{"version":"2.7","format":"coworkcanvas","description":"Auditober 2026 event pack: the fictional Bluth Company on the Studio v21 canonical workflow templates plus the three model-inventory templates. It carries twelve item types (the eleven Studio types and model) with their records, relationships, item-template links, template step links and template-bound workflow runs, and four fictional users. No dashboards.","data":{"itemTypes":[{"slug":"audit","name":"Audit","namePlural":"Audits","description":"Audit engagements and assessments — internal audits, SOX testing, compliance reviews, external attestations","icon":"ClipboardCheck","color":"#1E9BE0","displayOrder":1,"defaultStatus":"PLANNED","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"audit_type","label":"Audit Type","fieldType":"SELECT","required":false,"options":[{"value":"internal","label":"Internal Audit"},{"value":"sox_testing","label":"SOX / ICFR Testing"},{"value":"compliance","label":"Compliance Review"},{"value":"operational","label":"Operational Audit"},{"value":"it_audit","label":"IT Audit"},{"value":"financial","label":"Financial Audit"},{"value":"vendor_review","label":"Third-Party / Vendor Review"},{"value":"investigation","label":"Investigation"},{"value":"advisory","label":"Advisory / Consulting"},{"value":"readiness","label":"Readiness Assessment"},{"value":"external_attestation","label":"External Attestation (SOC / ISO)"},{"value":"regulatory_exam","label":"Regulatory Exam Support"}],"order":2,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"scope","label":"Scope","fieldType":"TEXTAREA","required":false,"options":null,"order":3,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"lead_auditor","label":"Lead Auditor","fieldType":"TEXT","required":false,"options":null,"order":4,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"external_firm","label":"External Firm","fieldType":"TEXT","required":false,"options":null,"order":5,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"rating","label":"Overall Rating","fieldType":"SELECT","required":false,"options":[{"value":"satisfactory","label":"Satisfactory"},{"value":"needs_improvement","label":"Needs Improvement"},{"value":"unsatisfactory","label":"Unsatisfactory"},{"value":"not_rated","label":"Not Rated"}],"order":6,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"opinion","label":"Opinion (attestation)","fieldType":"SELECT","required":false,"options":[{"value":"unqualified","label":"Unqualified"},{"value":"qualified","label":"Qualified"},{"value":"adverse","label":"Adverse"},{"value":"disclaimer","label":"Disclaimer"},{"value":"na","label":"N/A"}],"order":7,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"period_start","label":"Period Start","fieldType":"DATE","required":false,"options":null,"order":8,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"period_end","label":"Period End","fieldType":"DATE","required":false,"options":null,"order":9,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"fieldwork_start","label":"Fieldwork Start","fieldType":"DATE","required":false,"options":null,"order":10,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"fieldwork_end","label":"Fieldwork End","fieldType":"DATE","required":false,"options":null,"order":11,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"report_date","label":"Report Date","fieldType":"DATE","required":false,"options":null,"order":12,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"fiscal_year","label":"Fiscal Year","fieldType":"TEXT","required":false,"options":null,"order":13,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true}]},{"slug":"risk","name":"Risk","namePlural":"Risks","description":"Enterprise risk register — risks rated inherent-to-residual and mapped to domains and taxonomy tags","icon":"AlertTriangle","color":"#EF4444","displayOrder":2,"defaultStatus":"OPEN","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"category","label":"Category","fieldType":"SELECT","required":false,"options":[{"value":"cyber_security","label":"Cyber Security"},{"value":"operational","label":"Operational"},{"value":"financial_reporting","label":"Financial Reporting"},{"value":"compliance_regulatory","label":"Compliance & Regulatory"},{"value":"third_party","label":"Third Party / Supply Chain"},{"value":"privacy","label":"Privacy & Data Protection"},{"value":"ai_governance","label":"AI Governance"},{"value":"strategic","label":"Strategic"},{"value":"reputational","label":"Reputational"},{"value":"esg","label":"ESG / Environmental"},{"value":"people_hr","label":"People & HR"},{"value":"business_continuity","label":"Business Continuity"}],"order":2,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"subcategory","label":"Subcategory","fieldType":"TEXT","required":false,"options":null,"order":3,"isCore":false,"isFilterable":true,"isSearchable":true,"group":null},{"fieldKey":"taxonomies","label":"Taxonomy Tags","fieldType":"MULTISELECT","required":false,"options":[{"value":"cyber_security","label":"Cyber Security"},{"value":"data_privacy","label":"Data Privacy"},{"value":"financial_reporting","label":"Financial Reporting"},{"value":"operational_resilience","label":"Operational Resilience"},{"value":"third_party_risk","label":"Third-Party Risk"},{"value":"ai_governance","label":"AI Governance"},{"value":"esg_sustainability","label":"ESG / Sustainability"},{"value":"people_hr","label":"People & HR"},{"value":"regulatory_compliance","label":"Regulatory Compliance"},{"value":"strategic_risk","label":"Strategic Risk"},{"value":"reputational_risk","label":"Reputational Risk"},{"value":"business_continuity","label":"Business Continuity"}],"order":4,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"domains","label":"Domains","fieldType":"MULTISELECT","required":false,"options":[{"value":"governance_policy_oversight","label":"Governance, Policy & Oversight"},{"value":"risk_assessment_management","label":"Risk Assessment & Management"},{"value":"asset_management_inventory","label":"Asset Management & Inventory"},{"value":"access_control_identity","label":"Access Control & Identity Management"},{"value":"cryptography_key_management","label":"Cryptography & Key Management"},{"value":"human_resources_personnel_security","label":"Human Resources / Personnel Security"},{"value":"physical_environmental_security","label":"Physical & Environmental Security"},{"value":"secure_configuration_change_management","label":"Secure Configuration & Change Management"},{"value":"vulnerability_patch_management","label":"Vulnerability & Patch Management"},{"value":"logging_monitoring_detection","label":"Logging, Monitoring & Detection"},{"value":"incident_management_response","label":"Incident Management & Response"},{"value":"business_continuity_disaster_recovery","label":"Business Continuity & Disaster Recovery"},{"value":"third_party_supply_chain_risk","label":"Third-Party / Supply-Chain Risk"},{"value":"data_protection_privacy","label":"Data Protection & Privacy"},{"value":"secure_development_sdlc","label":"Secure Development (SDLC) & Application Security"},{"value":"network_communications_security","label":"Network & Communications Security"},{"value":"awareness_training","label":"Awareness & Training"},{"value":"compliance_audit_assurance","label":"Compliance, Audit & Assurance"},{"value":"ai_governance","label":"AI Governance"},{"value":"financial_reporting_controls","label":"Financial Reporting Controls (SOX)"}],"order":5,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"likelihood","label":"Likelihood","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"},{"value":"very_high","label":"Very High"}],"order":6,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"impact","label":"Impact","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"},{"value":"critical","label":"Critical"}],"order":7,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"inherent_likelihood","label":"Inherent Likelihood","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"},{"value":"very_high","label":"Very High"}],"order":8,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"inherent_impact","label":"Inherent Impact","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"},{"value":"critical","label":"Critical"}],"order":9,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"inherent_rating","label":"Inherent Rating","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"},{"value":"critical","label":"Critical"}],"order":10,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"residual_rating","label":"Residual Rating","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"},{"value":"critical","label":"Critical"}],"order":11,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"treatment","label":"Treatment","fieldType":"SELECT","required":false,"options":[{"value":"mitigate","label":"Mitigate"},{"value":"accept","label":"Accept"},{"value":"transfer","label":"Transfer"},{"value":"avoid","label":"Avoid"}],"order":12,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"risk_owner","label":"Risk Owner","fieldType":"TEXT","required":false,"options":null,"order":13,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null}]},{"slug":"control","name":"Control","namePlural":"Controls","description":"Control library — controls mapped to frameworks and domains, with type, automation, and operating frequency","icon":"ShieldCheck","color":"#10B981","displayOrder":3,"defaultStatus":"ACTIVE","fieldDefinitions":[{"fieldKey":"control_id","label":"Control ID","fieldType":"TEXT","required":false,"options":null,"order":0,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":2,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"framework","label":"Frameworks","fieldType":"MULTISELECT","required":false,"options":[{"value":"nist-800-53","label":"NIST SP 800-53 Rev 5"},{"value":"nist-csf-2","label":"NIST CSF 2.0"},{"value":"cobit-2019","label":"COBIT 2019"},{"value":"iso-27001","label":"ISO/IEC 27001:2022"},{"value":"iso-42001","label":"ISO/IEC 42001:2023"},{"value":"iso-31000","label":"ISO 31000:2018"},{"value":"soc2","label":"AICPA SOC 2"},{"value":"soc1","label":"AICPA SOC 1 (SSAE 18)"},{"value":"sox","label":"SOX 404"},{"value":"coso-ic","label":"COSO Internal Control"},{"value":"coso-erm","label":"COSO ERM"},{"value":"iia-2024","label":"IIA 2024 Global Standards"},{"value":"gdpr","label":"EU GDPR"},{"value":"dora","label":"EU DORA"},{"value":"nydfs-500","label":"NYDFS Part 500"},{"value":"eu-ai-act","label":"EU AI Act"},{"value":"nis2","label":"EU NIS2"},{"value":"pci-dss","label":"PCI DSS 4.0"},{"value":"hipaa","label":"HIPAA"},{"value":"ccpa","label":"CCPA/CPRA"}],"order":3,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"family","label":"Family / Group","fieldType":"TEXT","required":false,"options":null,"order":4,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"domains","label":"Domains","fieldType":"MULTISELECT","required":false,"options":[{"value":"governance_policy_oversight","label":"Governance, Policy & Oversight"},{"value":"risk_assessment_management","label":"Risk Assessment & Management"},{"value":"asset_management_inventory","label":"Asset Management & Inventory"},{"value":"access_control_identity","label":"Access Control & Identity Management"},{"value":"cryptography_key_management","label":"Cryptography & Key Management"},{"value":"human_resources_personnel_security","label":"Human Resources / Personnel Security"},{"value":"physical_environmental_security","label":"Physical & Environmental Security"},{"value":"secure_configuration_change_management","label":"Secure Configuration & Change Management"},{"value":"vulnerability_patch_management","label":"Vulnerability & Patch Management"},{"value":"logging_monitoring_detection","label":"Logging, Monitoring & Detection"},{"value":"incident_management_response","label":"Incident Management & Response"},{"value":"business_continuity_disaster_recovery","label":"Business Continuity & Disaster Recovery"},{"value":"third_party_supply_chain_risk","label":"Third-Party / Supply-Chain Risk"},{"value":"data_protection_privacy","label":"Data Protection & Privacy"},{"value":"secure_development_sdlc","label":"Secure Development (SDLC) & Application Security"},{"value":"network_communications_security","label":"Network & Communications Security"},{"value":"awareness_training","label":"Awareness & Training"},{"value":"compliance_audit_assurance","label":"Compliance, Audit & Assurance"},{"value":"ai_governance","label":"AI Governance"},{"value":"financial_reporting_controls","label":"Financial Reporting Controls (SOX)"}],"order":5,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"control_type","label":"Control Type","fieldType":"SELECT","required":false,"options":[{"value":"preventive","label":"Preventive"},{"value":"detective","label":"Detective"},{"value":"corrective","label":"Corrective"}],"order":6,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"control_category","label":"Control Category","fieldType":"SELECT","required":false,"options":[{"value":"administrative","label":"Administrative"},{"value":"technical","label":"Technical"},{"value":"physical","label":"Physical"}],"order":7,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"control_class","label":"Control Class","fieldType":"SELECT","required":false,"options":[{"value":"entity_level","label":"Entity-Level"},{"value":"business_process","label":"Business Process"},{"value":"itgc","label":"ITGC"},{"value":"itac","label":"ITAC"},{"value":"soc1_service_delivery","label":"SOC 1 Service Delivery"}],"order":8,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"itgc_domain","label":"ITGC Domain","fieldType":"SELECT","required":false,"options":[{"value":"access_to_programs_data","label":"Access to Programs & Data"},{"value":"program_changes","label":"Program Changes"},{"value":"computer_operations","label":"Computer Operations"},{"value":"program_development","label":"Program Development"},{"value":"end_user_computing","label":"End-User Computing (EUC)"}],"order":9,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"automation","label":"Automation","fieldType":"SELECT","required":false,"options":[{"value":"automated","label":"Automated"},{"value":"manual","label":"Manual"},{"value":"hybrid","label":"Hybrid"}],"order":10,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"key_control","label":"Key Control","fieldType":"SELECT","required":false,"options":[{"value":"true","label":"Key control"},{"value":"false","label":"Non-key"}],"order":11,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"sox_applicable","label":"SOX Applicable","fieldType":"BOOLEAN","required":false,"options":null,"order":12,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"frequency","label":"Operating Frequency","fieldType":"SELECT","required":false,"options":[{"value":"continuous","label":"Continuous"},{"value":"daily","label":"Daily"},{"value":"weekly","label":"Weekly"},{"value":"monthly","label":"Monthly"},{"value":"quarterly","label":"Quarterly"},{"value":"semi_annual","label":"Semi-Annual"},{"value":"annual","label":"Annual"},{"value":"ad_hoc","label":"Ad hoc / Event-driven"}],"order":13,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"locations","label":"Locations","fieldType":"TEXT","required":false,"options":null,"order":14,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"control_owner","label":"Control Owner","fieldType":"TEXT","required":false,"options":null,"order":15,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"design_conclusion","label":"Design Conclusion","fieldType":"SELECT","required":false,"options":[{"value":"not_assessed","label":"Not Assessed"},{"value":"effective","label":"Effective"},{"value":"deficient","label":"Deficient"}],"order":16,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"interim_result","label":"Interim Test Result","fieldType":"SELECT","required":false,"options":[{"value":"not_tested","label":"Not Tested"},{"value":"in_progress","label":"In Progress"},{"value":"effective","label":"Effective"},{"value":"exception","label":"Exception"}],"order":17,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"ye_result","label":"Year-End Test Result","fieldType":"SELECT","required":false,"options":[{"value":"not_tested","label":"Not Tested"},{"value":"in_progress","label":"In Progress"},{"value":"effective","label":"Effective"},{"value":"exception","label":"Exception"}],"order":18,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"rollforward_strategy","label":"Roll-Forward Strategy","fieldType":"SELECT","required":false,"options":[{"value":"full_retest","label":"Full Retest"},{"value":"roll_forward","label":"Roll-Forward"},{"value":"interim_sufficient","label":"Interim Sufficient"},{"value":"not_required","label":"Not Required"}],"order":19,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"last_tested_fy","label":"Last Tested FY","fieldType":"TEXT","required":false,"options":null,"order":20,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"workpaper","label":"Workpaper","fieldType":"DOCUMENT","required":false,"options":null,"order":21,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null}]},{"slug":"issue","name":"Issue","namePlural":"Issues","description":"Findings, observations, exceptions and waivers — identification, classification and response; corrective actions are linked Remediation items","icon":"Flag","color":"#F97316","displayOrder":4,"defaultStatus":"DRAFT","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"severity","label":"Severity","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"},{"value":"critical","label":"Critical"}],"order":2,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"issue_type","label":"Issue Type","fieldType":"SELECT","required":false,"options":[{"value":"finding","label":"Finding"},{"value":"observation","label":"Observation"},{"value":"opportunity","label":"Opportunity for Improvement"},{"value":"exception","label":"Test Exception"},{"value":"policy_exception","label":"Policy Exception / Waiver"},{"value":"deficiency","label":"Deficiency"},{"value":"significant_deficiency","label":"Significant Deficiency"},{"value":"material_weakness","label":"Material Weakness"},{"value":"pbc_request","label":"PBC Request"}],"order":3,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"source","label":"Source","fieldType":"SELECT","required":false,"options":[{"value":"internal_audit","label":"Internal Audit"},{"value":"external_audit","label":"External Audit"},{"value":"sox_testing","label":"SOX Testing"},{"value":"compliance_review","label":"Compliance Review"},{"value":"self_assessment","label":"Self-Assessment"},{"value":"penetration_test","label":"Penetration Test"},{"value":"vulnerability_scan","label":"Vulnerability Scan"},{"value":"regulatory_exam","label":"Regulatory Exam"},{"value":"management_identified","label":"Management Identified"}],"order":4,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"sox_deficiency","label":"SOX Deficiency","fieldType":"SELECT","required":false,"options":[{"value":"control_deficiency","label":"Control Deficiency"},{"value":"significant_deficiency","label":"Significant Deficiency"},{"value":"material_weakness","label":"Material Weakness"}],"order":5,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"root_cause","label":"Root Cause","fieldType":"TEXTAREA","required":false,"options":null,"order":6,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"recommendation","label":"Recommendation","fieldType":"RICHTEXT","required":false,"options":null,"order":7,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"management_response","label":"Management Response","fieldType":"RICHTEXT","required":false,"options":null,"order":8,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"issue_owner","label":"Issue Owner","fieldType":"USER","required":false,"options":null,"order":9,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"issue_collaborators","label":"Issue Collaborators","fieldType":"USERS","required":false,"options":null,"order":10,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"identified_date","label":"Identified / Open Date","fieldType":"DATE","required":false,"options":null,"order":11,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"reported_date","label":"Reported Date","fieldType":"DATE","required":false,"options":null,"order":12,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"exception_approver","label":"Exception Approver","fieldType":"TEXT","required":false,"options":null,"order":13,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"exception_expiry_date","label":"Exception Expiry / Re-review Date","fieldType":"DATE","required":false,"options":null,"order":14,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"target_remediation_date","label":"Target remediation date","fieldType":"DATE","required":false,"options":null,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null,"order":15,"isSystem":true},{"fieldKey":"actual_remediation_date","label":"Actual remediation date","fieldType":"DATE","required":false,"options":null,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null,"order":16,"isSystem":true}]},{"slug":"remediation","name":"Remediation","namePlural":"Remediations","description":"Remediation actions — the discrete corrective actions that clear findings and exceptions, each with its own owner, dates, validation method and closure evidence","icon":"Wrench","color":"#6366F1","displayOrder":5,"defaultStatus":"OPEN","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"plan","label":"Remediation Plan","fieldType":"RICHTEXT","required":false,"options":null,"order":2,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"remediation_type","label":"Remediation Type","fieldType":"SELECT","required":false,"options":[{"value":"control_redesign","label":"Control Redesign"},{"value":"new_control","label":"New Control"},{"value":"system_configuration","label":"System Configuration"},{"value":"process_change","label":"Process Change"},{"value":"policy_update","label":"Policy Update"},{"value":"training","label":"Training"},{"value":"data_correction","label":"Data Correction"},{"value":"third_party_action","label":"Third-Party Action"},{"value":"evidence_submission","label":"Evidence Submission"},{"value":"monitoring_only","label":"Monitoring Only"}],"order":3,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"action_owner","label":"Action Owner","fieldType":"TEXT","required":false,"options":null,"order":4,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"priority","label":"Priority","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"},{"value":"critical","label":"Critical"}],"order":5,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"target_date","label":"Target Date","fieldType":"DATE","required":false,"options":null,"order":6,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"revised_target_date","label":"Revised Target Date","fieldType":"DATE","required":false,"options":null,"order":7,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"completed_date","label":"Completed Date","fieldType":"DATE","required":false,"options":null,"order":8,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"verified_date","label":"Verification Date","fieldType":"DATE","required":false,"options":null,"order":9,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"verified_by","label":"Verified By","fieldType":"TEXT","required":false,"options":null,"order":10,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"validation_method","label":"Validation Method","fieldType":"SELECT","required":false,"options":[{"value":"design_retest","label":"Design Retest"},{"value":"operating_retest","label":"Operating Effectiveness Retest"},{"value":"evidence_inspection","label":"Evidence Inspection"},{"value":"reperformance","label":"Reperformance"},{"value":"monitoring","label":"Monitoring Period"}],"order":11,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"closure_criteria","label":"Closure Criteria","fieldType":"TEXTAREA","required":false,"options":null,"order":12,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"evidence","label":"Closure Evidence","fieldType":"DOCUMENT","required":false,"options":null,"order":13,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null}]},{"slug":"process","name":"Process","namePlural":"Processes","description":"Auditable business and IT processes — the entities audits scope over and controls operate within","icon":"GitBranch","color":"#8B5CF6","displayOrder":6,"defaultStatus":"ACTIVE","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"process_type","label":"Process Type","fieldType":"SELECT","required":false,"options":[{"value":"business_process","label":"Business Process"},{"value":"financial_reporting","label":"Financial Reporting Cycle"},{"value":"it_general_control","label":"IT General Control"},{"value":"security_process","label":"Security Process"},{"value":"operational","label":"Operational"}],"order":2,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"process_owner","label":"Process Owner","fieldType":"TEXT","required":false,"options":null,"order":3,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"frequency","label":"Frequency","fieldType":"TEXT","required":false,"options":null,"order":4,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"fsli_significance","label":"Financial Significance to FSLIs","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":5,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"process_complexity","label":"Process Complexity","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":6,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"manual_intervention","label":"Degree of Manual Intervention","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":7,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"issue_history","label":"History of Issues / Findings","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":8,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"third_party_reliance","label":"Reliance on Third Parties","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":9,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"process_change","label":"Level of Change to Process","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":10,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"monitoring_gap","label":"Lack of Monitoring Function","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":11,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"bp_weighted_score","label":"BP Weighted Score","fieldType":"NUMBER","required":false,"options":null,"order":12,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"bp_overall_assessment","label":"BP Overall Assessment","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":13,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"in_scope","label":"In Scope This Year","fieldType":"BOOLEAN","required":false,"options":null,"order":14,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"scope_rationale","label":"Scope Rationale","fieldType":"TEXTAREA","required":false,"options":null,"order":15,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"last_tested_fy","label":"Last Tested FY","fieldType":"TEXT","required":false,"options":null,"order":16,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null}]},{"slug":"policy","name":"Policy","namePlural":"Policies","description":"Policy library — policies, standards, procedures, guidelines and charters with ownership, versioning, framework mapping and review cycles","icon":"ScrollText","color":"#14B8A6","displayOrder":7,"defaultStatus":"ACTIVE","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"policy_type","label":"Policy Type","fieldType":"SELECT","required":false,"options":[{"value":"policy","label":"Policy"},{"value":"standard","label":"Standard"},{"value":"procedure","label":"Procedure"},{"value":"guideline","label":"Guideline"},{"value":"charter","label":"Charter"}],"order":2,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"policy_owner","label":"Policy Owner","fieldType":"TEXT","required":false,"options":null,"order":3,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"approved_by","label":"Approved By","fieldType":"TEXT","required":false,"options":null,"order":4,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"version","label":"Version","fieldType":"TEXT","required":false,"options":null,"order":5,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"framework","label":"Frameworks","fieldType":"MULTISELECT","required":false,"options":[{"value":"nist-800-53","label":"NIST SP 800-53 Rev 5"},{"value":"nist-csf-2","label":"NIST CSF 2.0"},{"value":"cobit-2019","label":"COBIT 2019"},{"value":"iso-27001","label":"ISO/IEC 27001:2022"},{"value":"iso-42001","label":"ISO/IEC 42001:2023"},{"value":"iso-31000","label":"ISO 31000:2018"},{"value":"soc2","label":"AICPA SOC 2"},{"value":"soc1","label":"AICPA SOC 1 (SSAE 18)"},{"value":"sox","label":"SOX 404"},{"value":"coso-ic","label":"COSO Internal Control"},{"value":"coso-erm","label":"COSO ERM"},{"value":"iia-2024","label":"IIA 2024 Global Standards"},{"value":"gdpr","label":"EU GDPR"},{"value":"dora","label":"EU DORA"},{"value":"nydfs-500","label":"NYDFS Part 500"},{"value":"eu-ai-act","label":"EU AI Act"},{"value":"nis2","label":"EU NIS2"},{"value":"pci-dss","label":"PCI DSS 4.0"},{"value":"hipaa","label":"HIPAA"},{"value":"ccpa","label":"CCPA/CPRA"}],"order":6,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"domains","label":"Domains","fieldType":"MULTISELECT","required":false,"options":[{"value":"governance_policy_oversight","label":"Governance, Policy & Oversight"},{"value":"risk_assessment_management","label":"Risk Assessment & Management"},{"value":"asset_management_inventory","label":"Asset Management & Inventory"},{"value":"access_control_identity","label":"Access Control & Identity Management"},{"value":"cryptography_key_management","label":"Cryptography & Key Management"},{"value":"human_resources_personnel_security","label":"Human Resources / Personnel Security"},{"value":"physical_environmental_security","label":"Physical & Environmental Security"},{"value":"secure_configuration_change_management","label":"Secure Configuration & Change Management"},{"value":"vulnerability_patch_management","label":"Vulnerability & Patch Management"},{"value":"logging_monitoring_detection","label":"Logging, Monitoring & Detection"},{"value":"incident_management_response","label":"Incident Management & Response"},{"value":"business_continuity_disaster_recovery","label":"Business Continuity & Disaster Recovery"},{"value":"third_party_supply_chain_risk","label":"Third-Party / Supply-Chain Risk"},{"value":"data_protection_privacy","label":"Data Protection & Privacy"},{"value":"secure_development_sdlc","label":"Secure Development (SDLC) & Application Security"},{"value":"network_communications_security","label":"Network & Communications Security"},{"value":"awareness_training","label":"Awareness & Training"},{"value":"compliance_audit_assurance","label":"Compliance, Audit & Assurance"},{"value":"ai_governance","label":"AI Governance"},{"value":"financial_reporting_controls","label":"Financial Reporting Controls (SOX)"}],"order":7,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"review_frequency","label":"Review Frequency","fieldType":"SELECT","required":false,"options":[{"value":"quarterly","label":"Quarterly"},{"value":"semi_annual","label":"Semi-Annual"},{"value":"annual","label":"Annual"},{"value":"biennial","label":"Biennial"},{"value":"ad_hoc","label":"Ad hoc / Event-driven"}],"order":8,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"effective_date","label":"Effective Date","fieldType":"DATE","required":false,"options":null,"order":9,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"next_review_date","label":"Next Review Date","fieldType":"DATE","required":false,"options":null,"order":10,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true}]},{"slug":"system","name":"System","namePlural":"Systems","description":"Systems and service-provider register — internal and third-party dependencies tiered by criticality and data exposure, with ownership, assessment cadence, monitoring status and contract dates","icon":"Server","color":"#F59E0B","displayOrder":8,"defaultStatus":"ACTIVE","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"vendor","label":"Vendor","fieldType":"BOOLEAN","required":false,"options":null,"order":2,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"category","label":"Category","fieldType":"SELECT","required":false,"options":[{"value":"saas_software","label":"SaaS / Software"},{"value":"cloud_infrastructure","label":"Cloud & Infrastructure"},{"value":"managed_services","label":"Managed Services"},{"value":"professional_services","label":"Professional Services"},{"value":"data_processing","label":"Data Processing"},{"value":"hardware_supplier","label":"Hardware Supplier"},{"value":"facilities","label":"Facilities"},{"value":"other","label":"Other"}],"order":3,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"tier","label":"Criticality Tier","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"},{"value":"critical","label":"Critical"}],"order":4,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"data_classification","label":"Highest Data Classification Shared","fieldType":"SELECT","required":false,"options":[{"value":"none","label":"None"},{"value":"public","label":"Public"},{"value":"internal","label":"Internal"},{"value":"confidential","label":"Confidential"},{"value":"restricted","label":"Restricted"}],"order":5,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"business_owner","label":"Business Owner","fieldType":"TEXT","required":false,"options":null,"order":6,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"risk_owner","label":"Risk Owner","fieldType":"TEXT","required":false,"options":null,"order":7,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"reassessment_cadence","label":"Reassessment Cadence","fieldType":"SELECT","required":false,"options":[{"value":"quarterly","label":"Quarterly"},{"value":"semi_annual","label":"Semi-Annual"},{"value":"annual","label":"Annual"},{"value":"biennial","label":"Biennial"},{"value":"ad_hoc","label":"Ad hoc / Event-driven"}],"order":8,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"last_assessment_date","label":"Last Assessment Date","fieldType":"DATE","required":false,"options":null,"order":9,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"next_reassessment_date","label":"Next Reassessment Date","fieldType":"DATE","required":false,"options":null,"order":10,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"monitoring_status","label":"Monitoring Status","fieldType":"SELECT","required":false,"options":[{"value":"enrolled","label":"Enrolled in Continuous Monitoring"},{"value":"not_enrolled","label":"Not Enrolled"},{"value":"exited","label":"Exited / Offboarded"}],"order":11,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"contract_end_date","label":"Contract End Date","fieldType":"DATE","required":false,"options":null,"order":12,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true}]},{"slug":"fsli","name":"FSLI","namePlural":"FSLIs","description":"Financial-statement line items and TB components — balances, weighted risk criteria, significance conclusions and assertions for SOX/ICFR scoping","icon":"Landmark","color":"#0EA5E9","displayOrder":9,"defaultStatus":"ACTIVE","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"statement","label":"Statement","fieldType":"SELECT","required":false,"options":[{"value":"balance_sheet","label":"Balance Sheet"},{"value":"income_statement","label":"Income Statement"},{"value":"cash_flow","label":"Cash Flow"},{"value":"equity","label":"Equity"},{"value":"disclosure","label":"Disclosure"}],"order":2,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"fs_order","label":"FS Order","fieldType":"TEXT","required":false,"options":null,"order":3,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"account_ref","label":"Account Ref","fieldType":"TEXT","required":false,"options":null,"order":4,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"tb_account","label":"TB Component","fieldType":"BOOLEAN","required":false,"options":null,"order":5,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"balance","label":"Balance","fieldType":"NUMBER","required":false,"options":null,"order":6,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"annualized_balance","label":"Annualized Balance","fieldType":"NUMBER","required":false,"options":null,"order":7,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"balance_date","label":"Balance Date","fieldType":"DATE","required":false,"options":null,"order":8,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"yoy_change_pct","label":"YoY Change %","fieldType":"NUMBER","required":false,"options":null,"order":9,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"financial_significance","label":"Financial Significance","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":10,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"valuation_complexity","label":"Valuation Complexity / Subjectivity","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":11,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"restatement_history","label":"History of Restatement / Errors","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":12,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"external_sensitivity","label":"Sensitivity to External Factors","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":13,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"fraud_risk","label":"Fraud Risk (Financial Reporting)","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":14,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"activity_volume","label":"Volume of Activity","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":15,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"volatility","label":"Level of Volatility","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":16,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"disclosure_impact","label":"Impact on Disclosures","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":17,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"weighted_score","label":"Weighted Score","fieldType":"NUMBER","required":false,"options":null,"order":18,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"overall_assessment","label":"Overall Assessment","fieldType":"SELECT","required":false,"options":[{"value":"low","label":"Low"},{"value":"medium","label":"Medium"},{"value":"high","label":"High"}],"order":19,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"significant","label":"Significant Account","fieldType":"BOOLEAN","required":false,"options":null,"order":20,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"assertions","label":"Relevant Assertions","fieldType":"MULTISELECT","required":false,"options":[{"value":"existence_occurrence","label":"Existence / Occurrence"},{"value":"completeness","label":"Completeness"},{"value":"accuracy_valuation","label":"Accuracy / Valuation"},{"value":"cutoff","label":"Cutoff"},{"value":"rights_obligations","label":"Rights & Obligations"},{"value":"classification","label":"Classification"},{"value":"presentation_disclosure","label":"Presentation & Disclosure"}],"order":21,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"rationale","label":"Rationale","fieldType":"TEXTAREA","required":false,"options":null,"order":22,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"assessed_fy","label":"Assessed FY","fieldType":"TEXT","required":false,"options":null,"order":23,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null}]},{"slug":"requirement","name":"Compliance Requirement","namePlural":"Compliance Requirements","description":"Compliance requirements — framework clauses, controls, criteria and obligations mapped to applicability, implementation status and evidence","icon":"BookCheck","color":"#64748B","displayOrder":10,"defaultStatus":"OPEN","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"full_description","label":"Full Description","fieldType":"TEXTAREA","required":false,"options":null,"order":1,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"reference","label":"Reference","fieldType":"TEXT","required":false,"options":null,"order":2,"isCore":false,"isFilterable":true,"isSearchable":true,"group":null},{"fieldKey":"framework","label":"Framework","fieldType":"SELECT","required":false,"options":[{"value":"nist-800-53","label":"NIST SP 800-53 Rev 5"},{"value":"nist-csf-2","label":"NIST CSF 2.0"},{"value":"cobit-2019","label":"COBIT 2019"},{"value":"iso-27001","label":"ISO/IEC 27001:2022"},{"value":"iso-42001","label":"ISO/IEC 42001:2023"},{"value":"iso-31000","label":"ISO 31000:2018"},{"value":"soc2","label":"AICPA SOC 2"},{"value":"soc1","label":"AICPA SOC 1 (SSAE 18)"},{"value":"sox","label":"SOX 404"},{"value":"coso-ic","label":"COSO Internal Control"},{"value":"coso-erm","label":"COSO ERM"},{"value":"iia-2024","label":"IIA 2024 Global Standards"},{"value":"gdpr","label":"EU GDPR"},{"value":"dora","label":"EU DORA"},{"value":"nydfs-500","label":"NYDFS Part 500"},{"value":"eu-ai-act","label":"EU AI Act"},{"value":"nis2","label":"EU NIS2"},{"value":"pci-dss","label":"PCI DSS 4.0"},{"value":"hipaa","label":"HIPAA"},{"value":"ccpa","label":"CCPA/CPRA"}],"order":3,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"framework_version","label":"Framework Version","fieldType":"TEXT","required":false,"options":null,"order":4,"isCore":false,"isFilterable":true,"isSearchable":true,"group":null},{"fieldKey":"domain","label":"Domain","fieldType":"TEXT","required":false,"options":null,"order":5,"isCore":false,"isFilterable":true,"isSearchable":true,"group":null,"isSystem":true},{"fieldKey":"requirement_kind","label":"Requirement Kind","fieldType":"SELECT","required":false,"options":[{"value":"clause","label":"Clause"},{"value":"control","label":"Control"},{"value":"criterion","label":"Criterion"},{"value":"obligation","label":"Obligation"}],"order":6,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"applicability","label":"Applicability","fieldType":"SELECT","required":false,"options":[{"value":"applicable","label":"Applicable"},{"value":"not_applicable","label":"Not Applicable"},{"value":"pending_review","label":"Pending Review"}],"order":7,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"applicability_justification","label":"Applicability Justification","fieldType":"TEXTAREA","required":false,"options":null,"order":8,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"implementation_status","label":"Implementation Status","fieldType":"SELECT","required":false,"options":[{"value":"implemented","label":"Implemented"},{"value":"partially_implemented","label":"Partially Implemented"},{"value":"planned","label":"Planned"},{"value":"not_implemented","label":"Not Implemented"},{"value":"not_applicable","label":"Not Applicable"}],"order":9,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"requirement_owner","label":"Requirement Owner","fieldType":"TEXT","required":false,"options":null,"order":10,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"last_review_date","label":"Last Review Date","fieldType":"DATE","required":false,"options":null,"order":11,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"next_review_date","label":"Next Review Date","fieldType":"DATE","required":false,"options":null,"order":12,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"domains","label":"Domains","fieldType":"MULTISELECT","required":false,"options":[{"value":"governance_policy_oversight","label":"Governance, Policy & Oversight"},{"value":"risk_assessment_management","label":"Risk Assessment & Management"},{"value":"asset_management_inventory","label":"Asset Management & Inventory"},{"value":"access_control_identity","label":"Access Control & Identity Management"},{"value":"cryptography_key_management","label":"Cryptography & Key Management"},{"value":"human_resources_personnel_security","label":"Human Resources / Personnel Security"},{"value":"physical_environmental_security","label":"Physical & Environmental Security"},{"value":"secure_configuration_change_management","label":"Secure Configuration & Change Management"},{"value":"vulnerability_patch_management","label":"Vulnerability & Patch Management"},{"value":"logging_monitoring_detection","label":"Logging, Monitoring & Detection"},{"value":"incident_management_response","label":"Incident Management & Response"},{"value":"business_continuity_disaster_recovery","label":"Business Continuity & Disaster Recovery"},{"value":"third_party_supply_chain_risk","label":"Third-Party / Supply-Chain Risk"},{"value":"data_protection_privacy","label":"Data Protection & Privacy"},{"value":"secure_development_sdlc","label":"Secure Development (SDLC) & Application Security"},{"value":"network_communications_security","label":"Network & Communications Security"},{"value":"awareness_training","label":"Awareness & Training"},{"value":"compliance_audit_assurance","label":"Compliance, Audit & Assurance"},{"value":"ai_governance","label":"AI Governance"},{"value":"financial_reporting_controls","label":"Financial Reporting Controls (SOX)"}],"order":13,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"evidence","label":"Evidence","fieldType":"DOCUMENT","required":false,"options":null,"order":14,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null}]},{"slug":"personnel","name":"Personnel","namePlural":"Personnel","description":"People register - the employees, contractors, founders, advisers and service-provider staff who hold roles in the control environment, with engagement status, reporting line, responsibilities, authority and the declared systems scope that access reviews and lifecycle workflows operate against","icon":"UserCog","color":"#EC4899","displayOrder":11,"defaultStatus":"DRAFT","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"personnel_key","label":"Personnel Key","fieldType":"TEXT","required":true,"options":null,"order":1,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"full_name","label":"Full Name","fieldType":"TEXT","required":false,"options":null,"order":2,"isCore":true,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"work_email","label":"Work Email","fieldType":"TEXT","required":false,"options":null,"order":3,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"user_account","label":"User Account","fieldType":"USER","required":false,"options":null,"order":4,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"affiliation","label":"Organization / Affiliation","fieldType":"TEXT","required":false,"options":null,"order":5,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"engagement_type","label":"Engagement Type","fieldType":"SELECT","required":false,"options":[{"value":"unconfirmed","label":"Not confirmed"},{"value":"employee","label":"Employee"},{"value":"contractor","label":"Contractor"},{"value":"founder","label":"Founder / principal"},{"value":"external_advisor","label":"External adviser"},{"value":"service_provider","label":"Service-provider personnel"}],"order":6,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"engagement_status","label":"Engagement Status","fieldType":"SELECT","required":false,"options":[{"value":"unconfirmed","label":"Not confirmed"},{"value":"planned","label":"Planned"},{"value":"active","label":"Active"},{"value":"on_leave","label":"On leave"},{"value":"ended","label":"Ended"}],"order":7,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"department","label":"Department / Function","fieldType":"TEXT","required":false,"options":null,"order":8,"isCore":true,"isFilterable":true,"isSearchable":true,"group":null},{"fieldKey":"position_title","label":"Position Title","fieldType":"TEXT","required":false,"options":null,"order":9,"isCore":true,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"manager_name","label":"Line Manager","fieldType":"TEXT","required":false,"options":null,"order":10,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"manager_personnel_key","label":"Manager Personnel Key","fieldType":"TEXT","required":false,"options":null,"order":11,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"reporting_arrangement","label":"Reporting Arrangement","fieldType":"SELECT","required":false,"options":[{"value":"line_managed","label":"Reports to a line manager"},{"value":"principal","label":"Principal / no line manager"},{"value":"independent_oversight","label":"Independent governance oversight"},{"value":"unconfirmed","label":"Not confirmed"}],"order":12,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"responsibilities","label":"Responsibilities","fieldType":"TEXTAREA","required":false,"options":null,"order":13,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"authority_and_escalation","label":"Authority and Escalation","fieldType":"TEXTAREA","required":false,"options":null,"order":14,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"responsibility_review_status","label":"Responsibility Review Status","fieldType":"SELECT","required":false,"options":[{"value":"proposed","label":"Proposed for review"},{"value":"documented","label":"Documented role scope"},{"value":"approved","label":"Approved individual assignment"}],"order":15,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"role_effective_date","label":"Role Effective Date","fieldType":"DATE","required":false,"options":null,"order":16,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"role_effective_date_basis","label":"Role Effective-Date Basis","fieldType":"TEXT","required":false,"options":null,"order":17,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"engagement_start_date","label":"Engagement Start Date","fieldType":"DATE","required":false,"options":null,"order":18,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"engagement_end_date","label":"Engagement End Date","fieldType":"DATE","required":false,"options":null,"order":19,"isCore":false,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"systems_scope","label":"Declared Systems Scope","fieldType":"TEXTAREA","required":false,"options":null,"order":20,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"role_description","label":"Approved Role Description","fieldType":"DOCUMENT","required":false,"options":null,"order":21,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"verification_gaps","label":"Details Requiring Confirmation","fieldType":"TEXTAREA","required":false,"options":null,"order":22,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"source_record_url","label":"Source Record","fieldType":"TEXT","required":false,"options":null,"order":23,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null},{"fieldKey":"source_evidence","label":"Data Sources","fieldType":"JSON","required":false,"options":null,"order":24,"isCore":false,"isFilterable":false,"isSearchable":false,"group":null}]},{"slug":"model","name":"Model","namePlural":"Models","description":"Model inventory: actuarial, pricing, reserving, machine learning and generative AI models with their risk tier, owner, validation schedule and monitoring status","icon":"BrainCircuit","color":"#6366F1","displayOrder":20,"defaultStatus":"ACTIVE","fieldDefinitions":[{"fieldKey":"description","label":"Description","fieldType":"TEXTAREA","required":false,"options":null,"order":0,"isCore":false,"isFilterable":false,"isSearchable":true,"group":null},{"fieldKey":"model_type","label":"Model Type","fieldType":"SELECT","required":true,"options":[{"value":"actuarial","label":"Actuarial"},{"value":"pricing","label":"Pricing"},{"value":"reserving","label":"Reserving"},{"value":"machine_learning","label":"Machine learning"},{"value":"genai","label":"GenAI"},{"value":"other","label":"Other"}],"order":1,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"model_tier","label":"Risk Tier","fieldType":"SELECT","required":true,"options":[{"value":"tier_1","label":"Tier 1 (validated yearly)"},{"value":"tier_2","label":"Tier 2 (validated every 2 years)"},{"value":"tier_3","label":"Tier 3 (validated every 3 years)"}],"order":2,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"model_owner","label":"Model Owner","fieldType":"USER","required":false,"options":null,"order":3,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null},{"fieldKey":"last_validation_date","label":"Last Validation","fieldType":"DATE","required":false,"options":null,"order":4,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"next_validation_date","label":"Next Validation Due","fieldType":"DATE","required":false,"options":null,"order":5,"isCore":true,"isFilterable":false,"isSearchable":false,"group":null,"isSystem":true},{"fieldKey":"monitoring_status","label":"Monitoring Status","fieldType":"SELECT","required":false,"options":[{"value":"within_threshold","label":"Within threshold"},{"value":"watch","label":"Watch"},{"value":"breach","label":"Breach"},{"value":"not_monitored","label":"Not monitored"}],"order":6,"isCore":true,"isFilterable":true,"isSearchable":false,"group":null}]}],"items":{"audit":[{"title":"FY2026 SOX Annual Program","status":"PLANNING","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"FY2026 SOX Annual Program is an engagement in the fictional Bluth Company's FY2026 audit plan.","full_description":"The engagement is at the planning stage of the Bluth Company's FY2026 audit plan.","audit_type":"sox_testing","scope":"Corporate governance, financial reporting, technology, and compliance operations.","lead_auditor":"michael.bluth@bluth.example","external_firm":"","rating":"not_rated","opinion":"na","period_start":"2026-01-01","period_end":"2026-12-31","fieldwork_start":"2026-06-12","fieldwork_end":"2026-08-26","report_date":"2026-08-10","fiscal_year":"FY2026"}},{"title":"Revenue Recognition Audit","status":"FIELDWORK","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Revenue Recognition Audit is an engagement in the fictional Bluth Company's FY2026 audit plan.","full_description":"The engagement is at the fieldwork stage of the Bluth Company's FY2026 audit plan.","audit_type":"financial","scope":"Corporate governance, financial reporting, technology, and compliance operations.","lead_auditor":"george.michael@bluth.example","external_firm":"","rating":"needs_improvement","opinion":"na","period_start":"2026-01-01","period_end":"2026-12-31","fieldwork_start":"2026-06-13","fieldwork_end":"2026-08-27","report_date":"2026-08-11","fiscal_year":"FY2026"}},{"title":"SOC 2 Security and Availability Readiness","status":"REPORTING","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"SOC 2 Security and Availability Readiness is an engagement in the fictional Bluth Company's FY2026 audit plan.","full_description":"The engagement is at the reporting stage of the Bluth Company's FY2026 audit plan.","audit_type":"readiness","scope":"Corporate governance, financial reporting, technology, and compliance operations.","lead_auditor":"maeby.fuenke@bluth.example","external_firm":"","rating":"satisfactory","opinion":"na","period_start":"2026-01-01","period_end":"2026-12-31","fieldwork_start":"2026-06-14","fieldwork_end":"2026-08-28","report_date":"2026-09-10","fiscal_year":"FY2026"}},{"title":"ISO 27001 Certification Readiness","status":"PAUSED","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"ISO 27001 Certification Readiness is an engagement in the fictional Bluth Company's FY2026 audit plan.","full_description":"The engagement is at the paused stage of the Bluth Company's FY2026 audit plan.","audit_type":"external_attestation","scope":"Corporate governance, financial reporting, technology, and compliance operations.","lead_auditor":"ann.veal@bluth.example","external_firm":"Harbor & Pine Assurance LLP","rating":"not_rated","opinion":"na","period_start":"2026-01-01","period_end":"2026-12-31","fieldwork_start":"2026-06-15","fieldwork_end":"2026-08-29","report_date":"2026-09-11","fiscal_year":"FY2026"}},{"title":"Identity and Access Management Audit","status":"CANCELLED","visibility":"private","owners":["michael.bluth@bluth.example"],"fields":{"description":"Identity and Access Management Audit is an engagement in the fictional Bluth Company's FY2026 audit plan.","full_description":"The engagement is at the cancelled stage of the Bluth Company's FY2026 audit plan.","audit_type":"it_audit","scope":"Corporate governance, financial reporting, technology, and compliance operations.","lead_auditor":"michael.bluth@bluth.example","external_firm":"","rating":"not_rated","opinion":"na","period_start":"2026-01-01","period_end":"2026-12-31","fieldwork_start":"2026-06-16","fieldwork_end":"2026-08-30","report_date":"2026-10-10","fiscal_year":"FY2026"}},{"title":"Procure to Pay Audit","status":"COMPLETE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Procure to Pay Audit is an engagement in the fictional Bluth Company's FY2026 audit plan.","full_description":"The engagement is at the complete stage of the Bluth Company's FY2026 audit plan.","audit_type":"operational","scope":"Corporate governance, financial reporting, technology, and compliance operations.","lead_auditor":"george.michael@bluth.example","external_firm":"","rating":"satisfactory","opinion":"unqualified","period_start":"2026-01-01","period_end":"2026-12-31","fieldwork_start":"2026-06-17","fieldwork_end":"2026-08-31","report_date":"2026-07-12","fiscal_year":"FY2026"}},{"title":"Vendor Risk Review","status":"ADVISORY","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Vendor Risk Review is an engagement in the fictional Bluth Company's FY2026 audit plan.","full_description":"The engagement is at the advisory stage of the Bluth Company's FY2026 audit plan.","audit_type":"vendor_review","scope":"Corporate governance, financial reporting, technology, and compliance operations.","lead_auditor":"maeby.fuenke@bluth.example","external_firm":"","rating":"not_rated","opinion":"na","period_start":"2026-01-01","period_end":"2026-12-31","fieldwork_start":"2026-06-18","fieldwork_end":"2026-09-01","report_date":"2026-11-09","fiscal_year":"FY2026"}},{"title":"Incident Response Investigation","status":"FIELDWORK","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Incident Response Investigation is an engagement in the fictional Bluth Company's FY2026 audit plan.","full_description":"The engagement is at the fieldwork stage of the Bluth Company's FY2026 audit plan.","audit_type":"investigation","scope":"Corporate governance, financial reporting, technology, and compliance operations.","lead_auditor":"ann.veal@bluth.example","external_firm":"","rating":"unsatisfactory","opinion":"na","period_start":"2026-01-01","period_end":"2026-12-31","fieldwork_start":"2026-06-19","fieldwork_end":"2026-09-02","report_date":"2026-07-11","fiscal_year":"FY2026"}},{"title":"Cybersecurity Program Audit","status":"PLANNING","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Cybersecurity Program Audit is an engagement in the fictional Bluth Company's FY2026 audit plan.","full_description":"The engagement is at the planning stage of the Bluth Company's FY2026 audit plan.","audit_type":"it_audit","scope":"Corporate governance, financial reporting, technology, and compliance operations.","lead_auditor":"michael.bluth@bluth.example","external_firm":"","rating":"not_rated","opinion":"na","period_start":"2026-01-01","period_end":"2026-12-31","fieldwork_start":"2026-06-20","fieldwork_end":"2026-09-03","report_date":"2026-11-07","fiscal_year":"FY2026"}}],"risk":[{"title":"Unauthorized privileged access","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Unauthorized privileged access could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this cyber security exposure using inherent and residual ratings and an explicit treatment choice.","category":"cyber_security","subcategory":"Identity and access","taxonomies":["cyber_security"],"domains":["access_control_identity"],"likelihood":"high","impact":"critical","inherent_likelihood":"high","inherent_impact":"critical","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example"}},{"title":"Revenue cut-off error","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Revenue cut-off error could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this financial reporting exposure using inherent and residual ratings and an explicit treatment choice.","category":"financial_reporting","subcategory":"Close and consolidation","taxonomies":["financial_reporting"],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_likelihood":"medium","inherent_impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example"}},{"title":"Third-party service interruption","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Third-party service interruption could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this third party exposure using inherent and residual ratings and an explicit treatment choice.","category":"third_party","subcategory":"Vendor performance","taxonomies":["third_party_risk"],"domains":["third_party_supply_chain_risk"],"likelihood":"high","impact":"high","inherent_likelihood":"high","inherent_impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"transfer","risk_owner":"maeby.fuenke@bluth.example"}},{"title":"Privacy consent failure","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Privacy consent failure could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this privacy exposure using inherent and residual ratings and an explicit treatment choice.","category":"privacy","subcategory":"Cross-border transfer","taxonomies":["data_privacy"],"domains":["data_protection_privacy"],"likelihood":"medium","impact":"high","inherent_likelihood":"medium","inherent_impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example"}},{"title":"AI model governance gap","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"AI model governance gap could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this ai governance exposure using inherent and residual ratings and an explicit treatment choice.","category":"ai_governance","subcategory":"Model oversight","taxonomies":["ai_governance"],"domains":["ai_governance"],"likelihood":"medium","impact":"medium","inherent_likelihood":"medium","inherent_impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"accept","risk_owner":"michael.bluth@bluth.example"}},{"title":"Business continuity outage","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Business continuity outage could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this business continuity exposure using inherent and residual ratings and an explicit treatment choice.","category":"business_continuity","subcategory":"Recovery capability","taxonomies":["business_continuity"],"domains":["business_continuity_disaster_recovery"],"likelihood":"low","impact":"critical","inherent_likelihood":"low","inherent_impact":"critical","inherent_rating":"critical","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example"}},{"title":"Regulatory filing delay","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Regulatory filing delay could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this compliance regulatory exposure using inherent and residual ratings and an explicit treatment choice.","category":"compliance_regulatory","subcategory":"Regulatory change","taxonomies":["regulatory_compliance"],"domains":["compliance_audit_assurance"],"likelihood":"low","impact":"low","inherent_likelihood":"low","inherent_impact":"low","inherent_rating":"low","residual_rating":"low","treatment":"accept","risk_owner":"maeby.fuenke@bluth.example"}},{"title":"Financial statement fraud","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Financial statement fraud could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this financial reporting exposure using inherent and residual ratings and an explicit treatment choice.","category":"financial_reporting","subcategory":"Close and consolidation","taxonomies":["financial_reporting"],"domains":["financial_reporting_controls"],"likelihood":"very_high","impact":"critical","inherent_likelihood":"very_high","inherent_impact":"critical","inherent_rating":"critical","residual_rating":"critical","treatment":"avoid","risk_owner":"ann.veal@bluth.example"}},{"title":"Vendor concentration exposure","status":"CLOSED","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Vendor concentration exposure could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this third party exposure using inherent and residual ratings and an explicit treatment choice.","category":"third_party","subcategory":"Vendor performance","taxonomies":["third_party_risk"],"domains":["third_party_supply_chain_risk"],"likelihood":"medium","impact":"medium","inherent_likelihood":"medium","inherent_impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"transfer","risk_owner":"michael.bluth@bluth.example"}},{"title":"Employee safety incident","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Employee safety incident could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this people hr exposure using inherent and residual ratings and an explicit treatment choice.","category":"people_hr","subcategory":"Workforce planning","taxonomies":["people_hr"],"domains":["human_resources_personnel_security"],"likelihood":"low","impact":"high","inherent_likelihood":"low","inherent_impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example"}},{"title":"Brand trust deterioration","status":"CLOSED","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Brand trust deterioration could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this reputational exposure using inherent and residual ratings and an explicit treatment choice.","category":"reputational","subcategory":"Public perception","taxonomies":["reputational_risk"],"domains":["governance_policy_oversight"],"likelihood":"medium","impact":"medium","inherent_likelihood":"medium","inherent_impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"accept","risk_owner":"maeby.fuenke@bluth.example"}},{"title":"Strategic acquisition integration","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Strategic acquisition integration could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this strategic exposure using inherent and residual ratings and an explicit treatment choice.","category":"strategic","subcategory":"Market position","taxonomies":["strategic_risk"],"domains":["risk_assessment_management"],"likelihood":"high","impact":"high","inherent_likelihood":"high","inherent_impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example"}},{"title":"Legacy system processing failure","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Legacy system processing failure could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this operational exposure using inherent and residual ratings and an explicit treatment choice.","category":"operational","subcategory":"Process execution","taxonomies":["operational_resilience"],"domains":["asset_management_inventory"],"likelihood":"high","impact":"medium","inherent_likelihood":"high","inherent_impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example"}},{"title":"Unrated emerging risk","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Unrated emerging risk could affect Bluth's fictional objectives and compliance commitments.","full_description":"Management assesses this esg exposure using inherent and residual ratings and an explicit treatment choice.","category":"esg","subcategory":"Environmental reporting","taxonomies":["esg_sustainability"],"domains":["governance_policy_oversight"],"likelihood":null,"impact":null,"inherent_likelihood":null,"inherent_impact":null,"inherent_rating":null,"residual_rating":null,"treatment":"accept","risk_owner":"george.michael@bluth.example"}},{"title":"Business combination purchase accounting misstatement (ASC 805)","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Business combination purchase accounting misstatement (ASC 805)","category":"financial_reporting","subcategory":"business combination","taxonomies":["financial_reporting"],"domains":["financial_reporting_controls"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","full_description":"Acquisition accounting under ASC 805 concentrates judgment into a short window — screen test, purchase price allocation, goodwill assignment, measurement-period adjustments — and an error embedded in the opening balance sheet propagates into depreciation, amortization and impairment for years. Inherent risk is high while the tuck-in pipeline stays active alongside the REIT transaction. The PPA workbook review, opening-balance-sheet integration review and specialist-reliance control reduce residual risk to medium. The FY2026 Business Combination & Opening Balance Sheet Review concluded satisfactory with two lower-severity items now remediated, supporting the residual rating; treatment keeps each future deal on the same review path with technical accounting engaged from commissioning.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Capex overrun on data-center fit-out","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Capex overrun on data-center fit-out","category":"operational","subcategory":"cost overrun","taxonomies":["operational_resilience","financial_reporting"],"domains":["financial_reporting_controls","asset_management_inventory"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Capitalization / CIP misstatement on data-center builds","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Capitalization / CIP misstatement on data-center builds","category":"financial_reporting","subcategory":"capitalization","taxonomies":["financial_reporting"],"domains":["financial_reporting_controls","asset_management_inventory"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","full_description":"Construction-in-progress is the dominant balance during build-out, and miscapitalization compounds quietly: ineligible costs, stale CIP that should be in service, or capitalized interest running past energization all overstate assets and understate expense until the error is large. Inherent risk is high across a multi-campus program with thousands of monthly cost lines from Banana ERP. AFE authorization, monthly budget-versus-EAC review, CIP-to-GL reconciliation and the placed-in-service determination bring residual risk to medium. The May finding that two data halls transferred late validates both the exposure and the detection path; treatment adds a milestone-driven transfer trigger so timing no longer depends on individual notifications.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Carrier interconnect concentration risk","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Carrier interconnect concentration risk","category":"third_party","subcategory":"carrier","taxonomies":["third_party_risk","operational_resilience"],"domains":["third_party_supply_chain_risk"],"likelihood":"medium","impact":"critical","inherent_rating":"critical","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","inherent_likelihood":"medium","inherent_impact":"critical"}},{"title":"Chilled-water plant failure causing thermal event","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Chilled-water plant failure causing thermal event","category":"operational","subcategory":"cooling failure","taxonomies":["operational_resilience","business_continuity"],"domains":["physical_environmental_security","business_continuity_disaster_recovery"],"likelihood":"low","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Colocation billing incomplete or inaccurate (SOC 1 user-entity impact)","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Colocation billing incomplete or inaccurate (SOC 1 user-entity impact)","category":"financial_reporting","subcategory":"billing accuracy","taxonomies":["financial_reporting","operational_resilience"],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","full_description":"Metered colocation billing depends on the usage chain — meter, metering platform, billing engine — and a completeness break understates revenue silently for both Bluth Company and the user entities that rely on billed amounts for their own reporting, which is why billing accuracy anchors the SOC 1 objectives. Inherent risk is high because usage data is machine-generated and no customer complains about an invoice that never arrives. Read-to-billing reconciliation, interface reconciliations and the billing-run completeness review catch breaks within the cycle, holding residual at medium. Residual cannot yet drop to low: FY2026 testing raised a significant deficiency over usage-extract IPE validation, and the remediated checklist must operate for consecutive cycles before reliance is restored.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Construction delay on critical-path equipment","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Construction delay on critical-path equipment","category":"operational","subcategory":"delay","taxonomies":["operational_resilience"],"domains":["asset_management_inventory","financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Data-center availability / environmental failure (SOC 1)","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Data-center availability / environmental failure (SOC 1)","category":"business_continuity","subcategory":"availability","taxonomies":["business_continuity","operational_resilience"],"domains":["business_continuity_disaster_recovery","physical_environmental_security"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Debt covenant breach under downside case","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Debt covenant breach under downside case","category":"financial_reporting","subcategory":"DSCR breach","taxonomies":["financial_reporting","strategic_risk"],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"ERP/HRIS implementation cutover errors impair opening balances","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"ERP/HRIS implementation cutover errors impair opening balances","category":"operational","subcategory":"implementation cutover","taxonomies":["operational_resilience","financial_reporting"],"domains":["secure_configuration_change_management"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Excess or unauthorized access to financial systems","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Excess or unauthorized access to financial systems","category":"cyber_security","subcategory":"financial-system access","taxonomies":["cyber_security"],"domains":["access_control_identity"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Excess privileged access to building-management systems","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Excess privileged access to building-management systems","category":"cyber_security","subcategory":"privileged access","taxonomies":["cyber_security"],"domains":["access_control_identity","logging_monitoring_detection"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"F-gas refrigerant leak above reporting threshold","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"F-gas refrigerant leak above reporting threshold","category":"esg","subcategory":"refrigerant","taxonomies":["esg_sustainability"],"domains":["physical_environmental_security","compliance_audit_assurance"],"likelihood":"medium","impact":"medium","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Financial close error or delay leading to restatement","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Financial close error or delay leading to restatement","category":"financial_reporting","subcategory":"close & consolidation","taxonomies":["financial_reporting","reputational_risk"],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","full_description":"A close error surfacing after issuance would mean restatement of lender reporting today and public financials after the IPO — reputational damage on top of the accounting correction. Inherent risk is high because the close spans consolidation, foreign-currency translation and heavy manual-entry volume on a compressed calendar. Journal-entry approval, balance-sheet reconciliations, the close calendar and the flux review reduce residual risk to medium. The January journal-approval material weakness demonstrated the inherent case exactly as modeled; its remediation, retrospective review and verified re-test support the medium residual, and treatment now emphasizes configuration-baseline monitoring so a silently disabled workflow cannot recur undetected.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Fraudulent or unauthorized disbursement (P2P / Treasury)","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Fraudulent or unauthorized disbursement (P2P / Treasury)","category":"financial_reporting","subcategory":"disbursement fraud","taxonomies":["financial_reporting","strategic_risk"],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"low","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","full_description":"Construction-heavy procurement concentrates high-value disbursements — progress payments, retentions, emergency purchases — where fictitious vendors, duplicate pay applications or diverted remittances can extract material amounts in a single run. Inherent risk is high given payment volume and the pace of site spend. The preventive chain of three-way match, vendor-master validation with bank-detail verification, and dual-authorization release reduces residual risk to low, and the June near-duplicate progress payment demonstrated the chain holding at the final gate while also exposing vendor-master hygiene for remediation. Treatment remains mitigation with quarterly deduplication sweeps and payment-run analytics layered onto the standing controls.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"ITGC deficiency in newly implemented Banana ERP / Never Nude HR Platform undermines ICFR","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"ITGC deficiency in newly implemented Banana ERP / Never Nude HR Platform undermines ICFR","category":"operational","subcategory":"ITGC deficiency","taxonomies":["cyber_security","financial_reporting"],"domains":["access_control_identity","secure_configuration_change_management"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","full_description":"The replatforming onto Banana ERP, Never Nude HR Platform and Banana ERP reset the ITGC baseline mid-flight: access models, change pipelines and job schedules were all rebuilt, and a deficiency in any of them undermines reliance on every automated control and system-generated report downstream. Inherent risk is high in the first year on a new stack. The ITGC suite — recertification, de-provisioning, change management, backup and interface monitoring — holds residual at medium, a rating corroborated by this cycle’s findings: the recertification significant deficiency, the contractor de-provisioning lag and the emergency-change gap are all open or recently remediated. Treatment is mitigation through the in-progress IT General Controls Audit and centralized campaign tracking, with residual reassessed after Q3 evidence.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Income / property / indirect tax misstatement (ASC 740)","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Income / property / indirect tax misstatement (ASC 740)","category":"compliance_regulatory","subcategory":"tax provision","taxonomies":["financial_reporting","regulatory_compliance"],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Inventory / critical-spares valuation or obsolescence error","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Inventory / critical-spares valuation or obsolescence error","category":"operational","subcategory":"inventory valuation","taxonomies":["financial_reporting","operational_resilience"],"domains":["asset_management_inventory","financial_reporting_controls"],"likelihood":"low","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","inherent_likelihood":"low","inherent_impact":"medium"}},{"title":"Lease accounting error (ASC 842) on ground/building leases","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Lease accounting error (ASC 842) on ground/building leases","category":"financial_reporting","subcategory":"lease accounting","taxonomies":["financial_reporting"],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Loss of utility power without N+1 failover","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Loss of utility power without N+1 failover","category":"operational","subcategory":"power redundancy","taxonomies":["operational_resilience","business_continuity"],"domains":["physical_environmental_security","business_continuity_disaster_recovery"],"likelihood":"medium","impact":"critical","inherent_rating":"critical","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","inherent_likelihood":"medium","inherent_impact":"critical"}},{"title":"Material weakness in ICFR undermines IPO readiness","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Material weakness in ICFR undermines IPO readiness","category":"strategic","subcategory":"IPO readiness","taxonomies":["financial_reporting","strategic_risk","reputational_risk"],"domains":["compliance_audit_assurance","financial_reporting_controls"],"likelihood":"high","impact":"critical","inherent_rating":"critical","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","full_description":"An unremediated material weakness at filing would have to be disclosed in the registration statement, reprice or delay the offering, and invite restatement scrutiny of prior periods. Inherent exposure is critical because Bluth Company is standing up public-company ICFR while absorbing an ERP replatforming, the REIT carve-out and first-year SOC 1 obligations — three concurrent change programs that each generate deficiencies. This is the aggregating risk over the whole register: cycle-level deficiencies roll up to it through the deficiency-evaluation step of the SOX 404 readiness program. Residual exposure stays high rather than medium because the January journal-approval material weakness, though remediated and verified in June, sits inside the lookback the underwriters and auditors will evaluate. Treatment is sustained clean operation of the remediated control plus closure of the two open significant deficiencies before the audited stub period.","inherent_likelihood":"high","inherent_impact":"critical"}},{"title":"Non-compliance with energy-efficiency reporting","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Non-compliance with energy-efficiency reporting","category":"compliance_regulatory","subcategory":"energy reporting","taxonomies":["regulatory_compliance","esg_sustainability"],"domains":["compliance_audit_assurance"],"likelihood":"low","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","inherent_likelihood":"low","inherent_impact":"medium"}},{"title":"REIT carve-out & sale-leaseback accounting error","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"REIT carve-out & sale-leaseback accounting error","category":"financial_reporting","subcategory":"carve-out & sale-leaseback","taxonomies":["financial_reporting","strategic_risk"],"domains":["financial_reporting_controls"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","full_description":"The REIT transaction requires carve-out financial statements and sale-leaseback accounting under ASC 842-40, where a failed-sale conclusion would flip derecognition entirely and misallocating the deferred gain distorts both the gain schedule and ongoing rent expense. Inherent risk is high: the mechanics are novel to the team, judgment-heavy, and material to the equity story ahead of the IPO. Technical-accounting memo governance and the lease classification reviews hold residual risk at medium. The June discovery of a $340k drift in the standalone deferred-gain workbook confirms why: treatment is migrating the schedules into the lease subledger and standing up the newly designed sale-leaseback review control, currently in design review, with residual revisited once it operates for a full quarter.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Refinancing risk at facility maturity","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Refinancing risk at facility maturity","category":"financial_reporting","subcategory":"refinancing","taxonomies":["financial_reporting","strategic_risk"],"domains":["financial_reporting_controls","governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Revenue recognized incorrectly on complex colocation contracts (ASC 606)","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Revenue recognized incorrectly on complex colocation contracts (ASC 606)","category":"financial_reporting","subcategory":"revenue recognition","taxonomies":["financial_reporting"],"domains":["financial_reporting_controls"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","full_description":"Colocation agreements bundle committed power, metered usage, cross-connects and remote hands, and each element can pull recognition in a different direction under ASC 606 — or out of ASC 606 entirely where the arrangement conveys a lease. Inherent risk is high given deal velocity and the non-standard terms hyperscale customers negotiate. The deal-desk review, the lease-vs-service determination and the standalone-selling-price allocation review reduce residual risk to medium by deciding classification before billing configuration rather than discovering it at close. Treatment is mitigation through those preventive gates plus the monthly revenue flux review; residual stays medium rather than low until a full year of the deal-desk gate has operated across a complete contract mix.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Segregation-of-duties conflicts across Banana ERP / Banana ERP","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Segregation-of-duties conflicts across Banana ERP / Banana ERP","category":"financial_reporting","subcategory":"segregation of duties","taxonomies":["financial_reporting"],"domains":["access_control_identity","financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Single-site outage without DR failover","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Single-site outage without DR failover","category":"operational","subcategory":"site outage","taxonomies":["operational_resilience","business_continuity"],"domains":["business_continuity_disaster_recovery","physical_environmental_security"],"likelihood":"low","impact":"critical","inherent_rating":"critical","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"Single-source dependency on cooling OEM","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Single-source dependency on cooling OEM","category":"third_party","subcategory":"single-source vendor","taxonomies":["third_party_risk","operational_resilience"],"domains":["third_party_supply_chain_risk"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Stock-based compensation expense misstated (ASC 718)","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Stock-based compensation expense misstated (ASC 718)","category":"financial_reporting","subcategory":"stock-based comp","taxonomies":["financial_reporting"],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Subcontractor fails security due-diligence","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Subcontractor fails security due-diligence","category":"third_party","subcategory":"subcontractor","taxonomies":["third_party_risk"],"domains":["third_party_supply_chain_risk","human_resources_personnel_security"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Subservice organization reliance failure (SOC 1 CUECs)","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Subservice organization reliance failure (SOC 1 CUECs)","category":"third_party","subcategory":"subservice reliance","taxonomies":["third_party_risk"],"domains":["third_party_supply_chain_risk","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Third-party / vendor concentration & SOC-report gap","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Third-party / vendor concentration & SOC-report gap","category":"third_party","subcategory":"SOC report gap","taxonomies":["third_party_risk"],"domains":["third_party_supply_chain_risk"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"george.michael@bluth.example","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Unapproved change introduces financial-system error","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Unapproved change introduces financial-system error","category":"operational","subcategory":"change management","taxonomies":["cyber_security","financial_reporting"],"domains":["secure_configuration_change_management"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Unauthorized access to customer environments / white space","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Unauthorized access to customer environments / white space","category":"cyber_security","subcategory":"unauthorized access","taxonomies":["cyber_security","operational_resilience"],"domains":["access_control_identity","physical_environmental_security"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Unauthorized or inaccurate payroll (Never Nude HR Platform)","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Unauthorized or inaccurate payroll (Never Nude HR Platform)","category":"people_hr","subcategory":"payroll accuracy","taxonomies":["people_hr","financial_reporting"],"domains":["human_resources_personnel_security","financial_reporting_controls"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Unhedged FX exposure on cross-border debt","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Unhedged FX exposure on cross-border debt","category":"financial_reporting","subcategory":"FX","taxonomies":["financial_reporting","strategic_risk"],"domains":["financial_reporting_controls","governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"transfer","risk_owner":"george.michael@bluth.example","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Valuation error — PPA, goodwill/intangibles or 409A equity","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Valuation error — PPA, goodwill/intangibles or 409A equity","category":"financial_reporting","subcategory":"valuation","taxonomies":["financial_reporting"],"domains":["financial_reporting_controls"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","full_description":"Purchase price allocations, goodwill impairment models and 409A equity valuations all rest on specialist models whose assumptions management must own and challenge — discount rates, lease-up trajectories, power-price curves. Inherent risk is high because errors flow directly into goodwill, intangibles, impairment timing and pre-IPO compensation expense, and because reliance on third-party specialists can substitute for review rather than inform it. The specialist-reliance control, the impairment analysis review and the 409A approval gate hold residual risk at medium. Treatment is mitigation through documented challenge of key assumptions each cycle; the Q1 tuck-in finding — an evidential gap remediated and verified in July — sharpened the commissioning-stage engagement of technical accounting.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"AI accountability gaps and organizational liability","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","governance_policy_oversight","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Ambiguous responsibility across developers, deployers, and operators means no party is clearly accountable when AI causes harm; organizations face reputational damage, regulatory sanctions, and civil liability from AI failures at scale, and operational disruption when AI is unavailable.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"AI agent makes unauthorized production changes","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"low","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"An AI agent connected via MCP bypasses the suggestion-only pattern and directly modifies production data, leading to unauthorized data changes or corruption.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"AI power concentration and erosion of societal trust","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","risk_assessment_management"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Disproportionate access to data, compute, and AI talent creates winner-take-all dynamics foreclosing competition; proliferation of AI-generated synthetic media and automated influence operations degrades the shared epistemic environment and democratic institutions.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"AI privacy leakage and re-identification","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"ai_governance","taxonomies":["data_privacy"],"domains":["ai_governance","data_protection_privacy"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Model inversion and membership-inference attacks reconstruct training data or reveal individuals in the training set; AI inference re-identifies anonymized data and infers sensitive attributes; training on data without consent/legal basis creates regulatory liability.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"AI safety failures causing physical or psychological harm","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","risk_assessment_management"],"likelihood":"low","impact":"critical","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"AI errors in safety-critical systems (autonomous vehicles, medical devices, industrial controls) cause injury or death; safety-constraint violations by agentic AI, cascading failures across coupled systems, and AI-generated misinformation/deepfakes cause harm.","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"AI supply-chain compromise and provider concentration","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","third_party_supply_chain_risk","secure_development_sdlc"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Because the organization relies on third-party pretrained models, datasets, and libraries that may carry backdoors, malicious code, or bias, and concentrates on a few external AI API providers, AI-dependent workflows are exposed to both supply-chain compromise and provider outage or insolvency, resulting in compromised model behaviour or sudden loss of AI capability.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Absence of privacy-by-design and default","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy","secure_development_sdlc"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Because systems and products are built without embedding privacy controls at the architecture level, privacy protections are bolted on after launch rather than applied by default, so personal data is over-collected and exposed and costly manual remediation is required.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Absent or untested business continuity / disaster recovery plan","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"business_continuity","taxonomies":["strategic_risk","cyber_security"],"domains":["business_continuity_disaster_recovery","risk_assessment_management"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"No BCP/DR plan, or plans that exist but have never been exercised end-to-end, so a natural disaster, pandemic, civil unrest, or infrastructure failure disables critical processes with no tested recovery path.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Absent or weak change-control procedures","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["secure_configuration_change_management","secure_development_sdlc"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Changes to systems, software, hardware, or configurations without formal approval and testing (including unauthorized or poorly tested hardware/config changes) introduce new vulnerabilities, instability, or failed releases.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Abuse of rights, forged rights, and repudiation of actions","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["access_control_identity","logging_monitoring_detection"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Authorized users or administrators exploit legitimate access beyond permitted scope, fabricate or forge credentials/rights to gain privileges, and repudiate performed actions - undermining accountability and audit-trail integrity.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Acceptance of data from untrustworthy sources","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["network_communications_security","secure_development_sdlc"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Injection or acceptance of data from untrusted or malicious sources (including position-detection/tracking data) causes incorrect processing or decisions and can seed downstream integrity loss.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Adversarial attacks, data poisoning and prompt injection","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","secure_development_sdlc","vulnerability_patch_management"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Data-poisoning corrupts training data and embeds backdoors; adversarial evasion, prompt injection, and jailbreaks fool deployed models at inference; model extraction steals proprietary weights/logic - enabling harmful or policy-violating outputs.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Adversary reconnaissance and information gathering","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["logging_monitoring_detection","network_communications_security"],"likelihood":"very_high","impact":"low","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Because adversaries scan perimeters, sniff exposed networks, mine open-source and public information, and surveil personnel and processes, they build a detailed map of the IT environment and its weaknesses, resulting in better-targeted, more likely-to-succeed follow-on attacks.","inherent_likelihood":"very_high","inherent_impact":"low"}},{"title":"Adverse regulatory or policy change","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":["strategic_risk"],"domains":["compliance_audit_assurance","risk_assessment_management"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Changes in law, regulation, tax policy, or government programs materially alter the entity’s cost structure, competitive dynamics, or permissible business practices, requiring costly adaptation.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Aging hardware with no periodic replacement scheme","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"operational","taxonomies":["cyber_security"],"domains":["asset_management_inventory","business_continuity_disaster_recovery"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Because maintenance routines and replacement schedules are absent, equipment is run beyond its reliable service life, so hardware fails - including correlated, pervasive disk failures from same-batch aging - resulting in outages and data loss.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Applications running with excessive privilege / insecure design","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["secure_development_sdlc","secure_configuration_change_management"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Applications or services running under privileged accounts, opening unnecessary network connections, or lacking secure-by-design architecture mean a single compromise grants broad system access and expands attack surface.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Assets not returned upon employee termination","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"people_hr","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Departing employees or contractors fail to return company assets (laptops, mobile devices, access tokens), potentially retaining access to company data or intellectual property.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Attacks by capable, motivated threat actors","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["risk_assessment_management","logging_monitoring_detection"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Because capable, motivated threat actors - outsiders, privileged and non-privileged insiders, organized groups, competitors, malicious partners or suppliers, and nation-states - actively target the organization's cyber resources, deliberate attacks are attempted against its systems and data, resulting in compromise, disruption, or theft when defenses are outmatched.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Brand and reputational crisis","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"reputational","taxonomies":["strategic_risk"],"domains":["risk_assessment_management","governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Product-safety/quality failures, executive misconduct, data breaches, adverse media, or viral social-media/activist campaigns erode customer trust, investor confidence, partnerships, and brand equity - with long-term value loss exceeding near-term financial impact.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Client intake, documentation and account-management failures","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"operational","taxonomies":[],"domains":["risk_assessment_management","access_control_identity"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Missing signed agreements, incomplete legal/ISDA documentation, unretained KYC/AML records, misfiled client files, unauthorized access to client accounts, and negligent loss of client assets held in custody.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Client selection, sponsorship and exposure-limit breaches","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":[],"domains":["risk_assessment_management","compliance_audit_assurance"],"likelihood":"low","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Failure to investigate clients per guidelines, exceeding single-counterparty exposure limits without approval, and sponsoring transactions without adequate counterparty-risk assessment or AML/CTF screening.","inherent_likelihood":"low","inherent_impact":"medium"}},{"title":"Client suitability, disclosure and fiduciary breaches","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":[],"domains":["compliance_audit_assurance","risk_assessment_management"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Recommending unsuitable products, failing to disclose conflicts of interest, breaching fiduciary duty, KYC failures, inadequate disclosure of fees/risks, negligent advisory activities, and product flaws causing systematic customer harm.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Climate transition risk - carbon pricing and stranded assets","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"esg","taxonomies":["strategic_risk"],"domains":["risk_assessment_management","governance_policy_oversight"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Carbon taxes, cap-and-trade, and mandatory Scope 1-2-3 reporting increase operating costs or strand carbon-intensive assets; failure to credibly plan a net-zero transition jeopardizes access to capital and changing consumer preferences.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Cloud multi-tenancy isolation and data-scavenging exploits","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["network_communications_security","data_protection_privacy","secure_configuration_change_management"],"likelihood":"low","impact":"high","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Adversary exploits multi-tenancy in a cloud environment to observe organizational processes, violates isolation mechanisms, or scavenges data used and deleted by cloud processes, compromising confidentiality and availability.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Communications interception, eavesdropping and man-in-the-middle","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["network_communications_security","cryptography_key_management","data_protection_privacy"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Passive monitoring/sniffing of communications, interception of unencrypted or weakly encrypted channels, wireless interception, and man-in-the-middle attacks capture or corrupt transmitted data - including TEMPEST-type emanation capture.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Competitive displacement by established GRC platforms","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"strategic","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Established GRC platforms (AuditBoard, ServiceNow, Workiva) with larger sales teams and brand recognition capture market share, limiting Bluth Company growth and threatening long-term viability of the business and its security program.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Competitive disruption and business-model obsolescence","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"strategic","taxonomies":["strategic_risk"],"domains":["risk_assessment_management","governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"A new entrant with a superior model, lower cost, or breakthrough technology captures share faster than the company can respond; industry/technology/customer shifts render the existing business model obsolete.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Compromised or counterfeit certificates / certificate authority","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["cryptography_key_management","network_communications_security"],"likelihood":"low","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Adversary counterfeits or compromises a certificate authority so that malware or connections appear legitimate, defeating trust in TLS and code-signing and enabling man-in-the-middle or malicious-code delivery.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Coordinated multi-stage / APT campaigns","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["logging_monitoring_detection","incident_management_response","network_communications_security"],"likelihood":"medium","impact":"critical","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Adversary coordinates continuous, adaptive, multi-staged campaigns (hopping across systems, combining insider/outsider/supply-chain vectors, spreading from existing presence) to persist and progressively undermine mission/business functions.","inherent_likelihood":"medium","inherent_impact":"critical"}},{"title":"Core process breakdown and inability to scale","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"operational","taxonomies":["strategic_risk"],"domains":["risk_assessment_management","governance_policy_oversight"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Poorly designed, undocumented, or poorly executed business processes lead to errors, rework, cost overruns, service failures, and inability to scale operations reliably; large change programs fail to deliver benefits on time and budget.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Corruption or integrity loss of critical data","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["data_protection_privacy","secure_development_sdlc"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Intentional or accidental alteration, deletion, defacement, or injection of false-but-believable data into systems (including web defacement and data from untrustworthy sources) renders data inaccurate and erodes confidence in it.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Credentials and sensitive data transmitted in clear text","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["cryptography_key_management","network_communications_security"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Authentication credentials or sensitive system communications transmitted unencrypted over networks, and absence of mutual sender/receiver authentication, enable interception, credential theft, and spoofing.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Credit and market (rate/FX) risk","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":null,"taxonomies":["strategic_risk"],"domains":["risk_assessment_management"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"transfer","risk_owner":"ann.veal@bluth.example","description":"Counterparty/customer default exceeding collateral, receivables concentration in deteriorating credits, and unhedged exposure to interest-rate, foreign-exchange, commodity, or equity movements causing material P&L or cash-flow volatility.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Critical subservice organization (firm) failure leaves governance, finance, and security oversight vacuum","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"third_party","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"low","impact":"critical","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"The fractional operations firm provides bookkeeping, vCISO oversight, legal, HR administration, and compliance advisory. Sudden termination, insolvency, or breach of contract leaves Bluth Company without independent security oversight, financial execution, policy approval authority, and HR continuity simultaneously. The four-person org has no internal capacity to absorb these functions.","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"Critical talent loss, scarcity and succession gaps","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"people_hr","taxonomies":["strategic_risk","cyber_security"],"domains":["human_resources_personnel_security","business_continuity_disaster_recovery"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Departure of key executives or irreplaceable specialists without succession or knowledge-transfer plans, plus inability to recruit/retain scarce skills (cyber, data, AI/ML), causing loss of institutional knowledge and execution capacity. Also covers loss of key personnel disrupting operations dependent on specialist knowledge.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Critical vendor failure, insolvency or concentration","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"third_party","taxonomies":["strategic_risk"],"domains":["third_party_supply_chain_risk","business_continuity_disaster_recovery"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"A key supplier, SaaS provider, or outsourced partner becomes insolvent, exits the market, or suffers a prolonged outage; sole-source and shared-tier concentration (multiple tier-1 vendors on a common tier-2) creates hidden single points of failure with no backup.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Cross-border personal-data transfer without safeguards","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy","compliance_audit_assurance","third_party_supply_chain_risk"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Transferring personal data to jurisdictions lacking equivalent protection without SCCs, BCRs, adequacy decisions, or other recognized mechanisms, exposing individuals and the organization to legal risk.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Customer concentration risk - over-reliance on key clients","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"strategic","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Revenue concentration in a small number of key customers creates financial vulnerability if any major customer churns, reduces scope, or delays payment, potentially threatening the organization's ability to maintain the security program and platform operations.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Data exfiltration and theft of information by attackers","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["strategic_risk"],"domains":["data_protection_privacy","network_communications_security","logging_monitoring_detection"],"likelihood":"medium","impact":"critical","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Adversary (outsider, insider, nation-state, or competitor) installs malware or sniffers to locate and exfiltrate sensitive/proprietary information, or steals data by external actors - including systems-security losses from hacking.","inherent_likelihood":"medium","inherent_impact":"critical"}},{"title":"Data-quality and IPE integrity failures in reporting","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"financial_reporting","taxonomies":["strategic_risk"],"domains":["financial_reporting_controls","data_protection_privacy","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Poor data lineage, inconsistent master-data definitions, or uncontrolled data transformation (weak IPE completeness/accuracy) cause management decisions and regulatory reports to rest on inaccurate or incomplete data.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Denial-of-service and system saturation","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["strategic_risk"],"domains":["network_communications_security","business_continuity_disaster_recovery"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Simple, targeted, or distributed denial-of-service attacks, wireless jamming, and saturation of systems or networks (adversarial or excessive legitimate load) make resources unavailable to intended users.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Deployment of prohibited AI practices (EU AI Act Art.5)","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","compliance_audit_assurance"],"likelihood":"low","impact":"critical","inherent_rating":"high","residual_rating":"high","treatment":"avoid","risk_owner":"michael.bluth@bluth.example","description":"Use of prohibited AI: subliminal/manipulative techniques, social scoring, untargeted facial-image scraping, real-time/post remote biometric identification for law enforcement, sensitive-attribute biometric categorization, and emotion recognition in work/education settings.","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"Developer self-approves and deploys own change via CI/CD","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"operational","taxonomies":["operational_resilience"],"domains":["secure_configuration_change_management"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"No segregation between the author and the deployer of a change through Model Home Data Lake CI, Cloud Build or Terraform.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Discrimination, harassment and hostile-workplace culture","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"people_hr","taxonomies":["strategic_risk"],"domains":["human_resources_personnel_security"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Systemic harassment or discrimination (race, gender, age, disability, etc.), pay-equity violations, retaliation, and inadequate speak-up channels resulting in regulatory action, litigation, attrition, and reputational harm.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Discriminatory outcomes from AI in employment","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","human_resources_personnel_security","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Because AI used for recruitment, selection, promotion, task allocation, or worker monitoring (Annex III(4)) operates without bias mitigation, worker transparency, human oversight, or a data-protection impact assessment, it can decide about workers on biased or opaque grounds, resulting in discriminatory or unfair employment outcomes.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Domain hijacking or DNS integrity failure at the registrar","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["network_communications_security"],"likelihood":"low","impact":"critical","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Compromise of the Sudden Valley Network registrar account, an unauthorized DNS zone change, or a lapsed registration redirects bluth.example traffic and email (MX/SPF/DKIM), enables fraudulent DNS-validated certificate issuance, or takes the product domain offline.","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"ESG disclosure gaps and greenwashing","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"esg","taxonomies":["strategic_risk"],"domains":["compliance_audit_assurance","governance_policy_oversight"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Public ESG commitments (carbon neutrality, DEI, supply-chain ethics) unsubstantiated by verifiable data, and non-compliant or inaccurate mandatory sustainability disclosures (CSRD, California SB 253/261, SEC climate rule) - inviting enforcement, investor backlash, and NGO campaigns.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Emergent behaviour and unsafe AI system integration","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","secure_development_sdlc"],"likelihood":"medium","impact":"high","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Large-scale or multi-model pipelines exhibit emergent capabilities/failures not present in any component and not predictable from component testing; integration with legacy systems introduces interface mismatches and configuration errors.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Employment-practice and labor-law violations","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"people_hr","taxonomies":[],"domains":["human_resources_personnel_security","compliance_audit_assurance"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Wrongful termination, wage-and-hour and overtime violations, benefit disputes, worker misclassification, whistleblower-protection breaches, and labor grievances/strike action causing litigation and operational loss.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Environmental degradation of equipment (dust, humidity, temperature, EMI)","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"operational","taxonomies":["cyber_security"],"domains":["physical_environmental_security"],"likelihood":"low","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Equipment sited without environmental controls suffers from dust, corrosion, freezing, humidity, voltage or temperature variation, and electromagnetic/thermal radiation or EMP, causing malfunction or failure.","inherent_likelihood":"low","inherent_impact":"medium"}},{"title":"Environmental footprint of AI training and infrastructure","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"esg","taxonomies":[],"domains":["ai_governance","risk_assessment_management"],"likelihood":"medium","impact":"low","inherent_rating":"low","residual_rating":"low","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Training and large-scale inference consume disproportionate energy and generate greenhouse-gas emissions; rapid AI-hardware obsolescence produces e-waste and pressures critical-mineral supply chains, with environmental and geopolitical risk.","inherent_likelihood":"medium","inherent_impact":"low"}},{"title":"Environmental regulatory non-compliance","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":[],"domains":["compliance_audit_assurance","risk_assessment_management"],"likelihood":"low","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Unauthorized emissions or discharges, improper hazardous-waste handling, missing permits, or non-compliance with PFAS/chemical-reporting rules under EPA/RCRA/Clean Air & Water Acts - driving penalties and remediation.","inherent_likelihood":"low","inherent_impact":"medium"}},{"title":"Erosion of individual trust and confidence in data practices","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy","awareness_training"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Systemic failure to meet reasonable privacy expectations undermines confidence in products and institutions, causing disengagement, reputational damage, and reduced adoption - an organizational as well as individual harm.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Excessive Cloud SQL access exposes regulated PII","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Broad PostgreSQL roles let users read PII beyond need-to-know.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Excessive Lucille Identity Cloud group membership grants unintended access","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["access_control_identity"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Broad Lucille Identity Cloud Group membership over-provisions downstream federated applications.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Excessive collection, purpose creep and secondary use","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Collecting more personal data than necessary (data-minimization failure) and using it for purposes materially different from those disclosed without fresh notice/consent, expanding attack surface and violating purpose-limitation.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Excessive privilege and wrong assignment of access rights","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security","data_privacy"],"domains":["access_control_identity","data_protection_privacy"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Overly broad or wrongly assigned access rights, applications/services running with excessive privileges, and failure to enforce least privilege - a compromise or insider then gains broad access to systems and data.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Excessive surveillance, appropriation and induced disclosure","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Pervasive monitoring beyond stated purpose (behavioral analytics, always-on telemetry, employee monitoring), using identity/data for organizational benefit without consent, and coercing individuals to over-share - causing chilling effects and loss of autonomy.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Exploitation of known, unpatched vulnerabilities","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["vulnerability_patch_management","secure_configuration_change_management"],"likelihood":"high","impact":"high","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Use of software with publicly known, unpatched flaws (CVEs) that adversaries readily exploit - including recently discovered vulnerabilities exploited before mitigations are in place, and internal-system vulnerability exploitation.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"External fraud - third-party theft, forgery, payment and account fraud","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"operational","taxonomies":["strategic_risk"],"domains":["access_control_identity","risk_assessment_management"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Third parties defraud the entity: cheque/payment-card forgery, counterfeit currency, identity theft, account takeover with stolen credentials, fraudulent loan applications, and first-party (bust-out) fraud by customers.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Failed M&A, integration or divestiture","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"strategic","taxonomies":["strategic_risk"],"domains":["risk_assessment_management","financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Acquisitions fail to achieve synergies due to cultural misalignment, IT-integration failure, or customer attrition; overpayment and hidden liabilities materialise as goodwill impairment; divestitures disrupt shared-service dependencies.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Failed or inaccurate mandatory regulatory reporting","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":[],"domains":["compliance_audit_assurance","financial_reporting_controls"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Late or inaccurate regulatory transaction reporting, missed regulatory-return deadlines, inaccurate risk reporting to management, and errors in suspicious-activity reporting - breaching disclosure obligations to regulators and stakeholders.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Failure to detect, assess, and notify breaches on time","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["incident_management_response","data_protection_privacy","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Failure to detect, assess, and notify affected individuals and regulators of personal-data breaches within required timeframes and content (GDPR Art.33/34, HIPAA breach rule), resulting in sanctions and compounded individual harm.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Financial-statement fraud and management override","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"financial_reporting","taxonomies":["strategic_risk"],"domains":["financial_reporting_controls","compliance_audit_assurance"],"likelihood":"low","impact":"critical","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Intentional misstatement through fictitious revenue, phantom inventory/assets, ghost-employee payroll, or management override of controls - inflating results and deceiving investors and regulators.","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"Firm-internal segregation of duties claimed but not enforced (paper-only)","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"third_party","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"If the same partner at the firm performs bookkeeping AND vCISO sign-off AND internal-audit sampling AND advisory services, the SoD compensating control is conceptual only. The firm becomes a single point of judgment failure equivalent to the CEO conflict it was meant to mitigate.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Model Home Data Lake outage without tested recovery causes prolonged downtime","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"business_continuity","taxonomies":["business_continuity"],"domains":["business_continuity_disaster_recovery"],"likelihood":"low","impact":"high","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"A regional Model Home Data Lake incident with no cross-zone failover or untested restore causes extended downtime.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"GPAI transparency, systemic-risk and synthetic-content obligations","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","third_party_supply_chain_risk","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"GPAI providers failing transparency/copyright/training-data obligations; systemic-risk models (>10^25 FLOPs) lacking red-teaming, incident reporting, and cybersecurity; unlabeled deepfake/synthetic content; and concentration of GPAI capability creating ecosystem single points of failure.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Geopolitical, macroeconomic and sovereign risk","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"strategic","taxonomies":["strategic_risk"],"domains":["risk_assessment_management","third_party_supply_chain_risk"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Armed conflict, political instability, sanctions, trade-policy reversals (tariffs, export bans, data-localization, forced tech transfer), expropriation/nationalization, and adverse macroeconomic cycles disrupt operations, supply chains, and cost structures.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Hardware and equipment failure","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"operational","taxonomies":[],"domains":["business_continuity_disaster_recovery","asset_management_inventory"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Malfunction or breakdown of storage, processing, communications, sensor, controller, or display equipment (aging, resource depletion, disk errors) disrupting availability or integrity - including intermittent/degraded operation producing incorrect results.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Harm to due process and democratic integrity from AI","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","governance_policy_oversight","compliance_audit_assurance"],"likelihood":"low","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Because AI assisting judicial decisions or intended to influence elections or voter behaviour (Annex III(8)) operates without human oversight, transparency, and integrity safeguards, it can distort legal outcomes or manipulate electorates, resulting in threats to due process and democratic integrity.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Harmful AI bias and discrimination against protected groups","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"ai_governance","taxonomies":["data_privacy"],"domains":["ai_governance","data_protection_privacy","compliance_audit_assurance"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Models encode/amplify historical bias, producing allocative harm (biased hiring/lending/housing/benefits), representational harm (stereotyping), and evaluation bias masking disparate subgroup performance - systematically disadvantaging protected groups.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"IT resilience failure - unplanned outage, data loss, slow recovery","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"business_continuity","taxonomies":["strategic_risk"],"domains":["business_continuity_disaster_recovery","logging_monitoring_detection"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Critical technology infrastructure or applications experience unplanned outages, data loss, or prolonged recovery times - including failure of DR systems to activate - disrupting operations and harming stakeholders.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Illegal processing of personal or sensitive data","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Processing personal or sensitive data without legal authority, consent, or in violation of regulatory requirements - a data-protection breach with legal, privacy, and reputational consequences.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Improper business or market practices","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":[],"domains":["compliance_audit_assurance","governance_policy_oversight"],"likelihood":"low","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Losses from antitrust violations, market manipulation (spoofing, layering, front-running), benchmark/rate rigging, unlicensed business activity, and sanctions/export-control violations in the conduct of business.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Inaccurate, unreliable or hallucinated AI outputs","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"ai_governance","taxonomies":[],"domains":["ai_governance","risk_assessment_management"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"AI outputs contain factual errors, hallucinations, or confidently wrong predictions; inappropriate proxy metrics, overfitting/underfitting, or insufficient pre-deployment testing undermine trust in decisions made on their basis.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Inadequate board and management oversight of risk and control","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"strategic","taxonomies":["strategic_risk","cyber_security"],"domains":["governance_policy_oversight","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Because board and management oversight of risk and control is weak - unclear tone at the top, ineffective board composition or independence, poor committee structure, and limited senior-management commitment - control priorities are not enforced and resources are withheld, so risks accumulate unmanaged and control failures go uncorrected across the entity.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Inadequate on-call coverage misses customer SLA commitments","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"operational","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"With two people on rotation (CEO + part-time reviewer), real 24/7 oncall is structurally impossible. If customer MSAs commit to faster response times than the rotation can deliver, the org breaches contract and fails CC7.3 evaluation.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Inadequate or absent risk assessment process","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"operational","taxonomies":["strategic_risk","data_privacy"],"domains":["risk_assessment_management","governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"No systematic process to identify, analyse, evaluate, and treat risk - including missing fraud-risk assessment and no ongoing risk monitoring - leaving material exposures unidentified and untreated before they materialise.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Inadequate physical protection and access controls","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["physical_environmental_security","access_control_identity"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Buildings and sensitive areas lacking perimeter security, key-card/lock/mantrap controls, or supervision of visitors and cleaning/outside staff allow unauthorized physical access to equipment and media - including tailgating past physical checks.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Inadequate security awareness and training","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security","data_privacy"],"domains":["awareness_training","human_resources_personnel_security"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Personnel lacking security awareness and training are more likely to make harmful mistakes, misconfigure systems, or be deceived - providing weak human defence and undermining every technical control. Includes insufficient privacy training.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Inadequate transparency, notice and deceptive privacy communications","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy","awareness_training"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Failure to give clear, timely notice of collection, use, retention, and sharing; misleading or dark-pattern consent flows; and failure to disclose automated decision-making - undermining meaningful consent and compounding power imbalance.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Incomplete asset inventory and classification","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"operational","taxonomies":["cyber_security"],"domains":["asset_management_inventory","data_protection_privacy"],"likelihood":"high","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"No authoritative inventory of information and associated assets, missing ownership, acceptable-use, classification, labelling, or handling rules - preventing effective protection, risk assessment, and secure disposal.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Ineffective ICFR / undisclosed material weakness","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"financial_reporting","taxonomies":["strategic_risk"],"domains":["financial_reporting_controls","compliance_audit_assurance","governance_policy_oversight"],"likelihood":"medium","impact":"critical","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Because internal control over financial reporting is not maintained effectively - material weaknesses undetected or undisclosed and certifications signed despite known deficiencies - financial statements may be materially misstated and filings delayed or restated, resulting in SEC enforcement, delisting, securities-fraud liability, and loss of investor confidence.","inherent_likelihood":"medium","inherent_impact":"critical"}},{"title":"Insufficient personnel screening and vetting","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"people_hr","taxonomies":["cyber_security"],"domains":["human_resources_personnel_security","access_control_identity"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Failure to vet employees, contractors, or third parties before granting access enables insider threats or introduces compromised individuals; adversaries may deliberately place subverted individuals into (privileged) positions.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Intellectual property loss or infringement","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":["strategic_risk"],"domains":["compliance_audit_assurance","asset_management_inventory"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Patent, trade-secret, copyright, or trademark infringement claims (competitors or NPEs), loss of key IP through invalidity rulings, inadequate protection of proprietary technology, or inability to enforce own IP against infringers.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Internal fraud - asset misappropriation, embezzlement, forgery","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"operational","taxonomies":["strategic_risk"],"domains":["governance_policy_oversight","financial_reporting_controls","risk_assessment_management"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Employees defraud the entity for financial gain: embezzlement or theft of company/client funds, fraudulent expense/payroll claims, forgery to obtain unauthorized disbursements, bribery/kickback schemes, insider trading on own account, and wilful tax evasion.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Internet-exposed or misconfigured systems","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["secure_configuration_change_management","network_communications_security","vulnerability_patch_management"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Adversary gains access through the Internet to systems not authorized for Internet connectivity or that do not meet configuration requirements, and exploits attacks over unauthorized ports, protocols, and services.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Lack of independent audit and compliance review","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":["cyber_security","strategic_risk"],"domains":["compliance_audit_assurance","governance_policy_oversight"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Because independent internal and external audit and review of information security are not performed, control deficiencies and non-conformities are neither detected nor challenged, so weaknesses persist unremediated and management and the board lose reliable assurance over control effectiveness.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Leaked CI/CD pipeline secret grants environment access","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["secure_development_sdlc"],"likelihood":"low","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"A hardcoded or over-scoped Model Home Data Lake CI / Cloud Build credential is exfiltrated.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Litigation, investigation and enforcement exposure","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":["strategic_risk"],"domains":["compliance_audit_assurance","governance_policy_oversight"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"transfer","risk_owner":"michael.bluth@bluth.example","description":"Adverse judgments, class actions, contract/IP disputes, government subpoenas, DOJ/FTC/SEC investigations, consent decrees, or deferred-prosecution agreements imposing penalties, remediation, and management distraction.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Loss of essential services (power, HVAC, telecoms)","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"business_continuity","taxonomies":["cyber_security"],"domains":["business_continuity_disaster_recovery","physical_environmental_security"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Interruption of power supply, air-conditioning/water utilities, or telecommunications - from unstable grids, single power feeds, UPS/generator failure, or carrier/fiber outages - stops operations or harms equipment and personnel.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Loss of system maintainability","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"operational","taxonomies":["cyber_security"],"domains":["secure_configuration_change_management","secure_development_sdlc"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Loss of the ability to maintain, update, or repair information systems due to missing documentation, tools, skills, or unversioned software - leaving systems unpatchable and increasingly fragile over time.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Malicious supply-chain injection of tampered hardware/software","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["third_party_supply_chain_risk","secure_development_sdlc","secure_configuration_change_management"],"likelihood":"low","impact":"critical","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Adversary creates false-front suppliers or intercepts the supply chain to insert counterfeit or tampered hardware, corrupted software/firmware, or malicious components into products and information systems.","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"Malware delivery, insertion and compromise of systems","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["secure_development_sdlc","network_communications_security","vulnerability_patch_management"],"likelihood":"high","impact":"critical","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Adversary crafts and delivers known, modified, or targeted malware (via email, web, removable media, or downloadable software) and compromises system software to take control, exfiltrate data, or degrade functions.","inherent_likelihood":"high","inherent_impact":"critical"}},{"title":"Manual journal entries and management-override risk","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"financial_reporting","taxonomies":[],"domains":["financial_reporting_controls","logging_monitoring_detection"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Manual/automated journal entries posted with transposition errors, wrong account codes, or amounts; recurring entries not updated; and top-side entries used to override controls and manage earnings at period-end.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Misconfigured Model Home Data Lake resource exposes data publicly","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["secure_configuration_change_management"],"likelihood":"medium","impact":"critical","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"An open Cloud Storage bucket, over-permissive firewall rule, or public Cloud SQL instance leaks sensitive data.","inherent_likelihood":"medium","inherent_impact":"critical"}},{"title":"Missing MFA on Lucille Identity Cloud enables account takeover","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["access_control_identity"],"likelihood":"low","impact":"critical","inherent_rating":"high","residual_rating":"low","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Credential stuffing or phishing succeeds against a Lucille Identity Cloud account without 2-Step Verification.","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"Missing or insufficient logging and audit trails","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["logging_monitoring_detection","incident_management_response"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Absence of logging/audit trails means unauthorized activity cannot be detected, investigated, or attributed, and adversary actions (obfuscation of intrusion detection, tampering with logs) go unnoticed.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Missing or insufficient security and privacy policies","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":["cyber_security","data_privacy"],"domains":["governance_policy_oversight","data_protection_privacy"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Because documented, approved, and enforced security and privacy policies are missing and roles and duties are undefined, personnel operate without guidance on required controls and behaviours, so controls are applied inconsistently and accountability gaps leave violations undetected and unaddressed.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Missing role-based and ongoing security/privacy training","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security","data_privacy"],"domains":["awareness_training","human_resources_personnel_security"],"likelihood":"high","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Because no role-based training program or ongoing awareness refresh exists for staff handling sensitive data or privileged systems, personnel cannot execute security procedures correctly or recognize evolving attacks, so avoidable errors and successful social-engineering compromises follow.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Missing security terms in contracts and no disciplinary process","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":["cyber_security"],"domains":["human_resources_personnel_security","governance_policy_oversight","third_party_supply_chain_risk"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Employment and supplier contracts omit security/confidentiality obligations, and there is no disciplinary process for security violations - removing legal recourse and the deterrent effect against repeat offenders.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"No or insufficient incident-response procedures","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security","data_privacy"],"domains":["incident_management_response"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Without documented, tested incident-response procedures, breaches and failures are handled inconsistently, slowly, or ineffectively, prolonging exposure and amplifying loss.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"No security monitoring or supervision of privileged activity","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["logging_monitoring_detection","incident_management_response"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Absence of monitoring mechanisms and supervision of personnel actions (especially privileged users) allows undetected misuse, and no process exists to supervise and escalate detected security breaches.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Orphaned or stale Lucille Identity Cloud accounts retain access","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["access_control_identity"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Leavers or role-changers keep Lucille Identity Cloud entitlements that cascade to Model Home Data Lake and Model Home Data Lake.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Over-privileged Model Home Data Lake IAM principal is compromised","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["access_control_identity"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"A leaked service-account key or over-broad role grants an attacker broad access to the Model Home Data Lake organization.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Over-retention of PII in Cloud SQL breaches privacy commitments","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"compliance_regulatory","taxonomies":["regulatory_compliance"],"domains":["data_protection_privacy"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"PII kept past its lawful basis or documented retention schedule.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Overstatement of assets/revenue (existence & occurrence)","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"financial_reporting","taxonomies":[],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Revenue, receivables, inventory, capitalized assets, prepaid expenses, treasury investments, or tax assets recorded without underlying existence or occurrence - inflating the balance sheet and income statement.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Phishing, spear-phishing and social engineering","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["awareness_training","access_control_identity"],"likelihood":"very_high","impact":"high","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Adversary counterfeits trustworthy communications (email, phone, spoofed websites) to trick individuals - including high-value executives - into revealing credentials or sensitive information, or into enabling wire-transfer/BEC fraud.","inherent_likelihood":"very_high","inherent_impact":"high"}},{"title":"Physical and cyber-physical attacks on facilities and infrastructure","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["physical_environmental_security","business_continuity_disaster_recovery"],"likelihood":"low","impact":"high","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Adversary conducts physical attacks on facilities (arson) or supporting infrastructure (cuts power/water), or cyber-physical attacks (remotely altering HVAC), damaging systems and supporting utilities.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Physical climate risk to facilities and supply chains","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"esg","taxonomies":["strategic_risk"],"domains":["business_continuity_disaster_recovery","physical_environmental_security","third_party_supply_chain_risk"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"transfer","risk_owner":"michael.bluth@bluth.example","description":"Extreme weather (flooding, wildfires, hurricanes, heat stress), sea-level rise, and resource scarcity damage owned/leased facilities, disrupt supplier operations, and impair logistics beyond insurance coverage.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Physical damage to assets from disaster, terrorism or vandalism","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"business_continuity","taxonomies":[],"domains":["physical_environmental_security","business_continuity_disaster_recovery"],"likelihood":"low","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"transfer","risk_owner":"george.michael@bluth.example","description":"Loss or damage to facilities, equipment, or physical property from natural disaster (earthquake, flood, hurricane, wildfire), terrorism, civil unrest, vandalism, utility-infrastructure damage, vehicle/aircraft collision, or environmental contamination.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Poor configuration management and insecure baseline drift","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["secure_configuration_change_management","vulnerability_patch_management"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Without documented, enforced baseline configurations and change control, systems drift into insecure states, contain unauthorized changes, or expose unnecessary network services, expanding attack surface.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Poor network architecture and unprotected public connections","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["network_communications_security","secure_configuration_change_management"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Because externally-facing connections lack perimeter controls (firewalls, DMZ) and the network lacks segmentation, redundancy, and defense-in-depth, attackers can breach the boundary and move laterally and single points of failure go unmitigated, resulting in intrusion, data exfiltration, and outage.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Power imbalance and loss of self-determination over personal data","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy","ai_governance"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Structural informational asymmetry (take-it-or-leave-it consent, opaque algorithmic decisions) and inability to correct, delete, or restrict processing deprive individuals of meaningful control over their own data and narrative.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Privacy-program non-compliance (GDPR, CCPA, state laws)","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy","compliance_audit_assurance"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Failure to honour data-subject rights (access, deletion, portability, restriction) on time, missing lawful-basis/consent documentation, defective consent mechanisms, invalid cross-border transfer mechanisms, or inadequate notices - driving fines and private rights of action.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Ransomware disrupting operations and data availability","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["strategic_risk"],"domains":["secure_development_sdlc","business_continuity_disaster_recovery","incident_management_response"],"likelihood":"medium","impact":"critical","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Criminal groups deploy ransomware that encrypts systems and data, disrupting operations, causing losses, and demanding extortion payment - a high-impact convergence of malware, availability, and continuity risk.","inherent_likelihood":"medium","inherent_impact":"critical"}},{"title":"Re-identification and unanticipated revelation from data","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Insufficient de-identification/pseudonymization, plus inference or linkage attacks and metadata leakage, re-identify individuals or reveal information they did not intend to disclose - causing embarrassment, harm, and regulatory exposure.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Remote spying and shoulder-surfing of screens/documents","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["physical_environmental_security","data_protection_privacy"],"likelihood":"medium","impact":"low","inherent_rating":"low","residual_rating":"low","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Observation of screens, documents, or activities from a distance (shoulder surfing, optical surveillance) and interception of compromising emanation signals capture sensitive information without system access.","inherent_likelihood":"medium","inherent_impact":"low"}},{"title":"Remote-work, mobile and split-tunneling exposure","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["network_communications_security","access_control_identity","data_protection_privacy"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Uncontrolled work outside the premises, split-tunneling, and exploitation of mobile devices/personal systems outside physical and firewall protection expose information through insecure environments and reintroduce compromised devices into the enterprise.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Residual data on improperly disposed or re-used media","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"privacy","taxonomies":["cyber_security"],"domains":["data_protection_privacy","asset_management_inventory"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Retrieval of recycled or discarded media, and disposal/reuse of storage without proper erasure, exposes residual sensitive information; also insecure/incomplete data deletion in multi-tenant/cloud environments.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Revenue sustainability and cash flow constraints","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"strategic","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"medium","impact":"critical","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Insufficient revenue generation or cash flow constraints limit the organization's ability to invest in security infrastructure, hire qualified security personnel, maintain compliance certifications, or fund ongoing operations.","inherent_likelihood":"medium","inherent_impact":"critical"}},{"title":"Secrets sprawl outside Secret Manager are leaked","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["cryptography_key_management"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Hardcoded or unrotated credentials stored outside Model Home Data Lake Secret Manager are exposed.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Sensitive data leaked through uncontrolled transfer channels","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"low","impact":"critical","inherent_rating":"critical","residual_rating":"critical","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Sensitive data is transferred through unapproved or insecure channels (personal email, unauthorized cloud storage, unencrypted transfer) leading to data leakage.","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"Single code reviewer dependency creates change-management bottleneck and SoD failure on reviewer's own changes","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"operational","taxonomies":[],"domains":["governance_policy_oversight"],"likelihood":"high","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"With one part-time code reviewer, their unavailability blocks all merges or pressures the CEO to self-merge - defeating the SoD compensating control for code changes. Additionally, when the reviewer authors code (hotfix, infra, oncall), no one is positioned to review their PRs without recreating the original conflict.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Single-site / single-region / single-supply concentration","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"business_continuity","taxonomies":["cyber_security"],"domains":["business_continuity_disaster_recovery","network_communications_security"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Headquarters, data centers, or manufacturing concentrated in one region, single power feed or network path with no redundancy, and no failover - so one catastrophe or outage disables the whole service. Includes backup-facility loss destroying backups.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Software and information-system failure","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"operational","taxonomies":[],"domains":["business_continuity_disaster_recovery","secure_development_sdlc"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Failure or malfunction of operating-system, networking, or application software (defects, resource depletion, failed releases) causing loss of availability/integrity and impeding mission/business functions - including core banking/payments outages.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Stakeholder trust and social-license erosion","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"reputational","taxonomies":["strategic_risk"],"domains":["governance_policy_oversight","risk_assessment_management"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Gradual loss of trust and social license among customers, employees, investors, regulators, and communities - from perceived values misalignment, poor ESG/governance conduct, or repeated service failures - weakening stakeholder relationships and long-term enterprise value even absent a single acute crisis.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Theft of equipment, media or unattended devices","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["physical_environmental_security","asset_management_inventory","data_protection_privacy"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Physical stealing of storage media, printouts, or computing/network equipment (including unattended laptops outside the perimeter), potentially exposing stored data. Unprotected storage locations increase exposure.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Third-party compliance failure creating vicarious liability","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"third_party","taxonomies":["strategic_risk"],"domains":["third_party_supply_chain_risk","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"A vendor, subcontractor, or channel partner violates labor, environmental, anti-bribery (FCPA/UKBA), or data-protection rules, exposing the company to liability and reputational harm; fourth-party/N-tier dependencies are opaque.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Unauthorized activity - rogue trading, position mismarking, concealment","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"operational","taxonomies":[],"domains":["risk_assessment_management","financial_reporting_controls","governance_policy_oversight"],"likelihood":"low","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Losses from transactions not reported or of an unauthorized type, deliberate mismarking of positions, fictitious trade bookings to conceal losses, and circumvention of position/risk limits without disclosure (e.g. rogue trader).","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Unauthorized disclosure / breach of sensitive information","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy","incident_management_response"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Unauthorized disclosure of information to parties not entitled to receive it, whether by insecure controls (insecurity), spillage, or authorized users induced to expose data - resulting in identity theft, economic loss, and loss of trust.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Unauthorized use of equipment and unauthorized access escalation","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["access_control_identity"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Use of systems, networks, or devices without authorization, and users with authorized access reaching resources that exceed their authorization, potentially to exfiltrate data or conduct attacks.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Uncontrolled copying to removable media / unmanaged software installs","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["asset_management_inventory","secure_configuration_change_management"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Absence of controls over copying data to removable devices, and users freely downloading/installing untested or unlicensed software, expands the attack surface and introduces malicious or unlicensed code into the environment.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Understatement of liabilities/expenses (completeness)","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"financial_reporting","taxonomies":[],"domains":["financial_reporting_controls"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Unrecorded payables (cut-off failure), accrued expenses, unrecorded revenue for delivered goods, off-balance-sheet obligations, uncaptured inventory write-downs, and understated payroll/tax liabilities - understating obligations and overstating income.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Undetected anomalous export from Cloud SQL","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["logging_monitoring_detection"],"likelihood":"low","impact":"high","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Large or off-hours extracts from the database go unmonitored.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Unencrypted or unmasked PII in Cloud SQL is exfiltrated","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy"],"likelihood":"low","impact":"critical","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"A breach or bulk export leaks regulated PII from the PostgreSQL database or its backups.","inherent_likelihood":"low","inherent_impact":"critical"}},{"title":"Unlawful retention or premature deletion of records","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"privacy","taxonomies":["data_privacy"],"domains":["data_protection_privacy","compliance_audit_assurance"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Retaining personal data beyond necessity/mandated schedules (privacy and breach risk) or deleting records before required retention periods (litigation-hold, regulatory, tax risk); records-management policy not enforced technically.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Unlogged Model Home Data Lake activity prevents breach detection","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["logging_monitoring_detection"],"likelihood":"low","impact":"high","inherent_rating":"medium","residual_rating":"low","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Disabled or gap-filled Cloud Audit Logs hide malicious action from detection.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Unmanaged third-party API token is leaked","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["third_party_risk"],"domains":["third_party_supply_chain_risk"],"likelihood":"low","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"A broad integration credential to a third-party API is exposed.","inherent_likelihood":"low","inherent_impact":"high"}},{"title":"Unreviewed change merged and deployed via Model Home Data Lake","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["secure_configuration_change_management"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Code reaches production without peer review or a passing Model Home Data Lake CI pipeline.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"User error and mishandling of sensitive information","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"operational","taxonomies":["cyber_security"],"domains":["awareness_training","data_protection_privacy","logging_monitoring_detection"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Authorized users make mistakes - incorrect data entry, misconfiguration, improper procedures, incorrect privilege settings, or spilling/mishandling sensitive information - causing harm to information assets without malicious intent.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Vulnerabilities introduced during software development","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["secure_development_sdlc","vulnerability_patch_management"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Inherent weaknesses in programming languages and development environments introduce errors and exploitable vulnerabilities into software products, and software malfunctions cause incorrect outputs, crashes, or security weaknesses.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Weak account provisioning/de-registration and access review","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["access_control_identity"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"No formal user registration/de-registration procedure and no periodic access-rights review, so orphaned or excessive accounts accumulate and access is not revoked when roles change or personnel leave.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Weak authentication and password management","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security"],"domains":["access_control_identity","network_communications_security"],"likelihood":"high","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Absent password policy, no MFA, credentials transmitted in clear text, and no session lock/logout on unattended workstations, making account compromise, brute-force login, and session hijacking easy.","inherent_likelihood":"high","inherent_impact":"high"}},{"title":"Weak internal control environment enabling fraud and error","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"financial_reporting","taxonomies":["strategic_risk"],"domains":["governance_policy_oversight","financial_reporting_controls","compliance_audit_assurance"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Because the internal control environment is weak - segregation of duties absent, authorization frameworks inadequate, and tone at the top poor - fraudulent and erroneous transactions can be initiated and concealed, resulting in material misstatement and financial, regulatory, and reputational loss.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Weak or absent encryption and key management","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"category":"cyber_security","taxonomies":["cyber_security","data_privacy"],"domains":["cryptography_key_management","data_protection_privacy","network_communications_security"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"michael.bluth@bluth.example","description":"Sensitive data stored or transmitted without adequate encryption, or use of weak/flawed cryptography and poor key generation, storage, rotation, and destruction - enabling interception, disclosure, or tampering of data.","inherent_likelihood":"medium","inherent_impact":"high"}},{"title":"Weak supplier security requirements and monitoring","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"category":"third_party","taxonomies":["cyber_security","data_privacy"],"domains":["third_party_supply_chain_risk","governance_policy_oversight"],"likelihood":"high","impact":"medium","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"george.michael@bluth.example","description":"Because supplier contracts omit security requirements and SLAs and third-party service delivery is not monitored, processors and sub-processors operate without equivalent, audited obligations, so third-party weaknesses and breaches propagate into the organization undetected.","inherent_likelihood":"high","inherent_impact":"medium"}},{"title":"Workplace health, safety and well-being failures","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"category":"people_hr","taxonomies":["strategic_risk"],"domains":["human_resources_personnel_security","physical_environmental_security"],"likelihood":"medium","impact":"medium","inherent_rating":"medium","residual_rating":"medium","treatment":"mitigate","risk_owner":"maeby.fuenke@bluth.example","description":"Workplace accidents, occupational illness, missing PPE, OHS-regulation violations, premises-liability incidents, and burnout leading to injury claims, workers-compensation, regulatory penalties, and productivity loss.","inherent_likelihood":"medium","inherent_impact":"medium"}},{"title":"Zero-day exploitation","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"category":"cyber_security","taxonomies":[],"domains":["vulnerability_patch_management","secure_development_sdlc"],"likelihood":"medium","impact":"high","inherent_rating":"high","residual_rating":"high","treatment":"mitigate","risk_owner":"ann.veal@bluth.example","description":"Adversary employs attacks that exploit as-yet-unpublicized vulnerabilities (targeted, based on reconnaissance, or nontargeted), compromising systems before any patch or signature exists.","inherent_likelihood":"medium","inherent_impact":"high"}}],"control":[{"title":"Quarterly Access Recertification","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"control_id":"BLU-C001","description":"Quarterly Access Recertification is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company entity-level control, with its owner, operation, testing and framework mapping recorded.","framework":["sox","soc2","iso-27001"],"family":"Control family 1","domains":["access_control_identity"],"control_type":"preventive","control_category":"administrative","control_class":"entity_level","automation":"automated","key_control":"false","sox_applicable":true,"frequency":"continuous","locations":"Newport Beach and Remote","control_owner":"michael.bluth@bluth.example","design_conclusion":"deficient","interim_result":"exception","ye_result":"exception","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Privileged Access Approval","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C002","description":"Privileged Access Approval is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company business process control, with its owner, operation, testing and framework mapping recorded.","framework":["coso-ic"],"family":"Control family 1","domains":["secure_configuration_change_management"],"control_type":"detective","control_category":"technical","control_class":"business_process","automation":"manual","key_control":"true","sox_applicable":true,"frequency":"daily","locations":"Phoenix and Remote","control_owner":"george.michael@bluth.example","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"effective","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Joiner Mover Leaver Automation","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"control_id":"BLU-C003","description":"Joiner Mover Leaver Automation is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT general control, with its owner, operation, testing and framework mapping recorded.","framework":["soc2"],"family":"Control family 1","domains":["logging_monitoring_detection"],"control_type":"corrective","control_category":"physical","control_class":"itgc","itgc_domain":"access_to_programs_data","automation":"hybrid","key_control":"true","sox_applicable":true,"frequency":"weekly","locations":"Newport Beach and Remote","control_owner":"maeby.fuenke@bluth.example","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Emergency Access Review","status":"ACTIVE","visibility":"private","owners":["ann.veal@bluth.example"],"fields":{"control_id":"BLU-C004","description":"Emergency Access Review is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT application control, with its owner, operation, testing and framework mapping recorded.","framework":["iso-27001"],"family":"Control family 2","domains":["secure_development_sdlc"],"control_type":"preventive","control_category":"administrative","control_class":"itac","automation":"automated","key_control":"false","sox_applicable":false,"frequency":"monthly","locations":"Phoenix and Remote","control_owner":"ann.veal@bluth.example","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2025"}},{"title":"Production Change Approval","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"control_id":"BLU-C005","description":"Production Change Approval is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company SOC 1 service delivery control, with its owner, operation, testing and framework mapping recorded.","framework":["nist-csf-2"],"family":"Control family 2","domains":["financial_reporting_controls"],"control_type":"detective","control_category":"technical","control_class":"soc1_service_delivery","automation":"manual","key_control":"true","sox_applicable":true,"frequency":"quarterly","locations":"Newport Beach and Remote","control_owner":"michael.bluth@bluth.example","design_conclusion":"effective","interim_result":"exception","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Segregated Deployment Pipeline","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C006","description":"Segregated Deployment Pipeline is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company entity-level control, with its owner, operation, testing and framework mapping recorded.","framework":["cobit-2019"],"family":"Control family 2","domains":["third_party_supply_chain_risk"],"control_type":"corrective","control_category":"physical","control_class":"entity_level","automation":"hybrid","key_control":"true","sox_applicable":true,"frequency":"semi_annual","locations":"Phoenix and Remote","control_owner":"george.michael@bluth.example","design_conclusion":"effective","interim_result":"effective","ye_result":"exception","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Change Migration Reconciliation","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"control_id":"BLU-C007","description":"Change Migration Reconciliation is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company business process control, with its owner, operation, testing and framework mapping recorded.","framework":["soc1","soc2","iso-27001"],"family":"Control family 3","domains":["incident_management_response"],"control_type":"preventive","control_category":"administrative","control_class":"business_process","automation":"automated","key_control":"false","sox_applicable":true,"frequency":"annual","locations":"Newport Beach and Remote","control_owner":"maeby.fuenke@bluth.example","design_conclusion":"deficient","interim_result":"in_progress","ye_result":"effective","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Batch Processing Monitoring","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"control_id":"BLU-C008","description":"Batch Processing Monitoring is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT general control, with its owner, operation, testing and framework mapping recorded.","framework":["sox"],"family":"Control family 3","domains":["data_protection_privacy"],"control_type":"detective","control_category":"technical","control_class":"itgc","itgc_domain":"program_changes","automation":"manual","key_control":"true","sox_applicable":false,"frequency":"ad_hoc","locations":"Phoenix and Remote","control_owner":"ann.veal@bluth.example","design_conclusion":"not_assessed","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2025"}},{"title":"Backup Restoration Test","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"control_id":"BLU-C009","description":"Backup Restoration Test is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT application control, with its owner, operation, testing and framework mapping recorded.","framework":["coso-ic"],"family":"Control family 3","domains":["physical_environmental_security"],"control_type":"corrective","control_category":"physical","control_class":"itac","automation":"hybrid","key_control":"true","sox_applicable":true,"frequency":"continuous","locations":"Newport Beach and Remote","control_owner":"michael.bluth@bluth.example","design_conclusion":"effective","interim_result":"exception","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Job Failure Escalation","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C010","description":"Job Failure Escalation is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company SOC 1 service delivery control, with its owner, operation, testing and framework mapping recorded.","framework":["soc2"],"family":"Control family 4","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","control_class":"soc1_service_delivery","automation":"automated","key_control":"false","sox_applicable":true,"frequency":"daily","locations":"Phoenix and Remote","control_owner":"george.michael@bluth.example","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Secure Development Gate","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"control_id":"BLU-C011","description":"Secure Development Gate is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company entity-level control, with its owner, operation, testing and framework mapping recorded.","framework":["iso-27001"],"family":"Control family 4","domains":["business_continuity_disaster_recovery"],"control_type":"detective","control_category":"technical","control_class":"entity_level","automation":"manual","key_control":"true","sox_applicable":true,"frequency":"weekly","locations":"Newport Beach and Remote","control_owner":"maeby.fuenke@bluth.example","design_conclusion":"effective","interim_result":"in_progress","ye_result":"exception","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"New Application Architecture Review","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"control_id":"BLU-C012","description":"New Application Architecture Review is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company business process control, with its owner, operation, testing and framework mapping recorded.","framework":["nist-csf-2"],"family":"Control family 4","domains":["access_control_identity"],"control_type":"corrective","control_category":"physical","control_class":"business_process","automation":"hybrid","key_control":"true","sox_applicable":false,"frequency":"monthly","locations":"Phoenix and Remote","control_owner":"ann.veal@bluth.example","design_conclusion":"effective","interim_result":"not_tested","ye_result":"effective","rollforward_strategy":"not_required","last_tested_fy":"FY2025"}},{"title":"Spreadsheet Inventory Review","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"control_id":"BLU-C013","description":"Spreadsheet Inventory Review is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT general control, with its owner, operation, testing and framework mapping recorded.","framework":["cobit-2019","soc2","iso-27001"],"family":"Control family 5","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"administrative","control_class":"itgc","itgc_domain":"computer_operations","automation":"automated","key_control":"false","sox_applicable":true,"frequency":"quarterly","locations":"Newport Beach and Remote","control_owner":"michael.bluth@bluth.example","design_conclusion":"deficient","interim_result":"exception","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"EUC Formula Validation","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C014","description":"EUC Formula Validation is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT application control, with its owner, operation, testing and framework mapping recorded.","framework":["soc1"],"family":"Control family 5","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"technical","control_class":"itac","automation":"manual","key_control":"true","sox_applicable":true,"frequency":"semi_annual","locations":"Phoenix and Remote","control_owner":"george.michael@bluth.example","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Revenue Contract Review","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"control_id":"BLU-C015","description":"Revenue Contract Review is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company SOC 1 service delivery control, with its owner, operation, testing and framework mapping recorded.","framework":["sox"],"family":"Control family 5","domains":["secure_development_sdlc"],"control_type":"corrective","control_category":"physical","control_class":"soc1_service_delivery","automation":"hybrid","key_control":"true","sox_applicable":true,"frequency":"annual","locations":"Newport Beach and Remote","control_owner":"maeby.fuenke@bluth.example","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Revenue Interface Reconciliation","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"control_id":"BLU-C016","description":"Revenue Interface Reconciliation is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company entity-level control, with its owner, operation, testing and framework mapping recorded.","framework":["coso-ic"],"family":"Control family 6","domains":["financial_reporting_controls"],"control_type":"preventive","control_category":"administrative","control_class":"entity_level","automation":"automated","key_control":"false","sox_applicable":false,"frequency":"ad_hoc","locations":"Phoenix and Remote","control_owner":"ann.veal@bluth.example","design_conclusion":"effective","interim_result":"not_tested","ye_result":"exception","rollforward_strategy":"not_required","last_tested_fy":"FY2025"}},{"title":"Journal Entry Approval","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"control_id":"BLU-C017","description":"Journal Entry Approval is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company business process control, with its owner, operation, testing and framework mapping recorded.","framework":["soc2"],"family":"Control family 6","domains":["third_party_supply_chain_risk"],"control_type":"detective","control_category":"technical","control_class":"business_process","automation":"manual","key_control":"true","sox_applicable":true,"frequency":"continuous","locations":"Newport Beach and Remote","control_owner":"michael.bluth@bluth.example","design_conclusion":"effective","interim_result":"exception","ye_result":"effective","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Account Reconciliation Review","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C018","description":"Account Reconciliation Review is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT general control, with its owner, operation, testing and framework mapping recorded.","framework":["iso-27001"],"family":"Control family 6","domains":["incident_management_response"],"control_type":"corrective","control_category":"physical","control_class":"itgc","itgc_domain":"program_development","automation":"hybrid","key_control":"true","sox_applicable":true,"frequency":"daily","locations":"Phoenix and Remote","control_owner":"george.michael@bluth.example","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Vendor Due Diligence","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"control_id":"BLU-C019","description":"Vendor Due Diligence is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT application control, with its owner, operation, testing and framework mapping recorded.","framework":["nist-csf-2","soc2","iso-27001"],"family":"Control family 7","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","control_class":"itac","automation":"automated","key_control":"false","sox_applicable":true,"frequency":"weekly","locations":"Newport Beach and Remote","control_owner":"maeby.fuenke@bluth.example","design_conclusion":"deficient","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"SOC Report and CUEC Review","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"control_id":"BLU-C020","description":"SOC Report and CUEC Review is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company SOC 1 service delivery control, with its owner, operation, testing and framework mapping recorded.","framework":["cobit-2019"],"family":"Control family 7","domains":["physical_environmental_security"],"control_type":"detective","control_category":"technical","control_class":"soc1_service_delivery","automation":"manual","key_control":"true","sox_applicable":false,"frequency":"monthly","locations":"Phoenix and Remote","control_owner":"ann.veal@bluth.example","design_conclusion":"not_assessed","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2025"}},{"title":"Security Incident Triage","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"control_id":"BLU-C021","description":"Security Incident Triage is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company entity-level control, with its owner, operation, testing and framework mapping recorded.","framework":["soc1"],"family":"Control family 7","domains":["governance_policy_oversight"],"control_type":"corrective","control_category":"physical","control_class":"entity_level","automation":"hybrid","key_control":"true","sox_applicable":true,"frequency":"quarterly","locations":"Newport Beach and Remote","control_owner":"michael.bluth@bluth.example","design_conclusion":"effective","interim_result":"exception","ye_result":"exception","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Vulnerability Remediation Review","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C022","description":"Vulnerability Remediation Review is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company business process control, with its owner, operation, testing and framework mapping recorded.","framework":["sox"],"family":"Control family 8","domains":["business_continuity_disaster_recovery"],"control_type":"preventive","control_category":"administrative","control_class":"business_process","automation":"automated","key_control":"false","sox_applicable":true,"frequency":"semi_annual","locations":"Phoenix and Remote","control_owner":"george.michael@bluth.example","design_conclusion":"effective","interim_result":"effective","ye_result":"effective","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Privacy Request Verification","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"control_id":"BLU-C023","description":"Privacy Request Verification is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT general control, with its owner, operation, testing and framework mapping recorded.","framework":["coso-ic"],"family":"Control family 8","domains":["access_control_identity"],"control_type":"detective","control_category":"technical","control_class":"itgc","itgc_domain":"end_user_computing","automation":"manual","key_control":"true","sox_applicable":true,"frequency":"annual","locations":"Newport Beach and Remote","control_owner":"maeby.fuenke@bluth.example","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Data Retention Enforcement","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"control_id":"BLU-C024","description":"Data Retention Enforcement is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT application control, with its owner, operation, testing and framework mapping recorded.","framework":["soc2"],"family":"Control family 8","domains":["secure_configuration_change_management"],"control_type":"corrective","control_category":"physical","control_class":"itac","automation":"hybrid","key_control":"true","sox_applicable":false,"frequency":"ad_hoc","locations":"Phoenix and Remote","control_owner":"ann.veal@bluth.example","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2025"}},{"title":"Physical Site Access Review","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"control_id":"BLU-C025","description":"Physical Site Access Review is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company SOC 1 service delivery control, with its owner, operation, testing and framework mapping recorded.","framework":["iso-27001","soc2","iso-27001"],"family":"Control family 9","domains":["logging_monitoring_detection"],"control_type":"preventive","control_category":"administrative","control_class":"soc1_service_delivery","automation":"automated","key_control":"false","sox_applicable":true,"frequency":"continuous","locations":"Newport Beach and Remote","control_owner":"michael.bluth@bluth.example","design_conclusion":"deficient","interim_result":"exception","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Visitor Badge Reconciliation","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C026","description":"Visitor Badge Reconciliation is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company entity-level control, with its owner, operation, testing and framework mapping recorded.","framework":["nist-csf-2"],"family":"Control family 9","domains":["secure_development_sdlc"],"control_type":"detective","control_category":"technical","control_class":"entity_level","automation":"manual","key_control":"true","sox_applicable":true,"frequency":"daily","locations":"Phoenix and Remote","control_owner":"george.michael@bluth.example","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"exception","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Board Risk Oversight","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"control_id":"BLU-C027","description":"Board Risk Oversight is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company business process control, with its owner, operation, testing and framework mapping recorded.","framework":["cobit-2019"],"family":"Control family 9","domains":["financial_reporting_controls"],"control_type":"corrective","control_category":"physical","control_class":"business_process","automation":"hybrid","key_control":"true","sox_applicable":true,"frequency":"weekly","locations":"Newport Beach and Remote","control_owner":"maeby.fuenke@bluth.example","design_conclusion":"effective","interim_result":"in_progress","ye_result":"effective","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Policy Exception Approval","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"control_id":"BLU-C028","description":"Policy Exception Approval is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT general control, with its owner, operation, testing and framework mapping recorded.","framework":["soc1"],"family":"Control family 10","domains":["third_party_supply_chain_risk"],"control_type":"preventive","control_category":"administrative","control_class":"itgc","itgc_domain":"access_to_programs_data","automation":"automated","key_control":"false","sox_applicable":false,"frequency":"monthly","locations":"Phoenix and Remote","control_owner":"ann.veal@bluth.example","design_conclusion":"effective","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2025"}},{"title":"Service Delivery Quality Review","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"control_id":"BLU-C029","description":"Service Delivery Quality Review is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company IT application control, with its owner, operation, testing and framework mapping recorded.","framework":["sox"],"family":"Control family 10","domains":["incident_management_response"],"control_type":"detective","control_category":"technical","control_class":"itac","automation":"manual","key_control":"true","sox_applicable":true,"frequency":"quarterly","locations":"Newport Beach and Remote","control_owner":"michael.bluth@bluth.example","design_conclusion":"effective","interim_result":"exception","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Business Continuity Exercise","status":"INACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C030","description":"Business Continuity Exercise is a preventive, detective or corrective control in the Bluth Company control library.","full_description":"A fictional Bluth Company SOC 1 service delivery control, with its owner, operation, testing and framework mapping recorded.","framework":["coso-ic"],"family":"Control family 10","domains":["data_protection_privacy"],"control_type":"corrective","control_category":"physical","control_class":"soc1_service_delivery","automation":"hybrid","key_control":"true","sox_applicable":true,"frequency":"semi_annual","locations":"Phoenix and Remote","control_owner":"george.michael@bluth.example","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Identify and manage legal, regulatory, and contractual obligations","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C031","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Identify, document, and keep current all legal, statutory, regulatory, and contractual requirements relevant to information security and privacy - including privacy and civil-liberties obligations - and define and assign the organization's approach to meeting each. Assess and document applicability determinations, including any regulatory exemptions claimed, and file the notices required to support those determinations. Review the obligations register at planned intervals and upon regulatory or business change.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.31 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Set tone at the top: integrity, ethics, and risk-aware culture","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C032","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Leadership defines and demonstrates commitment to integrity, core ethical values, and the desired risk-aware culture through an adopted code of conduct, consistent leadership behavior, and periodic evaluation of adherence with timely remediation of deviations. Organizational leadership is responsible and accountable for cybersecurity and internal-control risk and fosters a culture that is ethical, risk-aware, and continually improving, with expectations communicated to all personnel and business partners.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC1.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Ensure board-level oversight of risk and internal control","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C033","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"The board of directors (or equivalent governing body), demonstrating independence from management and appropriate expertise, oversees the development and performance of internal control and the cybersecurity risk management program, approving the risk strategy and material policies. The board periodically reviews risk-management outcomes, program effectiveness, and management reporting, and directs adjustments to strategy and direction; oversight activities and decisions are documented in minutes and supporting materials.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC1.2 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Define security roles, responsibilities, and authorities","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C034","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Establish and document organizational structures, reporting lines, and the roles, responsibilities, and authorities for information security, risk management, and internal control, with board oversight of their design. Communicate assignments to the individuals and teams concerned, keep them current through organizational and personnel change, and enforce them in practice so that ownership of each security obligation is unambiguous.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.2 | Full | - |\n| SOC 2 (TSC) | CC1.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Hold individuals accountable for control responsibilities","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C035","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Management requires all personnel to apply information security in accordance with established policies and procedures and holds individuals accountable for their internal control responsibilities. Accountability is enforced through defined expectations, documented rules of behavior acknowledged before access is granted and re-acknowledged when updated, performance measures and incentives, and disciplinary consequences for violations.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.4 | Full | - |\n| SOC 2 (TSC) | CC1.5 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Segregate conflicting duties and areas of responsibility","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C036","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Identify duties and areas of responsibility that conflict - such as requesting versus approving access, development versus production deployment, or initiating versus approving transactions - and segregate them among different individuals or roles. Where segregation is impracticable, apply and document compensating controls such as enhanced monitoring, logging, or independent review.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"entity_level","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Establish and maintain approved security policies and procedures","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C037","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Establish, approve, publish, and maintain the organization's information-security policy suite as a governed whole: a top-level policy plus the topic-specific policies, each with an accountable owner, board/management approval, planned review cycles, and communication to relevant parties. Domain-specific policy content is governed by its own unified control; this objective owns the suite-level lifecycle (inventory, approval chain, review cadence, communication, exceptions).\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.1 | Partial | Policies must also be acknowledged by relevant personnel and interested parties |\n| ISO/IEC 27001:2022 | A.5.37 | Full | - |\n| SOC 2 (TSC) | CC5.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Select and tailor a risk-based control baseline","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C038","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Select and document a baseline of security and privacy controls - including general controls over technology - responsive to assessed risks, and tailor it to the organization's environment, complexity, and risk appetite, considering an appropriate mix of preventive and detective control types and segregation of duties. Centrally identify, manage, and deploy common controls where appropriate, and document and approve the rationale for all tailoring decisions.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC5.1 | Full | - |\n| SOC 2 (TSC) | CC5.2 | Partial | developing and operating the specific technology general controls (infrastructure, security management, acquisition/development/maintenance) satisfied by dedicated ITGC companion controls; this UC delivers their selection into the baseline |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Communicate and report risk and control information","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C039","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Establish channels, responsibilities, and cadences to communicate risk, control, and performance information internally at all levels - including objectives and internal control responsibilities - and with external stakeholders, business partners, and the technology function. Leverage information systems to capture, process, and deliver this reporting, and report on risk, culture, and performance to stakeholders at defined intervals and on significant events.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC2.2 | Full | - |\n| SOC 2 (TSC) | CC2.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Assess control effectiveness and authorize systems","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C040","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Maintain a documented assessment and authorization policy with procedures, defined performance measures, and quality monitoring to regularly evaluate whether security policies, standards, and risk-management measures are implemented, complied with, and effective - including managers' reviews of compliance within their areas of responsibility. Feed assessment results into a formal, risk-based authorization process in which a senior official explicitly accepts residual risk before systems operate and at defined intervals thereafter, and track findings to closure.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.36 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"entity_level","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Maintain contacts with authorities and special interest groups","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C041","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Establish, document, and maintain contacts and communication channels with relevant authorities (e.g., regulators, supervisory bodies, law enforcement) and with special interest groups, security forums, and professional associations, defining when and by whom each contact is used, including during incidents. Review contact lists at defined intervals to keep them current, and use these channels to stay abreast of recommended practices, emerging threats, and regulatory expectations.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.5 | Full | - |\n| ISO/IEC 27001:2022 | A.5.6 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Maintain business continuity and contingency planning policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C042","family":"Governance, Policy & Oversight","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Establish, document, and disseminate contingency planning policy and procedures, identify risks arising from potential business disruptions - including to critical infrastructure and essential services - and select and develop mitigation activities (including consideration of insurance and other risk transfer) proportionate to those risks. Review and update the policy and the mitigation portfolio at defined intervals and after significant disruptions.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC9.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Integrate risk management into enterprise processes and projects","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C043","family":"Risk Assessment & Management","domains":["risk_assessment_management"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Risk management is integrated into organizational structures, decision-making, and business activities rather than operated as a standalone silo. Cybersecurity and information security risk activities are incorporated into enterprise risk management processes, and information security risk is addressed within project management for all projects from initiation through delivery. ERM artifacts referencing cyber risk and project gate documentation with security risk sections evidence operation.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.8 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Define objectives and business context for risk assessment","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C044","family":"Risk Assessment & Management","domains":["risk_assessment_management"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"The organization specifies business objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives. Mission-essential and business processes are defined, including their information protection needs, and serve as the basis for risk assessment scoping. Objective and process definitions are documented, approved, and revisited when strategy or operations change.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC3.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Perform periodic enterprise risk assessments","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C045","family":"Risk Assessment & Management","domains":["risk_assessment_management"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"The organization performs an enterprise-wide risk assessment at least annually and upon significant change, identifying and analyzing risks to the achievement of objectives, including cybersecurity, privacy, and financial reporting risks. Assessments follow the documented methodology, address the design of the control environment and evolving threats and technologies, and are approved by management. Assessment reports, methodology references, and approvals are retained as evidence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC3.2 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Assess changes that could significantly affect risk and control","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C046","family":"Risk Assessment & Management","domains":["risk_assessment_management"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"The organization identifies and assesses internal and external changes - new business models, leadership, systems, regulations, and operating environment - that could significantly affect its risk profile or system of internal control. Risk assessments and responses are updated dynamically as changes and emerging risks are detected. Change-triggered assessments and resulting updates are documented.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC3.4 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"entity_level","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"not_assessed","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Assess and mitigate fraud risk including management override","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C047","family":"Risk Assessment & Management","domains":["risk_assessment_management"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"A documented fraud risk assessment considers fraudulent reporting, asset misappropriation, and corruption, evaluating incentives, pressures, opportunities, and rationalizations, and explicitly addresses the risk of management override of controls. Specific anti-override controls operate, including review of journal entries and significant estimates at an appropriate level of precision. The assessment and mitigating controls are refreshed at least annually with documented results.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC3.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Monitor and review risk management performance","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C048","family":"Risk Assessment & Management","domains":["risk_assessment_management"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"The organization performs ongoing and separate evaluations of risk management and internal control performance, periodically measuring the framework's effectiveness against its design and intended outcomes. Risk and business performance are reviewed together at defined intervals and results are reported to accountable management. Evaluation schedules, results, and review minutes are retained as evidence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC4.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"entity_level","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Track deficiencies to closure with remediation action plans","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C049","family":"Risk Assessment & Management","domains":["risk_assessment_management"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Control deficiencies and assessment findings are evaluated and communicated in a timely manner to the parties responsible for corrective action, including senior management and the board as appropriate. A remediation action plan (or equivalent log) documents planned corrective actions, owners, required resources, and completion dates for each finding. Plans are maintained, kept current, and tracked through closure.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC4.2 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"entity_level","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Operate threat intelligence and threat hunting","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C050","family":"Risk Assessment & Management","domains":["risk_assessment_management"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Information relating to threats is collected from internal and external sources and analyzed to produce actionable strategic, tactical, and operational threat intelligence that informs risk assessments and defensive measures. A threat hunting capability proactively searches organizational systems for indicators of compromise that evade existing detection controls. Intelligence products and hunt reports are produced on a defined cadence and drive response actions.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.7 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Maintain a complete inventory of systems, hardware, and software","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C051","family":"Asset Management & Inventory","domains":["asset_management_inventory"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Maintain a documented inventory of all hardware, software, systems, and services, recording owner, location, and the attributes needed for accountability and security management. Update the inventory as part of component installation, removal, and change, and reconcile it at least quarterly to correct discrepancies. Include every in-scope component so the inventory serves as the authoritative record of protected information assets for audit and compliance scoping.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.9 | Partial | inventorying information (data) assets themselves, addressed by the data-inventory control |\n| SOC 2 (TSC) | CC6.1 | Partial | logical access architecture and enforcement addressed by access-control domain |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Classify, prioritize, and label information and assets","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C052","family":"Asset Management & Inventory","domains":["asset_management_inventory"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Classify information and associated assets under a documented scheme based on sensitivity, criticality, and business impact, and prioritize assets and protections accordingly. Apply labels and markings, including on physical media, that identify the classification and any distribution or handling limitations. Identify confidential information at creation or receipt and keep classifications and priorities current through periodic review.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.12 | Full | - |\n| ISO/IEC 27001:2022 | A.5.13 | Full | - |\n| SOC 2 (TSC) | C1.1 | Partial | also requires retaining and protecting confidential information per commitments |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Control storage media through use, storage, and destruction","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C053","family":"Asset Management & Inventory","domains":["asset_management_inventory"],"control_type":"preventive","control_category":"physical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Restrict access to and use of removable and other storage media to authorized personnel and approved media types, and physically secure media commensurate with the classification of the data it holds. Sanitize or destroy media and equipment containing storage using approved techniques before disposal, reuse, or release from control, and verify that data can no longer be read or recovered before protections are discontinued. Retain records of media use, movement, sanitization, and destruction.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.7.10 | Full | - |\n| ISO/IEC 27001:2022 | A.7.14 | Full | - |\n| SOC 2 (TSC) | CC6.5 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Govern acceptable use of endpoints, off-site, and external systems","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C054","family":"Asset Management & Inventory","domains":["asset_management_inventory"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Define, communicate, and require acknowledgment of acceptable-use rules for information and associated assets. Protect user endpoint devices with enforced safeguards such as encryption, screen locking, and centralized management, and protect organizational assets used off premises against loss, theft, and observation. Permit use of or connection to external systems only under established terms and conditions consistent with the trust relationship, including restrictions on processing organizational information and on portable storage.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.10 | Full | - |\n| ISO/IEC 27001:2022 | A.7.9 | Full | - |\n| ISO/IEC 27001:2022 | A.8.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Manage assets through their life cycle and recover them at exit","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C055","family":"Asset Management & Inventory","domains":["asset_management_inventory"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Manage systems, hardware, software, services, and data through their full life cycles from acquisition through secure retirement, with defined ownership and handling at each stage. Recover all organizational assets from personnel and other interested parties upon termination or change of engagement, tracking issuance and verified return.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.11 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"not_assessed","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Transfer information securely under defined rules and agreements","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C056","family":"Asset Management & Inventory","domains":["asset_management_inventory"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Establish rules, procedures, and agreements that protect information transferred within the organization and with external parties, covering electronic transfer, physical media in transit, and verbal disclosure. Require safeguards proportionate to classification, such as encryption in transit and tracked courier services, and bind external recipients through transfer agreements.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.14 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Provision and deprovision accounts through a managed lifecycle","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1","soc2"],"control_id":"BLU-C057","family":"Access Control & Identity Management","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"All accounts are created only on a documented, owner-approved request that specifies role-based entitlements and is uniquely attributable to an individual or service. Access is modified on role change and disabled or removed within one business day of termination or loss of authorization, with dormant accounts automatically disabled after a defined period. All provisioning, modification, and deprovisioning events are logged and retained as evidence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 1 | SOC1-1 | Partial | authentication, periodic review, and privileged access satisfied by companion unified controls |\n| SOC 2 (TSC) | CC6.2 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Review user access rights periodically","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C058","family":"Access Control & Identity Management","domains":["access_control_identity"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"All user and privileged access rights are reviewed at least annually, and more frequently for high-risk systems, by system or data owners who confirm each entitlement remains limited to business need. Unnecessary accounts and excess privileges identified in reviews are disabled or removed within a defined SLA. Completed reviews and remediation evidence are retained.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.18 | Partial | provisioning, adjustment, and revocation satisfied by the account lifecycle control |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Enforce least privilege, need-to-know, and segregation of duties","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C059","family":"Access Control & Identity Management","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"A documented access control policy grants access strictly on business need-to-know, with entitlements defined through roles that default to least privilege. Segregation-of-duties conflicts (e.g., request versus approve, develop versus deploy) are defined in a conflict matrix, enforced in systems, and mitigated with compensating controls where unavoidable. Role and entitlement definitions are approved by data or system owners and re-approved whenever they change.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.15 | Partial | also requires rules controlling physical access to information and assets |\n| SOC 2 (TSC) | CC6.3 | Partial | modifying/removing access on change and periodic role review handled by companion controls |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Restrict privileged rights, utilities, and unauthorized software","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C060","family":"Access Control & Identity Management","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Privileged access rights are individually authorized against a business justification, time-bound or periodically recertified, and issued on separate accounts distinct from daily-use identities. Use of utility programs capable of overriding system or application controls is restricted to authorized administrators and logged. Application allowlisting or equivalent controls prevent installation and execution of unauthorized software on managed systems.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.18 | Full | - |\n| ISO/IEC 27001:2022 | A.8.2 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Enforce approved authorizations for information and functions","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C061","family":"Access Control & Identity Management","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Systems mediate every access attempt through a tamper-resistant, always-invoked enforcement mechanism that applies approved authorizations before granting access to information or functions. Restrictions use roles and security attributes bound to data and subjects, limiting access to sensitive information, source code, and administrative functions to explicitly authorized identities. Enforcement rules are applied consistently across applications, databases, and infrastructure and are tested for effectiveness.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.3 | Full | - |\n| ISO/IEC 27001:2022 | A.8.4 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Manage unique identities and identifiers end to end","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C062","family":"Access Control & Identity Management","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Every user, service, and device is assigned a unique identifier from an authoritative source; shared or group identifiers are prohibited except under documented approval with compensating controls. Identifiers are issued through a controlled process, mapped to accountable owners, deactivated promptly when no longer needed, and not reused for a defined period.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.16 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Manage and protect authenticators across their lifecycle","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C063","family":"Access Control & Identity Management","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Authenticators (passwords, tokens, keys, certificates) are issued through a verified process, with vendor defaults changed before use and minimum strength requirements enforced. Authentication information is protected in storage (salted hashing or encryption) and in transmission, masked during entry, and never embedded in code or scripts. Authenticators are revoked on compromise or separation and rotated at defined intervals or events.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.17 | Partial | advising personnel on proper handling and protection of authentication information |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Authenticate all users with multi-factor authentication","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C064","family":"Access Control & Identity Management","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Every user is uniquely identified and authenticated before access, with multi-factor authentication enforced for remote access, privileged access, and access to sensitive data environments. Authentication follows secure log-on practices: credentials are validated only over protected channels, and federated identity assertions (e.g., SAML/OIDC tokens) are signed, protected, and verified. External and non-organizational users are held to the same authentication rigor, with authentication strength documented against the risk of the interaction.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.5 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Phoenix and Remote","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Authorize, test, and approve changes and development","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1"],"control_id":"BLU-C065","family":"Secure Configuration & Change Management","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Changes to applications and infrastructure, and new system development, follow a documented lifecycle: authorized request, risk-assessed design, testing in non-production environments, documented approval, and controlled migration to production by personnel independent of development. Emergency changes are ratified retrospectively, and evidence of each gate is retained.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 1 | SOC1-2 | Full | - |\n| SOC 1 | SOC1-3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Execute, monitor, and recover production processing","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc1"],"control_id":"BLU-C066","family":"Business Continuity & Disaster Recovery","domains":["business_continuity_disaster_recovery"],"control_type":"corrective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Production batch jobs and scheduled processing are defined, authorized, and monitored, with failures and exceptions logged, tracked, and resolved in a timely manner. Data is backed up on a defined schedule with protected, retained copies, and restoration is periodically tested to confirm recoverability within objectives.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 1 | SOC1-4 | Full | - |\n| SOC 1 | SOC1-5 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Log and monitor system activity, capacity, and incidents","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001","soc1"],"control_id":"BLU-C067","family":"Logging, Monitoring & Detection","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Systems generate log records that are protected and made available for continuous monitoring. Performance, capacity, and security events are monitored against thresholds, with alerts triaged and incidents identified and resolved through a tracked process. Resource use is projected and tuned to meet current and future capacity requirements.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.6 | Full | - |\n| SOC 1 | SOC1-11 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"continuous","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Restrict physical access and maintain environmental safeguards","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc1"],"control_id":"BLU-C068","family":"Physical & Environmental Security","domains":["physical_environmental_security"],"control_type":"preventive","control_category":"physical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Physical access to facilities, data centers, and protected assets is authorized, badged, logged, monitored, and revoked on separation, commensurate with risk. Environmental protections including power conditioning and backup, fire detection and suppression, and temperature and humidity control safeguard systems, and physical access and environmental events are reviewed.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 1 | SOC1-10 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Ensure complete, accurate, and authorized data processing","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1"],"control_id":"BLU-C069","family":"Financial Reporting Controls (SOX)","domains":["financial_reporting_controls"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Transactions and data entering the system are validated for completeness, accuracy, and authorization through edit checks, batch totals, and exception queues. Interfaces and transmissions between systems are controlled with reconciliation, error handling, and timeliness checks, and processing applies complete and accurate logic in the proper period. Outputs and reports are validated and distributed only to authorized recipients.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 1 | SOC1-6 | Full | - |\n| SOC 1 | SOC1-7 | Full | - |\n| SOC 1 | SOC1-8 | Full | - |\n| SOC 1 | SOC1-9 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Manage subservice organizations supporting the system","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc1"],"control_id":"BLU-C070","family":"Third-Party / Supply-Chain Risk","domains":["third_party_supply_chain_risk"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Subservice organizations relevant to user entities' control objectives are identified, contractually bound to security and processing commitments, and monitored through review of their independent assurance reports, complementary user-entity controls, and performance. Identified issues are tracked to resolution.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 1 | SOC1-12 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Encrypt data at rest and in transit","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C071","family":"Cryptography & Key Management","domains":["cryptography_key_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Sensitive and nonpublic data at rest is rendered unreadable using strong, industry-accepted encryption, or truncation/tokenization for stored account data, with storage and retention minimized to defined business need. Data in transit is protected with strong cryptography and trusted certificates over all open, public, or external networks, rejecting fallback to insecure protocols. Transmission, movement, and removal of information, including to removable media, is restricted to authorized users and processes, and the integrity of data in both states is protected. Where encryption of nonpublic information is infeasible, compensating controls are documented, approved by the CISO, and reviewed at least annually.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC6.7 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Use approved algorithms and validated cryptographic modules","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C072","family":"Cryptography & Key Management","domains":["cryptography_key_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"A cryptography standard defines approved algorithms, protocols, key lengths, and certificate profiles aligned to current industry guidance, and prohibits deprecated primitives (e.g., SSL/early TLS, SHA-1, RSA below 2048 bits). Cryptographic operations protecting sensitive data use independently validated cryptographic modules operating in approved modes. The standard is reviewed at least annually against emerging cryptanalytic and post-quantum developments.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.24 | Partial | key management rules satisfied by the key lifecycle control |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Screen personnel commensurate with position risk","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C073","family":"Human Resources / Personnel Security","domains":["human_resources_personnel_security"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Every position is assigned a risk designation that determines its screening requirements and is reviewed as roles change. Background verification, including identity, employment and education history, and criminal or other checks as permitted by law, is completed before employment and before access to systems or sensitive information, proportional to position risk and data sensitivity. Personnel in high-risk roles are rescreened at defined intervals, and screening records are retained.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.6.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Formalize security responsibilities in employment terms","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C074","family":"Human Resources / Personnel Security","domains":["human_resources_personnel_security"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Employment contracts and terms state each individual's information security responsibilities, including obligations that survive employment. Personnel sign confidentiality or non-disclosure agreements and access agreements before being granted access, and re-sign when agreements are materially updated. Position descriptions document role-specific security duties, and signed acknowledgments are retained as evidence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.6.2 | Full | - |\n| ISO/IEC 27001:2022 | A.6.6 | Partial | NDAs from external/other interested parties, addressed by the third-party personnel control |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Secure termination and transfer of personnel","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C075","family":"Human Resources / Personnel Security","domains":["human_resources_personnel_security"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"A documented separation process ensures that on termination, system access is revoked and organizational assets are recovered on a defined timeline, same-day for involuntary separations, with exit discussions reaffirming surviving confidentiality obligations and notification of relevant parties. On transfer or role change, access is re-evaluated and adjusted to the new role within a defined period, with changes logged.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.6.5 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Enforce a formal disciplinary process for violations","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C076","family":"Human Resources / Personnel Security","domains":["human_resources_personnel_security"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"A formal, communicated disciplinary process is applied to personnel who violate information security policies, providing graduated, consistent sanctions proportional to severity and intent. Violations, sanctions applied, and notifications to defined roles are documented and retained, and outcomes feed back into awareness and control improvements.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.6.4 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Hold third-party personnel to equivalent security terms","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C077","family":"Human Resources / Personnel Security","domains":["human_resources_personnel_security"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Contracts with suppliers and external organizations whose personnel access systems or data require equivalent personnel security measures, including screening, confidentiality agreements, and defined security responsibilities, and oblige the provider to notify the organization of personnel transfers or terminations affecting access. Third-party compliance with these personnel requirements is monitored.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.20 | Partial | broader supplier security terms addressed under third-party risk domain |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Embed security and competence in HR practices","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C078","family":"Human Resources / Personnel Security","domains":["human_resources_personnel_security"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Human resources processes incorporate cybersecurity at each stage, from recruiting and onboarding through role change and separation, with defined security checkpoints. The organization defines competence requirements for roles, attracts and develops qualified personnel through training and performance evaluation, and plans for succession and contingency in security-relevant positions.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC1.4 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Secure remote working arrangements","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C079","family":"Human Resources / Personnel Security","domains":["human_resources_personnel_security"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"A remote-working policy defines the physical, device, and communications security measures required when personnel work outside organizational premises, including screen privacy, secured work environments, encrypted connectivity, and rules for handling sensitive information remotely. Compliance is attested, and equipment and configuration requirements are enforced before remote access is granted.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.6.7 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Restrict physical access to facilities and secure areas","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C080","family":"Physical & Environmental Security","domains":["physical_environmental_security"],"control_type":"preventive","control_category":"physical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Define physical security perimeters and secure areas, and authorize, issue, and periodically review physical access credentials so only authorized personnel can enter facilities, offices, and sensitive locations such as data centers and backup media storage. Enforce entry controls at every access point, escort and log visitors, and apply defined rules for working in secure areas. Maintain physical access audit logs for entries and exits at controlled access points, and secure, inventory, and rotate physical access devices such as keys, combinations, and badges when compromised or when personnel change. Revoke or adjust physical access promptly upon termination or role change.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.7.1 | Full | - |\n| ISO/IEC 27001:2022 | A.7.2 | Full | - |\n| ISO/IEC 27001:2022 | A.7.3 | Full | - |\n| ISO/IEC 27001:2022 | A.7.6 | Full | - |\n| SOC 2 (TSC) | CC6.4 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._\n\n---\nBluth Company implementation:\n- Physical security inherited from Model Home Data Lake data centers (reviewed via Model Home Data Lake SOC 2): Physical security for production infrastructure is inherited from Model Home Data Lake. Model Home Data Lake provides multi-layered physical security including perimeter fencing, biometric access controls, 24/7 security staff, video surveillance, and environmental controls. Effectiveness is verified through annual review of Model Home Data Lake SOC 2 Type II report.","sox_applicable":true,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Monitor physical access and retain visitor and entry records","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C081","family":"Physical & Environmental Security","domains":["physical_environmental_security"],"control_type":"detective","control_category":"physical","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Continuously monitor physical access to facilities and sensitive areas using surveillance, intrusion detection, and review of physical access logs. Maintain visitor access records including identity, date, time, and purpose of entry. Review monitoring output and access records on a defined cadence, retain them for the required period, and investigate anomalies and apparent violations.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.7.4 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Protect facilities against fire, water, and environmental hazards","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C082","family":"Physical & Environmental Security","domains":["physical_environmental_security"],"control_type":"preventive","control_category":"physical","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Design and equip facilities to protect technology assets from fire, water, temperature, humidity, and other physical and environmental threats. Deploy and independently maintain fire detection and suppression, water damage detection with accessible shutoff valves, and environmental monitoring and control at required levels. Configure alarms to notify responsible personnel automatically when protective systems activate or parameters go out of range.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.7.5 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"not_assessed","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Site facilities and equipment to minimize hazards and exposure","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C083","family":"Physical & Environmental Security","domains":["physical_environmental_security"],"control_type":"preventive","control_category":"physical","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Position facilities and system components to minimize damage from physical and environmental hazards and to reduce opportunities for unauthorized access and observation. Consider physical and environmental risk when selecting facility locations, and apply compensating safeguards for equipment sited in higher-risk locations.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.7.8 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Provide emergency power, lighting, and resilient utilities","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C084","family":"Physical & Environmental Security","domains":["physical_environmental_security"],"control_type":"corrective","control_category":"physical","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Protect supporting utilities such as power, HVAC, and telecommunications from failure and disruption, with inspection and maintenance on a defined schedule. Provide uninterruptible power and generator capacity sized to enable orderly shutdown or continued operation of critical systems, and automatic emergency lighting covering evacuation routes. Provide accessible, protected emergency shutoff capability to cut power to systems safely in an emergency.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.7.11 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Protect power and communications cabling from damage and taps","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C085","family":"Physical & Environmental Security","domains":["physical_environmental_security"],"control_type":"preventive","control_category":"physical","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Protect power equipment and power and telecommunications cabling from interception, interference, and damage, using measures such as protected conduits, separation of power and communications lines, and controlled access to patch panels, wiring closets, and transmission infrastructure. Periodically inspect cabling and access points for tampering or unauthorized devices.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.7.12 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Maintain equipment to preserve availability and integrity","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C086","family":"Physical & Environmental Security","domains":["physical_environmental_security"],"control_type":"preventive","control_category":"physical","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Maintain equipment according to manufacturer specifications and a defined schedule, using only authorized maintenance personnel. Record all maintenance activity and suspected or actual faults, and apply safeguards that prevent information exposure during servicing, including clearing or supervising equipment sent off site for repair.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.7.13 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Prevent information exposure at desks, screens, and outputs","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C087","family":"Physical & Environmental Security","domains":["physical_environmental_security"],"control_type":"preventive","control_category":"physical","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Enforce clear desk and clear screen rules so sensitive information is not left visible on unattended workspaces, displays, or printed materials. Restrict physical access to printers, scanners, and other output devices so only authorized individuals can retrieve output, and require prompt collection of printed material.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.7.7 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Harden systems to approved secure configuration baselines","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C088","family":"Secure Configuration & Change Management","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Establish, document, and maintain current baseline configurations and mandatory secure settings for all system components, including network security controls, aligned to accepted industry hardening standards. Configure systems for least functionality by disabling or restricting unnecessary ports, protocols, services, and functions. Monitor deployed configurations for deviations from baseline and for changes that introduce vulnerabilities, remediating drift as findings, and reassess baselines periodically and upon significant change.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.9 | Full | - |\n| SOC 2 (TSC) | CC7.1 | Partial | also requires monitoring susceptibility to newly discovered vulnerabilities |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Authorize, test, and approve changes before production","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C089","family":"Secure Configuration & Change Management","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Manage changes to applications, databases, infrastructure, configurations, and procedures through a documented process in which changes are requested, analyzed for security and risk impact, authorized, tested, approved, and implemented by appropriate personnel. Require migration to production to be performed by individuals independent of development, and retain records evidencing each step. Define rollback plans and an emergency-change path with retrospective review and approval.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.32 | Full | - |\n| SOC 2 (TSC) | CC8.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Separate environments and protect production data in testing","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C090","family":"Secure Configuration & Change Management","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Separate development, test, and production environments, and enforce physical and logical access restrictions so only authorized personnel can make changes to production systems. Select, protect, and manage information used for testing, anonymizing or masking production data before use in non-production environments and removing it when testing completes.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.31 | Full | - |\n| ISO/IEC 27001:2022 | A.8.33 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Permit only authorized software installation and use","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C091","family":"Secure Configuration & Change Management","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Restrict installation of software on operational systems to authorized personnel installing approved software from trusted sources, and govern user-installed software through explicit policy and technical enforcement such as allowlisting. Combine these restrictions with anti-malware controls that prevent or detect and act upon unauthorized or malicious software. Track software installation and use to comply with contract terms and license entitlements.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.19 | Full | - |\n| SOC 2 (TSC) | CC6.8 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"not_assessed","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Remediate identified flaws within defined timeframes","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C092","family":"Vulnerability & Patch Management","domains":["vulnerability_patch_management"],"control_type":"corrective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Identify, evaluate, and install security-relevant software and firmware updates within documented, risk-based timeframes (for example, critical flaws within 15 days and high-severity within 30). Test patches for effectiveness and side effects before production deployment, use central patch-management tooling to measure coverage, and verify remediation by rescan or configuration check. Document time-bound compensating measures or formal risk acceptance for any flaw that cannot be corrected on schedule.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.8 | Partial | also requires obtaining vulnerability intelligence and evaluating exposure |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Test software security during development and acceptance","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C093","family":"Vulnerability & Patch Management","domains":["vulnerability_patch_management"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Require developers and project teams to perform security testing throughout development and at acceptance, including a documented test plan, static and dynamic analysis appropriate to the technology, and retained evidence of test execution and results. Define security acceptance criteria for new systems and major upgrades, and remediate weaknesses found before release into production.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.29 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Block malware, spam, and phishing across all systems","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C094","family":"Vulnerability & Patch Management","domains":["vulnerability_patch_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Deploy centrally managed anti-malware protection on all system components commonly affected by malicious software, with real-time and periodic scanning, automatic signature and engine updates, and tamper protection so users cannot disable or alter it. Quarantine or block detected code, alert responders, and log all detections; periodically re-evaluate components deemed not commonly affected. Filter email and web channels for spam and phishing at entry and exit points, and support the technical controls with user awareness on malware and phishing.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.7 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Log security-relevant events across all systems","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C095","family":"Logging, Monitoring & Detection","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Enable audit logging on all systems, applications, and network components, generating records for a defined catalog of security-relevant event types - at minimum authentication, all access to sensitive or regulated data (such as cardholder data), privileged actions, account and configuration changes, and security-tool events. Review and update the event catalog periodically with system owners, ensure logging is enabled by default on newly deployed components, and verify logging coverage on a defined cadence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.15 | Partial | also requires protecting, storing, and analysing produced logs |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"continuous","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Record complete audit content with synchronized clocks","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C096","family":"Logging, Monitoring & Detection","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Capture audit records whose content establishes what happened, when it happened, where it occurred, the source, the outcome, and the identity of associated users or subjects, with centrally managed additional fields where investigations require them. Synchronize clocks on all logging systems to an approved authoritative time source, record timestamps in a consistent format mappable to UTC with defined granularity, and monitor for and correct clock drift.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.17 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"continuous","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Continuously monitor systems for anomalous activity","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C097","family":"Logging, Monitoring & Detection","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Operate continuous monitoring under a documented strategy that defines what is monitored, the metrics, and the frequencies - including ongoing assessment of security-control effectiveness - and report security status to defined roles on a defined cadence. Deploy monitoring across hosts, networks, and applications, at the perimeter and interior, to detect attacks, indicators of compromise, unauthorized connections, and anomalous behaviour indicative of malicious acts, natural disasters, or errors. Analyze flagged anomalies promptly to determine whether they represent security events requiring further evaluation.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.16 | Full | - |\n| SOC 2 (TSC) | CC7.2 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"continuous","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Evaluate events and declare incidents against defined criteria","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C098","family":"Logging, Monitoring & Detection","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Define written criteria for declaring a security incident, including thresholds that identify a reportable personal-data breach. Evaluate analyzed events against those criteria, declare incidents and initiate the response process when criteria are met, and record the assessment and rationale for every evaluated event. For reportable personal-data breaches, notify the competent regulator within the mandated statutory window with the prescribed content, and document all breaches, their effects, and remediation regardless of whether notification was required.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC7.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"continuous","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Secure and monitor networks and network services","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C099","family":"Network & Communications Security","domains":["network_communications_security"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Secure and actively manage networks and network services: document the security features, service levels, and management responsibilities of all network services (including outsourced ones), harden and control network devices, and monitor delivered network services for conformance with the documented security features and service levels, addressing deviations.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.20 | Full | - |\n| ISO/IEC 27001:2022 | A.8.21 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Maintain an approved incident response plan","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C100","family":"Incident Management & Response","domains":["incident_management_response"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Maintain a written incident response plan that defines the mission and scope of the response capability, incident definitions and severity structure, roles, responsibilities, and communication paths, and how the capability coordinates with business continuity and third parties. Have the plan approved by designated management, distribute it to named response personnel, and review and update it on a defined frequency and after significant incidents or organizational changes, protecting it from unauthorized disclosure and modification.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.24 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Provide channels to report events and obtain response help","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C101","family":"Incident Management & Response","domains":["incident_management_response"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Operate well-known channels - such as a monitored mailbox, hotline, or service portal - through which all personnel can and are directed to report observed or suspected security events as quickly as possible. Provide an incident response support resource, integral to the response capability, that offers advice and assistance to users on reporting and on handling suspected events. Acknowledge every report and route it into triage.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.6.8 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Triage, categorize, and escalate reported security events","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C102","family":"Incident Management & Response","domains":["incident_management_response"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Triage every reported security event: validate that it is genuine, assess it against the agreed classification scheme, and decide whether to declare it an incident. Categorize and prioritize declared incidents by type, severity, and business impact, and escalate or elevate them to defined roles and management tiers according to documented thresholds and timeframes. Record triage decisions and their rationale in the incident system of record.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.25 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Respond to, contain, and eradicate declared incidents","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C103","family":"Incident Management & Response","domains":["incident_management_response"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"On declaration of an incident, execute the incident response plan in coordination with internal teams and relevant third parties such as providers, law enforcement, and insurers. Contain the incident using predefined strategies for its category, eradicate the cause by removing malicious artifacts and closing exploited weaknesses, and coordinate handling with contingency and recovery activities through to resolution. Communicate response status as the plan requires and document all response actions taken, feeding lessons into response procedures.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.26 | Full | - |\n| SOC 2 (TSC) | CC7.4 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Investigate incidents and preserve evidence and records","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C104","family":"Incident Management & Response","domains":["incident_management_response"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Track and document every incident from declaration to closure in a system of record covering status, actions performed, decisions, and timeline. Collect incident data and evidence using documented procedures that preserve integrity, provenance, and chain of custody so evidence remains suitable for disciplinary and legal proceedings, and record investigation actions as they are performed. Perform analysis, including root-cause analysis, to establish what took place and why, and record the conclusions.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.28 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Recover from incidents using defined initiation criteria","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C105","family":"Incident Management & Response","domains":["incident_management_response"],"control_type":"corrective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Define objective criteria for initiating incident recovery - such as confirmed eradication, completed forensic preservation, and management authorization - and apply them before restoration begins. Identify, develop, and execute recovery activities that restore affected systems, data, and services to a known-good state, verifying integrity before return to production and confirming with business owners that normal operations have resumed.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC7.5 | Partial | root-cause determination, changes to prevent recurrence, and recovery-plan improvement and testing satisfied by the post-incident review and contingency-testing companion controls |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Learn from incidents and communicate corrective actions","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C106","family":"Incident Management & Response","domains":["incident_management_response"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Hold post-incident reviews for incidents meeting defined thresholds to capture what happened, what worked, and what failed. Convert lessons into tracked corrective actions - updates to controls, plans, training, and configurations - and use incident trends to identify and reduce recurring exposure. Communicate identified deficiencies and corrective-action status in a timely manner to the parties responsible for remediation, including senior management and, where significant, the board.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.27 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Maintain business continuity and disaster recovery plans","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C107","family":"Business Continuity & Disaster Recovery","domains":["business_continuity_disaster_recovery"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Maintain documented, management-approved business continuity and disaster recovery plans that cover critical business functions and ICT services, recovery time and recovery point objectives, assigned roles, and how information security is preserved at required levels during disruption. Base the plans on a business impact analysis, distribute them to responsible personnel, and review and update them at least annually and after significant organizational or technology changes.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.29 | Full | - |\n| ISO/IEC 27001:2022 | A.5.30 | Partial | periodic ICT readiness testing satisfied by the testing control |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Back up data and verify restorability","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C108","family":"Business Continuity & Disaster Recovery","domains":["business_continuity_disaster_recovery"],"control_type":"corrective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Back up information, software, and system images at a frequency and scope aligned to defined recovery point objectives, protect backup copies from unauthorized access and modification, and keep copies separate from the primary environment. Verify backup integrity and restorability through periodic test restores, and verify the integrity of backups before using them for restoration.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.13 | Full | - |\n| SOC 2 (TSC) | A1.2 | Partial | environmental protections and recovery-infrastructure operation satisfied by companion controls |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Provide redundant and alternate processing, storage, and telecom","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C109","family":"Business Continuity & Disaster Recovery","domains":["business_continuity_disaster_recovery"],"control_type":"corrective","control_category":"technical","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Implement redundancy and alternate capability sufficient to meet availability and recovery objectives: an alternate storage site for backup media, alternate processing capability sufficiently separated from the primary site to avoid shared hazards, and diverse or alternate telecommunications services with priority-of-service provisions. Ensure alternate facilities provide security controls equivalent to the primary site and can assume operations within recovery time objectives.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.14 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Manage capacity to meet availability requirements","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C110","family":"Business Continuity & Disaster Recovery","domains":["business_continuity_disaster_recovery"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Determine and monitor the processing capacity and utilization of infrastructure, data, and software against current and forecast demand, and add capacity before demand exceeds defined thresholds. Protect availability of shared resources through priority-based allocation or quotas, and alert responsible personnel when capacity thresholds are breached.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | A1.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"business_process","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Test recovery capabilities and train contingency personnel","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C111","family":"Business Continuity & Disaster Recovery","domains":["business_continuity_disaster_recovery"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Test business continuity, disaster recovery, and restoration capabilities at least annually through scenario exercises, failover and restore tests, and, where required for critical systems, advanced or threat-led penetration testing. Train all personnel with contingency roles on their responsibilities upon assignment and periodically thereafter. Review test and exercise results and remediate identified gaps.