All Workflows

Every open-source GRC workflow template in one place — internal audit, SOX, IT and security controls, privacy, third-party risk and AI governance. Search, preview and import into your AssureSwarm instance.

All workflows 212 IT 92 HR 11 Finance 27 Internal Audit 45 Risk Management 32 Compliance & Legal 32 Privacy 11 Procurement 15 Executive 20 AI Governance 11 Facilities 7 Business Operations 9
  • AI Governance & Risk/Impact Assessment — AI Governance · 10 steps
    Assess AI system context, impacts and risks; authorize treatment and monitored deployment, route residual risks to the proper authority and approve the evidenced assessment package.
  • AI Governance Framework, Roles & Obligations Review — AI Governance; with Executive · 7 steps
    Review AI policy, role competence, resource dependencies and provider or deployer obligations; approve necessary changes, resolve gaps and retain the published policy and cycle evidence.
  • AI Guardrail Configuration & Agent Permission Review — AI Governance; with IT · 5 steps
    Operate the monthly and per-release first-line review of the guardrail stack around every deployed AI agent: confirm the layered input defenses and endpoint limits that screen adversarial input, injection, and jailbreak attempts and prevent scraping and model extraction; diff each agent's tool allow-list, permissions, approval gates, sandboxing, and configuration artifacts against its authorized scope; and check output filters and grounding, secrets redaction, misuse refusals, and secure-code-generation defaults against baseline. Two decisions route over-permissioned agents and guardrail drift through remediation and retest. The cycle closes with a signed guardrail attestation, cycle metrics, and owned remediation actions linked to the anchor Control.
  • AI Operations Monitoring & Incident Response — AI Governance; with IT · 5 steps
    Operate the monthly review of the deployed AI estate: confirm automatic event logging and retention and work performance, anomaly, and drift alerts to closure; verify human-oversight staffing and intervention records; and screen AI uses against intended use and legal prohibitions. Triage reports from the AI concern channels, execute any required incident communications and regulator reporting within mandated timeframes, and retain all resolution records.
  • AI Service Data Policy & Quality Management Cycle — AI Governance; with Privacy · 5 steps
    Review AI service input and output data policies, collect required customer acknowledgments, assess quality management and obligations, and track corrective actions with a retained cycle record.
  • AI System Development, Data & Deployment Gate — AI Governance; with IT · 7 steps
    Run the release board gate that every new AI system and substantial modification must clear before deployment. The gate approves responsible-AI objectives and per-system requirements before build, governs training, validation, and test data with bias mitigation, executes the pre-deployment impact assessment and EU AI Act risk classification, confirms Annex IV-grade technical documentation, and records verification, validation, and deployment sign-off, with retraining and other changes re-entering the same gate.
  • AI Transparency & Value-Chain Communications — AI Governance; with Compliance & Legal · 6 steps
    Run the recurring AI-transparency cycle: keep each AI system's user and deployer documentation, AI-interaction disclosures, and AI-generated-content marking (including deepfakes) current with system changes, and retain distribution evidence. Evaluate AI suppliers against the organization's responsible-AI requirements and review customer needs and communications so customers have what they need to use the systems responsibly.
  • Annual ICFR Scoping & Risk Assessment — Finance · 13 steps
    Perform annual SOX scoping from materiality and significant accounts through RMMs, key controls, fraud risk, concurrence, and RCM publication.
  • Annual Internal Audit Planning & Resource Management — Internal Audit · 7 steps
    Run the chief audit executive's annual internal audit planning cycle: refresh the audit universe and the documented understanding of governance, risk, and control processes, develop the risk-based strategy and plan, secure the budget, staffing, and technology to deliver it, obtain board approval, and reassess the plan and resource sufficiency each quarter as the risk landscape changes.
  • Annual Policy Review — Compliance & Legal · 2 steps
    Obtain substantive owner and policy-team review, route material revisions separately and approve the next review date.
  • Audit Engagement Planning — Internal Audit · 8 steps
    Establish the scope, engagement risk assessment, control population, and sampling plan for an already-opened audit engagement — together the engagement Risk & Control Matrix (RCM) — culminating in an approved planning memo and an enriched audit record handed to fieldwork.
  • Audit Fieldwork, Findings & Reporting — Internal Audit · 3 steps
    Execute approved audit procedures, evaluate and clear observations, issue a supported report, and close the engagement record with tracked actions.
  • Audit Logging Coverage & Integrity Operations — IT · 5 steps
    Operate the monthly cycle that verifies audit logging is enabled across systems, applications, and network components against the security-relevant event catalog, validates record content completeness and clock synchronization, and confirms log protection, tamper alerting, and retention against the documented schedule. Each monthly instance attaches to the existing audit-logging Control (UC-LOG-01) in the control library and produces a coverage matrix, record content-completeness results, clock-drift report, and retention and capacity attestation, with every gap logged as an Issue related back to that Control.
  • Audit Planning and Scoping — Internal Audit · 2 steps
    Define engagement objectives, boundaries, independence, program, resources and approval before fieldwork.
  • Audit Report Drafting — Internal Audit · 10 steps
    Compile fieldwork findings into a formal audit report, from issue drafting and executive summary through management responses and final issuance.
  • Authentication Platform & Session Policy Operations — IT · 5 steps
    Monthly authentication-platform operating cycle: verify MFA enforcement and enrollment across remote, privileged, and sensitive-data access, confirm secure log-on and federation channels, defend against brute-force and anomalous logons, and enforce session lock, termination, and concurrent-session limits together with the system-use and last-logon notifications shown at every sign-in.
  • Authorized Software & Component Integrity Control — IT · 7 steps
    Operate the monthly software-estate cycle: reconcile installed software against the approved catalog and allowlist, remove or escalate unauthorized installations, and confirm installation rights stay restricted to authorized personnel from trusted sources with usage tracked against license entitlements. For everything entering the estate, verify supplier trust and signature integrity before installation, blocking and investigating anything that fails.
  • Backup & Recovery Testing — IT · 2 steps
    Test recoverability for a system by performing an actual restoration and measuring the result against recovery objectives.
  • Board Risk & Internal Control Oversight Cycle — Executive; with Risk Management · 7 steps
    Support the independent board’s risk and internal-control oversight, annual governance-framework evaluation and approval of strategy and policies; adopt the minutes and carry an owned directives register into implementation and the next cycle.
  • Business Continuity & DR Test Exercise — Business Operations; with IT · 6 steps
    Run one operating cycle of a BC/DR plan-testing control: plan and execute a business continuity or disaster recovery exercise against RTO and RPO objectives, capture gaps as findings, and fold them back into the BC and DR plans.
  • Change & Release Management (CAB) — IT; with Finance · 7 steps
    Operate the weekly Change Advisory Board and the per-change pipeline for every application, database, infrastructure, configuration, and procedure change: request intake, security and risk impact analysis, environment segregation and configuration-baseline verification, acceptance testing, CAB authorization, and controlled deployment with rollback plans and post-implementation verification. Emergency changes follow the expedited path and are ratified at the next CAB, all under one evidence set.
  • Change Request, Approval & Migration — IT · 2 steps
    Move a system change from request through independent testing and approval to production migration, evidencing developer-migrator segregation.
  • Code of Conduct & Workforce Accountability Cycle — HR; with Compliance & Legal · 6 steps
    Adopt the code of conduct and its performance, incentive and disciplinary expectations; communicate it, gate access on acknowledgments, assess violations and verify timely disciplinary and remediation outcomes.
  • Combined Assurance Mapping — Internal Audit; with Risk Management · 7 steps
    Map effective assurance across the Three Lines, resolve self-review safeguards, assess independent reliance and agree coverage commitments; govern remaining gaps and deliver the map and evidence to audit-committee reporting.
