package — status report, evaluation results, remediation register — into a distributable set; `/coach-dashboard-create` builds the status dashboard from the cycle's items.","label":"Report compliance status to management","performedBy":{"note":"","primitives":["coach-query-data","coach-dashboard-create","coach-document-upload","coach-render-package","coach-item-create","coach-workflow-export","coach-notify","coach-item-update"]}},"id":"report-to-management"}],"sourceTemplateId":"workflow-library:reg-legal-regulatory-compliance-register-evaluation"}