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | A1.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Operate a third-party security risk management program","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C112","family":"Third-Party / Supply-Chain Risk","domains":["third_party_supply_chain_risk"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Establish and operate a management-approved third-party and supply-chain risk management program with a written strategy, policies, and procedures, reviewed at defined intervals and after significant changes to the supply chain or threat landscape. Define and communicate roles and responsibilities for supplier, customer, and partner relationships, and integrate third-party and supply-chain risk into enterprise and cybersecurity risk management. Maintain a register of third-party relationships and contractual arrangements prioritized by criticality, and assess criticality, substitutability, and concentration risk before contracting. Apply risk-based due diligence, embed security requirements, audit and access rights, termination rights, and sub-outsourcing conditions in agreements, and protect organizational information processed, stored, or transmitted on external systems. Define, agree, and periodically review service agreements and supplier performance, reassess third parties on a defined cycle, operate controls to identify and address weaknesses across the relationship life cycle, and maintain documented, tested exit strategies for providers supporting critical or important functions.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.19 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Perform risk-based due diligence before engaging vendors","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C113","family":"Third-Party / Supply-Chain Risk","domains":["third_party_supply_chain_risk"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Before entering a formal relationship, perform security due diligence on prospective vendors and business partners proportionate to their criticality, evaluating security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision. Use acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before contract award.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | CC9.2 | Partial | ongoing monitoring, termination handling, and contractual security/confidentiality commitments satisfied by companion vendor-management and vendor-contract controls |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Monitor vendor performance, services, and risk","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C114","family":"Third-Party / Supply-Chain Risk","domains":["third_party_supply_chain_risk"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Continuously monitor third-party performance, service delivery, and security posture against contractual and risk requirements throughout the relationship. Conduct periodic reassessments and reviews, such as questionnaires, assurance reports, and audits, at a frequency based on criticality, and manage changes to supplier services. Record, prioritize, and track identified vendor risks through response and remediation.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.22 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Verify component authenticity, provenance, and integrity","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C115","family":"Third-Party / Supply-Chain Risk","domains":["third_party_supply_chain_risk"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Document and maintain the provenance of critical systems, components, and data through the supply chain, for example with bills of materials and chain-of-custody records. Apply anti-tamper and anti-counterfeit measures: tamper-resistant and tamper-evident packaging and design, inspection of systems and components at receipt and on indication of tampering, and verification of component authenticity with training and reporting of suspected counterfeits.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.21 | Partial | propagation of security requirements through the ICT supply chain via contract control |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Govern security of external and cloud service use","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C116","family":"Third-Party / Supply-Chain Risk","domains":["third_party_supply_chain_risk"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Define and enforce processes for acquiring, using, managing, and exiting external system services and cloud services in line with the organization's information security requirements. Require external providers to comply with those requirements, define oversight roles and responsibilities on both sides, agree service and exit terms, and monitor provider compliance on an ongoing basis.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.23 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Process personal data only under a documented lawful basis","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C117","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Identify and document the lawful basis and organizational authority for each personal-data processing activity before data is collected or processed. Record the basis (e.g., consent, contract, legal obligation, legitimate interest) in the processing register and collect personal data only for those documented purposes. Review the register at least annually and whenever processing changes.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P3.1 | Partial | fair collection methods and reliable data sources (with collection transparency delivered by the privacy-notice companion), beyond documented lawful basis and purpose limitation |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Obtain and honor consent for collection, use, and disclosure","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C118","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Where consent or authorization is the basis for collecting, using, retaining, disclosing, selling, or sharing personal data, present the available choices and their consequences clearly and capture freely given, specific, informed consent before the data is collected or disclosed. Maintain auditable consent records, honor withdrawal and opt-out requests (including opt-out of sale/sharing and limits on sensitive-data use) as easily as consent was given, and use compliant authorization forms where required. Document the basis for any implied consent relied upon.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P2.1 | Full | - |\n| SOC 2 (TSC) | P3.2 | Full | - |\n| SOC 2 (TSC) | P6.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"not_assessed","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Limit personal-data use to stated purposes and minimum necessary","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C119","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Identify and document the specific purposes for which personal data is processed, and restrict use and disclosure to those purposes or documented compatible ones. Apply the minimum-necessary standard so only the least data required is used, disclosed, or requested for each purpose. Obtain new authority or consent before processing for any new purpose.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P4.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Provide privacy notices and transparency to data subjects","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C120","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Publish and maintain privacy notices that describe, in clear and plain language, the categories of personal data collected, purposes, lawful bases, recipients, retention periods, and data-subject rights, and deliver them at or before the point of collection. Update and re-communicate notices in a timely manner when practices change, and publish any legally required registrations such as system-of-records notices. Retain dated notice versions as evidence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P1.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Provide data subjects access to their personal data","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C121","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Operate a mechanism for identified and authenticated individuals to obtain confirmation of processing and a copy of their personal data, including the categories collected, sold, shared, or disclosed and the categories of recipients, within statutory deadlines. Where access is denied, inform the individual of the denial, the reason, and any recourse. Log all requests and responses as evidence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P5.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Keep personal data accurate and honor correction requests","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C122","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Maintain personal data that is accurate, complete, up to date, and relevant for its intended use, with periodic data-quality checks. Provide a process for individuals to request correction or amendment, execute or formally deny each request within statutory deadlines with stated reasons, and communicate corrections to third parties to whom the data was disclosed.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P5.2 | Full | - |\n| SOC 2 (TSC) | P7.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Retain personal and confidential data per schedule, then destroy it","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C123","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Maintain an approved retention schedule for personal and confidential information tied to documented legal and business requirements, and retain data no longer than the schedule permits. When retention ends, delete or irreversibly destroy the information wherever it resides, including in external services, using methods that prevent reconstruction, and record disposal actions as evidence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.10 | Full | - |\n| SOC 2 (TSC) | C1.2 | Full | - |\n| SOC 2 (TSC) | P4.2 | Full | - |\n| SOC 2 (TSC) | P4.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Control data flows, leakage, and cross-border transfers","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C124","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Enforce approved authorizations for information flows within and between systems using technical flow-control mechanisms, and deploy data-leakage-prevention measures on systems and channels that could exfiltrate sensitive data. Transfer personal data across borders only under a valid transfer mechanism (adequacy decision, standard contractual clauses, binding corporate rules, or a documented derogation), with the transfer risk assessed and the safeguard recorded.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.12 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"De-identify, mask, or pseudonymize personal data","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C125","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Apply masking, pseudonymization, or de-identification when full identifiers are not required, following policy and the applicable legal standard (e.g., expert determination or safe-harbor methods, limited data sets under agreement). Protect the keys and mappings that could re-identify data, and prohibit re-identification attempts.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.11 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Safeguard personal information with reasonable security","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C126","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Identify the statutory, regulatory, and contractual requirements that apply to the personal information the organization holds, and implement reasonable administrative, technical, and physical safeguards appropriate to its volume and sensitivity. Assign responsibility for PII protection, verify the safeguards periodically, and remediate identified gaps.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.34 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Maintain and provide an accounting of disclosures","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C127","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Record every authorized disclosure of personal information - recipient, date, data categories, and purpose - completely, accurately, and in a timely manner. Upon a verified request, provide the data subject an accounting of the personal information held and its disclosures within the required timeframe.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P6.2 | Full | - |\n| SOC 2 (TSC) | P6.7 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"not_assessed","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Record and notify unauthorized disclosures of personal data","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C128","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Log every detected or reported unauthorized disclosure or breach of personal information in a complete, accurate, and timely register. Notify affected data subjects, regulators, and other required parties within the applicable statutory windows, and retain the notifications and supporting analysis as evidence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P6.3 | Full | - |\n| SOC 2 (TSC) | P6.6 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Bind third parties handling personal data to privacy commitments","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C129","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Before granting vendors or other third parties access to personal information, obtain written privacy commitments covering permitted use, safeguards, and notification of actual or suspected unauthorized disclosures. Assess their compliance periodically and as needed, route their breach notifications into the incident-response process, and take corrective action or terminate access when commitments are not met.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P6.4 | Full | - |\n| SOC 2 (TSC) | P6.5 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Resolve privacy inquiries, complaints, and disputes","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C130","family":"Data Protection & Privacy","domains":["data_protection_privacy"],"control_type":"corrective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Operate a documented channel for receiving, tracking, addressing, and resolving privacy inquiries, complaints, and disputes from data subjects and other parties. Communicate resolutions to the complainant, make corrections for identified deficiencies in a timely manner, and monitor complaint trends for systemic issues.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | P8.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Follow a secure development lifecycle with approval gates","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C131","family":"Secure Development (SDLC) & Application Security","domains":["secure_development_sdlc"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Define and follow a documented development lifecycle with security integrated into every phase from requirements through design, build, test, and release, including defined security activities, secure development standards and tooling, and management approval gates. Ensure new systems and significant changes are designed, developed, tested, and approved in accordance with management's specifications before migration to production. Monitor adherence to and performance of the secure development process.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.25 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Define and approve security requirements for applications","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C132","family":"Secure Development (SDLC) & Application Security","domains":["secure_development_sdlc"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Elicit, analyze, document, and approve functional and non-functional requirements, including application security requirements such as authentication, authorization, input and output handling, logging, and data protection, before solution design and build, assessing feasibility and alternative options. Manage requirement changes and requirements risk, and obtain stakeholder and management approval of the final requirements.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.26 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Engineer systems with secure architecture and design","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C133","family":"Secure Development (SDLC) & Application Security","domains":["secure_development_sdlc"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Design and build systems using established secure architecture and engineering principles: least privilege, defense in depth, isolation of execution domains (process and memory separation), fail-safe defaults, and attack-surface minimization, applied from concept through implementation. Require developers to produce and maintain a security architecture description consistent with the enterprise architecture. Engineer solutions to remain accurate, robust, and resilient against errors, faults, and adversarial manipulation.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.27 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Enforce secure coding and input validation standards","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C134","family":"Secure Development (SDLC) & Application Security","domains":["secure_development_sdlc"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Establish and enforce secure coding standards for in-house and reused code, covering common weakness classes and secure use of components. Validate all information inputs for syntax, semantics, type, length, and range at trust boundaries, rejecting or safely encoding unsafe input. Verify adherence through code review and static analysis before release.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.28 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Oversee outsourced development and vet developers","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C135","family":"Secure Development (SDLC) & Application Security","domains":["secure_development_sdlc"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Direct, monitor, and review outsourced and third-party development: contractually define secure-development requirements, intellectual property ownership, and audit rights, review deliverables against requirements, and obtain evidence of security testing. Screen developers of critical systems against defined criteria before granting them access to development environments.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.30 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Protect production systems during audit testing","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C136","family":"Secure Development (SDLC) & Application Security","domains":["secure_development_sdlc"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Plan and agree audit and assurance testing of operational systems between the tester and appropriate management before testing begins: define and approve scope, limit testers to read-only access where possible or use isolated copies, schedule tests to minimize disruption, and monitor and log all audit access.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.34 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Segment networks and defend the external boundary","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C137","family":"Network & Communications Security","domains":["network_communications_security"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Segment networks into zones based on trust level, sensitivity, and function, and mediate all traffic at managed interfaces (firewalls, gateways, proxies) with deny-by-default rules at the external boundary and key internal boundaries. Monitor and control communications crossing each boundary to protect against threats originating outside the system boundary, and review segmentation and rule sets periodically.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.22 | Full | - |\n| SOC 2 (TSC) | CC6.6 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Control mobile code and web content","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C138","family":"Network & Communications Security","domains":["network_communications_security"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Define acceptable and unacceptable mobile-code technologies, and authorize, monitor, and control mobile code so unauthorized active content cannot execute in browsers, documents, or email. Filter access to external websites by category and reputation to reduce exposure to malicious content, and log enforcement actions.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.8.23 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Deliver security awareness training to all personnel","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C139","family":"Awareness & Training","domains":["awareness_training"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Provide security and privacy awareness training to all personnel as part of onboarding, at least annually thereafter, and when threats, policies, or systems change materially. Include practical exercises reflecting current threats, such as phishing simulations and social-engineering awareness, and update content based on lessons learned and emerging risks. Require timely completion as a condition of continued system access.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.6.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Coordinate independent assurance reviews across providers","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C140","family":"Compliance, Audit & Assurance","domains":["compliance_audit_assurance"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.35 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Manage compliance with external legal and regulatory requirements","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["iso-27001"],"control_id":"BLU-C141","family":"Compliance, Audit & Assurance","domains":["compliance_audit_assurance"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"The organization identifies applicable external legal, regulatory, and contractual requirements - including intellectual property rights and software licensing obligations - and maintains them in a compliance register with assigned owners. Compliance with these requirements is evaluated on a defined cadence, confirmed through documented reviews, and non-compliance is remediated with status reported to management. The register and evaluation results are retained as evidence.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.32 | Partial | operational IPR safeguards - license/asset registers with usage-vs-entitlement enforcement, proof-of-license retention, and acquisition from authorized sources - beyond registering and periodically evaluating the obligation |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Maintain quality records and information for internal control","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["iso-27001","soc2"],"control_id":"BLU-C142","family":"Compliance, Audit & Assurance","domains":["compliance_audit_assurance"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"The organization obtains or generates and uses relevant, quality information to support the functioning of internal control, with defined expectations for accuracy, completeness, and timeliness. Records are protected against loss, destruction, falsification, and unauthorized access or release, and are retained and disposed of in accordance with retention schedules aligned to legal, regulatory, contractual, and business requirements.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| ISO/IEC 27001:2022 | A.5.33 | Full | - |\n| SOC 2 (TSC) | CC2.1 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"entity_level","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Validate completeness and accuracy of system inputs","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C143","family":"Financial Reporting Controls (SOX)","domains":["financial_reporting_controls"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Implement input controls over data entered into financial systems, including edit and validation checks, required-field and format controls, completeness checks, and rejection or suspense handling of invalid entries, so that inputs are complete, accurate, and valid. Define these controls in documented policies and procedures over system inputs and retest their configuration on change. Evidence includes configuration baselines, validation rules, and rejected-input handling records.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | PI1.2 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"business_process","frequency":"monthly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Control automated processing and resolve exceptions","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C144","family":"Financial Reporting Controls (SOX)","domains":["financial_reporting_controls"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Configure automated processing controls, including system-enforced calculations, three-way matches, tolerance checks, and other configurable application controls, under documented policies and procedures so transactions are processed completely, accurately, and in the proper period. Generate exception, error, and edit reports from processing, and review and resolve reported items timely with documented disposition. Evidence includes control configurations, configuration change approvals, and exception-report review records.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | PI1.3 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Control interface transfers and output delivery","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C145","family":"Financial Reporting Controls (SOX)","domains":["financial_reporting_controls"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"false","control_owner":"maeby.fuenke@bluth.example","description":"Control data transferred between systems and delivered as output so that it is complete, accurate, timely, and processed only once, using record counts, control totals, or hash checks reconciled at each interface with automated error handling and alerting for failures. Deliver or make output available in accordance with documented specifications, and investigate and resolve interface or delivery failures timely. Evidence includes the interface inventory, reconciliation results, and failure-resolution logs.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | PI1.4 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":true,"control_class":"business_process","frequency":"monthly","locations":"Newport Beach and Remote","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Ensure quality of information used in reporting","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C146","family":"Financial Reporting Controls (SOX)","domains":["financial_reporting_controls"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Define and communicate the information requirements for financial processing and reporting, including data definitions and report specifications. Validate the completeness and accuracy of system-generated reports, queries, and spreadsheets used in the operation of controls or in financial reporting by verifying source data, report logic and parameters, and totals before reliance, and baseline standard reports with revalidation on change. Retain validation evidence for each report relied upon.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | PI1.1 | Partial | UC is scoped to financial-reporting IPE; PI1.1's service-wide processing-objective information - data definitions, quality information, and product/service specifications across the entity's services - is not covered |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Safeguard assets and stored financial data","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2"],"control_id":"BLU-C147","family":"Financial Reporting Controls (SOX)","domains":["financial_reporting_controls"],"control_type":"preventive","control_category":"physical","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Restrict physical custody of financial assets, negotiable instruments, and accounting records to authorized custodians, and perform periodic counts and inspections reconciled to the accounting records. Store transaction inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications and retention requirements, protecting them against loss and unauthorized alteration. Evidence includes custody logs, count results, and storage and retention configurations.\n\n| Framework | Reference | Coverage | Residual / companion coverage |\n|---|---|---|---|\n| SOC 2 (TSC) | PI1.5 | Full | - |\n\n_Partial means this control covers only the stated portion; the residual must be met by companion controls and retained audit evidence._","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake account & project baseline hardening","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C148","family":"Cloud & Infrastructure","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Model Home Data Lake projects are configured against the CIS Model Home Data Lake Foundations benchmark; configuration drift is detected and remediated.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake IAM least-privilege & owner protection","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C149","family":"Cloud & Infrastructure","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"IAM policies grant least privilege; roles/owner is restricted to break-glass use and protected with FIDO2 MFA.\n\n---\nBluth Company implementation:\n- Privileged-access inventory maintained by vCISO with quarterly review by Internal Audit (firm-internal independence): An inventory of all individuals holding privileged roles is maintained covering at minimum: Model Home Data Lake organization administrator, Model Home Data Lake project owner, Model Home Data Lake group owner, production deploy approver, Cloud SQL database superuser, Cloud KMS key administrator. The inventory lists each role, the named individual(s), the justification for the grant, and the grant date. Tidewell Advisory Group's vCISO (Person B) maintains the inventory and approves new privileged grants. Tidewell Advisory Group's Internal Audit (Person C, distinct from operational personnel) reviews the inventory quarterly, samples a subset of grants for justification appropriateness, and flags any unexpected entries. The CEO does not approve their own privileged access grants - the vCISO does.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"access_to_programs_data","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake network segmentation & firewall control","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C150","family":"Cloud & Infrastructure","domains":["network_communications_security"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"VPC firewall rules restrict ingress/egress; public exposure of Cloud Storage and Cloud SQL is prevented.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake encryption at rest & in transit","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C151","family":"Cloud & Infrastructure","domains":["cryptography_key_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Cloud SQL, Cloud Storage and disks use managed / Cloud KMS encryption; TLS is enforced in transit.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C152","family":"Cloud & Infrastructure","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Cloud Audit Logs are enabled org-wide, centralized in Cloud Logging, and alerted on via Cloud Monitoring.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"continuous","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake infrastructure change management (Terraform IaC review)","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C153","family":"Cloud & Infrastructure","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Infrastructure changes go through peer-reviewed Terraform pipelines rather than console click-ops.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"program_changes","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake backup & disaster recovery","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C154","family":"Cloud & Infrastructure","domains":["business_continuity_disaster_recovery"],"control_type":"corrective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Cloud SQL automated backups and cross-zone redundancy are maintained; restores are tested against RTO/RPO.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"not_assessed","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Sudden Valley Network registrar account security & DNS change control","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C155","family":"Cloud & Infrastructure","domains":["network_communications_security"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"The Sudden Valley Network registrar account is restricted to named owners with MFA enforced; DNS zone and domain-contact changes are made only by an authorized owner and verified after the change; registrar transfer lock and auto-renewal are enabled so domains cannot be hijacked or lapse unnoticed.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"program_changes","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Lucille Identity Cloud SSO & MFA enforcement","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C156","family":"Identity & Access","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Application access is brokered through Lucille Identity Cloud (Lucille Identity Cloud OIDC) with 2-Step Verification required for all users.\n\n---\nBluth Company implementation:\n- MFA enforced for all production system access; FIDO2 hardware keys required for privileged Model Home Data Lake IAM: Multi-factor authentication is enforced for all access to production systems, cloud consoles, source code repositories, and administrative interfaces. MFA is configured at the identity provider level (Lucille Identity Cloud via Lucille Identity Cloud OIDC) and cannot be bypassed. For standard production access, supported methods include 2-Step Verification (TOTP via Authenticator app, push notification, or hardware key). For privileged Model Home Data Lake IAM operations (roles/owner, roles/iam.securityAdmin), FIDO2 hardware security keys (e.g., YubiKey) are required and TOTP-only is not accepted.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"access_to_programs_data","frequency":"quarterly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Lucille Identity Cloud joiner-mover-leaver provisioning","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C157","family":"Identity & Access","domains":["access_control_identity"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Accounts are created, role-changed and suspended in Lucille Identity Cloud on authoritative HR events; suspension revokes federated access.\n\n---\nBluth Company implementation:\n- Access revoked within 24 hours of termination: Access to all systems is revoked within 24 hours of employment termination or contract end. The HR termination process triggers IT access revocation procedures. Revocation covers identity provider accounts, cloud access, source code repositories, and SaaS applications.\n- Termination workflow produces single signed packet per termination event (logical + physical/asset combined): For each personnel termination or role change requiring access removal, Tidewell Advisory Group's HR function produces a single signed termination packet containing: (a) termination event trigger and date; (b) access-revocation log across every system (Model Home Data Lake, Model Home Data Lake, Lucille Identity Cloud, the Bluth Company system of record, paging tool, monitoring tools, third-party SaaS) with timestamps showing revocation within 24 hours; (c) asset-return checklist completed (laptop, FIDO2 keys, badges if any) with itemized acknowledgment; (d) NDA + IP post-employment reminder issued and acknowledged; (e) exit-interview security debrief log; (f) signature of the HR personnel completing the workflow. The packet is filed in the personnel file and a copy linked to the relevant termination item in the Bluth Company system of record.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"access_to_programs_data","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Lucille Identity Cloud periodic access & group review","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C158","family":"Identity & Access","domains":["access_control_identity"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Lucille Identity Cloud group and application assignments are recertified quarterly.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"access_to_programs_data","frequency":"quarterly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Lucille Identity Cloud password & authentication policy","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C159","family":"Identity & Access","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Password length, lockout and session policies are enforced centrally in Lucille Identity Cloud.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"access_to_programs_data","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Lucille Identity Cloud authentication & admin-event logging","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C160","family":"Identity & Access","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Sign-in and admin-console events are logged and alerted on (impossible travel, admin changes).\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"continuous","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake branch protection & mandatory code review","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C161","family":"Dev & Change Management","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Changes to protected branches require peer review and passing Model Home Data Lake CI checks before merge.\n\n---\nBluth Company implementation:\n- All code changes require merge request with peer review before merge: All code changes require a merge request with at least one peer review approval before merging to the main branch. Model Home Data Lake branch protection and approval rules enforce this requirement. Direct commits to protected branches are blocked. Reviews evaluate correctness, security, and test coverage.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"program_changes","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C162","family":"Dev & Change Management","domains":["secure_configuration_change_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Production deployment via Model Home Data Lake CI, Cloud Build and Terraform requires approval and is segregated from the change author.\n\n---\nBluth Company implementation:\n- Automated CI/CD pipeline runs tests before deployment: The Model Home Data Lake CI/CD pipeline automatically executes unit tests, integration tests, linting, type checking, and the Model Home Data Lake Ultimate scanning suite (SAST, Secret Detection, Dependency Scanning, Container Scanning) for every merge request and before deployment. Deployments are blocked if critical checks fail. Pipeline configuration is version-controlled in `.gitlab-ci.yml`.\n- Development, test, and production environments separated with documented promotion gates: Three logical environment tiers are maintained: (a) Development - local developer machines and ephemeral preview branches in Model Home Data Lake CI, no access to production data; (b) Test/Staging - the internal staging instance (running production builds against a non-customer database), used for pre-release validation of the unified core+MCP image; (c) Production - per-tenant the Model Home compute tier services in dedicated Model Home Data Lake projects backed by per-tenant Cloud SQL instances. Promotion is gated: dev → test requires merge to main (Controls 32, 33, 34); test → prod requires (i) staging smoke-test sign-off, (ii) explicit CEO or designated-operator promotion via the deployment dashboard, (iii) post-deployment review in the next monthly information security meeting. Each environment has separate Model Home Data Lake IAM bindings, separate Cloud KMS keys, separate Cloud Logging sinks, and separate Cloud SQL credentials retrieved via per-environment Secret Manager paths. Production data flows downstream (prod → masked test data); test data never flows upstream into production.\n- Production deployments require approval from authorized personnel: Production deployments require explicit approval from authorized personnel separate from the change author, enforcing segregation of duties. Deployment approval is documented in the CI/CD system with approver identity and timestamp.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"program_changes","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake repository & project access management","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C163","family":"Dev & Change Management","domains":["access_control_identity"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Model Home Data Lake repository and pipeline access is granted by role and reviewed periodically.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"access_to_programs_data","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"not_assessed","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C164","family":"Dev & Change Management","domains":["secure_development_sdlc"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Pipeline secrets are stored in the Model Home Data Lake CI / Cloud Build managed secret stores, scoped and rotated, never hardcoded.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"program_changes","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake audit logging of changes & approvals","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C165","family":"Dev & Change Management","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Model Home Data Lake merge, deploy and approval events are logged and retained.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"continuous","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Cloud SQL access control & least privilege","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C166","family":"Data & Privacy","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"PostgreSQL roles grant least privilege; access is granted on request and reviewed.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"access_to_programs_data","frequency":"quarterly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Cloud SQL encryption & Cloud KMS key management","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C167","family":"Data & Privacy","domains":["cryptography_key_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"michael.bluth@bluth.example","description":"Data at rest and in transit is encrypted; field-level AES-256-GCM keys are managed in Cloud KMS and rotated.\n\n---\nBluth Company implementation:\n- Encryption at rest (AES-256-GCM) for sensitive data fields: Sensitive data fields are encrypted at rest using AES-256-GCM, providing field-level encryption beyond database-level encryption. This includes API keys, authentication tokens, and other sensitive attributes. Encryption keys are managed through Model Home Data Lake Cloud KMS with annual rotation.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"business_process","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Cloud SQL PII classification & field-level masking","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C168","family":"Data & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Sensitive PII columns are classified; field-level encryption / masking protects them.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Cloud SQL query & access audit logging","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C169","family":"Data & Privacy","domains":["logging_monitoring_detection"],"control_type":"detective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Access to sensitive data is logged and monitored for anomalous queries / exports.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"continuous","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Cloud SQL data retention & secure disposal","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C170","family":"Data & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Data is retained per schedule and securely deleted at end of life.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"business_process","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Cloud SQL backup, integrity & recovery","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C171","family":"Data & Privacy","domains":["business_continuity_disaster_recovery"],"control_type":"corrective","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Automated backups are taken, integrity-checked and restores are tested; backups are encrypted.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Data subject rights & consent handling (PII)","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C172","family":"Data & Privacy","domains":["data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"george.michael@bluth.example","description":"Access, deletion and consent requests for PII are fulfilled within statutory timelines.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"business_process","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Model Home Data Lake Secret Manager secrets management","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C173","family":"Security Tooling","domains":["cryptography_key_management"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Shared application and infrastructure secrets are stored in Model Home Data Lake Secret Manager, access-controlled and rotated.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"access_to_programs_data","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Third-party vendor risk assessment & monitoring","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C174","family":"Third-Party & Business Apps","domains":["third_party_supply_chain_risk"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"false","control_owner":"ann.veal@bluth.example","description":"Critical vendors and subservice organizations are risk-assessed, have reviewed assurance reports (SOC 2 where published; posture review where none exists, e.g. the registrar), and their security / DR is monitored.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"business_process","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Third-party data-sharing & API access control","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc1","soc2","iso-27001"],"control_id":"BLU-C175","family":"Third-Party & Business Apps","domains":["access_control_identity"],"control_type":"preventive","control_category":"technical","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Integrations and API tokens to third-party vendors are scoped, inventoried and rotated.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"access_to_programs_data","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"AI agents restricted to suggestion-only pattern - no direct production writes","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C176","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"automated","key_control":"true","control_owner":"george.michael@bluth.example","description":"AI agents connected via MCP are architecturally restricted to writing only to the AISuggestion table. They cannot directly modify production data. All AI-proposed changes require human review and explicit approval before being applied to production items.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"entity_level","frequency":"continuous","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"AI suggestions require human approval before production changes","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2","iso-27001","soc1"],"control_id":"BLU-C177","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"automated","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"All changes proposed by AI agents through the MCP interface are stored as suggestions that require explicit human approval before being applied to production data. The approval interface displays the proposed changes for review. Approved and rejected suggestions are logged with the approver identity.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"entity_level","frequency":"continuous","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"CEO role description with documented conflicts, recusals, and no-override commitments","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2","iso-27001","soc1"],"control_id":"BLU-C178","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"A one-page CEO role description is maintained that explicitly enumerates: (a) the inherent conflicts of the CEO role (operator + authorizer + signer + admin); (b) the compensating control applied to each conflict (e.g., Model Home Data Lake branch protection with no founder-override role; quarterly IAM grants review by Internal Audit; advisor counter-sign on risk register; firm executes/records financial transactions the CEO authorizes); (c) the recusal commitments (decisions the CEO does not make alone - own access requests, own performance review, own equity grants, own code merges, solo-authoring SoD memo, solo-accepting material risks); (d) the no-override commitments and their evidence (no self-merge, no IAM bypass, no audit-log tampering, no skipping vCISO + advisor cadence, no solo policy exceptions). The document is signed by the CEO annually and counter-signed by the Independent Governance Advisor.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"entity_level","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C179","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"A signed Master Services Agreement is in force with Tidewell Advisory Group. Exhibit A enumerates each contracted function (bookkeeping, vCISO, legal review, HR administration, compliance advisory) with named deliverables and cadence. The MSA includes right-to-audit clauses, 90-day termination notice with orderly transition, breach notification within 72 hours, data residency disclosure, subprocessor consent, and the firm's own SOC 2 report (or carve-out language).\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Customer data is not used for AI model training; Vertex AI data governance in force","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C180","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Personal information and customer data collected through the platform is used only for the purposes documented in the Privacy Notice and the Master Services Agreement; the platform does not use customer data to train AI models. AI inference for the demo AI agent runs on Lucille Identity Cloud Vertex AI (Gemini) under Model Home Data Lake data-governance commitments: customer data sent for inference is not used to train models and prompt retention is disabled.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2","iso-27001","soc1"],"control_id":"BLU-C181","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Annually, Tidewell Advisory Group provides a signed attestation naming the specific individuals performing each contracted function on the Bluth Company engagement and confirming the SoD constraints below. Minimum 3 named individuals: (a) Bookkeeping personnel, (b) vCISO personnel (Advisory work may be performed by the same individual), (c) Internal-audit-sampling personnel. The internal-audit individual must not be involved in designing or operating any control they sample. Bookkeeping personnel must not be the same individual as internal-audit personnel. The attestation is counter-signed by the fractional CISO (Independent Governance Advisor). The Tidewell Advisory Group MSA includes the 3-person named-personnel separation as a contractual condition.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"not_assessed","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Immutable Cloud Audit Logs sink for management-override compensation","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C182","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"detective","control_category":"administrative","automation":"automated","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Model Home Data Lake Cloud Audit Logs (Admin Activity, Data Access, System Event) are exported via Cloud Logging log sink to a dedicated logging-only project with IAM bindings that prevent modification or deletion by anyone, including the Chief Executive Officer. The sink retention is configured for a minimum of 7 years to support investigative review.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"entity_level","frequency":"continuous","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C183","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"A signed advisor agreement is in force with the Independent Governance Advisor specifying scope (security program oversight, risk-acceptance review, CEO accountability), cadence (quarterly meetings, 2–4 hours per quarter), compensation, confidentiality, conflict-of-interest disclosure, and 60-day notice with successor-identification clause. After each quarterly meeting, the advisor provides a signed written attestation memo documenting their independent assessment of the security program.\n\n---\nBluth Company implementation:\n- CEO annual performance review signed by independent advisor (not firm, not self): Annually, the Independent Governance Advisor conducts a written performance and conduct review of the CEO covering security commitments, accountability against the prior year's objectives, ethical conduct, and competence development. The signed review is retained in the personnel file maintained by the firm's HR function. The CEO's objectives for the coming year are also reviewed and approved by the advisor.\n- Independent advisor counter-signs five high-stakes governance artifacts (quarterly risk register, annual fraud risk, annual SoD memo, annual firm-internal SoD attestation, annual CEO role description): The Independent Governance Advisor (the fractional CISO) counter-signs five governance artifacts on the cadence noted: (a) **Quarterly** - risk register (Tidewell Advisory Group's vCISO signs first, Tom counter-signs - this is the one routine sign-off Tom keeps because the risk register is the foundational governance artifact); (b) **Annual** - fraud risk assessment including management-override scenarios (Tidewell Advisory Group's vCISO drafts, Tom counter-signs because the topic is management override and needs a voice outside both management AND the firm); (c) **Annual** - SoD compensating controls memo (Tidewell Advisory Group's vCISO drafts, Tom counter-signs because the firm itself is part of the SoD compensation and cannot fully self-validate; CEO ratifies but does not author); (d) **Annual** - firm-internal SoD attestation (Tidewell Advisory Group drafts the named-personnel attestation, Tom counter-signs because the firm cannot independently attest to its own SoD structure); (e) **Annual** - CEO role description with conflicts and recusals (CEO drafts, Tom counter-signs because it is CEO-specific governance and the firm reports to the CEO). Tidewell Advisory Group's vCISO is the sign-off layer for all other operational compliance items (major policy changes, BCP/DR tabletop action items, P0/P1 post-mortem action items, incident-vs-noise criteria, non-code change risk samples) - those do not require Tom counter-signature.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"MCP tool surface documented and self-describing via get_schema","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C184","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"technical","automation":"automated","key_control":"true","control_owner":"george.michael@bluth.example","description":"The MCP tool surface (get_schema, query_data, suggest_change, get_current_context, get_step_context, upload_document, download_document) is documented in the MCP server source and surfaced to AI agents via the get_schema tool. Agents can discover available capabilities and their parameters without out-of-band documentation, reducing the risk of unintended or undocumented behavior.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"entity_level","frequency":"continuous","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Migrate-on-startup ties code and schema into single deployable artifact","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C185","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"technical","automation":"automated","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Database migrations are bundled into the Docker image and run on container startup via the migrate-on-startup entrypoint. Each image rebuild therefore acts as both a code deploy and a schema migration, ensuring code and schema stay aligned. Migrations are forward-compatible (additive) to allow rolling deploys; destructive migrations require an explicit two-step process documented in the Change Management Policy.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"entity_level","frequency":"continuous","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Per-tenant database isolation prevents cross-tenant data access","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2","iso-27001","soc1"],"control_id":"BLU-C186","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"technical","automation":"automated","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Each customer tenant operates on a dedicated database instance with separate credentials and connection strings. The application routes requests to the correct tenant database based on authenticated tenant context. No shared database access exists between tenants.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"entity_level","frequency":"continuous","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"in_progress","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Segregation of duties enforced for critical functions with documented compensating controls","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2","iso-27001","soc1"],"control_id":"BLU-C187","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"automated","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Segregation of duties is enforced through technical controls for critical functions where feasible. Specifically: (a) no developer can self-approve a merge request to main; (b) tenant image rollout to production is performed by the Chief Executive Officer or a designated operator, separate from the developer who authored the change; (c) Model Home Data Lake IAM roles/owner is restricted to the Chief Executive Officer. Where role count precludes strict separation, the following compensating controls apply and are documented in the compensating-controls memo in the Bluth Company system of record: merge request peer review, immutable audit logs to the central log sink, and post-deployment review during the monthly information security review.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"entity_level","frequency":"continuous","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Annual performance and conduct evaluation per personnel","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2","iso-27001","soc1"],"control_id":"BLU-C188","family":"Bluth Company Company-Specific","domains":["human_resources_personnel_security","governance_policy_oversight"],"control_type":"detective","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"george.michael@bluth.example","description":"Managers complete a documented performance and conduct evaluation for every direct report at least annually (the Human Resources Security Policy sets the cadence at semi-annual), covering adherence to the Code of Conduct and the Bluth Company policy suite and the individual's internal-control responsibilities. The evaluation informs recognition and, for conduct violations, the disciplinary process.\n\n---\nBluth Company implementation:\n- The CEO evaluates each employee, fractional worker, and contractor with production, source-code, or customer-data access; the Independent Governance Advisor conducts the CEO's own annual review. Tidewell Advisory Group's HR function administers the cycle and retains the signed evaluation records.\n- The Code of Conduct & Workforce Accountability Cycle links the evaluation to the code, incentives, and the disciplinary process each year and evidences completion for the whole roster; a missing or late evaluation is logged as an accountability deviation.\n- SOC 2 Type 1 readiness: closes gap G-03 (CC1.4 / CC1.5).\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":true,"control_class":"entity_level","frequency":"semi_annual","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"External-facing system description maintained and accurate","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C189","family":"Bluth Company Company-Specific","domains":["governance_policy_oversight","compliance_audit_assurance"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Management maintains an accurate, current description of the Bluth Company system for internal and external users - the services provided, the infrastructure, software, people, procedures, and data that deliver them, the system boundary and the carve-out subservice organizations (Lucille Identity Cloud, Model Home Data Lake, Tidewell Advisory Group), the principal service commitments and system requirements, and the complementary user-entity controls customers must operate - together with the published customer-facing documents it references: the customer terms and security commitments, the privacy policy, the operating and support guidance at docs.bluth.example, and the public reporting routes.\n\n---\nBluth Company implementation:\n- The Service Commitments & System Description Maintenance cycle drafts the description, reconciles it to the live estate and the control set, obtains the CEO's approval as management's assertion, publishes the customer-facing documents, and files the package for the examination; it re-runs annually and on any material change (new subservice organization, boundary change, commitment change).\n- SOC 2 Type 1 readiness: closes gaps G-07 (system description), G-08 (customer terms with security commitments) and G-09 (customer operating guidance and support resources) under CC2.2 / CC2.3.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"entity_level","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Customers notified of critical system changes affecting their processing","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C190","family":"Bluth Company Company-Specific","domains":["secure_configuration_change_management","governance_policy_oversight"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Customers are notified of critical system changes that may affect their processing before the change is deployed. A change is critical when it alters the data model or export format, the MCP or API contract, authentication or SSO behavior, a published availability or maintenance window, a subprocessor, or any customer-facing commitment recorded in the system description. Planned critical changes are announced at least five business days ahead through the release notes and an e-mail to each tenant's administrators; an emergency change meeting the trigger is notified within one business day after implementation, and the notification record is retained with the change record.\n\n---\nBluth Company implementation:\n- The trigger, channel, and notice period are defined in Change Management Policy Statement 4.11; the Change & Release Management (CAB) authorization step classifies each change against the trigger, and the Service Commitments & System Description Maintenance cycle keeps the commitment current and evidences the notifications sent.\n- SOC 2 Type 1 readiness: closes gap G-12 (CC2.3 / CC8.1), which found no defined customer-notification trigger, channel, or lead time.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"program_changes","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"not_assessed","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Incident reporting channels documented and communicated","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C191","family":"Bluth Company Company-Specific","domains":["incident_management_response","governance_policy_oversight"],"control_type":"detective","control_category":"administrative","automation":"hybrid","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Well-known channels through which personnel, customers, and other external parties report security events, system failures, concerns, and complaints are documented in the Incident Response Policy, published on the public website and the documentation site, communicated to all personnel at hire and annually, and monitored by named owners. Every report is acknowledged, recorded, and tracked through to resolution in the incident system of record - the Security Incident register in the Bluth Company system of record - with engineering remediation mirrored to Model Home Data Lake issues.\n\n---\nBluth Company implementation:\n- Public routes: michael.bluth@bluth.example and michael.bluth@bluth.example on bluth.example and the support page at docs.bluth.example; internal routes: incident@ / security-incident@ (monitored Lucille Identity Cloud Groups), oncall@ for Critical and High severity, and the grccanvas plugin's /grc-incident-open skill for customers. All routes deliver to the same monitored groups and are exercised by the Incident Reporting Channels & Spillage Response cycle, which sweeps the channels, acknowledges reporters within SLA, and routes genuine events to Cybersecurity Incident Response.\n- The system of record is named in Incident Response Policy Statement 4.10.\n- SOC 2 Type 1 readiness: closes gaps G-10 (public contact route, CC2.3) and G-25 (incident tracking system of record, CC7.2 / CC7.3).\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"annual","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"in_progress","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C192","family":"Bluth Company Company-Specific","domains":["logging_monitoring_detection","network_communications_security"],"control_type":"detective","control_category":"technical","automation":"automated","key_control":"true","control_owner":"george.michael@bluth.example","description":"Bluth Company runs no network intrusion detection appliance: its production estate is serverless Model Home Data Lake (the Model Home compute tier, Cloud SQL, Cloud Storage) behind Lucille Identity Cloud's edge, so the intrusion-detection function is delivered by the cloud-native detection stack - Security Command Center's Event Threat Detection and Security Health Analytics findings across every in-scope Model Home Data Lake project, Cloud Audit Log-based alerting policies in Cloud Monitoring for privileged and anomalous activity, and Cloud Armor edge logging. Findings and alerts are aggregated into a single detection queue, triaged on a defined cadence, and escalated to Cybersecurity Incident Response when they represent security events.\n\n---\nBluth Company implementation:\n- The Security Monitoring & Detection Operations cycle verifies Security Command Center and Cloud Monitoring coverage against the current project inventory, works the detection queue, records each triage disposition, and evidences the alert rules in force; Threat Intelligence & Insider Threat Program feeds detection watchlists.\n- SOC 2 Type 1 readiness: restates the workbook's IDS control statement (G-21, CC6.6 / CC7.2) in terms of the detection stack Bluth Company actually operates, so the control can be evidenced rather than left open for a product the entity does not run.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"continuous","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C193","family":"Bluth Company Company-Specific","domains":["asset_management_inventory","data_protection_privacy"],"control_type":"preventive","control_category":"administrative","automation":"manual","key_control":"true","control_owner":"maeby.fuenke@bluth.example","description":"Removable and portable media (USB drives, SD cards, external drives) shall not be used to store or transport company data, and customer data is never transferred via removable media under any circumstance; company and customer data live in Cloud SQL and Cloud Storage. The narrow approved exception - the storage media inside an end-of-life company device awaiting sanitization - is tracked as a media-custody record, stored encrypted (full-disk encryption remains enforced on the device), and sanitized or destroyed under the Asset & Media Management Policy.\n\n---\nBluth Company implementation:\n- The prohibition is Remote Working & Clear Desk Policy Statement 4.10; the Endpoint, Media & Information Handling Custody cycle operates the exception desk (authorize-and-track-removable-media) and verifies each cycle that no removable-media use exists outside it.\n- SOC 2 Type 1 readiness: closes gap G-22 (CC6.7) by stating the position plainly - prohibition, with encryption and custody tracking for the only approved exception - instead of an unenforced encryption-of-media requirement.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"quarterly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"User endpoint devices protected and managed (includes remote working security)","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C194","family":"Bluth Company Company-Specific","domains":["asset_management_inventory","network_communications_security"],"control_type":"preventive","control_category":"technical","automation":"hybrid","key_control":"true","control_owner":"ann.veal@bluth.example","description":"Every device used to access Bluth Company systems or data is a company-managed or approved endpoint configured with full-disk encryption, screen lock, current operating-system patches, and OS-native anti-malware, as the Remote Working & Clear Desk Policy requires. Endpoints are inventoried and their compliance verified centrally through Lucille Identity Cloud endpoint management - every device that signs in to a Bluth Company Lucille Identity Cloud account appears in the admin console's device list with its operating system, last sync, and policy state - reconciled each custody cycle against the workforce roster and the remote-work security attestations.\n\n---\nBluth Company implementation:\n- Lucille Identity Cloud endpoint management is the lightweight endpoint-management (device policy) console the tailored templates already name; it is included in the existing Lucille Identity Cloud subscription, so no additional MDM product is procured or run. The Endpoint, Media & Information Handling Custody cycle (verify-endpoint-safeguards-and-acceptable-use) reconciles the device list to the roster and the Workplace & Remote Work Security Cycle collects the attestations; an unmanaged or non-compliant device is logged as a corrective action and blocked from Workspace access until remediated.\n- SOC 2 Type 1 readiness: closes gap G-23 (CC6.7) by naming the central endpoint inventory and verification mechanism and the workflow that evidences it.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"monthly","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"not_tested","ye_result":"not_tested","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Anti-malware / endpoint protection deployed on personnel endpoints","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"framework":["soc2","iso-27001"],"control_id":"BLU-C195","family":"Bluth Company Company-Specific","domains":["vulnerability_patch_management","network_communications_security"],"control_type":"preventive","control_category":"technical","automation":"hybrid","key_control":"true","control_owner":"michael.bluth@bluth.example","description":"Personnel endpoints run OS-native anti-malware and endpoint protection - macOS XProtect and Gatekeeper, Microsoft Defender on Windows - with automatic operating-system and signature updates enabled and real-time scanning on; users cannot disable them. Inbound e-mail and web content are protected by Lucille Identity Cloud and Gmail advanced protection (malware, spam, and phishing detection with quarantine) and Chrome Safe Browsing. Bluth Company operates no separately procured, centrally managed anti-malware product; protection currency is verified per endpoint each cycle rather than pushed from a console.\n\n---\nBluth Company implementation:\n- The design is Network Security Policy Statement 4.3 and Remote Working & Clear Desk Policy Statement 4.1. The Malware, Email & Web Content Defense Operations cycle verifies OS patch and protection currency across the fleet via the Lucille Identity Cloud endpoint inventory and the remote-work attestations, reviews Gmail's detection and quarantine log, confirms Critical and High detections reached on-call, and records scan and update behavior as the control's evidence.\n- SOC 2 Type 1 readiness: closes gap G-24 (CC6.8) with a factual restatement - OS-native protection with automatic updates, verified per cycle - rather than an unevidenced central-console claim.\n\n_The framework tags on this company-specific control are scoping hints, not direct criterion references._\n\nUse the reviewed unified-control mappings above for criterion-level traceability.","sox_applicable":false,"control_class":"itgc","itgc_domain":"computer_operations","frequency":"monthly","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"in_progress","ye_result":"not_tested","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Availability & capacity management (SLA)","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C196","description":"Monthly per-facility review of uptime vs SLA and N+1 capacity headroom; breaches feed the SLA-credit process and ops governance","full_description":"**Control activity**\n\nMonthly, Critical Facilities produces the availability and capacity report for every operated facility: measured uptime against each contracted SLA tier (up to 99.999% for 2N halls), downtime minutes by incident from the DCIM/BMS event history reconciled to the OPS-04 incident log, maintenance-window compliance, and power and cooling utilization against installed capacity with N+1 redundancy headroom. SLA breaches are computed per the customer contract and routed to billing for service-credit memos in Banana ERP; utilization above 85% of rated capacity in any hall triggers a documented capacity-plan action (densification, an expansion phase gate, or sales throttling). The VP Operations chairs a monthly operations review where the report, credits and capacity actions are approved and minuted.\n\n**Key risk**\n\nAvailability misses and SLA breaches go unmeasured or unreported, so service credits owed to user entities are not accrued, reported uptime is unreliable, and capacity exhaustion goes unmanaged.\n\n**Assertions:** Completeness, Accuracy / Valuation, Existence / Occurrence\n\n**Test procedure**\n\nFor sample months across the SOC 1 examination period, recompute reported uptime from DCIM/BMS event data and the incident log; trace computed SLA breaches to credit memos in Banana ERP; inspect the operations-review minutes approving the report and any capacity actions.\n\n**Evidence**\n\nEvidence for OPS-03: monthly availability and capacity reports, DCIM downtime extracts, SLA-credit calculations and credit memos, and operations-review minutes.","framework":["soc1"],"family":"Data Center Operations & Service Delivery (SOC 1)","domains":["business_continuity_disaster_recovery"],"control_type":"detective","control_category":"technical","control_class":"soc1_service_delivery","itgc_domain":null,"automation":"manual","key_control":"false","sox_applicable":false,"frequency":"monthly","control_owner":"george.michael@bluth.example","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"in_progress","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}},{"title":"Business continuity & disaster recovery plan testing","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"control_id":"BLU-C197","description":"Annual per-facility DR exercise — generator and UPS load tests, live failover, tabletop — with RTO targets and remediation retest","full_description":"**Control activity**\n\nEach facility maintains a documented business-continuity and disaster-recovery plan, reviewed and updated annually, with a testing program scoped to the facility's redundancy tier. The annual program includes monthly generator no-load runs and an annual full-load bank test per engine, annual UPS battery-string discharge tests, a live utility-failover test (open-transition or pull-the-plug per the site risk assessment) executed during an announced maintenance window, and a tabletop exercise covering a regional scenario (grid loss, flood, wildfire smoke) — with at least one live failover per facility per year. Recovery time and recovery point objectives for the DCIM/BMS and facility-management systems are defined and measured against actuals during each exercise. User entities are notified of test windows at least 10 business days in advance per contract; every failed or deviated step is logged with a remediation owner and due date and is retested; and results roll up to the VP Operations and the quarterly operations governance review.\n\n**Key risk**\n\nAn unproven continuity plan fails during a real event — an extended facility outage breaches availability commitments and delays or loses the DCIM/metering data user entities depend on for their financial processing.\n\n**Assertions:** Existence / Occurrence, Completeness\n\n**Test procedure**\n\nInspect the current-year test calendar and, for a sample of facilities across tiers, the generator load-bank and UPS discharge results, the live failover runbook with measured times against RTO targets, customer notification records for the 10-day standard, and remediation-with-retest evidence for any failed step across the SOC 1 examination period.\n\n**Evidence**\n\nEvidence for EOPS-01: facility DR plans, load-bank and battery test reports, failover exercise runbooks with RTO/RPO actuals, tabletop minutes, customer notifications, and the remediation tracker.","framework":["soc1"],"family":"Data Center Operations & Service Delivery (SOC 1)","domains":["business_continuity_disaster_recovery","physical_environmental_security"],"control_type":"detective","control_category":"administrative","control_class":"soc1_service_delivery","itgc_domain":null,"automation":"manual","key_control":"true","sox_applicable":false,"frequency":"annual","control_owner":"maeby.fuenke@bluth.example","locations":"Newport Beach and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"interim_sufficient","last_tested_fy":"FY2026"}},{"title":"Vendor onboarding due diligence & risk tiering","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"control_id":"BLU-C198","description":"New vendors are tiered and vetted in the board portal — sanctions, viability, security — before activation in the Banana ERP vendor master","full_description":"**Control activity**\n\nBefore a new vendor can transact, the TPRM Lead completes onboarding due diligence in the board portal scaled to the vendor's inherent-risk tier (projected spend, access to systems or data, site access, single-source exposure, impact on financial processing): sanctions/denied-party and adverse-media screening for all vendors; financial-viability review for single-source construction and long-lead equipment suppliers (generators, switchgear, chillers); a security questionnaire or current SOC report for vendors touching Bluth Company systems or data; and certificate-of-insurance validation for on-site contractors. The assigned tier sets the ongoing monitoring cadence — critical and high vendors enter the annual TPRM-01 reassessment population. Activation of the vendor master record in Banana ERP is blocked until the the board portal assessment is approved, and the tier and assessment reference are recorded on the vendor record.\n\n**Key risk**\n\nUnvetted vendors enter the payment master — sanctioned parties, shell or fraudulent vendors, financially fragile single-source suppliers — exposing Bluth Company to fraud, build-schedule and subservice risk.\n\n**Assertions:** Existence / Occurrence, Rights / Obligations\n\n**Test procedure**\n\nSample vendors first activated in Banana ERP during the period; for each, verify the the board portal assessment was approved before activation, screening results are on file, and the assigned tier matches the documented risk factors.\n\n**Evidence**\n\nEvidence for TPRM-03: the board portal onboarding assessments, screening and viability results, insurance certificates, tier assignments, and the Banana ERP activation log.","framework":["sox","soc1"],"family":"Third-Party / Vendor Risk Management","domains":["third_party_supply_chain_risk"],"control_type":"preventive","control_category":"administrative","control_class":"business_process","itgc_domain":null,"automation":"manual","key_control":"false","sox_applicable":true,"frequency":"ad_hoc","control_owner":"ann.veal@bluth.example","design_conclusion":"not_assessed","interim_result":"not_tested","ye_result":"not_tested","locations":"Phoenix and Remote","rollforward_strategy":"roll_forward","last_tested_fy":"FY2026"}},{"title":"Third-party risk assessment & SOC report review","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"control_id":"BLU-C199","description":"Annual risk reassessment of critical vendors in the board portal with SOC 1/SOC 2 report review, CUEC mapping and exception disposition","full_description":"**Control activity**\n\nAnnually, the TPRM Lead reassesses every vendor tiered critical or high in the board portal — the financially relevant SaaS stack (Banana ERP, Never Nude HR Platform, Banana ERP, Banana ERP, Banana ERP), colocation-critical suppliers such as utilities and generator/UPS service providers, and outsourced processors. For each system vendor the current SOC 1 and/or SOC 2 Type II report is obtained and reviewed: opinion, period coverage against Bluth Company's fiscal year (bridge letters requested for gaps over three months), subservice organizations and carve-outs, exceptions assessed for impact on Bluth Company's ICFR reliance and on Bluth Company's own SOC 1 examination, and the complementary user-entity controls mapped to specific Bluth Company controls with confirmation each is operating. Review conclusions, exceptions and remediation actions are tracked in the board portal to closure and summarized to the Chief Risk Officer.\n\n**Key risk**\n\nA critical vendor's control failure, SOC-report exception or unperformed CUEC goes unassessed, undermining both SOX reliance on the SaaS stack and the subservice-organization representations in Bluth Company's own SOC 1 report.\n\n**Assertions:** Existence / Occurrence, Completeness, Accuracy / Valuation\n\n**Test procedure**\n\nFor a sample of critical and high vendors, inspect the annual reassessment in the board portal, the SOC-report review memo (opinion, period, exceptions dispositioned), the CUEC mapping with operating evidence, and bridge letters where report periods lagged the fiscal year.\n\n**Evidence**\n\nEvidence for TPRM-01: the board portal assessment records, SOC-report review memos, CUEC matrix with control mapping, bridge letters, and the exception/remediation log.","framework":["sox","soc1"],"family":"Third-Party / Vendor Risk Management","domains":["third_party_supply_chain_risk"],"control_type":"detective","control_category":"administrative","control_class":"business_process","itgc_domain":null,"automation":"manual","key_control":"true","sox_applicable":true,"frequency":"annual","control_owner":"michael.bluth@bluth.example","design_conclusion":"not_assessed","interim_result":"not_tested","ye_result":"not_tested","locations":"Newport Beach and Remote","rollforward_strategy":"not_required","last_tested_fy":"FY2026"}},{"title":"Incident management & customer notification","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"control_id":"BLU-C200","description":"Facility incidents are logged, severity-classed and customer-notified within SLA; RCAs and corrective actions tracked to closure","full_description":"**Control activity**\n\nAll facility incidents — utility interruptions, generator or UPS transfers, cooling excursions, water detection, fire-system activations, physical-security events and network outages — are logged in the IT service-management queue with severity assigned at triage: S1 (customer impact or loss of redundancy) requires notification to affected customers within 15 minutes of confirmation with hourly updates until stable; S2 (single-path degradation, no customer impact) notifies within one hour where contractually required. Root-cause analysis is completed within five business days for S1/S2 incidents and corrective actions are tracked to closure with named owners. Incidents with SLA or billing impact are flagged to the OPS-03 credit process. Weekly, the Service Delivery Manager reconciles the incident log against DCIM/BMS alarm history to confirm no qualifying event went unlogged.\n\n**Key risk**\n\nIncidents go unlogged, unclassified or uncommunicated, so user entities cannot assess the impact on their processing, SLA credits are missed, and repeat failures persist without corrective action.\n\n**Assertions:** Completeness, Existence / Occurrence\n\n**Test procedure**\n\nSample S1/S2 incidents across the SOC 1 examination period: verify notification timestamps against the 15-minute and one-hour standards, RCA completion within five business days, and corrective-action closure; reperform one weekly alarm-to-ticket reconciliation.\n\n**Evidence**\n\nEvidence for OPS-04: incident tickets with severity and timestamps, customer notification records, RCA reports, the corrective-action tracker, and the weekly alarm reconciliation.","framework":["soc1"],"family":"Data Center Operations & Service Delivery (SOC 1)","domains":["incident_management_response"],"control_type":"corrective","control_category":"administrative","control_class":"soc1_service_delivery","itgc_domain":null,"automation":"manual","key_control":"false","sox_applicable":false,"frequency":"ad_hoc","control_owner":"george.michael@bluth.example","locations":"Phoenix and Remote","design_conclusion":"effective","interim_result":"effective","ye_result":"not_tested","rollforward_strategy":"full_retest","last_tested_fy":"FY2026"}}],"issue":[{"title":"Quarterly access recertification missed two finance approvers","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"The Q3 recertification of Record to Report access did not include two finance approvers added during the quarter.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"low","issue_type":"finding","source":"internal_audit","sox_deficiency":"control_deficiency","root_cause":"The recertification listing was extracted before the two approvers were added to the ERP.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-07-12","reported_date":"2026-07-14","target_remediation_date":"2026-08-10"}},{"title":"Privileged access granted before approval during the close","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Temporary administrator access for the financial close was granted first and approved afterwards.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"medium","issue_type":"exception","source":"sox_testing","sox_deficiency":"control_deficiency","root_cause":"Administrators granted close-period access to meet the deadline and recorded the approvals later.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-07-11","reported_date":"2026-07-13","target_remediation_date":"2026-08-09"}},{"title":"Leaver accounts in Banana ERP disabled late","status":"IN_PROGRESS","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Accounts of employees who left were disabled in Banana ERP up to a week after their leaving date.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"medium","issue_type":"observation","source":"self_assessment","root_cause":"The HR leaver feed reaches Banana ERP only in the weekly batch.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-06-12","reported_date":"2026-06-14","target_remediation_date":"2026-08-20"}},{"title":"Emergency access sessions not reviewed","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Emergency access sessions have not had their after-the-fact review since July.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"high","issue_type":"deficiency","source":"sox_testing","sox_deficiency":"significant_deficiency","root_cause":"No reviewer was assigned to the emergency access log after the security lead left.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-06-11","reported_date":"2026-06-13","target_remediation_date":"2026-08-11"}},{"title":"Change approval waived for a revenue system release","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"A revenue system release went to production under a change approval waiver that is still open.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"high","issue_type":"policy_exception","source":"management_identified","root_cause":"The release was treated as an emergency to meet quarter end, and the waiver was never closed.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-05-13","reported_date":"2026-05-15","exception_approver":"George Michael Bluth","exception_expiry_date":"2026-08-31","target_remediation_date":"2026-08-07"}},{"title":"Developers can deploy their own changes to production","status":"IN_PROGRESS","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"The deployment pipeline does not stop the author of a change from approving and releasing it.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"critical","issue_type":"material_weakness","source":"external_audit","sox_deficiency":"material_weakness","root_cause":"Separate approval was never enforced in the pipeline configuration.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-05-12","reported_date":"2026-05-14","target_remediation_date":"2026-08-08"}},{"title":"Opportunity to automate change migration reconciliation","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Monthly change migration reconciliation could be automated by matching ticket and deployment logs.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"low","issue_type":"opportunity","source":"compliance_review","root_cause":"Change migrations are reconciled by hand each month from two separate logs.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-08-12","reported_date":"2026-08-14"}},{"title":"Failed vendor payment batches went unnoticed","status":"RESOLVED","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Two failed vendor payment batches were found days late. The batches were re-run and alerting was fixed.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"medium","issue_type":"finding","source":"internal_audit","sox_deficiency":"control_deficiency","root_cause":"Batch failure alerts went to a shared mailbox that nobody monitored; they now go to the on-call queue.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-04-13","reported_date":"2026-04-15","actual_remediation_date":"2026-08-06"}},{"title":"Payroll backup restore test ran a month late","status":"CLOSED","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"The annual payroll backup restore test ran a month after its scheduled date.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"low","issue_type":"observation","source":"self_assessment","root_cause":"The test was moved for a payroll system upgrade, and management accepted the delay.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-02-12","reported_date":"2026-02-14","actual_remediation_date":"2026-03-14"}},{"title":"PBC Request 1 — Revenue Population","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"PBC Request 1 — Revenue Population: raised for its owner to evaluate and resolve.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"high","issue_type":"pbc_request","source":"external_audit","root_cause":"The revenue population must be extracted from Cornballer Revenue Engine by the system owner.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-08-01","reported_date":"2026-08-03","target_remediation_date":"2026-08-11"}},{"title":"PBC Request 2 — Access Listing","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"PBC Request 2 — Access Listing: raised for its owner to evaluate and resolve.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"medium","issue_type":"pbc_request","source":"external_audit","root_cause":"User listings come from Lucille Identity Cloud and need the administrator to run the report.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-07-22","reported_date":"2026-07-24","target_remediation_date":"2026-08-12"}},{"title":"PBC Request 3 — Change Samples","status":"IN_PROGRESS","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"PBC Request 3 — Change Samples: raised for its owner to evaluate and resolve.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"critical","issue_type":"pbc_request","source":"external_audit","root_cause":"Change tickets for the sample have to be pulled from the change management tool.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-07-02","reported_date":"2026-07-04","target_remediation_date":"2026-08-13"}},{"title":"PBC Request 4 — Vendor Reports","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"PBC Request 4 — Vendor Reports: raised for its owner to evaluate and resolve.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"low","issue_type":"pbc_request","source":"external_audit","root_cause":"SOC reports are held by vendor management and are shared under NDA.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-06-22","reported_date":"2026-06-24","target_remediation_date":"2026-08-14"}},{"title":"PBC Request 5 — Legal Confirmations","status":"RESOLVED","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"PBC Request 5 — Legal Confirmations: raised for its owner to evaluate and resolve.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"medium","issue_type":"pbc_request","source":"external_audit","root_cause":"Outside counsel confirmations are requested through the legal department.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-06-02","reported_date":"2026-06-04","actual_remediation_date":"2026-08-06"}},{"title":"PBC Request 6 — Board Minutes","status":"CLOSED","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"PBC Request 6 — Board Minutes: raised for its owner to evaluate and resolve.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"high","issue_type":"pbc_request","source":"external_audit","root_cause":"Board minutes are released by the corporate secretary after approval.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-05-23","reported_date":"2026-05-25","actual_remediation_date":"2026-08-06"}},{"title":"Penetration Test Vulnerability","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Penetration Test Vulnerability: raised for its owner to evaluate and resolve.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"critical","issue_type":"finding","source":"penetration_test","root_cause":"An externally exposed web server was missing security patches from the last two cycles.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-07-27","reported_date":"2026-07-29","target_remediation_date":"2026-08-17"}},{"title":"Privacy Waiver Expiring","status":"OPEN","visibility":"private","owners":["michael.bluth@bluth.example"],"fields":{"description":"Privacy Waiver Expiring: raised for its owner to evaluate and resolve.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"medium","issue_type":"policy_exception","source":"management_identified","root_cause":"The data transfer agreement that the waiver depends on is still being negotiated.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-06-27","reported_date":"2026-06-29","exception_approver":"George Michael Bluth","exception_expiry_date":"2027-01-08","target_remediation_date":"2026-08-17"}},{"title":"Regulatory Examination Observation","status":"CLOSED","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Regulatory Examination Observation: raised for its owner to evaluate and resolve.","full_description":"The issue carries only identification, classification, cause, and management-response evidence; corrective action dates live on linked Remediation items.","severity":"high","issue_type":"observation","source":"regulatory_exam","root_cause":"Complaint handling records were not retained for the full period the regulator expects.","recommendation":"Management should address the condition through a separately owned remediation action.","management_response":"Management accepts the recommendation and will provide evidence through the linked action.","identified_date":"2026-01-23","reported_date":"2026-01-25","actual_remediation_date":"2026-08-06"}},{"title":"Policy exception — AI Governance & Acceptable AI Use Policy","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Time-bound exception to \"AI Governance & Acceptable AI Use Policy\" while a compensating arrangement is in place.","severity":"high","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-07-02","reported_date":"2026-07-04","exception_approver":"George Michael Bluth","exception_expiry_date":"2026-08-01"}},{"title":"Policy exception — Access Control Standard","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Time-bound exception to \"Access Control Standard\" while a compensating arrangement is in place.","severity":"medium","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-07-22","reported_date":"2026-07-24","exception_approver":"Maeby Fünke","exception_expiry_date":"2026-08-23"}},{"title":"Policy exception — Board & Governance Policy","status":"IN_PROGRESS","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Time-bound exception to \"Board & Governance Policy\" while a compensating arrangement is in place.","severity":"critical","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-07-07","reported_date":"2026-07-09","exception_approver":"Michael Bluth","exception_expiry_date":"2026-09-05"}},{"title":"Policy exception — Cloud Services Security Policy","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Time-bound exception to \"Cloud Services Security Policy\" while a compensating arrangement is in place.","severity":"low","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-06-24","reported_date":"2026-06-26","exception_approver":"Ann Veal","exception_expiry_date":"2026-09-25"}},{"title":"Policy exception — Data Classification & Handling Policy","status":"IN_PROGRESS","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Time-bound exception to \"Data Classification & Handling Policy\" while a compensating arrangement is in place.","severity":"medium","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-06-12","reported_date":"2026-06-14","exception_approver":"George Michael Bluth","exception_expiry_date":"2026-10-10"}},{"title":"Policy exception — Financial Close Procedure","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Time-bound exception to \"Financial Close Procedure\" while a compensating arrangement is in place.","severity":"high","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-05-28","reported_date":"2026-05-30","exception_approver":"Maeby Fünke","exception_expiry_date":"2026-11-09"}},{"title":"Policy exception — Incident Response Policy","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Time-bound exception to \"Incident Response Policy\" while a compensating arrangement is in place.","severity":"medium","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-05-13","reported_date":"2026-05-15","exception_approver":"Michael Bluth","exception_expiry_date":"2026-12-09"}},{"title":"Policy exception — Information Transfer & Leakage Prevention Policy","status":"IN_PROGRESS","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Time-bound exception to \"Information Transfer & Leakage Prevention Policy\" while a compensating arrangement is in place.","severity":"low","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-04-28","reported_date":"2026-04-30","exception_approver":"Ann Veal","exception_expiry_date":"2027-02-07"}},{"title":"Policy exception — Management Review Procedure","status":"CLOSED","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Time-bound exception to \"Management Review Procedure\" while a compensating arrangement is in place.","severity":"medium","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-03-14","reported_date":"2026-03-16","exception_approver":"George Michael Bluth","exception_expiry_date":"2027-04-08","actual_remediation_date":"2026-04-13"}},{"title":"Policy exception — Physical Security Policy","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Time-bound exception to \"Physical Security Policy\" while a compensating arrangement is in place.","severity":"high","issue_type":"policy_exception","source":"management_identified","identified_date":"2026-07-30","reported_date":"2026-08-01","exception_approver":"Maeby Fünke"}}],"remediation":[{"title":"Re-run the access recertification for Record to Report approvers","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Repeat the recertification with a listing extracted on the review date.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Repeat the recertification with a listing extracted on the review date. Keep the evidence ready for review.","remediation_type":"control_redesign","action_owner":"michael.bluth@bluth.example","priority":"critical","target_date":"2026-09-10","revised_target_date":"2026-08-10","validation_method":"design_retest","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Require approval before privileged access is granted","status":"IN_PROGRESS","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Configure the access tool so close-period administrator access waits for approval.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Configure the access tool so close-period administrator access waits for approval. Keep the evidence ready for review.","remediation_type":"new_control","action_owner":"george.michael@bluth.example","priority":"high","target_date":"2026-08-09","validation_method":"operating_retest","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Move the HR leaver feed to a daily run","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Run the HR leaver feed to Banana ERP every day instead of weekly.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Run the HR leaver feed to Banana ERP every day instead of weekly. Keep the evidence ready for review.","remediation_type":"system_configuration","action_owner":"maeby.fuenke@bluth.example","priority":"medium","validation_method":"evidence_inspection","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Review all emergency access sessions since July","status":"IN_PROGRESS","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Assign a reviewer and review every emergency access session since July.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Assign a reviewer and review every emergency access session since July. Keep the evidence ready for review.","remediation_type":"process_change","action_owner":"ann.veal@bluth.example","priority":"low","target_date":"2026-08-11","validation_method":"reperformance","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Close the change approval waiver and log the exception","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Complete the change approval for the release and record the exception under the Risk Management Policy.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Complete the change approval for the release and record the exception under the Risk Management Policy. Keep the evidence ready for review.","remediation_type":"policy_update","action_owner":"michael.bluth@bluth.example","priority":"medium","target_date":"2026-08-07","validation_method":"monitoring","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Enforce separate approval in the deployment pipeline","status":"IN_PROGRESS","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Block self-approval in the pipeline and brief release managers on the new rule.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Block self-approval in the pipeline and brief release managers on the new rule. Keep the evidence ready for review.","remediation_type":"training","action_owner":"george.michael@bluth.example","priority":"high","target_date":"2026-08-08","validation_method":"design_retest","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Re-run and reconcile the failed vendor payment batches","status":"RESOLVED","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Re-run the two failed batches and reconcile the payments to the vendor ledger.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Re-run the two failed batches and reconcile the payments to the vendor ledger. Keep the evidence ready for review.","remediation_type":"data_correction","action_owner":"maeby.fuenke@bluth.example","priority":"critical","target_date":"2026-08-09","completed_date":"2026-08-06","validation_method":"evidence_inspection","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Confirm the ticketing vendor supports log export","status":"CLOSED","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"The vendor confirmed that ticket logs can be exported for automated matching.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"The vendor confirmed that ticket logs can be exported for automated matching. Keep the evidence ready for review.","remediation_type":"third_party_action","action_owner":"ann.veal@bluth.example","priority":"medium","target_date":"2026-08-10","completed_date":"2026-08-06","verified_date":"2026-08-09","verified_by":"michael.bluth@bluth.example","validation_method":"monitoring","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"PBC Delivery 1 — Revenue Population","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"PBC Delivery 1 — Revenue Population: a corrective or evidence-delivery action tracked to closure.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Deliver the requested evidence to the audit team. Keep the evidence ready for review.","remediation_type":"evidence_submission","action_owner":"michael.bluth@bluth.example","priority":"high","target_date":"2026-08-11","validation_method":"evidence_inspection","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"PBC Delivery 2 — Access Listing","status":"IN_PROGRESS","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"PBC Delivery 2 — Access Listing: a corrective or evidence-delivery action tracked to closure.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Deliver the requested evidence to the audit team. Keep the evidence ready for review.","remediation_type":"evidence_submission","action_owner":"george.michael@bluth.example","priority":"medium","target_date":"2026-08-12","validation_method":"reperformance","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"PBC Delivery 3 — Change Samples","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"PBC Delivery 3 — Change Samples: a corrective or evidence-delivery action tracked to closure.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Deliver the requested evidence to the audit team. Keep the evidence ready for review.","remediation_type":"evidence_submission","action_owner":"maeby.fuenke@bluth.example","priority":"critical","target_date":"2026-08-13","validation_method":"evidence_inspection","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"PBC Delivery 4 — Vendor Reports","status":"IN_PROGRESS","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"PBC Delivery 4 — Vendor Reports: a corrective or evidence-delivery action tracked to closure.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Deliver the requested evidence to the audit team. Keep the evidence ready for review.","remediation_type":"evidence_submission","action_owner":"ann.veal@bluth.example","priority":"low","target_date":"2026-08-14","validation_method":"monitoring","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"PBC Delivery 5 — Legal Confirmations","status":"RESOLVED","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"PBC Delivery 5 — Legal Confirmations: a corrective or evidence-delivery action tracked to closure.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Deliver the requested evidence to the audit team. Keep the evidence ready for review.","remediation_type":"evidence_submission","action_owner":"michael.bluth@bluth.example","priority":"medium","target_date":"2026-08-15","completed_date":"2026-08-06","validation_method":"evidence_inspection","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"PBC Delivery 6 — Board Minutes","status":"CLOSED","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"PBC Delivery 6 — Board Minutes: a corrective or evidence-delivery action tracked to closure.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Deliver the requested evidence to the audit team. Keep the evidence ready for review.","remediation_type":"evidence_submission","action_owner":"george.michael@bluth.example","priority":"high","target_date":"2026-08-16","completed_date":"2026-08-06","verified_date":"2026-08-09","verified_by":"maeby.fuenke@bluth.example","validation_method":"reperformance","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Monitor the penetration test and privacy waiver fixes","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Check for two months that the web server patches hold and the privacy waiver is renewed or closed.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Check for two months that the web server patches hold and the privacy waiver is renewed or closed. Keep the evidence ready for review.","remediation_type":"monitoring_only","action_owner":"maeby.fuenke@bluth.example","priority":"low","target_date":"2026-08-17","validation_method":"monitoring","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Route batch failure alerts to the on-call queue","status":"CLOSED","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Send batch failure alerts to the on-call queue and confirm one test alert.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Send batch failure alerts to the on-call queue and confirm one test alert. Keep the evidence ready for review.","remediation_type":"control_redesign","action_owner":"ann.veal@bluth.example","priority":"critical","target_date":"2026-08-18","completed_date":"2026-08-06","verified_date":"2026-08-09","verified_by":"michael.bluth@bluth.example","validation_method":"operating_retest","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Retain complaint records for the full regulatory period","status":"RESOLVED","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Extend complaint record retention to the period the regulator expects.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Extend complaint record retention to the period the regulator expects. Keep the evidence ready for review.","remediation_type":"process_change","action_owner":"michael.bluth@bluth.example","priority":"medium","target_date":"2026-08-19","completed_date":"2026-08-06","validation_method":"design_retest","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}},{"title":"Test leaver access removal next quarter","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Confirm next quarter that leaver accounts are disabled within one day.","full_description":"Tracked separately from its issue, with its own plan, owner, due dates, validation method and closure evidence.","plan":"Confirm next quarter that leaver accounts are disabled within one day. Keep the evidence ready for review.","remediation_type":"system_configuration","action_owner":"george.michael@bluth.example","priority":"high","target_date":"2026-08-20","validation_method":"reperformance","closure_criteria":"Evidence is complete, internally consistent, and independently validated."}}],"process":[{"title":"Financial Reporting Area","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Financial Reporting Area groups related operating processes for hierarchy reporting.","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"michael.bluth@bluth.example","frequency":"Area container","fsli_significance":"high","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one canonical subprocess.","last_tested_fy":"FY2026"}},{"title":"Revenue and Receivables Area","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Revenue and Receivables Area groups related operating processes for hierarchy reporting.","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"george.michael@bluth.example","frequency":"Area container","fsli_significance":"high","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one canonical subprocess.","last_tested_fy":"FY2026"}},{"title":"Procure to Pay Area","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Procure to Pay Area groups related operating processes for hierarchy reporting.","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"maeby.fuenke@bluth.example","frequency":"Area container","fsli_significance":"high","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one canonical subprocess.","last_tested_fy":"FY2026"}},{"title":"People and Payroll Area","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"People and Payroll Area groups related operating processes for hierarchy reporting.","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"ann.veal@bluth.example","frequency":"Area container","fsli_significance":"high","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one canonical subprocess.","last_tested_fy":"FY2026"}},{"title":"Technology Area","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Technology Area groups related operating processes for hierarchy reporting.","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"michael.bluth@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one canonical subprocess.","last_tested_fy":"FY2026"}},{"title":"Security and Privacy Area","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Security and Privacy Area groups related operating processes for hierarchy reporting.","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"george.michael@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one canonical subprocess.","last_tested_fy":"FY2026"}},{"title":"Governance and Assurance Area","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Governance and Assurance Area groups related operating processes for hierarchy reporting.","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"maeby.fuenke@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one canonical subprocess.","last_tested_fy":"FY2026"}},{"title":"Record to Report","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Record to Report is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"financial_reporting","process_owner":"michael.bluth@bluth.example","frequency":"Continuous","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Financial Close and Consolidation","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Financial Close and Consolidation is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"financial_reporting","process_owner":"george.michael@bluth.example","frequency":"Daily","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"SOX Program Management","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"SOX Program Management is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"business_process","process_owner":"maeby.fuenke@bluth.example","frequency":"Monthly","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Order to Cash","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Order to Cash is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"business_process","process_owner":"ann.veal@bluth.example","frequency":"Quarterly","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Revenue Recognition","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Revenue Recognition is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"financial_reporting","process_owner":"michael.bluth@bluth.example","frequency":"Annual","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":false,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Credit and Collections","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Credit and Collections is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"business_process","process_owner":"george.michael@bluth.example","frequency":"Continuous","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Procure to Pay","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Procure to Pay is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"business_process","process_owner":"maeby.fuenke@bluth.example","frequency":"Daily","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Vendor Lifecycle Management","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Vendor Lifecycle Management is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"business_process","process_owner":"ann.veal@bluth.example","frequency":"Monthly","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Payroll Administration","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Payroll Administration is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"business_process","process_owner":"michael.bluth@bluth.example","frequency":"Quarterly","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"User Access Management","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"User Access Management is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"it_general_control","process_owner":"george.michael@bluth.example","frequency":"Annual","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":false,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Change Management","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Change Management is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"it_general_control","process_owner":"maeby.fuenke@bluth.example","frequency":"Continuous","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"IT Operations","status":"ACTIVE","visibility":"private","owners":["ann.veal@bluth.example"],"fields":{"description":"IT Operations is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"it_general_control","process_owner":"ann.veal@bluth.example","frequency":"Daily","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Incident and Privacy Response","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Incident and Privacy Response is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"security_process","process_owner":"michael.bluth@bluth.example","frequency":"Monthly","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Risk and Compliance Management","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Risk and Compliance Management is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"business_process","process_owner":"george.michael@bluth.example","frequency":"Quarterly","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Internal Audit Delivery","status":"PLANNED","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Internal Audit Delivery is an auditable operating process with control and subprocess coverage.","full_description":"A fictional Bluth Company business process, linked to its parent process and to the controls that operate in it.","process_type":"business_process","process_owner":"maeby.fuenke@bluth.example","frequency":"Annual","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":false,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Access, Identity & Cryptography","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"# Access, Identity & Cryptography\n\n## Purpose\nGovern who and what can reach systems and data across the joiner-mover-leaver lifecycle, and control the cryptographic keys and secrets that protect them.\n\n## Role in the Operating Model\nThis is a process area - an organizational container that groups the operating processes below. It carries no framework sections and hosts no attached runs of its own; each process owns the framework references, controls, risks, policies, and operating workflow runs that operationalize this area. Use it to browse and report on the area as a whole and to navigate to the process that performs the work.\n\n## Operating Processes\n- Identity, Authentication & Access Lifecycle\n- Cryptography, Key & Secrets Management","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"george.michael@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one operating process carried from the operating-process register.","last_tested_fy":"FY2026"}},{"title":"Data Protection & Privacy","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"# Data Protection & Privacy\n\n## Purpose\nProtect information across its lifecycle - asset inventory and classification, privacy and data-subject rights, handling, retention and disposal, and secure transfer.\n\n## Role in the Operating Model\nThis is a process area - an organizational container that groups the operating processes below. It carries no framework sections and hosts no attached runs of its own; each process owns the framework references, controls, risks, policies, and operating workflow runs that operationalize this area. Use it to browse and report on the area as a whole and to navigate to the process that performs the work.\n\n## Operating Processes\n- Asset, Media & Classification\n- Privacy, Data Lifecycle & Secure Transfer","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"michael.bluth@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one operating process carried from the operating-process register.","last_tested_fy":"FY2026"}},{"title":"Governance, Risk & Compliance","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"# Governance, Risk & Compliance\n\n## Purpose\nDirect the ISMS - governance and oversight, policy lifecycle, enterprise risk and Statement of Applicability, internal audit and management review, external compliance obligations, and AI governance.\n\n## Role in the Operating Model\nThis is a process area - an organizational container that groups the operating processes below. It carries no framework sections and hosts no attached runs of its own; each process owns the framework references, controls, risks, policies, and operating workflow runs that operationalize this area. Use it to browse and report on the area as a whole and to navigate to the process that performs the work.\n\n## Operating Processes\n- ISMS Governance, Scope & Objectives\n- Policy Lifecycle, Publication, Acknowledgment & Exceptions\n- Enterprise Risk Assessment, Treatment & SoA\n- Internal Audit, Management Review, Nonconformity & Improvement\n- Compliance Obligations, Evidence & External Assurance\n- AI Governance & Human Approval","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"maeby.fuenke@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one operating process carried from the operating-process register.","last_tested_fy":"FY2026"}},{"title":"People & Workforce Security","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"# People & Workforce Security\n\n## Purpose\nSecure the workforce lifecycle - screening, agreements, acceptable use, remote and physical safeguards, and security awareness and role-based training.\n\n## Role in the Operating Model\nThis is a process area - an organizational container that groups the operating processes below. It carries no framework sections and hosts no attached runs of its own; each process owns the framework references, controls, risks, policies, and operating workflow runs that operationalize this area. Use it to browse and report on the area as a whole and to navigate to the process that performs the work.\n\n## Operating Processes\n- Workforce Security, Acceptable Use & Remote Work\n- Security Awareness & Role Training","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"george.michael@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one operating process carried from the operating-process register.","last_tested_fy":"FY2026"}},{"title":"Secure Development, Change & Infrastructure","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"# Secure Development, Change & Infrastructure\n\n## Purpose\nBuild and change the platform securely - SDLC and application security, change/release and database migration, vulnerability and patch management, cloud/network configuration, and tenant and on-prem delivery.\n\n## Role in the Operating Model\nThis is a process area - an organizational container that groups the operating processes below. It carries no framework sections and hosts no attached runs of its own; each process owns the framework references, controls, risks, policies, and operating workflow runs that operationalize this area. Use it to browse and report on the area as a whole and to navigate to the process that performs the work.\n\n## Operating Processes\n- Network, Cloud Configuration & Physical Reliance\n- Secure SDLC & Application Security\n- Change, Release & Database Migration\n- Vulnerability, Patch & Technical Testing\n- Tenant Provisioning, Isolation & Teardown\n- On-Prem Appliance & Release Lifecycle","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"george.michael@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one operating process carried from the operating-process register.","last_tested_fy":"FY2026"}},{"title":"Security Operations & Resilience","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"# Security Operations & Resilience\n\n## Purpose\nDetect, respond and recover - logging, monitoring and detection, security-incident and privacy-breach response, and backup, recovery and business continuity.\n\n## Role in the Operating Model\nThis is a process area - an organizational container that groups the operating processes below. It carries no framework sections and hosts no attached runs of its own; each process owns the framework references, controls, risks, policies, and operating workflow runs that operationalize this area. Use it to browse and report on the area as a whole and to navigate to the process that performs the work.\n\n## Operating Processes\n- Logging, Monitoring, Detection & Threat Intelligence\n- Security Incident, Privacy Breach & Postmortem\n- Backup, Recovery, BC/DR & Capacity","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"george.michael@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one operating process carried from the operating-process register.","last_tested_fy":"FY2026"}},{"title":"Service Delivery & Third-Party","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"# Service Delivery & Third-Party\n\n## Purpose\nOperate the service and its supply chain - vendor and subservice-organization management, production processing integrity, and continuous control operation and evidence monitoring.\n\n## Role in the Operating Model\nThis is a process area - an organizational container that groups the operating processes below. It carries no framework sections and hosts no attached runs of its own; each process owns the framework references, controls, risks, policies, and operating workflow runs that operationalize this area. Use it to browse and report on the area as a whole and to navigate to the process that performs the work.\n\n## Operating Processes\n- Vendor, Subservice & CUEC Management\n- Production Operations & SOC 1 Processing Integrity\n- Continuous Control Operation & Evidence Monitoring","full_description":"This area container is governed but is not itself an operating process.","process_type":"operational","process_owner":"maeby.fuenke@bluth.example","frequency":"Area container","fsli_significance":"medium","process_complexity":"medium","manual_intervention":"low","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1.5,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"The area governs at least one operating process carried from the operating-process register.","last_tested_fy":"FY2026"}},{"title":"AI Governance & Human Approval","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"# AI Governance & Human Approval\n\n## Purpose\nRegister AI use, assess risk and privacy, enforce suggestion-only operation and human approval, monitor drift, and investigate exceptions.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** CEO / Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"security_process","process_owner":"michael.bluth@bluth.example","frequency":"Continuous and quarterly","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Asset, Media & Classification","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"# Asset, Media & Classification\n\n## Purpose\nInventory, classify, assign ownership, handle, transfer, sanitize, and dispose of information, devices, software, and media.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering / Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"security_process","process_owner":"maeby.fuenke@bluth.example","frequency":"Continuous and quarterly","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Backup, Recovery, BC/DR & Capacity","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"# Backup, Recovery, BC/DR & Capacity\n\n## Purpose\nOperate backups, restoration testing, redundancy, capacity monitoring, business continuity, disaster recovery, and improvement exercises.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"it_general_control","process_owner":"ann.veal@bluth.example","frequency":"Continuous quarterly and annual","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Change, Release & Database Migration","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"# Change, Release & Database Migration\n\n## Purpose\nAuthorize, test, segregate, deploy, verify, roll back, and retrospectively review normal and emergency changes and database migrations.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"it_general_control","process_owner":"michael.bluth@bluth.example","frequency":"Per change","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Compliance Obligations, Evidence & External Assurance","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"# Compliance Obligations, Evidence & External Assurance\n\n## Purpose\nMaintain the obligations register, assemble evidence, coordinate external examinations, and remediate assurance findings.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"business_process","process_owner":"george.michael@bluth.example","frequency":"Quarterly and per audit","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Continuous Control Operation & Evidence Monitoring","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"# Continuous Control Operation & Evidence Monitoring\n\n## Purpose\nMonitor control execution, collect evidence, evaluate exceptions and metrics, assign remediation, and report effectiveness to management.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"business_process","process_owner":"maeby.fuenke@bluth.example","frequency":"Continuous and monthly","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Cryptography, Key & Secrets Management","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"# Cryptography, Key & Secrets Management\n\n## Purpose\nSelect cryptographic standards and control the creation, storage, access, rotation, revocation, recovery, and destruction of keys and secrets.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"it_general_control","process_owner":"ann.veal@bluth.example","frequency":"Continuous and annual","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Enterprise Risk Assessment, Treatment & SoA","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"# Enterprise Risk Assessment, Treatment & SoA\n\n## Purpose\nIdentify, analyze, evaluate, treat, accept, and monitor enterprise and information-security risk, including the Statement of Applicability.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"business_process","process_owner":"george.michael@bluth.example","frequency":"Quarterly and annual","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"ISMS Governance, Scope & Objectives","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"# ISMS Governance, Scope & Objectives\n\n## Purpose\nMaintain the ISMS context, scope, leadership accountability, objectives, resources, and executive oversight cadence.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** CEO / Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.\n\n## Incorporated Operating Detail\n\n# Quarterly Independent Oversight Process\n\n## 1. Purpose\nThis process operationalizes independent, executive-level oversight of Bluth Company's governance and risk-acceptance decisions through the Independent Governance Advisor, providing an outside check on CEO authority that a founder-led company without a formal board would otherwise lack. It supports the executive-oversight and board-independence expectations documented in the Board & Governance Policy.\n\n## 2. Scope\nThis process covers the Independent Governance Advisor's (the fractional CISO) recurring engagement with the CEO: review of the enterprise risk register, risk-acceptance decisions, policy exceptions, management-override scenarios, and the annual CEO performance and segregation-of-duties (SoD) review. It does not cover the Tidewell Advisory Group vCISO's own operational security-oversight activities - internal audit sampling and management review facilitation - which are separate engagements under the Internal Audit Program and Management Review Procedure, though the vCISO's outputs are a direct input to this process.\n\n## 3. Procedure Steps\n3.1 Each quarter, the Advisor meets with the CEO for two to four hours to conduct the independent oversight review. [CEO administers/schedules; Advisor conducts]\n3.2 The Advisor reviews the Tidewell Advisory Group vCISO's prior-quarter attestation, produced under the Internal Audit Program and Management Review Procedure, as a key input, and counter-signs the current risk register maintained under the Risk Management Policy. [Advisor]\n3.3 The Advisor reviews material risk-acceptance decisions taken since the prior quarter, any policy exceptions granted, and any management-override-of-controls scenarios, assessing whether each was appropriately justified, approved, and documented. [Advisor]\n3.4 The Advisor issues a signed quarterly attestation memo recording the review performed, any concerns raised, and follow-up items; the memo is retained as an ISMS record. [Advisor]\n3.5 Annually, the Advisor performs the CEO's performance review and signs the segregation-of-duties compensating-controls memo, attesting that the compensating controls in place for the CEO's concentration of duties remain adequate. [Advisor; CEO participates]\n3.6 Any concern raised in a quarterly attestation memo that indicates a control deficiency is logged as a nonconformity and routed through the Nonconformity & Corrective Action Procedure. [CEO / Security Lead]\n\n## 4. Records & Evidence\nSigned quarterly attestation memos; the counter-signed, dated risk register; the annual CEO performance review record; the annual signed segregation-of-duties compensating-controls memo - all retained as ISMS records and available for auditor review.\n\n## 5. Review & Ownership\nProcess owner (engagement administration): CEO. Content owner: Independent Governance Advisor. Review cadence: quarterly engagement per §3; the process itself is reassessed annually alongside the Board & Governance Policy.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"business_process","process_owner":"ann.veal@bluth.example","frequency":"Quarterly and on significant change","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Identity, Authentication & Access Lifecycle","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"# Identity, Authentication & Access Lifecycle\n\n## Purpose\nAuthorize, provision, authenticate, review, modify, and revoke workforce and service-account access, including privileged access.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering / Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"it_general_control","process_owner":"michael.bluth@bluth.example","frequency":"Continuous and quarterly","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Internal Audit, Management Review, Nonconformity & Improvement","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"# Internal Audit, Management Review, Nonconformity & Improvement\n\n## Purpose\nIndependently evaluate the ISMS, conduct management review, correct root causes, and verify continual improvement.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Tidewell Advisory Group vCISO / CEO. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"business_process","process_owner":"george.michael@bluth.example","frequency":"Quarterly and annual","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Logging, Monitoring, Detection & Threat Intelligence","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"# Logging, Monitoring, Detection & Threat Intelligence\n\n## Purpose\nDefine event coverage, protect and review logs, monitor security and availability, investigate alerts, and feed threat intelligence into risk decisions.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering / Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"security_process","process_owner":"maeby.fuenke@bluth.example","frequency":"Continuous","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Network, Cloud Configuration & Physical Reliance","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"# Network, Cloud Configuration & Physical Reliance\n\n## Purpose\nMaintain secure cloud and network architecture, hardened baselines, segmentation, provider monitoring, and inherited physical safeguards.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"it_general_control","process_owner":"ann.veal@bluth.example","frequency":"Continuous and quarterly","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"On-Prem Appliance & Release Lifecycle","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"# On-Prem Appliance & Release Lifecycle\n\n## Purpose\nBuild, sign, publish, deploy, support, update, revoke, and retire on-prem releases and appliances with customer-boundary evidence.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"operational","process_owner":"michael.bluth@bluth.example","frequency":"Per release and deployment","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Policy Lifecycle, Publication, Acknowledgment & Exceptions","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"# Policy Lifecycle, Publication, Acknowledgment & Exceptions\n\n## Purpose\nDraft, approve, publish, acknowledge, review, version, and retire every policy while governing time-bound exceptions.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"business_process","process_owner":"maeby.fuenke@bluth.example","frequency":"Annual and on change","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Privacy, Data Lifecycle & Secure Transfer","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"# Privacy, Data Lifecycle & Secure Transfer\n\n## Purpose\nGovern privacy notices, lawful processing, consent, data-subject requests, minimization, masking, retention, disposal, and secure transfer.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"security_process","process_owner":"ann.veal@bluth.example","frequency":"Continuous and on request","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Production Operations & SOC 1 Processing Integrity","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"# Production Operations & SOC 1 Processing Integrity\n\n## Purpose\nMonitor scheduled and transactional processing, validate inputs and outputs, resolve exceptions, preserve traceability, and attest completeness and accuracy.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"it_general_control","process_owner":"michael.bluth@bluth.example","frequency":"Continuous daily and monthly","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Secure SDLC & Application Security","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"# Secure SDLC & Application Security\n\n## Purpose\nEmbed security requirements, architecture, coding, review, testing, dependency, data-masking, and approval gates throughout development.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"it_general_control","process_owner":"maeby.fuenke@bluth.example","frequency":"Per change and continuous","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Security Awareness & Role Training","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"# Security Awareness & Role Training\n\n## Purpose\nDeliver, track, assess, and improve onboarding, annual, and role-based security and privacy training.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"security_process","process_owner":"ann.veal@bluth.example","frequency":"On hire and annual","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Security Incident, Privacy Breach & Postmortem","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"# Security Incident, Privacy Breach & Postmortem\n\n## Purpose\nDetect, triage, contain, eradicate, recover, notify, preserve evidence, analyze root cause, and verify corrective action.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"security_process","process_owner":"michael.bluth@bluth.example","frequency":"On event and annual exercise","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Tenant Provisioning, Isolation & Teardown","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"# Tenant Provisioning, Isolation & Teardown\n\n## Purpose\nProvision, isolate, validate, modify, export, retain, and securely remove tenant resources through approved lifecycle gates.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"operational","process_owner":"ann.veal@bluth.example","frequency":"Per tenant event","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}},{"title":"Vendor, Subservice & CUEC Management","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"# Vendor, Subservice & CUEC Management\n\n## Purpose\nRisk-tier, diligence, contract, onboard, monitor, reassess, and offboard vendors and subservice organizations while operating CUECs.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Security Lead / CEO. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.\n\n## Incorporated Operating Detail\n\n# Subservice Organization Critical-Vendor Lifecycle Process\n\n## 1. Purpose\nThis process operationalizes the enhanced protections the Vendor Management Policy requires for subservice organizations classified as critical - those whose failure would materially disrupt Bluth Company's governance, technical platform, or ability to obtain attestation - carrying each through onboarding, ongoing oversight, and offboarding.\n\n## 2. Scope\nThis process covers the currently designated critical subservice organizations: Tidewell Advisory Group (governance, finance, and HR support), Model Home Data Lake, Lucille Identity Cloud, and Model Home Data Lake (technical platform), and the SOC 2 examining CPA firm (attestation). Vendors that are not classified critical are managed under the general provisions of the Vendor Management Policy, not this lifecycle.\n\n## 3. Procedure Steps\n3.1 Onboarding - A vendor risk assessment is completed; the master services agreement is negotiated with right-to-audit, 90-day termination, and transition clauses; a data processing agreement is executed where personal data is involved; the vendor's SOC 2 report (or equivalent) is reviewed; the vendor is added to the public subprocessor list within 30 days if it processes customer or personal data. [Security Lead facilitates; CEO approves and signs]\n3.2 Ongoing - The vendor's SOC 2 report (or equivalent assurance report) is refreshed and reviewed annually, and its complementary user entity controls (CUECs) are re-verified; for Tidewell Advisory Group specifically, records under its custody are exported to Bluth Company-controlled storage quarterly; a pre-qualified secondary or backup provider is identified and kept on a 30-day-engageable shortlist, refreshed annually. [Security Lead]\n3.3 Continuous Monitoring - Each critical subservice organization's vendor-register entry is reviewed quarterly per the Vendor Management Policy, and any security incident or breach notification received from the vendor is routed through the Incident Response Policy. [Security Lead]\n3.4 Offboarding - When a critical subservice relationship ends, an orderly handoff is executed per the agreed transition plan; the vendor provides data return and/or destruction with written certification retained as evidence; the pre-qualified backup provider - or a newly assessed replacement, onboarded per §3.1 - is engaged before or immediately upon cutover to avoid a coverage gap. [Security Lead; CEO approves]\n\n## 4. Records & Evidence\nSigned master services agreements and data processing agreements with the required clauses; annual SOC-report review records and CUEC verification notes; quarterly records-export confirmations for Tidewell Advisory Group; the refreshed backup-provider shortlist; offboarding transition plans and data-return/destruction certifications.\n\n## 5. Review & Ownership\nOwner: Security Lead. Review cadence: annually for the process itself; underlying vendor relationships follow the quarterly monitoring and annual SOC-refresh cadence in §3.2–§3.3.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"business_process","process_owner":"michael.bluth@bluth.example","frequency":"Onboarding quarterly annual and exit","fsli_significance":"medium","process_complexity":"high","manual_intervention":"medium","issue_history":"medium","third_party_reliance":"high","process_change":"high","monitoring_gap":"medium","bp_weighted_score":2,"bp_overall_assessment":"medium","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Vulnerability, Patch & Technical Testing","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"# Vulnerability, Patch & Technical Testing\n\n## Purpose\nCollect intelligence, scan and assess exposure, prioritize remediation, deploy patches, test security, and track exceptions to closure.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** Head of Engineering / Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"security_process","process_owner":"george.michael@bluth.example","frequency":"Continuous weekly and annual","fsli_significance":"high","process_complexity":"low","manual_intervention":"low","issue_history":"high","third_party_reliance":"low","process_change":"medium","monitoring_gap":"high","bp_weighted_score":3,"bp_overall_assessment":"high","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2026"}},{"title":"Workforce Security, Acceptable Use & Remote Work","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"# Workforce Security, Acceptable Use & Remote Work\n\n## Purpose\nApply screening, agreements, acceptable-use, remote-work, physical, disciplinary, and termination safeguards across the workforce lifecycle.\n\n## Scope and Trigger\nThis process applies to Bluth Company personnel, contractors, systems, data, vendors, and customer-facing services identified by its linked policies, controls, and risks. It runs on the cadence shown on the Process record and whenever a material change, exception, incident, audit finding, or risk decision triggers an out-of-cycle run.\n\n## Accountability\n**Process owner:** CEO / Security Lead. The owner opens each run, assigns accountable people, confirms segregation of duties, resolves overdue work, and approves closure. People performing work attach evidence to the step that produced it; reviewers must be able to reperform the conclusion from the retained record.\n\n## Operating Method\n1. Confirm scope, trigger, responsible people, due dates, and the current versions of all linked policies.\n2. Review linked risks and changes since the prior run; document applicability, assumptions, exceptions, and required approvals.\n3. Execute the linked workflow steps and controls; retain system-generated evidence wherever practical.\n4. Record deviations as issues, contain material exposure, assign corrective action, and escalate risk acceptance to the authorized approver.\n5. Independently review completeness, approve or reject the result, and prevent closure while required evidence or remediation is missing.\n6. Report metrics and overdue actions, update policies/controls/risks when lessons require it, and retain the signed run record for audit.\n\n## Evidence and Metrics\nMinimum evidence is the workflow history, linked source records, approvals, exceptions, corrective actions, and the final owner sign-off. Metrics include on-time completion, exception count and age, failed or missed controls, evidence completeness, remediation SLA performance, and repeat findings.\n\n## Enforcement and Improvement\nMissed mandatory steps, unapproved exceptions, overdue high-risk actions, or policy violations are escalated to the Security Lead and CEO. Material control failures enter incident response or nonconformity/corrective action as appropriate. The owner reviews recurring failures and updates this process, its policies, risks, controls, or workflow before the next run.","full_description":"Operating process carried from the operating-process register; governed through canonical parentage and outgoing control implementation relationships.","process_type":"business_process","process_owner":"maeby.fuenke@bluth.example","frequency":"On hire on change and annual","fsli_significance":"low","process_complexity":"medium","manual_intervention":"high","issue_history":"low","third_party_reliance":"medium","process_change":"low","monitoring_gap":"low","bp_weighted_score":1,"bp_overall_assessment":"low","in_scope":true,"scope_rationale":"Scoped based on financial significance, complexity, change, and assurance needs.","last_tested_fy":"FY2025"}}],"policy":[{"title":"Information Security Policy","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Information Security Policy defines fictional governance expectations and accountability.","full_description":"A fictional Bluth Company policy, with its type, lifecycle stage, framework, domain and review date recorded.","policy_type":"policy","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"v1.0","framework":["iso-27001","soc2"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2025-08-11","next_review_date":"2026-08-10"}},{"title":"Access Control Standard","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Access Control Standard defines fictional governance expectations and accountability.","full_description":"A fictional Bluth Company policy, with its type, lifecycle stage, framework, domain and review date recorded.","policy_type":"standard","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"v2.0","framework":["sox","coso-ic"],"domains":["access_control_identity"],"review_frequency":"semi_annual","effective_date":"2025-08-12","next_review_date":"2026-08-11"}},{"title":"Financial Close Procedure","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Financial Close Procedure defines fictional governance expectations and accountability.","full_description":"A fictional Bluth Company policy, with its type, lifecycle stage, framework, domain and review date recorded.","policy_type":"procedure","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"v3.0","framework":["nist-csf-2"],"domains":["financial_reporting_controls"],"review_frequency":"quarterly","effective_date":"2025-08-13","next_review_date":"2026-09-10"}},{"title":"Vendor Risk Management Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Vendor Risk Management Policy defines fictional governance expectations and accountability.","full_description":"A fictional Bluth Company policy, with its type, lifecycle stage, framework, domain and review date recorded.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"v4.0","framework":["iso-27001","soc2"],"domains":["third_party_supply_chain_risk"],"review_frequency":"annual","effective_date":"2025-08-14","next_review_date":"2026-09-11"}},{"title":"Incident Response Plan","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Incident Response Plan defines fictional governance expectations and accountability.","full_description":"A fictional Bluth Company policy, with its type, lifecycle stage, framework, domain and review date recorded.","policy_type":"procedure","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"v5.0","framework":["sox","coso-ic"],"domains":["incident_management_response"],"review_frequency":"annual","effective_date":"2025-08-15","next_review_date":"2026-11-09"}},{"title":"Business Continuity Standard","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Business Continuity Standard defines fictional governance expectations and accountability.","full_description":"A fictional Bluth Company policy, with its type, lifecycle stage, framework, domain and review date recorded.","policy_type":"standard","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"v6.0","framework":["nist-csf-2"],"domains":["business_continuity_disaster_recovery"],"review_frequency":"annual","effective_date":"2025-08-16","next_review_date":"2026-11-10"}},{"title":"Audit Committee Charter","status":"ACTIVE","visibility":"private","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Audit Committee Charter defines fictional governance expectations and accountability.","full_description":"A fictional Bluth Company policy, with its type, lifecycle stage, framework, domain and review date recorded.","policy_type":"charter","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"v7.0","framework":["iso-27001","soc2"],"domains":["compliance_audit_assurance"],"review_frequency":"biennial","effective_date":"2025-08-17","next_review_date":null}},{"title":"Responsible AI Guideline","status":"DRAFT","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Responsible AI Guideline defines fictional governance expectations and accountability.","full_description":"A fictional Bluth Company policy, with its type, lifecycle stage, framework, domain and review date recorded.","policy_type":"guideline","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"v8.0","framework":["sox","coso-ic"],"domains":["ai_governance"],"review_frequency":"ad_hoc","effective_date":"2025-08-18","next_review_date":"2027-02-07"}},{"title":"AI Governance & Acceptable AI Use Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Governs Bluth Company's use of generative-AI tools and the acceptable-use boundaries, human-approval requirements, and data protections for the AI agents the platform exposes to customers through its Model Context Protocol (MCP) interface.","full_description":"# AI Governance & Acceptable AI Use Policy\n\n## 1. Purpose\nThis policy governs Bluth Company's use of artificial intelligence in three dimensions: the organization's own use of generative-AI tools, the behavior of the AI agents the Bluth Company platform exposes to customers through its Model Context Protocol (MCP) interface, and the AI agents that operate Bluth Company's own platform infrastructure through the tenant-operations control plane. It exists because Bluth Company is an AI-native product - agents act on live customer data and on the production fleet itself - which demands explicit boundaries, human accountability, and an auditable approval trail. This is Bluth Company's named policy for acceptable use of generative AI.\n\n## 2. Scope\nThis policy applies to: (a) Bluth Company and Tidewell Advisory Group personnel who use generative-AI tools (coding or chat assistants) in company work; (b) the architecture and behavior of AI agents that connect to the platform via MCP and act on customer data on a user's behalf; and (c) AI agents that execute platform operations - tenant provisioning, redeployment, settings changes, release orchestration, and reporting - through the tenant-operations control plane. It governs the platform's AI-agent write path, human-approval mechanism, data boundaries, model-training exclusions, and the identity and authorization model for operations agents. Personnel-facing rules for which tools are approved and what may be submitted to them are in the Acceptable Use Policy; this policy is authoritative for the platform's AI-agent architecture and organization-wide AI governance.\n\n## 3. Roles & Responsibilities\nThe Head of Engineering owns the AI-agent architecture, the MCP tool surface, and the technical enforcement of the suggestion-only write path. The Security Lead owns the list of approved AI providers and tools and the AI-provider data-protection terms (Model Home Data Lake's Vertex AI data-governance commitments for Gemini inference), and leads incident response for any AI-related event. All personnel who use generative-AI tools are accountable for reviewing AI output before relying on it, per the Acceptable Use Policy. The CEO approves this policy and any material change to the AI-agent architecture's data boundaries.\n\n## 4. Policy Statements\n4.1 Bluth Company maintains this named AI-governance policy - covering both organizational generative-AI use and the platform's own AI-agent behavior - as a standing element of its policy set.\n4.2 AI agents connected to a Bluth Company tenant via the MCP interface are architecturally restricted to writing only to the AISuggestion table; they cannot directly create, modify, or delete production data. Personnel shall not attempt to circumvent this restriction or configure an AI agent with direct write access to production systems.\n4.3 Every change an AI agent proposes through the MCP interface is stored as a pending suggestion and is reviewed by an authorized human for completeness, accuracy, and appropriateness before it is applied to production data; no AI-proposed change reaches production without this review-and-approval step, and the approval interface displays the proposed change in full for review.\n4.4 The identity of the human who approves or rejects each AI suggestion is logged together with the suggestion's content and disposition. Where an AI-generated output materially influences a customer-facing decision or a production change, that provenance is attributed in the audit log and the output is reviewed by a human before being applied, so that customer-facing results attributable to AI assistance remain accurate and accountable.\n4.5 Personal information and customer data processed through the platform's AI features are used only for the purposes documented in the Privacy Policy and the governing customer agreement; the platform does not use customer data to train AI models. Platform AI inference runs on Lucille Identity Cloud Vertex AI (Gemini) under Model Home Data Lake's data-governance commitments - prompt retention is disabled, so data submitted for inference is not retained by the provider or used to train its models.\n4.6 The MCP tool surface available to AI agents - including get_schema, query_data, suggest_change, get_current_context, get_step_context, upload_document, and download_document - is documented in the MCP server source and is discoverable by an agent at runtime through the get_schema tool, so that agent capabilities are self-describing rather than dependent on out-of-band documentation.\n4.7 Confidential or Restricted data, per the Data Classification & Handling Policy, is processed by a generative-AI tool only where that tool operates under a zero-data-retention agreement or equivalent confidentiality terms; the current list of approved tools and the employee-facing rules for what may be submitted to them are maintained in the Acceptable Use Policy, which this policy cross-references rather than duplicates.\n4.8 The Head of Engineering and Security Lead jointly review the AI-agent architecture, the MCP tool surface, the operations-agent authorization matrix, and the list of approved generative-AI tools and providers at least annually and upon material change - a new AI provider, a new MCP tool, or a change to the AI provider's data-protection terms - and update this policy and the Acceptable Use Policy accordingly.\n4.9 AI agents that operate the platform's own infrastructure act under dedicated, least-privilege service-account identities - never under a person's credentials or ambient owner authority. The control plane derives each caller's identity class (human or agent) from its verified identity rather than from self-report, and enforces an authorization matrix that limits agent identities to a defined operation set: tenant provisioning, redeployment, settings changes, release orchestration, and read-only reporting. Destructive lifecycle actions - tenant decommissioning and purge, administrator-roster changes, and break-glass - are refused to agent identities and reserved to named human super-administrators.\n4.10 Every agent-executed platform operation carries the same workflow reference, recorded approval, and redacted evidence bundle as a human-executed one; the executing interface is recorded in the operation's evidence and audit trail, and agent-executed operations are reviewed through the monthly tenant-operations reconciliation report alongside human activity.\n\n## 5. Exceptions\nA request to grant an AI agent capability beyond the suggestion-only write path, or to use a generative-AI tool without a ZDR or equivalent agreement for Confidential or Restricted data, is documented with its business justification and risk assessment, approved jointly by the Head of Engineering and the Security Lead, time-bound, and reviewed at renewal or at least annually.\n\n## 6. Enforcement\nAn attempt to circumvent the suggestion-only write path, to bypass human approval of an AI-proposed production change, to run a platform-operations agent under a human credential or outside its authorization matrix, or to submit Confidential or Restricted data to a non-approved AI tool is treated as a security incident under the Incident Response Policy and may result in disciplinary action under the Human Resources Security Policy. Compliance is monitored through review of AISuggestion approval logs, periodic testing that the MCP write path cannot bypass the AISuggestion table, and the annual internal audit program.\n\n## 7. Review & Ownership\nOwner: Head of Engineering and Security Lead (joint). Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Acceptable Use Policy (personnel-facing generative-AI use rules; this policy owns platform-agent architecture and organizational AI governance); Data Classification & Handling Policy; Privacy Policy; Access Control Policy; Software Development Lifecycle Policy; Logging & Monitoring Policy; Incident Response Policy.\nGoverns controls: AI agents restricted to suggestion-only pattern - no direct production writes; AI suggestions require human approval before production changes; Customer data is not used for AI model training; Vertex AI data governance in force; MCP tool surface documented and self-describing via get_schema.\nOperated by: the standing AI-agent oversight and suggestion-approval monitoring workflow in the Bluth Company workflow library, together with the AISuggestion approval gate embedded in the core application's agent-review interface.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-03-09","next_review_date":"2026-12-09"}},{"title":"Acceptable Use Policy","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"This policy defines acceptable and prohibited uses of Bluth Company information systems, devices, network resources, and generative AI tools to protect the organization from legal liability and security risks arising from misuse.","full_description":"# Acceptable Use Policy\n\n## 1. Purpose\nThis policy defines acceptable and prohibited use of Bluth Company information systems, devices, and generative AI tools by personnel, protecting the organization from the legal, security, and reputational risks of misuse.\n\n## 2. Scope\nThis policy applies to personnel use of Bluth Company-owned systems, networks, applications, email, internet access, and generative AI tools (including but not limited to Anthropic Claude, Lucille Identity Cloud Gemini, GitHub Copilot, Cursor, and public consumer AI tools), plus personal devices used to access company data (BYOD). Bluth Company is fully remote; this policy governs use from home offices and any other work location, not a corporate network. It governs personnel behavior; how the Bluth Company platform's own AI agents are architecturally restricted is governed separately (see Related Documents & Controls).\n\n## 3. Roles & Responsibilities\nThe Security Lead maintains this policy, defines the approved-AI-tool list, and investigates reported violations. The CEO approves exceptions and disciplinary escalations. Managers confirm their reports have acknowledged the policy and understand it. All personnel are responsible for using systems and AI tools responsibly and for reporting misuse they observe.\n\n## 4. Policy Statements\n4.1 Bluth Company systems shall be used primarily for business purposes; incidental personal use is permitted only where it does not interfere with duties, consume material resources, or violate another security policy.\n4.2 Personnel shall not install unauthorized software, disable or attempt to bypass a security control, or share credentials. Circumventing a security measure is prohibited regardless of intent, and installing software outside approved channels is treated as a potential malware-introduction risk.\n4.3 Bluth Company systems and communications shall not be used to access, store, or transmit illegal content or malware, or for harassment, discrimination, or unauthorized solicitation.\n4.4 Devices used to access company data - company-issued or personal (BYOD) - shall be protected by full-disk encryption, a screen lock, and current operating-system patches. Company data shall not be copied to personal cloud storage without authorization; use of removable media is governed separately by the Remote Working & Clear Desk Policy and the Asset & Media Management Policy.\n4.5 This policy, the Employee Handbook, and the Code of Conduct are published to all personnel via Lucille Identity Cloud, communicated during onboarding, and acknowledged by every individual on hire and again annually as policies are refreshed; annual re-acknowledgment is tracked to completion.\n4.6 Generative AI tools may be used for legitimate business purposes - code authoring, drafting, summarization, research. Personnel remain accountable for AI-generated output they accept: it is reviewed for accuracy and appropriateness before use, never accepted uncritically.\n4.7 Data classified as Confidential or Restricted shall not be submitted to a generative AI tool unless that tool operates under an executed zero-data-retention (ZDR) agreement, or equivalent no-training commitment, on file. Bluth Company's approved AI tools operate under commercial no-training / zero-retention terms (Anthropic commercial terms for Claude; Model Home Data Lake data-governance commitments for Gemini on Vertex AI); submission of Confidential or Restricted data to those tools under these terms is permitted.\n4.8 Source code may be submitted only to approved AI coding assistants operating under ZDR or equivalent confidentiality terms - currently Anthropic Claude (via Claude Code), GitHub Copilot, and Cursor. Source code shall not be submitted to general-purpose public AI tools (for example, consumer web chat interfaces) without prior Security Lead approval.\n4.9 Personnel shall never submit, upload, or otherwise cause a Bluth Company system or AI tool to process a data category the company is not contracted to handle - including electronic protected health information, payment-card data, GLBA nonpublic personal information, government identification numbers, or biometric data. The complete prohibited-data list and its contractual basis are maintained in the Data Classification & Handling Policy.\n\n## 5. Exceptions\nA request to use an AI tool, personal device, or software outside this policy is submitted to the Security Lead with business justification and a risk assessment. An approved exception specifies compensating controls (for example, data-type restrictions) and a review date, and is reassessed at that interval or at least annually.\n\n## 6. Enforcement\nCompliance is monitored through endpoint configuration checks and periodic review of AI-tool usage patterns. Violations are handled under the Human Resources Security Policy's disciplinary process and may result in access revocation, a formal warning, or termination; a violation involving customer or personal data is additionally handled as a security incident under the Incident Response Policy.\n\n## 7. Review & Ownership\nOwner: CEO / Security Lead. Review cadence: at least annually and on significant change - including any change to the approved-AI-tool list - via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: AI Governance & Acceptable AI Use Policy (this document covers personnel/user behavior toward AI tools; the AI Governance Policy covers the platform's own AI-agent architecture, approval gates, and organizational AI governance - the two are complementary, not overlapping); Data Classification & Handling Policy (prohibited-data list); Remote Working & Clear Desk Policy and Asset & Media Management Policy (removable media and BYOD device detail); Human Resources Security Policy (disciplinary process); Incident Response Policy.\nGoverns controls: A.5.10 - Acceptable use of information and other associated assets; User endpoint devices protected and managed (includes remote working security).\nOperated by: the onboarding acknowledgment and annual policy re-acknowledgment cycle described in Statement 4.5.","policy_type":"policy","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["asset_management_inventory","network_communications_security"],"review_frequency":"annual","effective_date":"2026-01-12","next_review_date":"2026-12-10"}},{"title":"Access Control Policy","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"This policy defines the requirements for managing logical access to Bluth Company information systems, ensuring that only authorized individuals have access to resources appropriate for their role.","full_description":"# Access Control Policy\n\n## 1. Purpose\nThis policy defines the requirements for managing logical access to Bluth Company information systems, ensuring that only authorized individuals and services hold access appropriate to their role, and that access is granted, reviewed, and removed in a controlled, auditable manner.\n\n## 2. Scope\nThis policy applies to all logical access to Bluth Company production infrastructure on Model Home Data Lake (Model Home Data Lake), per-tenant Cloud SQL databases, source code and pipelines in Model Home Data Lake, Lucille Identity Cloud, and the IAP-gated administrative control-plane console. It covers human user accounts (employee and contractor), service accounts, and API/integration credentials, across every environment - development, staging, and per-tenant production. Authentication mechanisms themselves - passwords, MFA, session and lockout controls - are governed by the Password & Authentication Policy; this policy governs who is authorized to hold access and how that authorization is granted, reviewed, and removed.\n\n## 3. Roles & Responsibilities\nThe Security Lead owns this policy, defines access-control standards, and approves privileged-access and segregation-of-duties exceptions. DevOps/Operations administers Lucille Identity Cloud, Model Home Data Lake IAM, and Model Home Data Lake group membership. Hiring managers request and justify access for new team members through the onboarding process. Resource and system owners approve access requests to the systems they own. All personnel safeguard their credentials and immediately report suspected unauthorized access.\n\n## 4. Policy Statements\n4.1 Access to production Model Home Data Lake resources, per-tenant Cloud SQL databases, Model Home Data Lake repositories and pipelines, and Lucille Identity Cloud is provisioned using role-based access control. Permissions follow the principle of least privilege, granting only the access required for the individual's current role.\n4.2 Access requests require documented approval from the resource or system owner before provisioning. Lucille Identity Cloud is the authoritative system of record for the joiner-mover-leaver lifecycle; a role change triggers a corresponding access review rather than an accumulation of standing permissions.\n4.3 All access covered by this policy is subject to multi-factor authentication as required by the Password & Authentication Policy; this policy does not separately define MFA mechanisms.\n4.4 Privileged access - Model Home Data Lake project Owner/IAM-Admin roles, Cloud SQL superuser access, Model Home Data Lake Owner/Maintainer roles, and the IAP-gated administrative control-plane console - is restricted to a named, minimal set of individuals, requires documented justification, and is logged. Model Home Data Lake `roles/owner` is reserved for break-glass use and protected with hardware-key (FIDO2) multi-factor authentication. Use of privileged administrative utilities or scripts capable of bypassing standard application controls is restricted to authorized personnel and logged. Operators of the tenant-operations control plane hold no standing tenant-mutation rights: they may only submit requests to the operations dispatcher; mutations execute under fixed per-action service accounts (provision, release, settings, deprovision, report), only the deprovision executor identity holds destroy rights, and break-glass execution rights exist solely as time-bound conditional IAM grants that expire automatically, with every use reported as a named line item in the next reconciliation report.\n4.5 User access reviews are conducted quarterly across all critical systems (Model Home Data Lake IAM, Cloud SQL, Model Home Data Lake, Lucille Identity Cloud). Reviews verify that access levels remain appropriate to current job function and that no orphaned or unrecognized accounts exist; the reviewer documents the outcome. For the tenant-operations control plane, the monthly reconciliation report additionally compares the platform-administrator roster, dispatcher and executor IAM principals, and evidence-bucket access against the authority records; the roster is the authority and IAM drift is a finding.\n4.6 Access is revoked within 24 hours of termination, or of a role change that no longer requires the access. IT offboarding includes access revocation across all in-scope systems as a mandatory, tracked step.\n4.7 Duties that would allow a single individual to both perform and conceal an error or improper act - for example, deploying a change and approving it, or initiating and approving a financial transaction - are segregated between individuals. Where Bluth Company's small team size makes full segregation impractical for a given function, a documented compensating control (independent management review and logging of the activity) is recorded in the risk register.\n4.8 Each customer tenant operates on a dedicated, isolated Cloud SQL instance with separate credentials. Per-tenant database isolation prevents cross-tenant data access, and no shared database credentials span multiple customer tenants.\n4.9 Access granted to third-party vendors, integrations, and API consumers is scoped to the minimum required data and operations, inventoried, and reviewed and rotated on the same cadence as service-account credentials.\n4.10 Authorization to operate the tenant-operations control plane is resolved against the platform-administrator roster: every verified caller must map to an enabled roster entry, and a role- and identity-class-based authorization matrix - enforced in the dispatcher on every request - determines which operations each identity may initiate. Destructive tenant-lifecycle actions (decommission and purge), administrator-roster changes, and break-glass are reserved to human super-administrators; purge of a decommissioned tenant is additionally code-refused before the tenant's retention window elapses.\n4.11 AI agents and service automations act under dedicated, least-privilege service-account identities - never under a person's credentials or ambient owner authority. The identity class of every caller (human or agent) is derived from its verified identity rather than self-reported, recorded in the operation's evidence and audit trail, and enforced against the authorization matrix; agent identities cannot hold or acquire destructive lifecycle, roster, or break-glass rights.\n\n## 5. Exceptions\nA request for an exception to this policy - for example, temporary elevated access during an incident, or a documented segregation-of-duties gap - is submitted to the Security Lead in writing, risk-assessed, and approved only once a compensating control (additional logging, time-bound expiry, or independent review) is identified. Approved exceptions are recorded in the exception register with an owner and an expiry or next-review date, and are reassessed no later than the following quarterly access review.\n\n## 6. Enforcement\nAccess identified as granted or retained in violation of this policy is revoked on discovery. Repeated or willful violations are treated as a personnel matter under the Human Resources Security Policy and may result in disciplinary action up to termination of employment or contract. Suspected unauthorized access is handled as a security incident under the Incident Response Policy. Compliance is monitored through the quarterly access reviews, automated authentication-event monitoring, and annual penetration testing.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Password & Authentication Policy (authentication mechanisms); Human Resources Security Policy (joiner-mover-leaver personnel process); Vendor Management Policy (third-party access agreements); Incident Response Policy; Change Management Policy (tenant-operations run discipline); AI Governance & Acceptable AI Use Policy (agent identities).\nGoverns controls: A.5.3, A.5.15, A.5.16, A.5.18, A.8.2, A.8.3, A.8.18, CC6.1, CC6.2, CC6.3, SOC1-1; Model Home Data Lake IAM least-privilege & owner protection; Cloud SQL access control & least privilege; Model Home Data Lake repository & project access management; Lucille Identity Cloud joiner-mover-leaver provisioning; Lucille Identity Cloud periodic access & group review; Model Home Data Lake Secret Manager secrets management; Third-party data-sharing & API access control; Per-tenant database isolation prevents cross-tenant data access; Segregation of duties enforced for critical functions with documented compensating controls.\nOperated by: the corresponding access-provisioning and periodic access-review workflows in the Bluth Company workflow library.","policy_type":"policy","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["access_control_identity","governance_policy_oversight","asset_management_inventory"],"review_frequency":"annual","effective_date":"2026-02-09","next_review_date":"2026-12-11"}},{"title":"Asset & Media Management Policy","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"This policy establishes requirements for identifying, inventorying, and managing information assets throughout their lifecycle to ensure appropriate protection and accountability.","full_description":"# Asset & Media Management Policy\n\n## 1. Purpose\nThis policy establishes requirements for identifying, inventorying, and managing Bluth Company's information assets throughout their lifecycle, and for the secure handling, maintenance, and disposal of the physical equipment and storage media that carry Bluth Company data - so both are protected and accounted for from acquisition through disposal.\n\n## 2. Scope\nThis policy covers all information assets: hardware (personnel laptops - Bluth Company is remote-first, with no owned servers, on-premises hardware, or office equipment), cloud resources (Model Home Data Lake services, SaaS subscriptions), data stores, and any storage media (external drives, USB media) used to process or store Bluth Company data. It addresses identification, ownership, acceptable use, return, maintenance, sanitization, and secure disposal.\n\n## 3. Roles & Responsibilities\nThe Operations Lead maintains the hardware and media asset inventory, tracks asset ownership and return, and approves sanitization and disposal methods. DevOps maintains the Model Home Data Lake cloud-resource inventory and identifies unmanaged (shadow-IT) resources. The Security Lead sets sanitization and encryption standards for media. Managers verify asset return during offboarding. All personnel safeguard assigned assets, report loss or theft immediately, and follow this policy's media-handling rules.\n\n## 4. Policy Statements\n\n**Part A - Asset inventory & ownership**\n4.1 An inventory of information assets - hardware, cloud resources, and data stores - shall be maintained and reviewed at least quarterly, recording asset type, owner, classification level, and location.\n4.2 Every asset shall have a designated owner accountable for its protection; ownership is updated promptly on personnel change or reassignment.\n4.3 Acceptable use of assets is documented in the Acceptable Use Policy and acknowledged by every individual; assets are handled according to the classification of the data they carry.\n4.4 All company assets shall be returned upon termination or contract end. Return is a mandatory line item on the offboarding checklist; an unreturned asset is tracked and escalated by the Operations Lead.\n4.5 Cloud resource inventory is maintained using Model Home Data Lake's asset-inventory tooling. A resource found outside that inventory (shadow IT) is identified and either brought under management or decommissioned.\n\n**Part B - Media & equipment handling**\n4.6 Storage media is managed across its full lifecycle - procurement, deployment, storage, transport, and disposal. Media holding Confidential or Restricted data shall be encrypted and tracked in the asset inventory for as long as it exists.\n4.7 Before disposal or re-use, equipment and media shall be sanitized using an approved method - cryptographic erasure, secure overwrite, or physical destruction - appropriate to the media type, with the method and outcome documented. Media that cannot be verifiably sanitized is physically destroyed rather than repaired, resold, or discarded intact.\n4.8 Equipment maintenance is performed only by authorized personnel. Maintenance touching equipment that holds customer data is logged; where equipment must go to an external repair provider, its storage media is removed or securely erased first.\n4.9 Removable media (USB drives, external drives, SD cards) is not the default means of storing or transporting company data - that default prohibition is set in the Remote Working & Clear Desk Policy. Where an exceptional business need for removable media is approved, it shall be encrypted, labelled with its classification, and tracked in the asset inventory for its full life; unencrypted removable media holding sensitive data is prohibited outright, and customer data is never carried on removable media under any circumstance.\n\n## 5. Exceptions\nA request to deviate from this policy - for example, an alternate sanitization method for media a standard method cannot handle - requires Operations Lead review, a documented risk assessment, and Security Lead sign-off, with the exception time-bound and reviewed at least annually.\n\n## 6. Enforcement\nCompliance is verified through quarterly inventory reviews, offboarding-checklist completion rates, cloud-resource audits, and disposal-verification records. An unreturned asset, an unlogged disposal, or use of unauthorized removable media is handled under the Human Resources Security Policy's disciplinary process; loss of media containing Confidential or Restricted data is handled as a security incident under the Incident Response Policy.\n\n## 7. Review & Ownership\nOwner: Operations Lead. Review cadence: at least annually, with the asset inventory itself reviewed quarterly, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Acceptable Use Policy (asset acceptable-use acknowledgment); Remote Working & Clear Desk Policy (default removable-media prohibition); Data Classification & Handling Policy (classification levels referenced in Statements 4.1 and 4.6); Human Resources Security Policy (offboarding checklist).\nGoverns controls: A.5.9 - Inventory of information and other associated assets; A.5.11 - Return of assets; A.7.10 - Storage media; A.7.13 - Equipment maintenance; A.7.14 - Secure disposal or re-use of equipment; CC6.5 - The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's objectives; Removable media prohibited for company and customer data; approved exceptions encrypted and tracked.\nOperated by: the quarterly asset-inventory review and disposal-verification process described in Statements 4.1 and 4.7.","policy_type":"policy","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["asset_management_inventory","data_protection_privacy","physical_environmental_security"],"review_frequency":"annual","effective_date":"2026-04-13","next_review_date":"2026-12-12"}},{"title":"Backup & Recovery Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"This policy defines backup and recovery requirements to ensure that critical data can be restored in the event of data loss, corruption, or system failure, supporting service availability and data integrity commitments.","full_description":"# Backup & Recovery Policy\n\n## 1. Purpose\nThis policy defines backup and recovery requirements so that critical data can be restored in the event of data loss, corruption, or system failure, supporting Bluth Company's service-availability and data-integrity commitments to customers.\n\n## 2. Scope\nThis policy covers all production databases (per-tenant PostgreSQL instances on Cloud SQL), application configuration, infrastructure-as-code definitions, and other critical data stores. It addresses backup frequency, encryption, geographic replication, retention, restoration testing, and recovery procedures.\n\n## 3. Roles & Responsibilities\nDevOps configures and monitors backup systems and administers the restricted set of recall/restore permissions. The Head of Engineering validates backup integrity during quarterly restoration tests and owns the RTO/RPO targets this policy must meet. The Security Lead ensures backup procedures meet compliance requirements. On-call engineers execute recovery procedures when needed.\n\n## 4. Policy Statements\n4.1 Automated daily backups are configured for all production databases using Model Home Data Lake Cloud SQL automated backups, with point-in-time recovery (PITR) and binary logging enabled to support recovery to any point within the retention window.\n4.2 Backup data is encrypted at rest and replicated to a geographically separate Model Home Data Lake region from the primary database; replication traffic between regions is itself encrypted in transit, so a regional failure cannot also expose the backup copy.\n4.3 In addition to the daily Cloud SQL backup cycle, production data is backed up and replicated to the geo-separate (offsite) region at least weekly at the storage layer. Model Home Data Lake's multi-region infrastructure fulfills the offsite-replication role - Bluth Company relies on Model Home Data Lake, its critical cloud subservice organization under the Vendor Management Policy, rather than a separate backup vendor, to perform and host this replication.\n4.4 The ability to recall, restore, or export backed-up data is restricted to a named, small set of authorized DevOps and Head of Engineering personnel through scoped Model Home Data Lake IAM roles; recall and restore actions are logged.\n4.5 Backup restoration is tested at least quarterly to verify data integrity and confirm that recovery procedures are functional; test results - time to restore, integrity-verification outcome, and any issues encountered - are documented.\n4.6 Documented recovery procedures specify step-by-step restoration instructions usable by any qualified engineer, the RTO and RPO targets the procedure must meet, and the escalation path if a target cannot be met.\n4.7 Backup monitoring detects and alerts on backup failures within one hour; failed backups are investigated and resolved the same business day, and consecutive failures are escalated as a high-priority issue.\n4.8 The backup methodology - what is backed up, how, retention duration, and encryption approach - is documented and reviewed at least annually, alongside the quarterly restore-test record, as the evidence set for backup assurance.\n4.9 Before a tenant is decommissioned, an on-demand recovery-anchor backup of its database is taken and verified as the first step of the decommission sequence, and its identifier is recorded in the operation's evidence bundle. A quarantined tenant's restoration path - recreating compute against the retained database and storage and verifying full health - is exercised as part of tenant-lifecycle acceptance drills; a failed restoration leaves the tenant safely quarantined and restorable, never partially active.\n\n## 5. Exceptions\nA deviation from this policy (for example, a temporary reduction in restore-test frequency during a platform migration) is documented by the Head of Engineering with the risk, a compensating control, and a review date, and is reported to the Security Lead.\n\n## 6. Enforcement\nFailing to run a scheduled backup, restoration test, or recall-access review without an approved exception is a policy violation handled per the Human Resources Security Policy's disciplinary process where individual negligence is a factor. Compliance is verified through automated backup-completion monitoring, quarterly restoration-test records, recall-access-permission reviews, and annual review of the backup configuration against this policy.\n\n## 7. Review & Ownership\nOwner: DevOps / Head of Engineering. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Business Continuity & Disaster Recovery Policy; Encryption Policy; Configuration Management Policy.\nGoverns controls: A.8.13 - Information backup; PI1.5; SOC1-5; Cloud SQL backup, integrity & recovery; Model Home Data Lake backup & disaster recovery.\nOperated by: business continuity and disaster recovery test exercises.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["soc2","iso-27001","soc1"],"domains":["business_continuity_disaster_recovery","financial_reporting_controls"],"review_frequency":"annual","effective_date":"2026-05-11","next_review_date":"2026-12-13"}},{"title":"Board & Governance Policy","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"This policy establishes the governance structure and oversight responsibilities for the Bluth Company information security program, ensuring that security is supported at the highest organizational level.","full_description":"# Board & Governance Policy\n\n## 1. Purpose\nThis policy establishes the governance structure and oversight responsibilities for the Bluth Company information security program, ensuring security receives senior-management and independent oversight even though Bluth Company is a founder-led company with no formal board of directors.\n\n## 2. Scope\nThis policy applies to the CEO in the CEO's governance capacity, the Independent Governance Advisor, and any other individual or outsourced function (the Tidewell Advisory Group vCISO) that participates in governing, reviewing, or overseeing the information security program. It defines the governance cadence, reporting lines, decision-making authority, and independence arrangements that substitute for a formal board at Bluth Company's size.\n\n## 3. Roles & Responsibilities\nThe CEO provides executive sponsorship for the security program, chairs the quarterly governance review, and makes final risk-acceptance decisions. The Independent Governance Advisor (the fractional CISO) provides board-equivalent independent oversight - a role held by someone outside Bluth Company management and outside the Tidewell Advisory Group vCISO engagement. The Tidewell Advisory Group vCISO facilitates governance-cycle logistics (audits, management review, risk cycle, incident post-mortems) but does not approve policy and does not substitute for the Independent Governance Advisor's independence. The Head of Engineering and the Operations Lead ensure their functions comply with approved policy and escalate resource constraints to the CEO.\n\n## 4. Policy Statements\n4.1 The CEO reviews information security program effectiveness at least quarterly, covering security metrics, risk register status, open incidents, audit findings, and compliance status; outcomes are documented as ISMS records per the Management Review Procedure.\n\n4.2 An organizational chart is maintained documenting reporting lines and accountability for information security, including the CEO (executive sponsor and de facto Security Lead), the Head of Engineering, the Operations Lead, and the outsourced Tidewell Advisory Group vCISO advisory function; security-relevant duties are explicitly assigned wherever a role carries them.\n\n4.3 Management allocates sufficient budget, personnel, and tooling to operate and improve the security program; resource adequacy is reassessed annually as part of the annual security program review.\n\n4.4 Every Bluth Company security policy is approved by the CEO before publication and communicated to all affected personnel; documented policy exceptions require a named approver and compensating controls, per each policy's own Exceptions section.\n\n4.5 Executive-level risk-acceptance decisions are documented with the accepted risk, the compensating controls in place, a time-bound review date, and the accepting executive's signed acknowledgment, per the Risk Management Policy.\n\n4.6 The Independent Governance Advisor is engaged specifically to provide the external oversight a board of directors would otherwise provide: the Advisor counter-signs the risk register each quarter, attests in writing to security program effectiveness each quarter, and conducts the CEO's annual performance review. Departure of the Advisor without an overlapping replacement is treated as a governance gap and escalated to the CEO immediately.\n\n4.7 The CEO's role description documents conflict-of-interest and recusal obligations and states explicitly that no individual - including the CEO - may override or bypass an approved control (for example, the no-self-approval rule in the Change Management Policy) except through the documented Exceptions process of the relevant policy.\n\n4.8 A confidential and anonymous ethics and whistleblower reporting channel is maintained through which employees, contractors, third parties, and customers are directed - via this policy, the code of conduct, the public website, and the internal intranet - to report suspected unethical, illegal, or policy-violating behavior without fear of retaliation. Reports are acknowledged, routed to the CEO and the Independent Governance Advisor, and evaluated and dispositioned through the Code of Conduct & Workforce Accountability process; retaliation against a good-faith reporter is itself a disciplinary violation.\n\n## 5. Exceptions\nAn exception to any governance provision of this policy (for example, a delayed quarterly review or a temporary gap in Independent Governance Advisor coverage) is documented by the CEO with the reason, the compensating arrangement, and a date by which normal governance resumes; any exception lasting beyond one quarter is disclosed at the next management review.\n\n## 6. Enforcement\nFailure to hold a required governance review, failure to document a risk-acceptance decision, or retaliation against a whistleblower is treated as a control failure: it is logged through the Nonconformity & Corrective Action Procedure and, where it involves an individual's conduct, handled per the Human Resources Security Policy's disciplinary process. Repeated or willful bypass of the no-override commitment in Statement 4.7 is grounds for disciplinary action regardless of the individual's seniority.\n\n## 7. Review & Ownership\nOwner: CEO. Review cadence: at least annually and on significant change; the Independent Governance Advisor arrangement is reviewed on the same annual cycle.\n\n## 8. Related Documents & Controls\nRelated policies: Information Security Policy (apex), Risk Management Policy (risk-acceptance detail), Human Resources Security Policy (disciplinary process), Change Management Policy (no-founder-override cross-reference), Management Review Procedure. Governs controls: A.5.2 - Information security roles and responsibilities; CC1.1; CC1.2; CC1.3; CEO role description with documented conflicts, recusals, and no-override commitments; Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations. Operated by: the ISMS internal audit and management review cycle; the policy review and approval process.","policy_type":"policy","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["soc2","iso-27001","soc1"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-06-08","next_review_date":"2026-12-14"}},{"title":"Business Continuity & Disaster Recovery Policy","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"This policy ensures that Bluth Company can maintain or quickly restore critical services following a disruptive event, meeting contractual availability commitments to customers.","full_description":"# Business Continuity & Disaster Recovery Policy\n\n## 1. Purpose\nThis policy ensures that Bluth Company can maintain, or quickly restore, critical services following a disruptive event, meeting its contractual availability commitments to customers.\n\n## 2. Scope\nThis policy covers all production services hosted on Model Home Data Lake, supporting infrastructure, critical SaaS dependencies, and the essential business processes needed to keep the platform running. It addresses localized failures (a single component or zone), broader disasters (a regional outage), and the processing-capacity management needed to avoid both.\n\n## 3. Roles & Responsibilities\nThe Head of Engineering owns the BCP and DR plans and the capacity-management program. DevOps maintains failover, redundancy configuration, and 24×7 capacity monitoring. The Security Lead coordinates BCP/DR testing and documents results. All personnel know their role during a disruption as defined in the BCP.\n\n## 4. Policy Statements\n4.1 A business continuity plan (BCP) is maintained and tested at least annually, identifying critical services, recovery priorities, communication procedures, and alternative-processing arrangements.\n4.2 Recovery time and recovery point objectives are defined for each critical service based on customer SLA commitments; current targets are an RTO of 4 hours and an RPO of 1 hour for production services, published in the Information Security Objectives.\n4.3 Automated failover and redundant, multi-zone Model Home Data Lake architecture (the Model Home compute tier autoscaling, Cloud SQL high availability) are configured for critical production services; single points of failure identified in the risk register are eliminated where feasible.\n4.4 A disaster recovery plan documents step-by-step procedures for restoring service from backup in a secondary region; the plan is tested at least annually (tabletop exercise or live failover), with results documented, the plan updated from findings, and gaps tracked to remediation as issues.\n4.5 Processing capacity is monitored 24×7 through Cloud Monitoring against defined utilization thresholds; capacity-driven infrastructure changes - such as raising a scaling limit or resizing an instance class - follow the standard Change Management process rather than being made ad hoc.\n4.6 Environmental and infrastructure-availability risks - a regional Model Home Data Lake outage, a zone failure, or a critical third-party dependency outage - are identified in the risk assessment and treated (avoided, mitigated, transferred, or accepted) alongside other enterprise risks.\n4.7 Redundancy of information-processing facilities is achieved through Model Home Data Lake's multi-zone deployment within a region and cross-region disaster-recovery failover capability, rather than Bluth Company-operated secondary data centers.\n4.8 Information security controls - access authorization, encryption, and audit logging - remain in force throughout a disruption and its recovery; any control exception an emergency response requires follows the Change Management emergency-change process rather than an informal bypass.\n4.9 BCP/DR test results and gap-remediation status are reported to management as part of the quarterly and annual governance cadence, alongside the annual incident-trend review.\n\n## 5. Exceptions\nA deviation from a stated RTO/RPO target or test cadence (for example, deferring an annual DR test during a major platform migration) is documented by the Head of Engineering with the risk, a compensating control, and a catch-up date, and is reported to the Security Lead and CEO.\n\n## 6. Enforcement\nFailing to test the BCP/DR plan on cadence, or bypassing information-security controls during a disruption without following the emergency-change process, is a policy violation handled per the Human Resources Security Policy's disciplinary process where individual negligence is a factor. Compliance is verified through annual plan-test records, quarterly capacity and backup-restoration metrics, and uptime monitoring.\n\n## 7. Review & Ownership\nOwner: Head of Engineering. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Backup & Recovery Policy; Risk Management Policy; Incident Response Policy; Configuration Management Policy.\nGoverns controls: A.5.29 - Information security during disruption; A.5.30 - ICT readiness for business continuity; A.8.6 - Capacity management; A.8.14 - Redundancy of information processing facilities; A1.1; A1.2; A1.3; CC7.5.\nOperated by: business continuity and disaster recovery test exercises.","policy_type":"policy","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["business_continuity_disaster_recovery","incident_management_response","logging_monitoring_detection"],"review_frequency":"annual","effective_date":"2026-01-12","next_review_date":"2026-12-15"}},{"title":"Change Management Policy","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"This policy ensures that all changes to Bluth Company production systems are authorized, tested, and implemented in a controlled manner to minimize the risk of service disruption, data loss, or security vulnerabilities.","full_description":"# Change Management Policy\n\n## 1. Purpose\nThis policy ensures that all changes to Bluth Company production systems - application code, infrastructure, and database schemas - are authorized, tested, and implemented in a controlled, auditable manner that minimizes the risk of service disruption, data loss, or security vulnerabilities.\n\n## 2. Scope\nThis policy applies to all changes to production application code (core, auth, and MCP apps), infrastructure-as-code, database schema migrations, Model Home Data Lake project and network configuration, and third-party integrations, across the dev → staging → per-tenant-production pipeline. It covers the canary tenant, every customer tenant, and the shared control-plane (admin) systems, and applies equally to planned changes, emergency changes, and infrastructure provisioned by the admin control plane's Terraform runner when it creates or modifies a customer's single-tenant Model Home Data Lake project. It also covers operational tenant-lifecycle changes - provisioning, redeployment, tier/compute/storage changes, decommissioning, restoration, and purge - executed through the tenant-operations control plane.\n\n## 3. Roles & Responsibilities\nThe Head of Engineering owns this policy and the branch-protection/CI gate configuration. Engineering leads review and approve merge requests for their services and serve as segregated deployment approvers. Developers author changes, write tests, and obtain review, and never self-approve or self-merge their own change. DevOps maintains the Model Home Data Lake CI/Cloud Build pipelines, the Terraform runner, and per-tenant deployment tooling. A designated backup code reviewer, onboarded with the full personnel security package, receives routed merge requests whenever the primary reviewer is unavailable or is the change's author. The CEO is subject to the same no-self-approval rule as all personnel; there is no founder override.\n\n## 4. Policy Statements\n4.1 All application code changes to production shall be made through a Model Home Data Lake merge request requiring at least one peer approval from someone other than the author; Model Home Data Lake branch protection disables direct commits to the protected (main/production) branch.\n4.2 An automated Model Home Data Lake CI / Cloud Build pipeline shall run unit tests, integration tests, and security scans (SAST, secret detection, dependency scanning) on every merge request; the pipeline blocks merging and deployment on any unwaived Critical or High finding or failing required job.\n4.3 Production deployment shall require approval from someone segregated from the change's authorship - a distinct deployment approver - enforced through Model Home Data Lake/Cloud Build environment protection rules.\n4.4 New releases shall be built from an exact, pipeline-green source commit into digest-pinned images and deployed first to the canary tenant under the Canary-First Deployment workflow, observed against error-rate, latency, and health-check thresholds; promotion then proceeds to the Bluth Company internal tenant as a second canary before the remaining per-tenant production Model Home Data Lake projects are updated in small fixed batches with a stop-on-first-failure rule. A failed or indeterminate tenant halts the rollout, and rollback restores application image digests only - never the database.\n4.5 Database schema changes shall follow the expand-contract pattern: additive, backward-compatible schema changes (\"expand\") are deployed and run alongside the prior code version before the dependent code change ships; removal of now-unused columns or tables (\"contract\") occurs only after the new code path is confirmed healthy in production. The platform's migrate-on-startup mechanism ties a given code version to its compatible schema version as a single deployable artifact, so code and schema cannot drift apart.\n4.6 Infrastructure changes - Model Home Data Lake project configuration, network, IAM, and the per-tenant provisioning module the admin control plane's Terraform runner applies - shall be defined as Terraform IaC, version-controlled, and pass the same merge-request review and approval gate as application code before `terraform apply` is executed by the tenant-provisioner job, which only the tenant-operations control plane's dedicated executor identities may invoke.\n4.7 Emergency changes that bypass the standard pre-approval sequence shall be documented within 48 hours of implementation, including justification, impact assessment, and a retroactive peer review by an engineering lead. An emergency tenant operation executed outside the normal control-plane path shall use the documented break-glass procedure - a declared reason, scope, and duration; a time-bound access grant that expires automatically; execution through the same validated executors with no relaxation of schema, guard, or checkpoint contracts; and a named line item in the next tenant-operations reconciliation report.\n4.8 Every change - code, infrastructure, or emergency - shall be traceable end-to-end in Model Home Data Lake, from its issue or change record through merge-request approvals and the CI/CD pipeline run to the deployment log, forming a durable audit trail.\n4.9 A secondary backup code reviewer shall be designated and routed merge requests whenever the primary reviewer is unavailable or is the change's author; the no-self-approval rule is enforced in Model Home Data Lake branch protection without exception, including for the CEO.\n4.10 Operational tenant-lifecycle changes shall be executed through the tenant-operations control plane as discrete, evidenced runs: a versioned request, an evidenced plan, an approval recorded in the corresponding operating workflow before apply, execution by a fixed managed executor under a per-action least-privilege service account, post-apply verification against authoritative state, and a redacted, checksummed evidence bundle written to a retention-locked bucket. The recorded approval is a detective control: execution does not read the workflow system, and the monthly reconciliation report surfaces any mutating run that lacks a workflow reference or precedes its recorded approval as a finding requiring disposition.\n\n4.11 Customers shall be notified of critical system changes that may affect their processing. A change is critical for this purpose when it alters the data model or export format, the MCP or API contract, authentication or SSO behavior, a published availability or maintenance window, a subprocessor, or any other customer-facing commitment recorded in the system description. Planned critical changes are announced at least five business days before deployment through the release notes and an e-mail to each tenant's administrators; an emergency change that meets the trigger is notified within one business day after implementation. The notification record - trigger, channel, recipients, and send date - is retained with the change record.\n\n## 5. Exceptions\nA request to deviate from this policy (for example, a one-time exception to the segregated-approval requirement for a single-person maintenance task) shall be submitted to the Head of Engineering, who assesses the risk and documents a compensating control before approving. Exceptions are recorded with their justification, compensating control, and a review date, and lapse automatically unless renewed.\n\n## 6. Enforcement\nViolations - including self-approval, bypassing required CI checks, or undocumented emergency changes - are policy violations handled through the disciplinary process described in the Human Resources Security Policy, up to and including access revocation. Compliance is monitored continuously through CI/CD pipeline enforcement and merge-request audit logs; the monthly tenant-operations reconciliation report verifies that every mutating tenant operation carries its workflow reference and approval lineage; and Tidewell Advisory Group's internal audit function additionally samples merged requests quarterly to verify no self-approvals occurred.\n\n## 7. Review & Ownership\nOwner: Head of Engineering. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Software Development Lifecycle Policy; Secure Coding Policy; Configuration Management Policy; Vulnerability & Patch Management Policy; Business Continuity & Disaster Recovery Policy; Access Control Policy (tenant-operations authorization matrix); AI Governance & Acceptable AI Use Policy (agent-executed operations).\nGoverns controls: A.8.32 - Change management; CC8.1; SOC1-2; Model Home Data Lake infrastructure change management (Terraform IaC review); Model Home Data Lake branch protection & mandatory code review; CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform); CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build); Migrate-on-startup ties code and schema into single deployable artifact; Customers notified of critical system changes affecting their processing.\nOperated by: the change and release management process; Canary-First Deployment Workflow; Database Migration Safety (Expand-Contract) Workflow.","policy_type":"policy","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["secure_configuration_change_management","governance_policy_oversight","network_communications_security"],"review_frequency":"annual","effective_date":"2026-02-09","next_review_date":"2026-12-16"}},{"title":"Cloud Services Security Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"This policy defines security requirements for the acquisition, use, management, and exit of cloud services to ensure that cloud-hosted data and services are appropriately protected.","full_description":"# Cloud Services Security Policy\n\n## 1. Purpose\nThis policy defines security requirements for the assessment, use, ongoing management, and exit from cloud services, so that cloud-hosted data and services remain appropriately protected throughout the vendor relationship.\n\n## 2. Scope\nThis policy covers all cloud services used by Bluth Company, with primary focus on Model Home Data Lake as the infrastructure provider for every per-tenant production environment, and secondarily the third-party SaaS applications used for business operations, development, and collaboration.\n\n## 3. Roles & Responsibilities\nDevOps manages Model Home Data Lake configuration and security settings. The Security Lead assesses cloud providers, reviews their compliance reports, and maintains exit-strategy documentation. Engineering ensures applications correctly use available cloud security features.\n\n## 4. Policy Statements\n4.1 Cloud service providers are assessed for security capabilities, compliance certifications (SOC 2, ISO 27001), data residency options, and contractual commitments before adoption, under the assessment process defined in the Vendor Management Policy; assessments are documented and reviewed by the Security Lead.\n4.2 Model Home Data Lake services are configured according to Model Home Data Lake security best practices and CIS Model Home Data Lake Foundations benchmarks; security configurations are codified as Terraform infrastructure-as-code, version-controlled, and peer-reviewed under the Change Management Policy.\n4.3 The shared-responsibility boundary is documented for each cloud service in use; Bluth Company's responsibilities within that boundary - such as IAM configuration, application-layer security, and encryption key choices - are assigned to a named owner.\n4.4 Data stored in cloud services is encrypted at rest and in transit per the Encryption Policy; customer data is stored only in Model Home Data Lake regions consistent with the customer's contractual data-residency requirements.\n4.5 Model Home Data Lake is treated as Bluth Company's primary infrastructure provider and as a critical subservice organization under the Vendor Management Policy; its SOC 2 report is reviewed at least annually, and its physical and environmental controls are relied upon under the Physical Security Policy rather than duplicated internally.\n4.6 An exit strategy and data-portability plan is maintained for each critical cloud service, addressing data extraction, format conversion, and migration timelines, and is reviewed at least annually.\n4.7 Model Home Data Lake Organization Policy constraints are applied at the org/folder level to restrict which Model Home Data Lake services and APIs may be enabled within a project, preventing a team from adopting an unassessed Model Home Data Lake service outside the review required by statement 4.1.\n4.8 Before go-live, a newly adopted cloud service is checked against the subprocessor-list obligations in the Vendor Management Policy, so that any service processing customer or personal data is published to the customer-facing subprocessor list within the required window.\n\n## 5. Exceptions\nAdoption of a cloud service that cannot meet a specific requirement of this policy (for example, a regional data-residency limitation) requires a documented risk assessment, a compensating control, and Security Lead approval before use, with a review date.\n\n## 6. Enforcement\nAdopting a cloud service for production or customer-data use without the required assessment is a policy violation. Compliance is verified through Model Home Data Lake security configuration audits, review of provider compliance reports, and periodic assessment of cloud service usage against the list of approved services.\n\n## 7. Review & Ownership\nOwner: DevOps / Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Vendor Management Policy; Physical Security Policy; Configuration Management Policy; Encryption Policy; Change Management Policy.\nGoverns controls: A.5.23 - Information security for use of cloud services.\nOperated by: the vendor assurance review process.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["iso-27001"],"domains":["third_party_supply_chain_risk"],"review_frequency":"annual","effective_date":"2026-03-09","next_review_date":"2026-12-17"}},{"title":"Code of Conduct","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"States the standards of integrity, ethical behavior, conflict-of-interest handling, confidentiality, and personal accountability for internal control that every individual acting on Bluth Company's behalf acknowledges at hire and annually, and against which conduct is evaluated and sanctioned.","full_description":"# Code of Conduct\n\n## 1. Purpose\nThis Code of Conduct states the standards of integrity, ethical behavior, and personal accountability that every person working for or with Bluth Company is expected to uphold. It is the document the Acceptable Use Policy, the Human Resources Security Policy, and the Board & Governance Policy refer to when they speak of \"the Code of Conduct\", and it is the standard against which conduct is evaluated, recognized, and - where necessary - sanctioned. It exists so that the commitment to integrity and ethical values is written down, adopted by leadership, acknowledged by every individual, and demonstrably enforced, rather than assumed.\n\n## 2. Scope\nThis Code applies to every individual acting on Bluth Company's behalf: employees, part-time and fractional staff, contractors, advisors, and personnel provided by the outsourced HR, bookkeeping, and virtual CISO firm, Tidewell Advisory Group - including the CEO, to whom it applies without exception. Business partners and vendors that handle Bluth Company or customer data are held to the conduct and confidentiality obligations in their written agreements, which are aligned to this Code.\n\n## 3. Roles & Responsibilities\nThe CEO owns this Code, adopts it, sets the tone at the top through consistent personal behavior, and decides disciplinary outcomes. The Independent Governance Advisor provides independent oversight of leadership's own adherence, receives whistleblower reports that concern the CEO, and reviews the annual adherence evaluation. Tidewell Advisory Group's HR function administers hire-time and annual acknowledgments, retains acknowledgment records, and administers the disciplinary process. Managers evaluate the conduct of their direct reports at least annually and model the Code in their own behavior. Every individual reads, acknowledges, follows, and - when they see a violation - reports.\n\n## 4. Policy Statements\n4.1 Integrity and ethical values - Every individual shall act honestly, keep the commitments Bluth Company makes to customers, regulators, and partners, and refuse to misrepresent facts, evidence, test results, or control performance to anyone, including auditors. Falsifying or backdating a record, an approval, or an attestation is gross misconduct.\n\n4.2 Compliance with law and policy - Every individual shall comply with applicable law and with the Bluth Company policy suite, and shall complete the security awareness training and policy acknowledgments the Human Resources Security Policy requires. Ignorance of a published policy is not a defense; every policy is available to all personnel through Lucille Identity Cloud.\n\n4.3 Conflicts of interest - Every individual shall disclose to the CEO any personal, financial, or family interest that could conflict with Bluth Company's interests, including outside employment with a customer, vendor, or competitor. The CEO's own conflicts, recusals, and no-override commitments are documented in the CEO role description; a matter in which the CEO is conflicted is referred to the Independent Governance Advisor.\n\n4.4 Confidentiality and customer data - Customer data, personal information, source code, credentials, and non-public business information shall be used only for the purpose for which access was granted, handled per the Data Classification & Handling Policy, and never disclosed, copied to unauthorized locations, or used for personal benefit. These obligations survive the end of employment or engagement.\n\n4.5 Use of company systems and AI tools - Company systems, devices, and generative-AI tools shall be used per the Acceptable Use Policy and the AI Governance & Acceptable AI Use Policy. No individual may bypass a security control, share an authenticator, or grant themselves or others access outside the documented provisioning process.\n\n4.6 Respect and a safe workplace - Every individual shall treat colleagues, customers, and partners with respect. Discrimination, harassment, retaliation, and abusive conduct are prohibited in every work setting, including remote and written communication.\n\n4.7 Accountability for internal control - Every individual is accountable for the internal-control responsibilities assigned to them: operating the controls they own on schedule, keeping the evidence those controls require, and escalating a control failure rather than concealing it. Control ownership assignments are reviewed at least quarterly and are inputs to the annual performance and conduct evaluation.\n\n4.8 Speaking up - Suspected unethical, illegal, or policy-violating behavior shall be reported through the confidential ethics and whistleblower channel described in the Board & Governance Policy, to the CEO, or - where the concern involves the CEO - directly to the Independent Governance Advisor. Good-faith reports never trigger retaliation; retaliation is itself a violation of this Code.\n\n4.9 Acknowledgment - Every individual shall acknowledge this Code in writing at the time of hire or engagement, before being granted access to Bluth Company systems or data, and again at least annually and whenever the Code changes materially. Acknowledgment records are retained by Tidewell Advisory Group's HR function for the duration of the engagement plus the retention period in the Data Retention & Disposal Policy.\n\n4.10 Evaluation and enforcement - Adherence to this Code is evaluated at least annually for every individual as part of the performance and conduct evaluation required by the Human Resources Security Policy, and deviations are handled through the disciplinary process in that policy - coaching, written warning, access restriction or suspension, and termination for gross misconduct - applied consistently regardless of role or tenure. Substantiated deviations, the response applied, and the timeliness of remediation are recorded as Issues in the Bluth Company system of record.\n\n## 5. Exceptions\nThere are no standing exceptions to this Code. A conduct question that the Code does not answer is raised with the CEO (or, for the CEO's own conduct, the Independent Governance Advisor) before acting, and the answer is recorded so it can inform the next annual refresh.\n\n## 6. Enforcement\nViolations of this Code are addressed through the disciplinary process in the Human Resources Security Policy. The CEO decides sanctions for personnel; the Independent Governance Advisor reviews any matter involving the CEO and records the outcome in the quarterly attestation memo. Violations by business partners are addressed under their agreements, up to suspension or termination of the engagement.\n\n## 7. Review & Ownership\nThis Code is owned by the CEO, reviewed at least annually through the Code of Conduct & Workforce Accountability Cycle - which reissues the Code, secures the CEO's adoption, communicates it to all personnel and partners, runs the acknowledgment campaign, and evaluates adherence - and updated whenever a material change in the business, the law, or an incident finding requires it. Each reissue carries a change summary that states whether re-acknowledgment is required.\n\n## 8. Related Documents & Controls\nRelated policies: Acceptable Use Policy (rules for systems, devices, and AI tools); Human Resources Security Policy (screening, acknowledgments, evaluation, disciplinary process); Board & Governance Policy (tone at the top, the Independent Governance Advisor, the whistleblower channel); AI Governance & Acceptable AI Use Policy; Data Classification & Handling Policy; Vendor Management Policy (partner conduct obligations).\nGoverns controls: CC1.1 - The entity demonstrates a commitment to integrity and ethical values; CC1.5 - The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives; A.6.4 - Disciplinary process; Annual performance and conduct evaluation per personnel.\nOperated by: the annual Code of Conduct & Workforce Accountability Cycle and the hire-time and annual acknowledgment campaign it runs.","policy_type":"policy","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["governance_policy_oversight","human_resources_personnel_security"],"review_frequency":"annual","effective_date":"2026-08-29","next_review_date":"2026-12-18"}},{"title":"Configuration Management Policy","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"This policy establishes requirements for managing and controlling configurations of systems, networks, and applications to maintain security, prevent unauthorized changes, and enable rapid detection of configuration drift.","full_description":"# Configuration Management Policy\n\n## 1. Purpose\nThis policy establishes requirements for managing and controlling the configuration of systems, networks, and applications to maintain security, prevent unauthorized change, and enable rapid detection of configuration drift.\n\n## 2. Scope\nThis policy covers all configuration items in the production environment: Model Home Data Lake resource configuration, application settings, database configuration, network and firewall rules, security-tool settings, and operating-system-level configuration, together with the time-synchronization and software-installation controls that keep those configurations trustworthy.\n\n## 3. Roles & Responsibilities\nDevOps and the Head of Engineering maintain configuration baselines, Terraform infrastructure-as-code definitions, and drift-detection tooling. The Security Lead defines security configuration requirements and reviews drift findings. Engineering teams manage application-level configuration within the approved baseline. Automated monitoring detects and alerts on configuration drift.\n\n## 4. Policy Statements\n4.1 Security configuration baselines are established and documented for all production systems and services, following vendor best practices, CIS benchmarks - including the CIS Model Home Data Lake Foundations benchmark - and technology-appropriate hardening guides.\n4.2 Configurations are managed through infrastructure-as-code (Terraform) stored in Model Home Data Lake version control. Manual configuration changes to production systems are prohibited except in a documented, time-bound emergency, which is retroactively reviewed and reconciled back into code.\n4.3 Configuration changes follow the Change Management process - peer review, testing, and approval before deployment - with a full audit trail from proposed change to applied state.\n4.4 Configuration drift detection, using Security Command Center findings and Cloud Audit Log-based alerting as the functional equivalent of file-integrity monitoring, continuously compares live configuration against the approved baseline. Unauthorized or unexpected configuration changes are investigated as potential security incidents and reverted to the approved baseline.\n4.5 Installation of software on operational (production) systems is restricted to authorized personnel and automated pipelines; ad hoc installation of software on production infrastructure outside the CI/CD pipeline is prohibited.\n4.6 Production systems and logging infrastructure synchronize to a common, reliable time source so that timestamps are consistent across systems and audit-log event correlation and log integrity are not compromised by clock skew.\n4.7 Configuration baselines are reviewed at least annually and updated to reflect new security requirements, vendor advisories, and lessons learned from incidents.\n\n## 5. Exceptions\nA request to deviate from an established baseline - for example, a temporary configuration needed to diagnose a production issue - is submitted to the Security Lead or Head of Engineering, risk-assessed, and approved only with a compensating control and a defined rollback or remediation timeline. Exceptions are recorded in the exception register with an owner and a review date and are reassessed at least annually.\n\n## 6. Enforcement\nConfiguration drift or an unauthorized change discovered outside an approved exception is investigated as a potential security incident under the Incident Response Policy and reverted to the approved baseline. Repeated unauthorized manual changes are treated as a policy violation under the Human Resources Security Policy. Compliance is verified through configuration scanning against baselines, infrastructure-as-code review records, change-management audit trails, and drift-detection reports.\n\n## 7. Review & Ownership\nOwner: DevOps / Head of Engineering. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Change Management Policy (change-approval process for configuration changes); Logging & Monitoring Policy (audit-log alerting used for drift detection); Cloud Services Security Policy (CIS baseline for Model Home Data Lake).\nGoverns controls: A.8.9, A.8.17, A.8.19; Model Home Data Lake account & project baseline hardening.\nOperated by: the corresponding secure-baseline and drift-management workflow in the Bluth Company workflow library.","policy_type":"policy","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["secure_configuration_change_management","logging_monitoring_detection"],"review_frequency":"annual","effective_date":"2026-04-13","next_review_date":"2026-12-19"}},{"title":"Continual Improvement Process","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"This document establishes the process for continual improvement of the Bluth Company ISMS in accordance with ISO/IEC 27001:2022 Clause 10.1, ensuring the ISMS remains effective in the face of evolving threats, business changes, and regulatory requirements.","full_description":"# Continual Improvement Process\n\n## 1. Purpose\nThis document establishes Bluth Company's process for continual improvement of the ISMS under ISO/IEC 27001:2022 Clause 10.1, so the ISMS keeps getting better in the face of evolving threats, business change, and new regulatory requirements, instead of standing still once it passes an audit.\n\n## 2. Scope\nThis process covers every improvement opportunity identified from any ISMS source, and the annual ISMS maturity assessment that sets the following year's improvement priorities.\n\n## 3. Procedure Steps\n3.1 Improvement opportunities are logged as items in the Bluth Company platform from five standing sources: management review outputs; internal and external audit findings; incident post-mortem lessons learned - including corrective actions closed out under the Nonconformity & Corrective Action Procedure, which routinely supplies validated root-cause fixes as improvement candidates once they are proven effective; security metric and KPI trend analysis; and feedback from employees, customers, and other stakeholders.\n\n3.2 Each logged improvement records its source, a description, the expected benefit, and a priority. The Security Lead triages incoming items and sets an initial priority based on risk-reduction potential, cost-effectiveness, and effort required.\n\n3.3 Priority is ratified during the quarterly management review, where improvement work is weighed against other resourcing decisions rather than approved in isolation.\n\n3.4 Approved improvements are assigned an owner and an implementation timeline; progress is tracked and reported in the monthly security metrics alongside the other ISMS KPIs.\n\n3.5 Implemented improvements are evaluated for effectiveness after a defined observation period. Effective improvements are institutionalized - the relevant policy, procedure, or training material is updated - so the gain survives even if the person who made it later changes roles.\n\n3.6 Bluth Company assesses overall ISMS maturity annually using a capability maturity model that rates each ISMS process from ad hoc through managed, defined, and optimized. The maturity assessment result, not merely a count of improvements shipped, sets the improvement roadmap priorities for the coming year and is itself reported at the annual management review.\n\n3.7 An improvement opportunity that traces back to a control gap rather than a process tweak - for example, a recurring incident root cause or an audit finding that reveals a missing control - is cross-logged to the risk register under the Risk Management Policy so the underlying risk, not just its symptom, is tracked and treated; this keeps the improvement loop and the risk-treatment loop from drifting out of sync.\n\n## 4. Records & Evidence\nLogged improvement items with source, description, expected benefit, priority, owner, and timeline; monthly progress metrics; effectiveness-evaluation notes for implemented improvements; cross-logged risk-register entries for control-gap-driven improvements; and the annual ISMS maturity assessment record together with the roadmap it produces.\n\n## 5. Review & Ownership\nOwner: Security Lead. Review cadence: annually, as part of the ISMS management review cycle.","policy_type":"procedure","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"1.0","framework":["soc2"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-05-11","next_review_date":"2026-12-20"}},{"title":"Data Classification & Handling Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"This policy establishes a data classification framework to ensure that information is identified, labeled, and protected according to its sensitivity and value, supporting both confidentiality requirements and regulatory obligations.","full_description":"# Data Classification & Handling Policy\n\n## 1. Purpose\nThis policy establishes Bluth Company's data classification framework and the labelling and handling requirements that follow from it, so that information receives protection commensurate with its sensitivity, supporting confidentiality commitments and regulatory obligations.\n\n## 2. Scope\nThis policy applies to all data in any form - electronic, paper, or verbal - created, processed, stored, or transmitted by Bluth Company, including customer data resident in per-tenant Cloud SQL (PostgreSQL) databases on Model Home Data Lake, internal business data, employee personal data, and intellectual property. It covers data at rest, in transit, and in use, and applies equally to Bluth Company personnel and to Tidewell Advisory Group personnel and other contractors granted system access.\n\n## 3. Roles & Responsibilities\nThe Security Lead owns the classification scheme and the labelling and handling standards that implement it. Data owners - typically the product or functional lead accountable for a given data set - assign, and, when circumstances change, approve reclassification of, the data in their area. The Head of Engineering ensures classification tags are reflected in the data-store asset inventory and that engineering handling practices (encryption, access, logging) match each level. All personnel apply labels correctly, handle data per its classification, and report suspected mishandling.\n\n## 4. Policy Statements\n4.1 All data is classified into one of four levels - Public, Internal, Confidential, or Restricted - based on its sensitivity, legal and contractual requirements, and the business impact of unauthorized disclosure. Customer data is classified as Confidential at minimum; personally identifiable information (PII) is classified as Restricted.\n4.2 Classification is indicated through labelling appropriate to the medium: electronic documents carry classification in a header or in document metadata; data stores and system components are tagged with their classification level in the asset inventory; verbal discussion of Confidential or Restricted information is conducted only in private settings (video calls, in person, or 1:1 channels), not in open or recorded public channels.\n4.3 Classification and reclassification decisions are made by the data owner, based on content sensitivity, legal and contractual obligations, and the impact of unauthorized disclosure or modification; data is not downgraded in classification without the data owner's approval.\n4.4 Confidential and Restricted data is encrypted at rest using AES-256-GCM and in transit using TLS 1.2 or higher, consistent with the Encryption Policy; unencrypted storage or transmission of Confidential or Restricted data is prohibited.\n4.5 Handling requirements are defined per classification level for creation, storage, transmission, sharing, archival, and disposal; disposal follows the Data Retention & Disposal Policy. All data stores are inventoried with their classification level documented in the asset register, and a new data store is classified before it is used in production.\n4.6 All personnel are trained on the four-level classification scheme, the labelling procedures, and the handling requirements for each classification level as a distinct, assessed component of annual security awareness training under the Human Resources Security Policy. This classification-specific training content is a requirement of this policy and is not satisfied by generic security-awareness coverage alone.\n4.7 Customers and users shall not upload, and Bluth Company is not contractually scoped to process, prohibited categories of regulated data - electronic protected health information (ePHI under HIPAA/HITECH), payment-card data (PCI-DSS), Gramm-Leach-Bliley Act (GLBA) non-public personal information, government-issued identification numbers, or biometric data. This restriction is bound in the customer subscription agreement, reflected in the complementary user-entity controls, and reinforced by the Acceptable Use Policy; suspected ingestion of prohibited-category data is handled as a security incident under the Incident Response Policy.\n4.8 Information found unclassified in a production system is classified and labelled within 30 days of discovery.\n\n## 5. Exceptions\nAn exception to this policy - for example, a data store that cannot yet meet its required encryption or labelling standard - is requested in writing to the Security Lead, includes a risk assessment and any compensating controls, and is approved by the Security Lead before the exception takes effect. Approved exceptions are logged in the risk register, time-bound, and reviewed at each renewal date or at least annually.\n\n## 6. Enforcement\nMishandling of Confidential or Restricted data is treated as a security incident under the Incident Response Policy. Violations of this policy may result in disciplinary action up to and including termination of employment or contract, consistent with the Human Resources Security Policy. Compliance is monitored through periodic audits of data-store classification tags, access controls, and encryption configuration, and through the annual internal audit program.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Data Retention & Disposal Policy; Data Masking Policy; Encryption Policy; Information Transfer & Leakage Prevention Policy; Human Resources Security Policy; Acceptable Use Policy; Incident Response Policy.\nGoverns controls: A.5.12 - Classification of information; A.5.13 - Labelling of information; C1.1 - The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality; PI1.1 - The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product and service specifications, to support the use of products and services.\nOperated by: classification and labelling practice is embedded in engineering onboarding of new data stores and in annual security awareness training; no single dedicated operational workflow exists for this policy area.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["soc2","iso-27001"],"domains":["asset_management_inventory","financial_reporting_controls"],"review_frequency":"annual","effective_date":"2026-06-08","next_review_date":"2026-12-21"}},{"title":"Data Masking Policy","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"This policy defines requirements for masking sensitive data to reduce the risk of unauthorized disclosure in non-production environments, logs, displays, and shared outputs.","full_description":"# Data Masking Policy\n\n## 1. Purpose\nThis policy defines requirements for masking or replacing sensitive data outside the contexts that genuinely require the real value, reducing the risk of unauthorized disclosure through non-production environments, application logs, user interfaces, and error output.\n\n## 2. Scope\nThis policy applies to all sensitive data categories - PII, credentials, financial data, and other data classified Confidential or Restricted under the Data Classification & Handling Policy - wherever they appear in development, staging, or test environments, application logs, user interfaces, error messages, analytics, and any other context where the full, unmasked value is not required to do the work at hand.\n\n## 3. Roles & Responsibilities\nThe Head of Engineering and Security Lead jointly define which data categories require masking and the required technique for each - non-production substitution, log masking, UI masking, or error-message masking. Engineering implements masking in application code, logging configuration, and non-production data provisioning. QA verifies masking effectiveness as part of release testing before a change ships.\n\n## 4. Policy Statements\n4.1 Development, staging, and test environments do not contain real production data; where test data must resemble production data in structure, it is synthetic or anonymized data generated for that purpose, not a copy of live customer or personal data.\n4.2 Application logs do not contain unmasked sensitive data - passwords, API keys, tokens, personal identifiers, or financial data are masked or omitted before a log line is emitted, not redacted after the fact downstream in the logging pipeline.\n4.3 User interfaces mask sensitive fields by default - for example, partial display of an account identifier or a masked API key - and the full value is revealed only on explicit user action by a user authorized to view it.\n4.4 Error messages returned to end users or to external systems do not expose internal system detail, database structure, or sensitive data values; full error detail is logged server-side but masked in the client-facing response.\n4.5 Masking rules are reviewed whenever a new sensitive data category or a new use case for existing sensitive data is introduced into the product, and masking effectiveness is verified through code review at the time of the change and through periodic testing of non-production environments for inadvertently present real data.\n4.6 Analytics, reporting, and business-intelligence outputs derived from production data apply the same masking rules as the underlying application before the output is shared outside the team that owns the source data.\n\n## 5. Exceptions\nA documented, time-bound exception - for example, a narrowly scoped need for production-shaped data in staging to reproduce a defect - requires a business justification, Security Lead approval, and a defined removal date, and is logged for follow-up.\n\n## 6. Enforcement\nDiscovery of unmasked sensitive data in a non-production environment, a log, or a client-facing output is treated as a security incident under the Incident Response Policy. Compliance is verified through log audits, code review of data-handling paths, and periodic testing of non-production environments for real data.\n\n## 7. Review & Ownership\nOwner: Head of Engineering, with the Security Lead co-owning masking requirements. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Data Classification & Handling Policy; Secure Coding Policy; Software Development Lifecycle Policy; Logging & Monitoring Policy.\nGoverns controls: A.8.11 - Data masking; A.8.33 - Test information; Cloud SQL PII classification & field-level masking.\nOperated by: masking requirements are enforced through code review and release testing under the Software Development Lifecycle Policy; no single dedicated operational workflow exists for this policy area.","policy_type":"policy","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["data_protection_privacy","secure_configuration_change_management"],"review_frequency":"annual","effective_date":"2026-01-12","next_review_date":"2026-12-22"}},{"title":"Data Retention & Disposal Policy","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"This policy defines retention periods and secure disposal requirements for all categories of data processed by Bluth Company, ensuring compliance with legal obligations and minimizing risk from retaining data beyond its useful life.","full_description":"# Data Retention & Disposal Policy\n\n## 1. Purpose\nThis policy defines how long Bluth Company retains each category of data and how that data is securely disposed of at the end of its life, so that data remains available for as long as it is genuinely needed and no longer, meeting legal, contractual, and confidentiality obligations.\n\n## 2. Scope\nThis policy applies to all data held in Bluth Company production databases (per-tenant Cloud SQL instances), backups and replicas, log aggregation, email and document storage, and any other repository, covering both customer data and internal business data.\n\n## 3. Roles & Responsibilities\nThe Security Lead maintains the retention schedule and oversees disposal verification. The Head of Engineering implements automated data-lifecycle management in the platform, including deletion across primary stores, backups, replicas, and caches. Data owners confirm the retention period assigned to their data category is correct. External legal counsel, coordinated by the CEO, advises on regulatory and contractual retention obligations, including legal holds.\n\n## 4. Policy Statements\n4.1 Retention periods are defined per data category based on legal requirements, contractual commitments, and business need, and are documented in a retention schedule. Customer data is retained for the duration of the service agreement plus a 90-day grace period, unless a longer period is required by law; audit and security event logs are retained for a minimum of one year, with the immutable Cloud Audit Logs sink retained for seven years (see the Logging & Monitoring Policy); application logs are retained for 90 days.\n4.2 Customer data is deleted within 90 days of contract termination or a verified customer deletion request, whichever is earlier, unless retention is required by law or a longer contracted retention window applies. Deletion covers primary data stores, backups, replicas, and caches - not the primary store alone. Tenant offboarding is two-stage: the tenant is decommissioned immediately - it stops serving, its compute is removed, and a recovery-anchor backup is taken - while its database, document storage, and audit records are retained in quarantine for the tenant's contracted retention window (default 45 days); true destruction (purge) - destroying the tenant project including Cloud SQL, storage, and backups, then permanently retiring the tenant identifier - is code-refused before that window elapses, so an unauthorized or mistaken offboarding remains fully reversible until the point of true deletion.\n4.3 Data that has exceeded its retention period, or that is the subject of a completed deletion request, is disposed of using methods appropriate to its classification under the Data Classification & Handling Policy: Confidential and Restricted data is cryptographically erased or, where the medium requires it, physically destroyed.\n4.4 Deletion is automated where technically feasible to reduce the risk of oversight, and automated deletion jobs verify that data has been removed from all locations, including backups and replicas, not the primary store alone.\n4.5 Every deletion request and every deletion action is logged - what was deleted, when, by whom or by which automated process, and the reason - and this deletion log is retained beyond the deletion of the underlying data itself, preserving an audit trail once the data it describes is gone. For tenant purges, the deletion evidence - the plan inventory, recorded approval and workflow reference, destroy outputs, and post-destroy verification - is written as a redacted, checksummed evidence bundle to a retention-locked (WORM) bucket held for at least 400 days, so the record of the deletion outlives the data it documents.\n4.6 Before data is deleted, it is checked for an outstanding legal hold, a regulatory retention requirement, or an active, unresolved data-subject request that would conflict with deletion; a positive check blocks deletion until the conflict is resolved. A quarantined tenant's immutable (WORM-locked) audit sink aligns with its retention window by construction - the sink stops receiving at decommission, so its youngest record ages out exactly when the purge timer opens - and the monthly reconciliation report lists every quarantined tenant with its purge-eligible date so an unrecognized decommission is caught, and reversed by restoration, before the window closes.\n4.7 Backup data follows the same retention schedule as the primary data it backs up and does not exceed the primary data's retention period by more than 30 days, so that a purged record does not persist indefinitely in backup.\n4.8 The retention schedule is reviewed at least annually, and whenever a legal, regulatory, or contractual requirement affecting a data category changes.\n\n## 5. Exceptions\nA deviation from a defined retention period or disposal method - for example, extending retention to satisfy a legal hold - is requested in writing, documented with its business or legal justification, approved by the Security Lead (with legal counsel input where the exception involves a hold or a regulatory question), and logged with a review date.\n\n## 6. Enforcement\nFailure to delete data within the required window, or disposal by a method inconsistent with the data's classification, is treated as a security incident under the Incident Response Policy and may result in disciplinary action under the Human Resources Security Policy. Compliance is monitored through quarterly review of data stores against the retention schedule, automated alerting on data exceeding its retention period, and deletion-log audits.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Data Classification & Handling Policy; Privacy Policy; Information Transfer & Leakage Prevention Policy; Encryption Policy; Incident Response Policy.\nGoverns controls: A.8.10 - Information deletion; C1.2 - The entity disposes of confidential information to meet the entity's objectives related to confidentiality; Cloud SQL data retention & secure disposal.\nOperated by: the operational workflow that fulfills data-subject access and deletion requests invokes this policy's deletion and verification requirements whenever a request includes an erasure component.","policy_type":"policy","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["data_protection_privacy"],"review_frequency":"annual","effective_date":"2025-06-15","next_review_date":"2026-12-23"}},{"title":"Encryption Policy","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"This policy establishes requirements for the use of cryptography to protect the confidentiality and integrity of data at rest and in transit across Bluth Company systems.","full_description":"# Encryption Policy\n\n## 1. Purpose\nThis policy establishes requirements for the use of cryptography - including the full lifecycle of encryption-key management - to protect the confidentiality and integrity of data at rest and in transit across Bluth Company systems, and to ensure encryption keys are generated, stored, rotated, and retired under controlled, auditable conditions.\n\n## 2. Scope\nThis policy applies to all encryption of customer data, internal data, credentials, and communications: data at rest in Cloud SQL and Cloud Storage, data in transit across every network boundary described in the Network Security Policy, field-level encryption of sensitive attributes, and the cryptographic keys that protect all of the above, wherever they are generated, stored, or used.\n\n## 3. Roles & Responsibilities\nThe Security Lead defines encryption standards, approved algorithms, and key-management requirements, and audits encryption and key configurations during periodic reviews. Engineering implements encryption and key usage in application code. DevOps configures TLS, database encryption, and Cloud KMS key rings and permissions. No single individual holds both unrestricted production data access and unilateral authority to rotate or destroy the keys protecting that data without a second party's review.\n\n## 4. Policy Statements\n4.1 Data classified as Confidential or Restricted is encrypted at rest using AES-256-GCM or an equivalent Model Home Data Lake-managed algorithm. Database-level encryption is enabled on every production Cloud SQL instance.\n4.2 All data in transit is encrypted using TLS 1.2 or higher. Unencrypted protocols (HTTP, FTP, Telnet) are prohibited for any connection carrying production or customer data; HTTPS is enforced for all web traffic, and internal service-to-service communication is encrypted where technically feasible.\n4.3 Field-level encryption using AES-256-GCM is applied to particularly sensitive fields, such as API keys, tokens, and credentials, as defense-in-depth beyond database-level encryption.\n4.4 Key generation: cryptographic keys are generated within Model Home Data Lake Cloud Key Management Service (KMS) - or, for application and vendor secrets, provisioned in Model Home Data Lake Secret Manager - using approved algorithms and key lengths. Keys are never generated ad hoc in application code.\n4.5 Key storage and access restriction: key material is held exclusively in Cloud KMS or Secret Manager; direct export of key material is disabled by default; access to manage or use a key is restricted to the named services and personnel whose role requires it, enforced through Model Home Data Lake IAM least privilege.\n4.6 Key rotation occurs at least annually, and immediately upon suspected compromise. Rotation is automated where Cloud KMS supports it and is logged, including the identity that triggered any manual rotation.\n4.7 Key revocation and destruction: a key is disabled or destroyed when it is compromised, superseded by rotation, or no longer needed, including as part of a data-deletion or crypto-erasure obligation under the Data Retention & Disposal Policy. Destruction is irreversible and is logged with the requester and the approver.\n4.8 Where key material is backed up or escrowed, recovery requires the independent action of two authorized individuals. This custodian separation-of-duties requirement is the compensating control against permanent loss of encryption keys.\n4.9 Deprecated or weak cryptographic algorithms and protocols - including DES, 3DES, MD5, SHA-1, RC4, SSLv3, and TLS 1.0/1.1 - are not used in any system. Cryptographic configurations are reviewed during periodic security assessments.\n\n## 5. Exceptions\nA request to use a non-standard algorithm, or to delay a required key rotation - for example, pending a vendor migration - is submitted to the Security Lead, risk-assessed, and approved only with a documented compensating control and a remediation timeline. Exceptions are recorded in the exception register with an owner and a review date and are reassessed at least annually.\n\n## 6. Enforcement\nNon-compliant encryption or key-management configurations are remediated within 30 days of discovery. Circumventing encryption controls, exporting key material outside approved storage, or unilaterally destroying keys without dual control is treated as a policy violation under the Human Resources Security Policy and, where data confidentiality or availability is affected, as a security incident under the Incident Response Policy. Compliance is verified through automated scanning of TLS configurations, database-encryption status checks, Cloud KMS access-log review, and code review of field-level encryption implementations.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Network Security Policy (network transport boundaries this policy's in-transit controls protect); Data Classification & Handling Policy (which data classes require encryption); Data Retention & Disposal Policy (crypto-erasure at end of life); Access Control Policy (IAM least privilege enforcing key access).\nGoverns controls: A.8.24; Cloud SQL encryption & Cloud KMS key management; Model Home Data Lake encryption at rest & in transit.\nOperated by: the corresponding data-protection and key-management workflow in the Bluth Company workflow library.","policy_type":"policy","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["cryptography_key_management"],"review_frequency":"annual","effective_date":"2026-03-09","next_review_date":"2026-12-24"}},{"title":"Human Resources Security Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"This policy defines security requirements for the hiring, employment, and termination phases of the personnel lifecycle to reduce the risk of insider threats and ensure all personnel understand their security obligations.","full_description":"# Human Resources Security Policy\n\n## 1. Purpose\nThis policy defines security requirements across the personnel lifecycle - hiring, onboarding, ongoing employment, and termination - to reduce insider-threat risk and ensure every individual who touches Bluth Company systems or data understands and accepts their security obligations before being granted access.\n\n## 2. Scope\nThis policy applies to every phase of engagement - pre-hire screening, onboarding, ongoing employment, role changes, and termination - for every individual granted access to Bluth Company production systems, source code, or customer data: employees, part-time staff, and contractors, including personnel provided by Bluth Company's outsourced HR and virtual CISO firm, Tidewell Advisory Group. Bluth Company is fully remote with no shared office; lifecycle events are administered centrally regardless of where someone works.\n\n## 3. Roles & Responsibilities\nTidewell Advisory Group's HR function runs hiring, background checks, training administration, acknowledgement tracking, and offboarding for employees and contractors alike. The CEO confirms Tidewell Advisory Group has completed the personnel security package before granting production access, and owns disciplinary/termination decisions. The Security Lead defines training content and monitors completion and training-needs assessments. The Head of Engineering identifies technical roles needing cross-training. Managers confirm role requirements at hire/transfer and evaluate performance. All personnel complete required training and acknowledgements on schedule.\n\n## 4. Policy Statements\n4.1 Background checks - identity, criminal history, and employment history - shall be completed for every new hire before their start date, commensurate with role sensitivity, and reviewed and documented by Tidewell Advisory Group's HR function.\n4.2 Every individual shall sign a confidentiality agreement with intellectual-property assignment before being granted any access to Bluth Company systems, source code, or customer data.\n4.3 Engagement terms - the offer letter or contractor agreement - shall document information-security responsibilities, confidentiality obligations, and an acceptable-use acknowledgment, regardless of employment classification.\n4.4 Security awareness training shall be completed within 30 days of hire and refreshed annually, covering acceptable use, phishing, endpoint/password security, MFA, malware, and incident reporting; security-sensitive roles (engineers, other production-access holders) additionally complete secure-development training and the annual incident-response tabletop.\n4.5 Job requirements shall be documented for every role and candidate competencies evaluated against them before hire or transfer; Tidewell Advisory Group sources, screens, and administers any outsourced training-delivery relationship. Training needs are reassessed at least annually against role changes, incidents, and audit findings.\n4.6 Performance and conduct - including adherence to this policy and the Code of Conduct - shall be formally evaluated at least semi-annually (self, peer, manager input), informing recognition for strong performance and, for underperformance or conduct violations, corrective action up to the disciplinary process below.