- AI Governance Framework, Roles & Obligations Review — AI Governance; with Executive · 7 steps
Review AI policy, role competence, resource dependencies and provider or deployer obligations; approve necessary changes, resolve gaps and retain the published policy and cycle evidence.
- Board Risk & Internal Control Oversight Cycle — Executive; with Risk Management · 7 steps
Support the independent board’s risk and internal-control oversight, annual governance-framework evaluation and approval of strategy and policies; adopt the minutes and carry an owned directives register into implementation and the next cycle.
- CSF 2.0 Profile & Maturity Assessment — IT; with Executive · 5 steps
Build a controls-scoped CSF Current Profile, Target Profile, Tier assessment, gap plan, and CISO-ready roadmap.
- Domain Oversight and Management Review — Risk Management; with Executive · 1 steps
Assess the domain’s register, operating evidence, risk posture and control exceptions, then record management priorities, resources and escalations with domain-owner and independent-reviewer approval.
- ESG-Related Risk Materiality & Integration — Risk Management; with Executive · 5 steps
Assess ESG impacts, risks and opportunities with affected stakeholders and information users; validate material topics, evaluate responses and disclosure readiness, and govern gaps or acceptance before board reporting.
- Fraud Risk Assessment & Anti-Override Control Review — Finance; with Executive · 6 steps
Lead the annual (or event-triggered) fraud risk assessment across fraudulent reporting, asset misappropriation, and corruption, evaluating incentives, opportunities, and rationalizations while explicitly rating the risk of management override of controls. Recalibrate the anti-override control set - journal-entry review criteria and significant-estimates scrutiny - and report refreshed results and mitigations to the audit committee.
- Information Security Program Governance Review — IT; with Executive · 6 steps
Operate the CISO's recurring security program governance review on the standing "Information Security Program Governance" Process item: each quarter enrich the senior-management-approved information security program plan (its Policy item) and keep security roles, authorities, and reporting lines current, and each year deliver the written board report confirming the CISO mandate and run the security workforce competency review, so the program stays approved, resourced, and owned through organizational change.
- Internal Audit Charter, Independence & Board Governance Cycle — Internal Audit; with Executive · 8 steps
Run the internal audit function's board-governance cycle: deliver the CAE's functional reporting and executive sessions to the audit committee, secure committee action on the CAE's appointment, evaluation, remuneration, and the audit plan and budget, and reaffirm the function's organizational independence in writing. Lead the periodic board review and reapproval of the audit mandate and charter with its unrestricted-access provisions, execute the stakeholder communication plan across the board, management, regulators, and external auditors, and retain the governance evidence.
- ISMS Internal Audit & Management Review — Internal Audit; with IT, Executive · 6 steps
Run the ISMS clause 9.2 internal audit and clause 9.3 management review: findings, corrective actions, review inputs, decisions, and follow-up.
- IT Governance Objective Review (COBIT) — Executive; with IT · 4 steps
Assess COBIT capability from evidence and owner interviews, compare it with approved targets and commit improvements where needed; obtain board direction and review actual progress through the closing cadence.
- Policy Lifecycle Management — Compliance & Legal; with Executive · 8 steps
Run a Policy item through its full lifecycle — drafting and control/authority linkage, stakeholder review, approval, publication, workforce attestation, monitoring, and scheduled refresh.
- Quarterly 302/906 Sub-Certification Cascade — Finance; with Executive · 6 steps
The SOX PMO runs the quarterly sub-certification ritual that underpins the principal officers' Section 302 and 906 certifications: it maintains the certifier hierarchy, refreshes the questionnaire for period changes, launches the cascade from process owners through controllers to segment CFOs, chases completion to the cutoff, and triages every exception or qualification raised. Material items reach the disclosure committee before the CEO and CFO sign, and the certification population and its evidence are archived with the period's filing support.
- Quarterly Board & Audit-Committee GRC Reporting — Risk Management; with Internal Audit, Executive · 6 steps
Compile the quarterly GRC board pack across risk profile, audit, SOX, regulatory deadlines, control health, incidents, issues, and decisions.
- Regulatory Compliance Attestation Cycle — Compliance & Legal; with Executive · 10 steps
Compile evidence for a regulation or obligation set, resolve gaps, route officer certification, and archive the attestation package.
- Risk & Resilience Framework Governance — Risk Management; with Executive · 8 steps
Establish, approve, and maintain the enterprise risk management framework and its ICT operational-resilience (DORA) and regulated-technology extensions - accountabilities, resources, processes, and risk tolerance - with management-body sponsorship, planned implementation across the organization, and at-least-annual review.
- Risk Appetite Definition & Board Reporting — Executive; with Risk Management · 8 steps
Define appetite statements, tolerances, KRIs, board approval, monitoring, and ERM reporting for governance oversight.
- SOC 2 Reporting and Management Assertion — Compliance & Legal; with Executive · 2 steps
Prepare the SOC 2 description and management assertion, reconcile subservice reliance, and approve the auditee report package.
- Strategic Context & Objectives Alignment Cycle — Executive; with Risk Management · 9 steps
Annually refresh the organization's documented mission, stakeholder expectations, and critical objectives and dependencies, and communicate that context to those who scope and prioritize risk work. Realign strategy with mission and risk profile, cascade objectives and publish the roadmap, then close by documenting mission-essential business processes and information-protection needs as the approved basis for risk-assessment scoping.
- Technology Investment & Project Risk Governance — Executive; with IT · 7 steps
The quarterly technology investment board applies defined benefit, cost, and risk criteria to evaluate, prioritize, and monitor the technology and innovation portfolio, taking corrective action where value is not being realized. The cycle carries the annual capital-planning leg that allocates security funding and personnel to the risk strategy and enforces security-risk sections in every project gate from initiation through delivery.
- Third-Party Risk Program & Vendor Oversight Cycle — Procurement; with Executive · 6 steps
Each quarter, the Vendor Risk Program Lead refreshes the third-party risk program's governing artifacts - the SCRM plan and policy, the criticality-ranked vendor inventory, the DORA Article 28(3) contract register, concentration-risk view, and critical-provider exit-strategy status - then executes this cycle's tiered reassessments, drives recorded vendor risks to remediation, and confirms external/cloud provider oversight and supplier incident-notification coverage remain current.