  • Compliance Monitoring & Attestation — Compliance & Legal · 2 steps
    Refresh evidence for an obligation on its review cycle, test continued conformance, and record the owner attestation with any exceptions.
  • Continuous Controls Monitoring (ISCM) Cycle — IT; with Risk Management · 4 steps
    Run recurring control monitoring by collecting metrics, comparing thresholds, triaging degradation, updating POA&M, reporting health, and tuning cadence.
  • Continuous Monitoring & Agent Evaluation — Internal Audit · 2 steps
    Run the standing continuous auditing program: define KRI thresholds and queries, build and approve the monitoring dashboard, run the recurring monitoring cycle and triage breaches, then sample and grade agent-drafted suggestions and step results from across the course against the agent-draft rubric and raise every agent-quality finding as an owned issue.
  • Control Design — Business Operations; with Risk Management · 3 steps
    Design a new control from objective definition through attribute specification, risk mapping, evidence and test approach definition, and final control record creation.
  • Control Design Assessment — Internal Audit · 1 steps
    Judge whether the control's precision, evidence, ownership, frequency and segregation address its stated risk.
  • Control Exception Evaluation and Remediation — Internal Audit; with Risk Management · 2 steps
    Evaluate exception scope, impact, severity and compensating controls, then obtain management-owned remediation and authorized escalation.
  • Control Interim Testing Record — Internal Audit · 2 steps
    Test a defined interim-period population using a documented sampling and attribute plan, then record exceptions and a bounded conclusion.
  • Control Library Lifecycle — Risk Management; with Finance · 3 steps
    Review proposed controls for duplication, classification and risk-policy-process linkage; govern publication and rework, then review operating changes and preserve history when a control is retired.
  • Control Remediation Retest and Closure — Internal Audit · 2 steps
    Independently retest failed attributes on post-remediation evidence, assess recurrence and authorize finding closure.
  • Control Responsibility Communications & Ethics Hotline — Compliance & Legal; with HR · 6 steps
    Approve tailored control-responsibility communications, assess acknowledgment coverage and verify concern-raising channels; test anonymous intake routing, review real matters and retain quarterly evidence with owned exceptions.
  • Control Walkthrough — Internal Audit · 1 steps
    Trace an actual occurrence from input through operator action and retained evidence, challenging differences between procedure and practice.
  • Controlled Hardware & System Maintenance — IT; with Facilities · 7 steps
    Operate the maintenance desk that schedules, approves, documents, and reviews hardware and system maintenance, repair, and replacement per manufacturer and organizational requirements, sanitizing equipment before off-site work and verifying security controls after every completion. Control the maintenance tools, personnel, and nonlocal sessions that touch in-scope systems, from inspection and approved-personnel checks to authenticated, recorded, and terminated remote connections.
  • Cryptographic Key Management Review — IT · 3 steps
    Periodic cryptographic hygiene review: inventory keys and certificates, verify custody and rotation, flag weak algorithms, and remediate.
  • CSF 2.0 Profile & Maturity Assessment — IT; with Executive · 5 steps
    Build a controls-scoped CSF Current Profile, Target Profile, Tier assessment, gap plan, and CISO-ready roadmap.
  • Cybersecurity Assurance Review — Internal Audit; with IT · 8 steps
    Run a CAE-owned cybersecurity assurance review on the existing IT-audit engagement item — IIA Topical Requirement coverage tested against NIST 800-53 — producing a four-Cs findings register and a Standard 14.5 posture conclusion for report drafting.
  • Cybersecurity Incident Response — IT · 5 steps
    Operate the controls-scoped detect-to-respond loop from validation through containment, eradication, recovery, POA&M updates, and technical lessons learned.
  • Data Conversion & Migration — IT · 2 steps
    Convert data into a target system with evidenced completeness and accuracy reconciliation between source and target.
  • Data Encryption & In-Use Protection Operations — IT · 5 steps
    Operate the quarterly sweep of data stores and transmission paths against the encryption standard: at-rest encryption or tokenization with minimized retention, strong cryptography and trusted certificates on every open and external channel, and controlled transmission and removable-media movement, with CISO-approved compensating controls kept current where encryption is infeasible. The same cycle verifies data-in-use protections - field masking, process isolation, enclave configurations, identity-scoped access, and memory clearing - on high-sensitivity workloads.
  • Data Governance Council Operations — Business Operations; with Privacy, IT · 6 steps
    Run quarterly data governance and required integrity-board oversight: review charter standing, lifecycle policy, quality and integrity trends and sharing agreements, then approve minutes and report owned actions at the defined interval.
  • Data Retention & Secure Disposal — IT; with Privacy · 4 steps
    Enforce retention schedules each cycle: identify expired data, dispose of it verifiably, and protect and sanitize physical media with certificates of destruction.
  • Deception, Honeytoken & OPSEC Concealment Operations — IT · 6 steps
    Run the standing detection-engineering deception cycle each quarter against the existing deception/OPSEC concealment Control in the control library: deploy, verify, and reposition honeypot/honeynet decoys and honeyclient sandbox detonation ahead of user delivery, and seed, monitor, and test honeytoken, beacon, and watermark taint mechanisms across systems and datasets. In parallel, operate the OPSEC process that identifies critical operational information (captured as Risk items), analyzes adversary collection paths, and deploys concealment and misdirection countermeasures (Control items) on designated systems, handing any confirmed activation to the incident-response workflow with a preserved evidence package rather than duplicating containment.
  • Deficiency Evaluation & Committee — Finance · 2 steps
    Evaluate SOX control deficiencies individually and in aggregate, obtain management challenge, and govern committee communication and disposition.
  • Domain Oversight and Management Review — Risk Management; with Executive · 1 steps
    Assess the domain’s register, operating evidence, risk posture and control exceptions, then record management priorities, resources and escalations with domain-owner and independent-reviewer approval.
  • DPIA / Privacy Impact Assessment — Privacy · 7 steps
    Screen a processing activity and, where required, run the full DPIA: necessity, privacy risks, mitigations, residual-risk decision, and sign-off.
  • DSAR Fulfillment (Access & Deletion Requests) — Privacy · 6 steps
    Fulfill a data-subject access or deletion request inside the statutory deadline: verify identity, locate data, apply exemptions, review, and deliver.
  • Emergency Change — IT · 2 steps
    Record an emergency change that bypassed normal change control, evidence the elevated access used, and retrospectively test whether the bypass was justified.
  • Emerging Risk & Horizon Scan — Risk Management · 1 steps
    Scan the forward horizon for signals of an emerging exposure, assess plausibility and velocity, and decide whether it enters the register or stays on the watchlist.
  • Employee Offboarding — HR; with IT · 4 steps
    HR authorizes the departure and effective time, IT evidences removal, the manager transfers work and assets, and HR decides closure with residual obligations visible.
  • Employee Onboarding — HR; with IT · 3 steps
    HR and the manager approve joiner facts and entitlements, IT evidences access grants, and HR resolves readiness conditions before recording an active engagement.
  • End-User Computing Inventory & Validation — IT · 2 steps
    Inventory the spreadsheets and end-user tools feeding reporting for a system, and test their access, change, and integrity controls.
  • Endpoint, Media & Information Handling Custody — IT · 5 steps
    Operate the monthly endpoint, media, and information-handling custody desk: verify fleet endpoint safeguards and acceptable-use acknowledgments, review off-premises and external-system use, and keep unneeded ports, I/O devices, and sensors restricted. Run removable media end to end — authorization, classification-based storage, tracked movement, and verified sanitization or destruction with retained certificates — and maintain the information-transfer rulebook and agreements covering electronic, physical-courier, and verbal disclosure.
  • Enterprise GRC Platform Integration Bridge — IT; with Risk Management · 5 steps
    Define mappings, migrate or provision records, run bidirectional sync, monitor health, resolve conflicts, and confirm system-of-record coverage.