\n4.7 A disciplinary process applies consistently to security-policy and conduct violations regardless of role or tenure: coaching or a verbal warning (first minor violation), a documented written warning (repeated or moderate violation), suspension or access restriction (serious violation), and termination for gross misconduct or material harm - including unauthorized use or disclosure of personal information. Severity, not sequence, sets the starting point, and a deliberate violation may bypass earlier steps. A good-faith whistleblower report (Board & Governance Policy) never itself triggers discipline.\n4.8 On termination, or a role change removing the need for current access, system access shall be revoked within 24 hours and all assets returned per the offboarding checklist, with an exit debrief confirming confidentiality, IP-assignment, and non-disclosure obligations survive termination.\n4.9 Critical knowledge for key technical roles shall be documented (runbooks, access procedures, architecture notes) and shared with at least one other qualified person - ordinarily spanning Engineering and DevOps, with Tidewell Advisory Group's vCISO able to surge - so no single departure stops incident response or recovery. Coverage is reviewed annually.\n4.10 Contractor and firm-provided personnel parity: every individual granted access to production systems, source code, or customer data - employee, fractional worker, contractor, or Tidewell Advisory Group-provided personnel alike - completes the identical personnel security package before access is granted: a signed NDA with IP assignment, a background check from an authorized provider, a signed Acceptable Use Policy acknowledgment, completed security awareness training, and an endpoint compliance attestation (or enrollment of a company-managed device). Employment status is never a basis for a reduced baseline; granting access ahead of a completed package is a policy violation and a control failure.\n\n## 5. Exceptions\nA deviation from this policy - e.g., an accelerated start date ahead of a cleared background check - requires documented justification, a risk assessment, and CEO approval with a compensating control and a time-bound review date, logged and revisited at the next management review. None may waive Statement 4.2's confidentiality-agreement requirement.\n\n## 6. Enforcement\nNon-compliance is addressed through the disciplinary process in Statement 4.7. Compliance is monitored via training-completion tracking, background-check documentation, and offboarding-checklist rates, reported quarterly to management and the Independent Governance Advisor; a violation constituting a security event is also handled under the Incident Response Policy.\n\n## 7. Review & Ownership\nOwner: CEO (Tidewell Advisory Group administers day-to-day HR operations). Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Acceptable Use Policy (onboarding acknowledgment); Board & Governance Policy (whistleblower channel); Incident Response Policy; Business Continuity & Disaster Recovery Policy (key-role continuity, Statement 4.9); Vendor Management Policy (Tidewell Advisory Group as critical subservice).\nGoverns controls: A.6.1 - Screening; A.6.2 - Terms and conditions of employment; A.6.3 - Information security awareness, education and training; A.6.4 - Disciplinary process; A.6.5 - Responsibilities after termination or change of employment; A.6.6 - Confidentiality or non-disclosure agreements; CC1.4 - The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives; CC1.5 - The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives; Annual performance and conduct evaluation per personnel.\nOperated by: the onboarding/offboarding cycle and the annual training-and-evaluation cycle described in Statements 4.1–4.9.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["human_resources_personnel_security","governance_policy_oversight","awareness_training"],"review_frequency":"annual","effective_date":"2026-04-13","next_review_date":"2026-12-25"}},{"title":"ISMS Scope Document","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"This document defines the scope of the Bluth Company Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022 Clause 4.3, establishing the boundaries and applicability of the ISMS.","full_description":"# ISMS Scope Document\n\n## 1. Purpose\nThis document defines the scope of the Bluth Company Information Security Management System (ISMS) per ISO/IEC 27001:2022 Clause 4.3, establishing the services, locations, personnel, technology, and exclusions to which the ISMS - and the SOC 2 and ISO 27001 control set built on it - applies.\n\n## 2. Scope Definition\n**Services:** the Bluth Company core web application, the MCP server that exposes Bluth Company data to AI agents, the agent chat interface, the authentication proxy service, and the supporting Model Home Data Lake infrastructure that develops, deploys, and operates them - covered end to end from design through production operation.\n\n**Locations:** Bluth Company is a fully remote-first company with no owned or leased office; personnel work from home offices and incidental remote locations. There is no Bluth Company-controlled physical facility in scope. Physical data-center security is inherited from Model Home Data Lake as Bluth Company's primary infrastructure provider and a critical subservice organization (see Physical Security Policy and Vendor Management Policy).\n\n**Personnel:** all employees, contractors, and third-party service providers who develop, operate, or support Bluth Company services - engineering, operations, security, management, and support functions - are in scope, regardless of employment classification.\n\n**Technology:** Model Home Data Lake (Cloud SQL, the Model Home compute tier, Cloud Storage, IAM, Cloud KMS) under a single-tenant-per-customer architecture in which each customer's data is isolated to its own Model Home Data Lake project and Cloud SQL database; application source repositories and CI/CD tooling (Model Home Data Lake, Model Home Data Lake CI, Cloud Build, Terraform); Lucille Identity Cloud for identity (OIDC SSO), email, and file storage; and Model Home Data Lake Secret Manager for secrets and credential management. There is no billing platform and no chat platform in scope: subscription billing is not yet operated, and operational communication and alerting run through Lucille Identity Cloud email groups and Cloud Monitoring notification channels.\n\n**Exclusions:** physical data-center infrastructure, delegated to Model Home Data Lake under the shared-responsibility model (the Cloud Services Security Policy documents the boundary); the bluth.example marketing and landing site, which holds no customer data or authentication surface; and sales/marketing activity that does not touch production systems or customer data.\n\n## 3. Interfaces & Dependencies\nThe ISMS interfaces with Model Home Data Lake as the primary infrastructure provider and a critical subservice organization; with customer organizations as data controllers under their subscription agreements; and with the other critical subservice organizations - Lucille Identity Cloud, Model Home Data Lake, and the Tidewell Advisory Group vCISO firm - managed through vendor risk assessment and contractual controls under the Vendor Management Policy. This scope statement reflects Bluth Company's actual organizational structure and remote-first operating model, and is the boundary condition against which risk identification and assessment under the Risk Management Policy is performed. A change to any in-scope service, technology, or interface is evaluated for ISMS-scope impact through the Change Management Policy and reflected here at the next scheduled review.\n\n## 4. Review & Ownership\nOwner: Security Lead. Review cadence: annually, and immediately following a significant change to the organization, technology, services, or regulatory environment, via management review.","policy_type":"standard","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["soc2"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-04-13","next_review_date":"2026-12-26"}},{"title":"Incident Response Policy","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"This policy establishes a structured approach for detecting, responding to, and recovering from security incidents to minimize damage and reduce recovery time and costs.","full_description":"# Incident Response Policy\n\n## 1. Purpose\nThis policy establishes a structured approach for detecting, responding to, and recovering from security incidents, so that damage, recovery time, and cost are minimized and lessons learned are fed back into the security program.\n\n## 2. Scope\nThis policy applies to all security events and incidents affecting Bluth Company production systems, customer data, corporate systems, and employee endpoints. It covers detection, classification, containment, eradication, recovery, external notification, and post-incident review.\n\n## 3. Roles & Responsibilities\nThe Security Lead serves as the default incident commander and maintains the incident response plan. Engineering on-call personnel perform initial triage. The CEO makes customer-notification decisions for significant incidents and, with legal counsel, is the point of contact for external authorities. The on-call rotation is administered by the CEO, with Tidewell Advisory Group's vCISO function facilitating post-mortems for P0/P1 incidents. All personnel are responsible for reporting suspected events.\n\n## 4. Policy Statements\n4.1 All personnel report suspected security events immediately through established channels: email to michael.bluth@bluth.example or its short alias michael.bluth@bluth.example - both monitored Lucille Identity Cloud Groups with named owners, not personal mailboxes - tracked as a support_intake record and promoted to a security_incident record on triage; direct escalation to the Security Lead or CEO for time-critical events; or, for customers, the grccanvas plugin's /grc-incident-open skill. Failure to report a known incident is itself a policy violation, and these channels are Bluth Company's documented mechanism for information security event reporting.\n4.2 Incidents are classified by severity (Critical (P0), High (P1), Medium, Low, Informational) against a defined severity matrix; Critical and High severity events are escalated without delay to michael.bluth@bluth.example, a monitored group that delivers directly to the Security Lead and CEO. A reporter's self-assessed severity is a hint, not authoritative - the triage operator assesses the event and decides its classification when promoting it to a security_incident record.\n4.3 An incident commander is designated for each active incident, coordinating the response, maintaining the incident timeline, and communicating status to stakeholders.\n4.4 Contact with external authorities - law enforcement, a data-protection regulator, or a payment processor - on a security matter is made only by the Security Lead or CEO, with legal counsel; individual employees do not independently contact external authorities on Bluth Company's behalf.\n4.5 Evidence relevant to an incident - logs, timestamps, affected records, and communications - is preserved from the point of detection, via the immutable Cloud Audit Logs sink and the incident record's attachments, and is not altered or deleted pending investigation closure.\n4.6 Post-mortem reviews are completed within five business days of incident resolution, documenting root cause, timeline, containment actions, and concrete remediation items; Tidewell Advisory Group's vCISO function facilitates the post-mortem for P0/P1 incidents.\n4.7 Customer notification is assessed for every incident involving potential data exposure; notifications are made within contractual and regulatory timeframes, with legal counsel involved for incidents affecting personal information.\n4.8 An on-call rotation, backed by Cloud Monitoring alerting policies delivering to the monitored on-call Lucille Identity Cloud Group, covers all personnel with production-system or customer-data access. Severity definitions and committed response times are reconciled at least quarterly against signed customer MSAs; if a contract commits to a response time the rotation cannot deliver, either the rotation is upgraded or the contract is renegotiated.\n4.9 The incident response plan is tested at least annually through a tabletop exercise facilitated by Tidewell Advisory Group. Incident metrics - detection time, response time, and resolution time - and an annual incident-trend summary are reported quarterly to management and the Independent Governance Advisor.\n\n4.10 The system of record for security incidents is the Bluth Company platform itself: every declared incident is recorded as a Security Incident item in the Bluth Company system of record, carrying the reporter, channel, detection time, severity classification, incident commander, timeline, containment and eradication actions, evidence attachments, and closure date, and it is tracked there through to resolution. Engineering remediation work arising from an incident is mirrored as Model Home Data Lake issues linked from the incident record; the incident record, not the Model Home Data Lake issue, is authoritative for status and closure. The public reporting routes - michael.bluth@bluth.example and michael.bluth@bluth.example on bluth.example and the support page at docs.bluth.example - are published so that customers and other external parties can report failures, incidents, concerns, and complaints, and they deliver to the same monitored groups as the internal channels in Statement 4.1.\n\n## 5. Exceptions\nWhere a specific step of this policy cannot be followed for a given incident (for example, an incident commander outside the default rotation), the Security Lead documents the deviation and the compensating action taken, and includes it in the post-mortem record.\n\n## 6. Enforcement\nFailing to report a known incident, or bypassing the severity-escalation or evidence-preservation requirements, is a policy violation handled per the Human Resources Security Policy's disciplinary process. Compliance is monitored through incident-record completeness, the five-business-day post-mortem SLA, and the quarterly metrics reported to management.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Business Continuity & Disaster Recovery Policy; Change Management Policy; Vulnerability & Patch Management Policy; Legal & Regulatory Compliance Policy.\nGoverns controls: A.5.5 - Contact with authorities; A.5.24 - Information security incident management planning and preparation; A.5.25 - Assessment and decision on information security events; A.5.26 - Response to information security incidents; A.5.27 - Learning from information security incidents; A.5.28 - Collection of evidence; A.6.8 - Information security event reporting; CC7.3; CC7.4; Incident reporting channels documented and communicated.\nOperated by: the incident response process.","policy_type":"policy","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["incident_management_response","governance_policy_oversight","logging_monitoring_detection"],"review_frequency":"annual","effective_date":"2026-05-11","next_review_date":"2026-12-27"}},{"title":"Information Security Objectives","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"This document establishes measurable information security objectives for Bluth Company in accordance with ISO/IEC 27001:2022 Clause 6.2. Objectives are consistent with the information security policy and provide a basis for measuring ISMS performance.","full_description":"# Information Security Objectives\n\n## 1. Purpose\nThis document establishes measurable information security objectives for Bluth Company per ISO/IEC 27001:2022 Clause 6.2. The objectives are consistent with the Information Security Policy and give the ISMS a concrete basis - metric, target, owner, and monitoring cadence per objective - for measuring whether the program is actually working, not just whether it is documented.\n\n## 2. Security Objectives\n1. **Zero customer data breaches.** Metric: number of confirmed data breaches involving customer data. Target: 0 for the assessment period. Owner: Security Lead (CEO-held). Monitored: continuously, through the incident-tracking process defined in the Incident Response Policy.\n2. **99.5% production uptime.** Metric: percentage uptime measured monthly across production services. Target: 99.5%, matching Bluth Company's customer-facing availability commitment. Owner: Head of Engineering. Monitored: monthly, through automated uptime monitoring and reporting (see Business Continuity & Disaster Recovery Policy).\n3. **100% security awareness training completion.** Metric: percentage of personnel completing required training. Target: 100% within 30 days of hire, and 100% on the annual refresh. Owner: CEO (Tidewell Advisory Group administers the training program). Monitored: quarterly, through training completion records (see Human Resources Security Policy).\n4. **Vulnerability remediation SLA.** Metric: mean time to remediate by severity. Target: critical vulnerabilities remediated within 7 days, high within 30 days. Owner: Head of Engineering / Security Lead. Monitored: continuously, through the vulnerability-tracking process (see Vulnerability & Patch Management Policy).\n5. **100% on-time access reviews.** Metric: percentage of scheduled access reviews completed by their due date, with zero overdue. Target: 100%. Owner: Security Lead. Monitored: quarterly, through access-review records (see Access Control Policy).\n\n## 3. Planning, Measurement & Integration\nEach objective has a designated owner, the resources needed to pursue it, an implementation timeline where applicable, and a defined method for evaluating results - consistent with how the objective's home policy (referenced above) actually operates it; this document reports the target that policy already commits to rather than setting a competing number. Progress toward all five objectives is reported together in the monthly security metrics package and reviewed during the quarterly management review, where objectives are weighed alongside the current risk register so that objective-setting and risk assessment inform one another instead of running as two disconnected exercises. These objectives are integrated into ordinary business planning: owner-level activities that support them are identified and tracked alongside other business goals, not treated as a separate compliance track.\n\n## 4. Review & Ownership\nOwner: CEO. Review cadence: annually, during the management review process; objectives may be updated based on business need, risk assessment results, audit findings, or management direction, with any change requiring CEO approval.","policy_type":"standard","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"1.0","framework":["soc2"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-06-08","next_review_date":"2026-12-28"}},{"title":"Information Transfer & Leakage Prevention Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"This policy establishes rules and procedures for securely transferring information to protect against unauthorized disclosure, modification, or loss during transit.","full_description":"# Information Transfer & Leakage Prevention Policy\n\n## 1. Purpose\nThis policy establishes how Bluth Company transfers information securely between systems, personnel, customers, and vendors, and how it prevents and detects unauthorized disclosure or exfiltration of sensitive data. It does not assume any particular data-loss-prevention product; Bluth Company achieves these outcomes through approved channels, authorization-and-logging controls on export paths, and code-review practice.\n\n## 2. Scope\nThis policy covers every method by which information moves into, out of, or within Bluth Company systems: email, file sharing, API integrations, database exports, removable media, source-code repositories, and verbal or physical communication. It applies to transfers between Bluth Company and customers, vendors, and partners, and between internal systems, and to every Bluth Company and Tidewell Advisory Group individual with access to Confidential or Restricted data.\n\n## 3. Roles & Responsibilities\nThe Security Lead defines approved transfer channels, maintains data processing agreements (DPAs) with recipients of customer data, and investigates suspected leakage. The Head of Engineering ensures automated data flows between systems use encrypted, authenticated channels and that bulk-export paths in the product are access-controlled and logged. All personnel use only approved channels for Confidential or Restricted data and follow the source-code handling rule in Policy Statement 4.5.\n\n## 4. Policy Statements\n4.1 Confidential or Restricted information is transferred only by an approved secure method: encrypted email, SFTP/SCP, an HTTPS API endpoint, or an approved cloud file-sharing service with access controls. Unencrypted channels are not used for Confidential or Restricted data.\n4.2 Transfer of customer data to a third party requires an executed data processing agreement beforehand and is limited to the minimum data necessary for the stated purpose; customer data is not transferred to a location or service that has not been approved through the Vendor Management Policy's assessment process.\n4.3 Automated data transfers between systems use encrypted, authenticated protocols (TLS 1.2+, SSH); credentials and API keys used for transfer are managed per the Password & Authentication Policy and the Encryption Policy.\n4.4 A bulk data export of Confidential or Restricted data requires authorization from the data owner and is logged for audit purposes; the product's export features are built so that a large or full-dataset export is attributable to an authenticated, authorized user.\n4.5 Source code and internal materials are not posted to a public repository, a public forum, or a general-purpose AI chat interface without review for sensitive content - credentials, internal URLs, or customer data. This review requirement applies regardless of whether the destination is a code-hosting platform or a generative-AI tool, and is reinforced by the Acceptable Use Policy and the AI Governance & Acceptable AI Use Policy.\n4.6 Use of removable media or unapproved personal cloud storage for Confidential or Restricted data is restricted; where removable media use is unavoidable, it is encrypted, labelled with its classification, tracked, and requires Security Lead approval.\n4.7 A physical transfer of Confidential or Restricted information, where unavoidable, uses a secure courier with recipient acknowledgment; a transfer agreement with a recurring counterparty documents the parties, data categories, transfer method, and security measures, and is reviewed annually.\n4.8 A suspected or confirmed instance of unauthorized disclosure or exfiltration - however discovered - is handled as a security incident under the Incident Response Policy, with containment and, where personal data is involved, coordination with the Privacy Policy's breach-notification requirements.\n4.9 Email sent as bluth.example is authenticated at the domain level: SPF, DKIM, and DMARC records are published in DNS and maintained under the Change Management Policy, and DMARC aggregate reports are delivered to the monitored michael.bluth@bluth.example group and reviewed for evidence of spoofing or unauthorized senders.\n4.10 Product transactional email - password-reset and account-invitation links - is sent only from the dedicated michael.bluth@bluth.example account over the authenticated Lucille Identity Cloud SMTP relay (TLS in transit, 2-Step Verification on the account, and an app-scoped credential held in Model Home Data Lake Secret Manager, never in source code or plain service configuration). The account is single-purpose: it is not used for human correspondence, and a message never contains a credential - only a single-use link governed by the Password & Authentication Policy.\n4.11 External role addresses - michael.bluth@bluth.example, security-incident@ (alias incident@), privacy@, and feedback@ - are implemented as monitored Lucille Identity Cloud Groups with named owners rather than personal mailboxes, so each intake channel survives personnel change; their purposes are defined in this policy, the Incident Response Policy, and the Privacy Policy.\n\n## 5. Exceptions\nA request to use a non-approved transfer method is submitted to the Security Lead, includes the business justification and a compensating control (for example, manual encryption or a one-time DPA), and is time-bound and logged for review.\n\n## 6. Enforcement\nAn unapproved transfer method is blocked where technically feasible and treated as a policy violation where it is not; confirmed leakage is escalated as a security incident. Compliance is verified through review of outbound transfer logs, DPA inventory checks, and audit of transfer-method configuration.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Data Classification & Handling Policy; Vendor Management Policy; Password & Authentication Policy; Encryption Policy; Acceptable Use Policy; AI Governance & Acceptable AI Use Policy; Incident Response Policy; Privacy Policy. Offsite backup replication is addressed by the Backup & Recovery Policy, not this policy.\nGoverns controls: A.5.14 - Information transfer; A.8.12 - Data leakage prevention; CC6.7 - The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives; SOC1-6 - Data transmission / interface controls: controls provide reasonable assurance that data transmitted to and from the system and across interfaces is complete, accurate, authorized, and timely.\nOperated by: transfer and export controls are embedded in product access controls and vendor onboarding; no single dedicated operational workflow exists for this policy area.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["iso-27001","soc1","soc2"],"domains":["asset_management_inventory","cryptography_key_management","data_protection_privacy"],"review_frequency":"annual","effective_date":"2026-02-09","next_review_date":"2026-12-29"}},{"title":"Internal Audit Program","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"This document establishes the internal audit program for evaluating the conformity and effectiveness of the Bluth Company ISMS in accordance with ISO/IEC 27001:2022 Clause 9.2.","full_description":"# Internal Audit Program\n\n## 1. Purpose\nThis document establishes Bluth Company's internal audit program under ISO/IEC 27001:2022 Clause 9.2. It produces objective, evidence-based assurance that the ISMS conforms both to Bluth Company's own requirements and to the standards it claims (ISO 27001, SOC 2), and that the ISMS is effectively implemented and maintained - not merely documented.\n\n## 2. Scope\nThis program covers every ISMS process and control across all services, technology, and personnel defined in the ISMS Scope Document, audited over a rolling cycle that does not exceed 12 months, so the full ISMS is covered at least once a year.\n\n## 3. Procedure Steps\n3.1 The Security Lead, with the Tidewell Advisory Group vCISO facilitating, maintains a 12-month internal audit plan covering every ISO 27001 clause and control domain in scope. Planning weighs process importance, prior-audit results, and current risk-register findings, so higher-risk areas are sampled more often than lower-risk ones.\n\n3.2 Auditors are selected for independence and objectivity: no auditor audits their own work or a process for which they hold ongoing operational responsibility. Because Bluth Company is a small team, the Tidewell Advisory Group vCISO - an outsourced firm with no line role in any audited process - conducts or facilitates the substantive audit work in place of a dedicated internal-audit function, satisfying the independence intent of A.5.35 without requiring headcount Bluth Company doesn't have.\n\n3.3 For each audit, the scope, criteria (the specific policy, procedure, and ISO clause under test), method (document review, interview, technical sampling), and reporting requirements are defined and recorded before fieldwork starts. Every audit evaluates both conformity - does practice match documented policy - and effectiveness - does the control actually achieve its intended outcome - which together is how the program evidences A.5.36 compliance review.\n\n3.4 Auditors collect and retain evidence (configuration exports, access-review records, log samples, interview notes) sufficient to support each finding. Where testing touches production systems, the auditor coordinates with the Head of Engineering beforehand so testing does not degrade system availability or integrity (A.8.34).\n\n3.5 Findings are classified as a major nonconformity, minor nonconformity, or opportunity for improvement, and logged in the Bluth Company platform issue tracker with an assigned owner, a root-cause note, and a target remediation date. Nonconformities are handed to the Nonconformity & Corrective Action Procedure for disposition.\n\n3.6 The audit report is delivered to the Security Lead and the CEO within 10 business days of fieldwork completion. Unresolved findings and overdue corrective actions are escalated at the next quarterly management review so the CEO - and, where material, the Independent Governance Advisor - has visibility into open audit risk.\n\n## 4. Records & Evidence\nThe rolling 12-month audit plan and schedule; per-audit scope, criteria, and method records; auditor-independence notes; the evidence collected for each audit; issue-tracker entries for every finding with its classification and disposition; the delivered audit report for each cycle; and the annual review record assessing the program's own effectiveness.\n\n## 5. Review & Ownership\nOwner: Security Lead (Tidewell Advisory Group vCISO facilitates execution). Review cadence: the program is reviewed annually for effectiveness; the underlying audit cycle it governs runs no less often than every 12 months.","policy_type":"procedure","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["iso-27001"],"domains":["compliance_audit_assurance","governance_policy_oversight","secure_development_sdlc"],"review_frequency":"annual","effective_date":"2026-03-09","next_review_date":"2026-12-30"}},{"title":"Legal & Regulatory Compliance Policy","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"This policy ensures that Bluth Company identifies, documents, and complies with all legal, statutory, regulatory, and contractual requirements relevant to information security and data protection.","full_description":"# Legal & Regulatory Compliance Policy\n\n## 1. Purpose\nThis policy ensures Bluth Company identifies, documents, and complies with the legal, statutory, regulatory, and contractual requirements relevant to information security and data protection.\n\n## 2. Scope\nThis policy covers all applicable laws, regulations, standards, and contractual obligations in the jurisdictions where Bluth Company operates, including data protection law, industry regulation, export control, intellectual property, and customer contractual security requirements.\n\n## 3. Roles & Responsibilities\nExternal legal counsel identifies applicable laws and regulations and advises on compliance requirements. The Security Lead maintains the requirements register and maps requirements to their implementing controls. The CEO approves compliance implementation plans and budgets.\n\n## 4. Policy Statements\n4.1 A legal and regulatory requirements register shall be maintained, identifying all applicable legal, statutory, regulatory, and contractual requirements related to information security and data protection; the register shall be reviewed quarterly and updated whenever a new requirement is identified.\n4.2 Intellectual property rights shall be respected and protected; software licensing compliance shall be maintained through the asset inventory, and open-source software usage shall comply with its license terms and be tracked in dependency manifests.\n4.3 Business records shall be protected from loss, destruction, falsification, and unauthorized access in accordance with legal retention requirements, coordinated with the Data Retention & Disposal Policy so records remain available for regulatory or legal purposes.\n4.4 Contractual security requirements from customer agreements shall be identified, documented, and mapped to their implementing controls; compliance with customer security requirements shall be verified during periodic reviews.\n4.5 Regulatory change - in data protection law, industry regulation, export control, or other applicable law - shall be monitored and its impact assessed; an implementation plan shall be developed for each new requirement with sufficient lead time to achieve compliance by its effective date.\n4.6 Data-protection and privacy-specific regulatory obligations, including GDPR and CCPA, are addressed principally in the Privacy Policy; this policy's requirements register tracks their existence and review cadence without duplicating the Privacy Policy's substantive commitments.\n\n## 5. Exceptions\nWhere full compliance with a new requirement cannot be achieved by its effective date, a documented remediation plan with interim compensating measures shall be approved by the CEO and tracked as a risk in the risk register until closed.\n\n## 6. Enforcement\nCompliance with this policy is monitored through the quarterly requirements-register review, quarterly compliance reviews against Bluth Company's policies and standards, and the annual Internal Audit Program, including its independent-review component. Gaps identified through any of these are tracked as compliance risks with treatment plans under the Risk Management Policy, and findings are tracked to remediation with management oversight under the Nonconformity & Corrective Action Procedure. Recurring or willful non-compliance is addressed under the Human Resources Security Policy's disciplinary provisions.\n\n## 7. Review & Ownership\nOwner: Security Lead (external legal counsel advises). Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually. The requirements register itself is reviewed quarterly.\n\n## 8. Related Documents & Controls\nRelated policies: Privacy Policy, Data Retention & Disposal Policy, Risk Management Policy, Vendor Management Policy, Internal Audit Program.\nGoverns controls: A.5.31 (Legal, statutory, regulatory and contractual requirements), A.5.32 (Intellectual property rights), A.5.33 (Protection of records).\nOperated by: finding remediation and action-plan monitoring.","policy_type":"policy","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["compliance_audit_assurance","governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-05-11","next_review_date":"2026-12-31"}},{"title":"Logging & Monitoring Policy","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"This policy establishes requirements for logging, monitoring, and alerting to ensure security events are detected, audit trails are maintained, and management has visibility into the security posture of the organization.","full_description":"# Logging & Monitoring Policy\n\n## 1. Purpose\nThis policy establishes requirements for logging, monitoring, and alerting so that security events are detected, a tamper-resistant audit trail is maintained, scheduled operational jobs are verified, and management has ongoing visibility into the effectiveness of Bluth Company's internal controls.\n\n## 2. Scope\nThis policy covers logging and monitoring from production applications, Model Home Data Lake infrastructure (Cloud Logging, Cloud Monitoring, Cloud Audit Logs), Lucille Identity Cloud, Model Home Data Lake, and Cloud SQL, together with the scheduled and automated jobs - backups and batch processing - that run against them. It applies to both automated alerting and management's periodic evaluation of control effectiveness.\n\n## 3. Roles & Responsibilities\nThe Security Lead defines logging and monitoring requirements and monitoring rules, and reviews alerts and control-effectiveness evaluations. DevOps implements log collection, aggregation, retention, and the immutable log sink. Engineering ensures applications emit required log events. Management reviews monthly security metrics and open control deficiencies.\n\n## 4. Policy Statements\n4.1 All production systems generate audit logs capturing authentication events, authorization decisions, data access, administrative actions, and configuration changes, each with a timestamp, the user or service identity, the action performed, the target resource, and the outcome.\n4.2 Cloud Audit Logs are enabled organization-wide and routed to a dedicated, access-restricted logging Model Home Data Lake project - an immutable log sink - that the personnel and systems being logged cannot modify or delete. Application and infrastructure audit logs are retained for a minimum of one year, and the immutable sink is retained for seven years to support management-override review and historical investigation.\n4.3 Security-relevant events are monitored continuously with automated alerting for suspicious patterns, including failed authentication attempts, privilege escalation, unauthorized access attempts, and anomalous data-access patterns, and more broadly for anomalies indicative of malicious acts, natural disasters, or errors that could affect Bluth Company's ability to meet its service commitments.\n4.4 Scheduled and automated processing, including database backups and batch data jobs, is monitored for successful completion; failures or exceptions generate an alert and are tracked to resolution.\n4.5 System performance, security events, and incidents are monitored on an ongoing basis, with defined escalation into the Incident Response Policy when a monitored condition indicates a possible incident.\n4.6 The Security Lead performs a periodic evaluation of whether logging, monitoring, and related security controls are present and operating as designed, independent of routine alert triage.\n4.7 Control deficiencies identified through monitoring or evaluation are communicated in a timely manner to management - and, where the deficiency has governance-level significance, to the Independent Governance Advisor - and are tracked in the compliance register with an assigned owner, a target remediation date, and progress updates until closed.\n4.8 Security metrics and key performance indicators - incident counts, mean time to detect, mean time to respond, control-effectiveness scores, and open vulnerability counts - are reported to management at least monthly.\n4.9 Tenant-operations activity is specifically evidenced and monitored: every operation run writes a redacted, checksummed evidence bundle to a retention-locked bucket; automated alerting covers failed operations jobs, operations-dispatcher errors, and operations stuck beyond defined thresholds; and a monthly reconciliation and audit report reconciles the fleet registry against live Model Home Data Lake projects, the platform-administrator roster against IAM grants, every mutating operation against its workflow reference and approval lineage, and evidence-bundle completeness - with each finding dispositioned by management in the operating workflow.\n\n## 5. Exceptions\nA request to reduce logging scope or retention for a specific system - for example, a low-risk internal tool - is submitted to the Security Lead, risk-assessed, and approved only where a compensating control offsets the reduced visibility. Exceptions are recorded with an owner and a review date and are reassessed at least annually.\n\n## 6. Enforcement\nGaps in required logging coverage are treated as security findings and remediated on a defined timeline. Disabling, tampering with, or circumventing logging or the immutable sink is treated as a policy violation under the Human Resources Security Policy and, where it affects the integrity of an audit trail, as a security incident under the Incident Response Policy. Logging completeness is verified through periodic checks that all in-scope systems emit logs to the central platform; monitoring-rule effectiveness is assessed during incident post-mortems and quarterly reviews.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Configuration Management Policy (clock synchronization underpinning accurate event correlation); Incident Response Policy; Vulnerability & Patch Management Policy (scan-result and metrics reporting cadence).\nGoverns controls: A.8.15, A.8.16, CC4.1, CC4.2, CC7.2, SOC1-4, SOC1-11; Model Home Data Lake audit logging & monitoring (Cloud Audit Logs); Lucille Identity Cloud authentication & admin-event logging; Model Home Data Lake audit logging of changes & approvals; Cloud SQL query & access audit logging; Immutable Cloud Audit Logs sink for management-override compensation; Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies).\nOperated by: the corresponding continuous-monitoring workflow in the Bluth Company workflow library.","policy_type":"policy","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["logging_monitoring_detection","risk_assessment_management","business_continuity_disaster_recovery"],"review_frequency":"annual","effective_date":"2026-06-08","next_review_date":"2027-01-01"}},{"title":"Management Review Procedure","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"This document establishes the management review process for the Bluth Company ISMS in accordance with ISO/IEC 27001:2022 Clause 9.3, ensuring that senior management regularly evaluates the ISMS for continuing suitability, adequacy, and effectiveness.","full_description":"# Management Review Procedure\n\n## 1. Purpose\nThis document establishes the management review process for the Bluth Company ISMS under ISO/IEC 27001:2022 Clause 9.3, so senior management - in practice, the CEO - regularly evaluates the ISMS's continuing suitability, adequacy, and effectiveness, and makes the resourcing, risk-acceptance, and policy decisions the ISMS needs in order to keep working.\n\n## 2. Scope\nThis procedure covers the standing quarterly review of the full ISMS. Additional ad hoc reviews are triggered by a P0/P1 security incident, a major organizational change, or an audit finding serious enough to require immediate management attention.\n\n## 3. Procedure Steps\n3.1 The CEO convenes a management review at least quarterly, aligned to the governance cadence the Board & Governance Policy defines. The Tidewell Advisory Group vCISO facilitates by preparing the input packet and drafting the minutes.\n\n3.2 Every review consumes a standing set of inputs: the status of action items from the prior review; changes in external or internal issues relevant to the ISMS (threat landscape, regulatory, organizational); performance metrics, including incident trend analysis, vulnerability remediation times, training completion, uptime, and control-effectiveness scores; the results of internal and external audits; and the current risk-register and risk-treatment status, including any risk that requires an executive acceptance decision.\n\n3.3 Incident trend analysis is a standing agenda item, not an occasional one: summarizing counts, severities, and recurring root causes from the preceding quarter lets the review surface a systemic fix instead of only closing out each incident individually.\n\n3.4 The review produces documented outputs: decisions on ISMS improvement opportunities, handed to the Continual Improvement Process; resource-allocation decisions covering budget, personnel, and tooling; risk-acceptance decisions for risks that cannot be further mitigated within acceptable cost, per the Risk Management Policy; and any policy or objective change needed to reflect evolving business or regulatory needs.\n\n3.5 Minutes are recorded for every review - attendees, topics, decisions, and action items with owners and due dates. Open action items carry forward onto the standing input list (Step 3.2) for the next review, so the loop closes and the review stays fed by current information rather than working from a stale snapshot.\n\n3.6 Internal-control deficiencies identified since the last review are checked for how promptly they reached the CEO (and, for material items, the Independent Governance Advisor), and are tracked to closure or to a formal, documented risk-acceptance decision - they are not allowed to simply age out.\n\n## 4. Records & Evidence\nQuarterly management review minutes; the standing input packet for each review (metrics, audit results, risk-register extract, incident trend summary); the action-item log with owner, due date, and status; and documented risk-acceptance decisions arising from review.\n\n## 5. Review & Ownership\nOwner: CEO. Review cadence: this procedure is reviewed annually; the management review it describes is conducted no less often than quarterly.","policy_type":"procedure","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["soc2"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-01-12","next_review_date":"2027-01-02"}},{"title":"Network Security Policy","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"This policy defines requirements for securing network infrastructure and communications to protect Bluth Company services and data from network-based attacks and unauthorized access.","full_description":"# Network Security Policy\n\n## 1. Purpose\nThis policy defines requirements for securing network infrastructure, network communications, and internet-facing or outbound network activity, to protect Bluth Company services and data from network-based attacks, unauthorized access, and malicious or risky web content.\n\n## 2. Scope\nThis policy covers all network infrastructure in the Model Home Data Lake production environment - Virtual Private Cloud (VPC) networks, firewall rules, Cloud Load Balancing, Cloud Armor, Cloud DNS, and Cloud NAT - together with outbound internet access from production systems and web-browsing activity on corporate endpoints. Bluth Company is a remote-first company with no traditional office network or on-premises network appliances; \"network security\" here means the Model Home Data Lake VPC boundary and endpoint network behavior, not physical network hardware.\n\n## 3. Roles & Responsibilities\nDevOps configures and maintains VPC network topology, firewall rules, Cloud Armor policies, and production egress rules. The Security Lead reviews network and filtering configurations quarterly and after significant changes, and approves filtering exceptions. Engineering designs services to operate within the defined network segmentation. All personnel keep endpoint anti-malware protection active and comply with web-filtering rules.\n\n## 4. Policy Statements\n4.1 Network segmentation isolates production, staging, and development environments in separate VPC networks and Model Home Data Lake projects. Production VPC firewall rules follow a default-deny approach, explicitly allowing only required traffic on required ports; broad allow rules (for example, all traffic from 0.0.0.0/0) are prohibited.\n4.2 Firewall and VPC configuration changes follow the Change Management process. Public-facing services are minimized and, where applicable, fronted by Cloud Armor web-application-firewall rules.\n4.3 Corporate endpoints run OS-native anti-malware and endpoint protections - macOS XProtect and Gatekeeper, Microsoft Defender on Windows - with automatic updates enabled; Bluth Company operates no separately procured, centrally managed anti-malware product. Coverage is verified through the endpoint compliance attestation and configuration audits (Human Resources Security Policy; Remote Working & Clear Desk Policy 4.12), Lucille Identity Cloud managed-browser Safe Browsing policies protect endpoint web activity, and production workloads rely on Model Home Data Lake-native workload security together with Model Home Data Lake CI dependency and container scanning of built artifacts.\n4.4 Outbound network access from production systems is restricted to documented destinations only; unrestricted outbound internet access from production infrastructure is prohibited, and the allow-list of destinations is reviewed quarterly.\n4.5 Web content reaching corporate endpoints is filtered to block known-malicious and phishing sites and categories of content that pose security risk, such as malware distribution or command-and-control domains. Files downloaded from the internet are scanned for malware before execution, and browser security settings are configured to warn on or block potentially dangerous file types.\n4.6 Exceptions to firewall, egress, or web-filtering rules require documented business justification and Security Lead approval, are time-limited, and are reviewed for continued necessity.\n4.7 Firewall and web-filtering logs are retained and available for security investigation. Repeated attempts to reach blocked destinations are investigated as potential indicators of compromise or policy violation, per the Logging & Monitoring Policy.\n4.8 Network infrastructure and filtering configurations are reviewed at least quarterly for unnecessary rules, open ports, deprecated services, and filtering-coverage gaps.\n\n## 5. Exceptions\nSee Statement 4.6 for firewall, egress, and web-filtering exceptions specifically. For any other deviation from this policy, a request is submitted to the Security Lead, risk-assessed, and approved only once a compensating control is identified; exceptions are recorded with an owner and a review date and are reassessed at least annually.\n\n## 6. Enforcement\nNon-compliant network or filtering configurations are remediated within a defined SLA from discovery. Circumventing network controls or filtering rules without an approved exception is a policy violation handled under the Human Resources Security Policy; confirmed network-based attacks or compromise are handled under the Incident Response Policy. Compliance is verified through automated firewall-rule scanning, review of the endpoint compliance attestations, and the quarterly configuration review.\n\n## 7. Review & Ownership\nOwner: Security Lead / DevOps. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Encryption Policy (encryption of data in transit across these network boundaries); Change Management Policy (firewall and network change control); Logging & Monitoring Policy (filtering and firewall log retention); Incident Response Policy.\nGoverns controls: A.8.7, A.8.20, A.8.21, A.8.22, A.8.23, CC6.6, CC6.8; Model Home Data Lake network segmentation & firewall control; Anti-malware / endpoint protection deployed on personnel endpoints.\nOperated by: the corresponding network-configuration and secure-baseline workflows in the Bluth Company workflow library.","policy_type":"policy","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["network_communications_security","vulnerability_patch_management","secure_configuration_change_management"],"review_frequency":"annual","effective_date":"2026-02-09","next_review_date":"2027-01-03"}},{"title":"Nonconformity & Corrective Action Procedure","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"This document establishes the process for identifying, documenting, and correcting nonconformities in the Bluth Company ISMS in accordance with ISO/IEC 27001:2022 Clause 10.2.","full_description":"# Nonconformity & Corrective Action Procedure\n\n## 1. Purpose\nThis procedure defines how Bluth Company identifies, documents, and corrects nonconformities in the ISMS in accordance with ISO/IEC 27001:2022 Clause 10.2, and is the mechanism by which internal control deficiencies identified through monitoring, audit, or incident review are evaluated and remediated.\n\n## 2. Scope\nThis procedure applies to every nonconformity identified through internal audit, external audit, incident investigation, management review, employee reporting, or control testing, across all ISMS processes and controls. It is distinct from routine incident handling under the Incident Response Policy: a nonconformity is a failure of the ISMS itself (a missing, broken, or bypassed process or control), whereas an incident is a security event; a security incident may surface a nonconformity that is then handled here in parallel.\n\n## 3. Procedure Steps\n3.1 Identification & Logging - Whoever identifies a nonconformity (auditor, employee, or control owner) logs it as an issue item in Bluth Company, referencing the ISMS process or control affected so trends can later be traced to a specific area of the management system. [Any personnel]\n3.2 Immediate Reaction - Containment action is taken where necessary to limit impact and address the immediate consequence before the underlying cause is fully understood. [Control/System Owner]\n3.3 Root Cause Analysis - A root cause analysis is performed, proportionate to the nonconformity's severity, to determine why it occurred and whether similar nonconformities exist or could occur elsewhere. [Security Lead]\n3.4 Corrective Action - A corrective action is determined and implemented to eliminate the root cause, addressing both the specific instance and any systemic factors identified; the action is proportionate to the nonconformity's effect. [Control/System Owner, with Security Lead]\n3.5 Classification & SLA - Nonconformities are classified Major (significant ISMS process or control failure, systemic issue) or Minor (isolated instance, limited impact); Major nonconformities are corrected within 30 days, Minor within 90 days. [Security Lead]\n3.6 Effectiveness Review - After implementation, the corrective action is reviewed to confirm the nonconformity is fully addressed and unlikely to recur; an ineffective corrective action is rejected and reworked with a revised approach. [Security Lead]\n\n## 4. Records & Evidence\nA record per nonconformity - description, classification, root cause analysis, corrective action taken, and effectiveness-review result - retained for the ISMS record-retention period; trend data summarized for Management Review; a cross-reference to any related risk-register entry or incident record where the nonconformity was identified through those channels.\n\n## 5. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually. Nonconformity trends are analyzed at each quarterly Management Review to identify systemic improvement opportunities, feeding the Continual Improvement Process.","policy_type":"procedure","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["soc2"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-03-09","next_review_date":"2027-01-04"}},{"title":"Password & Authentication Policy","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"This policy defines standards for authentication and password management to prevent unauthorized access through weak, stolen, or compromised credentials.","full_description":"# Password & Authentication Policy\n\n## 1. Purpose\nThis policy defines standards for authentication and password management to prevent unauthorized access through weak, guessed, stolen, or otherwise compromised credentials, and establishes this document as the single authority on authentication mechanisms referenced by other access policies.\n\n## 2. Scope\nThis policy applies to all authentication to Bluth Company systems, including Lucille Identity Cloud (the primary identity provider), Model Home Data Lake consoles, Model Home Data Lake, SaaS applications, and API access. It covers human user accounts, service accounts, and API keys. It defines how an identity proves itself; the Access Control Policy defines what an authenticated identity is authorized to do once it has done so.\n\n## 3. Roles & Responsibilities\nThe Security Lead defines authentication standards, configures the Lucille Identity Cloud authentication policy, and monitors compliance. DevOps manages service-account credentials and API-key rotation. Engineering implements authentication controls in application code. All personnel safeguard their credentials, enroll in multi-factor authentication, and report suspected credential compromise immediately.\n\n## 4. Policy Statements\n4.1 Lucille Identity Cloud OIDC single sign-on is the primary and preferred authentication method for Bluth Company systems that support federation, reducing password proliferation and centralizing authentication-policy enforcement.\n4.2 Multi-factor authentication is required for all access to production systems, Model Home Data Lake consoles, Model Home Data Lake, and any system holding customer data, using Lucille Identity Cloud 2-Step Verification (hardware security key/FIDO2 or authenticator-app TOTP) or an equivalent mechanism. Single-factor authentication is not permitted for any such system.\n4.3 Where a local password is used - for a system that does not support Workspace SSO - the password must be at least 12 characters using a mix of character types. Consistent with NIST SP 800-63B guidance, passwords are not subject to mandatory periodic rotation absent evidence of compromise; where a password change is required, the new password may not repeat any of the individual's last five passwords.\n4.4 Failed authentication attempts are logged and monitored. An account is temporarily locked after 10 consecutive failed attempts. Persistent or distributed failed-authentication patterns trigger a security investigation under the Logging & Monitoring Policy.\n4.5 Service accounts and API keys are managed with the same rigor as human credentials: each has a named owner, minimum necessary permissions, and is rotated at least annually. Service-account keys and API keys are stored in Model Home Data Lake Secret Manager or Cloud KMS, and are never embedded in source code.\n4.6 Credential sharing is prohibited; each individual uses unique credentials. Shared credentials are permitted only for service accounts with documented justification and a compensating control such as restricted scope or enhanced logging.\n4.7 Authentication events - successful, failed, and administrative changes to authentication configuration - are logged and retained per the Logging & Monitoring Policy.\n4.8 Credential recovery for Bluth Company product accounts uses the product's built-in reset flow: a single-use reset link valid for 24 hours, delivered by email from the dedicated transactional sender defined in the Information Transfer & Leakage Prevention Policy, with only a hash of the token stored server-side. The request endpoint is rate-limited and enumeration-safe - its response never discloses whether an account exists - and a reset never enables password login for an account that authenticates only through SSO. Where email delivery is unavailable, an administrator issues the same single-use link directly to the verified user; a password itself is never communicated over any channel.\n\n## 5. Exceptions\nA request to deviate from this policy - for example, a legacy integration that cannot support MFA - is submitted to the Security Lead, risk-assessed, and approved only with a documented compensating control (network restriction, enhanced monitoring, or a defined remediation timeline). Exceptions are recorded in the exception register with an owner and a review date and are reassessed at least annually or on system change.\n\n## 6. Enforcement\nSystems found without required MFA, or not meeting minimum password standards, are flagged for immediate remediation. Sharing credentials or circumventing authentication controls is treated as a policy violation under the Human Resources Security Policy and may result in disciplinary action up to termination. Suspected credential compromise is handled as a security incident under the Incident Response Policy. Compliance is verified through configuration audits of MFA enforcement, authentication-event monitoring, and service-account inventory review.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Access Control Policy (authorization and access lifecycle, which defers to this policy for authentication-mechanism standards); Human Resources Security Policy; Incident Response Policy; Information Transfer & Leakage Prevention Policy (transactional-email sender and domain email authentication).\nGoverns controls: A.5.17, A.8.5; Lucille Identity Cloud SSO & MFA enforcement; Lucille Identity Cloud password & authentication policy.\nOperated by: the corresponding access-provisioning workflow in the Bluth Company workflow library, to the extent it verifies MFA enrollment at onboarding.","policy_type":"policy","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"1.0","framework":["iso-27001","soc1","soc2"],"domains":["access_control_identity"],"review_frequency":"annual","effective_date":"2026-04-13","next_review_date":"2027-01-05"}},{"title":"Physical Security Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"This policy defines physical security requirements to protect Bluth Company information systems and data from unauthorized physical access, damage, and interference.","full_description":"# Physical Security Policy\n\n## 1. Purpose\nThis policy defines how Bluth Company protects information systems and data from unauthorized physical access, damage, and environmental interference - which, for Bluth Company, means stating plainly what is inherited from its cloud infrastructure provider, what does not apply because Bluth Company has no offices, and where physical-security responsibility genuinely sits.\n\n## 2. Scope\nBluth Company is a cloud-native SaaS company. It leases, owns, and operates no office space, data center, or corporate premises of any kind; all personnel work remotely. This policy covers two things: (a) the data-center physical and environmental security that Bluth Company relies on Model Home Data Lake to provide, and (b) an explicit statement of which office-oriented physical controls are not applicable to Bluth Company's operating model, rather than leaving them silently untested. Physical security for the locations where work actually happens - personnel's homes - is addressed by the Remote Working & Clear Desk Policy and incorporated here by reference.\n\n## 3. Roles & Responsibilities\nThe Security Lead reviews Model Home Data Lake's SOC 2 Type II report annually and folds physical-security posture into the annual risk assessment. The Operations Lead tracks Model Home Data Lake as a critical subservice organization under the Vendor Management Policy's oversight cadence. The CEO accepts, as a documented business-model decision, that Bluth Company operates no corporate office and therefore has no CCTV, badge system, or visitor log to test. All personnel follow the Remote Working & Clear Desk Policy for the physical security of their own workspace.\n\n## 4. Policy Statements\n4.1 Physical security perimeters, physical security monitoring, and protection against physical and environmental threats for all production infrastructure are inherited entirely from Model Home Data Lake's data centers. Bluth Company does not operate, and does not claim to operate, any Bluth Company-controlled data-center perimeter, monitoring system, or environmental control.\n4.2 Equipment siting and protection, supporting utilities (power and climate control), and cabling security for production infrastructure are likewise Model Home Data Lake's responsibility as the sole infrastructure provider; Bluth Company owns no server room, uninterruptible power supply, generator, or physical cabling plant.\n4.3 Model Home Data Lake's physical and environmental controls - perimeter fencing, multi-factor and biometric entry control, 24/7 trained security personnel, and environmental monitoring - are verified at least annually by the Security Lead through review of Model Home Data Lake's current SOC 2 Type II report, consistent with the critical-subservice oversight set out in the Vendor Management Policy. This annual review is the mechanism by which Bluth Company's restriction of physical access to facilities, data centers, and backup media, and its physical/environmental control assurance, are discharged.\n4.4 Bluth Company leases, owns, and operates no corporate office, and consequently has no badge-access system, CCTV, staffed reception, or visitor log. Physical entry control, the securing of offices, rooms, and facilities, and working in secure areas are Not Applicable to Bluth Company's fully remote operating model. This is documented here as a business-model fact confirmed annually alongside the ISMS Scope Document, not left untested by omission.\n4.5 Physical security for the locations where Bluth Company work is actually performed - personnel's home offices and incidental remote locations - is governed by the Remote Working & Clear Desk Policy (workspace privacy, device security, screen lock, clear desk) and the Asset & Media Management Policy (equipment handling and disposal); this policy incorporates that coverage by reference rather than restating it.\n4.6 Should Bluth Company's operating model change to include a leased office, a dedicated co-working space, or any other physical facility, a physical-security risk assessment shall be completed before occupancy, and this policy updated to scope in the applicable badge, CCTV, and visitor-management controls at that time.\n4.7 Physical security posture - the continued validity of the Model Home Data Lake-inheritance and no-office facts above - is reassessed at least annually as part of the enterprise risk assessment, and on any change to Bluth Company's primary infrastructure provider or work-location model.\n\n## 5. Exceptions\nThere is no exception process for claiming a physical control Bluth Company does not actually operate. An exception applies only to the review cadence itself - for example, a delayed Model Home Data Lake SOC 2 report review pending the vendor's own report timing - and requires Security Lead approval, a documented interim compensating step (such as reliance on the prior period's report), and a catch-up date.\n\n## 6. Enforcement\nCompliance is verified through the annual Model Home Data Lake SOC 2 report review record and the annual risk-assessment update confirming the no-office status. A physical security incident of any kind - including one arising within the Remote Working & Clear Desk Policy's scope - is reported and investigated through the Incident Response Policy.\n\n## 7. Review & Ownership\nOwner: Operations Lead / Security Lead. Review cadence: at least annually and on any change to infrastructure provider or work-location model, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Vendor Management Policy (Model Home Data Lake critical-subservice oversight, right-to-audit); Cloud Services Security Policy (Model Home Data Lake shared-responsibility boundaries); Remote Working & Clear Desk Policy (actual workspace physical security); Asset & Media Management Policy (equipment handling); ISMS Scope Document (remote-first scope statement).\nGoverns controls: A.7.1 - Physical security perimeters; A.7.2 - Physical entry; A.7.3 - Securing offices, rooms and facilities; A.7.4 - Physical security monitoring; A.7.5 - Protecting against physical and environmental threats; A.7.6 - Working in secure areas; A.7.8 - Equipment siting and protection; A.7.11 - Supporting utilities; A.7.12 - Cabling security; CC6.4 - The entity restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives; SOC1-10 - Physical security and environmental controls - controls provide reasonable assurance that physical access to facilities and data centers is restricted and that environmental protections safeguard systems.\nOperated by: the annual Model Home Data Lake SOC 2 report review described in Statement 4.3.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["iso-27001","soc1","soc2"],"domains":["physical_environmental_security"],"review_frequency":"annual","effective_date":"2026-05-11","next_review_date":"2027-01-06"}},{"title":"Privacy Policy","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"This policy establishes Bluth Company's commitment to protecting the privacy of personal information and meeting obligations under applicable data protection regulations and the SOC 2 Privacy criteria.","full_description":"# Privacy Policy\n\n## 1. Purpose\nThis policy establishes Bluth Company's commitments and operating practices for protecting personal information, meeting applicable data-protection law and the SOC 2 Privacy category, across every stage of the personal-information lifecycle from notice through disposal.\n\n## 2. Scope\nThis policy covers all personally identifiable information (PII) processed by Bluth Company - whether belonging to a customer's end users, Bluth Company employees, or business contacts - including production data in per-tenant Cloud SQL databases on Model Home Data Lake. Bluth Company is a B2B SaaS provider: for a customer's own end-user data, Bluth Company acts as processor/service provider under the customer's instructions and Master Services Agreement. Read together with the Data Classification & Handling Policy, the Data Retention & Disposal Policy, and the AI Governance & Acceptable AI Use Policy.\n\n## 3. Roles & Responsibilities\nThe Security Lead serves as the privacy point of contact, reachable through the monitored michael.bluth@bluth.example group, maintains the privacy notice, and owns DSAR handling. The Head of Engineering implements privacy-by-design in product development and coordinates privacy impact assessments. External legal counsel, coordinated by the CEO, reviews data processing agreements and advises on regulatory obligations, including GDPR and CCPA where applicable. All personnel handle personal data per its classification under the Data Classification & Handling Policy.\n\n## 4. Policy Statements\n4.1 **Notice.** A privacy notice is published at bluth.example describing what personal data is collected, how it is used, with whom it is shared, and how long it is retained. The notice is reviewed at least annually and updated whenever processing activities materially change, with the effective date disclosed.\n4.2 **Consent and choice.** Where consent is the basis for collecting or using personal information, Bluth Company communicates the choices available and the consequences of withholding consent, and obtains consent before collection; where consent is treated as implicit, the basis is documented. As a B2B processor, notice and consent to a customer's own end users is primarily that customer's responsibility as data controller; this policy's commitments operate within that structure.\n4.3 **Collection minimization.** Personal information is collected only to the extent consistent with the purpose disclosed in the privacy notice or the applicable customer agreement; a field or integration not necessary for a stated purpose is not added speculatively.\n4.4 **Use limitation.** Personal information is used only for the purposes identified at collection and is not used for a materially different, incompatible purpose without additional notice or consent. Personal information, including customer data processed by AI features, is not used to train AI models; platform AI inference runs on Lucille Identity Cloud Vertex AI (Gemini) under Model Home Data Lake's data-governance commitments, with prompt retention disabled (see the AI Governance & Acceptable AI Use Policy).\n4.5 **Retention and disposal.** Personal information is retained and disposed of per the schedule in the Data Retention & Disposal Policy, the authoritative source for retention periods and disposal methods; this policy's commitments do not extend retention beyond what that policy specifies.\n4.6 **Data subject access, correction, and deletion.** A data subject access request (DSAR) - to access, correct, or delete personal information, or to receive an accounting of information held and its disclosures - is acknowledged and fulfilled within 30 days of receipt and identity verification; a denied request states the reason. A request with a deletion component is executed per the Data Retention & Disposal Policy.\n4.7 **Third-party disclosure and disclosure records.** Personal information is disclosed to a third party only with the data subject's explicit consent, or another documented lawful basis, obtained before disclosure. Bluth Company keeps a complete, accurate, timely record of authorized disclosures and of any detected or reported unauthorized disclosure, including breaches.\n4.8 **Vendor and processor privacy commitments.** A data processing agreement is executed with every third-party processor of personal information before data is shared, covering security requirements, processing limitations, sub-processor notification, and an obligation to notify Bluth Company of a suspected unauthorized disclosure; processor compliance is assessed periodically under the Vendor Management Policy.\n4.9 **Breach notification.** Notification of a breach or privacy incident is provided to affected data subjects, regulators, and contracting customers within contractual and legal timeframes, coordinated with the Incident Response Policy and legal counsel for any incident involving personal data.\n4.10 **Privacy impact assessment.** A privacy impact assessment is conducted for a new feature, product, or processing activity involving personal information, identifying risks and documenting mitigations before the feature ships.\n4.11 **Accuracy.** Personal information that Bluth Company maintains directly - as opposed to data a customer controls within its own tenant - is kept accurate, complete, and up to date for the purpose for which it is used, and is corrected on verified request.\n4.12 **Complaints.** A data subject or other party may submit a privacy complaint or inquiry to michael.bluth@bluth.example, or through michael.bluth@bluth.example, which routes it to the privacy point of contact; Bluth Company acknowledges, investigates, resolves, and communicates the resolution of the complaint, and reviews complaint volume and themes as part of the quarterly management review.\n\n## 5. Exceptions\nAn exception to a stated privacy commitment - for example, an extended retention period under legal hold, addressed operationally by the Data Retention & Disposal Policy - is documented, risk-assessed, approved by the Security Lead, and time-bound with a review date.\n\n## 6. Enforcement\nViolation of this policy, including unauthorized use, disclosure, or retention of personal information beyond policy, is treated as a security incident under the Incident Response Policy and may result in disciplinary action under the Human Resources Security Policy. Compliance is monitored through DSAR tracking, the DPA inventory, privacy-impact-assessment records, and annual notice review, with deviations tracked to remediation.\n\n## 7. Review & Ownership\nOwner: Security Lead (privacy point of contact). Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Data Classification & Handling Policy; Data Retention & Disposal Policy; Information Transfer & Leakage Prevention Policy; Vendor Management Policy; AI Governance & Acceptable AI Use Policy; Incident Response Policy; Legal & Regulatory Compliance Policy.\nGoverns controls: A.5.34 - Privacy and protection of personal identifiable information (PII); the SOC 2 Privacy category in full - P1.1, P2.1, P3.1, P3.2, P4.1, P4.2, P4.3, P5.1, P5.2, P6.1, P6.2, P6.3, P6.4, P6.5, P6.6, P6.7, P7.1, P8.1; Data subject rights & consent handling (PII).\nOperated by: the operational workflow that fulfills data-subject access and deletion requests.","policy_type":"policy","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["soc2","iso-27001"],"domains":["data_protection_privacy"],"review_frequency":"annual","effective_date":"2026-06-08","next_review_date":"2027-01-07"}},{"title":"Remote Working & Clear Desk Policy","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"This policy defines security requirements for remote working arrangements to ensure that information accessed, processed, or stored outside corporate facilities is adequately protected.","full_description":"# Remote Working & Clear Desk Policy\n\n## 1. Purpose\nThis policy protects information that is accessed, processed, or stored outside a traditional office - which, for a fully remote Bluth Company, means everywhere work happens - by setting device- and access-security requirements for remote work (Part A) and clear-desk/clear-screen workspace behavior (Part B).\n\n## 2. Scope\nThis policy applies to all Bluth Company personnel, who work exclusively remotely - from home offices, and occasionally from co-working spaces or while traveling. It covers the devices and channels used to reach Bluth Company systems, and the physical workspace conditions under which personnel handle company information, including any setting where a non-Bluth Company individual (household member, guest, neighbor, fellow traveler) might see or access company data.\n\n## 3. Roles & Responsibilities\nThe Security Lead defines remote-access and workspace-security requirements and owns this policy. DevOps/IT provisions approved devices and remote-access tooling (Lucille Identity Cloud SSO with MFA, and Model Home Data Lake IAP for production paths). The CEO includes a remote-workspace self-attestation in the annual security review. All personnel are responsible for the security of their own workspace and devices and for reporting incidents immediately.\n\n## 4. Policy Statements\n\n**Part A - Remote access and device security**\n4.1 Company systems shall be accessed only from company-managed or approved devices configured with full-disk encryption, current operating-system patches, and endpoint anti-malware protection.\n4.2 Remote access to production systems and internal tools uses approved secure channels - Lucille Identity Cloud SSO with MFA-protected web access over TLS, with Model Home Data Lake IAP (context-aware access) where a direct production path is required; Bluth Company operates no corporate VPN. On public Wi-Fi or other untrusted networks, company systems are reached only through these TLS-protected channels, and Confidential or Restricted data is never accessed over an unsecured protocol.\n4.3 Company data shall not be stored on a personal device or personal cloud storage without explicit authorization. Any copy taken for offline work is encrypted and deleted as soon as it is no longer needed.\n4.4 A lost or stolen device, and any suspected compromise of a remote workspace or device, is reported immediately through the Incident Response Policy's reporting channels.\n\n**Part B - Clear desk and clear screen**\n4.5 Screens shall auto-lock after no more than 5 minutes of inactivity, and are locked manually whenever personnel step away while others are present in the home or workspace.\n4.6 A non-Bluth Company individual - household member, guest, or child - shall not use a company-issued device, even momentarily; devices are locked or stored securely whenever the assigned individual is not present.\n4.7 Workstations shall be positioned so the screen is not visible to a non-Bluth Company individual through windows, doorways, or a shared sightline while Confidential or Restricted information is displayed; a privacy screen is encouraged in a high-traffic home. Equipment used off-premises - which, in a fully remote model, is everywhere it is used - remains subject to this positioning requirement.\n4.8 Confidential or Restricted information is not printed at home; if an exceptional circumstance requires it, the printout is cross-cut shredded immediately after use and never left in an output tray.\n4.9 A credential, access code, or MFA backup code shall never be written on physical media (a sticky note, notebook, or whiteboard); credentials are held only in the approved stores - Lucille Identity Cloud Password Manager under the corporate Lucille Identity Cloud account for personal credentials, Model Home Data Lake Secret Manager for shared application and infrastructure secrets.\n4.10 Removable media (USB drives, SD cards) shall not be used to store or transport company data, and customer data is never transferred via removable media under any circumstance; the narrow, approved-exception handling for removable media as a tracked asset is set out in the Asset & Media Management Policy.\n4.11 A video call discussing Confidential or Restricted information is conducted in a private space where a non-Bluth Company individual cannot overhear; noise-cancelling headphones are used where a fully private room is unavailable.\n4.12 Personnel complete an annual remote-workspace self-attestation (including a photo of the workspace setup) as part of the annual security review, confirming continued compliance with Parts A and B.\n\n## 5. Exceptions\nA request to deviate from this policy - for example, a temporary exception to the private-workspace requirement while traveling - requires Security Lead approval, a documented compensating control, and a review date; exceptions are logged and reassessed at least annually.\n\n## 6. Enforcement\nCompliance is verified through endpoint configuration audits (encryption, patch status, screen-lock timeout) and the annual workspace self-attestation. A violation is addressed first through coaching and, if persistent, through the Human Resources Security Policy's disciplinary process; a confirmed data exposure is handled as a security incident under the Incident Response Policy.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Acceptable Use Policy (BYOD/device baseline); Asset & Media Management Policy (removable-media asset lifecycle); Password & Authentication Policy (credential-storage authority); Physical Security Policy (remote-work physical security is incorporated there by reference to this policy); Incident Response Policy.\nGoverns controls: A.6.7 - Remote working; A.7.7 - Clear desk and clear screen; A.7.9 - Security of assets off-premises; A.8.1 - User endpoint devices; User endpoint devices protected and managed (includes remote working security); Removable media prohibited for company and customer data; approved exceptions encrypted and tracked; Anti-malware / endpoint protection deployed on personnel endpoints.\nOperated by: the annual remote-workspace self-attestation described in Statement 4.12.","policy_type":"policy","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["asset_management_inventory","network_communications_security","data_protection_privacy"],"review_frequency":"annual","effective_date":"2026-01-12","next_review_date":"2027-01-08"}},{"title":"Risk Assessment Methodology","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"This document defines the methodology for identifying, analyzing, evaluating, and treating information security risks in accordance with ISO/IEC 27001:2022 Clause 6.1.2. It ensures a consistent, repeatable approach to risk assessment across the organization.","full_description":"# Risk Assessment Methodology\n\n## 1. Purpose\nThis procedure defines the methodology for identifying, analyzing, evaluating, and treating information security risks in accordance with ISO/IEC 27001:2022 Clause 6.1.2, producing a consistent, repeatable, and comparable risk assessment across Bluth Company.\n\n## 2. Scope\nThis procedure applies to every risk assessment conducted under the Risk Management Policy, across all risk categories: operational, technical, compliance, vendor, people, financial, and strategic. It governs the assessment stage only; once a risk is evaluated here, its treatment is carried out under the Risk Treatment Process.\n\n## 3. Procedure Steps\n3.1 Risk Identification - Risks are identified from threat intelligence, vulnerability assessments, incident post-mortems, audit findings, regulatory changes, and stakeholder input, and logged in the risk register with a unique identifier, description, category, and owner. [Security Lead facilitates; risk owners contribute]\n3.2 Risk Analysis - Each risk is scored for likelihood (1 Very Low – 5 Very High) and impact (1 Very Low – 5 Very High) on a 5-point scale; the inherent risk score is Likelihood × Impact, producing a value from 1 to 25. [Risk Owner, with Security Lead]\n3.3 Risk Evaluation - Scores of 1–4 are Low (generally acceptable), 5–9 Medium (monitor, consider treatment), 10–15 High (treatment required), and 16–25 Critical (immediate treatment required); residual risk is assessed after accounting for existing controls. [Security Lead]\n3.4 Risk Treatment Selection - The risk owner selects Mitigate, Accept, Transfer, or Avoid per the Risk Treatment Process, and links the treatment plan to specific controls in the control register. [Risk Owner]\n3.5 Risk Monitoring - The risk register is reviewed quarterly; risk owners report treatment-plan status, and new risks identified from threat intelligence, incidents, or organizational change are added as they arise. [Security Lead]\n3.6 Risk Acceptance - Residual risk scores of 9 or below may be accepted by management as part of the quarterly review. Residual scores of 10 or above require CEO approval and a documented compensating control; every acceptance decision records the accepting authority, the date, and the review timeline. [CEO / Security Lead]\n\n## 4. Records & Evidence\nThe risk register (unique ID, category, likelihood/impact scores, inherent and residual scores, owner, treatment plan, and review history); documented risk-acceptance approvals for residual scores of 10 or above; quarterly risk-review notes; the mapping from each risk to its assigned category and to the business objective it threatens, which supports the objective-clarity and risk-identification statements of the Risk Management Policy.\n\n## 5. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually, and whenever lessons learned from risk assessments or changes to organizational context warrant an update. Material changes to the scales, bands, or acceptance criteria are communicated to all risk owners and reflected in the next quarterly risk-register review.","policy_type":"procedure","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"1.0","framework":["soc2"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-02-09","next_review_date":"2027-01-09"}},{"title":"Risk Management Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"This policy defines the risk management framework for identifying, assessing, treating, and monitoring risks that could affect Bluth Company's ability to protect customer data and maintain service availability.","full_description":"# Risk Management Policy\n\n## 1. Purpose\nThis policy establishes Bluth Company's risk management framework for identifying, assessing, treating, and monitoring the risks that could affect the company's ability to protect customer data and maintain service availability.\n\n## 2. Scope\nThis policy covers operational, technical, compliance, vendor, people, financial, and strategic risks across the organization. It applies to all business processes, information systems, and third-party relationships, and it is the parent framework under which the Risk Assessment Methodology and Risk Treatment Process operate.\n\n## 3. Roles & Responsibilities\nThe Security Lead owns the risk management program, facilitates risk assessments, and maintains the risk register. Risk owners are accountable for implementing treatment plans for their assigned risks. The CEO reviews the risk register quarterly, approves risk-acceptance decisions above the methodology's threshold, and reviews cyber-liability coverage adequacy annually. The Head of Engineering provides technical-risk input for infrastructure and product changes. All personnel may identify and report risks.\n\n## 4. Policy Statements\n4.1 A formal enterprise risk assessment shall be conducted at least annually, covering every risk category in scope, using the likelihood × impact methodology defined in the Risk Assessment Methodology to produce consistent, quantified risk scores.\n4.2 The enterprise risk register shall be maintained in Bluth Company and reviewed quarterly by the Security Lead and the CEO; each risk shall have a named owner, a treatment decision (mitigate, accept, transfer, or avoid), and a documented target residual risk level.\n4.3 Selection and design of control activities - including technology general controls governing access, change management, and operations - shall be driven directly by risk assessment results, so that every mitigating control in the control register is traceable back to the risk it addresses and forward to its supporting evidence.\n4.4 An annual fraud risk assessment shall be performed, explicitly evaluating management-override-of-controls scenarios, with identified fraud risks and their compensating controls documented in the risk register.\n4.5 Risks to business continuity and service availability shall be assessed at least annually as part of the enterprise risk cycle, cross-referenced to the treatment and testing program in the Business Continuity & Disaster Recovery Policy.\n4.6 Material changes in the threat landscape, business operations, or regulatory environment shall trigger an ad-hoc risk assessment; new product features, vendor relationships, and infrastructure changes shall each include a documented risk evaluation before launch.\n4.7 Cyber-liability insurance shall be maintained as an explicit risk-transfer control to offset financial loss arising from a critical security incident or exploited vulnerability; coverage adequacy shall be reviewed at least annually against the risk register, and the current policy certificate retained for auditor review.\n\n## 5. Exceptions\nAny risk-acceptance decision above the residual-risk threshold defined in the Risk Assessment Methodology requires documented executive approval identifying the accepting authority, the rationale, and any compensating controls; accepted risks are time-bound and re-reviewed at the next quarterly register review, or sooner if circumstances change.\n\n## 6. Enforcement\nCompliance is evaluated through the quarterly register review, control-testing results referenced from the control register, and an annual assessment of the risk program's overall effectiveness. The risk register and treatment plans are available for auditor review at all times. Failure to maintain an assigned risk or treatment plan, or bypassing the risk-acceptance approval requirement, is addressed under the disciplinary provisions of the Human Resources Security Policy.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually. The risk register itself is reviewed quarterly.\n\n## 8. Related Documents & Controls\nRelated policies: Risk Assessment Methodology, Risk Treatment Process, Business Continuity & Disaster Recovery Policy, Vendor Management Policy.\nGoverns controls: CC3.1, CC3.2, CC3.3, CC3.4, CC5.1 (COSO 10 - selection and design of control activities), CC5.2 (COSO 11 - technology general controls), CC9.1 (risk mitigation for business disruptions).\nOperated by: the risk assessment and treatment cycle.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["soc2"],"domains":["risk_assessment_management","governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-03-09","next_review_date":"2027-01-10"}},{"title":"Risk Treatment Process","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"This document defines the process for selecting, implementing, and monitoring risk treatment actions in accordance with ISO/IEC 27001:2022 Clause 6.1.3. It ensures that identified risks are treated effectively and that residual risk levels are acceptable.","full_description":"# Risk Treatment Process\n\n## 1. Purpose\nThis procedure defines the process for selecting, implementing, and monitoring risk treatment actions in accordance with ISO/IEC 27001:2022 Clause 6.1.3, ensuring identified risks are treated effectively and residual risk is brought within acceptable levels.\n\n## 2. Scope\nThis procedure applies to every risk in the Bluth Company risk register that requires treatment under the Risk Assessment Methodology (Medium, High, or Critical inherent risk), and to the resulting Statement of Applicability for ISO 27001:2022 Annex A controls.\n\n## 3. Procedure Steps\n3.1 Treatment Selection - For each risk requiring treatment, the risk owner evaluates Mitigate, Accept, Transfer, or Avoid, weighing cost-effectiveness, feasibility, operational impact, and alignment with business objectives; the selected option and rationale are documented in the risk register. [Risk Owner]\n3.2 Control Selection - For risks being mitigated, controls are selected from the control register or newly designed, drawing on ISO 27001:2022 Annex A, the SOC 2 Trust Services Criteria, and industry practice; each mitigating control is linked to its risk in Bluth Company. [Risk Owner, with Security Lead]\n3.3 Implementation Planning - A treatment plan specifies the controls to implement, the responsible person, the timeline, required resources, and the expected residual risk after treatment; the plan is approved by the risk owner and the Security Lead. [Security Lead]\n3.4 Implementation & Verification - Controls are implemented per the plan and verified by testing, review, or inspection; control status is progressed in the control register from Designed to Implemented to Operating. [System/Control Owner]\n3.5 Residual Risk Assessment - After treatment, residual risk is reassessed; if it still exceeds the acceptance criteria in the Risk Assessment Methodology, additional treatment is applied or formal risk acceptance is obtained from the CEO. [Risk Owner / CEO]\n3.6 Effectiveness Reporting - Treatment progress and residual-risk outcomes are summarized for the quarterly risk-register review and, where a treatment plan is materially behind schedule or ineffective, escalated to the Nonconformity & Corrective Action Procedure. [Security Lead]\n3.7 Statement of Applicability - The Statement of Applicability (SoA) documents every Annex A control's applicability and justification, maintained as a live dashboard in Bluth Company showing applicability, implementation status, and compliance-criteria mapping; it is reviewed annually and whenever a control changes. [Security Lead]\n\n## 4. Records & Evidence\nDocumented treatment plans and selection rationale; control register status history (Designed / Implemented / Operating); the Statement of Applicability dashboard; residual-risk reassessment records; quarterly effectiveness-reporting summaries; and any formal risk-acceptance approvals.\n\n## 5. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually, alongside the Risk Assessment Methodology, to keep the two procedures consistent.","policy_type":"procedure","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["soc2"],"domains":["governance_policy_oversight"],"review_frequency":"annual","effective_date":"2026-04-13","next_review_date":"2027-01-11"}},{"title":"Secure Coding Policy","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"This policy establishes secure coding standards and practices to minimize security vulnerabilities in Bluth Company application code, supplementing the SDLC Policy with specific coding requirements.","full_description":"# Secure Coding Policy\n\n## 1. Purpose\nThis policy establishes secure coding standards and practices to minimize security vulnerabilities in Bluth Company application code, supplementing the Software Development Lifecycle Policy with language- and framework-level coding requirements.\n\n## 2. Scope\nThis policy applies to all code written for the core, auth, and MCP applications and shared packages, across all languages, frameworks, and libraries in the codebase, and to how source code itself is accessed and controlled.\n\n## 3. Roles & Responsibilities\nThe Head of Engineering maintains the secure coding guidelines and the security review checklist. Developers write code to those standards and remediate identified vulnerabilities. The Security Lead monitors dependency vulnerabilities and defines remediation SLA timelines in coordination with the Vulnerability & Patch Management Policy.\n\n## 4. Policy Statements\n4.1 Developers follow secure coding guidelines based on the OWASP Top 10 and relevant language-specific practices; common vulnerability patterns (injection, XSS, CSRF, insecure deserialization) are addressed through framework-level protections and code review.\n4.2 All database queries use parameterized queries or Prisma ORM-generated queries; dynamic query construction by string concatenation is prohibited.\n4.3 Source code access is managed exclusively through the Model Home Data Lake version control system with branch protection; direct pushes to a protected branch are disabled, and every change goes through merge-request review.\n4.4 Security-focused code review, using a documented security review checklist, is mandatory for changes to authentication, authorization, encryption, data handling, and API or MCP tool endpoint code.\n4.5 Third-party dependencies are evaluated for known vulnerabilities before adoption and monitored continuously through Model Home Data Lake Ultimate dependency scanning; dependencies with an unpatched Critical vulnerability are updated or replaced within the SLA timelines set by the Vulnerability & Patch Management Policy.\n4.6 Recurring vulnerability patterns identified in scan results, code review, or penetration-test findings trigger an update to the secure coding guidelines and, where warranted, targeted developer training.\n4.7 Code style and static-analysis lint rules are enforced in the CI pipeline through the project's linter configuration, including a ratcheting security-relevant rule set (for example, prohibiting console-based debug output that could leak sensitive data into production logs); the enforced baseline may only tighten, never loosen, from one release to the next.\n4.8 Code authored or suggested by an approved AI coding assistant (for example, Claude Code, GitHub Copilot, or Cursor, as approved under the Acceptable Use Policy) is subject to the same merge-request review, static analysis, and dependency-scanning gates as human-authored code; no change merges to a protected branch without the reviews required by statements 4.1–4.4, regardless of its authorship tooling.\n\n## 5. Exceptions\nWhere a third-party library or legacy code path cannot immediately meet a coding standard (for example, a dependency with no patched version yet available), the Head of Engineering documents the risk, a compensating control (such as additional input validation or network isolation), and a time-bound remediation date.\n\n## 6. Enforcement\nRecurring or willful disregard of secure coding standards is addressed through code review rejection, mandatory remediation, and - for repeated violations - the disciplinary process in the Human Resources Security Policy. Compliance is verified through static analysis results, code review records, dependency vulnerability reports, and penetration test findings.\n\n## 7. Review & Ownership\nOwner: Head of Engineering. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Software Development Lifecycle Policy; Vulnerability & Patch Management Policy; Change Management Policy.\nGoverns controls: A.8.4 - Access to source code; A.8.28 - Secure coding.\nOperated by: the secure development and release security gate process.","policy_type":"policy","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["iso-27001"],"domains":["access_control_identity","secure_development_sdlc"],"review_frequency":"annual","effective_date":"2026-05-11","next_review_date":"2027-01-12"}},{"title":"Software Development Lifecycle Policy","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"This policy establishes secure software development practices to ensure that application code is developed, tested, and deployed in a manner that maintains processing integrity and protects against security vulnerabilities.","full_description":"# Software Development Lifecycle Policy\n\n## 1. Purpose\nThis policy establishes secure software development practices so that Bluth Company application code is designed, built, tested, and deployed in a manner that maintains processing integrity and resists security vulnerabilities across the full development lifecycle.\n\n## 2. Scope\nThis policy applies to all software development for the core, auth, and MCP applications and shared workspace packages, from requirements and design through build, test, deployment, and maintenance. It covers security-by-design review, peer review, automated security testing, input handling, environment segregation, and documenting what data the platform processes and how. It is supplemented by the Secure Coding Policy for language-level detail and the Change Management Policy for deployment mechanics.\n\n## 3. Roles & Responsibilities\nThe Head of Engineering owns this policy and defines coding standards and review requirements. Developers follow secure coding practices, write tests, and remediate findings. The Security Lead configures and maintains SAST, dependency, and secret-scanning tools. DevOps maintains environment segregation and the CI/CD pipeline.\n\n## 4. Policy Statements\n4.1 Security requirements are identified during the design phase of all new features and significant changes; threat modeling is performed for features touching authentication, authorization, data handling, or external and AI-agent integrations, as a security-by-design review.\n4.2 The types of data input by user-entity customers (workflow, control, and document records created through the app and the MCP) and by internal personnel (administrative configuration) are documented as part of the data classification inventory, so that input types are known and reviewable.\n4.3 All code undergoes peer review via a Model Home Data Lake merge request before merging to the protected branch; reviewers evaluate security, adherence to coding standards, test coverage, and correctness.\n4.4 Automated security testing - static analysis (SAST), dependency vulnerability scanning, and secret detection - runs in the CI/CD pipeline on every merge request; a build with an unwaived Critical or High finding is blocked from merging.\n4.5 Input validation is enforced on all user inputs and API/MCP tool endpoints; all database access uses parameterized, Prisma ORM-generated queries, and string-concatenated dynamic query construction is prohibited.\n4.6 Development, staging, and production run in logically and physically separate Model Home Data Lake projects; production data is never copied into development or test environments without masking under the Data Masking Policy, and developers hold no standing write access to production databases.\n4.7 Processed data and system output are reviewed on a routine basis (application dashboards, scheduled monitoring checks) for completeness, accuracy, and timeliness; detected processing errors are logged and corrected under the Incident Response or Change Management process as their severity warrants.\n4.8 New systems, applications, and significant enhancements are tested, reviewed, and approved before production implementation, consistent with the documented intent of the change, with the approval trail carried on the merge request and CI pipeline record.\n\n## 5. Exceptions\nA request to skip a specific SDLC control (for example, deferring threat modeling on a time-boxed spike) is submitted to the Head of Engineering, who documents the risk, a compensating control (such as a follow-up review before general availability), and a review date before approving.\n\n## 6. Enforcement\nBypassing a required SDLC control - merging without review, disabling a CI security gate, or shipping without the documented design review - is a policy violation tracked through the change management system and handled per the Human Resources Security Policy's disciplinary process where applicable. Compliance is monitored through merge-request audit trails, CI/CD pipeline reports, and security-scan findings.\n\n## 7. Review & Ownership\nOwner: Head of Engineering. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Secure Coding Policy; Change Management Policy; Data Masking Policy; Data Classification & Handling Policy.\nGoverns controls: A.5.8 - Information security in project management; A.8.25 - Secure development life cycle; A.8.26 - Application security requirements; A.8.27 - Secure system architecture and engineering principles; A.8.29 - Security testing in development and acceptance; A.8.31 - Separation of development, test and production environments; PI1.2; PI1.3; PI1.4; SOC1-3; SOC1-7; SOC1-8; SOC1-9.\nOperated by: the secure development and release security gate process.","policy_type":"policy","policy_owner":"maeby.fuenke@bluth.example","approved_by":"ann.veal@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["financial_reporting_controls","secure_development_sdlc","secure_configuration_change_management"],"review_frequency":"annual","effective_date":"2026-06-08","next_review_date":"2027-01-13"}},{"title":"Threat Intelligence Policy","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"This policy establishes requirements for collecting, analyzing, and acting upon threat intelligence to proactively identify and mitigate emerging threats to Bluth Company systems and data.","full_description":"# Threat Intelligence Policy\n\n## 1. Purpose\nThis policy establishes requirements for collecting, analyzing, and acting on threat intelligence to proactively identify and mitigate emerging threats to Bluth Company systems and data.\n\n## 2. Scope\nThis policy applies to all sources of threat intelligence relevant to a cloud-hosted SaaS platform - vendor advisories, government alerts (CISA, CERT), industry information-sharing groups, security research feeds, and internal telemetry - and covers strategic, tactical, and operational threat intelligence.\n\n## 3. Roles & Responsibilities\nThe Security Lead manages threat intelligence collection, analysis, and liaison with information-security interest groups. Engineering and DevOps act on tactical intelligence such as patching and configuration changes. The Head of Engineering is briefed on intelligence affecting the development toolchain or production infrastructure. The CEO receives strategic threat-intelligence summaries as part of quarterly security reporting.\n\n## 4. Policy Statements\n4.1 The Security Lead shall maintain subscriptions to threat intelligence sources relevant to Bluth Company's technology stack, including Model Home Data Lake security bulletins, CISA advisories, CVE databases, and industry feeds for SaaS and cloud infrastructure.\n4.2 Threat intelligence shall be reviewed continuously and triaged for relevance to Bluth Company's technology stack and risk profile; actionable intelligence shall be acted on within severity-based timelines aligned to the Vulnerability & Patch Management Policy.\n4.3 Threat intelligence findings shall be integrated into the risk assessment process: newly identified threats shall be evaluated against existing controls and, where a gap exists, logged as a risk in the risk register with a treatment plan.\n4.4 Threat intelligence shall be shared with relevant internal teams - engineering, DevOps, and security - in a timely manner to support informed decisions about security priorities and defensive measures.\n4.5 Bluth Company shall maintain contact with, and participate in, relevant information-security special interest groups and professional communities to exchange threat information and stay current on emerging attack techniques, independent of any single vendor relationship.\n4.6 Insider-threat indicators - anomalous data access, unusual credential use, or reports from personnel - shall be treated as a threat-intelligence input and triaged jointly with the Logging & Monitoring Policy's alerting and the Incident Response Policy's investigation process.\n4.7 Threat intelligence indicating a credible, specific threat to Bluth Company systems or data shall be escalated immediately to the Security Lead for assessment and, where warranted, invocation of the Incident Response Policy.\n\n## 5. Exceptions\nA decision to defer action on a specific piece of threat intelligence - for example, because it is assessed as not relevant to Bluth Company's stack - is documented with its rationale and revisited at the next quarterly security report if the threat landscape changes.\n\n## 6. Enforcement\nThreat intelligence compliance is verified through documentation of active intelligence sources, evidence of timely review and action on relevant alerts, and integration of threat findings into the risk register. Failure to act on a credible, escalated threat within its defined timeline is treated as a control deficiency under the Nonconformity & Corrective Action Procedure.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Vulnerability & Patch Management Policy, Risk Management Policy, Logging & Monitoring Policy, Incident Response Policy.\nGoverns controls: A.5.6 (Contact with special interest groups), A.5.7 (Threat intelligence); Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies).\nOperated by: the threat intelligence program.","policy_type":"policy","policy_owner":"ann.veal@bluth.example","approved_by":"michael.bluth@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["governance_policy_oversight","logging_monitoring_detection","network_communications_security"],"review_frequency":"annual","effective_date":"2026-01-12","next_review_date":"2027-01-14"}},{"title":"Vendor Management Policy","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"This policy establishes requirements for assessing, onboarding, and monitoring third-party vendors to ensure they maintain security practices consistent with Bluth Company's obligations to its customers.","full_description":"# Vendor Management Policy\n\n## 1. Purpose\nThis policy establishes requirements for assessing, onboarding, and monitoring third-party vendors and subservice organizations across their full lifecycle, so they maintain security practices consistent with Bluth Company's obligations to its customers.\n\n## 2. Scope\nThis policy applies to every vendor that accesses, processes, or stores Bluth Company or customer data, or connects to production systems - cloud infrastructure and identity (Lucille Identity Cloud - Cloud Platform, Cloud SQL, and Workspace), SaaS tools (Model Home Data Lake), professional-services firms (Tidewell Advisory Group for governance, finance, and HR support; the SOC 2 examining CPA firm for attestation), and any contracted or outsourced development work. It covers the full lifecycle from selection through termination.\n\n## 3. Roles & Responsibilities\nThe Security Lead owns the vendor risk assessment process, maintains the vendor register, reviews subservice organization SOC reports, and tracks vendor compliance. The CEO sponsors and approves critical-vendor contractual terms. Business owners who initiate a vendor relationship are responsible for ensuring the risk assessment is completed before onboarding. The Tidewell Advisory Group vCISO function performs the quarterly review of critical-vendor records exports on the Security Lead's behalf.\n\n## 4. Policy Statements\n4.1 A vendor risk assessment shall be completed before onboarding any new vendor that will access, process, or store customer data or connect to production systems, evaluating the vendor's security posture, compliance certifications, and data-handling practices.\n4.2 Vendor agreements shall include security requirements, data-protection obligations, incident-notification clauses, audit rights, and termination data-return/destruction provisions; agreements are reviewed by the Security Lead before execution.\n4.3 Where development work is contracted to an external party - not a standing arrangement for Bluth Company's core platform today - the vendor risk assessment and the source-code security requirements and merge-request review gate defined in the Secure Coding and Software Development Lifecycle Policies shall apply before any outsourced code is accepted.\n4.4 Subservice organization SOC reports (or equivalent assurance reports) shall be reviewed at least annually; complementary user entity controls (CUECs) identified in those reports shall be documented and verified as operating effectively, and vendor service delivery shall be monitored on an ongoing basis against agreed terms.\n4.5 Vendor access to Bluth Company systems shall follow least privilege and be subject to the same access-control requirements as employee access, including multi-factor authentication and periodic access review.\n4.6 A vendor register shall be maintained documenting all active vendors, their risk tier, last assessment date, and review schedule; high-risk vendors are reviewed annually and critical vendors quarterly.\n4.7 Subservice organizations classified as critical - currently Tidewell Advisory Group, Model Home Data Lake, Lucille Identity Cloud, Model Home Data Lake, and the SOC 2 examining CPA firm - require enhanced contractual protections: right-to-audit clauses, transition plans with 90-day notice, breach notification within 72 hours, data-residency disclosure, subprocessor consent, firm-internal segregation-of-duties attestation where applicable, and quarterly export of records under their custody to Bluth Company-controlled storage; a pre-qualified secondary provider is maintained on a 30-day-engageable shortlist, refreshed annually.\n4.8 The customer-facing subprocessor list published at bluth.example shall be updated within 30 days of engaging any new subservice organization that processes customer or personal data, and customers subscribed to change notifications shall be notified.\n4.9 Bluth Company operates no payment processor and stores no cardholder data; PCI-DSS is out of scope. Before any payment processor is engaged, it shall be assessed for PCI-DSS compliance at onboarding and reassessed annually under §4.1, and this policy updated to name it.\n\n## 5. Exceptions\nAn exception to the risk-assessment or contractual-protection requirements above - for example, onboarding a vendor before assessment completes because of an urgent business need - requires documented justification, a compensating control, and Security Lead approval; exceptions are time-bound and reviewed at the next quarterly vendor register review.\n\n## 6. Enforcement\nEngaging a vendor without completing the required risk assessment is a policy violation addressed under the disciplinary provisions of the Human Resources Security Policy. Failing to update the public subprocessor list within 30 days of a critical-vendor change is treated as a customer-contract compliance issue and escalated to the Security Lead and CEO immediately. Compliance is monitored through the vendor register, assessment records, and SOC-report review documentation.\n\n## 7. Review & Ownership\nOwner: Security Lead. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually. Critical vendors are reviewed quarterly per §4.6.\n\n## 8. Related Documents & Controls\nRelated policies: Human Resources Security Policy (vendor and contractor personnel parity), Privacy Policy (data processing agreements, subprocessor privacy obligations), Legal & Regulatory Compliance Policy (contractual requirements register), Access Control Policy (vendor account access), Subservice Organization Critical-Vendor Lifecycle Process.\nGoverns controls: A.5.19, A.5.20, A.5.21, A.5.22, A.8.30, CC9.2, SOC1-12, Third-party vendor risk assessment & monitoring, Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit, Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled).\nOperated by: the vendor assurance review process; Subservice Organization Critical-Vendor Lifecycle Process.","policy_type":"policy","policy_owner":"michael.bluth@bluth.example","approved_by":"george.michael@bluth.example","version":"1.0","framework":["iso-27001","soc2","soc1"],"domains":["third_party_supply_chain_risk","governance_policy_oversight","human_resources_personnel_security"],"review_frequency":"annual","effective_date":"2026-02-09","next_review_date":"2027-01-15"}},{"title":"Vulnerability & Patch Management Policy","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Defines risk-based vulnerability identification, severity-tiered remediation SLAs (Critical 7d / High 30d / Medium 90d / Low 180d), scheduled patching, annual penetration testing, and rescan verification across Bluth Company infrastructure, applications, and dependencies.","full_description":"# Vulnerability & Patch Management Policy\n\n## 1. Purpose\nThis policy establishes requirements for identifying, assessing, prioritizing, remediating, and verifying technical vulnerabilities across Bluth Company infrastructure, applications, and dependencies, so that exploitable weaknesses are addressed before they can be used against the platform or customer data.\n\n## 2. Scope\nThis policy applies to all production infrastructure on Model Home Data Lake (the Model Home compute tier, Cloud SQL, networking), application code and third-party dependencies, container images, and the development toolchain. It covers automated scanning, manual assessment, and third-party penetration-test findings.\n\n## 3. Roles & Responsibilities\nThe Security Lead configures scanning, triages results, sets SLA timelines, and reports metrics. System owners remediate vulnerabilities in their systems within SLA. DevOps maintains scanning infrastructure and applies infrastructure patches. Engineering updates application dependencies and code-level fixes. Management reviews metrics and approves risk-acceptance exceptions.\n\n## 4. Policy Statements\n4.1 Automated vulnerability scanning runs at least weekly across Model Home Data Lake infrastructure via Security Command Center, and on every merge request and scheduled pipeline via Model Home Data Lake Ultimate's SAST, Secret Detection, Dependency Scanning, and Container Scanning; this scanning is Bluth Company's detection mechanism both for configuration changes that introduce new vulnerabilities and for newly disclosed vulnerabilities affecting existing configurations. A merge is blocked on any unwaived Critical or High finding.\n4.2 Vulnerabilities are triaged, de-duplicated, and prioritized by CVSS score and exploitability, and tracked to closure in the Model Home Data Lake issue tracker with an assigned owner.\n4.3 Remediation meets defined service levels by severity: Critical within 7 days, High within 30 days, Medium within 90 days, and Low within 180 days. Where remediation within SLA is infeasible, a documented, time-bound risk acceptance with compensating controls is approved by the Security Lead.\n4.4 System patches and security updates follow the Change Management process and are applied on a configured schedule; container base images are rebuilt regularly to pick up upstream security fixes.\n4.5 A third-party penetration test of the customer-facing platform (GOB Security Monitoring) is performed at least annually, with findings tracked to remediation and Critical/High findings retested to confirm closure.\n4.6 Remediation is verified by rescan, and vulnerability metrics - counts by severity, SLA compliance, and mean time to remediate - are reported to management at least monthly.\n4.7 A vulnerability reported from outside Bluth Company - by a customer, researcher, or vendor - is received through the monitored michael.bluth@bluth.example group, acknowledged to the reporter, and enters the same triage, prioritization, and remediation-SLA flow as an internally discovered finding; a report indicating active exploitation is escalated as a security incident under the Incident Response Policy.\n\n## 5. Exceptions\nWhere remediating a vulnerability within its SLA would require disruptive downtime or an unavailable vendor fix, the Security Lead documents a time-bound risk acceptance naming the compensating control (such as network isolation or enhanced monitoring) and a re-review date; the acceptance is reported to management.\n\n## 6. Enforcement\nMissing a remediation SLA without an approved risk acceptance, or disabling a required scan, is a policy violation escalated to the Head of Engineering and, for repeated occurrences, handled under the Human Resources Security Policy's disciplinary process. Compliance is verified through weekly scan reports, triage and remediation records, rescan verification, the annual penetration-test report, and the monthly metrics reported to management.\n\n## 7. Review & Ownership\nOwner: Security Lead / Head of Engineering. Review cadence: at least annually and on significant change, via annual policy review; approved by the CEO before publication; acknowledged by personnel on hire and annually.\n\n## 8. Related Documents & Controls\nRelated policies: Change Management Policy; Secure Coding Policy; Software Development Lifecycle Policy; Configuration Management Policy; Threat Intelligence Policy.\nGoverns controls: A.8.8 - Management of technical vulnerabilities; CC7.1.\nOperated by: the vulnerability and patch management cycle; technical security testing and penetration-test engagements.","policy_type":"policy","policy_owner":"george.michael@bluth.example","approved_by":"maeby.fuenke@bluth.example","version":"1.0","framework":["iso-27001","soc2"],"domains":["secure_configuration_change_management","vulnerability_patch_management"],"review_frequency":"annual","effective_date":"2026-03-09","next_review_date":"2027-01-16"}}],"system":[{"title":"Banana ERP","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Banana ERP is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":false,"category":"saas_software","tier":"critical","data_classification":"restricted","business_owner":"michael.bluth@bluth.example","risk_owner":"george.michael@bluth.example","reassessment_cadence":"quarterly","last_assessment_date":"2026-07-12","next_reassessment_date":"2026-11-10","monitoring_status":"enrolled","contract_end_date":null}},{"title":"Lucille Identity Cloud","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Lucille Identity Cloud is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":true,"category":"cloud_infrastructure","tier":"critical","data_classification":"restricted","business_owner":"george.michael@bluth.example","risk_owner":"maeby.fuenke@bluth.example","reassessment_cadence":"semi_annual","last_assessment_date":"2026-08-01","next_reassessment_date":"2026-09-10","monitoring_status":"enrolled","contract_end_date":"2027-01-18"}},{"title":"Cornballer Revenue Engine","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Cornballer Revenue Engine is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":false,"category":"saas_software","tier":"high","data_classification":"confidential","business_owner":"maeby.fuenke@bluth.example","risk_owner":"ann.veal@bluth.example","reassessment_cadence":"annual","last_assessment_date":"2025-08-11","next_reassessment_date":"2026-12-09","monitoring_status":"enrolled","contract_end_date":null}},{"title":"Seaward Payroll Service","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Seaward Payroll Service is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":true,"category":"data_processing","tier":"high","data_classification":"restricted","business_owner":"ann.veal@bluth.example","risk_owner":"michael.bluth@bluth.example","reassessment_cadence":"biennial","last_assessment_date":"2026-07-02","next_reassessment_date":"2027-02-27","monitoring_status":"not_enrolled","contract_end_date":"2028-07-11"}},{"title":"Model Home Data Lake","status":"INACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Model Home Data Lake is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":false,"category":"cloud_infrastructure","tier":"high","data_classification":"confidential","business_owner":"michael.bluth@bluth.example","risk_owner":"george.michael@bluth.example","reassessment_cadence":"ad_hoc","last_assessment_date":"2026-05-03","next_reassessment_date":"2026-08-10","monitoring_status":"exited","contract_end_date":null}},{"title":"Never Nude HR Platform","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Never Nude HR Platform is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":true,"category":"saas_software","tier":"medium","data_classification":"confidential","business_owner":"george.michael@bluth.example","risk_owner":"maeby.fuenke@bluth.example","reassessment_cadence":"quarterly","last_assessment_date":"2026-05-12","next_reassessment_date":"2026-11-19","monitoring_status":"not_enrolled","contract_end_date":"2027-09-15"}},{"title":"Sudden Valley Network","status":"ACTIVE","visibility":"private","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Sudden Valley Network is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":false,"category":"hardware_supplier","tier":"medium","data_classification":"internal","business_owner":"maeby.fuenke@bluth.example","risk_owner":"ann.veal@bluth.example","reassessment_cadence":"semi_annual","last_assessment_date":"2026-08-12","next_reassessment_date":"2027-02-07","monitoring_status":"enrolled","contract_end_date":null}},{"title":"GOB Security Monitoring","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"GOB Security Monitoring is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":true,"category":"managed_services","tier":"high","data_classification":"restricted","business_owner":"ann.veal@bluth.example","risk_owner":"michael.bluth@bluth.example","reassessment_cadence":"annual","last_assessment_date":"2026-08-06","next_reassessment_date":"2026-08-06","monitoring_status":"enrolled","contract_end_date":"2026-10-30"}},{"title":"Tidewell File Exchange","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Tidewell File Exchange is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":true,"category":"professional_services","tier":"low","data_classification":"public","business_owner":"michael.bluth@bluth.example","risk_owner":"george.michael@bluth.example","reassessment_cadence":"biennial","last_assessment_date":"2025-03-29","next_reassessment_date":"2027-09-15","contract_end_date":"2026-07-12"}},{"title":"Stair Car Facilities System","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Stair Car Facilities System is a fictional technology or service-provider dependency.","full_description":"A fictional Bluth Company system, with its monitoring, criticality, assessment evidence, owner and hosting recorded.","vendor":false,"category":"facilities","tier":"low","data_classification":"none","business_owner":"george.michael@bluth.example","risk_owner":"maeby.fuenke@bluth.example","reassessment_cadence":"ad_hoc","last_assessment_date":"2026-07-22","next_reassessment_date":"2026-11-11","monitoring_status":"enrolled","contract_end_date":null}},{"title":"Sitwell Payroll Bureau","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Sitwell Payroll Bureau: third-party data processing provider.","vendor":true,"category":"data_processing","tier":"critical","data_classification":"restricted","business_owner":"ann.veal@bluth.example","risk_owner":"george.michael@bluth.example","reassessment_cadence":"annual","last_assessment_date":"2025-09-15","next_reassessment_date":"2026-07-27","contract_end_date":"2026-09-20","monitoring_status":"enrolled"}},{"title":"Magic Supply Wholesale","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Magic Supply Wholesale: third-party hardware supplier provider.","vendor":true,"category":"hardware_supplier","tier":"medium","data_classification":"internal","business_owner":"george.michael@bluth.example","risk_owner":"maeby.fuenke@bluth.example","reassessment_cadence":"biennial","last_assessment_date":"2026-01-23","next_reassessment_date":"2026-08-31","contract_end_date":"2026-08-06","monitoring_status":"enrolled"}},{"title":"Seaside Cloud Hosting","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Seaside Cloud Hosting: third-party cloud infrastructure provider.","vendor":true,"category":"cloud_infrastructure","tier":"high","data_classification":"confidential","business_owner":"maeby.fuenke@bluth.example","risk_owner":"michael.bluth@bluth.example","reassessment_cadence":"semi_annual","last_assessment_date":"2026-02-22","next_reassessment_date":"2026-10-25","contract_end_date":"2027-01-08","monitoring_status":"enrolled"}},{"title":"Bluth Legal Retainer Services","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth Legal Retainer Services: third-party professional services provider.","vendor":true,"category":"professional_services","tier":"low","data_classification":"confidential","business_owner":"michael.bluth@bluth.example","risk_owner":"ann.veal@bluth.example","reassessment_cadence":"annual","last_assessment_date":"2026-06-12","next_reassessment_date":"2027-06-07","contract_end_date":"2027-10-05","monitoring_status":"enrolled"}}],"fsli":[{"title":"Cash and Cash Equivalents","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Cash and Cash Equivalents is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"balance_sheet","fs_order":"1.0","account_ref":"BLU-FS-001","tb_account":false,"balance":1500000,"annualized_balance":1800000,"balance_date":"2026-06-30","yoy_change_pct":-14,"financial_significance":"high","valuation_complexity":"low","restatement_history":"medium","external_sensitivity":"high","fraud_risk":"low","activity_volume":"high","volatility":"medium","disclosure_impact":"low","weighted_score":3,"overall_assessment":"high","significant":true,"assertions":["existence_occurrence","rights_obligations"],"rationale":"Balance, activity, complexity, or disclosure exposure makes this account significant.","assessed_fy":"FY2026"}},{"title":"Accounts Receivable","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Accounts Receivable is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"income_statement","fs_order":"2.0","account_ref":"BLU-FS-002","tb_account":false,"balance":3000000,"annualized_balance":3600000,"balance_date":"2026-06-30","yoy_change_pct":-10.5,"financial_significance":"high","valuation_complexity":"medium","restatement_history":"low","external_sensitivity":"medium","fraud_risk":"high","activity_volume":"medium","volatility":"low","disclosure_impact":"medium","weighted_score":3,"overall_assessment":"high","significant":true,"assertions":["completeness","accuracy_valuation"],"rationale":"Balance, activity, complexity, or disclosure exposure makes this account significant.","assessed_fy":"FY2026"}},{"title":"Property and Equipment","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Property and Equipment is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"cash_flow","fs_order":"3.0","account_ref":"BLU-FS-003","tb_account":false,"balance":4500000,"annualized_balance":5400000,"balance_date":"2026-06-30","yoy_change_pct":-7,"financial_significance":"medium","valuation_complexity":"high","restatement_history":"high","external_sensitivity":"low","fraud_risk":"medium","activity_volume":"low","volatility":"high","disclosure_impact":"high","weighted_score":2,"overall_assessment":"medium","significant":false,"assertions":["accuracy_valuation","classification"],"rationale":"The account remains below the current scoping threshold.","assessed_fy":"FY2026"}},{"title":"Accounts Payable","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Accounts Payable is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"equity","fs_order":"4.0","account_ref":"BLU-FS-004","tb_account":false,"balance":6000000,"annualized_balance":7200000,"balance_date":"2026-06-30","yoy_change_pct":-3.5,"financial_significance":"high","valuation_complexity":"low","restatement_history":"medium","external_sensitivity":"high","fraud_risk":"low","activity_volume":"high","volatility":"medium","disclosure_impact":"low","weighted_score":3,"overall_assessment":"high","significant":true,"assertions":["cutoff","completeness"],"rationale":"Balance, activity, complexity, or disclosure exposure makes this account significant.","assessed_fy":"FY2026"}},{"title":"Revenue","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Revenue is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"disclosure","fs_order":"5.0","account_ref":"BLU-FS-005","tb_account":false,"balance":7500000,"annualized_balance":9000000,"balance_date":"2026-06-30","yoy_change_pct":0,"financial_significance":"high","valuation_complexity":"medium","restatement_history":"low","external_sensitivity":"medium","fraud_risk":"high","activity_volume":"medium","volatility":"low","disclosure_impact":"high","weighted_score":3,"overall_assessment":"high","significant":true,"assertions":["presentation_disclosure"],"rationale":"Balance, activity, complexity, or disclosure exposure makes this account significant.","assessed_fy":"FY2026"}},{"title":"Operating Expenses","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Operating Expenses is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"balance_sheet","fs_order":"6.0","account_ref":"BLU-FS-006","tb_account":false,"balance":9000000,"annualized_balance":10800000,"balance_date":"2026-06-30","yoy_change_pct":3.5,"financial_significance":"medium","valuation_complexity":"high","restatement_history":"high","external_sensitivity":"low","fraud_risk":"medium","activity_volume":"low","volatility":"high","disclosure_impact":"high","weighted_score":2,"overall_assessment":"medium","significant":false,"assertions":["existence_occurrence","rights_obligations"],"rationale":"The account remains below the current scoping threshold.","assessed_fy":"FY2026"}},{"title":"Net Cash from Operations","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Net Cash from Operations is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"income_statement","fs_order":"7.0","account_ref":"BLU-FS-007","tb_account":false,"balance":10500000,"annualized_balance":12600000,"balance_date":"2026-06-30","yoy_change_pct":7,"financial_significance":"high","valuation_complexity":"low","restatement_history":"medium","external_sensitivity":"high","fraud_risk":"low","activity_volume":"high","volatility":"medium","disclosure_impact":"low","weighted_score":3,"overall_assessment":"high","significant":true,"assertions":["completeness","accuracy_valuation"],"rationale":"Balance, activity, complexity, or disclosure exposure makes this account significant.","assessed_fy":"FY2026"}},{"title":"Common Stock and APIC","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Common Stock and APIC is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"cash_flow","fs_order":"8.0","account_ref":"BLU-FS-008","tb_account":false,"balance":12000000,"annualized_balance":14400000,"balance_date":"2026-06-30","yoy_change_pct":10.5,"financial_significance":"high","valuation_complexity":"medium","restatement_history":"low","external_sensitivity":"medium","fraud_risk":"high","activity_volume":"medium","volatility":"low","disclosure_impact":"medium","weighted_score":3,"overall_assessment":"high","significant":true,"assertions":["accuracy_valuation","classification"],"rationale":"Balance, activity, complexity, or disclosure exposure makes this account significant.","assessed_fy":"FY2026"}},{"title":"Retained Earnings","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Retained Earnings is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"equity","fs_order":"9.0","account_ref":"BLU-FS-009","tb_account":false,"balance":13500000,"annualized_balance":16200000,"balance_date":"2026-06-30","yoy_change_pct":14,"financial_significance":"medium","valuation_complexity":"high","restatement_history":"high","external_sensitivity":"low","fraud_risk":"medium","activity_volume":"low","volatility":"high","disclosure_impact":"high","weighted_score":2,"overall_assessment":"medium","significant":false,"assertions":["cutoff","completeness"],"rationale":"The account remains below the current scoping threshold.","assessed_fy":"FY2026"}},{"title":"Commitments and Contingencies","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Commitments and Contingencies is a fictional financial-statement line item.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"disclosure","fs_order":"10.0","account_ref":"BLU-FS-010","tb_account":false,"balance":15000000,"annualized_balance":18000000,"balance_date":"2026-06-30","yoy_change_pct":17.5,"financial_significance":"high","valuation_complexity":"low","restatement_history":"medium","external_sensitivity":"high","fraud_risk":"low","activity_volume":"high","volatility":"medium","disclosure_impact":"high","weighted_score":3,"overall_assessment":"high","significant":true,"assertions":["presentation_disclosure"],"rationale":"Balance, activity, complexity, or disclosure exposure makes this account significant.","assessed_fy":"FY2026"}},{"title":"Operating Cash Accounts","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Operating Cash Accounts is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"balance_sheet","fs_order":"1.1","account_ref":"BLU-TB-001","tb_account":true,"balance":250000,"annualized_balance":300000,"balance_date":"2026-06-30","yoy_change_pct":-14,"significant":false}},{"title":"Customer Receivables","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Customer Receivables is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"income_statement","fs_order":"2.1","account_ref":"BLU-TB-002","tb_account":true,"balance":500000,"annualized_balance":600000,"balance_date":"2026-06-30","yoy_change_pct":-10.5,"significant":false}},{"title":"Construction in Progress","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Construction in Progress is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"cash_flow","fs_order":"3.1","account_ref":"BLU-TB-003","tb_account":true,"balance":750000,"annualized_balance":900000,"balance_date":"2026-06-30","yoy_change_pct":-7,"significant":false}},{"title":"Trade Payables","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Trade Payables is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"equity","fs_order":"4.1","account_ref":"BLU-TB-004","tb_account":true,"balance":1000000,"annualized_balance":1200000,"balance_date":"2026-06-30","yoy_change_pct":-3.5,"significant":false}},{"title":"Subscription Revenue","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Subscription Revenue is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"disclosure","fs_order":"5.1","account_ref":"BLU-TB-005","tb_account":true,"balance":1250000,"annualized_balance":1500000,"balance_date":"2026-06-30","yoy_change_pct":0,"significant":false}},{"title":"Payroll Expense","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Payroll Expense is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"balance_sheet","fs_order":"6.1","account_ref":"BLU-TB-006","tb_account":true,"balance":1500000,"annualized_balance":1800000,"balance_date":"2026-06-30","yoy_change_pct":3.5,"significant":false}},{"title":"Cash Collections","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Cash Collections is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"income_statement","fs_order":"7.1","account_ref":"BLU-TB-007","tb_account":true,"balance":1750000,"annualized_balance":2100000,"balance_date":"2026-06-30","yoy_change_pct":7,"significant":false}},{"title":"Employee Equity Awards","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Employee Equity Awards is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"cash_flow","fs_order":"8.1","account_ref":"BLU-TB-008","tb_account":true,"balance":2000000,"annualized_balance":2400000,"balance_date":"2026-06-30","yoy_change_pct":10.5,"significant":false}},{"title":"Current Period Earnings","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Current Period Earnings is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"equity","fs_order":"9.1","account_ref":"BLU-TB-009","tb_account":true,"balance":2250000,"annualized_balance":2700000,"balance_date":"2026-06-30","yoy_change_pct":14,"significant":false}},{"title":"Legal Contingencies","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Legal Contingencies is a fictional trial-balance component.","full_description":"A Bluth Company financial statement line item, with its SOX materiality, assertions, statement, parent account and assessment recorded.","statement":"disclosure","fs_order":"10.1","account_ref":"BLU-TB-010","tb_account":true,"balance":2500000,"annualized_balance":3000000,"balance_date":"2026-06-30","yoy_change_pct":17.5,"significant":false}}],"requirement":[{"title":"ISO 27001 A.5.1 — Information-security policy governance","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates information-security policy governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates information-security policy governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.1","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.1 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"not_implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.2 — Security accountability assignments","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates security accountability assignments within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates security accountability assignments within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.2","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.2 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.3 — Conflicting-duty separation","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates conflicting-duty separation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates conflicting-duty separation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.3","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.3 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.4 — Manager security obligations","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates manager security obligations within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates manager security obligations within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.4","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.4 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.5 — Regulatory authority coordination","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates regulatory authority coordination within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates regulatory authority coordination within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.5","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.5 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.6 — Security community engagement","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates security community engagement within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates security community engagement within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.6","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.6 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.7 — Emerging threat insights","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates emerging threat insights within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates emerging threat insights within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.7","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.7 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.8 — Project security integration","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates project security integration within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates project security integration within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.8","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.8 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.9 — Information-asset register","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates information-asset register within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates information-asset register within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.9","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.9 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.10 — Approved asset-use rules","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates approved asset-use rules within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates approved asset-use rules within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.10","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.10 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.11 — Asset recovery at exit","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates asset recovery at exit within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates asset recovery at exit within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.11","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.11 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.12 — Information sensitivity classification","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates information sensitivity classification within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates information sensitivity classification within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.12","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.12 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.13 — Classification marking practices","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates classification marking practices within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates classification marking practices within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.13","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.13 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.14 — Protected data exchange","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates protected data exchange within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates protected data exchange within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.14","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.14 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"not_implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.15 — Logical and physical access governance","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates logical and physical access governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates logical and physical access governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.15","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.15 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.16 — Identity lifecycle governance","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates identity lifecycle governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates identity lifecycle governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.16","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.16 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.17 — Authenticator protection","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates authenticator protection within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates authenticator protection within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.17","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"not_applicable","applicability_justification":"Bluth excludes A.5.17 from the current Statement of Applicability because the fictional operating model has no corresponding in-scope activity; the exclusion is reviewed annually.","implementation_status":"not_applicable","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.18 — Access entitlement administration","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates access entitlement administration within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates access entitlement administration within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.18","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.18 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.19 — Supplier security governance","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates supplier security governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates supplier security governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.19","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"pending_review","applicability_justification":"Bluth has scheduled the A.5.19 applicability decision for the next ISMS review; it remains outside covered totals until an accountable reviewer records the decision.","implementation_status":"planned","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.20 — Contracted supplier safeguards","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates contracted supplier safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates contracted supplier safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.20","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.20 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.21 — Technology supply-chain assurance","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates technology supply-chain assurance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates technology supply-chain assurance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.21","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.21 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.22 — Supplier service oversight","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates supplier service oversight within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates supplier service oversight within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.22","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.22 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.23 — Cloud service security governance","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates cloud service security governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates cloud service security governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.23","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.23 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.24 — Incident response preparedness","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates incident response preparedness within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates incident response preparedness within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.24","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.24 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.25 — Security event triage","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates security event triage within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates security event triage within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.25","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.25 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.26 — Incident containment and response","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates incident containment and response within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates incident containment and response within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.26","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.26 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.27 — Post-incident improvement","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates post-incident improvement within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates post-incident improvement within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.27","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.27 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"not_implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.28 — Forensic evidence handling","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates forensic evidence handling within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates forensic evidence handling within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.28","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.28 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.29 — Security controls during disruption","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates security controls during disruption within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates security controls during disruption within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.29","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.29 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.30 — Technology continuity readiness","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates technology continuity readiness within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates technology continuity readiness within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.30","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.30 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.31 — Compliance obligation register","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates compliance obligation register within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates compliance obligation register within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.31","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.31 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.32 — Intellectual-property safeguards","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates intellectual-property safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates intellectual-property safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.32","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.32 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.33 — Records retention and integrity","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates records retention and integrity within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates records retention and integrity within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.33","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.33 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.34 — Personal-data privacy safeguards","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates personal-data privacy safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates personal-data privacy safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.34","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"not_applicable","applicability_justification":"Bluth excludes A.5.34 from the current Statement of Applicability because the fictional operating model has no corresponding in-scope activity; the exclusion is reviewed annually.","implementation_status":"not_applicable","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.35 — Independent security assurance","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates independent security assurance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates independent security assurance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.35","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.35 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.36 — Security-policy compliance checks","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates security-policy compliance checks within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates security-policy compliance checks within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.36","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.36 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.5.37 — Controlled operating procedures","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates controlled operating procedures within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates controlled operating procedures within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.5.37","framework":"iso-27001","framework_version":"2022","domain":"Organizational","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.5.37 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"ISO 27001 A.6.1 — Personnel vetting","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates personnel vetting within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates personnel vetting within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.6.1","framework":"iso-27001","framework_version":"2022","domain":"People","requirement_kind":"control","applicability":"pending_review","applicability_justification":"Bluth has scheduled the A.6.1 applicability decision for the next ISMS review; it remains outside covered totals until an accountable reviewer records the decision.","implementation_status":"planned","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["human_resources_personnel_security"]}},{"title":"ISO 27001 A.6.2 — Employment security terms","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates employment security terms within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates employment security terms within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.6.2","framework":"iso-27001","framework_version":"2022","domain":"People","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.6.2 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["human_resources_personnel_security"]}},{"title":"ISO 27001 A.6.3 — Workforce security learning","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates workforce security learning within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates workforce security learning within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.6.3","framework":"iso-27001","framework_version":"2022","domain":"People","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.6.3 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"not_implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["human_resources_personnel_security"]}},{"title":"ISO 27001 A.6.4 — Security conduct enforcement","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates security conduct enforcement within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates security conduct enforcement within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.6.4","framework":"iso-27001","framework_version":"2022","domain":"People","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.6.4 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["human_resources_personnel_security"]}},{"title":"ISO 27001 A.6.5 — Exit and role-change obligations","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates exit and role-change obligations within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates exit and role-change obligations within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.6.5","framework":"iso-27001","framework_version":"2022","domain":"People","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.6.5 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["human_resources_personnel_security"]}},{"title":"ISO 27001 A.6.6 — Confidentiality commitments","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates confidentiality commitments within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates confidentiality commitments within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.6.6","framework":"iso-27001","framework_version":"2022","domain":"People","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.6.6 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["human_resources_personnel_security"]}},{"title":"ISO 27001 A.6.7 — Secure remote-work practices","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates secure remote-work practices within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates secure remote-work practices within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.6.7","framework":"iso-27001","framework_version":"2022","domain":"People","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.6.7 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["human_resources_personnel_security"]}},{"title":"ISO 27001 A.6.8 — Workforce event escalation","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates workforce event escalation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates workforce event escalation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.6.8","framework":"iso-27001","framework_version":"2022","domain":"People","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.6.8 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["human_resources_personnel_security"]}},{"title":"ISO 27001 A.7.1 — Protected facility boundaries","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates protected facility boundaries within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates protected facility boundaries within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.1","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.1 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.2 — Authorized facility access","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates authorized facility access within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates authorized facility access within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.2","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.2 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.3 — Secure workspaces and rooms","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates secure workspaces and rooms within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates secure workspaces and rooms within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.3","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.3 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.4 — Facility surveillance","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates facility surveillance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates facility surveillance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.4","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.4 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.5 — Environmental and physical resilience","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates environmental and physical resilience within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates environmental and physical resilience within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.5","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.5 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.6 — Restricted-area working practices","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates restricted-area working practices within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates restricted-area working practices within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.6","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"not_applicable","applicability_justification":"Bluth excludes A.7.6 from the current Statement of Applicability because the fictional operating model has no corresponding in-scope activity; the exclusion is reviewed annually.","implementation_status":"not_applicable","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.7 — Unattended workspace hygiene","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates unattended workspace hygiene within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates unattended workspace hygiene within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.7","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.7 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.8 — Protected equipment placement","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates protected equipment placement within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates protected equipment placement within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.8","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.8 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"not_implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.9 — Off-site asset protection","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates off-site asset protection within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates off-site asset protection within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.9","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.9 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.10 — Removable and stored media protection","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates removable and stored media protection within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates removable and stored media protection within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.10","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.10 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.11 — Resilient facility utilities","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates resilient facility utilities within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates resilient facility utilities within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.11","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.11 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.12 — Protected power and data cabling","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates protected power and data cabling within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates protected power and data cabling within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.12","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"pending_review","applicability_justification":"Bluth has scheduled the A.7.12 applicability decision for the next ISMS review; it remains outside covered totals until an accountable reviewer records the decision.","implementation_status":"planned","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.13 — Secure equipment servicing","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates secure equipment servicing within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates secure equipment servicing within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.13","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.13 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.7.14 — Equipment sanitization and disposal","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates equipment sanitization and disposal within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates equipment sanitization and disposal within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.7.14","framework":"iso-27001","framework_version":"2022","domain":"Physical","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.7.14 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["physical_environmental_security"]}},{"title":"ISO 27001 A.8.1 — Endpoint security baseline","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates endpoint security baseline within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates endpoint security baseline within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.1","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.1 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.2 — Administrative privilege governance","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates administrative privilege governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates administrative privilege governance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.2","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.2 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.3 — Need-to-know data access","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates need-to-know data access within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates need-to-know data access within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.3","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.3 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.4 — Source repository access","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates source repository access within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates source repository access within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.4","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.4 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.5 — Strong user authentication","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates strong user authentication within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates strong user authentication within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.5","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.5 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.6 — Resource capacity planning","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates resource capacity planning within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates resource capacity planning within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.6","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.6 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.7 — Malware defense","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates malware defense within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates malware defense within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.7","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.7 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"not_implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.8 — Vulnerability remediation program","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates vulnerability remediation program within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates vulnerability remediation program within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.8","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.8 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.9 — Secure configuration baselines","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates secure configuration baselines within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates secure configuration baselines within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.9","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"not_applicable","applicability_justification":"Bluth excludes A.8.9 from the current Statement of Applicability because the fictional operating model has no corresponding in-scope activity; the exclusion is reviewed annually.","implementation_status":"not_applicable","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.10 — Verified data disposal","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates verified data disposal within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates verified data disposal within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.10","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.10 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.11 — Sensitive-data obfuscation","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates sensitive-data obfuscation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates sensitive-data obfuscation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.11","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.11 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.12 — Data exfiltration safeguards","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates data exfiltration safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates data exfiltration safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.12","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.12 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.13 — Resilient backups","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates resilient backups within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates resilient backups within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.13","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.13 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.14 — Processing-service redundancy","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates processing-service redundancy within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates processing-service redundancy within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.14","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.14 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.15 — Security event logging","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates security event logging within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates security event logging within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.15","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.15 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.16 — Security telemetry monitoring","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates security telemetry monitoring within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates security telemetry monitoring within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.16","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.16 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.17 — Trusted time sources","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates trusted time sources within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates trusted time sources within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.17","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"pending_review","applicability_justification":"Bluth has scheduled the A.8.17 applicability decision for the next ISMS review; it remains outside covered totals until an accountable reviewer records the decision.","implementation_status":"planned","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.18 — Privileged utility restrictions","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates privileged utility restrictions within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates privileged utility restrictions within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.18","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.18 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.19 — Production software authorization","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates production software authorization within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates production software authorization within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.19","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.19 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"planned","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.20 — Network protection architecture","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates network protection architecture within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates network protection architecture within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.20","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.20 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"not_implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.21 — Network service assurance","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates network service assurance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates network service assurance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.21","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.21 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.22 — Network zone isolation","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates network zone isolation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates network zone isolation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.22","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.22 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.23 — Harmful web-content controls","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates harmful web-content controls within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates harmful web-content controls within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.23","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.23 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.24 — Cryptographic protection","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates cryptographic protection within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates cryptographic protection within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.24","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.24 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.25 — Secure product delivery lifecycle","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates secure product delivery lifecycle within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates secure product delivery lifecycle within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.25","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.25 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.26 — Application protection specifications","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates application protection specifications within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates application protection specifications within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.26","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"not_applicable","applicability_justification":"Bluth excludes A.8.26 from the current Statement of Applicability because the fictional operating model has no corresponding in-scope activity; the exclusion is reviewed annually.","implementation_status":"not_applicable","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.27 — Secure-by-design architecture","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates secure-by-design architecture within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates secure-by-design architecture within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.27","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.27 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.28 — Defensive coding practices","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates defensive coding practices within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates defensive coding practices within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.28","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.28 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.29 — Pre-release security validation","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates pre-release security validation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates pre-release security validation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.29","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.29 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.30 — Third-party development assurance","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates third-party development assurance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates third-party development assurance within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.30","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.30 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.31 — Environment separation","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth evaluates environment separation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates environment separation within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.31","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.31 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.32 — Controlled technology changes","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth evaluates controlled technology changes within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates controlled technology changes within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.32","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.32 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"partially_implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.33 — Protected test datasets","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth evaluates protected test datasets within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates protected test datasets within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.33","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.33 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"not_implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"ISO 27001 A.8.34 — Audit-test safeguards","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth evaluates audit-test safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up.","full_description":"Bluth evaluates audit-test safeguards within its ISO 27001 Annex A applicability review, recording accountable ownership, implementation controls, evidence expectations, and review follow-up. Source: ISO/IEC 27001:2022 Annex A.","reference":"A.8.34","framework":"iso-27001","framework_version":"2022","domain":"Technological","requirement_kind":"control","applicability":"applicable","applicability_justification":"A.8.34 is applicable to Bluth's fictional ISMS scope and is assessed through accountable controls, operating evidence, and annual Statement of Applicability review.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["secure_configuration_change_management"]}},{"title":"SOC 2 CC1.1 — Integrity and ethical values","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates integrity and ethical values; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates integrity and ethical values; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC1.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC1.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC1.2 — Board independence and oversight","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates board independence and oversight; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates board independence and oversight; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC1.2","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC1.2 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC1.3 — Organizational authority and accountability","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates organizational authority and accountability; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates organizational authority and accountability; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC1.3","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC1.3 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC1.4 — Competence and retention","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates competence and retention; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates competence and retention; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC1.4","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC1.4 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC1.5 — Internal-control accountability","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates internal-control accountability; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates internal-control accountability; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC1.5","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC1.5 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"partially_implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC2.1 — Quality information","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates quality information; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates quality information; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC2.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC2.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC2.2 — Internal communication","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates internal communication; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates internal communication; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC2.2","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC2.2 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC2.3 — External communication","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates external communication; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates external communication; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC2.3","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC2.3 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC3.1 — Clear objectives","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates clear objectives; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates clear objectives; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC3.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC3.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC3.2 — Enterprise risk identification and analysis","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates enterprise risk identification and analysis; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates enterprise risk identification and analysis; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC3.2","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC3.2 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"partially_implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC3.3 — Fraud-risk assessment","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates fraud-risk assessment; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates fraud-risk assessment; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC3.3","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC3.3 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"not_implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC3.4 — Change-risk assessment","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates change-risk assessment; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates change-risk assessment; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC3.4","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC3.4 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC4.1 — Ongoing and separate evaluations","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates ongoing and separate evaluations; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates ongoing and separate evaluations; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC4.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC4.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC4.2 — Deficiency communication","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates deficiency communication; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates deficiency communication; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC4.2","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC4.2 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC5.1 — Risk-mitigating control activities","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates risk-mitigating control activities; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates risk-mitigating control activities; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC5.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC5.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"partially_implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC5.2 — Technology general controls","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates technology general controls; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates technology general controls; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC5.2","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC5.2 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC5.3 — Policy-driven procedures","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates policy-driven procedures; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates policy-driven procedures; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC5.3","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC5.3 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC6.1 — Logical access safeguards","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates logical access safeguards; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates logical access safeguards; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC6.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC6.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC6.2 — Credential issuance and removal","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates credential issuance and removal; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates credential issuance and removal; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC6.2","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC6.2 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC6.3 — Role-based access changes","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates role-based access changes; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates role-based access changes; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC6.3","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC6.3 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"partially_implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC6.4 — Physical access restrictions","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates physical access restrictions; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates physical access restrictions; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC6.4","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC6.4 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC6.5 — Secure asset disposal","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates secure asset disposal; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates secure asset disposal; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC6.5","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC6.5 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"not_implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC6.6 — Boundary protection","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates boundary protection; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates boundary protection; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC6.6","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC6.6 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC6.7 — Secure information transmission","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates secure information transmission; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates secure information transmission; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC6.7","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC6.7 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC6.8 — Malicious software defenses","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates malicious software defenses; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates malicious software defenses; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC6.8","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC6.8 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"partially_implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC7.1 — Vulnerability and configuration monitoring","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates vulnerability and configuration monitoring; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates vulnerability and configuration monitoring; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC7.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC7.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC7.2 — Anomaly monitoring","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates anomaly monitoring; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates anomaly monitoring; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC7.2","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC7.2 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC7.3 — Security event evaluation","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates security event evaluation; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates security event evaluation; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC7.3","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC7.3 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC7.4 — Incident response","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates incident response; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates incident response; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC7.4","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC7.4 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC7.5 — Incident recovery","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates incident recovery; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates incident recovery; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC7.5","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC7.5 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"partially_implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC8.1 — Change management","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates change management; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates change management; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC8.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC8.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC9.1 — Business disruption risk","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates business disruption risk; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates business disruption risk; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC9.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC9.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 CC9.2 — Vendor and business-partner risk","status":"OPEN","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates vendor and business-partner risk; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates vendor and business-partner risk; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"CC9.2","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Security","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"CC9.2 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"not_implemented","requirement_owner":"george.michael@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["governance_policy_oversight"]}},{"title":"SOC 2 A1.1 — Capacity monitoring","status":"OPEN","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates capacity monitoring; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates capacity monitoring; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"A1.1","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Availability","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"A1.1 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"maeby.fuenke@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["business_continuity_disaster_recovery"]}},{"title":"SOC 2 A1.2 — Environmental and resilience safeguards","status":"OPEN","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates environmental and resilience safeguards; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates environmental and resilience safeguards; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"A1.2","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Availability","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"A1.2 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"partially_implemented","requirement_owner":"ann.veal@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["business_continuity_disaster_recovery"]}},{"title":"SOC 2 A1.3 — Recovery testing","status":"OPEN","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Bluth's declared SOC 2 Security and Availability scope evaluates recovery testing; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action.","full_description":"Bluth's declared SOC 2 Security and Availability scope evaluates recovery testing; reviewers document responsible controls, current evidence, identified gaps, and the next assessment action. Source: AICPA SOC 2 Trust Services Criteria — Security and Availability.","reference":"A1.3","framework":"soc2","framework_version":"2017 TSC (revised 2022)","domain":"Availability","requirement_kind":"criterion","applicability":"applicable","applicability_justification":"A1.3 is included in Bluth's declared SOC 2 Security and Availability scope and is assessed against mapped controls and current-period evidence.","implementation_status":"implemented","requirement_owner":"michael.bluth@bluth.example","last_review_date":"2026-08-11","next_review_date":"2027-08-11","domains":["business_continuity_disaster_recovery"]}}],"personnel":[{"title":"Michael Bluth","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Michael Bluth - President & Chief Executive, Executive.","personnel_key":"bluth-michael-bluth","full_name":"Michael Bluth","work_email":"michael.bluth@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"active","department":"Executive","position_title":"President & Chief Executive","reporting_arrangement":"principal","responsibilities":"Accountable executive for the Bluth control environment: approves policies, risk-acceptance decisions and the annual audit plan, chairs the quarterly control review, and signs the management assertion.","authority_and_escalation":"Executive approval for policy, budget and material risk acceptance; recuses from approving changes, access or remediation he requested himself.","responsibility_review_status":"approved","role_effective_date":"2016-08-11","role_effective_date_basis":"Engagement start date","engagement_start_date":"2016-08-11","systems_scope":"Banana ERP; Lucille Identity Cloud; Model Home Data Lake"}},{"title":"Ann Veal","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Ann Veal - Compliance Analyst, Compliance.","personnel_key":"bluth-ann-veal","full_name":"Ann Veal","work_email":"ann.veal@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"active","department":"Compliance","position_title":"Compliance Analyst","manager_name":"Michael Bluth","manager_personnel_key":"bluth-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Maintains the compliance requirement register, the policy review calendar and the risk register; coordinates evidence for regulatory attestations.","authority_and_escalation":"Records applicability and review conclusions; policy approval and risk acceptance remain with the President.","responsibility_review_status":"documented","role_effective_date":"2025-02-18","role_effective_date_basis":"Engagement start date","engagement_start_date":"2025-02-18","systems_scope":"Banana ERP; Lucille Identity Cloud; Tidewell File Exchange"}},{"title":"Lucille Austero","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Lucille Austero - Interim Controller, Finance.","personnel_key":"bluth-lucille-austero","full_name":"Lucille Austero","work_email":"lucille.austero@bluth.example","affiliation":"Austero Advisory","engagement_type":"contractor","engagement_status":"active","department":"Finance","position_title":"Interim Controller","manager_name":"Michael Bluth","manager_personnel_key":"bluth-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Runs the monthly close, reviews journal entries and reconciliations, and supervises the accounting and revenue teams until a permanent controller is appointed.","authority_and_escalation":"Approves journal entries and reconciliations within the delegation of authority; cannot approve her own entries or vendor payments.","responsibility_review_status":"documented","role_effective_date":"2026-07-28","role_effective_date_basis":"Engagement start date","engagement_start_date":"2026-07-28","systems_scope":"Banana ERP; Cornballer Revenue Engine"}},{"title":"Marta Estrella","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Marta Estrella - Revenue Analyst, Finance.","personnel_key":"bluth-marta-estrella","full_name":"Marta Estrella","work_email":"marta.estrella@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"active","department":"Finance","position_title":"Revenue Analyst","manager_name":"Lucille Austero","manager_personnel_key":"bluth-lucille-austero","reporting_arrangement":"line_managed","responsibilities":"Prepares revenue schedules, contract reviews and the monthly revenue reconciliation between the revenue engine and the ledger.","authority_and_escalation":"Prepares only; revenue recognition conclusions are reviewed by the Interim Controller.","responsibility_review_status":"documented","role_effective_date":"2026-06-27","role_effective_date_basis":"Engagement start date","engagement_start_date":"2026-06-27","systems_scope":"Cornballer Revenue Engine; Banana ERP"}},{"title":"Kitty Sanchez","status":"DRAFT","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Kitty Sanchez - Staff Accountant, Accounting.","personnel_key":"bluth-kitty-sanchez","full_name":"Kitty Sanchez","work_email":"kitty.sanchez@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"planned","department":"Accounting","position_title":"Staff Accountant","manager_name":"Lucille Austero","manager_personnel_key":"bluth-lucille-austero","reporting_arrangement":"line_managed","responsibilities":"Will post journal entries, maintain fixed-asset and prepaid schedules, and prepare balance-sheet reconciliations for controller review.","authority_and_escalation":"Prepares only once onboarded; no approval authority.","responsibility_review_status":"proposed","role_effective_date":"2026-08-16","role_effective_date_basis":"Engagement start date","engagement_start_date":"2026-08-16","systems_scope":"Banana ERP; Lucille Identity Cloud","verification_gaps":"Start date and access profile confirmed on the signed offer; background screening outstanding. No access is granted until the onboarding run completes."}},{"title":"Steve Holt","status":"DRAFT","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Steve Holt - Site Supervisor, Construction.","personnel_key":"bluth-steve-holt","full_name":"Steve Holt","work_email":"steve.holt@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"planned","department":"Construction","position_title":"Site Supervisor","manager_name":"Michael Bluth","manager_personnel_key":"bluth-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Will supervise Sudden Valley site crews, log facilities work orders and approve site timesheets.","authority_and_escalation":"Site-level timesheet approval once onboarded; no financial-system authority.","responsibility_review_status":"proposed","role_effective_date":"2026-08-09","role_effective_date_basis":"Engagement start date","engagement_start_date":"2026-08-09","systems_scope":"Stair Car Facilities System; Lucille Identity Cloud","verification_gaps":"Started on site two days ago; identity and facilities-system provisioning is in progress on the onboarding run."}},{"title":"Oscar Bluth","status":"DRAFT","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Oscar Bluth - Project Accountant, Accounting.","personnel_key":"bluth-oscar-bluth","full_name":"Oscar Bluth","work_email":"oscar.bluth@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"planned","department":"Accounting","position_title":"Project Accountant","manager_name":"Lucille Austero","manager_personnel_key":"bluth-lucille-austero","reporting_arrangement":"line_managed","responsibilities":"Will track construction project budgets, capitalization and cost-to-complete for the Sudden Valley developments.","authority_and_escalation":"Prepares only once onboarded; no approval authority.","responsibility_review_status":"proposed","role_effective_date":"2026-08-14","role_effective_date_basis":"Rehire; the prior engagement ended in 2025 and its entitlements were revoked, so provisioning starts from the role profile","engagement_start_date":"2026-08-14","systems_scope":"Banana ERP","verification_gaps":"Rehire: confirm no dormant accounts from the prior engagement remain before provisioning."}},{"title":"Annyong Bluth","status":"DRAFT","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Annyong Bluth - Integration Developer, Technology.","personnel_key":"bluth-annyong-bluth","full_name":"Annyong Bluth","work_email":"annyong.bluth@bluth.example","affiliation":"Hel-loh Integration Partners","engagement_type":"contractor","engagement_status":"planned","department":"Technology","position_title":"Integration Developer","manager_name":"George Michael Bluth","manager_personnel_key":"bluth-george-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Will build and support the file-exchange integrations under a fixed-scope statement of work.","authority_and_escalation":"No production change or approval authority; changes go through the change request workflow.","responsibility_review_status":"proposed","role_effective_date":"2026-08-25","role_effective_date_basis":"Engagement start date","engagement_start_date":"2026-08-25","systems_scope":"Tidewell File Exchange; Sudden Valley Network","verification_gaps":"Statement of work signed; engagement type contractor pending the vendor security review."}},{"title":"George Michael Bluth","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"George Michael Bluth - IT Operations Lead, Technology.","personnel_key":"bluth-george-michael-bluth","full_name":"George Michael Bluth","work_email":"george.michael@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"active","department":"Technology","position_title":"IT Operations Lead","manager_name":"Michael Bluth","manager_personnel_key":"bluth-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Operates the identity platform and network estate: provisions approved entitlements, produces the quarterly access recertification extracts, and maintains the facilities-system integration.","authority_and_escalation":"Executes approved access and change tickets; cannot approve his own provisioning or changes.","responsibility_review_status":"documented","role_effective_date":"2026-07-06","role_effective_date_basis":"Internal transfer from banana-stand operations into IT Operations; the access modification run removes the retail entitlements","engagement_start_date":"2023-06-13","systems_scope":"Lucille Identity Cloud; Sudden Valley Network; Stair Car Facilities System; GOB Security Monitoring"}},{"title":"Maeby Fünke","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Maeby Fünke - Senior Internal Auditor, Internal Audit.","personnel_key":"bluth-maeby-funke","full_name":"Maeby Fünke","work_email":"maeby.fuenke@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"active","department":"Internal Audit","position_title":"Senior Internal Auditor","manager_name":"Michael Bluth","manager_personnel_key":"bluth-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Plans and performs the internal audit program, tests SOX key controls, raises findings and validates remediation before closure.","authority_and_escalation":"Independent of the processes she audits; concludes on findings and escalates unresolved exceptions to the President.","responsibility_review_status":"approved","role_effective_date":"2026-06-01","role_effective_date_basis":"Promotion from Internal Auditor; audit-system entitlements widened to the data lake","engagement_start_date":"2024-09-03","systems_scope":"Banana ERP; Model Home Data Lake"}},{"title":"Lindsay Fünke","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Lindsay Fünke - Senior Revenue Analyst, Finance.","personnel_key":"bluth-lindsay-funke","full_name":"Lindsay Fünke","work_email":"lindsay.funke@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"active","department":"Finance","position_title":"Senior Revenue Analyst","manager_name":"Lucille Austero","manager_personnel_key":"bluth-lucille-austero","reporting_arrangement":"line_managed","responsibilities":"Reviews revenue schedules and contract modifications prepared by the analysts and owns the monthly revenue reconciliation.","authority_and_escalation":"Approves analyst-prepared schedules; cannot approve schedules she prepared.","responsibility_review_status":"documented","role_effective_date":"2026-08-04","role_effective_date_basis":"Promotion from Revenue Analyst; gains revenue-schedule approval in the revenue engine","engagement_start_date":"2025-07-07","systems_scope":"Cornballer Revenue Engine; Banana ERP"}},{"title":"Tony Wonder","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Tony Wonder - Security Engineer, Security.","personnel_key":"bluth-tony-wonder","full_name":"Tony Wonder","work_email":"tony.wonder@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"active","department":"Security","position_title":"Security Engineer","manager_name":"Michael Bluth","manager_personnel_key":"bluth-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Tunes security monitoring, triages alerts and runs the privileged access review extracts.","authority_and_escalation":"Investigates and escalates; account disablement outside an incident requires IT Operations approval.","responsibility_review_status":"documented","role_effective_date":"2026-08-21","role_effective_date_basis":"Transfer from IT Operations to Security effective in ten days; the modification run is drafted ahead of the effective date","engagement_start_date":"2024-02-23","systems_scope":"GOB Security Monitoring; Sudden Valley Network"}},{"title":"Tobias Fünke","status":"INACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Tobias Fünke - Payroll Administrator, People Operations.","personnel_key":"bluth-tobias-funke","full_name":"Tobias Fünke","work_email":"tobias.funke@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"ended","department":"People Operations","position_title":"Payroll Administrator","manager_name":"Michael Bluth","manager_personnel_key":"bluth-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Ran the payroll cycle and maintained employee master data in the HR platform.","authority_and_escalation":"None after the engagement end date; all entitlements revoked and verified.","responsibility_review_status":"documented","role_effective_date":"2023-01-19","role_effective_date_basis":"Engagement start date","engagement_start_date":"2023-01-19","engagement_end_date":"2026-07-12","systems_scope":"Seaward Payroll Service; Never Nude HR Platform"}},{"title":"Buster Bluth","status":"INACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Buster Bluth - Database Administrator, Technology.","personnel_key":"bluth-buster-bluth","full_name":"Buster Bluth","work_email":"buster.bluth@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"ended","department":"Technology","position_title":"Database Administrator","manager_name":"George Michael Bluth","manager_personnel_key":"bluth-george-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Administered the ERP and data-lake databases, including privileged service accounts.","authority_and_escalation":"None after the engagement end date.","responsibility_review_status":"documented","role_effective_date":"2020-11-10","role_effective_date_basis":"Engagement start date","engagement_start_date":"2020-11-10","engagement_end_date":"2026-08-08","systems_scope":"Banana ERP; Sudden Valley Network; Model Home Data Lake","verification_gaps":"EXCEPTION: privileged database access is still active three days after the end date, beyond the 24-hour revocation standard. The offboarding run is in progress and an issue is raised against the JML control."}},{"title":"Gob Bluth","status":"INACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Gob Bluth - Regional Sales Manager, Sales.","personnel_key":"bluth-gob-bluth","full_name":"Gob Bluth","work_email":"gob.bluth@bluth.example","affiliation":"Bluth Company","engagement_type":"employee","engagement_status":"ended","department":"Sales","position_title":"Regional Sales Manager","manager_name":"Michael Bluth","manager_personnel_key":"bluth-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Managed the regional sales team and approved customer contracts within his delegation.","authority_and_escalation":"None after the engagement end date; all entitlements revoked and verified.","responsibility_review_status":"documented","role_effective_date":"2021-09-06","role_effective_date_basis":"Engagement start date","engagement_start_date":"2021-09-06","engagement_end_date":"2026-05-13","systems_scope":"Cornballer Revenue Engine"}},{"title":"Dexter Holloway","status":"INACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Dexter Holloway - Integration Developer, Technology.","personnel_key":"bluth-dexter-holloway","full_name":"Dexter Holloway","work_email":"dexter.holloway@bluth.example","affiliation":"Holloway Integration Services","engagement_type":"contractor","engagement_status":"ended","department":"Technology","position_title":"Integration Developer","manager_name":"George Michael Bluth","manager_personnel_key":"bluth-george-michael-bluth","reporting_arrangement":"line_managed","responsibilities":"Built and supported the file-exchange integrations under a fixed-scope statement of work.","authority_and_escalation":"None after the engagement end date.","responsibility_review_status":"documented","role_effective_date":"2025-07-27","role_effective_date_basis":"Engagement start date","engagement_start_date":"2025-07-27","engagement_end_date":"2026-07-28","systems_scope":"Tidewell File Exchange; Sudden Valley Network","verification_gaps":"Statement of work closed two weeks ago; the shared integration credential rotation is the open item on the offboarding run."}}],"model":[{"title":"Banana Stand Demand Forecast","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Banana Stand Demand Forecast: machine learning model, tier 1.","model_type":"machine_learning","model_tier":"tier_1","monitoring_status":"breach","last_validation_date":"2025-10-15","next_validation_date":"2026-07-22"}},{"title":"Model Home Pricing Engine","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Model Home Pricing Engine: pricing model, tier 1.","model_type":"pricing","model_tier":"tier_1","monitoring_status":"watch","last_validation_date":"2026-01-23","next_validation_date":"2026-09-05"}},{"title":"Sudden Valley Reserve Model","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Sudden Valley Reserve Model: reserving model, tier 1.","model_type":"reserving","model_tier":"tier_1","monitoring_status":"within_threshold","last_validation_date":"2026-04-13","next_validation_date":"2027-04-13"}},{"title":"Frozen Banana Churn Classifier","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Frozen Banana Churn Classifier: machine learning model, tier 2.","model_type":"machine_learning","model_tier":"tier_2","monitoring_status":"breach","last_validation_date":"2025-07-07","next_validation_date":"2026-07-07"}},{"title":"Construction Cost Estimator","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Construction Cost Estimator: actuarial model, tier 2.","model_type":"actuarial","model_tier":"tier_2","monitoring_status":"within_threshold","last_validation_date":"2026-05-13","next_validation_date":"2026-10-10"}},{"title":"Claims Triage GenAI Assistant","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Claims Triage GenAI Assistant: genai model, tier 1.","model_type":"genai","model_tier":"tier_1","monitoring_status":"watch","last_validation_date":"2026-06-27","next_validation_date":"2026-12-29"}},{"title":"Cornballer Warranty Reserve","status":"ACTIVE","visibility":"public","owners":["maeby.fuenke@bluth.example"],"fields":{"description":"Cornballer Warranty Reserve: reserving model, tier 3.","model_type":"reserving","model_tier":"tier_3","monitoring_status":"not_monitored","last_validation_date":"2025-03-29","next_validation_date":"2027-06-07"}},{"title":"Staffing Optimizer","status":"ACTIVE","visibility":"public","owners":["michael.bluth@bluth.example"],"fields":{"description":"Staffing Optimizer: other model, tier 2.","model_type":"other","model_tier":"tier_2","monitoring_status":"within_threshold","last_validation_date":"2026-03-14","next_validation_date":"2028-03-13"}},{"title":"Balboa Towers Occupancy Model","status":"ACTIVE","visibility":"public","owners":["ann.veal@bluth.example"],"fields":{"description":"Balboa Towers Occupancy Model: pricing model, tier 3.","model_type":"pricing","model_tier":"tier_3","monitoring_status":"not_monitored"}},{"title":"Tenant Credit Risk Scorecard","status":"ACTIVE","visibility":"public","owners":["george.michael@bluth.example"],"fields":{"description":"Tenant Credit Risk Scorecard: machine learning model, tier 1.","model_type":"machine_learning","model_tier":"tier_1","monitoring_status":"within_threshold","last_validation_date":"2026-06-12","next_validation_date":"2026-11-04"}}]},"itemRelationships":[{"sourceItemTitle":"Financial Reporting Area","sourceItemType":"process","targetItemTitle":"Record to Report","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Financial Reporting Area","sourceItemType":"process","targetItemTitle":"Financial Close and Consolidation","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Financial Reporting Area","sourceItemType":"process","targetItemTitle":"SOX Program Management","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Revenue and Receivables Area","sourceItemType":"process","targetItemTitle":"Order to Cash","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Revenue and Receivables Area","sourceItemType":"process","targetItemTitle":"Revenue Recognition","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Revenue and Receivables Area","sourceItemType":"process","targetItemTitle":"Credit and Collections","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Procure to Pay Area","sourceItemType":"process","targetItemTitle":"Procure to Pay","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Procure to Pay Area","sourceItemType":"process","targetItemTitle":"Vendor Lifecycle Management","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"People and Payroll Area","sourceItemType":"process","targetItemTitle":"Payroll Administration","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Technology Area","sourceItemType":"process","targetItemTitle":"User Access Management","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Technology Area","sourceItemType":"process","targetItemTitle":"Change Management","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Technology Area","sourceItemType":"process","targetItemTitle":"IT Operations","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Security and Privacy Area","sourceItemType":"process","targetItemTitle":"Incident and Privacy Response","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Governance and Assurance Area","sourceItemType":"process","targetItemTitle":"Risk and Compliance Management","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Governance and Assurance Area","sourceItemType":"process","targetItemTitle":"Internal Audit Delivery","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Cash and Cash Equivalents","sourceItemType":"fsli","targetItemTitle":"Operating Cash Accounts","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Accounts Receivable","sourceItemType":"fsli","targetItemTitle":"Customer Receivables","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Property and Equipment","sourceItemType":"fsli","targetItemTitle":"Construction in Progress","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Accounts Payable","sourceItemType":"fsli","targetItemTitle":"Trade Payables","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Revenue","sourceItemType":"fsli","targetItemTitle":"Subscription Revenue","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Operating Expenses","sourceItemType":"fsli","targetItemTitle":"Payroll Expense","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Net Cash from Operations","sourceItemType":"fsli","targetItemTitle":"Cash Collections","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Common Stock and APIC","sourceItemType":"fsli","targetItemTitle":"Employee Equity Awards","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Retained Earnings","sourceItemType":"fsli","targetItemTitle":"Current Period Earnings","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Commitments and Contingencies","sourceItemType":"fsli","targetItemTitle":"Legal Contingencies","targetItemType":"fsli","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Record to Report","sourceItemType":"process","targetItemTitle":"Journal Entry Approval","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Record to Report","sourceItemType":"process","targetItemTitle":"Account Reconciliation Review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Record to Report","sourceItemType":"process","targetItemTitle":"Quarterly Access Recertification","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Financial Close and Consolidation","sourceItemType":"process","targetItemTitle":"Spreadsheet Inventory Review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Financial Close and Consolidation","sourceItemType":"process","targetItemTitle":"EUC Formula Validation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"SOX Program Management","sourceItemType":"process","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"SOX Program Management","sourceItemType":"process","targetItemTitle":"Policy Exception Approval","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Order to Cash","sourceItemType":"process","targetItemTitle":"Batch Processing Monitoring","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Order to Cash","sourceItemType":"process","targetItemTitle":"Service Delivery Quality Review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Revenue Recognition","sourceItemType":"process","targetItemTitle":"Revenue Contract Review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Revenue Recognition","sourceItemType":"process","targetItemTitle":"Revenue Interface Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Credit and Collections","sourceItemType":"process","targetItemTitle":"Privacy Request Verification","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Credit and Collections","sourceItemType":"process","targetItemTitle":"Data Retention Enforcement","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Procure to Pay","sourceItemType":"process","targetItemTitle":"Change Migration Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Procure to Pay","sourceItemType":"process","targetItemTitle":"Business Continuity Exercise","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor Lifecycle Management","sourceItemType":"process","targetItemTitle":"Vendor Due Diligence","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor Lifecycle Management","sourceItemType":"process","targetItemTitle":"SOC Report and CUEC Review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor Lifecycle Management","sourceItemType":"process","targetItemTitle":"Revenue Interface Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Payroll Administration","sourceItemType":"process","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Payroll Administration","sourceItemType":"process","targetItemTitle":"Emergency Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"User Access Management","sourceItemType":"process","targetItemTitle":"Quarterly Access Recertification","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"User Access Management","sourceItemType":"process","targetItemTitle":"Privileged Access Approval","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"User Access Management","sourceItemType":"process","targetItemTitle":"Vendor Due Diligence","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change Management","sourceItemType":"process","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change Management","sourceItemType":"process","targetItemTitle":"Segregated Deployment Pipeline","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"IT Operations","sourceItemType":"process","targetItemTitle":"Backup Restoration Test","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"IT Operations","sourceItemType":"process","targetItemTitle":"Job Failure Escalation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"IT Operations","sourceItemType":"process","targetItemTitle":"Business Continuity Exercise","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Incident and Privacy Response","sourceItemType":"process","targetItemTitle":"Security Incident Triage","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Incident and Privacy Response","sourceItemType":"process","targetItemTitle":"Vulnerability Remediation Review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Risk and Compliance Management","sourceItemType":"process","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Risk and Compliance Management","sourceItemType":"process","targetItemTitle":"Visitor Badge Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Risk and Compliance Management","sourceItemType":"process","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit Delivery","sourceItemType":"process","targetItemTitle":"Secure Development Gate","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit Delivery","sourceItemType":"process","targetItemTitle":"New Application Architecture Review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Unauthorized privileged access","sourceItemType":"risk","targetItemTitle":"Quarterly Access Recertification","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized privileged access","sourceItemType":"risk","targetItemTitle":"Privileged Access Approval","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized privileged access","sourceItemType":"risk","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized privileged access","sourceItemType":"risk","targetItemTitle":"Emergency Access Review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Revenue cut-off error","sourceItemType":"risk","targetItemTitle":"Revenue Contract Review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Revenue cut-off error","sourceItemType":"risk","targetItemTitle":"Revenue Interface Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Revenue cut-off error","sourceItemType":"risk","targetItemTitle":"Journal Entry Approval","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Revenue cut-off error","sourceItemType":"risk","targetItemTitle":"Account Reconciliation Review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Third-party service interruption","sourceItemType":"risk","targetItemTitle":"Vendor Due Diligence","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Third-party service interruption","sourceItemType":"risk","targetItemTitle":"SOC Report and CUEC Review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy consent failure","sourceItemType":"risk","targetItemTitle":"Privacy Request Verification","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy consent failure","sourceItemType":"risk","targetItemTitle":"Data Retention Enforcement","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI model governance gap","sourceItemType":"risk","targetItemTitle":"Secure Development Gate","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI model governance gap","sourceItemType":"risk","targetItemTitle":"New Application Architecture Review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Business continuity outage","sourceItemType":"risk","targetItemTitle":"Backup Restoration Test","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Business continuity outage","sourceItemType":"risk","targetItemTitle":"Business Continuity Exercise","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Regulatory filing delay","sourceItemType":"risk","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Financial statement fraud","sourceItemType":"risk","targetItemTitle":"Spreadsheet Inventory Review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Financial statement fraud","sourceItemType":"risk","targetItemTitle":"EUC Formula Validation","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Vendor concentration exposure","sourceItemType":"risk","targetItemTitle":"Service Delivery Quality Review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Employee safety incident","sourceItemType":"risk","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Employee safety incident","sourceItemType":"risk","targetItemTitle":"Visitor Badge Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Brand trust deterioration","sourceItemType":"risk","targetItemTitle":"Security Incident Triage","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Strategic acquisition integration","sourceItemType":"risk","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Strategic acquisition integration","sourceItemType":"risk","targetItemTitle":"Segregated Deployment Pipeline","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Legacy system processing failure","sourceItemType":"risk","targetItemTitle":"Change Migration Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Legacy system processing failure","sourceItemType":"risk","targetItemTitle":"Batch Processing Monitoring","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Legacy system processing failure","sourceItemType":"risk","targetItemTitle":"Job Failure Escalation","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unrated emerging risk","sourceItemType":"risk","targetItemTitle":"Vulnerability Remediation Review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unrated emerging risk","sourceItemType":"risk","targetItemTitle":"Policy Exception Approval","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Quarterly Access Recertification","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Privileged Access Approval","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Joiner Mover Leaver Automation","sourceItemType":"control","targetItemTitle":"Seaward Payroll Service","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Emergency Access Review","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Production Change Approval","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Segregated Deployment Pipeline","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Change Migration Reconciliation","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Batch Processing Monitoring","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Backup Restoration Test","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Job Failure Escalation","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Secure Development Gate","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"New Application Architecture Review","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Spreadsheet Inventory Review","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"EUC Formula Validation","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Revenue Contract Review","sourceItemType":"control","targetItemTitle":"Cornballer Revenue Engine","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Revenue Interface Reconciliation","sourceItemType":"control","targetItemTitle":"Cornballer Revenue Engine","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Journal Entry Approval","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Account Reconciliation Review","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Vendor Due Diligence","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"SOC Report and CUEC Review","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Security Incident Triage","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Vulnerability Remediation Review","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Privacy Request Verification","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Data Retention Enforcement","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Physical Site Access Review","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Visitor Badge Reconciliation","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Board Risk Oversight","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Policy Exception Approval","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Service Delivery Quality Review","sourceItemType":"control","targetItemTitle":"Cornballer Revenue Engine","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Business Continuity Exercise","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Information Security Policy","sourceItemType":"policy","targetItemTitle":"Change Migration Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Security Policy","sourceItemType":"policy","targetItemTitle":"Batch Processing Monitoring","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Security Policy","sourceItemType":"policy","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Security Policy","sourceItemType":"policy","targetItemTitle":"Visitor Badge Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Standard","sourceItemType":"policy","targetItemTitle":"Quarterly Access Recertification","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Standard","sourceItemType":"policy","targetItemTitle":"Privileged Access Approval","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Standard","sourceItemType":"policy","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Standard","sourceItemType":"policy","targetItemTitle":"Emergency Access Review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Financial Close Procedure","sourceItemType":"policy","targetItemTitle":"Spreadsheet Inventory Review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Financial Close Procedure","sourceItemType":"policy","targetItemTitle":"EUC Formula Validation","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Financial Close Procedure","sourceItemType":"policy","targetItemTitle":"Revenue Contract Review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Financial Close Procedure","sourceItemType":"policy","targetItemTitle":"Revenue Interface Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Financial Close Procedure","sourceItemType":"policy","targetItemTitle":"Journal Entry Approval","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Financial Close Procedure","sourceItemType":"policy","targetItemTitle":"Account Reconciliation Review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Risk Management Policy","sourceItemType":"policy","targetItemTitle":"Vendor Due Diligence","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Risk Management Policy","sourceItemType":"policy","targetItemTitle":"SOC Report and CUEC Review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Risk Management Policy","sourceItemType":"policy","targetItemTitle":"Service Delivery Quality Review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Plan","sourceItemType":"policy","targetItemTitle":"Security Incident Triage","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Plan","sourceItemType":"policy","targetItemTitle":"Vulnerability Remediation Review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Plan","sourceItemType":"policy","targetItemTitle":"Privacy Request Verification","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Plan","sourceItemType":"policy","targetItemTitle":"Data Retention Enforcement","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity Standard","sourceItemType":"policy","targetItemTitle":"Backup Restoration Test","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity Standard","sourceItemType":"policy","targetItemTitle":"Job Failure Escalation","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity Standard","sourceItemType":"policy","targetItemTitle":"Business Continuity Exercise","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Audit Committee Charter","sourceItemType":"policy","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Audit Committee Charter","sourceItemType":"policy","targetItemTitle":"Policy Exception Approval","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Responsible AI Guideline","sourceItemType":"policy","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Responsible AI Guideline","sourceItemType":"policy","targetItemTitle":"Segregated Deployment Pipeline","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Responsible AI Guideline","sourceItemType":"policy","targetItemTitle":"Secure Development Gate","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Responsible AI Guideline","sourceItemType":"policy","targetItemTitle":"New Application Architecture Review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Record to Report","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Financial Close and Consolidation","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"SOX Program Management","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Order to Cash","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Revenue Recognition","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Credit and Collections","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"User Access Management","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Change Management","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"IT Operations","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"ISO 27001 Certification Readiness","sourceItemType":"audit","targetItemTitle":"Risk and Compliance Management","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Identity and Access Management Audit","sourceItemType":"audit","targetItemTitle":"User Access Management","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"Procure to Pay","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"Vendor Lifecycle Management","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Vendor Risk Review","sourceItemType":"audit","targetItemTitle":"Vendor Lifecycle Management","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Incident Response Investigation","sourceItemType":"audit","targetItemTitle":"Incident and Privacy Response","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"User Access Management","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"IT Operations","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"Incident and Privacy Response","targetItemType":"process","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Journal Entry Approval","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Account Reconciliation Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Policy Exception Approval","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Batch Processing Monitoring","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Revenue Contract Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Revenue Interface Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Service Delivery Quality Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Segregated Deployment Pipeline","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Backup Restoration Test","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Job Failure Escalation","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Privacy Request Verification","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Data Retention Enforcement","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Business Continuity Exercise","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"ISO 27001 Certification Readiness","sourceItemType":"audit","targetItemTitle":"Secure Development Gate","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"ISO 27001 Certification Readiness","sourceItemType":"audit","targetItemTitle":"New Application Architecture Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"ISO 27001 Certification Readiness","sourceItemType":"audit","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"ISO 27001 Certification Readiness","sourceItemType":"audit","targetItemTitle":"Visitor Badge Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Identity and Access Management Audit","sourceItemType":"audit","targetItemTitle":"Quarterly Access Recertification","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Identity and Access Management Audit","sourceItemType":"audit","targetItemTitle":"Privileged Access Approval","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Identity and Access Management Audit","sourceItemType":"audit","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Identity and Access Management Audit","sourceItemType":"audit","targetItemTitle":"Emergency Access Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"Change Migration Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"Spreadsheet Inventory Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"EUC Formula Validation","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Vendor Risk Review","sourceItemType":"audit","targetItemTitle":"Vendor Due Diligence","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Vendor Risk Review","sourceItemType":"audit","targetItemTitle":"SOC Report and CUEC Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Incident Response Investigation","sourceItemType":"audit","targetItemTitle":"Security Incident Triage","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Incident Response Investigation","sourceItemType":"audit","targetItemTitle":"Vulnerability Remediation Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"Quarterly Access Recertification","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"Privileged Access Approval","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"Vulnerability Remediation Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"Security Incident Triage","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"SOC Report and CUEC Review","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"Data Retention Enforcement","targetItemType":"control","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Cash and Cash Equivalents","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Property and Equipment","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Common Stock and APIC","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Retained Earnings","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Commitments and Contingencies","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Accounts Receivable","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Revenue","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Customer Receivables","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Subscription Revenue","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Construction in Progress","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"ISO 27001 Certification Readiness","sourceItemType":"audit","targetItemTitle":"Legal Contingencies","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Identity and Access Management Audit","sourceItemType":"audit","targetItemTitle":"Employee Equity Awards","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"Accounts Payable","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"Operating Expenses","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"Trade Payables","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"Payroll Expense","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Vendor Risk Review","sourceItemType":"audit","targetItemTitle":"Net Cash from Operations","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Vendor Risk Review","sourceItemType":"audit","targetItemTitle":"Cash Collections","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Incident Response Investigation","sourceItemType":"audit","targetItemTitle":"Operating Cash Accounts","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Incident Response Investigation","sourceItemType":"audit","targetItemTitle":"Current Period Earnings","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"Payroll Expense","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"Operating Cash Accounts","targetItemType":"fsli","kind":"related","metadata":{"role":"scopes"}},{"sourceItemTitle":"Quarterly access recertification missed two finance approvers","sourceItemType":"issue","targetItemTitle":"Quarterly Access Recertification","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Privileged access granted before approval during the close","sourceItemType":"issue","targetItemTitle":"Privileged Access Approval","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Leaver accounts in Banana ERP disabled late","sourceItemType":"issue","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Emergency access sessions not reviewed","sourceItemType":"issue","targetItemTitle":"Emergency Access Review","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Change approval waived for a revenue system release","sourceItemType":"issue","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Developers can deploy their own changes to production","sourceItemType":"issue","targetItemTitle":"Segregated Deployment Pipeline","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Opportunity to automate change migration reconciliation","sourceItemType":"issue","targetItemTitle":"Change Migration Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Failed vendor payment batches went unnoticed","sourceItemType":"issue","targetItemTitle":"Batch Processing Monitoring","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Payroll backup restore test ran a month late","sourceItemType":"issue","targetItemTitle":"Backup Restoration Test","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 1 — Revenue Population","sourceItemType":"issue","targetItemTitle":"Job Failure Escalation","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 2 — Access Listing","sourceItemType":"issue","targetItemTitle":"Secure Development Gate","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 3 — Change Samples","sourceItemType":"issue","targetItemTitle":"New Application Architecture Review","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 4 — Vendor Reports","sourceItemType":"issue","targetItemTitle":"Spreadsheet Inventory Review","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 5 — Legal Confirmations","sourceItemType":"issue","targetItemTitle":"EUC Formula Validation","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 6 — Board Minutes","sourceItemType":"issue","targetItemTitle":"Revenue Contract Review","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Penetration Test Vulnerability","sourceItemType":"issue","targetItemTitle":"Revenue Interface Reconciliation","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Privacy Waiver Expiring","sourceItemType":"issue","targetItemTitle":"Journal Entry Approval","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Regulatory Examination Observation","sourceItemType":"issue","targetItemTitle":"Account Reconciliation Review","targetItemType":"control","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Quarterly access recertification missed two finance approvers","sourceItemType":"issue","targetItemTitle":"Record to Report","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Privileged access granted before approval during the close","sourceItemType":"issue","targetItemTitle":"Financial Close and Consolidation","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Leaver accounts in Banana ERP disabled late","sourceItemType":"issue","targetItemTitle":"SOX Program Management","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Emergency access sessions not reviewed","sourceItemType":"issue","targetItemTitle":"Order to Cash","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Change approval waived for a revenue system release","sourceItemType":"issue","targetItemTitle":"Revenue Recognition","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Developers can deploy their own changes to production","sourceItemType":"issue","targetItemTitle":"Credit and Collections","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Opportunity to automate change migration reconciliation","sourceItemType":"issue","targetItemTitle":"Procure to Pay","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Failed vendor payment batches went unnoticed","sourceItemType":"issue","targetItemTitle":"Vendor Lifecycle Management","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Payroll backup restore test ran a month late","sourceItemType":"issue","targetItemTitle":"Payroll Administration","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 1 — Revenue Population","sourceItemType":"issue","targetItemTitle":"User Access Management","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 2 — Access Listing","sourceItemType":"issue","targetItemTitle":"Change Management","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 3 — Change Samples","sourceItemType":"issue","targetItemTitle":"IT Operations","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 4 — Vendor Reports","sourceItemType":"issue","targetItemTitle":"Incident and Privacy Response","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 5 — Legal Confirmations","sourceItemType":"issue","targetItemTitle":"Risk and Compliance Management","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"PBC Request 6 — Board Minutes","sourceItemType":"issue","targetItemTitle":"Internal Audit Delivery","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Penetration Test Vulnerability","sourceItemType":"issue","targetItemTitle":"Record to Report","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Privacy Waiver Expiring","sourceItemType":"issue","targetItemTitle":"Financial Close and Consolidation","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Regulatory Examination Observation","sourceItemType":"issue","targetItemTitle":"SOX Program Management","targetItemType":"process","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Quarterly access recertification missed two finance approvers","sourceItemType":"issue","targetItemTitle":"Unauthorized privileged access","targetItemType":"risk","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Privileged access granted before approval during the close","sourceItemType":"issue","targetItemTitle":"FY2026 SOX Annual Program","targetItemType":"audit","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"Leaver accounts in Banana ERP disabled late","sourceItemType":"issue","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Quarterly access recertification missed two finance approvers","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Payroll backup restore test ran a month late","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"FY2026 SOX Annual Program","sourceItemType":"audit","targetItemTitle":"Privacy Waiver Expiring","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Privileged access granted before approval during the close","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"PBC Request 1 — Revenue Population","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Revenue Recognition Audit","sourceItemType":"audit","targetItemTitle":"Regulatory Examination Observation","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"Leaver accounts in Banana ERP disabled late","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"SOC 2 Security and Availability Readiness","sourceItemType":"audit","targetItemTitle":"PBC Request 2 — Access Listing","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"ISO 27001 Certification Readiness","sourceItemType":"audit","targetItemTitle":"Emergency access sessions not reviewed","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"ISO 27001 Certification Readiness","sourceItemType":"audit","targetItemTitle":"PBC Request 3 — Change Samples","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Identity and Access Management Audit","sourceItemType":"audit","targetItemTitle":"Change approval waived for a revenue system release","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Identity and Access Management Audit","sourceItemType":"audit","targetItemTitle":"PBC Request 4 — Vendor Reports","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"Developers can deploy their own changes to production","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Procure to Pay Audit","sourceItemType":"audit","targetItemTitle":"PBC Request 5 — Legal Confirmations","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Vendor Risk Review","sourceItemType":"audit","targetItemTitle":"Opportunity to automate change migration reconciliation","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Vendor Risk Review","sourceItemType":"audit","targetItemTitle":"PBC Request 6 — Board Minutes","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Incident Response Investigation","sourceItemType":"audit","targetItemTitle":"Failed vendor payment batches went unnoticed","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Incident Response Investigation","sourceItemType":"audit","targetItemTitle":"Penetration Test Vulnerability","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Cybersecurity Program Audit","sourceItemType":"audit","targetItemTitle":"Penetration Test Vulnerability","targetItemType":"issue","kind":"related","metadata":{"role":"identified"}},{"sourceItemTitle":"Re-run the access recertification for Record to Report approvers","sourceItemType":"remediation","targetItemTitle":"Quarterly access recertification missed two finance approvers","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Require approval before privileged access is granted","sourceItemType":"remediation","targetItemTitle":"Privileged access granted before approval during the close","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Move the HR leaver feed to a daily run","sourceItemType":"remediation","targetItemTitle":"Leaver accounts in Banana ERP disabled late","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Review all emergency access sessions since July","sourceItemType":"remediation","targetItemTitle":"Emergency access sessions not reviewed","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Close the change approval waiver and log the exception","sourceItemType":"remediation","targetItemTitle":"Change approval waived for a revenue system release","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Enforce separate approval in the deployment pipeline","sourceItemType":"remediation","targetItemTitle":"Developers can deploy their own changes to production","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Re-run and reconcile the failed vendor payment batches","sourceItemType":"remediation","targetItemTitle":"Failed vendor payment batches went unnoticed","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Confirm the ticketing vendor supports log export","sourceItemType":"remediation","targetItemTitle":"Opportunity to automate change migration reconciliation","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"PBC Delivery 1 — Revenue Population","sourceItemType":"remediation","targetItemTitle":"PBC Request 1 — Revenue Population","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"PBC Delivery 2 — Access Listing","sourceItemType":"remediation","targetItemTitle":"PBC Request 2 — Access Listing","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"PBC Delivery 3 — Change Samples","sourceItemType":"remediation","targetItemTitle":"PBC Request 3 — Change Samples","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"PBC Delivery 4 — Vendor Reports","sourceItemType":"remediation","targetItemTitle":"PBC Request 4 — Vendor Reports","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"PBC Delivery 5 — Legal Confirmations","sourceItemType":"remediation","targetItemTitle":"PBC Request 5 — Legal Confirmations","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"PBC Delivery 6 — Board Minutes","sourceItemType":"remediation","targetItemTitle":"PBC Request 6 — Board Minutes","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Monitor the penetration test and privacy waiver fixes","sourceItemType":"remediation","targetItemTitle":"Penetration Test Vulnerability","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Monitor the penetration test and privacy waiver fixes","sourceItemType":"remediation","targetItemTitle":"Privacy Waiver Expiring","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Route batch failure alerts to the on-call queue","sourceItemType":"remediation","targetItemTitle":"Failed vendor payment batches went unnoticed","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Retain complaint records for the full regulatory period","sourceItemType":"remediation","targetItemTitle":"Regulatory Examination Observation","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Test leaver access removal next quarter","sourceItemType":"remediation","targetItemTitle":"Leaver accounts in Banana ERP disabled late","targetItemType":"issue","kind":"related","metadata":{"role":"remediates"}},{"sourceItemTitle":"Michael Bluth","sourceItemType":"personnel","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Michael Bluth","sourceItemType":"personnel","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Michael Bluth","sourceItemType":"personnel","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Ann Veal","sourceItemType":"personnel","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Ann Veal","sourceItemType":"personnel","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Ann Veal","sourceItemType":"personnel","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Lucille Austero","sourceItemType":"personnel","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Lucille Austero","sourceItemType":"personnel","targetItemTitle":"Cornballer Revenue Engine","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Marta Estrella","sourceItemType":"personnel","targetItemTitle":"Cornballer Revenue Engine","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Marta Estrella","sourceItemType":"personnel","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Kitty Sanchez","sourceItemType":"personnel","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Kitty Sanchez","sourceItemType":"personnel","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Steve Holt","sourceItemType":"personnel","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Steve Holt","sourceItemType":"personnel","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Oscar Bluth","sourceItemType":"personnel","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Annyong Bluth","sourceItemType":"personnel","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Annyong Bluth","sourceItemType":"personnel","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"George Michael Bluth","sourceItemType":"personnel","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"George Michael Bluth","sourceItemType":"personnel","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"George Michael Bluth","sourceItemType":"personnel","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"George Michael Bluth","sourceItemType":"personnel","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Maeby Fünke","sourceItemType":"personnel","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Maeby Fünke","sourceItemType":"personnel","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Lindsay Fünke","sourceItemType":"personnel","targetItemTitle":"Cornballer Revenue Engine","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Lindsay Fünke","sourceItemType":"personnel","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Tony Wonder","sourceItemType":"personnel","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Tony Wonder","sourceItemType":"personnel","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Tobias Fünke","sourceItemType":"personnel","targetItemTitle":"Seaward Payroll Service","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Tobias Fünke","sourceItemType":"personnel","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Buster Bluth","sourceItemType":"personnel","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Buster Bluth","sourceItemType":"personnel","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Buster Bluth","sourceItemType":"personnel","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Gob Bluth","sourceItemType":"personnel","targetItemTitle":"Cornballer Revenue Engine","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Dexter Holloway","sourceItemType":"personnel","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"Dexter Holloway","sourceItemType":"personnel","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"scoped-to"}},{"sourceItemTitle":"ISO 27001 A.5.10 — Approved asset-use rules","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.11 — Asset recovery at exit","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.12 — Information sensitivity classification","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.13 — Classification marking practices","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.16 — Identity lifecycle governance","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.18 — Access entitlement administration","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.2 — Security accountability assignments","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.20 — Contracted supplier safeguards","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.21 — Technology supply-chain assurance","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.23 — Cloud service security governance","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.24 — Incident response preparedness","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.25 — Security event triage","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.26 — Incident containment and response","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.28 — Forensic evidence handling","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.3 — Conflicting-duty separation","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.30 — Technology continuity readiness","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.31 — Compliance obligation register","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.32 — Intellectual-property safeguards","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.33 — Records retention and integrity","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.35 — Independent security assurance","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.37 — Controlled operating procedures","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.4 — Manager security obligations","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.5 — Regulatory authority coordination","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.6 — Security community engagement","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.7 — Emerging threat insights","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.9 — Information-asset register","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.6.2 — Employment security terms","sourceItemType":"requirement","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.6.4 — Security conduct enforcement","sourceItemType":"requirement","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.6.5 — Exit and role-change obligations","sourceItemType":"requirement","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.6.7 — Secure remote-work practices","sourceItemType":"requirement","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.6.8 — Workforce event escalation","sourceItemType":"requirement","targetItemTitle":"Joiner Mover Leaver Automation","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.1 — Protected facility boundaries","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.10 — Removable and stored media protection","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.11 — Resilient facility utilities","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.13 — Secure equipment servicing","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.14 — Equipment sanitization and disposal","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.2 — Authorized facility access","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.3 — Secure workspaces and rooms","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.4 — Facility surveillance","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.7 — Unattended workspace hygiene","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.7.9 — Off-site asset protection","sourceItemType":"requirement","targetItemTitle":"Physical Site Access Review","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.1 — Endpoint security baseline","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.10 — Verified data disposal","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.11 — Sensitive-data obfuscation","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.13 — Resilient backups","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.14 — Processing-service redundancy","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.15 — Security event logging","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.16 — Security telemetry monitoring","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.18 — Privileged utility restrictions","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.2 — Administrative privilege governance","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.21 — Network service assurance","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.22 — Network zone isolation","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.23 — Harmful web-content controls","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.24 — Cryptographic protection","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.25 — Secure product delivery lifecycle","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.27 — Secure-by-design architecture","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.28 — Defensive coding practices","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.29 — Pre-release security validation","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.3 — Need-to-know data access","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.30 — Third-party development assurance","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.31 — Environment separation","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.32 — Controlled technology changes","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.34 — Audit-test safeguards","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.4 — Source repository access","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.6 — Resource capacity planning","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.8.8 — Vulnerability remediation program","sourceItemType":"requirement","targetItemTitle":"Production Change Approval","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 A1.1 — Capacity monitoring","sourceItemType":"requirement","targetItemTitle":"Business Continuity Exercise","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 A1.2 — Environmental and resilience safeguards","sourceItemType":"requirement","targetItemTitle":"Business Continuity Exercise","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 A1.3 — Recovery testing","sourceItemType":"requirement","targetItemTitle":"Business Continuity Exercise","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC1.1 — Integrity and ethical values","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC1.2 — Board independence and oversight","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC1.3 — Organizational authority and accountability","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC1.4 — Competence and retention","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC1.5 — Internal-control accountability","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC2.1 — Quality information","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC2.2 — Internal communication","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC2.3 — External communication","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC3.1 — Clear objectives","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC3.2 — Enterprise risk identification and analysis","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC3.4 — Change-risk assessment","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC4.1 — Ongoing and separate evaluations","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC4.2 — Deficiency communication","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC5.1 — Risk-mitigating control activities","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC5.2 — Technology general controls","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC5.3 — Policy-driven procedures","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC6.1 — Logical access safeguards","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC6.2 — Credential issuance and removal","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC6.3 — Role-based access changes","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC6.4 — Physical access restrictions","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC6.6 — Boundary protection","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC6.7 — Secure information transmission","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC6.8 — Malicious software defenses","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC7.1 — Vulnerability and configuration monitoring","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC7.2 — Anomaly monitoring","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC7.3 — Security event evaluation","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC7.4 — Incident response","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC7.5 — Incident recovery","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC8.1 — Change management","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC9.1 — Business disruption risk","sourceItemType":"requirement","targetItemTitle":"Board Risk Oversight","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.2 — Security accountability assignments","sourceItemType":"requirement","targetItemTitle":"Quarterly Access Recertification","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"SOC 2 CC1.1 — Integrity and ethical values","sourceItemType":"requirement","targetItemTitle":"Quarterly Access Recertification","targetItemType":"control","kind":"related","metadata":{"role":"implemented-by"}},{"sourceItemTitle":"ISO 27001 A.5.1 — Information-security policy governance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.10 — Approved asset-use rules","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.11 — Asset recovery at exit","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.12 — Information sensitivity classification","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.13 — Classification marking practices","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.14 — Protected data exchange","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.15 — Logical and physical access governance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.16 — Identity lifecycle governance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.17 — Authenticator protection","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.18 — Access entitlement administration","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.19 — Supplier security governance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.2 — Security accountability assignments","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.20 — Contracted supplier safeguards","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.21 — Technology supply-chain assurance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.22 — Supplier service oversight","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.23 — Cloud service security governance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.24 — Incident response preparedness","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.25 — Security event triage","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.26 — Incident containment and response","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.27 — Post-incident improvement","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.28 — Forensic evidence handling","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.29 — Security controls during disruption","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.3 — Conflicting-duty separation","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.30 — Technology continuity readiness","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.31 — Compliance obligation register","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.32 — Intellectual-property safeguards","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.33 — Records retention and integrity","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.34 — Personal-data privacy safeguards","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.35 — Independent security assurance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.36 — Security-policy compliance checks","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.37 — Controlled operating procedures","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.4 — Manager security obligations","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.5 — Regulatory authority coordination","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.6 — Security community engagement","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.7 — Emerging threat insights","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.8 — Project security integration","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.5.9 — Information-asset register","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.6.1 — Personnel vetting","sourceItemType":"requirement","targetItemTitle":"Access Control Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.6.2 — Employment security terms","sourceItemType":"requirement","targetItemTitle":"Access Control Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.6.3 — Workforce security learning","sourceItemType":"requirement","targetItemTitle":"Access Control Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.6.4 — Security conduct enforcement","sourceItemType":"requirement","targetItemTitle":"Access Control Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.6.5 — Exit and role-change obligations","sourceItemType":"requirement","targetItemTitle":"Access Control Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.6.6 — Confidentiality commitments","sourceItemType":"requirement","targetItemTitle":"Access Control Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.6.7 — Secure remote-work practices","sourceItemType":"requirement","targetItemTitle":"Access Control Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.6.8 — Workforce event escalation","sourceItemType":"requirement","targetItemTitle":"Access Control Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.1 — Protected facility boundaries","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.10 — Removable and stored media protection","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.11 — Resilient facility utilities","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.12 — Protected power and data cabling","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.13 — Secure equipment servicing","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.14 — Equipment sanitization and disposal","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.2 — Authorized facility access","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.3 — Secure workspaces and rooms","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.4 — Facility surveillance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.5 — Environmental and physical resilience","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.6 — Restricted-area working practices","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.7 — Unattended workspace hygiene","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.8 — Protected equipment placement","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.7.9 — Off-site asset protection","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.1 — Endpoint security baseline","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.10 — Verified data disposal","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.11 — Sensitive-data obfuscation","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.12 — Data exfiltration safeguards","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.13 — Resilient backups","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.14 — Processing-service redundancy","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.15 — Security event logging","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.16 — Security telemetry monitoring","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.17 — Trusted time sources","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.18 — Privileged utility restrictions","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.19 — Production software authorization","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.2 — Administrative privilege governance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.20 — Network protection architecture","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.21 — Network service assurance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.22 — Network zone isolation","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.23 — Harmful web-content controls","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.24 — Cryptographic protection","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.25 — Secure product delivery lifecycle","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.26 — Application protection specifications","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.27 — Secure-by-design architecture","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.28 — Defensive coding practices","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.29 — Pre-release security validation","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.3 — Need-to-know data access","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.30 — Third-party development assurance","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.31 — Environment separation","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.32 — Controlled technology changes","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.33 — Protected test datasets","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.34 — Audit-test safeguards","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.4 — Source repository access","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.5 — Strong user authentication","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.6 — Resource capacity planning","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.7 — Malware defense","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.8 — Vulnerability remediation program","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"ISO 27001 A.8.9 — Secure configuration baselines","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 A1.1 — Capacity monitoring","sourceItemType":"requirement","targetItemTitle":"Business Continuity Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 A1.2 — Environmental and resilience safeguards","sourceItemType":"requirement","targetItemTitle":"Business Continuity Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 A1.3 — Recovery testing","sourceItemType":"requirement","targetItemTitle":"Business Continuity Standard","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC1.1 — Integrity and ethical values","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC1.2 — Board independence and oversight","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC1.3 — Organizational authority and accountability","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC1.4 — Competence and retention","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC1.5 — Internal-control accountability","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC2.1 — Quality information","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC2.2 — Internal communication","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC2.3 — External communication","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC3.1 — Clear objectives","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC3.2 — Enterprise risk identification and analysis","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC3.3 — Fraud-risk assessment","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC3.4 — Change-risk assessment","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC4.1 — Ongoing and separate evaluations","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC4.2 — Deficiency communication","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC5.1 — Risk-mitigating control activities","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC5.2 — Technology general controls","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC5.3 — Policy-driven procedures","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC6.1 — Logical access safeguards","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC6.2 — Credential issuance and removal","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC6.3 — Role-based access changes","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC6.4 — Physical access restrictions","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC6.5 — Secure asset disposal","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC6.6 — Boundary protection","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC6.7 — Secure information transmission","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC6.8 — Malicious software defenses","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC7.1 — Vulnerability and configuration monitoring","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC7.2 — Anomaly monitoring","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC7.3 — Security event evaluation","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC7.4 — Incident response","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC7.5 — Incident recovery","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC8.1 — Change management","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC9.1 — Business disruption risk","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"SOC 2 CC9.2 — Vendor and business-partner risk","sourceItemType":"requirement","targetItemTitle":"Information Security Policy","targetItemType":"policy","kind":"related","metadata":{"role":"governed-by"}},{"sourceItemTitle":"Access, Identity & Cryptography","sourceItemType":"process","targetItemTitle":"Cryptography, Key & Secrets Management","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Access, Identity & Cryptography","sourceItemType":"process","targetItemTitle":"Identity, Authentication & Access Lifecycle","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Data Protection & Privacy","sourceItemType":"process","targetItemTitle":"Asset, Media & Classification","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Data Protection & Privacy","sourceItemType":"process","targetItemTitle":"Privacy, Data Lifecycle & Secure Transfer","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Governance, Risk & Compliance","sourceItemType":"process","targetItemTitle":"AI Governance & Human Approval","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Governance, Risk & Compliance","sourceItemType":"process","targetItemTitle":"Compliance Obligations, Evidence & External Assurance","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Governance, Risk & Compliance","sourceItemType":"process","targetItemTitle":"Enterprise Risk Assessment, Treatment & SoA","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Governance, Risk & Compliance","sourceItemType":"process","targetItemTitle":"ISMS Governance, Scope & Objectives","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Governance, Risk & Compliance","sourceItemType":"process","targetItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Governance, Risk & Compliance","sourceItemType":"process","targetItemTitle":"Policy Lifecycle, Publication, Acknowledgment & Exceptions","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"People & Workforce Security","sourceItemType":"process","targetItemTitle":"Security Awareness & Role Training","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"People & Workforce Security","sourceItemType":"process","targetItemTitle":"Workforce Security, Acceptable Use & Remote Work","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Secure Development, Change & Infrastructure","sourceItemType":"process","targetItemTitle":"Change, Release & Database Migration","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Secure Development, Change & Infrastructure","sourceItemType":"process","targetItemTitle":"Network, Cloud Configuration & Physical Reliance","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Secure Development, Change & Infrastructure","sourceItemType":"process","targetItemTitle":"On-Prem Appliance & Release Lifecycle","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Secure Development, Change & Infrastructure","sourceItemType":"process","targetItemTitle":"Secure SDLC & Application Security","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Secure Development, Change & Infrastructure","sourceItemType":"process","targetItemTitle":"Tenant Provisioning, Isolation & Teardown","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Secure Development, Change & Infrastructure","sourceItemType":"process","targetItemTitle":"Vulnerability, Patch & Technical Testing","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Security Operations & Resilience","sourceItemType":"process","targetItemTitle":"Backup, Recovery, BC/DR & Capacity","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Security Operations & Resilience","sourceItemType":"process","targetItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Security Operations & Resilience","sourceItemType":"process","targetItemTitle":"Security Incident, Privacy Breach & Postmortem","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Service Delivery & Third-Party","sourceItemType":"process","targetItemTitle":"Continuous Control Operation & Evidence Monitoring","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Service Delivery & Third-Party","sourceItemType":"process","targetItemTitle":"Production Operations & SOC 1 Processing Integrity","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"Service Delivery & Third-Party","sourceItemType":"process","targetItemTitle":"Vendor, Subservice & CUEC Management","targetItemType":"process","kind":"parent","metadata":{"role":"parent-of"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"AI suggestions require human approval before production changes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Cloud SQL access control & least privilege","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Customer data is not used for AI model training; Vertex AI data governance in force","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Data subject rights & consent handling (PII)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Enforce secure coding and input validation standards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Keep personal data accurate and honor correction requests","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud periodic access & group review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"MCP tool surface documented and self-describing via get_schema","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Maintain and provide an accounting of disclosures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Manage unique identities and identifiers end to end","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Model Home Data Lake IAM least-privilege & owner protection","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Model Home Data Lake Secret Manager secrets management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Model Home Data Lake repository & project access management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Provision and deprovision accounts through a managed lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Restrict privileged rights, utilities, and unauthorized software","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Review user access rights periodically","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Segregate conflicting duties and areas of responsibility","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Test software security during development and acceptance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Third-party data-sharing & API access control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI Governance & Human Approval","sourceItemType":"process","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Classify, prioritize, and label information and assets","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Cloud SQL data retention & secure disposal","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Control storage media through use, storage, and destruction","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Ensure quality of information used in reporting","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Maintain equipment to preserve availability and integrity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Manage assets through their life cycle and recover them at exit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Prevent information exposure at desks, screens, and outputs","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"Secure remote working arrangements","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Asset, Media & Classification","sourceItemType":"process","targetItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Availability & capacity management (SLA)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Back up data and verify restorability","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Business continuity & disaster recovery plan testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Cloud SQL backup, integrity & recovery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Evaluate events and declare incidents against defined criteria","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Incident management & customer notification","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Incident reporting channels documented and communicated","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Investigate incidents and preserve evidence and records","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Learn from incidents and communicate corrective actions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Maintain an approved incident response plan","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Maintain business continuity and disaster recovery plans","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Maintain contacts with authorities and special interest groups","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Manage capacity to meet availability requirements","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake account & project baseline hardening","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake backup & disaster recovery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Permit only authorized software installation and use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Provide channels to report events and obtain response help","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Provide redundant and alternate processing, storage, and telecom","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Record complete audit content with synchronized clocks","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Recover from incidents using defined initiation criteria","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Safeguard assets and stored financial data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Test recovery capabilities and train contingency personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Backup, Recovery, BC/DR & Capacity","sourceItemType":"process","targetItemTitle":"Triage, categorize, and escalate reported security events","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes before production","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Customers notified of critical system changes affecting their processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Enforce secure coding and input validation standards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Model Home Data Lake account & project baseline hardening","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Model Home Data Lake branch protection & mandatory code review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Permit only authorized software installation and use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Record complete audit content with synchronized clocks","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Sudden Valley Network registrar account security & DNS change control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Test software security during development and acceptance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Change, Release & Database Migration","sourceItemType":"process","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Assess control effectiveness and authorize systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Communicate and report risk and control information","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Define security roles, responsibilities, and authorities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Ensure board-level oversight of risk and internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"External-facing system description maintained and accurate","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Hold third-party personnel to equivalent security terms","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Identify and manage legal, regulatory, and contractual obligations","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Manage compliance with external legal and regulatory requirements","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Manage subservice organizations supporting the system","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Monitor vendor performance, services, and risk","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Operate a third-party security risk management program","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Oversee outsourced development and vet developers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Perform risk-based due diligence before engaging vendors","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Protect production systems during audit testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Third-party vendor risk assessment & monitoring","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Compliance Obligations, Evidence & External Assurance","sourceItemType":"process","targetItemTitle":"Verify component authenticity, provenance, and integrity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Assess control effectiveness and authorize systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Cloud SQL query & access audit logging","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Communicate and report risk and control information","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"External-facing system description maintained and accurate","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Log security-relevant events across all systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud authentication & admin-event logging","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Model Home Data Lake audit logging of changes & approvals","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Monitor and review risk management performance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Protect production systems during audit testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Continuous Control Operation & Evidence Monitoring","sourceItemType":"process","targetItemTitle":"Track deficiencies to closure with remediation action plans","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Authenticate all users with multi-factor authentication","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Classify, prioritize, and label information and assets","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Cloud SQL encryption & Cloud KMS key management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Ensure quality of information used in reporting","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud SSO & MFA enforcement","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud password & authentication policy","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Model Home Data Lake encryption at rest & in transit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Cryptography, Key & Secrets Management","sourceItemType":"process","targetItemTitle":"Use approved algorithms and validated cryptographic modules","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Enterprise Risk Assessment, Treatment & SoA","sourceItemType":"process","targetItemTitle":"Assess and mitigate fraud risk including management override","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Enterprise Risk Assessment, Treatment & SoA","sourceItemType":"process","targetItemTitle":"Assess changes that could significantly affect risk and control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Enterprise Risk Assessment, Treatment & SoA","sourceItemType":"process","targetItemTitle":"Define objectives and business context for risk assessment","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Enterprise Risk Assessment, Treatment & SoA","sourceItemType":"process","targetItemTitle":"Maintain business continuity and contingency planning policy","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Enterprise Risk Assessment, Treatment & SoA","sourceItemType":"process","targetItemTitle":"Perform periodic enterprise risk assessments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Enterprise Risk Assessment, Treatment & SoA","sourceItemType":"process","targetItemTitle":"Select and tailor a risk-based control baseline","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Assess and mitigate fraud risk including management override","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Assess changes that could significantly affect risk and control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Communicate and report risk and control information","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Define objectives and business context for risk assessment","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Define security roles, responsibilities, and authorities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Ensure board-level oversight of risk and internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"External-facing system description maintained and accurate","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Maintain business continuity and contingency planning policy","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Perform periodic enterprise risk assessments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Select and tailor a risk-based control baseline","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"ISMS Governance, Scope & Objectives","sourceItemType":"process","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Annual performance and conduct evaluation per personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Authenticate all users with multi-factor authentication","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Cloud SQL access control & least privilege","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Deliver security awareness training to all personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Embed security and competence in HR practices","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Enforce a formal disciplinary process for violations","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Formalize security responsibilities in employment terms","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud SSO & MFA enforcement","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud password & authentication policy","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud periodic access & group review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Manage unique identities and identifiers end to end","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Model Home Data Lake IAM least-privilege & owner protection","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Model Home Data Lake Secret Manager secrets management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Model Home Data Lake repository & project access management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Provision and deprovision accounts through a managed lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Restrict privileged rights, utilities, and unauthorized software","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Review user access rights periodically","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Screen personnel commensurate with position risk","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Secure termination and transfer of personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Segregate conflicting duties and areas of responsibility","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"Third-party data-sharing & API access control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Identity, Authentication & Access Lifecycle","sourceItemType":"process","targetItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Assess control effectiveness and authorize systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Communicate and report risk and control information","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Define security roles, responsibilities, and authorities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Ensure board-level oversight of risk and internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"External-facing system description maintained and accurate","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Protect production systems during audit testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","sourceItemType":"process","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Cloud SQL query & access audit logging","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Evaluate events and declare incidents against defined criteria","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Incident reporting channels documented and communicated","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Investigate incidents and preserve evidence and records","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Learn from incidents and communicate corrective actions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Log security-relevant events across all systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud authentication & admin-event logging","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Maintain an approved incident response plan","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Maintain contacts with authorities and special interest groups","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Model Home Data Lake audit logging of changes & approvals","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Monitor and review risk management performance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Operate threat intelligence and threat hunting","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Provide channels to report events and obtain response help","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Track deficiencies to closure with remediation action plans","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Logging, Monitoring, Detection & Threat Intelligence","sourceItemType":"process","targetItemTitle":"Triage, categorize, and escalate reported security events","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Block malware, spam, and phishing across all systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Control mobile code and web content","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Hold third-party personnel to equivalent security terms","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Manage subservice organizations supporting the system","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Model Home Data Lake account & project baseline hardening","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Model Home Data Lake network segmentation & firewall control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Monitor physical access and retain visitor and entry records","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Monitor vendor performance, services, and risk","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Operate a third-party security risk management program","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Oversee outsourced development and vet developers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Perform risk-based due diligence before engaging vendors","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Permit only authorized software installation and use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Protect facilities against fire, water, and environmental hazards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Protect power and communications cabling from damage and taps","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Provide emergency power, lighting, and resilient utilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Record complete audit content with synchronized clocks","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Restrict physical access and maintain environmental safeguards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Restrict physical access to facilities and secure areas","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Secure and monitor networks and network services","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Segment networks and defend the external boundary","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Site facilities and equipment to minimize hazards and exposure","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Third-party risk assessment & SOC report review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Third-party vendor risk assessment & monitoring","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Vendor onboarding due diligence & risk tiering","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Network, Cloud Configuration & Physical Reliance","sourceItemType":"process","targetItemTitle":"Verify component authenticity, provenance, and integrity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes before production","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Customers notified of critical system changes affecting their processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Hold third-party personnel to equivalent security terms","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Manage subservice organizations supporting the system","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Model Home Data Lake account & project baseline hardening","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Model Home Data Lake branch protection & mandatory code review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Monitor vendor performance, services, and risk","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Operate a third-party security risk management program","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Oversee outsourced development and vet developers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Perform risk-based due diligence before engaging vendors","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Permit only authorized software installation and use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Record complete audit content with synchronized clocks","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Sudden Valley Network registrar account security & DNS change control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Test software security during development and acceptance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Third-party vendor risk assessment & monitoring","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"On-Prem Appliance & Release Lifecycle","sourceItemType":"process","targetItemTitle":"Verify component authenticity, provenance, and integrity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Policy Lifecycle, Publication, Acknowledgment & Exceptions","sourceItemType":"process","targetItemTitle":"Communicate and report risk and control information","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Policy Lifecycle, Publication, Acknowledgment & Exceptions","sourceItemType":"process","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Classify, prioritize, and label information and assets","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Cloud SQL PII classification & field-level masking","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Cloud SQL data retention & secure disposal","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Cloud SQL encryption & Cloud KMS key management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Control data flows, leakage, and cross-border transfers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Data subject rights & consent handling (PII)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"De-identify, mask, or pseudonymize personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Encrypt data at rest and in transit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Ensure quality of information used in reporting","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Hold third-party personnel to equivalent security terms","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Keep personal data accurate and honor correction requests","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Maintain and provide an accounting of disclosures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Manage subservice organizations supporting the system","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Model Home Data Lake encryption at rest & in transit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Monitor vendor performance, services, and risk","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Operate a third-party security risk management program","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Oversee outsourced development and vet developers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Perform risk-based due diligence before engaging vendors","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Third-party vendor risk assessment & monitoring","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Transfer information securely under defined rules and agreements","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Use approved algorithms and validated cryptographic modules","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Privacy, Data Lifecycle & Secure Transfer","sourceItemType":"process","targetItemTitle":"Verify component authenticity, provenance, and integrity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes before production","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Back up data and verify restorability","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Cloud SQL access control & least privilege","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Cloud SQL backup, integrity & recovery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Cloud SQL query & access audit logging","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Communicate and report risk and control information","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Customers notified of critical system changes affecting their processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"External-facing system description maintained and accurate","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Log security-relevant events across all systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud authentication & admin-event logging","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud periodic access & group review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Manage unique identities and identifiers end to end","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake IAM least-privilege & owner protection","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake Secret Manager secrets management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake audit logging of changes & approvals","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake backup & disaster recovery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake branch protection & mandatory code review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Model Home Data Lake repository & project access management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Monitor and review risk management performance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Provision and deprovision accounts through a managed lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Restrict privileged rights, utilities, and unauthorized software","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Review user access rights periodically","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Safeguard assets and stored financial data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Segregate conflicting duties and areas of responsibility","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Sudden Valley Network registrar account security & DNS change control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Test software security during development and acceptance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Third-party data-sharing & API access control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Track deficiencies to closure with remediation action plans","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Production Operations & SOC 1 Processing Integrity","sourceItemType":"process","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes before production","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Cloud SQL PII classification & field-level masking","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Customers notified of critical system changes affecting their processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"De-identify, mask, or pseudonymize personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Enforce secure coding and input validation standards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Model Home Data Lake branch protection & mandatory code review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Sudden Valley Network registrar account security & DNS change control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Test software security during development and acceptance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Secure SDLC & Application Security","sourceItemType":"process","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Annual performance and conduct evaluation per personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Data subject rights & consent handling (PII)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Deliver security awareness training to all personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Embed security and competence in HR practices","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Enforce a formal disciplinary process for violations","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Evaluate events and declare incidents against defined criteria","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Formalize security responsibilities in employment terms","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Incident reporting channels documented and communicated","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Investigate incidents and preserve evidence and records","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Keep personal data accurate and honor correction requests","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Learn from incidents and communicate corrective actions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Maintain an approved incident response plan","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Maintain and provide an accounting of disclosures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Maintain contacts with authorities and special interest groups","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Provide channels to report events and obtain response help","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Screen personnel commensurate with position risk","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Secure termination and transfer of personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"Triage, categorize, and escalate reported security events","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Awareness & Role Training","sourceItemType":"process","targetItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Back up data and verify restorability","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Cloud SQL query & access audit logging","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Data subject rights & consent handling (PII)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Evaluate events and declare incidents against defined criteria","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Incident reporting channels documented and communicated","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Investigate incidents and preserve evidence and records","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Keep personal data accurate and honor correction requests","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Learn from incidents and communicate corrective actions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Log security-relevant events across all systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud authentication & admin-event logging","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Maintain an approved incident response plan","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Maintain and provide an accounting of disclosures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Maintain business continuity and disaster recovery plans","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Maintain contacts with authorities and special interest groups","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Manage capacity to meet availability requirements","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Model Home Data Lake audit logging of changes & approvals","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Monitor and review risk management performance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Provide channels to report events and obtain response help","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Provide redundant and alternate processing, storage, and telecom","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Recover from incidents using defined initiation criteria","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Test recovery capabilities and train contingency personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Track deficiencies to closure with remediation action plans","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Security Incident, Privacy Breach & Postmortem","sourceItemType":"process","targetItemTitle":"Triage, categorize, and escalate reported security events","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Classify, prioritize, and label information and assets","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Cloud SQL access control & least privilege","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Cloud SQL data retention & secure disposal","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Cloud SQL encryption & Cloud KMS key management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Data subject rights & consent handling (PII)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Ensure quality of information used in reporting","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Keep personal data accurate and honor correction requests","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Lucille Identity Cloud periodic access & group review","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Maintain and provide an accounting of disclosures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Manage unique identities and identifiers end to end","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Model Home Data Lake IAM least-privilege & owner protection","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Model Home Data Lake Secret Manager secrets management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Model Home Data Lake encryption at rest & in transit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Model Home Data Lake repository & project access management","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Provision and deprovision accounts through a managed lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Restrict privileged rights, utilities, and unauthorized software","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Review user access rights periodically","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Segregate conflicting duties and areas of responsibility","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Third-party data-sharing & API access control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Tenant Provisioning, Isolation & Teardown","sourceItemType":"process","targetItemTitle":"Use approved algorithms and validated cryptographic modules","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Control data flows, leakage, and cross-border transfers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Data subject rights & consent handling (PII)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Encrypt data at rest and in transit","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Hold third-party personnel to equivalent security terms","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Identify and manage legal, regulatory, and contractual obligations","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Keep personal data accurate and honor correction requests","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Maintain and provide an accounting of disclosures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Manage compliance with external legal and regulatory requirements","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Manage subservice organizations supporting the system","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Monitor physical access and retain visitor and entry records","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Monitor vendor performance, services, and risk","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Operate a third-party security risk management program","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Oversee outsourced development and vet developers","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Perform risk-based due diligence before engaging vendors","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Protect facilities against fire, water, and environmental hazards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Protect power and communications cabling from damage and taps","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Provide emergency power, lighting, and resilient utilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Restrict physical access and maintain environmental safeguards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Restrict physical access to facilities and secure areas","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Site facilities and equipment to minimize hazards and exposure","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Third-party vendor risk assessment & monitoring","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Transfer information securely under defined rules and agreements","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vendor, Subservice & CUEC Management","sourceItemType":"process","targetItemTitle":"Verify component authenticity, provenance, and integrity","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Enforce secure coding and input validation standards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Maintain contacts with authorities and special interest groups","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Model Home Data Lake account & project baseline hardening","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Operate threat intelligence and threat hunting","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Permit only authorized software installation and use","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Record complete audit content with synchronized clocks","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Test software security during development and acceptance","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Vulnerability, Patch & Technical Testing","sourceItemType":"process","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Annual performance and conduct evaluation per personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Communicate and report risk and control information","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Deliver security awareness training to all personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Embed security and competence in HR practices","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Enforce a formal disciplinary process for violations","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"External-facing system description maintained and accurate","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Formalize security responsibilities in employment terms","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Monitor physical access and retain visitor and entry records","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Prevent information exposure at desks, screens, and outputs","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Protect facilities against fire, water, and environmental hazards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Protect power and communications cabling from damage and taps","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Provide emergency power, lighting, and resilient utilities","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Restrict physical access and maintain environmental safeguards","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Restrict physical access to facilities and secure areas","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Screen personnel commensurate with position risk","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Secure remote working arrangements","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Secure termination and transfer of personnel","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"Site facilities and equipment to minimize hazards and exposure","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"Workforce Security, Acceptable Use & Remote Work","sourceItemType":"process","targetItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"control","kind":"related","metadata":{"role":"implements"}},{"sourceItemTitle":"AI accountability gaps and organizational liability","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI agent makes unauthorized production changes","sourceItemType":"risk","targetItemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI agent makes unauthorized production changes","sourceItemType":"risk","targetItemTitle":"AI suggestions require human approval before production changes","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI agent makes unauthorized production changes","sourceItemType":"risk","targetItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI agent makes unauthorized production changes","sourceItemType":"risk","targetItemTitle":"MCP tool surface documented and self-describing via get_schema","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI power concentration and erosion of societal trust","sourceItemType":"risk","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI privacy leakage and re-identification","sourceItemType":"risk","targetItemTitle":"De-identify, mask, or pseudonymize personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI safety failures causing physical or psychological harm","sourceItemType":"risk","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI supply-chain compromise and provider concentration","sourceItemType":"risk","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI supply-chain compromise and provider concentration","sourceItemType":"risk","targetItemTitle":"Operate a third-party security risk management program","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI supply-chain compromise and provider concentration","sourceItemType":"risk","targetItemTitle":"Oversee outsourced development and vet developers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI supply-chain compromise and provider concentration","sourceItemType":"risk","targetItemTitle":"Perform risk-based due diligence before engaging vendors","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI supply-chain compromise and provider concentration","sourceItemType":"risk","targetItemTitle":"Verify component authenticity, provenance, and integrity","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Absence of privacy-by-design and default","sourceItemType":"risk","targetItemTitle":"De-identify, mask, or pseudonymize personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Absent or untested business continuity / disaster recovery plan","sourceItemType":"risk","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Absent or untested business continuity / disaster recovery plan","sourceItemType":"risk","targetItemTitle":"Maintain business continuity and disaster recovery plans","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Absent or untested business continuity / disaster recovery plan","sourceItemType":"risk","targetItemTitle":"Test recovery capabilities and train contingency personnel","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Absent or weak change-control procedures","sourceItemType":"risk","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Absent or weak change-control procedures","sourceItemType":"risk","targetItemTitle":"Authorize, test, and approve changes before production","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Absent or weak change-control procedures","sourceItemType":"risk","targetItemTitle":"Customers notified of critical system changes affecting their processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Absent or weak change-control procedures","sourceItemType":"risk","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Absent or weak change-control procedures","sourceItemType":"risk","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Log security-relevant events across all systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Manage unique identities and identifiers end to end","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Provision and deprovision accounts through a managed lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Record complete audit content with synchronized clocks","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Restrict privileged rights, utilities, and unauthorized software","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Review user access rights periodically","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Abuse of rights, forged rights, and repudiation of actions","sourceItemType":"risk","targetItemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Acceptance of data from untrustworthy sources","sourceItemType":"risk","targetItemTitle":"Control mobile code and web content","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Acceptance of data from untrustworthy sources","sourceItemType":"risk","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Adversarial attacks, data poisoning and prompt injection","sourceItemType":"risk","targetItemTitle":"Enforce secure coding and input validation standards","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Adversarial attacks, data poisoning and prompt injection","sourceItemType":"risk","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Adversary reconnaissance and information gathering","sourceItemType":"risk","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Adversary reconnaissance and information gathering","sourceItemType":"risk","targetItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Adverse regulatory or policy change","sourceItemType":"risk","targetItemTitle":"Assess changes that could significantly affect risk and control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Aging hardware with no periodic replacement scheme","sourceItemType":"risk","targetItemTitle":"Manage assets through their life cycle and recover them at exit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Applications running with excessive privilege / insecure design","sourceItemType":"risk","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Applications running with excessive privilege / insecure design","sourceItemType":"risk","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Assets not returned upon employee termination","sourceItemType":"risk","targetItemTitle":"Manage assets through their life cycle and recover them at exit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Attacks by capable, motivated threat actors","sourceItemType":"risk","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Attacks by capable, motivated threat actors","sourceItemType":"risk","targetItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Attacks by capable, motivated threat actors","sourceItemType":"risk","targetItemTitle":"Evaluate events and declare incidents against defined criteria","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Attacks by capable, motivated threat actors","sourceItemType":"risk","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Attacks by capable, motivated threat actors","sourceItemType":"risk","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Attacks by capable, motivated threat actors","sourceItemType":"risk","targetItemTitle":"Operate threat intelligence and threat hunting","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Attacks by capable, motivated threat actors","sourceItemType":"risk","targetItemTitle":"Perform periodic enterprise risk assessments","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Brand and reputational crisis","sourceItemType":"risk","targetItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Brand and reputational crisis","sourceItemType":"risk","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Business combination purchase accounting misstatement (ASC 805)","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Capex overrun on data-center fit-out","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Capitalization / CIP misstatement on data-center builds","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Carrier interconnect concentration risk","sourceItemType":"risk","targetItemTitle":"Third-party risk assessment & SOC report review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Carrier interconnect concentration risk","sourceItemType":"risk","targetItemTitle":"Vendor onboarding due diligence & risk tiering","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Chilled-water plant failure causing thermal event","sourceItemType":"risk","targetItemTitle":"Availability & capacity management (SLA)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Chilled-water plant failure causing thermal event","sourceItemType":"risk","targetItemTitle":"Business continuity & disaster recovery plan testing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Client intake, documentation and account-management failures","sourceItemType":"risk","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Client selection, sponsorship and exposure-limit breaches","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Client suitability, disclosure and fiduciary breaches","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Climate transition risk - carbon pricing and stranded assets","sourceItemType":"risk","targetItemTitle":"Identify and manage legal, regulatory, and contractual obligations","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Climate transition risk - carbon pricing and stranded assets","sourceItemType":"risk","targetItemTitle":"Maintain business continuity and contingency planning policy","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Cloud multi-tenancy isolation and data-scavenging exploits","sourceItemType":"risk","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Colocation billing incomplete or inaccurate (SOC 1 user-entity impact)","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Communications interception, eavesdropping and man-in-the-middle","sourceItemType":"risk","targetItemTitle":"Use approved algorithms and validated cryptographic modules","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Competitive displacement by established GRC platforms","sourceItemType":"risk","targetItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Competitive disruption and business-model obsolescence","sourceItemType":"risk","targetItemTitle":"Assess changes that could significantly affect risk and control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Compromised or counterfeit certificates / certificate authority","sourceItemType":"risk","targetItemTitle":"Encrypt data at rest and in transit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Compromised or counterfeit certificates / certificate authority","sourceItemType":"risk","targetItemTitle":"Use approved algorithms and validated cryptographic modules","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Construction delay on critical-path equipment","sourceItemType":"risk","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Coordinated multi-stage / APT campaigns","sourceItemType":"risk","targetItemTitle":"Investigate incidents and preserve evidence and records","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Coordinated multi-stage / APT campaigns","sourceItemType":"risk","targetItemTitle":"Recover from incidents using defined initiation criteria","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Coordinated multi-stage / APT campaigns","sourceItemType":"risk","targetItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Coordinated multi-stage / APT campaigns","sourceItemType":"risk","targetItemTitle":"Segment networks and defend the external boundary","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Core process breakdown and inability to scale","sourceItemType":"risk","targetItemTitle":"Define security roles, responsibilities, and authorities","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Corruption or integrity loss of critical data","sourceItemType":"risk","targetItemTitle":"Keep personal data accurate and honor correction requests","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Corruption or integrity loss of critical data","sourceItemType":"risk","targetItemTitle":"Protect production systems during audit testing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Credentials and sensitive data transmitted in clear text","sourceItemType":"risk","targetItemTitle":"Encrypt data at rest and in transit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Credit and market (rate/FX) risk","sourceItemType":"risk","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Critical subservice organization (firm) failure leaves governance, finance, and security oversight vacuum","sourceItemType":"risk","targetItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Critical talent loss, scarcity and succession gaps","sourceItemType":"risk","targetItemTitle":"Embed security and competence in HR practices","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Critical talent loss, scarcity and succession gaps","sourceItemType":"risk","targetItemTitle":"Test recovery capabilities and train contingency personnel","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Critical vendor failure, insolvency or concentration","sourceItemType":"risk","targetItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Critical vendor failure, insolvency or concentration","sourceItemType":"risk","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Critical vendor failure, insolvency or concentration","sourceItemType":"risk","targetItemTitle":"Manage subservice organizations supporting the system","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Critical vendor failure, insolvency or concentration","sourceItemType":"risk","targetItemTitle":"Monitor vendor performance, services, and risk","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Critical vendor failure, insolvency or concentration","sourceItemType":"risk","targetItemTitle":"Perform risk-based due diligence before engaging vendors","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Cross-border personal-data transfer without safeguards","sourceItemType":"risk","targetItemTitle":"Control data flows, leakage, and cross-border transfers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Customer concentration risk - over-reliance on key clients","sourceItemType":"risk","targetItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data exfiltration and theft of information by attackers","sourceItemType":"risk","targetItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data exfiltration and theft of information by attackers","sourceItemType":"risk","targetItemTitle":"Control data flows, leakage, and cross-border transfers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data exfiltration and theft of information by attackers","sourceItemType":"risk","targetItemTitle":"Evaluate events and declare incidents against defined criteria","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data exfiltration and theft of information by attackers","sourceItemType":"risk","targetItemTitle":"Log security-relevant events across all systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data exfiltration and theft of information by attackers","sourceItemType":"risk","targetItemTitle":"Record complete audit content with synchronized clocks","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data-center availability / environmental failure (SOC 1)","sourceItemType":"risk","targetItemTitle":"Availability & capacity management (SLA)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data-center availability / environmental failure (SOC 1)","sourceItemType":"risk","targetItemTitle":"Business continuity & disaster recovery plan testing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data-center availability / environmental failure (SOC 1)","sourceItemType":"risk","targetItemTitle":"Incident management & customer notification","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data-quality and IPE integrity failures in reporting","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data-quality and IPE integrity failures in reporting","sourceItemType":"risk","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data-quality and IPE integrity failures in reporting","sourceItemType":"risk","targetItemTitle":"Ensure quality of information used in reporting","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data-quality and IPE integrity failures in reporting","sourceItemType":"risk","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data-quality and IPE integrity failures in reporting","sourceItemType":"risk","targetItemTitle":"Safeguard assets and stored financial data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Data-quality and IPE integrity failures in reporting","sourceItemType":"risk","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Debt covenant breach under downside case","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Denial-of-service and system saturation","sourceItemType":"risk","targetItemTitle":"Manage capacity to meet availability requirements","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Deployment of prohibited AI practices (EU AI Act Art.5)","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Developer self-approves and deploys own change via CI/CD","sourceItemType":"risk","targetItemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Discrimination, harassment and hostile-workplace culture","sourceItemType":"risk","targetItemTitle":"Formalize security responsibilities in employment terms","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Discrimination, harassment and hostile-workplace culture","sourceItemType":"risk","targetItemTitle":"Screen personnel commensurate with position risk","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Discriminatory outcomes from AI in employment","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Domain hijacking or DNS integrity failure at the registrar","sourceItemType":"risk","targetItemTitle":"Sudden Valley Network registrar account security & DNS change control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"ERP/HRIS implementation cutover errors impair opening balances","sourceItemType":"risk","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"ESG disclosure gaps and greenwashing","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Emergent behaviour and unsafe AI system integration","sourceItemType":"risk","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Emergent behaviour and unsafe AI system integration","sourceItemType":"risk","targetItemTitle":"Authorize, test, and approve changes before production","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Employment-practice and labor-law violations","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Environmental degradation of equipment (dust, humidity, temperature, EMI)","sourceItemType":"risk","targetItemTitle":"Maintain equipment to preserve availability and integrity","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Environmental footprint of AI training and infrastructure","sourceItemType":"risk","targetItemTitle":"Monitor and review risk management performance","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Environmental regulatory non-compliance","sourceItemType":"risk","targetItemTitle":"Manage compliance with external legal and regulatory requirements","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Erosion of individual trust and confidence in data practices","sourceItemType":"risk","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Erosion of individual trust and confidence in data practices","sourceItemType":"risk","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Erosion of individual trust and confidence in data practices","sourceItemType":"risk","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excess or unauthorized access to financial systems","sourceItemType":"risk","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excess privileged access to building-management systems","sourceItemType":"risk","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive Cloud SQL access exposes regulated PII","sourceItemType":"risk","targetItemTitle":"Cloud SQL access control & least privilege","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive Lucille Identity Cloud group membership grants unintended access","sourceItemType":"risk","targetItemTitle":"Lucille Identity Cloud periodic access & group review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive collection, purpose creep and secondary use","sourceItemType":"risk","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive collection, purpose creep and secondary use","sourceItemType":"risk","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive collection, purpose creep and secondary use","sourceItemType":"risk","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive privilege and wrong assignment of access rights","sourceItemType":"risk","targetItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive privilege and wrong assignment of access rights","sourceItemType":"risk","targetItemTitle":"Provision and deprovision accounts through a managed lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive privilege and wrong assignment of access rights","sourceItemType":"risk","targetItemTitle":"Restrict privileged rights, utilities, and unauthorized software","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive privilege and wrong assignment of access rights","sourceItemType":"risk","targetItemTitle":"Review user access rights periodically","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive surveillance, appropriation and induced disclosure","sourceItemType":"risk","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Excessive surveillance, appropriation and induced disclosure","sourceItemType":"risk","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Exploitation of known, unpatched vulnerabilities","sourceItemType":"risk","targetItemTitle":"Block malware, spam, and phishing across all systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Exploitation of known, unpatched vulnerabilities","sourceItemType":"risk","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Exploitation of known, unpatched vulnerabilities","sourceItemType":"risk","targetItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Exploitation of known, unpatched vulnerabilities","sourceItemType":"risk","targetItemTitle":"Test software security during development and acceptance","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"External fraud - third-party theft, forgery, payment and account fraud","sourceItemType":"risk","targetItemTitle":"Authenticate all users with multi-factor authentication","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"External fraud - third-party theft, forgery, payment and account fraud","sourceItemType":"risk","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"External fraud - third-party theft, forgery, payment and account fraud","sourceItemType":"risk","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"External fraud - third-party theft, forgery, payment and account fraud","sourceItemType":"risk","targetItemTitle":"Operate threat intelligence and threat hunting","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"F-gas refrigerant leak above reporting threshold","sourceItemType":"risk","targetItemTitle":"Availability & capacity management (SLA)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Failed M&A, integration or divestiture","sourceItemType":"risk","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Failed or inaccurate mandatory regulatory reporting","sourceItemType":"risk","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Failure to detect, assess, and notify breaches on time","sourceItemType":"risk","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Failure to detect, assess, and notify breaches on time","sourceItemType":"risk","targetItemTitle":"Incident reporting channels documented and communicated","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Failure to detect, assess, and notify breaches on time","sourceItemType":"risk","targetItemTitle":"Maintain an approved incident response plan","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Failure to detect, assess, and notify breaches on time","sourceItemType":"risk","targetItemTitle":"Provide channels to report events and obtain response help","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Failure to detect, assess, and notify breaches on time","sourceItemType":"risk","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Failure to detect, assess, and notify breaches on time","sourceItemType":"risk","targetItemTitle":"Triage, categorize, and escalate reported security events","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Financial close error or delay leading to restatement","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Financial-statement fraud and management override","sourceItemType":"risk","targetItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Financial-statement fraud and management override","sourceItemType":"risk","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Firm-internal segregation of duties claimed but not enforced (paper-only)","sourceItemType":"risk","targetItemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Firm-internal segregation of duties claimed but not enforced (paper-only)","sourceItemType":"risk","targetItemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Firm-internal segregation of duties claimed but not enforced (paper-only)","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake branch protection & mandatory code review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Fraudulent or unauthorized disbursement (P2P / Treasury)","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"GPAI transparency, systemic-risk and synthetic-content obligations","sourceItemType":"risk","targetItemTitle":"Operate a third-party security risk management program","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Geopolitical, macroeconomic and sovereign risk","sourceItemType":"risk","targetItemTitle":"Assess changes that could significantly affect risk and control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Geopolitical, macroeconomic and sovereign risk","sourceItemType":"risk","targetItemTitle":"Operate a third-party security risk management program","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Hardware and equipment failure","sourceItemType":"risk","targetItemTitle":"Manage assets through their life cycle and recover them at exit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Harm to due process and democratic integrity from AI","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Harmful AI bias and discrimination against protected groups","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"IT resilience failure - unplanned outage, data loss, slow recovery","sourceItemType":"risk","targetItemTitle":"Back up data and verify restorability","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"IT resilience failure - unplanned outage, data loss, slow recovery","sourceItemType":"risk","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"IT resilience failure - unplanned outage, data loss, slow recovery","sourceItemType":"risk","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"IT resilience failure - unplanned outage, data loss, slow recovery","sourceItemType":"risk","targetItemTitle":"Manage capacity to meet availability requirements","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"IT resilience failure - unplanned outage, data loss, slow recovery","sourceItemType":"risk","targetItemTitle":"Provide redundant and alternate processing, storage, and telecom","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"IT resilience failure - unplanned outage, data loss, slow recovery","sourceItemType":"risk","targetItemTitle":"Test recovery capabilities and train contingency personnel","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"ITGC deficiency in newly implemented Banana ERP / Never Nude HR Platform undermines ICFR","sourceItemType":"risk","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Illegal processing of personal or sensitive data","sourceItemType":"risk","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Illegal processing of personal or sensitive data","sourceItemType":"risk","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Illegal processing of personal or sensitive data","sourceItemType":"risk","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Improper business or market practices","sourceItemType":"risk","targetItemTitle":"Assess control effectiveness and authorize systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inaccurate, unreliable or hallucinated AI outputs","sourceItemType":"risk","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate board and management oversight of risk and control","sourceItemType":"risk","targetItemTitle":"Ensure board-level oversight of risk and internal control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate board and management oversight of risk and control","sourceItemType":"risk","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate on-call coverage misses customer SLA commitments","sourceItemType":"risk","targetItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate on-call coverage misses customer SLA commitments","sourceItemType":"risk","targetItemTitle":"Third-party vendor risk assessment & monitoring","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate or absent risk assessment process","sourceItemType":"risk","targetItemTitle":"Define objectives and business context for risk assessment","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate or absent risk assessment process","sourceItemType":"risk","targetItemTitle":"Monitor and review risk management performance","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate or absent risk assessment process","sourceItemType":"risk","targetItemTitle":"Perform periodic enterprise risk assessments","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate or absent risk assessment process","sourceItemType":"risk","targetItemTitle":"Track deficiencies to closure with remediation action plans","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate physical protection and access controls","sourceItemType":"risk","targetItemTitle":"Monitor physical access and retain visitor and entry records","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate physical protection and access controls","sourceItemType":"risk","targetItemTitle":"Restrict physical access and maintain environmental safeguards","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate physical protection and access controls","sourceItemType":"risk","targetItemTitle":"Restrict physical access to facilities and secure areas","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate physical protection and access controls","sourceItemType":"risk","targetItemTitle":"Site facilities and equipment to minimize hazards and exposure","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate security awareness and training","sourceItemType":"risk","targetItemTitle":"Deliver security awareness training to all personnel","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate security awareness and training","sourceItemType":"risk","targetItemTitle":"Embed security and competence in HR practices","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate transparency, notice and deceptive privacy communications","sourceItemType":"risk","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inadequate transparency, notice and deceptive privacy communications","sourceItemType":"risk","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Income / property / indirect tax misstatement (ASC 740)","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Incomplete asset inventory and classification","sourceItemType":"risk","targetItemTitle":"Classify, prioritize, and label information and assets","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Incomplete asset inventory and classification","sourceItemType":"risk","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Incomplete asset inventory and classification","sourceItemType":"risk","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Incomplete asset inventory and classification","sourceItemType":"risk","targetItemTitle":"Manage assets through their life cycle and recover them at exit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ineffective ICFR / undisclosed material weakness","sourceItemType":"risk","targetItemTitle":"Ensure board-level oversight of risk and internal control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ineffective ICFR / undisclosed material weakness","sourceItemType":"risk","targetItemTitle":"Ensure quality of information used in reporting","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ineffective ICFR / undisclosed material weakness","sourceItemType":"risk","targetItemTitle":"Segregate conflicting duties and areas of responsibility","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ineffective ICFR / undisclosed material weakness","sourceItemType":"risk","targetItemTitle":"Select and tailor a risk-based control baseline","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Insufficient personnel screening and vetting","sourceItemType":"risk","targetItemTitle":"Enforce a formal disciplinary process for violations","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Insufficient personnel screening and vetting","sourceItemType":"risk","targetItemTitle":"Hold third-party personnel to equivalent security terms","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Insufficient personnel screening and vetting","sourceItemType":"risk","targetItemTitle":"Screen personnel commensurate with position risk","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Insufficient personnel screening and vetting","sourceItemType":"risk","targetItemTitle":"Secure termination and transfer of personnel","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Intellectual property loss or infringement","sourceItemType":"risk","targetItemTitle":"Classify, prioritize, and label information and assets","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Intellectual property loss or infringement","sourceItemType":"risk","targetItemTitle":"Transfer information securely under defined rules and agreements","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Internal fraud - asset misappropriation, embezzlement, forgery","sourceItemType":"risk","targetItemTitle":"Assess and mitigate fraud risk including management override","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Internal fraud - asset misappropriation, embezzlement, forgery","sourceItemType":"risk","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Internal fraud - asset misappropriation, embezzlement, forgery","sourceItemType":"risk","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Internal fraud - asset misappropriation, embezzlement, forgery","sourceItemType":"risk","targetItemTitle":"Segregate conflicting duties and areas of responsibility","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Internal fraud - asset misappropriation, embezzlement, forgery","sourceItemType":"risk","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Internet-exposed or misconfigured systems","sourceItemType":"risk","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Internet-exposed or misconfigured systems","sourceItemType":"risk","targetItemTitle":"Secure and monitor networks and network services","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Internet-exposed or misconfigured systems","sourceItemType":"risk","targetItemTitle":"Segment networks and defend the external boundary","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Inventory / critical-spares valuation or obsolescence error","sourceItemType":"risk","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Lack of independent audit and compliance review","sourceItemType":"risk","targetItemTitle":"Assess control effectiveness and authorize systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Lack of independent audit and compliance review","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Lack of independent audit and compliance review","sourceItemType":"risk","targetItemTitle":"External-facing system description maintained and accurate","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Leaked CI/CD pipeline secret grants environment access","sourceItemType":"risk","targetItemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Lease accounting error (ASC 842) on ground/building leases","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Litigation, investigation and enforcement exposure","sourceItemType":"risk","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Litigation, investigation and enforcement exposure","sourceItemType":"risk","targetItemTitle":"Identify and manage legal, regulatory, and contractual obligations","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Litigation, investigation and enforcement exposure","sourceItemType":"risk","targetItemTitle":"Maintain contacts with authorities and special interest groups","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Litigation, investigation and enforcement exposure","sourceItemType":"risk","targetItemTitle":"Manage compliance with external legal and regulatory requirements","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Loss of essential services (power, HVAC, telecoms)","sourceItemType":"risk","targetItemTitle":"Maintain equipment to preserve availability and integrity","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Loss of essential services (power, HVAC, telecoms)","sourceItemType":"risk","targetItemTitle":"Protect power and communications cabling from damage and taps","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Loss of essential services (power, HVAC, telecoms)","sourceItemType":"risk","targetItemTitle":"Provide emergency power, lighting, and resilient utilities","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Loss of essential services (power, HVAC, telecoms)","sourceItemType":"risk","targetItemTitle":"Restrict physical access and maintain environmental safeguards","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Loss of system maintainability","sourceItemType":"risk","targetItemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Loss of system maintainability","sourceItemType":"risk","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Loss of utility power without N+1 failover","sourceItemType":"risk","targetItemTitle":"Availability & capacity management (SLA)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Loss of utility power without N+1 failover","sourceItemType":"risk","targetItemTitle":"Business continuity & disaster recovery plan testing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Malicious supply-chain injection of tampered hardware/software","sourceItemType":"risk","targetItemTitle":"Oversee outsourced development and vet developers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Malicious supply-chain injection of tampered hardware/software","sourceItemType":"risk","targetItemTitle":"Verify component authenticity, provenance, and integrity","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Malware delivery, insertion and compromise of systems","sourceItemType":"risk","targetItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Malware delivery, insertion and compromise of systems","sourceItemType":"risk","targetItemTitle":"Block malware, spam, and phishing across all systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Malware delivery, insertion and compromise of systems","sourceItemType":"risk","targetItemTitle":"Control mobile code and web content","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Malware delivery, insertion and compromise of systems","sourceItemType":"risk","targetItemTitle":"Enforce secure coding and input validation standards","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Malware delivery, insertion and compromise of systems","sourceItemType":"risk","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Manual journal entries and management-override risk","sourceItemType":"risk","targetItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Manual journal entries and management-override risk","sourceItemType":"risk","targetItemTitle":"Restrict privileged rights, utilities, and unauthorized software","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Manual journal entries and management-override risk","sourceItemType":"risk","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Material weakness in ICFR undermines IPO readiness","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Misconfigured Model Home Data Lake resource exposes data publicly","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake account & project baseline hardening","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Misconfigured Model Home Data Lake resource exposes data publicly","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake encryption at rest & in transit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Misconfigured Model Home Data Lake resource exposes data publicly","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Misconfigured Model Home Data Lake resource exposes data publicly","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake network segmentation & firewall control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing MFA on Lucille Identity Cloud enables account takeover","sourceItemType":"risk","targetItemTitle":"Lucille Identity Cloud SSO & MFA enforcement","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing MFA on Lucille Identity Cloud enables account takeover","sourceItemType":"risk","targetItemTitle":"Lucille Identity Cloud authentication & admin-event logging","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing MFA on Lucille Identity Cloud enables account takeover","sourceItemType":"risk","targetItemTitle":"Lucille Identity Cloud password & authentication policy","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing or insufficient logging and audit trails","sourceItemType":"risk","targetItemTitle":"Investigate incidents and preserve evidence and records","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing or insufficient logging and audit trails","sourceItemType":"risk","targetItemTitle":"Log security-relevant events across all systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing or insufficient logging and audit trails","sourceItemType":"risk","targetItemTitle":"Record complete audit content with synchronized clocks","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing or insufficient security and privacy policies","sourceItemType":"risk","targetItemTitle":"Define security roles, responsibilities, and authorities","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing or insufficient security and privacy policies","sourceItemType":"risk","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing or insufficient security and privacy policies","sourceItemType":"risk","targetItemTitle":"Maintain business continuity and contingency planning policy","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing role-based and ongoing security/privacy training","sourceItemType":"risk","targetItemTitle":"Embed security and competence in HR practices","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing role-based and ongoing security/privacy training","sourceItemType":"risk","targetItemTitle":"Secure remote working arrangements","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing security terms in contracts and no disciplinary process","sourceItemType":"risk","targetItemTitle":"Annual performance and conduct evaluation per personnel","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing security terms in contracts and no disciplinary process","sourceItemType":"risk","targetItemTitle":"Enforce a formal disciplinary process for violations","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing security terms in contracts and no disciplinary process","sourceItemType":"risk","targetItemTitle":"Formalize security responsibilities in employment terms","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing security terms in contracts and no disciplinary process","sourceItemType":"risk","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Missing security terms in contracts and no disciplinary process","sourceItemType":"risk","targetItemTitle":"Hold third-party personnel to equivalent security terms","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Model Home Data Lake outage without tested recovery causes prolonged downtime","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake backup & disaster recovery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"No or insufficient incident-response procedures","sourceItemType":"risk","targetItemTitle":"Incident reporting channels documented and communicated","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"No or insufficient incident-response procedures","sourceItemType":"risk","targetItemTitle":"Learn from incidents and communicate corrective actions","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"No or insufficient incident-response procedures","sourceItemType":"risk","targetItemTitle":"Maintain an approved incident response plan","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"No or insufficient incident-response procedures","sourceItemType":"risk","targetItemTitle":"Provide channels to report events and obtain response help","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"No or insufficient incident-response procedures","sourceItemType":"risk","targetItemTitle":"Triage, categorize, and escalate reported security events","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"No security monitoring or supervision of privileged activity","sourceItemType":"risk","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"No security monitoring or supervision of privileged activity","sourceItemType":"risk","targetItemTitle":"Evaluate events and declare incidents against defined criteria","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"No security monitoring or supervision of privileged activity","sourceItemType":"risk","targetItemTitle":"Provide channels to report events and obtain response help","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"No security monitoring or supervision of privileged activity","sourceItemType":"risk","targetItemTitle":"Triage, categorize, and escalate reported security events","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Non-compliance with energy-efficiency reporting","sourceItemType":"risk","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Orphaned or stale Lucille Identity Cloud accounts retain access","sourceItemType":"risk","targetItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Orphaned or stale Lucille Identity Cloud accounts retain access","sourceItemType":"risk","targetItemTitle":"Lucille Identity Cloud periodic access & group review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Over-privileged Model Home Data Lake IAM principal is compromised","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake IAM least-privilege & owner protection","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Over-retention of PII in Cloud SQL breaches privacy commitments","sourceItemType":"risk","targetItemTitle":"Cloud SQL data retention & secure disposal","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Over-retention of PII in Cloud SQL breaches privacy commitments","sourceItemType":"risk","targetItemTitle":"Data subject rights & consent handling (PII)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Overstatement of assets/revenue (existence & occurrence)","sourceItemType":"risk","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Overstatement of assets/revenue (existence & occurrence)","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Overstatement of assets/revenue (existence & occurrence)","sourceItemType":"risk","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Overstatement of assets/revenue (existence & occurrence)","sourceItemType":"risk","targetItemTitle":"Safeguard assets and stored financial data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Phishing, spear-phishing and social engineering","sourceItemType":"risk","targetItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Phishing, spear-phishing and social engineering","sourceItemType":"risk","targetItemTitle":"Authenticate all users with multi-factor authentication","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Phishing, spear-phishing and social engineering","sourceItemType":"risk","targetItemTitle":"Deliver security awareness training to all personnel","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical and cyber-physical attacks on facilities and infrastructure","sourceItemType":"risk","targetItemTitle":"Monitor physical access and retain visitor and entry records","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical and cyber-physical attacks on facilities and infrastructure","sourceItemType":"risk","targetItemTitle":"Protect power and communications cabling from damage and taps","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical and cyber-physical attacks on facilities and infrastructure","sourceItemType":"risk","targetItemTitle":"Restrict physical access and maintain environmental safeguards","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical and cyber-physical attacks on facilities and infrastructure","sourceItemType":"risk","targetItemTitle":"Restrict physical access to facilities and secure areas","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical climate risk to facilities and supply chains","sourceItemType":"risk","targetItemTitle":"Maintain business continuity and disaster recovery plans","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical climate risk to facilities and supply chains","sourceItemType":"risk","targetItemTitle":"Protect facilities against fire, water, and environmental hazards","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical climate risk to facilities and supply chains","sourceItemType":"risk","targetItemTitle":"Provide redundant and alternate processing, storage, and telecom","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical climate risk to facilities and supply chains","sourceItemType":"risk","targetItemTitle":"Site facilities and equipment to minimize hazards and exposure","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical damage to assets from disaster, terrorism or vandalism","sourceItemType":"risk","targetItemTitle":"Protect facilities against fire, water, and environmental hazards","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical damage to assets from disaster, terrorism or vandalism","sourceItemType":"risk","targetItemTitle":"Provide emergency power, lighting, and resilient utilities","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Physical damage to assets from disaster, terrorism or vandalism","sourceItemType":"risk","targetItemTitle":"Site facilities and equipment to minimize hazards and exposure","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Poor configuration management and insecure baseline drift","sourceItemType":"risk","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Poor configuration management and insecure baseline drift","sourceItemType":"risk","targetItemTitle":"Authorize, test, and approve changes before production","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Poor configuration management and insecure baseline drift","sourceItemType":"risk","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Poor configuration management and insecure baseline drift","sourceItemType":"risk","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Poor network architecture and unprotected public connections","sourceItemType":"risk","targetItemTitle":"Secure and monitor networks and network services","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Poor network architecture and unprotected public connections","sourceItemType":"risk","targetItemTitle":"Segment networks and defend the external boundary","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Power imbalance and loss of self-determination over personal data","sourceItemType":"risk","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Power imbalance and loss of self-determination over personal data","sourceItemType":"risk","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","sourceItemType":"risk","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","sourceItemType":"risk","targetItemTitle":"Keep personal data accurate and honor correction requests","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","sourceItemType":"risk","targetItemTitle":"Maintain and provide an accounting of disclosures","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","sourceItemType":"risk","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","sourceItemType":"risk","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","sourceItemType":"risk","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","sourceItemType":"risk","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","sourceItemType":"risk","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"REIT carve-out & sale-leaseback accounting error","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ransomware disrupting operations and data availability","sourceItemType":"risk","targetItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ransomware disrupting operations and data availability","sourceItemType":"risk","targetItemTitle":"Back up data and verify restorability","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ransomware disrupting operations and data availability","sourceItemType":"risk","targetItemTitle":"Enforce secure coding and input validation standards","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ransomware disrupting operations and data availability","sourceItemType":"risk","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ransomware disrupting operations and data availability","sourceItemType":"risk","targetItemTitle":"Recover from incidents using defined initiation criteria","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Ransomware disrupting operations and data availability","sourceItemType":"risk","targetItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Re-identification and unanticipated revelation from data","sourceItemType":"risk","targetItemTitle":"De-identify, mask, or pseudonymize personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Re-identification and unanticipated revelation from data","sourceItemType":"risk","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Refinancing risk at facility maturity","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Remote spying and shoulder-surfing of screens/documents","sourceItemType":"risk","targetItemTitle":"Prevent information exposure at desks, screens, and outputs","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Remote-work, mobile and split-tunneling exposure","sourceItemType":"risk","targetItemTitle":"Secure remote working arrangements","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Remote-work, mobile and split-tunneling exposure","sourceItemType":"risk","targetItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Residual data on improperly disposed or re-used media","sourceItemType":"risk","targetItemTitle":"Classify, prioritize, and label information and assets","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Residual data on improperly disposed or re-used media","sourceItemType":"risk","targetItemTitle":"Control storage media through use, storage, and destruction","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Residual data on improperly disposed or re-used media","sourceItemType":"risk","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Revenue recognized incorrectly on complex colocation contracts (ASC 606)","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Revenue sustainability and cash flow constraints","sourceItemType":"risk","targetItemTitle":"Identify and manage legal, regulatory, and contractual obligations","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Revenue sustainability and cash flow constraints","sourceItemType":"risk","targetItemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Secrets sprawl outside Secret Manager are leaked","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake Secret Manager secrets management","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Segregation-of-duties conflicts across Banana ERP / Banana ERP","sourceItemType":"risk","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Sensitive data leaked through uncontrolled transfer channels","sourceItemType":"risk","targetItemTitle":"Control data flows, leakage, and cross-border transfers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Sensitive data leaked through uncontrolled transfer channels","sourceItemType":"risk","targetItemTitle":"Customer data is not used for AI model training; Vertex AI data governance in force","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Sensitive data leaked through uncontrolled transfer channels","sourceItemType":"risk","targetItemTitle":"Transfer information securely under defined rules and agreements","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Single code reviewer dependency creates change-management bottleneck and SoD failure on reviewer's own changes","sourceItemType":"risk","targetItemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Single code reviewer dependency creates change-management bottleneck and SoD failure on reviewer's own changes","sourceItemType":"risk","targetItemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Single-site / single-region / single-supply concentration","sourceItemType":"risk","targetItemTitle":"Back up data and verify restorability","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Single-site / single-region / single-supply concentration","sourceItemType":"risk","targetItemTitle":"Maintain business continuity and disaster recovery plans","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Single-site / single-region / single-supply concentration","sourceItemType":"risk","targetItemTitle":"Provide redundant and alternate processing, storage, and telecom","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Single-site outage without DR failover","sourceItemType":"risk","targetItemTitle":"Business continuity & disaster recovery plan testing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Single-site outage without DR failover","sourceItemType":"risk","targetItemTitle":"Incident management & customer notification","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Single-source dependency on cooling OEM","sourceItemType":"risk","targetItemTitle":"Vendor onboarding due diligence & risk tiering","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Software and information-system failure","sourceItemType":"risk","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Software and information-system failure","sourceItemType":"risk","targetItemTitle":"Manage capacity to meet availability requirements","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Software and information-system failure","sourceItemType":"risk","targetItemTitle":"Protect production systems during audit testing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Stakeholder trust and social-license erosion","sourceItemType":"risk","targetItemTitle":"Communicate and report risk and control information","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Stakeholder trust and social-license erosion","sourceItemType":"risk","targetItemTitle":"Customers notified of critical system changes affecting their processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Stakeholder trust and social-license erosion","sourceItemType":"risk","targetItemTitle":"External-facing system description maintained and accurate","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Stock-based compensation expense misstated (ASC 718)","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Subcontractor fails security due-diligence","sourceItemType":"risk","targetItemTitle":"Third-party risk assessment & SOC report review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Subcontractor fails security due-diligence","sourceItemType":"risk","targetItemTitle":"Vendor onboarding due diligence & risk tiering","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Subservice organization reliance failure (SOC 1 CUECs)","sourceItemType":"risk","targetItemTitle":"Third-party risk assessment & SOC report review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Theft of equipment, media or unattended devices","sourceItemType":"risk","targetItemTitle":"Control storage media through use, storage, and destruction","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Theft of equipment, media or unattended devices","sourceItemType":"risk","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Theft of equipment, media or unattended devices","sourceItemType":"risk","targetItemTitle":"Manage assets through their life cycle and recover them at exit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Theft of equipment, media or unattended devices","sourceItemType":"risk","targetItemTitle":"Monitor physical access and retain visitor and entry records","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Theft of equipment, media or unattended devices","sourceItemType":"risk","targetItemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Theft of equipment, media or unattended devices","sourceItemType":"risk","targetItemTitle":"Restrict physical access to facilities and secure areas","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Theft of equipment, media or unattended devices","sourceItemType":"risk","targetItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Third-party / vendor concentration & SOC-report gap","sourceItemType":"risk","targetItemTitle":"Vendor onboarding due diligence & risk tiering","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Third-party compliance failure creating vicarious liability","sourceItemType":"risk","targetItemTitle":"Manage subservice organizations supporting the system","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Third-party compliance failure creating vicarious liability","sourceItemType":"risk","targetItemTitle":"Monitor vendor performance, services, and risk","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unapproved change introduces financial-system error","sourceItemType":"risk","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized access to customer environments / white space","sourceItemType":"risk","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized activity - rogue trading, position mismarking, concealment","sourceItemType":"risk","targetItemTitle":"Assess and mitigate fraud risk including management override","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized activity - rogue trading, position mismarking, concealment","sourceItemType":"risk","targetItemTitle":"Segregate conflicting duties and areas of responsibility","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized disclosure / breach of sensitive information","sourceItemType":"risk","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized disclosure / breach of sensitive information","sourceItemType":"risk","targetItemTitle":"Control data flows, leakage, and cross-border transfers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized disclosure / breach of sensitive information","sourceItemType":"risk","targetItemTitle":"De-identify, mask, or pseudonymize personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized disclosure / breach of sensitive information","sourceItemType":"risk","targetItemTitle":"Maintain and provide an accounting of disclosures","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized disclosure / breach of sensitive information","sourceItemType":"risk","targetItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized disclosure / breach of sensitive information","sourceItemType":"risk","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized disclosure / breach of sensitive information","sourceItemType":"risk","targetItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized disclosure / breach of sensitive information","sourceItemType":"risk","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized disclosure / breach of sensitive information","sourceItemType":"risk","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized or inaccurate payroll (Never Nude HR Platform)","sourceItemType":"risk","targetItemTitle":"Enforce a formal disciplinary process for violations","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized use of equipment and unauthorized access escalation","sourceItemType":"risk","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized use of equipment and unauthorized access escalation","sourceItemType":"risk","targetItemTitle":"Manage unique identities and identifiers end to end","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unauthorized use of equipment and unauthorized access escalation","sourceItemType":"risk","targetItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Uncontrolled copying to removable media / unmanaged software installs","sourceItemType":"risk","targetItemTitle":"Control storage media through use, storage, and destruction","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Uncontrolled copying to removable media / unmanaged software installs","sourceItemType":"risk","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Uncontrolled copying to removable media / unmanaged software installs","sourceItemType":"risk","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Uncontrolled copying to removable media / unmanaged software installs","sourceItemType":"risk","targetItemTitle":"Permit only authorized software installation and use","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Uncontrolled copying to removable media / unmanaged software installs","sourceItemType":"risk","targetItemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Understatement of liabilities/expenses (completeness)","sourceItemType":"risk","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Understatement of liabilities/expenses (completeness)","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Understatement of liabilities/expenses (completeness)","sourceItemType":"risk","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Understatement of liabilities/expenses (completeness)","sourceItemType":"risk","targetItemTitle":"Ensure quality of information used in reporting","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Understatement of liabilities/expenses (completeness)","sourceItemType":"risk","targetItemTitle":"Safeguard assets and stored financial data","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Understatement of liabilities/expenses (completeness)","sourceItemType":"risk","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Undetected anomalous export from Cloud SQL","sourceItemType":"risk","targetItemTitle":"Cloud SQL query & access audit logging","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unencrypted or unmasked PII in Cloud SQL is exfiltrated","sourceItemType":"risk","targetItemTitle":"Cloud SQL PII classification & field-level masking","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unencrypted or unmasked PII in Cloud SQL is exfiltrated","sourceItemType":"risk","targetItemTitle":"Cloud SQL backup, integrity & recovery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unencrypted or unmasked PII in Cloud SQL is exfiltrated","sourceItemType":"risk","targetItemTitle":"Cloud SQL encryption & Cloud KMS key management","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unhedged FX exposure on cross-border debt","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unlawful retention or premature deletion of records","sourceItemType":"risk","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unlawful retention or premature deletion of records","sourceItemType":"risk","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unlogged Model Home Data Lake activity prevents breach detection","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unmanaged third-party API token is leaked","sourceItemType":"risk","targetItemTitle":"Third-party data-sharing & API access control","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unreviewed change merged and deployed via Model Home Data Lake","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake audit logging of changes & approvals","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unreviewed change merged and deployed via Model Home Data Lake","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake branch protection & mandatory code review","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Unreviewed change merged and deployed via Model Home Data Lake","sourceItemType":"risk","targetItemTitle":"Model Home Data Lake repository & project access management","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"User error and mishandling of sensitive information","sourceItemType":"risk","targetItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"User error and mishandling of sensitive information","sourceItemType":"risk","targetItemTitle":"Control data flows, leakage, and cross-border transfers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"User error and mishandling of sensitive information","sourceItemType":"risk","targetItemTitle":"Deliver security awareness training to all personnel","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"User error and mishandling of sensitive information","sourceItemType":"risk","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Valuation error — PPA, goodwill/intangibles or 409A equity","sourceItemType":"risk","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Vulnerabilities introduced during software development","sourceItemType":"risk","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Vulnerabilities introduced during software development","sourceItemType":"risk","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Vulnerabilities introduced during software development","sourceItemType":"risk","targetItemTitle":"Oversee outsourced development and vet developers","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Vulnerabilities introduced during software development","sourceItemType":"risk","targetItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Vulnerabilities introduced during software development","sourceItemType":"risk","targetItemTitle":"Test software security during development and acceptance","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak account provisioning/de-registration and access review","sourceItemType":"risk","targetItemTitle":"Manage unique identities and identifiers end to end","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak account provisioning/de-registration and access review","sourceItemType":"risk","targetItemTitle":"Provision and deprovision accounts through a managed lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak account provisioning/de-registration and access review","sourceItemType":"risk","targetItemTitle":"Review user access rights periodically","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak authentication and password management","sourceItemType":"risk","targetItemTitle":"Authenticate all users with multi-factor authentication","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak authentication and password management","sourceItemType":"risk","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak internal control environment enabling fraud and error","sourceItemType":"risk","targetItemTitle":"Annual performance and conduct evaluation per personnel","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak internal control environment enabling fraud and error","sourceItemType":"risk","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak internal control environment enabling fraud and error","sourceItemType":"risk","targetItemTitle":"Select and tailor a risk-based control baseline","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak internal control environment enabling fraud and error","sourceItemType":"risk","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak or absent encryption and key management","sourceItemType":"risk","targetItemTitle":"Encrypt data at rest and in transit","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak or absent encryption and key management","sourceItemType":"risk","targetItemTitle":"Use approved algorithms and validated cryptographic modules","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak supplier security requirements and monitoring","sourceItemType":"risk","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak supplier security requirements and monitoring","sourceItemType":"risk","targetItemTitle":"Manage subservice organizations supporting the system","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Weak supplier security requirements and monitoring","sourceItemType":"risk","targetItemTitle":"Monitor vendor performance, services, and risk","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Workplace health, safety and well-being failures","sourceItemType":"risk","targetItemTitle":"Protect facilities against fire, water, and environmental hazards","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Workplace health, safety and well-being failures","sourceItemType":"risk","targetItemTitle":"Provide emergency power, lighting, and resilient utilities","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Zero-day exploitation","sourceItemType":"risk","targetItemTitle":"Block malware, spam, and phishing across all systems","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"Zero-day exploitation","sourceItemType":"risk","targetItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"control","kind":"related","metadata":{"role":"mitigates"}},{"sourceItemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"AI suggestions require human approval before production changes","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Annual performance and conduct evaluation per personnel","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Assess and mitigate fraud risk including management override","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Assess changes that could significantly affect risk and control","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Assess control effectiveness and authorize systems","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Authenticate all users with multi-factor authentication","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Authorize, test, and approve changes and development","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Authorize, test, and approve changes before production","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Availability & capacity management (SLA)","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Back up data and verify restorability","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Bind third parties handling personal data to privacy commitments","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Block malware, spam, and phishing across all systems","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Business continuity & disaster recovery plan testing","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Classify, prioritize, and label information and assets","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Cloud SQL PII classification & field-level masking","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Cloud SQL access control & least privilege","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Cloud SQL backup, integrity & recovery","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Cloud SQL data retention & secure disposal","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Cloud SQL encryption & Cloud KMS key management","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Cloud SQL query & access audit logging","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Communicate and report risk and control information","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Continuously monitor systems for anomalous activity","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Control automated processing and resolve exceptions","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Control data flows, leakage, and cross-border transfers","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Control interface transfers and output delivery","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Control mobile code and web content","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Control storage media through use, storage, and destruction","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Coordinate independent assurance reviews across providers","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Customer data is not used for AI model training; Vertex AI data governance in force","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Customers notified of critical system changes affecting their processing","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Data subject rights & consent handling (PII)","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"De-identify, mask, or pseudonymize personal data","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Define and approve security requirements for applications","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Define objectives and business context for risk assessment","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Define security roles, responsibilities, and authorities","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Deliver security awareness training to all personnel","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Embed security and competence in HR practices","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Encrypt data at rest and in transit","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Enforce a formal disciplinary process for violations","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Enforce approved authorizations for information and functions","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Enforce secure coding and input validation standards","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Engineer systems with secure architecture and design","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Ensure board-level oversight of risk and internal control","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Ensure complete, accurate, and authorized data processing","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Ensure quality of information used in reporting","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Establish and maintain approved security policies and procedures","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Evaluate events and declare incidents against defined criteria","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Execute, monitor, and recover production processing","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"External-facing system description maintained and accurate","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Follow a secure development lifecycle with approval gates","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Formalize security responsibilities in employment terms","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Govern security of external and cloud service use","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Harden systems to approved secure configuration baselines","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Hold individuals accountable for control responsibilities","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Hold third-party personnel to equivalent security terms","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Identify and manage legal, regulatory, and contractual obligations","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Incident management & customer notification","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Incident reporting channels documented and communicated","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Integrate risk management into enterprise processes and projects","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Investigate incidents and preserve evidence and records","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Keep personal data accurate and honor correction requests","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Learn from incidents and communicate corrective actions","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Limit personal-data use to stated purposes and minimum necessary","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Log and monitor system activity, capacity, and incidents","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Log security-relevant events across all systems","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Lucille Identity Cloud SSO & MFA enforcement","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Lucille Identity Cloud authentication & admin-event logging","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Lucille Identity Cloud password & authentication policy","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Lucille Identity Cloud periodic access & group review","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"MCP tool surface documented and self-describing via get_schema","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Maintain a complete inventory of systems, hardware, and software","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Maintain an approved incident response plan","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Maintain and provide an accounting of disclosures","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Maintain business continuity and contingency planning policy","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Maintain business continuity and disaster recovery plans","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Maintain contacts with authorities and special interest groups","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Maintain equipment to preserve availability and integrity","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Maintain quality records and information for internal control","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Manage and protect authenticators across their lifecycle","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Manage assets through their life cycle and recover them at exit","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Manage capacity to meet availability requirements","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Manage compliance with external legal and regulatory requirements","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Manage subservice organizations supporting the system","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Manage unique identities and identifiers end to end","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake IAM least-privilege & owner protection","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake Secret Manager secrets management","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake account & project baseline hardening","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake audit logging of changes & approvals","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake backup & disaster recovery","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake branch protection & mandatory code review","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake encryption at rest & in transit","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake network segmentation & firewall control","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Model Home Data Lake repository & project access management","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Monitor and review risk management performance","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Monitor physical access and retain visitor and entry records","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Monitor vendor performance, services, and risk","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Obtain and honor consent for collection, use, and disclosure","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Operate a third-party security risk management program","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Operate threat intelligence and threat hunting","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Oversee outsourced development and vet developers","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Per-tenant database isolation prevents cross-tenant data access","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Perform periodic enterprise risk assessments","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Perform risk-based due diligence before engaging vendors","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Permit only authorized software installation and use","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Prevent information exposure at desks, screens, and outputs","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Process personal data only under a documented lawful basis","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Protect facilities against fire, water, and environmental hazards","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Protect power and communications cabling from damage and taps","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Protect production systems during audit testing","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Provide channels to report events and obtain response help","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Provide data subjects access to their personal data","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Provide emergency power, lighting, and resilient utilities","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Provide privacy notices and transparency to data subjects","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Provide redundant and alternate processing, storage, and telecom","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Provision and deprovision accounts through a managed lifecycle","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Record and notify unauthorized disclosures of personal data","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Record complete audit content with synchronized clocks","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Recover from incidents using defined initiation criteria","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Remediate identified flaws within defined timeframes","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Resolve privacy inquiries, complaints, and disputes","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Respond to, contain, and eradicate declared incidents","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Restrict physical access and maintain environmental safeguards","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Restrict physical access to facilities and secure areas","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Restrict privileged rights, utilities, and unauthorized software","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Retain personal and confidential data per schedule, then destroy it","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Review user access rights periodically","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Safeguard assets and stored financial data","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Safeguard personal information with reasonable security","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Screen personnel commensurate with position risk","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Secure and monitor networks and network services","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Secure remote working arrangements","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Secure termination and transfer of personnel","sourceItemType":"control","targetItemTitle":"Never Nude HR Platform","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Segment networks and defend the external boundary","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Segregate conflicting duties and areas of responsibility","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Select and tailor a risk-based control baseline","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Separate environments and protect production data in testing","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Site facilities and equipment to minimize hazards and exposure","sourceItemType":"control","targetItemTitle":"Stair Car Facilities System","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Sudden Valley Network registrar account security & DNS change control","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Test recovery capabilities and train contingency personnel","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Test software security during development and acceptance","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Third-party data-sharing & API access control","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Third-party risk assessment & SOC report review","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Third-party vendor risk assessment & monitoring","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Track deficiencies to closure with remediation action plans","sourceItemType":"control","targetItemTitle":"Model Home Data Lake","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Transfer information securely under defined rules and agreements","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Triage, categorize, and escalate reported security events","sourceItemType":"control","targetItemTitle":"GOB Security Monitoring","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Use approved algorithms and validated cryptographic modules","sourceItemType":"control","targetItemTitle":"Lucille Identity Cloud","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"User endpoint devices protected and managed (includes remote working security)","sourceItemType":"control","targetItemTitle":"Sudden Valley Network","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Validate completeness and accuracy of system inputs","sourceItemType":"control","targetItemTitle":"Banana ERP","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Vendor onboarding due diligence & risk tiering","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"Verify component authenticity, provenance, and integrity","sourceItemType":"control","targetItemTitle":"Tidewell File Exchange","targetItemType":"system","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemTitle":"AI Governance & Acceptable AI Use Policy","sourceItemType":"policy","targetItemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"AI Governance & Acceptable AI Use Policy","sourceItemType":"policy","targetItemTitle":"AI suggestions require human approval before production changes","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"AI Governance & Acceptable AI Use Policy","sourceItemType":"policy","targetItemTitle":"Customer data is not used for AI model training; Vertex AI data governance in force","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"AI Governance & Acceptable AI Use Policy","sourceItemType":"policy","targetItemTitle":"MCP tool surface documented and self-describing via get_schema","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Acceptable Use Policy","sourceItemType":"policy","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Acceptable Use Policy","sourceItemType":"policy","targetItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Cloud SQL access control & least privilege","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Lucille Identity Cloud periodic access & group review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Manage unique identities and identifiers end to end","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake IAM least-privilege & owner protection","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake Secret Manager secrets management","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake repository & project access management","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Provision and deprovision accounts through a managed lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Restrict privileged rights, utilities, and unauthorized software","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Review user access rights periodically","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Segregate conflicting duties and areas of responsibility","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Access Control Policy","sourceItemType":"policy","targetItemTitle":"Third-party data-sharing & API access control","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Asset & Media Management Policy","sourceItemType":"policy","targetItemTitle":"Control storage media through use, storage, and destruction","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Asset & Media Management Policy","sourceItemType":"policy","targetItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Asset & Media Management Policy","sourceItemType":"policy","targetItemTitle":"Maintain equipment to preserve availability and integrity","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Asset & Media Management Policy","sourceItemType":"policy","targetItemTitle":"Manage assets through their life cycle and recover them at exit","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Asset & Media Management Policy","sourceItemType":"policy","targetItemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Backup & Recovery Policy","sourceItemType":"policy","targetItemTitle":"Back up data and verify restorability","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Backup & Recovery Policy","sourceItemType":"policy","targetItemTitle":"Cloud SQL backup, integrity & recovery","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Backup & Recovery Policy","sourceItemType":"policy","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Backup & Recovery Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake backup & disaster recovery","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Backup & Recovery Policy","sourceItemType":"policy","targetItemTitle":"Safeguard assets and stored financial data","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Board & Governance Policy","sourceItemType":"policy","targetItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Board & Governance Policy","sourceItemType":"policy","targetItemTitle":"Define security roles, responsibilities, and authorities","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Board & Governance Policy","sourceItemType":"policy","targetItemTitle":"Ensure board-level oversight of risk and internal control","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Board & Governance Policy","sourceItemType":"policy","targetItemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Board & Governance Policy","sourceItemType":"policy","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity & Disaster Recovery Policy","sourceItemType":"policy","targetItemTitle":"Availability & capacity management (SLA)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity & Disaster Recovery Policy","sourceItemType":"policy","targetItemTitle":"Back up data and verify restorability","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity & Disaster Recovery Policy","sourceItemType":"policy","targetItemTitle":"Business continuity & disaster recovery plan testing","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity & Disaster Recovery Policy","sourceItemType":"policy","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity & Disaster Recovery Policy","sourceItemType":"policy","targetItemTitle":"Maintain business continuity and disaster recovery plans","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity & Disaster Recovery Policy","sourceItemType":"policy","targetItemTitle":"Manage capacity to meet availability requirements","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity & Disaster Recovery Policy","sourceItemType":"policy","targetItemTitle":"Provide redundant and alternate processing, storage, and telecom","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity & Disaster Recovery Policy","sourceItemType":"policy","targetItemTitle":"Recover from incidents using defined initiation criteria","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Business Continuity & Disaster Recovery Policy","sourceItemType":"policy","targetItemTitle":"Test recovery capabilities and train contingency personnel","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Change Management Policy","sourceItemType":"policy","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Change Management Policy","sourceItemType":"policy","targetItemTitle":"Authorize, test, and approve changes before production","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Change Management Policy","sourceItemType":"policy","targetItemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Change Management Policy","sourceItemType":"policy","targetItemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Change Management Policy","sourceItemType":"policy","targetItemTitle":"Customers notified of critical system changes affecting their processing","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Change Management Policy","sourceItemType":"policy","targetItemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Change Management Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake branch protection & mandatory code review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Change Management Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Change Management Policy","sourceItemType":"policy","targetItemTitle":"Sudden Valley Network registrar account security & DNS change control","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Cloud Services Security Policy","sourceItemType":"policy","targetItemTitle":"Govern security of external and cloud service use","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Code of Conduct","sourceItemType":"policy","targetItemTitle":"Annual performance and conduct evaluation per personnel","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Code of Conduct","sourceItemType":"policy","targetItemTitle":"Enforce a formal disciplinary process for violations","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Code of Conduct","sourceItemType":"policy","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Code of Conduct","sourceItemType":"policy","targetItemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Configuration Management Policy","sourceItemType":"policy","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Configuration Management Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake account & project baseline hardening","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Configuration Management Policy","sourceItemType":"policy","targetItemTitle":"Permit only authorized software installation and use","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Configuration Management Policy","sourceItemType":"policy","targetItemTitle":"Record complete audit content with synchronized clocks","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Data Classification & Handling Policy","sourceItemType":"policy","targetItemTitle":"Classify, prioritize, and label information and assets","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Data Classification & Handling Policy","sourceItemType":"policy","targetItemTitle":"Ensure quality of information used in reporting","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Data Masking Policy","sourceItemType":"policy","targetItemTitle":"Cloud SQL PII classification & field-level masking","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Data Masking Policy","sourceItemType":"policy","targetItemTitle":"De-identify, mask, or pseudonymize personal data","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Data Masking Policy","sourceItemType":"policy","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Data Retention & Disposal Policy","sourceItemType":"policy","targetItemTitle":"Cloud SQL data retention & secure disposal","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Data Retention & Disposal Policy","sourceItemType":"policy","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Encryption Policy","sourceItemType":"policy","targetItemTitle":"Cloud SQL encryption & Cloud KMS key management","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Encryption Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake encryption at rest & in transit","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Encryption Policy","sourceItemType":"policy","targetItemTitle":"Use approved algorithms and validated cryptographic modules","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Human Resources Security Policy","sourceItemType":"policy","targetItemTitle":"Annual performance and conduct evaluation per personnel","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Human Resources Security Policy","sourceItemType":"policy","targetItemTitle":"Deliver security awareness training to all personnel","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Human Resources Security Policy","sourceItemType":"policy","targetItemTitle":"Embed security and competence in HR practices","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Human Resources Security Policy","sourceItemType":"policy","targetItemTitle":"Enforce a formal disciplinary process for violations","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Human Resources Security Policy","sourceItemType":"policy","targetItemTitle":"Formalize security responsibilities in employment terms","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Human Resources Security Policy","sourceItemType":"policy","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Human Resources Security Policy","sourceItemType":"policy","targetItemTitle":"Screen personnel commensurate with position risk","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Human Resources Security Policy","sourceItemType":"policy","targetItemTitle":"Secure termination and transfer of personnel","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Evaluate events and declare incidents against defined criteria","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Incident management & customer notification","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Incident reporting channels documented and communicated","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Investigate incidents and preserve evidence and records","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Learn from incidents and communicate corrective actions","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Maintain an approved incident response plan","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Maintain contacts with authorities and special interest groups","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Provide channels to report events and obtain response help","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Incident Response Policy","sourceItemType":"policy","targetItemTitle":"Triage, categorize, and escalate reported security events","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Security Policy","sourceItemType":"policy","targetItemTitle":"Communicate and report risk and control information","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Security Policy","sourceItemType":"policy","targetItemTitle":"Establish and maintain approved security policies and procedures","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Security Policy","sourceItemType":"policy","targetItemTitle":"External-facing system description maintained and accurate","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Security Policy","sourceItemType":"policy","targetItemTitle":"Hold individuals accountable for control responsibilities","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Security Policy","sourceItemType":"policy","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Transfer & Leakage Prevention Policy","sourceItemType":"policy","targetItemTitle":"Control data flows, leakage, and cross-border transfers","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Transfer & Leakage Prevention Policy","sourceItemType":"policy","targetItemTitle":"Encrypt data at rest and in transit","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Transfer & Leakage Prevention Policy","sourceItemType":"policy","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Information Transfer & Leakage Prevention Policy","sourceItemType":"policy","targetItemTitle":"Transfer information securely under defined rules and agreements","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Internal Audit Program","sourceItemType":"policy","targetItemTitle":"Assess control effectiveness and authorize systems","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Internal Audit Program","sourceItemType":"policy","targetItemTitle":"Coordinate independent assurance reviews across providers","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Internal Audit Program","sourceItemType":"policy","targetItemTitle":"Protect production systems during audit testing","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Legal & Regulatory Compliance Policy","sourceItemType":"policy","targetItemTitle":"Identify and manage legal, regulatory, and contractual obligations","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Legal & Regulatory Compliance Policy","sourceItemType":"policy","targetItemTitle":"Maintain quality records and information for internal control","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Legal & Regulatory Compliance Policy","sourceItemType":"policy","targetItemTitle":"Manage compliance with external legal and regulatory requirements","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Cloud SQL query & access audit logging","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Execute, monitor, and recover production processing","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Log security-relevant events across all systems","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Lucille Identity Cloud authentication & admin-event logging","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake audit logging of changes & approvals","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Monitor and review risk management performance","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Logging & Monitoring Policy","sourceItemType":"policy","targetItemTitle":"Track deficiencies to closure with remediation action plans","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Network Security Policy","sourceItemType":"policy","targetItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Network Security Policy","sourceItemType":"policy","targetItemTitle":"Block malware, spam, and phishing across all systems","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Network Security Policy","sourceItemType":"policy","targetItemTitle":"Control mobile code and web content","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Network Security Policy","sourceItemType":"policy","targetItemTitle":"Model Home Data Lake network segmentation & firewall control","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Network Security Policy","sourceItemType":"policy","targetItemTitle":"Permit only authorized software installation and use","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Network Security Policy","sourceItemType":"policy","targetItemTitle":"Secure and monitor networks and network services","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Network Security Policy","sourceItemType":"policy","targetItemTitle":"Segment networks and defend the external boundary","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Password & Authentication Policy","sourceItemType":"policy","targetItemTitle":"Authenticate all users with multi-factor authentication","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Password & Authentication Policy","sourceItemType":"policy","targetItemTitle":"Lucille Identity Cloud SSO & MFA enforcement","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Password & Authentication Policy","sourceItemType":"policy","targetItemTitle":"Lucille Identity Cloud password & authentication policy","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Password & Authentication Policy","sourceItemType":"policy","targetItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Physical Security Policy","sourceItemType":"policy","targetItemTitle":"Monitor physical access and retain visitor and entry records","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Physical Security Policy","sourceItemType":"policy","targetItemTitle":"Protect facilities against fire, water, and environmental hazards","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Physical Security Policy","sourceItemType":"policy","targetItemTitle":"Protect power and communications cabling from damage and taps","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Physical Security Policy","sourceItemType":"policy","targetItemTitle":"Provide emergency power, lighting, and resilient utilities","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Physical Security Policy","sourceItemType":"policy","targetItemTitle":"Restrict physical access and maintain environmental safeguards","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Physical Security Policy","sourceItemType":"policy","targetItemTitle":"Restrict physical access to facilities and secure areas","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Physical Security Policy","sourceItemType":"policy","targetItemTitle":"Site facilities and equipment to minimize hazards and exposure","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Bind third parties handling personal data to privacy commitments","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Data subject rights & consent handling (PII)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Keep personal data accurate and honor correction requests","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Limit personal-data use to stated purposes and minimum necessary","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Maintain and provide an accounting of disclosures","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Obtain and honor consent for collection, use, and disclosure","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Process personal data only under a documented lawful basis","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Provide data subjects access to their personal data","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Provide privacy notices and transparency to data subjects","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Record and notify unauthorized disclosures of personal data","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Resolve privacy inquiries, complaints, and disputes","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Retain personal and confidential data per schedule, then destroy it","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Privacy Policy","sourceItemType":"policy","targetItemTitle":"Safeguard personal information with reasonable security","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Remote Working & Clear Desk Policy","sourceItemType":"policy","targetItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Remote Working & Clear Desk Policy","sourceItemType":"policy","targetItemTitle":"Govern acceptable use of endpoints, off-site, and external systems","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Remote Working & Clear Desk Policy","sourceItemType":"policy","targetItemTitle":"Prevent information exposure at desks, screens, and outputs","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Remote Working & Clear Desk Policy","sourceItemType":"policy","targetItemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Remote Working & Clear Desk Policy","sourceItemType":"policy","targetItemTitle":"Secure remote working arrangements","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Remote Working & Clear Desk Policy","sourceItemType":"policy","targetItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Risk Management Policy","sourceItemType":"policy","targetItemTitle":"Assess and mitigate fraud risk including management override","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Risk Management Policy","sourceItemType":"policy","targetItemTitle":"Assess changes that could significantly affect risk and control","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Risk Management Policy","sourceItemType":"policy","targetItemTitle":"Define objectives and business context for risk assessment","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Risk Management Policy","sourceItemType":"policy","targetItemTitle":"Maintain business continuity and contingency planning policy","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Risk Management Policy","sourceItemType":"policy","targetItemTitle":"Perform periodic enterprise risk assessments","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Risk Management Policy","sourceItemType":"policy","targetItemTitle":"Select and tailor a risk-based control baseline","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Secure Coding Policy","sourceItemType":"policy","targetItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Secure Coding Policy","sourceItemType":"policy","targetItemTitle":"Enforce secure coding and input validation standards","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Authorize, test, and approve changes and development","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Control automated processing and resolve exceptions","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Control interface transfers and output delivery","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Define and approve security requirements for applications","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Engineer systems with secure architecture and design","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Follow a secure development lifecycle with approval gates","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Integrate risk management into enterprise processes and projects","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Separate environments and protect production data in testing","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Test software security during development and acceptance","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Software Development Lifecycle Policy","sourceItemType":"policy","targetItemTitle":"Validate completeness and accuracy of system inputs","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Threat Intelligence Policy","sourceItemType":"policy","targetItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Threat Intelligence Policy","sourceItemType":"policy","targetItemTitle":"Maintain contacts with authorities and special interest groups","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Threat Intelligence Policy","sourceItemType":"policy","targetItemTitle":"Operate threat intelligence and threat hunting","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Hold third-party personnel to equivalent security terms","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Manage subservice organizations supporting the system","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Monitor vendor performance, services, and risk","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Operate a third-party security risk management program","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Oversee outsourced development and vet developers","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Perform risk-based due diligence before engaging vendors","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Third-party risk assessment & SOC report review","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Third-party vendor risk assessment & monitoring","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Vendor onboarding due diligence & risk tiering","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vendor Management Policy","sourceItemType":"policy","targetItemTitle":"Verify component authenticity, provenance, and integrity","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vulnerability & Patch Management Policy","sourceItemType":"policy","targetItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemTitle":"Vulnerability & Patch Management Policy","sourceItemType":"policy","targetItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"control","kind":"related","metadata":{"role":"governs"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","targetItemType":"policy","targetItemTitle":"AI Governance & Acceptable AI Use Policy","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","targetItemType":"control","targetItemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Access Control Standard","targetItemType":"policy","targetItemTitle":"Access Control Standard","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Access Control Standard","targetItemType":"control","targetItemTitle":"Emergency Access Review","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Board & Governance Policy","targetItemType":"policy","targetItemTitle":"Board & Governance Policy","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Board & Governance Policy","targetItemType":"control","targetItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Cloud Services Security Policy","targetItemType":"policy","targetItemTitle":"Cloud Services Security Policy","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Cloud Services Security Policy","targetItemType":"control","targetItemTitle":"Govern security of external and cloud service use","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Data Classification & Handling Policy","targetItemType":"policy","targetItemTitle":"Data Classification & Handling Policy","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Data Classification & Handling Policy","targetItemType":"control","targetItemTitle":"Classify, prioritize, and label information and assets","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Financial Close Procedure","targetItemType":"policy","targetItemTitle":"Financial Close Procedure","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Financial Close Procedure","targetItemType":"control","targetItemTitle":"Account Reconciliation Review","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Incident Response Policy","targetItemType":"policy","targetItemTitle":"Incident Response Policy","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Incident Response Policy","targetItemType":"control","targetItemTitle":"Evaluate events and declare incidents against defined criteria","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","targetItemType":"policy","targetItemTitle":"Information Transfer & Leakage Prevention Policy","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","targetItemType":"control","targetItemTitle":"Control data flows, leakage, and cross-border transfers","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Management Review Procedure","targetItemType":"policy","targetItemTitle":"Management Review Procedure","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Physical Security Policy","targetItemType":"policy","targetItemTitle":"Physical Security Policy","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Policy exception — Physical Security Policy","targetItemType":"control","targetItemTitle":"Monitor physical access and retain visitor and entry records","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Change approval waived for a revenue system release","targetItemType":"policy","targetItemTitle":"Risk Management Policy","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"issue","sourceItemTitle":"Privacy Waiver Expiring","targetItemType":"policy","targetItemTitle":"Threat Intelligence Policy","kind":"related","metadata":{"role":"raised-against"}},{"sourceItemType":"control","sourceItemTitle":"Privileged Access Approval","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Privileged Access Approval","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Joiner Mover Leaver Automation","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Production Change Approval","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Segregated Deployment Pipeline","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Segregated Deployment Pipeline","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Batch Processing Monitoring","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Backup Restoration Test","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Secure Development Gate","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Secure Development Gate","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"New Application Architecture Review","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"EUC Formula Validation","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Revenue Contract Review","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Revenue Contract Review","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Journal Entry Approval","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Account Reconciliation Review","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"SOC Report and CUEC Review","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"SOC Report and CUEC Review","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Security Incident Triage","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Privacy Request Verification","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Data Retention Enforcement","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Data Retention Enforcement","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Visitor Badge Reconciliation","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Board Risk Oversight","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Service Delivery Quality Review","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Service Delivery Quality Review","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Business Continuity Exercise","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Segregate conflicting duties and areas of responsibility","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Maintain a complete inventory of systems, hardware, and software","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Control storage media through use, storage, and destruction","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Provision and deprovision accounts through a managed lifecycle","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Review user access rights periodically","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Review user access rights periodically","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Enforce least privilege, need-to-know, and segregation of duties","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Restrict privileged rights, utilities, and unauthorized software","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Enforce approved authorizations for information and functions","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Manage unique identities and identifiers end to end","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Manage and protect authenticators across their lifecycle","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Authenticate all users with multi-factor authentication","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Authenticate all users with multi-factor authentication","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Authorize, test, and approve changes and development","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Execute, monitor, and recover production processing","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Log and monitor system activity, capacity, and incidents","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Restrict physical access and maintain environmental safeguards","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Ensure complete, accurate, and authorized data processing","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Manage subservice organizations supporting the system","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Manage subservice organizations supporting the system","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Encrypt data at rest and in transit","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Use approved algorithms and validated cryptographic modules","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Restrict physical access to facilities and secure areas","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Restrict physical access to facilities and secure areas","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Harden systems to approved secure configuration baselines","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Authorize, test, and approve changes before production","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Permit only authorized software installation and use","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Permit only authorized software installation and use","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Remediate identified flaws within defined timeframes","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Block malware, spam, and phishing across all systems","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Log security-relevant events across all systems","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Log security-relevant events across all systems","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Continuously monitor systems for anomalous activity","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Evaluate events and declare incidents against defined criteria","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Respond to, contain, and eradicate declared incidents","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Recover from incidents using defined initiation criteria","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Back up data and verify restorability","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Segment networks and defend the external boundary","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Segment networks and defend the external boundary","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake account & project baseline hardening","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake IAM least-privilege & owner protection","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake network segmentation & firewall control","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake network segmentation & firewall control","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake backup & disaster recovery","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake backup & disaster recovery","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Sudden Valley Network registrar account security & DNS change control","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Lucille Identity Cloud SSO & MFA enforcement","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Lucille Identity Cloud periodic access & group review","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Lucille Identity Cloud password & authentication policy","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Lucille Identity Cloud authentication & admin-event logging","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Lucille Identity Cloud authentication & admin-event logging","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake branch protection & mandatory code review","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake repository & project access management","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake repository & project access management","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake audit logging of changes & approvals","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Cloud SQL access control & least privilege","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Cloud SQL access control & least privilege","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Cloud SQL query & access audit logging","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Cloud SQL backup, integrity & recovery","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake Secret Manager secrets management","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Model Home Data Lake Secret Manager secrets management","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Third-party data-sharing & API access control","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"AI suggestions require human approval before production changes","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"AI suggestions require human approval before production changes","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Customer data is not used for AI model training; Vertex AI data governance in force","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Customer data is not used for AI model training; Vertex AI data governance in force","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"MCP tool surface documented and self-describing via get_schema","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Per-tenant database isolation prevents cross-tenant data access","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Annual performance and conduct evaluation per personnel","targetItemType":"fsli","targetItemTitle":"Cash Collections","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"External-facing system description maintained and accurate","targetItemType":"fsli","targetItemTitle":"Employee Equity Awards","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"External-facing system description maintained and accurate","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Customers notified of critical system changes affecting their processing","targetItemType":"fsli","targetItemTitle":"Current Period Earnings","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Incident reporting channels documented and communicated","targetItemType":"fsli","targetItemTitle":"Legal Contingencies","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"fsli","targetItemTitle":"Operating Cash Accounts","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","targetItemType":"fsli","targetItemTitle":"Customer Receivables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"User endpoint devices protected and managed (includes remote working security)","targetItemType":"fsli","targetItemTitle":"Construction in Progress","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"fsli","targetItemTitle":"Trade Payables","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Business continuity & disaster recovery plan testing","targetItemType":"fsli","targetItemTitle":"Subscription Revenue","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"control","sourceItemTitle":"Third-party risk assessment & SOC report review","targetItemType":"fsli","targetItemTitle":"Payroll Expense","kind":"related","metadata":{"role":"covers"}},{"sourceItemType":"model","sourceItemTitle":"Banana Stand Demand Forecast","targetItemType":"system","targetItemTitle":"Banana ERP","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Banana Stand Demand Forecast","targetItemType":"risk","targetItemTitle":"AI accountability gaps and organizational liability","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"model","sourceItemTitle":"Model Home Pricing Engine","targetItemType":"system","targetItemTitle":"Cornballer Revenue Engine","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Model Home Pricing Engine","targetItemType":"risk","targetItemTitle":"AI agent makes unauthorized production changes","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"model","sourceItemTitle":"Sudden Valley Reserve Model","targetItemType":"system","targetItemTitle":"GOB Security Monitoring","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Sudden Valley Reserve Model","targetItemType":"risk","targetItemTitle":"AI model governance gap","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"model","sourceItemTitle":"Frozen Banana Churn Classifier","targetItemType":"system","targetItemTitle":"Lucille Identity Cloud","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Frozen Banana Churn Classifier","targetItemType":"risk","targetItemTitle":"AI power concentration and erosion of societal trust","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"model","sourceItemTitle":"Construction Cost Estimator","targetItemType":"system","targetItemTitle":"Model Home Data Lake","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Construction Cost Estimator","targetItemType":"risk","targetItemTitle":"AI privacy leakage and re-identification","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"model","sourceItemTitle":"Claims Triage GenAI Assistant","targetItemType":"system","targetItemTitle":"Never Nude HR Platform","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Claims Triage GenAI Assistant","targetItemType":"risk","targetItemTitle":"AI safety failures causing physical or psychological harm","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"model","sourceItemTitle":"Cornballer Warranty Reserve","targetItemType":"system","targetItemTitle":"Seaward Payroll Service","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Cornballer Warranty Reserve","targetItemType":"risk","targetItemTitle":"AI supply-chain compromise and provider concentration","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"model","sourceItemTitle":"Staffing Optimizer","targetItemType":"system","targetItemTitle":"Stair Car Facilities System","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Staffing Optimizer","targetItemType":"risk","targetItemTitle":"Adversarial attacks, data poisoning and prompt injection","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"model","sourceItemTitle":"Balboa Towers Occupancy Model","targetItemType":"system","targetItemTitle":"Sudden Valley Network","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Balboa Towers Occupancy Model","targetItemType":"risk","targetItemTitle":"Aging hardware with no periodic replacement scheme","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"model","sourceItemTitle":"Tenant Credit Risk Scorecard","targetItemType":"system","targetItemTitle":"Tidewell File Exchange","kind":"related","metadata":{"role":"runs-on"}},{"sourceItemType":"model","sourceItemTitle":"Tenant Credit Risk Scorecard","targetItemType":"risk","targetItemTitle":"Business combination purchase accounting misstatement (ASC 805)","kind":"related","metadata":{"role":"model-risk"}},{"sourceItemType":"risk","sourceItemTitle":"Legacy system processing failure","targetItemType":"remediation","targetItemTitle":"Re-run and reconcile the failed vendor payment batches","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Unauthorized privileged access","targetItemType":"remediation","targetItemTitle":"Review all emergency access sessions since July","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Unauthorized privileged access","targetItemType":"remediation","targetItemTitle":"Test leaver access removal next quarter","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Revenue cut-off error","targetItemType":"remediation","targetItemTitle":"Monitor the penetration test and privacy waiver fixes","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Unauthorized privileged access","targetItemType":"remediation","targetItemTitle":"Require approval before privileged access is granted","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Strategic acquisition integration","targetItemType":"remediation","targetItemTitle":"Close the change approval waiver and log the exception","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Revenue cut-off error","targetItemType":"remediation","targetItemTitle":"Retain complaint records for the full regulatory period","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Unauthorized privileged access","targetItemType":"remediation","targetItemTitle":"Re-run the access recertification for Record to Report approvers","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Legacy system processing failure","targetItemType":"remediation","targetItemTitle":"Confirm the ticketing vendor supports log export","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Strategic acquisition integration","targetItemType":"remediation","targetItemTitle":"Enforce separate approval in the deployment pipeline","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Unauthorized privileged access","targetItemType":"remediation","targetItemTitle":"Move the HR leaver feed to a daily run","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Legacy system processing failure","targetItemType":"remediation","targetItemTitle":"Route batch failure alerts to the on-call queue","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Legacy system processing failure","targetItemType":"remediation","targetItemTitle":"PBC Delivery 1 — Revenue Population","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"AI model governance gap","targetItemType":"remediation","targetItemTitle":"PBC Delivery 2 — Access Listing","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"AI model governance gap","targetItemType":"remediation","targetItemTitle":"PBC Delivery 3 — Change Samples","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Financial statement fraud","targetItemType":"remediation","targetItemTitle":"PBC Delivery 4 — Vendor Reports","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Financial statement fraud","targetItemType":"remediation","targetItemTitle":"PBC Delivery 5 — Legal Confirmations","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"risk","sourceItemTitle":"Revenue cut-off error","targetItemType":"remediation","targetItemTitle":"PBC Delivery 6 — Board Minutes","kind":"related","metadata":{"role":"treated-by"}},{"sourceItemType":"control","sourceItemTitle":"Joiner Mover Leaver Automation","targetItemType":"system","targetItemTitle":"Sitwell Payroll Bureau","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemType":"control","sourceItemTitle":"Batch Processing Monitoring","targetItemType":"system","targetItemTitle":"Magic Supply Wholesale","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemType":"control","sourceItemTitle":"Spreadsheet Inventory Review","targetItemType":"system","targetItemTitle":"Seaside Cloud Hosting","kind":"related","metadata":{"role":"operates-on"}},{"sourceItemType":"control","sourceItemTitle":"Account Reconciliation Review","targetItemType":"system","targetItemTitle":"Bluth Legal Retainer Services","kind":"related","metadata":{"role":"operates-on"}}],"itemTemplateLinks":[{"itemType":"audit","itemTitle":"Cybersecurity Program Audit","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"audit","itemTitle":"FY2026 SOX Annual Program","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"audit","itemTitle":"FY2026 SOX Annual Program","templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment"},{"itemType":"audit","itemTitle":"FY2026 SOX Annual Program","templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee"},{"itemType":"audit","itemTitle":"FY2026 SOX Annual Program","templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion"},{"itemType":"audit","itemTitle":"FY2026 SOX Annual Program","templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC"},{"itemType":"audit","itemTitle":"FY2026 SOX Annual Program","templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward"},{"itemType":"audit","itemTitle":"ISO 27001 Certification Readiness","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"audit","itemTitle":"ISO 27001 Certification Readiness","templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness"},{"itemType":"audit","itemTitle":"Identity and Access Management Audit","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"audit","itemTitle":"Identity and Access Management Audit","templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness"},{"itemType":"audit","itemTitle":"Identity and Access Management Audit","templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness"},{"itemType":"audit","itemTitle":"Identity and Access Management Audit","templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment"},{"itemType":"audit","itemTitle":"Identity and Access Management Audit","templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee"},{"itemType":"audit","itemTitle":"Identity and Access Management Audit","templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion"},{"itemType":"audit","itemTitle":"Identity and Access Management Audit","templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC"},{"itemType":"audit","itemTitle":"Identity and Access Management Audit","templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward"},{"itemType":"audit","itemTitle":"Incident Response Investigation","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting"},{"itemType":"audit","itemTitle":"Incident Response Investigation","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"audit","itemTitle":"Incident Response Investigation","templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness"},{"itemType":"audit","itemTitle":"Incident Response Investigation","templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness"},{"itemType":"audit","itemTitle":"Procure to Pay Audit","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting"},{"itemType":"audit","itemTitle":"Procure to Pay Audit","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"audit","itemTitle":"Procure to Pay Audit","templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment"},{"itemType":"audit","itemTitle":"Procure to Pay Audit","templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee"},{"itemType":"audit","itemTitle":"Procure to Pay Audit","templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion"},{"itemType":"audit","itemTitle":"Procure to Pay Audit","templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC"},{"itemType":"audit","itemTitle":"Procure to Pay Audit","templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward"},{"itemType":"audit","itemTitle":"Revenue Recognition Audit","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting"},{"itemType":"audit","itemTitle":"Revenue Recognition Audit","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"audit","itemTitle":"Revenue Recognition Audit","templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment"},{"itemType":"audit","itemTitle":"Revenue Recognition Audit","templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee"},{"itemType":"audit","itemTitle":"Revenue Recognition Audit","templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion"},{"itemType":"audit","itemTitle":"Revenue Recognition Audit","templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC"},{"itemType":"audit","itemTitle":"Revenue Recognition Audit","templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward"},{"itemType":"audit","itemTitle":"SOC 2 Security and Availability Readiness","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting"},{"itemType":"audit","itemTitle":"SOC 2 Security and Availability Readiness","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"audit","itemTitle":"SOC 2 Security and Availability Readiness","templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness"},{"itemType":"audit","itemTitle":"Vendor Risk Review","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"audit","itemTitle":"Vendor Risk Review","templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness"},{"itemType":"audit","itemTitle":"Vendor Risk Review","templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness"},{"itemType":"control","itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"AI suggestions require human approval before production changes","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"AI suggestions require human approval before production changes","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Account Reconciliation Review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Account Reconciliation Review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Annual performance and conduct evaluation per personnel","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Annual performance and conduct evaluation per personnel","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Assess and mitigate fraud risk including management override","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Assess and mitigate fraud risk including management override","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Assess changes that could significantly affect risk and control","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Assess changes that could significantly affect risk and control","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Assess control effectiveness and authorize systems","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Assess control effectiveness and authorize systems","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Authenticate all users with multi-factor authentication","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Authenticate all users with multi-factor authentication","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Authorize, test, and approve changes and development","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Authorize, test, and approve changes and development","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Authorize, test, and approve changes before production","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Authorize, test, and approve changes before production","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Availability & capacity management (SLA)","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Availability & capacity management (SLA)","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Back up data and verify restorability","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Back up data and verify restorability","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Backup Restoration Test","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Backup Restoration Test","templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation"},{"itemType":"control","itemTitle":"Backup Restoration Test","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Batch Processing Monitoring","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Batch Processing Monitoring","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Bind third parties handling personal data to privacy commitments","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Bind third parties handling personal data to privacy commitments","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Block malware, spam, and phishing across all systems","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Block malware, spam, and phishing across all systems","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Board Risk Oversight","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Board Risk Oversight","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Business Continuity Exercise","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Business Continuity Exercise","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Business continuity & disaster recovery plan testing","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Business continuity & disaster recovery plan testing","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"CEO role description with documented conflicts, recusals, and no-override commitments","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"CI/CD pipeline access & deployment approval (Model Home Data Lake CI, Cloud Build, Terraform)","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"CI/CD secrets & credential protection (Model Home Data Lake CI, Cloud Build)","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Change Migration Reconciliation","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Change Migration Reconciliation","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Classify, prioritize, and label information and assets","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Classify, prioritize, and label information and assets","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Cloud SQL PII classification & field-level masking","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Cloud SQL PII classification & field-level masking","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Cloud SQL access control & least privilege","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Cloud SQL access control & least privilege","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Cloud SQL backup, integrity & recovery","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Cloud SQL backup, integrity & recovery","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Cloud SQL data retention & secure disposal","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Cloud SQL data retention & secure disposal","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Cloud SQL encryption & Cloud KMS key management","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Cloud SQL encryption & Cloud KMS key management","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Cloud SQL query & access audit logging","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Cloud SQL query & access audit logging","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Cloud-native intrusion detection and alerting (Security Command Center + Cloud Audit Log alert policies)","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Communicate and report risk and control information","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Communicate and report risk and control information","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Continuously monitor systems for anomalous activity","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Continuously monitor systems for anomalous activity","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Control automated processing and resolve exceptions","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Control automated processing and resolve exceptions","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Control data flows, leakage, and cross-border transfers","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Control data flows, leakage, and cross-border transfers","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Control interface transfers and output delivery","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Control interface transfers and output delivery","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Control mobile code and web content","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Control mobile code and web content","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Control storage media through use, storage, and destruction","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Control storage media through use, storage, and destruction","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Coordinate independent assurance reviews across providers","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Coordinate independent assurance reviews across providers","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Critical subservice organization (firm) engaged with documented function-level scope and right-to-audit","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Customer data is not used for AI model training; Vertex AI data governance in force","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Customer data is not used for AI model training; Vertex AI data governance in force","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Customers notified of critical system changes affecting their processing","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Customers notified of critical system changes affecting their processing","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Data Retention Enforcement","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Data Retention Enforcement","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Data subject rights & consent handling (PII)","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Data subject rights & consent handling (PII)","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"De-identify, mask, or pseudonymize personal data","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"De-identify, mask, or pseudonymize personal data","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Define and approve security requirements for applications","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Define and approve security requirements for applications","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Define objectives and business context for risk assessment","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Define objectives and business context for risk assessment","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Define security roles, responsibilities, and authorities","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Define security roles, responsibilities, and authorities","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Deliver security awareness training to all personnel","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Deliver security awareness training to all personnel","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"EUC Formula Validation","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"EUC Formula Validation","templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing"},{"itemType":"control","itemTitle":"EUC Formula Validation","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Embed security and competence in HR practices","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Embed security and competence in HR practices","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Emergency Access Review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Emergency Access Review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Encrypt data at rest and in transit","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Encrypt data at rest and in transit","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Enforce a formal disciplinary process for violations","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Enforce a formal disciplinary process for violations","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Enforce approved authorizations for information and functions","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Enforce approved authorizations for information and functions","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Enforce least privilege, need-to-know, and segregation of duties","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Enforce least privilege, need-to-know, and segregation of duties","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Enforce secure coding and input validation standards","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Enforce secure coding and input validation standards","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Engineer systems with secure architecture and design","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Engineer systems with secure architecture and design","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Ensure board-level oversight of risk and internal control","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Ensure board-level oversight of risk and internal control","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Ensure complete, accurate, and authorized data processing","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Ensure complete, accurate, and authorized data processing","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Ensure quality of information used in reporting","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Ensure quality of information used in reporting","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Establish and maintain approved security policies and procedures","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Establish and maintain approved security policies and procedures","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Evaluate events and declare incidents against defined criteria","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Evaluate events and declare incidents against defined criteria","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Execute, monitor, and recover production processing","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Execute, monitor, and recover production processing","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"External-facing system description maintained and accurate","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"External-facing system description maintained and accurate","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Firm-internal segregation of duties attested annually (3-person minimum: Bookkeeping ≠ Internal Audit, with vCISO+Advisory bundled)","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Follow a secure development lifecycle with approval gates","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Follow a secure development lifecycle with approval gates","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Formalize security responsibilities in employment terms","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Formalize security responsibilities in employment terms","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Govern acceptable use of endpoints, off-site, and external systems","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Govern acceptable use of endpoints, off-site, and external systems","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Govern security of external and cloud service use","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Govern security of external and cloud service use","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Harden systems to approved secure configuration baselines","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Harden systems to approved secure configuration baselines","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Hold individuals accountable for control responsibilities","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Hold individuals accountable for control responsibilities","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Hold third-party personnel to equivalent security terms","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Hold third-party personnel to equivalent security terms","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Identify and manage legal, regulatory, and contractual obligations","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Identify and manage legal, regulatory, and contractual obligations","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Immutable Cloud Audit Logs sink for management-override compensation","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Incident management & customer notification","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Incident management & customer notification","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Incident reporting channels documented and communicated","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Incident reporting channels documented and communicated","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Independent governance advisor engaged with quarterly oversight cadence and signed quarterly attestations","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Integrate risk management into enterprise processes and projects","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Integrate risk management into enterprise processes and projects","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Investigate incidents and preserve evidence and records","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Investigate incidents and preserve evidence and records","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Job Failure Escalation","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Job Failure Escalation","templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing"},{"itemType":"control","itemTitle":"Job Failure Escalation","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Joiner Mover Leaver Automation","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Joiner Mover Leaver Automation","templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing"},{"itemType":"control","itemTitle":"Joiner Mover Leaver Automation","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Journal Entry Approval","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Journal Entry Approval","templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation"},{"itemType":"control","itemTitle":"Journal Entry Approval","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Journal Entry Approval","templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing"},{"itemType":"control","itemTitle":"Keep personal data accurate and honor correction requests","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Keep personal data accurate and honor correction requests","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Learn from incidents and communicate corrective actions","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Learn from incidents and communicate corrective actions","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Limit personal-data use to stated purposes and minimum necessary","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Limit personal-data use to stated purposes and minimum necessary","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Log and monitor system activity, capacity, and incidents","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Log and monitor system activity, capacity, and incidents","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Log security-relevant events across all systems","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Log security-relevant events across all systems","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Lucille Identity Cloud SSO & MFA enforcement","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Lucille Identity Cloud SSO & MFA enforcement","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Lucille Identity Cloud authentication & admin-event logging","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Lucille Identity Cloud authentication & admin-event logging","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Lucille Identity Cloud joiner-mover-leaver provisioning","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Lucille Identity Cloud password & authentication policy","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Lucille Identity Cloud password & authentication policy","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Lucille Identity Cloud periodic access & group review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Lucille Identity Cloud periodic access & group review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"MCP tool surface documented and self-describing via get_schema","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"MCP tool surface documented and self-describing via get_schema","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Maintain a complete inventory of systems, hardware, and software","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Maintain a complete inventory of systems, hardware, and software","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Maintain an approved incident response plan","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Maintain an approved incident response plan","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Maintain and provide an accounting of disclosures","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Maintain and provide an accounting of disclosures","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Maintain business continuity and contingency planning policy","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Maintain business continuity and contingency planning policy","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Maintain business continuity and disaster recovery plans","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Maintain business continuity and disaster recovery plans","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Maintain contacts with authorities and special interest groups","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Maintain contacts with authorities and special interest groups","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Maintain equipment to preserve availability and integrity","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Maintain equipment to preserve availability and integrity","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Maintain quality records and information for internal control","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Maintain quality records and information for internal control","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Manage and protect authenticators across their lifecycle","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Manage and protect authenticators across their lifecycle","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Manage assets through their life cycle and recover them at exit","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Manage assets through their life cycle and recover them at exit","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Manage capacity to meet availability requirements","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Manage capacity to meet availability requirements","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Manage compliance with external legal and regulatory requirements","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Manage compliance with external legal and regulatory requirements","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Manage subservice organizations supporting the system","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Manage subservice organizations supporting the system","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Manage unique identities and identifiers end to end","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Manage unique identities and identifiers end to end","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Migrate-on-startup ties code and schema into single deployable artifact","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake IAM least-privilege & owner protection","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake IAM least-privilege & owner protection","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake Secret Manager secrets management","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake Secret Manager secrets management","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake account & project baseline hardening","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake account & project baseline hardening","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake audit logging & monitoring (Cloud Audit Logs)","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake audit logging of changes & approvals","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake audit logging of changes & approvals","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake backup & disaster recovery","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake backup & disaster recovery","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake branch protection & mandatory code review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake branch protection & mandatory code review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake encryption at rest & in transit","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake encryption at rest & in transit","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake infrastructure change management (Terraform IaC review)","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake network segmentation & firewall control","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake network segmentation & firewall control","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Model Home Data Lake repository & project access management","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Model Home Data Lake repository & project access management","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Monitor and review risk management performance","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Monitor and review risk management performance","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Monitor physical access and retain visitor and entry records","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Monitor physical access and retain visitor and entry records","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Monitor vendor performance, services, and risk","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Monitor vendor performance, services, and risk","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"New Application Architecture Review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"New Application Architecture Review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Obtain and honor consent for collection, use, and disclosure","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Obtain and honor consent for collection, use, and disclosure","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Operate a third-party security risk management program","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Operate a third-party security risk management program","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Operate threat intelligence and threat hunting","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Operate threat intelligence and threat hunting","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Oversee outsourced development and vet developers","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Oversee outsourced development and vet developers","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Per-tenant database isolation prevents cross-tenant data access","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Per-tenant database isolation prevents cross-tenant data access","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Perform periodic enterprise risk assessments","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Perform periodic enterprise risk assessments","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Perform risk-based due diligence before engaging vendors","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Perform risk-based due diligence before engaging vendors","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Permit only authorized software installation and use","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Permit only authorized software installation and use","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Physical Site Access Review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Physical Site Access Review","templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure"},{"itemType":"control","itemTitle":"Physical Site Access Review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Policy Exception Approval","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Policy Exception Approval","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Prevent information exposure at desks, screens, and outputs","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Prevent information exposure at desks, screens, and outputs","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Privacy Request Verification","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Privacy Request Verification","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Privileged Access Approval","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Privileged Access Approval","templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing"},{"itemType":"control","itemTitle":"Privileged Access Approval","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Privileged Access Approval","templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing"},{"itemType":"control","itemTitle":"Process personal data only under a documented lawful basis","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Process personal data only under a documented lawful basis","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Production Change Approval","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Production Change Approval","templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation"},{"itemType":"control","itemTitle":"Production Change Approval","templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing"},{"itemType":"control","itemTitle":"Production Change Approval","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Production Change Approval","templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing"},{"itemType":"control","itemTitle":"Protect facilities against fire, water, and environmental hazards","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Protect facilities against fire, water, and environmental hazards","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Protect power and communications cabling from damage and taps","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Protect power and communications cabling from damage and taps","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Protect production systems during audit testing","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Protect production systems during audit testing","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Provide channels to report events and obtain response help","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Provide channels to report events and obtain response help","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Provide data subjects access to their personal data","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Provide data subjects access to their personal data","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Provide emergency power, lighting, and resilient utilities","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Provide emergency power, lighting, and resilient utilities","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Provide privacy notices and transparency to data subjects","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Provide privacy notices and transparency to data subjects","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Provide redundant and alternate processing, storage, and telecom","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Provide redundant and alternate processing, storage, and telecom","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Provision and deprovision accounts through a managed lifecycle","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Provision and deprovision accounts through a managed lifecycle","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Quarterly Access Recertification","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Quarterly Access Recertification","templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing"},{"itemType":"control","itemTitle":"Quarterly Access Recertification","templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure"},{"itemType":"control","itemTitle":"Quarterly Access Recertification","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Record and notify unauthorized disclosures of personal data","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Record and notify unauthorized disclosures of personal data","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Record complete audit content with synchronized clocks","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Record complete audit content with synchronized clocks","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Recover from incidents using defined initiation criteria","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Recover from incidents using defined initiation criteria","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Remediate identified flaws within defined timeframes","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Remediate identified flaws within defined timeframes","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Removable media prohibited for company and customer data; approved exceptions encrypted and tracked","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Resolve privacy inquiries, complaints, and disputes","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Resolve privacy inquiries, complaints, and disputes","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Respond to, contain, and eradicate declared incidents","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Respond to, contain, and eradicate declared incidents","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Restrict physical access and maintain environmental safeguards","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Restrict physical access and maintain environmental safeguards","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Restrict physical access to facilities and secure areas","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Restrict physical access to facilities and secure areas","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Restrict privileged rights, utilities, and unauthorized software","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Restrict privileged rights, utilities, and unauthorized software","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Retain personal and confidential data per schedule, then destroy it","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Retain personal and confidential data per schedule, then destroy it","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Revenue Contract Review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Revenue Contract Review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Revenue Contract Review","templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing"},{"itemType":"control","itemTitle":"Revenue Interface Reconciliation","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Revenue Interface Reconciliation","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Review user access rights periodically","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Review user access rights periodically","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"SOC Report and CUEC Review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"SOC Report and CUEC Review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Safeguard assets and stored financial data","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Safeguard assets and stored financial data","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Safeguard personal information with reasonable security","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Safeguard personal information with reasonable security","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Screen personnel commensurate with position risk","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Screen personnel commensurate with position risk","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Secure Development Gate","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Secure Development Gate","templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing"},{"itemType":"control","itemTitle":"Secure Development Gate","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Secure and monitor networks and network services","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Secure and monitor networks and network services","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Secure remote working arrangements","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Secure remote working arrangements","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Secure termination and transfer of personnel","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Secure termination and transfer of personnel","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Security Incident Triage","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Security Incident Triage","templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation"},{"itemType":"control","itemTitle":"Security Incident Triage","templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure"},{"itemType":"control","itemTitle":"Security Incident Triage","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Segment networks and defend the external boundary","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Segment networks and defend the external boundary","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Segregate conflicting duties and areas of responsibility","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Segregate conflicting duties and areas of responsibility","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Segregated Deployment Pipeline","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Segregated Deployment Pipeline","templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing"},{"itemType":"control","itemTitle":"Segregated Deployment Pipeline","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Segregation of duties enforced for critical functions with documented compensating controls","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Select and tailor a risk-based control baseline","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Select and tailor a risk-based control baseline","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Separate environments and protect production data in testing","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Separate environments and protect production data in testing","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Service Delivery Quality Review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Service Delivery Quality Review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Set tone at the top: integrity, ethics, and risk-aware culture","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Site facilities and equipment to minimize hazards and exposure","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Site facilities and equipment to minimize hazards and exposure","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Spreadsheet Inventory Review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Spreadsheet Inventory Review","templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure"},{"itemType":"control","itemTitle":"Spreadsheet Inventory Review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Sudden Valley Network registrar account security & DNS change control","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Sudden Valley Network registrar account security & DNS change control","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Test recovery capabilities and train contingency personnel","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Test recovery capabilities and train contingency personnel","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Test software security during development and acceptance","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Test software security during development and acceptance","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Third-party data-sharing & API access control","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Third-party data-sharing & API access control","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Third-party risk assessment & SOC report review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Third-party risk assessment & SOC report review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Third-party vendor risk assessment & monitoring","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Third-party vendor risk assessment & monitoring","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Track deficiencies to closure with remediation action plans","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Track deficiencies to closure with remediation action plans","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Transfer information securely under defined rules and agreements","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Transfer information securely under defined rules and agreements","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Triage, categorize, and escalate reported security events","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Triage, categorize, and escalate reported security events","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Use approved algorithms and validated cryptographic modules","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Use approved algorithms and validated cryptographic modules","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"User endpoint devices protected and managed (includes remote working security)","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"User endpoint devices protected and managed (includes remote working security)","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Validate completeness and accuracy of system inputs","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Validate completeness and accuracy of system inputs","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Vendor Due Diligence","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Vendor Due Diligence","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Vendor onboarding due diligence & risk tiering","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Vendor onboarding due diligence & risk tiering","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Verify component authenticity, provenance, and integrity","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Verify component authenticity, provenance, and integrity","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Visitor Badge Reconciliation","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Visitor Badge Reconciliation","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"control","itemTitle":"Vulnerability Remediation Review","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"control","itemTitle":"Vulnerability Remediation Review","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"fsli","itemTitle":"Accounts Payable","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Accounts Receivable","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Cash Collections","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Cash and Cash Equivalents","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Commitments and Contingencies","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Common Stock and APIC","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Construction in Progress","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Current Period Earnings","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Customer Receivables","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Employee Equity Awards","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Legal Contingencies","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Net Cash from Operations","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Operating Cash Accounts","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Operating Expenses","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Payroll Expense","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Property and Equipment","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Retained Earnings","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Revenue","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Subscription Revenue","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"fsli","itemTitle":"Trade Payables","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"issue","itemTitle":"Quarterly access recertification missed two finance approvers","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Privileged access granted before approval during the close","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Leaver accounts in Banana ERP disabled late","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Emergency access sessions not reviewed","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Change approval waived for a revenue system release","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Developers can deploy their own changes to production","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Payroll backup restore test ran a month late","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Opportunity to automate change migration reconciliation","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Failed vendor payment batches went unnoticed","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"PBC Request 1 — Revenue Population","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"PBC Request 2 — Access Listing","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"PBC Request 3 — Change Samples","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"PBC Request 4 — Vendor Reports","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"PBC Request 5 — Legal Confirmations","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"PBC Request 6 — Board Minutes","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Penetration Test Vulnerability","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Privacy Waiver Expiring","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Regulatory Examination Observation","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"personnel","itemTitle":"Buster Bluth","templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation"},{"itemType":"personnel","itemTitle":"Dexter Holloway","templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation"},{"itemType":"personnel","itemTitle":"George Michael Bluth","templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification"},{"itemType":"personnel","itemTitle":"Gob Bluth","templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation"},{"itemType":"personnel","itemTitle":"Kitty Sanchez","templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning"},{"itemType":"personnel","itemTitle":"Lindsay Fünke","templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification"},{"itemType":"personnel","itemTitle":"Maeby Fünke","templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification"},{"itemType":"personnel","itemTitle":"Marta Estrella","templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning"},{"itemType":"personnel","itemTitle":"Oscar Bluth","templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning"},{"itemType":"personnel","itemTitle":"Steve Holt","templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning"},{"itemType":"personnel","itemTitle":"Tobias Fünke","templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation"},{"itemType":"personnel","itemTitle":"Tony Wonder","templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification"},{"itemType":"policy","itemTitle":"AI Governance & Acceptable AI Use Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Acceptable Use Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Access Control Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Access Control Standard","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Access Control Standard","templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change"},{"itemType":"policy","itemTitle":"Asset & Media Management Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Audit Committee Charter","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Backup & Recovery Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Board & Governance Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Business Continuity & Disaster Recovery Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Business Continuity Standard","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Change Management Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Cloud Services Security Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Code of Conduct","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Configuration Management Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Continual Improvement Process","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Data Classification & Handling Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Data Masking Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Data Retention & Disposal Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Encryption Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Financial Close Procedure","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Financial Close Procedure","templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change"},{"itemType":"policy","itemTitle":"Human Resources Security Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"ISMS Scope Document","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Incident Response Plan","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Incident Response Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Information Security Objectives","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Information Security Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Information Security Policy","templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change"},{"itemType":"policy","itemTitle":"Information Transfer & Leakage Prevention Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Internal Audit Program","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Legal & Regulatory Compliance Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Logging & Monitoring Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Management Review Procedure","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Network Security Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Nonconformity & Corrective Action Procedure","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Password & Authentication Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Physical Security Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Privacy Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Remote Working & Clear Desk Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Responsible AI Guideline","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Responsible AI Guideline","templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change"},{"itemType":"policy","itemTitle":"Risk Assessment Methodology","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Risk Management Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Risk Treatment Process","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Secure Coding Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Software Development Lifecycle Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Threat Intelligence Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Vendor Management Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Vendor Risk Management Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"policy","itemTitle":"Vulnerability & Patch Management Policy","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"process","itemTitle":"AI Governance & Human Approval","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Access, Identity & Cryptography","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Asset, Media & Classification","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Backup, Recovery, BC/DR & Capacity","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Change Management","templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration"},{"itemType":"process","itemTitle":"Change Management","templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure"},{"itemType":"process","itemTitle":"Change Management","templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration"},{"itemType":"process","itemTitle":"Change Management","templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change"},{"itemType":"process","itemTitle":"Change