Risk Management Workflows

Open-source workflows owned by or involving Risk Management. Review the steps, responsibilities and evidence, then download templates for your AssureSwarm instance.

All workflows 212 IT 92 HR 11 Finance 27 Internal Audit 45 Risk Management 32 Compliance & Legal 32 Privacy 11 Procurement 15 Executive 20 AI Governance 11 Facilities 7 Business Operations 9
  • Board Risk & Internal Control Oversight Cycle — Executive; with Risk Management · 7 steps
    Support the independent board’s risk and internal-control oversight, annual governance-framework evaluation and approval of strategy and policies; adopt the minutes and carry an owned directives register into implementation and the next cycle.
  • Combined Assurance Mapping — Internal Audit; with Risk Management · 7 steps
    Map effective assurance across the Three Lines, resolve self-review safeguards, assess independent reliance and agree coverage commitments; govern remaining gaps and deliver the map and evidence to audit-committee reporting.
  • Continuous Controls Monitoring (ISCM) Cycle — IT; with Risk Management · 4 steps
    Run recurring control monitoring by collecting metrics, comparing thresholds, triaging degradation, updating POA&M, reporting health, and tuning cadence.
  • Control Design — Business Operations; with Risk Management · 3 steps
    Design a new control from objective definition through attribute specification, risk mapping, evidence and test approach definition, and final control record creation.
  • Control Exception Evaluation and Remediation — Internal Audit; with Risk Management · 2 steps
    Evaluate exception scope, impact, severity and compensating controls, then obtain management-owned remediation and authorized escalation.
  • Control Library Lifecycle — Risk Management; with Finance · 3 steps
    Review proposed controls for duplication, classification and risk-policy-process linkage; govern publication and rework, then review operating changes and preserve history when a control is retired.
  • Domain Oversight and Management Review — Risk Management; with Executive · 1 steps
    Assess the domain’s register, operating evidence, risk posture and control exceptions, then record management priorities, resources and escalations with domain-owner and independent-reviewer approval.
  • Emerging Risk & Horizon Scan — Risk Management · 1 steps
    Scan the forward horizon for signals of an emerging exposure, assess plausibility and velocity, and decide whether it enters the register or stays on the watchlist.
  • Enterprise GRC Platform Integration Bridge — IT; with Risk Management · 5 steps
    Define mappings, migrate or provision records, run bidirectional sync, monitor health, resolve conflicts, and confirm system-of-record coverage.
  • Enterprise Risk Assessment & Portfolio Oversight Cycle — Risk Management · 8 steps
    Assess enterprise risks on a fixed appetite and scoring basis, obtain owned responses and appropriate acceptance authority, and approve the residual portfolio and movement narrative for governance reporting.
  • Enterprise Risk Register Lifecycle — Risk Management · 6 steps
    Maintain the risk register with distinct Three Lines responsibilities, evidence-backed owner-approved ratings and calibrated KRIs; govern treatment or acceptance and hand the maintained portfolio to assessment and appetite reporting.
  • Enterprise Risk Treatment Operations Cycle — Business Operations; with Risk Management · 5 steps
    Assess enterprise threats and opportunities, implement owned treatment for tolerance breaches and reassess residual exposure; obtain required senior acceptance and approve a current register, portfolio report and change-monitoring record.
  • ERM Risk Identification & Register Refresh — Risk Management · 1 steps
    Run a periodic enterprise risk identification cycle, consolidate candidate risks, and approve the resulting register changes.
  • ESG-Related Risk Materiality & Integration — Risk Management; with Executive · 5 steps
    Assess ESG impacts, risks and opportunities with affected stakeholders and information users; validate material topics, evaluate responses and disclosure readiness, and govern gaps or acceptance before board reporting.
  • Framework Adoption & Cross-Mapping — Compliance & Legal; with Risk Management · 5 steps
    Set obligation- and appetite-based framework targets, assess current evidence and crosswalk coverage, and govern risk-ranked gaps; deliver approved policy/control work with a maintained mapping table and versioned adoption record.
  • GCP Physical and Environmental Subservice Reliance — IT; with Risk Management · 5 steps
    Evaluate GCP assurance-report scope, physical and environmental controls, exceptions and user responsibilities; record a bounded reliance decision rather than claiming to operate provider facilities.