  • Enterprise Risk Assessment & Portfolio Oversight Cycle — Risk Management · 8 steps
    Assess enterprise risks on a fixed appetite and scoring basis, obtain owned responses and appropriate acceptance authority, and approve the residual portfolio and movement narrative for governance reporting.
  • Enterprise Risk Register Lifecycle — Risk Management · 6 steps
    Maintain the risk register with distinct Three Lines responsibilities, evidence-backed owner-approved ratings and calibrated KRIs; govern treatment or acceptance and hand the maintained portfolio to assessment and appetite reporting.
  • Enterprise Risk Treatment Operations Cycle — Business Operations; with Risk Management · 5 steps
    Assess enterprise threats and opportunities, implement owned treatment for tolerance breaches and reassess residual exposure; obtain required senior acceptance and approve a current register, portfolio report and change-monitoring record.
  • Environmental & Utility Systems Maintenance — Facilities; with IT · 5 steps
    Run the monthly preventive-maintenance calendar that independently tests and maintains fire and water detection systems, environmental monitoring, emergency power and lighting, protected cabling, and electromagnetic shielding, producing the single maintenance-and-inspection log of test records, service tickets, and alarm-notification checks.
  • Equipment Maintenance, Movement & Marking Control — Facilities; with IT · 7 steps
    Operate the recurring equipment control cycle: run maintenance to manufacturer specification with only authorized personnel and full activity/fault logging, and authorize, monitor, and track every asset delivery, removal, and movement through isolated loading areas. Apply the siting checklist and marking verification at installation or relocation, and tie maintenance, movement, and marking evidence together in the quarterly reconciliation.
  • ERM Risk Identification & Register Refresh — Risk Management · 1 steps
    Run a periodic enterprise risk identification cycle, consolidate candidate risks, and approve the resulting register changes.
  • ESG-Related Risk Materiality & Integration — Risk Management; with Executive · 5 steps
    Assess ESG impacts, risks and opportunities with affected stakeholders and information users; validate material topics, evaluate responses and disclosure readiness, and govern gaps or acceptance before board reporting.
  • EU AI Act Obligation Impact Analysis — AI Governance; with Compliance & Legal · 10 steps
    Parse EU AI Act obligations, map affected AI use cases, crosswalk controls, flag conformity gaps, and hand high-risk items to AIMS.
  • External Audit Support & PBC — Finance · 1 steps
    Govern external-audit PBC requests from intake and preparation through quality review, secure delivery, clarification, and complete request closure.
  • Facility Access Administration & Monitoring — Facilities; with IT · 6 steps
    Operate continuous facility-access administration: authorize, issue, and periodically review physical credentials, enforce entry controls and visitor escort/logging, and secure, rotate, and revoke keys, combinations, and badges on compromise, termination, or role change. Run the monthly review of surveillance, intrusion-detection output, physical access logs, and visitor records, investigate anomalies, and confirm data-center/protected-asset access and environmental safeguards with facilities.
  • Financial Controls Policy & Segregation-of-Duties Governance — Finance · 6 steps
    The SOX PMO reapproves and communicates the financial-control policy suite, including entity-wide ITGC and period-end reporting oversight policies, on its annual cycle. Every quarter it also refreshes the segregation-of-duties conflict matrix, screens role design and system access for incompatible duties, and documents mitigating controls where segregation isn't practicable.
  • Financial Systems Transaction Integrity Monitoring — Finance; with IT · 6 steps
    Operate the recurring financial-systems transaction-integrity cycle each period on the existing financial-reporting Process — clearing rejected-input and suspense queues, dispositioning automated-processing exceptions, and reconciling interface transfers. Validate system-generated reports and spreadsheets before reliance, with configuration retested on every change and evidence captured as you go.
  • Finding Remediation & Action-Plan Monitoring — Internal Audit · 7 steps
    Track audit findings and agreed actions from registration through evidence validation, escalation, risk acceptance, and committee reporting.
  • Framework Adoption & Cross-Mapping — Compliance & Legal; with Risk Management · 5 steps
    Set obligation- and appetite-based framework targets, assess current evidence and crosswalk coverage, and govern risk-ranked gaps; deliver approved policy/control work with a maintained mapping table and versioned adoption record.
  • Fraud & Forensic Investigation Engagement — Internal Audit; with Compliance & Legal · 13 steps
    Run a predication-gated fraud and forensic investigation from allegation intake through evidence preservation, forensic procedures, interviews, loss quantification, audit-committee reporting, and referral and remediation handoffs.
  • Fraud Risk Assessment & Anti-Override Control Review — Finance; with Executive · 6 steps
    Lead the annual (or event-triggered) fraud risk assessment across fraudulent reporting, asset misappropriation, and corruption, evaluating incentives, opportunities, and rationalizations while explicitly rating the risk of management override of controls. Recalibrate the anti-override control set - journal-entry review criteria and significant-estimates scrutiny - and report refreshed results and mitigations to the audit committee.
  • Fraud Risk Assessment & JE Testing — Internal Audit · 2 steps
    Assess fraud risks across the fraud triangle and management override, map anti-fraud controls, profile and flag the journal-entry population, draw a reproducible random sample from the unflagged remainder, test every selected entry for support, and raise unsupported anomalies as issues.
  • FSLI Significance Assessment — Finance · 1 steps
    Assess quantitative and qualitative significance for a financial statement line item and approve its scoped assertions, locations, and process dependencies.
  • GCP Physical and Environmental Subservice Reliance — IT; with Risk Management · 5 steps
    Evaluate GCP assurance-report scope, physical and environmental controls, exceptions and user responsibilities; record a bounded reliance decision rather than claiming to operate provider facilities.
  • GPAI Model Provider Compliance Cycle — AI Governance; with Compliance & Legal · 8 steps
    Run the recurring compliance cycle owned by providers of general-purpose AI models: maintain model technical documentation and the downstream-provider information pack, operate the EU copyright reservation-of-rights policy, and publish the training-content summary on every model release and quarterly refresh. For models designated as posing systemic risk, the cycle additionally runs state-of-the-art model evaluations with adversarial testing, assesses and mitigates systemic risks, tracks and reports serious incidents to the AI Office, and verifies cybersecurity protection of the model and its infrastructure.
  • Identity & Authenticator Lifecycle Administration — IT · 6 steps
    Operate the standing identity desk: issue unique identifiers for every user, service, and device from the authoritative source, hold shared-identifier requests to documented approval with compensating controls, and run the monthly sweep that deactivates dormant identifiers and enforces non-reuse. Proof identities proportional to assurance level before binding credentials, then administer the authenticator lifecycle end to end: verified issuance with defaults changed and strength enforced, protected storage, transmission, and entry, embedded-credential checks, and scheduled rotation or compromise- and separation-triggered revocation.
  • Identity Assurance Review — IT · 5 steps
    Review IAL, AAL, and FAL requirements against current identity proofing, authentication, and federation controls, then remediate and validate gaps.
  • Incident & Problem Management — IT · 2 steps
    Record an incident on a system, evidence containment against response targets, and determine root cause with preventive action.
  • Incident Management Lifecycle — Business Operations; with IT, Compliance & Legal · 7 steps
    Assess and govern an incident from its detection clock through verified recovery and approved notifications; determine corrective actions or risk acceptance and retain the evidence, reporting handoff and follow-up schedule.
  • Incident Reporting Channels & Spillage Response — IT; with Compliance & Legal · 7 steps
    Operate the standing incident-reporting capability: run the monitored mailbox, hotline, and service portal with full acknowledgment and triage routing, execute the information-spillage response procedure end to end, and maintain reviewed contacts with authorities and special-interest groups.