Management","templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)"},{"itemType":"process","itemTitle":"Change Management","templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change"},{"itemType":"process","itemTitle":"Change Management","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Change, Release & Database Migration","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Compliance Obligations, Evidence & External Assurance","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Continuous Control Operation & Evidence Monitoring","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Credit and Collections","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Cryptography, Key & Secrets Management","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Data Protection & Privacy","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Enterprise Risk Assessment, Treatment & SoA","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Financial Close and Consolidation","templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing"},{"itemType":"process","itemTitle":"Financial Close and Consolidation","templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation"},{"itemType":"process","itemTitle":"Financial Close and Consolidation","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Financial Close and Consolidation","templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment"},{"itemType":"process","itemTitle":"Financial Close and Consolidation","templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward"},{"itemType":"process","itemTitle":"Financial Reporting Area","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Governance and Assurance Area","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Governance, Risk & Compliance","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"ISMS Governance, Scope & Objectives","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"IT Operations","templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing"},{"itemType":"process","itemTitle":"IT Operations","templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring"},{"itemType":"process","itemTitle":"IT Operations","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Identity, Authentication & Access Lifecycle","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Incident and Privacy Response","templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management"},{"itemType":"process","itemTitle":"Incident and Privacy Response","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"process","itemTitle":"Incident and Privacy Response","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Internal Audit Delivery","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting"},{"itemType":"process","itemTitle":"Internal Audit Delivery","templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping"},{"itemType":"process","itemTitle":"Internal Audit Delivery","templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation"},{"itemType":"process","itemTitle":"Internal Audit Delivery","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Logging, Monitoring, Detection & Threat Intelligence","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Network, Cloud Configuration & Physical Reliance","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"On-Prem Appliance & Release Lifecycle","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Order to Cash","templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough"},{"itemType":"process","itemTitle":"Order to Cash","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Payroll Administration","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"People & Workforce Security","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"People and Payroll Area","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Policy Lifecycle, Publication, Acknowledgment & Exceptions","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Privacy, Data Lifecycle & Secure Transfer","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Procure to Pay","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Procure to Pay Area","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Production Operations & SOC 1 Processing Integrity","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Record to Report","templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment"},{"itemType":"process","itemTitle":"Record to Report","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment"},{"itemType":"process","itemTitle":"Record to Report","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Record to Report","templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment"},{"itemType":"process","itemTitle":"Revenue Recognition","templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing"},{"itemType":"process","itemTitle":"Revenue Recognition","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Revenue Recognition","templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment"},{"itemType":"process","itemTitle":"Revenue and Receivables Area","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","templateName":"Emerging Risk & Horizon Scan"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","templateName":"ERM Risk Identification & Register Refresh"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","templateName":"Risk Appetite & Tolerance Calibration"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"process","itemTitle":"Risk and Compliance Management","templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness"},{"itemType":"process","itemTitle":"SOX Program Management","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"SOX Program Management","templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment"},{"itemType":"process","itemTitle":"SOX Program Management","templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing"},{"itemType":"process","itemTitle":"SOX Program Management","templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee"},{"itemType":"process","itemTitle":"SOX Program Management","templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion"},{"itemType":"process","itemTitle":"SOX Program Management","templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC"},{"itemType":"process","itemTitle":"SOX Program Management","templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment"},{"itemType":"process","itemTitle":"Secure Development, Change & Infrastructure","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Secure SDLC & Application Security","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Security Awareness & Role Training","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Security Incident, Privacy Breach & Postmortem","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Security Operations & Resilience","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Security and Privacy Area","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Service Delivery & Third-Party","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Technology Area","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Tenant Provisioning, Isolation & Teardown","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"User Access Management","templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation"},{"itemType":"process","itemTitle":"User Access Management","templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning"},{"itemType":"process","itemTitle":"User Access Management","templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review"},{"itemType":"process","itemTitle":"User Access Management","templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review"},{"itemType":"process","itemTitle":"User Access Management","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"User Access Management","templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification"},{"itemType":"process","itemTitle":"Vendor Lifecycle Management","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Vendor Lifecycle Management","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review"},{"itemType":"process","itemTitle":"Vendor Lifecycle Management","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"process","itemTitle":"Vendor, Subservice & CUEC Management","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Vulnerability, Patch & Technical Testing","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"process","itemTitle":"Workforce Security, Acceptable Use & Remote Work","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough"},{"itemType":"remediation","itemTitle":"Re-run and reconcile the failed vendor payment batches","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Review all emergency access sessions since July","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Test leaver access removal next quarter","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Monitor the penetration test and privacy waiver fixes","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Require approval before privileged access is granted","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Close the change approval waiver and log the exception","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Retain complaint records for the full regulatory period","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Re-run the access recertification for Record to Report approvers","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Confirm the ticketing vendor supports log export","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Enforce separate approval in the deployment pipeline","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Move the HR leaver feed to a daily run","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"Route batch failure alerts to the on-call queue","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"PBC Delivery 1 — Revenue Population","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"PBC Delivery 2 — Access Listing","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"PBC Delivery 3 — Change Samples","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"PBC Delivery 4 — Vendor Reports","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"PBC Delivery 5 — Legal Confirmations","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"remediation","itemTitle":"PBC Delivery 6 — Board Minutes","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.1 — Information-security policy governance","templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.1 — Information-security policy governance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.10 — Approved asset-use rules","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.11 — Asset recovery at exit","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.12 — Information sensitivity classification","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.13 — Classification marking practices","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.14 — Protected data exchange","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.15 — Logical and physical access governance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.16 — Identity lifecycle governance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.17 — Authenticator protection","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.18 — Access entitlement administration","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.19 — Supplier security governance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.2 — Security accountability assignments","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.20 — Contracted supplier safeguards","templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.20 — Contracted supplier safeguards","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.21 — Technology supply-chain assurance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.22 — Supplier service oversight","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.23 — Cloud service security governance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.24 — Incident response preparedness","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.25 — Security event triage","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.26 — Incident containment and response","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.27 — Post-incident improvement","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.28 — Forensic evidence handling","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.29 — Security controls during disruption","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.3 — Conflicting-duty separation","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.30 — Technology continuity readiness","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.31 — Compliance obligation register","templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.31 — Compliance obligation register","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.32 — Intellectual-property safeguards","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.33 — Records retention and integrity","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.34 — Personal-data privacy safeguards","templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.34 — Personal-data privacy safeguards","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.35 — Independent security assurance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.36 — Security-policy compliance checks","templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.36 — Security-policy compliance checks","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.37 — Controlled operating procedures","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.4 — Manager security obligations","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.5 — Regulatory authority coordination","templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.5 — Regulatory authority coordination","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.6 — Security community engagement","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.7 — Emerging threat insights","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.8 — Project security integration","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.5.9 — Information-asset register","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.6.1 — Personnel vetting","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.6.2 — Employment security terms","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.6.3 — Workforce security learning","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.6.4 — Security conduct enforcement","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.6.5 — Exit and role-change obligations","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.6.6 — Confidentiality commitments","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.6.7 — Secure remote-work practices","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.6.8 — Workforce event escalation","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.1 — Protected facility boundaries","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.10 — Removable and stored media protection","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.11 — Resilient facility utilities","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.12 — Protected power and data cabling","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.13 — Secure equipment servicing","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.14 — Equipment sanitization and disposal","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.2 — Authorized facility access","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.3 — Secure workspaces and rooms","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.4 — Facility surveillance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.5 — Environmental and physical resilience","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.6 — Restricted-area working practices","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.7 — Unattended workspace hygiene","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.8 — Protected equipment placement","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.7.9 — Off-site asset protection","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.1 — Endpoint security baseline","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.10 — Verified data disposal","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.11 — Sensitive-data obfuscation","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.12 — Data exfiltration safeguards","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.13 — Resilient backups","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.14 — Processing-service redundancy","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.15 — Security event logging","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.16 — Security telemetry monitoring","templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.16 — Security telemetry monitoring","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.17 — Trusted time sources","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.18 — Privileged utility restrictions","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.19 — Production software authorization","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.2 — Administrative privilege governance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.20 — Network protection architecture","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.21 — Network service assurance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.22 — Network zone isolation","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.23 — Harmful web-content controls","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.24 — Cryptographic protection","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.25 — Secure product delivery lifecycle","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.26 — Application protection specifications","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.27 — Secure-by-design architecture","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.28 — Defensive coding practices","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.29 — Pre-release security validation","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.3 — Need-to-know data access","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.30 — Third-party development assurance","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.31 — Environment separation","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.32 — Controlled technology changes","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.33 — Protected test datasets","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.34 — Audit-test safeguards","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.4 — Source repository access","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.5 — Strong user authentication","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.6 — Resource capacity planning","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.7 — Malware defense","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.8 — Vulnerability remediation program","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"ISO 27001 A.8.9 — Secure configuration baselines","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 A1.1 — Capacity monitoring","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 A1.2 — Environmental and resilience safeguards","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 A1.3 — Recovery testing","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC1.1 — Integrity and ethical values","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC1.2 — Board independence and oversight","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC1.3 — Organizational authority and accountability","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC1.4 — Competence and retention","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC1.5 — Internal-control accountability","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC2.1 — Quality information","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC2.2 — Internal communication","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC2.3 — External communication","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC3.1 — Clear objectives","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC3.2 — Enterprise risk identification and analysis","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC3.3 — Fraud-risk assessment","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC3.4 — Change-risk assessment","templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment"},{"itemType":"requirement","itemTitle":"SOC 2 CC3.4 — Change-risk assessment","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC4.1 — Ongoing and separate evaluations","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC4.2 — Deficiency communication","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC5.1 — Risk-mitigating control activities","templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption"},{"itemType":"requirement","itemTitle":"SOC 2 CC5.1 — Risk-mitigating control activities","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC5.2 — Technology general controls","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC5.3 — Policy-driven procedures","templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption"},{"itemType":"requirement","itemTitle":"SOC 2 CC5.3 — Policy-driven procedures","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC6.1 — Logical access safeguards","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC6.2 — Credential issuance and removal","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC6.3 — Role-based access changes","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC6.4 — Physical access restrictions","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC6.5 — Secure asset disposal","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC6.6 — Boundary protection","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC6.7 — Secure information transmission","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC6.8 — Malicious software defenses","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC7.1 — Vulnerability and configuration monitoring","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC7.2 — Anomaly monitoring","templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation"},{"itemType":"requirement","itemTitle":"SOC 2 CC7.2 — Anomaly monitoring","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC7.3 — Security event evaluation","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC7.4 — Incident response","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC7.5 — Incident recovery","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC8.1 — Change management","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC9.1 — Business disruption risk","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"requirement","itemTitle":"SOC 2 CC9.2 — Vendor and business-partner risk","templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation"},{"itemType":"requirement","itemTitle":"SOC 2 CC9.2 — Vendor and business-partner risk","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping"},{"itemType":"risk","itemTitle":"AI accountability gaps and organizational liability","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"AI agent makes unauthorized production changes","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"AI model governance gap","templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","templateName":"Emerging Risk & Horizon Scan"},{"itemType":"risk","itemTitle":"AI model governance gap","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"AI power concentration and erosion of societal trust","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"AI privacy leakage and re-identification","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"AI safety failures causing physical or psychological harm","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"AI supply-chain compromise and provider concentration","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Absence of privacy-by-design and default","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Absent or untested business continuity / disaster recovery plan","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Absent or weak change-control procedures","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Abuse of rights, forged rights, and repudiation of actions","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Acceptance of data from untrustworthy sources","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Adversarial attacks, data poisoning and prompt injection","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Adversary reconnaissance and information gathering","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Adverse regulatory or policy change","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Aging hardware with no periodic replacement scheme","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Applications running with excessive privilege / insecure design","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Assets not returned upon employee termination","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Attacks by capable, motivated threat actors","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Brand and reputational crisis","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Brand trust deterioration","templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","templateName":"Risk Appetite & Tolerance Calibration"},{"itemType":"risk","itemTitle":"Brand trust deterioration","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Business combination purchase accounting misstatement (ASC 805)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Business continuity outage","templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","templateName":"Emerging Risk & Horizon Scan"},{"itemType":"risk","itemTitle":"Business continuity outage","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Capex overrun on data-center fit-out","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Capitalization / CIP misstatement on data-center builds","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Carrier interconnect concentration risk","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Chilled-water plant failure causing thermal event","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Client intake, documentation and account-management failures","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Client selection, sponsorship and exposure-limit breaches","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Client suitability, disclosure and fiduciary breaches","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Climate transition risk - carbon pricing and stranded assets","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Cloud multi-tenancy isolation and data-scavenging exploits","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Colocation billing incomplete or inaccurate (SOC 1 user-entity impact)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Communications interception, eavesdropping and man-in-the-middle","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Competitive displacement by established GRC platforms","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Competitive disruption and business-model obsolescence","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Compromised or counterfeit certificates / certificate authority","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Construction delay on critical-path equipment","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Coordinated multi-stage / APT campaigns","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Core process breakdown and inability to scale","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Corruption or integrity loss of critical data","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Credentials and sensitive data transmitted in clear text","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Credit and market (rate/FX) risk","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Critical subservice organization (firm) failure leaves governance, finance, and security oversight vacuum","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Critical talent loss, scarcity and succession gaps","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Critical vendor failure, insolvency or concentration","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Cross-border personal-data transfer without safeguards","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Customer concentration risk - over-reliance on key clients","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Data exfiltration and theft of information by attackers","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Data-center availability / environmental failure (SOC 1)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Data-quality and IPE integrity failures in reporting","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Debt covenant breach under downside case","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Denial-of-service and system saturation","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Deployment of prohibited AI practices (EU AI Act Art.5)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Developer self-approves and deploys own change via CI/CD","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Discrimination, harassment and hostile-workplace culture","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Discriminatory outcomes from AI in employment","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Domain hijacking or DNS integrity failure at the registrar","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"ERP/HRIS implementation cutover errors impair opening balances","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"ESG disclosure gaps and greenwashing","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Emergent behaviour and unsafe AI system integration","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Employee safety incident","templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","templateName":"Emerging Risk & Horizon Scan"},{"itemType":"risk","itemTitle":"Employee safety incident","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Employment-practice and labor-law violations","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Environmental degradation of equipment (dust, humidity, temperature, EMI)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Environmental footprint of AI training and infrastructure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Environmental regulatory non-compliance","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Erosion of individual trust and confidence in data practices","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Excess or unauthorized access to financial systems","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Excess privileged access to building-management systems","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Excessive Cloud SQL access exposes regulated PII","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Excessive Lucille Identity Cloud group membership grants unintended access","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Excessive collection, purpose creep and secondary use","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Excessive privilege and wrong assignment of access rights","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Excessive surveillance, appropriation and induced disclosure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Exploitation of known, unpatched vulnerabilities","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"External fraud - third-party theft, forgery, payment and account fraud","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"F-gas refrigerant leak above reporting threshold","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Failed M&A, integration or divestiture","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Failed or inaccurate mandatory regulatory reporting","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Failure to detect, assess, and notify breaches on time","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Financial close error or delay leading to restatement","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Financial statement fraud","templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","templateName":"Risk Appetite & Tolerance Calibration"},{"itemType":"risk","itemTitle":"Financial statement fraud","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Financial-statement fraud and management override","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Firm-internal segregation of duties claimed but not enforced (paper-only)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Fraudulent or unauthorized disbursement (P2P / Treasury)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"GPAI transparency, systemic-risk and synthetic-content obligations","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Geopolitical, macroeconomic and sovereign risk","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Hardware and equipment failure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Harm to due process and democratic integrity from AI","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Harmful AI bias and discrimination against protected groups","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"IT resilience failure - unplanned outage, data loss, slow recovery","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"ITGC deficiency in newly implemented Banana ERP / Never Nude HR Platform undermines ICFR","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Illegal processing of personal or sensitive data","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Improper business or market practices","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Inaccurate, unreliable or hallucinated AI outputs","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Inadequate board and management oversight of risk and control","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Inadequate on-call coverage misses customer SLA commitments","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Inadequate or absent risk assessment process","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Inadequate physical protection and access controls","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Inadequate security awareness and training","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Inadequate transparency, notice and deceptive privacy communications","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Income / property / indirect tax misstatement (ASC 740)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Incomplete asset inventory and classification","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Ineffective ICFR / undisclosed material weakness","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Insufficient personnel screening and vetting","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Intellectual property loss or infringement","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Internal fraud - asset misappropriation, embezzlement, forgery","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Internet-exposed or misconfigured systems","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Inventory / critical-spares valuation or obsolescence error","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Lack of independent audit and compliance review","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Leaked CI/CD pipeline secret grants environment access","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Lease accounting error (ASC 842) on ground/building leases","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Legacy system processing failure","templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","templateName":"ERM Risk Identification & Register Refresh"},{"itemType":"risk","itemTitle":"Legacy system processing failure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Litigation, investigation and enforcement exposure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Loss of essential services (power, HVAC, telecoms)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Loss of system maintainability","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Loss of utility power without N+1 failover","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Malicious supply-chain injection of tampered hardware/software","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Malware delivery, insertion and compromise of systems","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Manual journal entries and management-override risk","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Material weakness in ICFR undermines IPO readiness","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Misconfigured Model Home Data Lake resource exposes data publicly","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Missing MFA on Lucille Identity Cloud enables account takeover","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Missing or insufficient logging and audit trails","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Missing or insufficient security and privacy policies","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Missing role-based and ongoing security/privacy training","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Missing security terms in contracts and no disciplinary process","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Model Home Data Lake outage without tested recovery causes prolonged downtime","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"No or insufficient incident-response procedures","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"No security monitoring or supervision of privileged activity","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Non-compliance with energy-efficiency reporting","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Orphaned or stale Lucille Identity Cloud accounts retain access","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Over-privileged Model Home Data Lake IAM principal is compromised","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Over-retention of PII in Cloud SQL breaches privacy commitments","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Overstatement of assets/revenue (existence & occurrence)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Phishing, spear-phishing and social engineering","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Physical and cyber-physical attacks on facilities and infrastructure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Physical climate risk to facilities and supply chains","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Physical damage to assets from disaster, terrorism or vandalism","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Poor configuration management and insecure baseline drift","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Poor network architecture and unprotected public connections","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Power imbalance and loss of self-determination over personal data","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Privacy consent failure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"REIT carve-out & sale-leaseback accounting error","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Ransomware disrupting operations and data availability","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Re-identification and unanticipated revelation from data","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Refinancing risk at facility maturity","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Regulatory filing delay","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Remote spying and shoulder-surfing of screens/documents","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Remote-work, mobile and split-tunneling exposure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Residual data on improperly disposed or re-used media","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Revenue cut-off error","templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","templateName":"ERM Risk Identification & Register Refresh"},{"itemType":"risk","itemTitle":"Revenue cut-off error","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Revenue recognized incorrectly on complex colocation contracts (ASC 606)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Revenue sustainability and cash flow constraints","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Secrets sprawl outside Secret Manager are leaked","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Segregation-of-duties conflicts across Banana ERP / Banana ERP","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Sensitive data leaked through uncontrolled transfer channels","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Single code reviewer dependency creates change-management bottleneck and SoD failure on reviewer's own changes","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Single-site / single-region / single-supply concentration","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Single-site outage without DR failover","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Single-source dependency on cooling OEM","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Software and information-system failure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Stakeholder trust and social-license erosion","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Stock-based compensation expense misstated (ASC 718)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Strategic acquisition integration","templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","templateName":"ERM Risk Identification & Register Refresh"},{"itemType":"risk","itemTitle":"Strategic acquisition integration","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Subcontractor fails security due-diligence","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Subservice organization reliance failure (SOC 1 CUECs)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Theft of equipment, media or unattended devices","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Third-party / vendor concentration & SOC-report gap","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Third-party compliance failure creating vicarious liability","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Third-party service interruption","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unapproved change introduces financial-system error","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unauthorized access to customer environments / white space","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unauthorized activity - rogue trading, position mismarking, concealment","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unauthorized disclosure / breach of sensitive information","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unauthorized or inaccurate payroll (Never Nude HR Platform)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unauthorized privileged access","templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","templateName":"Risk Appetite & Tolerance Calibration"},{"itemType":"risk","itemTitle":"Unauthorized privileged access","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unauthorized use of equipment and unauthorized access escalation","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Uncontrolled copying to removable media / unmanaged software installs","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Understatement of liabilities/expenses (completeness)","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Undetected anomalous export from Cloud SQL","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unencrypted or unmasked PII in Cloud SQL is exfiltrated","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unhedged FX exposure on cross-border debt","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unlawful retention or premature deletion of records","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unlogged Model Home Data Lake activity prevents breach detection","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unmanaged third-party API token is leaked","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unrated emerging risk","templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","templateName":"Emerging Risk & Horizon Scan"},{"itemType":"risk","itemTitle":"Unrated emerging risk","templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","templateName":"ERM Risk Identification & Register Refresh"},{"itemType":"risk","itemTitle":"Unrated emerging risk","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Unreviewed change merged and deployed via Model Home Data Lake","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"User error and mishandling of sensitive information","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Valuation error — PPA, goodwill/intangibles or 409A equity","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Vendor concentration exposure","templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","templateName":"Risk Appetite & Tolerance Calibration"},{"itemType":"risk","itemTitle":"Vendor concentration exposure","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Vulnerabilities introduced during software development","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Weak account provisioning/de-registration and access review","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Weak authentication and password management","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Weak internal control environment enabling fraud and error","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Weak or absent encryption and key management","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Weak supplier security requirements and monitoring","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Workplace health, safety and well-being failures","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"risk","itemTitle":"Zero-day exploitation","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review"},{"itemType":"system","itemTitle":"Banana ERP","templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing"},{"itemType":"system","itemTitle":"Banana ERP","templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration"},{"itemType":"system","itemTitle":"Banana ERP","templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration"},{"itemType":"system","itemTitle":"Banana ERP","templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change"},{"itemType":"system","itemTitle":"Banana ERP","templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation"},{"itemType":"system","itemTitle":"Banana ERP","templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring"},{"itemType":"system","itemTitle":"Banana ERP","templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review"},{"itemType":"system","itemTitle":"Banana ERP","templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review"},{"itemType":"system","itemTitle":"Banana ERP","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Tidewell File Exchange","templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing"},{"itemType":"system","itemTitle":"Tidewell File Exchange","templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration"},{"itemType":"system","itemTitle":"Tidewell File Exchange","templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management"},{"itemType":"system","itemTitle":"Tidewell File Exchange","templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)"},{"itemType":"system","itemTitle":"Tidewell File Exchange","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Cornballer Revenue Engine","templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration"},{"itemType":"system","itemTitle":"Cornballer Revenue Engine","templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change"},{"itemType":"system","itemTitle":"Cornballer Revenue Engine","templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation"},{"itemType":"system","itemTitle":"Cornballer Revenue Engine","templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring"},{"itemType":"system","itemTitle":"Cornballer Revenue Engine","templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review"},{"itemType":"system","itemTitle":"Cornballer Revenue Engine","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"GOB Security Monitoring","templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management"},{"itemType":"system","itemTitle":"GOB Security Monitoring","templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review"},{"itemType":"system","itemTitle":"GOB Security Monitoring","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review"},{"itemType":"system","itemTitle":"GOB Security Monitoring","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Lucille Identity Cloud","templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management"},{"itemType":"system","itemTitle":"Lucille Identity Cloud","templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review"},{"itemType":"system","itemTitle":"Lucille Identity Cloud","templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review"},{"itemType":"system","itemTitle":"Lucille Identity Cloud","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review"},{"itemType":"system","itemTitle":"Lucille Identity Cloud","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Model Home Data Lake","templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing"},{"itemType":"system","itemTitle":"Model Home Data Lake","templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration"},{"itemType":"system","itemTitle":"Model Home Data Lake","templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration"},{"itemType":"system","itemTitle":"Model Home Data Lake","templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation"},{"itemType":"system","itemTitle":"Model Home Data Lake","templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring"},{"itemType":"system","itemTitle":"Model Home Data Lake","templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)"},{"itemType":"system","itemTitle":"Model Home Data Lake","templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review"},{"itemType":"system","itemTitle":"Model Home Data Lake","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Never Nude HR Platform","templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration"},{"itemType":"system","itemTitle":"Never Nude HR Platform","templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change"},{"itemType":"system","itemTitle":"Never Nude HR Platform","templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)"},{"itemType":"system","itemTitle":"Never Nude HR Platform","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review"},{"itemType":"system","itemTitle":"Never Nude HR Platform","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Seaward Payroll Service","templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration"},{"itemType":"system","itemTitle":"Seaward Payroll Service","templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation"},{"itemType":"system","itemTitle":"Seaward Payroll Service","templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring"},{"itemType":"system","itemTitle":"Seaward Payroll Service","templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)"},{"itemType":"system","itemTitle":"Seaward Payroll Service","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review"},{"itemType":"system","itemTitle":"Seaward Payroll Service","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Stair Car Facilities System","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Sudden Valley Network","templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing"},{"itemType":"system","itemTitle":"Sudden Valley Network","templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change"},{"itemType":"system","itemTitle":"Sudden Valley Network","templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management"},{"itemType":"system","itemTitle":"Sudden Valley Network","templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review"},{"itemType":"system","itemTitle":"Sudden Valley Network","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"issue","itemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Policy exception — Access Control Standard","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — Access Control Standard","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Policy exception — Board & Governance Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — Board & Governance Policy","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Policy exception — Cloud Services Security Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — Cloud Services Security Policy","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Policy exception — Data Classification & Handling Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — Data Classification & Handling Policy","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Policy exception — Financial Close Procedure","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — Financial Close Procedure","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Policy exception — Incident Response Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — Incident Response Policy","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Policy exception — Management Review Procedure","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — Management Review Procedure","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Policy exception — Physical Security Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Policy exception — Physical Security Policy","templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition"},{"itemType":"issue","itemTitle":"Change approval waived for a revenue system release","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"issue","itemTitle":"Privacy Waiver Expiring","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance"},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"model","itemTitle":"Model Home Pricing Engine","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Model Home Pricing Engine","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Model Home Pricing Engine","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"model","itemTitle":"Sudden Valley Reserve Model","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Sudden Valley Reserve Model","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Sudden Valley Reserve Model","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"model","itemTitle":"Construction Cost Estimator","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Construction Cost Estimator","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Construction Cost Estimator","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"model","itemTitle":"Cornballer Warranty Reserve","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Cornballer Warranty Reserve","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Cornballer Warranty Reserve","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"model","itemTitle":"Staffing Optimizer","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Staffing Optimizer","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Staffing Optimizer","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"model","itemTitle":"Balboa Towers Occupancy Model","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Balboa Towers Occupancy Model","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Balboa Towers Occupancy Model","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"model","itemTitle":"Tenant Credit Risk Scorecard","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation"},{"itemType":"model","itemTitle":"Tenant Credit Risk Scorecard","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review"},{"itemType":"model","itemTitle":"Tenant Credit Risk Scorecard","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring"},{"itemType":"system","itemTitle":"Sitwell Payroll Bureau","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Sitwell Payroll Bureau","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review"},{"itemType":"system","itemTitle":"Magic Supply Wholesale","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Magic Supply Wholesale","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review"},{"itemType":"system","itemTitle":"Seaside Cloud Hosting","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"},{"itemType":"system","itemTitle":"Bluth Legal Retainer Services","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review"}],"workflowTemplateStepLinks":[{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"risk","itemTitle":"Unrated emerging risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"rcm","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"rcm","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"rcm","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"execute-fieldwork","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"execute-fieldwork","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"execute-fieldwork","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"execute-fieldwork","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"findings-clearance","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"findings-clearance","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"findings-clearance","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"reporting-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"reporting-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-scope-risk","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-scope-risk","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-scope-risk","itemType":"control","itemTitle":"Journal Entry Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-scope-risk","itemType":"control","itemTitle":"Account Reconciliation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-scope-risk","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-planning-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-planning-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-planning-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-planning-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"roll-forward-strategy","itemType":"control","itemTitle":"Account Reconciliation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"roll-forward-strategy","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"roll-forward-strategy","itemType":"control","itemTitle":"Journal Entry Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"roll-forward-strategy","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"year-end-plan-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"year-end-plan-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"year-end-plan-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"year-end-plan-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"severity-aggregation","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"severity-aggregation","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"severity-aggregation","itemType":"control","itemTitle":"Journal Entry Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"severity-aggregation","itemType":"control","itemTitle":"Account Reconciliation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"severity-aggregation","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"deficiency-evaluation-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"deficiency-evaluation-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"deficiency-evaluation-closure","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"assessment-synthesis","itemType":"control","itemTitle":"Journal Entry Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"assessment-synthesis","itemType":"control","itemTitle":"Account Reconciliation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"assessment-synthesis","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"assessment-synthesis","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"assessment-synthesis","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"management-assessment-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"management-assessment-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"management-assessment-closure","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"control","itemTitle":"Journal Entry Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"control","itemTitle":"Account Reconciliation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"control","itemTitle":"Production Change Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"control","itemTitle":"Segregated Deployment Pipeline","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"risk","itemTitle":"Third-party service interruption","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"control","itemTitle":"Backup Restoration Test","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"control","itemTitle":"Job Failure Escalation","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"control","itemTitle":"Privacy Request Verification","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"control","itemTitle":"Data Retention Enforcement","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"control","itemTitle":"Business Continuity Exercise","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"risk","itemTitle":"Business continuity outage","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"control","itemTitle":"Backup Restoration Test","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"control","itemTitle":"Job Failure Escalation","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"control","itemTitle":"Business Continuity Exercise","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"risk","itemTitle":"Business continuity outage","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"control","itemTitle":"Privacy Request Verification","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"control","itemTitle":"Data Retention Enforcement","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"risk","itemTitle":"Privacy consent failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-clause-control-review","itemType":"control","itemTitle":"Physical Site Access Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-clause-control-review","itemType":"risk","itemTitle":"Employee safety incident","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-clause-control-review","itemType":"control","itemTitle":"Secure Development Gate","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-clause-control-review","itemType":"control","itemTitle":"New Application Architecture Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-clause-control-review","itemType":"control","itemTitle":"Visitor Badge Reconciliation","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-clause-control-review","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-clause-control-review","itemType":"risk","itemTitle":"AI model governance gap","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-readiness-closure","itemType":"control","itemTitle":"Secure Development Gate","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-readiness-closure","itemType":"control","itemTitle":"New Application Architecture Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-readiness-closure","itemType":"risk","itemTitle":"AI model governance gap","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-readiness-closure","itemType":"control","itemTitle":"Visitor Badge Reconciliation","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-readiness-closure","itemType":"control","itemTitle":"Physical Site Access Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-readiness-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review","nodeId":"risk-assessment","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review","nodeId":"risk-assessment","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review","nodeId":"risk-review-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review","nodeId":"risk-review-closure","itemType":"control","itemTitle":"Business Continuity Exercise","kind":"related"},{"templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","templateName":"Risk Assessment & Treatment Review","nodeId":"risk-review-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","templateName":"ERM Risk Identification & Register Refresh","nodeId":"erm-refresh-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","templateName":"ERM Risk Identification & Register Refresh","nodeId":"erm-refresh-closure","itemType":"control","itemTitle":"Security Incident Triage","kind":"related"},{"templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","templateName":"ERM Risk Identification & Register Refresh","nodeId":"erm-refresh-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","templateName":"Risk Appetite & Tolerance Calibration","nodeId":"appetite-statement","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","templateName":"Risk Appetite & Tolerance Calibration","nodeId":"appetite-statement","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","templateName":"Risk Appetite & Tolerance Calibration","nodeId":"appetite-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","templateName":"Risk Appetite & Tolerance Calibration","nodeId":"appetite-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","templateName":"Emerging Risk & Horizon Scan","nodeId":"horizon-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","templateName":"Emerging Risk & Horizon Scan","nodeId":"horizon-closure","itemType":"control","itemTitle":"Security Incident Triage","kind":"related"},{"templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","templateName":"Emerging Risk & Horizon Scan","nodeId":"horizon-closure","itemType":"control","itemTitle":"Vulnerability Remediation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","templateName":"Emerging Risk & Horizon Scan","nodeId":"horizon-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment","nodeId":"design-conclusion","itemType":"risk","itemTitle":"Unrated emerging risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment","nodeId":"design-conclusion","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment","nodeId":"design-conclusion","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment","nodeId":"design-conclusion","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment","nodeId":"design-conclusion","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough","nodeId":"walkthrough-conclusion","itemType":"risk","itemTitle":"Unrated emerging risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough","nodeId":"walkthrough-conclusion","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough","nodeId":"walkthrough-conclusion","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough","nodeId":"walkthrough-conclusion","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough","nodeId":"walkthrough-conclusion","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"population-validate","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"population-validate","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"population-validate","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"interim-conclusion","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"interim-conclusion","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"interim-conclusion","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"change-assessment","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"change-assessment","itemType":"risk","itemTitle":"Strategic acquisition integration","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"change-assessment","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"rollforward-conclusion","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"rollforward-conclusion","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"rollforward-conclusion","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation","nodeId":"impact-evaluate","itemType":"risk","itemTitle":"Unrated emerging risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation","nodeId":"impact-evaluate","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation","nodeId":"impact-evaluate","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation","nodeId":"exception-conclusion","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation","nodeId":"exception-conclusion","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-plan","itemType":"risk","itemTitle":"Unrated emerging risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-plan","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-closure","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"sample","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"sample","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"sample","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"test","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"test","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"test","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-assessment","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-assessment","itemType":"risk","itemTitle":"Unrated emerging risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-assessment","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-assessment","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-assessment","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-triage-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-triage-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-triage-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-triage-closure","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-plan","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-plan","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-delivery","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-delivery","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-delivery","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-review-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-review-closure","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-review-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-transaction-trace","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-transaction-trace","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-transaction-trace","itemType":"control","itemTitle":"Journal Entry Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-transaction-trace","itemType":"control","itemTitle":"Account Reconciliation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-transaction-trace","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-walkthrough-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-walkthrough-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-walkthrough-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-walkthrough-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"owner-signoff","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"owner-signoff","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"owner-signoff","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"policy-team-signoff","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"policy-team-signoff","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"policy-team-signoff","itemType":"risk","itemTitle":"Unrated emerging risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"propose","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"propose","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"propose","itemType":"risk","itemTitle":"AI model governance gap","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"approve","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"approve","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"approve","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"approve","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"approve","itemType":"risk","itemTitle":"Unrated emerging risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-risk-assessment","itemType":"control","itemTitle":"Vendor Due Diligence","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-risk-assessment","itemType":"risk","itemTitle":"Third-party service interruption","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-risk-assessment","itemType":"control","itemTitle":"SOC Report and CUEC Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-risk-assessment","itemType":"risk","itemTitle":"Vendor concentration exposure","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-review-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-review-closure","itemType":"risk","itemTitle":"Vendor concentration exposure","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-review-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-review-closure","itemType":"risk","itemTitle":"Third-party service interruption","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-report-evaluation","itemType":"control","itemTitle":"SOC Report and CUEC Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-report-evaluation","itemType":"risk","itemTitle":"Third-party service interruption","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-report-evaluation","itemType":"control","itemTitle":"Vendor Due Diligence","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-report-evaluation","itemType":"risk","itemTitle":"Vendor concentration exposure","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-review-closure","itemType":"control","itemTitle":"SOC Report and CUEC Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-review-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-review-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-review-closure","itemType":"risk","itemTitle":"Vendor concentration exposure","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"control","itemTitle":"Account Reconciliation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"control","itemTitle":"Journal Entry Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-applicability","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-applicability","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-applicability","itemType":"risk","itemTitle":"Unrated emerging risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-mapping-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-mapping-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-mapping-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-applicability","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-applicability","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-intake-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-intake-closure","itemType":"risk","itemTitle":"Privacy consent failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-intake-closure","itemType":"risk","itemTitle":"AI model governance gap","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-intake-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-scope","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-scope","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-closure","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-closure","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"conformance-testing","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"conformance-testing","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"conformance-testing","itemType":"control","itemTitle":"Policy Exception Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"conformance-testing","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"monitoring-closure","itemType":"control","itemTitle":"Board Risk Oversight","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"monitoring-closure","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"monitoring-closure","itemType":"risk","itemTitle":"Regulatory filing delay","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"access-approval","itemType":"control","itemTitle":"Joiner Mover Leaver Automation","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"access-approval","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"access-approval","itemType":"control","itemTitle":"Privileged Access Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"onboarding-closure","itemType":"control","itemTitle":"Joiner Mover Leaver Automation","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"onboarding-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"onboarding-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"onboarding-closure","itemType":"control","itemTitle":"Quarterly Access Recertification","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-approval","itemType":"control","itemTitle":"Joiner Mover Leaver Automation","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-approval","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-approval","itemType":"control","itemTitle":"Privileged Access Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-closure","itemType":"control","itemTitle":"Joiner Mover Leaver Automation","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-closure","itemType":"control","itemTitle":"Quarterly Access Recertification","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-execution","itemType":"control","itemTitle":"Joiner Mover Leaver Automation","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-execution","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-execution","itemType":"control","itemTitle":"Emergency Access Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-closure","itemType":"control","itemTitle":"Quarterly Access Recertification","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-closure","itemType":"control","itemTitle":"Privileged Access Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review","nodeId":"uar-distribution","itemType":"control","itemTitle":"Quarterly Access Recertification","kind":"related"},{"templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review","nodeId":"uar-distribution","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review","nodeId":"uar-closure","itemType":"control","itemTitle":"Quarterly Access Recertification","kind":"related"},{"templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review","nodeId":"uar-closure","itemType":"control","itemTitle":"Joiner Mover Leaver Automation","kind":"related"},{"templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review","nodeId":"uar-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-justification","itemType":"control","itemTitle":"Privileged Access Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-justification","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-justification","itemType":"control","itemTitle":"Emergency Access Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-closure","itemType":"control","itemTitle":"Emergency Access Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-closure","itemType":"control","itemTitle":"Quarterly Access Recertification","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-closure","itemType":"control","itemTitle":"Privileged Access Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-approval","itemType":"control","itemTitle":"Production Change Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-approval","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-approval","itemType":"risk","itemTitle":"Strategic acquisition integration","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-closure","itemType":"control","itemTitle":"Segregated Deployment Pipeline","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-closure","itemType":"control","itemTitle":"Change Migration Reconciliation","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-closure","itemType":"control","itemTitle":"Production Change Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-intake","itemType":"control","itemTitle":"Emergency Access Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-intake","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-closure","itemType":"control","itemTitle":"Segregated Deployment Pipeline","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-closure","itemType":"control","itemTitle":"Production Change Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-closure","itemType":"risk","itemTitle":"Strategic acquisition integration","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-requirements","itemType":"control","itemTitle":"New Application Architecture Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-requirements","itemType":"risk","itemTitle":"AI model governance gap","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-closure","itemType":"control","itemTitle":"Secure Development Gate","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-closure","itemType":"control","itemTitle":"New Application Architecture Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-closure","itemType":"control","itemTitle":"Production Change Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-closure","itemType":"risk","itemTitle":"Strategic acquisition integration","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-scope","itemType":"control","itemTitle":"Change Migration Reconciliation","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-scope","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-closure","itemType":"control","itemTitle":"Change Migration Reconciliation","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-closure","itemType":"control","itemTitle":"Account Reconciliation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-closure","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-closure","itemType":"control","itemTitle":"Production Change Approval","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-closure","itemType":"risk","itemTitle":"Strategic acquisition integration","kind":"related"},{"templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring","nodeId":"batch-closure","itemType":"control","itemTitle":"Batch Processing Monitoring","kind":"related"},{"templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring","nodeId":"batch-closure","itemType":"risk","itemTitle":"Legacy system processing failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring","nodeId":"batch-closure","itemType":"control","itemTitle":"Job Failure Escalation","kind":"related"},{"templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring","nodeId":"batch-closure","itemType":"risk","itemTitle":"Business continuity outage","kind":"related"},{"templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing","nodeId":"backup-scope","itemType":"control","itemTitle":"Backup Restoration Test","kind":"related"},{"templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing","nodeId":"backup-scope","itemType":"risk","itemTitle":"Business continuity outage","kind":"related"},{"templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing","nodeId":"backup-closure","itemType":"control","itemTitle":"Backup Restoration Test","kind":"related"},{"templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing","nodeId":"backup-closure","itemType":"risk","itemTitle":"Business continuity outage","kind":"related"},{"templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing","nodeId":"backup-closure","itemType":"control","itemTitle":"Business Continuity Exercise","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-response","itemType":"control","itemTitle":"Security Incident Triage","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-response","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-response","itemType":"risk","itemTitle":"Business continuity outage","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-closure","itemType":"control","itemTitle":"Vulnerability Remediation Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-closure","itemType":"control","itemTitle":"Security Incident Triage","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-closure","itemType":"risk","itemTitle":"Unauthorized privileged access","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-closure","itemType":"risk","itemTitle":"Brand trust deterioration","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-controls","itemType":"control","itemTitle":"Spreadsheet Inventory Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-controls","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-controls","itemType":"control","itemTitle":"EUC Formula Validation","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-closure","itemType":"control","itemTitle":"EUC Formula Validation","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-closure","itemType":"risk","itemTitle":"Revenue cut-off error","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-closure","itemType":"control","itemTitle":"Spreadsheet Inventory Review","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-closure","itemType":"risk","itemTitle":"Financial statement fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"risk","itemTitle":"AI accountability gaps and organizational liability","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"risk","itemTitle":"AI agent makes unauthorized production changes","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"rcm","itemType":"risk","itemTitle":"AI power concentration and erosion of societal trust","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"rcm","itemType":"risk","itemTitle":"AI privacy leakage and re-identification","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"execute-fieldwork","itemType":"risk","itemTitle":"AI safety failures causing physical or psychological harm","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"execute-fieldwork","itemType":"risk","itemTitle":"AI supply-chain compromise and provider concentration","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"findings-clearance","itemType":"risk","itemTitle":"Absence of privacy-by-design and default","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"reporting-closure","itemType":"risk","itemTitle":"Absent or untested business continuity / disaster recovery plan","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-scope-risk","itemType":"risk","itemTitle":"Absent or weak change-control procedures","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-scope-risk","itemType":"risk","itemTitle":"Abuse of rights, forged rights, and repudiation of actions","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-planning-closure","itemType":"risk","itemTitle":"Acceptance of data from untrustworthy sources","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-planning-closure","itemType":"risk","itemTitle":"Adversarial attacks, data poisoning and prompt injection","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"roll-forward-strategy","itemType":"risk","itemTitle":"Adversary reconnaissance and information gathering","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"roll-forward-strategy","itemType":"risk","itemTitle":"Adverse regulatory or policy change","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"year-end-plan-closure","itemType":"risk","itemTitle":"Aging hardware with no periodic replacement scheme","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"year-end-plan-closure","itemType":"risk","itemTitle":"Applications running with excessive privilege / insecure design","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"severity-aggregation","itemType":"risk","itemTitle":"Assets not returned upon employee termination","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"severity-aggregation","itemType":"risk","itemTitle":"Attacks by capable, motivated threat actors","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"deficiency-evaluation-closure","itemType":"risk","itemTitle":"Brand and reputational crisis","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"deficiency-evaluation-closure","itemType":"risk","itemTitle":"Business combination purchase accounting misstatement (ASC 805)","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"assessment-synthesis","itemType":"risk","itemTitle":"Capex overrun on data-center fit-out","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"assessment-synthesis","itemType":"risk","itemTitle":"Capitalization / CIP misstatement on data-center builds","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"management-assessment-closure","itemType":"risk","itemTitle":"Carrier interconnect concentration risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","templateName":"Management Assessment & Assertion","nodeId":"management-assessment-closure","itemType":"risk","itemTitle":"Chilled-water plant failure causing thermal event","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"risk","itemTitle":"Client intake, documentation and account-management failures","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"risk","itemTitle":"Client selection, sponsorship and exposure-limit breaches","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"risk","itemTitle":"Client suitability, disclosure and fiduciary breaches","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-pbc","templateName":"External Audit Support & PBC","nodeId":"pbc-request-closure","itemType":"risk","itemTitle":"Climate transition risk - carbon pricing and stranded assets","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-criteria-mapping","itemType":"risk","itemTitle":"Cloud multi-tenancy isolation and data-scavenging exploits","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"risk","itemTitle":"Colocation billing incomplete or inaccurate (SOC 1 user-entity impact)","kind":"related"},{"templateSourceId":"coworkcanvas:template:soc2-readiness","templateName":"SOC 2 Trust Services Readiness","nodeId":"soc2-readiness-closure","itemType":"risk","itemTitle":"Communications interception, eavesdropping and man-in-the-middle","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-clause-control-review","itemType":"risk","itemTitle":"Competitive displacement by established GRC platforms","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-clause-control-review","itemType":"risk","itemTitle":"Competitive disruption and business-model obsolescence","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-readiness-closure","itemType":"risk","itemTitle":"Compromised or counterfeit certificates / certificate authority","kind":"related"},{"templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","templateName":"ISO 27001 Certification Readiness","nodeId":"iso-readiness-closure","itemType":"risk","itemTitle":"Construction delay on critical-path equipment","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment","nodeId":"design-conclusion","itemType":"risk","itemTitle":"Coordinated multi-stage / APT campaigns","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment","nodeId":"design-conclusion","itemType":"risk","itemTitle":"Core process breakdown and inability to scale","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment","nodeId":"design-conclusion","itemType":"risk","itemTitle":"Corruption or integrity loss of critical data","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-design-assessment","templateName":"Control Design Assessment","nodeId":"design-conclusion","itemType":"risk","itemTitle":"Credentials and sensitive data transmitted in clear text","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough","nodeId":"walkthrough-conclusion","itemType":"risk","itemTitle":"Credit and market (rate/FX) risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough","nodeId":"walkthrough-conclusion","itemType":"risk","itemTitle":"Critical subservice organization (firm) failure leaves governance, finance, and security oversight vacuum","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough","nodeId":"walkthrough-conclusion","itemType":"risk","itemTitle":"Critical talent loss, scarcity and succession gaps","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-walkthrough","templateName":"Control Walkthrough","nodeId":"walkthrough-conclusion","itemType":"risk","itemTitle":"Critical vendor failure, insolvency or concentration","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"population-validate","itemType":"risk","itemTitle":"Cross-border personal-data transfer without safeguards","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"population-validate","itemType":"risk","itemTitle":"Customer concentration risk - over-reliance on key clients","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"interim-conclusion","itemType":"risk","itemTitle":"Data exfiltration and theft of information by attackers","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","templateName":"Interim Operating Effectiveness Testing","nodeId":"interim-conclusion","itemType":"risk","itemTitle":"Data-center availability / environmental failure (SOC 1)","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"change-assessment","itemType":"risk","itemTitle":"Data-quality and IPE integrity failures in reporting","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"change-assessment","itemType":"risk","itemTitle":"Debt covenant breach under downside case","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"rollforward-conclusion","itemType":"risk","itemTitle":"Denial-of-service and system saturation","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","templateName":"Period-End Roll-Forward / Rollover Testing","nodeId":"rollforward-conclusion","itemType":"risk","itemTitle":"Deployment of prohibited AI practices (EU AI Act Art.5)","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation","nodeId":"impact-evaluate","itemType":"risk","itemTitle":"Developer self-approves and deploys own change via CI/CD","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation","nodeId":"impact-evaluate","itemType":"risk","itemTitle":"Discrimination, harassment and hostile-workplace culture","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation","nodeId":"exception-conclusion","itemType":"risk","itemTitle":"Discriminatory outcomes from AI in employment","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","templateName":"Control Exception Evaluation & Remediation","nodeId":"exception-conclusion","itemType":"risk","itemTitle":"Domain hijacking or DNS integrity failure at the registrar","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-plan","itemType":"risk","itemTitle":"ERP/HRIS implementation cutover errors impair opening balances","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-closure","itemType":"risk","itemTitle":"ESG disclosure gaps and greenwashing","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-closure","itemType":"risk","itemTitle":"Emergent behaviour and unsafe AI system integration","kind":"related"},{"templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","templateName":"Control Remediation Retest & Closure","nodeId":"retest-closure","itemType":"risk","itemTitle":"Employment-practice and labor-law violations","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"sample","itemType":"risk","itemTitle":"Environmental degradation of equipment (dust, humidity, temperature, EMI)","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"sample","itemType":"risk","itemTitle":"Environmental footprint of AI training and infrastructure","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"sample","itemType":"risk","itemTitle":"Environmental regulatory non-compliance","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"test","itemType":"risk","itemTitle":"Erosion of individual trust and confidence in data practices","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"test","itemType":"risk","itemTitle":"Excess or unauthorized access to financial systems","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","nodeId":"test","itemType":"risk","itemTitle":"Excess privileged access to building-management systems","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-assessment","itemType":"risk","itemTitle":"Excessive Cloud SQL access exposes regulated PII","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-assessment","itemType":"risk","itemTitle":"Excessive Lucille Identity Cloud group membership grants unintended access","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-triage-closure","itemType":"risk","itemTitle":"Excessive collection, purpose creep and secondary use","kind":"related"},{"templateSourceId":"coworkcanvas:template:issue-triage-disposition","templateName":"Issue Triage & Disposition","nodeId":"issue-triage-closure","itemType":"risk","itemTitle":"Excessive privilege and wrong assignment of access rights","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-plan","itemType":"risk","itemTitle":"Excessive surveillance, appropriation and induced disclosure","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-delivery","itemType":"risk","itemTitle":"Exploitation of known, unpatched vulnerabilities","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-review-closure","itemType":"risk","itemTitle":"External fraud - third-party theft, forgery, payment and account fraud","kind":"related"},{"templateSourceId":"coworkcanvas:template:remediation-delivery-validation","templateName":"Remediation Delivery & Validation","nodeId":"remediation-review-closure","itemType":"risk","itemTitle":"F-gas refrigerant leak above reporting threshold","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"risk","itemTitle":"Failed M&A, integration or divestiture","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"risk","itemTitle":"Failed or inaccurate mandatory regulatory reporting","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"risk","itemTitle":"Failure to detect, assess, and notify breaches on time","kind":"related"},{"templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","templateName":"Process Narrative & Walkthrough","nodeId":"process-record-closure","itemType":"risk","itemTitle":"Financial close error or delay leading to restatement","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-transaction-trace","itemType":"risk","itemTitle":"Financial-statement fraud and management override","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-transaction-trace","itemType":"risk","itemTitle":"Firm-internal segregation of duties claimed but not enforced (paper-only)","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-walkthrough-closure","itemType":"risk","itemTitle":"Fraudulent or unauthorized disbursement (P2P / Treasury)","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-walkthrough","templateName":"Process Walkthrough & Design Assessment","nodeId":"sox-walkthrough-closure","itemType":"risk","itemTitle":"GPAI transparency, systemic-risk and synthetic-content obligations","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"owner-signoff","itemType":"risk","itemTitle":"Geopolitical, macroeconomic and sovereign risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"owner-signoff","itemType":"risk","itemTitle":"Hardware and equipment failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"policy-team-signoff","itemType":"risk","itemTitle":"Harm to due process and democratic integrity from AI","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-annual-review","templateName":"Annual Policy Review","nodeId":"policy-team-signoff","itemType":"risk","itemTitle":"Harmful AI bias and discrimination against protected groups","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"propose","itemType":"risk","itemTitle":"IT resilience failure - unplanned outage, data loss, slow recovery","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"approve","itemType":"risk","itemTitle":"ITGC deficiency in newly implemented Banana ERP / Never Nude HR Platform undermines ICFR","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"approve","itemType":"risk","itemTitle":"Illegal processing of personal or sensitive data","kind":"related"},{"templateSourceId":"coworkcanvas:template:policy-change","templateName":"Policy Change","nodeId":"approve","itemType":"risk","itemTitle":"Improper business or market practices","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-risk-assessment","itemType":"risk","itemTitle":"Inaccurate, unreliable or hallucinated AI outputs","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-risk-assessment","itemType":"risk","itemTitle":"Inadequate board and management oversight of risk and control","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-review-closure","itemType":"risk","itemTitle":"Inadequate on-call coverage misses customer SLA commitments","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","nodeId":"system-review-closure","itemType":"risk","itemTitle":"Inadequate or absent risk assessment process","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-report-evaluation","itemType":"risk","itemTitle":"Inadequate physical protection and access controls","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-report-evaluation","itemType":"risk","itemTitle":"Inadequate security awareness and training","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-review-closure","itemType":"risk","itemTitle":"Inadequate transparency, notice and deceptive privacy communications","kind":"related"},{"templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","nodeId":"soc-review-closure","itemType":"risk","itemTitle":"Income / property / indirect tax misstatement (ASC 740)","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"risk","itemTitle":"Incomplete asset inventory and classification","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"risk","itemTitle":"Ineffective ICFR / undisclosed material weakness","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"risk","itemTitle":"Insufficient personnel screening and vetting","kind":"related"},{"templateSourceId":"coworkcanvas:template:fsli-significance-assessment","templateName":"FSLI Significance Assessment","nodeId":"fsli-assessment-closure","itemType":"risk","itemTitle":"Intellectual property loss or infringement","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-applicability","itemType":"risk","itemTitle":"Internal fraud - asset misappropriation, embezzlement, forgery","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-applicability","itemType":"risk","itemTitle":"Internet-exposed or misconfigured systems","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-mapping-closure","itemType":"risk","itemTitle":"Inventory / critical-spares valuation or obsolescence error","kind":"related"},{"templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","templateName":"Requirement Applicability & Control Mapping","nodeId":"requirement-mapping-closure","itemType":"risk","itemTitle":"Lack of independent audit and compliance review","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-applicability","itemType":"risk","itemTitle":"Leaked CI/CD pipeline secret grants environment access","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-applicability","itemType":"risk","itemTitle":"Lease accounting error (ASC 842) on ground/building leases","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-intake-closure","itemType":"risk","itemTitle":"Litigation, investigation and enforcement exposure","kind":"related"},{"templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","templateName":"Regulatory Change Intake & Impact Assessment","nodeId":"change-intake-closure","itemType":"risk","itemTitle":"Loss of essential services (power, HVAC, telecoms)","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-scope","itemType":"risk","itemTitle":"Loss of system maintainability","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-closure","itemType":"risk","itemTitle":"Loss of utility power without N+1 failover","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-closure","itemType":"risk","itemTitle":"Malicious supply-chain injection of tampered hardware/software","kind":"related"},{"templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","templateName":"Obligation Implementation & Adoption","nodeId":"adoption-closure","itemType":"risk","itemTitle":"Malware delivery, insertion and compromise of systems","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"conformance-testing","itemType":"risk","itemTitle":"Manual journal entries and management-override risk","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"conformance-testing","itemType":"risk","itemTitle":"Material weakness in ICFR undermines IPO readiness","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"monitoring-closure","itemType":"risk","itemTitle":"Misconfigured Model Home Data Lake resource exposes data publicly","kind":"related"},{"templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","templateName":"Compliance Monitoring & Attestation","nodeId":"monitoring-closure","itemType":"risk","itemTitle":"Missing MFA on Lucille Identity Cloud enables account takeover","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"access-approval","itemType":"risk","itemTitle":"Missing or insufficient logging and audit trails","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"access-approval","itemType":"risk","itemTitle":"Missing or insufficient security and privacy policies","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"onboarding-closure","itemType":"risk","itemTitle":"Missing role-based and ongoing security/privacy training","kind":"related"},{"templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","templateName":"Onboarding & Access Provisioning","nodeId":"onboarding-closure","itemType":"risk","itemTitle":"Missing security terms in contracts and no disciplinary process","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-approval","itemType":"risk","itemTitle":"Model Home Data Lake outage without tested recovery causes prolonged downtime","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-approval","itemType":"risk","itemTitle":"No or insufficient incident-response procedures","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-closure","itemType":"risk","itemTitle":"No security monitoring or supervision of privileged activity","kind":"related"},{"templateSourceId":"coworkcanvas:template:transfer-access-modification","templateName":"Transfer & Access Modification","nodeId":"modification-closure","itemType":"risk","itemTitle":"Non-compliance with energy-efficiency reporting","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-execution","itemType":"risk","itemTitle":"Orphaned or stale Lucille Identity Cloud accounts retain access","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-execution","itemType":"risk","itemTitle":"Over-privileged Model Home Data Lake IAM principal is compromised","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-closure","itemType":"risk","itemTitle":"Over-retention of PII in Cloud SQL breaches privacy commitments","kind":"related"},{"templateSourceId":"coworkcanvas:template:offboarding-access-revocation","templateName":"Offboarding & Access Revocation","nodeId":"revocation-closure","itemType":"risk","itemTitle":"Overstatement of assets/revenue (existence & occurrence)","kind":"related"},{"templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review","nodeId":"uar-distribution","itemType":"risk","itemTitle":"Phishing, spear-phishing and social engineering","kind":"related"},{"templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review","nodeId":"uar-distribution","itemType":"risk","itemTitle":"Physical and cyber-physical attacks on facilities and infrastructure","kind":"related"},{"templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review","nodeId":"uar-closure","itemType":"risk","itemTitle":"Physical climate risk to facilities and supply chains","kind":"related"},{"templateSourceId":"coworkcanvas:template:periodic-user-access-review","templateName":"Periodic User Access Review","nodeId":"uar-closure","itemType":"risk","itemTitle":"Physical damage to assets from disaster, terrorism or vandalism","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-justification","itemType":"risk","itemTitle":"Poor configuration management and insecure baseline drift","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-justification","itemType":"risk","itemTitle":"Poor network architecture and unprotected public connections","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-closure","itemType":"risk","itemTitle":"Power imbalance and loss of self-determination over personal data","kind":"related"},{"templateSourceId":"coworkcanvas:template:privileged-access-review","templateName":"Privileged Access Review","nodeId":"pa-closure","itemType":"risk","itemTitle":"Privacy-program non-compliance (GDPR, CCPA, state laws)","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-approval","itemType":"risk","itemTitle":"REIT carve-out & sale-leaseback accounting error","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-approval","itemType":"risk","itemTitle":"Ransomware disrupting operations and data availability","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-closure","itemType":"risk","itemTitle":"Re-identification and unanticipated revelation from data","kind":"related"},{"templateSourceId":"coworkcanvas:template:change-request-approval-migration","templateName":"Change Request, Approval & Migration","nodeId":"change-closure","itemType":"risk","itemTitle":"Refinancing risk at facility maturity","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-intake","itemType":"risk","itemTitle":"Remote spying and shoulder-surfing of screens/documents","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-closure","itemType":"risk","itemTitle":"Remote-work, mobile and split-tunneling exposure","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-closure","itemType":"risk","itemTitle":"Residual data on improperly disposed or re-used media","kind":"related"},{"templateSourceId":"coworkcanvas:template:emergency-change","templateName":"Emergency Change","nodeId":"emergency-closure","itemType":"risk","itemTitle":"Revenue recognized incorrectly on complex colocation contracts (ASC 606)","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-requirements","itemType":"risk","itemTitle":"Revenue sustainability and cash flow constraints","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-closure","itemType":"risk","itemTitle":"Secrets sprawl outside Secret Manager are leaked","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-closure","itemType":"risk","itemTitle":"Segregation-of-duties conflicts across Banana ERP / Banana ERP","kind":"related"},{"templateSourceId":"coworkcanvas:template:new-system-implementation","templateName":"New System Implementation (SDLC)","nodeId":"sdlc-closure","itemType":"risk","itemTitle":"Sensitive data leaked through uncontrolled transfer channels","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-scope","itemType":"risk","itemTitle":"Single code reviewer dependency creates change-management bottleneck and SoD failure on reviewer's own changes","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-closure","itemType":"risk","itemTitle":"Single-site / single-region / single-supply concentration","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-closure","itemType":"risk","itemTitle":"Single-site outage without DR failover","kind":"related"},{"templateSourceId":"coworkcanvas:template:data-conversion-migration","templateName":"Data Conversion & Migration","nodeId":"conversion-closure","itemType":"risk","itemTitle":"Single-source dependency on cooling OEM","kind":"related"},{"templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring","nodeId":"batch-closure","itemType":"risk","itemTitle":"Software and information-system failure","kind":"related"},{"templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring","nodeId":"batch-closure","itemType":"risk","itemTitle":"Stakeholder trust and social-license erosion","kind":"related"},{"templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring","nodeId":"batch-closure","itemType":"risk","itemTitle":"Stock-based compensation expense misstated (ASC 718)","kind":"related"},{"templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","templateName":"Job Scheduling & Batch Monitoring","nodeId":"batch-closure","itemType":"risk","itemTitle":"Subcontractor fails security due-diligence","kind":"related"},{"templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing","nodeId":"backup-scope","itemType":"risk","itemTitle":"Subservice organization reliance failure (SOC 1 CUECs)","kind":"related"},{"templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing","nodeId":"backup-closure","itemType":"risk","itemTitle":"Theft of equipment, media or unattended devices","kind":"related"},{"templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing","nodeId":"backup-closure","itemType":"risk","itemTitle":"Third-party / vendor concentration & SOC-report gap","kind":"related"},{"templateSourceId":"coworkcanvas:template:backup-recovery-testing","templateName":"Backup & Recovery Testing","nodeId":"backup-closure","itemType":"risk","itemTitle":"Third-party compliance failure creating vicarious liability","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-response","itemType":"risk","itemTitle":"Unapproved change introduces financial-system error","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-response","itemType":"risk","itemTitle":"Unauthorized access to customer environments / white space","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-closure","itemType":"risk","itemTitle":"Unauthorized activity - rogue trading, position mismarking, concealment","kind":"related"},{"templateSourceId":"coworkcanvas:template:incident-problem-management","templateName":"Incident & Problem Management","nodeId":"incident-closure","itemType":"risk","itemTitle":"Unauthorized disclosure / breach of sensitive information","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-controls","itemType":"risk","itemTitle":"Unauthorized or inaccurate payroll (Never Nude HR Platform)","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-controls","itemType":"risk","itemTitle":"Unauthorized use of equipment and unauthorized access escalation","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-closure","itemType":"risk","itemTitle":"Uncontrolled copying to removable media / unmanaged software installs","kind":"related"},{"templateSourceId":"coworkcanvas:template:euc-inventory-validation","templateName":"End-User Computing Inventory & Validation","nodeId":"euc-closure","itemType":"risk","itemTitle":"Understatement of liabilities/expenses (completeness)","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"walkthrough-questions","itemType":"risk","itemTitle":"Undetected anomalous export from Cloud SQL","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"rcm","itemType":"risk","itemTitle":"Unencrypted or unmasked PII in Cloud SQL is exfiltrated","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-planning-scoping","templateName":"Audit Planning & Scoping","nodeId":"rcm","itemType":"risk","itemTitle":"Unhedged FX exposure on cross-border debt","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"execute-fieldwork","itemType":"risk","itemTitle":"Unlawful retention or premature deletion of records","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"execute-fieldwork","itemType":"risk","itemTitle":"Unlogged Model Home Data Lake activity prevents breach detection","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"findings-clearance","itemType":"risk","itemTitle":"Unmanaged third-party API token is leaked","kind":"related"},{"templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","nodeId":"reporting-closure","itemType":"risk","itemTitle":"Unreviewed change merged and deployed via Model Home Data Lake","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-scope-risk","itemType":"risk","itemTitle":"User error and mishandling of sensitive information","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-scope-risk","itemType":"risk","itemTitle":"Valuation error — PPA, goodwill/intangibles or 409A equity","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-planning-closure","itemType":"risk","itemTitle":"Vulnerabilities introduced during software development","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-annual-planning","templateName":"SOX Annual Planning & Risk Assessment","nodeId":"sox-planning-closure","itemType":"risk","itemTitle":"Weak account provisioning/de-registration and access review","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"roll-forward-strategy","itemType":"risk","itemTitle":"Weak authentication and password management","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"roll-forward-strategy","itemType":"risk","itemTitle":"Weak internal control environment enabling fraud and error","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"year-end-plan-closure","itemType":"risk","itemTitle":"Weak or absent encryption and key management","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-ye-planning","templateName":"Year-End Planning & Roll-Forward","nodeId":"year-end-plan-closure","itemType":"risk","itemTitle":"Weak supplier security requirements and monitoring","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"severity-aggregation","itemType":"risk","itemTitle":"Workplace health, safety and well-being failures","kind":"related"},{"templateSourceId":"coworkcanvas:template:sox-deficiency-eval","templateName":"Deficiency Evaluation & Committee","nodeId":"severity-aggregation","itemType":"risk","itemTitle":"Zero-day exploitation","kind":"related"}],"workflows":[{"sourceTemplateId":"coworkcanvas:template:audit-planning-scoping","name":"Audit Planning & Scoping","description":"Runs on the existing audit item. Plan an audit engagement from four independent starting points — management self-identified issues, the external threat and regulatory landscape, prior audit history, and the in-scope risk and control set — which converge into the walkthrough question set, the walkthrough, and the approved risk and control matrix that governs fieldwork. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"audit","autoCreateOnItem":true,"nodes":[{"id":"walkthrough-questions","data":{"label":"Draft the walkthrough question set","kind":"task","instructions":"**Objective**\nDraft the walkthrough question set. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the engagement mandate, the self-identification form issued to control owners, the obligations register with regulator and incident reporting, prior audit reports and open Issues for the area, and the risk and control registers.\n2. Use the self-identified issues and the owners who reported nothing, the external candidate risks and near-term obligations, the prior coverage and open findings, and the in-scope risk and control set with its unmapped risks and orphaned controls.\n\n**Procedure**\n1. Use current management self-identifications first. Only when a named control owner who is not executing this workflow must supply missing facts, prepare a form limited to those facts; request or chase responses only through an authorized channel. Restate each dated external source as a candidate risk. List prior coverage, carry open findings forward, and decide what can be relied on. Select the in-scope risks with a reason for each, list their asserted controls, and note the mapping gaps.\n2. Derive questions from each input and keep the origin attached, ask how the control actually operates, who performs it, what evidence it leaves, and what happens when it fails or is bypassed rather than whether it exists, include a question for every contradiction between the inputs, and sequence by process flow with an interviewee and evidence request on each.\n\nVerify team competence, disclose independence impairments and resolve safeguards before fieldwork; agree objectives, criteria, period, scope and materiality.\n\n**Record in AssureSwarm**\n1. Record the response status, the issues disclosed and the owners who did not respond; the sources reviewed, candidate risks and near-term obligations; prior coverage, open findings carried forward and the prior conclusions relied on; and the in-scope risks with rationale, their asserted controls, and the mapping gaps. Raise new items as Issues and link the risks and controls to this audit.\n2. Record the question set with the source of each question, the assigned interviewee, and the evidence to request, together with the interviewees, sessions, and dates. Also record evidence to request in the room.\n\n**Exit criteria**\nEngagement lead provides expertise: Every owner has responded or is recorded as non-responsive, the external view is sourced and dated, each reliance on a prior conclusion has a basis, the risk set is justified with its controls, and every contradiction between the inputs is a walkthrough question, not a conclusion. Every question traces to a planning input, contradictions between inputs are represented, each question has an interviewee and evidence request, and an approver accepted the instrument before the business is engaged.","requiredApprovals":1,"controls":[],"type":"TASK"},"position":{"x":0,"y":0}},{"id":"rcm","data":{"label":"Build the risk and control matrix","kind":"task","instructions":"**Objective**\nBuild the risk and control matrix. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved question set, the in-scope risk and control set, process narratives, system screens, reports, and evidence produced in the room, and the interviewees confirmed for each session.\n2. Use the in-scope risk and control set, the walkthrough observations and deviations, prior testing results and reliance decisions, and the external obligations in scope.\n\n**Procedure**\n1. Walk the process in operating order rather than register order, follow at least one live item through every handoff, system, approval, and exception path, ask the assigned questions and follow each answer where it goes, observe the control operating rather than accepting a description, and capture who can override and what an override leaves behind.\n2. Record for each in-scope risk the controls that address it with owner, frequency, automation, and key-control status, conclude on design from what was observed rather than asserted, record a design gap where no control addresses a risk, define the testing approach and population for each control to be tested, and route gaps to Issues.\n\n**Record in AssureSwarm**\n1. Record the sessions, participants, item traced, observations against each question, deviations between asserted and observed design, and the evidence obtained or still outstanding. Also record walkthrough date; evidence still outstanding, with owner and date.\n2. Record the matrix row by row with risk, control, owner, design conclusion, testing approach, and population, link the risks and controls to this audit, and raise Issues for the design gaps. Also record matrix summary - risk, control, owner, design conclusion, testing approach; design gaps raised as Issues; planning decision.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: The process has been observed end to end with at least one item traced through, every approved question is answered or recorded as unanswered with a reason, deviations are documented, and outstanding evidence requests have owners and dates. Every in-scope risk has either a mapped control with a design conclusion or a recorded design gap, the testing approach is defined for each control to be tested, and The authorized reviewer have accepted the matrix as the basis for fieldwork.","requiredApprovals":1,"controls":["UC-AUDIT-05","UC-AUDIT-11","UC-AUDIT-12"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-walkthrough-questions-rcm","source":"walkthrough-questions","target":"rcm"}],"metadata":{"kind":"audit-planning-scoping","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:audit-planning-scoping","sourceNodeMap":{"planning-inputs":"walkthrough-questions","walkthrough-questions":"walkthrough-questions","walkthrough":"rcm","rcm":"rcm"},"legacyNodeOrder":["planning-inputs","walkthrough-questions","walkthrough","rcm"],"legacyRequiredApprovals":{"planning-inputs":0,"walkthrough-questions":1,"walkthrough":0,"rcm":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"audit"},"roles":[{"id":"reviewer-1","description":"Engagement lead. Draft the walkthrough question set.","nodeIds":["walkthrough-questions"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent audit supervisor. Build the risk and control matrix.","nodeIds":["rcm"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:audit-engagement-planning"}]},"teams":["internal-audit"],"capabilities":["audit-planning-scoping"]}},{"sourceTemplateId":"coworkcanvas:template:audit-fieldwork-reporting","name":"Audit Fieldwork, Findings & Reporting","description":"Runs on the existing audit item. Execute approved audit procedures, evaluate and clear observations, issue a supported report, and close the engagement record with tracked actions. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"audit","autoCreateOnItem":false,"nodes":[{"id":"execute-fieldwork","data":{"label":"Execute and review fieldwork","kind":"task","instructions":"**Objective**\nExecute and review fieldwork. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved planning record, work program, risk-to-procedure mapping, data requests, population reconciliations, independence confirmations, stakeholder contacts, and known constraints.\n2. Use the approved program, reconciled populations, source evidence, interviews, observations, system data, criteria, prior work, methodology, and reviewer instructions.\n\n**Procedure**\n1. Validate evidence access and population completeness, brief the team on documentation and escalation expectations, assign procedures and reviewers, resolve planning gaps, and record any approved scope or timing change.\n2. Execute each procedure as designed, retain selection rationale, corroborate representations, investigate anomalies, cross-reference evidence, quantify deviations, document limitations, and obtain timely supervisory review and clearance.\n\n**Record in AssureSwarm**\n1. Capture the plan reference, procedure assignments, evidence and data status, reconciled populations, review responsibilities, open requests, scope changes, constraints, owners, and due dates. Also record approved plan reference; readiness notes.\n2. Link the workpaper index and individual evidence records, identify preparer and reviewer, dates, population and sample, procedure performed, evidence considered, exceptions, review notes, responses, and disposition. Also record workpaper index reference.\n\n**Exit criteria**\nAudit supervisor provides expertise: The team can execute each approved procedure from authoritative inputs, material access gaps are resolved or escalated, and deviations from plan are formally visible. Planned work is complete or approved as modified, workpapers support recorded results, review notes are cleared or assigned, and potential observations are ready for evaluation.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"findings-clearance","data":{"label":"Evaluate and clear findings","kind":"task","instructions":"**Objective**\nEvaluate and clear findings. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use reviewed workpapers, exceptions, criteria, quantified populations, root-cause analysis, corroborating and contrary evidence, prior issues, management responses, and proposed corrective actions.\n\n**Procedure**\n1. Validate factual accuracy, assess significance and pervasiveness, distinguish isolated deviations from systemic causes, challenge unsupported management explanations, conduct clearance discussions, and define practical owned actions and dates.\n\n**Record in AssureSwarm**\n1. Document each finding or cleared observation, evidence, criteria, cause, risk and impact, rating basis, management response, agreed or disputed action, owner, due date, and approval decision. Also record finding disposition.\n\n**Exit criteria**\nManagement and audit lead provides expertise: An approver accepts each disposition and supporting rationale, disagreements and limitations remain visible, and reportable matters are factually cleared without suppressing contrary evidence.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":160}},{"id":"reporting-closure","data":{"label":"Approve report and engagement closure","kind":"task","instructions":"**Objective**\nApprove report and engagement closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved plan, completed workpapers, cleared findings, management responses, quality-review notes, report draft, scope changes, limitations, distribution list, and action tracking records.\n\n**Procedure**\n1. Verify report statements trace to workpapers, conclusions stay within scope and evidence, ratings are consistent, responses and disagreements are accurate, actions are linked, and final quality and authorization reviews are complete.\n\n**Record in AssureSwarm**\n1. Capture the authorized reviewer, final report reference and date, distribution, scope and limitations, findings and actions, unresolved disagreements, owners, due dates, follow-up route, and archive index.\n\n**Exit criteria**\nChief audit executive provides approval: The authorized reviewer authorize the supported report and complete engagement record; the workflow itself does not create an audit opinion beyond the expressly approved report language.","requiredApprovals":1,"controls":["UC-AUDIT-13","UC-AUDIT-14","UC-AUDIT-16"],"type":"TASK"},"position":{"x":0,"y":320}}],"edges":[{"id":"e-execute-fieldwork-findings-clearance","source":"execute-fieldwork","target":"findings-clearance"},{"id":"e-findings-clearance-reporting-closure","source":"findings-clearance","target":"reporting-closure"}],"metadata":{"kind":"audit-fieldwork-reporting","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:audit-fieldwork-findings-reporting","sourceNodeMap":{"fieldwork-readiness":"execute-fieldwork","execute-fieldwork":"execute-fieldwork","findings-clearance":"findings-clearance","reporting-closure":"reporting-closure"},"legacyNodeOrder":["fieldwork-readiness","execute-fieldwork","findings-clearance","reporting-closure"],"legacyRequiredApprovals":{"fieldwork-readiness":0,"execute-fieldwork":0,"findings-clearance":1,"reporting-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"audit"},"roles":[{"id":"reviewer-1","description":"Audit supervisor. Execute and review fieldwork.","nodeIds":["execute-fieldwork"],"contribution":"expertise"},{"id":"reviewer-2","description":"Management and audit lead. Evaluate and clear findings.","nodeIds":["findings-clearance"],"contribution":"expertise"},{"id":"reviewer-3","description":"Chief audit executive. Approve report and engagement closure.","nodeIds":["reporting-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:audit-engagement-lifecycle"}]},"teams":["internal-audit"],"capabilities":["audit-fieldwork-reporting"]}},{"sourceTemplateId":"coworkcanvas:template:sox-annual-planning","name":"SOX Annual Planning & Risk Assessment","description":"Runs on the existing audit item. Plan the annual SOX program through materiality, entity and account scoping, risk and control mapping, reliance strategy, calendar, and governance approval. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"audit","autoCreateOnItem":false,"nodes":[{"id":"sox-scope-risk","data":{"label":"Assess ICFR scope and risks","kind":"task","instructions":"**Objective**\nAssess ICFR scope and risks. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review financial plans and statements, approved materiality, legal entities, locations, acquisitions and divestitures, systems, service organizations, prior scope, deficiencies, auditor strategy, and regulatory deadlines.\n2. Use reconciled financial data, FSLI significance assessments, quantitative coverage, qualitative factors, transaction classes, risk assessments, entity-level controls, IT landscape, prior errors, and deficiencies.\n\n**Procedure**\n1. Reconcile entity and reporting data, validate planning thresholds and ownership, identify significant changes, set the annual calendar and decision rights, and define how scope or risk changes will be approved.\n2. Calculate coverage, evaluate qualitative significance and aggregation, identify relevant assertions and reasonable misstatement risks, map processes and systems, consider fraud and management override, and explain all inclusions and exclusions.\n\n**Record in AssureSwarm**\n1. Capture fiscal year, reporting perimeter, materiality reference and thresholds, governance roles, methodology, milestones, changes, dependencies, assumptions, data limitations, and responsible owners.\n2. Document calculations, scoped entities, locations, FSLIs, disclosures, assertions, processes, systems, fraud risks, qualitative judgments, exclusions, coverage gaps, and reassessment triggers. Also record scope analysis reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The planning basis agrees to authoritative reporting information, roles and thresholds are approved inputs, and known changes or limitations are visible for scoping analysis. The proposed scope is reproducible and risk-based, material relationships and exclusions are explicit, and unresolved data or mapping gaps are assigned before program design.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"sox-planning-closure","data":{"label":"Approve annual SOX plan","kind":"task","instructions":"**Objective**\nApprove annual SOX plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use proposed scope, risk-control matrices, control frequency and ownership, prior testing, deficiencies, internal audit and external auditor plans, service-auditor reports, resources, specialists, and reporting dates.\n2. Review materiality, scope calculations, risk assessments, program design, staffing, calendar, external auditor feedback, governance comments, limitations, and open data or mapping actions.\n\n**Procedure**\n1. Set testing timing and extent, allocate controls and locations, define roll-forward and year-end work, coordinate reliance and PBC needs, assign reviewers, plan deficiency escalation, and test feasibility against deadlines and capacity.\n2. Challenge risk-to-coverage alignment, confirm key changes and exclusions are addressed, reconcile populations and milestones, verify ownership and escalation, and return unsupported scope or reliance assumptions for correction.\n\n**Record in AssureSwarm**\n1. Capture the control universe, coverage plan, timing, reliance assumptions, owners, resources, milestones, quality reviews, committee calendar, auditor coordination, decision, and required revisions. Also record program decision.\n2. Document the authorized reviewer, final scope and coverage references, methodology, program calendar, resources, reliance, limitations, open actions, owners, due dates, and reassessment triggers. Also record annual SOX plan summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts a feasible program responsive to scoped risks, reliance and exclusions are supportable, and unresolved capacity or coverage gaps have explicit escalation. The authorized reviewer accepts the annual management plan and authorize its documented work; planning closure is not a management assertion, audit opinion, or operating-effectiveness conclusion.","requiredApprovals":1,"controls":["UC-AUDIT-12"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-sox-scope-risk-sox-planning-closure","source":"sox-scope-risk","target":"sox-planning-closure"}],"metadata":{"kind":"sox-annual-planning","source":"studio-seed","framework":"sox","canonicalSourceTemplateId":"workflow-library:sox-annual-program-planning","sourceNodeMap":{"sox-planning-basis":"sox-scope-risk","sox-scope-risk":"sox-scope-risk","sox-program-design":"sox-planning-closure","sox-planning-closure":"sox-planning-closure"},"legacyNodeOrder":["sox-planning-basis","sox-scope-risk","sox-program-design","sox-planning-closure"],"legacyRequiredApprovals":{"sox-planning-basis":0,"sox-scope-risk":0,"sox-program-design":1,"sox-planning-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"audit"},"roles":[{"id":"reviewer-1","description":"Engagement lead. Assess ICFR scope and risks.","nodeIds":["sox-scope-risk"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent audit supervisor. Approve annual SOX plan.","nodeIds":["sox-planning-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-annual-icfr-scoping-risk-assessment"}]},"teams":["finance"],"capabilities":["sox-annual-planning"]}},{"sourceTemplateId":"coworkcanvas:template:sox-ye-planning","name":"Year-End Planning & Roll-Forward","description":"Runs on the existing audit item. Plan and govern SOX year-end and roll-forward coverage based on interim results, changes, deficiencies, remaining populations, and reporting deadlines. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"audit","autoCreateOnItem":false,"nodes":[{"id":"roll-forward-strategy","data":{"label":"Design roll-forward and year-end work","kind":"task","instructions":"**Objective**\nDesign roll-forward and year-end work. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review annual scope and plan, interim testing tracker, reviewed workpapers, exceptions, deficiencies, remediation, changes, new entities or systems, auditor requests, control calendars, and close timetable.\n2. Use reconciled interim status, control frequencies, last test dates, remaining populations, risk and assertion mapping, changes, exceptions, deficiencies, remediation evidence, close activities, and methodology.\n\n**Procedure**\n1. Reconcile planned controls to completed and reviewed work, identify remaining periods and populations, confirm unresolved exceptions and remediation status, assess changes since interim, and validate owner availability and due dates.\n2. Determine where inquiry and change confirmation are sufficient versus additional selection or reperformance, plan year-end-only controls, define population reconciliation, schedule remediation retests, and avoid unsupported reliance on elapsed interim work.\n\n**Record in AssureSwarm**\n1. Capture the year-end period, interim status reference, completed and remaining coverage, changes, exceptions, deficiencies, remediation status, missing evidence, owners, and critical dates.\n2. Document the procedure and basis by control, remaining period, population, selection method, change checks, year-end evidence, remediation dependencies, preparer, reviewer, and due date. Also record roll-forward basis.\n\n**Exit criteria**\nEngagement lead provides expertise: The interim record reconciles to the approved plan, remaining work is accurately identified, and material changes or gaps are visible for risk reassessment. Every in-scope control has a risk-responsive year-end disposition, rationale is specific to evidence and change, and unaddressed coverage gaps have owners.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"year-end-plan-closure","data":{"label":"Approve year-end plan","kind":"task","instructions":"**Objective**\nApprove year-end plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the control-specific strategy, PBC tracker, population owners, financial close calendar, staffing and specialists, external auditor coordination, open deficiencies, remediation dates, and committee schedule.\n2. Review all stage records, interim tracker, control strategies, readiness decision, approved conditions, PBC and review calendars, deficiency status, auditor coordination, and unresolved limitations.\n\n**Procedure**\n1. Challenge feasibility and sequencing, confirm access and accountable owners, prioritize high-risk and year-end-only controls, set escalation thresholds, resolve conflicts with close activities, and document conditions that could prevent timely completion.\n2. Trace remaining work to in-scope controls and risks, verify strategies reflect frequency and change, confirm conditions are assigned, reconcile dates and ownership, and return unsupported shortcuts or missing coverage for correction.\n\n**Record in AssureSwarm**\n1. Capture the readiness decision, conditions, critical path, evidence owners, staffing, review schedule, auditor dependencies, deficiency and remediation milestones, escalations, and due dates.\n2. Document the authorized reviewer, final year-end plan reference, remaining coverage, critical dates, resources, conditions, deficiencies, remediation and auditor dependencies, owners, and escalation route. Also record year-end plan summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts a feasible year-end execution path or records specific blockers, conditions, owners, and escalation before work is represented as ready. The authorized reviewer authorize the documented year-end work, while plan closure does not establish management assessment, an audit opinion, or operating effectiveness.","requiredApprovals":1,"controls":["UC-AUDIT-12"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-roll-forward-strategy-year-end-plan-closure","source":"roll-forward-strategy","target":"year-end-plan-closure"}],"metadata":{"kind":"sox-ye-planning","source":"studio-seed","framework":"sox","canonicalSourceTemplateId":"workflow-library:sox-year-end-program-planning","sourceNodeMap":{"year-end-status":"roll-forward-strategy","roll-forward-strategy":"roll-forward-strategy","year-end-readiness-gate":"year-end-plan-closure","year-end-plan-closure":"year-end-plan-closure"},"legacyNodeOrder":["year-end-status","roll-forward-strategy","year-end-readiness-gate","year-end-plan-closure"],"legacyRequiredApprovals":{"year-end-status":0,"roll-forward-strategy":0,"year-end-readiness-gate":1,"year-end-plan-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"audit"},"roles":[{"id":"reviewer-1","description":"Engagement lead. Design roll-forward and year-end work.","nodeIds":["roll-forward-strategy"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent audit supervisor. Approve year-end plan.","nodeIds":["year-end-plan-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-period-end-roll-forward-testing"}]},"teams":["finance"],"capabilities":["sox-ye-planning"]}},{"sourceTemplateId":"coworkcanvas:template:sox-deficiency-eval","name":"Deficiency Evaluation & Committee","description":"Runs on the existing audit item. Evaluate SOX control deficiencies individually and in aggregate, obtain management challenge, and govern committee communication and disposition. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"audit","autoCreateOnItem":false,"nodes":[{"id":"severity-aggregation","data":{"label":"Assess severity and aggregation","kind":"task","instructions":"**Objective**\nAssess severity and aggregation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review failed test or monitoring work, control description, exceptions and population, risk and assertion mappings, process walkthrough, owner response, prior issues, compensating activities, and supporting evidence.\n2. Use validated facts, materiality, affected accounts and assertions, transaction volume, exposure period, compensating controls, possible misstatement scenarios, related deficiencies, prior errors, and auditor observations.\n\n**Procedure**\n1. Reperform the fact pattern, separate evidence gaps from control failures, quantify known exceptions and affected periods, confirm whether the issue is isolated or systemic, identify root cause, and search for related deficiencies.\n2. Develop reasonably possible misstatement scenarios, evaluate magnitude and likelihood, assess precision and evidence for compensating controls, consider aggregation by cause and assertion, compare indicators, and document contrary factors.\n\n**Record in AssureSwarm**\n1. Capture the deficiency reference, validated condition, criteria, cause, affected controls and assertions, population and exceptions, period, locations, systems, owner response, limitations, and immediate actions. Also record validated fact summary.\n2. Document proposed severity, scenario calculations, likelihood and magnitude rationale, compensating-control analysis, aggregation set, indicators considered, differences of view, and additional evidence needed.\n\n**Exit criteria**\nSOX technical evaluator provides expertise: The factual record is supported and complete enough for severity analysis, disputed facts remain explicit, and related or recurring matters are identified for aggregation. The proposed severity is reproducible from evidence and applicable criteria, aggregation has been explicitly addressed, and unresolved judgments are ready for management challenge.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"deficiency-evaluation-closure","data":{"label":"Approve deficiency evaluation","kind":"task","instructions":"**Objective**\nApprove deficiency evaluation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the fact record, severity analysis, aggregation inventory, management response, remediation plan, disclosure considerations, external auditor view where available, and draft governance materials.\n2. Review all stage evidence, final calculations and criteria, committee disposition, management response, auditor communication, remediation plan, disclosures, related deficiencies, and outstanding limitations.\n\n**Procedure**\n1. Present evidence and judgments, record questions and dissent, challenge optimistic assumptions and unsupported compensating controls, confirm communication requirements and timing, and route material changes back through evaluation.\n2. Verify the final severity follows supported facts, aggregation and dissent are addressed, required communications occurred, linked issue and remediation records agree, and return any unsupported or inconsistent disposition.\n\n**Record in AssureSwarm**\n1. Capture attendees, date, materials, questions, management and committee views, disposition, revised severity or conditions, disclosure and auditor communications, remediation commitments, owners, and due dates.\n2. Document the authorized reviewer, final severity and rationale, aggregation set, committee date and decision, communications, disclosure impact, remediation owner and due date, reassessment triggers, and links. Also record final evaluation summary.\n\n**Exit criteria**\nManagement and audit committee provides approval: An approver confirms required governance review is evidenced, the accepted or revised evaluation is clear, and dissent or unresolved reporting implications remain visible. The authorized reviewer accepts the documented management evaluation and governance record; workflow completion alone does not constitute management assertion or an auditor conclusion.","requiredApprovals":1,"controls":["UC-RISK-14","UC-GOV-21"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-severity-aggregation-deficiency-evaluation-closure","source":"severity-aggregation","target":"deficiency-evaluation-closure"}],"metadata":{"kind":"sox-deficiency-eval","source":"studio-seed","framework":"sox","canonicalSourceTemplateId":"workflow-library:sox-program-deficiency-committee-review","sourceNodeMap":{"deficiency-intake":"severity-aggregation","severity-aggregation":"severity-aggregation","management-committee-review":"deficiency-evaluation-closure","deficiency-evaluation-closure":"deficiency-evaluation-closure"},"legacyNodeOrder":["deficiency-intake","severity-aggregation","management-committee-review","deficiency-evaluation-closure"],"legacyRequiredApprovals":{"deficiency-intake":0,"severity-aggregation":0,"management-committee-review":1,"deficiency-evaluation-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"audit"},"roles":[{"id":"reviewer-1","description":"SOX technical evaluator. Assess severity and aggregation.","nodeIds":["severity-aggregation"],"contribution":"expertise"},{"id":"reviewer-2","description":"Management and audit committee. Approve deficiency evaluation.","nodeIds":["deficiency-evaluation-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-deficiency-aggregation-evaluation"}]},"teams":["finance"],"capabilities":["sox-deficiency-eval"]}},{"sourceTemplateId":"coworkcanvas:template:sox-mgmt-assessment","name":"Management Assessment & Assertion","description":"Runs on the existing audit item. Assemble and govern management’s annual ICFR assessment record, including scope, test results, deficiencies, certifications, disclosures, and assertion approval. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"audit","autoCreateOnItem":false,"nodes":[{"id":"assessment-synthesis","data":{"label":"Synthesize ICFR results","kind":"task","instructions":"**Objective**\nSynthesize ICFR results. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review approved SOX scope and plans, risk-control matrices, walkthroughs, testing trackers and workpapers, entity and IT coverage, service-auditor reports, sub-certifications, changes, and deficiency inventory.\n2. Use reviewed testing results, exceptions, deficiency evaluations, remediation and retests, entity-level and IT results, service-auditor reports, certifications, close controls, subsequent events, and disclosure drafts.\n\n**Procedure**\n1. Reconcile scoped controls to completed testing, identify missing reviews and evidence, validate entity and period coverage, confirm changes are reflected, inventory open deficiencies, and establish the assessment calendar and decision owners.\n2. Aggregate results by process and assertion, verify unresolved exceptions are captured, evaluate scope and evidence limitations, reconcile deficiency severity, consider subsequent changes, and draft conclusions tied to specific supporting records.\n\n**Record in AssureSwarm**\n1. Capture assessment period, scope reference, control and testing reconciliation, certifications, service-provider coverage, changes, deficiencies, missing work, reporting criteria, owners, and due dates. Also record approved scope reference.\n2. Link the results memorandum, summarize coverage and outcomes, list exceptions and deficiencies, limitations, remediation status, contradictory evidence, disclosure considerations, and remaining management judgments. Also record results memorandum reference.\n\n**Exit criteria**\nSOX assessment reviewer provides expertise: The assessment population reconciles to approved scope, incomplete evidence and review are visible, and management has a supportable basis for result synthesis. The synthesis is traceable to reviewed evidence, does not hide gaps or dissent, and all judgments requiring certification or disclosure review are explicit.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"management-assessment-closure","data":{"label":"Approve management assessment record","kind":"task","instructions":"**Objective**\nApprove management assessment record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the population reconciliation, results memorandum, final deficiency evaluations, certifications, disclosure drafts, remediation status, external auditor communications, legal input, and proposed assertion wording.\n2. Review all stage records, final results memorandum, signed certifications, approved assertion and disclosures, deficiency and remediation status, committee materials, auditor communications, and unresolved limitations.\n\n**Procedure**\n1. Challenge evidence sufficiency and scope, verify assertion language matches the evaluated criteria and period, reconcile material weakness determinations and disclosures, record dissent and conditions, and prohibit approval while material support remains incomplete.\n2. Trace material statements to evidence, verify approved versions and dates, confirm required governance and disclosures, reconcile linked records, and return the package if results, deficiencies, or assertion language conflict.\n\n**Record in AssureSwarm**\n1. Capture the decision, approvers, assertion and disclosure versions reviewed, evidence and criteria considered, conditions, dissent, unresolved items, communications, owners, and due dates. Also record assertion package decision.\n2. Document the authorized reviewer, final assessment and assertion references, period, criteria, scope, deficiencies, disclosure outcome, certifications, committee and auditor communications, limitations, and archive index. Also record management assessment summary.\n\n**Exit criteria**\nAuthorized management signatory provides approval: An approver accepts the package for final governance or records precise revisions and blockers; the workflow does not itself issue management’s formal assertion. The authorized reviewer accepts the support and governance record; only the separately approved management assertion carries its stated meaning, not workflow completion.","requiredApprovals":1,"controls":["UC-GOV-21"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-assessment-synthesis-management-assessment-closure","source":"assessment-synthesis","target":"management-assessment-closure"}],"metadata":{"kind":"sox-mgmt-assessment","source":"studio-seed","framework":"sox","canonicalSourceTemplateId":"workflow-library:sox-management-assessment-assertion","sourceNodeMap":{"assessment-population":"assessment-synthesis","assessment-synthesis":"assessment-synthesis","management-assertion-review":"management-assessment-closure","management-assessment-closure":"management-assessment-closure"},"legacyNodeOrder":["assessment-population","assessment-synthesis","management-assertion-review","management-assessment-closure"],"legacyRequiredApprovals":{"assessment-population":0,"assessment-synthesis":0,"management-assertion-review":1,"management-assessment-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"audit"},"roles":[{"id":"reviewer-1","description":"SOX assessment reviewer. Synthesize ICFR results.","nodeIds":["assessment-synthesis"],"contribution":"expertise"},{"id":"reviewer-2","description":"Authorized management signatory. Approve management assessment record.","nodeIds":["management-assessment-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-subcertification-cascade"}]},"teams":["finance"],"capabilities":["sox-mgmt-assessment"]}},{"sourceTemplateId":"coworkcanvas:template:sox-pbc","name":"External Audit Support & PBC","description":"Runs on the existing audit item. Govern external-audit PBC requests from intake and preparation through quality review, secure delivery, clarification, and complete request closure. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"audit","autoCreateOnItem":false,"nodes":[{"id":"pbc-request-closure","data":{"label":"Approve PBC request closure","kind":"task","instructions":"**Objective**\nApprove PBC request closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the auditor request list and correspondence, prior submissions, SOX scope, control and process records, data owners, retention requirements, confidentiality rules, and reporting calendar.\n2. Use the validated request, authoritative reports and documents, source-system extracts, report parameters, reconciliations, prior submissions, retention rules, and approved secure workspace.\n3. Review the request and clarification history, prepared package, reconciliation, source parameters, redactions, limitations, related submissions, legal or security restrictions, and delivery protocol.\n4. Review the released response, delivery evidence, auditor acknowledgment, follow-up questions, supplemental packages, dispute or restriction decisions, request tracker, and related SOX records.\n\n**Procedure**\n1. Clarify ambiguous wording and dates with the auditor, identify the authoritative source and preparer, detect duplicate or superseded requests, assess sensitive data, agree delivery format, and set preparation and review milestones.\n2. Generate or collect support with reproducible parameters, reconcile totals and populations, validate dates and identifiers, explain transformations, remove out-of-scope sensitive data, preserve source versions, and identify limitations.\n3. Reperform key reconciliations, inspect samples of source agreement, confirm no privileged or out-of-scope data is included, verify explanations are factual, approve the exact version, and transmit through the authorized channel.\n4. Confirm the tracker reflects the exact response and status, link all clarifications and supplements, ensure superseded versions cannot be mistaken for final, assign open questions, and preserve the secure audit trail.\n\n**Record in AssureSwarm**\n1. Capture request reference, exact scope, period, requested format, purpose, auditor contact, preparer, reviewer, source system, confidentiality, dependencies, due date, and clarification history. Also record requested population and period.\n2. Link the response package, source and query parameters, reconciliation, preparer and date, transformations, redactions, exceptions, limitations, version, and cross-references to related controls or workpapers. Also record prepared response reference.\n3. Capture the release decision, reviewer, approved version and hash or identifier, reconciliation checks, restrictions, delivery channel, recipient, timestamp, portal confirmation, and any required revision.\n4. Document the authorized reviewer, closure status, final package and delivery reference, auditor receipt, clarifications, supplemental versions, open items, owners, due dates, restrictions, and archive location. Also record request closure status.\n\n**Exit criteria**\nPBC release authority provides approval: The request is unambiguous and owned, sensitive handling is defined, duplicates are resolved, and the preparer can produce the requested support from an authoritative source. The response matches the request and authoritative records, reconciliation and handling are evidenced, and differences or limitations are explicit for quality review. An approver authorizes the exact package and secure delivery is evidenced, or the request remains held with specific revision or escalation requirements. The authorized reviewer accepts a complete request trail and accurate status; closure evidences request handling and does not imply auditor acceptance of management’s broader controls.","requiredApprovals":1,"controls":["UC-AUDIT-25"],"type":"TASK"},"position":{"x":0,"y":0}}],"edges":[],"metadata":{"kind":"sox-pbc","source":"studio-seed","framework":"sox","canonicalSourceTemplateId":"workflow-library:sox-external-audit-pbc-request","sourceNodeMap":{"pbc-intake":"pbc-request-closure","pbc-preparation":"pbc-request-closure","pbc-quality-release":"pbc-request-closure","pbc-request-closure":"pbc-request-closure"},"legacyNodeOrder":["pbc-intake","pbc-preparation","pbc-quality-release","pbc-request-closure"],"legacyRequiredApprovals":{"pbc-intake":0,"pbc-preparation":0,"pbc-quality-release":1,"pbc-request-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"audit"},"roles":[{"id":"reviewer-1","description":"PBC release authority. Approve PBC request closure.","nodeIds":["pbc-request-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed PBC package, delivery evidence and open clarifications for the auditor request owner and the company's approved PBC procedure"}]},"teams":["finance"],"capabilities":["sox-pbc"]}},{"sourceTemplateId":"coworkcanvas:template:soc2-readiness","name":"SOC 2 Trust Services Readiness","description":"Runs on the existing Audit engagement with its system description, service commitments, review period, control and risk registers, and available evidence; assesses CC1–CC9 design readiness and consumes reviewed companion assessments for selected optional Trust Services categories. Delivers the criterion-to-control mapping, criterion-level evidence and design conclusions, owned gap register, and approved SOC 2 readiness disposition to management for remediation and examination planning; Type II testing, management-owned PBC preparation and management assertion remain separate workflows.","itemTypeSlug":"audit","autoCreateOnItem":false,"nodes":[{"id":"soc2-criteria-mapping","data":{"label":"Map criteria, risks, and controls","kind":"task","instructions":"**Objective**\nMap criteria, risks, and controls. The engagement lead applies expertise to system boundaries, category applicability and complementary responsibilities.\n\n**Inputs**\n1. Review contracts and commitments, architecture and data flows, inventories, policies, risk assessments, vendor relationships, prior reports, incidents, change plans, and selected Trust Services Criteria.\n2. Use the approved boundary, criteria, risk register, control inventory, policies and procedures, architecture, vendor controls, customer responsibilities, prior findings, and available evidence.\n\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\nBefore execution, resolve the declared roles to named tenant users and verify native assignments and counts on every instantiated step. Assign two distinct people, the executive sponsor and security and compliance lead, to the assessment package. Assign a separate independent readiness reviewer who did not prepare or operate the assessed controls. Library role declarations do not assign users or enforce role membership; changing approvers may replace the required count, so recheck the two-person assignments after any change.\n\n**Procedure**\n1. Interview accountable owners, reconcile the system description to deployed services, identify carve-out or inclusive subservice treatment, define customers and commitments, select categories, and document boundary exclusions and dependencies.\n2. Assess criterion applicability, identify control coverage and gaps, test mapping specificity, document complementary user and subservice controls, trace system-description assertions to support, and challenge duplicate controls that do not address the criterion.\n3. Security common criteria CC1–CC9 remain in scope. For Availability, Confidentiality, Processing Integrity and Privacy, record category selection from service commitments and engagement scope, with the reason for each exclusion. Identify the reviewed companion assessment and its period, boundary, evidence, findings and approval version for each selected category. A missing or incompatible output is an explicit readiness gap, never an assumed pass.\n4. Prepare one evidence index across criteria: identify each artifact once with source, version, period, control references and the criteria it supports.\n\n**Record in AssureSwarm**\n1. Step result: Capture the review period, intended report type and period, services, trust categories, system components, locations, subservice organizations, commitments, boundaries, exclusions, changes, and limitations. Use the Audit.scope and Audit.period_start / Audit.period_end fields only after checking the tenant schema.\n2. Step document: Attach the criterion-to-control mapping and evidence index; document applicability rationale, risks, controls, evidence sources, owners, frequencies, subservice and user controls, system-description references, gaps, and conflicting evidence. Record the document reference in the step result.\n\n**Exit criteria**\nEngagement lead provides expertise: The readiness boundary and selected criteria are unambiguous, subservice treatment is explicit, and material components or commitments are not omitted without documented rationale. Every selected criterion has supported coverage or a visible gap, mappings are specific enough for evidence assessment, and owners agree on responsibility boundaries.\nThe engagement lead checks that the assessment package uses the same reviewed boundary and evidence index; optional categories remain scoped companion assessments, with no executor questionnaire.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"soc2-common-criteria-assessment","data":{"label":"Review common criteria design","kind":"task","requiredApprovals":2,"controls":["UC-ACCESS-01","UC-ACCESS-03","UC-ASSET-01","UC-ASSET-04","UC-AUDIT-25","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-05","UC-CRYPTO-01","UC-GOV-04","UC-GOV-05","UC-GOV-06","UC-GOV-07","UC-GOV-14","UC-GOV-16","UC-GOV-21","UC-GOV-34","UC-HR-06","UC-IR-06","UC-IR-09","UC-LOG-04","UC-LOG-06","UC-NET-01","UC-PHYS-01","UC-RISK-04","UC-RISK-06","UC-RISK-11","UC-RISK-12","UC-RISK-13","UC-RISK-14","UC-TPRM-02"],"performedBy":{"primitives":["coach-document-upload","coach-query-data"],"note":"Agent retrieves authorized evidence and prepares attachments. The assigned assessor evaluates evidence and drafts signed criterion conclusions; management acknowledges findings and actions through native approvals. The separate independent readiness reviewer challenges all conclusions before final disposition."},"instructions":"**Objective**\nAssess CC1–CC9 design and obtain the two management contributions to the criterion-level evidence and action package. The executive sponsor approves governance and technical commitments and action ownership; the security and compliance lead applies expertise to the control design and approves the criterion findings and owned actions.\n\n**Inputs**\nConsume the reviewed system boundary, criteria-to-control mapping and resource-reference index from soc2-criteria-mapping. Use its named systems of record, current policy versions, review period and control references to resolve the evidence below. Record unavailable resources as gaps.\n\n_CC1 Control Environment Assessment_\n- Board & Governance Policy and Information Security Policy (current approved versions with effective dates)\n- Acceptable Use Policy acknowledgment records for employees and contractors\n- Minutes and decisions from the two most recent quarterly governance reviews\n- Signed quarterly attestations from the independent governance advisor, as executed to date under the prospective engagement\n- The linked consolidated controls for tone at the top and board-level oversight\n\nRole definitions for the executive sponsor, technology owner, and security and compliance lead, plus any outsourced security leadership or advisory scope\n- Information Security Policy sections assigning security roles, responsibilities, and authorities\n- Human Resources Security Policy with screening, onboarding agreement, and training records for the assessment window\n- Access documentation mapping role authority to cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform permissions\n\nBoard & Governance Policy and Human Resources Security Policy (accountability, performance, and sanctions provisions)\n- Control-owner assignments on the linked consolidated controls\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- Quarterly oversight reporting covering control metrics, overdue actions, and escalations\n\n_CC2 Communication and Information Assessment_\n- Information Security Objectives with the security metrics catalog and owners\n- The linked consolidated control for quality records and control information\n- A sample of recent control-run records with attached evidence across the operating processes\n- System-generated exports used by recurring controls: cloud identity and access management bindings, the workforce identity and collaboration platform membership, the continuous integration service results\n\nPolicy publication and acknowledgment records across the applicable governing policies\n- Security awareness communications and onboarding materials for the window\n- Customer-facing commitments: terms, support channels, and incident notification obligations\n- Subservice communication evidence: the cloud provider, the workforce identity and collaboration platform, and the source-control platform advisories and status feeds\n\n_CC3 Risk Assessment_\n- Information Security Objectives and business-context documentation\n- Risk Assessment Methodology and the current risk register with scores and owners\n- The most recent enterprise risk assessment run and its sign-off record\n- The linked consolidated controls for objective-setting and periodic risk assessment\n\nFraud-risk entries in the risk register, including management override and misappropriation scenarios\n- The linked consolidated controls for fraud risk and change-impact assessment\n- Segregation-of-duties documentation across cloud identity and access management, the source-control platform, and the billing surface\n- Change-assessment records for significant platform or organizational changes in the window\n\nRisk Management Policy and Risk Assessment Methodology (current approved versions with effective dates)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the risk-assessment series\n\n_CC4 Monitoring Activities Assessment_\n- The linked consolidated control for monitoring risk and control performance\n- Control-run completion data across the operating processes for the window\n- Internal audit program schedule and any completed engagement records\n- Quarterly governance review minutes covering control metrics\n\nThe linked consolidated control for deficiency tracking and remediation\n- The issue register for the window: source, severity, owner, age, and status\n- Escalation records for material deficiencies, including governance review minutes\n- Remediation action plans with due dates and closure evidence\n\n_CC5 Control Activities Assessment_\n- The linked consolidated control for the risk-based control baseline\n- The risk register with treatment mappings from risk to mitigating controls\n- The consolidated control set with its domain coverage (access, change, operations)\n- Segregation-of-duties expectations for control performers and approvers\n\nInformation Security Policy and the policy register with owners, versions, and review dates\n- The linked consolidated control for maintaining approved policies and procedures\n- Process records showing which procedures operationalize which policies\n- Acknowledgment and exception records for the window\n\n_CC6 Logical and Physical Access Controls Assessment_\n- The asset and system inventory identifying protected information assets\n- The linked consolidated controls for account lifecycle, least privilege, and asset inventory\n- Joiner, mover, and leaver records for the window with matching cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform changes\n- Role-to-permission mappings including privileged roles\n\nThe linked consolidated controls for physical access and media handling\n- The carve-out position for the cloud provider data-center physical security with current attestation coverage\n- Endpoint and media inventory: laptops and any removable media in circulation\n- Disposal and sanitization records for devices retired during the window\n\nThe linked consolidated controls for network boundary, encryption, and software restriction\n- Network and service architecture for the customer environments: ingress paths, TLS termination, service-to-service authentication\n- Encryption standards for data at rest and in transit, with key management ownership\n- Endpoint protection and allowed-software configuration for workforce devices\n\nAccess Control Policy, Password & Authentication Policy, and Physical Security Policy (current approved versions)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the access series\n\n_CC7 System Operations Assessment_\n- The linked consolidated controls for configuration baselines and continuous monitoring\n- Vulnerability management records: scans, dependency checks in the continuous integration service, and triage decisions\n- Configuration baselines for the customer environments and drift-detection evidence\n- Monitoring and alerting configuration with escalation routing\n\nThe linked consolidated controls for event evaluation and incident response\n- Incident response plan with declaration criteria, severity levels, and role assignments\n- Event triage records and any declared-incident records for the window\n- Notification obligations toward customers and dependencies on subservice providers\n\nThe linked consolidated control for incident recovery\n- Recovery procedures: infrastructure redeployment, backup restore, and credential rotation paths\n- Postmortem records or recovery exercise results for the window\n- Dependencies on subservice recovery commitments from the cloud provider\n\n_CC8 Change Management Assessment_\n- The linked consolidated control for change authorization and approval\n- the source-control platform configuration: protected branches, merge request approval rules, CI gate definitions\n- A sample of production changes from the window: application code, infrastructure, and database migrations\n- Emergency change records with retrospective approvals\n\nChange Management Policy and Software Development Lifecycle Policy (current approved versions with effective dates)\n- The design conclusion and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the change series\n\n_CC9 Risk Mitigation Assessment_\n- The linked consolidated control for business continuity and contingency planning policy\n- Disruption scenarios in the risk register with their selected mitigations\n- Continuity plan with roles, activation criteria, and recovery priorities\n- Key-person and succession arrangements for critical roles\n\nThe linked consolidated control for vendor due diligence\n- Vendor register with criticality tiers, owners, and review dates\n- Attestation evidence on file: SOC 2 or equivalent reports for the subservice organizations\n- Contracts and data processing terms for vendors touching customer data\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb the detailed assessment activities below; the assigned assessor evaluates the evidence and drafts each criterion conclusion for management review. Original criterion procedures retain their evidence and conclusion requirements within this package.*\n\n_CC1 Control Environment Assessment_\n1. Assessment scope for Assess Tone at the Top & Board Oversight: Assess CC1.1 and CC1.2: the entity demonstrates a commitment to integrity and ethical values, and the board function demonstrates independence from management and exercises oversight of the development and performance of internal control. Assess the ethical culture and governance oversight anchoring the scoped control environment.\n\n2. Read the Board & Governance Policy and confirm it defines standards of conduct, conflict-of-interest handling, and escalation paths that bind the executive sponsor as well as staff.\n\n3. Trace the two most recent quarterly governance reviews end to end: agenda, minutes, decisions, and follow-up actions recorded against the owning process in AssureSwarm.\n\n4. Verify the independent governance advisor's engagement establishes independence from day-to-day management, a defined oversight cadence, and a direct escalation path.\n\n5. Sample Acceptable Use Policy acknowledgments across the workforce and confirm any deviation was handled under the Human Resources Security Policy's sanctions provisions.\n\n6. Compare observed practice against each linked control's statement and record a design conclusion per criterion, noting gaps as candidate findings.\n\n7. Assessment scope for Evaluate Organizational Structure & Competence: Evaluate CC1.3 and CC1.4: management establishes structures, reporting lines, and authorities appropriate for the organization and its documented service architecture, and the organization attracts, develops, and retains competent people in alignment with its objectives.\n\n8. Confirm documented reporting lines match practice: who authorizes risk acceptances, production releases, and vendor commitments, and where each decision escalates.\n\n9. Verify segregation between engineering execution and independent review - including the firm-internal segregation attested through the advisory engagement - is reflected in the role definitions.\n\n10. Inspect screening evidence and signed confidentiality and acceptable-use agreements for personnel onboarded during the window.\n\n11. Review security awareness and role-based training completion and confirm that misses triggered documented follow-up.\n\n12. Test that authority in systems mirrors authority on paper by sampling cloud identity and access management bindings and the source-control platform access for one privileged role and one standard role.\n\n13. Record a design conclusion per criterion and log any mismatch as a candidate finding.\n\n14. Assessment scope for Conclude on Accountability & Control Environment: Assess CC1.5: individuals are held accountable for their internal control responsibilities. Then close the control-environment portion of the readiness assessment by consolidating the conclusions of the Assess Tone at the Top & Board Oversight and Evaluate Organizational Structure & Competence activities.\n\n15. Verify every in-scope control names an accountable owner and that ownership was reassigned promptly for any joiner, mover, or leaver event during the window.\n\n16. Inspect how missed control executions and policy violations were handled: escalation to the security and compliance lead and executive sponsor, sanctions applied under the Human Resources Security Policy, and corrective actions tracked to closure.\n\n17. Confirm performance expectations for roles holding privileged access or approval authority explicitly reference their control responsibilities.\n\n18. Consolidate the design conclusions for the full control-environment series into the readiness summary, classifying each criterion as designed or gap.\n\n19. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC2 Communication and Information Assessment_\n20. Assessment scope for Assess Quality of Control Information: Assess CC2.1: the entity obtains or generates and uses relevant, quality information to support the functioning of internal control. For the scoped service this means the information the control set runs on - control-run evidence in AssureSwarm, the cloud provider audit and application logs, the source-control platform pipeline results, and access exports - is relevant, complete, accurate, and timely enough to support control conclusions.\n\n21. Inventory the information each recurring control consumes and identify its source system, producer, and refresh cadence.\n\n22. For a sample of control runs in the assessment window, verify the evidence attached was system-generated where practical and current as of the run date.\n\n23. Trace two security metrics from the Information Security Objectives to their underlying data and confirm the figures are reproducible.\n\n24. Check that information the controls depend on is retained per requirements and remains retrievable for the audit period.\n\n25. Record a design conclusion for CC2.1 and log information-quality gaps as candidate findings.\n\n26. Assessment scope for Evaluate Internal & External Communication: Evaluate CC2.2 and CC2.3: the entity internally communicates information necessary for internal control to function, including objectives and responsibilities, and communicates with external parties on matters affecting internal control. In scope are onboarding and policy communication to the workforce, and the channels the organization maintains with customers, subservice organizations, and other external parties.\n\n27. Verify each policy names an owner and audience and that publication reached the affected workforce through the acknowledgment flow.\n\n28. Inspect how control responsibilities reach individuals: onboarding materials, role definitions, and recurring security awareness communications.\n\n29. Confirm externally facing channels exist for customers to report security, availability, and privacy concerns, and that inbound reports route to the incident process.\n\n30. Verify subservice advisories and status changes from the cloud provider, the workforce identity and collaboration platform, and the source-control platform are monitored and acted on.\n\n31. Record a design conclusion per criterion and log any communication gap as a candidate finding.\n\n_CC3 Risk Assessment_\n32. Assessment scope for Assess Objectives & Enterprise Risk Identification: Assess CC3.1 and CC3.2: the entity specifies objectives with sufficient clarity to enable identification and assessment of risks, and identifies and analyzes risks across the entity as a basis for determining how they are managed. For the scoped service the anchor artifacts are the Information Security Objectives and the periodic enterprise risk assessment feeding the risk register.\n\n33. Verify objectives are specific enough that a risk can be traced to the objective it threatens - sample three register entries and walk the trace.\n\n34. Confirm the enterprise risk assessment covered the platform, the subservice dependencies (the cloud provider, the workforce identity and collaboration platform, the source-control platform), and the workforce dimension.\n\n35. Check each identified risk carries an analysis: likelihood, impact, inherent and residual scores per the methodology, and a treatment decision.\n\n36. Verify risk owners exist for every open register entry and treatment actions carry target dates.\n\n37. Record a design conclusion per criterion and note gaps as candidate findings.\n\n38. Assessment scope for Evaluate Fraud Risk & Significant Change: Evaluate CC3.3 and CC3.4: the entity considers the potential for fraud in assessing risks, and identifies and assesses changes that could significantly impact the system of internal control. Assess management-override exposure and the available segregation of duties; change assessment must catch platform, subservice, and organizational shifts before they erode the control set.\n\n39. Verify the register carries explicit fraud scenarios - override of controls, unauthorized data access for gain, and misstatement - with analysis and treatments.\n\n40. Assess whether compensating measures for the small-team override risk are designed: independent review through the governance advisor, dual approvals, and immutable audit logging.\n\n41. Inspect how significant changes - new subservice providers, architecture shifts, tenancy model changes, key-person changes - enter risk assessment before adoption.\n\n42. Walk one significant change from the window through its documented risk assessment and approval.\n\n43. Record a design conclusion per criterion with gaps as candidate findings.\n\n44. Assessment scope for Conclude on Risk Assessment Design: Close the risk-assessment portion of the readiness assessment by consolidating the conclusions of the Assess Objectives & Enterprise Risk Identification and Evaluate Fraud Risk & Significant Change activities into a single series verdict against the governing risk policies.\n\n45. Confirm the Risk Management Policy and Risk Assessment Methodology are current, approved, and reflected in the practices the assessment observed.\n\n46. Reconcile every design conclusion recorded in this workflow against its criterion and confirm none is unsupported by attached evidence.\n\n47. Verify each open gap exists as an issue on the readiness audit with a named owner and a target date, and that no gap is silently absorbed into the verdict.\n\n48. Draft the risk-assessment section of the readiness summary, classifying each criterion as designed or gap.\n\n49. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC4 Monitoring Activities Assessment_\n50. Assessment scope for Assess Ongoing & Separate Evaluations: Assess CC4.1: the entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. For the scoped service the design rests on continuous control operation in AssureSwarm with recurring process runs, plus separate evaluations - the internal audit program, quarterly reviews with the governance advisor, and this readiness assessment itself.\n\n51. Verify recurring control runs have a defined cadence and an owner, and that completion is visible on the compliance dashboards.\n\n52. Confirm separate evaluations are scheduled with defined scope and independence - internal audit, the governance advisor's quarterly review, and external assessments.\n\n53. Inspect how monitoring results feed back: who reviews completion rates, missed runs, and stale evidence, and on what cadence.\n\n54. Walk one monitoring cycle end to end, from signal through review to a recorded action.\n\n55. Record a design conclusion for CC4.1 and note monitoring blind spots as candidate findings.\n\n56. Assessment scope for Evaluate Deficiency Communication & Remediation: Evaluate CC4.2: the entity evaluates and communicates internal control deficiencies in a timely manner to the parties responsible for corrective action, including senior management. For the scoped service deficiencies surface as issues in AssureSwarm; the design question is whether they reach the security and compliance lead and the executive sponsor fast enough and are tracked to closure rather than aging quietly.\n\n57. Verify each deficiency was recorded as an issue with severity, an accountable owner, and a remediation date at intake.\n\n58. Trace two deficiencies from detection through communication to the responsible owner and on to closure, confirming timelines match the severity.\n\n59. Confirm material deficiencies reached the executive sponsor and the governance advisor's quarterly review, with decisions minuted.\n\n60. Check that overdue remediation triggers escalation rather than silent date slippage.\n\n61. Record a design conclusion for CC4.2 and log any gap as a candidate finding.\n\n_CC5 Control Activities Assessment_\n62. Assessment scope for Assess Control Selection & Technology General Controls: Assess CC5.1 and CC5.2: the entity selects and develops control activities that mitigate risks to the achievement of objectives to acceptable levels, and selects and develops general control activities over technology. For the scoped service the design rests on a risk-based control baseline mapped to the register, with technology general controls spanning access, change, and operations across the cloud provider, the application hosting service, and the source-control platform.\n\n63. Sample three high residual risks and verify each maps to at least one designed control whose statement actually addresses the risk.\n\n64. Confirm the baseline covers the technology layers the platform depends on: the cloud provider infrastructure and IAM, the application hosting services, the managed database layer, and the source-control platform pipeline.\n\n65. Verify control activities mix types - preventive and detective, automated and manual - proportionate to the risk they mitigate.\n\n66. Check segregation of duties between performing a control and approving its result, with the small-team compensations documented.\n\n67. Record a design conclusion per criterion and log coverage gaps as candidate findings.\n\n68. Assessment scope for Evaluate Policy-to-Procedure Deployment: Evaluate CC5.3: the entity deploys control activities through policies that establish what is expected and procedures that put policies into action. The design question is whether the applicable governing policies anchored by the Information Security Policy translate into operable procedures - the recurring process runs and control activities in AssureSwarm - rather than sitting as shelfware.\n\n69. Verify every policy names an owner, carries an approval and a next review date, and completed its periodic review on schedule.\n\n70. Sample three policies and confirm each is deployed through at least one linked process or control that puts it into action.\n\n71. Confirm policy exceptions follow the documented path - time-boxed, risk-assessed, and approved by the authorized role.\n\n72. Check the accountability wiring: performers can reach the procedure that governs their control activity from the control record itself.\n\n73. Record a design conclusion for CC5.3 and note deployment gaps as candidate findings.\n\n_CC6 Logical and Physical Access Controls Assessment_\n74. Assessment scope for Assess Logical Access Architecture & Credential Lifecycle: Assess CC6.1, CC6.2, and CC6.3: logical access security software and architectures protect information assets; new users are registered and authorized before credentials issue and credentials are removed when access ends; and access is authorized, modified, or removed based on roles with least privilege and segregation of duties. Evaluate the documented customer-isolation architecture where the scoped service hosts multiple customers.\n\n75. Verify the inventory covers the systems holding customer and corporate data, so access architecture decisions rest on a complete asset picture.\n\n76. Confirm the documented customer-isolation model through scoped service identities and segregation of customer resources; verify that credentials cannot cross an unauthorized customer boundary.\n\n77. Trace each leaver in the window to credential removal across cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform within the required interval.\n\n78. Sample privileged and standard role grants and verify authorization preceded issuance and matches the role mapping.\n\n79. Record a design conclusion per criterion and log deviations as candidate findings.\n\n80. Assessment scope for Evaluate Physical Safeguards & Asset Disposal: Evaluate CC6.4 and CC6.5: physical access to facilities and protected information assets is restricted to authorized personnel, and physical protections are discontinued only after the ability to read or recover data has been diminished. Identify direct and inherited physical responsibilities from the documented operating model. Review provider attestations where relied upon, and assess controlled facilities, workforce endpoints, remote workspaces where applicable, and media disposal.\n\n81. Confirm the boundary: which physical responsibilities are inherited from the hosting provider and which remain with the organization, and that the inherited portion is covered by current attestations.\n\n82. Verify workforce physical practice is defined for remote work - screen locking, clear desk, secured devices - and communicated to everyone with production access.\n\n83. Check every retired device in the window has a sanitization or destruction record before leaving control.\n\n84. Verify media containing customer data never leaves the cloud boundary except through approved, encrypted paths.\n\n85. Record a design conclusion per criterion and log gaps as candidate findings.\n\n86. Assessment scope for Assess Boundary Defense, Transmission Protection & Malware Controls: Assess CC6.6, CC6.7, and CC6.8: logical access measures protect against threats from outside the system boundary; transmission, movement, and removal of information is restricted to authorized parties and protected in motion; and controls prevent or detect the introduction of unauthorized or malicious software. The perimeter under review is the application hosting service boundary of each scoped customer environment plus the workforce endpoint fleet.\n\n87. Verify each customer environment exposes only intended ingress: authenticated application hosting service endpoints behind TLS, no stray listeners or publicly readable storage.\n\n88. Confirm encryption in transit end to end and at rest on managed storage, with key management responsibilities documented.\n\n89. Check information movement paths - exports, support access, engineering diagnostics - are restricted to authorized users and logged.\n\n90. Verify endpoint protection and software allow-listing are deployed on workforce devices, with unauthorized-software detection feeding alerts.\n\n91. Record a design conclusion per criterion and log exposures as candidate findings.\n\n92. Assessment scope for Conclude on Access Control Design: Close the logical and physical access portion of the readiness assessment by consolidating the conclusions of the Assess Logical Access Architecture & Credential Lifecycle, Evaluate Physical Safeguards & Asset Disposal, and Assess Boundary Defense, Transmission Protection & Malware Controls activities into a single series verdict against the governing access policies.\n\n93. Confirm the three governing policies are current, approved, and consistent with the access practices the assessment observed.\n\n94. Reconcile the design conclusion for each of the eight criteria against its supporting evidence and flag any unsupported verdict.\n\n95. Verify every open access gap exists as an issue on the readiness audit with a named owner and a target date.\n\n96. Draft the access section of the readiness summary, classifying each criterion as designed or gap.\n\n97. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC7 System Operations Assessment_\n98. Assessment scope for Assess Vulnerability Detection & Anomaly Monitoring: Assess CC7.1 and CC7.2: detection and monitoring procedures identify configuration changes that introduce vulnerabilities and susceptibilities to newly discovered ones, and system components are monitored for anomalies indicative of malicious acts, natural disasters, or errors. The surface is the cloud provider estate and the application hosting services plus the source-control platform pipeline that changes them.\n\n99. Verify hardened baselines exist for the platform's building blocks and that deviations surface as findings rather than persisting silently.\n\n100. Confirm dependency and container scanning runs in the source-control platform pipeline with triage timelines tied to severity.\n\n101. Inspect alert coverage across the customer environments: authentication anomalies, availability signals, and error-rate spikes reach an accountable responder.\n\n102. Walk one vulnerability and one anomaly from detection to disposition.\n\n103. Record a design conclusion per criterion and log blind spots as candidate findings.\n\n104. Assessment scope for Evaluate Event Evaluation & Incident Response: Evaluate CC7.3 and CC7.4: the entity evaluates security events to determine whether they are security incidents, and responds to incidents through a defined program to understand, contain, remediate, and communicate. The design under review is the incident lifecycle from event triage through declared-incident execution, including customer notification duties and coordination with subservice providers.\n\n105. Verify declaration criteria distinguish events from incidents and that triage decisions in the window applied them consistently.\n\n106. Confirm the response program defines roles, containment playbooks, evidence preservation, and communication duties, including customer notification thresholds.\n\n107. Walk one event through triage and, if any incident was declared, through containment, remediation, and communication to closure; otherwise inspect the most recent response exercise.\n\n108. Check that post-incident review feeds corrective actions into the issue register.\n\n109. Record a design conclusion per criterion and log gaps as candidate findings.\n\n110. Assessment scope for Assess Incident Recovery Activities: Assess CC7.5: the entity identifies, develops, and implements activities to recover from identified security incidents. For the scoped service this means restoring affected customer services after a security incident - rebuilding from clean infrastructure definitions and restoring from protected backups - and folding lessons learned back into controls and playbooks.\n\n111. Verify documented recovery procedures exist for the plausible incident classes: compromised credentials, malicious change, data corruption, and service compromise.\n\n112. Confirm recovery is exercisable - a tenant environment can be redeployed from definitions and data restored from backups - with recent evidence of a test.\n\n113. Check recovery includes integrity verification before returning to service, so a compromise is not restored along with the data.\n\n114. Verify postmortems produced corrective actions with owners and dates, and that those actions closed.\n\n115. Record a design conclusion for CC7.5 and log gaps as candidate findings.\n\n_CC8 Change Management Assessment_\n116. Assessment scope for Assess Change Authorization, Testing & Deployment: Assess CC8.1: the entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures. Assess the approved production change path: independently reviewed change requests, automated test gates, protected branches, infrastructure definitions, and database migrations.\n\n117. Verify the pipeline enforces the lifecycle: no direct pushes to protected branches, independent review before merge, and green CI gates before deploy.\n\n118. Sample changes across the three classes - application code, infrastructure definitions, database migrations - and confirm each shows authorization, testing, approval, and deployment evidence.\n\n119. Check segregation between author and approver holds in practice, including the small-team case with documented compensations.\n\n120. Verify emergency changes follow the expedited path and receive retrospective review within the required interval.\n\n121. Record a design conclusion for CC8.1 and log deviations as candidate findings.\n\n122. Assessment scope for Conclude on Change Management Design: Close the change-management portion of the readiness assessment by consolidating the conclusion of the Assess Change Authorization, Testing & Deployment activity into a series verdict against the governing change policies.\n\n123. Confirm both governing policies are current, approved, and consistent with the observed pipeline practice, including the emergency path.\n\n124. Reconcile the CC8.1 design conclusion against its supporting evidence and flag anything unsupported.\n\n125. Verify every open change gap exists as an issue on the readiness audit with a named owner and a target date.\n\n126. Draft the change section of the readiness summary, classifying the criterion as designed or gap.\n\n127. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the assessment activity instead of closing it here.\n\n_CC9 Risk Mitigation Assessment_\n128. Assessment scope for Assess Business Disruption Risk Mitigation: Assess CC9.1: the entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions. For the scoped service, assess disruptions including hosting-region loss, key-person unavailability, subservice failure, and funding interruption; the design anchor is the business continuity and contingency planning framework.\n\n129. Verify the register carries the disruption scenarios that matter for the operating model and each carries a selected mitigation, not just an acceptance.\n\n130. Confirm the continuity plan assigns roles and activation criteria and covers the platform's dependency on the cloud provider regional services.\n\n131. Check key-person risk carries concrete mitigations: documented runbooks, credential escrow, and cross-training or advisory cover.\n\n132. Verify mitigation activities have owners and review dates, so they survive personnel and platform change.\n\n133. Record a design conclusion for CC9.1 and log gaps as candidate findings.\n\n134. Assessment scope for Evaluate Vendor & Business Partner Risk Management: Evaluate CC9.2: the entity assesses and manages risks associated with vendors and business partners. Use the approved vendor register to identify material cloud, identity, development-platform, and advisory dependencies; document the significance of each relationship.\n\n135. Verify every active vendor appears in the register with a criticality tier, an owner, and a next review date.\n\n136. Confirm due diligence preceded engagement for vendors touching customer data and was refreshed on schedule for the critical tier.\n\n137. Inspect the most recent attestation review for each subservice organization, including exceptions noted and complementary controls adopted in response.\n\n138. Check exit thinking exists for the concentrated dependencies: what happens if a critical vendor degrades, and who decides.\n\n139. Record a design conclusion for CC9.2 and log gaps as candidate findings.\n\n140. Keep a separate conclusion for each criterion, with the assessor identity, evidence references, applicable controls, design or implementation gaps and rationale. Preserve adverse and conflicting evidence. The executive sponsor and security and compliance lead each review this exact package version and acknowledge findings, action ownership and commitments through separate native approvals; an unresolved objection prevents completion and requires correction. Their approval does not replace the independent readiness review at soc2-readiness-closure.\n\n**Record in AssureSwarm**\nUse the markdown step result for the signed assessor conclusions, criterion-to-evidence references and limitations; use attached step documents for the workpapers listed below. After checking the tenant schema, create or update each gap as an Issue (issue_type: finding, source: internal_audit, severity, issue_owner) and link it to the existing Audit and affected Control records. Record each corrective action on a linked Remediation item using plan, action_owner and target_date. If those fields or the Remediation type are unavailable, retain the action plan, owner and target date in the step workpaper and disclose the missing destination; do not invent Issue fields. Describe criterion identifiers in the workpaper and Issue; no Criterion item is required. Bind both native management approvals to the same reviewed package version. Substantive changes require renewed approvals before downstream reliance.\n\n_CC1 Control Environment Assessment_\nAttach the governance minutes, the advisor attestations, and the acknowledgment export to this step. Raise each design gap as an issue linked to the readiness audit, referencing the affected control by title, and note the design conclusion in the step record.\n\nAttach the role definitions, sampled screening and training evidence, and the permission exports to this step. Link each gap to the affected control, raise it as an issue on the readiness audit, and capture the rationale for each conclusion in the step record.\n\nRecord the consolidated conclusion on this step and attach the control-environment section of the readiness summary. Confirm every gap exists as an issue linked to the readiness audit with a named owner and a target date before requesting approval.\n\n_CC2 Communication and Information Assessment_\nAttach the information inventory, sampled control-run evidence, and metric traces to this step. Raise each information-quality gap as an issue linked to the readiness audit, referencing the affected control by title.\n\nAttach acknowledgment exports, sample communications, and the external-channel inventory to this step. Raise gaps as issues linked to the readiness audit and record the conclusion for each criterion in the step record.\n\n_CC3 Risk Assessment_\nAttach the risk register export and the assessment sign-off to this step. Raise each gap as an issue linked to the readiness audit and record the design conclusions in the step record.\n\nAttach the fraud-risk extract, override compensations, and the sampled change assessment to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the risk-assessment section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC4 Monitoring Activities Assessment_\nAttach the cadence inventory, completion metrics, and review minutes to this step. Raise blind spots as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the issue register export and the traced deficiency records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC5 Control Activities Assessment_\nAttach the risk-to-control mapping sample and the domain coverage summary to this step. Raise coverage gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the policy register export and the sampled policy-to-procedure traces to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC6 Logical and Physical Access Controls Assessment_\nAttach the inventory extract, lifecycle samples, and permission exports to this step. Raise deviations as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the carve-out summary, endpoint inventory, and disposal records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the architecture summary, encryption standard, and endpoint configuration evidence to this step. Raise exposures as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the access section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC7 System Operations Assessment_\nAttach scan samples, baseline evidence, and alert-routing configuration to this step. Raise blind spots as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach triage samples, the response plan, and walkthrough records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach recovery procedures, exercise evidence, and postmortem records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC8 Change Management Assessment_\nAttach the pipeline configuration export and the sampled change records to this step. Raise deviations as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the change section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC9 Risk Mitigation Assessment_\nAttach the disruption-scenario extract and continuity plan to this step. Raise gaps as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the vendor register export and attestation review notes to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n**Exit criteria**\n_CC1 Control Environment Assessment_\nCC1.1 and CC1.2 each carry a documented design conclusion supported by attached evidence, and every candidate finding has a named owner and a target date. CC1.3 and CC1.4 each carry a supported design conclusion across structures, reporting lines, and competence practices, and any divergence between documented authority and system permissions is logged as an issue with an owner and a target date. All five control-environment criteria (CC1.1–CC1.5) carry a supported design conclusion, both approvers have signed off on this step, and no control-environment gap remains without an owner, a target date, and a linked issue.\n\n_CC2 Communication and Information Assessment_\nCC2.1 carries a documented design conclusion supported by attached evidence, and every information-quality gap has a named owner and a target date. CC2.2 and CC2.3 each carry a documented design conclusion, every communication gap is logged with a named owner and a target date, and the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC3 Risk Assessment_\nCC3.1 and CC3.2 each carry a documented design conclusion supported by attached evidence, and identified gaps have named owners and target dates. CC3.3 and CC3.4 each carry a documented design conclusion, and every gap is logged with a named owner and a target date. All four criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no risk-assessment gap remains without an owner, a target date, and a linked issue.\n\n_CC4 Monitoring Activities Assessment_\nCC4.1 carries a documented design conclusion supported by attached evidence, and every monitoring blind spot has a named owner and a target date. CC4.2 carries a documented design conclusion, both traced deficiencies show timely communication and closure, and remaining gaps carry named owners and target dates.\n\n_CC5 Control Activities Assessment_\nCC5.1 and CC5.2 each carry a documented design conclusion, and every coverage gap is logged with a named owner and a target date. CC5.3 carries a documented design conclusion, sampled policies trace to operating procedures, and every deployment gap has a named owner and a target date.\n\n_CC6 Logical and Physical Access Controls Assessment_\nCC6.1, CC6.2, and CC6.3 each carry a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC6.4 and CC6.5 each carry a documented design conclusion, the inherited-versus-retained boundary is explicit, and every gap has a named owner and a target date. CC6.6, CC6.7, and CC6.8 each carry a documented design conclusion supported by attached evidence, and every exposure has a named owner and a target date. All eight criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no access gap remains without an owner, a target date, and a linked issue.\n\n_CC7 System Operations Assessment_\nCC7.1 and CC7.2 each carry a documented design conclusion supported by attached evidence, and every blind spot has a named owner and a target date. CC7.3 and CC7.4 each carry a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC7.5 carries a documented design conclusion supported by attached evidence, and every recovery gap has a named owner and a target date.\n\n_CC8 Change Management Assessment_\nCC8.1 carries a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC8.1 carries a supported design conclusion, both approvers have signed off on this step, and no change gap remains without an owner, a target date, and a linked issue.\n\n_CC9 Risk Mitigation Assessment_\nCC9.1 carries a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC9.2 carries a documented design conclusion supported by attached evidence, and every vendor gap has a named owner and a target date.\n\nThe executive sponsor and security and compliance lead are two distinct assigned approvers. Both have approved this version, every criterion has a signed assessor conclusion and evidence or a visible gap, and all gaps have owners and dates. The independent readiness conclusion remains pending until soc2-readiness-closure.","type":"TASK"},"position":{"x":0,"y":160}},{"id":"soc2-readiness-closure","data":{"label":"Approve SOC 2 readiness record","kind":"task","instructions":"**Objective**\nApprove SOC 2 readiness record. The independent readiness reviewer challenges evidence sufficiency and approves the examination-planning disposition.\n\n**Inputs**\nConsume the reviewed assessment package from soc2-common-criteria-assessment, with its two management approvals, signed assessor conclusions, criterion evidence and owned gap register. Also consume the reviewed companion assessment for each selected optional category; exclusions must trace to the approved scope.\n1. Review mapped controls, walkthroughs, sample evidence across the intended period, system-description draft, incidents, exceptions, vendor reports, gap inventory, remediation plans, and readiness milestones.\n2. Review all stage evidence, final mapping, system-description version, gap and remediation tracker, readiness result, subservice and user responsibilities, changes, limitations, and stakeholder comments.\n\n**Procedure**\n1. Inspect evidence quality and continuity, identify missing operating history, validate design and implementation observations, assess gap impact by criterion, sequence remediation and evidence generation, and avoid presenting readiness work as examination testing.\n2. Trace the disposition to criterion-level evidence, verify gaps and dependencies remain visible, reconcile document versions and scope, challenge unsupported timing, and return inconsistencies or hidden limitations for correction.\n3. Independently challenge all 33 common-criteria conclusions (CC1.1–CC1.5, CC2.1–CC2.3, CC3.1–CC3.4, CC4.1–CC4.2, CC5.1–CC5.3, CC6.1–CC6.8, CC7.1–CC7.5, CC8.1, CC9.1–CC9.2). For each, record the independent reviewer conclusion, evidence sufficiency, control mapping and remaining gap; reconcile the four optional categories to the approved engagement scope and applicable reviewed companion outputs.\n4. Verify both named management roles approved the exact package versions and that the reviewer is independent of preparation and operation of the assessed controls. Return unsupported or disputed conclusions to the owning assessment package; substantive corrections require its renewed dual approvals and this independent review. Management acceptance cannot cure insufficient evidence or override the independent conclusion.\n5. Hand the approved disposition, conditions and action tracker to management for remediation and examination planning. Keep SOC 2 Type II interim testing, PBC evidence preparation and management assertion with their separate owners and workflows. The service auditor retains responsibility for any SOC opinion.\n\n**Record in AssureSwarm**\n1. Step result: Document the readiness result by criterion, evidence reviewed, design or implementation gaps, operating-history needs, remediation owner and due date, dependencies, conditions, and proposed examination timing.\n2. Step document: Attach the SOC 2 readiness summary and final evidence index; capture the authorized reviewer, final boundary and mapping references, readiness result, conditions, gaps, remediation owners and dates, system-description status, intended next step, limitations, and reassessment triggers. The native approval records the independent reviewer’s decision against this version.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the evidence-based readiness disposition, conditions and gaps are fully owned, and no claim of SOC 2 certification or auditor opinion is made. The authorized reviewer accepts a management readiness record for planning purposes; closure is not certification and does not predict or replace a service auditor’s opinion.\nEvery common criterion and selected optional category has an independent conclusion with evidence or an explicit limitation. The independent readiness reviewer has recorded native approval; the two management approvals remain separate and traceable.","requiredApprovals":1,"controls":["UC-ACCESS-01","UC-ACCESS-03","UC-ASSET-01","UC-ASSET-04","UC-AUDIT-13","UC-AUDIT-25","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-05","UC-CRYPTO-01","UC-GOV-04","UC-GOV-05","UC-GOV-06","UC-GOV-07","UC-GOV-14","UC-GOV-16","UC-GOV-21","UC-GOV-34","UC-HR-06","UC-IR-06","UC-IR-09","UC-LOG-04","UC-LOG-06","UC-NET-01","UC-PHYS-01","UC-RISK-04","UC-RISK-06","UC-RISK-11","UC-RISK-12","UC-RISK-13","UC-RISK-14","UC-TPRM-02"],"roleIntegrity":{"ermPhase":"report","lineRole":"third","serviceMode":"assurance","decisionOwner":"Independent readiness reviewer","independenceRequired":true},"type":"TASK"},"position":{"x":0,"y":320}}],"edges":[{"id":"e-soc2-criteria-mapping-soc2-common-criteria-assessment","source":"soc2-criteria-mapping","target":"soc2-common-criteria-assessment"},{"id":"e-soc2-common-criteria-assessment-soc2-readiness-closure","source":"soc2-common-criteria-assessment","target":"soc2-readiness-closure"}],"metadata":{"kind":"soc2-readiness","source":"studio-seed","framework":"soc2","scope":"Design-readiness assessment of CC1–CC9 within the documented system boundary and review period. Operating examples support design and implementation observations; this workflow does not issue certification, an examination result or a SOC 2 Type II opinion.","controlMappingQualification":"Control references cover only the procedures and criteria assessed here. Shared unified-control mappings do not extend the conclusion to other requirements or prove native tenant links or control operation.","configuration":["engagement_scope","applicable_criteria","review_period","responsible_roles","resource_reference_index"],"consolidation":{"date":"2026-09-11","sources":[{"sourceTemplateId":"workflow-library:audit-soc2-cc1-control-environment-assessment","sourceNodeId":"step-3","targetNodeId":"soc2-common-criteria-assessment","criteria":["CC1.1","CC1.2","CC1.3","CC1.4","CC1.5"],"controls":["UC-GOV-04","UC-GOV-05","UC-GOV-06","UC-GOV-07","UC-HR-06"]},{"sourceTemplateId":"workflow-library:audit-soc2-cc2-communication-information-assessment","sourceNodeId":"step-2","targetNodeId":"soc2-common-criteria-assessment","criteria":["CC2.1","CC2.2","CC2.3"],"controls":["UC-AUDIT-25","UC-GOV-21"]},{"sourceTemplateId":"workflow-library:audit-soc2-cc3-risk-assessment","sourceNodeId":"step-3","targetNodeId":"soc2-common-criteria-assessment","criteria":["CC3.1","CC3.2","CC3.3","CC3.4"],"controls":["UC-RISK-04","UC-RISK-06","UC-RISK-11","UC-RISK-12"]},{"sourceTemplateId":"workflow-library:audit-soc2-cc4-monitoring-activities-assessment","sourceNodeId":"step-2","targetNodeId":"soc2-common-criteria-assessment","criteria":["CC4.1","CC4.2"],"controls":["UC-RISK-13","UC-RISK-14"]},{"sourceTemplateId":"workflow-library:audit-soc2-cc5-control-activities-assessment","sourceNodeId":"step-2","targetNodeId":"soc2-common-criteria-assessment","criteria":["CC5.1","CC5.2","CC5.3"],"controls":["UC-GOV-14","UC-GOV-16"]},{"sourceTemplateId":"workflow-library:audit-soc2-cc6-access-controls-assessment","sourceNodeId":"step-4","targetNodeId":"soc2-common-criteria-assessment","criteria":["CC6.1","CC6.2","CC6.3","CC6.4","CC6.5","CC6.6","CC6.7","CC6.8"],"controls":["UC-ACCESS-01","UC-ACCESS-03","UC-ASSET-01","UC-ASSET-04","UC-CONFIG-05","UC-CRYPTO-01","UC-NET-01","UC-PHYS-01"]},{"sourceTemplateId":"workflow-library:audit-soc2-cc7-system-operations-assessment","sourceNodeId":"step-3","targetNodeId":"soc2-common-criteria-assessment","criteria":["CC7.1","CC7.2","CC7.3","CC7.4","CC7.5"],"controls":["UC-CONFIG-01","UC-IR-06","UC-IR-09","UC-LOG-04","UC-LOG-06"]},{"sourceTemplateId":"workflow-library:audit-soc2-cc8-change-management-assessment","sourceNodeId":"step-2","targetNodeId":"soc2-common-criteria-assessment","criteria":["CC8.1"],"controls":["UC-CONFIG-02"]},{"sourceTemplateId":"workflow-library:audit-soc2-cc9-risk-mitigation-assessment","sourceNodeId":"step-2","targetNodeId":"soc2-common-criteria-assessment","criteria":["CC9.1","CC9.2"],"controls":["UC-GOV-34","UC-TPRM-02"]}],"note":"Supersedes entries preserve historical catalog lineage and public redirects, not import identity. This new canonical library release does not change installed tenant workflows or rewrite immutable releases."},"canonicalSourceTemplateId":"workflow-library:audit-soc2-readiness-disposition","sourceNodeMap":{"soc2-boundary":"soc2-criteria-mapping","soc2-criteria-mapping":"soc2-criteria-mapping","soc2-gap-evaluation":"soc2-readiness-closure","soc2-readiness-closure":"soc2-readiness-closure"},"legacyNodeOrder":["soc2-boundary","soc2-criteria-mapping","soc2-gap-evaluation","soc2-readiness-closure"],"legacyRequiredApprovals":{"soc2-boundary":0,"soc2-criteria-mapping":0,"soc2-gap-evaluation":1,"soc2-readiness-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"audit"},"roles":[{"id":"engagement-lead","description":"Engagement lead applies expertise to the boundary, category applicability and criteria-to-control mapping; assign this named user before execution.","nodeIds":["soc2-criteria-mapping"],"contribution":"expertise"},{"id":"assigned-assessor","description":"Assigned assessor evaluates source evidence and drafts signed criterion-level conclusions in the assessment package results. This preparer must not be the independent readiness reviewer.","nodeIds":["soc2-common-criteria-assessment"],"contribution":"expertise"},{"id":"executive-sponsor","description":"Executive sponsor approves governance and technical commitments and acknowledges findings and action ownership, including CC1, CC3, CC6 and CC8. Assign a distinct native approver on the assessment package and verify the required count remains two after assignment.","nodeIds":["soc2-common-criteria-assessment"],"contribution":"approval"},{"id":"security-compliance-lead","description":"Security and compliance lead applies domain expertise and approves criterion findings and action ownership, including CC1, CC3, CC6 and CC8. Assign a different native approver from the executive sponsor on the assessment package.","nodeIds":["soc2-common-criteria-assessment"],"contribution":"approval"},{"id":"independent-readiness-reviewer","description":"Independent engagement reviewer / audit supervisor challenges every criterion conclusion and evidence package, including selected optional categories, and gives final native readiness approval. Must be separate from package preparation, assessed control operation and both management approvers; verify named tenant assignments before execution.","nodeIds":["soc2-readiness-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"input","name":"Reviewed availability assessment only when its category is selected in the engagement scope; align boundary, period, findings and approval version.","sourceTemplateId":"workflow-library:audit-soc2-availability-assessment"},{"direction":"input","name":"Reviewed confidentiality assessment only when its category is selected in the engagement scope; align boundary, period, findings and approval version.","sourceTemplateId":"workflow-library:audit-soc2-confidentiality-assessment"},{"direction":"input","name":"Reviewed processing integrity assessment only when its category is selected in the engagement scope; align boundary, period, findings and approval version.","sourceTemplateId":"workflow-library:audit-soc2-processing-integrity-assessment"},{"direction":"input","name":"Reviewed privacy criteria assessment only when its category is selected in the engagement scope; align boundary, period, findings and approval version.","sourceTemplateId":"workflow-library:audit-soc2-privacy-criteria-assessment"},{"direction":"output","name":"Approved readiness disposition and owned gaps for management PBC preparation and remediation","sourceTemplateId":"workflow-library:controls-soc2-readiness-evidence-cycle"},{"direction":"output","name":"Approved readiness disposition for separately scoped Type II interim testing","sourceTemplateId":"workflow-library:audit-soc2-type2-interim-testing"},{"direction":"output","name":"Readiness disposition and limitations for management-owned assertion preparation","sourceTemplateId":"workflow-library:grc-soc2-reporting-management-assertion"}]},"teams":["internal-audit"],"capabilities":["soc2-readiness"]}},{"sourceTemplateId":"coworkcanvas:template:iso27001-certification-readiness","name":"ISO 27001 Certification Readiness","description":"Runs on the existing audit item. Assess ISO/IEC 27001 certification readiness across ISMS scope, clauses, risk treatment, Annex A applicability, internal assurance, gaps, and audit-entry governance. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"audit","autoCreateOnItem":false,"nodes":[{"id":"iso-clause-control-review","data":{"label":"Assess clauses and Statement of Applicability","kind":"task","instructions":"**Objective**\nAssess clauses and Statement of Applicability. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved ISMS scope, context and interested-party analysis, organization and asset inventories, architecture, legal and contractual obligations, risk methodology, prior audits, incidents, and change plans.\n2. Use the scoped ISMS, policies and objectives, risk methodology and assessment, treatment plan, Statement of Applicability, Annex A controls, documented processes, competence records, monitoring, and corrective actions.\n\n**Procedure**\n1. Reconcile the scope to actual activities and dependencies, identify outsourced processes and interfaces, verify leadership ownership, select the applicable standard edition and certification stage, and document defensible exclusions or constraints.\n2. Evaluate each clause requirement, trace risks to treatment decisions, verify inclusion and exclusion rationale in the Statement of Applicability, inspect representative implementation evidence, and identify missing or contradictory documentation and practice.\n\n**Record in AssureSwarm**\n1. Capture the standard reference, scope statement, products, entities, locations, systems, interfaces, outsourced dependencies, interested parties, certification objective, target dates, exclusions, changes, and limitations. Also record standard edition and criteria; iSMS scope statement.\n2. Link the clause assessment and Statement of Applicability, document evidence, implementation observations, risk-treatment alignment, exclusions, owners, gaps, and required document or practice updates. Also record statement of Applicability reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The ISMS and readiness boundary are coherent and approved inputs, material interfaces are visible, and criteria or scope ambiguities are resolved before clause assessment. Every clause and applicability decision has evidence or a visible gap, risk treatment and control status reconcile, and unsupported exclusions are assigned for correction.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"iso-readiness-closure","data":{"label":"Approve ISO 27001 readiness record","kind":"task","instructions":"**Objective**\nApprove ISO 27001 readiness record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review internal audit program and results, management-review minutes and inputs, security objectives and measures, nonconformities, corrective actions, competence records, document control, gap tracker, and certification-body prerequisites.\n2. Review all stage records, current scope and criteria, clause evidence, Statement of Applicability, treatment plan, internal audit, management review, corrective actions, readiness decision, and certification-body coordination.\n\n**Procedure**\n1. Check required assurance cycles and inputs, validate corrective-action root causes and evidence, assess whether records cover the scoped ISMS, identify open major dependencies, sequence closure and operating history, and challenge schedule pressure.\n2. Trace material readiness statements to evidence, confirm gaps and unsupported exclusions remain visible, reconcile document versions and owners, verify conditions and timing, and return incomplete or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Document the readiness decision, internal audit and management-review status, gaps and nonconformities, corrective actions, evidence history, competence or document issues, conditions, owners, and due dates. Also record certification readiness.\n2. Capture the authorized reviewer, final scope, criteria and Statement of Applicability references, readiness result, conditions, gaps and corrective actions, owners, dates, proposed certification next step, and reassessment triggers. Also record iSO 27001 readiness summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the supported readiness disposition, all conditions are owned and time-bound, and readiness is not described as certification or a registrar conclusion. The authorized reviewer accepts an internal readiness record for planning; workflow closure neither certifies the ISMS nor predicts or replaces the certification body’s determination.","requiredApprovals":1,"controls":["UC-AUDIT-13"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-iso-clause-control-review-iso-readiness-closure","source":"iso-clause-control-review","target":"iso-readiness-closure"}],"metadata":{"kind":"iso27001-certification-readiness","source":"studio-seed","framework":"iso-27001","canonicalSourceTemplateId":"workflow-library:audit-iso27001-certification-readiness","sourceNodeMap":{"isms-readiness-scope":"iso-clause-control-review","iso-clause-control-review":"iso-clause-control-review","iso-assurance-readiness":"iso-readiness-closure","iso-readiness-closure":"iso-readiness-closure"},"legacyNodeOrder":["isms-readiness-scope","iso-clause-control-review","iso-assurance-readiness","iso-readiness-closure"],"legacyRequiredApprovals":{"isms-readiness-scope":0,"iso-clause-control-review":0,"iso-assurance-readiness":1,"iso-readiness-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"audit"},"roles":[{"id":"reviewer-1","description":"Engagement lead. Assess clauses and Statement of Applicability.","nodeIds":["iso-clause-control-review"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent audit supervisor. Approve ISO 27001 readiness record.","nodeIds":["iso-readiness-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:audit-iso27001-stage1-documentation-review"}]},"teams":["internal-audit"],"capabilities":["iso27001-certification-readiness"]}},{"sourceTemplateId":"coworkcanvas:template:risk-assessment-treatment-review","name":"Risk Assessment & Treatment Review","description":"Runs on the existing risk item. Assess a risk against current context and evidence, select a supported treatment response, and approve a traceable review record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"risk","autoCreateOnItem":true,"nodes":[{"id":"risk-assessment","data":{"label":"Assess exposure and control response","kind":"task","instructions":"**Objective**\nAssess exposure and control response. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, business objectives, process and system maps, incidents, issues, loss events, prior assessments, control results, external changes, and approved scoring criteria.\n2. Use the confirmed context, scoring rubric, control design and testing results, monitoring trends, incidents, issues, scenarios, threat information, financial data, and owner representations.\n\n**Procedure**\n1. Reframe the risk as a clear cause-event-impact statement, confirm affected assets and stakeholders, reconcile ownership, identify material assumptions and dependencies, and document scope changes since the prior review.\n2. Score each required dimension, test the rationale against cited facts, evaluate control coverage and limitations, compare current and prior results, perform scenario analysis where material, and challenge optimistic assumptions.\n\n**Record in AssureSwarm**\n1. Capture the assessment period, risk context, owner, affected objectives, boundaries, assumptions, dependencies, change triggers, source references, and information gaps.\n2. Document scores, rating direction, calculation or rubric applied, supporting and contrary evidence, control reliance, uncertainty, sensitivity, prior-period comparison, and unresolved data requests. Also record assessment result.\n\n**Exit criteria**\nRisk assessment specialist provides expertise: The risk statement is decision-useful, ownership and assessment criteria are confirmed, and gaps that could change the assessment are visible and assigned. The assessment is reproducible from the cited evidence, rating changes are explained, and material uncertainty or control limitations are carried into treatment analysis.","requiredApprovals":1,"controls":[],"type":"TASK"},"position":{"x":0,"y":0}},{"id":"risk-review-closure","data":{"label":"Approve risk review record","kind":"task","instructions":"**Objective**\nApprove risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, appetite and tolerance statements, existing initiatives, proposed controls, insurance or contractual terms, budget and resource constraints, dependencies, and stakeholder analysis.\n2. Review all stage records, scoring support, control evidence, treatment analysis, appetite exceptions, stakeholder responses, linked actions, monitoring measures, and open information gaps.\n\n**Procedure**\n1. Compare accept, mitigate, transfer, and avoid options; estimate risk reduction and secondary effects; define measurable actions and escalation triggers; identify owners and dates; and route appetite exceptions to authorized governance.\n2. Trace material ratings and decisions to evidence, verify action ownership and dates, confirm contrary evidence remains visible, reconcile linked records, and return incomplete or inconsistent analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the treatment decision, rationale, response plan, expected residual exposure, action owners, milestones, resources, dependencies, monitoring indicators, escalation thresholds, and linked remediation items.\n2. Capture the authorized reviewer, the review summary, accepted assessment and treatment references, effective review date, monitoring cadence, linked actions, open limitations, owners, and due dates. Also record risk review summary.\n\n**Exit criteria**\nRisk acceptance authority provides approval: An approver accepts that the selected response follows from the assessment and appetite criteria, while rejected options and any required exception approval remain traceable. The authorized reviewer accepts the risk review as a traceable record of analysis and decisions, linked records can be updated consistently, and no assurance claim is inferred from closure.","requiredApprovals":1,"controls":["UC-RISK-04","UC-RISK-07","UC-RISK-08","UC-RISK-09","UC-RISK-13"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-risk-assessment-risk-review-closure","source":"risk-assessment","target":"risk-review-closure"}],"metadata":{"kind":"risk-assessment-treatment-review","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:grc-risk-assessment-treatment-review","sourceNodeMap":{"risk-context":"risk-assessment","risk-assessment":"risk-assessment","risk-treatment":"risk-review-closure","risk-review-closure":"risk-review-closure"},"legacyNodeOrder":["risk-context","risk-assessment","risk-treatment","risk-review-closure"],"legacyRequiredApprovals":{"risk-context":0,"risk-assessment":0,"risk-treatment":1,"risk-review-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"risk"},"roles":[{"id":"reviewer-1","description":"Risk assessment specialist. Assess exposure and control response.","nodeIds":["risk-assessment"],"contribution":"expertise"},{"id":"reviewer-2","description":"Risk acceptance authority. Approve risk review record.","nodeIds":["risk-review-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-enterprise-risk-assessment-cycle"}]},"teams":["risk-management"],"capabilities":["risk-assessment-treatment-review"]}},{"sourceTemplateId":"coworkcanvas:template:erm-risk-identification-register-refresh","name":"ERM Risk Identification & Register Refresh","description":"Runs on the existing risk item. Run a periodic enterprise risk identification cycle, consolidate candidate risks, and approve the resulting register changes. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"risk","autoCreateOnItem":false,"nodes":[{"id":"erm-refresh-closure","data":{"label":"Approve register refresh record","kind":"task","instructions":"**Objective**\nApprove register refresh record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the enterprise risk taxonomy, prior cycle output, strategy and objective statements, organizational structure, incidents, issues, audit results, control failures, external environment reports, and the approved risk criteria.\n2. Use workshop output, interview notes, incident and loss data, audit and assurance findings, control testing results, external threat and regulatory intelligence, strategic initiatives, and the current register.\n3. Use the consolidated candidate set, the taxonomy and domain vocabulary, organizational accountability maps, existing register entries and their owners, and the qualification criteria from the scoping stage.\n4. Review all stage records, the candidate inventory and its source attribution, duplicate dispositions, taxonomy placements, ownership nominations, watchlist referrals, and open coverage gaps.\n\n**Procedure**\n1. Fix the cycle boundaries, confirm which units and domains participate, reconcile the taxonomy version against the register, identify data sources and workshop participants, and document coverage exclusions with rationale.\n2. Normalize each candidate into a cause-event-impact statement, compare it against existing register entries, merge genuine duplicates, keep materially distinct exposures separate, and record why each merge or split was chosen.\n3. Assign category and subcategory, map affected domains, nominate an accountable owner with the authority to act, choose the register action, and route contested ownership or classification to the accountable role before advancing.\n4. Trace material additions and merges to their evidence, confirm every new entry has an accountable owner and a next assessment date, verify excluded scope remains visible, and return incomplete classification with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the cycle period, identification scope, taxonomy version, participating units, data sources, qualification criteria, exclusions, accountable facilitator, and known coverage gaps.\n2. Document the candidate inventory, source attribution for each candidate, duplicate disposition, merge and split rationale, withdrawn candidates, and candidates deferred to the watchlist.\n3. Record the taxonomy placement, register action, nominated owner, affected domains, prior entry references for merges and updates, contested classifications, and items routed to the watchlist.\n4. Capture the authorized reviewer, the refresh summary, accepted register actions, effective cycle date, next cycle cadence, watchlist referrals, open coverage gaps, owners, and due dates.\n\n**Exit criteria**\nRisk register owner provides approval: The cycle scope is explicit, the taxonomy and qualification criteria are agreed, and exclusions that could hide exposure are visible and assigned. Every candidate is traceable to a source, duplicates are resolved with stated reasoning, and the surviving set is ready for taxonomy placement. An approver accepts that each classification and ownership assignment follows from the consolidation evidence, and unresolved ownership is escalated rather than defaulted. The authorized reviewer accepts the refresh as a traceable record of identification work, the register can be updated consistently, and no assurance over completeness of risk identification is implied by closure.","requiredApprovals":1,"controls":["UC-RISK-07","UC-RISK-10"],"type":"TASK"},"position":{"x":0,"y":0}}],"edges":[],"metadata":{"kind":"erm-risk-identification-register-refresh","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:grc-risk-register-refresh","sourceNodeMap":{"erm-cycle-scope":"erm-refresh-closure","erm-candidate-consolidation":"erm-refresh-closure","erm-register-classification":"erm-refresh-closure","erm-refresh-closure":"erm-refresh-closure"},"legacyNodeOrder":["erm-cycle-scope","erm-candidate-consolidation","erm-register-classification","erm-refresh-closure"],"legacyRequiredApprovals":{"erm-cycle-scope":0,"erm-candidate-consolidation":0,"erm-register-classification":1,"erm-refresh-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"risk"},"roles":[{"id":"reviewer-1","description":"Risk register owner. Approve register refresh record.","nodeIds":["erm-refresh-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-enterprise-risk-register-lifecycle"}]},"teams":["risk-management"],"capabilities":["erm-risk-identification-register-refresh"]}},{"sourceTemplateId":"coworkcanvas:template:risk-appetite-tolerance-calibration","name":"Risk Appetite & Tolerance Calibration","description":"Runs on the existing risk item. Set or recalibrate the appetite statement and tolerance thresholds for a risk, test the current position against them, and approve the escalation record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"risk","autoCreateOnItem":false,"nodes":[{"id":"appetite-statement","data":{"label":"Set appetite statement and tolerance thresholds","kind":"task","instructions":"**Objective**\nSet appetite statement and tolerance thresholds. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, board and committee charters, strategy and objective statements, prior appetite statements, capital and liquidity constraints, regulatory expectations, and the approved risk criteria.\n2. Use the confirmed mandate, the risk assessment and its scoring rubric, loss history, control effectiveness results, monitoring indicators, industry and peer benchmarks, and stakeholder expectations.\n\n**Procedure**\n1. Confirm which body owns the appetite decision, reconcile the stated period against the planning cycle, identify the objectives and constraints the appetite must respect, and document any mandate ambiguity before setting thresholds.\n2. Draft an appetite statement in decision-useful language, define threshold values with units and measurement basis, nominate the indicators that evidence position, test the thresholds against historical data for realism, and record rejected calibrations.\n\n**Record in AssureSwarm**\n1. Capture the appetite period, governance mandate, approving authority, objectives served, binding constraints, prior statement reference, and unresolved mandate questions.\n2. Document the appetite statement, threshold values with units and measurement basis, nominated indicators and their data sources, calibration rationale, rejected alternatives, and measurement limitations. Also record tolerance thresholds.\n\n**Exit criteria**\nRisk appetite authority provides expertise: The approving authority and period are unambiguous, the objectives and constraints are documented, and mandate gaps are escalated rather than assumed. The appetite statement is measurable through named indicators, thresholds are reproducible from a stated basis, and measurement limitations are carried into the position test.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"appetite-closure","data":{"label":"Approve appetite and escalation record","kind":"task","instructions":"**Objective**\nApprove appetite and escalation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the calibrated thresholds, current residual rating, indicator readings and their as-of dates, control testing results, open issues and remediations, and the escalation matrix in the governance mandate.\n2. Review all stage records, calibration rationale and rejected alternatives, indicator readings, threshold comparisons, breach responses, escalation confirmations, and open measurement limitations.\n\n**Procedure**\n1. Read each indicator against its threshold, classify the status, evaluate whether a breach requires acceptance, mitigation, or escalation, define trigger points for re-measurement, and route breaches to the authorized body before advancing.\n2. Trace the statement and thresholds to their stated basis, verify escalations reached the authorized body, confirm monitoring cadence and indicator ownership, and return unsupported calibration with precise comments.\n\n**Record in AssureSwarm**\n1. Record the tolerance status, indicator readings with as-of dates, threshold comparisons, breach response, escalation route and recipients, re-measurement triggers, and any indicator that could not be measured. Also record breach or monitoring response.\n2. Capture the authorized reviewer, the calibration summary, accepted appetite statement and thresholds, effective date, review cadence, escalation confirmations, open limitations, owners, and due dates.\n\n**Exit criteria**\nRisk oversight owner provides approval: An approver accepts that the status follows from the measured readings, breaches are routed to the authorized body, and unmeasurable indicators are declared rather than assumed compliant. The authorized reviewer accepts the calibration as a traceable record of appetite decisions, monitoring can proceed against named indicators, and closure implies no assurance that the position will remain within tolerance.","requiredApprovals":1,"controls":["UC-RISK-03"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-appetite-statement-appetite-closure","source":"appetite-statement","target":"appetite-closure"}],"metadata":{"kind":"risk-appetite-tolerance-calibration","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:grc-risk-appetite-tolerance-calibration","sourceNodeMap":{"appetite-basis":"appetite-statement","appetite-statement":"appetite-statement","tolerance-position":"appetite-closure","appetite-closure":"appetite-closure"},"legacyNodeOrder":["appetite-basis","appetite-statement","tolerance-position","appetite-closure"],"legacyRequiredApprovals":{"appetite-basis":0,"appetite-statement":0,"tolerance-position":1,"appetite-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"risk"},"roles":[{"id":"reviewer-1","description":"Risk appetite authority. Set appetite statement and tolerance thresholds.","nodeIds":["appetite-statement"],"contribution":"expertise"},{"id":"reviewer-2","description":"Risk oversight owner. Approve appetite and escalation record.","nodeIds":["appetite-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-risk-appetite-board-reporting"}]},"teams":["risk-management"],"capabilities":["risk-appetite-tolerance-calibration"]}},{"sourceTemplateId":"coworkcanvas:template:emerging-risk-horizon-scan","name":"Emerging Risk & Horizon Scan","description":"Runs on the existing risk item. Scan the forward horizon for signals of an emerging exposure, assess plausibility and velocity, and decide whether it enters the register or stays on the watchlist. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"risk","autoCreateOnItem":false,"nodes":[{"id":"horizon-closure","data":{"label":"Approve scan record and watchlist disposition","kind":"task","instructions":"**Objective**\nApprove scan record and watchlist disposition. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, strategy and objective statements, prior scan output and watchlist, regulatory and technology intelligence, peer and industry reporting, threat feeds, scenario libraries, and the risk taxonomy.\n2. Use the agreed source list, published intelligence and reporting, internal incident and near-miss data, stakeholder observations, prior watchlist entries and their status, and the qualification criteria.\n3. Use the screened watchlist, scenario analysis, existing control and continuity capability, exposure and dependency maps, expert input, comparable events elsewhere, and the approved risk criteria.\n4. Review all stage records, the signal inventory and its attribution, screening rejections, plausibility and velocity reasoning, dispositions, trigger conditions, dissenting views, and declared blind spots.\n\n**Procedure**\n1. Fix the horizon window, select the domains and objectives in scope, enumerate the sources to be consulted with their reliability, define the signal qualification criteria, and document sources deliberately excluded.\n2. Record each signal with its source and date, apply the qualification criteria consistently, retain signals that fail screening with the reason, look for convergence between weak signals, and challenge confirmation bias in retained selections.\n3. Evaluate plausibility against evidence rather than vividness, rate velocity, estimate impact ranges under stated assumptions, assess current preparedness, define observable trigger conditions, and challenge both dismissal and alarm.\n4. Trace promotions and closures to their evidence, verify trigger conditions have named observers and a cadence, confirm dissent remains visible, reconcile promotions with register entries, and return unsupported dispositions with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the scan horizon, domains and objectives covered, source list with reliability notes, qualification criteria, exclusions and their rationale, accountable scanner, and known blind spots. Also record scan sources.\n2. Document the signal inventory with source and date attribution, screening basis and criteria applied, retained and rejected signals with reasons, convergence observations, and source coverage that returned nothing.\n3. Document plausibility reasoning, velocity rating, impact range with assumptions, preparedness assessment, disposition, trigger conditions with named observers, and dissenting views retained. Also record watchlist disposition.\n4. Capture the authorized reviewer, the scan summary, accepted dispositions, effective scan date, next scan cadence, promoted register references, retained watchlist entries, blind spots, owners, and due dates. Also record horizon scan summary.\n\n**Exit criteria**\nRisk horizon review panel provides variance: The horizon and source coverage are explicit, qualification criteria are stated in advance of screening, and blind spots are visible rather than implied. Every retained signal is traceable to a dated source, rejections are reasoned rather than silent, and the candidate watchlist is ready for assessment. An approver accepts that each disposition follows from the assessed evidence, trigger conditions are observable and owned, and uncertainty is expressed rather than resolved by assertion. The authorized reviewer accepts the scan as a traceable record of forward-looking analysis, watchlist and register stay reconciled, and closure implies no assurance that unscanned exposures do not exist.","requiredApprovals":1,"controls":["UC-RISK-07","UC-RISK-11"],"type":"TASK"},"position":{"x":0,"y":0}}],"edges":[],"metadata":{"kind":"emerging-risk-horizon-scan","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:grc-emerging-risk-horizon-scan","sourceNodeMap":{"horizon-scope":"horizon-closure","signal-screening":"horizon-closure","emerging-assessment":"horizon-closure","horizon-closure":"horizon-closure"},"legacyNodeOrder":["horizon-scope","signal-screening","emerging-assessment","horizon-closure"],"legacyRequiredApprovals":{"horizon-scope":0,"signal-screening":0,"emerging-assessment":1,"horizon-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"risk"},"roles":[{"id":"reviewer-1","description":"Risk horizon review panel. Approve scan record and watchlist disposition.","nodeIds":["horizon-closure"],"contribution":"variance"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:reg-horizon-scanning-triage"}]},"teams":["risk-management"],"capabilities":["emerging-risk-horizon-scan"]}},{"sourceTemplateId":"coworkcanvas:template:control-design-assessment","name":"Control Design Assessment","description":"Runs on the existing control item. Assess whether a control is clearly specified and designed to address its stated risk before deciding what follow-up or testing is appropriate. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"control","autoCreateOnItem":true,"nodes":[{"id":"design-conclusion","data":{"label":"Approve design-assessment conclusion","kind":"task","instructions":"**Objective**\nApprove design-assessment conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, linked risk and requirement records, owner, frequency, system dependencies, assertions, and current narrative or procedure.\n2. Use the approved risk statement, mapped compliance requirements, process objective, financial assertion where relevant, and the scoped control statement from intake.\n3. Consider performance criteria, thresholds, review precision, source-report reliability, segregation of duties, escalation rules, evidence retention, frequency, and the expected population.\n4. Use the approved scope, criterion-level assessment, linked evidence, owner responses, and all unresolved limitations or corrective actions.\n\n**Procedure**\n1. Reconcile the control title and description to the actual activity; identify who performs and reviews it, what population it covers, when it occurs, and which risk mechanism it is intended to interrupt.\n2. Trace each material risk cause and consequence to a specific preventive or detective feature; challenge vague monitoring language, unsupported mappings, and control objectives that merely restate the risk.\n3. Evaluate each design element against the risk and frequency; inspect how exceptions are identified and resolved, how reviewer challenge is shown, and how changes in systems or personnel affect execution.\n4. Confirm that the proposed conclusion matches the evidence, distinguish design observations from execution testing, and verify that gaps and dependencies are neither omitted nor described as tested operating results.\n\nAdditional canonical requirements reviewed with this package:\nDocument Control Objective and Risk Linkage: Identify the control objective, risk addressed, authoritative policy or process, and the consequence if the control does not operate.\nAssess Control Precision: Evaluate the trigger, population, threshold, criteria, performer competence, and review precision needed to prevent or detect the identified risk.\nAssess Evidence Design: Identify the evidence produced, source system, retention period, integrity attributes, and how an independent reviewer can reperform the control.\nConfirm Owner and Frequency: Confirm the accountable owner, operator, cadence, escalation path, and separation between preparation and review are explicit and current.\nRecord Design Conclusion: Record whether the design is adequate, each gap or compensating control, and the owner and due date for required remediation.\n\n**Record in AssureSwarm**\n1. Document the in-scope control statement, assessment period, stakeholders, dependencies, and any boundary exclusions that could change the conclusion. Also record scope notes.\n2. Capture the alignment result by risk or requirement, the rationale for each mapping, gaps in coverage, and any redundant or compensating activity considered. Also record risk-response alignment.\n3. Record criterion-level observations, supporting examples, information-produced-by-entity dependencies, identified design gaps, and the basis for the provisional design result.\n4. State the conclusion, rationale, scope limitations, design improvements, owners, and target dates; link any resulting Issue or remediation record rather than burying it in narrative. Also record design assessment conclusion; follow-up actions.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The control and risk boundary are unambiguous, the accountable participants are identified, and missing source material is either obtained or logged for follow-up. Every claimed risk response is supported by a concrete control feature and any uncovered exposure is described precisely enough to assign corrective action. The design result follows from documented criteria, material gaps are separated from editorial improvements, and necessary corrective actions have accountable owners. The authorized reviewer can trace the conclusion to the recorded criteria, limitations are explicit, and all follow-up work is assigned without implying effectiveness from workflow completion.","requiredApprovals":1,"controls":["UC-AUDIT-13","UC-AUDIT-21"],"type":"TASK"},"position":{"x":0,"y":0}}],"edges":[],"metadata":{"kind":"control-design-assessment","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:audit-control-design-assessment","sourceNodeMap":{"design-intake":"design-conclusion","risk-response":"design-conclusion","design-criteria":"design-conclusion","design-conclusion":"design-conclusion"},"legacyNodeOrder":["design-intake","risk-response","design-criteria","design-conclusion"],"legacyRequiredApprovals":{"design-intake":0,"risk-response":1,"design-criteria":1,"design-conclusion":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"control"},"roles":[{"id":"reviewer-1","description":"Test supervisor independent of the operator. Approve design-assessment conclusion.","nodeIds":["design-conclusion"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-design"}]},"teams":["internal-audit"],"capabilities":["control-design-assessment"]}},{"sourceTemplateId":"coworkcanvas:template:control-walkthrough","name":"Control Walkthrough","description":"Runs on the existing control item. Walk one representative transaction or event through the control to understand actual execution, evidence, handoffs, and changes. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"control","autoCreateOnItem":true,"nodes":[{"id":"walkthrough-conclusion","data":{"label":"Approve walkthrough conclusion","kind":"task","instructions":"**Objective**\nApprove walkthrough conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current control description, process narrative, system flow, prior walkthrough, open changes, linked risks, and the population from which an occurrence can be selected.\n2. Use the selected occurrence, control procedure, role assignments, screen or report access, expected evidence, and the preparer questions derived during planning.\n3. Use source documents, system timestamps, report parameters, approvals, exception logs, downstream records, and the execution sequence established through inquiry.\n4. Review the plan, inquiry notes, complete evidence trace, deviations, owner explanations, system changes, and any open documentation questions.\n\n**Procedure**\n1. Select a recent representative occurrence without allowing the owner to substitute a polished example; schedule the preparer, performer, reviewer, and system contacts needed to explain each handoff.\n2. Ask the performer to demonstrate the activity in sequence, explain decision points and exceptions, identify reports and parameters used, and show how reviewer challenge differs from routine preparation.\n3. Agree identifiers and amounts across each handoff, inspect the timing and authority of approvals, reproduce key report filters where feasible, and investigate missing links or post-dated evidence.\n4. Reconcile observed practice to the control and process narratives, assess whether deviations require documentation or design changes, and separate walkthrough observations from any later population-based testing conclusion.\n\nAdditional canonical requirements reviewed with this package:\nSelect a Real Control Occurrence: Select a representative occurrence and document the date, population context, operator, and source records used for the walkthrough.\nInterview the Control Operator: Interview the operator about trigger, decision points, exceptions, tools, handoffs, and evidence retention; capture any practice variation.\nTrace Inputs, Actions and Outputs: Trace the occurrence from complete inputs through performed actions and resulting output, checking that each documented control activity occurred.\nInspect Retained Evidence: Inspect retained evidence for completeness, integrity, timing, and retrievability; link the source records sufficient for reperformance.\nRecord Practice-versus-Documentation Conclusion: Record whether observed practice matches the approved procedure, list deviations, and route material gaps to exception remediation.\n\n**Record in AssureSwarm**\n1. Record the occurrence identifier, date, participants, systems, planned route, known changes, and any confidentiality or access constraints affecting evidence capture. Also record walkthrough date.\n2. Capture who performed each action, what was observed, the systems and reports used, key judgments, deviations from the documented design, and evidence references for the occurrence. Also record inquiry and observation summary.\n3. Map the evidence chain, note agreements and deviations at each point, identify system-generated dependencies, and record whether the occurrence is representative of normal execution. Also record trace result.\n4. Document the conclusion, changes required, evidence limitations, responsible owners, target dates, and links to any issue, design assessment, or planned test prompted by the walkthrough. Also record changes and follow-up.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: A traceable occurrence and knowledgeable participants are confirmed, the route covers initiation through evidence retention, and known changes are in scope. The actual execution sequence and reviewer involvement are understood, unsupported explanations are flagged, and each key claim has observable or documentary support. The occurrence is traceable end to end or the precise break is documented, observed deviations are supported, and the trace result is ready for independent review. The authorized reviewer can follow the occurrence and rationale, documentation changes are assigned, and the record does not overstate what a single walkthrough demonstrates.","requiredApprovals":1,"controls":["UC-AUDIT-13","UC-AUDIT-21"],"type":"TASK"},"position":{"x":0,"y":0}}],"edges":[],"metadata":{"kind":"control-walkthrough","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:audit-control-walkthrough","sourceNodeMap":{"walkthrough-plan":"walkthrough-conclusion","performer-inquiry":"walkthrough-conclusion","transaction-trace":"walkthrough-conclusion","walkthrough-conclusion":"walkthrough-conclusion"},"legacyNodeOrder":["walkthrough-plan","performer-inquiry","transaction-trace","walkthrough-conclusion"],"legacyRequiredApprovals":{"walkthrough-plan":0,"performer-inquiry":0,"transaction-trace":1,"walkthrough-conclusion":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"control"},"roles":[{"id":"reviewer-1","description":"Test supervisor independent of the operator. Approve walkthrough conclusion.","nodeIds":["walkthrough-conclusion"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-walkthrough"}]},"teams":["internal-audit"],"capabilities":["control-walkthrough"]}},{"sourceTemplateId":"coworkcanvas:template:control-interim-operating-effectiveness","name":"Interim Operating Effectiveness Testing","description":"Runs on the existing control item. Test a defined interim-period population using a documented sampling and attribute plan, then record exceptions and a bounded conclusion. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"control","autoCreateOnItem":false,"nodes":[{"id":"population-validate","data":{"label":"Validate the population and select the sample","kind":"task","instructions":"**Objective**\nValidate the population and select the sample. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current control design, walkthrough, population source, risk and assertion mapping, prior results, changes, and the program-specific sampling methodology.\n2. Use the native system extract, report logic and parameters, control frequency, period calendar, sequence counts, reconciliations, owner certification and source totals, together with the sampling guidance, random seed or interval, required sample size and high-risk strata.\n\n**Procedure**\n1. Confirm the control was in scope and available throughout the period, identify excluded intervals or implementations, set the test attributes, and obtain approval for any planned reliance on prior work.\n2. Inspect report parameters, reconcile counts and key totals, test sequence or date coverage, identify duplicates and omissions, and assess whether manual additions changed the source population. Then execute the selection once, preserve the method and seed, distinguish random from targeted selections, and investigate unavailable items rather than silently replacing them.\n\n**Record in AssureSwarm**\n1. Document the period, objective, frequency, population owner, expected evidence, attributes, scope exclusions, and the source of the sampling approach. Also record interim period; test objective.\n2. Retain the original population, extraction evidence, parameter screenshots, reconciliations, final count and the rationale for accepting it, then the sample listing with stable identifiers, selection method, seed or interval, strata and replacement rationale, linked back to the frozen population. Also record population validation; sample size.