  • ISMS Risk Assessment & Treatment Cycle — IT; with Risk Management · 7 steps
    Perform ISO 27005 risk assessment and treatment planning to produce current risks and SoA inputs for ISO 27001 control applicability.
  • Issue Remediation and Verification — Risk Management; with Business Operations · 2 steps
    Agree cause-based, separately owned remediation actions and validate each by its committed method; approve the finding’s closure only when every linked action is validated and closed.
  • Issue Triage & Disposition — Risk Management · 2 steps
    Substantiate a reported issue, assess its severity and cause, select a governed disposition, and approve the triage record.
  • Policy Exception & Risk Acceptance — Risk Management; with Compliance & Legal · 6 steps
    Manage policy exceptions end-to-end: justify, risk-assess, compensate, approve time-bound, register with expiry, and re-review.
  • Quarterly Board & Audit-Committee GRC Reporting — Risk Management; with Internal Audit, Executive · 6 steps
    Compile the quarterly GRC board pack across risk profile, audit, SOX, regulatory deadlines, control health, incidents, issues, and decisions.
  • Risk & Control Self-Assessment (RCSA) Program — Business Operations; with Risk Management · 8 steps
    Run first-line risk and control self-assessment with evidence-backed owner ratings and native attestations, second-line challenge and calibration, explicit unassessed units, risk-register updates, remediation or acceptance handoffs, and risk-committee reporting.
  • Risk & Resilience Framework Governance — Risk Management; with Executive · 8 steps
    Establish, approve, and maintain the enterprise risk management framework and its ICT operational-resilience (DORA) and regulated-technology extensions - accountabilities, resources, processes, and risk tolerance - with management-body sponsorship, planned implementation across the organization, and at-least-annual review.
  • Risk Appetite & Tolerance Calibration — Risk Management · 2 steps
    Set or recalibrate the appetite statement and tolerance thresholds for a risk, test the current position against them, and approve the escalation record.
  • Risk Appetite Definition & Board Reporting — Executive; with Risk Management · 8 steps
    Define appetite statements, tolerances, KRIs, board approval, monitoring, and ERM reporting for governance oversight.
  • Risk Assessment and Treatment Review — Risk Management · 2 steps
    Apply the approved rating method to a defined scenario, evaluate controls, select treatment and approve residual risk and monitoring.
  • Risk Communication, Reporting & Performance Review — Risk Management · 8 steps
    Each quarter - and on an event-driven basis whenever a significant matter arises - the ERM office runs structured stakeholder consultation across the risk process, including supplier and third-party risk and human and cultural factors, and delivers the cadenced risk, control, and performance reporting packages internally at every level and to external stakeholders and partners. The same cycle reviews risk-management and internal-control performance against the framework's design and intended outcomes with accountable management, then converts the lessons into owned, tracked improvement actions driven to closure.
  • Risk Register Intake — Risk Management · 4 steps
    Capture a new risk from initial identification through inherent scoring, control mapping, residual scoring, and owner assignment with a defined review cadence.
  • SOC Report, Subservice & CUEC Review — Risk Management · 2 steps
    Evaluate a service-organization report, subservice coverage, exceptions, and complementary user-entity controls for a governed reliance decision.
  • Strategic Context & Objectives Alignment Cycle — Executive; with Risk Management · 9 steps
    Annually refresh the organization's documented mission, stakeholder expectations, and critical objectives and dependencies, and communicate that context to those who scope and prioritize risk work. Realign strategy with mission and risk profile, cascade objectives and publish the roadmap, then close by documenting mission-essential business processes and information-protection needs as the approved basis for risk-assessment scoping.
  • System and Third-Party Risk Review — Risk Management; with IT, Procurement · 2 steps
    Evaluate system criticality, data flows, supplier evidence, gaps and compensating controls before accepting its risk posture.
  • Vendor Risk Assessment and Disposition — Procurement; with Risk Management, IT · 2 steps
    Assess the actual supplier's contracts, assurance reports, access, continuity and exit evidence; obtain expert challenge and an authorized reliance disposition.
Privacy Terms