{"description":"Runs on the existing requirement item. Refresh evidence for an obligation on its review cycle, test continued conformance, and record the owner attestation with any exceptions. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-conformance-testing-monitoring-closure","source":"conformance-testing","target":"monitoring-closure"}],"isPublic":true,"itemTypeSlug":"requirement","metadata":{"capabilities":["compliance-monitoring-attestation"],"controlVerbs":{"UC-GOV-03":"operates"},"controls":["UC-GOV-03"],"department":"compliance-legal","domains":["reg"],"kind":"compliance-monitoring-attestation","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:compliance-monitoring-attestation"}],"canonicalUrl":"https://workflow-library.com/all/?w=reg-requirement-monitoring-attestation","contentDigest":"sha256:ad7012c05025dde69c0c869deeeb3928f0ec6ddd9a4919c58063fc8613b0ebbf","prerequisites":{"anchorItemType":{"slug":"requirement"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:reg-compliance-attestation-cycle"}],"roles":[{"contribution":"expertise","description":"Legal or regulatory specialist. Refresh evidence and test continued conformance.","id":"reviewer-1","nodeIds":["conformance-testing"]},{"contribution":"approval","description":"Compliance owner. Approve attestation record.","id":"reviewer-2","nodeIds":["monitoring-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:compliance-monitoring-attestation"}],"releaseId":"sha256:ad7012c05025dde69c0c869deeeb3928f0ec6ddd9a4919c58063fc8613b0ebbf","schemaVersion":1,"sourceTemplateId":"workflow-library:reg-requirement-monitoring-attestation"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"reg-requirement-monitoring-attestation","source":"coworkcanvas-gallery","standards":[],"teams":["compliance-legal"]},"name":"Compliance Monitoring & Attestation","nodes":[{"data":{"instructions":"**Objective**\nRefresh evidence and test continued conformance. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, its mapped controls and policies, the prior monitoring record, the last review date, framework version history, organizational and system changes, and the evidence expectations on record.\n2. Use the evidence expectations, control operation records and testing results, policy publication and attestation records, system configuration extracts, incident and exception logs, and prior-period evidence for comparison.\n\n**Procedure**\n1. Fix the period boundaries, confirm the mapped artifact set is still current, identify organizational, system, or framework changes since the last review, restate the evidence expected per clause, and note scope no longer applicable.\n2. Inspect evidence covering the whole period rather than a point in time, compare against prior-period evidence for drift, separate management representation from inspected support, and classify results against stated criteria rather than impression.\n\n**Record in AssureSwarm**\n1. Capture the monitoring period, clauses and artifacts in scope, evidence expectations, changes since last review, scope removed with rationale, accountable reviewer, and known evidence availability risks.\n2. Document the evidence refresh with source and date per clause, conformance result, period coverage achieved, drift observed against prior period, representations relied upon, and clauses left untested with reasons.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The period and artifact scope are current, evidence expectations are restated before collection, and changes that could break conformance are visible. Each clause result is supported by dated evidence covering the period, untested clauses are declared, and drift is recorded rather than smoothed.","kind":"task","label":"Refresh evidence and test continued conformance","requiredApprovals":1},"id":"conformance-testing"},{"data":{"controls":["UC-GOV-03"],"instructions":"**Objective**\nApprove attestation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the conformance results and their evidence, deviation and exception detail, compensating measures, open issues and remediations, the escalation matrix, and the owner representations.\n2. Review all stage records, evidence references and their period coverage, drift observations, untested clauses, exception dispositions, attestation and its qualifications, and escalation confirmations.\n\n**Procedure**\n1. Present the tested position to the owner without softening deviations, record each exception with cause, exposure, and disposition, evaluate compensating measures on evidence, and escalate declined attestations and material deviations before advancing.\n2. Trace each conformance result to dated evidence, verify exceptions carry owners and dates, confirm escalations reached the authorized body, set the next review date against the required cadence, and return unsupported conclusions with precise comments.\n\n**Record in AssureSwarm**\n1. Record the attestation decision, attesting owner and date, each exception with cause, exposure, compensating measure and disposition, escalation route and recipients, and linked issues or remediations raised. Also record exception detail.\n2. Capture the authorized reviewer, the monitoring summary, accepted conformance results, attestation decision, next review date to record, exception register references, linked issues, owners, and due dates.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the attestation reflects the tested position, exceptions carry disposition and ownership, and declined or material positions are escalated rather than restated as conforming. The authorized reviewer accepts the monitoring record as a traceable record of the period, the next review is scheduled, and closure implies no assurance for periods or clauses not tested.","kind":"task","label":"Approve attestation record","requiredApprovals":1},"id":"monitoring-closure"}],"sourceTemplateId":"workflow-library:reg-requirement-monitoring-attestation"}