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The approved plan states what will be tested and what it cannot demonstrate, all period gaps are visible, and the population request is reproducible. The population can be reproduced and tied to an authoritative source, every selected item traces to it, the method can be re-created, substitutions are justified, and the sample is ready for attribute testing.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"interim-conclusion","data":{"label":"Approve interim test conclusion","kind":"task","instructions":"**Objective**\nApprove interim test conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the frozen sample, attribute definitions, expected evidence, source documents, system records, approvals, reviewer annotations, and approved handling for unavailable evidence.\n2. Review the test plan, population validation, selection record, per-item results, exception responses, scope limitations, control changes, and the untested portion of the year.\n\n**Procedure**\n1. Apply attributes consistently, retain per-item support, distinguish control failure from documentation deficiency, corroborate dates and authority, and obtain owner responses without changing the original tester result.\n2. Recalculate result counts, assess whether exceptions require separate evaluation, identify unresolved evidence gaps, and design a roll-forward plan proportionate to elapsed time, frequency, risk, and change.\n\n**Record in AssureSwarm**\n1. Complete the item-by-attribute matrix, reference evidence files, record exceptions and explanations, identify missing support, and summarize counts without obscuring individual results. Also record items with exceptions.\n2. State the interim conclusion and basis, exceptions and limitations, affected assertions or risks, planned roll-forward procedures, owners, timing, and links to issue or remediation records. Also record period-end roll-forward plan.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: Every sample and attribute has a supported disposition, exceptions are reproducible and owner responses are retained separately, and the matrix reconciles to the sample. The authorized reviewer can trace the bounded conclusion to the work, remaining period-end procedures are explicit, and completion is not described as proof beyond the tested interim period.","requiredApprovals":1,"controls":["UC-AUDIT-21"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-population-validate-interim-conclusion","source":"population-validate","target":"interim-conclusion"}],"metadata":{"kind":"control-interim-operating-effectiveness","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:sox-control-interim-testing-record","sourceNodeMap":{"interim-scope":"population-validate","population-validate":"population-validate","attribute-test":"interim-conclusion","interim-conclusion":"interim-conclusion"},"legacyNodeOrder":["interim-scope","population-validate","attribute-test","interim-conclusion"],"legacyRequiredApprovals":{"interim-scope":0,"population-validate":1,"attribute-test":1,"interim-conclusion":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"control"},"roles":[{"id":"reviewer-1","description":"Test supervisor independent of the operator. Validate the population and select the sample.","nodeIds":["population-validate"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent audit reviewer. Approve interim test conclusion.","nodeIds":["interim-conclusion"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-interim-operating-effectiveness-testing"}]},"teams":["internal-audit"],"capabilities":["control-interim-operating-effectiveness"]}},{"sourceTemplateId":"coworkcanvas:template:control-period-end-roll-forward","name":"Period-End Roll-Forward / Rollover Testing","description":"Runs on the existing control item. Bridge an approved interim control test through period end by assessing change, remaining occurrences, incremental evidence, and unresolved exceptions. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"control","autoCreateOnItem":false,"nodes":[{"id":"change-assessment","data":{"label":"Assess changes since interim","kind":"task","instructions":"**Objective**\nAssess changes since interim. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Obtain the approved interim workpaper, tested population and result, remaining-period calendar, control frequency, open exceptions, changes, and period-end reporting deadline.\n2. Use change tickets, release logs, organization changes, updated narratives, incident records, exception logs, owner inquiry, configuration evidence, and current risk assessments.\n\n**Procedure**\n1. Verify the interim work is final and applicable to the same control, reconcile the untested interval and expected occurrences, and identify limitations that require new testing rather than roll-forward reliance.\n2. Compare each relevant control element to the interim state, corroborate inquiry with records, evaluate the effective date and affected occurrences, and decide whether targeted bridge work or full retesting is necessary.\n\n**Record in AssureSwarm**\n1. Record the interim reference, cutoff dates, remaining occurrences, applicable assertions, unresolved items, planned bridge method, and rationale for the selected approach. Also record bridge period; approved interim work reference.\n2. Document each change considered, evidence reviewed, timing, impact on design and prior results, decision, and the additional procedure required to address it. Also record change assessment.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The bridge period and reliance basis are precise, the expected remaining population is quantified, and ineligible prior work is excluded before further procedures. The change assessment is supported rather than inquiry-only, material changes are reflected in the test plan, and the approved bridge approach remains defensible.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"rollforward-conclusion","data":{"label":"Approve period-end conclusion","kind":"task","instructions":"**Objective**\nApprove period-end conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the native remaining-period extract, frequency calendar, sequence records and period-end close schedule, together with the approved change assessment, selection plan, control attributes, period-end evidence, interim exceptions and any targeted high-risk items.\n2. Review interim conclusions, change assessment, remaining-population reconciliation, incremental results, exception evaluations, scope limitations, and period-end evidence.\n\n**Procedure**\n1. Reconcile the first and last occurrence, inspect gaps and duplicates, identify period-end and nonroutine events, and separate out-of-scope records with reasons. Then test selected occurrences consistently with interim attributes, perform additional procedures for changes, revisit unresolved exceptions, and retain per-item conclusions and reviewer challenge.\n2. Confirm the bridge covers the full remaining interval, reconcile results and exceptions, challenge reliance where changes occurred, and identify any additional work before recording the bounded conclusion.\n\n**Record in AssureSwarm**\n1. Retain the source population, count reconciliation, identified special items and excluded records, and the final population used for selection; then complete the incremental results matrix with evidence references, change-specific procedures, exception status and tested counts reconciled to that population. Also record remaining occurrences; incremental exceptions.\n2. Document the result, basis, interim and incremental references, changes, exceptions, limitations, affected risks, and links to issue or remediation follow-up. Also record roll-forward conclusion; conclusion basis.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: The remaining population bridges exactly from interim to period end, all planned bridge procedures are complete, results reconcile to selected items, exceptions are evaluated or routed, and no unsupported gap remains. The authorized reviewer can trace the period-end result across both work periods, exceptions and limitations remain visible, and completion does not substitute for the recorded evidence-based conclusion.","requiredApprovals":1,"controls":["UC-AUDIT-21"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-change-assessment-rollforward-conclusion","source":"change-assessment","target":"rollforward-conclusion"}],"metadata":{"kind":"control-period-end-roll-forward","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:sox-control-roll-forward-record","sourceNodeMap":{"rollforward-intake":"change-assessment","change-assessment":"change-assessment","incremental-testing":"rollforward-conclusion","rollforward-conclusion":"rollforward-conclusion"},"legacyNodeOrder":["rollforward-intake","change-assessment","incremental-testing","rollforward-conclusion"],"legacyRequiredApprovals":{"rollforward-intake":0,"change-assessment":1,"incremental-testing":1,"rollforward-conclusion":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"control"},"roles":[{"id":"reviewer-1","description":"Test supervisor independent of the operator. Assess changes since interim.","nodeIds":["change-assessment"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent audit reviewer. Approve period-end conclusion.","nodeIds":["rollforward-conclusion"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-period-end-roll-forward-testing"}]},"teams":["internal-audit"],"capabilities":["control-period-end-roll-forward"]}},{"sourceTemplateId":"coworkcanvas:template:control-exception-evaluation-remediation","name":"Control Exception Evaluation & Remediation","description":"Runs on the existing control item. Validate a control-test exception, evaluate its scope and implications, determine disposition, and establish accountable remediation where needed. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"control","autoCreateOnItem":false,"nodes":[{"id":"impact-evaluate","data":{"label":"Evaluate impact and disposition","kind":"task","instructions":"**Objective**\nEvaluate impact and disposition. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved testing matrix, failed attribute and supporting evidence, tester notes and owner response, existing Issue records, comparable occurrences, population data, system changes and the relevant policy or procedure.\n2. Use the validated facts, extent analysis, risk and requirement mappings, prior exceptions, compensating-control evidence, relevant program criteria, and management response.\n\n**Procedure**\n1. Restate the observed condition factually, verify the evidence reference, distinguish a control deviation from a testing or documentation error, and search for related exceptions before opening anything new. Then reperform the failed attribute, challenge alternative explanations, inspect additional occurrences when warranted, determine the condition window, and identify whether the same cause could affect untested items.\n2. Assess likelihood and consequence without conflating sample rate with population impact, validate claimed compensating controls, consider aggregation with related conditions, and select a disposition supported by evidence.\n\n**Record in AssureSwarm**\n1. Capture the source test, item identifiers, attribute, expected and observed condition, duplicate check and initial owner response, then the validation steps, corroborating evidence, additional items reviewed, confirmed facts, affected period and population, rejected explanations and the validation result. Also record exception reference; exception summary.\n2. Record the impact factors, compensating activity, aggregation analysis, rationale, disposition, affected risks or assertions, escalation needs, and links to any formal Issue.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The exception is reproducible from source work and described without premature severity language, the condition is confirmed or closed with a supported reason, potential extent is bounded, and open information requests have owners and due dates. The disposition is approved and traceable to stated criteria, unsupported mitigation claims are excluded, and conditions requiring action advance to an accountable remediation plan.","requiredApprovals":1,"controls":[],"type":"TASK"},"position":{"x":0,"y":0}},{"id":"exception-conclusion","data":{"label":"Approve exception evaluation","kind":"task","instructions":"**Objective**\nApprove exception evaluation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the confirmed condition, root-cause analysis, impact disposition, owner proposal, change constraints, affected procedures and systems, and required reporting dates.\n2. Review intake, validation, extent and impact analyses, disposition approval, linked Issue and remediation records, monitoring commitments, and remaining limitations.\n\n**Procedure**\n1. Challenge whether proposed actions address cause rather than symptoms, define measurable completion evidence, establish interim safeguards, set realistic milestones, and design retesting independent of self-certified completion.\n2. Confirm the narrative is internally consistent, all evidence references resolve, the disposition matches the analysis, duplicate records are avoided, and required escalation or reporting has occurred.\n\nAdditional canonical requirements reviewed with this package:\nClassify Control Exception: Record the failed control attribute, occurrence, evidence, preliminary cause, and whether the exception is isolated, systemic, or suspected fraud.\nAssess Scope and Impact: Determine affected population, systems, data, customers, financial or compliance impact, and whether expanded testing or escalation is required.\nDetermine Deficiency Severity: Apply the documented severity criteria, identify compensating controls, and state the rationale for the assigned deficiency level.\nAssign Corrective Action: Define corrective action, accountable owner, target date, validation evidence, and interim safeguard while remediation remains open.\nRecord Containment Decision and Approval: Approve the containment plan, escalation path, and acceptance decision; do not close this record without a documented owner and due date.\n\n**Record in AssureSwarm**\n1. Create or link the remediation record and capture owner, actions, milestones, target date, interim measures, completion evidence, validator, retest population, and escalation threshold. Also record planned validation method.\n2. State the approved evaluation conclusion, rationale, open actions, owners, dates, linked records, and the event that will trigger retest, monitoring review, or final closure.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: The plan addresses the documented cause, responsibilities and dates are accepted, validation is executable, and any risk acceptance follows the proper approval route. The authorized reviewer accepts the evaluation and handoff, every open action lives in a trackable record, and this workflow does not imply remediation is effective or closed before validation.","requiredApprovals":1,"controls":["UC-AUDIT-14","UC-RISK-14"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-impact-evaluate-exception-conclusion","source":"impact-evaluate","target":"exception-conclusion"}],"metadata":{"kind":"control-exception-evaluation-remediation","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:audit-control-exception-evaluation-remediation","sourceNodeMap":{"exception-validate":"impact-evaluate","impact-evaluate":"impact-evaluate","remediation-plan":"exception-conclusion","exception-conclusion":"exception-conclusion"},"legacyNodeOrder":["exception-validate","impact-evaluate","remediation-plan","exception-conclusion"],"legacyRequiredApprovals":{"exception-validate":1,"impact-evaluate":1,"remediation-plan":1,"exception-conclusion":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"control"},"roles":[{"id":"reviewer-1","description":"Test supervisor independent of the operator. Evaluate impact and disposition.","nodeIds":["impact-evaluate"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent audit reviewer. Approve exception evaluation.","nodeIds":["exception-conclusion"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-deficiency-remediation"}]},"teams":["internal-audit","risk-management"],"capabilities":["control-exception-evaluation-remediation"]}},{"sourceTemplateId":"coworkcanvas:template:control-remediation-retest-closure","name":"Control Remediation Retest & Closure","description":"Runs on the existing control item. Verify remediation readiness, independently retest the changed control, evaluate sustained results, and approve a supported closure decision. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"control","autoCreateOnItem":false,"nodes":[{"id":"retest-plan","data":{"label":"Confirm readiness and approve the independent retest plan","kind":"task","instructions":"**Objective**\nConfirm readiness and approve the independent retest plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved remediation plan and its completion evidence, change tickets, updated control description, owner certification and expected post-change occurrences, with the original exception, impact evaluation, updated attributes and independence requirements.\n\n**Procedure**\n1. Inspect implementation evidence rather than accepting status, compare delivered actions to the plan, verify effective dates and scope, and quantify occurrences since implementation. Then set the period, population, sample or full-inspection method, attributes, evidence expectations, recurrence criteria, tester independence and treatment of transitional items.\n\n**Record in AssureSwarm**\n1. Document each action with its evidence reference and implementation date, deviations from plan, the available population and the readiness decision, then the approved scope, tester, population source, sample basis, attributes, change-specific procedures, success criteria and exclusions. Also record readiness result; retest period; retest method.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The remediation is demonstrably implemented or returned with precise gaps, enough post-change activity exists for the chosen method, the plan directly tests the remediated cause, independence is documented, and success criteria are set before execution.","requiredApprovals":1,"controls":[],"type":"TASK"},"position":{"x":0,"y":0}},{"id":"retest-closure","data":{"label":"Approve remediation closure","kind":"task","instructions":"**Objective**\nApprove remediation closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the frozen post-change population, approved selection, updated control criteria, implementation evidence, source records, system logs, approvals, and original failure pattern.\n2. Review the approved plan, item-level results, new exceptions, original root cause, implementation timeline, monitoring evidence, control frequency, and owner accountability.\n3. Use all remediation milestones, retest work, exception results, evaluation, monitoring commitments, Issue status, owner response, and required governance approvals.\n\n**Procedure**\n1. Test each item consistently, retain evidence for all attributes, compare results to the original condition, investigate anomalies and unavailable support, and keep management explanations separate from tester results.\n2. Reconcile counts, assess any recurrence or new failure mode, consider whether the observation period is representative, verify sustainable ownership and monitoring, and decide whether added work is necessary.\n3. Confirm closure criteria are met, link the exact evidence supporting each criterion, verify related records are consistent, and return or reopen the matter when limitations or recurrence prevent closure.\n\nAdditional canonical requirements reviewed with this package:\nVerify Remediation Implementation: Verify the approved corrective action is implemented as designed, including configuration, procedure, owner, and retained implementation evidence.\nSelect Post-Remediation Sample: Define the post-remediation population and select a sample that covers the corrected control operation and relevant risk scenarios.\nReperform Failed Attributes: Independently reperform the attributes that failed, comparing evidence and timing to the corrected design rather than relying on management assertion.\nAssess Recurrence Risk: Assess whether the root cause can recur, whether related controls require testing, and whether compensating controls remain necessary.\nIndependently Approve Closure: Record the independent closure conclusion, residual risk, linked evidence, and any follow-up monitoring required after closure.\n\n**Record in AssureSwarm**\n1. Complete the item-level matrix, evidence links, tester identity, dates, exception details, recurrence analysis, count reconciliation, and any deviations from the approved plan. Also record items tested; exceptions found.\n2. Document the evaluation, result pattern, sustainability factors, limitations, monitoring commitments, reopened actions, and the rationale for closure consideration or continued remediation. Also record retest evaluation.\n3. Record the decision, rationale, approvers, closure or continuation date, remaining monitoring, linked Issue and remediation updates, and any residual action owner.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: All planned items and attributes have supported results, deviations are approved or resolved, observed exceptions are reproducible, and the work is ready for independent evaluation. The evaluation follows the preapproved criteria, contrary evidence is addressed, remaining risk is explicit, and only supported cases advance to final closure approval. The authorized reviewer accepts a decision supported by the full record, linked statuses can be updated consistently, and workflow completion is not used as a substitute for the explicit closure decision.","requiredApprovals":1,"controls":["UC-AUDIT-17","UC-AUDIT-21"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-retest-plan-retest-closure","source":"retest-plan","target":"retest-closure"}],"metadata":{"kind":"control-remediation-retest-closure","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:audit-control-remediation-retest-closure","sourceNodeMap":{"retest-plan":"retest-plan","retest-execute":"retest-closure","sustainability-evaluate":"retest-closure","retest-closure":"retest-closure"},"legacyNodeOrder":["retest-plan","retest-execute","sustainability-evaluate","retest-closure"],"legacyRequiredApprovals":{"retest-plan":1,"retest-execute":1,"sustainability-evaluate":1,"retest-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"control"},"roles":[{"id":"reviewer-1","description":"Test supervisor independent of the operator. Confirm readiness and approve the independent retest plan.","nodeIds":["retest-plan"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent audit reviewer. Approve remediation closure.","nodeIds":["retest-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-remediation-delivery"}]},"teams":["internal-audit"],"capabilities":["control-remediation-retest-closure"]}},{"sourceTemplateId":"coworkcanvas:template:sox-control-testing","name":"SOX Control Testing","description":"Runs on an existing SOX-applicable Control under a sox-testing template. SAMPLE reviews history, attributes and reproducible selection; TEST reviews evidence, exceptions and the approved result artifact. Keep fiscal year on Workflow.customFields.sox.fiscalYear and hand the published result to the SOX program.","itemTypeSlug":"control","autoCreateOnItem":false,"nodes":[{"id":"sample","data":{"label":"SAMPLE","kind":"task","instructions":"**Objective**\nSAMPLE. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, SOX applicability, walkthrough and design work, risk and FSLI mappings, control frequency and the approved test plan, with prior approved workpapers, previous exceptions and remediation, change assessments and program reliance guidance.\n2. Review the approved control design, risk and assertion mapping, walkthrough, policy or procedure, reviewer precision, thresholds, system dependencies, the approved history and reliance decision, and prior attribute definitions.\n3. Use the native population extract, report parameters, control frequency, expected occurrence count, the approved attribute plan and its population applicability, sampling guidance, prior-period considerations, and approved targeted strata.\n\n**Procedure**\n1. Verify the control was in scope for the period, reconcile its description to program documentation, identify design or ownership changes and define reliance boundaries. Then confirm prior work relates to the same control and attributes, compare performers, systems, frequency and evidence, identify recurring conditions, and document whether history informs expectations or qualifies for approved reliance.\n2. Translate each essential control feature into an observable pass/fail criterion, define not-applicable handling, specify expected evidence and timing, and distinguish design, performance, and review attributes.\n3. Validate completeness and accuracy, reconcile counts and date coverage, preserve the original population, execute the approved random, systematic, targeted, or full-population selection, and document replacements.\n\n**Record in AssureSwarm**\n1. Document the fiscal period, scope, control version, assertions, preparer and reviewer roles, known changes and limitations; attach or link the prior workpaper and record its period, conclusion, exceptions, remediation status, the reliance decision and the procedure it affects. Also record testing scope summary; history and reliance assessment.\n2. List each numbered attribute, its expected value or evidence, population applicability, source, failure condition, and approved treatment for missing or conflicting support. Also record attribute plan.\n3. Record the period and test kind in the native sample result, attach the frozen population and sample listing, and record extraction logic, reconciliation, sample size, selection method, seed or interval, and substitutions. Also record test of design; test of operating effectiveness.\nStep.result is markdown. Include exactly one versioned JSON block with the actual period and kind (tod or toe):\n```json\n{\"soxSample\":{\"schemaVersion\":1,\"period\":\"2026-Q2\",\"kind\":\"toe\"}}\n```\nReplace the example period for this run. Keep fiscal year in Workflow.customFields.sox.fiscalYear.\n\nRecord `period` (Testing period) in Step.result fenced json soxSample.period.\n\nRecord `kind` (Test kind; values: tod, toe) in Step.result fenced json soxSample.kind.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The test objective and period are unambiguous under an approved scope, history is considered without replacing current-period evidence, recurring matters are carried forward visibly, any reliance is approved, bounded and supported, and its effect on attribute scope and sample extent is stated. Attributes cover the relevant control features without ambiguity, can be applied consistently by another tester, and changes after testing starts require documented approval and rework assessment. The population is suitable, every selected item traces to it, the method can be reproduced, and the sample covers the period and risk characteristics required by the plan.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"test","data":{"label":"TEST","kind":"task","instructions":"**Objective**\nApprove SOX testing record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved sample and attributes, original source documents, system records, report outputs, approvals, reviewer annotations, population support, and authorized owner responses.\n2. Use the frozen sample, approved attribute plan, indexed evidence, relevant history, control and risk context, exception criteria, owner responses, and required result schema.\n3. Review the scope, population and sample, attributes, evidence index, history assessment, workpaper, results artifact, proposed conclusion, exceptions, limitations, and linked follow-up records.\n\n**Procedure**\n1. Obtain evidence for each sample and attribute, verify dates and identifiers, retain native or authoritative formats where practical, name files consistently, and flag missing, altered, late, or owner-created-after-selection support.\n2. Test every item and attribute, retain per-cell results and support, distinguish control exceptions from documentation issues, investigate contradictory evidence, reconcile counts, and route confirmed exceptions for evaluation.\n3. Trace selected results to evidence, recalculate counts, challenge contrary evidence and scope limitations, verify published-result compatibility, and return incomplete or inconsistent work with specific review notes.\n\n**Record in AssureSwarm**\n1. Attach evidence to this CAPS stage, maintain a sample-to-file index, record source and receipt date, identify confidentiality restrictions, and cross-reference evidence that legitimately supports multiple attributes. Also record evidence index and gaps.\n2. Upload the annotated workpaper and required results artifact, record the conclusion, exception count and workpaper reference in the markdown step result, and link exception or remediation records without hiding limitations. Also record operating Effectively; exceptions Noted; not Operating Effectively; exceptions count.\n3. Document reviewer comments and resolutions, the approved or returned status, the authorized reviewer, date, remaining limitations, exception handoffs, and the exact workpaper and results references reviewed. Also record final review summary.\nRetain conclusion, exceptions_count and workpaper_reference in the markdown step result. Publish the supported SOX results JSON document and annotated workpaper on TEST using the existing publication schema. Native approval and validated result documents drive publication; narrative alone is not publication.\n\nRecord `conclusion` (Testing conclusion; values: operating_effectively, exceptions_noted, not_operating_effectively) in Step.result markdown.\n\nRecord `exceptions_count` (Exceptions) in Step.result markdown.\n\nRecord `workpaper_reference` (Workpaper reference) in Step.result markdown.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: Each selected item has indexed support or a documented evidence gap, identifiers agree to the sample, source and timing are clear, and testing can begin without relying on undocumented explanations. Results reconcile to the sample and attributes, the proposed conclusion follows the evidence, every exception is traceable, and reviewer approval evaluates the work rather than inferring effectiveness from completion. The authorized reviewer can support the explicit conclusion from the complete record, review notes are resolved or retained, follow-up is assigned, and closure does not create an audit opinion by itself.","requiredApprovals":1,"controls":["UC-AUDIT-21"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-sample-test","source":"sample","target":"test"}],"metadata":{"kind":"sox-testing","source":"studio-seed","framework":"sox","canonicalSourceTemplateId":"workflow-library:sox-control-testing-publication","sourceNodeMap":{"prior-workpapers":"sample","attributes":"sample","sample":"sample","evidence":"test","test":"test","testing-closure":"test"},"legacyNodeOrder":["prior-workpapers","attributes","sample","evidence","test","testing-closure"],"legacyRequiredApprovals":{"prior-workpapers":1,"attributes":1,"sample":1,"evidence":1,"test":1,"testing-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"control"},"roles":[{"id":"reviewer-1","description":"Test supervisor independent of the operator. SAMPLE.","nodeIds":["sample"],"contribution":"approval"},{"id":"reviewer-2","description":"Independent audit reviewer. Approve SOX testing record.","nodeIds":["test"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-key-control-tod-toe-test"}]},"teams":["internal-audit"],"capabilities":["sox-control-testing","audit-testing"]}},{"sourceTemplateId":"coworkcanvas:template:issue-triage-disposition","name":"Issue Triage & Disposition","description":"Runs on the existing issue item. Substantiate a reported issue, assess its severity and cause, select a governed disposition, and approve the triage record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"issue","autoCreateOnItem":true,"nodes":[{"id":"issue-assessment","data":{"label":"Assess severity and cause","kind":"task","instructions":"**Objective**\nAssess severity and cause. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Issue item, source report, exception evidence, incident or complaint records, audit work, policies, requirements, controls, affected transactions, prior issues, and reporter representations.\n2. Use the substantiated condition, affected population, severity criteria, loss or exposure data, control results, related risks, issue history, process and system changes, management responses, and specialist input.\n\n**Procedure**\n1. Validate the reported condition against source evidence, distinguish symptoms from the underlying problem, identify applicable criteria, bound the affected population and period, remove duplicates, and initiate urgent containment when warranted.\n2. Apply the approved severity rubric, quantify or bound exposure, analyze recurrence and aggregation, test proposed causes using evidence, distinguish causal factors from symptoms, and identify uncertainty that could change priority or reporting.\n\n**Record in AssureSwarm**\n1. Capture intake source, issue statement, condition, criteria, affected items and period, reporter, accountable owner, duplicate analysis, immediate safeguards, evidence references, and unresolved questions.\n2. Document severity and rationale, actual and potential impact, affected stakeholders, pervasiveness, recurrence, root cause status and evidence, compensating measures, related issues, and data limitations. Also record severity basis.\n\n**Exit criteria**\nIssue assessment specialist provides expertise: The issue is sufficiently substantiated for assessment, duplicates and unsupported allegations are handled transparently, and urgent exposure has an assigned containment response. The severity and causal analysis are reproducible, contrary evidence is retained, and uncertainties or escalation conditions are explicit before disposition.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"issue-triage-closure","data":{"label":"Approve issue triage record","kind":"task","instructions":"**Objective**\nApprove issue triage record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, remediation feasibility, exception authority, duplicate analysis, legal or regulatory advice, reporting thresholds, stakeholder responses, and proposed ownership and dates.\n2. Review every stage result, source evidence, assessment support, approvals, remediation or exception links, reporting confirmations, management responses, and unresolved information requests.\n\n**Procedure**\n1. Compare remediation, exception, monitoring, merge, and unsubstantiated closure paths; verify decision authority; define reporting and escalation; create required linked actions; and prevent administrative closure from concealing unresolved exposure.\n2. Trace the issue statement and severity to support, verify the disposition and approver authority, reconcile owners and dates across linked records, retain contrary evidence, and return unsupported or inconsistent work for correction.\n\n**Record in AssureSwarm**\n1. Record the disposition, rationale, authorized approver, linked remediation or exception, reporting route, owner, target date, monitoring trigger, merged issue reference, and conditions for reconsideration.\n2. Capture the authorized reviewer, triage summary, final severity and disposition, linked remediation or exception references, reporting status, responsible owners, due dates, and remaining limitations. Also record issue triage summary.\n\n**Exit criteria**\nIssue disposition authority provides approval: An approver accepts that the disposition is authorized and evidence-based, required actions and reporting are linked, and unresolved exposure remains visible. The authorized reviewer accepts the triage record as a traceable account of work and decisions, downstream records can proceed consistently, and closure is not represented as assurance.","requiredApprovals":1,"controls":["UC-RISK-14"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-issue-assessment-issue-triage-closure","source":"issue-assessment","target":"issue-triage-closure"}],"metadata":{"kind":"issue-triage-disposition","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:grc-issue-triage-disposition","sourceNodeMap":{"issue-intake":"issue-assessment","issue-assessment":"issue-assessment","issue-disposition":"issue-triage-closure","issue-triage-closure":"issue-triage-closure"},"legacyNodeOrder":["issue-intake","issue-assessment","issue-disposition","issue-triage-closure"],"legacyRequiredApprovals":{"issue-intake":0,"issue-assessment":0,"issue-disposition":1,"issue-triage-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"issue"},"roles":[{"id":"reviewer-1","description":"Issue assessment specialist. Assess severity and cause.","nodeIds":["issue-assessment"],"contribution":"expertise"},{"id":"reviewer-2","description":"Issue disposition authority. Approve issue triage record.","nodeIds":["issue-triage-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-issue-remediation-verification"}]},"teams":["risk-management"],"capabilities":["issue-triage-disposition"]}},{"sourceTemplateId":"coworkcanvas:template:policy-exception-risk-acceptance","name":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance as a decision-aware workflow. It carries a waiver from request and justification through risk assessment, compensating controls, time-bound approval, registration with expiry, and re-review so no exception outlives its rationale. The exception IS an Issue item (issue_type: policy_exception) — the workflow runs on it, and the exception register is simply the set of those Issues, queryable by their filterable exception_expiry_date. The affected policy is a Policy item the Issue links to; a granted acceptance also sets treatment: accept on the linked Risk item. In scope: time-bound exceptions/waivers to an existing policy that are risk-accepted for a bounded window. Out of scope: permanent policy-change proposals, which route to the Policy Lifecycle Management workflow (the Policy item's revision process) rather than this waiver workflow. No upstream or downstream workflow feeds or consumes this one; the exception request is the initial input, and recurring-exception patterns are compiled as feedback onto the affected Policy items at close.","itemTypeSlug":"issue","autoCreateOnItem":false,"nodes":[{"id":"assess-and-package","data":{"label":"Assess and package","description":"The requestor and sponsor submit the exception on this step's form; the agent de-duplicates it, drafts the rated risk assessment against appetite and the compensating-control plan, and the risk owner endorses the packet and the approval authority it requires","instructions":"**Objective** — Produce a risk-owner-endorsed approval packet for a single policy exception: business justification, a rated risk assessment positioned against appetite, a compensating-control plan, and the residual rating that determines which approval authority the request needs.\n\n**Inputs**\n- The exception request, submitted by the requestor on this step's form (the workflow's initial input): the affected Policy item and the specific clause that cannot be met, named requestor and business unit, accountable sponsor, in-scope assets/processes with explicit out-of-scope items, and the requested duration. A request that is really a permanent policy-change proposal is out of scope — return it to the policy owner (the Policy item's policy_owner) rather than assessing it here.\n- The risk register — Risk items touching the same assets/requirement — the org's standard likelihood/impact scale, and documented appetite/tolerance thresholds.\n- The control inventory — Control items as candidate compensating controls — and the governance approval/authority matrix.\n- Prior exception history for the same clause: query Issue items with issue_type policy_exception linked to the same Policy (active duplicates, prior rejections).\n\n**Procedure**\n1. Validate intake completeness and de-duplicate: confirm the requestor has supplied each missing business fact and resolve the sponsor from the exception ownership record, then query the exception register and prior history for the same policy clause. Flag duplicates of an active exception or a re-submission of a previously rejected request. Confirm exactly one accountable requestor and one sponsor, and that the requested duration is a genuine time bound, not an open-ended waiver.\n2. Test the submitted business justification rather than restating it: why the requirement cannot be met as written, the cost and timeline of full compliance, the compliant alternative that was considered and why it was rejected, and the remediation milestone the requested duration is tied to. Send the form back where any of these is assertion rather than argument.\n3. Draft the risk assessment consistent with COSO ERM risk-response practice and ISO 27001 risk-acceptance expectations: identify what the waived requirement protects against, rate likelihood and impact over the requested window on the standard scale, and state the inherent position before mitigation.\n4. Position against appetite: link the affected risk-register entries, compare the exposure to documented appetite/tolerance, and flag any breach explicitly (a breach forces escalation at the approval decision).\n5. Build the compensating-control plan: enumerate candidate controls (heightened monitoring, restricted access, segmentation, added review gates, reduced data scope), each with a proposed owner, operating frequency, the evidence it produces, and a required-by date; then re-estimate residual risk with those controls in place.\n6. Assemble the packet and identify the approver the authority matrix requires for that residual level: request, justification, risk assessment with appetite position, compensating-control plan, residual rating, and required approver.\n7. Route the assembled packet to the risk owner for endorsement.\n\n**Record in AssureSwarm**\n- Create/update the exception's Issue item — issue_type: policy_exception, identified_date (request date), issue_owner (the accountable sponsor), severity (from the residual rating) — with the policy clause, bounded scope, duration, duplicate-check result, ratings, and required approver in its description (item create/update).\n- The form on this step, answered by the business exception requestor outside the workflow’s executing and approving roles, captures the request itself: the policy clause at issue, why it cannot be met, the compliant alternative rejected and why, the cost and timeline of full compliance, the in-scope and out-of-scope boundary, the requested end date, the remediation milestone it is tied to, with the accountable sponsor resolved from the exception ownership record.\n- Link the Issue to the affected Risk items and the Policy item (items link).\n- Attach the assembled approval packet document (document upload).\n\n**Exit criteria** — Risk owner has endorsed the packet; ratings follow the standard methodology and cover the full duration and scope; the appetite position is stated honestly; every compensating control is operable by a named owner rather than aspirational; the required approver is identified.\n\n**Form recipient** — this step's form is answered by the business exception requestor outside the workflow’s executing and approving roles, not by any executing risk owner, sponsor, control owner, approver or monitor; those roles record their work in native results. Send it with a form assignment; the owner's own work goes in the step result.","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload"]},"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"route-for-approval","data":{"label":"Route for approval","description":"Agent stages the endorsed packet with the approver the authority matrix requires; the approver decides: approve time-bound, reject, or escalate","kind":"decision","decisionField":"approval_decision","instructions":"**Objective** — Resolve who bears the exposure and whether the exception proceeds. The approver the authority matrix names for the packet's residual level decides to approve the exception time-bound, reject it, or escalate it to the risk committee.\n\n**Decision criteria**\n- `approved_time_bound` — Residual risk sits within the approver's delegated authority and within documented appetite; the compensating-control plan is operable by its named owners; and the requested window ties to a real remediation milestone. Approve with an explicit expiry date — an approval is never open-ended.\n- `rejected` — The exposure is not acceptable at any compensating-control level the organization will fund, the justification does not hold, or a compliant alternative exists. The policy requirement stands and a dated compliance deadline applies.\n- `escalated` — The residual exposure exceeds the approver's delegated authority or breaches appetite/tolerance, so the decision belongs to the risk committee rather than this approver.\n\n**Record in AssureSwarm** — Submit `approval_decision` (SELECT). Enter the step result citing the specific evidence references (risk rating, appetite position, compensating-control plan) and, for an approval, the approved expiry date; record the step's approver record (approver name and role).\n\n**Exit criteria** — `approval_decision` is submitted with a rationale that cites evidence; for an approval, an explicit expiry date is recorded; the branches not selected are prunable.","performedBy":{"primitives":["coach-query-data","coach-document-upload"]},"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":160}},{"id":"committee-review","data":{"label":"Committee review","description":"Agent schedules the committee slot, distributes the packet, and drafts minutes and the recorded decision; the committee decides","instructions":"**Objective** — Obtain and record the risk committee's decision on an escalated exception whose exposure exceeds delegated authority: accept time-bound, accept with conditions, or reject.\n\n**Inputs**\n- The endorsed approval packet and the escalation grounds (appetite breach or authority overflow) from the `escalated` branch of the approval decision.\n- The committee's schedule, quorum rules, and submission template.\n\n**Procedure**\n1. Schedule the item on the next committee session — or an interim delegated review if waiting would leave the requestor operating in an ungoverned gap — respecting quorum rules and the submission template.\n2. Distribute the decision memo and full packet to members ahead of the session: quantified exposure, the appetite-breach analysis, compensating controls and remaining gaps, and explicit options with a recommendation.\n3. Draft the minutes during the session, capturing attendees, quorum confirmation, questions raised, and the decision as stated.\n4. Draft the recorded decision — accepted time-bound, accepted with conditions, or rejected — translating every imposed condition into a named owner and due date and capturing the committee-approved scope, compensating-control requirements, and expiry date.\n5. Update the exception record with the decision verbatim from the minutes; if the committee rejected the request, mark it closed-rejected so the register preserves the history.\n\n**Record in AssureSwarm**\n- Attach the minutes and the recorded decision documents (document upload).\n- Link the packet and the related risk-register entries (document link).\n- Update the exception item with the verbatim decision, conditions, approved scope, and expiry.\n\n**Exit criteria** — The chair has verified that the drafted minutes and recorded decision match what was decided verbatim; every condition has an owner and a due date; the expiry is explicit rather than implied; the signed decision is attached and the record updated.","performedBy":{"primitives":["coach-query-data","coach-document-upload"]},"requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":320}},{"id":"register-and-implement","data":{"label":"Register and implement","description":"Agent registers the exception with expiry, wires monitoring for compensating controls, schedules the re-review, and notifies stakeholders; human validates the register entry","instructions":"**Objective** — Bring an approved (or committee-accepted) exception live: create the register entry with a hard expiry and an accountable owner, stand up monitoring for every compensating control, schedule the pre-expiry re-review, and notify stakeholders. This node also records a committee rejection as closed-rejected with no active waiver.\n\n**Inputs**\n- The approval decision and expiry date from the `approved_time_bound` branch, OR the committee's recorded decision, conditions, and expiry from committee review. This is a join: it starts once whichever approving path applies has delivered its reviewed decision (only one path fires per request).\n- The compensating-control plan (owners, frequencies, evidence) from the endorsed packet.\n- The related risk-register items, the affected policy record, and the approval evidence.\n\n**Procedure**\n1. Complete the exception's Issue item as the register entry: set exception_approver (the approval authority), exception_expiry_date (the hard expiry — this filterable field IS the register's expiry index), and issue_owner (the accountable owner); record the approved conditions, compensating controls, and the remediation milestone the expiry is tied to in remediation_plan. For a committee rejection, record it as closed-rejected with no active waiver so the history is preserved.\n2. Link the entry to the related Risk items — setting treatment: accept on the Risk whose exposure this waiver accepts — the affected Policy item, and the approval evidence.\n3. Implement the monitoring hooks for each compensating control: where its operating evidence lands, the check frequency, and the breach condition that raises a flag. Capture first-run evidence that every control the approval requires to be live is actually operating before the waiver is relied upon.\n4. Schedule the pre-expiry re-review and reminder triggers well ahead of the expiry date.\n5. Draft and send the decision notice to the requestor, sponsor, policy owner, control owners, and assurance functions — stating the exact scope, the expiry, and each owner's compensating-control obligations — and collect acknowledgements from owners carrying ongoing obligations.\n\n**Record in AssureSwarm**\n- Field updates on the exception's Issue item: exception_approver, exception_expiry_date, issue_owner, with conditions and compensating-control obligations in remediation_plan (item update).\n- Link the Risk items (treatment set to accept where the waiver accepts that exposure), the Policy item, and the approval evidence (items link).\n- Attach first-run control evidence and the decision notice (document upload).\n\n**Exit criteria** — No exception is registered without exception_expiry_date and an accountable issue_owner; every approval condition is present with its owner and date; first-run control evidence is real rather than documented intent; obligation owners have acknowledged; the exception window is confirmed live (or the record is closed-rejected).\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-scan` wires the compensating-control checks and the pre-expiry reminders; `/coach-notify` sends the decision notice and collects owner acknowledgements.","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload","coach-workflow-scan","coach-notify"]},"requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":480}},{"id":"monitor-to-expiry","data":{"label":"Monitor to expiry","description":"Agent monitors compensating controls, flags breaches, and triggers the pre-expiry re-review; human re-decides the exception's end state at expiry","instructions":"**Objective** — Keep the compensating controls honest across the exception window and drive the pre-expiry re-review that sets the exception's end state before it lapses silently.\n\n**Inputs**\n- The live exception Issue with its exception_expiry_date, compensating-control obligations, and remediation milestone (from register and implement). The expiring-exceptions watchlist is a query on issue_type: policy_exception ordered by exception_expiry_date.\n- Operating evidence for each compensating control as it accrues.\n\n**Procedure**\n1. On the agreed cadence, pull operating evidence for each compensating control and verify it ran as designed — sample the actual evidence rather than accepting attestations alone.\n2. Chase gaps with the control owner within the period; log each monitoring cycle's date, evidence checked, control status, and gap resolution.\n3. Watch for scope creep beyond the approved boundary and for material shifts in the risk profile; raise a finding to the exception owner and approver when a control fails or exposure deteriorates, since that can force an early re-review.\n4. Ahead of expiry, trigger the scheduled re-review and prepare the brief: remediation-milestone status, the full monitoring trail, and whether the policy requirement can now be met.\n5. If renewal is sought, stage it as a fresh request with updated justification and risk assessment through this same workflow — never a silent auto-renewal.\n\n**Record in AssureSwarm**\n- Update the exception Issue with each monitoring cycle's status (item update); a retirement on evidence the requirement is met sets actual_remediation_date, and the re-review confirmation sets verified_date.\n- Attach the monitoring trail and the pre-expiry re-review brief (document upload).\n\n**Exit criteria** — At the re-review, the exception's end state is decided before exception_expiry_date passes — retired on evidence the requirement is now met, renewed via a properly grounded fresh request, or compliance enforced with a dated plan — and any early-termination call on a failed control or material risk shift is ruled on.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-scan` pulls each control's operating evidence on cadence and fires the pre-expiry re-review reminder.","performedBy":{"primitives":["coach-query-data","coach-item-update","coach-workflow-scan","coach-document-upload"]},"requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":640}},{"id":"close-and-archive","data":{"label":"Close and archive","description":"Automatically deliver any direct rejection, retain its compliance-gap tracking or the authorized expiry outcome, reconcile the register and archive the policy feedback.","instructions":"**Objective** — Retain the prior authorized exception outcome, process a direct rejection only on that route, and archive the full record with recurring-policy feedback.\n\n**Inputs**\n- The rejected exception record plus the approver's rationale and compliance guidance (from the `rejected` branch of the approval decision).\n- The in-scope systems/processes and their owners.\n- The final-state record from whichever terminal path reached here: a monitored exception's re-review outcome (retired / expired / renewed) from monitor to expiry, or a rejected exception's compliance-tracking outcome from communicate rejection.\n- The full trail: request, justification, risk assessment, compensating-control plan and evidence, approval or committee records, register entry, monitoring trail, re-review outcome, and stakeholder communications.\n\n**Procedure**\n*The agent incorporates Communicate rejection after the preceding authorized decisions; the policy owner confirms the closed record as this step’s single approval.*\n1. Only for the direct rejected route, draft the rejection notice to the requestor and sponsor, explaining the rationale in terms of risk appetite and policy intent and restating that the policy requirement stands as written.\n2. Only for the direct rejected route, derive the compliance deadline from the approver's guidance and state the date by which the in-scope systems/processes must be brought into compliance.\n3. Only for the direct rejected route, open a tracked issue for the outstanding compliance gap with a named owner and the communicated due date, so the gap lives in the system of record and not only in the notice.\n4. Only for the direct rejected route, send the notice; log the notification date and recipients; attach the issue reference and any requestor response to the exception record.\n5. Verify the register entry status matches the final outcome — retired, expired, renewed under a new request, or rejected — and that no compensating-control obligation remains active on a closing record.\n6. Archive the complete package where audit and certification reviews can retrieve it (every artifact listed under Inputs).\n7. Update the linked Risk items (re-confirm treatment and residual_rating now the waiver has ended) and the Policy item to reflect the closure.\n8. Compile policy feedback for the Policy item's policy_owner — surfacing recurring-exception patterns such as repeated waivers against the same clause (query the closed policy_exception Issues linked to that Policy) as input for its next review cycle (next_review_date) — and record the closure date, closer, final status, and archive location.\n\n**Record in AssureSwarm**\n- Create the compliance-gap Issue item — issue_type: deficiency, source: compliance_review, issue_owner, target_remediation_date (the compliance deadline), identified_date — linked to the affected Policy item (item create).\n- Mark the exception's policy_exception Issue rejected (no active waiver) so the register preserves the history.\n- Attach the rejection notice document and log recipients (document upload).\n- Export the closed workflow package to the archive location (workflow export).\n- Attach the policy-feedback summary to the affected Policy item (document upload).\n- Close the exception Issue; its history stays queryable in the register.\n\n**Exit criteria**\nAutomatically deliver any direct rejection, retain its compliance-gap tracking or the authorized expiry outcome, reconcile the register and archive the policy feedback.\nFor a direct rejection, the delivery record names both requestor and sponsor as recipients; the compliance deadline is dated and realistic; the gap is tracked as its own Issue in the system of record; the exception record is released for closure.\n\n\nThe archive is complete and retrievable; no obligation is still live; the register status matches reality; the recurring-pattern feedback is routed to policy governance; the exception record is closed under its prior authorized outcome.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` compiles the audit-ready archive from the workflow's linked artifacts.","performedBy":{"primitives":["coach-item-create","coach-document-upload","coach-notify","coach-workflow-export","coach-render-package"]},"requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":800}}],"edges":[{"id":"e-assess-and-package-route-for-approval","source":"assess-and-package","target":"route-for-approval"},{"id":"e-route-for-approval-register-and-implement","source":"route-for-approval","target":"register-and-implement","whenValue":"approved_time_bound","label":"Approved"},{"id":"e-route-for-approval-close-and-archive","source":"route-for-approval","target":"close-and-archive","whenValue":"rejected","label":"Rejected"},{"id":"e-route-for-approval-committee-review","source":"route-for-approval","target":"committee-review","whenValue":"escalated","label":"Escalated"},{"id":"e-committee-review-register-and-implement","source":"committee-review","target":"register-and-implement"},{"id":"e-register-and-implement-monitor-to-expiry","source":"register-and-implement","target":"monitor-to-expiry"},{"id":"e-monitor-to-expiry-close-and-archive","source":"monitor-to-expiry","target":"close-and-archive"}],"metadata":{"kind":"policy-exception-risk-acceptance","source":"studio-seed","formRespondents":{"assess-and-package":{"role":"Business exception requestor and accountable sponsor, outside the workflow’s executing and approving roles","missingInputs":"The policy clause that cannot be met and why, the compliant alternative considered and rejected, the cost and timeline of full compliance, the in-scope and out-of-scope boundary, the requested end date and the remediation milestone it is tied to","nonExecuting":true}},"canonicalSourceTemplateId":"workflow-library:grc-policy-exception-risk-acceptance","sourceNodeMap":{"assess-and-package":"assess-and-package","route-for-approval":"route-for-approval","committee-review":"committee-review","register-and-implement":"register-and-implement","monitor-to-expiry":"monitor-to-expiry","close-and-archive":"close-and-archive"},"legacyNodeOrder":["assess-and-package","route-for-approval","committee-review","register-and-implement","monitor-to-expiry","close-and-archive"],"legacyRequiredApprovals":{"assess-and-package":1,"route-for-approval":1,"committee-review":1,"register-and-implement":1,"monitor-to-expiry":1,"close-and-archive":1},"prerequisites":{"status":"declared","anchorItemType":{"slug":"issue"},"fields":[{"itemTypeSlug":"issue","key":"issue_type"},{"itemTypeSlug":"issue","key":"issue_owner"},{"itemTypeSlug":"issue","key":"exception_approver"},{"itemTypeSlug":"issue","key":"exception_expiry_date"},{"itemTypeSlug":"issue","key":"remediation_plan"},{"itemTypeSlug":"policy","key":"policy_owner"},{"itemTypeSlug":"risk","key":"treatment"}],"roles":[{"id":"risk-owner","description":"Risk owner. Endorses the assessed packet (the rated risk position against appetite, the compensating-control plan and the approval authority it requires) and, once approved, validates the live register entry, the control monitoring and the notices.","nodeIds":["assess-and-package","register-and-implement"],"contribution":"expertise"},{"id":"approval-authority","description":"Delegated approval authority named by the authority matrix for the packet’s residual rating. Approves the exception time-bound with an explicit expiry, rejects it, or escalates it to the risk committee.","nodeIds":["route-for-approval"],"contribution":"approval"},{"id":"risk-committee","description":"Risk committee chair. Decides an escalated exception whose exposure exceeds delegated authority and verifies that the minutes and the recorded decision match what was decided.","nodeIds":["committee-review"],"contribution":"approval"},{"id":"exception-owner","description":"Accountable exception owner (the Issue’s issue_owner). Rules on compensating-control breaches during the window and decides the exception’s end state at the pre-expiry re-review: retired, renewed through a fresh request, or compliance enforced.","nodeIds":["monitor-to-expiry"],"contribution":"approval"},{"id":"policy-owner","description":"Policy owner (policy_owner of the waived Policy). Confirms the closed record and takes the recurring-exception feedback into the next policy review.","nodeIds":["close-and-archive"],"contribution":"interest"}],"evidenceDestinations":[{"id":"exception-record","description":"The exception Issue (issue_type policy_exception) carrying exception_approver, exception_expiry_date, issue_owner and remediation_plan, linked to the waived Policy and the accepted Risk; the packet, minutes, monitoring trail and notices as step documents; decisions in native approvals and step results."}],"handoffs":[{"direction":"input","name":"Exception request submitted by the business requestor on the first step’s form"},{"direction":"output","name":"Recurring-exception feedback for the next policy review","sourceTemplateId":"workflow-library:grc-annual-policy-review"}]},"teams":["risk-management","compliance-legal"],"capabilities":["policy-exception-risk-acceptance"]}},{"sourceTemplateId":"coworkcanvas:template:remediation-delivery-validation","name":"Remediation Delivery & Validation","description":"Runs on the existing remediation item. Plan and deliver corrective action, independently validate it against agreed closure criteria, and approve a traceable remediation record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"remediation","autoCreateOnItem":true,"nodes":[{"id":"remediation-plan","data":{"label":"Define remediation plan and criteria","kind":"task","instructions":"**Objective**\nDefine remediation plan and criteria. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Remediation item, linked issue and root cause, risk treatment, management response, relevant controls and requirements, target dates, approved exceptions, resource constraints, and prior attempts.\n\n**Procedure**\n1. Confirm the plan addresses documented cause rather than symptoms, decompose delivery into measurable milestones, define design and operating criteria, identify affected processes and systems, assess change risk, and agree evidence required for validation.\n\n**Record in AssureSwarm**\n1. Capture the delivery plan, closure criteria, action owner, milestones, target and contingency dates, dependencies, resources, change and rollback approach, expected evidence, validator independence, and escalation triggers.\n\n**Exit criteria**\nRemediation sponsor provides expertise: The plan is actionable, criteria are observable and aligned to the underlying issue, ownership and dependencies are accepted, and validation requirements are defined before delivery.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"remediation-delivery","data":{"label":"Deliver corrective action","kind":"task","instructions":"**Objective**\nDeliver corrective action. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved plan, design specifications, change tickets, configurations, procedures, training, communications, approvals, deployment records, reconciliations, affected populations, and rollback or contingency arrangements.\n\n**Procedure**\n1. Perform each milestone, verify authorized change and segregation, reconcile deployed scope to the plan, preserve before-and-after evidence, document deviations and failed steps, update affected documentation, and escalate blockers or date changes.\n\n**Record in AssureSwarm**\n1. Document delivery status, completed milestones, change identifiers, dates, performers and reviewers, scope deployed, evidence links, deviations, incidents, rollback decisions, revised dates, and residual open actions. Also record delivery evidence summary.\n\n**Exit criteria**\nAction owner provides expertise: Delivered work is traceable to the approved plan, deviations and incomplete scope remain visible, implementation evidence is assembled, and the package is ready for validation.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":160}},{"id":"remediation-review-closure","data":{"label":"Approve remediation record","kind":"task","instructions":"**Objective**\nApprove remediation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use closure criteria, delivery evidence, configurations, updated documentation, populations, transaction samples, monitoring results, interviews, linked issue evidence, deviations, and validator independence requirements.\n2. Review all stage records, linked issue and risk information, approved plan, change evidence, validation work, exceptions, monitoring commitments, revised dates, and stakeholder responses.\n\n**Procedure**\n1. Verify the delivered scope, inspect or reperform evidence for every criterion, test data completeness and relevant operation period, investigate exceptions, compare residual exposure to the intended response, and avoid relying solely on owner attestation.\n2. Trace each closure criterion to validation support, verify the validator and approval chain, reconcile owners and dates, confirm failed or partial results remain open, and return incomplete or inconsistent evidence for correction.\n\n**Record in AssureSwarm**\n1. Record the validation method, period and population, selections, results by criterion, exceptions, evidence references, residual exposure, validator identity, independence considerations, and required follow-up. Also record validation summary.\n2. Capture the authorized reviewer, closure summary, delivery and validation dates, final result, linked issue and risk references, residual actions, monitoring owner, due dates, and evidence package location. Also record remediation record summary.\n\n**Exit criteria**\nIndependent remediation validator provides approval: An approver accepts that the validation result follows from sufficient cited work, unmet criteria remain open, and the result is not inferred merely from delivery or workflow completion. The authorized reviewer accepts the remediation record as a traceable account of delivery and validation, linked records can be updated consistently, and closure itself is not an assurance conclusion.","requiredApprovals":1,"controls":["UC-RISK-14"],"type":"TASK"},"position":{"x":0,"y":320}}],"edges":[{"id":"e-remediation-plan-remediation-delivery","source":"remediation-plan","target":"remediation-delivery"},{"id":"e-remediation-delivery-remediation-review-closure","source":"remediation-delivery","target":"remediation-review-closure"}],"metadata":{"kind":"remediation-delivery-validation","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-remediation-delivery-validation","sourceNodeMap":{"remediation-plan":"remediation-plan","remediation-delivery":"remediation-delivery","remediation-validation":"remediation-review-closure","remediation-review-closure":"remediation-review-closure"},"legacyNodeOrder":["remediation-plan","remediation-delivery","remediation-validation","remediation-review-closure"],"legacyRequiredApprovals":{"remediation-plan":0,"remediation-delivery":0,"remediation-validation":1,"remediation-review-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"remediation"},"roles":[{"id":"reviewer-1","description":"Remediation sponsor. Define remediation plan and criteria.","nodeIds":["remediation-plan"],"contribution":"expertise"},{"id":"reviewer-2","description":"Action owner. Deliver corrective action.","nodeIds":["remediation-delivery"],"contribution":"expertise"},{"id":"reviewer-3","description":"Independent remediation validator. Approve remediation record.","nodeIds":["remediation-review-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-remediation-delivery"}]},"teams":["operations"],"capabilities":["remediation-delivery-validation"]}},{"sourceTemplateId":"coworkcanvas:template:process-narrative-walkthrough","name":"Process Narrative & Walkthrough","description":"Runs on the existing process item. Document an end-to-end process, corroborate the narrative through a representative walkthrough, and approve a traceable current-state record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"process","autoCreateOnItem":true,"nodes":[{"id":"process-record-closure","data":{"label":"Approve process record","kind":"task","instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","requiredApprovals":1,"controls":["UC-AUDIT-13"],"type":"TASK"},"position":{"x":0,"y":0}}],"edges":[],"metadata":{"kind":"process-narrative-walkthrough","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:audit-process-narrative-walkthrough","sourceNodeMap":{"process-scope":"process-record-closure","narrative-draft":"process-record-closure","transaction-walkthrough":"process-record-closure","process-record-closure":"process-record-closure"},"legacyNodeOrder":["process-scope","narrative-draft","transaction-walkthrough","process-record-closure"],"legacyRequiredApprovals":{"process-scope":0,"narrative-draft":0,"transaction-walkthrough":1,"process-record-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"process"},"roles":[{"id":"reviewer-1","description":"Process owner and walkthrough specialist. Approve process record.","nodeIds":["process-record-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:audit-engagement-planning"}]},"teams":["internal-audit"],"capabilities":["process-narrative-walkthrough"]}},{"sourceTemplateId":"coworkcanvas:template:sox-walkthrough","name":"Process Walkthrough & Design Assessment","description":"Runs on the existing process item. Perform a SOX process walkthrough, update the ICFR narrative and control mapping, and document design observations for management follow-up. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"process","autoCreateOnItem":false,"nodes":[{"id":"sox-transaction-trace","data":{"label":"Trace transactions and close activities","kind":"task","instructions":"**Objective**\nTrace transactions and close activities. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review SOX scoping, significant accounts and disclosures, relevant assertions, prior narratives, risk-control matrix, entity and IT dependencies, deficiencies, changes, and auditor requests.\n2. Use selected source documents, system records, journal entries, reconciliations, reports, approvals, interfaces, spreadsheets, narrative, flowchart, and knowledgeable personnel.\n\n**Procedure**\n1. Reconcile the Process item to current SOX scope, identify material transaction streams and close activities, select representative transactions, confirm process and control owners, and surface changes since prior testing.\n2. Follow identifiers and amounts across each handoff, inspect evidence of approvals and review, observe information-produced-by-entity dependencies, inquire about exceptions and overrides, and compare practice to documentation.\n\n**Record in AssureSwarm**\n1. Capture fiscal period, cycles, assertions, locations, applications, key reports, service organizations, selected transactions, stakeholders, changes, exclusions, and known limitations. Also record in-scope cycles and locations.\n2. Link the transaction trails and evidence, identify performers and reviewers, record system and manual steps, report logic, deviations, changes, missing evidence, and follow-up by assertion. Also record transaction trace reference.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides expertise: The walkthrough boundary aligns to approved ICFR scope, selected transactions cover material paths, and dependencies or exclusions requiring governance attention are assigned. Each selected item is traceable to the financial records, observed practice is reconciled to the narrative, and unexplained deviations or missing support have owners and due dates.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"sox-walkthrough-closure","data":{"label":"Approve SOX walkthrough record","kind":"task","instructions":"**Objective**\nApprove SOX walkthrough record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the traced transactions, current risk-control matrix, control descriptions, owners, frequencies, evidence, precision criteria, information dependencies, prior findings, and process changes.\n2. Review scope, trace evidence, updated process documents, control evaluations, change analysis, gaps, proposed matrix updates, management responses, and linked deficiency work.\n\n**Procedure**\n1. Assess who performs and reviews each control, what triggers it, population completeness, threshold and follow-up precision, segregation of duties, evidence retention, and whether implementation is demonstrated for the walkthrough item.\n2. Confirm material transaction streams and assertions were addressed, trace conclusions to evidence, ensure gaps remain visible, reconcile document versions and mappings, and return unsupported conclusions for correction.\n\n**Record in AssureSwarm**\n1. Document the design result by control, rationale, walkthrough evidence, assertion coverage, gaps, compensating activities, proposed mapping changes, and linked deficiency or action references. Also record design assessment result.\n2. Capture the authorized reviewer, final narrative and matrix references, walkthrough summary, design observations, changes, linked deficiencies or actions, owners, due dates, and planned testing handoff.\n\n**Exit criteria**\nIndependent design reviewer provides approval: An approver accepts the documented design and implementation observations, all gaps are routed for evaluation, and no operating-effectiveness conclusion is inferred from the walkthrough. The authorized reviewer accepts a complete ICFR walkthrough record, linked records can be updated consistently, and closure does not claim an audit opinion or operating effectiveness.","requiredApprovals":1,"controls":["UC-AUDIT-21"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-sox-transaction-trace-sox-walkthrough-closure","source":"sox-transaction-trace","target":"sox-walkthrough-closure"}],"metadata":{"kind":"sox-walkthrough","source":"studio-seed","framework":"sox","canonicalSourceTemplateId":"workflow-library:sox-process-walkthrough-record","sourceNodeMap":{"sox-walkthrough-scope":"sox-transaction-trace","sox-transaction-trace":"sox-transaction-trace","sox-design-evaluation":"sox-walkthrough-closure","sox-walkthrough-closure":"sox-walkthrough-closure"},"legacyNodeOrder":["sox-walkthrough-scope","sox-transaction-trace","sox-design-evaluation","sox-walkthrough-closure"],"legacyRequiredApprovals":{"sox-walkthrough-scope":0,"sox-transaction-trace":0,"sox-design-evaluation":1,"sox-walkthrough-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"process"},"roles":[{"id":"reviewer-1","description":"Process owner and walkthrough specialist. Trace transactions and close activities.","nodeIds":["sox-transaction-trace"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent design reviewer. Approve SOX walkthrough record.","nodeIds":["sox-walkthrough-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-walkthrough"}]},"teams":["internal-audit"],"capabilities":["sox-walkthrough"]}},{"sourceTemplateId":"coworkcanvas:template:policy-annual-review","name":"Annual Policy Review","description":"Runs on the existing policy item. Canonical annual policy review: establish scope, obtain the policy owner and policy team sign-offs, record any required change path, and approve a documented review outcome and next review date. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"policy","autoCreateOnItem":true,"nodes":[{"id":"owner-signoff","data":{"label":"Policy owner review & sign-off","kind":"task","instructions":"**Objective**\nPolicy owner review & sign-off. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current policy document, Policy item metadata, prior review, open policy changes, mapped requirements and controls, exceptions, incidents, audit findings, and organization changes.\n2. Use the scoped policy, current operating procedures, organization and system changes, incidents, exceptions, control and requirement mappings, stakeholder feedback, and prior commitments.\n\n**Procedure**\n1. Verify the authoritative version and review population, identify stakeholders and legal or subject-matter input, reconcile outstanding changes, and define which updates belong in this review versus a separate Policy Change workflow.\n2. Read the policy end to end, verify scope, roles, statements, links, and procedures, compare documented requirements to observed practice, correct purely editorial issues, and route substantive revisions through Policy Change.\n\n**Record in AssureSwarm**\n1. Document the version, effective and next-review dates, scope, participants, sources to be consulted, linked changes or issues, and any limitations that could prevent a complete review. Also record review period.\n2. Complete the preserved outcome, summary, and attestation fields; list sources and stakeholders reviewed, editorial corrections, gaps, affected sections, and the source ID of any required Policy Change.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `outcome` (Review outcome; values: current, updated, revision_required) in Step.result markdown.\n\nRecord `summary` (Review summary) in Step.result markdown.\n\nRecord `attestation` (I attest this policy is accurate, current, and aligned to practice) in Step.result markdown.\n\n**Exit criteria**\nPolicy owner provides expertise: The document of record and review boundary are unambiguous, required stakeholders are identified, open change work is visible, and the owner can begin substantive review. The owner outcome is supported by a specific review summary, substantive changes are not hidden as editorial edits, and any required revision has a defined owner and next action.","requiredApprovals":1,"controls":[],"type":"TASK"},"position":{"x":0,"y":0}},{"id":"policy-team-signoff","data":{"label":"Approve annual review record","kind":"task","instructions":"**Objective**\nApprove annual review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the authoritative policy and metadata, intake scope, owner outcome and evidence, editorial updates, linked Policy Change, mapped requirements and controls, and applicable review cadence.\n2. Use the intake record, the policy owner’s upstream markdown result and native approval, the policy team’s current review result, supporting evidence, approved editorial updates, linked substantive change work, Policy item metadata, and unresolved conditions.\n\n**Procedure**\n1. Verify the owner considered relevant change signals, inspect changes against document-control rules, challenge stale or unsupported statements, confirm required approvers and audiences, and calculate the next review date consistently.\n2. Trace each sign-off to its evidence, verify the decision and dates agree across records, confirm substantive revisions have not been published without approval, and return incomplete or inconsistent work with explicit comments.\n\n**Record in AssureSwarm**\n1. Complete the preserved decision, next-review-date, and comments fields; capture review notes, owner resolutions, related change references, and any conditions that must be met before approval.\n2. Record the policy owner’s upstream review and the independent policy authority’s native approval, closure summary, date, final review outcome, mirrored next review date, open Policy Change or other follow-up, owner, and due date. Also record annual review closure summary.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `decision` (Decision; values: approve, return) in Step.result markdown.\n\nRecord `next_review_date` (Next review date) in Policy.fields.next_review_date.\n\nRecord `comments` (Policy team comments) in Step.result markdown.\n\n**Exit criteria**\nPolicy governance approval authority provides approval: The policy-team decision is supported, returned items are specific and assigned, the next review date is accurate, and the final closure reviewer has a complete governance record. The authorized reviewer accepts a coherent review record, Policy metadata can be updated without ambiguity, all substantive follow-up remains trackable, and closure is not represented as certification.","requiredApprovals":1,"controls":["UC-GOV-14"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-owner-signoff-policy-team-signoff","source":"owner-signoff","target":"policy-team-signoff"}],"metadata":{"kind":"policy-annual-review","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:grc-annual-policy-review","sourceNodeMap":{"review-intake":"owner-signoff","owner-signoff":"owner-signoff","policy-team-signoff":"policy-team-signoff","review-closure":"policy-team-signoff"},"legacyNodeOrder":["review-intake","owner-signoff","policy-team-signoff","review-closure"],"legacyRequiredApprovals":{"review-intake":0,"owner-signoff":1,"policy-team-signoff":1,"review-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"policy"},"roles":[{"id":"reviewer-1","description":"Policy owner. Policy owner review & sign-off.","nodeIds":["owner-signoff"],"contribution":"expertise"},{"id":"reviewer-2","description":"Policy governance approval authority. Approve annual review record.","nodeIds":["policy-team-signoff"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-policy-lifecycle-management"}]},"teams":["compliance-legal"],"capabilities":["policy-annual-review"]}},{"sourceTemplateId":"coworkcanvas:template:policy-change","name":"Policy Change","description":"Runs on the existing policy item. Canonical policy-change governance: scope and propose a controlled change, obtain policy-team approval, publish only the approved version, and close with a traceable document and communication record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"policy","autoCreateOnItem":false,"nodes":[{"id":"propose","data":{"label":"Confirm the scope and propose the change","kind":"task","instructions":"**Objective**\nConfirm the scope and propose the change. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the current controlled document and Policy item, the triggering review, regulatory change, issue, incident or business change, the authoritative source for the driver, related policies, mapped requirements and controls, stakeholder input and document standards.\n\n**Procedure**\n1. Confirm the request is not a duplicate, define the problem and desired outcome, and identify affected obligations, processes, controls, systems, owners, audiences and any urgent interim instruction. Then draft a redline, explain each substantive change, distinguish consequential edits from cleanup, analyze downstream effects, and define implementation and communication needs.\n\n**Record in AssureSwarm**\n1. Record the change request reference, current version, scope summary, initiator, stakeholders, dependencies, urgency, duplicate search and interim measures; complete the preserved change-summary, driver, sections-affected and proposed-effective-date fields; attach the redline and impact analysis and link the triggering issue, requirement or annual review.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `change_summary` (Proposed change) in Step.result markdown.\n\nRecord `driver` (Reason for the change; values: regulatory_change, audit_finding, incident_lesson, business_change, annual_review, other) in Step.result markdown.\n\nRecord `sections_affected` (Sections affected) in Step.result markdown.\n\nRecord `proposed_effective_date` (Proposed effective date) in Step.result markdown.\n\n**Exit criteria**\nPolicy owner provides expertise: The change boundary and governance route are clear, the exact proposal and rationale are understandable without oral context, affected records and audiences are listed, and the policy team can approve, reject or return the defined change.","requiredApprovals":1,"controls":[],"type":"TASK"},"position":{"x":0,"y":0}},{"id":"approve","data":{"label":"Approve policy change record","kind":"task","instructions":"**Objective**\nApprove policy change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review intake, redline, preserved proposal fields, driver evidence, impacted policies and controls, stakeholder and legal input, proposed date, implementation plan, and current document standards.\n2. Use the approved redline and conditions, current controlled document, version convention, effective date, distribution list, training and procedure impacts, archive rules, and owner and approver metadata.\n3. Review intake, proposal and redline, policy-team decision, final comparison, published document, archive record, Policy item metadata, communication evidence, and open follow-up.\n\n**Procedure**\n1. Compare proposed language to authoritative obligations, challenge conflicts and vague responsibilities, verify affected controls and procedures, ensure the approver has authority, and record conditions or reasons for approval, rejection, or return.\n2. Compare the final document to the approved redline, prevent unapproved edits, update version and effective date, archive the superseded copy, refresh related procedures and links, and communicate to affected audiences.\n3. Verify the final version implements exactly the approved change and conditions, reconcile version and effective dates, confirm distribution evidence, and return the workflow if records conflict or work remains unassigned.\n\n**Record in AssureSwarm**\n1. Complete the preserved decision and comments fields, identify the exact redline reviewed, capture approver and date, list conditions, and link any additional evidence or required rework.\n2. Complete the preserved new-version, effective-date, and communicated fields; attach or link the published document, comparison proof, archive reference, distribution evidence, and implementation follow-up.\n3. Record the policy owner’s upstream review and the independent policy authority’s native approval, summary, date, published version reference, effective date, communication completion, linked records, and all remaining owners and due dates. Also record policy change closure summary.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `decision` (Decision; values: approve, reject, return) in Step.result markdown.\n\nRecord `comments` (Policy team comments) in Step.result markdown.\n\nRecord `new_version` (New version) in Policy.fields.version.\n\nRecord `effective_date` (Effective date) in Policy.fields.effective_date.\n\nRecord `communicated` (Affected teams notified) in Step.result markdown.\n\n**Exit criteria**\nPolicy governance approval authority provides approval: The decision is supported and scoped to the submitted proposal, approval conditions are explicit, and publication cannot proceed on a rejected, returned, or subsequently changed draft. The published document matches approval, the superseded version is controlled, Policy metadata is current, communications are evidenced, and unresolved implementation tasks are assigned. The authorized reviewer accepts a traceable controlled-change record, metadata and document references agree, remaining actions are monitored, and closure does not imply certification or an audit conclusion.","requiredApprovals":1,"controls":["UC-GOV-14"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-propose-approve","source":"propose","target":"approve"}],"metadata":{"kind":"policy-change","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:grc-policy-change","sourceNodeMap":{"propose":"propose","approve":"approve","publish":"approve","change-closure":"approve"},"legacyNodeOrder":["propose","approve","publish","change-closure"],"legacyRequiredApprovals":{"propose":0,"approve":1,"publish":1,"change-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"policy"},"roles":[{"id":"reviewer-1","description":"Policy owner. Confirm the scope and propose the change.","nodeIds":["propose"],"contribution":"expertise"},{"id":"reviewer-2","description":"Policy governance approval authority. Approve policy change record.","nodeIds":["approve"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-policy-lifecycle-management"}]},"teams":["compliance-legal"],"capabilities":["policy-change"]}},{"sourceTemplateId":"coworkcanvas:template:system-third-party-risk-review","name":"System & Third-Party Risk Review","description":"Runs on the existing system item. Review system and provider dependencies, assess current risk and control evidence, select response actions, and approve the review record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":true,"nodes":[{"id":"system-risk-assessment","data":{"label":"Assess system and third-party risk","kind":"task","instructions":"**Objective**\nAssess system and third-party risk. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, architecture and data-flow records, inventory, contracts, service descriptions, business impact analysis, prior assessments, incidents, changes, user populations, and provider documentation.\n2. Use the confirmed scope, risk criteria, due-diligence responses, security and privacy evidence, service performance, incidents, vulnerabilities, continuity tests, contract terms, change history, monitoring, and prior findings.\n\n**Procedure**\n1. Reconcile inventory and ownership, map data types and trust boundaries, identify critical business processes and integrations, distinguish provider and customer responsibilities, identify material fourth parties, and document scope changes.\n2. Evaluate threats and business impacts, inspect control and performance evidence, assess concentration and exit risk, compare contract commitments to practice, analyze incidents and changes, and challenge ratings based only on questionnaires or attestations.\n\nMap data flows, access boundaries and system/provider dependencies explicitly and inspect associated security/control coverage.\n\n**Record in AssureSwarm**\n1. Capture the review period, system and service scope, owners, provider, environments, data classification, users, integrations, critical processes, subservices, locations, changes, exclusions, and information gaps.\n2. Document risk ratings and direction, criteria, evidence, control strengths and gaps, provider and customer responsibilities, concentration and resilience concerns, incidents, uncertainties, and prior-period comparison. Also record risk assessment.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The review boundary and responsibility model are unambiguous, critical dependencies are represented, and missing information that could affect risk is assigned. The assessment is reproducible, material gaps and uncertainty remain visible, and rating changes or reliance on provider evidence are supported before response selection.","requiredApprovals":1,"controls":[],"type":"TASK"},"position":{"x":0,"y":0}},{"id":"system-review-closure","data":{"label":"Approve system risk review record","kind":"task","instructions":"**Objective**\nApprove system risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, open findings, service roadmap, remediation commitments, contract rights, business continuity and exit plans, stakeholder needs, appetite criteria, and proposed monitoring indicators.\n2. Review every stage result, source evidence, ratings, provider and customer responsibilities, response approval, linked issues, monitoring commitments, contract actions, and information gaps.\n\n**Procedure**\n1. Compare continued use, remediation, restriction, replacement, and exception paths; define commitments and evidence; confirm decision authority; set performance and risk triggers; plan escalation and exit readiness; and create linked actions.\n2. Trace material ratings and decisions to evidence, verify commitments and dates, reconcile inventory and linked records, confirm contrary evidence remains visible, and return unsupported or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Record the decision, rationale, authorized approver, remediation commitments, monitoring indicators and cadence, contract actions, restrictions, contingency or exit steps, linked issues, owners, and due dates. Also record response decision; monitoring plan.\n2. Capture the authorized reviewer, review summary, accepted ratings and response, review effective date, monitoring cadence, provider commitments, linked issues, limitations, owners, and due dates. Also record system risk review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that the response follows from risk and criticality, decision authority is confirmed, and monitoring and action commitments are measurable. The authorized reviewer accepts the review as a traceable record of work and decisions, related records can be updated consistently, and closure is not represented as assurance.","requiredApprovals":1,"controls":["UC-RISK-18","UC-CONFIG-10","UC-TPRM-02","UC-TPRM-04","UC-TPRM-08"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-system-risk-assessment-system-review-closure","source":"system-risk-assessment","target":"system-review-closure"}],"metadata":{"kind":"system-third-party-risk-review","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:grc-system-third-party-risk-review","sourceNodeMap":{"system-scope":"system-risk-assessment","system-risk-assessment":"system-risk-assessment","system-risk-response":"system-review-closure","system-review-closure":"system-review-closure"},"legacyNodeOrder":["system-scope","system-risk-assessment","system-risk-response","system-review-closure"],"legacyRequiredApprovals":{"system-scope":0,"system-risk-assessment":0,"system-risk-response":1,"system-review-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"System owner and technical specialist. Assess system and third-party risk.","nodeIds":["system-risk-assessment"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent system-risk reviewer. Approve system risk review record.","nodeIds":["system-review-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-third-party-vendor-risk-lifecycle"}]},"teams":["risk-management","it","procurement"],"capabilities":["system-third-party-risk-review"]}},{"sourceTemplateId":"coworkcanvas:template:system-soc-report-cuec-review","name":"SOC Report, Subservice & CUEC Review","description":"Runs on the existing system item. Evaluate a service-organization report, subservice coverage, exceptions, and complementary user-entity controls for a governed reliance decision. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"soc-report-evaluation","data":{"label":"Evaluate opinion, controls, and exceptions","kind":"task","instructions":"**Objective**\nEvaluate opinion, controls, and exceptions. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, current SOC report and bridge letter, contract and service description, architecture and data flows, relevant processes and controls, user population, prior review, and reporting period.\n2. Use the scoped report, independent auditor opinion, system description, control matrix, test procedures and results, exceptions, management responses, subsequent-event disclosure, bridge letter, and customer risk-control mapping.\n\n**Procedure**\n1. Verify report authenticity and period, compare covered services and locations to actual use, identify scope exclusions and boundary differences, determine bridge-period needs, map business dependencies, and flag stale or missing reports.\n2. Read the opinion and basis, map relevant controls to dependencies, analyze exception populations and impact, evaluate testing periods and methods, assess subsequent changes, challenge unsupported remediation claims, and identify reliance limitations.\n\n**Record in AssureSwarm**\n1. Capture report type, auditor, opinion date and period, criteria, services, locations, actual-use alignment, boundary differences, bridge coverage, excluded components, reliance purpose, and information gaps. Also record scope alignment.\n2. Document the opinion result, relevant controls and criteria, exceptions and affected populations, management responses, period limitations, subsequent events, mapping references, reliance implications, and follow-up requests. Also record report evaluation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The report is identified and aligned to actual service use, scope and period gaps are explicit, and the evidence package is sufficient for detailed evaluation. The opinion and testing results are evaluated against actual reliance needs, material exceptions and limitations remain visible, and subservice and CUEC analysis can proceed.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"soc-review-closure","data":{"label":"Approve SOC review record","kind":"task","instructions":"**Objective**\nApprove SOC review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the report evaluation, subservice disclosures, carve-out or inclusive method, complementary subservice controls, CUEC list, customer policies and controls, test results, contracts, architecture, and open exceptions.\n2. Review all stage records, report and bridge evidence, mappings, exception analysis, subservice and CUEC conclusions, customer control support, linked issues, and monitoring commitments.\n\n**Procedure**\n1. Map each relevant CUEC to an owned control and evidence, assess operating support, trace subservice dependencies, evaluate uncovered responsibilities, determine compensating measures, define reliance limits, and create linked issues for material gaps.\n2. Trace each reliance conclusion to report and customer evidence, verify gaps and exceptions are routed, reconcile owners and dates, confirm report-period limitations remain visible, and return unsupported analysis for correction.\n\n**Record in AssureSwarm**\n1. Record CUEC status and mappings, control owners and evidence, subservice method and dependencies, gaps, compensating controls, reliance response, linked issues, monitoring requirements, owners, and due dates.\n2. Capture the authorized reviewer, review summary, report period and opinion, reliance response, material exceptions, CUEC and subservice status, linked issues, monitoring dates, owners, and evidence references.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts the documented responsibility and reliance response, all relevant CUECs and subservices are addressed, and unsupported coverage remains an explicit gap. The authorized reviewer accepts the SOC review as a traceable analysis record, related system and control records can be updated consistently, and closure does not establish assurance.","requiredApprovals":1,"controls":["UC-ACCESS-21"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-soc-report-evaluation-soc-review-closure","source":"soc-report-evaluation","target":"soc-review-closure"}],"metadata":{"kind":"system-soc-report-cuec-review","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:grc-system-soc-cuec-review","sourceNodeMap":{"soc-report-scope":"soc-report-evaluation","soc-report-evaluation":"soc-report-evaluation","soc-cuec-mapping":"soc-review-closure","soc-review-closure":"soc-review-closure"},"legacyNodeOrder":["soc-report-scope","soc-report-evaluation","soc-cuec-mapping","soc-review-closure"],"legacyRequiredApprovals":{"soc-report-scope":0,"soc-report-evaluation":0,"soc-cuec-mapping":1,"soc-review-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"System owner and technical specialist. Evaluate opinion, controls, and exceptions.","nodeIds":["soc-report-evaluation"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent system-risk reviewer. Approve SOC review record.","nodeIds":["soc-review-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-vendor-soc-cuec-review"}]},"teams":["risk-management"],"capabilities":["system-soc-report-cuec-review"]}},{"sourceTemplateId":"coworkcanvas:template:fsli-significance-assessment","name":"FSLI Significance Assessment","description":"Runs on the existing fsli item. Assess quantitative and qualitative significance for a financial statement line item and approve its scoped assertions, locations, and process dependencies. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"fsli","autoCreateOnItem":true,"nodes":[{"id":"fsli-assessment-closure","data":{"label":"Approve FSLI significance assessment","kind":"task","instructions":"**Objective**\nApprove FSLI significance assessment. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the trial balance, consolidation mapping, financial statements and disclosures, chart of accounts, ledger extracts, reporting packages, prior scoping, organization changes, and materiality basis.\n2. Use approved materiality thresholds, population data, volatility, transaction volume and complexity, estimation uncertainty, fraud susceptibility, related parties, changes, errors, deficiencies, and disclosure sensitivity.\n3. Use population and risk analysis, financial statement presentation, accounting policies, process maps, system inventory, prior risk-control mappings, entity scope, service providers, and identified changes.\n4. Review all calculations, source reconciliations, qualitative analysis, proposed decision, mappings, reviewer comments, related line items, approved materiality, changes, and unresolved limitations.\n\n**Procedure**\n1. Reconcile the line item to financial reporting records, identify accounts and disclosures included, normalize currencies and periods, separate unusual or nonrecurring components, and verify completeness across entities and locations.\n2. Compare balances and disclosures to relevant thresholds, analyze composition and trends, identify concentrations and unusual entries, evaluate estimation and judgment, consider aggregation with related line items, and document countervailing factors.\n3. Select assertions exposed to reasonable misstatement risk, map transaction classes and close processes, identify locations and systems contributing material activity, consider entity-level and IT dependencies, and challenge unsupported roll-forwards.\n4. Reperform key calculations, challenge borderline and contradictory factors, confirm aggregation was considered, verify mapped coverage matches the approved decision, and return incomplete support rather than inferring assurance.\n\n**Record in AssureSwarm**\n1. Capture the fiscal period, population reference, balance or disclosure magnitude, component accounts, currencies, entities, locations, preparer, reconciliation, exclusions, and data limitations.\n2. Document calculations, thresholds, ratios, trends, qualitative factors, contradictory evidence, aggregation analysis, preliminary significance view, and any additional data requested.\n3. Record the proposed decision and rationale, relevant assertions, locations, processes, systems, risks and controls, aggregation relationships, coverage gaps, and required follow-up. Also record proposed scope decision.\n4. Capture the authorized reviewer, final decision, rationale, materiality basis, relevant assertions, locations, linked processes, systems, risks and controls, open actions, owners, and reassessment triggers. Also record assessment conclusion and rationale.\n\n**Exit criteria**\nSOX scoping reviewer provides approval: The population agrees to authoritative reporting records, aggregation and exclusions are transparent, and quantitative analysis can proceed from a complete supported basis. The preliminary view is reproducible from cited data, both quantitative and qualitative factors are addressed, and unresolved factors are assigned before assertion mapping. An approver accepts that the proposed scope and mappings follow from the evidence, or returns specific unsupported elements for further analysis before final decision. The authorized reviewer accepts a traceable management scoping record, downstream planning can use the mapped decision consistently, and closure does not provide certification or an audit opinion.","requiredApprovals":1,"controls":["UC-RISK-08"],"type":"TASK"},"position":{"x":0,"y":0}}],"edges":[],"metadata":{"kind":"fsli-significance-assessment","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:sox-fsli-significance-assessment","sourceNodeMap":{"fsli-population":"fsli-assessment-closure","fsli-risk-analysis":"fsli-assessment-closure","fsli-scope-mapping":"fsli-assessment-closure","fsli-assessment-closure":"fsli-assessment-closure"},"legacyNodeOrder":["fsli-population","fsli-risk-analysis","fsli-scope-mapping","fsli-assessment-closure"],"legacyRequiredApprovals":{"fsli-population":0,"fsli-risk-analysis":0,"fsli-scope-mapping":1,"fsli-assessment-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"fsli"},"roles":[{"id":"reviewer-1","description":"SOX scoping reviewer. Approve FSLI significance assessment.","nodeIds":["fsli-assessment-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-annual-icfr-scoping-risk-assessment"}]},"teams":["finance"],"capabilities":["fsli-significance-assessment"]}},{"sourceTemplateId":"coworkcanvas:template:requirement-applicability-control-mapping","name":"Requirement Applicability & Control Mapping","description":"Runs on the existing requirement item. Interpret a requirement, determine supported applicability, map obligations to controls and evidence, and approve the mapping record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"requirement","autoCreateOnItem":true,"nodes":[{"id":"requirement-applicability","data":{"label":"Determine applicability and scope","kind":"task","instructions":"**Objective**\nDetermine applicability and scope. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, authoritative law, regulation, standard, contract, policy, guidance, amendments, definitions, legal or compliance interpretation, organizational profile, and prior mapping.\n2. Use the interpreted obligation, corporate and legal-entity profile, products and services, customer and contract terms, data inventory, locations, thresholds, licenses, process and system maps, and specialist advice.\n\n**Procedure**\n1. Verify the authoritative citation and effective text, parse mandatory and conditional clauses, identify actors and triggering conditions, distinguish guidance from obligation, surface ambiguity, and obtain specialist interpretation where needed.\n2. Test each triggering condition against supported organizational facts, evaluate exemptions and thresholds, identify partial or phased scope, distinguish current from prospective applicability, challenge unsupported exclusions, and define reassessment triggers.\n\n**Record in AssureSwarm**\n1. Capture the authority reference, effective date, exact clause location, interpreted obligation, defined terms, triggering conditions, exceptions, dependencies, interpretation owner, assumptions, and unresolved ambiguity.\n2. Document the applicability decision and rationale, in-scope and excluded entities or activities, triggering facts, thresholds, exemptions, effective period, cited evidence, assumptions, owner, and reassessment triggers.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The obligation is traceable to authoritative text, assumptions and ambiguity are explicit, and the interpretation is specific enough for an applicability decision. The applicability decision is reproducible from authoritative criteria and organizational evidence, while exclusions, partial scope, and unresolved questions remain explicit.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"requirement-mapping-closure","data":{"label":"Approve requirement mapping record","kind":"task","instructions":"**Objective**\nApprove requirement mapping record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the applicability record, clause decomposition, control library, policy and process records, system responsibilities, test results, monitoring, prior assessments, exceptions, issues, and evidence-retention requirements.\n2. Review every stage result, authoritative references, organizational evidence, specialist interpretations, mappings, control and test support, linked issues, exceptions, and open ambiguity.\n\n**Procedure**\n1. Decompose obligations into testable elements, map preventive and detective coverage, verify control ownership and frequency, inspect current evidence, identify overlaps and gaps, distinguish design from operating support, and create linked action records.\n2. Trace applicability and coverage decisions to sources, verify every applicable element is mapped or identified as a gap, reconcile linked records and owners, retain contrary evidence, and return unsupported conclusions for correction.\n\n**Record in AssureSwarm**\n1. Record mapping status and rationale by obligation element, linked controls and owners, policies and processes, evidence and testing references, coverage limitations, gaps, compensating measures, linked issues, and due dates.\n2. Capture the authorized reviewer, review summary, authority and effective date, applicability result, mapping status, linked controls and issues, limitations, reassessment trigger, owners, due dates, and evidence references. Also record requirement mapping summary.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that mappings are specific and evidence-based, applicable elements are accounted for, and design or operating gaps remain visible for action. The authorized reviewer accepts the requirement mapping as a traceable analysis record, downstream records can be maintained consistently, and closure does not establish compliance or assurance.","requiredApprovals":1,"controls":["UC-GOV-03"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-requirement-applicability-requirement-mapping-closure","source":"requirement-applicability","target":"requirement-mapping-closure"}],"metadata":{"kind":"requirement-applicability-control-mapping","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:reg-requirement-applicability-mapping","sourceNodeMap":{"requirement-interpretation":"requirement-applicability","requirement-applicability":"requirement-applicability","requirement-control-mapping":"requirement-mapping-closure","requirement-mapping-closure":"requirement-mapping-closure"},"legacyNodeOrder":["requirement-interpretation","requirement-applicability","requirement-control-mapping","requirement-mapping-closure"],"legacyRequiredApprovals":{"requirement-interpretation":0,"requirement-applicability":0,"requirement-control-mapping":1,"requirement-mapping-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"requirement"},"roles":[{"id":"reviewer-1","description":"Legal or regulatory specialist. Determine applicability and scope.","nodeIds":["requirement-applicability"],"contribution":"expertise"},{"id":"reviewer-2","description":"Compliance owner. Approve requirement mapping record.","nodeIds":["requirement-mapping-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:reg-impact-analysis-obligation-mapping"}]},"teams":["compliance-legal"],"capabilities":["requirement-applicability-control-mapping"]}},{"sourceTemplateId":"coworkcanvas:template:regulatory-change-intake-impact","name":"Regulatory Change Intake & Impact Assessment","description":"Runs on the existing requirement item. Validate a new or amended external obligation against its authoritative source, determine applicability, and assess the impact on controls, policies, processes and systems. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"requirement","autoCreateOnItem":false,"nodes":[{"id":"change-applicability","data":{"label":"Determine applicability and affected scope","kind":"task","instructions":"**Objective**\nDetermine applicability and affected scope. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, the primary authoritative source text, the superseded version, regulator or standards-body publications, legal and advisory summaries, and the framework version currently recorded.\n2. Use the validated change, entity and jurisdiction maps, product and service inventory, data flows and classifications, customer and employee populations, existing applicability determinations, and thresholds or exemptions in the source text.\n\n**Procedure**\n1. Read the primary source rather than commentary, compare new and superseded text clause by clause, establish effective and transition dates, distinguish binding obligations from guidance, and flag interpretive ambiguity for legal input.\n2. Test each applicability criterion against documented facts, evaluate thresholds and exemptions explicitly, identify partially reached scope, reconcile against the prior determination, and record where facts were unavailable.\n\n**Record in AssureSwarm**\n1. Capture the authority reference, framework and version, change description with clause-level differences, effective and transition dates, binding versus advisory classification, source citations, and interpretive questions raised.\n2. Document the applicability decision, criterion-by-criterion analysis, entities and jurisdictions reached, exemptions relied upon with justification, prior determination comparison, and unresolved factual gaps. Also record scope analysis.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The change is verified against primary source with citations, timing is established, and interpretive ambiguity is routed to the accountable role rather than resolved by assumption. The applicability decision is supported criterion by criterion, exemptions carry stated justification, and factual gaps that could reverse the decision are visible and assigned.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"change-intake-closure","data":{"label":"Approve impact assessment and route implementation","kind":"task","instructions":"**Objective**\nApprove impact assessment and route implementation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the applicability decision, the mapped control set, policy library, process narratives, system and vendor inventory, existing evidence expectations, current implementation status, and delivery capacity.\n2. Review all stage records, primary source citations, applicability analysis and exemptions, clause-to-artifact mapping, gap inventory, effort estimates, ownership nominations, and feasibility escalations.\n\n**Procedure**\n1. Trace each changed clause to the artifacts that satisfy it, identify gaps where no artifact exists, estimate effort and dependency, rate aggregate impact, name accountable owners, and escalate where the effective date is not achievable.\n2. Verify citations resolve to primary source, confirm the applicability decision is criterion-supported, check every gap has an owner and target date, reconcile the recorded framework version, and return unsupported analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the impact rating, clause-to-artifact mapping, identified gaps, affected controls, policies, processes and systems, effort and dependency estimates, nominated owners, and feasibility escalations. Also record impact analysis.\n2. Capture the authorized reviewer, the intake summary, accepted applicability and impact conclusions, framework version to record, effective and transition dates, implementation route and owners, open gaps, and due dates. Also record change intake summary.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the impact rating follows from the traced analysis, gaps are owned, and any effective date the organization cannot meet is escalated rather than absorbed. The authorized reviewer accepts the intake as a traceable record of change analysis, implementation can be routed against named owners, and closure implies no assurance that the obligation is yet met.","requiredApprovals":1,"controls":["UC-GOV-03","UC-RISK-11"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-change-applicability-change-intake-closure","source":"change-applicability","target":"change-intake-closure"}],"metadata":{"kind":"regulatory-change-intake-impact","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:reg-requirement-change-impact","sourceNodeMap":{"change-validation":"change-applicability","change-applicability":"change-applicability","change-impact":"change-intake-closure","change-intake-closure":"change-intake-closure"},"legacyNodeOrder":["change-validation","change-applicability","change-impact","change-intake-closure"],"legacyRequiredApprovals":{"change-validation":0,"change-applicability":0,"change-impact":1,"change-intake-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"requirement"},"roles":[{"id":"reviewer-1","description":"Legal or regulatory specialist. Determine applicability and affected scope.","nodeIds":["change-applicability"],"contribution":"expertise"},{"id":"reviewer-2","description":"Compliance owner. Approve impact assessment and route implementation.","nodeIds":["change-intake-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:reg-impact-analysis-obligation-mapping"}]},"teams":["compliance-legal"],"capabilities":["regulatory-change-intake-impact"]}},{"sourceTemplateId":"coworkcanvas:template:obligation-implementation-adoption","name":"Obligation Implementation & Adoption","description":"Runs on the existing requirement item. Deliver the control, policy and process changes an obligation requires, validate readiness evidence, and approve the adoption record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"requirement","autoCreateOnItem":false,"nodes":[{"id":"adoption-scope","data":{"label":"Confirm implementation scope and readiness date","kind":"task","instructions":"**Objective**\nConfirm implementation scope and readiness date. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, the approved impact assessment, gap inventory, affected controls, policies, processes and systems, delivery capacity, dependency and change calendars, and the obligation effective date.\n\n**Procedure**\n1. Convert each gap into a deliverable with an owner and date, sequence work against dependencies and freeze periods, reconcile the readiness date against the effective date, and escalate where capacity cannot meet the deadline.\n\n**Record in AssureSwarm**\n1. Capture the target readiness date, implementation scope and deliverables, owners, sequence and dependencies, capacity constraints, freeze-period conflicts, and escalations raised.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: Every gap has a deliverable, an owner, and a date; the readiness date reconciles to the effective date or the shortfall is escalated rather than hidden.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"adoption-closure","data":{"label":"Approve adoption record","kind":"task","instructions":"**Objective**\nApprove adoption record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the implementation scope and deliverable list, control and policy drafts, process narratives, system change records, training and communication plans, approval routes, and the change and release calendar.\n2. Use the obligation text and clause-level requirements, the change inventory and its evidence, control operation evidence since the change, policy publication records, training completion, and the original gap inventory.\n3. Review all stage records, the deliverable list and its execution evidence, deviations, clause-by-clause validation, residual gaps, blockers, and representations relied upon.\n\n**Procedure**\n1. Execute each deliverable through its normal approval route, record deviations from plan with reasons, keep superseded versions traceable, confirm communication and training reached affected roles, and surface blockers rather than silently deferring them.\n2. Test each clause against delivered evidence rather than intent, inspect operating evidence where the obligation requires operation, distinguish documented from operating readiness, and refuse to close clauses supported only by representation.\n3. Trace the readiness conclusion to inspected evidence, verify residual gaps carry owners and dates, confirm the implementation status to record matches the validated position, and return overstated readiness with precise comments.\n\n**Record in AssureSwarm**\n1. Document the change inventory with before-and-after references, execution status per deliverable, deviations from plan, approval records, communication and training evidence, and blockers with owners.\n2. Record the readiness conclusion, clause-by-clause validation with evidence references, residual gaps with owners and target dates, representations relied upon, and clauses that could not be validated.\n3. Capture the authorized reviewer, the adoption summary, accepted readiness conclusion, implementation status to record, adoption effective date, residual gaps, monitoring handover, owners, and due dates.\n\n**Exit criteria**\nCompliance owner provides approval: Delivered changes are traceable to approved deliverables, deviations are reasoned, and blocked work is visible with an owner rather than absorbed into the next stage. An approver accepts that the readiness conclusion follows from inspected evidence, residual gaps are owned and dated, and unvalidated clauses are declared rather than presumed satisfied. The authorized reviewer accepts the adoption as a traceable record of implementation work, monitoring can take over against a stated position, and closure implies no assurance beyond the clauses actually validated.","requiredApprovals":1,"controls":["UC-GOV-03"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-adoption-scope-adoption-closure","source":"adoption-scope","target":"adoption-closure"}],"metadata":{"kind":"obligation-implementation-adoption","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:reg-requirement-implementation-adoption","sourceNodeMap":{"adoption-scope":"adoption-scope","adoption-execution":"adoption-closure","adoption-validation":"adoption-closure","adoption-closure":"adoption-closure"},"legacyNodeOrder":["adoption-scope","adoption-execution","adoption-validation","adoption-closure"],"legacyRequiredApprovals":{"adoption-scope":0,"adoption-execution":0,"adoption-validation":1,"adoption-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"requirement"},"roles":[{"id":"reviewer-1","description":"Legal or regulatory specialist. Confirm implementation scope and readiness date.","nodeIds":["adoption-scope"],"contribution":"expertise"},{"id":"reviewer-2","description":"Compliance owner. Approve adoption record.","nodeIds":["adoption-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:reg-obligation-implementation"}]},"teams":["compliance-legal"],"capabilities":["obligation-implementation-adoption"]}},{"sourceTemplateId":"coworkcanvas:template:compliance-monitoring-attestation","name":"Compliance Monitoring & Attestation","description":"Runs on the existing requirement item. Refresh evidence for an obligation on its review cycle, test continued conformance, and record the owner attestation with any exceptions. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"requirement","autoCreateOnItem":false,"nodes":[{"id":"conformance-testing","data":{"label":"Refresh evidence and test continued conformance","kind":"task","instructions":"**Objective**\nRefresh evidence and test continued conformance. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, its mapped controls and policies, the prior monitoring record, the last review date, framework version history, organizational and system changes, and the evidence expectations on record.\n2. Use the evidence expectations, control operation records and testing results, policy publication and attestation records, system configuration extracts, incident and exception logs, and prior-period evidence for comparison.\n\n**Procedure**\n1. Fix the period boundaries, confirm the mapped artifact set is still current, identify organizational, system, or framework changes since the last review, restate the evidence expected per clause, and note scope no longer applicable.\n2. Inspect evidence covering the whole period rather than a point in time, compare against prior-period evidence for drift, separate management representation from inspected support, and classify results against stated criteria rather than impression.\n\n**Record in AssureSwarm**\n1. Capture the monitoring period, clauses and artifacts in scope, evidence expectations, changes since last review, scope removed with rationale, accountable reviewer, and known evidence availability risks.\n2. Document the evidence refresh with source and date per clause, conformance result, period coverage achieved, drift observed against prior period, representations relied upon, and clauses left untested with reasons.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The period and artifact scope are current, evidence expectations are restated before collection, and changes that could break conformance are visible. Each clause result is supported by dated evidence covering the period, untested clauses are declared, and drift is recorded rather than smoothed.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"monitoring-closure","data":{"label":"Approve attestation record","kind":"task","instructions":"**Objective**\nApprove attestation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the conformance results and their evidence, deviation and exception detail, compensating measures, open issues and remediations, the escalation matrix, and the owner representations.\n2. Review all stage records, evidence references and their period coverage, drift observations, untested clauses, exception dispositions, attestation and its qualifications, and escalation confirmations.\n\n**Procedure**\n1. Present the tested position to the owner without softening deviations, record each exception with cause, exposure, and disposition, evaluate compensating measures on evidence, and escalate declined attestations and material deviations before advancing.\n2. Trace each conformance result to dated evidence, verify exceptions carry owners and dates, confirm escalations reached the authorized body, set the next review date against the required cadence, and return unsupported conclusions with precise comments.\n\n**Record in AssureSwarm**\n1. Record the attestation decision, attesting owner and date, each exception with cause, exposure, compensating measure and disposition, escalation route and recipients, and linked issues or remediations raised. Also record exception detail.\n2. Capture the authorized reviewer, the monitoring summary, accepted conformance results, attestation decision, next review date to record, exception register references, linked issues, owners, and due dates.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the attestation reflects the tested position, exceptions carry disposition and ownership, and declined or material positions are escalated rather than restated as conforming. The authorized reviewer accepts the monitoring record as a traceable record of the period, the next review is scheduled, and closure implies no assurance for periods or clauses not tested.","requiredApprovals":1,"controls":["UC-GOV-03"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-conformance-testing-monitoring-closure","source":"conformance-testing","target":"monitoring-closure"}],"metadata":{"kind":"compliance-monitoring-attestation","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:reg-requirement-monitoring-attestation","sourceNodeMap":{"monitoring-scope":"conformance-testing","conformance-testing":"conformance-testing","attestation":"monitoring-closure","monitoring-closure":"monitoring-closure"},"legacyNodeOrder":["monitoring-scope","conformance-testing","attestation","monitoring-closure"],"legacyRequiredApprovals":{"monitoring-scope":0,"conformance-testing":0,"attestation":1,"monitoring-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"requirement"},"roles":[{"id":"reviewer-1","description":"Legal or regulatory specialist. Refresh evidence and test continued conformance.","nodeIds":["conformance-testing"],"contribution":"expertise"},{"id":"reviewer-2","description":"Compliance owner. Approve attestation record.","nodeIds":["monitoring-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:reg-compliance-attestation-cycle"}]},"teams":["compliance-legal"],"capabilities":["compliance-monitoring-attestation"]}},{"sourceTemplateId":"coworkcanvas:template:onboarding-access-provisioning","name":"Onboarding & Access Provisioning","description":"Runs on the existing personnel item. Provision a joiner access from an approved role profile, evidence each grant, and approve the provisioning record that ITGC access testing samples. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"personnel","autoCreateOnItem":false,"nodes":[{"id":"access-approval","data":{"label":"Obtain entitlement approval","kind":"task","instructions":"**Objective**\nObtain entitlement approval. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the signed offer or engagement record, the position description, the approved role-to-entitlement profile, the systems in scope, and pre-start conditions such as background screening.\n2. Use the confirmed profile, the entitlement catalogue, segregation-of-duties rules and the conflict matrix, system owner approval routes, privileged-access policy, and prior exceptions for comparable roles.\n\n**Procedure**\n1. Verify the joiner record against the authoritative HR source, confirm the role profile is current, identify entitlements requested outside the profile, check pre-start conditions are satisfied, and hold provisioning where authorization is incomplete.\n2. Route each entitlement to its authorized approver, test the COMBINED set against the conflict matrix rather than entitlement by entitlement, evaluate compensating measures where a conflict is accepted, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the start date, requested access profile, systems in scope, out-of-profile requests with justification, pre-start condition status, requesting manager, and authorization references.\n2. Document approved entitlements with approver and date, conflicts identified, disposition and compensating measures, privileged entitlements flagged separately, and requests declined with reasons. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The joiner and role profile are confirmed against an authoritative source, out-of-profile requests are justified, and provisioning does not begin on incomplete authorization. An approver accepts that every entitlement carries authorized approval and that conflicts are dispositioned rather than ignored; blocked conflicts stop provisioning instead of proceeding.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"onboarding-closure","data":{"label":"Approve provisioning record","kind":"task","instructions":"**Objective**\nApprove provisioning record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved entitlement list, system administration consoles and provisioning tooling, identity directory records, screenshots or extracts evidencing each grant, and the timing expectations in policy.\n2. Review all stage records, authorization references, entitlement approvals, conflict dispositions, provisioning evidence and reconciliation, deviations, and outstanding items with owners.\n\n**Procedure**\n1. Provision only what was approved, capture dated evidence per system, reconcile granted against approved line by line, record any grant made outside approval as a deviation, and confirm inherited or default entitlements were reviewed rather than assumed.\n2. Trace each granted entitlement to an approval, verify accepted conflicts carry compensating measures, confirm evidence covers every in-scope system, and return unreconciled deviations with precise comments.\n\n**Record in AssureSwarm**\n1. Document provisioned accounts and entitlements per system with evidence references and dates, the provisioning outcome, deviations with cause, inherited entitlements reviewed, and outstanding items with owners.\n2. Capture the authorized reviewer, the provisioning summary, HR-backed Personnel updates specified below, deviations accepted, outstanding items with owners and dates, and linked issues raised.\n\nUpdate Personnel.engagement_status and Personnel.engagement_start_date only from the authoritative HR or engagement record and its effective date. Provisioned access alone does not establish that the person is active; retain planned or unconfirmed status when that is the supported position. Record the approved role using Personnel.position_title, Personnel.department and Personnel.role_effective_date only when the source establishes those facts. Put access execution dates, requested/approved/granted entitlements, system evidence, accepted deviations and open exceptions in the markdown step result; attach extracts and grant evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: Granted access reconciles to approved access with deviations named, evidence is dated and system-specific, and outstanding items carry owners rather than being closed optimistically. The authorized reviewer accepts the provisioning record as evidence an access control operated for this joiner, and closure implies no assurance over entitlements granted outside this action.","requiredApprovals":1,"controls":["UC-ACCESS-01","UC-ACCESS-03"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-access-approval-onboarding-closure","source":"access-approval","target":"onboarding-closure"}],"metadata":{"kind":"onboarding-access-provisioning","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-personnel-onboarding-access","sourceNodeMap":{"joiner-intake":"access-approval","access-approval":"access-approval","provisioning-execution":"onboarding-closure","onboarding-closure":"onboarding-closure"},"legacyNodeOrder":["joiner-intake","access-approval","provisioning-execution","onboarding-closure"],"legacyRequiredApprovals":{"joiner-intake":0,"access-approval":1,"provisioning-execution":0,"onboarding-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"personnel"},"roles":[{"id":"reviewer-1","description":"Manager and entitlement authority. Obtain entitlement approval.","nodeIds":["access-approval"],"contribution":"approval"},{"id":"reviewer-2","description":"Independent access reviewer. Approve provisioning record.","nodeIds":["onboarding-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-joiner-mover-leaver"}],"fields":[{"itemTypeSlug":"personnel","key":"engagement_status"},{"itemTypeSlug":"personnel","key":"engagement_start_date"},{"itemTypeSlug":"personnel","key":"role_effective_date"},{"itemTypeSlug":"personnel","key":"position_title"},{"itemTypeSlug":"personnel","key":"department"}]},"teams":["it"],"capabilities":["onboarding-access-provisioning"]}},{"sourceTemplateId":"coworkcanvas:template:transfer-access-modification","name":"Transfer & Access Modification","description":"Runs on the existing personnel item. Modify a mover access for a new role, remove entitlements the prior role no longer justifies, and approve the modification record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"personnel","autoCreateOnItem":false,"nodes":[{"id":"modification-approval","data":{"label":"Approve additions and removals","kind":"task","instructions":"**Objective**\nApprove additions and removals. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR transfer record, prior and new position descriptions, current entitlement extracts from each in-scope system, and the role profiles for both positions.\n2. Use the prior entitlement inventory, the new role profile, the entitlement catalogue, the conflict matrix, system owner approval routes, and policy on retaining prior access during transition.\n\n**Procedure**\n1. Extract current entitlements from source systems rather than from memory or prior tickets, compare against the prior role profile, identify accumulated entitlements outside any profile, and confirm the effective date against the HR record.\n2. Default to REMOVING prior-role entitlements and justify each retention explicitly, route additions and removals to their authorized approvers, test the resulting combined set against the conflict matrix, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the transfer effective date, prior and new position, the complete prior entitlement inventory per system with extract dates, entitlements held outside profile, and extraction gaps.\n2. Document additions and removals with approver and date, retentions with justification and expiry, conflicts and their disposition, privileged entitlements flagged separately, and declined requests. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The prior entitlement inventory is extracted from source systems and dated, accumulated access is visible, and extraction gaps are declared rather than assumed empty. An approver accepts that removals were considered by default rather than by exception, retentions carry justification and an expiry, and conflicts are dispositioned before provisioning.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"modification-closure","data":{"label":"Approve modification record","kind":"task","instructions":"**Objective**\nApprove modification record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved delta, system administration consoles, post-change entitlement extracts, evidence of each addition and removal, and the timing expectations for transfer changes in policy.\n2. Review all stage records, the prior and post-change extracts, approvals for additions and removals, retention justifications and expiries, conflict dispositions, deviations, and outstanding items.\n\n**Procedure**\n1. Apply removals as well as additions, RE-EXTRACT entitlements after the change, reconcile the post-change state against the approved target line by line, and record residual prior-role access as a deviation rather than an oversight.\n2. Trace the post-change state to approved decisions, verify every retention carries an expiry, confirm removals actually took effect in the extract, and return unreconciled residual access with precise comments.\n\n**Record in AssureSwarm**\n1. Document applied changes per system with evidence references and dates, the post-change entitlement extract, reconciliation result, deviations with cause, and outstanding items with owners. Also record modification outcome.\n2. Capture the authorized reviewer, the modification summary, HR-backed Personnel updates specified below, retentions and their expiries, deviations accepted, outstanding items with owners, and linked issues raised.\n\nUpdate Personnel.position_title, Personnel.department and Personnel.role_effective_date only from the authoritative approved HR transfer record. Update Personnel.manager_name and Personnel.manager_personnel_key when the source establishes a changed reporting line. A transfer must not reset Personnel.engagement_start_date or Personnel.engagement_end_date; change Personnel.engagement_status only when a separate authoritative HR status event supports it. Put access execution dates, before/after entitlement inventories, approved additions/removals, retention expiries and exceptions in the markdown step result; attach approval and re-extraction evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: The post-change state reconciles to the approved target, residual prior-role access is named as a deviation, and outstanding removals carry owners and dates. The authorized reviewer accepts the modification record as evidence an access control operated for this transfer, and closure implies no assurance over entitlements in systems outside the stated scope.","requiredApprovals":1,"controls":["UC-ACCESS-01","UC-ACCESS-03"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-modification-approval-modification-closure","source":"modification-approval","target":"modification-closure"}],"metadata":{"kind":"transfer-access-modification","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-personnel-transfer-access","sourceNodeMap":{"mover-intake":"modification-approval","modification-approval":"modification-approval","modification-execution":"modification-closure","modification-closure":"modification-closure"},"legacyNodeOrder":["mover-intake","modification-approval","modification-execution","modification-closure"],"legacyRequiredApprovals":{"mover-intake":0,"modification-approval":1,"modification-execution":0,"modification-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"personnel"},"roles":[{"id":"reviewer-1","description":"Manager and entitlement authority. Approve additions and removals.","nodeIds":["modification-approval"],"contribution":"approval"},{"id":"reviewer-2","description":"Independent access reviewer. Approve modification record.","nodeIds":["modification-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-joiner-mover-leaver"}],"fields":[{"itemTypeSlug":"personnel","key":"position_title"},{"itemTypeSlug":"personnel","key":"department"},{"itemTypeSlug":"personnel","key":"role_effective_date"},{"itemTypeSlug":"personnel","key":"manager_name"},{"itemTypeSlug":"personnel","key":"manager_personnel_key"}]},"teams":["it"],"capabilities":["transfer-access-modification"]}},{"sourceTemplateId":"coworkcanvas:template:offboarding-access-revocation","name":"Offboarding & Access Revocation","description":"Runs on the existing personnel item. Revoke a leaver access across every in-scope system within the policy window, evidence each revocation, and approve the revocation record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"personnel","autoCreateOnItem":false,"nodes":[{"id":"revocation-execution","data":{"label":"Revoke access and capture evidence","kind":"task","instructions":"**Objective**\nRevoke access and capture evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR termination record, entitlement extracts from every in-scope system, asset and device registers, shared and service account membership, physical access records, and the revocation window in policy.\n2. Use the access inventory and deadline, system administration consoles, directory disablement records, asset recovery receipts, shared-credential rotation records, and physical badge deactivation logs.\n\n**Procedure**\n1. Extract entitlements from source systems, INCLUDE shared accounts, service accounts, and non-directory credentials that role-based extracts miss, confirm whether the termination type requires immediate revocation, and compute the deadline from the effective date.\n2. Revoke in dependency order so directory disablement does not hide downstream entitlements, ROTATE shared credentials the leaver knew rather than only removing membership, capture dated evidence per system, and record each revocation against the deadline rather than in aggregate.\n\n**Record in AssureSwarm**\n1. Capture the termination effective date and type, revocation deadline, the complete access inventory per system with extract dates, devices and physical credentials, shared and service account membership, and extraction gaps.\n2. Document revoked access per system with evidence references and timestamps, credential rotations performed, devices recovered, physical access deactivated, timeliness per item, and outstanding revocations with owners.\n\n**Exit criteria**\nManager and entitlement authority provides expertise: The inventory covers named, shared, and service access plus physical credentials; the deadline is computed from policy; and extraction gaps are declared rather than presumed empty. Every inventoried item is revoked, rotated, or recorded as outstanding with an owner; timeliness is measured per item against the deadline; and shared credentials are rotated rather than assumed safe.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"revocation-closure","data":{"label":"Approve revocation record","kind":"task","instructions":"**Objective**\nApprove revocation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use post-revocation entitlement extracts, directory status, authentication and access logs since the termination date, asset register status, and the original inventory for comparison.\n2. Review all stage records, the original and post-revocation extracts, timeliness per item, credential rotations, asset recovery, verification comparison, residual access, and unverifiable items.\n\n**Procedure**\n1. Re-extract INDEPENDENTLY rather than accepting the operator confirmation, compare against the original inventory item by item, inspect authentication activity after the termination date, and classify unverifiable items as unverifiable rather than complete.\n2. Trace every inventoried item to a revocation or an owned exception, confirm late revocations are recorded as such rather than smoothed, verify residual access has a remediation owner, and return incomplete verification with precise comments.\n\n**Record in AssureSwarm**\n1. Record the verification result, post-revocation extract references and dates, item-by-item comparison, residual access with cause and owner, post-termination authentication observed, and items that could not be verified. Also record residual access detail.\n2. Capture the authorized reviewer, the revocation summary, HR-backed Personnel updates specified below, late revocations, residual access with owners and dates, unverifiable items, and linked issues raised.\n\nUpdate Personnel.engagement_end_date and Personnel.engagement_status only from the authoritative HR termination or engagement-end record and its effective date. Completed access revocation alone does not establish that the engagement ended; do not mark ended before the supported end date. Preserve Personnel.engagement_start_date and historical role dates. Put per-system access revocation/verification dates, the original entitlement inventory, credential rotations, late removals, residual access and unverifiable items in the markdown step result; attach source extracts and verification evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: An approver accepts that verification rests on independent re-extraction, residual access carries an owner and a date, and unverifiable items are declared rather than treated as clean. The authorized reviewer accepts the revocation record as evidence an access control operated for this leaver, late and residual items stay visible as control exceptions, and closure implies no assurance over systems outside the stated scope.","requiredApprovals":1,"controls":["UC-ACCESS-01"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-revocation-execution-revocation-closure","source":"revocation-execution","target":"revocation-closure"}],"metadata":{"kind":"offboarding-access-revocation","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-personnel-offboarding-access","sourceNodeMap":{"leaver-intake":"revocation-execution","revocation-execution":"revocation-execution","revocation-verification":"revocation-closure","revocation-closure":"revocation-closure"},"legacyNodeOrder":["leaver-intake","revocation-execution","revocation-verification","revocation-closure"],"legacyRequiredApprovals":{"leaver-intake":0,"revocation-execution":0,"revocation-verification":1,"revocation-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"personnel"},"roles":[{"id":"reviewer-1","description":"Manager and entitlement authority. Revoke access and capture evidence.","nodeIds":["revocation-execution"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent access reviewer. Approve revocation record.","nodeIds":["revocation-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-joiner-mover-leaver"}],"fields":[{"itemTypeSlug":"personnel","key":"engagement_status"},{"itemTypeSlug":"personnel","key":"engagement_end_date"}]},"teams":["it"],"capabilities":["offboarding-access-revocation"]}},{"sourceTemplateId":"coworkcanvas:template:periodic-user-access-review","name":"Periodic User Access Review","description":"Runs on the existing system item. Run a periodic entitlement recertification for a system, evidence reviewer decisions, and confirm that required revocations were executed. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"uar-distribution","data":{"label":"Distribute entitlement listings","kind":"task","instructions":"**Objective**\nDistribute entitlement listings. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the entitlement extract and how it was generated, the identity directory, the reviewer assignment map, prior review results, and the recertification cadence in policy.\n2. Use the reconciled population, reviewer assignments, distribution tooling or campaign records, the response deadline, and escalation contacts for non-responding reviewers.\n\n**Procedure**\n1. Reconcile the extract to an independent count so completeness is evidenced rather than assumed, confirm reviewers hold the authority to decide, identify accounts with no accountable reviewer, and note privileged and service accounts requiring separate handling.\n2. Dispatch listings with the decision options and deadline stated, reconcile distributed line counts back to the population, chase undelivered listings, and record accounts covered by no dispatched listing as a gap rather than an omission.\n\n**Record in AssureSwarm**\n1. Capture the review period, population basis and reconciliation, extract date and generator, reviewer assignments, orphaned accounts, service and privileged accounts, and completeness limitations.\n2. Document reviewer assignments and dispatch dates, distribution status, line-count reconciliation to the population, undelivered listings, non-responding reviewers, and accounts left uncovered.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is evidenced as complete, every account has an accountable reviewer, and orphaned or unreviewable accounts are visible rather than dropped. Distributed listings reconcile to the population, the deadline and decision options were communicated, and uncovered accounts are named rather than silently excluded.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"uar-closure","data":{"label":"Approve access review record","kind":"task","instructions":"**Objective**\nApprove access review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use returned reviewer responses and their timestamps, revocation tickets and system evidence, post-revocation extracts, non-response records, and prior-period recurring exceptions.\n2. Review all stage records, the population reconciliation, distribution coverage, reviewer responses, revocation evidence, non-responses, and residual exceptions with owners.\n\n**Procedure**\n1. Test response quality for blanket approval patterns and implausible turnaround, trace each removal decision to executed revocation evidence, re-extract to confirm removal, and treat non-response as a failure rather than as implicit approval.\n2. Trace the outcome to the population basis, verify uncovered accounts and non-responses carry owners, confirm revocation evidence is dated and independent, and return blanket-approval patterns with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, response rates and quality observations, removal decisions traced to revocation evidence, revocations not executed, non-responses and their treatment, and recurring exceptions. Also record revocation detail and execution evidence.\n2. Capture the authorized reviewer, the review summary, accepted outcome, effective review date, next recertification cadence, unresolved exceptions with owners and dates, and linked issues raised. Also record access review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that decisions are evidenced rather than rubber-stamped, required revocations are confirmed executed by re-extraction, and non-response is treated as an exception rather than approval. The authorized reviewer accepts the record as evidence the recertification control operated for the period, and closure implies no assurance over accounts excluded from the population.","requiredApprovals":1,"controls":["UC-ACCESS-02"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-uar-distribution-uar-closure","source":"uar-distribution","target":"uar-closure"}],"metadata":{"kind":"periodic-user-access-review","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-access-recertification","sourceNodeMap":{"uar-scope":"uar-distribution","uar-distribution":"uar-distribution","uar-disposition":"uar-closure","uar-closure":"uar-closure"},"legacyNodeOrder":["uar-scope","uar-distribution","uar-disposition","uar-closure"],"legacyRequiredApprovals":{"uar-scope":0,"uar-distribution":0,"uar-disposition":1,"uar-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"System owner and technical specialist. Distribute entitlement listings.","nodeIds":["uar-distribution"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent system-risk reviewer. Approve access review record.","nodeIds":["uar-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-user-access-review"}]},"teams":["it"],"capabilities":["periodic-user-access-review"]}},{"sourceTemplateId":"coworkcanvas:template:privileged-access-review","name":"Privileged Access Review","description":"Runs on the existing system item. Review privileged, service, and emergency accounts on a system for continued business justification, supporting activity, and compensating monitoring. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"pa-justification","data":{"label":"Test business justification and activity","kind":"task","instructions":"**Objective**\nTest business justification and activity. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, role and permission definitions, group membership extracts, service and application account inventories, break-glass account registers, and the privileged-access policy.\n2. Use the privileged population, current role and job descriptions, activity and session logs for the period, change and incident records, and prior review justifications.\n\n**Procedure**\n1. State the privilege criteria before enumerating, extract membership for every qualifying role, include non-human and emergency accounts that user-focused extracts miss, and reconcile the population to an independent source.\n2. Test justification against the current role rather than the role at grant, inspect activity logs for accounts with no use and for use inconsistent with the stated purpose, and record logging gaps as gaps rather than as clean results.\n\n**Record in AssureSwarm**\n1. Capture the review period, privilege criteria applied, population per account class with extract dates, service and emergency accounts, reconciliation basis, and enumeration gaps. Also record privileged definition and population.\n2. Document the justification assessment per account, activity review coverage, dormant privileged accounts, activity inconsistent with stated purpose, logging gaps, and justifications relying only on representation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: Privilege is defined before enumeration, non-human and break-glass accounts are in scope, and enumeration gaps are declared rather than presumed empty. Justification is tested against current roles and observed activity, dormant and inconsistent accounts are surfaced, and logging gaps are declared rather than read as no findings.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"pa-closure","data":{"label":"Approve privileged access record","kind":"task","instructions":"**Objective**\nApprove privileged access record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the justification assessment, removal tickets and post-removal extracts, monitoring and alerting configuration, session recording coverage, and the escalation route for accepted exceptions.\n2. Review all stage records, the enumeration and its reconciliation, justification results, activity coverage and logging gaps, removal evidence, monitoring tests, and accepted exceptions.\n\n**Procedure**\n1. Trace each removal decision to executed evidence, test that claimed compensating monitoring is actually configured and reviewed rather than merely available, and route accepted exceptions to the authorized approver before advancing.\n2. Trace dispositions to justification and activity evidence, verify retained access carries an expiry and tested monitoring, confirm logging gaps are owned, and return unevidenced monitoring claims with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, removals traced to evidence, retained access with justification and expiry, compensating monitoring tested with configuration references, accepted exceptions and their approver, and residual gaps. Also record compensating monitoring detail.\n2. Capture the authorized reviewer, the summary, accepted outcome, effective review date, next review cadence, retained access with expiries, logging gaps with owners, and linked issues raised. Also record privileged access summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that retained privilege carries tested compensating monitoring rather than an assertion, removals are evidenced, and exceptions reached the authorized approver. The authorized reviewer accepts the record as evidence the privileged-access control operated for the period, and closure implies no assurance over account classes excluded from enumeration.","requiredApprovals":1,"controls":["UC-ACCESS-04"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-pa-justification-pa-closure","source":"pa-justification","target":"pa-closure"}],"metadata":{"kind":"privileged-access-review","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-privileged-access-review","sourceNodeMap":{"pa-scope":"pa-justification","pa-justification":"pa-justification","pa-disposition":"pa-closure","pa-closure":"pa-closure"},"legacyNodeOrder":["pa-scope","pa-justification","pa-disposition","pa-closure"],"legacyRequiredApprovals":{"pa-scope":0,"pa-justification":0,"pa-disposition":1,"pa-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"System owner and technical specialist. Test business justification and activity.","nodeIds":["pa-justification"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent system-risk reviewer. Approve privileged access record.","nodeIds":["pa-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-privileged-access-authorization-model-management"}]},"teams":["it"],"capabilities":["privileged-access-review"]}},{"sourceTemplateId":"coworkcanvas:template:change-request-approval-migration","name":"Change Request, Approval & Migration","description":"Runs on the existing system item. Move a system change from request through independent testing and approval to production migration, evidencing developer-migrator segregation. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"change-approval","data":{"label":"Obtain approval and test evidence","kind":"task","instructions":"**Objective**\nObtain approval and test evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the change record, requirements or defect reference, affected component and interface inventory, the change classification policy, and the release calendar.\n2. Use the change record, test plans and executed results, defect logs and retest evidence, user acceptance sign-off, the approver identity and role, and the developer identity.\n\n**Procedure**\n1. Verify the change is recorded before work began, confirm the classification drives the correct approval path, identify affected downstream interfaces and reporting, and flag changes classified below their actual risk.\n2. Inspect executed test results rather than a test plan, confirm the approver is independent of the developer by identity comparison, verify conditions of approval are recorded, and refuse approval evidenced only by workflow status.\n\n**Record in AssureSwarm**\n1. Capture the change reference, requester and business reason, affected components and interfaces, classification with rationale, required approval path, target release window, and classification challenges raised. Also record change description and classification.\n2. Document test evidence with dates and executor, defects raised and retested, approver identity and independence basis, approval status and conditions, and testing the change did not receive.\n\n**Exit criteria**\nIndependent change approver provides approval: The change is recorded in advance with an evidenced classification, the approval path follows from the classification, and under-classification is challenged rather than accepted. Testing is evidenced by executed results, approver independence is demonstrated by identity rather than assumed, and approval conditions are recorded before migration.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"change-closure","data":{"label":"Approve change record","kind":"task","instructions":"**Objective**\nApprove change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved change package, deployment pipeline and migration logs, production verification results, the migrator identity, rollback plan, and post-migration monitoring.\n2. Review all stage records, classification rationale, executed test evidence, approver and migrator identities, deployed-versus-approved comparison, and open post-migration issues.\n\n**Procedure**\n1. Compare the deployed artifact against the approved package rather than trusting the pipeline, confirm migrator identity differs from developer identity, verify post-migration behaviour, and record an unsegregated migration as a control exception.\n2. Trace the deployed change to an approval and executed tests, verify both independence checks rest on identity evidence, confirm open issues carry owners, and return approvals evidenced only by status with precise comments.\n\n**Record in AssureSwarm**\n1. Record the migration outcome, deployed artifact compared to approval, migrator identity and segregation basis, verification results, issues and rollback actions, and compensating controls where segregation failed. Also record developer/migrator segregation.\n2. Capture the authorized reviewer, the change summary, accepted outcome, migration date, segregation conclusion, compensating controls, open issues with owners and dates, and linked exceptions raised.\n\n**Exit criteria**\nIndependent release reviewer provides approval: An approver accepts that production matches the approved package, segregation is evidenced by identity comparison, and a segregation failure is recorded as an exception rather than waived. The authorized reviewer accepts the record as evidence the change control operated for this change, and closure implies no assurance over changes migrated outside this process.","requiredApprovals":1,"controls":["UC-SDLC-07"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-change-approval-change-closure","source":"change-approval","target":"change-closure"}],"metadata":{"kind":"change-request-approval-migration","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-change-approval-migration","sourceNodeMap":{"change-intake":"change-approval","change-approval":"change-approval","change-migration":"change-closure","change-closure":"change-closure"},"legacyNodeOrder":["change-intake","change-approval","change-migration","change-closure"],"legacyRequiredApprovals":{"change-intake":0,"change-approval":0,"change-migration":1,"change-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"Independent change approver. Obtain approval and test evidence.","nodeIds":["change-approval"],"contribution":"approval"},{"id":"reviewer-2","description":"Independent release reviewer. Approve change record.","nodeIds":["change-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-change-release-management-operation"}]},"teams":["it"],"capabilities":["change-request-approval-migration"]}},{"sourceTemplateId":"coworkcanvas:template:emergency-change","name":"Emergency Change","description":"Runs on the existing system item. Record an emergency change that bypassed normal change control, evidence the elevated access used, and retrospectively test whether the bypass was justified. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"emergency-intake","data":{"label":"Record the emergency and authorization","kind":"task","instructions":"**Objective**\nRecord the emergency and authorization. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident or outage record, the emergency-change policy and its authorization matrix, the authorizer identity and role, and the business impact being averted.\n\n**Procedure**\n1. Establish that the trigger genuinely met the emergency criteria rather than reflecting poor planning, confirm the authorizer held the delegated authority, capture the authorization timestamp relative to the change, and compute the retrospective review deadline.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, trigger and business impact, emergency criteria met, authorizer identity and authority basis, authorization timing relative to the change, and the retrospective review deadline. Also record emergency justification and authorization.\n\n**Exit criteria**\nEmergency change authority provides approval: The emergency criteria and delegated authority are evidenced, authorization timing relative to the change is recorded honestly, and the retrospective deadline is set.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"emergency-closure","data":{"label":"Approve emergency change record","kind":"task","instructions":"**Objective**\nApprove emergency change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use production change and deployment logs, session recordings, break-glass checkout records, the elevated-access grant and its expiry, and post-change system state.\n2. Use the authorization record, the reconstructed change, incident timeline, testing performed after the fact, comparable prior emergencies, and the emergency-change rate for this system.\n3. Review all stage records, authorization timing, log-reconstructed change, elevated access grant and revocation, retrospective testing, control gaps, and remediation owners.\n\n**Procedure**\n1. Reconstruct the change from system logs rather than from recollection, record every command or artifact applied, confirm elevated access carried an expiry, and verify that break-glass credentials were rotated after use.\n2. Test the change against the requirements it should have met, compare the emergency rate against normal change volume for a pattern of routine bypass, confirm the review happened inside the policy window, and classify avoidable emergencies as control gaps.\n3. Trace the applied change to the authorization and to post-hoc testing, verify elevated access was revoked and credentials rotated, confirm control gaps carry remediation, and return self-justifying retrospectives with precise comments.\n\n**Record in AssureSwarm**\n1. Document the change applied with log references and timestamps, access class used, elevated grant and expiry, credential rotation after use, session evidence, and any change made beyond the emergency scope.\n2. Record the retrospective result, review date against the deadline, post-hoc testing performed, emergency-rate observations, control gaps identified, remediation with owners and dates, and unauthorized changes escalated. Also record remediation detail.\n3. Capture the authorized reviewer, the summary, accepted retrospective result, review date, elevated-access closure evidence, control gaps and remediation with owners and dates, and linked exceptions raised. Also record emergency change summary.\n\n**Exit criteria**\nIndependent retrospective reviewer provides approval: The applied change is reconstructed from logs, elevated access is shown to be time-bound and revoked, and scope creep beyond the emergency is surfaced rather than folded in. An approver accepts that the retrospective rests on post-hoc testing rather than restated justification, late reviews are recorded as such, and routine bypass patterns are surfaced as control gaps. The authorized reviewer accepts the record as evidence the emergency-change control operated, and closure implies no assurance that the bypassed normal controls would have passed.","requiredApprovals":1,"controls":["UC-SDLC-07"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-emergency-intake-emergency-closure","source":"emergency-intake","target":"emergency-closure"}],"metadata":{"kind":"emergency-change","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-emergency-change","sourceNodeMap":{"emergency-intake":"emergency-intake","emergency-execution":"emergency-closure","emergency-retrospective":"emergency-closure","emergency-closure":"emergency-closure"},"legacyNodeOrder":["emergency-intake","emergency-execution","emergency-retrospective","emergency-closure"],"legacyRequiredApprovals":{"emergency-intake":0,"emergency-execution":0,"emergency-retrospective":1,"emergency-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"Emergency change authority. Record the emergency and authorization.","nodeIds":["emergency-intake"],"contribution":"approval"},{"id":"reviewer-2","description":"Independent retrospective reviewer. Approve emergency change record.","nodeIds":["emergency-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Accepted retrospective, access-closure evidence and remediation actions for the change authority and the tenant's approved emergency-change procedure"}]},"teams":["it"],"capabilities":["emergency-change"]}},{"sourceTemplateId":"coworkcanvas:template:new-system-implementation","name":"New System Implementation (SDLC)","description":"Runs on the existing system item. Take a new system from control requirements through testing and acceptance to an evidenced go-live readiness decision. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"sdlc-requirements","data":{"label":"Confirm requirements and control design","kind":"task","instructions":"**Objective**\nConfirm requirements and control design. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, business and functional requirements, the process and data flows the system will serve, applicable framework requirements, the existing control set it replaces, and architecture review output.\n\n**Procedure**\n1. Derive control requirements from the processes and obligations the system will carry rather than from vendor capability, identify controls the system cannot support, and record where a compensating manual control will be required.\n\n**Record in AssureSwarm**\n1. Capture the implementation scope, control requirements traced to processes and obligations, controls the platform cannot support, planned compensating controls, architecture review outcome, and unresolved requirement gaps.\n\n**Exit criteria**\nBusiness and control sponsor provides expertise: Control requirements are derived from obligations rather than from product capability, unsupported controls are named before build, and compensating controls are planned rather than discovered at go-live.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"sdlc-closure","data":{"label":"Approve implementation record","kind":"task","instructions":"**Objective**\nApprove implementation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use test strategy and phase plans, executed unit, integration, and user acceptance results, defect logs with severity and status, the UAT tester identities, and the acceptance criteria agreed at requirements.\n2. Use acceptance results and open defects, control requirement coverage, cutover and rollback plans, data conversion readiness, support and monitoring arrangements, and the agreed go-live criteria.\n3. Review all stage records, requirement traceability, executed test evidence, UAT independence, defect dispositions, readiness criteria assessment, and open conditions with owners.\n\n**Procedure**\n1. Inspect executed results per phase, confirm UAT testers are business users by identity rather than by role label, trace open defects to a severity-based acceptance decision, and test the control requirements specifically rather than only functionality.\n2. Test the decision against the criteria agreed at requirements rather than against schedule pressure, confirm rollback is demonstrated rather than documented, verify compensating controls are operating, and record conditions with owners and deadlines.\n3. Trace every control requirement to a test result or a named compensating control, verify conditions carry deadlines, confirm the go decision cites criteria rather than schedule, and return untested control requirements with precise comments.\n\n**Record in AssureSwarm**\n1. Document test phases with executed results and dates, control requirements tested and their outcomes, defects by severity with status, UAT tester identities and independence, acceptance status, and untested requirements.\n2. Record the readiness decision against each criterion, residual risks and their owners, cutover and rollback evidence, compensating controls confirmed operating, conditions with deadlines, and criteria not met.\n3. Capture the authorized reviewer, the summary, accepted readiness decision, go-live date, residual risks and conditions with owners and dates, compensating controls in force, and linked issues raised. Also record implementation summary.\n\n**Exit criteria**\nGo-live authority provides approval: Each phase is evidenced by executed results, UAT independence is demonstrated by identity, control requirements are tested distinctly from functionality, and open defects carry a severity-based decision. An approver accepts that readiness is measured against the pre-agreed criteria, rollback capability is demonstrated, and unmet criteria are carried as conditions with owners rather than waived silently. The authorized reviewer accepts the record as evidence the implementation control operated, and closure implies no assurance over control requirements deferred to post-go-live.","requiredApprovals":1,"controls":["UC-SDLC-03","UC-SDLC-07"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-sdlc-requirements-sdlc-closure","source":"sdlc-requirements","target":"sdlc-closure"}],"metadata":{"kind":"new-system-implementation","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-implementation-readiness","sourceNodeMap":{"sdlc-requirements":"sdlc-requirements","sdlc-testing":"sdlc-closure","sdlc-readiness":"sdlc-closure","sdlc-closure":"sdlc-closure"},"legacyNodeOrder":["sdlc-requirements","sdlc-testing","sdlc-readiness","sdlc-closure"],"legacyRequiredApprovals":{"sdlc-requirements":0,"sdlc-testing":0,"sdlc-readiness":1,"sdlc-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"Business and control sponsor. Confirm requirements and control design.","nodeIds":["sdlc-requirements"],"contribution":"expertise"},{"id":"reviewer-2","description":"Go-live authority. Approve implementation record.","nodeIds":["sdlc-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-secure-sdlc-phase-gate-program"}]},"teams":["it"],"capabilities":["new-system-implementation"]}},{"sourceTemplateId":"coworkcanvas:template:data-conversion-migration","name":"Data Conversion & Migration","description":"Runs on the existing system item. Convert data into a target system with evidenced completeness and accuracy reconciliation between source and target. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"conversion-scope","data":{"label":"Confirm conversion scope and source data","kind":"task","instructions":"**Objective**\nConfirm conversion scope and source data. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, source system extracts and their generation method, data dictionaries and mapping specifications, the conversion cut-off, and records deliberately excluded from conversion.\n\n**Procedure**\n1. Capture record counts and monetary or quantitative control totals before conversion, evidence the extract is complete against the source of record, confirm the cut-off is enforced, and document excluded records with rationale.\n\n**Record in AssureSwarm**\n1. Capture the conversion scope and data objects, source record counts and control totals with extract timestamps, completeness basis, cut-off enforcement, exclusions with rationale, and known source data quality issues.\n\n**Exit criteria**\nData owner provides approval: Source control totals are captured before conversion from an evidenced-complete extract, the cut-off is enforced, and exclusions are documented rather than emerging as variances later.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"conversion-closure","data":{"label":"Approve conversion record","kind":"task","instructions":"**Objective**\nApprove conversion record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the source control totals, conversion job logs and error reports, target extracts after load, the transformation and mapping specification, and rejected-record queues.\n2. Use the reconciliation results, a sample selected from the source population, target field values, the mapping specification, business validation queries, and prior conversion exceptions.\n3. Review all stage records, source and target control totals, variance explanations, rejected records, sample testing results, business sign-off, and accepted exceptions.\n\n**Procedure**\n1. Reconcile counts and totals independently of the conversion tool own reporting, trace each variance to a documented transformation rule or a rejection, inspect the rejected queue rather than ignoring it, and refuse to net variances against each other.\n2. Select the sample from the SOURCE population so unconverted records can be found, compare field values against the mapping specification, test transformed and derived fields specifically, and treat totals agreement as insufficient evidence of accuracy.\n3. Trace the closing position to the source control totals, verify every variance carries a documented explanation, confirm rejected records were dispositioned, and return totals-only accuracy claims with precise comments.\n\n**Record in AssureSwarm**\n1. Document the reconciliation of counts and totals source to target, variances traced to rules or rejections, rejected records and their disposition, conversion errors, and variances that remain unexplained. Also record reconciliation result; conversion outcome.\n2. Record the validation result, sample basis and size, field-level comparison outcomes, transformation errors found, business sign-off and its scope, exceptions accepted with owners, and fields not tested. Also record exception detail.\n3. Capture the authorized reviewer, the summary, accepted validation result, conversion date, final reconciliation position, exceptions with owners and dates, untested fields, and linked issues raised.\n\n**Exit criteria**\nIndependent conversion validator provides approval: Reconciliation is independent of the conversion tool reporting, every variance is traced to a rule or a rejection, and unexplained variances block rather than net out. An approver accepts that accuracy rests on source-selected field-level testing rather than totals alone, exceptions carry owners, and untested fields are declared rather than implied accurate. The authorized reviewer accepts the record as evidence the conversion control operated, and closure implies no assurance over records excluded from the conversion scope.","requiredApprovals":1,"controls":["UC-ACCESS-20"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-conversion-scope-conversion-closure","source":"conversion-scope","target":"conversion-closure"}],"metadata":{"kind":"data-conversion-migration","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-data-conversion-validation","sourceNodeMap":{"conversion-scope":"conversion-scope","conversion-execution":"conversion-closure","conversion-validation":"conversion-closure","conversion-closure":"conversion-closure"},"legacyNodeOrder":["conversion-scope","conversion-execution","conversion-validation","conversion-closure"],"legacyRequiredApprovals":{"conversion-scope":0,"conversion-execution":0,"conversion-validation":1,"conversion-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"Data owner. Confirm conversion scope and source data.","nodeIds":["conversion-scope"],"contribution":"approval"},{"id":"reviewer-2","description":"Independent conversion validator. Approve conversion record.","nodeIds":["conversion-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed conversion reconciliation, validation evidence and open actions for the data owner and the tenant's approved migration procedure"}]},"teams":["it"],"capabilities":["data-conversion-migration"]}},{"sourceTemplateId":"coworkcanvas:template:job-scheduling-batch-monitoring","name":"Job Scheduling & Batch Monitoring","description":"Runs on the existing system item. Review scheduled job execution for a system over a period, evidencing failure detection, escalation, and resolution. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"batch-closure","data":{"label":"Approve batch monitoring record","kind":"task","instructions":"**Objective**\nApprove batch monitoring record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the job scheduler configuration and calendar, the critical job inventory and its basis, alerting and notification configuration, and the on-call or operations rota.\n2. Use scheduler execution logs for the full period, alert and incident records, rerun and manual intervention logs, downstream data completeness checks, and the prior period failure profile.\n3. Use the failure inventory, alert delivery evidence, incident tickets with timestamps, resolution notes, downstream reconciliation after rerun, and the response targets in policy.\n4. Review all stage records, the critical job basis, expected-versus-actual reconciliation, failure inventory, timing measurements, downstream verification, and open items with owners.\n\n**Procedure**\n1. Confirm the critical job list is derived from downstream financial and operational dependency rather than convention, verify alerting is configured for each critical job, and identify jobs whose failure would be silent.\n2. Inspect the log for the WHOLE period rather than sampling a date, reconcile expected against actual executions to find jobs that never ran, distinguish reruns that succeeded from those that masked a data gap, and record log gaps as gaps.\n3. Measure detection-to-escalation and escalation-to-resolution against the policy targets per failure, confirm downstream data was reconciled after each rerun, and treat failures closed without data verification as unresolved.\n4. Trace the result to per-failure timing evidence, verify jobs with no alerting carry a remediation owner, confirm downstream reconciliation for every rerun, and return status-only resolutions with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the monitoring period, critical job population with dependency rationale, detection and alerting configuration per job, accountable responders, jobs with no alerting, and scope exclusions. Also record critical job population and detection basis.\n2. Document the failure inventory with timestamps and job identity, jobs that never executed, reruns and manual interventions, downstream impact observed, resolution status per failure, and log coverage gaps.\n3. Record the monitoring result, per-failure timing against targets, alerts that did not reach a responder, downstream reconciliation evidence, failures closed without data verification, and recurring failure patterns. Also record escalation and resolution detail.\n4. Capture the authorized reviewer, the summary, accepted result, period covered, unresolved failures and data impact with owners and dates, alerting gaps, and linked issues raised. Also record batch monitoring summary.\n\n**Exit criteria**\nSystem owner and technical specialist provides approval: Criticality is justified by downstream dependency, alerting coverage is evidenced per job, and silently-failing jobs are surfaced rather than assumed healthy. The review covers the whole period, missing executions are found by expected-versus-actual reconciliation, and log gaps are declared rather than read as clean periods. An approver accepts that timing is measured per failure against policy targets, downstream data impact is verified rather than assumed, and recurring patterns are surfaced. The authorized reviewer accepts the record as evidence the monitoring control operated for the period, and closure implies no assurance over jobs excluded from the critical population.","requiredApprovals":1,"controls":["UC-ACCESS-17"],"type":"TASK"},"position":{"x":0,"y":0}}],"edges":[],"metadata":{"kind":"job-scheduling-batch-monitoring","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-batch-processing-review","sourceNodeMap":{"batch-scope":"batch-closure","batch-review":"batch-closure","batch-evaluation":"batch-closure","batch-closure":"batch-closure"},"legacyNodeOrder":["batch-scope","batch-review","batch-evaluation","batch-closure"],"legacyRequiredApprovals":{"batch-scope":0,"batch-review":0,"batch-evaluation":1,"batch-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"System owner and technical specialist. Approve batch monitoring record.","nodeIds":["batch-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-production-operations-processing-integrity-cycle"}]},"teams":["it"],"capabilities":["job-scheduling-batch-monitoring"]}},{"sourceTemplateId":"coworkcanvas:template:backup-recovery-testing","name":"Backup & Recovery Testing","description":"Runs on the existing system item. Test recoverability for a system by performing an actual restoration and measuring the result against recovery objectives. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"backup-scope","data":{"label":"Confirm backup scope and recovery objectives","kind":"task","instructions":"**Objective**\nConfirm backup scope and recovery objectives. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the backup configuration and retention schedule, business impact analysis with RPO and RTO, the continuity plan, prior restoration test results, and dependency maps.\n\n**Procedure**\n1. Confirm the objectives come from business impact analysis rather than from what the backup tooling currently achieves, identify data in scope that is not backed up, and select a restoration scenario that exercises a realistic failure.\n\n**Record in AssureSwarm**\n1. Capture the test period, RPO and RTO with their business basis, data and configuration in scope, items not covered by backup, the restoration scenario selected, and dependencies required for recovery. Also record recovery objectives (RPO/RTO) and data in scope.\n\n**Exit criteria**\nBusiness recovery owner provides approval: Objectives are traced to business impact rather than to tooling capability, unbacked-up data is named, and the test scenario exercises a realistic failure rather than a convenient one.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"backup-closure","data":{"label":"Approve recovery test record","kind":"task","instructions":"**Objective**\nApprove recovery test record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the selected backup set and its age, restoration tooling and runbooks, an isolated restore target, data completeness checks against the source, application startup and integrity checks, and elapsed timing.\n2. Use the restoration evidence and timings, the backup set age against RPO, the stated RTO, dependency recovery sequencing, and resource constraints observed during the test.\n3. Review all stage records, objectives and their business basis, unbacked-up data, restoration evidence and timings, computed achieved values, scale assumptions, and open gaps.\n\n**Procedure**\n1. RESTORE rather than inspect backup job status, verify restored data completeness against known source values, start the application against the restored data where feasible, and record elapsed time from initiation to usable state.\n2. Compute achieved RPO from the restored backup age and achieved RTO from measured elapsed time, test whether the result would hold at production scale, and record an untested dependency as a gap rather than an assumption.\n3. Trace achieved values to measured evidence, verify unbacked-up data and untested dependencies carry owners, confirm the scenario was realistic, and return job-status-only evidence with precise comments.\n\n**Record in AssureSwarm**\n1. Document the backup set restored and its age, restoration steps and elapsed timings, completeness and integrity checks with results, application startup verification, failures encountered, and manual intervention required. Also record restoration evidence; restoration outcome.\n2. Record objectives met or missed with computed achieved values, scale assumptions and their basis, untested dependencies, gaps with remediation owners and dates, and constraints that would worsen a real recovery. Also record gap detail and remediation.\n3. Capture the authorized reviewer, the summary, accepted conclusion, test date, achieved RPO and RTO, gaps with owners and dates, scope not covered by backup, and linked issues raised. Also record recovery test summary.\n\n**Exit criteria**\nIndependent recovery reviewer provides approval: Recoverability is evidenced by an actual restoration verified for completeness and usability, elapsed time is measured, and manual interventions are recorded rather than normalized. An approver accepts that achieved values are computed from the test rather than asserted, scale limitations are stated, and gaps carry remediation owners. The authorized reviewer accepts the record as evidence the recovery control was tested, and closure implies no assurance for data, systems, or scale not exercised by this test.","requiredApprovals":1,"controls":["UC-BCDR-03"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-backup-scope-backup-closure","source":"backup-scope","target":"backup-closure"}],"metadata":{"kind":"backup-recovery-testing","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-backup-restoration-test","sourceNodeMap":{"backup-scope":"backup-scope","backup-restoration":"backup-closure","backup-evaluation":"backup-closure","backup-closure":"backup-closure"},"legacyNodeOrder":["backup-scope","backup-restoration","backup-evaluation","backup-closure"],"legacyRequiredApprovals":{"backup-scope":0,"backup-restoration":0,"backup-evaluation":1,"backup-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"Business recovery owner. Confirm backup scope and recovery objectives.","nodeIds":["backup-scope"],"contribution":"approval"},{"id":"reviewer-2","description":"Independent recovery reviewer. Approve recovery test record.","nodeIds":["backup-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-bcdr-test-exercise"}]},"teams":["it"],"capabilities":["backup-recovery-testing"]}},{"sourceTemplateId":"coworkcanvas:template:incident-problem-management","name":"Incident & Problem Management","description":"Runs on the existing system item. Record an incident on a system, evidence containment against response targets, and determine root cause with preventive action. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"incident-response","data":{"label":"Record response and containment","kind":"task","instructions":"**Objective**\nRecord response and containment. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident ticket and its timeline, monitoring alerts or the reporting source, affected system and data inventory, the severity matrix, and regulatory notification thresholds.\n2. Use the incident timeline and ticket updates, system and access logs during the incident, containment actions and their timestamps, communications and notifications sent, and the response targets in policy.\n\n**Procedure**\n1. Establish detection time from the alert or report rather than from ticket creation, test the assigned severity against the matrix, identify data categories affected, and flag under-classification that would relax response targets.\n2. Reconstruct the timeline from logs rather than from ticket narrative, measure each interval against the target for the severity, confirm required notifications were sent inside their windows, and record evidence preserved for later analysis.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, detection time and source, systems and data affected, severity with matrix rationale, notification duties triggered, and classification challenges raised.\n2. Document response actions with timestamps, intervals measured against targets, containment status and its basis, notifications sent with recipients and times, evidence preserved, and targets missed. Also record response actions and timeline.\n\n**Exit criteria**\nIncident commander provides expertise: Detection time is evidenced independently of ticket creation, severity follows the matrix, and notification duties are identified before the response window closes. The timeline is reconstructed from logs, intervals are measured against severity targets, missed notifications are recorded as exceptions, and evidence is preserved rather than overwritten by recovery.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"incident-closure","data":{"label":"Approve incident record","kind":"task","instructions":"**Objective**\nApprove incident record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the reconstructed timeline, system and change records preceding the incident, prior incidents with similar signatures, known problem records, and control failures the incident revealed.\n2. Review all stage records, detection evidence, severity rationale, measured intervals, notification evidence, root cause analysis, prior incident matches, and preventive actions with owners.\n\n**Procedure**\n1. Distinguish trigger from underlying cause, search prior incidents for the same signature before declaring a novel cause, identify which control should have prevented or detected it, and record undetermined causes as undetermined rather than plausible.\n2. Trace the timeline to log evidence, verify missed targets and notifications are recorded as exceptions, confirm preventive actions address the named control failure, and return trigger-only cause analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the root cause result and its evidence, prior incident matches, the control that failed to prevent or detect, preventive actions with owners and dates, and cause elements that remain undetermined.\n2. Capture the authorized reviewer, the summary, accepted root cause result, closure date, targets missed, control failures identified, preventive actions with owners and dates, and linked issues raised. Also record incident summary.\n\n**Exit criteria**\nProblem-management reviewer provides approval: An approver accepts that cause analysis distinguishes trigger from underlying cause and searched for recurrence, the failed control is named, and undetermined causes are stated rather than assumed. The authorized reviewer accepts the record as evidence the incident control operated, and closure implies no assurance that the underlying cause is remediated until preventive actions complete.","requiredApprovals":1,"controls":["UC-BCDR-06"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-incident-response-incident-closure","source":"incident-response","target":"incident-closure"}],"metadata":{"kind":"incident-problem-management","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-incident-problem-review","sourceNodeMap":{"incident-intake":"incident-response","incident-response":"incident-response","incident-problem":"incident-closure","incident-closure":"incident-closure"},"legacyNodeOrder":["incident-intake","incident-response","incident-problem","incident-closure"],"legacyRequiredApprovals":{"incident-intake":0,"incident-response":0,"incident-problem":1,"incident-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"Incident commander. Record response and containment.","nodeIds":["incident-response"],"contribution":"expertise"},{"id":"reviewer-2","description":"Problem-management reviewer. Approve incident record.","nodeIds":["incident-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-cybersecurity-incident-response"}]},"teams":["it"],"capabilities":["incident-problem-management"]}},{"sourceTemplateId":"coworkcanvas:template:euc-inventory-validation","name":"End-User Computing Inventory & Validation","description":"Runs on the existing system item. Inventory the spreadsheets and end-user tools feeding reporting for a system, and test their access, change, and integrity controls. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","itemTypeSlug":"system","autoCreateOnItem":false,"nodes":[{"id":"euc-controls","data":{"label":"Test access, change and integrity controls","kind":"task","instructions":"**Objective**\nTest access, change and integrity controls. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, process narratives and reporting data flows, the prior EUC inventory, file share and collaboration locations, report preparer interviews, and the EUC policy criteria.\n2. Use file and folder permissions, version history and change logs, formula audit or comparison tooling, input source reconciliation, review evidence by someone other than the preparer, and prior error history.\n\n**Procedure**\n1. Trace reporting outputs back to their inputs so undeclared spreadsheets are found rather than self-reported, rate criticality by reliance and complexity, and record locations searched that returned nothing.\n2. Inspect actual permissions rather than intended ones, compare current formulas against a known-good baseline where one exists, reconcile inputs to their source system, and confirm review was performed by someone other than the preparer.\n\n**Record in AssureSwarm**\n1. Capture the inventory period, EUC population with location and owner, criticality rating with reliance basis, tools newly identified since the prior inventory, search coverage, and known blind spots.\n2. Document permissions inspected per EUC, version and change traceability, formula integrity testing and its method, input reconciliation results, independent review evidence, and controls found absent.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is derived by tracing reporting inputs rather than by self-declaration, criticality reflects reliance, and search blind spots are declared rather than implied complete. Access is tested as configured rather than as intended, formula integrity is tested by comparison rather than inspection alone, and independent review is evidenced by identity.","requiredApprovals":1,"type":"TASK"},"position":{"x":0,"y":0}},{"id":"euc-closure","data":{"label":"Approve EUC validation record","kind":"task","instructions":"**Objective**\nApprove EUC validation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the control testing results, the reliance placed on each output, error history and downstream impact, available platform alternatives, and the materiality of the balances or decisions affected.\n2. Review all stage records, the inventory derivation and blind spots, control evidence per EUC, reliance conclusions and their materiality basis, conditions with expiry, and remediation owners.\n\n**Procedure**\n1. Weigh control weaknesses against the materiality of the reliance rather than treating all EUCs alike, identify EUCs whose function belongs in a controlled system, and record conditions of reliance with expiry rather than open-ended acceptance.\n2. Trace each reliance conclusion to tested control evidence, verify conditions carry expiry dates, confirm blind spots and migration candidates carry owners, and return self-declared inventories with precise comments.\n\n**Record in AssureSwarm**\n1. Record the reliance conclusion per EUC, control weaknesses weighed against materiality, conditions of reliance with expiry, migration candidates, remediation with owners and dates, and outputs that should not be relied upon. Also record remediation detail.\n2. Capture the authorized reviewer, the summary, accepted reliance conclusions, effective inventory date, next inventory cadence, conditions and remediation with owners and dates, blind spots, and linked issues raised. Also record eUC validation summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that reliance is weighed against materiality, conditions carry expiry rather than being open-ended, and outputs judged unreliable are named rather than qualified into acceptance. The authorized reviewer accepts the record as evidence the EUC control operated, and closure implies no assurance over end-user tools the inventory did not reach.","requiredApprovals":1,"controls":["UC-ACCESS-20"],"type":"TASK"},"position":{"x":0,"y":160}}],"edges":[{"id":"e-euc-controls-euc-closure","source":"euc-controls","target":"euc-closure"}],"metadata":{"kind":"euc-inventory-validation","source":"studio-seed","canonicalSourceTemplateId":"workflow-library:controls-system-euc-validation","sourceNodeMap":{"euc-scope":"euc-controls","euc-controls":"euc-controls","euc-evaluation":"euc-closure","euc-closure":"euc-closure"},"legacyNodeOrder":["euc-scope","euc-controls","euc-evaluation","euc-closure"],"legacyRequiredApprovals":{"euc-scope":0,"euc-controls":0,"euc-evaluation":1,"euc-closure":2},"prerequisites":{"status":"declared","anchorItemType":{"slug":"system"},"roles":[{"id":"reviewer-1","description":"System owner and technical specialist. Test access, change and integrity controls.","nodeIds":["euc-controls"],"contribution":"expertise"},{"id":"reviewer-2","description":"Independent system-risk reviewer. Approve EUC validation record.","nodeIds":["euc-closure"],"contribution":"approval"}],"evidenceDestinations":[{"id":"review-evidence","description":"Restricted native step results, attached documents, durable item fields and native approvals."}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:sox-ipe-validation"}]},"teams":["it"],"capabilities":["euc-inventory-validation"]}},{"sourceTemplateId":"coworkcanvas:template:model-validation","name":"Model Validation","description":"Runs on the existing Model item. Input: the model's documentation, development data and prior validation findings. Deliverable: the independent validation report with a rated outcome and the next validation date, recorded on the Model item. Handoff: findings that need fixing go to the model owner as Issue items.","itemTypeSlug":"model","autoCreateOnItem":false,"nodes":[{"id":"independent-validation","data":{"label":"Independent validation review","kind":"task","description":"The independent validator challenges the agent-prepared validation package: conceptual soundness, data, implementation and outcomes analysis.","instructions":"**Objective**\nProduce the independent validation report for this model, reviewed by a validator who did not build or run it.\n\n**Inputs**\n1. The Model item: model_type, model_tier, model_owner, last_validation_date and its description.\n2. Model documentation, development and monitoring data attached to the Model item or to prior workflow steps on it.\n3. Open Issue items linked to the model from earlier validations.\n\n**Procedure**\n1. Check the documentation against the model's stated purpose and the tier's validation scope (Tier 1 full scope, Tier 2 and 3 targeted).\n2. Assess conceptual soundness: assumptions, method choice and known limitations.\n3. Test the data: sources, completeness, and representativeness of the development sample.\n4. Re-perform or benchmark key outputs; run back-testing or outcomes analysis on the latest monitoring period.\n5. List each finding with its severity and the evidence behind it; state the overall rating (satisfactory, needs improvement, unsatisfactory).\n\n**Record in Canvas**\n- The validation report and rating in the step result; working files as step documents.\n- One Issue item per finding, linked to the Model item.\n\n**Exit criteria**\nThe validator (expertise and variance) confirms every finding is evidenced and the rating follows from them.","requiredApprovals":1,"type":"TASK"}},{"id":"approve-validation","data":{"label":"Approve the validation outcome","kind":"task","description":"The head of model risk management approves the rated outcome, any use restrictions and the next validation date.","instructions":"**Objective**\nAn authorized decision on the validation outcome: approve the model for continued use, approve with restrictions, or withdraw it.\n\n**Inputs**\n1. The reviewed validation report and rating from the previous step.\n2. The findings raised as Issue items and the model owner's response.\n\n**Procedure**\n1. Summarize the rating, the open findings and any proposed use restriction for the approver.\n2. Propose the next validation date from the tier cadence (Tier 1 one year, Tier 2 two, Tier 3 three), earlier when findings are open.\n\n**Record in Canvas**\n- On the Model item: last_validation_date = the approval date; next_validation_date = the approved next date.\n- The decision and any restriction in the step result.\n\n**Exit criteria**\nThe head of model risk management (approval) signs off the outcome and the next validation date.","requiredApprovals":1,"type":"TASK"}}],"edges":[{"id":"e-independent-validation-approve-validation","source":"independent-validation","target":"approve-validation"}],"metadata":{"kind":"model-validation","source":"model-inventory-pack","prerequisites":{"status":"declared","anchorItemType":{"slug":"model"},"roles":[{"id":"validator","description":"Independent model validator, not the model's developer or owner.","nodeIds":["independent-validation"],"contribution":"expertise"},{"id":"mrm-head","description":"Head of model risk management.","nodeIds":["approve-validation"],"contribution":"approval"}]}}},{"sourceTemplateId":"coworkcanvas:template:model-monitoring-breach-review","name":"Model Monitoring Breach Review","description":"Runs on the existing Model item when a monitoring result falls below its threshold. Input: the monitoring run that breached. Deliverable: the breach diagnosis and the approved response (recalibrate, restrict use, revalidate or accept). An open run of this workflow is what the Model Inventory dashboard counts as a monitoring breach.","itemTypeSlug":"model","autoCreateOnItem":false,"nodes":[{"id":"diagnose-breach","data":{"label":"Diagnose the breach","kind":"task","description":"The model owner confirms the cause of the breach from the agent-prepared diagnosis.","instructions":"**Objective**\nA diagnosis of why the monitoring metric fell below its threshold, confirmed by the model owner.\n\n**Inputs**\n1. The breaching Model Performance Monitoring run on this Model item: its monitoring_metric and monitoring_threshold.\n2. The earlier monitoring runs on the model (the trend on the Model Inventory dashboard).\n\n**Procedure**\n1. Quantify the breach: the metric, the threshold, the gap and how many periods it has lasted.\n2. Test the likely causes: data drift, a population or process change, an upstream system change, or a model defect.\n3. Estimate the business impact while the breach lasts.\n\n**Record in Canvas**\n- The diagnosis in the step result; supporting analysis as step documents.\n- Set monitoring_status on the Model item to breach.\n\n**Exit criteria**\nThe model owner (expertise) confirms the cause or names the one the analysis missed.","requiredApprovals":1,"type":"TASK"}},{"id":"decide-response","data":{"label":"Approve the response","kind":"task","description":"The head of model risk management approves the response to the breach.","instructions":"**Objective**\nAn authorized response to the breach: recalibrate, restrict use, bring the validation forward, or accept the breach for a stated period.\n\n**Inputs**\n1. The confirmed diagnosis from the previous step.\n\n**Procedure**\n1. Lay out the response options with their cost, time and residual risk.\n2. Recommend one and draft the actions, owners and dates.\n\n**Record in Canvas**\n- The decision in the step result; each action as an Issue item linked to the Model item.\n- When the validation is brought forward, update next_validation_date on the Model item. When the model is back within threshold, set monitoring_status to within_threshold.\n\n**Exit criteria**\nThe head of model risk management (approval) signs off the response.","requiredApprovals":1,"type":"TASK"}}],"edges":[{"id":"e-diagnose-breach-decide-response","source":"diagnose-breach","target":"decide-response"}],"metadata":{"kind":"model-monitoring-breach-review","source":"model-inventory-pack","prerequisites":{"status":"declared","anchorItemType":{"slug":"model"},"roles":[{"id":"model-owner","description":"The model owner (model_owner on the Model item).","nodeIds":["diagnose-breach"],"contribution":"expertise"},{"id":"mrm-head","description":"Head of model risk management.","nodeIds":["decide-response"],"contribution":"approval"}]}}},{"sourceTemplateId":"coworkcanvas:template:model-performance-monitoring","name":"Model Performance Monitoring","description":"Runs on the existing Model item once per monitoring period. Input: the period's performance result, supplied on the step form by the model's monitoring owner (the business or data science team that measures it), who does not run this workflow. Deliverable: the reviewed monitoring result; the Model Inventory dashboard plots monitoring_metric against monitoring_threshold from completed runs. Handoff: a result below the threshold starts a Model Monitoring Breach Review.","itemTypeSlug":"model","autoCreateOnItem":false,"nodes":[{"id":"review-monitoring-result","data":{"label":"Review the period's monitoring result","kind":"task","description":"The monitoring owner submits the period's metric and threshold on the form; the model risk analyst challenges it before sign-off.","instructions":"**Objective**\nA reviewed monitoring result for the period, with the metric compared to its threshold.\n\n**Inputs**\n1. The step form, submitted by the model's monitoring owner: monitoring_metric (the period's value of the model's key performance metric; higher is better) and monitoring_threshold (the minimum acceptable value).\n2. The previous monitoring runs on this Model item.\n\n**Procedure**\n1. Check the submitted metric against its source report and the period it covers.\n2. Compare it with the threshold and the previous periods; flag a sharp move even inside the threshold.\n3. When the metric is below the threshold, prepare a Model Monitoring Breach Review on the Model item.\n\n**Record in Canvas**\n- The comparison in the step result; the source report as a step document.\n- Set monitoring_status on the Model item: within_threshold, watch or breach.\n\n**Exit criteria**\nThe model risk analyst (variance) confirms the metric matches its source and the status follows from it.","formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"requiredApprovals":1,"type":"TASK"}}],"edges":[],"metadata":{"kind":"model-performance-monitoring","source":"model-inventory-pack","prerequisites":{"status":"declared","anchorItemType":{"slug":"model"},"roles":[{"id":"monitoring-owner","description":"The team that measures the model's performance; supplies the metric and threshold on the step form.","nodeIds":["review-monitoring-result"],"contribution":"expertise"},{"id":"mrm-analyst","description":"Model risk analyst who reviews the submitted result.","nodeIds":["review-monitoring-result"],"contribution":"variance"}]}}}],"workflowsAttached":[{"itemTitle":"Incident Response Investigation","itemType":"audit","name":"Audit Fieldwork, Findings & Reporting — Incident Response Investigation — next cycle","templateName":"Audit Fieldwork, Findings & Reporting","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","description":"Audit Fieldwork, Findings & Reporting for Incident Response Investigation (next cycle).","status":"DRAFT","displayOrder":1,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Execute and review fieldwork","description":null,"summary":null,"instructions":"**Objective**\nExecute and review fieldwork. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved planning record, work program, risk-to-procedure mapping, data requests, population reconciliations, independence confirmations, stakeholder contacts, and known constraints.\n2. Use the approved program, reconciled populations, source evidence, interviews, observations, system data, criteria, prior work, methodology, and reviewer instructions.\n\n**Procedure**\n1. Validate evidence access and population completeness, brief the team on documentation and escalation expectations, assign procedures and reviewers, resolve planning gaps, and record any approved scope or timing change.\n2. Execute each procedure as designed, retain selection rationale, corroborate representations, investigate anomalies, cross-reference evidence, quantify deviations, document limitations, and obtain timely supervisory review and clearance.\n\n**Record in AssureSwarm**\n1. Capture the plan reference, procedure assignments, evidence and data status, reconciled populations, review responsibilities, open requests, scope changes, constraints, owners, and due dates. Also record approved plan reference; readiness notes.\n2. Link the workpaper index and individual evidence records, identify preparer and reviewer, dates, population and sample, procedure performed, evidence considered, exceptions, review notes, responses, and disposition. Also record workpaper index reference.\n\n**Exit criteria**\nAudit supervisor provides expertise: The team can execute each approved procedure from authoritative inputs, material access gaps are resolved or escalated, and deviations from plan are formally visible. Planned work is complete or approved as modified, workpapers support recorded results, review notes are cleared or assigned, and potential observations are ready for evaluation.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Incident Response Investigation","itemType":"audit","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Evaluate and clear findings","description":null,"summary":null,"instructions":"**Objective**\nEvaluate and clear findings. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use reviewed workpapers, exceptions, criteria, quantified populations, root-cause analysis, corroborating and contrary evidence, prior issues, management responses, and proposed corrective actions.\n\n**Procedure**\n1. Validate factual accuracy, assess significance and pervasiveness, distinguish isolated deviations from systemic causes, challenge unsupported management explanations, conduct clearance discussions, and define practical owned actions and dates.\n\n**Record in AssureSwarm**\n1. Document each finding or cleared observation, evidence, criteria, cause, risk and impact, rating basis, management response, agreed or disputed action, owner, due date, and approval decision. Also record finding disposition.\n\n**Exit criteria**\nManagement and audit lead provides expertise: An approver accepts each disposition and supporting rationale, disagreements and limitations remain visible, and reportable matters are factually cleared without suppressing contrary evidence.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Incident Response Investigation","itemType":"audit","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":3,"name":"Approve report and engagement closure","description":null,"summary":null,"instructions":"**Objective**\nApprove report and engagement closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved plan, completed workpapers, cleared findings, management responses, quality-review notes, report draft, scope changes, limitations, distribution list, and action tracking records.\n\n**Procedure**\n1. Verify report statements trace to workpapers, conclusions stay within scope and evidence, ratings are consistent, responses and disagreements are accurate, actions are linked, and final quality and authorization reviews are complete.\n\n**Record in AssureSwarm**\n1. Capture the authorized reviewer, final report reference and date, distribution, scope and limitations, findings and actions, unresolved disagreements, owners, due dates, follow-up route, and archive index.\n\n**Exit criteria**\nChief audit executive provides approval: The authorized reviewer authorize the supported report and complete engagement record; the workflow itself does not create an audit opinion beyond the expressly approved report language.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Incident Response Investigation","itemType":"audit","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Procure to Pay Audit","itemType":"audit","name":"Audit Fieldwork, Findings & Reporting — Procure to Pay Audit — current cycle","templateName":"Audit Fieldwork, Findings & Reporting","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","description":"Audit Fieldwork, Findings & Reporting for Procure to Pay Audit (current cycle).","status":"ACTIVE","displayOrder":2,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Execute and review fieldwork","description":null,"summary":null,"instructions":"**Objective**\nExecute and review fieldwork. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved planning record, work program, risk-to-procedure mapping, data requests, population reconciliations, independence confirmations, stakeholder contacts, and known constraints.\n2. Use the approved program, reconciled populations, source evidence, interviews, observations, system data, criteria, prior work, methodology, and reviewer instructions.\n\n**Procedure**\n1. Validate evidence access and population completeness, brief the team on documentation and escalation expectations, assign procedures and reviewers, resolve planning gaps, and record any approved scope or timing change.\n2. Execute each procedure as designed, retain selection rationale, corroborate representations, investigate anomalies, cross-reference evidence, quantify deviations, document limitations, and obtain timely supervisory review and clearance.\n\n**Record in AssureSwarm**\n1. Capture the plan reference, procedure assignments, evidence and data status, reconciled populations, review responsibilities, open requests, scope changes, constraints, owners, and due dates. Also record approved plan reference; readiness notes.\n2. Link the workpaper index and individual evidence records, identify preparer and reviewer, dates, population and sample, procedure performed, evidence considered, exceptions, review notes, responses, and disposition. Also record workpaper index reference.\n\n**Exit criteria**\nAudit supervisor provides expertise: The team can execute each approved procedure from authoritative inputs, material access gaps are resolved or escalated, and deviations from plan are formally visible. Planned work is complete or approved as modified, workpapers support recorded results, review notes are cleared or assigned, and potential observations are ready for evaluation.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Evaluate and clear findings","description":null,"summary":null,"instructions":"**Objective**\nEvaluate and clear findings. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use reviewed workpapers, exceptions, criteria, quantified populations, root-cause analysis, corroborating and contrary evidence, prior issues, management responses, and proposed corrective actions.\n\n**Procedure**\n1. Validate factual accuracy, assess significance and pervasiveness, distinguish isolated deviations from systemic causes, challenge unsupported management explanations, conduct clearance discussions, and define practical owned actions and dates.\n\n**Record in AssureSwarm**\n1. Document each finding or cleared observation, evidence, criteria, cause, risk and impact, rating basis, management response, agreed or disputed action, owner, due date, and approval decision. Also record finding disposition.\n\n**Exit criteria**\nManagement and audit lead provides expertise: An approver accepts each disposition and supporting rationale, disagreements and limitations remain visible, and reportable matters are factually cleared without suppressing contrary evidence.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":3,"name":"Approve report and engagement closure","description":null,"summary":null,"instructions":"**Objective**\nApprove report and engagement closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved plan, completed workpapers, cleared findings, management responses, quality-review notes, report draft, scope changes, limitations, distribution list, and action tracking records.\n\n**Procedure**\n1. Verify report statements trace to workpapers, conclusions stay within scope and evidence, ratings are consistent, responses and disagreements are accurate, actions are linked, and final quality and authorization reviews are complete.\n\n**Record in AssureSwarm**\n1. Capture the authorized reviewer, final report reference and date, distribution, scope and limitations, findings and actions, unresolved disagreements, owners, due dates, follow-up route, and archive index.\n\n**Exit criteria**\nChief audit executive provides approval: The authorized reviewer authorize the supported report and complete engagement record; the workflow itself does not create an audit opinion beyond the expressly approved report language.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Revenue Recognition Audit","itemType":"audit","name":"Audit Fieldwork, Findings & Reporting — Revenue Recognition Audit — prior cycle","templateName":"Audit Fieldwork, Findings & Reporting","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","description":"Audit Fieldwork, Findings & Reporting for Revenue Recognition Audit (prior cycle).","status":"COMPLETED","displayOrder":3,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Execute and review fieldwork","description":null,"summary":null,"instructions":"**Objective**\nExecute and review fieldwork. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved planning record, work program, risk-to-procedure mapping, data requests, population reconciliations, independence confirmations, stakeholder contacts, and known constraints.\n2. Use the approved program, reconciled populations, source evidence, interviews, observations, system data, criteria, prior work, methodology, and reviewer instructions.\n\n**Procedure**\n1. Validate evidence access and population completeness, brief the team on documentation and escalation expectations, assign procedures and reviewers, resolve planning gaps, and record any approved scope or timing change.\n2. Execute each procedure as designed, retain selection rationale, corroborate representations, investigate anomalies, cross-reference evidence, quantify deviations, document limitations, and obtain timely supervisory review and clearance.\n\n**Record in AssureSwarm**\n1. Capture the plan reference, procedure assignments, evidence and data status, reconciled populations, review responsibilities, open requests, scope changes, constraints, owners, and due dates. Also record approved plan reference; readiness notes.\n2. Link the workpaper index and individual evidence records, identify preparer and reviewer, dates, population and sample, procedure performed, evidence considered, exceptions, review notes, responses, and disposition. Also record workpaper index reference.\n\n**Exit criteria**\nAudit supervisor provides expertise: The team can execute each approved procedure from authoritative inputs, material access gaps are resolved or escalated, and deviations from plan are formally visible. Planned work is complete or approved as modified, workpapers support recorded results, review notes are cleared or assigned, and potential observations are ready for evaluation.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"},{"itemTitle":"Batch Processing Monitoring","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Evaluate and clear findings","description":null,"summary":null,"instructions":"**Objective**\nEvaluate and clear findings. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use reviewed workpapers, exceptions, criteria, quantified populations, root-cause analysis, corroborating and contrary evidence, prior issues, management responses, and proposed corrective actions.\n\n**Procedure**\n1. Validate factual accuracy, assess significance and pervasiveness, distinguish isolated deviations from systemic causes, challenge unsupported management explanations, conduct clearance discussions, and define practical owned actions and dates.\n\n**Record in AssureSwarm**\n1. Document each finding or cleared observation, evidence, criteria, cause, risk and impact, rating basis, management response, agreed or disputed action, owner, due date, and approval decision. Also record finding disposition.\n\n**Exit criteria**\nManagement and audit lead provides expertise: An approver accepts each disposition and supporting rationale, disagreements and limitations remain visible, and reportable matters are factually cleared without suppressing contrary evidence.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"},{"itemTitle":"Batch Processing Monitoring","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":3,"name":"Approve report and engagement closure","description":null,"summary":null,"instructions":"**Objective**\nApprove report and engagement closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved plan, completed workpapers, cleared findings, management responses, quality-review notes, report draft, scope changes, limitations, distribution list, and action tracking records.\n\n**Procedure**\n1. Verify report statements trace to workpapers, conclusions stay within scope and evidence, ratings are consistent, responses and disagreements are accurate, actions are linked, and final quality and authorization reviews are complete.\n\n**Record in AssureSwarm**\n1. Capture the authorized reviewer, final report reference and date, distribution, scope and limitations, findings and actions, unresolved disagreements, owners, due dates, follow-up route, and archive index.\n\n**Exit criteria**\nChief audit executive provides approval: The authorized reviewer authorize the supported report and complete engagement record; the workflow itself does not create an audit opinion beyond the expressly approved report language.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"},{"itemTitle":"Batch Processing Monitoring","itemType":"control","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","name":"Audit Planning & Scoping — FY2026 SOX Annual Program — next cycle","templateName":"Audit Planning & Scoping","templateSourceId":"coworkcanvas:template:audit-planning-scoping","description":"Audit Planning & Scoping for FY2026 SOX Annual Program (next cycle).","status":"DRAFT","displayOrder":11,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Draft the walkthrough question set","description":null,"summary":null,"instructions":"**Objective**\nDraft the walkthrough question set. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the engagement mandate, the self-identification form issued to control owners, the obligations register with regulator and incident reporting, prior audit reports and open Issues for the area, and the risk and control registers.\n2. Use the self-identified issues and the owners who reported nothing, the external candidate risks and near-term obligations, the prior coverage and open findings, and the in-scope risk and control set with its unmapped risks and orphaned controls.\n\n**Procedure**\n1. Use current management self-identifications first. Only when a named control owner who is not executing this workflow must supply missing facts, prepare a form limited to those facts; request or chase responses only through an authorized channel. Restate each dated external source as a candidate risk. List prior coverage, carry open findings forward, and decide what can be relied on. Select the in-scope risks with a reason for each, list their asserted controls, and note the mapping gaps.\n2. Derive questions from each input and keep the origin attached, ask how the control actually operates, who performs it, what evidence it leaves, and what happens when it fails or is bypassed rather than whether it exists, include a question for every contradiction between the inputs, and sequence by process flow with an interviewee and evidence request on each.\n\nVerify team competence, disclose independence impairments and resolve safeguards before fieldwork; agree objectives, criteria, period, scope and materiality.\n\n**Record in AssureSwarm**\n1. Record the response status, the issues disclosed and the owners who did not respond; the sources reviewed, candidate risks and near-term obligations; prior coverage, open findings carried forward and the prior conclusions relied on; and the in-scope risks with rationale, their asserted controls, and the mapping gaps. Raise new items as Issues and link the risks and controls to this audit.\n2. Record the question set with the source of each question, the assigned interviewee, and the evidence to request, together with the interviewees, sessions, and dates. Also record evidence to request in the room.\n\n**Exit criteria**\nEngagement lead provides expertise: Every owner has responded or is recorded as non-responsive, the external view is sourced and dated, each reliance on a prior conclusion has a basis, the risk set is justified with its controls, and every contradiction between the inputs is a walkthrough question, not a conclusion. Every question traces to a planning input, contradictions between inputs are represented, each question has an interviewee and evidence request, and an approver accepted the instrument before the business is engaged.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Build the risk and control matrix","description":null,"summary":null,"instructions":"**Objective**\nBuild the risk and control matrix. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved question set, the in-scope risk and control set, process narratives, system screens, reports, and evidence produced in the room, and the interviewees confirmed for each session.\n2. Use the in-scope risk and control set, the walkthrough observations and deviations, prior testing results and reliance decisions, and the external obligations in scope.\n\n**Procedure**\n1. Walk the process in operating order rather than register order, follow at least one live item through every handoff, system, approval, and exception path, ask the assigned questions and follow each answer where it goes, observe the control operating rather than accepting a description, and capture who can override and what an override leaves behind.\n2. Record for each in-scope risk the controls that address it with owner, frequency, automation, and key-control status, conclude on design from what was observed rather than asserted, record a design gap where no control addresses a risk, define the testing approach and population for each control to be tested, and route gaps to Issues.\n\n**Record in AssureSwarm**\n1. Record the sessions, participants, item traced, observations against each question, deviations between asserted and observed design, and the evidence obtained or still outstanding. Also record walkthrough date; evidence still outstanding, with owner and date.\n2. Record the matrix row by row with risk, control, owner, design conclusion, testing approach, and population, link the risks and controls to this audit, and raise Issues for the design gaps. Also record matrix summary - risk, control, owner, design conclusion, testing approach; design gaps raised as Issues; planning decision.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: The process has been observed end to end with at least one item traced through, every approved question is answered or recorded as unanswered with a reason, deviations are documented, and outstanding evidence requests have owners and dates. Every in-scope risk has either a mapped control with a design conclusion or a recorded design gap, the testing approach is defined for each control to be tested, and The authorized reviewer have accepted the matrix as the basis for fieldwork.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 Certification Readiness","itemType":"audit","name":"Audit Planning & Scoping — ISO 27001 Certification Readiness — current cycle","templateName":"Audit Planning & Scoping","templateSourceId":"coworkcanvas:template:audit-planning-scoping","description":"Audit Planning & Scoping for ISO 27001 Certification Readiness (current cycle).","status":"ACTIVE","displayOrder":12,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Draft the walkthrough question set","description":null,"summary":null,"instructions":"**Objective**\nDraft the walkthrough question set. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the engagement mandate, the self-identification form issued to control owners, the obligations register with regulator and incident reporting, prior audit reports and open Issues for the area, and the risk and control registers.\n2. Use the self-identified issues and the owners who reported nothing, the external candidate risks and near-term obligations, the prior coverage and open findings, and the in-scope risk and control set with its unmapped risks and orphaned controls.\n\n**Procedure**\n1. Use current management self-identifications first. Only when a named control owner who is not executing this workflow must supply missing facts, prepare a form limited to those facts; request or chase responses only through an authorized channel. Restate each dated external source as a candidate risk. List prior coverage, carry open findings forward, and decide what can be relied on. Select the in-scope risks with a reason for each, list their asserted controls, and note the mapping gaps.\n2. Derive questions from each input and keep the origin attached, ask how the control actually operates, who performs it, what evidence it leaves, and what happens when it fails or is bypassed rather than whether it exists, include a question for every contradiction between the inputs, and sequence by process flow with an interviewee and evidence request on each.\n\nVerify team competence, disclose independence impairments and resolve safeguards before fieldwork; agree objectives, criteria, period, scope and materiality.\n\n**Record in AssureSwarm**\n1. Record the response status, the issues disclosed and the owners who did not respond; the sources reviewed, candidate risks and near-term obligations; prior coverage, open findings carried forward and the prior conclusions relied on; and the in-scope risks with rationale, their asserted controls, and the mapping gaps. Raise new items as Issues and link the risks and controls to this audit.\n2. Record the question set with the source of each question, the assigned interviewee, and the evidence to request, together with the interviewees, sessions, and dates. Also record evidence to request in the room.\n\n**Exit criteria**\nEngagement lead provides expertise: Every owner has responded or is recorded as non-responsive, the external view is sourced and dated, each reliance on a prior conclusion has a basis, the risk set is justified with its controls, and every contradiction between the inputs is a walkthrough question, not a conclusion. Every question traces to a planning input, contradictions between inputs are represented, each question has an interviewee and evidence request, and an approver accepted the instrument before the business is engaged.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 Certification Readiness","itemType":"audit","kind":"related"},{"itemTitle":"New Application Architecture Review","itemType":"control","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Build the risk and control matrix","description":null,"summary":null,"instructions":"**Objective**\nBuild the risk and control matrix. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved question set, the in-scope risk and control set, process narratives, system screens, reports, and evidence produced in the room, and the interviewees confirmed for each session.\n2. Use the in-scope risk and control set, the walkthrough observations and deviations, prior testing results and reliance decisions, and the external obligations in scope.\n\n**Procedure**\n1. Walk the process in operating order rather than register order, follow at least one live item through every handoff, system, approval, and exception path, ask the assigned questions and follow each answer where it goes, observe the control operating rather than accepting a description, and capture who can override and what an override leaves behind.\n2. Record for each in-scope risk the controls that address it with owner, frequency, automation, and key-control status, conclude on design from what was observed rather than asserted, record a design gap where no control addresses a risk, define the testing approach and population for each control to be tested, and route gaps to Issues.\n\n**Record in AssureSwarm**\n1. Record the sessions, participants, item traced, observations against each question, deviations between asserted and observed design, and the evidence obtained or still outstanding. Also record walkthrough date; evidence still outstanding, with owner and date.\n2. Record the matrix row by row with risk, control, owner, design conclusion, testing approach, and population, link the risks and controls to this audit, and raise Issues for the design gaps. Also record matrix summary - risk, control, owner, design conclusion, testing approach; design gaps raised as Issues; planning decision.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: The process has been observed end to end with at least one item traced through, every approved question is answered or recorded as unanswered with a reason, deviations are documented, and outstanding evidence requests have owners and dates. Every in-scope risk has either a mapped control with a design conclusion or a recorded design gap, the testing approach is defined for each control to be tested, and The authorized reviewer have accepted the matrix as the basis for fieldwork.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 Certification Readiness","itemType":"audit","kind":"related"},{"itemTitle":"New Application Architecture Review","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","name":"Audit Planning & Scoping — Identity and Access Management Audit — prior cycle","templateName":"Audit Planning & Scoping","templateSourceId":"coworkcanvas:template:audit-planning-scoping","description":"Audit Planning & Scoping for Identity and Access Management Audit (prior cycle).","status":"COMPLETED","displayOrder":13,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Draft the walkthrough question set","description":null,"summary":null,"instructions":"**Objective**\nDraft the walkthrough question set. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the engagement mandate, the self-identification form issued to control owners, the obligations register with regulator and incident reporting, prior audit reports and open Issues for the area, and the risk and control registers.\n2. Use the self-identified issues and the owners who reported nothing, the external candidate risks and near-term obligations, the prior coverage and open findings, and the in-scope risk and control set with its unmapped risks and orphaned controls.\n\n**Procedure**\n1. Use current management self-identifications first. Only when a named control owner who is not executing this workflow must supply missing facts, prepare a form limited to those facts; request or chase responses only through an authorized channel. Restate each dated external source as a candidate risk. List prior coverage, carry open findings forward, and decide what can be relied on. Select the in-scope risks with a reason for each, list their asserted controls, and note the mapping gaps.\n2. Derive questions from each input and keep the origin attached, ask how the control actually operates, who performs it, what evidence it leaves, and what happens when it fails or is bypassed rather than whether it exists, include a question for every contradiction between the inputs, and sequence by process flow with an interviewee and evidence request on each.\n\nVerify team competence, disclose independence impairments and resolve safeguards before fieldwork; agree objectives, criteria, period, scope and materiality.\n\n**Record in AssureSwarm**\n1. Record the response status, the issues disclosed and the owners who did not respond; the sources reviewed, candidate risks and near-term obligations; prior coverage, open findings carried forward and the prior conclusions relied on; and the in-scope risks with rationale, their asserted controls, and the mapping gaps. Raise new items as Issues and link the risks and controls to this audit.\n2. Record the question set with the source of each question, the assigned interviewee, and the evidence to request, together with the interviewees, sessions, and dates. Also record evidence to request in the room.\n\n**Exit criteria**\nEngagement lead provides expertise: Every owner has responded or is recorded as non-responsive, the external view is sourced and dated, each reliance on a prior conclusion has a basis, the risk set is justified with its controls, and every contradiction between the inputs is a walkthrough question, not a conclusion. Every question traces to a planning input, contradictions between inputs are represented, each question has an interviewee and evidence request, and an approver accepted the instrument before the business is engaged.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Build the risk and control matrix","description":null,"summary":null,"instructions":"**Objective**\nBuild the risk and control matrix. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved question set, the in-scope risk and control set, process narratives, system screens, reports, and evidence produced in the room, and the interviewees confirmed for each session.\n2. Use the in-scope risk and control set, the walkthrough observations and deviations, prior testing results and reliance decisions, and the external obligations in scope.\n\n**Procedure**\n1. Walk the process in operating order rather than register order, follow at least one live item through every handoff, system, approval, and exception path, ask the assigned questions and follow each answer where it goes, observe the control operating rather than accepting a description, and capture who can override and what an override leaves behind.\n2. Record for each in-scope risk the controls that address it with owner, frequency, automation, and key-control status, conclude on design from what was observed rather than asserted, record a design gap where no control addresses a risk, define the testing approach and population for each control to be tested, and route gaps to Issues.\n\n**Record in AssureSwarm**\n1. Record the sessions, participants, item traced, observations against each question, deviations between asserted and observed design, and the evidence obtained or still outstanding. Also record walkthrough date; evidence still outstanding, with owner and date.\n2. Record the matrix row by row with risk, control, owner, design conclusion, testing approach, and population, link the risks and controls to this audit, and raise Issues for the design gaps. Also record matrix summary - risk, control, owner, design conclusion, testing approach; design gaps raised as Issues; planning decision.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: The process has been observed end to end with at least one item traced through, every approved question is answered or recorded as unanswered with a reason, deviations are documented, and outstanding evidence requests have owners and dates. Every in-scope risk has either a mapped control with a design conclusion or a recorded design gap, the testing approach is defined for each control to be tested, and The authorized reviewer have accepted the matrix as the basis for fieldwork.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Banana ERP","itemType":"system","name":"Backup & Recovery Testing — Banana ERP — current cycle","templateName":"Backup & Recovery Testing","templateSourceId":"coworkcanvas:template:backup-recovery-testing","description":"Backup & Recovery Testing for Banana ERP (current cycle).","status":"ACTIVE","displayOrder":22,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm backup scope and recovery objectives","description":null,"summary":null,"instructions":"**Objective**\nConfirm backup scope and recovery objectives. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the backup configuration and retention schedule, business impact analysis with RPO and RTO, the continuity plan, prior restoration test results, and dependency maps.\n\n**Procedure**\n1. Confirm the objectives come from business impact analysis rather than from what the backup tooling currently achieves, identify data in scope that is not backed up, and select a restoration scenario that exercises a realistic failure.\n\n**Record in AssureSwarm**\n1. Capture the test period, RPO and RTO with their business basis, data and configuration in scope, items not covered by backup, the restoration scenario selected, and dependencies required for recovery. Also record recovery objectives (RPO/RTO) and data in scope.\n\n**Exit criteria**\nBusiness recovery owner provides approval: Objectives are traced to business impact rather than to tooling capability, unbacked-up data is named, and the test scenario exercises a realistic failure rather than a convenient one.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve recovery test record","description":null,"summary":null,"instructions":"**Objective**\nApprove recovery test record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the selected backup set and its age, restoration tooling and runbooks, an isolated restore target, data completeness checks against the source, application startup and integrity checks, and elapsed timing.\n2. Use the restoration evidence and timings, the backup set age against RPO, the stated RTO, dependency recovery sequencing, and resource constraints observed during the test.\n3. Review all stage records, objectives and their business basis, unbacked-up data, restoration evidence and timings, computed achieved values, scale assumptions, and open gaps.\n\n**Procedure**\n1. RESTORE rather than inspect backup job status, verify restored data completeness against known source values, start the application against the restored data where feasible, and record elapsed time from initiation to usable state.\n2. Compute achieved RPO from the restored backup age and achieved RTO from measured elapsed time, test whether the result would hold at production scale, and record an untested dependency as a gap rather than an assumption.\n3. Trace achieved values to measured evidence, verify unbacked-up data and untested dependencies carry owners, confirm the scenario was realistic, and return job-status-only evidence with precise comments.\n\n**Record in AssureSwarm**\n1. Document the backup set restored and its age, restoration steps and elapsed timings, completeness and integrity checks with results, application startup verification, failures encountered, and manual intervention required. Also record restoration evidence; restoration outcome.\n2. Record objectives met or missed with computed achieved values, scale assumptions and their basis, untested dependencies, gaps with remediation owners and dates, and constraints that would worsen a real recovery. Also record gap detail and remediation.\n3. Capture the authorized reviewer, the summary, accepted conclusion, test date, achieved RPO and RTO, gaps with owners and dates, scope not covered by backup, and linked issues raised. Also record recovery test summary.\n\n**Exit criteria**\nIndependent recovery reviewer provides approval: Recoverability is evidenced by an actual restoration verified for completeness and usability, elapsed time is measured, and manual interventions are recorded rather than normalized. An approver accepts that achieved values are computed from the test rather than asserted, scale limitations are stated, and gaps carry remediation owners. The authorized reviewer accepts the record as evidence the recovery control was tested, and closure implies no assurance for data, systems, or scale not exercised by this test.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Model Home Data Lake","itemType":"system","name":"Backup & Recovery Testing — Model Home Data Lake — next cycle","templateName":"Backup & Recovery Testing","templateSourceId":"coworkcanvas:template:backup-recovery-testing","description":"Backup & Recovery Testing for Model Home Data Lake (next cycle).","status":"DRAFT","displayOrder":21,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm backup scope and recovery objectives","description":null,"summary":null,"instructions":"**Objective**\nConfirm backup scope and recovery objectives. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the backup configuration and retention schedule, business impact analysis with RPO and RTO, the continuity plan, prior restoration test results, and dependency maps.\n\n**Procedure**\n1. Confirm the objectives come from business impact analysis rather than from what the backup tooling currently achieves, identify data in scope that is not backed up, and select a restoration scenario that exercises a realistic failure.\n\n**Record in AssureSwarm**\n1. Capture the test period, RPO and RTO with their business basis, data and configuration in scope, items not covered by backup, the restoration scenario selected, and dependencies required for recovery. Also record recovery objectives (RPO/RTO) and data in scope.\n\n**Exit criteria**\nBusiness recovery owner provides approval: Objectives are traced to business impact rather than to tooling capability, unbacked-up data is named, and the test scenario exercises a realistic failure rather than a convenient one.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve recovery test record","description":null,"summary":null,"instructions":"**Objective**\nApprove recovery test record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the selected backup set and its age, restoration tooling and runbooks, an isolated restore target, data completeness checks against the source, application startup and integrity checks, and elapsed timing.\n2. Use the restoration evidence and timings, the backup set age against RPO, the stated RTO, dependency recovery sequencing, and resource constraints observed during the test.\n3. Review all stage records, objectives and their business basis, unbacked-up data, restoration evidence and timings, computed achieved values, scale assumptions, and open gaps.\n\n**Procedure**\n1. RESTORE rather than inspect backup job status, verify restored data completeness against known source values, start the application against the restored data where feasible, and record elapsed time from initiation to usable state.\n2. Compute achieved RPO from the restored backup age and achieved RTO from measured elapsed time, test whether the result would hold at production scale, and record an untested dependency as a gap rather than an assumption.\n3. Trace achieved values to measured evidence, verify unbacked-up data and untested dependencies carry owners, confirm the scenario was realistic, and return job-status-only evidence with precise comments.\n\n**Record in AssureSwarm**\n1. Document the backup set restored and its age, restoration steps and elapsed timings, completeness and integrity checks with results, application startup verification, failures encountered, and manual intervention required. Also record restoration evidence; restoration outcome.\n2. Record objectives met or missed with computed achieved values, scale assumptions and their basis, untested dependencies, gaps with remediation owners and dates, and constraints that would worsen a real recovery. Also record gap detail and remediation.\n3. Capture the authorized reviewer, the summary, accepted conclusion, test date, achieved RPO and RTO, gaps with owners and dates, scope not covered by backup, and linked issues raised. Also record recovery test summary.\n\n**Exit criteria**\nIndependent recovery reviewer provides approval: Recoverability is evidenced by an actual restoration verified for completeness and usability, elapsed time is measured, and manual interventions are recorded rather than normalized. An approver accepts that achieved values are computed from the test rather than asserted, scale limitations are stated, and gaps carry remediation owners. The authorized reviewer accepts the record as evidence the recovery control was tested, and closure implies no assurance for data, systems, or scale not exercised by this test.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Sudden Valley Network","itemType":"system","name":"Backup & Recovery Testing — Sudden Valley Network — prior cycle","templateName":"Backup & Recovery Testing","templateSourceId":"coworkcanvas:template:backup-recovery-testing","description":"Backup & Recovery Testing for Sudden Valley Network (prior cycle).","status":"COMPLETED","displayOrder":23,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm backup scope and recovery objectives","description":null,"summary":null,"instructions":"**Objective**\nConfirm backup scope and recovery objectives. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the backup configuration and retention schedule, business impact analysis with RPO and RTO, the continuity plan, prior restoration test results, and dependency maps.\n\n**Procedure**\n1. Confirm the objectives come from business impact analysis rather than from what the backup tooling currently achieves, identify data in scope that is not backed up, and select a restoration scenario that exercises a realistic failure.\n\n**Record in AssureSwarm**\n1. Capture the test period, RPO and RTO with their business basis, data and configuration in scope, items not covered by backup, the restoration scenario selected, and dependencies required for recovery. Also record recovery objectives (RPO/RTO) and data in scope.\n\n**Exit criteria**\nBusiness recovery owner provides approval: Objectives are traced to business impact rather than to tooling capability, unbacked-up data is named, and the test scenario exercises a realistic failure rather than a convenient one.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Sudden Valley Network","itemType":"system","kind":"related"},{"itemTitle":"Availability & capacity management (SLA)","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve recovery test record","description":null,"summary":null,"instructions":"**Objective**\nApprove recovery test record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the selected backup set and its age, restoration tooling and runbooks, an isolated restore target, data completeness checks against the source, application startup and integrity checks, and elapsed timing.\n2. Use the restoration evidence and timings, the backup set age against RPO, the stated RTO, dependency recovery sequencing, and resource constraints observed during the test.\n3. Review all stage records, objectives and their business basis, unbacked-up data, restoration evidence and timings, computed achieved values, scale assumptions, and open gaps.\n\n**Procedure**\n1. RESTORE rather than inspect backup job status, verify restored data completeness against known source values, start the application against the restored data where feasible, and record elapsed time from initiation to usable state.\n2. Compute achieved RPO from the restored backup age and achieved RTO from measured elapsed time, test whether the result would hold at production scale, and record an untested dependency as a gap rather than an assumption.\n3. Trace achieved values to measured evidence, verify unbacked-up data and untested dependencies carry owners, confirm the scenario was realistic, and return job-status-only evidence with precise comments.\n\n**Record in AssureSwarm**\n1. Document the backup set restored and its age, restoration steps and elapsed timings, completeness and integrity checks with results, application startup verification, failures encountered, and manual intervention required. Also record restoration evidence; restoration outcome.\n2. Record objectives met or missed with computed achieved values, scale assumptions and their basis, untested dependencies, gaps with remediation owners and dates, and constraints that would worsen a real recovery. Also record gap detail and remediation.\n3. Capture the authorized reviewer, the summary, accepted conclusion, test date, achieved RPO and RTO, gaps with owners and dates, scope not covered by backup, and linked issues raised. Also record recovery test summary.\n\n**Exit criteria**\nIndependent recovery reviewer provides approval: Recoverability is evidenced by an actual restoration verified for completeness and usability, elapsed time is measured, and manual interventions are recorded rather than normalized. An approver accepts that achieved values are computed from the test rather than asserted, scale limitations are stated, and gaps carry remediation owners. The authorized reviewer accepts the record as evidence the recovery control was tested, and closure implies no assurance for data, systems, or scale not exercised by this test.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Sudden Valley Network","itemType":"system","kind":"related"},{"itemTitle":"Availability & capacity management (SLA)","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Banana ERP","itemType":"system","name":"Change Request, Approval & Migration — Banana ERP — current cycle","templateName":"Change Request, Approval & Migration","templateSourceId":"coworkcanvas:template:change-request-approval-migration","description":"Change Request, Approval & Migration for Banana ERP (current cycle).","status":"ACTIVE","displayOrder":32,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Obtain approval and test evidence","description":null,"summary":null,"instructions":"**Objective**\nObtain approval and test evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the change record, requirements or defect reference, affected component and interface inventory, the change classification policy, and the release calendar.\n2. Use the change record, test plans and executed results, defect logs and retest evidence, user acceptance sign-off, the approver identity and role, and the developer identity.\n\n**Procedure**\n1. Verify the change is recorded before work began, confirm the classification drives the correct approval path, identify affected downstream interfaces and reporting, and flag changes classified below their actual risk.\n2. Inspect executed test results rather than a test plan, confirm the approver is independent of the developer by identity comparison, verify conditions of approval are recorded, and refuse approval evidenced only by workflow status.\n\n**Record in AssureSwarm**\n1. Capture the change reference, requester and business reason, affected components and interfaces, classification with rationale, required approval path, target release window, and classification challenges raised. Also record change description and classification.\n2. Document test evidence with dates and executor, defects raised and retested, approver identity and independence basis, approval status and conditions, and testing the change did not receive.\n\n**Exit criteria**\nIndependent change approver provides approval: The change is recorded in advance with an evidenced classification, the approval path follows from the classification, and under-classification is challenged rather than accepted. Testing is evidenced by executed results, approver independence is demonstrated by identity rather than assumed, and approval conditions are recorded before migration.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve change record","description":null,"summary":null,"instructions":"**Objective**\nApprove change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved change package, deployment pipeline and migration logs, production verification results, the migrator identity, rollback plan, and post-migration monitoring.