  • Incident Response Readiness Program — IT · 6 steps
    Operate the annual incident response readiness cycle against the existing incident-response Control (UC-IR-01, with the training-and-testing Control UC-IR-02 linked to the same instance): maintain the written IR plan — a Policy item whose governed document attaches to it — through designated-management approval and protected distribution to named responders, then deliver role-based IR training and run the scheduled capability test as a readiness Audit. Feed exercise and training gaps back into the plan and training program as corrective-action Issue items, with significant incidents or organizational changes triggering off-cycle runs of the same procedure.
  • Information Security Program Governance Review — IT; with Executive · 6 steps
    Operate the CISO's recurring security program governance review on the standing "Information Security Program Governance" Process item: each quarter enrich the senior-management-approved information security program plan (its Policy item) and keep security roles, authorities, and reporting lines current, and each year deliver the written board report confirming the CISO mandate and run the security workforce competency review, so the program stays approved, resourced, and owned through organizational change.
  • Interim Operating Effectiveness Testing — Internal Audit; with Finance · 2 steps
    Review program coverage and aggregate interim exceptions from approved Control tests, then agree auditor reliance and management actions.
  • Internal Audit Charter, Independence & Board Governance Cycle — Internal Audit; with Executive · 8 steps
    Run the internal audit function's board-governance cycle: deliver the CAE's functional reporting and executive sessions to the audit committee, secure committee action on the CAE's appointment, evaluation, remuneration, and the audit plan and budget, and reaffirm the function's organizational independence in writing. Lead the periodic board review and reapproval of the audit mandate and charter with its unrestricted-access provisions, execute the stakeholder communication plan across the board, management, regulators, and external auditors, and retain the governance evidence.
  • Internal Audit Engagement Lifecycle — Internal Audit · 7 steps
    Run an IIA-aligned engagement on the existing Audit item — from evidence requests and fieldwork through an evaluated findings register (Issue items), conclusions per objective, a report-ready handoff package, and registered action plans.
  • Internal Audit Ethics, Objectivity & Competency Program — Internal Audit · 6 steps
    Run the internal audit function's annual professional-practice cycle: every auditor and assisting party attests to the ethics and professional-courage expectations with deviations documented and resolved, signs conflict-of-interest declarations backed by per-engagement conflict screening, assignment rotation, and recusal, and completes confidentiality acknowledgments while access to audit files is reviewed and restricted; the cycle closes with competency assessment against role requirements and approved, tracked continuing-professional-development plans for each auditor.
  • ISMS Internal Audit & Management Review — Internal Audit; with IT, Executive · 6 steps
    Run the ISMS clause 9.2 internal audit and clause 9.3 management review: findings, corrective actions, review inputs, decisions, and follow-up.
  • ISMS Risk Assessment & Treatment Cycle — IT; with Risk Management · 7 steps
    Perform ISO 27005 risk assessment and treatment planning to produce current risks and SoA inputs for ISO 27001 control applicability.
  • ISO 27001 Certification Readiness — Internal Audit · 2 steps
    Assess ISO/IEC 27001 certification readiness across ISMS scope, clauses, risk treatment, Annex A applicability, internal assurance, gaps, and audit-entry governance.
  • ISO 27001 SoA Review & Controls Assessment — IT; with Compliance & Legal · 8 steps
    Review Statement of Applicability decisions, verify implementation evidence, assess controls, remediate gaps, and publish the approved SoA version.
  • ISO 27001 Stage 1 ISMS Documentation Review — Internal Audit · 1 steps
    Review ISMS clauses 4–10 documentation, record findings, and conclude readiness for Stage 2 planning.
  • ISO 27001 Stage 2 Annex A Controls Audit — Internal Audit · 5 steps
    Audit the organizational, people, physical and technological Annex A controls in the approved Statement of Applicability, with specialist assessments and an independent conclusion.
  • ISO/IEC 42001 AI Management System Internal Audit — Internal Audit; with AI Governance · 2 steps
    Plan and perform an independent internal audit of an AI management system against ISO/IEC 42001, using AIUC-1 crosswalk evidence where it helps test AI-specific safeguards; document findings, management actions, and an independent conclusion without presenting the work as certification.
  • Issue Remediation and Verification — Risk Management; with Business Operations · 2 steps
    Agree cause-based, separately owned remediation actions and validate each by its committed method; approve the finding’s closure only when every linked action is validated and closed.
  • Issue Triage & Disposition — Risk Management · 2 steps
    Substantiate a reported issue, assess its severity and cause, select a governed disposition, and approve the triage record.
  • IT Asset Inventory & Classification Upkeep — IT · 6 steps
    Run the quarterly cycle that reconciles the authoritative hardware, software, systems, and services inventory against discovery scans and change records, correcting discrepancies and confirming owner, location, and security attributes for every in-scope component. In the same cycle, review and refresh the classification, priority, and labeling of information and associated assets, including on physical media, so both registers stay current for downstream audit, compliance, and security scoping.
  • IT Availability & Resilient Failure Operations — IT · 5 steps
    Operate the monthly IT availability control across the full cycle: monitor scheduled batch jobs and system processing with documented incident and problem resolution, verify backups with periodic restore testing and track processing availability against service expectations, protect network services against denial-of-service events with fail-secure component behavior and alternate communications readiness, and work the mean-time-to-failure replacement queue with verified fail-safe procedures that place failing systems into a known, alerting safe state.
  • IT Governance Objective Review (COBIT) — Executive; with IT · 4 steps
    Assess COBIT capability from evidence and owner interviews, compare it with approved targets and commit improvements where needed; obtain board direction and review actual progress through the closing cadence.
  • IT Operations & Capacity Management Cycle — IT · 5 steps
    Operate the weekly IT operations and capacity management cycle against the standing IT Operations & Capacity Management process — each week a new workflow instance on that Process item executes job scheduling, processing, infrastructure monitoring, and facility management per documented procedure, then reconciles outcomes and corrects any exceptions. Review processing capacity and utilization against forecast demand, trigger capacity additions before thresholds are breached, and confirm priority-based allocation and quotas keep protecting shared resources, with breach alerts routed to responsible personnel. Produces the named evidence set: the weekly operations review minutes, the consolidated exception log, and the capacity-and-utilization report.
  • ITGC Change & Provisioning Testing — Internal Audit · 2 steps
    Test the design and operating effectiveness of change-management and access-provisioning controls for one in-scope system: validate the populations, draw the samples, test each ticket against the control's attributes, conclude, and raise exceptions.
  • Job Scheduling & Batch Monitoring — IT · 1 steps
    Review scheduled job execution for a system over a period, evidencing failure detection, escalation, and resolution.
  • Joiner-Mover-Leaver Access Lifecycle — IT; with HR · 6 steps
    Handle joiner, mover, and leaver events end-to-end: provision role-based access, adjust with SoD checks on transfer, and evidence timely removal on exit.
  • Legal & Regulatory Compliance Register Evaluation — Compliance & Legal · 6 steps
    Run the compliance office's recurring register-evaluation cycle as a per-cycle compliance-review Audit item: maintain the register of applicable legal, regulatory, and contractual requirements — including intellectual-property and software-licensing obligations — with named owners, evaluate compliance with each requirement on its defined cadence through documented reviews, drive remediation of non-compliance as Issues linked to the cycle Audit with status reported to management, and retain the register and evaluation results as evidence.
  • Malware, Email & Web Content Defense Operations — IT · 5 steps
    Operate the monthly malicious-content defense cycle: verify centrally managed anti-malware coverage, scanning, signature updates, and tamper protection across every commonly affected component, and review quarantine, alerting, and detection-log handling. Tune email and web filtering for spam and phishing at entry and exit points, and maintain mobile-code technology authorizations and website category and reputation filtering with enforcement-log review.
