{"description":"Runs on the existing requirement item. Validate a new or amended external obligation against its authoritative source, determine applicability, and assess the impact on controls, policies, processes and systems. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-change-applicability-change-intake-closure","source":"change-applicability","target":"change-intake-closure"}],"isPublic":true,"itemTypeSlug":"requirement","metadata":{"capabilities":["regulatory-change-intake-impact"],"controlVerbs":{"UC-GOV-03":"operates","UC-RISK-11":"operates"},"controls":["UC-GOV-03","UC-RISK-11"],"department":"compliance-legal","domains":["reg"],"kind":"regulatory-change-intake-impact","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:regulatory-change-intake-impact"}],"canonicalUrl":"https://workflow-library.com/all/?w=reg-requirement-change-impact","contentDigest":"sha256:f9d7dd896fe1b8d970e7a18a1a27353bda68aa7f6f78f2a54e9194dd7a7c021a","prerequisites":{"anchorItemType":{"slug":"requirement"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:reg-impact-analysis-obligation-mapping"}],"roles":[{"contribution":"expertise","description":"Legal or regulatory specialist. Determine applicability and affected scope.","id":"reviewer-1","nodeIds":["change-applicability"]},{"contribution":"approval","description":"Compliance owner. Approve impact assessment and route implementation.","id":"reviewer-2","nodeIds":["change-intake-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:regulatory-change-intake-impact"}],"releaseId":"sha256:f9d7dd896fe1b8d970e7a18a1a27353bda68aa7f6f78f2a54e9194dd7a7c021a","schemaVersion":1,"sourceTemplateId":"workflow-library:reg-requirement-change-impact"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"reg-requirement-change-impact","source":"coworkcanvas-gallery","standards":[],"teams":["compliance-legal"]},"name":"Regulatory Change Intake & Impact Assessment","nodes":[{"data":{"instructions":"**Objective**\nDetermine applicability and affected scope. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, the primary authoritative source text, the superseded version, regulator or standards-body publications, legal and advisory summaries, and the framework version currently recorded.\n2. Use the validated change, entity and jurisdiction maps, product and service inventory, data flows and classifications, customer and employee populations, existing applicability determinations, and thresholds or exemptions in the source text.\n\n**Procedure**\n1. Read the primary source rather than commentary, compare new and superseded text clause by clause, establish effective and transition dates, distinguish binding obligations from guidance, and flag interpretive ambiguity for legal input.\n2. Test each applicability criterion against documented facts, evaluate thresholds and exemptions explicitly, identify partially reached scope, reconcile against the prior determination, and record where facts were unavailable.\n\n**Record in AssureSwarm**\n1. Capture the authority reference, framework and version, change description with clause-level differences, effective and transition dates, binding versus advisory classification, source citations, and interpretive questions raised.\n2. Document the applicability decision, criterion-by-criterion analysis, entities and jurisdictions reached, exemptions relied upon with justification, prior determination comparison, and unresolved factual gaps. Also record scope analysis.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The change is verified against primary source with citations, timing is established, and interpretive ambiguity is routed to the accountable role rather than resolved by assumption. The applicability decision is supported criterion by criterion, exemptions carry stated justification, and factual gaps that could reverse the decision are visible and assigned.","kind":"task","label":"Determine applicability and affected scope","requiredApprovals":1},"id":"change-applicability"},{"data":{"controls":["UC-GOV-03","UC-RISK-11"],"instructions":"**Objective**\nApprove impact assessment and route implementation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the applicability decision, the mapped control set, policy library, process narratives, system and vendor inventory, existing evidence expectations, current implementation status, and delivery capacity.\n2. Review all stage records, primary source citations, applicability analysis and exemptions, clause-to-artifact mapping, gap inventory, effort estimates, ownership nominations, and feasibility escalations.\n\n**Procedure**\n1. Trace each changed clause to the artifacts that satisfy it, identify gaps where no artifact exists, estimate effort and dependency, rate aggregate impact, name accountable owners, and escalate where the effective date is not achievable.\n2. Verify citations resolve to primary source, confirm the applicability decision is criterion-supported, check every gap has an owner and target date, reconcile the recorded framework version, and return unsupported analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the impact rating, clause-to-artifact mapping, identified gaps, affected controls, policies, processes and systems, effort and dependency estimates, nominated owners, and feasibility escalations. Also record impact analysis.\n2. Capture the authorized reviewer, the intake summary, accepted applicability and impact conclusions, framework version to record, effective and transition dates, implementation route and owners, open gaps, and due dates. Also record change intake summary.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the impact rating follows from the traced analysis, gaps are owned, and any effective date the organization cannot meet is escalated rather than absorbed. The authorized reviewer accepts the intake as a traceable record of change analysis, implementation can be routed against named owners, and closure implies no assurance that the obligation is yet met.","kind":"task","label":"Approve impact assessment and route implementation","requiredApprovals":1},"id":"change-intake-closure"}],"sourceTemplateId":"workflow-library:reg-requirement-change-impact"}