\n2. Review all stage records, classification rationale, executed test evidence, approver and migrator identities, deployed-versus-approved comparison, and open post-migration issues.\n\n**Procedure**\n1. Compare the deployed artifact against the approved package rather than trusting the pipeline, confirm migrator identity differs from developer identity, verify post-migration behaviour, and record an unsegregated migration as a control exception.\n2. Trace the deployed change to an approval and executed tests, verify both independence checks rest on identity evidence, confirm open issues carry owners, and return approvals evidenced only by status with precise comments.\n\n**Record in AssureSwarm**\n1. Record the migration outcome, deployed artifact compared to approval, migrator identity and segregation basis, verification results, issues and rollback actions, and compensating controls where segregation failed. Also record developer/migrator segregation.\n2. Capture the authorized reviewer, the change summary, accepted outcome, migration date, segregation conclusion, compensating controls, open issues with owners and dates, and linked exceptions raised.\n\n**Exit criteria**\nIndependent release reviewer provides approval: An approver accepts that production matches the approved package, segregation is evidenced by identity comparison, and a segregation failure is recorded as an exception rather than waived. The authorized reviewer accepts the record as evidence the change control operated for this change, and closure implies no assurance over changes migrated outside this process.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Cornballer Revenue Engine","itemType":"system","name":"Change Request, Approval & Migration — Cornballer Revenue Engine — next cycle","templateName":"Change Request, Approval & Migration","templateSourceId":"coworkcanvas:template:change-request-approval-migration","description":"Change Request, Approval & Migration for Cornballer Revenue Engine (next cycle).","status":"DRAFT","displayOrder":31,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Obtain approval and test evidence","description":null,"summary":null,"instructions":"**Objective**\nObtain approval and test evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the change record, requirements or defect reference, affected component and interface inventory, the change classification policy, and the release calendar.\n2. Use the change record, test plans and executed results, defect logs and retest evidence, user acceptance sign-off, the approver identity and role, and the developer identity.\n\n**Procedure**\n1. Verify the change is recorded before work began, confirm the classification drives the correct approval path, identify affected downstream interfaces and reporting, and flag changes classified below their actual risk.\n2. Inspect executed test results rather than a test plan, confirm the approver is independent of the developer by identity comparison, verify conditions of approval are recorded, and refuse approval evidenced only by workflow status.\n\n**Record in AssureSwarm**\n1. Capture the change reference, requester and business reason, affected components and interfaces, classification with rationale, required approval path, target release window, and classification challenges raised. Also record change description and classification.\n2. Document test evidence with dates and executor, defects raised and retested, approver identity and independence basis, approval status and conditions, and testing the change did not receive.\n\n**Exit criteria**\nIndependent change approver provides approval: The change is recorded in advance with an evidenced classification, the approval path follows from the classification, and under-classification is challenged rather than accepted. Testing is evidenced by executed results, approver independence is demonstrated by identity rather than assumed, and approval conditions are recorded before migration.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve change record","description":null,"summary":null,"instructions":"**Objective**\nApprove change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved change package, deployment pipeline and migration logs, production verification results, the migrator identity, rollback plan, and post-migration monitoring.\n2. Review all stage records, classification rationale, executed test evidence, approver and migrator identities, deployed-versus-approved comparison, and open post-migration issues.\n\n**Procedure**\n1. Compare the deployed artifact against the approved package rather than trusting the pipeline, confirm migrator identity differs from developer identity, verify post-migration behaviour, and record an unsegregated migration as a control exception.\n2. Trace the deployed change to an approval and executed tests, verify both independence checks rest on identity evidence, confirm open issues carry owners, and return approvals evidenced only by status with precise comments.\n\n**Record in AssureSwarm**\n1. Record the migration outcome, deployed artifact compared to approval, migrator identity and segregation basis, verification results, issues and rollback actions, and compensating controls where segregation failed. Also record developer/migrator segregation.\n2. Capture the authorized reviewer, the change summary, accepted outcome, migration date, segregation conclusion, compensating controls, open issues with owners and dates, and linked exceptions raised.\n\n**Exit criteria**\nIndependent release reviewer provides approval: An approver accepts that production matches the approved package, segregation is evidenced by identity comparison, and a segregation failure is recorded as an exception rather than waived. The authorized reviewer accepts the record as evidence the change control operated for this change, and closure implies no assurance over changes migrated outside this process.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Model Home Data Lake","itemType":"system","name":"Change Request, Approval & Migration — Model Home Data Lake — prior cycle","templateName":"Change Request, Approval & Migration","templateSourceId":"coworkcanvas:template:change-request-approval-migration","description":"Change Request, Approval & Migration for Model Home Data Lake (prior cycle).","status":"COMPLETED","displayOrder":33,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Obtain approval and test evidence","description":null,"summary":null,"instructions":"**Objective**\nObtain approval and test evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the change record, requirements or defect reference, affected component and interface inventory, the change classification policy, and the release calendar.\n2. Use the change record, test plans and executed results, defect logs and retest evidence, user acceptance sign-off, the approver identity and role, and the developer identity.\n\n**Procedure**\n1. Verify the change is recorded before work began, confirm the classification drives the correct approval path, identify affected downstream interfaces and reporting, and flag changes classified below their actual risk.\n2. Inspect executed test results rather than a test plan, confirm the approver is independent of the developer by identity comparison, verify conditions of approval are recorded, and refuse approval evidenced only by workflow status.\n\n**Record in AssureSwarm**\n1. Capture the change reference, requester and business reason, affected components and interfaces, classification with rationale, required approval path, target release window, and classification challenges raised. Also record change description and classification.\n2. Document test evidence with dates and executor, defects raised and retested, approver identity and independence basis, approval status and conditions, and testing the change did not receive.\n\n**Exit criteria**\nIndependent change approver provides approval: The change is recorded in advance with an evidenced classification, the approval path follows from the classification, and under-classification is challenged rather than accepted. Testing is evidenced by executed results, approver independence is demonstrated by identity rather than assumed, and approval conditions are recorded before migration.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve change record","description":null,"summary":null,"instructions":"**Objective**\nApprove change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved change package, deployment pipeline and migration logs, production verification results, the migrator identity, rollback plan, and post-migration monitoring.\n2. Review all stage records, classification rationale, executed test evidence, approver and migrator identities, deployed-versus-approved comparison, and open post-migration issues.\n\n**Procedure**\n1. Compare the deployed artifact against the approved package rather than trusting the pipeline, confirm migrator identity differs from developer identity, verify post-migration behaviour, and record an unsegregated migration as a control exception.\n2. Trace the deployed change to an approval and executed tests, verify both independence checks rest on identity evidence, confirm open issues carry owners, and return approvals evidenced only by status with precise comments.\n\n**Record in AssureSwarm**\n1. Record the migration outcome, deployed artifact compared to approval, migrator identity and segregation basis, verification results, issues and rollback actions, and compensating controls where segregation failed. Also record developer/migrator segregation.\n2. Capture the authorized reviewer, the change summary, accepted outcome, migration date, segregation conclusion, compensating controls, open issues with owners and dates, and linked exceptions raised.\n\n**Exit criteria**\nIndependent release reviewer provides approval: An approver accepts that production matches the approved package, segregation is evidenced by identity comparison, and a segregation failure is recorded as an exception rather than waived. The authorized reviewer accepts the record as evidence the change control operated for this change, and closure implies no assurance over changes migrated outside this process.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 A.5.36 — Security-policy compliance checks","itemType":"requirement","name":"Compliance Monitoring & Attestation — ISO 27001 A.5.36 — Security-policy compliance checks — next cycle","templateName":"Compliance Monitoring & Attestation","templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","description":"Compliance Monitoring & Attestation for ISO 27001 A.5.36 — Security-policy compliance checks (next cycle).","status":"DRAFT","displayOrder":41,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Refresh evidence and test continued conformance","description":null,"summary":null,"instructions":"**Objective**\nRefresh evidence and test continued conformance. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, its mapped controls and policies, the prior monitoring record, the last review date, framework version history, organizational and system changes, and the evidence expectations on record.\n2. Use the evidence expectations, control operation records and testing results, policy publication and attestation records, system configuration extracts, incident and exception logs, and prior-period evidence for comparison.\n\n**Procedure**\n1. Fix the period boundaries, confirm the mapped artifact set is still current, identify organizational, system, or framework changes since the last review, restate the evidence expected per clause, and note scope no longer applicable.\n2. Inspect evidence covering the whole period rather than a point in time, compare against prior-period evidence for drift, separate management representation from inspected support, and classify results against stated criteria rather than impression.\n\n**Record in AssureSwarm**\n1. Capture the monitoring period, clauses and artifacts in scope, evidence expectations, changes since last review, scope removed with rationale, accountable reviewer, and known evidence availability risks.\n2. Document the evidence refresh with source and date per clause, conformance result, period coverage achieved, drift observed against prior period, representations relied upon, and clauses left untested with reasons.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The period and artifact scope are current, evidence expectations are restated before collection, and changes that could break conformance are visible. Each clause result is supported by dated evidence covering the period, untested clauses are declared, and drift is recorded rather than smoothed.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.36 — Security-policy compliance checks","itemType":"requirement","kind":"related"},{"itemTitle":"Information Security Policy","itemType":"policy","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve attestation record","description":null,"summary":null,"instructions":"**Objective**\nApprove attestation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the conformance results and their evidence, deviation and exception detail, compensating measures, open issues and remediations, the escalation matrix, and the owner representations.\n2. Review all stage records, evidence references and their period coverage, drift observations, untested clauses, exception dispositions, attestation and its qualifications, and escalation confirmations.\n\n**Procedure**\n1. Present the tested position to the owner without softening deviations, record each exception with cause, exposure, and disposition, evaluate compensating measures on evidence, and escalate declined attestations and material deviations before advancing.\n2. Trace each conformance result to dated evidence, verify exceptions carry owners and dates, confirm escalations reached the authorized body, set the next review date against the required cadence, and return unsupported conclusions with precise comments.\n\n**Record in AssureSwarm**\n1. Record the attestation decision, attesting owner and date, each exception with cause, exposure, compensating measure and disposition, escalation route and recipients, and linked issues or remediations raised. Also record exception detail.\n2. Capture the authorized reviewer, the monitoring summary, accepted conformance results, attestation decision, next review date to record, exception register references, linked issues, owners, and due dates.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the attestation reflects the tested position, exceptions carry disposition and ownership, and declined or material positions are escalated rather than restated as conforming. The authorized reviewer accepts the monitoring record as a traceable record of the period, the next review is scheduled, and closure implies no assurance for periods or clauses not tested.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.36 — Security-policy compliance checks","itemType":"requirement","kind":"related"},{"itemTitle":"Information Security Policy","itemType":"policy","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 A.8.16 — Security telemetry monitoring","itemType":"requirement","name":"Compliance Monitoring & Attestation — ISO 27001 A.8.16 — Security telemetry monitoring — prior cycle","templateName":"Compliance Monitoring & Attestation","templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","description":"Compliance Monitoring & Attestation for ISO 27001 A.8.16 — Security telemetry monitoring (prior cycle).","status":"COMPLETED","displayOrder":43,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Refresh evidence and test continued conformance","description":null,"summary":null,"instructions":"**Objective**\nRefresh evidence and test continued conformance. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, its mapped controls and policies, the prior monitoring record, the last review date, framework version history, organizational and system changes, and the evidence expectations on record.\n2. Use the evidence expectations, control operation records and testing results, policy publication and attestation records, system configuration extracts, incident and exception logs, and prior-period evidence for comparison.\n\n**Procedure**\n1. Fix the period boundaries, confirm the mapped artifact set is still current, identify organizational, system, or framework changes since the last review, restate the evidence expected per clause, and note scope no longer applicable.\n2. Inspect evidence covering the whole period rather than a point in time, compare against prior-period evidence for drift, separate management representation from inspected support, and classify results against stated criteria rather than impression.\n\n**Record in AssureSwarm**\n1. Capture the monitoring period, clauses and artifacts in scope, evidence expectations, changes since last review, scope removed with rationale, accountable reviewer, and known evidence availability risks.\n2. Document the evidence refresh with source and date per clause, conformance result, period coverage achieved, drift observed against prior period, representations relied upon, and clauses left untested with reasons.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The period and artifact scope are current, evidence expectations are restated before collection, and changes that could break conformance are visible. Each clause result is supported by dated evidence covering the period, untested clauses are declared, and drift is recorded rather than smoothed.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.8.16 — Security telemetry monitoring","itemType":"requirement","kind":"related"},{"itemTitle":"Production Change Approval","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve attestation record","description":null,"summary":null,"instructions":"**Objective**\nApprove attestation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the conformance results and their evidence, deviation and exception detail, compensating measures, open issues and remediations, the escalation matrix, and the owner representations.\n2. Review all stage records, evidence references and their period coverage, drift observations, untested clauses, exception dispositions, attestation and its qualifications, and escalation confirmations.\n\n**Procedure**\n1. Present the tested position to the owner without softening deviations, record each exception with cause, exposure, and disposition, evaluate compensating measures on evidence, and escalate declined attestations and material deviations before advancing.\n2. Trace each conformance result to dated evidence, verify exceptions carry owners and dates, confirm escalations reached the authorized body, set the next review date against the required cadence, and return unsupported conclusions with precise comments.\n\n**Record in AssureSwarm**\n1. Record the attestation decision, attesting owner and date, each exception with cause, exposure, compensating measure and disposition, escalation route and recipients, and linked issues or remediations raised. Also record exception detail.\n2. Capture the authorized reviewer, the monitoring summary, accepted conformance results, attestation decision, next review date to record, exception register references, linked issues, owners, and due dates.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the attestation reflects the tested position, exceptions carry disposition and ownership, and declined or material positions are escalated rather than restated as conforming. The authorized reviewer accepts the monitoring record as a traceable record of the period, the next review is scheduled, and closure implies no assurance for periods or clauses not tested.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.8.16 — Security telemetry monitoring","itemType":"requirement","kind":"related"},{"itemTitle":"Production Change Approval","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"SOC 2 CC7.2 — Anomaly monitoring","itemType":"requirement","name":"Compliance Monitoring & Attestation — SOC 2 CC7.2 — Anomaly monitoring — current cycle","templateName":"Compliance Monitoring & Attestation","templateSourceId":"coworkcanvas:template:compliance-monitoring-attestation","description":"Compliance Monitoring & Attestation for SOC 2 CC7.2 — Anomaly monitoring (current cycle).","status":"ACTIVE","displayOrder":42,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Refresh evidence and test continued conformance","description":null,"summary":null,"instructions":"**Objective**\nRefresh evidence and test continued conformance. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, its mapped controls and policies, the prior monitoring record, the last review date, framework version history, organizational and system changes, and the evidence expectations on record.\n2. Use the evidence expectations, control operation records and testing results, policy publication and attestation records, system configuration extracts, incident and exception logs, and prior-period evidence for comparison.\n\n**Procedure**\n1. Fix the period boundaries, confirm the mapped artifact set is still current, identify organizational, system, or framework changes since the last review, restate the evidence expected per clause, and note scope no longer applicable.\n2. Inspect evidence covering the whole period rather than a point in time, compare against prior-period evidence for drift, separate management representation from inspected support, and classify results against stated criteria rather than impression.\n\n**Record in AssureSwarm**\n1. Capture the monitoring period, clauses and artifacts in scope, evidence expectations, changes since last review, scope removed with rationale, accountable reviewer, and known evidence availability risks.\n2. Document the evidence refresh with source and date per clause, conformance result, period coverage achieved, drift observed against prior period, representations relied upon, and clauses left untested with reasons.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The period and artifact scope are current, evidence expectations are restated before collection, and changes that could break conformance are visible. Each clause result is supported by dated evidence covering the period, untested clauses are declared, and drift is recorded rather than smoothed.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"SOC 2 CC7.2 — Anomaly monitoring","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve attestation record","description":null,"summary":null,"instructions":"**Objective**\nApprove attestation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the conformance results and their evidence, deviation and exception detail, compensating measures, open issues and remediations, the escalation matrix, and the owner representations.\n2. Review all stage records, evidence references and their period coverage, drift observations, untested clauses, exception dispositions, attestation and its qualifications, and escalation confirmations.\n\n**Procedure**\n1. Present the tested position to the owner without softening deviations, record each exception with cause, exposure, and disposition, evaluate compensating measures on evidence, and escalate declined attestations and material deviations before advancing.\n2. Trace each conformance result to dated evidence, verify exceptions carry owners and dates, confirm escalations reached the authorized body, set the next review date against the required cadence, and return unsupported conclusions with precise comments.\n\n**Record in AssureSwarm**\n1. Record the attestation decision, attesting owner and date, each exception with cause, exposure, compensating measure and disposition, escalation route and recipients, and linked issues or remediations raised. Also record exception detail.\n2. Capture the authorized reviewer, the monitoring summary, accepted conformance results, attestation decision, next review date to record, exception register references, linked issues, owners, and due dates.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the attestation reflects the tested position, exceptions carry disposition and ownership, and declined or material positions are escalated rather than restated as conforming. The authorized reviewer accepts the monitoring record as a traceable record of the period, the next review is scheduled, and closure implies no assurance for periods or clauses not tested.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"SOC 2 CC7.2 — Anomaly monitoring","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Account Reconciliation Review","itemType":"control","name":"Control Design Assessment — Account Reconciliation Review — next cycle","templateName":"Control Design Assessment","templateSourceId":"coworkcanvas:template:control-design-assessment","description":"Control Design Assessment for Account Reconciliation Review (next cycle).","status":"DRAFT","displayOrder":51,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve design-assessment conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove design-assessment conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, linked risk and requirement records, owner, frequency, system dependencies, assertions, and current narrative or procedure.\n2. Use the approved risk statement, mapped compliance requirements, process objective, financial assertion where relevant, and the scoped control statement from intake.\n3. Consider performance criteria, thresholds, review precision, source-report reliability, segregation of duties, escalation rules, evidence retention, frequency, and the expected population.\n4. Use the approved scope, criterion-level assessment, linked evidence, owner responses, and all unresolved limitations or corrective actions.\n\n**Procedure**\n1. Reconcile the control title and description to the actual activity; identify who performs and reviews it, what population it covers, when it occurs, and which risk mechanism it is intended to interrupt.\n2. Trace each material risk cause and consequence to a specific preventive or detective feature; challenge vague monitoring language, unsupported mappings, and control objectives that merely restate the risk.\n3. Evaluate each design element against the risk and frequency; inspect how exceptions are identified and resolved, how reviewer challenge is shown, and how changes in systems or personnel affect execution.\n4. Confirm that the proposed conclusion matches the evidence, distinguish design observations from execution testing, and verify that gaps and dependencies are neither omitted nor described as tested operating results.\n\nAdditional canonical requirements reviewed with this package:\nDocument Control Objective and Risk Linkage: Identify the control objective, risk addressed, authoritative policy or process, and the consequence if the control does not operate.\nAssess Control Precision: Evaluate the trigger, population, threshold, criteria, performer competence, and review precision needed to prevent or detect the identified risk.\nAssess Evidence Design: Identify the evidence produced, source system, retention period, integrity attributes, and how an independent reviewer can reperform the control.\nConfirm Owner and Frequency: Confirm the accountable owner, operator, cadence, escalation path, and separation between preparation and review are explicit and current.\nRecord Design Conclusion: Record whether the design is adequate, each gap or compensating control, and the owner and due date for required remediation.\n\n**Record in AssureSwarm**\n1. Document the in-scope control statement, assessment period, stakeholders, dependencies, and any boundary exclusions that could change the conclusion. Also record scope notes.\n2. Capture the alignment result by risk or requirement, the rationale for each mapping, gaps in coverage, and any redundant or compensating activity considered. Also record risk-response alignment.\n3. Record criterion-level observations, supporting examples, information-produced-by-entity dependencies, identified design gaps, and the basis for the provisional design result.\n4. State the conclusion, rationale, scope limitations, design improvements, owners, and target dates; link any resulting Issue or remediation record rather than burying it in narrative. Also record design assessment conclusion; follow-up actions.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The control and risk boundary are unambiguous, the accountable participants are identified, and missing source material is either obtained or logged for follow-up. Every claimed risk response is supported by a concrete control feature and any uncovered exposure is described precisely enough to assign corrective action. The design result follows from documented criteria, material gaps are separated from editorial improvements, and necessary corrective actions have accountable owners. The authorized reviewer can trace the conclusion to the recorded criteria, limitations are explicit, and all follow-up work is assigned without implying effectiveness from workflow completion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Backup Restoration Test","itemType":"control","name":"Control Design Assessment — Backup Restoration Test — current cycle","templateName":"Control Design Assessment","templateSourceId":"coworkcanvas:template:control-design-assessment","description":"Control Design Assessment for Backup Restoration Test (current cycle).","status":"ACTIVE","displayOrder":52,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve design-assessment conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove design-assessment conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, linked risk and requirement records, owner, frequency, system dependencies, assertions, and current narrative or procedure.\n2. Use the approved risk statement, mapped compliance requirements, process objective, financial assertion where relevant, and the scoped control statement from intake.\n3. Consider performance criteria, thresholds, review precision, source-report reliability, segregation of duties, escalation rules, evidence retention, frequency, and the expected population.\n4. Use the approved scope, criterion-level assessment, linked evidence, owner responses, and all unresolved limitations or corrective actions.\n\n**Procedure**\n1. Reconcile the control title and description to the actual activity; identify who performs and reviews it, what population it covers, when it occurs, and which risk mechanism it is intended to interrupt.\n2. Trace each material risk cause and consequence to a specific preventive or detective feature; challenge vague monitoring language, unsupported mappings, and control objectives that merely restate the risk.\n3. Evaluate each design element against the risk and frequency; inspect how exceptions are identified and resolved, how reviewer challenge is shown, and how changes in systems or personnel affect execution.\n4. Confirm that the proposed conclusion matches the evidence, distinguish design observations from execution testing, and verify that gaps and dependencies are neither omitted nor described as tested operating results.\n\nAdditional canonical requirements reviewed with this package:\nDocument Control Objective and Risk Linkage: Identify the control objective, risk addressed, authoritative policy or process, and the consequence if the control does not operate.\nAssess Control Precision: Evaluate the trigger, population, threshold, criteria, performer competence, and review precision needed to prevent or detect the identified risk.\nAssess Evidence Design: Identify the evidence produced, source system, retention period, integrity attributes, and how an independent reviewer can reperform the control.\nConfirm Owner and Frequency: Confirm the accountable owner, operator, cadence, escalation path, and separation between preparation and review are explicit and current.\nRecord Design Conclusion: Record whether the design is adequate, each gap or compensating control, and the owner and due date for required remediation.\n\n**Record in AssureSwarm**\n1. Document the in-scope control statement, assessment period, stakeholders, dependencies, and any boundary exclusions that could change the conclusion. Also record scope notes.\n2. Capture the alignment result by risk or requirement, the rationale for each mapping, gaps in coverage, and any redundant or compensating activity considered. Also record risk-response alignment.\n3. Record criterion-level observations, supporting examples, information-produced-by-entity dependencies, identified design gaps, and the basis for the provisional design result.\n4. State the conclusion, rationale, scope limitations, design improvements, owners, and target dates; link any resulting Issue or remediation record rather than burying it in narrative. Also record design assessment conclusion; follow-up actions.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The control and risk boundary are unambiguous, the accountable participants are identified, and missing source material is either obtained or logged for follow-up. Every claimed risk response is supported by a concrete control feature and any uncovered exposure is described precisely enough to assign corrective action. The design result follows from documented criteria, material gaps are separated from editorial improvements, and necessary corrective actions have accountable owners. The authorized reviewer can trace the conclusion to the recorded criteria, limitations are explicit, and all follow-up work is assigned without implying effectiveness from workflow completion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Batch Processing Monitoring","itemType":"control","name":"Control Design Assessment — Batch Processing Monitoring — prior cycle","templateName":"Control Design Assessment","templateSourceId":"coworkcanvas:template:control-design-assessment","description":"Control Design Assessment for Batch Processing Monitoring (prior cycle).","status":"COMPLETED","displayOrder":53,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve design-assessment conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove design-assessment conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, linked risk and requirement records, owner, frequency, system dependencies, assertions, and current narrative or procedure.\n2. Use the approved risk statement, mapped compliance requirements, process objective, financial assertion where relevant, and the scoped control statement from intake.\n3. Consider performance criteria, thresholds, review precision, source-report reliability, segregation of duties, escalation rules, evidence retention, frequency, and the expected population.\n4. Use the approved scope, criterion-level assessment, linked evidence, owner responses, and all unresolved limitations or corrective actions.\n\n**Procedure**\n1. Reconcile the control title and description to the actual activity; identify who performs and reviews it, what population it covers, when it occurs, and which risk mechanism it is intended to interrupt.\n2. Trace each material risk cause and consequence to a specific preventive or detective feature; challenge vague monitoring language, unsupported mappings, and control objectives that merely restate the risk.\n3. Evaluate each design element against the risk and frequency; inspect how exceptions are identified and resolved, how reviewer challenge is shown, and how changes in systems or personnel affect execution.\n4. Confirm that the proposed conclusion matches the evidence, distinguish design observations from execution testing, and verify that gaps and dependencies are neither omitted nor described as tested operating results.\n\nAdditional canonical requirements reviewed with this package:\nDocument Control Objective and Risk Linkage: Identify the control objective, risk addressed, authoritative policy or process, and the consequence if the control does not operate.\nAssess Control Precision: Evaluate the trigger, population, threshold, criteria, performer competence, and review precision needed to prevent or detect the identified risk.\nAssess Evidence Design: Identify the evidence produced, source system, retention period, integrity attributes, and how an independent reviewer can reperform the control.\nConfirm Owner and Frequency: Confirm the accountable owner, operator, cadence, escalation path, and separation between preparation and review are explicit and current.\nRecord Design Conclusion: Record whether the design is adequate, each gap or compensating control, and the owner and due date for required remediation.\n\n**Record in AssureSwarm**\n1. Document the in-scope control statement, assessment period, stakeholders, dependencies, and any boundary exclusions that could change the conclusion. Also record scope notes.\n2. Capture the alignment result by risk or requirement, the rationale for each mapping, gaps in coverage, and any redundant or compensating activity considered. Also record risk-response alignment.\n3. Record criterion-level observations, supporting examples, information-produced-by-entity dependencies, identified design gaps, and the basis for the provisional design result.\n4. State the conclusion, rationale, scope limitations, design improvements, owners, and target dates; link any resulting Issue or remediation record rather than burying it in narrative. Also record design assessment conclusion; follow-up actions.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The control and risk boundary are unambiguous, the accountable participants are identified, and missing source material is either obtained or logged for follow-up. Every claimed risk response is supported by a concrete control feature and any uncovered exposure is described precisely enough to assign corrective action. The design result follows from documented criteria, material gaps are separated from editorial improvements, and necessary corrective actions have accountable owners. The authorized reviewer can trace the conclusion to the recorded criteria, limitations are explicit, and all follow-up work is assigned without implying effectiveness from workflow completion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Batch Processing Monitoring","itemType":"control","kind":"related"},{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Backup Restoration Test","itemType":"control","name":"Control Exception Evaluation & Remediation — Backup Restoration Test — next cycle","templateName":"Control Exception Evaluation & Remediation","templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","description":"Control Exception Evaluation & Remediation for Backup Restoration Test (next cycle).","status":"DRAFT","displayOrder":61,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Evaluate impact and disposition","description":null,"summary":null,"instructions":"**Objective**\nEvaluate impact and disposition. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved testing matrix, failed attribute and supporting evidence, tester notes and owner response, existing Issue records, comparable occurrences, population data, system changes and the relevant policy or procedure.\n2. Use the validated facts, extent analysis, risk and requirement mappings, prior exceptions, compensating-control evidence, relevant program criteria, and management response.\n\n**Procedure**\n1. Restate the observed condition factually, verify the evidence reference, distinguish a control deviation from a testing or documentation error, and search for related exceptions before opening anything new. Then reperform the failed attribute, challenge alternative explanations, inspect additional occurrences when warranted, determine the condition window, and identify whether the same cause could affect untested items.\n2. Assess likelihood and consequence without conflating sample rate with population impact, validate claimed compensating controls, consider aggregation with related conditions, and select a disposition supported by evidence.\n\n**Record in AssureSwarm**\n1. Capture the source test, item identifiers, attribute, expected and observed condition, duplicate check and initial owner response, then the validation steps, corroborating evidence, additional items reviewed, confirmed facts, affected period and population, rejected explanations and the validation result. Also record exception reference; exception summary.\n2. Record the impact factors, compensating activity, aggregation analysis, rationale, disposition, affected risks or assertions, escalation needs, and links to any formal Issue.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The exception is reproducible from source work and described without premature severity language, the condition is confirmed or closed with a supported reason, potential extent is bounded, and open information requests have owners and due dates. The disposition is approved and traceable to stated criteria, unsupported mitigation claims are excluded, and conditions requiring action advance to an accountable remediation plan.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve exception evaluation","description":null,"summary":null,"instructions":"**Objective**\nApprove exception evaluation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the confirmed condition, root-cause analysis, impact disposition, owner proposal, change constraints, affected procedures and systems, and required reporting dates.\n2. Review intake, validation, extent and impact analyses, disposition approval, linked Issue and remediation records, monitoring commitments, and remaining limitations.\n\n**Procedure**\n1. Challenge whether proposed actions address cause rather than symptoms, define measurable completion evidence, establish interim safeguards, set realistic milestones, and design retesting independent of self-certified completion.\n2. Confirm the narrative is internally consistent, all evidence references resolve, the disposition matches the analysis, duplicate records are avoided, and required escalation or reporting has occurred.\n\nAdditional canonical requirements reviewed with this package:\nClassify Control Exception: Record the failed control attribute, occurrence, evidence, preliminary cause, and whether the exception is isolated, systemic, or suspected fraud.\nAssess Scope and Impact: Determine affected population, systems, data, customers, financial or compliance impact, and whether expanded testing or escalation is required.\nDetermine Deficiency Severity: Apply the documented severity criteria, identify compensating controls, and state the rationale for the assigned deficiency level.\nAssign Corrective Action: Define corrective action, accountable owner, target date, validation evidence, and interim safeguard while remediation remains open.\nRecord Containment Decision and Approval: Approve the containment plan, escalation path, and acceptance decision; do not close this record without a documented owner and due date.\n\n**Record in AssureSwarm**\n1. Create or link the remediation record and capture owner, actions, milestones, target date, interim measures, completion evidence, validator, retest population, and escalation threshold. Also record planned validation method.\n2. State the approved evaluation conclusion, rationale, open actions, owners, dates, linked records, and the event that will trigger retest, monitoring review, or final closure.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: The plan addresses the documented cause, responsibilities and dates are accepted, validation is executable, and any risk acceptance follows the proper approval route. The authorized reviewer accepts the evaluation and handoff, every open action lives in a trackable record, and this workflow does not imply remediation is effective or closed before validation.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Journal Entry Approval","itemType":"control","name":"Control Exception Evaluation & Remediation — Journal Entry Approval — current cycle","templateName":"Control Exception Evaluation & Remediation","templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","description":"Control Exception Evaluation & Remediation for Journal Entry Approval (current cycle).","status":"ACTIVE","displayOrder":62,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Evaluate impact and disposition","description":null,"summary":null,"instructions":"**Objective**\nEvaluate impact and disposition. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved testing matrix, failed attribute and supporting evidence, tester notes and owner response, existing Issue records, comparable occurrences, population data, system changes and the relevant policy or procedure.\n2. Use the validated facts, extent analysis, risk and requirement mappings, prior exceptions, compensating-control evidence, relevant program criteria, and management response.\n\n**Procedure**\n1. Restate the observed condition factually, verify the evidence reference, distinguish a control deviation from a testing or documentation error, and search for related exceptions before opening anything new. Then reperform the failed attribute, challenge alternative explanations, inspect additional occurrences when warranted, determine the condition window, and identify whether the same cause could affect untested items.\n2. Assess likelihood and consequence without conflating sample rate with population impact, validate claimed compensating controls, consider aggregation with related conditions, and select a disposition supported by evidence.\n\n**Record in AssureSwarm**\n1. Capture the source test, item identifiers, attribute, expected and observed condition, duplicate check and initial owner response, then the validation steps, corroborating evidence, additional items reviewed, confirmed facts, affected period and population, rejected explanations and the validation result. Also record exception reference; exception summary.\n2. Record the impact factors, compensating activity, aggregation analysis, rationale, disposition, affected risks or assertions, escalation needs, and links to any formal Issue.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The exception is reproducible from source work and described without premature severity language, the condition is confirmed or closed with a supported reason, potential extent is bounded, and open information requests have owners and due dates. The disposition is approved and traceable to stated criteria, unsupported mitigation claims are excluded, and conditions requiring action advance to an accountable remediation plan.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Journal Entry Approval","itemType":"control","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve exception evaluation","description":null,"summary":null,"instructions":"**Objective**\nApprove exception evaluation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the confirmed condition, root-cause analysis, impact disposition, owner proposal, change constraints, affected procedures and systems, and required reporting dates.\n2. Review intake, validation, extent and impact analyses, disposition approval, linked Issue and remediation records, monitoring commitments, and remaining limitations.\n\n**Procedure**\n1. Challenge whether proposed actions address cause rather than symptoms, define measurable completion evidence, establish interim safeguards, set realistic milestones, and design retesting independent of self-certified completion.\n2. Confirm the narrative is internally consistent, all evidence references resolve, the disposition matches the analysis, duplicate records are avoided, and required escalation or reporting has occurred.\n\nAdditional canonical requirements reviewed with this package:\nClassify Control Exception: Record the failed control attribute, occurrence, evidence, preliminary cause, and whether the exception is isolated, systemic, or suspected fraud.\nAssess Scope and Impact: Determine affected population, systems, data, customers, financial or compliance impact, and whether expanded testing or escalation is required.\nDetermine Deficiency Severity: Apply the documented severity criteria, identify compensating controls, and state the rationale for the assigned deficiency level.\nAssign Corrective Action: Define corrective action, accountable owner, target date, validation evidence, and interim safeguard while remediation remains open.\nRecord Containment Decision and Approval: Approve the containment plan, escalation path, and acceptance decision; do not close this record without a documented owner and due date.\n\n**Record in AssureSwarm**\n1. Create or link the remediation record and capture owner, actions, milestones, target date, interim measures, completion evidence, validator, retest population, and escalation threshold. Also record planned validation method.\n2. State the approved evaluation conclusion, rationale, open actions, owners, dates, linked records, and the event that will trigger retest, monitoring review, or final closure.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: The plan addresses the documented cause, responsibilities and dates are accepted, validation is executable, and any risk acceptance follows the proper approval route. The authorized reviewer accepts the evaluation and handoff, every open action lives in a trackable record, and this workflow does not imply remediation is effective or closed before validation.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Journal Entry Approval","itemType":"control","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Production Change Approval","itemType":"control","name":"Control Exception Evaluation & Remediation — Production Change Approval — prior cycle","templateName":"Control Exception Evaluation & Remediation","templateSourceId":"coworkcanvas:template:control-exception-evaluation-remediation","description":"Control Exception Evaluation & Remediation for Production Change Approval (prior cycle).","status":"COMPLETED","displayOrder":63,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Evaluate impact and disposition","description":null,"summary":null,"instructions":"**Objective**\nEvaluate impact and disposition. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved testing matrix, failed attribute and supporting evidence, tester notes and owner response, existing Issue records, comparable occurrences, population data, system changes and the relevant policy or procedure.\n2. Use the validated facts, extent analysis, risk and requirement mappings, prior exceptions, compensating-control evidence, relevant program criteria, and management response.\n\n**Procedure**\n1. Restate the observed condition factually, verify the evidence reference, distinguish a control deviation from a testing or documentation error, and search for related exceptions before opening anything new. Then reperform the failed attribute, challenge alternative explanations, inspect additional occurrences when warranted, determine the condition window, and identify whether the same cause could affect untested items.\n2. Assess likelihood and consequence without conflating sample rate with population impact, validate claimed compensating controls, consider aggregation with related conditions, and select a disposition supported by evidence.\n\n**Record in AssureSwarm**\n1. Capture the source test, item identifiers, attribute, expected and observed condition, duplicate check and initial owner response, then the validation steps, corroborating evidence, additional items reviewed, confirmed facts, affected period and population, rejected explanations and the validation result. Also record exception reference; exception summary.\n2. Record the impact factors, compensating activity, aggregation analysis, rationale, disposition, affected risks or assertions, escalation needs, and links to any formal Issue.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The exception is reproducible from source work and described without premature severity language, the condition is confirmed or closed with a supported reason, potential extent is bounded, and open information requests have owners and due dates. The disposition is approved and traceable to stated criteria, unsupported mitigation claims are excluded, and conditions requiring action advance to an accountable remediation plan.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Production Change Approval","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve exception evaluation","description":null,"summary":null,"instructions":"**Objective**\nApprove exception evaluation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the confirmed condition, root-cause analysis, impact disposition, owner proposal, change constraints, affected procedures and systems, and required reporting dates.\n2. Review intake, validation, extent and impact analyses, disposition approval, linked Issue and remediation records, monitoring commitments, and remaining limitations.\n\n**Procedure**\n1. Challenge whether proposed actions address cause rather than symptoms, define measurable completion evidence, establish interim safeguards, set realistic milestones, and design retesting independent of self-certified completion.\n2. Confirm the narrative is internally consistent, all evidence references resolve, the disposition matches the analysis, duplicate records are avoided, and required escalation or reporting has occurred.\n\nAdditional canonical requirements reviewed with this package:\nClassify Control Exception: Record the failed control attribute, occurrence, evidence, preliminary cause, and whether the exception is isolated, systemic, or suspected fraud.\nAssess Scope and Impact: Determine affected population, systems, data, customers, financial or compliance impact, and whether expanded testing or escalation is required.\nDetermine Deficiency Severity: Apply the documented severity criteria, identify compensating controls, and state the rationale for the assigned deficiency level.\nAssign Corrective Action: Define corrective action, accountable owner, target date, validation evidence, and interim safeguard while remediation remains open.\nRecord Containment Decision and Approval: Approve the containment plan, escalation path, and acceptance decision; do not close this record without a documented owner and due date.\n\n**Record in AssureSwarm**\n1. Create or link the remediation record and capture owner, actions, milestones, target date, interim measures, completion evidence, validator, retest population, and escalation threshold. Also record planned validation method.\n2. State the approved evaluation conclusion, rationale, open actions, owners, dates, linked records, and the event that will trigger retest, monitoring review, or final closure.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: The plan addresses the documented cause, responsibilities and dates are accepted, validation is executable, and any risk acceptance follows the proper approval route. The authorized reviewer accepts the evaluation and handoff, every open action lives in a trackable record, and this workflow does not imply remediation is effective or closed before validation.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Production Change Approval","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Joiner Mover Leaver Automation","itemType":"control","name":"Interim Operating Effectiveness Testing — Joiner Mover Leaver Automation — next cycle","templateName":"Interim Operating Effectiveness Testing","templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","description":"Interim Operating Effectiveness Testing for Joiner Mover Leaver Automation (next cycle).","status":"DRAFT","displayOrder":71,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Validate the population and select the sample","description":null,"summary":null,"instructions":"**Objective**\nValidate the population and select the sample. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current control design, walkthrough, population source, risk and assertion mapping, prior results, changes, and the program-specific sampling methodology.\n2. Use the native system extract, report logic and parameters, control frequency, period calendar, sequence counts, reconciliations, owner certification and source totals, together with the sampling guidance, random seed or interval, required sample size and high-risk strata.\n\n**Procedure**\n1. Confirm the control was in scope and available throughout the period, identify excluded intervals or implementations, set the test attributes, and obtain approval for any planned reliance on prior work.\n2. Inspect report parameters, reconcile counts and key totals, test sequence or date coverage, identify duplicates and omissions, and assess whether manual additions changed the source population. Then execute the selection once, preserve the method and seed, distinguish random from targeted selections, and investigate unavailable items rather than silently replacing them.\n\n**Record in AssureSwarm**\n1. Document the period, objective, frequency, population owner, expected evidence, attributes, scope exclusions, and the source of the sampling approach. Also record interim period; test objective.\n2. Retain the original population, extraction evidence, parameter screenshots, reconciliations, final count and the rationale for accepting it, then the sample listing with stable identifiers, selection method, seed or interval, strata and replacement rationale, linked back to the frozen population. Also record population validation; sample size.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The approved plan states what will be tested and what it cannot demonstrate, all period gaps are visible, and the population request is reproducible. The population can be reproduced and tied to an authoritative source, every selected item traces to it, the method can be re-created, substitutions are justified, and the sample is ready for attribute testing.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Joiner Mover Leaver Automation","itemType":"control","kind":"related"},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve interim test conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove interim test conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the frozen sample, attribute definitions, expected evidence, source documents, system records, approvals, reviewer annotations, and approved handling for unavailable evidence.\n2. Review the test plan, population validation, selection record, per-item results, exception responses, scope limitations, control changes, and the untested portion of the year.\n\n**Procedure**\n1. Apply attributes consistently, retain per-item support, distinguish control failure from documentation deficiency, corroborate dates and authority, and obtain owner responses without changing the original tester result.\n2. Recalculate result counts, assess whether exceptions require separate evaluation, identify unresolved evidence gaps, and design a roll-forward plan proportionate to elapsed time, frequency, risk, and change.\n\n**Record in AssureSwarm**\n1. Complete the item-by-attribute matrix, reference evidence files, record exceptions and explanations, identify missing support, and summarize counts without obscuring individual results. Also record items with exceptions.\n2. State the interim conclusion and basis, exceptions and limitations, affected assertions or risks, planned roll-forward procedures, owners, timing, and links to issue or remediation records. Also record period-end roll-forward plan.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: Every sample and attribute has a supported disposition, exceptions are reproducible and owner responses are retained separately, and the matrix reconciles to the sample. The authorized reviewer can trace the bounded conclusion to the work, remaining period-end procedures are explicit, and completion is not described as proof beyond the tested interim period.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Joiner Mover Leaver Automation","itemType":"control","kind":"related"},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Production Change Approval","itemType":"control","name":"Interim Operating Effectiveness Testing — Production Change Approval — current cycle","templateName":"Interim Operating Effectiveness Testing","templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","description":"Interim Operating Effectiveness Testing for Production Change Approval (current cycle).","status":"ACTIVE","displayOrder":72,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Validate the population and select the sample","description":null,"summary":null,"instructions":"**Objective**\nValidate the population and select the sample. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current control design, walkthrough, population source, risk and assertion mapping, prior results, changes, and the program-specific sampling methodology.\n2. Use the native system extract, report logic and parameters, control frequency, period calendar, sequence counts, reconciliations, owner certification and source totals, together with the sampling guidance, random seed or interval, required sample size and high-risk strata.\n\n**Procedure**\n1. Confirm the control was in scope and available throughout the period, identify excluded intervals or implementations, set the test attributes, and obtain approval for any planned reliance on prior work.\n2. Inspect report parameters, reconcile counts and key totals, test sequence or date coverage, identify duplicates and omissions, and assess whether manual additions changed the source population. Then execute the selection once, preserve the method and seed, distinguish random from targeted selections, and investigate unavailable items rather than silently replacing them.\n\n**Record in AssureSwarm**\n1. Document the period, objective, frequency, population owner, expected evidence, attributes, scope exclusions, and the source of the sampling approach. Also record interim period; test objective.\n2. Retain the original population, extraction evidence, parameter screenshots, reconciliations, final count and the rationale for accepting it, then the sample listing with stable identifiers, selection method, seed or interval, strata and replacement rationale, linked back to the frozen population. Also record population validation; sample size.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The approved plan states what will be tested and what it cannot demonstrate, all period gaps are visible, and the population request is reproducible. The population can be reproduced and tied to an authoritative source, every selected item traces to it, the method can be re-created, substitutions are justified, and the sample is ready for attribute testing.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Production Change Approval","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve interim test conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove interim test conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the frozen sample, attribute definitions, expected evidence, source documents, system records, approvals, reviewer annotations, and approved handling for unavailable evidence.\n2. Review the test plan, population validation, selection record, per-item results, exception responses, scope limitations, control changes, and the untested portion of the year.\n\n**Procedure**\n1. Apply attributes consistently, retain per-item support, distinguish control failure from documentation deficiency, corroborate dates and authority, and obtain owner responses without changing the original tester result.\n2. Recalculate result counts, assess whether exceptions require separate evaluation, identify unresolved evidence gaps, and design a roll-forward plan proportionate to elapsed time, frequency, risk, and change.\n\n**Record in AssureSwarm**\n1. Complete the item-by-attribute matrix, reference evidence files, record exceptions and explanations, identify missing support, and summarize counts without obscuring individual results. Also record items with exceptions.\n2. State the interim conclusion and basis, exceptions and limitations, affected assertions or risks, planned roll-forward procedures, owners, timing, and links to issue or remediation records. Also record period-end roll-forward plan.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: Every sample and attribute has a supported disposition, exceptions are reproducible and owner responses are retained separately, and the matrix reconciles to the sample. The authorized reviewer can trace the bounded conclusion to the work, remaining period-end procedures are explicit, and completion is not described as proof beyond the tested interim period.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Production Change Approval","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Quarterly Access Recertification","itemType":"control","name":"Interim Operating Effectiveness Testing — Quarterly Access Recertification — prior cycle","templateName":"Interim Operating Effectiveness Testing","templateSourceId":"coworkcanvas:template:control-interim-operating-effectiveness","description":"Interim Operating Effectiveness Testing for Quarterly Access Recertification (prior cycle).","status":"COMPLETED","displayOrder":73,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Validate the population and select the sample","description":null,"summary":null,"instructions":"**Objective**\nValidate the population and select the sample. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current control design, walkthrough, population source, risk and assertion mapping, prior results, changes, and the program-specific sampling methodology.\n2. Use the native system extract, report logic and parameters, control frequency, period calendar, sequence counts, reconciliations, owner certification and source totals, together with the sampling guidance, random seed or interval, required sample size and high-risk strata.\n\n**Procedure**\n1. Confirm the control was in scope and available throughout the period, identify excluded intervals or implementations, set the test attributes, and obtain approval for any planned reliance on prior work.\n2. Inspect report parameters, reconcile counts and key totals, test sequence or date coverage, identify duplicates and omissions, and assess whether manual additions changed the source population. Then execute the selection once, preserve the method and seed, distinguish random from targeted selections, and investigate unavailable items rather than silently replacing them.\n\n**Record in AssureSwarm**\n1. Document the period, objective, frequency, population owner, expected evidence, attributes, scope exclusions, and the source of the sampling approach. Also record interim period; test objective.\n2. Retain the original population, extraction evidence, parameter screenshots, reconciliations, final count and the rationale for accepting it, then the sample listing with stable identifiers, selection method, seed or interval, strata and replacement rationale, linked back to the frozen population. Also record population validation; sample size.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The approved plan states what will be tested and what it cannot demonstrate, all period gaps are visible, and the population request is reproducible. The population can be reproduced and tied to an authoritative source, every selected item traces to it, the method can be re-created, substitutions are justified, and the sample is ready for attribute testing.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Quarterly Access Recertification","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve interim test conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove interim test conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the frozen sample, attribute definitions, expected evidence, source documents, system records, approvals, reviewer annotations, and approved handling for unavailable evidence.\n2. Review the test plan, population validation, selection record, per-item results, exception responses, scope limitations, control changes, and the untested portion of the year.\n\n**Procedure**\n1. Apply attributes consistently, retain per-item support, distinguish control failure from documentation deficiency, corroborate dates and authority, and obtain owner responses without changing the original tester result.\n2. Recalculate result counts, assess whether exceptions require separate evaluation, identify unresolved evidence gaps, and design a roll-forward plan proportionate to elapsed time, frequency, risk, and change.\n\n**Record in AssureSwarm**\n1. Complete the item-by-attribute matrix, reference evidence files, record exceptions and explanations, identify missing support, and summarize counts without obscuring individual results. Also record items with exceptions.\n2. State the interim conclusion and basis, exceptions and limitations, affected assertions or risks, planned roll-forward procedures, owners, timing, and links to issue or remediation records. Also record period-end roll-forward plan.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: Every sample and attribute has a supported disposition, exceptions are reproducible and owner responses are retained separately, and the matrix reconciles to the sample. The authorized reviewer can trace the bounded conclusion to the work, remaining period-end procedures are explicit, and completion is not described as proof beyond the tested interim period.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Quarterly Access Recertification","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"EUC Formula Validation","itemType":"control","name":"Period-End Roll-Forward / Rollover Testing — EUC Formula Validation — next cycle","templateName":"Period-End Roll-Forward / Rollover Testing","templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","description":"Period-End Roll-Forward / Rollover Testing for EUC Formula Validation (next cycle).","status":"DRAFT","displayOrder":81,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess changes since interim","description":null,"summary":null,"instructions":"**Objective**\nAssess changes since interim. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Obtain the approved interim workpaper, tested population and result, remaining-period calendar, control frequency, open exceptions, changes, and period-end reporting deadline.\n2. Use change tickets, release logs, organization changes, updated narratives, incident records, exception logs, owner inquiry, configuration evidence, and current risk assessments.\n\n**Procedure**\n1. Verify the interim work is final and applicable to the same control, reconcile the untested interval and expected occurrences, and identify limitations that require new testing rather than roll-forward reliance.\n2. Compare each relevant control element to the interim state, corroborate inquiry with records, evaluate the effective date and affected occurrences, and decide whether targeted bridge work or full retesting is necessary.\n\n**Record in AssureSwarm**\n1. Record the interim reference, cutoff dates, remaining occurrences, applicable assertions, unresolved items, planned bridge method, and rationale for the selected approach. Also record bridge period; approved interim work reference.\n2. Document each change considered, evidence reviewed, timing, impact on design and prior results, decision, and the additional procedure required to address it. Also record change assessment.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The bridge period and reliance basis are precise, the expected remaining population is quantified, and ineligible prior work is excluded before further procedures. The change assessment is supported rather than inquiry-only, material changes are reflected in the test plan, and the approved bridge approach remains defensible.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"EUC Formula Validation","itemType":"control","kind":"related"},{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve period-end conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove period-end conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the native remaining-period extract, frequency calendar, sequence records and period-end close schedule, together with the approved change assessment, selection plan, control attributes, period-end evidence, interim exceptions and any targeted high-risk items.\n2. Review interim conclusions, change assessment, remaining-population reconciliation, incremental results, exception evaluations, scope limitations, and period-end evidence.\n\n**Procedure**\n1. Reconcile the first and last occurrence, inspect gaps and duplicates, identify period-end and nonroutine events, and separate out-of-scope records with reasons. Then test selected occurrences consistently with interim attributes, perform additional procedures for changes, revisit unresolved exceptions, and retain per-item conclusions and reviewer challenge.\n2. Confirm the bridge covers the full remaining interval, reconcile results and exceptions, challenge reliance where changes occurred, and identify any additional work before recording the bounded conclusion.\n\n**Record in AssureSwarm**\n1. Retain the source population, count reconciliation, identified special items and excluded records, and the final population used for selection; then complete the incremental results matrix with evidence references, change-specific procedures, exception status and tested counts reconciled to that population. Also record remaining occurrences; incremental exceptions.\n2. Document the result, basis, interim and incremental references, changes, exceptions, limitations, affected risks, and links to issue or remediation follow-up. Also record roll-forward conclusion; conclusion basis.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: The remaining population bridges exactly from interim to period end, all planned bridge procedures are complete, results reconcile to selected items, exceptions are evaluated or routed, and no unsupported gap remains. The authorized reviewer can trace the period-end result across both work periods, exceptions and limitations remain visible, and completion does not substitute for the recorded evidence-based conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"EUC Formula Validation","itemType":"control","kind":"related"},{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Job Failure Escalation","itemType":"control","name":"Period-End Roll-Forward / Rollover Testing — Job Failure Escalation — current cycle","templateName":"Period-End Roll-Forward / Rollover Testing","templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","description":"Period-End Roll-Forward / Rollover Testing for Job Failure Escalation (current cycle).","status":"ACTIVE","displayOrder":82,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess changes since interim","description":null,"summary":null,"instructions":"**Objective**\nAssess changes since interim. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Obtain the approved interim workpaper, tested population and result, remaining-period calendar, control frequency, open exceptions, changes, and period-end reporting deadline.\n2. Use change tickets, release logs, organization changes, updated narratives, incident records, exception logs, owner inquiry, configuration evidence, and current risk assessments.\n\n**Procedure**\n1. Verify the interim work is final and applicable to the same control, reconcile the untested interval and expected occurrences, and identify limitations that require new testing rather than roll-forward reliance.\n2. Compare each relevant control element to the interim state, corroborate inquiry with records, evaluate the effective date and affected occurrences, and decide whether targeted bridge work or full retesting is necessary.\n\n**Record in AssureSwarm**\n1. Record the interim reference, cutoff dates, remaining occurrences, applicable assertions, unresolved items, planned bridge method, and rationale for the selected approach. Also record bridge period; approved interim work reference.\n2. Document each change considered, evidence reviewed, timing, impact on design and prior results, decision, and the additional procedure required to address it. Also record change assessment.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The bridge period and reliance basis are precise, the expected remaining population is quantified, and ineligible prior work is excluded before further procedures. The change assessment is supported rather than inquiry-only, material changes are reflected in the test plan, and the approved bridge approach remains defensible.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Job Failure Escalation","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve period-end conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove period-end conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the native remaining-period extract, frequency calendar, sequence records and period-end close schedule, together with the approved change assessment, selection plan, control attributes, period-end evidence, interim exceptions and any targeted high-risk items.\n2. Review interim conclusions, change assessment, remaining-population reconciliation, incremental results, exception evaluations, scope limitations, and period-end evidence.\n\n**Procedure**\n1. Reconcile the first and last occurrence, inspect gaps and duplicates, identify period-end and nonroutine events, and separate out-of-scope records with reasons. Then test selected occurrences consistently with interim attributes, perform additional procedures for changes, revisit unresolved exceptions, and retain per-item conclusions and reviewer challenge.\n2. Confirm the bridge covers the full remaining interval, reconcile results and exceptions, challenge reliance where changes occurred, and identify any additional work before recording the bounded conclusion.\n\n**Record in AssureSwarm**\n1. Retain the source population, count reconciliation, identified special items and excluded records, and the final population used for selection; then complete the incremental results matrix with evidence references, change-specific procedures, exception status and tested counts reconciled to that population. Also record remaining occurrences; incremental exceptions.\n2. Document the result, basis, interim and incremental references, changes, exceptions, limitations, affected risks, and links to issue or remediation follow-up. Also record roll-forward conclusion; conclusion basis.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: The remaining population bridges exactly from interim to period end, all planned bridge procedures are complete, results reconcile to selected items, exceptions are evaluated or routed, and no unsupported gap remains. The authorized reviewer can trace the period-end result across both work periods, exceptions and limitations remain visible, and completion does not substitute for the recorded evidence-based conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Job Failure Escalation","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Privileged Access Approval","itemType":"control","name":"Period-End Roll-Forward / Rollover Testing — Privileged Access Approval — prior cycle","templateName":"Period-End Roll-Forward / Rollover Testing","templateSourceId":"coworkcanvas:template:control-period-end-roll-forward","description":"Period-End Roll-Forward / Rollover Testing for Privileged Access Approval (prior cycle).","status":"COMPLETED","displayOrder":83,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess changes since interim","description":null,"summary":null,"instructions":"**Objective**\nAssess changes since interim. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Obtain the approved interim workpaper, tested population and result, remaining-period calendar, control frequency, open exceptions, changes, and period-end reporting deadline.\n2. Use change tickets, release logs, organization changes, updated narratives, incident records, exception logs, owner inquiry, configuration evidence, and current risk assessments.\n\n**Procedure**\n1. Verify the interim work is final and applicable to the same control, reconcile the untested interval and expected occurrences, and identify limitations that require new testing rather than roll-forward reliance.\n2. Compare each relevant control element to the interim state, corroborate inquiry with records, evaluate the effective date and affected occurrences, and decide whether targeted bridge work or full retesting is necessary.\n\n**Record in AssureSwarm**\n1. Record the interim reference, cutoff dates, remaining occurrences, applicable assertions, unresolved items, planned bridge method, and rationale for the selected approach. Also record bridge period; approved interim work reference.\n2. Document each change considered, evidence reviewed, timing, impact on design and prior results, decision, and the additional procedure required to address it. Also record change assessment.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The bridge period and reliance basis are precise, the expected remaining population is quantified, and ineligible prior work is excluded before further procedures. The change assessment is supported rather than inquiry-only, material changes are reflected in the test plan, and the approved bridge approach remains defensible.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Privileged Access Approval","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve period-end conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove period-end conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the native remaining-period extract, frequency calendar, sequence records and period-end close schedule, together with the approved change assessment, selection plan, control attributes, period-end evidence, interim exceptions and any targeted high-risk items.\n2. Review interim conclusions, change assessment, remaining-population reconciliation, incremental results, exception evaluations, scope limitations, and period-end evidence.\n\n**Procedure**\n1. Reconcile the first and last occurrence, inspect gaps and duplicates, identify period-end and nonroutine events, and separate out-of-scope records with reasons. Then test selected occurrences consistently with interim attributes, perform additional procedures for changes, revisit unresolved exceptions, and retain per-item conclusions and reviewer challenge.\n2. Confirm the bridge covers the full remaining interval, reconcile results and exceptions, challenge reliance where changes occurred, and identify any additional work before recording the bounded conclusion.\n\n**Record in AssureSwarm**\n1. Retain the source population, count reconciliation, identified special items and excluded records, and the final population used for selection; then complete the incremental results matrix with evidence references, change-specific procedures, exception status and tested counts reconciled to that population. Also record remaining occurrences; incremental exceptions.\n2. Document the result, basis, interim and incremental references, changes, exceptions, limitations, affected risks, and links to issue or remediation follow-up. Also record roll-forward conclusion; conclusion basis.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: The remaining population bridges exactly from interim to period end, all planned bridge procedures are complete, results reconcile to selected items, exceptions are evaluated or routed, and no unsupported gap remains. The authorized reviewer can trace the period-end result across both work periods, exceptions and limitations remain visible, and completion does not substitute for the recorded evidence-based conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Privileged Access Approval","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Physical Site Access Review","itemType":"control","name":"Control Remediation Retest & Closure — Physical Site Access Review — next cycle","templateName":"Control Remediation Retest & Closure","templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","description":"Control Remediation Retest & Closure for Physical Site Access Review (next cycle).","status":"DRAFT","displayOrder":91,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm readiness and approve the independent retest plan","description":null,"summary":null,"instructions":"**Objective**\nConfirm readiness and approve the independent retest plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved remediation plan and its completion evidence, change tickets, updated control description, owner certification and expected post-change occurrences, with the original exception, impact evaluation, updated attributes and independence requirements.\n\n**Procedure**\n1. Inspect implementation evidence rather than accepting status, compare delivered actions to the plan, verify effective dates and scope, and quantify occurrences since implementation. Then set the period, population, sample or full-inspection method, attributes, evidence expectations, recurrence criteria, tester independence and treatment of transitional items.\n\n**Record in AssureSwarm**\n1. Document each action with its evidence reference and implementation date, deviations from plan, the available population and the readiness decision, then the approved scope, tester, population source, sample basis, attributes, change-specific procedures, success criteria and exclusions. Also record readiness result; retest period; retest method.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The remediation is demonstrably implemented or returned with precise gaps, enough post-change activity exists for the chosen method, the plan directly tests the remediated cause, independence is documented, and success criteria are set before execution.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Physical Site Access Review","itemType":"control","kind":"related"},{"itemTitle":"ISO 27001 Certification Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve remediation closure","description":null,"summary":null,"instructions":"**Objective**\nApprove remediation closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the frozen post-change population, approved selection, updated control criteria, implementation evidence, source records, system logs, approvals, and original failure pattern.\n2. Review the approved plan, item-level results, new exceptions, original root cause, implementation timeline, monitoring evidence, control frequency, and owner accountability.\n3. Use all remediation milestones, retest work, exception results, evaluation, monitoring commitments, Issue status, owner response, and required governance approvals.\n\n**Procedure**\n1. Test each item consistently, retain evidence for all attributes, compare results to the original condition, investigate anomalies and unavailable support, and keep management explanations separate from tester results.\n2. Reconcile counts, assess any recurrence or new failure mode, consider whether the observation period is representative, verify sustainable ownership and monitoring, and decide whether added work is necessary.\n3. Confirm closure criteria are met, link the exact evidence supporting each criterion, verify related records are consistent, and return or reopen the matter when limitations or recurrence prevent closure.\n\nAdditional canonical requirements reviewed with this package:\nVerify Remediation Implementation: Verify the approved corrective action is implemented as designed, including configuration, procedure, owner, and retained implementation evidence.\nSelect Post-Remediation Sample: Define the post-remediation population and select a sample that covers the corrected control operation and relevant risk scenarios.\nReperform Failed Attributes: Independently reperform the attributes that failed, comparing evidence and timing to the corrected design rather than relying on management assertion.\nAssess Recurrence Risk: Assess whether the root cause can recur, whether related controls require testing, and whether compensating controls remain necessary.\nIndependently Approve Closure: Record the independent closure conclusion, residual risk, linked evidence, and any follow-up monitoring required after closure.\n\n**Record in AssureSwarm**\n1. Complete the item-level matrix, evidence links, tester identity, dates, exception details, recurrence analysis, count reconciliation, and any deviations from the approved plan. Also record items tested; exceptions found.\n2. Document the evaluation, result pattern, sustainability factors, limitations, monitoring commitments, reopened actions, and the rationale for closure consideration or continued remediation. Also record retest evaluation.\n3. Record the decision, rationale, approvers, closure or continuation date, remaining monitoring, linked Issue and remediation updates, and any residual action owner.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: All planned items and attributes have supported results, deviations are approved or resolved, observed exceptions are reproducible, and the work is ready for independent evaluation. The evaluation follows the preapproved criteria, contrary evidence is addressed, remaining risk is explicit, and only supported cases advance to final closure approval. The authorized reviewer accepts a decision supported by the full record, linked statuses can be updated consistently, and workflow completion is not used as a substitute for the explicit closure decision.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Physical Site Access Review","itemType":"control","kind":"related"},{"itemTitle":"ISO 27001 Certification Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Quarterly Access Recertification","itemType":"control","name":"Control Remediation Retest & Closure — Quarterly Access Recertification — current cycle","templateName":"Control Remediation Retest & Closure","templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","description":"Control Remediation Retest & Closure for Quarterly Access Recertification (current cycle).","status":"ACTIVE","displayOrder":92,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm readiness and approve the independent retest plan","description":null,"summary":null,"instructions":"**Objective**\nConfirm readiness and approve the independent retest plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved remediation plan and its completion evidence, change tickets, updated control description, owner certification and expected post-change occurrences, with the original exception, impact evaluation, updated attributes and independence requirements.\n\n**Procedure**\n1. Inspect implementation evidence rather than accepting status, compare delivered actions to the plan, verify effective dates and scope, and quantify occurrences since implementation. Then set the period, population, sample or full-inspection method, attributes, evidence expectations, recurrence criteria, tester independence and treatment of transitional items.\n\n**Record in AssureSwarm**\n1. Document each action with its evidence reference and implementation date, deviations from plan, the available population and the readiness decision, then the approved scope, tester, population source, sample basis, attributes, change-specific procedures, success criteria and exclusions. Also record readiness result; retest period; retest method.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The remediation is demonstrably implemented or returned with precise gaps, enough post-change activity exists for the chosen method, the plan directly tests the remediated cause, independence is documented, and success criteria are set before execution.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Quarterly Access Recertification","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve remediation closure","description":null,"summary":null,"instructions":"**Objective**\nApprove remediation closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the frozen post-change population, approved selection, updated control criteria, implementation evidence, source records, system logs, approvals, and original failure pattern.\n2. Review the approved plan, item-level results, new exceptions, original root cause, implementation timeline, monitoring evidence, control frequency, and owner accountability.\n3. Use all remediation milestones, retest work, exception results, evaluation, monitoring commitments, Issue status, owner response, and required governance approvals.\n\n**Procedure**\n1. Test each item consistently, retain evidence for all attributes, compare results to the original condition, investigate anomalies and unavailable support, and keep management explanations separate from tester results.\n2. Reconcile counts, assess any recurrence or new failure mode, consider whether the observation period is representative, verify sustainable ownership and monitoring, and decide whether added work is necessary.\n3. Confirm closure criteria are met, link the exact evidence supporting each criterion, verify related records are consistent, and return or reopen the matter when limitations or recurrence prevent closure.\n\nAdditional canonical requirements reviewed with this package:\nVerify Remediation Implementation: Verify the approved corrective action is implemented as designed, including configuration, procedure, owner, and retained implementation evidence.\nSelect Post-Remediation Sample: Define the post-remediation population and select a sample that covers the corrected control operation and relevant risk scenarios.\nReperform Failed Attributes: Independently reperform the attributes that failed, comparing evidence and timing to the corrected design rather than relying on management assertion.\nAssess Recurrence Risk: Assess whether the root cause can recur, whether related controls require testing, and whether compensating controls remain necessary.\nIndependently Approve Closure: Record the independent closure conclusion, residual risk, linked evidence, and any follow-up monitoring required after closure.\n\n**Record in AssureSwarm**\n1. Complete the item-level matrix, evidence links, tester identity, dates, exception details, recurrence analysis, count reconciliation, and any deviations from the approved plan. Also record items tested; exceptions found.\n2. Document the evaluation, result pattern, sustainability factors, limitations, monitoring commitments, reopened actions, and the rationale for closure consideration or continued remediation. Also record retest evaluation.\n3. Record the decision, rationale, approvers, closure or continuation date, remaining monitoring, linked Issue and remediation updates, and any residual action owner.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: All planned items and attributes have supported results, deviations are approved or resolved, observed exceptions are reproducible, and the work is ready for independent evaluation. The evaluation follows the preapproved criteria, contrary evidence is addressed, remaining risk is explicit, and only supported cases advance to final closure approval. The authorized reviewer accepts a decision supported by the full record, linked statuses can be updated consistently, and workflow completion is not used as a substitute for the explicit closure decision.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Quarterly Access Recertification","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Security Incident Triage","itemType":"control","name":"Control Remediation Retest & Closure — Security Incident Triage — prior cycle","templateName":"Control Remediation Retest & Closure","templateSourceId":"coworkcanvas:template:control-remediation-retest-closure","description":"Control Remediation Retest & Closure for Security Incident Triage (prior cycle).","status":"COMPLETED","displayOrder":93,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm readiness and approve the independent retest plan","description":null,"summary":null,"instructions":"**Objective**\nConfirm readiness and approve the independent retest plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved remediation plan and its completion evidence, change tickets, updated control description, owner certification and expected post-change occurrences, with the original exception, impact evaluation, updated attributes and independence requirements.\n\n**Procedure**\n1. Inspect implementation evidence rather than accepting status, compare delivered actions to the plan, verify effective dates and scope, and quantify occurrences since implementation. Then set the period, population, sample or full-inspection method, attributes, evidence expectations, recurrence criteria, tester independence and treatment of transitional items.\n\n**Record in AssureSwarm**\n1. Document each action with its evidence reference and implementation date, deviations from plan, the available population and the readiness decision, then the approved scope, tester, population source, sample basis, attributes, change-specific procedures, success criteria and exclusions. Also record readiness result; retest period; retest method.\n\n**Exit criteria**\nTest supervisor independent of the operator provides expertise: The remediation is demonstrably implemented or returned with precise gaps, enough post-change activity exists for the chosen method, the plan directly tests the remediated cause, independence is documented, and success criteria are set before execution.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve remediation closure","description":null,"summary":null,"instructions":"**Objective**\nApprove remediation closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the frozen post-change population, approved selection, updated control criteria, implementation evidence, source records, system logs, approvals, and original failure pattern.\n2. Review the approved plan, item-level results, new exceptions, original root cause, implementation timeline, monitoring evidence, control frequency, and owner accountability.\n3. Use all remediation milestones, retest work, exception results, evaluation, monitoring commitments, Issue status, owner response, and required governance approvals.\n\n**Procedure**\n1. Test each item consistently, retain evidence for all attributes, compare results to the original condition, investigate anomalies and unavailable support, and keep management explanations separate from tester results.\n2. Reconcile counts, assess any recurrence or new failure mode, consider whether the observation period is representative, verify sustainable ownership and monitoring, and decide whether added work is necessary.\n3. Confirm closure criteria are met, link the exact evidence supporting each criterion, verify related records are consistent, and return or reopen the matter when limitations or recurrence prevent closure.\n\nAdditional canonical requirements reviewed with this package:\nVerify Remediation Implementation: Verify the approved corrective action is implemented as designed, including configuration, procedure, owner, and retained implementation evidence.\nSelect Post-Remediation Sample: Define the post-remediation population and select a sample that covers the corrected control operation and relevant risk scenarios.\nReperform Failed Attributes: Independently reperform the attributes that failed, comparing evidence and timing to the corrected design rather than relying on management assertion.\nAssess Recurrence Risk: Assess whether the root cause can recur, whether related controls require testing, and whether compensating controls remain necessary.\nIndependently Approve Closure: Record the independent closure conclusion, residual risk, linked evidence, and any follow-up monitoring required after closure.\n\n**Record in AssureSwarm**\n1. Complete the item-level matrix, evidence links, tester identity, dates, exception details, recurrence analysis, count reconciliation, and any deviations from the approved plan. Also record items tested; exceptions found.\n2. Document the evaluation, result pattern, sustainability factors, limitations, monitoring commitments, reopened actions, and the rationale for closure consideration or continued remediation. Also record retest evaluation.\n3. Record the decision, rationale, approvers, closure or continuation date, remaining monitoring, linked Issue and remediation updates, and any residual action owner.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: All planned items and attributes have supported results, deviations are approved or resolved, observed exceptions are reproducible, and the work is ready for independent evaluation. The evaluation follows the preapproved criteria, contrary evidence is addressed, remaining risk is explicit, and only supported cases advance to final closure approval. The authorized reviewer accepts a decision supported by the full record, linked statuses can be updated consistently, and workflow completion is not used as a substitute for the explicit closure decision.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Account Reconciliation Review","itemType":"control","name":"Control Walkthrough — Account Reconciliation Review — next cycle","templateName":"Control Walkthrough","templateSourceId":"coworkcanvas:template:control-walkthrough","description":"Control Walkthrough for Account Reconciliation Review (next cycle).","status":"DRAFT","displayOrder":101,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve walkthrough conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove walkthrough conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current control description, process narrative, system flow, prior walkthrough, open changes, linked risks, and the population from which an occurrence can be selected.\n2. Use the selected occurrence, control procedure, role assignments, screen or report access, expected evidence, and the preparer questions derived during planning.\n3. Use source documents, system timestamps, report parameters, approvals, exception logs, downstream records, and the execution sequence established through inquiry.\n4. Review the plan, inquiry notes, complete evidence trace, deviations, owner explanations, system changes, and any open documentation questions.\n\n**Procedure**\n1. Select a recent representative occurrence without allowing the owner to substitute a polished example; schedule the preparer, performer, reviewer, and system contacts needed to explain each handoff.\n2. Ask the performer to demonstrate the activity in sequence, explain decision points and exceptions, identify reports and parameters used, and show how reviewer challenge differs from routine preparation.\n3. Agree identifiers and amounts across each handoff, inspect the timing and authority of approvals, reproduce key report filters where feasible, and investigate missing links or post-dated evidence.\n4. Reconcile observed practice to the control and process narratives, assess whether deviations require documentation or design changes, and separate walkthrough observations from any later population-based testing conclusion.\n\nAdditional canonical requirements reviewed with this package:\nSelect a Real Control Occurrence: Select a representative occurrence and document the date, population context, operator, and source records used for the walkthrough.\nInterview the Control Operator: Interview the operator about trigger, decision points, exceptions, tools, handoffs, and evidence retention; capture any practice variation.\nTrace Inputs, Actions and Outputs: Trace the occurrence from complete inputs through performed actions and resulting output, checking that each documented control activity occurred.\nInspect Retained Evidence: Inspect retained evidence for completeness, integrity, timing, and retrievability; link the source records sufficient for reperformance.\nRecord Practice-versus-Documentation Conclusion: Record whether observed practice matches the approved procedure, list deviations, and route material gaps to exception remediation.\n\n**Record in AssureSwarm**\n1. Record the occurrence identifier, date, participants, systems, planned route, known changes, and any confidentiality or access constraints affecting evidence capture. Also record walkthrough date.\n2. Capture who performed each action, what was observed, the systems and reports used, key judgments, deviations from the documented design, and evidence references for the occurrence. Also record inquiry and observation summary.\n3. Map the evidence chain, note agreements and deviations at each point, identify system-generated dependencies, and record whether the occurrence is representative of normal execution. Also record trace result.\n4. Document the conclusion, changes required, evidence limitations, responsible owners, target dates, and links to any issue, design assessment, or planned test prompted by the walkthrough. Also record changes and follow-up.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: A traceable occurrence and knowledgeable participants are confirmed, the route covers initiation through evidence retention, and known changes are in scope. The actual execution sequence and reviewer involvement are understood, unsupported explanations are flagged, and each key claim has observable or documentary support. The occurrence is traceable end to end or the precise break is documented, observed deviations are supported, and the trace result is ready for independent review. The authorized reviewer can follow the occurrence and rationale, documentation changes are assigned, and the record does not overstate what a single walkthrough demonstrates.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Backup Restoration Test","itemType":"control","name":"Control Walkthrough — Backup Restoration Test — current cycle","templateName":"Control Walkthrough","templateSourceId":"coworkcanvas:template:control-walkthrough","description":"Control Walkthrough for Backup Restoration Test (current cycle).","status":"ACTIVE","displayOrder":102,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve walkthrough conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove walkthrough conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current control description, process narrative, system flow, prior walkthrough, open changes, linked risks, and the population from which an occurrence can be selected.\n2. Use the selected occurrence, control procedure, role assignments, screen or report access, expected evidence, and the preparer questions derived during planning.\n3. Use source documents, system timestamps, report parameters, approvals, exception logs, downstream records, and the execution sequence established through inquiry.\n4. Review the plan, inquiry notes, complete evidence trace, deviations, owner explanations, system changes, and any open documentation questions.\n\n**Procedure**\n1. Select a recent representative occurrence without allowing the owner to substitute a polished example; schedule the preparer, performer, reviewer, and system contacts needed to explain each handoff.\n2. Ask the performer to demonstrate the activity in sequence, explain decision points and exceptions, identify reports and parameters used, and show how reviewer challenge differs from routine preparation.\n3. Agree identifiers and amounts across each handoff, inspect the timing and authority of approvals, reproduce key report filters where feasible, and investigate missing links or post-dated evidence.\n4. Reconcile observed practice to the control and process narratives, assess whether deviations require documentation or design changes, and separate walkthrough observations from any later population-based testing conclusion.\n\nAdditional canonical requirements reviewed with this package:\nSelect a Real Control Occurrence: Select a representative occurrence and document the date, population context, operator, and source records used for the walkthrough.\nInterview the Control Operator: Interview the operator about trigger, decision points, exceptions, tools, handoffs, and evidence retention; capture any practice variation.\nTrace Inputs, Actions and Outputs: Trace the occurrence from complete inputs through performed actions and resulting output, checking that each documented control activity occurred.\nInspect Retained Evidence: Inspect retained evidence for completeness, integrity, timing, and retrievability; link the source records sufficient for reperformance.\nRecord Practice-versus-Documentation Conclusion: Record whether observed practice matches the approved procedure, list deviations, and route material gaps to exception remediation.\n\n**Record in AssureSwarm**\n1. Record the occurrence identifier, date, participants, systems, planned route, known changes, and any confidentiality or access constraints affecting evidence capture. Also record walkthrough date.\n2. Capture who performed each action, what was observed, the systems and reports used, key judgments, deviations from the documented design, and evidence references for the occurrence. Also record inquiry and observation summary.\n3. Map the evidence chain, note agreements and deviations at each point, identify system-generated dependencies, and record whether the occurrence is representative of normal execution. Also record trace result.\n4. Document the conclusion, changes required, evidence limitations, responsible owners, target dates, and links to any issue, design assessment, or planned test prompted by the walkthrough. Also record changes and follow-up.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: A traceable occurrence and knowledgeable participants are confirmed, the route covers initiation through evidence retention, and known changes are in scope. The actual execution sequence and reviewer involvement are understood, unsupported explanations are flagged, and each key claim has observable or documentary support. The occurrence is traceable end to end or the precise break is documented, observed deviations are supported, and the trace result is ready for independent review. The authorized reviewer can follow the occurrence and rationale, documentation changes are assigned, and the record does not overstate what a single walkthrough demonstrates.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Batch Processing Monitoring","itemType":"control","name":"Control Walkthrough — Batch Processing Monitoring — prior cycle","templateName":"Control Walkthrough","templateSourceId":"coworkcanvas:template:control-walkthrough","description":"Control Walkthrough for Batch Processing Monitoring (prior cycle).","status":"COMPLETED","displayOrder":103,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve walkthrough conclusion","description":null,"summary":null,"instructions":"**Objective**\nApprove walkthrough conclusion. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current control description, process narrative, system flow, prior walkthrough, open changes, linked risks, and the population from which an occurrence can be selected.\n2. Use the selected occurrence, control procedure, role assignments, screen or report access, expected evidence, and the preparer questions derived during planning.\n3. Use source documents, system timestamps, report parameters, approvals, exception logs, downstream records, and the execution sequence established through inquiry.\n4. Review the plan, inquiry notes, complete evidence trace, deviations, owner explanations, system changes, and any open documentation questions.\n\n**Procedure**\n1. Select a recent representative occurrence without allowing the owner to substitute a polished example; schedule the preparer, performer, reviewer, and system contacts needed to explain each handoff.\n2. Ask the performer to demonstrate the activity in sequence, explain decision points and exceptions, identify reports and parameters used, and show how reviewer challenge differs from routine preparation.\n3. Agree identifiers and amounts across each handoff, inspect the timing and authority of approvals, reproduce key report filters where feasible, and investigate missing links or post-dated evidence.\n4. Reconcile observed practice to the control and process narratives, assess whether deviations require documentation or design changes, and separate walkthrough observations from any later population-based testing conclusion.\n\nAdditional canonical requirements reviewed with this package:\nSelect a Real Control Occurrence: Select a representative occurrence and document the date, population context, operator, and source records used for the walkthrough.\nInterview the Control Operator: Interview the operator about trigger, decision points, exceptions, tools, handoffs, and evidence retention; capture any practice variation.\nTrace Inputs, Actions and Outputs: Trace the occurrence from complete inputs through performed actions and resulting output, checking that each documented control activity occurred.\nInspect Retained Evidence: Inspect retained evidence for completeness, integrity, timing, and retrievability; link the source records sufficient for reperformance.\nRecord Practice-versus-Documentation Conclusion: Record whether observed practice matches the approved procedure, list deviations, and route material gaps to exception remediation.\n\n**Record in AssureSwarm**\n1. Record the occurrence identifier, date, participants, systems, planned route, known changes, and any confidentiality or access constraints affecting evidence capture. Also record walkthrough date.\n2. Capture who performed each action, what was observed, the systems and reports used, key judgments, deviations from the documented design, and evidence references for the occurrence. Also record inquiry and observation summary.\n3. Map the evidence chain, note agreements and deviations at each point, identify system-generated dependencies, and record whether the occurrence is representative of normal execution. Also record trace result.\n4. Document the conclusion, changes required, evidence limitations, responsible owners, target dates, and links to any issue, design assessment, or planned test prompted by the walkthrough. Also record changes and follow-up.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: A traceable occurrence and knowledgeable participants are confirmed, the route covers initiation through evidence retention, and known changes are in scope. The actual execution sequence and reviewer involvement are understood, unsupported explanations are flagged, and each key claim has observable or documentary support. The occurrence is traceable end to end or the precise break is documented, observed deviations are supported, and the trace result is ready for independent review. The authorized reviewer can follow the occurrence and rationale, documentation changes are assigned, and the record does not overstate what a single walkthrough demonstrates.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Batch Processing Monitoring","itemType":"control","kind":"related"},{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Banana ERP","itemType":"system","name":"Data Conversion & Migration — Banana ERP — prior cycle","templateName":"Data Conversion & Migration","templateSourceId":"coworkcanvas:template:data-conversion-migration","description":"Data Conversion & Migration for Banana ERP (prior cycle).","status":"COMPLETED","displayOrder":113,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm conversion scope and source data","description":null,"summary":null,"instructions":"**Objective**\nConfirm conversion scope and source data. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, source system extracts and their generation method, data dictionaries and mapping specifications, the conversion cut-off, and records deliberately excluded from conversion.\n\n**Procedure**\n1. Capture record counts and monetary or quantitative control totals before conversion, evidence the extract is complete against the source of record, confirm the cut-off is enforced, and document excluded records with rationale.\n\n**Record in AssureSwarm**\n1. Capture the conversion scope and data objects, source record counts and control totals with extract timestamps, completeness basis, cut-off enforcement, exclusions with rationale, and known source data quality issues.\n\n**Exit criteria**\nData owner provides approval: Source control totals are captured before conversion from an evidenced-complete extract, the cut-off is enforced, and exclusions are documented rather than emerging as variances later.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve conversion record","description":null,"summary":null,"instructions":"**Objective**\nApprove conversion record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the source control totals, conversion job logs and error reports, target extracts after load, the transformation and mapping specification, and rejected-record queues.\n2. Use the reconciliation results, a sample selected from the source population, target field values, the mapping specification, business validation queries, and prior conversion exceptions.\n3. Review all stage records, source and target control totals, variance explanations, rejected records, sample testing results, business sign-off, and accepted exceptions.\n\n**Procedure**\n1. Reconcile counts and totals independently of the conversion tool own reporting, trace each variance to a documented transformation rule or a rejection, inspect the rejected queue rather than ignoring it, and refuse to net variances against each other.\n2. Select the sample from the SOURCE population so unconverted records can be found, compare field values against the mapping specification, test transformed and derived fields specifically, and treat totals agreement as insufficient evidence of accuracy.\n3. Trace the closing position to the source control totals, verify every variance carries a documented explanation, confirm rejected records were dispositioned, and return totals-only accuracy claims with precise comments.\n\n**Record in AssureSwarm**\n1. Document the reconciliation of counts and totals source to target, variances traced to rules or rejections, rejected records and their disposition, conversion errors, and variances that remain unexplained. Also record reconciliation result; conversion outcome.\n2. Record the validation result, sample basis and size, field-level comparison outcomes, transformation errors found, business sign-off and its scope, exceptions accepted with owners, and fields not tested. Also record exception detail.\n3. Capture the authorized reviewer, the summary, accepted validation result, conversion date, final reconciliation position, exceptions with owners and dates, untested fields, and linked issues raised.\n\n**Exit criteria**\nIndependent conversion validator provides approval: Reconciliation is independent of the conversion tool reporting, every variance is traced to a rule or a rejection, and unexplained variances block rather than net out. An approver accepts that accuracy rests on source-selected field-level testing rather than totals alone, exceptions carry owners, and untested fields are declared rather than implied accurate. The authorized reviewer accepts the record as evidence the conversion control operated, and closure implies no assurance over records excluded from the conversion scope.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Model Home Data Lake","itemType":"system","name":"Data Conversion & Migration — Model Home Data Lake — current cycle","templateName":"Data Conversion & Migration","templateSourceId":"coworkcanvas:template:data-conversion-migration","description":"Data Conversion & Migration for Model Home Data Lake (current cycle).","status":"ACTIVE","displayOrder":112,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm conversion scope and source data","description":null,"summary":null,"instructions":"**Objective**\nConfirm conversion scope and source data. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, source system extracts and their generation method, data dictionaries and mapping specifications, the conversion cut-off, and records deliberately excluded from conversion.\n\n**Procedure**\n1. Capture record counts and monetary or quantitative control totals before conversion, evidence the extract is complete against the source of record, confirm the cut-off is enforced, and document excluded records with rationale.\n\n**Record in AssureSwarm**\n1. Capture the conversion scope and data objects, source record counts and control totals with extract timestamps, completeness basis, cut-off enforcement, exclusions with rationale, and known source data quality issues.\n\n**Exit criteria**\nData owner provides approval: Source control totals are captured before conversion from an evidenced-complete extract, the cut-off is enforced, and exclusions are documented rather than emerging as variances later.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve conversion record","description":null,"summary":null,"instructions":"**Objective**\nApprove conversion record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the source control totals, conversion job logs and error reports, target extracts after load, the transformation and mapping specification, and rejected-record queues.\n2. Use the reconciliation results, a sample selected from the source population, target field values, the mapping specification, business validation queries, and prior conversion exceptions.\n3. Review all stage records, source and target control totals, variance explanations, rejected records, sample testing results, business sign-off, and accepted exceptions.\n\n**Procedure**\n1. Reconcile counts and totals independently of the conversion tool own reporting, trace each variance to a documented transformation rule or a rejection, inspect the rejected queue rather than ignoring it, and refuse to net variances against each other.\n2. Select the sample from the SOURCE population so unconverted records can be found, compare field values against the mapping specification, test transformed and derived fields specifically, and treat totals agreement as insufficient evidence of accuracy.\n3. Trace the closing position to the source control totals, verify every variance carries a documented explanation, confirm rejected records were dispositioned, and return totals-only accuracy claims with precise comments.\n\n**Record in AssureSwarm**\n1. Document the reconciliation of counts and totals source to target, variances traced to rules or rejections, rejected records and their disposition, conversion errors, and variances that remain unexplained. Also record reconciliation result; conversion outcome.\n2. Record the validation result, sample basis and size, field-level comparison outcomes, transformation errors found, business sign-off and its scope, exceptions accepted with owners, and fields not tested. Also record exception detail.\n3. Capture the authorized reviewer, the summary, accepted validation result, conversion date, final reconciliation position, exceptions with owners and dates, untested fields, and linked issues raised.\n\n**Exit criteria**\nIndependent conversion validator provides approval: Reconciliation is independent of the conversion tool reporting, every variance is traced to a rule or a rejection, and unexplained variances block rather than net out. An approver accepts that accuracy rests on source-selected field-level testing rather than totals alone, exceptions carry owners, and untested fields are declared rather than implied accurate. The authorized reviewer accepts the record as evidence the conversion control operated, and closure implies no assurance over records excluded from the conversion scope.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Never Nude HR Platform","itemType":"system","name":"Data Conversion & Migration — Never Nude HR Platform — next cycle","templateName":"Data Conversion & Migration","templateSourceId":"coworkcanvas:template:data-conversion-migration","description":"Data Conversion & Migration for Never Nude HR Platform (next cycle).","status":"DRAFT","displayOrder":111,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm conversion scope and source data","description":null,"summary":null,"instructions":"**Objective**\nConfirm conversion scope and source data. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, source system extracts and their generation method, data dictionaries and mapping specifications, the conversion cut-off, and records deliberately excluded from conversion.\n\n**Procedure**\n1. Capture record counts and monetary or quantitative control totals before conversion, evidence the extract is complete against the source of record, confirm the cut-off is enforced, and document excluded records with rationale.\n\n**Record in AssureSwarm**\n1. Capture the conversion scope and data objects, source record counts and control totals with extract timestamps, completeness basis, cut-off enforcement, exclusions with rationale, and known source data quality issues.\n\n**Exit criteria**\nData owner provides approval: Source control totals are captured before conversion from an evidenced-complete extract, the cut-off is enforced, and exclusions are documented rather than emerging as variances later.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Never Nude HR Platform","itemType":"system","kind":"related"},{"itemTitle":"Annual performance and conduct evaluation per personnel","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve conversion record","description":null,"summary":null,"instructions":"**Objective**\nApprove conversion record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the source control totals, conversion job logs and error reports, target extracts after load, the transformation and mapping specification, and rejected-record queues.\n2. Use the reconciliation results, a sample selected from the source population, target field values, the mapping specification, business validation queries, and prior conversion exceptions.\n3. Review all stage records, source and target control totals, variance explanations, rejected records, sample testing results, business sign-off, and accepted exceptions.\n\n**Procedure**\n1. Reconcile counts and totals independently of the conversion tool own reporting, trace each variance to a documented transformation rule or a rejection, inspect the rejected queue rather than ignoring it, and refuse to net variances against each other.\n2. Select the sample from the SOURCE population so unconverted records can be found, compare field values against the mapping specification, test transformed and derived fields specifically, and treat totals agreement as insufficient evidence of accuracy.\n3. Trace the closing position to the source control totals, verify every variance carries a documented explanation, confirm rejected records were dispositioned, and return totals-only accuracy claims with precise comments.\n\n**Record in AssureSwarm**\n1. Document the reconciliation of counts and totals source to target, variances traced to rules or rejections, rejected records and their disposition, conversion errors, and variances that remain unexplained. Also record reconciliation result; conversion outcome.\n2. Record the validation result, sample basis and size, field-level comparison outcomes, transformation errors found, business sign-off and its scope, exceptions accepted with owners, and fields not tested. Also record exception detail.\n3. Capture the authorized reviewer, the summary, accepted validation result, conversion date, final reconciliation position, exceptions with owners and dates, untested fields, and linked issues raised.\n\n**Exit criteria**\nIndependent conversion validator provides approval: Reconciliation is independent of the conversion tool reporting, every variance is traced to a rule or a rejection, and unexplained variances block rather than net out. An approver accepts that accuracy rests on source-selected field-level testing rather than totals alone, exceptions carry owners, and untested fields are declared rather than implied accurate. The authorized reviewer accepts the record as evidence the conversion control operated, and closure implies no assurance over records excluded from the conversion scope.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Never Nude HR Platform","itemType":"system","kind":"related"},{"itemTitle":"Annual performance and conduct evaluation per personnel","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Banana ERP","itemType":"system","name":"Emergency Change — Banana ERP — next cycle","templateName":"Emergency Change","templateSourceId":"coworkcanvas:template:emergency-change","description":"Emergency Change for Banana ERP (next cycle).","status":"DRAFT","displayOrder":121,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Record the emergency and authorization","description":null,"summary":null,"instructions":"**Objective**\nRecord the emergency and authorization. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident or outage record, the emergency-change policy and its authorization matrix, the authorizer identity and role, and the business impact being averted.\n\n**Procedure**\n1. Establish that the trigger genuinely met the emergency criteria rather than reflecting poor planning, confirm the authorizer held the delegated authority, capture the authorization timestamp relative to the change, and compute the retrospective review deadline.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, trigger and business impact, emergency criteria met, authorizer identity and authority basis, authorization timing relative to the change, and the retrospective review deadline. Also record emergency justification and authorization.\n\n**Exit criteria**\nEmergency change authority provides approval: The emergency criteria and delegated authority are evidenced, authorization timing relative to the change is recorded honestly, and the retrospective deadline is set.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve emergency change record","description":null,"summary":null,"instructions":"**Objective**\nApprove emergency change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use production change and deployment logs, session recordings, break-glass checkout records, the elevated-access grant and its expiry, and post-change system state.\n2. Use the authorization record, the reconstructed change, incident timeline, testing performed after the fact, comparable prior emergencies, and the emergency-change rate for this system.\n3. Review all stage records, authorization timing, log-reconstructed change, elevated access grant and revocation, retrospective testing, control gaps, and remediation owners.\n\n**Procedure**\n1. Reconstruct the change from system logs rather than from recollection, record every command or artifact applied, confirm elevated access carried an expiry, and verify that break-glass credentials were rotated after use.\n2. Test the change against the requirements it should have met, compare the emergency rate against normal change volume for a pattern of routine bypass, confirm the review happened inside the policy window, and classify avoidable emergencies as control gaps.\n3. Trace the applied change to the authorization and to post-hoc testing, verify elevated access was revoked and credentials rotated, confirm control gaps carry remediation, and return self-justifying retrospectives with precise comments.\n\n**Record in AssureSwarm**\n1. Document the change applied with log references and timestamps, access class used, elevated grant and expiry, credential rotation after use, session evidence, and any change made beyond the emergency scope.\n2. Record the retrospective result, review date against the deadline, post-hoc testing performed, emergency-rate observations, control gaps identified, remediation with owners and dates, and unauthorized changes escalated. Also record remediation detail.\n3. Capture the authorized reviewer, the summary, accepted retrospective result, review date, elevated-access closure evidence, control gaps and remediation with owners and dates, and linked exceptions raised. Also record emergency change summary.\n\n**Exit criteria**\nIndependent retrospective reviewer provides approval: The applied change is reconstructed from logs, elevated access is shown to be time-bound and revoked, and scope creep beyond the emergency is surfaced rather than folded in. An approver accepts that the retrospective rests on post-hoc testing rather than restated justification, late reviews are recorded as such, and routine bypass patterns are surfaced as control gaps. The authorized reviewer accepts the record as evidence the emergency-change control operated, and closure implies no assurance that the bypassed normal controls would have passed.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Cornballer Revenue Engine","itemType":"system","name":"Emergency Change — Cornballer Revenue Engine — prior cycle","templateName":"Emergency Change","templateSourceId":"coworkcanvas:template:emergency-change","description":"Emergency Change for Cornballer Revenue Engine (prior cycle).","status":"COMPLETED","displayOrder":123,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Record the emergency and authorization","description":null,"summary":null,"instructions":"**Objective**\nRecord the emergency and authorization. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident or outage record, the emergency-change policy and its authorization matrix, the authorizer identity and role, and the business impact being averted.\n\n**Procedure**\n1. Establish that the trigger genuinely met the emergency criteria rather than reflecting poor planning, confirm the authorizer held the delegated authority, capture the authorization timestamp relative to the change, and compute the retrospective review deadline.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, trigger and business impact, emergency criteria met, authorizer identity and authority basis, authorization timing relative to the change, and the retrospective review deadline. Also record emergency justification and authorization.\n\n**Exit criteria**\nEmergency change authority provides approval: The emergency criteria and delegated authority are evidenced, authorization timing relative to the change is recorded honestly, and the retrospective deadline is set.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve emergency change record","description":null,"summary":null,"instructions":"**Objective**\nApprove emergency change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use production change and deployment logs, session recordings, break-glass checkout records, the elevated-access grant and its expiry, and post-change system state.\n2. Use the authorization record, the reconstructed change, incident timeline, testing performed after the fact, comparable prior emergencies, and the emergency-change rate for this system.\n3. Review all stage records, authorization timing, log-reconstructed change, elevated access grant and revocation, retrospective testing, control gaps, and remediation owners.\n\n**Procedure**\n1. Reconstruct the change from system logs rather than from recollection, record every command or artifact applied, confirm elevated access carried an expiry, and verify that break-glass credentials were rotated after use.\n2. Test the change against the requirements it should have met, compare the emergency rate against normal change volume for a pattern of routine bypass, confirm the review happened inside the policy window, and classify avoidable emergencies as control gaps.\n3. Trace the applied change to the authorization and to post-hoc testing, verify elevated access was revoked and credentials rotated, confirm control gaps carry remediation, and return self-justifying retrospectives with precise comments.\n\n**Record in AssureSwarm**\n1. Document the change applied with log references and timestamps, access class used, elevated grant and expiry, credential rotation after use, session evidence, and any change made beyond the emergency scope.\n2. Record the retrospective result, review date against the deadline, post-hoc testing performed, emergency-rate observations, control gaps identified, remediation with owners and dates, and unauthorized changes escalated. Also record remediation detail.\n3. Capture the authorized reviewer, the summary, accepted retrospective result, review date, elevated-access closure evidence, control gaps and remediation with owners and dates, and linked exceptions raised. Also record emergency change summary.\n\n**Exit criteria**\nIndependent retrospective reviewer provides approval: The applied change is reconstructed from logs, elevated access is shown to be time-bound and revoked, and scope creep beyond the emergency is surfaced rather than folded in. An approver accepts that the retrospective rests on post-hoc testing rather than restated justification, late reviews are recorded as such, and routine bypass patterns are surfaced as control gaps. The authorized reviewer accepts the record as evidence the emergency-change control operated, and closure implies no assurance that the bypassed normal controls would have passed.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Sudden Valley Network","itemType":"system","name":"Emergency Change — Sudden Valley Network — current cycle","templateName":"Emergency Change","templateSourceId":"coworkcanvas:template:emergency-change","description":"Emergency Change for Sudden Valley Network (current cycle).","status":"ACTIVE","displayOrder":122,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Record the emergency and authorization","description":null,"summary":null,"instructions":"**Objective**\nRecord the emergency and authorization. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident or outage record, the emergency-change policy and its authorization matrix, the authorizer identity and role, and the business impact being averted.\n\n**Procedure**\n1. Establish that the trigger genuinely met the emergency criteria rather than reflecting poor planning, confirm the authorizer held the delegated authority, capture the authorization timestamp relative to the change, and compute the retrospective review deadline.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, trigger and business impact, emergency criteria met, authorizer identity and authority basis, authorization timing relative to the change, and the retrospective review deadline. Also record emergency justification and authorization.\n\n**Exit criteria**\nEmergency change authority provides approval: The emergency criteria and delegated authority are evidenced, authorization timing relative to the change is recorded honestly, and the retrospective deadline is set.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Sudden Valley Network","itemType":"system","kind":"related"},{"itemTitle":"Availability & capacity management (SLA)","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve emergency change record","description":null,"summary":null,"instructions":"**Objective**\nApprove emergency change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use production change and deployment logs, session recordings, break-glass checkout records, the elevated-access grant and its expiry, and post-change system state.\n2. Use the authorization record, the reconstructed change, incident timeline, testing performed after the fact, comparable prior emergencies, and the emergency-change rate for this system.\n3. Review all stage records, authorization timing, log-reconstructed change, elevated access grant and revocation, retrospective testing, control gaps, and remediation owners.\n\n**Procedure**\n1. Reconstruct the change from system logs rather than from recollection, record every command or artifact applied, confirm elevated access carried an expiry, and verify that break-glass credentials were rotated after use.\n2. Test the change against the requirements it should have met, compare the emergency rate against normal change volume for a pattern of routine bypass, confirm the review happened inside the policy window, and classify avoidable emergencies as control gaps.\n3. Trace the applied change to the authorization and to post-hoc testing, verify elevated access was revoked and credentials rotated, confirm control gaps carry remediation, and return self-justifying retrospectives with precise comments.\n\n**Record in AssureSwarm**\n1. Document the change applied with log references and timestamps, access class used, elevated grant and expiry, credential rotation after use, session evidence, and any change made beyond the emergency scope.\n2. Record the retrospective result, review date against the deadline, post-hoc testing performed, emergency-rate observations, control gaps identified, remediation with owners and dates, and unauthorized changes escalated. Also record remediation detail.\n3. Capture the authorized reviewer, the summary, accepted retrospective result, review date, elevated-access closure evidence, control gaps and remediation with owners and dates, and linked exceptions raised. Also record emergency change summary.\n\n**Exit criteria**\nIndependent retrospective reviewer provides approval: The applied change is reconstructed from logs, elevated access is shown to be time-bound and revoked, and scope creep beyond the emergency is surfaced rather than folded in. An approver accepts that the retrospective rests on post-hoc testing rather than restated justification, late reviews are recorded as such, and routine bypass patterns are surfaced as control gaps. The authorized reviewer accepts the record as evidence the emergency-change control operated, and closure implies no assurance that the bypassed normal controls would have passed.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Sudden Valley Network","itemType":"system","kind":"related"},{"itemTitle":"Availability & capacity management (SLA)","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"AI model governance gap","itemType":"risk","name":"Emerging Risk & Horizon Scan — AI model governance gap — next cycle","templateName":"Emerging Risk & Horizon Scan","templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","description":"Emerging Risk & Horizon Scan for AI model governance gap (next cycle).","status":"DRAFT","displayOrder":131,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve scan record and watchlist disposition","description":null,"summary":null,"instructions":"**Objective**\nApprove scan record and watchlist disposition. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, strategy and objective statements, prior scan output and watchlist, regulatory and technology intelligence, peer and industry reporting, threat feeds, scenario libraries, and the risk taxonomy.\n2. Use the agreed source list, published intelligence and reporting, internal incident and near-miss data, stakeholder observations, prior watchlist entries and their status, and the qualification criteria.\n3. Use the screened watchlist, scenario analysis, existing control and continuity capability, exposure and dependency maps, expert input, comparable events elsewhere, and the approved risk criteria.\n4. Review all stage records, the signal inventory and its attribution, screening rejections, plausibility and velocity reasoning, dispositions, trigger conditions, dissenting views, and declared blind spots.\n\n**Procedure**\n1. Fix the horizon window, select the domains and objectives in scope, enumerate the sources to be consulted with their reliability, define the signal qualification criteria, and document sources deliberately excluded.\n2. Record each signal with its source and date, apply the qualification criteria consistently, retain signals that fail screening with the reason, look for convergence between weak signals, and challenge confirmation bias in retained selections.\n3. Evaluate plausibility against evidence rather than vividness, rate velocity, estimate impact ranges under stated assumptions, assess current preparedness, define observable trigger conditions, and challenge both dismissal and alarm.\n4. Trace promotions and closures to their evidence, verify trigger conditions have named observers and a cadence, confirm dissent remains visible, reconcile promotions with register entries, and return unsupported dispositions with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the scan horizon, domains and objectives covered, source list with reliability notes, qualification criteria, exclusions and their rationale, accountable scanner, and known blind spots. Also record scan sources.\n2. Document the signal inventory with source and date attribution, screening basis and criteria applied, retained and rejected signals with reasons, convergence observations, and source coverage that returned nothing.\n3. Document plausibility reasoning, velocity rating, impact range with assumptions, preparedness assessment, disposition, trigger conditions with named observers, and dissenting views retained. Also record watchlist disposition.\n4. Capture the authorized reviewer, the scan summary, accepted dispositions, effective scan date, next scan cadence, promoted register references, retained watchlist entries, blind spots, owners, and due dates. Also record horizon scan summary.\n\n**Exit criteria**\nRisk horizon review panel provides variance: The horizon and source coverage are explicit, qualification criteria are stated in advance of screening, and blind spots are visible rather than implied. Every retained signal is traceable to a dated source, rejections are reasoned rather than silent, and the candidate watchlist is ready for assessment. An approver accepts that each disposition follows from the assessed evidence, trigger conditions are observable and owned, and uncertainty is expressed rather than resolved by assertion. The authorized reviewer accepts the scan as a traceable record of forward-looking analysis, watchlist and register stay reconciled, and closure implies no assurance that unscanned exposures do not exist.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"AI model governance gap","itemType":"risk","kind":"related"},{"itemTitle":"New Application Architecture Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Business continuity outage","itemType":"risk","name":"Emerging Risk & Horizon Scan — Business continuity outage — prior cycle","templateName":"Emerging Risk & Horizon Scan","templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","description":"Emerging Risk & Horizon Scan for Business continuity outage (prior cycle).","status":"COMPLETED","displayOrder":133,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve scan record and watchlist disposition","description":null,"summary":null,"instructions":"**Objective**\nApprove scan record and watchlist disposition. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, strategy and objective statements, prior scan output and watchlist, regulatory and technology intelligence, peer and industry reporting, threat feeds, scenario libraries, and the risk taxonomy.\n2. Use the agreed source list, published intelligence and reporting, internal incident and near-miss data, stakeholder observations, prior watchlist entries and their status, and the qualification criteria.\n3. Use the screened watchlist, scenario analysis, existing control and continuity capability, exposure and dependency maps, expert input, comparable events elsewhere, and the approved risk criteria.\n4. Review all stage records, the signal inventory and its attribution, screening rejections, plausibility and velocity reasoning, dispositions, trigger conditions, dissenting views, and declared blind spots.\n\n**Procedure**\n1. Fix the horizon window, select the domains and objectives in scope, enumerate the sources to be consulted with their reliability, define the signal qualification criteria, and document sources deliberately excluded.\n2. Record each signal with its source and date, apply the qualification criteria consistently, retain signals that fail screening with the reason, look for convergence between weak signals, and challenge confirmation bias in retained selections.\n3. Evaluate plausibility against evidence rather than vividness, rate velocity, estimate impact ranges under stated assumptions, assess current preparedness, define observable trigger conditions, and challenge both dismissal and alarm.\n4. Trace promotions and closures to their evidence, verify trigger conditions have named observers and a cadence, confirm dissent remains visible, reconcile promotions with register entries, and return unsupported dispositions with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the scan horizon, domains and objectives covered, source list with reliability notes, qualification criteria, exclusions and their rationale, accountable scanner, and known blind spots. Also record scan sources.\n2. Document the signal inventory with source and date attribution, screening basis and criteria applied, retained and rejected signals with reasons, convergence observations, and source coverage that returned nothing.\n3. Document plausibility reasoning, velocity rating, impact range with assumptions, preparedness assessment, disposition, trigger conditions with named observers, and dissenting views retained. Also record watchlist disposition.\n4. Capture the authorized reviewer, the scan summary, accepted dispositions, effective scan date, next scan cadence, promoted register references, retained watchlist entries, blind spots, owners, and due dates. Also record horizon scan summary.\n\n**Exit criteria**\nRisk horizon review panel provides variance: The horizon and source coverage are explicit, qualification criteria are stated in advance of screening, and blind spots are visible rather than implied. Every retained signal is traceable to a dated source, rejections are reasoned rather than silent, and the candidate watchlist is ready for assessment. An approver accepts that each disposition follows from the assessed evidence, trigger conditions are observable and owned, and uncertainty is expressed rather than resolved by assertion. The authorized reviewer accepts the scan as a traceable record of forward-looking analysis, watchlist and register stay reconciled, and closure implies no assurance that unscanned exposures do not exist.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Business continuity outage","itemType":"risk","kind":"related"},{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Unrated emerging risk","itemType":"risk","name":"Emerging Risk & Horizon Scan — Unrated emerging risk — current cycle","templateName":"Emerging Risk & Horizon Scan","templateSourceId":"coworkcanvas:template:emerging-risk-horizon-scan","description":"Emerging Risk & Horizon Scan for Unrated emerging risk (current cycle).","status":"ACTIVE","displayOrder":132,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve scan record and watchlist disposition","description":null,"summary":null,"instructions":"**Objective**\nApprove scan record and watchlist disposition. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, strategy and objective statements, prior scan output and watchlist, regulatory and technology intelligence, peer and industry reporting, threat feeds, scenario libraries, and the risk taxonomy.\n2. Use the agreed source list, published intelligence and reporting, internal incident and near-miss data, stakeholder observations, prior watchlist entries and their status, and the qualification criteria.\n3. Use the screened watchlist, scenario analysis, existing control and continuity capability, exposure and dependency maps, expert input, comparable events elsewhere, and the approved risk criteria.\n4. Review all stage records, the signal inventory and its attribution, screening rejections, plausibility and velocity reasoning, dispositions, trigger conditions, dissenting views, and declared blind spots.\n\n**Procedure**\n1. Fix the horizon window, select the domains and objectives in scope, enumerate the sources to be consulted with their reliability, define the signal qualification criteria, and document sources deliberately excluded.\n2. Record each signal with its source and date, apply the qualification criteria consistently, retain signals that fail screening with the reason, look for convergence between weak signals, and challenge confirmation bias in retained selections.\n3. Evaluate plausibility against evidence rather than vividness, rate velocity, estimate impact ranges under stated assumptions, assess current preparedness, define observable trigger conditions, and challenge both dismissal and alarm.\n4. Trace promotions and closures to their evidence, verify trigger conditions have named observers and a cadence, confirm dissent remains visible, reconcile promotions with register entries, and return unsupported dispositions with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the scan horizon, domains and objectives covered, source list with reliability notes, qualification criteria, exclusions and their rationale, accountable scanner, and known blind spots. Also record scan sources.\n2. Document the signal inventory with source and date attribution, screening basis and criteria applied, retained and rejected signals with reasons, convergence observations, and source coverage that returned nothing.\n3. Document plausibility reasoning, velocity rating, impact range with assumptions, preparedness assessment, disposition, trigger conditions with named observers, and dissenting views retained. Also record watchlist disposition.\n4. Capture the authorized reviewer, the scan summary, accepted dispositions, effective scan date, next scan cadence, promoted register references, retained watchlist entries, blind spots, owners, and due dates. Also record horizon scan summary.\n\n**Exit criteria**\nRisk horizon review panel provides variance: The horizon and source coverage are explicit, qualification criteria are stated in advance of screening, and blind spots are visible rather than implied. Every retained signal is traceable to a dated source, rejections are reasoned rather than silent, and the candidate watchlist is ready for assessment. An approver accepts that each disposition follows from the assessed evidence, trigger conditions are observable and owned, and uncertainty is expressed rather than resolved by assertion. The authorized reviewer accepts the scan as a traceable record of forward-looking analysis, watchlist and register stay reconciled, and closure implies no assurance that unscanned exposures do not exist.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Unrated emerging risk","itemType":"risk","kind":"related"},{"itemTitle":"Policy Exception Approval","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Legacy system processing failure","itemType":"risk","name":"ERM Risk Identification & Register Refresh — Legacy system processing failure — current cycle","templateName":"ERM Risk Identification & Register Refresh","templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","description":"ERM Risk Identification & Register Refresh for Legacy system processing failure (current cycle).","status":"ACTIVE","displayOrder":142,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve register refresh record","description":null,"summary":null,"instructions":"**Objective**\nApprove register refresh record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the enterprise risk taxonomy, prior cycle output, strategy and objective statements, organizational structure, incidents, issues, audit results, control failures, external environment reports, and the approved risk criteria.\n2. Use workshop output, interview notes, incident and loss data, audit and assurance findings, control testing results, external threat and regulatory intelligence, strategic initiatives, and the current register.\n3. Use the consolidated candidate set, the taxonomy and domain vocabulary, organizational accountability maps, existing register entries and their owners, and the qualification criteria from the scoping stage.\n4. Review all stage records, the candidate inventory and its source attribution, duplicate dispositions, taxonomy placements, ownership nominations, watchlist referrals, and open coverage gaps.\n\n**Procedure**\n1. Fix the cycle boundaries, confirm which units and domains participate, reconcile the taxonomy version against the register, identify data sources and workshop participants, and document coverage exclusions with rationale.\n2. Normalize each candidate into a cause-event-impact statement, compare it against existing register entries, merge genuine duplicates, keep materially distinct exposures separate, and record why each merge or split was chosen.\n3. Assign category and subcategory, map affected domains, nominate an accountable owner with the authority to act, choose the register action, and route contested ownership or classification to the accountable role before advancing.\n4. Trace material additions and merges to their evidence, confirm every new entry has an accountable owner and a next assessment date, verify excluded scope remains visible, and return incomplete classification with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the cycle period, identification scope, taxonomy version, participating units, data sources, qualification criteria, exclusions, accountable facilitator, and known coverage gaps.\n2. Document the candidate inventory, source attribution for each candidate, duplicate disposition, merge and split rationale, withdrawn candidates, and candidates deferred to the watchlist.\n3. Record the taxonomy placement, register action, nominated owner, affected domains, prior entry references for merges and updates, contested classifications, and items routed to the watchlist.\n4. Capture the authorized reviewer, the refresh summary, accepted register actions, effective cycle date, next cycle cadence, watchlist referrals, open coverage gaps, owners, and due dates.\n\n**Exit criteria**\nRisk register owner provides approval: The cycle scope is explicit, the taxonomy and qualification criteria are agreed, and exclusions that could hide exposure are visible and assigned. Every candidate is traceable to a source, duplicates are resolved with stated reasoning, and the surviving set is ready for taxonomy placement. An approver accepts that each classification and ownership assignment follows from the consolidation evidence, and unresolved ownership is escalated rather than defaulted. The authorized reviewer accepts the refresh as a traceable record of identification work, the register can be updated consistently, and no assurance over completeness of risk identification is implied by closure.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Legacy system processing failure","itemType":"risk","kind":"related"},{"itemTitle":"Batch Processing Monitoring","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Revenue cut-off error","itemType":"risk","name":"ERM Risk Identification & Register Refresh — Revenue cut-off error — prior cycle","templateName":"ERM Risk Identification & Register Refresh","templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","description":"ERM Risk Identification & Register Refresh for Revenue cut-off error (prior cycle).","status":"COMPLETED","displayOrder":143,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve register refresh record","description":null,"summary":null,"instructions":"**Objective**\nApprove register refresh record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the enterprise risk taxonomy, prior cycle output, strategy and objective statements, organizational structure, incidents, issues, audit results, control failures, external environment reports, and the approved risk criteria.\n2. Use workshop output, interview notes, incident and loss data, audit and assurance findings, control testing results, external threat and regulatory intelligence, strategic initiatives, and the current register.\n3. Use the consolidated candidate set, the taxonomy and domain vocabulary, organizational accountability maps, existing register entries and their owners, and the qualification criteria from the scoping stage.\n4. Review all stage records, the candidate inventory and its source attribution, duplicate dispositions, taxonomy placements, ownership nominations, watchlist referrals, and open coverage gaps.\n\n**Procedure**\n1. Fix the cycle boundaries, confirm which units and domains participate, reconcile the taxonomy version against the register, identify data sources and workshop participants, and document coverage exclusions with rationale.\n2. Normalize each candidate into a cause-event-impact statement, compare it against existing register entries, merge genuine duplicates, keep materially distinct exposures separate, and record why each merge or split was chosen.\n3. Assign category and subcategory, map affected domains, nominate an accountable owner with the authority to act, choose the register action, and route contested ownership or classification to the accountable role before advancing.\n4. Trace material additions and merges to their evidence, confirm every new entry has an accountable owner and a next assessment date, verify excluded scope remains visible, and return incomplete classification with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the cycle period, identification scope, taxonomy version, participating units, data sources, qualification criteria, exclusions, accountable facilitator, and known coverage gaps.\n2. Document the candidate inventory, source attribution for each candidate, duplicate disposition, merge and split rationale, withdrawn candidates, and candidates deferred to the watchlist.\n3. Record the taxonomy placement, register action, nominated owner, affected domains, prior entry references for merges and updates, contested classifications, and items routed to the watchlist.\n4. Capture the authorized reviewer, the refresh summary, accepted register actions, effective cycle date, next cycle cadence, watchlist referrals, open coverage gaps, owners, and due dates.\n\n**Exit criteria**\nRisk register owner provides approval: The cycle scope is explicit, the taxonomy and qualification criteria are agreed, and exclusions that could hide exposure are visible and assigned. Every candidate is traceable to a source, duplicates are resolved with stated reasoning, and the surviving set is ready for taxonomy placement. An approver accepts that each classification and ownership assignment follows from the consolidation evidence, and unresolved ownership is escalated rather than defaulted. The authorized reviewer accepts the refresh as a traceable record of identification work, the register can be updated consistently, and no assurance over completeness of risk identification is implied by closure.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Revenue cut-off error","itemType":"risk","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Strategic acquisition integration","itemType":"risk","name":"ERM Risk Identification & Register Refresh — Strategic acquisition integration — next cycle","templateName":"ERM Risk Identification & Register Refresh","templateSourceId":"coworkcanvas:template:erm-risk-identification-register-refresh","description":"ERM Risk Identification & Register Refresh for Strategic acquisition integration (next cycle).","status":"DRAFT","displayOrder":141,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve register refresh record","description":null,"summary":null,"instructions":"**Objective**\nApprove register refresh record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the enterprise risk taxonomy, prior cycle output, strategy and objective statements, organizational structure, incidents, issues, audit results, control failures, external environment reports, and the approved risk criteria.\n2. Use workshop output, interview notes, incident and loss data, audit and assurance findings, control testing results, external threat and regulatory intelligence, strategic initiatives, and the current register.\n3. Use the consolidated candidate set, the taxonomy and domain vocabulary, organizational accountability maps, existing register entries and their owners, and the qualification criteria from the scoping stage.\n4. Review all stage records, the candidate inventory and its source attribution, duplicate dispositions, taxonomy placements, ownership nominations, watchlist referrals, and open coverage gaps.\n\n**Procedure**\n1. Fix the cycle boundaries, confirm which units and domains participate, reconcile the taxonomy version against the register, identify data sources and workshop participants, and document coverage exclusions with rationale.\n2. Normalize each candidate into a cause-event-impact statement, compare it against existing register entries, merge genuine duplicates, keep materially distinct exposures separate, and record why each merge or split was chosen.\n3. Assign category and subcategory, map affected domains, nominate an accountable owner with the authority to act, choose the register action, and route contested ownership or classification to the accountable role before advancing.\n4. Trace material additions and merges to their evidence, confirm every new entry has an accountable owner and a next assessment date, verify excluded scope remains visible, and return incomplete classification with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the cycle period, identification scope, taxonomy version, participating units, data sources, qualification criteria, exclusions, accountable facilitator, and known coverage gaps.\n2. Document the candidate inventory, source attribution for each candidate, duplicate disposition, merge and split rationale, withdrawn candidates, and candidates deferred to the watchlist.\n3. Record the taxonomy placement, register action, nominated owner, affected domains, prior entry references for merges and updates, contested classifications, and items routed to the watchlist.\n4. Capture the authorized reviewer, the refresh summary, accepted register actions, effective cycle date, next cycle cadence, watchlist referrals, open coverage gaps, owners, and due dates.\n\n**Exit criteria**\nRisk register owner provides approval: The cycle scope is explicit, the taxonomy and qualification criteria are agreed, and exclusions that could hide exposure are visible and assigned. Every candidate is traceable to a source, duplicates are resolved with stated reasoning, and the surviving set is ready for taxonomy placement. An approver accepts that each classification and ownership assignment follows from the consolidation evidence, and unresolved ownership is escalated rather than defaulted. The authorized reviewer accepts the refresh as a traceable record of identification work, the register can be updated consistently, and no assurance over completeness of risk identification is implied by closure.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Strategic acquisition integration","itemType":"risk","kind":"related"},{"itemTitle":"Production Change Approval","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Banana ERP","itemType":"system","name":"End-User Computing Inventory & Validation — Banana ERP — next cycle","templateName":"End-User Computing Inventory & Validation","templateSourceId":"coworkcanvas:template:euc-inventory-validation","description":"End-User Computing Inventory & Validation for Banana ERP (next cycle).","status":"DRAFT","displayOrder":151,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Test access, change and integrity controls","description":null,"summary":null,"instructions":"**Objective**\nTest access, change and integrity controls. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, process narratives and reporting data flows, the prior EUC inventory, file share and collaboration locations, report preparer interviews, and the EUC policy criteria.\n2. Use file and folder permissions, version history and change logs, formula audit or comparison tooling, input source reconciliation, review evidence by someone other than the preparer, and prior error history.\n\n**Procedure**\n1. Trace reporting outputs back to their inputs so undeclared spreadsheets are found rather than self-reported, rate criticality by reliance and complexity, and record locations searched that returned nothing.\n2. Inspect actual permissions rather than intended ones, compare current formulas against a known-good baseline where one exists, reconcile inputs to their source system, and confirm review was performed by someone other than the preparer.\n\n**Record in AssureSwarm**\n1. Capture the inventory period, EUC population with location and owner, criticality rating with reliance basis, tools newly identified since the prior inventory, search coverage, and known blind spots.\n2. Document permissions inspected per EUC, version and change traceability, formula integrity testing and its method, input reconciliation results, independent review evidence, and controls found absent.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is derived by tracing reporting inputs rather than by self-declaration, criticality reflects reliance, and search blind spots are declared rather than implied complete. Access is tested as configured rather than as intended, formula integrity is tested by comparison rather than inspection alone, and independent review is evidenced by identity.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve EUC validation record","description":null,"summary":null,"instructions":"**Objective**\nApprove EUC validation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the control testing results, the reliance placed on each output, error history and downstream impact, available platform alternatives, and the materiality of the balances or decisions affected.\n2. Review all stage records, the inventory derivation and blind spots, control evidence per EUC, reliance conclusions and their materiality basis, conditions with expiry, and remediation owners.\n\n**Procedure**\n1. Weigh control weaknesses against the materiality of the reliance rather than treating all EUCs alike, identify EUCs whose function belongs in a controlled system, and record conditions of reliance with expiry rather than open-ended acceptance.\n2. Trace each reliance conclusion to tested control evidence, verify conditions carry expiry dates, confirm blind spots and migration candidates carry owners, and return self-declared inventories with precise comments.\n\n**Record in AssureSwarm**\n1. Record the reliance conclusion per EUC, control weaknesses weighed against materiality, conditions of reliance with expiry, migration candidates, remediation with owners and dates, and outputs that should not be relied upon. Also record remediation detail.\n2. Capture the authorized reviewer, the summary, accepted reliance conclusions, effective inventory date, next inventory cadence, conditions and remediation with owners and dates, blind spots, and linked issues raised. Also record eUC validation summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that reliance is weighed against materiality, conditions carry expiry rather than being open-ended, and outputs judged unreliable are named rather than qualified into acceptance. The authorized reviewer accepts the record as evidence the EUC control operated, and closure implies no assurance over end-user tools the inventory did not reach.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Cornballer Revenue Engine","itemType":"system","name":"End-User Computing Inventory & Validation — Cornballer Revenue Engine — current cycle","templateName":"End-User Computing Inventory & Validation","templateSourceId":"coworkcanvas:template:euc-inventory-validation","description":"End-User Computing Inventory & Validation for Cornballer Revenue Engine (current cycle).","status":"ACTIVE","displayOrder":152,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Test access, change and integrity controls","description":null,"summary":null,"instructions":"**Objective**\nTest access, change and integrity controls. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, process narratives and reporting data flows, the prior EUC inventory, file share and collaboration locations, report preparer interviews, and the EUC policy criteria.\n2. Use file and folder permissions, version history and change logs, formula audit or comparison tooling, input source reconciliation, review evidence by someone other than the preparer, and prior error history.\n\n**Procedure**\n1. Trace reporting outputs back to their inputs so undeclared spreadsheets are found rather than self-reported, rate criticality by reliance and complexity, and record locations searched that returned nothing.\n2. Inspect actual permissions rather than intended ones, compare current formulas against a known-good baseline where one exists, reconcile inputs to their source system, and confirm review was performed by someone other than the preparer.\n\n**Record in AssureSwarm**\n1. Capture the inventory period, EUC population with location and owner, criticality rating with reliance basis, tools newly identified since the prior inventory, search coverage, and known blind spots.\n2. Document permissions inspected per EUC, version and change traceability, formula integrity testing and its method, input reconciliation results, independent review evidence, and controls found absent.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is derived by tracing reporting inputs rather than by self-declaration, criticality reflects reliance, and search blind spots are declared rather than implied complete. Access is tested as configured rather than as intended, formula integrity is tested by comparison rather than inspection alone, and independent review is evidenced by identity.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve EUC validation record","description":null,"summary":null,"instructions":"**Objective**\nApprove EUC validation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the control testing results, the reliance placed on each output, error history and downstream impact, available platform alternatives, and the materiality of the balances or decisions affected.\n2. Review all stage records, the inventory derivation and blind spots, control evidence per EUC, reliance conclusions and their materiality basis, conditions with expiry, and remediation owners.\n\n**Procedure**\n1. Weigh control weaknesses against the materiality of the reliance rather than treating all EUCs alike, identify EUCs whose function belongs in a controlled system, and record conditions of reliance with expiry rather than open-ended acceptance.\n2. Trace each reliance conclusion to tested control evidence, verify conditions carry expiry dates, confirm blind spots and migration candidates carry owners, and return self-declared inventories with precise comments.\n\n**Record in AssureSwarm**\n1. Record the reliance conclusion per EUC, control weaknesses weighed against materiality, conditions of reliance with expiry, migration candidates, remediation with owners and dates, and outputs that should not be relied upon. Also record remediation detail.\n2. Capture the authorized reviewer, the summary, accepted reliance conclusions, effective inventory date, next inventory cadence, conditions and remediation with owners and dates, blind spots, and linked issues raised. Also record eUC validation summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that reliance is weighed against materiality, conditions carry expiry rather than being open-ended, and outputs judged unreliable are named rather than qualified into acceptance. The authorized reviewer accepts the record as evidence the EUC control operated, and closure implies no assurance over end-user tools the inventory did not reach.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Model Home Data Lake","itemType":"system","name":"End-User Computing Inventory & Validation — Model Home Data Lake — prior cycle","templateName":"End-User Computing Inventory & Validation","templateSourceId":"coworkcanvas:template:euc-inventory-validation","description":"End-User Computing Inventory & Validation for Model Home Data Lake (prior cycle).","status":"COMPLETED","displayOrder":153,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Test access, change and integrity controls","description":null,"summary":null,"instructions":"**Objective**\nTest access, change and integrity controls. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, process narratives and reporting data flows, the prior EUC inventory, file share and collaboration locations, report preparer interviews, and the EUC policy criteria.\n2. Use file and folder permissions, version history and change logs, formula audit or comparison tooling, input source reconciliation, review evidence by someone other than the preparer, and prior error history.\n\n**Procedure**\n1. Trace reporting outputs back to their inputs so undeclared spreadsheets are found rather than self-reported, rate criticality by reliance and complexity, and record locations searched that returned nothing.\n2. Inspect actual permissions rather than intended ones, compare current formulas against a known-good baseline where one exists, reconcile inputs to their source system, and confirm review was performed by someone other than the preparer.\n\n**Record in AssureSwarm**\n1. Capture the inventory period, EUC population with location and owner, criticality rating with reliance basis, tools newly identified since the prior inventory, search coverage, and known blind spots.\n2. Document permissions inspected per EUC, version and change traceability, formula integrity testing and its method, input reconciliation results, independent review evidence, and controls found absent.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is derived by tracing reporting inputs rather than by self-declaration, criticality reflects reliance, and search blind spots are declared rather than implied complete. Access is tested as configured rather than as intended, formula integrity is tested by comparison rather than inspection alone, and independent review is evidenced by identity.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve EUC validation record","description":null,"summary":null,"instructions":"**Objective**\nApprove EUC validation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the control testing results, the reliance placed on each output, error history and downstream impact, available platform alternatives, and the materiality of the balances or decisions affected.\n2. Review all stage records, the inventory derivation and blind spots, control evidence per EUC, reliance conclusions and their materiality basis, conditions with expiry, and remediation owners.\n\n**Procedure**\n1. Weigh control weaknesses against the materiality of the reliance rather than treating all EUCs alike, identify EUCs whose function belongs in a controlled system, and record conditions of reliance with expiry rather than open-ended acceptance.\n2. Trace each reliance conclusion to tested control evidence, verify conditions carry expiry dates, confirm blind spots and migration candidates carry owners, and return self-declared inventories with precise comments.\n\n**Record in AssureSwarm**\n1. Record the reliance conclusion per EUC, control weaknesses weighed against materiality, conditions of reliance with expiry, migration candidates, remediation with owners and dates, and outputs that should not be relied upon. Also record remediation detail.\n2. Capture the authorized reviewer, the summary, accepted reliance conclusions, effective inventory date, next inventory cadence, conditions and remediation with owners and dates, blind spots, and linked issues raised. Also record eUC validation summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that reliance is weighed against materiality, conditions carry expiry rather than being open-ended, and outputs judged unreliable are named rather than qualified into acceptance. The authorized reviewer accepts the record as evidence the EUC control operated, and closure implies no assurance over end-user tools the inventory did not reach.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Accounts Payable","itemType":"fsli","name":"FSLI Significance Assessment — Accounts Payable — next cycle","templateName":"FSLI Significance Assessment","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","description":"FSLI Significance Assessment for Accounts Payable (next cycle).","status":"DRAFT","displayOrder":161,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve FSLI significance assessment","description":null,"summary":null,"instructions":"**Objective**\nApprove FSLI significance assessment. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the trial balance, consolidation mapping, financial statements and disclosures, chart of accounts, ledger extracts, reporting packages, prior scoping, organization changes, and materiality basis.\n2. Use approved materiality thresholds, population data, volatility, transaction volume and complexity, estimation uncertainty, fraud susceptibility, related parties, changes, errors, deficiencies, and disclosure sensitivity.\n3. Use population and risk analysis, financial statement presentation, accounting policies, process maps, system inventory, prior risk-control mappings, entity scope, service providers, and identified changes.\n4. Review all calculations, source reconciliations, qualitative analysis, proposed decision, mappings, reviewer comments, related line items, approved materiality, changes, and unresolved limitations.\n\n**Procedure**\n1. Reconcile the line item to financial reporting records, identify accounts and disclosures included, normalize currencies and periods, separate unusual or nonrecurring components, and verify completeness across entities and locations.\n2. Compare balances and disclosures to relevant thresholds, analyze composition and trends, identify concentrations and unusual entries, evaluate estimation and judgment, consider aggregation with related line items, and document countervailing factors.\n3. Select assertions exposed to reasonable misstatement risk, map transaction classes and close processes, identify locations and systems contributing material activity, consider entity-level and IT dependencies, and challenge unsupported roll-forwards.\n4. Reperform key calculations, challenge borderline and contradictory factors, confirm aggregation was considered, verify mapped coverage matches the approved decision, and return incomplete support rather than inferring assurance.\n\n**Record in AssureSwarm**\n1. Capture the fiscal period, population reference, balance or disclosure magnitude, component accounts, currencies, entities, locations, preparer, reconciliation, exclusions, and data limitations.\n2. Document calculations, thresholds, ratios, trends, qualitative factors, contradictory evidence, aggregation analysis, preliminary significance view, and any additional data requested.\n3. Record the proposed decision and rationale, relevant assertions, locations, processes, systems, risks and controls, aggregation relationships, coverage gaps, and required follow-up. Also record proposed scope decision.\n4. Capture the authorized reviewer, final decision, rationale, materiality basis, relevant assertions, locations, linked processes, systems, risks and controls, open actions, owners, and reassessment triggers. Also record assessment conclusion and rationale.\n\n**Exit criteria**\nSOX scoping reviewer provides approval: The population agrees to authoritative reporting records, aggregation and exclusions are transparent, and quantitative analysis can proceed from a complete supported basis. The preliminary view is reproducible from cited data, both quantitative and qualitative factors are addressed, and unresolved factors are assigned before assertion mapping. An approver accepts that the proposed scope and mappings follow from the evidence, or returns specific unsupported elements for further analysis before final decision. The authorized reviewer accepts a traceable management scoping record, downstream planning can use the mapped decision consistently, and closure does not provide certification or an audit opinion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Accounts Payable","itemType":"fsli","kind":"related"},{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Accounts Receivable","itemType":"fsli","name":"FSLI Significance Assessment — Accounts Receivable — current cycle","templateName":"FSLI Significance Assessment","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","description":"FSLI Significance Assessment for Accounts Receivable (current cycle).","status":"ACTIVE","displayOrder":162,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve FSLI significance assessment","description":null,"summary":null,"instructions":"**Objective**\nApprove FSLI significance assessment. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the trial balance, consolidation mapping, financial statements and disclosures, chart of accounts, ledger extracts, reporting packages, prior scoping, organization changes, and materiality basis.\n2. Use approved materiality thresholds, population data, volatility, transaction volume and complexity, estimation uncertainty, fraud susceptibility, related parties, changes, errors, deficiencies, and disclosure sensitivity.\n3. Use population and risk analysis, financial statement presentation, accounting policies, process maps, system inventory, prior risk-control mappings, entity scope, service providers, and identified changes.\n4. Review all calculations, source reconciliations, qualitative analysis, proposed decision, mappings, reviewer comments, related line items, approved materiality, changes, and unresolved limitations.\n\n**Procedure**\n1. Reconcile the line item to financial reporting records, identify accounts and disclosures included, normalize currencies and periods, separate unusual or nonrecurring components, and verify completeness across entities and locations.\n2. Compare balances and disclosures to relevant thresholds, analyze composition and trends, identify concentrations and unusual entries, evaluate estimation and judgment, consider aggregation with related line items, and document countervailing factors.\n3. Select assertions exposed to reasonable misstatement risk, map transaction classes and close processes, identify locations and systems contributing material activity, consider entity-level and IT dependencies, and challenge unsupported roll-forwards.\n4. Reperform key calculations, challenge borderline and contradictory factors, confirm aggregation was considered, verify mapped coverage matches the approved decision, and return incomplete support rather than inferring assurance.\n\n**Record in AssureSwarm**\n1. Capture the fiscal period, population reference, balance or disclosure magnitude, component accounts, currencies, entities, locations, preparer, reconciliation, exclusions, and data limitations.\n2. Document calculations, thresholds, ratios, trends, qualitative factors, contradictory evidence, aggregation analysis, preliminary significance view, and any additional data requested.\n3. Record the proposed decision and rationale, relevant assertions, locations, processes, systems, risks and controls, aggregation relationships, coverage gaps, and required follow-up. Also record proposed scope decision.\n4. Capture the authorized reviewer, final decision, rationale, materiality basis, relevant assertions, locations, linked processes, systems, risks and controls, open actions, owners, and reassessment triggers. Also record assessment conclusion and rationale.\n\n**Exit criteria**\nSOX scoping reviewer provides approval: The population agrees to authoritative reporting records, aggregation and exclusions are transparent, and quantitative analysis can proceed from a complete supported basis. The preliminary view is reproducible from cited data, both quantitative and qualitative factors are addressed, and unresolved factors are assigned before assertion mapping. An approver accepts that the proposed scope and mappings follow from the evidence, or returns specific unsupported elements for further analysis before final decision. The authorized reviewer accepts a traceable management scoping record, downstream planning can use the mapped decision consistently, and closure does not provide certification or an audit opinion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Accounts Receivable","itemType":"fsli","kind":"related"},{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Cash Collections","itemType":"fsli","name":"FSLI Significance Assessment — Cash Collections — prior cycle","templateName":"FSLI Significance Assessment","templateSourceId":"coworkcanvas:template:fsli-significance-assessment","description":"FSLI Significance Assessment for Cash Collections (prior cycle).","status":"COMPLETED","displayOrder":163,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve FSLI significance assessment","description":null,"summary":null,"instructions":"**Objective**\nApprove FSLI significance assessment. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the trial balance, consolidation mapping, financial statements and disclosures, chart of accounts, ledger extracts, reporting packages, prior scoping, organization changes, and materiality basis.\n2. Use approved materiality thresholds, population data, volatility, transaction volume and complexity, estimation uncertainty, fraud susceptibility, related parties, changes, errors, deficiencies, and disclosure sensitivity.\n3. Use population and risk analysis, financial statement presentation, accounting policies, process maps, system inventory, prior risk-control mappings, entity scope, service providers, and identified changes.\n4. Review all calculations, source reconciliations, qualitative analysis, proposed decision, mappings, reviewer comments, related line items, approved materiality, changes, and unresolved limitations.\n\n**Procedure**\n1. Reconcile the line item to financial reporting records, identify accounts and disclosures included, normalize currencies and periods, separate unusual or nonrecurring components, and verify completeness across entities and locations.\n2. Compare balances and disclosures to relevant thresholds, analyze composition and trends, identify concentrations and unusual entries, evaluate estimation and judgment, consider aggregation with related line items, and document countervailing factors.\n3. Select assertions exposed to reasonable misstatement risk, map transaction classes and close processes, identify locations and systems contributing material activity, consider entity-level and IT dependencies, and challenge unsupported roll-forwards.\n4. Reperform key calculations, challenge borderline and contradictory factors, confirm aggregation was considered, verify mapped coverage matches the approved decision, and return incomplete support rather than inferring assurance.\n\n**Record in AssureSwarm**\n1. Capture the fiscal period, population reference, balance or disclosure magnitude, component accounts, currencies, entities, locations, preparer, reconciliation, exclusions, and data limitations.\n2. Document calculations, thresholds, ratios, trends, qualitative factors, contradictory evidence, aggregation analysis, preliminary significance view, and any additional data requested.\n3. Record the proposed decision and rationale, relevant assertions, locations, processes, systems, risks and controls, aggregation relationships, coverage gaps, and required follow-up. Also record proposed scope decision.\n4. Capture the authorized reviewer, final decision, rationale, materiality basis, relevant assertions, locations, linked processes, systems, risks and controls, open actions, owners, and reassessment triggers. Also record assessment conclusion and rationale.\n\n**Exit criteria**\nSOX scoping reviewer provides approval: The population agrees to authoritative reporting records, aggregation and exclusions are transparent, and quantitative analysis can proceed from a complete supported basis. The preliminary view is reproducible from cited data, both quantitative and qualitative factors are addressed, and unresolved factors are assigned before assertion mapping. An approver accepts that the proposed scope and mappings follow from the evidence, or returns specific unsupported elements for further analysis before final decision. The authorized reviewer accepts a traceable management scoping record, downstream planning can use the mapped decision consistently, and closure does not provide certification or an audit opinion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cash Collections","itemType":"fsli","kind":"related"},{"itemTitle":"Vendor Risk Review","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"GOB Security Monitoring","itemType":"system","name":"Incident & Problem Management — GOB Security Monitoring — next cycle","templateName":"Incident & Problem Management","templateSourceId":"coworkcanvas:template:incident-problem-management","description":"Incident & Problem Management for GOB Security Monitoring (next cycle).","status":"DRAFT","displayOrder":171,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Record response and containment","description":null,"summary":null,"instructions":"**Objective**\nRecord response and containment. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident ticket and its timeline, monitoring alerts or the reporting source, affected system and data inventory, the severity matrix, and regulatory notification thresholds.\n2. Use the incident timeline and ticket updates, system and access logs during the incident, containment actions and their timestamps, communications and notifications sent, and the response targets in policy.\n\n**Procedure**\n1. Establish detection time from the alert or report rather than from ticket creation, test the assigned severity against the matrix, identify data categories affected, and flag under-classification that would relax response targets.\n2. Reconstruct the timeline from logs rather than from ticket narrative, measure each interval against the target for the severity, confirm required notifications were sent inside their windows, and record evidence preserved for later analysis.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, detection time and source, systems and data affected, severity with matrix rationale, notification duties triggered, and classification challenges raised.\n2. Document response actions with timestamps, intervals measured against targets, containment status and its basis, notifications sent with recipients and times, evidence preserved, and targets missed. Also record response actions and timeline.\n\n**Exit criteria**\nIncident commander provides expertise: Detection time is evidenced independently of ticket creation, severity follows the matrix, and notification duties are identified before the response window closes. The timeline is reconstructed from logs, intervals are measured against severity targets, missed notifications are recorded as exceptions, and evidence is preserved rather than overwritten by recovery.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"GOB Security Monitoring","itemType":"system","kind":"related"},{"itemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve incident record","description":null,"summary":null,"instructions":"**Objective**\nApprove incident record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the reconstructed timeline, system and change records preceding the incident, prior incidents with similar signatures, known problem records, and control failures the incident revealed.\n2. Review all stage records, detection evidence, severity rationale, measured intervals, notification evidence, root cause analysis, prior incident matches, and preventive actions with owners.\n\n**Procedure**\n1. Distinguish trigger from underlying cause, search prior incidents for the same signature before declaring a novel cause, identify which control should have prevented or detected it, and record undetermined causes as undetermined rather than plausible.\n2. Trace the timeline to log evidence, verify missed targets and notifications are recorded as exceptions, confirm preventive actions address the named control failure, and return trigger-only cause analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the root cause result and its evidence, prior incident matches, the control that failed to prevent or detect, preventive actions with owners and dates, and cause elements that remain undetermined.\n2. Capture the authorized reviewer, the summary, accepted root cause result, closure date, targets missed, control failures identified, preventive actions with owners and dates, and linked issues raised. Also record incident summary.\n\n**Exit criteria**\nProblem-management reviewer provides approval: An approver accepts that cause analysis distinguishes trigger from underlying cause and searched for recurrence, the failed control is named, and undetermined causes are stated rather than assumed. The authorized reviewer accepts the record as evidence the incident control operated, and closure implies no assurance that the underlying cause is remediated until preventive actions complete.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"GOB Security Monitoring","itemType":"system","kind":"related"},{"itemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Lucille Identity Cloud","itemType":"system","name":"Incident & Problem Management — Lucille Identity Cloud — prior cycle","templateName":"Incident & Problem Management","templateSourceId":"coworkcanvas:template:incident-problem-management","description":"Incident & Problem Management for Lucille Identity Cloud (prior cycle).","status":"COMPLETED","displayOrder":173,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Record response and containment","description":null,"summary":null,"instructions":"**Objective**\nRecord response and containment. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident ticket and its timeline, monitoring alerts or the reporting source, affected system and data inventory, the severity matrix, and regulatory notification thresholds.\n2. Use the incident timeline and ticket updates, system and access logs during the incident, containment actions and their timestamps, communications and notifications sent, and the response targets in policy.\n\n**Procedure**\n1. Establish detection time from the alert or report rather than from ticket creation, test the assigned severity against the matrix, identify data categories affected, and flag under-classification that would relax response targets.\n2. Reconstruct the timeline from logs rather than from ticket narrative, measure each interval against the target for the severity, confirm required notifications were sent inside their windows, and record evidence preserved for later analysis.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, detection time and source, systems and data affected, severity with matrix rationale, notification duties triggered, and classification challenges raised.\n2. Document response actions with timestamps, intervals measured against targets, containment status and its basis, notifications sent with recipients and times, evidence preserved, and targets missed. Also record response actions and timeline.\n\n**Exit criteria**\nIncident commander provides expertise: Detection time is evidenced independently of ticket creation, severity follows the matrix, and notification duties are identified before the response window closes. The timeline is reconstructed from logs, intervals are measured against severity targets, missed notifications are recorded as exceptions, and evidence is preserved rather than overwritten by recovery.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"},{"itemTitle":"Authenticate all users with multi-factor authentication","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve incident record","description":null,"summary":null,"instructions":"**Objective**\nApprove incident record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the reconstructed timeline, system and change records preceding the incident, prior incidents with similar signatures, known problem records, and control failures the incident revealed.\n2. Review all stage records, detection evidence, severity rationale, measured intervals, notification evidence, root cause analysis, prior incident matches, and preventive actions with owners.\n\n**Procedure**\n1. Distinguish trigger from underlying cause, search prior incidents for the same signature before declaring a novel cause, identify which control should have prevented or detected it, and record undetermined causes as undetermined rather than plausible.\n2. Trace the timeline to log evidence, verify missed targets and notifications are recorded as exceptions, confirm preventive actions address the named control failure, and return trigger-only cause analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the root cause result and its evidence, prior incident matches, the control that failed to prevent or detect, preventive actions with owners and dates, and cause elements that remain undetermined.\n2. Capture the authorized reviewer, the summary, accepted root cause result, closure date, targets missed, control failures identified, preventive actions with owners and dates, and linked issues raised. Also record incident summary.\n\n**Exit criteria**\nProblem-management reviewer provides approval: An approver accepts that cause analysis distinguishes trigger from underlying cause and searched for recurrence, the failed control is named, and undetermined causes are stated rather than assumed. The authorized reviewer accepts the record as evidence the incident control operated, and closure implies no assurance that the underlying cause is remediated until preventive actions complete.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"},{"itemTitle":"Authenticate all users with multi-factor authentication","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Sudden Valley Network","itemType":"system","name":"Incident & Problem Management — Sudden Valley Network — current cycle","templateName":"Incident & Problem Management","templateSourceId":"coworkcanvas:template:incident-problem-management","description":"Incident & Problem Management for Sudden Valley Network (current cycle).","status":"ACTIVE","displayOrder":172,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Record response and containment","description":null,"summary":null,"instructions":"**Objective**\nRecord response and containment. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident ticket and its timeline, monitoring alerts or the reporting source, affected system and data inventory, the severity matrix, and regulatory notification thresholds.\n2. Use the incident timeline and ticket updates, system and access logs during the incident, containment actions and their timestamps, communications and notifications sent, and the response targets in policy.\n\n**Procedure**\n1. Establish detection time from the alert or report rather than from ticket creation, test the assigned severity against the matrix, identify data categories affected, and flag under-classification that would relax response targets.\n2. Reconstruct the timeline from logs rather than from ticket narrative, measure each interval against the target for the severity, confirm required notifications were sent inside their windows, and record evidence preserved for later analysis.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, detection time and source, systems and data affected, severity with matrix rationale, notification duties triggered, and classification challenges raised.\n2. Document response actions with timestamps, intervals measured against targets, containment status and its basis, notifications sent with recipients and times, evidence preserved, and targets missed. Also record response actions and timeline.\n\n**Exit criteria**\nIncident commander provides expertise: Detection time is evidenced independently of ticket creation, severity follows the matrix, and notification duties are identified before the response window closes. The timeline is reconstructed from logs, intervals are measured against severity targets, missed notifications are recorded as exceptions, and evidence is preserved rather than overwritten by recovery.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Sudden Valley Network","itemType":"system","kind":"related"},{"itemTitle":"Availability & capacity management (SLA)","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve incident record","description":null,"summary":null,"instructions":"**Objective**\nApprove incident record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the reconstructed timeline, system and change records preceding the incident, prior incidents with similar signatures, known problem records, and control failures the incident revealed.\n2. Review all stage records, detection evidence, severity rationale, measured intervals, notification evidence, root cause analysis, prior incident matches, and preventive actions with owners.\n\n**Procedure**\n1. Distinguish trigger from underlying cause, search prior incidents for the same signature before declaring a novel cause, identify which control should have prevented or detected it, and record undetermined causes as undetermined rather than plausible.\n2. Trace the timeline to log evidence, verify missed targets and notifications are recorded as exceptions, confirm preventive actions address the named control failure, and return trigger-only cause analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the root cause result and its evidence, prior incident matches, the control that failed to prevent or detect, preventive actions with owners and dates, and cause elements that remain undetermined.\n2. Capture the authorized reviewer, the summary, accepted root cause result, closure date, targets missed, control failures identified, preventive actions with owners and dates, and linked issues raised. Also record incident summary.\n\n**Exit criteria**\nProblem-management reviewer provides approval: An approver accepts that cause analysis distinguishes trigger from underlying cause and searched for recurrence, the failed control is named, and undetermined causes are stated rather than assumed. The authorized reviewer accepts the record as evidence the incident control operated, and closure implies no assurance that the underlying cause is remediated until preventive actions complete.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Sudden Valley Network","itemType":"system","kind":"related"},{"itemTitle":"Availability & capacity management (SLA)","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 Certification Readiness","itemType":"audit","name":"ISO 27001 Certification Readiness — ISO 27001 Certification Readiness — next cycle","templateName":"ISO 27001 Certification Readiness","templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","description":"ISO 27001 Certification Readiness for ISO 27001 Certification Readiness (next cycle).","status":"DRAFT","displayOrder":181,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess clauses and Statement of Applicability","description":null,"summary":null,"instructions":"**Objective**\nAssess clauses and Statement of Applicability. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved ISMS scope, context and interested-party analysis, organization and asset inventories, architecture, legal and contractual obligations, risk methodology, prior audits, incidents, and change plans.\n2. Use the scoped ISMS, policies and objectives, risk methodology and assessment, treatment plan, Statement of Applicability, Annex A controls, documented processes, competence records, monitoring, and corrective actions.\n\n**Procedure**\n1. Reconcile the scope to actual activities and dependencies, identify outsourced processes and interfaces, verify leadership ownership, select the applicable standard edition and certification stage, and document defensible exclusions or constraints.\n2. Evaluate each clause requirement, trace risks to treatment decisions, verify inclusion and exclusion rationale in the Statement of Applicability, inspect representative implementation evidence, and identify missing or contradictory documentation and practice.\n\n**Record in AssureSwarm**\n1. Capture the standard reference, scope statement, products, entities, locations, systems, interfaces, outsourced dependencies, interested parties, certification objective, target dates, exclusions, changes, and limitations. Also record standard edition and criteria; iSMS scope statement.\n2. Link the clause assessment and Statement of Applicability, document evidence, implementation observations, risk-treatment alignment, exclusions, owners, gaps, and required document or practice updates. Also record statement of Applicability reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The ISMS and readiness boundary are coherent and approved inputs, material interfaces are visible, and criteria or scope ambiguities are resolved before clause assessment. Every clause and applicability decision has evidence or a visible gap, risk treatment and control status reconcile, and unsupported exclusions are assigned for correction.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 Certification Readiness","itemType":"audit","kind":"related"},{"itemTitle":"New Application Architecture Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve ISO 27001 readiness record","description":null,"summary":null,"instructions":"**Objective**\nApprove ISO 27001 readiness record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review internal audit program and results, management-review minutes and inputs, security objectives and measures, nonconformities, corrective actions, competence records, document control, gap tracker, and certification-body prerequisites.\n2. Review all stage records, current scope and criteria, clause evidence, Statement of Applicability, treatment plan, internal audit, management review, corrective actions, readiness decision, and certification-body coordination.\n\n**Procedure**\n1. Check required assurance cycles and inputs, validate corrective-action root causes and evidence, assess whether records cover the scoped ISMS, identify open major dependencies, sequence closure and operating history, and challenge schedule pressure.\n2. Trace material readiness statements to evidence, confirm gaps and unsupported exclusions remain visible, reconcile document versions and owners, verify conditions and timing, and return incomplete or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Document the readiness decision, internal audit and management-review status, gaps and nonconformities, corrective actions, evidence history, competence or document issues, conditions, owners, and due dates. Also record certification readiness.\n2. Capture the authorized reviewer, final scope, criteria and Statement of Applicability references, readiness result, conditions, gaps and corrective actions, owners, dates, proposed certification next step, and reassessment triggers. Also record iSO 27001 readiness summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the supported readiness disposition, all conditions are owned and time-bound, and readiness is not described as certification or a registrar conclusion. The authorized reviewer accepts an internal readiness record for planning; workflow closure neither certifies the ISMS nor predicts or replaces the certification body’s determination.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 Certification Readiness","itemType":"audit","kind":"related"},{"itemTitle":"New Application Architecture Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","name":"ISO 27001 Certification Readiness — Identity and Access Management Audit — current cycle","templateName":"ISO 27001 Certification Readiness","templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","description":"ISO 27001 Certification Readiness for Identity and Access Management Audit (current cycle).","status":"ACTIVE","displayOrder":182,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess clauses and Statement of Applicability","description":null,"summary":null,"instructions":"**Objective**\nAssess clauses and Statement of Applicability. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved ISMS scope, context and interested-party analysis, organization and asset inventories, architecture, legal and contractual obligations, risk methodology, prior audits, incidents, and change plans.\n2. Use the scoped ISMS, policies and objectives, risk methodology and assessment, treatment plan, Statement of Applicability, Annex A controls, documented processes, competence records, monitoring, and corrective actions.\n\n**Procedure**\n1. Reconcile the scope to actual activities and dependencies, identify outsourced processes and interfaces, verify leadership ownership, select the applicable standard edition and certification stage, and document defensible exclusions or constraints.\n2. Evaluate each clause requirement, trace risks to treatment decisions, verify inclusion and exclusion rationale in the Statement of Applicability, inspect representative implementation evidence, and identify missing or contradictory documentation and practice.\n\n**Record in AssureSwarm**\n1. Capture the standard reference, scope statement, products, entities, locations, systems, interfaces, outsourced dependencies, interested parties, certification objective, target dates, exclusions, changes, and limitations. Also record standard edition and criteria; iSMS scope statement.\n2. Link the clause assessment and Statement of Applicability, document evidence, implementation observations, risk-treatment alignment, exclusions, owners, gaps, and required document or practice updates. Also record statement of Applicability reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The ISMS and readiness boundary are coherent and approved inputs, material interfaces are visible, and criteria or scope ambiguities are resolved before clause assessment. Every clause and applicability decision has evidence or a visible gap, risk treatment and control status reconcile, and unsupported exclusions are assigned for correction.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve ISO 27001 readiness record","description":null,"summary":null,"instructions":"**Objective**\nApprove ISO 27001 readiness record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review internal audit program and results, management-review minutes and inputs, security objectives and measures, nonconformities, corrective actions, competence records, document control, gap tracker, and certification-body prerequisites.\n2. Review all stage records, current scope and criteria, clause evidence, Statement of Applicability, treatment plan, internal audit, management review, corrective actions, readiness decision, and certification-body coordination.\n\n**Procedure**\n1. Check required assurance cycles and inputs, validate corrective-action root causes and evidence, assess whether records cover the scoped ISMS, identify open major dependencies, sequence closure and operating history, and challenge schedule pressure.\n2. Trace material readiness statements to evidence, confirm gaps and unsupported exclusions remain visible, reconcile document versions and owners, verify conditions and timing, and return incomplete or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Document the readiness decision, internal audit and management-review status, gaps and nonconformities, corrective actions, evidence history, competence or document issues, conditions, owners, and due dates. Also record certification readiness.\n2. Capture the authorized reviewer, final scope, criteria and Statement of Applicability references, readiness result, conditions, gaps and corrective actions, owners, dates, proposed certification next step, and reassessment triggers. Also record iSO 27001 readiness summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the supported readiness disposition, all conditions are owned and time-bound, and readiness is not described as certification or a registrar conclusion. The authorized reviewer accepts an internal readiness record for planning; workflow closure neither certifies the ISMS nor predicts or replaces the certification body’s determination.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Incident Response Investigation","itemType":"audit","name":"ISO 27001 Certification Readiness — Incident Response Investigation — prior cycle","templateName":"ISO 27001 Certification Readiness","templateSourceId":"coworkcanvas:template:iso27001-certification-readiness","description":"ISO 27001 Certification Readiness for Incident Response Investigation (prior cycle).","status":"COMPLETED","displayOrder":183,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess clauses and Statement of Applicability","description":null,"summary":null,"instructions":"**Objective**\nAssess clauses and Statement of Applicability. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved ISMS scope, context and interested-party analysis, organization and asset inventories, architecture, legal and contractual obligations, risk methodology, prior audits, incidents, and change plans.\n2. Use the scoped ISMS, policies and objectives, risk methodology and assessment, treatment plan, Statement of Applicability, Annex A controls, documented processes, competence records, monitoring, and corrective actions.\n\n**Procedure**\n1. Reconcile the scope to actual activities and dependencies, identify outsourced processes and interfaces, verify leadership ownership, select the applicable standard edition and certification stage, and document defensible exclusions or constraints.\n2. Evaluate each clause requirement, trace risks to treatment decisions, verify inclusion and exclusion rationale in the Statement of Applicability, inspect representative implementation evidence, and identify missing or contradictory documentation and practice.\n\n**Record in AssureSwarm**\n1. Capture the standard reference, scope statement, products, entities, locations, systems, interfaces, outsourced dependencies, interested parties, certification objective, target dates, exclusions, changes, and limitations. Also record standard edition and criteria; iSMS scope statement.\n2. Link the clause assessment and Statement of Applicability, document evidence, implementation observations, risk-treatment alignment, exclusions, owners, gaps, and required document or practice updates. Also record statement of Applicability reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The ISMS and readiness boundary are coherent and approved inputs, material interfaces are visible, and criteria or scope ambiguities are resolved before clause assessment. Every clause and applicability decision has evidence or a visible gap, risk treatment and control status reconcile, and unsupported exclusions are assigned for correction.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Incident Response Investigation","itemType":"audit","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve ISO 27001 readiness record","description":null,"summary":null,"instructions":"**Objective**\nApprove ISO 27001 readiness record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review internal audit program and results, management-review minutes and inputs, security objectives and measures, nonconformities, corrective actions, competence records, document control, gap tracker, and certification-body prerequisites.\n2. Review all stage records, current scope and criteria, clause evidence, Statement of Applicability, treatment plan, internal audit, management review, corrective actions, readiness decision, and certification-body coordination.\n\n**Procedure**\n1. Check required assurance cycles and inputs, validate corrective-action root causes and evidence, assess whether records cover the scoped ISMS, identify open major dependencies, sequence closure and operating history, and challenge schedule pressure.\n2. Trace material readiness statements to evidence, confirm gaps and unsupported exclusions remain visible, reconcile document versions and owners, verify conditions and timing, and return incomplete or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Document the readiness decision, internal audit and management-review status, gaps and nonconformities, corrective actions, evidence history, competence or document issues, conditions, owners, and due dates. Also record certification readiness.\n2. Capture the authorized reviewer, final scope, criteria and Statement of Applicability references, readiness result, conditions, gaps and corrective actions, owners, dates, proposed certification next step, and reassessment triggers. Also record iSO 27001 readiness summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the supported readiness disposition, all conditions are owned and time-bound, and readiness is not described as certification or a registrar conclusion. The authorized reviewer accepts an internal readiness record for planning; workflow closure neither certifies the ISMS nor predicts or replaces the certification body’s determination.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Incident Response Investigation","itemType":"audit","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Quarterly access recertification missed two finance approvers","itemType":"issue","name":"Issue Triage & Disposition — Quarterly access recertification missed two finance approvers — next cycle","templateName":"Issue Triage & Disposition","templateSourceId":"coworkcanvas:template:issue-triage-disposition","description":"Issue Triage & Disposition for Quarterly access recertification missed two finance approvers (next cycle).","status":"DRAFT","displayOrder":191,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess severity and cause","description":null,"summary":null,"instructions":"**Objective**\nAssess severity and cause. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Issue item, source report, exception evidence, incident or complaint records, audit work, policies, requirements, controls, affected transactions, prior issues, and reporter representations.\n2. Use the substantiated condition, affected population, severity criteria, loss or exposure data, control results, related risks, issue history, process and system changes, management responses, and specialist input.\n\n**Procedure**\n1. Validate the reported condition against source evidence, distinguish symptoms from the underlying problem, identify applicable criteria, bound the affected population and period, remove duplicates, and initiate urgent containment when warranted.\n2. Apply the approved severity rubric, quantify or bound exposure, analyze recurrence and aggregation, test proposed causes using evidence, distinguish causal factors from symptoms, and identify uncertainty that could change priority or reporting.\n\n**Record in AssureSwarm**\n1. Capture intake source, issue statement, condition, criteria, affected items and period, reporter, accountable owner, duplicate analysis, immediate safeguards, evidence references, and unresolved questions.\n2. Document severity and rationale, actual and potential impact, affected stakeholders, pervasiveness, recurrence, root cause status and evidence, compensating measures, related issues, and data limitations. Also record severity basis.\n\n**Exit criteria**\nIssue assessment specialist provides expertise: The issue is sufficiently substantiated for assessment, duplicates and unsupported allegations are handled transparently, and urgent exposure has an assigned containment response. The severity and causal analysis are reproducible, contrary evidence is retained, and uncertainties or escalation conditions are explicit before disposition.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Quarterly access recertification missed two finance approvers","itemType":"issue","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve issue triage record","description":null,"summary":null,"instructions":"**Objective**\nApprove issue triage record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, remediation feasibility, exception authority, duplicate analysis, legal or regulatory advice, reporting thresholds, stakeholder responses, and proposed ownership and dates.\n2. Review every stage result, source evidence, assessment support, approvals, remediation or exception links, reporting confirmations, management responses, and unresolved information requests.\n\n**Procedure**\n1. Compare remediation, exception, monitoring, merge, and unsubstantiated closure paths; verify decision authority; define reporting and escalation; create required linked actions; and prevent administrative closure from concealing unresolved exposure.\n2. Trace the issue statement and severity to support, verify the disposition and approver authority, reconcile owners and dates across linked records, retain contrary evidence, and return unsupported or inconsistent work for correction.\n\n**Record in AssureSwarm**\n1. Record the disposition, rationale, authorized approver, linked remediation or exception, reporting route, owner, target date, monitoring trigger, merged issue reference, and conditions for reconsideration.\n2. Capture the authorized reviewer, triage summary, final severity and disposition, linked remediation or exception references, reporting status, responsible owners, due dates, and remaining limitations. Also record issue triage summary.\n\n**Exit criteria**\nIssue disposition authority provides approval: An approver accepts that the disposition is authorized and evidence-based, required actions and reporting are linked, and unresolved exposure remains visible. The authorized reviewer accepts the triage record as a traceable account of work and decisions, downstream records can proceed consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Quarterly access recertification missed two finance approvers","itemType":"issue","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Privileged access granted before approval during the close","itemType":"issue","name":"Issue Triage & Disposition — Privileged access granted before approval during the close — current cycle","templateName":"Issue Triage & Disposition","templateSourceId":"coworkcanvas:template:issue-triage-disposition","description":"Issue Triage & Disposition for Privileged access granted before approval during the close (current cycle).","status":"ACTIVE","displayOrder":192,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess severity and cause","description":null,"summary":null,"instructions":"**Objective**\nAssess severity and cause. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Issue item, source report, exception evidence, incident or complaint records, audit work, policies, requirements, controls, affected transactions, prior issues, and reporter representations.\n2. Use the substantiated condition, affected population, severity criteria, loss or exposure data, control results, related risks, issue history, process and system changes, management responses, and specialist input.\n\n**Procedure**\n1. Validate the reported condition against source evidence, distinguish symptoms from the underlying problem, identify applicable criteria, bound the affected population and period, remove duplicates, and initiate urgent containment when warranted.\n2. Apply the approved severity rubric, quantify or bound exposure, analyze recurrence and aggregation, test proposed causes using evidence, distinguish causal factors from symptoms, and identify uncertainty that could change priority or reporting.\n\n**Record in AssureSwarm**\n1. Capture intake source, issue statement, condition, criteria, affected items and period, reporter, accountable owner, duplicate analysis, immediate safeguards, evidence references, and unresolved questions.\n2. Document severity and rationale, actual and potential impact, affected stakeholders, pervasiveness, recurrence, root cause status and evidence, compensating measures, related issues, and data limitations. Also record severity basis.\n\n**Exit criteria**\nIssue assessment specialist provides expertise: The issue is sufficiently substantiated for assessment, duplicates and unsupported allegations are handled transparently, and urgent exposure has an assigned containment response. The severity and causal analysis are reproducible, contrary evidence is retained, and uncertainties or escalation conditions are explicit before disposition.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Privileged access granted before approval during the close","itemType":"issue","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve issue triage record","description":null,"summary":null,"instructions":"**Objective**\nApprove issue triage record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, remediation feasibility, exception authority, duplicate analysis, legal or regulatory advice, reporting thresholds, stakeholder responses, and proposed ownership and dates.\n2. Review every stage result, source evidence, assessment support, approvals, remediation or exception links, reporting confirmations, management responses, and unresolved information requests.\n\n**Procedure**\n1. Compare remediation, exception, monitoring, merge, and unsubstantiated closure paths; verify decision authority; define reporting and escalation; create required linked actions; and prevent administrative closure from concealing unresolved exposure.\n2. Trace the issue statement and severity to support, verify the disposition and approver authority, reconcile owners and dates across linked records, retain contrary evidence, and return unsupported or inconsistent work for correction.\n\n**Record in AssureSwarm**\n1. Record the disposition, rationale, authorized approver, linked remediation or exception, reporting route, owner, target date, monitoring trigger, merged issue reference, and conditions for reconsideration.\n2. Capture the authorized reviewer, triage summary, final severity and disposition, linked remediation or exception references, reporting status, responsible owners, due dates, and remaining limitations. Also record issue triage summary.\n\n**Exit criteria**\nIssue disposition authority provides approval: An approver accepts that the disposition is authorized and evidence-based, required actions and reporting are linked, and unresolved exposure remains visible. The authorized reviewer accepts the triage record as a traceable account of work and decisions, downstream records can proceed consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Privileged access granted before approval during the close","itemType":"issue","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Leaver accounts in Banana ERP disabled late","itemType":"issue","name":"Issue Triage & Disposition — Leaver accounts in Banana ERP disabled late — prior cycle","templateName":"Issue Triage & Disposition","templateSourceId":"coworkcanvas:template:issue-triage-disposition","description":"Issue Triage & Disposition for Leaver accounts in Banana ERP disabled late (prior cycle).","status":"COMPLETED","displayOrder":193,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess severity and cause","description":null,"summary":null,"instructions":"**Objective**\nAssess severity and cause. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Issue item, source report, exception evidence, incident or complaint records, audit work, policies, requirements, controls, affected transactions, prior issues, and reporter representations.\n2. Use the substantiated condition, affected population, severity criteria, loss or exposure data, control results, related risks, issue history, process and system changes, management responses, and specialist input.\n\n**Procedure**\n1. Validate the reported condition against source evidence, distinguish symptoms from the underlying problem, identify applicable criteria, bound the affected population and period, remove duplicates, and initiate urgent containment when warranted.\n2. Apply the approved severity rubric, quantify or bound exposure, analyze recurrence and aggregation, test proposed causes using evidence, distinguish causal factors from symptoms, and identify uncertainty that could change priority or reporting.\n\n**Record in AssureSwarm**\n1. Capture intake source, issue statement, condition, criteria, affected items and period, reporter, accountable owner, duplicate analysis, immediate safeguards, evidence references, and unresolved questions.\n2. Document severity and rationale, actual and potential impact, affected stakeholders, pervasiveness, recurrence, root cause status and evidence, compensating measures, related issues, and data limitations. Also record severity basis.\n\n**Exit criteria**\nIssue assessment specialist provides expertise: The issue is sufficiently substantiated for assessment, duplicates and unsupported allegations are handled transparently, and urgent exposure has an assigned containment response. The severity and causal analysis are reproducible, contrary evidence is retained, and uncertainties or escalation conditions are explicit before disposition.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Leaver accounts in Banana ERP disabled late","itemType":"issue","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve issue triage record","description":null,"summary":null,"instructions":"**Objective**\nApprove issue triage record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, remediation feasibility, exception authority, duplicate analysis, legal or regulatory advice, reporting thresholds, stakeholder responses, and proposed ownership and dates.\n2. Review every stage result, source evidence, assessment support, approvals, remediation or exception links, reporting confirmations, management responses, and unresolved information requests.\n\n**Procedure**\n1. Compare remediation, exception, monitoring, merge, and unsubstantiated closure paths; verify decision authority; define reporting and escalation; create required linked actions; and prevent administrative closure from concealing unresolved exposure.\n2. Trace the issue statement and severity to support, verify the disposition and approver authority, reconcile owners and dates across linked records, retain contrary evidence, and return unsupported or inconsistent work for correction.\n\n**Record in AssureSwarm**\n1. Record the disposition, rationale, authorized approver, linked remediation or exception, reporting route, owner, target date, monitoring trigger, merged issue reference, and conditions for reconsideration.\n2. Capture the authorized reviewer, triage summary, final severity and disposition, linked remediation or exception references, reporting status, responsible owners, due dates, and remaining limitations. Also record issue triage summary.\n\n**Exit criteria**\nIssue disposition authority provides approval: An approver accepts that the disposition is authorized and evidence-based, required actions and reporting are linked, and unresolved exposure remains visible. The authorized reviewer accepts the triage record as a traceable account of work and decisions, downstream records can proceed consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Leaver accounts in Banana ERP disabled late","itemType":"issue","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Banana ERP","itemType":"system","name":"Job Scheduling & Batch Monitoring — Banana ERP — current cycle","templateName":"Job Scheduling & Batch Monitoring","templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","description":"Job Scheduling & Batch Monitoring for Banana ERP (current cycle).","status":"ACTIVE","displayOrder":202,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve batch monitoring record","description":null,"summary":null,"instructions":"**Objective**\nApprove batch monitoring record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the job scheduler configuration and calendar, the critical job inventory and its basis, alerting and notification configuration, and the on-call or operations rota.\n2. Use scheduler execution logs for the full period, alert and incident records, rerun and manual intervention logs, downstream data completeness checks, and the prior period failure profile.\n3. Use the failure inventory, alert delivery evidence, incident tickets with timestamps, resolution notes, downstream reconciliation after rerun, and the response targets in policy.\n4. Review all stage records, the critical job basis, expected-versus-actual reconciliation, failure inventory, timing measurements, downstream verification, and open items with owners.\n\n**Procedure**\n1. Confirm the critical job list is derived from downstream financial and operational dependency rather than convention, verify alerting is configured for each critical job, and identify jobs whose failure would be silent.\n2. Inspect the log for the WHOLE period rather than sampling a date, reconcile expected against actual executions to find jobs that never ran, distinguish reruns that succeeded from those that masked a data gap, and record log gaps as gaps.\n3. Measure detection-to-escalation and escalation-to-resolution against the policy targets per failure, confirm downstream data was reconciled after each rerun, and treat failures closed without data verification as unresolved.\n4. Trace the result to per-failure timing evidence, verify jobs with no alerting carry a remediation owner, confirm downstream reconciliation for every rerun, and return status-only resolutions with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the monitoring period, critical job population with dependency rationale, detection and alerting configuration per job, accountable responders, jobs with no alerting, and scope exclusions. Also record critical job population and detection basis.\n2. Document the failure inventory with timestamps and job identity, jobs that never executed, reruns and manual interventions, downstream impact observed, resolution status per failure, and log coverage gaps.\n3. Record the monitoring result, per-failure timing against targets, alerts that did not reach a responder, downstream reconciliation evidence, failures closed without data verification, and recurring failure patterns. Also record escalation and resolution detail.\n4. Capture the authorized reviewer, the summary, accepted result, period covered, unresolved failures and data impact with owners and dates, alerting gaps, and linked issues raised. Also record batch monitoring summary.\n\n**Exit criteria**\nSystem owner and technical specialist provides approval: Criticality is justified by downstream dependency, alerting coverage is evidenced per job, and silently-failing jobs are surfaced rather than assumed healthy. The review covers the whole period, missing executions are found by expected-versus-actual reconciliation, and log gaps are declared rather than read as clean periods. An approver accepts that timing is measured per failure against policy targets, downstream data impact is verified rather than assumed, and recurring patterns are surfaced. The authorized reviewer accepts the record as evidence the monitoring control operated for the period, and closure implies no assurance over jobs excluded from the critical population.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Cornballer Revenue Engine","itemType":"system","name":"Job Scheduling & Batch Monitoring — Cornballer Revenue Engine — next cycle","templateName":"Job Scheduling & Batch Monitoring","templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","description":"Job Scheduling & Batch Monitoring for Cornballer Revenue Engine (next cycle).","status":"DRAFT","displayOrder":201,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve batch monitoring record","description":null,"summary":null,"instructions":"**Objective**\nApprove batch monitoring record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the job scheduler configuration and calendar, the critical job inventory and its basis, alerting and notification configuration, and the on-call or operations rota.\n2. Use scheduler execution logs for the full period, alert and incident records, rerun and manual intervention logs, downstream data completeness checks, and the prior period failure profile.\n3. Use the failure inventory, alert delivery evidence, incident tickets with timestamps, resolution notes, downstream reconciliation after rerun, and the response targets in policy.\n4. Review all stage records, the critical job basis, expected-versus-actual reconciliation, failure inventory, timing measurements, downstream verification, and open items with owners.\n\n**Procedure**\n1. Confirm the critical job list is derived from downstream financial and operational dependency rather than convention, verify alerting is configured for each critical job, and identify jobs whose failure would be silent.\n2. Inspect the log for the WHOLE period rather than sampling a date, reconcile expected against actual executions to find jobs that never ran, distinguish reruns that succeeded from those that masked a data gap, and record log gaps as gaps.\n3. Measure detection-to-escalation and escalation-to-resolution against the policy targets per failure, confirm downstream data was reconciled after each rerun, and treat failures closed without data verification as unresolved.\n4. Trace the result to per-failure timing evidence, verify jobs with no alerting carry a remediation owner, confirm downstream reconciliation for every rerun, and return status-only resolutions with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the monitoring period, critical job population with dependency rationale, detection and alerting configuration per job, accountable responders, jobs with no alerting, and scope exclusions. Also record critical job population and detection basis.\n2. Document the failure inventory with timestamps and job identity, jobs that never executed, reruns and manual interventions, downstream impact observed, resolution status per failure, and log coverage gaps.\n3. Record the monitoring result, per-failure timing against targets, alerts that did not reach a responder, downstream reconciliation evidence, failures closed without data verification, and recurring failure patterns. Also record escalation and resolution detail.\n4. Capture the authorized reviewer, the summary, accepted result, period covered, unresolved failures and data impact with owners and dates, alerting gaps, and linked issues raised. Also record batch monitoring summary.\n\n**Exit criteria**\nSystem owner and technical specialist provides approval: Criticality is justified by downstream dependency, alerting coverage is evidenced per job, and silently-failing jobs are surfaced rather than assumed healthy. The review covers the whole period, missing executions are found by expected-versus-actual reconciliation, and log gaps are declared rather than read as clean periods. An approver accepts that timing is measured per failure against policy targets, downstream data impact is verified rather than assumed, and recurring patterns are surfaced. The authorized reviewer accepts the record as evidence the monitoring control operated for the period, and closure implies no assurance over jobs excluded from the critical population.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Seaward Payroll Service","itemType":"system","name":"Job Scheduling & Batch Monitoring — Seaward Payroll Service — prior cycle","templateName":"Job Scheduling & Batch Monitoring","templateSourceId":"coworkcanvas:template:job-scheduling-batch-monitoring","description":"Job Scheduling & Batch Monitoring for Seaward Payroll Service (prior cycle).","status":"COMPLETED","displayOrder":203,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve batch monitoring record","description":null,"summary":null,"instructions":"**Objective**\nApprove batch monitoring record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the job scheduler configuration and calendar, the critical job inventory and its basis, alerting and notification configuration, and the on-call or operations rota.\n2. Use scheduler execution logs for the full period, alert and incident records, rerun and manual intervention logs, downstream data completeness checks, and the prior period failure profile.\n3. Use the failure inventory, alert delivery evidence, incident tickets with timestamps, resolution notes, downstream reconciliation after rerun, and the response targets in policy.\n4. Review all stage records, the critical job basis, expected-versus-actual reconciliation, failure inventory, timing measurements, downstream verification, and open items with owners.\n\n**Procedure**\n1. Confirm the critical job list is derived from downstream financial and operational dependency rather than convention, verify alerting is configured for each critical job, and identify jobs whose failure would be silent.\n2. Inspect the log for the WHOLE period rather than sampling a date, reconcile expected against actual executions to find jobs that never ran, distinguish reruns that succeeded from those that masked a data gap, and record log gaps as gaps.\n3. Measure detection-to-escalation and escalation-to-resolution against the policy targets per failure, confirm downstream data was reconciled after each rerun, and treat failures closed without data verification as unresolved.\n4. Trace the result to per-failure timing evidence, verify jobs with no alerting carry a remediation owner, confirm downstream reconciliation for every rerun, and return status-only resolutions with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the monitoring period, critical job population with dependency rationale, detection and alerting configuration per job, accountable responders, jobs with no alerting, and scope exclusions. Also record critical job population and detection basis.\n2. Document the failure inventory with timestamps and job identity, jobs that never executed, reruns and manual interventions, downstream impact observed, resolution status per failure, and log coverage gaps.\n3. Record the monitoring result, per-failure timing against targets, alerts that did not reach a responder, downstream reconciliation evidence, failures closed without data verification, and recurring failure patterns. Also record escalation and resolution detail.\n4. Capture the authorized reviewer, the summary, accepted result, period covered, unresolved failures and data impact with owners and dates, alerting gaps, and linked issues raised. Also record batch monitoring summary.\n\n**Exit criteria**\nSystem owner and technical specialist provides approval: Criticality is justified by downstream dependency, alerting coverage is evidenced per job, and silently-failing jobs are surfaced rather than assumed healthy. The review covers the whole period, missing executions are found by expected-versus-actual reconciliation, and log gaps are declared rather than read as clean periods. An approver accepts that timing is measured per failure against policy targets, downstream data impact is verified rather than assumed, and recurring patterns are surfaced. The authorized reviewer accepts the record as evidence the monitoring control operated for the period, and closure implies no assurance over jobs excluded from the critical population.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Seaward Payroll Service","itemType":"system","kind":"related"},{"itemTitle":"Joiner Mover Leaver Automation","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Tidewell File Exchange","itemType":"system","name":"New System Implementation (SDLC) — Tidewell File Exchange — current cycle","templateName":"New System Implementation (SDLC)","templateSourceId":"coworkcanvas:template:new-system-implementation","description":"New System Implementation (SDLC) for Tidewell File Exchange (current cycle).","status":"ACTIVE","displayOrder":212,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm requirements and control design","description":null,"summary":null,"instructions":"**Objective**\nConfirm requirements and control design. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, business and functional requirements, the process and data flows the system will serve, applicable framework requirements, the existing control set it replaces, and architecture review output.\n\n**Procedure**\n1. Derive control requirements from the processes and obligations the system will carry rather than from vendor capability, identify controls the system cannot support, and record where a compensating manual control will be required.\n\n**Record in AssureSwarm**\n1. Capture the implementation scope, control requirements traced to processes and obligations, controls the platform cannot support, planned compensating controls, architecture review outcome, and unresolved requirement gaps.\n\n**Exit criteria**\nBusiness and control sponsor provides expertise: Control requirements are derived from obligations rather than from product capability, unsupported controls are named before build, and compensating controls are planned rather than discovered at go-live.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Tidewell File Exchange","itemType":"system","kind":"related"},{"itemTitle":"Govern security of external and cloud service use","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve implementation record","description":null,"summary":null,"instructions":"**Objective**\nApprove implementation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use test strategy and phase plans, executed unit, integration, and user acceptance results, defect logs with severity and status, the UAT tester identities, and the acceptance criteria agreed at requirements.\n2. Use acceptance results and open defects, control requirement coverage, cutover and rollback plans, data conversion readiness, support and monitoring arrangements, and the agreed go-live criteria.\n3. Review all stage records, requirement traceability, executed test evidence, UAT independence, defect dispositions, readiness criteria assessment, and open conditions with owners.\n\n**Procedure**\n1. Inspect executed results per phase, confirm UAT testers are business users by identity rather than by role label, trace open defects to a severity-based acceptance decision, and test the control requirements specifically rather than only functionality.\n2. Test the decision against the criteria agreed at requirements rather than against schedule pressure, confirm rollback is demonstrated rather than documented, verify compensating controls are operating, and record conditions with owners and deadlines.\n3. Trace every control requirement to a test result or a named compensating control, verify conditions carry deadlines, confirm the go decision cites criteria rather than schedule, and return untested control requirements with precise comments.\n\n**Record in AssureSwarm**\n1. Document test phases with executed results and dates, control requirements tested and their outcomes, defects by severity with status, UAT tester identities and independence, acceptance status, and untested requirements.\n2. Record the readiness decision against each criterion, residual risks and their owners, cutover and rollback evidence, compensating controls confirmed operating, conditions with deadlines, and criteria not met.\n3. Capture the authorized reviewer, the summary, accepted readiness decision, go-live date, residual risks and conditions with owners and dates, compensating controls in force, and linked issues raised. Also record implementation summary.\n\n**Exit criteria**\nGo-live authority provides approval: Each phase is evidenced by executed results, UAT independence is demonstrated by identity, control requirements are tested distinctly from functionality, and open defects carry a severity-based decision. An approver accepts that readiness is measured against the pre-agreed criteria, rollback capability is demonstrated, and unmet criteria are carried as conditions with owners rather than waived silently. The authorized reviewer accepts the record as evidence the implementation control operated, and closure implies no assurance over control requirements deferred to post-go-live.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Tidewell File Exchange","itemType":"system","kind":"related"},{"itemTitle":"Govern security of external and cloud service use","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Model Home Data Lake","itemType":"system","name":"New System Implementation (SDLC) — Model Home Data Lake — next cycle","templateName":"New System Implementation (SDLC)","templateSourceId":"coworkcanvas:template:new-system-implementation","description":"New System Implementation (SDLC) for Model Home Data Lake (next cycle).","status":"DRAFT","displayOrder":211,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm requirements and control design","description":null,"summary":null,"instructions":"**Objective**\nConfirm requirements and control design. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, business and functional requirements, the process and data flows the system will serve, applicable framework requirements, the existing control set it replaces, and architecture review output.\n\n**Procedure**\n1. Derive control requirements from the processes and obligations the system will carry rather than from vendor capability, identify controls the system cannot support, and record where a compensating manual control will be required.\n\n**Record in AssureSwarm**\n1. Capture the implementation scope, control requirements traced to processes and obligations, controls the platform cannot support, planned compensating controls, architecture review outcome, and unresolved requirement gaps.\n\n**Exit criteria**\nBusiness and control sponsor provides expertise: Control requirements are derived from obligations rather than from product capability, unsupported controls are named before build, and compensating controls are planned rather than discovered at go-live.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve implementation record","description":null,"summary":null,"instructions":"**Objective**\nApprove implementation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use test strategy and phase plans, executed unit, integration, and user acceptance results, defect logs with severity and status, the UAT tester identities, and the acceptance criteria agreed at requirements.\n2. Use acceptance results and open defects, control requirement coverage, cutover and rollback plans, data conversion readiness, support and monitoring arrangements, and the agreed go-live criteria.\n3. Review all stage records, requirement traceability, executed test evidence, UAT independence, defect dispositions, readiness criteria assessment, and open conditions with owners.\n\n**Procedure**\n1. Inspect executed results per phase, confirm UAT testers are business users by identity rather than by role label, trace open defects to a severity-based acceptance decision, and test the control requirements specifically rather than only functionality.\n2. Test the decision against the criteria agreed at requirements rather than against schedule pressure, confirm rollback is demonstrated rather than documented, verify compensating controls are operating, and record conditions with owners and deadlines.\n3. Trace every control requirement to a test result or a named compensating control, verify conditions carry deadlines, confirm the go decision cites criteria rather than schedule, and return untested control requirements with precise comments.\n\n**Record in AssureSwarm**\n1. Document test phases with executed results and dates, control requirements tested and their outcomes, defects by severity with status, UAT tester identities and independence, acceptance status, and untested requirements.\n2. Record the readiness decision against each criterion, residual risks and their owners, cutover and rollback evidence, compensating controls confirmed operating, conditions with deadlines, and criteria not met.\n3. Capture the authorized reviewer, the summary, accepted readiness decision, go-live date, residual risks and conditions with owners and dates, compensating controls in force, and linked issues raised. Also record implementation summary.\n\n**Exit criteria**\nGo-live authority provides approval: Each phase is evidenced by executed results, UAT independence is demonstrated by identity, control requirements are tested distinctly from functionality, and open defects carry a severity-based decision. An approver accepts that readiness is measured against the pre-agreed criteria, rollback capability is demonstrated, and unmet criteria are carried as conditions with owners rather than waived silently. The authorized reviewer accepts the record as evidence the implementation control operated, and closure implies no assurance over control requirements deferred to post-go-live.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Model Home Data Lake","itemType":"system","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Never Nude HR Platform","itemType":"system","name":"New System Implementation (SDLC) — Never Nude HR Platform — prior cycle","templateName":"New System Implementation (SDLC)","templateSourceId":"coworkcanvas:template:new-system-implementation","description":"New System Implementation (SDLC) for Never Nude HR Platform (prior cycle).","status":"COMPLETED","displayOrder":213,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm requirements and control design","description":null,"summary":null,"instructions":"**Objective**\nConfirm requirements and control design. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, business and functional requirements, the process and data flows the system will serve, applicable framework requirements, the existing control set it replaces, and architecture review output.\n\n**Procedure**\n1. Derive control requirements from the processes and obligations the system will carry rather than from vendor capability, identify controls the system cannot support, and record where a compensating manual control will be required.\n\n**Record in AssureSwarm**\n1. Capture the implementation scope, control requirements traced to processes and obligations, controls the platform cannot support, planned compensating controls, architecture review outcome, and unresolved requirement gaps.\n\n**Exit criteria**\nBusiness and control sponsor provides expertise: Control requirements are derived from obligations rather than from product capability, unsupported controls are named before build, and compensating controls are planned rather than discovered at go-live.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Never Nude HR Platform","itemType":"system","kind":"related"},{"itemTitle":"Annual performance and conduct evaluation per personnel","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve implementation record","description":null,"summary":null,"instructions":"**Objective**\nApprove implementation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use test strategy and phase plans, executed unit, integration, and user acceptance results, defect logs with severity and status, the UAT tester identities, and the acceptance criteria agreed at requirements.\n2. Use acceptance results and open defects, control requirement coverage, cutover and rollback plans, data conversion readiness, support and monitoring arrangements, and the agreed go-live criteria.\n3. Review all stage records, requirement traceability, executed test evidence, UAT independence, defect dispositions, readiness criteria assessment, and open conditions with owners.\n\n**Procedure**\n1. Inspect executed results per phase, confirm UAT testers are business users by identity rather than by role label, trace open defects to a severity-based acceptance decision, and test the control requirements specifically rather than only functionality.\n2. Test the decision against the criteria agreed at requirements rather than against schedule pressure, confirm rollback is demonstrated rather than documented, verify compensating controls are operating, and record conditions with owners and deadlines.\n3. Trace every control requirement to a test result or a named compensating control, verify conditions carry deadlines, confirm the go decision cites criteria rather than schedule, and return untested control requirements with precise comments.\n\n**Record in AssureSwarm**\n1. Document test phases with executed results and dates, control requirements tested and their outcomes, defects by severity with status, UAT tester identities and independence, acceptance status, and untested requirements.\n2. Record the readiness decision against each criterion, residual risks and their owners, cutover and rollback evidence, compensating controls confirmed operating, conditions with deadlines, and criteria not met.