  • Management Assessment & Assertion — Finance · 2 steps
    Assemble and govern management’s annual ICFR assessment record, including scope, test results, deficiencies, certifications, disclosures, and assertion approval.
  • Monthly Financial Close — Finance · 3 steps
    Reconcile the period, review proposed adjustments independently, and post and close through authorized ledger operators with a named period package.
  • Network & Provider Service Monitoring — IT; with Procurement · 5 steps
    Operate the monthly cycle that keeps network devices hardened and controlled and network-service documentation (security features, service levels, management responsibilities, including outsourced services) current, monitoring delivered services for conformance and addressing deviations. Review external providers' activity, service status, and security-relevant events against contractual obligations through their logs and reports, confirm cross-organizational audit-exchange methods and identity-context preservation, and feed every deviation into a single owned remediation log.
  • Network Segmentation & Boundary Rule Management — IT · 6 steps
    Operate the boundary estate end to end as a quarterly workflow instance on the existing boundary-protection Control: maintain the trust-zone model, gate and implement rule changes to managed interfaces under a deny-by-default baseline, monitor boundary traffic for external threats, and run the quarterly segmentation and rule-set review evidenced by a verified rule-change record log. Enforce label preservation and guard-rule policy at every cross-domain interconnection point so only authorized data types and flow directions pass between security domains.
  • New System Implementation (SDLC) — IT · 2 steps
    Take a new system from control requirements through testing and acceptance to an evidenced go-live readiness decision.
  • NIST RMF System Authorization (ATO) Cycle — IT; with Compliance & Legal · 9 steps
    Move a single information system through the seven RMF phases — prepare, categorize, select, implement, assess, authorize, and monitor — to reach and sustain an authorization-to-operate, producing the FIPS 199 categorization, SSP, SAR, POA&M, and signed ATO letter as one authorization package.
  • Obligation Implementation & Adoption — Compliance & Legal · 2 steps
    Deliver the control, policy and process changes an obligation requires, validate readiness evidence, and approve the adoption record.
  • Offboarding & Access Revocation — IT · 2 steps
    Revoke a leaver access across every in-scope system within the policy window, evidence each revocation, and approve the revocation record.
  • Onboarding & Access Provisioning — IT · 2 steps
    Provision a joiner access from an approved role profile, evidence each grant, and approve the provisioning record that ITGC access testing samples.
  • Outsourced & Critical-Component Development Oversight — Procurement; with IT · 6 steps
    Each quarter, review every active outsourced and third-party development engagement for secure-development, IP-ownership, and audit-rights contract terms, verify deliverables against requirements with security-testing evidence on file, and screen developers of critical systems before granting development-environment access. Maintain the register of components critical to security or mission and the rationale and assurance evidence behind every specialized or custom development decision made because commercial items could not meet requirements.
  • Period-End Roll-Forward / Rollover Testing — Internal Audit · 2 steps
    Bridge an approved interim control test through period end by assessing change, remaining occurrences, incremental evidence, and unresolved exceptions.
  • Period-End Roll-Forward Testing — Internal Audit; with Finance · 3 steps
    Bridge interim testing to period end using the remaining population, control changes, additional evidence and a bounded combined conclusion.
  • Periodic User Access Review — IT · 2 steps
    Run a periodic entitlement recertification for a system, evidence reviewer decisions, and confirm that required revocations were executed.
  • Personal Data Quality & De-identification — Privacy · 7 steps
    Run the recurring PII data-hygiene cycle: check personal data for accuracy, relevance, timeliness, and completeness, correct or delete failing records and notify recipients, execute individual correction requests, and de-identify data where full identifiers are not required.
  • Personnel Screening, Agreements & Sanctions Administration — HR · 8 steps
    Apply proportional personnel screening, adjudicate adverse findings and obtain required signed security agreements before access; determine consistent sanctions on substantiated violations and retain the access/notification evidence and rescreen record.
  • Physical Asset Custody & Count Program — Finance; with Facilities · 7 steps
    Operate the standing physical-asset custody and count program each cycle — counting and reconciling cash, negotiable instruments, and accounting records to the books, verifying custody-log authorization, and confirming storage and retention safeguards — with audit-ready evidence captured as you go. Each cycle's instance operates the existing UC-FIN-10 custody-and-count Control, enriching that control's operating history rather than creating a new record.
  • Physical Environment Monitoring Review — Facilities · 6 steps
    Operate the monthly physical-environment monitoring review across facilities hosting systems and data: sweep badge and entry logs, camera surveillance coverage and flagged footage, and environmental sensor alerts, and feed every confirmed anomaly into security-event analysis.
  • Platform Isolation & Separation Enforcement — IT · 5 steps
    Operate the semiannual platform isolation cycle: verify user, system-management, and security functions remain separated across sensitivity domains via partitioning or virtualization, confirm shared resources are cleared or sanitized between users and processes while covert-channel bandwidth stays under threshold, and verify hardware- and software-enforced separation mechanisms keep critical code protected from runtime alteration.
  • Policy Change — Compliance & Legal · 2 steps
    Review a policy redline and its obligation impact, obtain authorized approval, publish the approved version and retain the change record.
  • Policy Exception & Risk Acceptance — Risk Management; with Compliance & Legal · 6 steps
    Manage policy exceptions end-to-end: justify, risk-assess, compensate, approve time-bound, register with expiry, and re-review.
  • Policy Lifecycle Management — Compliance & Legal; with Executive · 8 steps
    Run a Policy item through its full lifecycle — drafting and control/authority linkage, stakeholder review, approval, publication, workforce attestation, monitoring, and scheduled refresh.
  • Privacy Breach Assessment & Notification — Privacy; with IT · 9 steps
    Assess a personal-data breach handed off from incident response: scope the exposure, decide notifiability against GDPR, US state, and HIPAA clocks, notify regulators and affected individuals on time, and close with a defensible breach-register entry.
  • Privacy Program Operations (Consent, Complaints & Sharing) — Privacy · 6 steps
    Run the standing Privacy Program Operations process on a recurring cycle: reconcile consent and preferences against processing activities, resolve privacy complaints with an accounting of disclosures, and govern data-sharing agreements against actual flows — logging every exception, complaint, and agreement gap as a tracked Issue.
  • Privacy Safeguards & Notice Management — Privacy · 7 steps
    Run the privacy office's periodic program cycle against the standing Privacy Program process: refresh the inventory of statutory, regulatory, and contractual privacy requirements, confirm PII-protection accountability, verify that administrative, technical, and physical safeguards remain appropriate to the data held, remediate gaps, and keep external privacy notices and required registrations accurate to actual processing and delivered at the point of collection.
  • Privileged Access & Authorization Model Management — IT · 6 steps
    Operate the quarterly privileged-access control cycle: recertify every privileged account against its business justification and time bound, enforce separate accounts for administrators, review logged utility-program use, and process application-allowlist changes so unauthorized software stays blocked. In the same cycle, maintain the role and security-attribute authorization model against organizational change and spot-test that enforcement points across applications, databases, and infrastructure apply approved authorizations to sensitive data, source code, and administrative functions.
  • Privileged Access Review — IT · 2 steps
    Review privileged, service, and emergency accounts on a system for continued business justification, supporting activity, and compensating monitoring.
  • Process Narrative & Walkthrough — Internal Audit · 1 steps
    Document an end-to-end process, corroborate the narrative through a representative walkthrough, and approve a traceable current-state record.
  • Process Walkthrough & Design Assessment — Internal Audit · 2 steps
    Perform a SOX process walkthrough, update the ICFR narrative and control mapping, and document design observations for management follow-up.
  • Production Operations & Processing Integrity Cycle — IT; with Finance · 6 steps
    Run the scheduled production-processing cycle, resolve batch and monitoring incidents, verify recoverability and input/output integrity, and certify the evidence with owned carry-forwards.
  • Public Content & External Sharing Authorization — IT; with Compliance & Legal · 5 steps
    Operate the standing publication-authorization capability: verify only trained, designated individuals post to public-facing systems, confirm external information shares carry information-owner authorization consistent with classification and sharing agreements, and run the quarterly sweep that re-verifies the documented no-authentication actions and inspects public content for nonpublic exposure.
  • Quality Assurance & Improvement Program Cycle — Internal Audit · 10 steps
    Operate the QAIP cycle on a per-cycle Audit item — ongoing-monitoring evidence, periodic self-assessment, external quality assessment support, improvement planning, and board reporting — producing the per-standard conformance ratings matrix, below-GC finding Issues, and the QAIP results report handed to board reporting.
  • Quarterly 302/906 Sub-Certification Cascade — Finance; with Executive · 6 steps
    The SOX PMO runs the quarterly sub-certification ritual that underpins the principal officers' Section 302 and 906 certifications: it maintains the certifier hierarchy, refreshes the questionnaire for period changes, launches the cascade from process owners through controllers to segment CFOs, chases completion to the cutoff, and triages every exception or qualification raised. Material items reach the disclosure committee before the CEO and CFO sign, and the certification population and its evidence are archived with the period's filing support.
  • Quarterly Board & Audit-Committee GRC Reporting — Risk Management; with Internal Audit, Executive · 6 steps
    Compile the quarterly GRC board pack across risk profile, audit, SOX, regulatory deadlines, control health, incidents, issues, and decisions.
  • Quarterly Third-Party AI Evaluation Cycle — AI Governance; with Procurement · 7 steps
    Operate the quarterly cycle in which the AI product team commissions an independent third-party evaluator to test every in-scope AI system for adversarial robustness and jailbreak resistance, harmful and out-of-scope outputs, agent-specific high-risk outputs, hallucination rates, and unsafe or unauthorized tool calls. The test scope, categories, and pass thresholds are fixed in advance, then every finding is triaged against those pre-agreed thresholds by category and severity. Failed categories are driven through remediation and evaluator retest, and the evaluator report is formally accepted or returned for rework. The cycle closes by publishing the accepted evaluation evidence — trust-portal summary, customer-facing attestation, and evidence register — and tuning the guardrails from what the evaluation found.
  • Recruiting and Hiring Decision — HR · 4 steps
    Approve a requisition, review candidates against job criteria, assess interview evidence and authorize an offer handoff.
  • Regulatory Change Intake & Impact Assessment — Compliance & Legal · 2 steps
    Validate a new or amended external obligation against its authoritative source, determine applicability, and assess the impact on controls, policies, processes and systems.
  • Regulatory Compliance Attestation Cycle — Compliance & Legal; with Executive · 10 steps
    Compile evidence for a regulation or obligation set, resolve gaps, route officer certification, and archive the attestation package.
  • Regulatory Exam & External Audit Management — Compliance & Legal · 10 steps
    Manage a live regulator exam or external audit from notification intake through request fulfillment, QC'd evidence release, fieldwork support, findings response, and commitment closure.
  • Regulatory Horizon Scanning & Triage — Compliance & Legal · 5 steps
    Ingest regulator publications, classify applicability, assign owners, and route relevant changes into impact analysis.
  • Regulatory Impact Analysis & Obligation Mapping — Compliance & Legal · 9 steps
    Parse regulatory changes into obligations, map them to policies and controls, identify gaps, and hand confirmed gaps to implementation.
  • Regulatory Obligation Implementation — Compliance & Legal · 7 steps
    Implement a new or changed regulatory obligation from gap analysis through policy update, control design, process operationalization, and coverage validation.
  • Remediation Delivery — Business Operations · 1 steps
    Agree observable closure criteria and deliver one owned corrective action; independent validation remains in the parent finding workflow.
  • Remediation Delivery & Validation — Business Operations · 3 steps
    Plan and deliver corrective action, independently validate it against agreed closure criteria, and approve a traceable remediation record.
  • Requirement Applicability & Control Mapping — Compliance & Legal · 2 steps
    Interpret a requirement, determine supported applicability, map obligations to controls and evidence, and approve the mapping record.
  • Resilience & Failover Readiness Verification — IT · 5 steps
    Each quarter, verify that the alternate storage site, alternate processing capability, and diverse telecommunications the organization's recovery objectives depend on remain current, separated from primary-site hazards, and able to assume operations within RTO, and that safe-mode, alternate-communications, and alternate-security-mechanism designs on critical systems are configured and ready. Findings convert into owned corrective actions, with any recovery-time-impacting gap escalated immediately rather than held for end-of-cycle closure.
  • Resilient Architecture & Non-Persistence Operations — IT · 5 steps
    Operate the quarterly non-persistence and resilient-architecture program against the existing NIST 800-53 SI/SC resilience Control: refresh designated non-persistent components and services from known-good trusted sources, purge stale information, verify diverse sourcing and fragmentation of high-value data, and review thin-node, technology-heterogeneity, and distributed processing and storage posture against current threats.
  • Risk & Control Self-Assessment (RCSA) Program — Business Operations; with Risk Management · 8 steps
    Run first-line risk and control self-assessment with evidence-backed owner ratings and native attestations, second-line challenge and calibration, explicit unassessed units, risk-register updates, remediation or acceptance handoffs, and risk-committee reporting.
  • Risk & Resilience Framework Governance — Risk Management; with Executive · 8 steps
    Establish, approve, and maintain the enterprise risk management framework and its ICT operational-resilience (DORA) and regulated-technology extensions - accountabilities, resources, processes, and risk tolerance - with management-body sponsorship, planned implementation across the organization, and at-least-annual review.
  • Risk Appetite & Tolerance Calibration — Risk Management · 2 steps
    Set or recalibrate the appetite statement and tolerance thresholds for a risk, test the current position against them, and approve the escalation record.
  • Risk Appetite Definition & Board Reporting — Executive; with Risk Management · 8 steps
    Define appetite statements, tolerances, KRIs, board approval, monitoring, and ERM reporting for governance oversight.
  • Risk Assessment and Treatment Review — Risk Management · 2 steps
    Apply the approved rating method to a defined scenario, evaluate controls, select treatment and approve residual risk and monitoring.
  • Risk Communication, Reporting & Performance Review — Risk Management · 8 steps
    Each quarter - and on an event-driven basis whenever a significant matter arises - the ERM office runs structured stakeholder consultation across the risk process, including supplier and third-party risk and human and cultural factors, and delivers the cadenced risk, control, and performance reporting packages internally at every level and to external stakeholders and partners. The same cycle reviews risk-management and internal-control performance against the framework's design and intended outcomes with accountable management, then converts the lessons into owned, tracked improvement actions driven to closure.
  • Risk Register Intake — Risk Management · 4 steps
    Capture a new risk from initial identification through inherent scoring, control mapping, residual scoring, and owner assignment with a defined review cadence.
  • Secure Baseline & Integrity Drift Management — IT · 7 steps
    Operate the monthly secure-baseline cycle: maintain and approve hardening baselines and least-functionality settings against accepted industry standards, run configuration-compliance scans and remediate drift as findings, triage file-integrity, hash/signature, and secure-boot alerts while verifying security functions operate correctly, and keep the configuration management plan and procedures current annually or after significant environment change.
  • Secure Connectivity & Network Trust Services Operation — IT · 5 steps
    Operate the quarterly cycle that re-authorizes remote, wireless, and organization-controlled mobile access, sweeps for rogue connections, and verifies session-trust and out-of-band credential-delivery protections. The same cycle confirms DNSSEC-authenticated, fault-tolerant name resolution and clock synchronization to authoritative time sources.
  • Secure Development & Release Security Gate — IT · 7 steps
    Operate the secure-development lifecycle at every release: engineer security and privacy-by-design requirements into the build, execute the documented security test plan with retained evidence against defined acceptance criteria, and verify hardened runtime behavior before production. Between releases, track vulnerability remediation and patching within risk-based timeframes and queue unsupported software for replacement at the quarterly portfolio review.
  • Secure SDLC Phase-Gate Program — IT · 8 steps
    Operate the secure SDLC phase-gate program that every development initiative passes through: chair the intake, requirements, design, and build/release gates against the documented secure development lifecycle, verifying governed scope and security resourcing, approved application-security requirements, secure-architecture review, and secure-coding and trust-boundary input-validation evidence at each stage. Monitor adherence to and performance of the process itself and track every exception to closure.
  • Security & Privacy Architecture Review Board — IT; with Privacy · 9 steps
    Operate the standing Security & Privacy Architecture Review Board: maintain the enterprise, security, and privacy architecture views that describe how systems, information flows, and protections align with mission and strategy, review solution designs and acquisition decisions for architectural alignment, and push approved updates into system security plans and acquisition requirements.
  • Security Awareness Training Campaign — IT; with HR · 4 steps
    Run a security awareness campaign end-to-end: curriculum, launch, completion tracking, phishing simulation, escalation, and effectiveness reporting.
  • Security Control Assessment & POA&M Remediation — IT; with Compliance & Legal · 7 steps
    Enrich the engagement Audit item: assess a system's controls with 800-53A methods, record determinations, open a POA&M Issue per gap, re-validate remediation, and issue the Security Assessment Report (SAR).
  • Security Monitoring & Detection Operations — IT · 7 steps
    Run the SOC's weekly monitoring cycle as a recurring instance on the standing continuous security-monitoring control: verify continuous monitoring is deployed and functioning under the documented strategy across hosts, networks, and applications, and report security status to the defined roles. Work the central SIEM analysis queue to correlate and enrich events with threat intelligence, triage flagged anomalies to genuine security events, and verify the health, coverage, and tuning of the continuous protection services.
  • Security Policy Suite Review — IT; with Compliance & Legal · 6 steps
    Operate the annual (and change-triggered) review cycle for the full security policy suite across eight policy families: secure acquisition, development, configuration-management, and maintenance; asset, media, and physical protection; access control, identification, and personnel security; communications protection and cryptography; security awareness and cyber-hygiene; audit-logging, monitoring, and system integrity; contingency planning and disruption mitigation; and incident response. Each policy is reviewed against current risk and threat inputs, updated, reapproved, and disseminated with communication and acknowledgment tracking captured as one evidence set.
  • SOC 2 Availability Assessment — Internal Audit · 1 steps
    Assess design readiness for Availability with documented evidence, findings and reviewer conclusions.
  • SOC 2 Confidentiality Assessment — Internal Audit · 1 steps
    Assess design readiness for Confidentiality with documented evidence, findings and reviewer conclusions.
  • SOC 2 Privacy Criteria Assessment — Internal Audit · 1 steps
    Assess design readiness for Privacy with documented evidence, findings and reviewer conclusions.
  • SOC 2 Processing Integrity Assessment — Internal Audit · 1 steps
    Assess design readiness for Processing Integrity with documented evidence, findings and reviewer conclusions.
  • SOC 2 Readiness & Evidence Collection — IT; with Compliance & Legal · 5 steps
    Get an already-opened SOC examination Audit engagement audit-ready for SOC 2/SOC 1: map the Control library to each in-scope Trust Services Criterion, close readiness gaps, run the PBC evidence request list with QA, and coordinate the CPA firm — producing the criteria-to-control mapping matrix and gap matrix, the owned PBC request list, the QA'd evidence set, and the cross-referenced PBC response package.
  • SOC 2 Reporting and Management Assertion — Compliance & Legal; with Executive · 2 steps
    Prepare the SOC 2 description and management assertion, reconcile subservice reliance, and approve the auditee report package.
  • SOC 2 Trust Services Readiness — Internal Audit · 3 steps
    Assess SOC 2 CC1–CC9 design readiness, reconcile scoped category assessments, and approve a criterion-level readiness disposition with evidence, findings and owned actions.
  • SOC 2 Type II Interim Testing — Internal Audit · 2 steps
    Perform SOC 2 Type II interim walkthroughs and control testing, then triage exceptions for remediation and retest.
  • SOC Report, Subservice & CUEC Review — Risk Management · 2 steps
    Evaluate a service-organization report, subservice coverage, exceptions, and complementary user-entity controls for a governed reliance decision.
  • SOX Annual Planning & Risk Assessment — Finance · 2 steps
    Plan the annual SOX program through materiality, entity and account scoping, risk and control mapping, reliance strategy, calendar, and governance approval.
  • SOX Control Testing — Internal Audit · 2 steps
    Native SAMPLE approves history, attributes and reproducible selection; TEST independently approves evidence, exceptions and the published SOX result for the fiscal year.
  • SOX Deficiency Remediation — Finance · 7 steps
    Track a control deficiency from initial identification and severity grading through root-cause analysis, remediation execution, and validated closure.
  • SOX IPE Validation — Internal Audit; with Finance · 7 steps
    Validate an Information Produced by the Entity (IPE) report for completeness and accuracy, then decide whether it is reliable control evidence or a deficiency.
  • SOX ITGC Testing — Internal Audit; with IT, Finance · 8 steps
    Scope and test SOX-relevant ITGCs by referencing the controls-owned 800-53 catalog and test scripts rather than rebuilding procedures.
  • SOX Key Control Operation (Close Cycle) — Finance · 5 steps
    Operate close-cycle reconciliations, management review and journal-entry approvals with validated IPE, independent review and a control-indexed period sub-certification.
  • SOX Key Control TOD/TOE Test — Internal Audit; with Finance · 10 steps
    Test key controls for design and operating effectiveness, including walkthrough, sampling, IPE linkage, exception handling, and reviewer sign-off.
  • SOX Process Walkthrough — Finance; with Internal Audit · 7 steps
    Capture an end-to-end process walkthrough and identify the key controls inside it, producing a walkthrough memo and draft control records.
  • SOX Scoping Decision — Finance · 4 steps
    Decide whether a process is SOX-relevant, then scope it or document the exclusion.
  • Strategic Context & Objectives Alignment Cycle — Executive; with Risk Management · 9 steps
    Annually refresh the organization's documented mission, stakeholder expectations, and critical objectives and dependencies, and communicate that context to those who scope and prioritize risk work. Realign strategy with mission and risk profile, cascade objectives and publish the roadmap, then close by documenting mission-essential business processes and information-protection needs as the approved basis for risk-assessment scoping.
  • Subservice Organization & Third-Party Personnel Oversight — Procurement; with HR · 7 steps
    On the annual per-vendor cycle with quarterly issue follow-up, the vendor risk manager enriches each subservice organization's Vendor register entry, verifies its contracts and assurance reports bind it to the security, data-processing, and third-party personnel-security commitments matching its mapped control objectives, and maps the assurance report's complementary user-entity controls (CUECs) to the organization's internal Controls. Every identified gap becomes a tracked Issue followed to closure, and the cycle closes into an archived, auditor-ready vendor file.
  • Substantive Testing & Data Analytics — Internal Audit · 2 steps
    Validates a test population, draws a reproducible sample sized to risk, runs whole-population analytics (duplicates, gaps, three-way match) alongside it, evaluates and projects exceptions, and concludes on the tested FSLI assertion(s).
  • Supplier Service Registry & Critical Supplier Assessment — Procurement · 8 steps
    The vendor risk manager maintains the register of supplier-delivered services - the systems and data each service touches and its internal relationship owner - keeping it current as services onboard, change, or exit, and runs security and risk assessments of critical suppliers before acquisition or engagement, recording results and triggering reassessment when services, dependencies, or risk profiles change.
  • Supply-Chain Integrity & OPSEC Operations — IT; with Procurement · 5 steps
    Operate the standing supply-chain integrity program: inspect each period's critical system and component receipts for tamper-evidence and authenticity, keep provenance and chain-of-custody records current, and disposition suspected counterfeits with inspector-training refresh where lapses appear. In the same monthly cycle, review the register of sensitive supply-chain information to confirm disclosure remains limited to parties with a validated need to know and remediate any overexposure found.
  • System and Third-Party Risk Review — Risk Management; with IT, Procurement · 2 steps
    Evaluate system criticality, data flows, supplier evidence, gaps and compensating controls before accepting its risk posture.
  • System Categorization, Security Planning & Authorization — IT; with Compliance & Legal · 7 steps
    Operate the per-system control — anchored on the existing NIST 800-53 system-authorization Control in the library, one workflow instance per system per authorization cycle — that categorizes each system and its information by confidentiality, integrity, and availability impact with criticality analysis and accountable-official approval, develops and maintains the approved system security and privacy plan (PL-2), authorizes and documents internal system connections (CA-9), and secures the formal authorization-to-operate decision before production use, with reauthorization tracked on frequency and significant change (CA-6). Named deliverables: the security categorization summary and criticality analysis, the system security and privacy plan, the internal-connection authorization register, and the signed authorization-to-operate decision with its plan of action and milestones.
  • System ITGC Operation — IT · 3 steps
    Operate account lifecycle, authentication, recertification, production-change review and vendor-assurance review for one system.
  • Technical Security Testing & Pentest Engagement — IT · 6 steps
    Plan, execute, rate, report, and retest an authorized penetration test on an existing IT-audit engagement record — producing the validated-findings register, the penetration-test report, and a per-control assurance conclusion — mapping each finding to affected controls and secure-design defects and confirming fixes.
  • Technology Investment & Project Risk Governance — Executive; with IT · 7 steps
    The quarterly technology investment board applies defined benefit, cost, and risk criteria to evaluate, prioritize, and monitor the technology and innovation portfolio, taking corrective action where value is not being realized. The cycle carries the annual capital-planning leg that allocates security funding and personnel to the risk strategy and enforces security-risk sections in every project gate from initiation through delivery.
  • Technology Lifecycle & Capacity Review — IT · 6 steps
    Quarterly cycle that reconciles the solution asset record for components, ownership, and licensing, acts on use and cost optimization, and drives components approaching end of support to a replacement or upgrade plan or a documented, risk-accepted compensating control before support lapses. The same cycle monitors solution availability and capacity against current and forecast demand, raises corrective plans for projected shortfalls, and validates that agreed targets were met in the prior period.
  • Third-Party ICT Vendor Regulatory Assurance — Procurement; with Compliance & Legal · 5 steps
    Assess third-party and ICT vendor regulatory obligations, gaps, remediation, and register updates for DORA, FFIEC, and related regimes.
  • Third-Party Risk Program & Vendor Oversight Cycle — Procurement; with Executive · 6 steps
    Each quarter, the Vendor Risk Program Lead refreshes the third-party risk program's governing artifacts - the SCRM plan and policy, the criticality-ranked vendor inventory, the DORA Article 28(3) contract register, concentration-risk view, and critical-provider exit-strategy status - then executes this cycle's tiered reassessments, drives recorded vendor risks to remediation, and confirms external/cloud provider oversight and supplier incident-notification coverage remain current.
  • Third-Party Vendor Assurance Engagement — Internal Audit; with Procurement · 8 steps
    Run an IA-led third-party assurance engagement covering governance, risk tiering, control environment, monitoring, exclusions, and reporting.
  • Third-Party Vendor Risk Lifecycle — Procurement · 9 steps
    Operate the enterprise vendor risk lifecycle from inventory and questionnaire through SOC review, C-SCRM controls, contract gates, monitoring, and reassessment.
  • Threat Intelligence & Insider Threat Program — IT · 7 steps
    Operate the threat program each cycle: ingest and share threat intelligence, run intel-driven hunts, and review insider-threat indicators with a governed response.
  • Transfer & Access Modification — IT · 2 steps
    Modify a mover access for a new role, remove entitlements the prior role no longer justifies, and approve the modification record.
  • User Access Review & Recertification — IT; with Finance · 5 steps
    Quarterly user access review: extract entitlements, certify with managers, revoke and evidence removals across in-scope systems.
  • User Activity & External Exposure Monitoring — IT; with HR · 7 steps
    Operate the monthly cycle of the standing user-activity and external-exposure monitoring control: review captured privileged and remote session activity and personnel technology usage against acceptable-use expectations, restricting access to authorized reviewers and routing findings to HR and legal counsel per the disclosed monitoring terms. In the same cycle, sweep external open-source and dark-web channels for improperly disclosed organizational information, alerting designated personnel and initiating takedown on discovery, with every confirmed finding from both halves recorded as an Issue linked to the control and consolidated into one restricted case log feeding security-event evaluation.
  • Vendor Due Diligence & Contracting Gate — Procurement; with Privacy · 9 steps
    For each new vendor engagement or contract renewal, this pre-contract gate runs on the vendor's register entry (the Vendor item — created for a net-new vendor, enriched for a renewal): tier the vendor by criticality, run proportionate due diligence across security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision before binding the contract to required security, privacy, and applicable regulatory clauses. It has no upstream workflow — the engagement trigger is its own entry point. Named deliverables: the vendor due-diligence report, the documented risk-acceptance decision, the executed contract bound to its security/privacy/regulatory clauses, and — where personal data is involved — the signed written privacy commitments obtained before access begins. On close it enrolls the Vendor in ongoing monitoring and hands the archived gate record to the third-party risk monitoring / vendor oversight lifecycle.
  • Vendor Offboarding & Secure Termination — Procurement; with IT · 8 steps
    Execute a vendor's contractual exit provisions end to end on each relationship termination: revoke all access and credentials, transition the service to its successor, return or verifiably destroy organizational data, securely dispose of dedicated components and tooling using defined techniques, and retain the required post-relationship evidence.
  • Vendor Risk Assessment and Disposition — Procurement; with Risk Management, IT · 2 steps
    Assess the actual supplier's contracts, assurance reports, access, continuity and exit evidence; obtain expert challenge and an authorized reliance disposition.
  • Vendor SOC 1/SOC 2 Report Review & CUEC Mapping — Procurement; with IT · 5 steps
    Review vendor SOC reports, exceptions, CUECs, bridge letters, and reliance conclusions for controls assurance and service-organization dependencies.
  • Vulnerability & Patch Management Cycle — IT · 6 steps
    Recurring vulnerability management cycle: scan, triage by severity, patch on SLA, verify by rescan, and risk-accept residuals with expiry.
  • Workplace & Remote Work Security Cycle — IT; with HR, Facilities · 6 steps
    Operate the quarterly workplace and remote-work security cycle: walk offices for clear-desk, clear-screen, and output-device compliance, and verify and enforce remote-working device, privacy, environment, and connectivity attestations before granting access. Review the approved alternate-work-site list, assess control effectiveness, and confirm workers there have a functioning incident-reporting channel.
  • Year-End Deficiency Aggregation & Severity Evaluation — Finance · 10 steps
    Freeze the year-end deficiency register, prove its completeness against testing results, aggregate related deficiencies, and evaluate severity through compensating-control and prudent-official conclusions that feed 302/404 certifications and audit-committee reporting.
  • Year-End Planning & Roll-Forward — Finance · 2 steps
    Plan and govern SOX year-end and roll-forward coverage based on interim results, changes, deficiencies, remaining populations, and reporting deadlines.
Privacy Terms