\n3. Capture the authorized reviewer, the summary, accepted readiness decision, go-live date, residual risks and conditions with owners and dates, compensating controls in force, and linked issues raised. Also record implementation summary.\n\n**Exit criteria**\nGo-live authority provides approval: Each phase is evidenced by executed results, UAT independence is demonstrated by identity, control requirements are tested distinctly from functionality, and open defects carry a severity-based decision. An approver accepts that readiness is measured against the pre-agreed criteria, rollback capability is demonstrated, and unmet criteria are carried as conditions with owners rather than waived silently. The authorized reviewer accepts the record as evidence the implementation control operated, and closure implies no assurance over control requirements deferred to post-go-live.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Never Nude HR Platform","itemType":"system","kind":"related"},{"itemTitle":"Annual performance and conduct evaluation per personnel","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 A.5.20 — Contracted supplier safeguards","itemType":"requirement","name":"Obligation Implementation & Adoption — ISO 27001 A.5.20 — Contracted supplier safeguards — current cycle","templateName":"Obligation Implementation & Adoption","templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","description":"Obligation Implementation & Adoption for ISO 27001 A.5.20 — Contracted supplier safeguards (current cycle).","status":"ACTIVE","displayOrder":222,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm implementation scope and readiness date","description":null,"summary":null,"instructions":"**Objective**\nConfirm implementation scope and readiness date. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, the approved impact assessment, gap inventory, affected controls, policies, processes and systems, delivery capacity, dependency and change calendars, and the obligation effective date.\n\n**Procedure**\n1. Convert each gap into a deliverable with an owner and date, sequence work against dependencies and freeze periods, reconcile the readiness date against the effective date, and escalate where capacity cannot meet the deadline.\n\n**Record in AssureSwarm**\n1. Capture the target readiness date, implementation scope and deliverables, owners, sequence and dependencies, capacity constraints, freeze-period conflicts, and escalations raised.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: Every gap has a deliverable, an owner, and a date; the readiness date reconciles to the effective date or the shortfall is escalated rather than hidden.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.20 — Contracted supplier safeguards","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve adoption record","description":null,"summary":null,"instructions":"**Objective**\nApprove adoption record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the implementation scope and deliverable list, control and policy drafts, process narratives, system change records, training and communication plans, approval routes, and the change and release calendar.\n2. Use the obligation text and clause-level requirements, the change inventory and its evidence, control operation evidence since the change, policy publication records, training completion, and the original gap inventory.\n3. Review all stage records, the deliverable list and its execution evidence, deviations, clause-by-clause validation, residual gaps, blockers, and representations relied upon.\n\n**Procedure**\n1. Execute each deliverable through its normal approval route, record deviations from plan with reasons, keep superseded versions traceable, confirm communication and training reached affected roles, and surface blockers rather than silently deferring them.\n2. Test each clause against delivered evidence rather than intent, inspect operating evidence where the obligation requires operation, distinguish documented from operating readiness, and refuse to close clauses supported only by representation.\n3. Trace the readiness conclusion to inspected evidence, verify residual gaps carry owners and dates, confirm the implementation status to record matches the validated position, and return overstated readiness with precise comments.\n\n**Record in AssureSwarm**\n1. Document the change inventory with before-and-after references, execution status per deliverable, deviations from plan, approval records, communication and training evidence, and blockers with owners.\n2. Record the readiness conclusion, clause-by-clause validation with evidence references, residual gaps with owners and target dates, representations relied upon, and clauses that could not be validated.\n3. Capture the authorized reviewer, the adoption summary, accepted readiness conclusion, implementation status to record, adoption effective date, residual gaps, monitoring handover, owners, and due dates.\n\n**Exit criteria**\nCompliance owner provides approval: Delivered changes are traceable to approved deliverables, deviations are reasoned, and blocked work is visible with an owner rather than absorbed into the next stage. An approver accepts that the readiness conclusion follows from inspected evidence, residual gaps are owned and dated, and unvalidated clauses are declared rather than presumed satisfied. The authorized reviewer accepts the adoption as a traceable record of implementation work, monitoring can take over against a stated position, and closure implies no assurance beyond the clauses actually validated.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.20 — Contracted supplier safeguards","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"SOC 2 CC5.1 — Risk-mitigating control activities","itemType":"requirement","name":"Obligation Implementation & Adoption — SOC 2 CC5.1 — Risk-mitigating control activities — prior cycle","templateName":"Obligation Implementation & Adoption","templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","description":"Obligation Implementation & Adoption for SOC 2 CC5.1 — Risk-mitigating control activities (prior cycle).","status":"COMPLETED","displayOrder":223,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm implementation scope and readiness date","description":null,"summary":null,"instructions":"**Objective**\nConfirm implementation scope and readiness date. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, the approved impact assessment, gap inventory, affected controls, policies, processes and systems, delivery capacity, dependency and change calendars, and the obligation effective date.\n\n**Procedure**\n1. Convert each gap into a deliverable with an owner and date, sequence work against dependencies and freeze periods, reconcile the readiness date against the effective date, and escalate where capacity cannot meet the deadline.\n\n**Record in AssureSwarm**\n1. Capture the target readiness date, implementation scope and deliverables, owners, sequence and dependencies, capacity constraints, freeze-period conflicts, and escalations raised.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: Every gap has a deliverable, an owner, and a date; the readiness date reconciles to the effective date or the shortfall is escalated rather than hidden.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"SOC 2 CC5.1 — Risk-mitigating control activities","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve adoption record","description":null,"summary":null,"instructions":"**Objective**\nApprove adoption record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the implementation scope and deliverable list, control and policy drafts, process narratives, system change records, training and communication plans, approval routes, and the change and release calendar.\n2. Use the obligation text and clause-level requirements, the change inventory and its evidence, control operation evidence since the change, policy publication records, training completion, and the original gap inventory.\n3. Review all stage records, the deliverable list and its execution evidence, deviations, clause-by-clause validation, residual gaps, blockers, and representations relied upon.\n\n**Procedure**\n1. Execute each deliverable through its normal approval route, record deviations from plan with reasons, keep superseded versions traceable, confirm communication and training reached affected roles, and surface blockers rather than silently deferring them.\n2. Test each clause against delivered evidence rather than intent, inspect operating evidence where the obligation requires operation, distinguish documented from operating readiness, and refuse to close clauses supported only by representation.\n3. Trace the readiness conclusion to inspected evidence, verify residual gaps carry owners and dates, confirm the implementation status to record matches the validated position, and return overstated readiness with precise comments.\n\n**Record in AssureSwarm**\n1. Document the change inventory with before-and-after references, execution status per deliverable, deviations from plan, approval records, communication and training evidence, and blockers with owners.\n2. Record the readiness conclusion, clause-by-clause validation with evidence references, residual gaps with owners and target dates, representations relied upon, and clauses that could not be validated.\n3. Capture the authorized reviewer, the adoption summary, accepted readiness conclusion, implementation status to record, adoption effective date, residual gaps, monitoring handover, owners, and due dates.\n\n**Exit criteria**\nCompliance owner provides approval: Delivered changes are traceable to approved deliverables, deviations are reasoned, and blocked work is visible with an owner rather than absorbed into the next stage. An approver accepts that the readiness conclusion follows from inspected evidence, residual gaps are owned and dated, and unvalidated clauses are declared rather than presumed satisfied. The authorized reviewer accepts the adoption as a traceable record of implementation work, monitoring can take over against a stated position, and closure implies no assurance beyond the clauses actually validated.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"SOC 2 CC5.1 — Risk-mitigating control activities","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"SOC 2 CC5.3 — Policy-driven procedures","itemType":"requirement","name":"Obligation Implementation & Adoption — SOC 2 CC5.3 — Policy-driven procedures — next cycle","templateName":"Obligation Implementation & Adoption","templateSourceId":"coworkcanvas:template:obligation-implementation-adoption","description":"Obligation Implementation & Adoption for SOC 2 CC5.3 — Policy-driven procedures (next cycle).","status":"DRAFT","displayOrder":221,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm implementation scope and readiness date","description":null,"summary":null,"instructions":"**Objective**\nConfirm implementation scope and readiness date. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, the approved impact assessment, gap inventory, affected controls, policies, processes and systems, delivery capacity, dependency and change calendars, and the obligation effective date.\n\n**Procedure**\n1. Convert each gap into a deliverable with an owner and date, sequence work against dependencies and freeze periods, reconcile the readiness date against the effective date, and escalate where capacity cannot meet the deadline.\n\n**Record in AssureSwarm**\n1. Capture the target readiness date, implementation scope and deliverables, owners, sequence and dependencies, capacity constraints, freeze-period conflicts, and escalations raised.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: Every gap has a deliverable, an owner, and a date; the readiness date reconciles to the effective date or the shortfall is escalated rather than hidden.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"SOC 2 CC5.3 — Policy-driven procedures","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve adoption record","description":null,"summary":null,"instructions":"**Objective**\nApprove adoption record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the implementation scope and deliverable list, control and policy drafts, process narratives, system change records, training and communication plans, approval routes, and the change and release calendar.\n2. Use the obligation text and clause-level requirements, the change inventory and its evidence, control operation evidence since the change, policy publication records, training completion, and the original gap inventory.\n3. Review all stage records, the deliverable list and its execution evidence, deviations, clause-by-clause validation, residual gaps, blockers, and representations relied upon.\n\n**Procedure**\n1. Execute each deliverable through its normal approval route, record deviations from plan with reasons, keep superseded versions traceable, confirm communication and training reached affected roles, and surface blockers rather than silently deferring them.\n2. Test each clause against delivered evidence rather than intent, inspect operating evidence where the obligation requires operation, distinguish documented from operating readiness, and refuse to close clauses supported only by representation.\n3. Trace the readiness conclusion to inspected evidence, verify residual gaps carry owners and dates, confirm the implementation status to record matches the validated position, and return overstated readiness with precise comments.\n\n**Record in AssureSwarm**\n1. Document the change inventory with before-and-after references, execution status per deliverable, deviations from plan, approval records, communication and training evidence, and blockers with owners.\n2. Record the readiness conclusion, clause-by-clause validation with evidence references, residual gaps with owners and target dates, representations relied upon, and clauses that could not be validated.\n3. Capture the authorized reviewer, the adoption summary, accepted readiness conclusion, implementation status to record, adoption effective date, residual gaps, monitoring handover, owners, and due dates.\n\n**Exit criteria**\nCompliance owner provides approval: Delivered changes are traceable to approved deliverables, deviations are reasoned, and blocked work is visible with an owner rather than absorbed into the next stage. An approver accepts that the readiness conclusion follows from inspected evidence, residual gaps are owned and dated, and unvalidated clauses are declared rather than presumed satisfied. The authorized reviewer accepts the adoption as a traceable record of implementation work, monitoring can take over against a stated position, and closure implies no assurance beyond the clauses actually validated.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"SOC 2 CC5.3 — Policy-driven procedures","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Buster Bluth","itemType":"personnel","name":"Offboarding & Access Revocation — Buster Bluth — current cycle","templateName":"Offboarding & Access Revocation","templateSourceId":"coworkcanvas:template:offboarding-access-revocation","description":"Offboarding & Access Revocation for Buster Bluth (current cycle).","status":"ACTIVE","displayOrder":232,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Revoke access and capture evidence","description":null,"summary":null,"instructions":"**Objective**\nRevoke access and capture evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR termination record, entitlement extracts from every in-scope system, asset and device registers, shared and service account membership, physical access records, and the revocation window in policy.\n2. Use the access inventory and deadline, system administration consoles, directory disablement records, asset recovery receipts, shared-credential rotation records, and physical badge deactivation logs.\n\n**Procedure**\n1. Extract entitlements from source systems, INCLUDE shared accounts, service accounts, and non-directory credentials that role-based extracts miss, confirm whether the termination type requires immediate revocation, and compute the deadline from the effective date.\n2. Revoke in dependency order so directory disablement does not hide downstream entitlements, ROTATE shared credentials the leaver knew rather than only removing membership, capture dated evidence per system, and record each revocation against the deadline rather than in aggregate.\n\n**Record in AssureSwarm**\n1. Capture the termination effective date and type, revocation deadline, the complete access inventory per system with extract dates, devices and physical credentials, shared and service account membership, and extraction gaps.\n2. Document revoked access per system with evidence references and timestamps, credential rotations performed, devices recovered, physical access deactivated, timeliness per item, and outstanding revocations with owners.\n\n**Exit criteria**\nManager and entitlement authority provides expertise: The inventory covers named, shared, and service access plus physical credentials; the deadline is computed from policy; and extraction gaps are declared rather than presumed empty. Every inventoried item is revoked, rotated, or recorded as outstanding with an owner; timeliness is measured per item against the deadline; and shared credentials are rotated rather than assumed safe.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Buster Bluth","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve revocation record","description":null,"summary":null,"instructions":"**Objective**\nApprove revocation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use post-revocation entitlement extracts, directory status, authentication and access logs since the termination date, asset register status, and the original inventory for comparison.\n2. Review all stage records, the original and post-revocation extracts, timeliness per item, credential rotations, asset recovery, verification comparison, residual access, and unverifiable items.\n\n**Procedure**\n1. Re-extract INDEPENDENTLY rather than accepting the operator confirmation, compare against the original inventory item by item, inspect authentication activity after the termination date, and classify unverifiable items as unverifiable rather than complete.\n2. Trace every inventoried item to a revocation or an owned exception, confirm late revocations are recorded as such rather than smoothed, verify residual access has a remediation owner, and return incomplete verification with precise comments.\n\n**Record in AssureSwarm**\n1. Record the verification result, post-revocation extract references and dates, item-by-item comparison, residual access with cause and owner, post-termination authentication observed, and items that could not be verified. Also record residual access detail.\n2. Capture the authorized reviewer, the revocation summary, HR-backed Personnel updates specified below, late revocations, residual access with owners and dates, unverifiable items, and linked issues raised.\n\nUpdate Personnel.engagement_end_date and Personnel.engagement_status only from the authoritative HR termination or engagement-end record and its effective date. Completed access revocation alone does not establish that the engagement ended; do not mark ended before the supported end date. Preserve Personnel.engagement_start_date and historical role dates. Put per-system access revocation/verification dates, the original entitlement inventory, credential rotations, late removals, residual access and unverifiable items in the markdown step result; attach source extracts and verification evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: An approver accepts that verification rests on independent re-extraction, residual access carries an owner and a date, and unverifiable items are declared rather than treated as clean. The authorized reviewer accepts the revocation record as evidence an access control operated for this leaver, late and residual items stay visible as control exceptions, and closure implies no assurance over systems outside the stated scope.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Buster Bluth","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Dexter Holloway","itemType":"personnel","name":"Offboarding & Access Revocation — Dexter Holloway — next cycle","templateName":"Offboarding & Access Revocation","templateSourceId":"coworkcanvas:template:offboarding-access-revocation","description":"Offboarding & Access Revocation for Dexter Holloway (next cycle).","status":"DRAFT","displayOrder":231,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Revoke access and capture evidence","description":null,"summary":null,"instructions":"**Objective**\nRevoke access and capture evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR termination record, entitlement extracts from every in-scope system, asset and device registers, shared and service account membership, physical access records, and the revocation window in policy.\n2. Use the access inventory and deadline, system administration consoles, directory disablement records, asset recovery receipts, shared-credential rotation records, and physical badge deactivation logs.\n\n**Procedure**\n1. Extract entitlements from source systems, INCLUDE shared accounts, service accounts, and non-directory credentials that role-based extracts miss, confirm whether the termination type requires immediate revocation, and compute the deadline from the effective date.\n2. Revoke in dependency order so directory disablement does not hide downstream entitlements, ROTATE shared credentials the leaver knew rather than only removing membership, capture dated evidence per system, and record each revocation against the deadline rather than in aggregate.\n\n**Record in AssureSwarm**\n1. Capture the termination effective date and type, revocation deadline, the complete access inventory per system with extract dates, devices and physical credentials, shared and service account membership, and extraction gaps.\n2. Document revoked access per system with evidence references and timestamps, credential rotations performed, devices recovered, physical access deactivated, timeliness per item, and outstanding revocations with owners.\n\n**Exit criteria**\nManager and entitlement authority provides expertise: The inventory covers named, shared, and service access plus physical credentials; the deadline is computed from policy; and extraction gaps are declared rather than presumed empty. Every inventoried item is revoked, rotated, or recorded as outstanding with an owner; timeliness is measured per item against the deadline; and shared credentials are rotated rather than assumed safe.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Dexter Holloway","itemType":"personnel","kind":"related"},{"itemTitle":"Tidewell File Exchange","itemType":"system","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve revocation record","description":null,"summary":null,"instructions":"**Objective**\nApprove revocation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use post-revocation entitlement extracts, directory status, authentication and access logs since the termination date, asset register status, and the original inventory for comparison.\n2. Review all stage records, the original and post-revocation extracts, timeliness per item, credential rotations, asset recovery, verification comparison, residual access, and unverifiable items.\n\n**Procedure**\n1. Re-extract INDEPENDENTLY rather than accepting the operator confirmation, compare against the original inventory item by item, inspect authentication activity after the termination date, and classify unverifiable items as unverifiable rather than complete.\n2. Trace every inventoried item to a revocation or an owned exception, confirm late revocations are recorded as such rather than smoothed, verify residual access has a remediation owner, and return incomplete verification with precise comments.\n\n**Record in AssureSwarm**\n1. Record the verification result, post-revocation extract references and dates, item-by-item comparison, residual access with cause and owner, post-termination authentication observed, and items that could not be verified. Also record residual access detail.\n2. Capture the authorized reviewer, the revocation summary, HR-backed Personnel updates specified below, late revocations, residual access with owners and dates, unverifiable items, and linked issues raised.\n\nUpdate Personnel.engagement_end_date and Personnel.engagement_status only from the authoritative HR termination or engagement-end record and its effective date. Completed access revocation alone does not establish that the engagement ended; do not mark ended before the supported end date. Preserve Personnel.engagement_start_date and historical role dates. Put per-system access revocation/verification dates, the original entitlement inventory, credential rotations, late removals, residual access and unverifiable items in the markdown step result; attach source extracts and verification evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: An approver accepts that verification rests on independent re-extraction, residual access carries an owner and a date, and unverifiable items are declared rather than treated as clean. The authorized reviewer accepts the revocation record as evidence an access control operated for this leaver, late and residual items stay visible as control exceptions, and closure implies no assurance over systems outside the stated scope.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Dexter Holloway","itemType":"personnel","kind":"related"},{"itemTitle":"Tidewell File Exchange","itemType":"system","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Tobias Fünke","itemType":"personnel","name":"Offboarding & Access Revocation — Tobias Fünke — prior cycle","templateName":"Offboarding & Access Revocation","templateSourceId":"coworkcanvas:template:offboarding-access-revocation","description":"Offboarding & Access Revocation for Tobias Fünke (prior cycle).","status":"COMPLETED","displayOrder":233,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Revoke access and capture evidence","description":null,"summary":null,"instructions":"**Objective**\nRevoke access and capture evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR termination record, entitlement extracts from every in-scope system, asset and device registers, shared and service account membership, physical access records, and the revocation window in policy.\n2. Use the access inventory and deadline, system administration consoles, directory disablement records, asset recovery receipts, shared-credential rotation records, and physical badge deactivation logs.\n\n**Procedure**\n1. Extract entitlements from source systems, INCLUDE shared accounts, service accounts, and non-directory credentials that role-based extracts miss, confirm whether the termination type requires immediate revocation, and compute the deadline from the effective date.\n2. Revoke in dependency order so directory disablement does not hide downstream entitlements, ROTATE shared credentials the leaver knew rather than only removing membership, capture dated evidence per system, and record each revocation against the deadline rather than in aggregate.\n\n**Record in AssureSwarm**\n1. Capture the termination effective date and type, revocation deadline, the complete access inventory per system with extract dates, devices and physical credentials, shared and service account membership, and extraction gaps.\n2. Document revoked access per system with evidence references and timestamps, credential rotations performed, devices recovered, physical access deactivated, timeliness per item, and outstanding revocations with owners.\n\n**Exit criteria**\nManager and entitlement authority provides expertise: The inventory covers named, shared, and service access plus physical credentials; the deadline is computed from policy; and extraction gaps are declared rather than presumed empty. Every inventoried item is revoked, rotated, or recorded as outstanding with an owner; timeliness is measured per item against the deadline; and shared credentials are rotated rather than assumed safe.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Tobias Fünke","itemType":"personnel","kind":"related"},{"itemTitle":"Never Nude HR Platform","itemType":"system","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve revocation record","description":null,"summary":null,"instructions":"**Objective**\nApprove revocation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use post-revocation entitlement extracts, directory status, authentication and access logs since the termination date, asset register status, and the original inventory for comparison.\n2. Review all stage records, the original and post-revocation extracts, timeliness per item, credential rotations, asset recovery, verification comparison, residual access, and unverifiable items.\n\n**Procedure**\n1. Re-extract INDEPENDENTLY rather than accepting the operator confirmation, compare against the original inventory item by item, inspect authentication activity after the termination date, and classify unverifiable items as unverifiable rather than complete.\n2. Trace every inventoried item to a revocation or an owned exception, confirm late revocations are recorded as such rather than smoothed, verify residual access has a remediation owner, and return incomplete verification with precise comments.\n\n**Record in AssureSwarm**\n1. Record the verification result, post-revocation extract references and dates, item-by-item comparison, residual access with cause and owner, post-termination authentication observed, and items that could not be verified. Also record residual access detail.\n2. Capture the authorized reviewer, the revocation summary, HR-backed Personnel updates specified below, late revocations, residual access with owners and dates, unverifiable items, and linked issues raised.\n\nUpdate Personnel.engagement_end_date and Personnel.engagement_status only from the authoritative HR termination or engagement-end record and its effective date. Completed access revocation alone does not establish that the engagement ended; do not mark ended before the supported end date. Preserve Personnel.engagement_start_date and historical role dates. Put per-system access revocation/verification dates, the original entitlement inventory, credential rotations, late removals, residual access and unverifiable items in the markdown step result; attach source extracts and verification evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: An approver accepts that verification rests on independent re-extraction, residual access carries an owner and a date, and unverifiable items are declared rather than treated as clean. The authorized reviewer accepts the revocation record as evidence an access control operated for this leaver, late and residual items stay visible as control exceptions, and closure implies no assurance over systems outside the stated scope.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Tobias Fünke","itemType":"personnel","kind":"related"},{"itemTitle":"Never Nude HR Platform","itemType":"system","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Kitty Sanchez","itemType":"personnel","name":"Onboarding & Access Provisioning — Kitty Sanchez — next cycle","templateName":"Onboarding & Access Provisioning","templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","description":"Onboarding & Access Provisioning for Kitty Sanchez (next cycle).","status":"DRAFT","displayOrder":241,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Obtain entitlement approval","description":null,"summary":null,"instructions":"**Objective**\nObtain entitlement approval. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the signed offer or engagement record, the position description, the approved role-to-entitlement profile, the systems in scope, and pre-start conditions such as background screening.\n2. Use the confirmed profile, the entitlement catalogue, segregation-of-duties rules and the conflict matrix, system owner approval routes, privileged-access policy, and prior exceptions for comparable roles.\n\n**Procedure**\n1. Verify the joiner record against the authoritative HR source, confirm the role profile is current, identify entitlements requested outside the profile, check pre-start conditions are satisfied, and hold provisioning where authorization is incomplete.\n2. Route each entitlement to its authorized approver, test the COMBINED set against the conflict matrix rather than entitlement by entitlement, evaluate compensating measures where a conflict is accepted, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the start date, requested access profile, systems in scope, out-of-profile requests with justification, pre-start condition status, requesting manager, and authorization references.\n2. Document approved entitlements with approver and date, conflicts identified, disposition and compensating measures, privileged entitlements flagged separately, and requests declined with reasons. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The joiner and role profile are confirmed against an authoritative source, out-of-profile requests are justified, and provisioning does not begin on incomplete authorization. An approver accepts that every entitlement carries authorized approval and that conflicts are dispositioned rather than ignored; blocked conflicts stop provisioning instead of proceeding.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Kitty Sanchez","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve provisioning record","description":null,"summary":null,"instructions":"**Objective**\nApprove provisioning record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved entitlement list, system administration consoles and provisioning tooling, identity directory records, screenshots or extracts evidencing each grant, and the timing expectations in policy.\n2. Review all stage records, authorization references, entitlement approvals, conflict dispositions, provisioning evidence and reconciliation, deviations, and outstanding items with owners.\n\n**Procedure**\n1. Provision only what was approved, capture dated evidence per system, reconcile granted against approved line by line, record any grant made outside approval as a deviation, and confirm inherited or default entitlements were reviewed rather than assumed.\n2. Trace each granted entitlement to an approval, verify accepted conflicts carry compensating measures, confirm evidence covers every in-scope system, and return unreconciled deviations with precise comments.\n\n**Record in AssureSwarm**\n1. Document provisioned accounts and entitlements per system with evidence references and dates, the provisioning outcome, deviations with cause, inherited entitlements reviewed, and outstanding items with owners.\n2. Capture the authorized reviewer, the provisioning summary, HR-backed Personnel updates specified below, deviations accepted, outstanding items with owners and dates, and linked issues raised.\n\nUpdate Personnel.engagement_status and Personnel.engagement_start_date only from the authoritative HR or engagement record and its effective date. Provisioned access alone does not establish that the person is active; retain planned or unconfirmed status when that is the supported position. Record the approved role using Personnel.position_title, Personnel.department and Personnel.role_effective_date only when the source establishes those facts. Put access execution dates, requested/approved/granted entitlements, system evidence, accepted deviations and open exceptions in the markdown step result; attach extracts and grant evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: Granted access reconciles to approved access with deviations named, evidence is dated and system-specific, and outstanding items carry owners rather than being closed optimistically. The authorized reviewer accepts the provisioning record as evidence an access control operated for this joiner, and closure implies no assurance over entitlements granted outside this action.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Kitty Sanchez","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Marta Estrella","itemType":"personnel","name":"Onboarding & Access Provisioning — Marta Estrella — prior cycle","templateName":"Onboarding & Access Provisioning","templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","description":"Onboarding & Access Provisioning for Marta Estrella (prior cycle).","status":"COMPLETED","displayOrder":243,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Obtain entitlement approval","description":null,"summary":null,"instructions":"**Objective**\nObtain entitlement approval. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the signed offer or engagement record, the position description, the approved role-to-entitlement profile, the systems in scope, and pre-start conditions such as background screening.\n2. Use the confirmed profile, the entitlement catalogue, segregation-of-duties rules and the conflict matrix, system owner approval routes, privileged-access policy, and prior exceptions for comparable roles.\n\n**Procedure**\n1. Verify the joiner record against the authoritative HR source, confirm the role profile is current, identify entitlements requested outside the profile, check pre-start conditions are satisfied, and hold provisioning where authorization is incomplete.\n2. Route each entitlement to its authorized approver, test the COMBINED set against the conflict matrix rather than entitlement by entitlement, evaluate compensating measures where a conflict is accepted, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the start date, requested access profile, systems in scope, out-of-profile requests with justification, pre-start condition status, requesting manager, and authorization references.\n2. Document approved entitlements with approver and date, conflicts identified, disposition and compensating measures, privileged entitlements flagged separately, and requests declined with reasons. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The joiner and role profile are confirmed against an authoritative source, out-of-profile requests are justified, and provisioning does not begin on incomplete authorization. An approver accepts that every entitlement carries authorized approval and that conflicts are dispositioned rather than ignored; blocked conflicts stop provisioning instead of proceeding.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Marta Estrella","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve provisioning record","description":null,"summary":null,"instructions":"**Objective**\nApprove provisioning record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved entitlement list, system administration consoles and provisioning tooling, identity directory records, screenshots or extracts evidencing each grant, and the timing expectations in policy.\n2. Review all stage records, authorization references, entitlement approvals, conflict dispositions, provisioning evidence and reconciliation, deviations, and outstanding items with owners.\n\n**Procedure**\n1. Provision only what was approved, capture dated evidence per system, reconcile granted against approved line by line, record any grant made outside approval as a deviation, and confirm inherited or default entitlements were reviewed rather than assumed.\n2. Trace each granted entitlement to an approval, verify accepted conflicts carry compensating measures, confirm evidence covers every in-scope system, and return unreconciled deviations with precise comments.\n\n**Record in AssureSwarm**\n1. Document provisioned accounts and entitlements per system with evidence references and dates, the provisioning outcome, deviations with cause, inherited entitlements reviewed, and outstanding items with owners.\n2. Capture the authorized reviewer, the provisioning summary, HR-backed Personnel updates specified below, deviations accepted, outstanding items with owners and dates, and linked issues raised.\n\nUpdate Personnel.engagement_status and Personnel.engagement_start_date only from the authoritative HR or engagement record and its effective date. Provisioned access alone does not establish that the person is active; retain planned or unconfirmed status when that is the supported position. Record the approved role using Personnel.position_title, Personnel.department and Personnel.role_effective_date only when the source establishes those facts. Put access execution dates, requested/approved/granted entitlements, system evidence, accepted deviations and open exceptions in the markdown step result; attach extracts and grant evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: Granted access reconciles to approved access with deviations named, evidence is dated and system-specific, and outstanding items carry owners rather than being closed optimistically. The authorized reviewer accepts the provisioning record as evidence an access control operated for this joiner, and closure implies no assurance over entitlements granted outside this action.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Marta Estrella","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Steve Holt","itemType":"personnel","name":"Onboarding & Access Provisioning — Steve Holt — current cycle","templateName":"Onboarding & Access Provisioning","templateSourceId":"coworkcanvas:template:onboarding-access-provisioning","description":"Onboarding & Access Provisioning for Steve Holt (current cycle).","status":"ACTIVE","displayOrder":242,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Obtain entitlement approval","description":null,"summary":null,"instructions":"**Objective**\nObtain entitlement approval. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the signed offer or engagement record, the position description, the approved role-to-entitlement profile, the systems in scope, and pre-start conditions such as background screening.\n2. Use the confirmed profile, the entitlement catalogue, segregation-of-duties rules and the conflict matrix, system owner approval routes, privileged-access policy, and prior exceptions for comparable roles.\n\n**Procedure**\n1. Verify the joiner record against the authoritative HR source, confirm the role profile is current, identify entitlements requested outside the profile, check pre-start conditions are satisfied, and hold provisioning where authorization is incomplete.\n2. Route each entitlement to its authorized approver, test the COMBINED set against the conflict matrix rather than entitlement by entitlement, evaluate compensating measures where a conflict is accepted, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the start date, requested access profile, systems in scope, out-of-profile requests with justification, pre-start condition status, requesting manager, and authorization references.\n2. Document approved entitlements with approver and date, conflicts identified, disposition and compensating measures, privileged entitlements flagged separately, and requests declined with reasons. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The joiner and role profile are confirmed against an authoritative source, out-of-profile requests are justified, and provisioning does not begin on incomplete authorization. An approver accepts that every entitlement carries authorized approval and that conflicts are dispositioned rather than ignored; blocked conflicts stop provisioning instead of proceeding.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Steve Holt","itemType":"personnel","kind":"related"},{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve provisioning record","description":null,"summary":null,"instructions":"**Objective**\nApprove provisioning record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved entitlement list, system administration consoles and provisioning tooling, identity directory records, screenshots or extracts evidencing each grant, and the timing expectations in policy.\n2. Review all stage records, authorization references, entitlement approvals, conflict dispositions, provisioning evidence and reconciliation, deviations, and outstanding items with owners.\n\n**Procedure**\n1. Provision only what was approved, capture dated evidence per system, reconcile granted against approved line by line, record any grant made outside approval as a deviation, and confirm inherited or default entitlements were reviewed rather than assumed.\n2. Trace each granted entitlement to an approval, verify accepted conflicts carry compensating measures, confirm evidence covers every in-scope system, and return unreconciled deviations with precise comments.\n\n**Record in AssureSwarm**\n1. Document provisioned accounts and entitlements per system with evidence references and dates, the provisioning outcome, deviations with cause, inherited entitlements reviewed, and outstanding items with owners.\n2. Capture the authorized reviewer, the provisioning summary, HR-backed Personnel updates specified below, deviations accepted, outstanding items with owners and dates, and linked issues raised.\n\nUpdate Personnel.engagement_status and Personnel.engagement_start_date only from the authoritative HR or engagement record and its effective date. Provisioned access alone does not establish that the person is active; retain planned or unconfirmed status when that is the supported position. Record the approved role using Personnel.position_title, Personnel.department and Personnel.role_effective_date only when the source establishes those facts. Put access execution dates, requested/approved/granted entitlements, system evidence, accepted deviations and open exceptions in the markdown step result; attach extracts and grant evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: Granted access reconciles to approved access with deviations named, evidence is dated and system-specific, and outstanding items carry owners rather than being closed optimistically. The authorized reviewer accepts the provisioning record as evidence an access control operated for this joiner, and closure implies no assurance over entitlements granted outside this action.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Steve Holt","itemType":"personnel","kind":"related"},{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Banana ERP","itemType":"system","name":"Periodic User Access Review — Banana ERP — next cycle","templateName":"Periodic User Access Review","templateSourceId":"coworkcanvas:template:periodic-user-access-review","description":"Periodic User Access Review for Banana ERP (next cycle).","status":"DRAFT","displayOrder":251,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Distribute entitlement listings","description":null,"summary":null,"instructions":"**Objective**\nDistribute entitlement listings. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the entitlement extract and how it was generated, the identity directory, the reviewer assignment map, prior review results, and the recertification cadence in policy.\n2. Use the reconciled population, reviewer assignments, distribution tooling or campaign records, the response deadline, and escalation contacts for non-responding reviewers.\n\n**Procedure**\n1. Reconcile the extract to an independent count so completeness is evidenced rather than assumed, confirm reviewers hold the authority to decide, identify accounts with no accountable reviewer, and note privileged and service accounts requiring separate handling.\n2. Dispatch listings with the decision options and deadline stated, reconcile distributed line counts back to the population, chase undelivered listings, and record accounts covered by no dispatched listing as a gap rather than an omission.\n\n**Record in AssureSwarm**\n1. Capture the review period, population basis and reconciliation, extract date and generator, reviewer assignments, orphaned accounts, service and privileged accounts, and completeness limitations.\n2. Document reviewer assignments and dispatch dates, distribution status, line-count reconciliation to the population, undelivered listings, non-responding reviewers, and accounts left uncovered.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is evidenced as complete, every account has an accountable reviewer, and orphaned or unreviewable accounts are visible rather than dropped. Distributed listings reconcile to the population, the deadline and decision options were communicated, and uncovered accounts are named rather than silently excluded.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve access review record","description":null,"summary":null,"instructions":"**Objective**\nApprove access review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use returned reviewer responses and their timestamps, revocation tickets and system evidence, post-revocation extracts, non-response records, and prior-period recurring exceptions.\n2. Review all stage records, the population reconciliation, distribution coverage, reviewer responses, revocation evidence, non-responses, and residual exceptions with owners.\n\n**Procedure**\n1. Test response quality for blanket approval patterns and implausible turnaround, trace each removal decision to executed revocation evidence, re-extract to confirm removal, and treat non-response as a failure rather than as implicit approval.\n2. Trace the outcome to the population basis, verify uncovered accounts and non-responses carry owners, confirm revocation evidence is dated and independent, and return blanket-approval patterns with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, response rates and quality observations, removal decisions traced to revocation evidence, revocations not executed, non-responses and their treatment, and recurring exceptions. Also record revocation detail and execution evidence.\n2. Capture the authorized reviewer, the review summary, accepted outcome, effective review date, next recertification cadence, unresolved exceptions with owners and dates, and linked issues raised. Also record access review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that decisions are evidenced rather than rubber-stamped, required revocations are confirmed executed by re-extraction, and non-response is treated as an exception rather than approval. The authorized reviewer accepts the record as evidence the recertification control operated for the period, and closure implies no assurance over accounts excluded from the population.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Cornballer Revenue Engine","itemType":"system","name":"Periodic User Access Review — Cornballer Revenue Engine — prior cycle","templateName":"Periodic User Access Review","templateSourceId":"coworkcanvas:template:periodic-user-access-review","description":"Periodic User Access Review for Cornballer Revenue Engine (prior cycle).","status":"COMPLETED","displayOrder":253,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Distribute entitlement listings","description":null,"summary":null,"instructions":"**Objective**\nDistribute entitlement listings. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the entitlement extract and how it was generated, the identity directory, the reviewer assignment map, prior review results, and the recertification cadence in policy.\n2. Use the reconciled population, reviewer assignments, distribution tooling or campaign records, the response deadline, and escalation contacts for non-responding reviewers.\n\n**Procedure**\n1. Reconcile the extract to an independent count so completeness is evidenced rather than assumed, confirm reviewers hold the authority to decide, identify accounts with no accountable reviewer, and note privileged and service accounts requiring separate handling.\n2. Dispatch listings with the decision options and deadline stated, reconcile distributed line counts back to the population, chase undelivered listings, and record accounts covered by no dispatched listing as a gap rather than an omission.\n\n**Record in AssureSwarm**\n1. Capture the review period, population basis and reconciliation, extract date and generator, reviewer assignments, orphaned accounts, service and privileged accounts, and completeness limitations.\n2. Document reviewer assignments and dispatch dates, distribution status, line-count reconciliation to the population, undelivered listings, non-responding reviewers, and accounts left uncovered.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is evidenced as complete, every account has an accountable reviewer, and orphaned or unreviewable accounts are visible rather than dropped. Distributed listings reconcile to the population, the deadline and decision options were communicated, and uncovered accounts are named rather than silently excluded.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve access review record","description":null,"summary":null,"instructions":"**Objective**\nApprove access review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use returned reviewer responses and their timestamps, revocation tickets and system evidence, post-revocation extracts, non-response records, and prior-period recurring exceptions.\n2. Review all stage records, the population reconciliation, distribution coverage, reviewer responses, revocation evidence, non-responses, and residual exceptions with owners.\n\n**Procedure**\n1. Test response quality for blanket approval patterns and implausible turnaround, trace each removal decision to executed revocation evidence, re-extract to confirm removal, and treat non-response as a failure rather than as implicit approval.\n2. Trace the outcome to the population basis, verify uncovered accounts and non-responses carry owners, confirm revocation evidence is dated and independent, and return blanket-approval patterns with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, response rates and quality observations, removal decisions traced to revocation evidence, revocations not executed, non-responses and their treatment, and recurring exceptions. Also record revocation detail and execution evidence.\n2. Capture the authorized reviewer, the review summary, accepted outcome, effective review date, next recertification cadence, unresolved exceptions with owners and dates, and linked issues raised. Also record access review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that decisions are evidenced rather than rubber-stamped, required revocations are confirmed executed by re-extraction, and non-response is treated as an exception rather than approval. The authorized reviewer accepts the record as evidence the recertification control operated for the period, and closure implies no assurance over accounts excluded from the population.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Lucille Identity Cloud","itemType":"system","name":"Periodic User Access Review — Lucille Identity Cloud — current cycle","templateName":"Periodic User Access Review","templateSourceId":"coworkcanvas:template:periodic-user-access-review","description":"Periodic User Access Review for Lucille Identity Cloud (current cycle).","status":"ACTIVE","displayOrder":252,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Distribute entitlement listings","description":null,"summary":null,"instructions":"**Objective**\nDistribute entitlement listings. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the entitlement extract and how it was generated, the identity directory, the reviewer assignment map, prior review results, and the recertification cadence in policy.\n2. Use the reconciled population, reviewer assignments, distribution tooling or campaign records, the response deadline, and escalation contacts for non-responding reviewers.\n\n**Procedure**\n1. Reconcile the extract to an independent count so completeness is evidenced rather than assumed, confirm reviewers hold the authority to decide, identify accounts with no accountable reviewer, and note privileged and service accounts requiring separate handling.\n2. Dispatch listings with the decision options and deadline stated, reconcile distributed line counts back to the population, chase undelivered listings, and record accounts covered by no dispatched listing as a gap rather than an omission.\n\n**Record in AssureSwarm**\n1. Capture the review period, population basis and reconciliation, extract date and generator, reviewer assignments, orphaned accounts, service and privileged accounts, and completeness limitations.\n2. Document reviewer assignments and dispatch dates, distribution status, line-count reconciliation to the population, undelivered listings, non-responding reviewers, and accounts left uncovered.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is evidenced as complete, every account has an accountable reviewer, and orphaned or unreviewable accounts are visible rather than dropped. Distributed listings reconcile to the population, the deadline and decision options were communicated, and uncovered accounts are named rather than silently excluded.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"},{"itemTitle":"Authenticate all users with multi-factor authentication","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve access review record","description":null,"summary":null,"instructions":"**Objective**\nApprove access review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use returned reviewer responses and their timestamps, revocation tickets and system evidence, post-revocation extracts, non-response records, and prior-period recurring exceptions.\n2. Review all stage records, the population reconciliation, distribution coverage, reviewer responses, revocation evidence, non-responses, and residual exceptions with owners.\n\n**Procedure**\n1. Test response quality for blanket approval patterns and implausible turnaround, trace each removal decision to executed revocation evidence, re-extract to confirm removal, and treat non-response as a failure rather than as implicit approval.\n2. Trace the outcome to the population basis, verify uncovered accounts and non-responses carry owners, confirm revocation evidence is dated and independent, and return blanket-approval patterns with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, response rates and quality observations, removal decisions traced to revocation evidence, revocations not executed, non-responses and their treatment, and recurring exceptions. Also record revocation detail and execution evidence.\n2. Capture the authorized reviewer, the review summary, accepted outcome, effective review date, next recertification cadence, unresolved exceptions with owners and dates, and linked issues raised. Also record access review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that decisions are evidenced rather than rubber-stamped, required revocations are confirmed executed by re-extraction, and non-response is treated as an exception rather than approval. The authorized reviewer accepts the record as evidence the recertification control operated for the period, and closure implies no assurance over accounts excluded from the population.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"},{"itemTitle":"Authenticate all users with multi-factor authentication","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Access Control Standard","itemType":"policy","name":"Annual Policy Review — Access Control Standard — next cycle","templateName":"Annual Policy Review","templateSourceId":"coworkcanvas:template:policy-annual-review","description":"Annual Policy Review for Access Control Standard (next cycle).","status":"DRAFT","displayOrder":261,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Policy owner review & sign-off","description":null,"summary":null,"instructions":"**Objective**\nPolicy owner review & sign-off. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current policy document, Policy item metadata, prior review, open policy changes, mapped requirements and controls, exceptions, incidents, audit findings, and organization changes.\n2. Use the scoped policy, current operating procedures, organization and system changes, incidents, exceptions, control and requirement mappings, stakeholder feedback, and prior commitments.\n\n**Procedure**\n1. Verify the authoritative version and review population, identify stakeholders and legal or subject-matter input, reconcile outstanding changes, and define which updates belong in this review versus a separate Policy Change workflow.\n2. Read the policy end to end, verify scope, roles, statements, links, and procedures, compare documented requirements to observed practice, correct purely editorial issues, and route substantive revisions through Policy Change.\n\n**Record in AssureSwarm**\n1. Document the version, effective and next-review dates, scope, participants, sources to be consulted, linked changes or issues, and any limitations that could prevent a complete review. Also record review period.\n2. Complete the preserved outcome, summary, and attestation fields; list sources and stakeholders reviewed, editorial corrections, gaps, affected sections, and the source ID of any required Policy Change.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `outcome` (Review outcome; values: current, updated, revision_required) in Step.result markdown.\n\nRecord `summary` (Review summary) in Step.result markdown.\n\nRecord `attestation` (I attest this policy is accurate, current, and aligned to practice) in Step.result markdown.\n\n**Exit criteria**\nPolicy owner provides expertise: The document of record and review boundary are unambiguous, required stakeholders are identified, open change work is visible, and the owner can begin substantive review. The owner outcome is supported by a specific review summary, substantive changes are not hidden as editorial edits, and any required revision has a defined owner and next action.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Access Control Standard","itemType":"policy","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve annual review record","description":null,"summary":null,"instructions":"**Objective**\nApprove annual review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the authoritative policy and metadata, intake scope, owner outcome and evidence, editorial updates, linked Policy Change, mapped requirements and controls, and applicable review cadence.\n2. Use the intake record, the policy owner’s upstream markdown result and native approval, the policy team’s current review result, supporting evidence, approved editorial updates, linked substantive change work, Policy item metadata, and unresolved conditions.\n\n**Procedure**\n1. Verify the owner considered relevant change signals, inspect changes against document-control rules, challenge stale or unsupported statements, confirm required approvers and audiences, and calculate the next review date consistently.\n2. Trace each sign-off to its evidence, verify the decision and dates agree across records, confirm substantive revisions have not been published without approval, and return incomplete or inconsistent work with explicit comments.\n\n**Record in AssureSwarm**\n1. Complete the preserved decision, next-review-date, and comments fields; capture review notes, owner resolutions, related change references, and any conditions that must be met before approval.\n2. Record the policy owner’s upstream review and the independent policy authority’s native approval, closure summary, date, final review outcome, mirrored next review date, open Policy Change or other follow-up, owner, and due date. Also record annual review closure summary.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `decision` (Decision; values: approve, return) in Step.result markdown.\n\nRecord `next_review_date` (Next review date) in Policy.fields.next_review_date.\n\nRecord `comments` (Policy team comments) in Step.result markdown.\n\n**Exit criteria**\nPolicy governance approval authority provides approval: The policy-team decision is supported, returned items are specific and assigned, the next review date is accurate, and the final closure reviewer has a complete governance record. The authorized reviewer accepts a coherent review record, Policy metadata can be updated without ambiguity, all substantive follow-up remains trackable, and closure is not represented as certification.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Access Control Standard","itemType":"policy","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Audit Committee Charter","itemType":"policy","name":"Annual Policy Review — Audit Committee Charter — current cycle","templateName":"Annual Policy Review","templateSourceId":"coworkcanvas:template:policy-annual-review","description":"Annual Policy Review for Audit Committee Charter (current cycle).","status":"ACTIVE","displayOrder":262,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Policy owner review & sign-off","description":null,"summary":null,"instructions":"**Objective**\nPolicy owner review & sign-off. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current policy document, Policy item metadata, prior review, open policy changes, mapped requirements and controls, exceptions, incidents, audit findings, and organization changes.\n2. Use the scoped policy, current operating procedures, organization and system changes, incidents, exceptions, control and requirement mappings, stakeholder feedback, and prior commitments.\n\n**Procedure**\n1. Verify the authoritative version and review population, identify stakeholders and legal or subject-matter input, reconcile outstanding changes, and define which updates belong in this review versus a separate Policy Change workflow.\n2. Read the policy end to end, verify scope, roles, statements, links, and procedures, compare documented requirements to observed practice, correct purely editorial issues, and route substantive revisions through Policy Change.\n\n**Record in AssureSwarm**\n1. Document the version, effective and next-review dates, scope, participants, sources to be consulted, linked changes or issues, and any limitations that could prevent a complete review. Also record review period.\n2. Complete the preserved outcome, summary, and attestation fields; list sources and stakeholders reviewed, editorial corrections, gaps, affected sections, and the source ID of any required Policy Change.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `outcome` (Review outcome; values: current, updated, revision_required) in Step.result markdown.\n\nRecord `summary` (Review summary) in Step.result markdown.\n\nRecord `attestation` (I attest this policy is accurate, current, and aligned to practice) in Step.result markdown.\n\n**Exit criteria**\nPolicy owner provides expertise: The document of record and review boundary are unambiguous, required stakeholders are identified, open change work is visible, and the owner can begin substantive review. The owner outcome is supported by a specific review summary, substantive changes are not hidden as editorial edits, and any required revision has a defined owner and next action.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Audit Committee Charter","itemType":"policy","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve annual review record","description":null,"summary":null,"instructions":"**Objective**\nApprove annual review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the authoritative policy and metadata, intake scope, owner outcome and evidence, editorial updates, linked Policy Change, mapped requirements and controls, and applicable review cadence.\n2. Use the intake record, the policy owner’s upstream markdown result and native approval, the policy team’s current review result, supporting evidence, approved editorial updates, linked substantive change work, Policy item metadata, and unresolved conditions.\n\n**Procedure**\n1. Verify the owner considered relevant change signals, inspect changes against document-control rules, challenge stale or unsupported statements, confirm required approvers and audiences, and calculate the next review date consistently.\n2. Trace each sign-off to its evidence, verify the decision and dates agree across records, confirm substantive revisions have not been published without approval, and return incomplete or inconsistent work with explicit comments.\n\n**Record in AssureSwarm**\n1. Complete the preserved decision, next-review-date, and comments fields; capture review notes, owner resolutions, related change references, and any conditions that must be met before approval.\n2. Record the policy owner’s upstream review and the independent policy authority’s native approval, closure summary, date, final review outcome, mirrored next review date, open Policy Change or other follow-up, owner, and due date. Also record annual review closure summary.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `decision` (Decision; values: approve, return) in Step.result markdown.\n\nRecord `next_review_date` (Next review date) in Policy.fields.next_review_date.\n\nRecord `comments` (Policy team comments) in Step.result markdown.\n\n**Exit criteria**\nPolicy governance approval authority provides approval: The policy-team decision is supported, returned items are specific and assigned, the next review date is accurate, and the final closure reviewer has a complete governance record. The authorized reviewer accepts a coherent review record, Policy metadata can be updated without ambiguity, all substantive follow-up remains trackable, and closure is not represented as certification.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Audit Committee Charter","itemType":"policy","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Business Continuity Standard","itemType":"policy","name":"Annual Policy Review — Business Continuity Standard — prior cycle","templateName":"Annual Policy Review","templateSourceId":"coworkcanvas:template:policy-annual-review","description":"Annual Policy Review for Business Continuity Standard (prior cycle).","status":"COMPLETED","displayOrder":263,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Policy owner review & sign-off","description":null,"summary":null,"instructions":"**Objective**\nPolicy owner review & sign-off. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the current policy document, Policy item metadata, prior review, open policy changes, mapped requirements and controls, exceptions, incidents, audit findings, and organization changes.\n2. Use the scoped policy, current operating procedures, organization and system changes, incidents, exceptions, control and requirement mappings, stakeholder feedback, and prior commitments.\n\n**Procedure**\n1. Verify the authoritative version and review population, identify stakeholders and legal or subject-matter input, reconcile outstanding changes, and define which updates belong in this review versus a separate Policy Change workflow.\n2. Read the policy end to end, verify scope, roles, statements, links, and procedures, compare documented requirements to observed practice, correct purely editorial issues, and route substantive revisions through Policy Change.\n\n**Record in AssureSwarm**\n1. Document the version, effective and next-review dates, scope, participants, sources to be consulted, linked changes or issues, and any limitations that could prevent a complete review. Also record review period.\n2. Complete the preserved outcome, summary, and attestation fields; list sources and stakeholders reviewed, editorial corrections, gaps, affected sections, and the source ID of any required Policy Change.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `outcome` (Review outcome; values: current, updated, revision_required) in Step.result markdown.\n\nRecord `summary` (Review summary) in Step.result markdown.\n\nRecord `attestation` (I attest this policy is accurate, current, and aligned to practice) in Step.result markdown.\n\n**Exit criteria**\nPolicy owner provides expertise: The document of record and review boundary are unambiguous, required stakeholders are identified, open change work is visible, and the owner can begin substantive review. The owner outcome is supported by a specific review summary, substantive changes are not hidden as editorial edits, and any required revision has a defined owner and next action.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Business Continuity Standard","itemType":"policy","kind":"related"},{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve annual review record","description":null,"summary":null,"instructions":"**Objective**\nApprove annual review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the authoritative policy and metadata, intake scope, owner outcome and evidence, editorial updates, linked Policy Change, mapped requirements and controls, and applicable review cadence.\n2. Use the intake record, the policy owner’s upstream markdown result and native approval, the policy team’s current review result, supporting evidence, approved editorial updates, linked substantive change work, Policy item metadata, and unresolved conditions.\n\n**Procedure**\n1. Verify the owner considered relevant change signals, inspect changes against document-control rules, challenge stale or unsupported statements, confirm required approvers and audiences, and calculate the next review date consistently.\n2. Trace each sign-off to its evidence, verify the decision and dates agree across records, confirm substantive revisions have not been published without approval, and return incomplete or inconsistent work with explicit comments.\n\n**Record in AssureSwarm**\n1. Complete the preserved decision, next-review-date, and comments fields; capture review notes, owner resolutions, related change references, and any conditions that must be met before approval.\n2. Record the policy owner’s upstream review and the independent policy authority’s native approval, closure summary, date, final review outcome, mirrored next review date, open Policy Change or other follow-up, owner, and due date. Also record annual review closure summary.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `decision` (Decision; values: approve, return) in Step.result markdown.\n\nRecord `next_review_date` (Next review date) in Policy.fields.next_review_date.\n\nRecord `comments` (Policy team comments) in Step.result markdown.\n\n**Exit criteria**\nPolicy governance approval authority provides approval: The policy-team decision is supported, returned items are specific and assigned, the next review date is accurate, and the final closure reviewer has a complete governance record. The authorized reviewer accepts a coherent review record, Policy metadata can be updated without ambiguity, all substantive follow-up remains trackable, and closure is not represented as certification.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Business Continuity Standard","itemType":"policy","kind":"related"},{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Access Control Standard","itemType":"policy","name":"Policy Change — Access Control Standard — next cycle","templateName":"Policy Change","templateSourceId":"coworkcanvas:template:policy-change","description":"Policy Change for Access Control Standard (next cycle).","status":"DRAFT","displayOrder":271,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm the scope and propose the change","description":null,"summary":null,"instructions":"**Objective**\nConfirm the scope and propose the change. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the current controlled document and Policy item, the triggering review, regulatory change, issue, incident or business change, the authoritative source for the driver, related policies, mapped requirements and controls, stakeholder input and document standards.\n\n**Procedure**\n1. Confirm the request is not a duplicate, define the problem and desired outcome, and identify affected obligations, processes, controls, systems, owners, audiences and any urgent interim instruction. Then draft a redline, explain each substantive change, distinguish consequential edits from cleanup, analyze downstream effects, and define implementation and communication needs.\n\n**Record in AssureSwarm**\n1. Record the change request reference, current version, scope summary, initiator, stakeholders, dependencies, urgency, duplicate search and interim measures; complete the preserved change-summary, driver, sections-affected and proposed-effective-date fields; attach the redline and impact analysis and link the triggering issue, requirement or annual review.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `change_summary` (Proposed change) in Step.result markdown.\n\nRecord `driver` (Reason for the change; values: regulatory_change, audit_finding, incident_lesson, business_change, annual_review, other) in Step.result markdown.\n\nRecord `sections_affected` (Sections affected) in Step.result markdown.\n\nRecord `proposed_effective_date` (Proposed effective date) in Step.result markdown.\n\n**Exit criteria**\nPolicy owner provides expertise: The change boundary and governance route are clear, the exact proposal and rationale are understandable without oral context, affected records and audiences are listed, and the policy team can approve, reject or return the defined change.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Access Control Standard","itemType":"policy","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve policy change record","description":null,"summary":null,"instructions":"**Objective**\nApprove policy change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review intake, redline, preserved proposal fields, driver evidence, impacted policies and controls, stakeholder and legal input, proposed date, implementation plan, and current document standards.\n2. Use the approved redline and conditions, current controlled document, version convention, effective date, distribution list, training and procedure impacts, archive rules, and owner and approver metadata.\n3. Review intake, proposal and redline, policy-team decision, final comparison, published document, archive record, Policy item metadata, communication evidence, and open follow-up.\n\n**Procedure**\n1. Compare proposed language to authoritative obligations, challenge conflicts and vague responsibilities, verify affected controls and procedures, ensure the approver has authority, and record conditions or reasons for approval, rejection, or return.\n2. Compare the final document to the approved redline, prevent unapproved edits, update version and effective date, archive the superseded copy, refresh related procedures and links, and communicate to affected audiences.\n3. Verify the final version implements exactly the approved change and conditions, reconcile version and effective dates, confirm distribution evidence, and return the workflow if records conflict or work remains unassigned.\n\n**Record in AssureSwarm**\n1. Complete the preserved decision and comments fields, identify the exact redline reviewed, capture approver and date, list conditions, and link any additional evidence or required rework.\n2. Complete the preserved new-version, effective-date, and communicated fields; attach or link the published document, comparison proof, archive reference, distribution evidence, and implementation follow-up.\n3. Record the policy owner’s upstream review and the independent policy authority’s native approval, summary, date, published version reference, effective date, communication completion, linked records, and all remaining owners and due dates. Also record policy change closure summary.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `decision` (Decision; values: approve, reject, return) in Step.result markdown.\n\nRecord `comments` (Policy team comments) in Step.result markdown.\n\nRecord `new_version` (New version) in Policy.fields.version.\n\nRecord `effective_date` (Effective date) in Policy.fields.effective_date.\n\nRecord `communicated` (Affected teams notified) in Step.result markdown.\n\n**Exit criteria**\nPolicy governance approval authority provides approval: The decision is supported and scoped to the submitted proposal, approval conditions are explicit, and publication cannot proceed on a rejected, returned, or subsequently changed draft. The published document matches approval, the superseded version is controlled, Policy metadata is current, communications are evidenced, and unresolved implementation tasks are assigned. The authorized reviewer accepts a traceable controlled-change record, metadata and document references agree, remaining actions are monitored, and closure does not imply certification or an audit conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Access Control Standard","itemType":"policy","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Financial Close Procedure","itemType":"policy","name":"Policy Change — Financial Close Procedure — current cycle","templateName":"Policy Change","templateSourceId":"coworkcanvas:template:policy-change","description":"Policy Change for Financial Close Procedure (current cycle).","status":"ACTIVE","displayOrder":272,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm the scope and propose the change","description":null,"summary":null,"instructions":"**Objective**\nConfirm the scope and propose the change. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the current controlled document and Policy item, the triggering review, regulatory change, issue, incident or business change, the authoritative source for the driver, related policies, mapped requirements and controls, stakeholder input and document standards.\n\n**Procedure**\n1. Confirm the request is not a duplicate, define the problem and desired outcome, and identify affected obligations, processes, controls, systems, owners, audiences and any urgent interim instruction. Then draft a redline, explain each substantive change, distinguish consequential edits from cleanup, analyze downstream effects, and define implementation and communication needs.\n\n**Record in AssureSwarm**\n1. Record the change request reference, current version, scope summary, initiator, stakeholders, dependencies, urgency, duplicate search and interim measures; complete the preserved change-summary, driver, sections-affected and proposed-effective-date fields; attach the redline and impact analysis and link the triggering issue, requirement or annual review.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `change_summary` (Proposed change) in Step.result markdown.\n\nRecord `driver` (Reason for the change; values: regulatory_change, audit_finding, incident_lesson, business_change, annual_review, other) in Step.result markdown.\n\nRecord `sections_affected` (Sections affected) in Step.result markdown.\n\nRecord `proposed_effective_date` (Proposed effective date) in Step.result markdown.\n\n**Exit criteria**\nPolicy owner provides expertise: The change boundary and governance route are clear, the exact proposal and rationale are understandable without oral context, affected records and audiences are listed, and the policy team can approve, reject or return the defined change.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Financial Close Procedure","itemType":"policy","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve policy change record","description":null,"summary":null,"instructions":"**Objective**\nApprove policy change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review intake, redline, preserved proposal fields, driver evidence, impacted policies and controls, stakeholder and legal input, proposed date, implementation plan, and current document standards.\n2. Use the approved redline and conditions, current controlled document, version convention, effective date, distribution list, training and procedure impacts, archive rules, and owner and approver metadata.\n3. Review intake, proposal and redline, policy-team decision, final comparison, published document, archive record, Policy item metadata, communication evidence, and open follow-up.\n\n**Procedure**\n1. Compare proposed language to authoritative obligations, challenge conflicts and vague responsibilities, verify affected controls and procedures, ensure the approver has authority, and record conditions or reasons for approval, rejection, or return.\n2. Compare the final document to the approved redline, prevent unapproved edits, update version and effective date, archive the superseded copy, refresh related procedures and links, and communicate to affected audiences.\n3. Verify the final version implements exactly the approved change and conditions, reconcile version and effective dates, confirm distribution evidence, and return the workflow if records conflict or work remains unassigned.\n\n**Record in AssureSwarm**\n1. Complete the preserved decision and comments fields, identify the exact redline reviewed, capture approver and date, list conditions, and link any additional evidence or required rework.\n2. Complete the preserved new-version, effective-date, and communicated fields; attach or link the published document, comparison proof, archive reference, distribution evidence, and implementation follow-up.\n3. Record the policy owner’s upstream review and the independent policy authority’s native approval, summary, date, published version reference, effective date, communication completion, linked records, and all remaining owners and due dates. Also record policy change closure summary.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `decision` (Decision; values: approve, reject, return) in Step.result markdown.\n\nRecord `comments` (Policy team comments) in Step.result markdown.\n\nRecord `new_version` (New version) in Policy.fields.version.\n\nRecord `effective_date` (Effective date) in Policy.fields.effective_date.\n\nRecord `communicated` (Affected teams notified) in Step.result markdown.\n\n**Exit criteria**\nPolicy governance approval authority provides approval: The decision is supported and scoped to the submitted proposal, approval conditions are explicit, and publication cannot proceed on a rejected, returned, or subsequently changed draft. The published document matches approval, the superseded version is controlled, Policy metadata is current, communications are evidenced, and unresolved implementation tasks are assigned. The authorized reviewer accepts a traceable controlled-change record, metadata and document references agree, remaining actions are monitored, and closure does not imply certification or an audit conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Financial Close Procedure","itemType":"policy","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Information Security Policy","itemType":"policy","name":"Policy Change — Information Security Policy — prior cycle","templateName":"Policy Change","templateSourceId":"coworkcanvas:template:policy-change","description":"Policy Change for Information Security Policy (prior cycle).","status":"COMPLETED","displayOrder":273,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Confirm the scope and propose the change","description":null,"summary":null,"instructions":"**Objective**\nConfirm the scope and propose the change. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the current controlled document and Policy item, the triggering review, regulatory change, issue, incident or business change, the authoritative source for the driver, related policies, mapped requirements and controls, stakeholder input and document standards.\n\n**Procedure**\n1. Confirm the request is not a duplicate, define the problem and desired outcome, and identify affected obligations, processes, controls, systems, owners, audiences and any urgent interim instruction. Then draft a redline, explain each substantive change, distinguish consequential edits from cleanup, analyze downstream effects, and define implementation and communication needs.\n\n**Record in AssureSwarm**\n1. Record the change request reference, current version, scope summary, initiator, stakeholders, dependencies, urgency, duplicate search and interim measures; complete the preserved change-summary, driver, sections-affected and proposed-effective-date fields; attach the redline and impact analysis and link the triggering issue, requirement or annual review.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `change_summary` (Proposed change) in Step.result markdown.\n\nRecord `driver` (Reason for the change; values: regulatory_change, audit_finding, incident_lesson, business_change, annual_review, other) in Step.result markdown.\n\nRecord `sections_affected` (Sections affected) in Step.result markdown.\n\nRecord `proposed_effective_date` (Proposed effective date) in Step.result markdown.\n\n**Exit criteria**\nPolicy owner provides expertise: The change boundary and governance route are clear, the exact proposal and rationale are understandable without oral context, affected records and audiences are listed, and the policy team can approve, reject or return the defined change.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Information Security Policy","itemType":"policy","kind":"related"},{"itemTitle":"Batch Processing Monitoring","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve policy change record","description":null,"summary":null,"instructions":"**Objective**\nApprove policy change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review intake, redline, preserved proposal fields, driver evidence, impacted policies and controls, stakeholder and legal input, proposed date, implementation plan, and current document standards.\n2. Use the approved redline and conditions, current controlled document, version convention, effective date, distribution list, training and procedure impacts, archive rules, and owner and approver metadata.\n3. Review intake, proposal and redline, policy-team decision, final comparison, published document, archive record, Policy item metadata, communication evidence, and open follow-up.\n\n**Procedure**\n1. Compare proposed language to authoritative obligations, challenge conflicts and vague responsibilities, verify affected controls and procedures, ensure the approver has authority, and record conditions or reasons for approval, rejection, or return.\n2. Compare the final document to the approved redline, prevent unapproved edits, update version and effective date, archive the superseded copy, refresh related procedures and links, and communicate to affected audiences.\n3. Verify the final version implements exactly the approved change and conditions, reconcile version and effective dates, confirm distribution evidence, and return the workflow if records conflict or work remains unassigned.\n\n**Record in AssureSwarm**\n1. Complete the preserved decision and comments fields, identify the exact redline reviewed, capture approver and date, list conditions, and link any additional evidence or required rework.\n2. Complete the preserved new-version, effective-date, and communicated fields; attach or link the published document, comparison proof, archive reference, distribution evidence, and implementation follow-up.\n3. Record the policy owner’s upstream review and the independent policy authority’s native approval, summary, date, published version reference, effective date, communication completion, linked records, and all remaining owners and due dates. Also record policy change closure summary.\nRecord executor decisions and rationale in the markdown step result. Update Policy.next_review_date, version and effective_date only when the reviewed outcome calls for those fields. Use native approval records for sign-off.\n\nRecord `decision` (Decision; values: approve, reject, return) in Step.result markdown.\n\nRecord `comments` (Policy team comments) in Step.result markdown.\n\nRecord `new_version` (New version) in Policy.fields.version.\n\nRecord `effective_date` (Effective date) in Policy.fields.effective_date.\n\nRecord `communicated` (Affected teams notified) in Step.result markdown.\n\n**Exit criteria**\nPolicy governance approval authority provides approval: The decision is supported and scoped to the submitted proposal, approval conditions are explicit, and publication cannot proceed on a rejected, returned, or subsequently changed draft. The published document matches approval, the superseded version is controlled, Policy metadata is current, communications are evidenced, and unresolved implementation tasks are assigned. The authorized reviewer accepts a traceable controlled-change record, metadata and document references agree, remaining actions are monitored, and closure does not imply certification or an audit conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Information Security Policy","itemType":"policy","kind":"related"},{"itemTitle":"Batch Processing Monitoring","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Banana ERP","itemType":"system","name":"Privileged Access Review — Banana ERP — current cycle","templateName":"Privileged Access Review","templateSourceId":"coworkcanvas:template:privileged-access-review","description":"Privileged Access Review for Banana ERP (current cycle).","status":"ACTIVE","displayOrder":282,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Test business justification and activity","description":null,"summary":null,"instructions":"**Objective**\nTest business justification and activity. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, role and permission definitions, group membership extracts, service and application account inventories, break-glass account registers, and the privileged-access policy.\n2. Use the privileged population, current role and job descriptions, activity and session logs for the period, change and incident records, and prior review justifications.\n\n**Procedure**\n1. State the privilege criteria before enumerating, extract membership for every qualifying role, include non-human and emergency accounts that user-focused extracts miss, and reconcile the population to an independent source.\n2. Test justification against the current role rather than the role at grant, inspect activity logs for accounts with no use and for use inconsistent with the stated purpose, and record logging gaps as gaps rather than as clean results.\n\n**Record in AssureSwarm**\n1. Capture the review period, privilege criteria applied, population per account class with extract dates, service and emergency accounts, reconciliation basis, and enumeration gaps. Also record privileged definition and population.\n2. Document the justification assessment per account, activity review coverage, dormant privileged accounts, activity inconsistent with stated purpose, logging gaps, and justifications relying only on representation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: Privilege is defined before enumeration, non-human and break-glass accounts are in scope, and enumeration gaps are declared rather than presumed empty. Justification is tested against current roles and observed activity, dormant and inconsistent accounts are surfaced, and logging gaps are declared rather than read as no findings.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve privileged access record","description":null,"summary":null,"instructions":"**Objective**\nApprove privileged access record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the justification assessment, removal tickets and post-removal extracts, monitoring and alerting configuration, session recording coverage, and the escalation route for accepted exceptions.\n2. Review all stage records, the enumeration and its reconciliation, justification results, activity coverage and logging gaps, removal evidence, monitoring tests, and accepted exceptions.\n\n**Procedure**\n1. Trace each removal decision to executed evidence, test that claimed compensating monitoring is actually configured and reviewed rather than merely available, and route accepted exceptions to the authorized approver before advancing.\n2. Trace dispositions to justification and activity evidence, verify retained access carries an expiry and tested monitoring, confirm logging gaps are owned, and return unevidenced monitoring claims with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, removals traced to evidence, retained access with justification and expiry, compensating monitoring tested with configuration references, accepted exceptions and their approver, and residual gaps. Also record compensating monitoring detail.\n2. Capture the authorized reviewer, the summary, accepted outcome, effective review date, next review cadence, retained access with expiries, logging gaps with owners, and linked issues raised. Also record privileged access summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that retained privilege carries tested compensating monitoring rather than an assertion, removals are evidenced, and exceptions reached the authorized approver. The authorized reviewer accepts the record as evidence the privileged-access control operated for the period, and closure implies no assurance over account classes excluded from enumeration.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Lucille Identity Cloud","itemType":"system","name":"Privileged Access Review — Lucille Identity Cloud — prior cycle","templateName":"Privileged Access Review","templateSourceId":"coworkcanvas:template:privileged-access-review","description":"Privileged Access Review for Lucille Identity Cloud (prior cycle).","status":"COMPLETED","displayOrder":283,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Test business justification and activity","description":null,"summary":null,"instructions":"**Objective**\nTest business justification and activity. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, role and permission definitions, group membership extracts, service and application account inventories, break-glass account registers, and the privileged-access policy.\n2. Use the privileged population, current role and job descriptions, activity and session logs for the period, change and incident records, and prior review justifications.\n\n**Procedure**\n1. State the privilege criteria before enumerating, extract membership for every qualifying role, include non-human and emergency accounts that user-focused extracts miss, and reconcile the population to an independent source.\n2. Test justification against the current role rather than the role at grant, inspect activity logs for accounts with no use and for use inconsistent with the stated purpose, and record logging gaps as gaps rather than as clean results.\n\n**Record in AssureSwarm**\n1. Capture the review period, privilege criteria applied, population per account class with extract dates, service and emergency accounts, reconciliation basis, and enumeration gaps. Also record privileged definition and population.\n2. Document the justification assessment per account, activity review coverage, dormant privileged accounts, activity inconsistent with stated purpose, logging gaps, and justifications relying only on representation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: Privilege is defined before enumeration, non-human and break-glass accounts are in scope, and enumeration gaps are declared rather than presumed empty. Justification is tested against current roles and observed activity, dormant and inconsistent accounts are surfaced, and logging gaps are declared rather than read as no findings.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"},{"itemTitle":"Authenticate all users with multi-factor authentication","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve privileged access record","description":null,"summary":null,"instructions":"**Objective**\nApprove privileged access record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the justification assessment, removal tickets and post-removal extracts, monitoring and alerting configuration, session recording coverage, and the escalation route for accepted exceptions.\n2. Review all stage records, the enumeration and its reconciliation, justification results, activity coverage and logging gaps, removal evidence, monitoring tests, and accepted exceptions.\n\n**Procedure**\n1. Trace each removal decision to executed evidence, test that claimed compensating monitoring is actually configured and reviewed rather than merely available, and route accepted exceptions to the authorized approver before advancing.\n2. Trace dispositions to justification and activity evidence, verify retained access carries an expiry and tested monitoring, confirm logging gaps are owned, and return unevidenced monitoring claims with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, removals traced to evidence, retained access with justification and expiry, compensating monitoring tested with configuration references, accepted exceptions and their approver, and residual gaps. Also record compensating monitoring detail.\n2. Capture the authorized reviewer, the summary, accepted outcome, effective review date, next review cadence, retained access with expiries, logging gaps with owners, and linked issues raised. Also record privileged access summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that retained privilege carries tested compensating monitoring rather than an assertion, removals are evidenced, and exceptions reached the authorized approver. The authorized reviewer accepts the record as evidence the privileged-access control operated for the period, and closure implies no assurance over account classes excluded from enumeration.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"},{"itemTitle":"Authenticate all users with multi-factor authentication","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Sudden Valley Network","itemType":"system","name":"Privileged Access Review — Sudden Valley Network — next cycle","templateName":"Privileged Access Review","templateSourceId":"coworkcanvas:template:privileged-access-review","description":"Privileged Access Review for Sudden Valley Network (next cycle).","status":"DRAFT","displayOrder":281,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Test business justification and activity","description":null,"summary":null,"instructions":"**Objective**\nTest business justification and activity. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, role and permission definitions, group membership extracts, service and application account inventories, break-glass account registers, and the privileged-access policy.\n2. Use the privileged population, current role and job descriptions, activity and session logs for the period, change and incident records, and prior review justifications.\n\n**Procedure**\n1. State the privilege criteria before enumerating, extract membership for every qualifying role, include non-human and emergency accounts that user-focused extracts miss, and reconcile the population to an independent source.\n2. Test justification against the current role rather than the role at grant, inspect activity logs for accounts with no use and for use inconsistent with the stated purpose, and record logging gaps as gaps rather than as clean results.\n\n**Record in AssureSwarm**\n1. Capture the review period, privilege criteria applied, population per account class with extract dates, service and emergency accounts, reconciliation basis, and enumeration gaps. Also record privileged definition and population.\n2. Document the justification assessment per account, activity review coverage, dormant privileged accounts, activity inconsistent with stated purpose, logging gaps, and justifications relying only on representation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: Privilege is defined before enumeration, non-human and break-glass accounts are in scope, and enumeration gaps are declared rather than presumed empty. Justification is tested against current roles and observed activity, dormant and inconsistent accounts are surfaced, and logging gaps are declared rather than read as no findings.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Sudden Valley Network","itemType":"system","kind":"related"},{"itemTitle":"Availability & capacity management (SLA)","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve privileged access record","description":null,"summary":null,"instructions":"**Objective**\nApprove privileged access record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the justification assessment, removal tickets and post-removal extracts, monitoring and alerting configuration, session recording coverage, and the escalation route for accepted exceptions.\n2. Review all stage records, the enumeration and its reconciliation, justification results, activity coverage and logging gaps, removal evidence, monitoring tests, and accepted exceptions.\n\n**Procedure**\n1. Trace each removal decision to executed evidence, test that claimed compensating monitoring is actually configured and reviewed rather than merely available, and route accepted exceptions to the authorized approver before advancing.\n2. Trace dispositions to justification and activity evidence, verify retained access carries an expiry and tested monitoring, confirm logging gaps are owned, and return unevidenced monitoring claims with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, removals traced to evidence, retained access with justification and expiry, compensating monitoring tested with configuration references, accepted exceptions and their approver, and residual gaps. Also record compensating monitoring detail.\n2. Capture the authorized reviewer, the summary, accepted outcome, effective review date, next review cadence, retained access with expiries, logging gaps with owners, and linked issues raised. Also record privileged access summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that retained privilege carries tested compensating monitoring rather than an assertion, removals are evidenced, and exceptions reached the authorized approver. The authorized reviewer accepts the record as evidence the privileged-access control operated for the period, and closure implies no assurance over account classes excluded from enumeration.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Sudden Valley Network","itemType":"system","kind":"related"},{"itemTitle":"Availability & capacity management (SLA)","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"AI Governance & Human Approval","itemType":"process","name":"Process Narrative & Walkthrough — AI Governance & Human Approval — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for AI Governance & Human Approval.","status":"ACTIVE","displayOrder":294,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"AI Governance & Human Approval","itemType":"process","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Asset, Media & Classification","itemType":"process","name":"Process Narrative & Walkthrough — Asset, Media & Classification — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Asset, Media & Classification.","status":"ACTIVE","displayOrder":295,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Asset, Media & Classification","itemType":"process","kind":"related"},{"itemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Backup, Recovery, BC/DR & Capacity","itemType":"process","name":"Process Narrative & Walkthrough — Backup, Recovery, BC/DR & Capacity — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Backup, Recovery, BC/DR & Capacity.","status":"ACTIVE","displayOrder":296,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Backup, Recovery, BC/DR & Capacity","itemType":"process","kind":"related"},{"itemTitle":"Availability & capacity management (SLA)","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Change Management","itemType":"process","name":"Process Narrative & Walkthrough — Change Management — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Change Management.","status":"ACTIVE","displayOrder":297,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Change Management","itemType":"process","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Change, Release & Database Migration","itemType":"process","name":"Process Narrative & Walkthrough — Change, Release & Database Migration — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Change, Release & Database Migration.","status":"ACTIVE","displayOrder":298,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Change, Release & Database Migration","itemType":"process","kind":"related"},{"itemTitle":"Authorize, test, and approve changes and development","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Compliance Obligations, Evidence & External Assurance","itemType":"process","name":"Process Narrative & Walkthrough — Compliance Obligations, Evidence & External Assurance — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Compliance Obligations, Evidence & External Assurance.","status":"ACTIVE","displayOrder":299,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Compliance Obligations, Evidence & External Assurance","itemType":"process","kind":"related"},{"itemTitle":"Assess control effectiveness and authorize systems","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Continuous Control Operation & Evidence Monitoring","itemType":"process","name":"Process Narrative & Walkthrough — Continuous Control Operation & Evidence Monitoring — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Continuous Control Operation & Evidence Monitoring.","status":"ACTIVE","displayOrder":300,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Continuous Control Operation & Evidence Monitoring","itemType":"process","kind":"related"},{"itemTitle":"Assess control effectiveness and authorize systems","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Credit and Collections","itemType":"process","name":"Process Narrative & Walkthrough — Credit and Collections — current cycle","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Process Narrative & Walkthrough for Credit and Collections (current cycle).","status":"ACTIVE","displayOrder":292,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Credit and Collections","itemType":"process","kind":"related"},{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Cryptography, Key & Secrets Management","itemType":"process","name":"Process Narrative & Walkthrough — Cryptography, Key & Secrets Management — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Cryptography, Key & Secrets Management.","status":"ACTIVE","displayOrder":301,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cryptography, Key & Secrets Management","itemType":"process","kind":"related"},{"itemTitle":"Authenticate all users with multi-factor authentication","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Enterprise Risk Assessment, Treatment & SoA","itemType":"process","name":"Process Narrative & Walkthrough — Enterprise Risk Assessment, Treatment & SoA — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Enterprise Risk Assessment, Treatment & SoA.","status":"ACTIVE","displayOrder":302,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Enterprise Risk Assessment, Treatment & SoA","itemType":"process","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Financial Close and Consolidation","itemType":"process","name":"Process Narrative & Walkthrough — Financial Close and Consolidation — prior cycle","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Process Narrative & Walkthrough for Financial Close and Consolidation (prior cycle).","status":"COMPLETED","displayOrder":293,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Financial Close and Consolidation","itemType":"process","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Financial Close and Consolidation","itemType":"process","name":"Process Narrative & Walkthrough — Financial Close and Consolidation — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Financial Close and Consolidation.","status":"ACTIVE","displayOrder":303,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Financial Close and Consolidation","itemType":"process","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Financial Reporting Area","itemType":"process","name":"Process Narrative & Walkthrough — Financial Reporting Area — next cycle","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Process Narrative & Walkthrough for Financial Reporting Area (next cycle).","status":"DRAFT","displayOrder":291,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Financial Reporting Area","itemType":"process","kind":"related"},{"itemTitle":"Financial Close and Consolidation","itemType":"process","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISMS Governance, Scope & Objectives","itemType":"process","name":"Process Narrative & Walkthrough — ISMS Governance, Scope & Objectives — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for ISMS Governance, Scope & Objectives.","status":"ACTIVE","displayOrder":304,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISMS Governance, Scope & Objectives","itemType":"process","kind":"related"},{"itemTitle":"Assess and mitigate fraud risk including management override","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"IT Operations","itemType":"process","name":"Process Narrative & Walkthrough — IT Operations — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for IT Operations.","status":"ACTIVE","displayOrder":305,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"IT Operations","itemType":"process","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Identity, Authentication & Access Lifecycle","itemType":"process","name":"Process Narrative & Walkthrough — Identity, Authentication & Access Lifecycle — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Identity, Authentication & Access Lifecycle.","status":"ACTIVE","displayOrder":306,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity, Authentication & Access Lifecycle","itemType":"process","kind":"related"},{"itemTitle":"Annual performance and conduct evaluation per personnel","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Incident and Privacy Response","itemType":"process","name":"Process Narrative & Walkthrough — Incident and Privacy Response — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Incident and Privacy Response.","status":"ACTIVE","displayOrder":307,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Incident and Privacy Response","itemType":"process","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Internal Audit Delivery","itemType":"process","name":"Process Narrative & Walkthrough — Internal Audit Delivery — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Internal Audit Delivery.","status":"ACTIVE","displayOrder":308,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Internal Audit Delivery","itemType":"process","kind":"related"},{"itemTitle":"New Application Architecture Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","itemType":"process","name":"Process Narrative & Walkthrough — Internal Audit, Management Review, Nonconformity & Improvement — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Internal Audit, Management Review, Nonconformity & Improvement.","status":"ACTIVE","displayOrder":309,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Internal Audit, Management Review, Nonconformity & Improvement","itemType":"process","kind":"related"},{"itemTitle":"Assess control effectiveness and authorize systems","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Logging, Monitoring, Detection & Threat Intelligence","itemType":"process","name":"Process Narrative & Walkthrough — Logging, Monitoring, Detection & Threat Intelligence — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Logging, Monitoring, Detection & Threat Intelligence.","status":"ACTIVE","displayOrder":310,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Logging, Monitoring, Detection & Threat Intelligence","itemType":"process","kind":"related"},{"itemTitle":"Cloud SQL query & access audit logging","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Network, Cloud Configuration & Physical Reliance","itemType":"process","name":"Process Narrative & Walkthrough — Network, Cloud Configuration & Physical Reliance — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Network, Cloud Configuration & Physical Reliance.","status":"ACTIVE","displayOrder":311,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Network, Cloud Configuration & Physical Reliance","itemType":"process","kind":"related"},{"itemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"On-Prem Appliance & Release Lifecycle","itemType":"process","name":"Process Narrative & Walkthrough — On-Prem Appliance & Release Lifecycle — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for On-Prem Appliance & Release Lifecycle.","status":"ACTIVE","displayOrder":312,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"On-Prem Appliance & Release Lifecycle","itemType":"process","kind":"related"},{"itemTitle":"Authorize, test, and approve changes and development","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Order to Cash","itemType":"process","name":"Process Narrative & Walkthrough — Order to Cash — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Order to Cash.","status":"ACTIVE","displayOrder":313,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Order to Cash","itemType":"process","kind":"related"},{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Payroll Administration","itemType":"process","name":"Process Narrative & Walkthrough — Payroll Administration — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Payroll Administration.","status":"ACTIVE","displayOrder":314,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Payroll Administration","itemType":"process","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Policy Lifecycle, Publication, Acknowledgment & Exceptions","itemType":"process","name":"Process Narrative & Walkthrough — Policy Lifecycle, Publication, Acknowledgment & Exceptions — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Policy Lifecycle, Publication, Acknowledgment & Exceptions.","status":"ACTIVE","displayOrder":315,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Policy Lifecycle, Publication, Acknowledgment & Exceptions","itemType":"process","kind":"related"},{"itemTitle":"Communicate and report risk and control information","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Privacy, Data Lifecycle & Secure Transfer","itemType":"process","name":"Process Narrative & Walkthrough — Privacy, Data Lifecycle & Secure Transfer — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Privacy, Data Lifecycle & Secure Transfer.","status":"ACTIVE","displayOrder":316,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Privacy, Data Lifecycle & Secure Transfer","itemType":"process","kind":"related"},{"itemTitle":"Bind third parties handling personal data to privacy commitments","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Procure to Pay","itemType":"process","name":"Process Narrative & Walkthrough — Procure to Pay — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Procure to Pay.","status":"ACTIVE","displayOrder":317,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay","itemType":"process","kind":"related"},{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Production Operations & SOC 1 Processing Integrity","itemType":"process","name":"Process Narrative & Walkthrough — Production Operations & SOC 1 Processing Integrity — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Production Operations & SOC 1 Processing Integrity.","status":"ACTIVE","displayOrder":318,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Production Operations & SOC 1 Processing Integrity","itemType":"process","kind":"related"},{"itemTitle":"Authorize, test, and approve changes and development","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Record to Report","itemType":"process","name":"Process Narrative & Walkthrough — Record to Report — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Record to Report.","status":"ACTIVE","displayOrder":319,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Record to Report","itemType":"process","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Revenue Recognition","itemType":"process","name":"Process Narrative & Walkthrough — Revenue Recognition — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Revenue Recognition.","status":"ACTIVE","displayOrder":320,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Revenue Recognition","itemType":"process","kind":"related"},{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Risk and Compliance Management","itemType":"process","name":"Process Narrative & Walkthrough — Risk and Compliance Management — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Risk and Compliance Management.","status":"ACTIVE","displayOrder":321,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Risk and Compliance Management","itemType":"process","kind":"related"},{"itemTitle":"ISO 27001 Certification Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"SOX Program Management","itemType":"process","name":"Process Narrative & Walkthrough — SOX Program Management — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for SOX Program Management.","status":"ACTIVE","displayOrder":322,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"SOX Program Management","itemType":"process","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Secure SDLC & Application Security","itemType":"process","name":"Process Narrative & Walkthrough — Secure SDLC & Application Security — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Secure SDLC & Application Security.","status":"ACTIVE","displayOrder":323,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Secure SDLC & Application Security","itemType":"process","kind":"related"},{"itemTitle":"Authorize, test, and approve changes and development","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Security Awareness & Role Training","itemType":"process","name":"Process Narrative & Walkthrough — Security Awareness & Role Training — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Security Awareness & Role Training.","status":"ACTIVE","displayOrder":324,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Security Awareness & Role Training","itemType":"process","kind":"related"},{"itemTitle":"Annual performance and conduct evaluation per personnel","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Security Incident, Privacy Breach & Postmortem","itemType":"process","name":"Process Narrative & Walkthrough — Security Incident, Privacy Breach & Postmortem — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Security Incident, Privacy Breach & Postmortem.","status":"ACTIVE","displayOrder":325,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Security Incident, Privacy Breach & Postmortem","itemType":"process","kind":"related"},{"itemTitle":"Back up data and verify restorability","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Tenant Provisioning, Isolation & Teardown","itemType":"process","name":"Process Narrative & Walkthrough — Tenant Provisioning, Isolation & Teardown — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Tenant Provisioning, Isolation & Teardown.","status":"ACTIVE","displayOrder":326,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Tenant Provisioning, Isolation & Teardown","itemType":"process","kind":"related"},{"itemTitle":"Bind third parties handling personal data to privacy commitments","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"User Access Management","itemType":"process","name":"Process Narrative & Walkthrough — User Access Management — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for User Access Management.","status":"ACTIVE","displayOrder":327,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"User Access Management","itemType":"process","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Vendor Lifecycle Management","itemType":"process","name":"Process Narrative & Walkthrough — Vendor Lifecycle Management — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Vendor Lifecycle Management.","status":"ACTIVE","displayOrder":328,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Vendor Lifecycle Management","itemType":"process","kind":"related"},{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Vendor, Subservice & CUEC Management","itemType":"process","name":"Process Narrative & Walkthrough — Vendor, Subservice & CUEC Management — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Vendor, Subservice & CUEC Management.","status":"ACTIVE","displayOrder":329,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Vendor, Subservice & CUEC Management","itemType":"process","kind":"related"},{"itemTitle":"Bind third parties handling personal data to privacy commitments","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Vulnerability, Patch & Technical Testing","itemType":"process","name":"Process Narrative & Walkthrough — Vulnerability, Patch & Technical Testing — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Vulnerability, Patch & Technical Testing.","status":"ACTIVE","displayOrder":330,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Vulnerability, Patch & Technical Testing","itemType":"process","kind":"related"},{"itemTitle":"Authorize, test, and approve changes and development","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Workforce Security, Acceptable Use & Remote Work","itemType":"process","name":"Process Narrative & Walkthrough — Workforce Security, Acceptable Use & Remote Work — Current narrative","templateName":"Process Narrative & Walkthrough","templateSourceId":"coworkcanvas:template:process-narrative-walkthrough","description":"Current narrative of Process Narrative & Walkthrough for Workforce Security, Acceptable Use & Remote Work.","status":"ACTIVE","displayOrder":331,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve process record","description":null,"summary":null,"instructions":"**Objective**\nApprove process record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Process item, prior narrative and flowchart, organization and system changes, policies, procedures, risks, controls, issues, and transaction populations.\n2. Use scoped interviews, procedures, system configurations, reports, forms, tickets, contracts, and the selected transaction without assuming the prior narrative remains accurate.\n3. Use the selected transaction, source documents, system records, approvals, calculations, interfaces, exception logs, narrative draft, mapped risks and controls, and participant explanations.\n4. Review every stage result, narrative and flowchart, transaction evidence, stakeholder responses, differences, updated mappings, linked issues, and open documentation actions.\n\n**Procedure**\n1. Interview the accountable process owner, reconcile the stated boundary to upstream and downstream handoffs, identify material variants and outsourced activities, and select a representative transaction for walkthrough.\n2. Describe each activity in sequence, identify performer and reviewer, inputs and outputs, system and manual steps, decision points, interfaces, risks, controls, exception routes, evidence retained, and timing.\n3. Observe or inspect each narrated step, match timestamps and identifiers across systems, verify handoffs and approvals, inquire about deviations, trace data transformations, and update the narrative for demonstrated practice.\n4. Trace material narrative claims to walkthrough support, confirm corrections were incorporated, verify exceptions and open gaps are not suppressed, and return incomplete or inconsistent work with precise comments.\n\n**Record in AssureSwarm**\n1. Capture the period, boundary, participants, applications, locations, variants, dependencies, selected transaction identifier, excluded paths, and limitations. Also record walkthrough period; process boundary.\n2. Link the dated narrative and flowchart, list source documents and interviewees, map material risks and controls to process points, and call out conflicting accounts or undocumented practice. Also record narrative reference.\n3. Document the transaction trail, people interviewed, screens or reports inspected, steps corroborated, differences, updates made, unresolved questions, owners, and due dates. Also record walkthrough result.\n4. Capture the authorized reviewer, closure summary, accepted narrative version and date, walkthrough result, linked risks, controls and issues, plus remaining action owners and due dates. Also record process record summary.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides approval: The process boundary and walkthrough selection are unambiguous, responsible participants are available, and material variants are included or assigned separate follow-up. The draft is sufficiently specific to replay the process, handoffs and exception paths are visible, and every material statement has an identified source or open validation item. An approver accepts that the walkthrough trail supports the recorded current state or that specific gaps and additional walkthrough work are assigned before closure. The authorized reviewer accepts the process record as a traceable description of work performed, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Workforce Security, Acceptable Use & Remote Work","itemType":"process","kind":"related"},{"itemTitle":"Annual performance and conduct evaluation per personnel","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 A.5.31 — Compliance obligation register","itemType":"requirement","name":"Regulatory Change Intake & Impact Assessment — ISO 27001 A.5.31 — Compliance obligation register — next cycle","templateName":"Regulatory Change Intake & Impact Assessment","templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","description":"Regulatory Change Intake & Impact Assessment for ISO 27001 A.5.31 — Compliance obligation register (next cycle).","status":"DRAFT","displayOrder":301,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Determine applicability and affected scope","description":null,"summary":null,"instructions":"**Objective**\nDetermine applicability and affected scope. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, the primary authoritative source text, the superseded version, regulator or standards-body publications, legal and advisory summaries, and the framework version currently recorded.\n2. Use the validated change, entity and jurisdiction maps, product and service inventory, data flows and classifications, customer and employee populations, existing applicability determinations, and thresholds or exemptions in the source text.\n\n**Procedure**\n1. Read the primary source rather than commentary, compare new and superseded text clause by clause, establish effective and transition dates, distinguish binding obligations from guidance, and flag interpretive ambiguity for legal input.\n2. Test each applicability criterion against documented facts, evaluate thresholds and exemptions explicitly, identify partially reached scope, reconcile against the prior determination, and record where facts were unavailable.\n\n**Record in AssureSwarm**\n1. Capture the authority reference, framework and version, change description with clause-level differences, effective and transition dates, binding versus advisory classification, source citations, and interpretive questions raised.\n2. Document the applicability decision, criterion-by-criterion analysis, entities and jurisdictions reached, exemptions relied upon with justification, prior determination comparison, and unresolved factual gaps. Also record scope analysis.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The change is verified against primary source with citations, timing is established, and interpretive ambiguity is routed to the accountable role rather than resolved by assumption. The applicability decision is supported criterion by criterion, exemptions carry stated justification, and factual gaps that could reverse the decision are visible and assigned.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.31 — Compliance obligation register","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve impact assessment and route implementation","description":null,"summary":null,"instructions":"**Objective**\nApprove impact assessment and route implementation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the applicability decision, the mapped control set, policy library, process narratives, system and vendor inventory, existing evidence expectations, current implementation status, and delivery capacity.\n2. Review all stage records, primary source citations, applicability analysis and exemptions, clause-to-artifact mapping, gap inventory, effort estimates, ownership nominations, and feasibility escalations.\n\n**Procedure**\n1. Trace each changed clause to the artifacts that satisfy it, identify gaps where no artifact exists, estimate effort and dependency, rate aggregate impact, name accountable owners, and escalate where the effective date is not achievable.\n2. Verify citations resolve to primary source, confirm the applicability decision is criterion-supported, check every gap has an owner and target date, reconcile the recorded framework version, and return unsupported analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the impact rating, clause-to-artifact mapping, identified gaps, affected controls, policies, processes and systems, effort and dependency estimates, nominated owners, and feasibility escalations. Also record impact analysis.\n2. Capture the authorized reviewer, the intake summary, accepted applicability and impact conclusions, framework version to record, effective and transition dates, implementation route and owners, open gaps, and due dates. Also record change intake summary.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the impact rating follows from the traced analysis, gaps are owned, and any effective date the organization cannot meet is escalated rather than absorbed. The authorized reviewer accepts the intake as a traceable record of change analysis, implementation can be routed against named owners, and closure implies no assurance that the obligation is yet met.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.31 — Compliance obligation register","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 A.5.34 — Personal-data privacy safeguards","itemType":"requirement","name":"Regulatory Change Intake & Impact Assessment — ISO 27001 A.5.34 — Personal-data privacy safeguards — prior cycle","templateName":"Regulatory Change Intake & Impact Assessment","templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","description":"Regulatory Change Intake & Impact Assessment for ISO 27001 A.5.34 — Personal-data privacy safeguards (prior cycle).","status":"COMPLETED","displayOrder":303,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Determine applicability and affected scope","description":null,"summary":null,"instructions":"**Objective**\nDetermine applicability and affected scope. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, the primary authoritative source text, the superseded version, regulator or standards-body publications, legal and advisory summaries, and the framework version currently recorded.\n2. Use the validated change, entity and jurisdiction maps, product and service inventory, data flows and classifications, customer and employee populations, existing applicability determinations, and thresholds or exemptions in the source text.\n\n**Procedure**\n1. Read the primary source rather than commentary, compare new and superseded text clause by clause, establish effective and transition dates, distinguish binding obligations from guidance, and flag interpretive ambiguity for legal input.\n2. Test each applicability criterion against documented facts, evaluate thresholds and exemptions explicitly, identify partially reached scope, reconcile against the prior determination, and record where facts were unavailable.\n\n**Record in AssureSwarm**\n1. Capture the authority reference, framework and version, change description with clause-level differences, effective and transition dates, binding versus advisory classification, source citations, and interpretive questions raised.\n2. Document the applicability decision, criterion-by-criterion analysis, entities and jurisdictions reached, exemptions relied upon with justification, prior determination comparison, and unresolved factual gaps. Also record scope analysis.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The change is verified against primary source with citations, timing is established, and interpretive ambiguity is routed to the accountable role rather than resolved by assumption. The applicability decision is supported criterion by criterion, exemptions carry stated justification, and factual gaps that could reverse the decision are visible and assigned.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.34 — Personal-data privacy safeguards","itemType":"requirement","kind":"related"},{"itemTitle":"Information Security Policy","itemType":"policy","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve impact assessment and route implementation","description":null,"summary":null,"instructions":"**Objective**\nApprove impact assessment and route implementation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the applicability decision, the mapped control set, policy library, process narratives, system and vendor inventory, existing evidence expectations, current implementation status, and delivery capacity.\n2. Review all stage records, primary source citations, applicability analysis and exemptions, clause-to-artifact mapping, gap inventory, effort estimates, ownership nominations, and feasibility escalations.\n\n**Procedure**\n1. Trace each changed clause to the artifacts that satisfy it, identify gaps where no artifact exists, estimate effort and dependency, rate aggregate impact, name accountable owners, and escalate where the effective date is not achievable.\n2. Verify citations resolve to primary source, confirm the applicability decision is criterion-supported, check every gap has an owner and target date, reconcile the recorded framework version, and return unsupported analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the impact rating, clause-to-artifact mapping, identified gaps, affected controls, policies, processes and systems, effort and dependency estimates, nominated owners, and feasibility escalations. Also record impact analysis.\n2. Capture the authorized reviewer, the intake summary, accepted applicability and impact conclusions, framework version to record, effective and transition dates, implementation route and owners, open gaps, and due dates. Also record change intake summary.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the impact rating follows from the traced analysis, gaps are owned, and any effective date the organization cannot meet is escalated rather than absorbed. The authorized reviewer accepts the intake as a traceable record of change analysis, implementation can be routed against named owners, and closure implies no assurance that the obligation is yet met.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.34 — Personal-data privacy safeguards","itemType":"requirement","kind":"related"},{"itemTitle":"Information Security Policy","itemType":"policy","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 A.5.5 — Regulatory authority coordination","itemType":"requirement","name":"Regulatory Change Intake & Impact Assessment — ISO 27001 A.5.5 — Regulatory authority coordination — current cycle","templateName":"Regulatory Change Intake & Impact Assessment","templateSourceId":"coworkcanvas:template:regulatory-change-intake-impact","description":"Regulatory Change Intake & Impact Assessment for ISO 27001 A.5.5 — Regulatory authority coordination (current cycle).","status":"ACTIVE","displayOrder":302,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Determine applicability and affected scope","description":null,"summary":null,"instructions":"**Objective**\nDetermine applicability and affected scope. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, the primary authoritative source text, the superseded version, regulator or standards-body publications, legal and advisory summaries, and the framework version currently recorded.\n2. Use the validated change, entity and jurisdiction maps, product and service inventory, data flows and classifications, customer and employee populations, existing applicability determinations, and thresholds or exemptions in the source text.\n\n**Procedure**\n1. Read the primary source rather than commentary, compare new and superseded text clause by clause, establish effective and transition dates, distinguish binding obligations from guidance, and flag interpretive ambiguity for legal input.\n2. Test each applicability criterion against documented facts, evaluate thresholds and exemptions explicitly, identify partially reached scope, reconcile against the prior determination, and record where facts were unavailable.\n\n**Record in AssureSwarm**\n1. Capture the authority reference, framework and version, change description with clause-level differences, effective and transition dates, binding versus advisory classification, source citations, and interpretive questions raised.\n2. Document the applicability decision, criterion-by-criterion analysis, entities and jurisdictions reached, exemptions relied upon with justification, prior determination comparison, and unresolved factual gaps. Also record scope analysis.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The change is verified against primary source with citations, timing is established, and interpretive ambiguity is routed to the accountable role rather than resolved by assumption. The applicability decision is supported criterion by criterion, exemptions carry stated justification, and factual gaps that could reverse the decision are visible and assigned.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.5 — Regulatory authority coordination","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve impact assessment and route implementation","description":null,"summary":null,"instructions":"**Objective**\nApprove impact assessment and route implementation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the applicability decision, the mapped control set, policy library, process narratives, system and vendor inventory, existing evidence expectations, current implementation status, and delivery capacity.\n2. Review all stage records, primary source citations, applicability analysis and exemptions, clause-to-artifact mapping, gap inventory, effort estimates, ownership nominations, and feasibility escalations.\n\n**Procedure**\n1. Trace each changed clause to the artifacts that satisfy it, identify gaps where no artifact exists, estimate effort and dependency, rate aggregate impact, name accountable owners, and escalate where the effective date is not achievable.\n2. Verify citations resolve to primary source, confirm the applicability decision is criterion-supported, check every gap has an owner and target date, reconcile the recorded framework version, and return unsupported analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the impact rating, clause-to-artifact mapping, identified gaps, affected controls, policies, processes and systems, effort and dependency estimates, nominated owners, and feasibility escalations. Also record impact analysis.\n2. Capture the authorized reviewer, the intake summary, accepted applicability and impact conclusions, framework version to record, effective and transition dates, implementation route and owners, open gaps, and due dates. Also record change intake summary.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that the impact rating follows from the traced analysis, gaps are owned, and any effective date the organization cannot meet is escalated rather than absorbed. The authorized reviewer accepts the intake as a traceable record of change analysis, implementation can be routed against named owners, and closure implies no assurance that the obligation is yet met.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.5 — Regulatory authority coordination","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Re-run and reconcile the failed vendor payment batches","itemType":"remediation","name":"Remediation Delivery & Validation — Re-run and reconcile the failed vendor payment batches — next cycle","templateName":"Remediation Delivery & Validation","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","description":"Remediation Delivery & Validation for Re-run and reconcile the failed vendor payment batches (next cycle).","status":"DRAFT","displayOrder":311,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Define remediation plan and criteria","description":null,"summary":null,"instructions":"**Objective**\nDefine remediation plan and criteria. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Remediation item, linked issue and root cause, risk treatment, management response, relevant controls and requirements, target dates, approved exceptions, resource constraints, and prior attempts.\n\n**Procedure**\n1. Confirm the plan addresses documented cause rather than symptoms, decompose delivery into measurable milestones, define design and operating criteria, identify affected processes and systems, assess change risk, and agree evidence required for validation.\n\n**Record in AssureSwarm**\n1. Capture the delivery plan, closure criteria, action owner, milestones, target and contingency dates, dependencies, resources, change and rollback approach, expected evidence, validator independence, and escalation triggers.\n\n**Exit criteria**\nRemediation sponsor provides expertise: The plan is actionable, criteria are observable and aligned to the underlying issue, ownership and dependencies are accepted, and validation requirements are defined before delivery.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Re-run and reconcile the failed vendor payment batches","itemType":"remediation","kind":"related"},{"itemTitle":"Failed vendor payment batches went unnoticed","itemType":"issue","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Deliver corrective action","description":null,"summary":null,"instructions":"**Objective**\nDeliver corrective action. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved plan, design specifications, change tickets, configurations, procedures, training, communications, approvals, deployment records, reconciliations, affected populations, and rollback or contingency arrangements.\n\n**Procedure**\n1. Perform each milestone, verify authorized change and segregation, reconcile deployed scope to the plan, preserve before-and-after evidence, document deviations and failed steps, update affected documentation, and escalate blockers or date changes.\n\n**Record in AssureSwarm**\n1. Document delivery status, completed milestones, change identifiers, dates, performers and reviewers, scope deployed, evidence links, deviations, incidents, rollback decisions, revised dates, and residual open actions. Also record delivery evidence summary.\n\n**Exit criteria**\nAction owner provides expertise: Delivered work is traceable to the approved plan, deviations and incomplete scope remain visible, implementation evidence is assembled, and the package is ready for validation.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Re-run and reconcile the failed vendor payment batches","itemType":"remediation","kind":"related"},{"itemTitle":"Failed vendor payment batches went unnoticed","itemType":"issue","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":3,"name":"Approve remediation record","description":null,"summary":null,"instructions":"**Objective**\nApprove remediation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use closure criteria, delivery evidence, configurations, updated documentation, populations, transaction samples, monitoring results, interviews, linked issue evidence, deviations, and validator independence requirements.\n2. Review all stage records, linked issue and risk information, approved plan, change evidence, validation work, exceptions, monitoring commitments, revised dates, and stakeholder responses.\n\n**Procedure**\n1. Verify the delivered scope, inspect or reperform evidence for every criterion, test data completeness and relevant operation period, investigate exceptions, compare residual exposure to the intended response, and avoid relying solely on owner attestation.\n2. Trace each closure criterion to validation support, verify the validator and approval chain, reconcile owners and dates, confirm failed or partial results remain open, and return incomplete or inconsistent evidence for correction.\n\n**Record in AssureSwarm**\n1. Record the validation method, period and population, selections, results by criterion, exceptions, evidence references, residual exposure, validator identity, independence considerations, and required follow-up. Also record validation summary.\n2. Capture the authorized reviewer, closure summary, delivery and validation dates, final result, linked issue and risk references, residual actions, monitoring owner, due dates, and evidence package location. Also record remediation record summary.\n\n**Exit criteria**\nIndependent remediation validator provides approval: An approver accepts that the validation result follows from sufficient cited work, unmet criteria remain open, and the result is not inferred merely from delivery or workflow completion. The authorized reviewer accepts the remediation record as a traceable account of delivery and validation, linked records can be updated consistently, and closure itself is not an assurance conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Re-run and reconcile the failed vendor payment batches","itemType":"remediation","kind":"related"},{"itemTitle":"Failed vendor payment batches went unnoticed","itemType":"issue","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Review all emergency access sessions since July","itemType":"remediation","name":"Remediation Delivery & Validation — Review all emergency access sessions since July — current cycle","templateName":"Remediation Delivery & Validation","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","description":"Remediation Delivery & Validation for Review all emergency access sessions since July (current cycle).","status":"ACTIVE","displayOrder":312,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Define remediation plan and criteria","description":null,"summary":null,"instructions":"**Objective**\nDefine remediation plan and criteria. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Remediation item, linked issue and root cause, risk treatment, management response, relevant controls and requirements, target dates, approved exceptions, resource constraints, and prior attempts.\n\n**Procedure**\n1. Confirm the plan addresses documented cause rather than symptoms, decompose delivery into measurable milestones, define design and operating criteria, identify affected processes and systems, assess change risk, and agree evidence required for validation.\n\n**Record in AssureSwarm**\n1. Capture the delivery plan, closure criteria, action owner, milestones, target and contingency dates, dependencies, resources, change and rollback approach, expected evidence, validator independence, and escalation triggers.\n\n**Exit criteria**\nRemediation sponsor provides expertise: The plan is actionable, criteria are observable and aligned to the underlying issue, ownership and dependencies are accepted, and validation requirements are defined before delivery.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Review all emergency access sessions since July","itemType":"remediation","kind":"related"},{"itemTitle":"Emergency access sessions not reviewed","itemType":"issue","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Deliver corrective action","description":null,"summary":null,"instructions":"**Objective**\nDeliver corrective action. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved plan, design specifications, change tickets, configurations, procedures, training, communications, approvals, deployment records, reconciliations, affected populations, and rollback or contingency arrangements.\n\n**Procedure**\n1. Perform each milestone, verify authorized change and segregation, reconcile deployed scope to the plan, preserve before-and-after evidence, document deviations and failed steps, update affected documentation, and escalate blockers or date changes.\n\n**Record in AssureSwarm**\n1. Document delivery status, completed milestones, change identifiers, dates, performers and reviewers, scope deployed, evidence links, deviations, incidents, rollback decisions, revised dates, and residual open actions. Also record delivery evidence summary.\n\n**Exit criteria**\nAction owner provides expertise: Delivered work is traceable to the approved plan, deviations and incomplete scope remain visible, implementation evidence is assembled, and the package is ready for validation.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Review all emergency access sessions since July","itemType":"remediation","kind":"related"},{"itemTitle":"Emergency access sessions not reviewed","itemType":"issue","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]},{"stepNumber":3,"name":"Approve remediation record","description":null,"summary":null,"instructions":"**Objective**\nApprove remediation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use closure criteria, delivery evidence, configurations, updated documentation, populations, transaction samples, monitoring results, interviews, linked issue evidence, deviations, and validator independence requirements.\n2. Review all stage records, linked issue and risk information, approved plan, change evidence, validation work, exceptions, monitoring commitments, revised dates, and stakeholder responses.\n\n**Procedure**\n1. Verify the delivered scope, inspect or reperform evidence for every criterion, test data completeness and relevant operation period, investigate exceptions, compare residual exposure to the intended response, and avoid relying solely on owner attestation.\n2. Trace each closure criterion to validation support, verify the validator and approval chain, reconcile owners and dates, confirm failed or partial results remain open, and return incomplete or inconsistent evidence for correction.\n\n**Record in AssureSwarm**\n1. Record the validation method, period and population, selections, results by criterion, exceptions, evidence references, residual exposure, validator identity, independence considerations, and required follow-up. Also record validation summary.\n2. Capture the authorized reviewer, closure summary, delivery and validation dates, final result, linked issue and risk references, residual actions, monitoring owner, due dates, and evidence package location. Also record remediation record summary.\n\n**Exit criteria**\nIndependent remediation validator provides approval: An approver accepts that the validation result follows from sufficient cited work, unmet criteria remain open, and the result is not inferred merely from delivery or workflow completion. The authorized reviewer accepts the remediation record as a traceable account of delivery and validation, linked records can be updated consistently, and closure itself is not an assurance conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Review all emergency access sessions since July","itemType":"remediation","kind":"related"},{"itemTitle":"Emergency access sessions not reviewed","itemType":"issue","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Test leaver access removal next quarter","itemType":"remediation","name":"Remediation Delivery & Validation — Test leaver access removal next quarter — prior cycle","templateName":"Remediation Delivery & Validation","templateSourceId":"coworkcanvas:template:remediation-delivery-validation","description":"Remediation Delivery & Validation for Test leaver access removal next quarter (prior cycle).","status":"COMPLETED","displayOrder":313,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Define remediation plan and criteria","description":null,"summary":null,"instructions":"**Objective**\nDefine remediation plan and criteria. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Remediation item, linked issue and root cause, risk treatment, management response, relevant controls and requirements, target dates, approved exceptions, resource constraints, and prior attempts.\n\n**Procedure**\n1. Confirm the plan addresses documented cause rather than symptoms, decompose delivery into measurable milestones, define design and operating criteria, identify affected processes and systems, assess change risk, and agree evidence required for validation.\n\n**Record in AssureSwarm**\n1. Capture the delivery plan, closure criteria, action owner, milestones, target and contingency dates, dependencies, resources, change and rollback approach, expected evidence, validator independence, and escalation triggers.\n\n**Exit criteria**\nRemediation sponsor provides expertise: The plan is actionable, criteria are observable and aligned to the underlying issue, ownership and dependencies are accepted, and validation requirements are defined before delivery.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Test leaver access removal next quarter","itemType":"remediation","kind":"related"},{"itemTitle":"Leaver accounts in Banana ERP disabled late","itemType":"issue","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Deliver corrective action","description":null,"summary":null,"instructions":"**Objective**\nDeliver corrective action. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved plan, design specifications, change tickets, configurations, procedures, training, communications, approvals, deployment records, reconciliations, affected populations, and rollback or contingency arrangements.\n\n**Procedure**\n1. Perform each milestone, verify authorized change and segregation, reconcile deployed scope to the plan, preserve before-and-after evidence, document deviations and failed steps, update affected documentation, and escalate blockers or date changes.\n\n**Record in AssureSwarm**\n1. Document delivery status, completed milestones, change identifiers, dates, performers and reviewers, scope deployed, evidence links, deviations, incidents, rollback decisions, revised dates, and residual open actions. Also record delivery evidence summary.\n\n**Exit criteria**\nAction owner provides expertise: Delivered work is traceable to the approved plan, deviations and incomplete scope remain visible, implementation evidence is assembled, and the package is ready for validation.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Test leaver access removal next quarter","itemType":"remediation","kind":"related"},{"itemTitle":"Leaver accounts in Banana ERP disabled late","itemType":"issue","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":3,"name":"Approve remediation record","description":null,"summary":null,"instructions":"**Objective**\nApprove remediation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use closure criteria, delivery evidence, configurations, updated documentation, populations, transaction samples, monitoring results, interviews, linked issue evidence, deviations, and validator independence requirements.\n2. Review all stage records, linked issue and risk information, approved plan, change evidence, validation work, exceptions, monitoring commitments, revised dates, and stakeholder responses.\n\n**Procedure**\n1. Verify the delivered scope, inspect or reperform evidence for every criterion, test data completeness and relevant operation period, investigate exceptions, compare residual exposure to the intended response, and avoid relying solely on owner attestation.\n2. Trace each closure criterion to validation support, verify the validator and approval chain, reconcile owners and dates, confirm failed or partial results remain open, and return incomplete or inconsistent evidence for correction.\n\n**Record in AssureSwarm**\n1. Record the validation method, period and population, selections, results by criterion, exceptions, evidence references, residual exposure, validator identity, independence considerations, and required follow-up. Also record validation summary.\n2. Capture the authorized reviewer, closure summary, delivery and validation dates, final result, linked issue and risk references, residual actions, monitoring owner, due dates, and evidence package location. Also record remediation record summary.\n\n**Exit criteria**\nIndependent remediation validator provides approval: An approver accepts that the validation result follows from sufficient cited work, unmet criteria remain open, and the result is not inferred merely from delivery or workflow completion. The authorized reviewer accepts the remediation record as a traceable account of delivery and validation, linked records can be updated consistently, and closure itself is not an assurance conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Test leaver access removal next quarter","itemType":"remediation","kind":"related"},{"itemTitle":"Leaver accounts in Banana ERP disabled late","itemType":"issue","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 A.5.1 — Information-security policy governance","itemType":"requirement","name":"Requirement Applicability & Control Mapping — ISO 27001 A.5.1 — Information-security policy governance — next cycle","templateName":"Requirement Applicability & Control Mapping","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","description":"Requirement Applicability & Control Mapping for ISO 27001 A.5.1 — Information-security policy governance (next cycle).","status":"DRAFT","displayOrder":321,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Determine applicability and scope","description":null,"summary":null,"instructions":"**Objective**\nDetermine applicability and scope. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, authoritative law, regulation, standard, contract, policy, guidance, amendments, definitions, legal or compliance interpretation, organizational profile, and prior mapping.\n2. Use the interpreted obligation, corporate and legal-entity profile, products and services, customer and contract terms, data inventory, locations, thresholds, licenses, process and system maps, and specialist advice.\n\n**Procedure**\n1. Verify the authoritative citation and effective text, parse mandatory and conditional clauses, identify actors and triggering conditions, distinguish guidance from obligation, surface ambiguity, and obtain specialist interpretation where needed.\n2. Test each triggering condition against supported organizational facts, evaluate exemptions and thresholds, identify partial or phased scope, distinguish current from prospective applicability, challenge unsupported exclusions, and define reassessment triggers.\n\n**Record in AssureSwarm**\n1. Capture the authority reference, effective date, exact clause location, interpreted obligation, defined terms, triggering conditions, exceptions, dependencies, interpretation owner, assumptions, and unresolved ambiguity.\n2. Document the applicability decision and rationale, in-scope and excluded entities or activities, triggering facts, thresholds, exemptions, effective period, cited evidence, assumptions, owner, and reassessment triggers.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The obligation is traceable to authoritative text, assumptions and ambiguity are explicit, and the interpretation is specific enough for an applicability decision. The applicability decision is reproducible from authoritative criteria and organizational evidence, while exclusions, partial scope, and unresolved questions remain explicit.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.1 — Information-security policy governance","itemType":"requirement","kind":"related"},{"itemTitle":"Information Security Policy","itemType":"policy","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve requirement mapping record","description":null,"summary":null,"instructions":"**Objective**\nApprove requirement mapping record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the applicability record, clause decomposition, control library, policy and process records, system responsibilities, test results, monitoring, prior assessments, exceptions, issues, and evidence-retention requirements.\n2. Review every stage result, authoritative references, organizational evidence, specialist interpretations, mappings, control and test support, linked issues, exceptions, and open ambiguity.\n\n**Procedure**\n1. Decompose obligations into testable elements, map preventive and detective coverage, verify control ownership and frequency, inspect current evidence, identify overlaps and gaps, distinguish design from operating support, and create linked action records.\n2. Trace applicability and coverage decisions to sources, verify every applicable element is mapped or identified as a gap, reconcile linked records and owners, retain contrary evidence, and return unsupported conclusions for correction.\n\n**Record in AssureSwarm**\n1. Record mapping status and rationale by obligation element, linked controls and owners, policies and processes, evidence and testing references, coverage limitations, gaps, compensating measures, linked issues, and due dates.\n2. Capture the authorized reviewer, review summary, authority and effective date, applicability result, mapping status, linked controls and issues, limitations, reassessment trigger, owners, due dates, and evidence references. Also record requirement mapping summary.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that mappings are specific and evidence-based, applicable elements are accounted for, and design or operating gaps remain visible for action. The authorized reviewer accepts the requirement mapping as a traceable analysis record, downstream records can be maintained consistently, and closure does not establish compliance or assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.1 — Information-security policy governance","itemType":"requirement","kind":"related"},{"itemTitle":"Information Security Policy","itemType":"policy","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 A.5.10 — Approved asset-use rules","itemType":"requirement","name":"Requirement Applicability & Control Mapping — ISO 27001 A.5.10 — Approved asset-use rules — current cycle","templateName":"Requirement Applicability & Control Mapping","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","description":"Requirement Applicability & Control Mapping for ISO 27001 A.5.10 — Approved asset-use rules (current cycle).","status":"ACTIVE","displayOrder":322,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Determine applicability and scope","description":null,"summary":null,"instructions":"**Objective**\nDetermine applicability and scope. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, authoritative law, regulation, standard, contract, policy, guidance, amendments, definitions, legal or compliance interpretation, organizational profile, and prior mapping.\n2. Use the interpreted obligation, corporate and legal-entity profile, products and services, customer and contract terms, data inventory, locations, thresholds, licenses, process and system maps, and specialist advice.\n\n**Procedure**\n1. Verify the authoritative citation and effective text, parse mandatory and conditional clauses, identify actors and triggering conditions, distinguish guidance from obligation, surface ambiguity, and obtain specialist interpretation where needed.\n2. Test each triggering condition against supported organizational facts, evaluate exemptions and thresholds, identify partial or phased scope, distinguish current from prospective applicability, challenge unsupported exclusions, and define reassessment triggers.\n\n**Record in AssureSwarm**\n1. Capture the authority reference, effective date, exact clause location, interpreted obligation, defined terms, triggering conditions, exceptions, dependencies, interpretation owner, assumptions, and unresolved ambiguity.\n2. Document the applicability decision and rationale, in-scope and excluded entities or activities, triggering facts, thresholds, exemptions, effective period, cited evidence, assumptions, owner, and reassessment triggers.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The obligation is traceable to authoritative text, assumptions and ambiguity are explicit, and the interpretation is specific enough for an applicability decision. The applicability decision is reproducible from authoritative criteria and organizational evidence, while exclusions, partial scope, and unresolved questions remain explicit.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.10 — Approved asset-use rules","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve requirement mapping record","description":null,"summary":null,"instructions":"**Objective**\nApprove requirement mapping record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the applicability record, clause decomposition, control library, policy and process records, system responsibilities, test results, monitoring, prior assessments, exceptions, issues, and evidence-retention requirements.\n2. Review every stage result, authoritative references, organizational evidence, specialist interpretations, mappings, control and test support, linked issues, exceptions, and open ambiguity.\n\n**Procedure**\n1. Decompose obligations into testable elements, map preventive and detective coverage, verify control ownership and frequency, inspect current evidence, identify overlaps and gaps, distinguish design from operating support, and create linked action records.\n2. Trace applicability and coverage decisions to sources, verify every applicable element is mapped or identified as a gap, reconcile linked records and owners, retain contrary evidence, and return unsupported conclusions for correction.\n\n**Record in AssureSwarm**\n1. Record mapping status and rationale by obligation element, linked controls and owners, policies and processes, evidence and testing references, coverage limitations, gaps, compensating measures, linked issues, and due dates.\n2. Capture the authorized reviewer, review summary, authority and effective date, applicability result, mapping status, linked controls and issues, limitations, reassessment trigger, owners, due dates, and evidence references. Also record requirement mapping summary.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that mappings are specific and evidence-based, applicable elements are accounted for, and design or operating gaps remain visible for action. The authorized reviewer accepts the requirement mapping as a traceable analysis record, downstream records can be maintained consistently, and closure does not establish compliance or assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.10 — Approved asset-use rules","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"ISO 27001 A.5.11 — Asset recovery at exit","itemType":"requirement","name":"Requirement Applicability & Control Mapping — ISO 27001 A.5.11 — Asset recovery at exit — prior cycle","templateName":"Requirement Applicability & Control Mapping","templateSourceId":"coworkcanvas:template:requirement-applicability-control-mapping","description":"Requirement Applicability & Control Mapping for ISO 27001 A.5.11 — Asset recovery at exit (prior cycle).","status":"COMPLETED","displayOrder":323,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Determine applicability and scope","description":null,"summary":null,"instructions":"**Objective**\nDetermine applicability and scope. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Requirement item, authoritative law, regulation, standard, contract, policy, guidance, amendments, definitions, legal or compliance interpretation, organizational profile, and prior mapping.\n2. Use the interpreted obligation, corporate and legal-entity profile, products and services, customer and contract terms, data inventory, locations, thresholds, licenses, process and system maps, and specialist advice.\n\n**Procedure**\n1. Verify the authoritative citation and effective text, parse mandatory and conditional clauses, identify actors and triggering conditions, distinguish guidance from obligation, surface ambiguity, and obtain specialist interpretation where needed.\n2. Test each triggering condition against supported organizational facts, evaluate exemptions and thresholds, identify partial or phased scope, distinguish current from prospective applicability, challenge unsupported exclusions, and define reassessment triggers.\n\n**Record in AssureSwarm**\n1. Capture the authority reference, effective date, exact clause location, interpreted obligation, defined terms, triggering conditions, exceptions, dependencies, interpretation owner, assumptions, and unresolved ambiguity.\n2. Document the applicability decision and rationale, in-scope and excluded entities or activities, triggering facts, thresholds, exemptions, effective period, cited evidence, assumptions, owner, and reassessment triggers.\n\n**Exit criteria**\nLegal or regulatory specialist provides expertise: The obligation is traceable to authoritative text, assumptions and ambiguity are explicit, and the interpretation is specific enough for an applicability decision. The applicability decision is reproducible from authoritative criteria and organizational evidence, while exclusions, partial scope, and unresolved questions remain explicit.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.11 — Asset recovery at exit","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve requirement mapping record","description":null,"summary":null,"instructions":"**Objective**\nApprove requirement mapping record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the applicability record, clause decomposition, control library, policy and process records, system responsibilities, test results, monitoring, prior assessments, exceptions, issues, and evidence-retention requirements.\n2. Review every stage result, authoritative references, organizational evidence, specialist interpretations, mappings, control and test support, linked issues, exceptions, and open ambiguity.\n\n**Procedure**\n1. Decompose obligations into testable elements, map preventive and detective coverage, verify control ownership and frequency, inspect current evidence, identify overlaps and gaps, distinguish design from operating support, and create linked action records.\n2. Trace applicability and coverage decisions to sources, verify every applicable element is mapped or identified as a gap, reconcile linked records and owners, retain contrary evidence, and return unsupported conclusions for correction.\n\n**Record in AssureSwarm**\n1. Record mapping status and rationale by obligation element, linked controls and owners, policies and processes, evidence and testing references, coverage limitations, gaps, compensating measures, linked issues, and due dates.\n2. Capture the authorized reviewer, review summary, authority and effective date, applicability result, mapping status, linked controls and issues, limitations, reassessment trigger, owners, due dates, and evidence references. Also record requirement mapping summary.\n\n**Exit criteria**\nCompliance owner provides approval: An approver accepts that mappings are specific and evidence-based, applicable elements are accounted for, and design or operating gaps remain visible for action. The authorized reviewer accepts the requirement mapping as a traceable analysis record, downstream records can be maintained consistently, and closure does not establish compliance or assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"ISO 27001 A.5.11 — Asset recovery at exit","itemType":"requirement","kind":"related"},{"itemTitle":"Board Risk Oversight","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Financial statement fraud","itemType":"risk","name":"Risk Appetite & Tolerance Calibration — Financial statement fraud — next cycle","templateName":"Risk Appetite & Tolerance Calibration","templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","description":"Risk Appetite & Tolerance Calibration for Financial statement fraud (next cycle).","status":"DRAFT","displayOrder":331,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Set appetite statement and tolerance thresholds","description":null,"summary":null,"instructions":"**Objective**\nSet appetite statement and tolerance thresholds. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, board and committee charters, strategy and objective statements, prior appetite statements, capital and liquidity constraints, regulatory expectations, and the approved risk criteria.\n2. Use the confirmed mandate, the risk assessment and its scoring rubric, loss history, control effectiveness results, monitoring indicators, industry and peer benchmarks, and stakeholder expectations.\n\n**Procedure**\n1. Confirm which body owns the appetite decision, reconcile the stated period against the planning cycle, identify the objectives and constraints the appetite must respect, and document any mandate ambiguity before setting thresholds.\n2. Draft an appetite statement in decision-useful language, define threshold values with units and measurement basis, nominate the indicators that evidence position, test the thresholds against historical data for realism, and record rejected calibrations.\n\n**Record in AssureSwarm**\n1. Capture the appetite period, governance mandate, approving authority, objectives served, binding constraints, prior statement reference, and unresolved mandate questions.\n2. Document the appetite statement, threshold values with units and measurement basis, nominated indicators and their data sources, calibration rationale, rejected alternatives, and measurement limitations. Also record tolerance thresholds.\n\n**Exit criteria**\nRisk appetite authority provides expertise: The approving authority and period are unambiguous, the objectives and constraints are documented, and mandate gaps are escalated rather than assumed. The appetite statement is measurable through named indicators, thresholds are reproducible from a stated basis, and measurement limitations are carried into the position test.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Financial statement fraud","itemType":"risk","kind":"related"},{"itemTitle":"EUC Formula Validation","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve appetite and escalation record","description":null,"summary":null,"instructions":"**Objective**\nApprove appetite and escalation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the calibrated thresholds, current residual rating, indicator readings and their as-of dates, control testing results, open issues and remediations, and the escalation matrix in the governance mandate.\n2. Review all stage records, calibration rationale and rejected alternatives, indicator readings, threshold comparisons, breach responses, escalation confirmations, and open measurement limitations.\n\n**Procedure**\n1. Read each indicator against its threshold, classify the status, evaluate whether a breach requires acceptance, mitigation, or escalation, define trigger points for re-measurement, and route breaches to the authorized body before advancing.\n2. Trace the statement and thresholds to their stated basis, verify escalations reached the authorized body, confirm monitoring cadence and indicator ownership, and return unsupported calibration with precise comments.\n\n**Record in AssureSwarm**\n1. Record the tolerance status, indicator readings with as-of dates, threshold comparisons, breach response, escalation route and recipients, re-measurement triggers, and any indicator that could not be measured. Also record breach or monitoring response.\n2. Capture the authorized reviewer, the calibration summary, accepted appetite statement and thresholds, effective date, review cadence, escalation confirmations, open limitations, owners, and due dates.\n\n**Exit criteria**\nRisk oversight owner provides approval: An approver accepts that the status follows from the measured readings, breaches are routed to the authorized body, and unmeasurable indicators are declared rather than assumed compliant. The authorized reviewer accepts the calibration as a traceable record of appetite decisions, monitoring can proceed against named indicators, and closure implies no assurance that the position will remain within tolerance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Financial statement fraud","itemType":"risk","kind":"related"},{"itemTitle":"EUC Formula Validation","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Unauthorized privileged access","itemType":"risk","name":"Risk Appetite & Tolerance Calibration — Unauthorized privileged access — current cycle","templateName":"Risk Appetite & Tolerance Calibration","templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","description":"Risk Appetite & Tolerance Calibration for Unauthorized privileged access (current cycle).","status":"ACTIVE","displayOrder":332,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Set appetite statement and tolerance thresholds","description":null,"summary":null,"instructions":"**Objective**\nSet appetite statement and tolerance thresholds. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, board and committee charters, strategy and objective statements, prior appetite statements, capital and liquidity constraints, regulatory expectations, and the approved risk criteria.\n2. Use the confirmed mandate, the risk assessment and its scoring rubric, loss history, control effectiveness results, monitoring indicators, industry and peer benchmarks, and stakeholder expectations.\n\n**Procedure**\n1. Confirm which body owns the appetite decision, reconcile the stated period against the planning cycle, identify the objectives and constraints the appetite must respect, and document any mandate ambiguity before setting thresholds.\n2. Draft an appetite statement in decision-useful language, define threshold values with units and measurement basis, nominate the indicators that evidence position, test the thresholds against historical data for realism, and record rejected calibrations.\n\n**Record in AssureSwarm**\n1. Capture the appetite period, governance mandate, approving authority, objectives served, binding constraints, prior statement reference, and unresolved mandate questions.\n2. Document the appetite statement, threshold values with units and measurement basis, nominated indicators and their data sources, calibration rationale, rejected alternatives, and measurement limitations. Also record tolerance thresholds.\n\n**Exit criteria**\nRisk appetite authority provides expertise: The approving authority and period are unambiguous, the objectives and constraints are documented, and mandate gaps are escalated rather than assumed. The appetite statement is measurable through named indicators, thresholds are reproducible from a stated basis, and measurement limitations are carried into the position test.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Unauthorized privileged access","itemType":"risk","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve appetite and escalation record","description":null,"summary":null,"instructions":"**Objective**\nApprove appetite and escalation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the calibrated thresholds, current residual rating, indicator readings and their as-of dates, control testing results, open issues and remediations, and the escalation matrix in the governance mandate.\n2. Review all stage records, calibration rationale and rejected alternatives, indicator readings, threshold comparisons, breach responses, escalation confirmations, and open measurement limitations.\n\n**Procedure**\n1. Read each indicator against its threshold, classify the status, evaluate whether a breach requires acceptance, mitigation, or escalation, define trigger points for re-measurement, and route breaches to the authorized body before advancing.\n2. Trace the statement and thresholds to their stated basis, verify escalations reached the authorized body, confirm monitoring cadence and indicator ownership, and return unsupported calibration with precise comments.\n\n**Record in AssureSwarm**\n1. Record the tolerance status, indicator readings with as-of dates, threshold comparisons, breach response, escalation route and recipients, re-measurement triggers, and any indicator that could not be measured. Also record breach or monitoring response.\n2. Capture the authorized reviewer, the calibration summary, accepted appetite statement and thresholds, effective date, review cadence, escalation confirmations, open limitations, owners, and due dates.\n\n**Exit criteria**\nRisk oversight owner provides approval: An approver accepts that the status follows from the measured readings, breaches are routed to the authorized body, and unmeasurable indicators are declared rather than assumed compliant. The authorized reviewer accepts the calibration as a traceable record of appetite decisions, monitoring can proceed against named indicators, and closure implies no assurance that the position will remain within tolerance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Unauthorized privileged access","itemType":"risk","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Vendor concentration exposure","itemType":"risk","name":"Risk Appetite & Tolerance Calibration — Vendor concentration exposure — prior cycle","templateName":"Risk Appetite & Tolerance Calibration","templateSourceId":"coworkcanvas:template:risk-appetite-tolerance-calibration","description":"Risk Appetite & Tolerance Calibration for Vendor concentration exposure (prior cycle).","status":"COMPLETED","displayOrder":333,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Set appetite statement and tolerance thresholds","description":null,"summary":null,"instructions":"**Objective**\nSet appetite statement and tolerance thresholds. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, board and committee charters, strategy and objective statements, prior appetite statements, capital and liquidity constraints, regulatory expectations, and the approved risk criteria.\n2. Use the confirmed mandate, the risk assessment and its scoring rubric, loss history, control effectiveness results, monitoring indicators, industry and peer benchmarks, and stakeholder expectations.\n\n**Procedure**\n1. Confirm which body owns the appetite decision, reconcile the stated period against the planning cycle, identify the objectives and constraints the appetite must respect, and document any mandate ambiguity before setting thresholds.\n2. Draft an appetite statement in decision-useful language, define threshold values with units and measurement basis, nominate the indicators that evidence position, test the thresholds against historical data for realism, and record rejected calibrations.\n\n**Record in AssureSwarm**\n1. Capture the appetite period, governance mandate, approving authority, objectives served, binding constraints, prior statement reference, and unresolved mandate questions.\n2. Document the appetite statement, threshold values with units and measurement basis, nominated indicators and their data sources, calibration rationale, rejected alternatives, and measurement limitations. Also record tolerance thresholds.\n\n**Exit criteria**\nRisk appetite authority provides expertise: The approving authority and period are unambiguous, the objectives and constraints are documented, and mandate gaps are escalated rather than assumed. The appetite statement is measurable through named indicators, thresholds are reproducible from a stated basis, and measurement limitations are carried into the position test.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Vendor concentration exposure","itemType":"risk","kind":"related"},{"itemTitle":"Service Delivery Quality Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve appetite and escalation record","description":null,"summary":null,"instructions":"**Objective**\nApprove appetite and escalation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the calibrated thresholds, current residual rating, indicator readings and their as-of dates, control testing results, open issues and remediations, and the escalation matrix in the governance mandate.\n2. Review all stage records, calibration rationale and rejected alternatives, indicator readings, threshold comparisons, breach responses, escalation confirmations, and open measurement limitations.\n\n**Procedure**\n1. Read each indicator against its threshold, classify the status, evaluate whether a breach requires acceptance, mitigation, or escalation, define trigger points for re-measurement, and route breaches to the authorized body before advancing.\n2. Trace the statement and thresholds to their stated basis, verify escalations reached the authorized body, confirm monitoring cadence and indicator ownership, and return unsupported calibration with precise comments.\n\n**Record in AssureSwarm**\n1. Record the tolerance status, indicator readings with as-of dates, threshold comparisons, breach response, escalation route and recipients, re-measurement triggers, and any indicator that could not be measured. Also record breach or monitoring response.\n2. Capture the authorized reviewer, the calibration summary, accepted appetite statement and thresholds, effective date, review cadence, escalation confirmations, open limitations, owners, and due dates.\n\n**Exit criteria**\nRisk oversight owner provides approval: An approver accepts that the status follows from the measured readings, breaches are routed to the authorized body, and unmeasurable indicators are declared rather than assumed compliant. The authorized reviewer accepts the calibration as a traceable record of appetite decisions, monitoring can proceed against named indicators, and closure implies no assurance that the position will remain within tolerance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Vendor concentration exposure","itemType":"risk","kind":"related"},{"itemTitle":"Service Delivery Quality Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"AI model governance gap","itemType":"risk","name":"Risk Assessment & Treatment Review — AI model governance gap — next cycle","templateName":"Risk Assessment & Treatment Review","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","description":"Risk Assessment & Treatment Review for AI model governance gap (next cycle).","status":"DRAFT","displayOrder":341,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess exposure and control response","description":null,"summary":null,"instructions":"**Objective**\nAssess exposure and control response. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, business objectives, process and system maps, incidents, issues, loss events, prior assessments, control results, external changes, and approved scoring criteria.\n2. Use the confirmed context, scoring rubric, control design and testing results, monitoring trends, incidents, issues, scenarios, threat information, financial data, and owner representations.\n\n**Procedure**\n1. Reframe the risk as a clear cause-event-impact statement, confirm affected assets and stakeholders, reconcile ownership, identify material assumptions and dependencies, and document scope changes since the prior review.\n2. Score each required dimension, test the rationale against cited facts, evaluate control coverage and limitations, compare current and prior results, perform scenario analysis where material, and challenge optimistic assumptions.\n\n**Record in AssureSwarm**\n1. Capture the assessment period, risk context, owner, affected objectives, boundaries, assumptions, dependencies, change triggers, source references, and information gaps.\n2. Document scores, rating direction, calculation or rubric applied, supporting and contrary evidence, control reliance, uncertainty, sensitivity, prior-period comparison, and unresolved data requests. Also record assessment result.\n\n**Exit criteria**\nRisk assessment specialist provides expertise: The risk statement is decision-useful, ownership and assessment criteria are confirmed, and gaps that could change the assessment are visible and assigned. The assessment is reproducible from the cited evidence, rating changes are explained, and material uncertainty or control limitations are carried into treatment analysis.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"AI model governance gap","itemType":"risk","kind":"related"},{"itemTitle":"New Application Architecture Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve risk review record","description":null,"summary":null,"instructions":"**Objective**\nApprove risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, appetite and tolerance statements, existing initiatives, proposed controls, insurance or contractual terms, budget and resource constraints, dependencies, and stakeholder analysis.\n2. Review all stage records, scoring support, control evidence, treatment analysis, appetite exceptions, stakeholder responses, linked actions, monitoring measures, and open information gaps.\n\n**Procedure**\n1. Compare accept, mitigate, transfer, and avoid options; estimate risk reduction and secondary effects; define measurable actions and escalation triggers; identify owners and dates; and route appetite exceptions to authorized governance.\n2. Trace material ratings and decisions to evidence, verify action ownership and dates, confirm contrary evidence remains visible, reconcile linked records, and return incomplete or inconsistent analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the treatment decision, rationale, response plan, expected residual exposure, action owners, milestones, resources, dependencies, monitoring indicators, escalation thresholds, and linked remediation items.\n2. Capture the authorized reviewer, the review summary, accepted assessment and treatment references, effective review date, monitoring cadence, linked actions, open limitations, owners, and due dates. Also record risk review summary.\n\n**Exit criteria**\nRisk acceptance authority provides approval: An approver accepts that the selected response follows from the assessment and appetite criteria, while rejected options and any required exception approval remain traceable. The authorized reviewer accepts the risk review as a traceable record of analysis and decisions, linked records can be updated consistently, and no assurance claim is inferred from closure.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"AI model governance gap","itemType":"risk","kind":"related"},{"itemTitle":"New Application Architecture Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Brand trust deterioration","itemType":"risk","name":"Risk Assessment & Treatment Review — Brand trust deterioration — current cycle","templateName":"Risk Assessment & Treatment Review","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","description":"Risk Assessment & Treatment Review for Brand trust deterioration (current cycle).","status":"ACTIVE","displayOrder":342,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess exposure and control response","description":null,"summary":null,"instructions":"**Objective**\nAssess exposure and control response. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, business objectives, process and system maps, incidents, issues, loss events, prior assessments, control results, external changes, and approved scoring criteria.\n2. Use the confirmed context, scoring rubric, control design and testing results, monitoring trends, incidents, issues, scenarios, threat information, financial data, and owner representations.\n\n**Procedure**\n1. Reframe the risk as a clear cause-event-impact statement, confirm affected assets and stakeholders, reconcile ownership, identify material assumptions and dependencies, and document scope changes since the prior review.\n2. Score each required dimension, test the rationale against cited facts, evaluate control coverage and limitations, compare current and prior results, perform scenario analysis where material, and challenge optimistic assumptions.\n\n**Record in AssureSwarm**\n1. Capture the assessment period, risk context, owner, affected objectives, boundaries, assumptions, dependencies, change triggers, source references, and information gaps.\n2. Document scores, rating direction, calculation or rubric applied, supporting and contrary evidence, control reliance, uncertainty, sensitivity, prior-period comparison, and unresolved data requests. Also record assessment result.\n\n**Exit criteria**\nRisk assessment specialist provides expertise: The risk statement is decision-useful, ownership and assessment criteria are confirmed, and gaps that could change the assessment are visible and assigned. The assessment is reproducible from the cited evidence, rating changes are explained, and material uncertainty or control limitations are carried into treatment analysis.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Brand trust deterioration","itemType":"risk","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve risk review record","description":null,"summary":null,"instructions":"**Objective**\nApprove risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, appetite and tolerance statements, existing initiatives, proposed controls, insurance or contractual terms, budget and resource constraints, dependencies, and stakeholder analysis.\n2. Review all stage records, scoring support, control evidence, treatment analysis, appetite exceptions, stakeholder responses, linked actions, monitoring measures, and open information gaps.\n\n**Procedure**\n1. Compare accept, mitigate, transfer, and avoid options; estimate risk reduction and secondary effects; define measurable actions and escalation triggers; identify owners and dates; and route appetite exceptions to authorized governance.\n2. Trace material ratings and decisions to evidence, verify action ownership and dates, confirm contrary evidence remains visible, reconcile linked records, and return incomplete or inconsistent analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the treatment decision, rationale, response plan, expected residual exposure, action owners, milestones, resources, dependencies, monitoring indicators, escalation thresholds, and linked remediation items.\n2. Capture the authorized reviewer, the review summary, accepted assessment and treatment references, effective review date, monitoring cadence, linked actions, open limitations, owners, and due dates. Also record risk review summary.\n\n**Exit criteria**\nRisk acceptance authority provides approval: An approver accepts that the selected response follows from the assessment and appetite criteria, while rejected options and any required exception approval remain traceable. The authorized reviewer accepts the risk review as a traceable record of analysis and decisions, linked records can be updated consistently, and no assurance claim is inferred from closure.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Brand trust deterioration","itemType":"risk","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Business continuity outage","itemType":"risk","name":"Risk Assessment & Treatment Review — Business continuity outage — prior cycle","templateName":"Risk Assessment & Treatment Review","templateSourceId":"coworkcanvas:template:risk-assessment-treatment-review","description":"Risk Assessment & Treatment Review for Business continuity outage (prior cycle).","status":"COMPLETED","displayOrder":343,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess exposure and control response","description":null,"summary":null,"instructions":"**Objective**\nAssess exposure and control response. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, business objectives, process and system maps, incidents, issues, loss events, prior assessments, control results, external changes, and approved scoring criteria.\n2. Use the confirmed context, scoring rubric, control design and testing results, monitoring trends, incidents, issues, scenarios, threat information, financial data, and owner representations.\n\n**Procedure**\n1. Reframe the risk as a clear cause-event-impact statement, confirm affected assets and stakeholders, reconcile ownership, identify material assumptions and dependencies, and document scope changes since the prior review.\n2. Score each required dimension, test the rationale against cited facts, evaluate control coverage and limitations, compare current and prior results, perform scenario analysis where material, and challenge optimistic assumptions.\n\n**Record in AssureSwarm**\n1. Capture the assessment period, risk context, owner, affected objectives, boundaries, assumptions, dependencies, change triggers, source references, and information gaps.\n2. Document scores, rating direction, calculation or rubric applied, supporting and contrary evidence, control reliance, uncertainty, sensitivity, prior-period comparison, and unresolved data requests. Also record assessment result.\n\n**Exit criteria**\nRisk assessment specialist provides expertise: The risk statement is decision-useful, ownership and assessment criteria are confirmed, and gaps that could change the assessment are visible and assigned. The assessment is reproducible from the cited evidence, rating changes are explained, and material uncertainty or control limitations are carried into treatment analysis.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Business continuity outage","itemType":"risk","kind":"related"},{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve risk review record","description":null,"summary":null,"instructions":"**Objective**\nApprove risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, appetite and tolerance statements, existing initiatives, proposed controls, insurance or contractual terms, budget and resource constraints, dependencies, and stakeholder analysis.\n2. Review all stage records, scoring support, control evidence, treatment analysis, appetite exceptions, stakeholder responses, linked actions, monitoring measures, and open information gaps.\n\n**Procedure**\n1. Compare accept, mitigate, transfer, and avoid options; estimate risk reduction and secondary effects; define measurable actions and escalation triggers; identify owners and dates; and route appetite exceptions to authorized governance.\n2. Trace material ratings and decisions to evidence, verify action ownership and dates, confirm contrary evidence remains visible, reconcile linked records, and return incomplete or inconsistent analysis with precise comments.\n\n**Record in AssureSwarm**\n1. Record the treatment decision, rationale, response plan, expected residual exposure, action owners, milestones, resources, dependencies, monitoring indicators, escalation thresholds, and linked remediation items.\n2. Capture the authorized reviewer, the review summary, accepted assessment and treatment references, effective review date, monitoring cadence, linked actions, open limitations, owners, and due dates. Also record risk review summary.\n\n**Exit criteria**\nRisk acceptance authority provides approval: An approver accepts that the selected response follows from the assessment and appetite criteria, while rejected options and any required exception approval remain traceable. The authorized reviewer accepts the risk review as a traceable record of analysis and decisions, linked records can be updated consistently, and no assurance claim is inferred from closure.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Business continuity outage","itemType":"risk","kind":"related"},{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","name":"SOC 2 Trust Services Readiness — Identity and Access Management Audit — next cycle","templateName":"SOC 2 Trust Services Readiness","templateSourceId":"coworkcanvas:template:soc2-readiness","description":"SOC 2 Trust Services Readiness for Identity and Access Management Audit (next cycle).","status":"DRAFT","displayOrder":351,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Map criteria, risks, and controls","description":null,"summary":null,"instructions":"**Objective**\nMap criteria, risks, and controls. The engagement lead applies expertise to system boundaries, category applicability and complementary responsibilities.\n\n**Inputs**\n1. Review contracts and commitments, architecture and data flows, inventories, policies, risk assessments, vendor relationships, prior reports, incidents, change plans, and selected Trust Services Criteria.\n2. Use the approved boundary, criteria, risk register, control inventory, policies and procedures, architecture, vendor controls, customer responsibilities, prior findings, and available evidence.\n\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\nBefore execution, resolve the declared roles to named tenant users and verify native assignments and counts on every instantiated step. Assign two distinct people, the executive sponsor and security and compliance lead, to the assessment package. Assign a separate independent readiness reviewer who did not prepare or operate the assessed controls. Library role declarations do not assign users or enforce role membership; changing approvers may replace the required count, so recheck the two-person assignments after any change.\n\n**Procedure**\n1. Interview accountable owners, reconcile the system description to deployed services, identify carve-out or inclusive subservice treatment, define customers and commitments, select categories, and document boundary exclusions and dependencies.\n2. Assess criterion applicability, identify control coverage and gaps, test mapping specificity, document complementary user and subservice controls, trace system-description assertions to support, and challenge duplicate controls that do not address the criterion.\n3. Security common criteria CC1–CC9 remain in scope. For Availability, Confidentiality, Processing Integrity and Privacy, record category selection from service commitments and engagement scope, with the reason for each exclusion. Identify the reviewed companion assessment and its period, boundary, evidence, findings and approval version for each selected category. A missing or incompatible output is an explicit readiness gap, never an assumed pass.\n4. Prepare one evidence index across criteria: identify each artifact once with source, version, period, control references and the criteria it supports.\n\n**Record in AssureSwarm**\n1. Step result: Capture the review period, intended report type and period, services, trust categories, system components, locations, subservice organizations, commitments, boundaries, exclusions, changes, and limitations. Use the Audit.scope and Audit.period_start / Audit.period_end fields only after checking the tenant schema.\n2. Step document: Attach the criterion-to-control mapping and evidence index; document applicability rationale, risks, controls, evidence sources, owners, frequencies, subservice and user controls, system-description references, gaps, and conflicting evidence. Record the document reference in the step result.\n\n**Exit criteria**\nEngagement lead provides expertise: The readiness boundary and selected criteria are unambiguous, subservice treatment is explicit, and material components or commitments are not omitted without documented rationale. Every selected criterion has supported coverage or a visible gap, mappings are specific enough for evidence assessment, and owners agree on responsibility boundaries.\nThe engagement lead checks that the assessment package uses the same reviewed boundary and evidence index; optional categories remain scoped companion assessments, with no executor questionnaire.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Review common criteria design","description":null,"summary":null,"instructions":"**Objective**\nAssess CC1–CC9 design and obtain the two management contributions to the criterion-level evidence and action package. The executive sponsor approves governance and technical commitments and action ownership; the security and compliance lead applies expertise to the control design and approves the criterion findings and owned actions.\n\n**Inputs**\nConsume the reviewed system boundary, criteria-to-control mapping and resource-reference index from soc2-criteria-mapping. Use its named systems of record, current policy versions, review period and control references to resolve the evidence below. Record unavailable resources as gaps.\n\n_CC1 Control Environment Assessment_\n- Board & Governance Policy and Information Security Policy (current approved versions with effective dates)\n- Acceptable Use Policy acknowledgment records for employees and contractors\n- Minutes and decisions from the two most recent quarterly governance reviews\n- Signed quarterly attestations from the independent governance advisor, as executed to date under the prospective engagement\n- The linked consolidated controls for tone at the top and board-level oversight\n\nRole definitions for the executive sponsor, technology owner, and security and compliance lead, plus any outsourced security leadership or advisory scope\n- Information Security Policy sections assigning security roles, responsibilities, and authorities\n- Human Resources Security Policy with screening, onboarding agreement, and training records for the assessment window\n- Access documentation mapping role authority to cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform permissions\n\nBoard & Governance Policy and Human Resources Security Policy (accountability, performance, and sanctions provisions)\n- Control-owner assignments on the linked consolidated controls\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- Quarterly oversight reporting covering control metrics, overdue actions, and escalations\n\n_CC2 Communication and Information Assessment_\n- Information Security Objectives with the security metrics catalog and owners\n- The linked consolidated control for quality records and control information\n- A sample of recent control-run records with attached evidence across the operating processes\n- System-generated exports used by recurring controls: cloud identity and access management bindings, the workforce identity and collaboration platform membership, the continuous integration service results\n\nPolicy publication and acknowledgment records across the applicable governing policies\n- Security awareness communications and onboarding materials for the window\n- Customer-facing commitments: terms, support channels, and incident notification obligations\n- Subservice communication evidence: the cloud provider, the workforce identity and collaboration platform, and the source-control platform advisories and status feeds\n\n_CC3 Risk Assessment_\n- Information Security Objectives and business-context documentation\n- Risk Assessment Methodology and the current risk register with scores and owners\n- The most recent enterprise risk assessment run and its sign-off record\n- The linked consolidated controls for objective-setting and periodic risk assessment\n\nFraud-risk entries in the risk register, including management override and misappropriation scenarios\n- The linked consolidated controls for fraud risk and change-impact assessment\n- Segregation-of-duties documentation across cloud identity and access management, the source-control platform, and the billing surface\n- Change-assessment records for significant platform or organizational changes in the window\n\nRisk Management Policy and Risk Assessment Methodology (current approved versions with effective dates)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the risk-assessment series\n\n_CC4 Monitoring Activities Assessment_\n- The linked consolidated control for monitoring risk and control performance\n- Control-run completion data across the operating processes for the window\n- Internal audit program schedule and any completed engagement records\n- Quarterly governance review minutes covering control metrics\n\nThe linked consolidated control for deficiency tracking and remediation\n- The issue register for the window: source, severity, owner, age, and status\n- Escalation records for material deficiencies, including governance review minutes\n- Remediation action plans with due dates and closure evidence\n\n_CC5 Control Activities Assessment_\n- The linked consolidated control for the risk-based control baseline\n- The risk register with treatment mappings from risk to mitigating controls\n- The consolidated control set with its domain coverage (access, change, operations)\n- Segregation-of-duties expectations for control performers and approvers\n\nInformation Security Policy and the policy register with owners, versions, and review dates\n- The linked consolidated control for maintaining approved policies and procedures\n- Process records showing which procedures operationalize which policies\n- Acknowledgment and exception records for the window\n\n_CC6 Logical and Physical Access Controls Assessment_\n- The asset and system inventory identifying protected information assets\n- The linked consolidated controls for account lifecycle, least privilege, and asset inventory\n- Joiner, mover, and leaver records for the window with matching cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform changes\n- Role-to-permission mappings including privileged roles\n\nThe linked consolidated controls for physical access and media handling\n- The carve-out position for the cloud provider data-center physical security with current attestation coverage\n- Endpoint and media inventory: laptops and any removable media in circulation\n- Disposal and sanitization records for devices retired during the window\n\nThe linked consolidated controls for network boundary, encryption, and software restriction\n- Network and service architecture for the customer environments: ingress paths, TLS termination, service-to-service authentication\n- Encryption standards for data at rest and in transit, with key management ownership\n- Endpoint protection and allowed-software configuration for workforce devices\n\nAccess Control Policy, Password & Authentication Policy, and Physical Security Policy (current approved versions)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the access series\n\n_CC7 System Operations Assessment_\n- The linked consolidated controls for configuration baselines and continuous monitoring\n- Vulnerability management records: scans, dependency checks in the continuous integration service, and triage decisions\n- Configuration baselines for the customer environments and drift-detection evidence\n- Monitoring and alerting configuration with escalation routing\n\nThe linked consolidated controls for event evaluation and incident response\n- Incident response plan with declaration criteria, severity levels, and role assignments\n- Event triage records and any declared-incident records for the window\n- Notification obligations toward customers and dependencies on subservice providers\n\nThe linked consolidated control for incident recovery\n- Recovery procedures: infrastructure redeployment, backup restore, and credential rotation paths\n- Postmortem records or recovery exercise results for the window\n- Dependencies on subservice recovery commitments from the cloud provider\n\n_CC8 Change Management Assessment_\n- The linked consolidated control for change authorization and approval\n- the source-control platform configuration: protected branches, merge request approval rules, CI gate definitions\n- A sample of production changes from the window: application code, infrastructure, and database migrations\n- Emergency change records with retrospective approvals\n\nChange Management Policy and Software Development Lifecycle Policy (current approved versions with effective dates)\n- The design conclusion and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the change series\n\n_CC9 Risk Mitigation Assessment_\n- The linked consolidated control for business continuity and contingency planning policy\n- Disruption scenarios in the risk register with their selected mitigations\n- Continuity plan with roles, activation criteria, and recovery priorities\n- Key-person and succession arrangements for critical roles\n\nThe linked consolidated control for vendor due diligence\n- Vendor register with criticality tiers, owners, and review dates\n- Attestation evidence on file: SOC 2 or equivalent reports for the subservice organizations\n- Contracts and data processing terms for vendors touching customer data\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb the detailed assessment activities below; the assigned assessor evaluates the evidence and drafts each criterion conclusion for management review. Original criterion procedures retain their evidence and conclusion requirements within this package.*\n\n_CC1 Control Environment Assessment_\n1. Assessment scope for Assess Tone at the Top & Board Oversight: Assess CC1.1 and CC1.2: the entity demonstrates a commitment to integrity and ethical values, and the board function demonstrates independence from management and exercises oversight of the development and performance of internal control. Assess the ethical culture and governance oversight anchoring the scoped control environment.\n\n2. Read the Board & Governance Policy and confirm it defines standards of conduct, conflict-of-interest handling, and escalation paths that bind the executive sponsor as well as staff.\n\n3. Trace the two most recent quarterly governance reviews end to end: agenda, minutes, decisions, and follow-up actions recorded against the owning process in AssureSwarm.\n\n4. Verify the independent governance advisor's engagement establishes independence from day-to-day management, a defined oversight cadence, and a direct escalation path.\n\n5. Sample Acceptable Use Policy acknowledgments across the workforce and confirm any deviation was handled under the Human Resources Security Policy's sanctions provisions.\n\n6. Compare observed practice against each linked control's statement and record a design conclusion per criterion, noting gaps as candidate findings.\n\n7. Assessment scope for Evaluate Organizational Structure & Competence: Evaluate CC1.3 and CC1.4: management establishes structures, reporting lines, and authorities appropriate for the organization and its documented service architecture, and the organization attracts, develops, and retains competent people in alignment with its objectives.\n\n8. Confirm documented reporting lines match practice: who authorizes risk acceptances, production releases, and vendor commitments, and where each decision escalates.\n\n9. Verify segregation between engineering execution and independent review - including the firm-internal segregation attested through the advisory engagement - is reflected in the role definitions.\n\n10. Inspect screening evidence and signed confidentiality and acceptable-use agreements for personnel onboarded during the window.\n\n11. Review security awareness and role-based training completion and confirm that misses triggered documented follow-up.\n\n12. Test that authority in systems mirrors authority on paper by sampling cloud identity and access management bindings and the source-control platform access for one privileged role and one standard role.\n\n13. Record a design conclusion per criterion and log any mismatch as a candidate finding.\n\n14. Assessment scope for Conclude on Accountability & Control Environment: Assess CC1.5: individuals are held accountable for their internal control responsibilities. Then close the control-environment portion of the readiness assessment by consolidating the conclusions of the Assess Tone at the Top & Board Oversight and Evaluate Organizational Structure & Competence activities.\n\n15. Verify every in-scope control names an accountable owner and that ownership was reassigned promptly for any joiner, mover, or leaver event during the window.\n\n16. Inspect how missed control executions and policy violations were handled: escalation to the security and compliance lead and executive sponsor, sanctions applied under the Human Resources Security Policy, and corrective actions tracked to closure.\n\n17. Confirm performance expectations for roles holding privileged access or approval authority explicitly reference their control responsibilities.\n\n18. Consolidate the design conclusions for the full control-environment series into the readiness summary, classifying each criterion as designed or gap.\n\n19. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC2 Communication and Information Assessment_\n20. Assessment scope for Assess Quality of Control Information: Assess CC2.1: the entity obtains or generates and uses relevant, quality information to support the functioning of internal control. For the scoped service this means the information the control set runs on - control-run evidence in AssureSwarm, the cloud provider audit and application logs, the source-control platform pipeline results, and access exports - is relevant, complete, accurate, and timely enough to support control conclusions.\n\n21. Inventory the information each recurring control consumes and identify its source system, producer, and refresh cadence.\n\n22. For a sample of control runs in the assessment window, verify the evidence attached was system-generated where practical and current as of the run date.\n\n23. Trace two security metrics from the Information Security Objectives to their underlying data and confirm the figures are reproducible.\n\n24. Check that information the controls depend on is retained per requirements and remains retrievable for the audit period.\n\n25. Record a design conclusion for CC2.1 and log information-quality gaps as candidate findings.\n\n26. Assessment scope for Evaluate Internal & External Communication: Evaluate CC2.2 and CC2.3: the entity internally communicates information necessary for internal control to function, including objectives and responsibilities, and communicates with external parties on matters affecting internal control. In scope are onboarding and policy communication to the workforce, and the channels the organization maintains with customers, subservice organizations, and other external parties.\n\n27. Verify each policy names an owner and audience and that publication reached the affected workforce through the acknowledgment flow.\n\n28. Inspect how control responsibilities reach individuals: onboarding materials, role definitions, and recurring security awareness communications.\n\n29. Confirm externally facing channels exist for customers to report security, availability, and privacy concerns, and that inbound reports route to the incident process.\n\n30. Verify subservice advisories and status changes from the cloud provider, the workforce identity and collaboration platform, and the source-control platform are monitored and acted on.\n\n31. Record a design conclusion per criterion and log any communication gap as a candidate finding.\n\n_CC3 Risk Assessment_\n32. Assessment scope for Assess Objectives & Enterprise Risk Identification: Assess CC3.1 and CC3.2: the entity specifies objectives with sufficient clarity to enable identification and assessment of risks, and identifies and analyzes risks across the entity as a basis for determining how they are managed. For the scoped service the anchor artifacts are the Information Security Objectives and the periodic enterprise risk assessment feeding the risk register.\n\n33. Verify objectives are specific enough that a risk can be traced to the objective it threatens - sample three register entries and walk the trace.\n\n34. Confirm the enterprise risk assessment covered the platform, the subservice dependencies (the cloud provider, the workforce identity and collaboration platform, the source-control platform), and the workforce dimension.\n\n35. Check each identified risk carries an analysis: likelihood, impact, inherent and residual scores per the methodology, and a treatment decision.\n\n36. Verify risk owners exist for every open register entry and treatment actions carry target dates.\n\n37. Record a design conclusion per criterion and note gaps as candidate findings.\n\n38. Assessment scope for Evaluate Fraud Risk & Significant Change: Evaluate CC3.3 and CC3.4: the entity considers the potential for fraud in assessing risks, and identifies and assesses changes that could significantly impact the system of internal control. Assess management-override exposure and the available segregation of duties; change assessment must catch platform, subservice, and organizational shifts before they erode the control set.\n\n39. Verify the register carries explicit fraud scenarios - override of controls, unauthorized data access for gain, and misstatement - with analysis and treatments.\n\n40. Assess whether compensating measures for the small-team override risk are designed: independent review through the governance advisor, dual approvals, and immutable audit logging.\n\n41. Inspect how significant changes - new subservice providers, architecture shifts, tenancy model changes, key-person changes - enter risk assessment before adoption.\n\n42. Walk one significant change from the window through its documented risk assessment and approval.\n\n43. Record a design conclusion per criterion with gaps as candidate findings.\n\n44. Assessment scope for Conclude on Risk Assessment Design: Close the risk-assessment portion of the readiness assessment by consolidating the conclusions of the Assess Objectives & Enterprise Risk Identification and Evaluate Fraud Risk & Significant Change activities into a single series verdict against the governing risk policies.\n\n45. Confirm the Risk Management Policy and Risk Assessment Methodology are current, approved, and reflected in the practices the assessment observed.\n\n46. Reconcile every design conclusion recorded in this workflow against its criterion and confirm none is unsupported by attached evidence.\n\n47. Verify each open gap exists as an issue on the readiness audit with a named owner and a target date, and that no gap is silently absorbed into the verdict.\n\n48. Draft the risk-assessment section of the readiness summary, classifying each criterion as designed or gap.\n\n49. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC4 Monitoring Activities Assessment_\n50. Assessment scope for Assess Ongoing & Separate Evaluations: Assess CC4.1: the entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. For the scoped service the design rests on continuous control operation in AssureSwarm with recurring process runs, plus separate evaluations - the internal audit program, quarterly reviews with the governance advisor, and this readiness assessment itself.\n\n51. Verify recurring control runs have a defined cadence and an owner, and that completion is visible on the compliance dashboards.\n\n52. Confirm separate evaluations are scheduled with defined scope and independence - internal audit, the governance advisor's quarterly review, and external assessments.\n\n53. Inspect how monitoring results feed back: who reviews completion rates, missed runs, and stale evidence, and on what cadence.\n\n54. Walk one monitoring cycle end to end, from signal through review to a recorded action.\n\n55. Record a design conclusion for CC4.1 and note monitoring blind spots as candidate findings.\n\n56. Assessment scope for Evaluate Deficiency Communication & Remediation: Evaluate CC4.2: the entity evaluates and communicates internal control deficiencies in a timely manner to the parties responsible for corrective action, including senior management. For the scoped service deficiencies surface as issues in AssureSwarm; the design question is whether they reach the security and compliance lead and the executive sponsor fast enough and are tracked to closure rather than aging quietly.\n\n57. Verify each deficiency was recorded as an issue with severity, an accountable owner, and a remediation date at intake.\n\n58. Trace two deficiencies from detection through communication to the responsible owner and on to closure, confirming timelines match the severity.\n\n59. Confirm material deficiencies reached the executive sponsor and the governance advisor's quarterly review, with decisions minuted.\n\n60. Check that overdue remediation triggers escalation rather than silent date slippage.\n\n61. Record a design conclusion for CC4.2 and log any gap as a candidate finding.\n\n_CC5 Control Activities Assessment_\n62. Assessment scope for Assess Control Selection & Technology General Controls: Assess CC5.1 and CC5.2: the entity selects and develops control activities that mitigate risks to the achievement of objectives to acceptable levels, and selects and develops general control activities over technology. For the scoped service the design rests on a risk-based control baseline mapped to the register, with technology general controls spanning access, change, and operations across the cloud provider, the application hosting service, and the source-control platform.\n\n63. Sample three high residual risks and verify each maps to at least one designed control whose statement actually addresses the risk.\n\n64. Confirm the baseline covers the technology layers the platform depends on: the cloud provider infrastructure and IAM, the application hosting services, the managed database layer, and the source-control platform pipeline.\n\n65. Verify control activities mix types - preventive and detective, automated and manual - proportionate to the risk they mitigate.\n\n66. Check segregation of duties between performing a control and approving its result, with the small-team compensations documented.\n\n67. Record a design conclusion per criterion and log coverage gaps as candidate findings.\n\n68. Assessment scope for Evaluate Policy-to-Procedure Deployment: Evaluate CC5.3: the entity deploys control activities through policies that establish what is expected and procedures that put policies into action. The design question is whether the applicable governing policies anchored by the Information Security Policy translate into operable procedures - the recurring process runs and control activities in AssureSwarm - rather than sitting as shelfware.\n\n69. Verify every policy names an owner, carries an approval and a next review date, and completed its periodic review on schedule.\n\n70. Sample three policies and confirm each is deployed through at least one linked process or control that puts it into action.\n\n71. Confirm policy exceptions follow the documented path - time-boxed, risk-assessed, and approved by the authorized role.\n\n72. Check the accountability wiring: performers can reach the procedure that governs their control activity from the control record itself.\n\n73. Record a design conclusion for CC5.3 and note deployment gaps as candidate findings.\n\n_CC6 Logical and Physical Access Controls Assessment_\n74. Assessment scope for Assess Logical Access Architecture & Credential Lifecycle: Assess CC6.1, CC6.2, and CC6.3: logical access security software and architectures protect information assets; new users are registered and authorized before credentials issue and credentials are removed when access ends; and access is authorized, modified, or removed based on roles with least privilege and segregation of duties. Evaluate the documented customer-isolation architecture where the scoped service hosts multiple customers.\n\n75. Verify the inventory covers the systems holding customer and corporate data, so access architecture decisions rest on a complete asset picture.\n\n76. Confirm the documented customer-isolation model through scoped service identities and segregation of customer resources; verify that credentials cannot cross an unauthorized customer boundary.\n\n77. Trace each leaver in the window to credential removal across cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform within the required interval.\n\n78. Sample privileged and standard role grants and verify authorization preceded issuance and matches the role mapping.\n\n79. Record a design conclusion per criterion and log deviations as candidate findings.\n\n80. Assessment scope for Evaluate Physical Safeguards & Asset Disposal: Evaluate CC6.4 and CC6.5: physical access to facilities and protected information assets is restricted to authorized personnel, and physical protections are discontinued only after the ability to read or recover data has been diminished. Identify direct and inherited physical responsibilities from the documented operating model. Review provider attestations where relied upon, and assess controlled facilities, workforce endpoints, remote workspaces where applicable, and media disposal.\n\n81. Confirm the boundary: which physical responsibilities are inherited from the hosting provider and which remain with the organization, and that the inherited portion is covered by current attestations.\n\n82. Verify workforce physical practice is defined for remote work - screen locking, clear desk, secured devices - and communicated to everyone with production access.\n\n83. Check every retired device in the window has a sanitization or destruction record before leaving control.\n\n84. Verify media containing customer data never leaves the cloud boundary except through approved, encrypted paths.\n\n85. Record a design conclusion per criterion and log gaps as candidate findings.\n\n86. Assessment scope for Assess Boundary Defense, Transmission Protection & Malware Controls: Assess CC6.6, CC6.7, and CC6.8: logical access measures protect against threats from outside the system boundary; transmission, movement, and removal of information is restricted to authorized parties and protected in motion; and controls prevent or detect the introduction of unauthorized or malicious software. The perimeter under review is the application hosting service boundary of each scoped customer environment plus the workforce endpoint fleet.\n\n87. Verify each customer environment exposes only intended ingress: authenticated application hosting service endpoints behind TLS, no stray listeners or publicly readable storage.\n\n88. Confirm encryption in transit end to end and at rest on managed storage, with key management responsibilities documented.\n\n89. Check information movement paths - exports, support access, engineering diagnostics - are restricted to authorized users and logged.\n\n90. Verify endpoint protection and software allow-listing are deployed on workforce devices, with unauthorized-software detection feeding alerts.\n\n91. Record a design conclusion per criterion and log exposures as candidate findings.\n\n92. Assessment scope for Conclude on Access Control Design: Close the logical and physical access portion of the readiness assessment by consolidating the conclusions of the Assess Logical Access Architecture & Credential Lifecycle, Evaluate Physical Safeguards & Asset Disposal, and Assess Boundary Defense, Transmission Protection & Malware Controls activities into a single series verdict against the governing access policies.\n\n93. Confirm the three governing policies are current, approved, and consistent with the access practices the assessment observed.\n\n94. Reconcile the design conclusion for each of the eight criteria against its supporting evidence and flag any unsupported verdict.\n\n95. Verify every open access gap exists as an issue on the readiness audit with a named owner and a target date.\n\n96. Draft the access section of the readiness summary, classifying each criterion as designed or gap.\n\n97. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC7 System Operations Assessment_\n98. Assessment scope for Assess Vulnerability Detection & Anomaly Monitoring: Assess CC7.1 and CC7.2: detection and monitoring procedures identify configuration changes that introduce vulnerabilities and susceptibilities to newly discovered ones, and system components are monitored for anomalies indicative of malicious acts, natural disasters, or errors. The surface is the cloud provider estate and the application hosting services plus the source-control platform pipeline that changes them.\n\n99. Verify hardened baselines exist for the platform's building blocks and that deviations surface as findings rather than persisting silently.\n\n100. Confirm dependency and container scanning runs in the source-control platform pipeline with triage timelines tied to severity.\n\n101. Inspect alert coverage across the customer environments: authentication anomalies, availability signals, and error-rate spikes reach an accountable responder.\n\n102. Walk one vulnerability and one anomaly from detection to disposition.\n\n103. Record a design conclusion per criterion and log blind spots as candidate findings.\n\n104. Assessment scope for Evaluate Event Evaluation & Incident Response: Evaluate CC7.3 and CC7.4: the entity evaluates security events to determine whether they are security incidents, and responds to incidents through a defined program to understand, contain, remediate, and communicate. The design under review is the incident lifecycle from event triage through declared-incident execution, including customer notification duties and coordination with subservice providers.\n\n105. Verify declaration criteria distinguish events from incidents and that triage decisions in the window applied them consistently.\n\n106. Confirm the response program defines roles, containment playbooks, evidence preservation, and communication duties, including customer notification thresholds.\n\n107. Walk one event through triage and, if any incident was declared, through containment, remediation, and communication to closure; otherwise inspect the most recent response exercise.\n\n108. Check that post-incident review feeds corrective actions into the issue register.\n\n109. Record a design conclusion per criterion and log gaps as candidate findings.\n\n110. Assessment scope for Assess Incident Recovery Activities: Assess CC7.5: the entity identifies, develops, and implements activities to recover from identified security incidents. For the scoped service this means restoring affected customer services after a security incident - rebuilding from clean infrastructure definitions and restoring from protected backups - and folding lessons learned back into controls and playbooks.\n\n111. Verify documented recovery procedures exist for the plausible incident classes: compromised credentials, malicious change, data corruption, and service compromise.\n\n112. Confirm recovery is exercisable - a tenant environment can be redeployed from definitions and data restored from backups - with recent evidence of a test.\n\n113. Check recovery includes integrity verification before returning to service, so a compromise is not restored along with the data.\n\n114. Verify postmortems produced corrective actions with owners and dates, and that those actions closed.\n\n115. Record a design conclusion for CC7.5 and log gaps as candidate findings.\n\n_CC8 Change Management Assessment_\n116. Assessment scope for Assess Change Authorization, Testing & Deployment: Assess CC8.1: the entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures. Assess the approved production change path: independently reviewed change requests, automated test gates, protected branches, infrastructure definitions, and database migrations.\n\n117. Verify the pipeline enforces the lifecycle: no direct pushes to protected branches, independent review before merge, and green CI gates before deploy.\n\n118. Sample changes across the three classes - application code, infrastructure definitions, database migrations - and confirm each shows authorization, testing, approval, and deployment evidence.\n\n119. Check segregation between author and approver holds in practice, including the small-team case with documented compensations.\n\n120. Verify emergency changes follow the expedited path and receive retrospective review within the required interval.\n\n121. Record a design conclusion for CC8.1 and log deviations as candidate findings.\n\n122. Assessment scope for Conclude on Change Management Design: Close the change-management portion of the readiness assessment by consolidating the conclusion of the Assess Change Authorization, Testing & Deployment activity into a series verdict against the governing change policies.\n\n123. Confirm both governing policies are current, approved, and consistent with the observed pipeline practice, including the emergency path.\n\n124. Reconcile the CC8.1 design conclusion against its supporting evidence and flag anything unsupported.\n\n125. Verify every open change gap exists as an issue on the readiness audit with a named owner and a target date.\n\n126. Draft the change section of the readiness summary, classifying the criterion as designed or gap.\n\n127. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the assessment activity instead of closing it here.\n\n_CC9 Risk Mitigation Assessment_\n128. Assessment scope for Assess Business Disruption Risk Mitigation: Assess CC9.1: the entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions. For the scoped service, assess disruptions including hosting-region loss, key-person unavailability, subservice failure, and funding interruption; the design anchor is the business continuity and contingency planning framework.\n\n129. Verify the register carries the disruption scenarios that matter for the operating model and each carries a selected mitigation, not just an acceptance.\n\n130. Confirm the continuity plan assigns roles and activation criteria and covers the platform's dependency on the cloud provider regional services.\n\n131. Check key-person risk carries concrete mitigations: documented runbooks, credential escrow, and cross-training or advisory cover.\n\n132. Verify mitigation activities have owners and review dates, so they survive personnel and platform change.\n\n133. Record a design conclusion for CC9.1 and log gaps as candidate findings.\n\n134. Assessment scope for Evaluate Vendor & Business Partner Risk Management: Evaluate CC9.2: the entity assesses and manages risks associated with vendors and business partners. Use the approved vendor register to identify material cloud, identity, development-platform, and advisory dependencies; document the significance of each relationship.\n\n135. Verify every active vendor appears in the register with a criticality tier, an owner, and a next review date.\n\n136. Confirm due diligence preceded engagement for vendors touching customer data and was refreshed on schedule for the critical tier.\n\n137. Inspect the most recent attestation review for each subservice organization, including exceptions noted and complementary controls adopted in response.\n\n138. Check exit thinking exists for the concentrated dependencies: what happens if a critical vendor degrades, and who decides.\n\n139. Record a design conclusion for CC9.2 and log gaps as candidate findings.\n\n140. Keep a separate conclusion for each criterion, with the assessor identity, evidence references, applicable controls, design or implementation gaps and rationale. Preserve adverse and conflicting evidence. The executive sponsor and security and compliance lead each review this exact package version and acknowledge findings, action ownership and commitments through separate native approvals; an unresolved objection prevents completion and requires correction. Their approval does not replace the independent readiness review at soc2-readiness-closure.\n\n**Record in AssureSwarm**\nUse the markdown step result for the signed assessor conclusions, criterion-to-evidence references and limitations; use attached step documents for the workpapers listed below. After checking the tenant schema, create or update each gap as an Issue (issue_type: finding, source: internal_audit, severity, issue_owner) and link it to the existing Audit and affected Control records. Record each corrective action on a linked Remediation item using plan, action_owner and target_date. If those fields or the Remediation type are unavailable, retain the action plan, owner and target date in the step workpaper and disclose the missing destination; do not invent Issue fields. Describe criterion identifiers in the workpaper and Issue; no Criterion item is required. Bind both native management approvals to the same reviewed package version. Substantive changes require renewed approvals before downstream reliance.\n\n_CC1 Control Environment Assessment_\nAttach the governance minutes, the advisor attestations, and the acknowledgment export to this step. Raise each design gap as an issue linked to the readiness audit, referencing the affected control by title, and note the design conclusion in the step record.\n\nAttach the role definitions, sampled screening and training evidence, and the permission exports to this step. Link each gap to the affected control, raise it as an issue on the readiness audit, and capture the rationale for each conclusion in the step record.\n\nRecord the consolidated conclusion on this step and attach the control-environment section of the readiness summary. Confirm every gap exists as an issue linked to the readiness audit with a named owner and a target date before requesting approval.\n\n_CC2 Communication and Information Assessment_\nAttach the information inventory, sampled control-run evidence, and metric traces to this step. Raise each information-quality gap as an issue linked to the readiness audit, referencing the affected control by title.\n\nAttach acknowledgment exports, sample communications, and the external-channel inventory to this step. Raise gaps as issues linked to the readiness audit and record the conclusion for each criterion in the step record.\n\n_CC3 Risk Assessment_\nAttach the risk register export and the assessment sign-off to this step. Raise each gap as an issue linked to the readiness audit and record the design conclusions in the step record.\n\nAttach the fraud-risk extract, override compensations, and the sampled change assessment to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the risk-assessment section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC4 Monitoring Activities Assessment_\nAttach the cadence inventory, completion metrics, and review minutes to this step. Raise blind spots as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the issue register export and the traced deficiency records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC5 Control Activities Assessment_\nAttach the risk-to-control mapping sample and the domain coverage summary to this step. Raise coverage gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the policy register export and the sampled policy-to-procedure traces to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC6 Logical and Physical Access Controls Assessment_\nAttach the inventory extract, lifecycle samples, and permission exports to this step. Raise deviations as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the carve-out summary, endpoint inventory, and disposal records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the architecture summary, encryption standard, and endpoint configuration evidence to this step. Raise exposures as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the access section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC7 System Operations Assessment_\nAttach scan samples, baseline evidence, and alert-routing configuration to this step. Raise blind spots as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach triage samples, the response plan, and walkthrough records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach recovery procedures, exercise evidence, and postmortem records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC8 Change Management Assessment_\nAttach the pipeline configuration export and the sampled change records to this step. Raise deviations as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the change section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC9 Risk Mitigation Assessment_\nAttach the disruption-scenario extract and continuity plan to this step. Raise gaps as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the vendor register export and attestation review notes to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n**Exit criteria**\n_CC1 Control Environment Assessment_\nCC1.1 and CC1.2 each carry a documented design conclusion supported by attached evidence, and every candidate finding has a named owner and a target date. CC1.3 and CC1.4 each carry a supported design conclusion across structures, reporting lines, and competence practices, and any divergence between documented authority and system permissions is logged as an issue with an owner and a target date. All five control-environment criteria (CC1.1–CC1.5) carry a supported design conclusion, both approvers have signed off on this step, and no control-environment gap remains without an owner, a target date, and a linked issue.\n\n_CC2 Communication and Information Assessment_\nCC2.1 carries a documented design conclusion supported by attached evidence, and every information-quality gap has a named owner and a target date. CC2.2 and CC2.3 each carry a documented design conclusion, every communication gap is logged with a named owner and a target date, and the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC3 Risk Assessment_\nCC3.1 and CC3.2 each carry a documented design conclusion supported by attached evidence, and identified gaps have named owners and target dates. CC3.3 and CC3.4 each carry a documented design conclusion, and every gap is logged with a named owner and a target date. All four criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no risk-assessment gap remains without an owner, a target date, and a linked issue.\n\n_CC4 Monitoring Activities Assessment_\nCC4.1 carries a documented design conclusion supported by attached evidence, and every monitoring blind spot has a named owner and a target date. CC4.2 carries a documented design conclusion, both traced deficiencies show timely communication and closure, and remaining gaps carry named owners and target dates.\n\n_CC5 Control Activities Assessment_\nCC5.1 and CC5.2 each carry a documented design conclusion, and every coverage gap is logged with a named owner and a target date. CC5.3 carries a documented design conclusion, sampled policies trace to operating procedures, and every deployment gap has a named owner and a target date.\n\n_CC6 Logical and Physical Access Controls Assessment_\nCC6.1, CC6.2, and CC6.3 each carry a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC6.4 and CC6.5 each carry a documented design conclusion, the inherited-versus-retained boundary is explicit, and every gap has a named owner and a target date. CC6.6, CC6.7, and CC6.8 each carry a documented design conclusion supported by attached evidence, and every exposure has a named owner and a target date. All eight criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no access gap remains without an owner, a target date, and a linked issue.\n\n_CC7 System Operations Assessment_\nCC7.1 and CC7.2 each carry a documented design conclusion supported by attached evidence, and every blind spot has a named owner and a target date. CC7.3 and CC7.4 each carry a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC7.5 carries a documented design conclusion supported by attached evidence, and every recovery gap has a named owner and a target date.\n\n_CC8 Change Management Assessment_\nCC8.1 carries a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC8.1 carries a supported design conclusion, both approvers have signed off on this step, and no change gap remains without an owner, a target date, and a linked issue.\n\n_CC9 Risk Mitigation Assessment_\nCC9.1 carries a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC9.2 carries a documented design conclusion supported by attached evidence, and every vendor gap has a named owner and a target date.\n\nThe executive sponsor and security and compliance lead are two distinct assigned approvers. Both have approved this version, every criterion has a signed assessor conclusion and evidence or a visible gap, and all gaps have owners and dates. The independent readiness conclusion remains pending until soc2-readiness-closure.","type":"TASK","requiredApprovals":2,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1},{"email":"george.michael@bluth.example","reviewLevel":2}]},{"stepNumber":3,"name":"Approve SOC 2 readiness record","description":null,"summary":null,"instructions":"**Objective**\nApprove SOC 2 readiness record. The independent readiness reviewer challenges evidence sufficiency and approves the examination-planning disposition.\n\n**Inputs**\nConsume the reviewed assessment package from soc2-common-criteria-assessment, with its two management approvals, signed assessor conclusions, criterion evidence and owned gap register. Also consume the reviewed companion assessment for each selected optional category; exclusions must trace to the approved scope.\n1. Review mapped controls, walkthroughs, sample evidence across the intended period, system-description draft, incidents, exceptions, vendor reports, gap inventory, remediation plans, and readiness milestones.\n2. Review all stage evidence, final mapping, system-description version, gap and remediation tracker, readiness result, subservice and user responsibilities, changes, limitations, and stakeholder comments.\n\n**Procedure**\n1. Inspect evidence quality and continuity, identify missing operating history, validate design and implementation observations, assess gap impact by criterion, sequence remediation and evidence generation, and avoid presenting readiness work as examination testing.\n2. Trace the disposition to criterion-level evidence, verify gaps and dependencies remain visible, reconcile document versions and scope, challenge unsupported timing, and return inconsistencies or hidden limitations for correction.\n3. Independently challenge all 33 common-criteria conclusions (CC1.1–CC1.5, CC2.1–CC2.3, CC3.1–CC3.4, CC4.1–CC4.2, CC5.1–CC5.3, CC6.1–CC6.8, CC7.1–CC7.5, CC8.1, CC9.1–CC9.2). For each, record the independent reviewer conclusion, evidence sufficiency, control mapping and remaining gap; reconcile the four optional categories to the approved engagement scope and applicable reviewed companion outputs.\n4. Verify both named management roles approved the exact package versions and that the reviewer is independent of preparation and operation of the assessed controls. Return unsupported or disputed conclusions to the owning assessment package; substantive corrections require its renewed dual approvals and this independent review. Management acceptance cannot cure insufficient evidence or override the independent conclusion.\n5. Hand the approved disposition, conditions and action tracker to management for remediation and examination planning. Keep SOC 2 Type II interim testing, PBC evidence preparation and management assertion with their separate owners and workflows. The service auditor retains responsibility for any SOC opinion.\n\n**Record in AssureSwarm**\n1. Step result: Document the readiness result by criterion, evidence reviewed, design or implementation gaps, operating-history needs, remediation owner and due date, dependencies, conditions, and proposed examination timing.\n2. Step document: Attach the SOC 2 readiness summary and final evidence index; capture the authorized reviewer, final boundary and mapping references, readiness result, conditions, gaps, remediation owners and dates, system-description status, intended next step, limitations, and reassessment triggers. The native approval records the independent reviewer’s decision against this version.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the evidence-based readiness disposition, conditions and gaps are fully owned, and no claim of SOC 2 certification or auditor opinion is made. The authorized reviewer accepts a management readiness record for planning purposes; closure is not certification and does not predict or replace a service auditor’s opinion.\nEvery common criterion and selected optional category has an independent conclusion with evidence or an explicit limitation. The independent readiness reviewer has recorded native approval; the two management approvals remain separate and traceable.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Incident Response Investigation","itemType":"audit","name":"SOC 2 Trust Services Readiness — Incident Response Investigation — current cycle","templateName":"SOC 2 Trust Services Readiness","templateSourceId":"coworkcanvas:template:soc2-readiness","description":"SOC 2 Trust Services Readiness for Incident Response Investigation (current cycle).","status":"ACTIVE","displayOrder":352,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Map criteria, risks, and controls","description":null,"summary":null,"instructions":"**Objective**\nMap criteria, risks, and controls. The engagement lead applies expertise to system boundaries, category applicability and complementary responsibilities.\n\n**Inputs**\n1. Review contracts and commitments, architecture and data flows, inventories, policies, risk assessments, vendor relationships, prior reports, incidents, change plans, and selected Trust Services Criteria.\n2. Use the approved boundary, criteria, risk register, control inventory, policies and procedures, architecture, vendor controls, customer responsibilities, prior findings, and available evidence.\n\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\nBefore execution, resolve the declared roles to named tenant users and verify native assignments and counts on every instantiated step. Assign two distinct people, the executive sponsor and security and compliance lead, to the assessment package. Assign a separate independent readiness reviewer who did not prepare or operate the assessed controls. Library role declarations do not assign users or enforce role membership; changing approvers may replace the required count, so recheck the two-person assignments after any change.\n\n**Procedure**\n1. Interview accountable owners, reconcile the system description to deployed services, identify carve-out or inclusive subservice treatment, define customers and commitments, select categories, and document boundary exclusions and dependencies.\n2. Assess criterion applicability, identify control coverage and gaps, test mapping specificity, document complementary user and subservice controls, trace system-description assertions to support, and challenge duplicate controls that do not address the criterion.\n3. Security common criteria CC1–CC9 remain in scope. For Availability, Confidentiality, Processing Integrity and Privacy, record category selection from service commitments and engagement scope, with the reason for each exclusion. Identify the reviewed companion assessment and its period, boundary, evidence, findings and approval version for each selected category. A missing or incompatible output is an explicit readiness gap, never an assumed pass.\n4. Prepare one evidence index across criteria: identify each artifact once with source, version, period, control references and the criteria it supports.\n\n**Record in AssureSwarm**\n1. Step result: Capture the review period, intended report type and period, services, trust categories, system components, locations, subservice organizations, commitments, boundaries, exclusions, changes, and limitations. Use the Audit.scope and Audit.period_start / Audit.period_end fields only after checking the tenant schema.\n2. Step document: Attach the criterion-to-control mapping and evidence index; document applicability rationale, risks, controls, evidence sources, owners, frequencies, subservice and user controls, system-description references, gaps, and conflicting evidence. Record the document reference in the step result.\n\n**Exit criteria**\nEngagement lead provides expertise: The readiness boundary and selected criteria are unambiguous, subservice treatment is explicit, and material components or commitments are not omitted without documented rationale. Every selected criterion has supported coverage or a visible gap, mappings are specific enough for evidence assessment, and owners agree on responsibility boundaries.\nThe engagement lead checks that the assessment package uses the same reviewed boundary and evidence index; optional categories remain scoped companion assessments, with no executor questionnaire.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Incident Response Investigation","itemType":"audit","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Review common criteria design","description":null,"summary":null,"instructions":"**Objective**\nAssess CC1–CC9 design and obtain the two management contributions to the criterion-level evidence and action package. The executive sponsor approves governance and technical commitments and action ownership; the security and compliance lead applies expertise to the control design and approves the criterion findings and owned actions.\n\n**Inputs**\nConsume the reviewed system boundary, criteria-to-control mapping and resource-reference index from soc2-criteria-mapping. Use its named systems of record, current policy versions, review period and control references to resolve the evidence below. Record unavailable resources as gaps.\n\n_CC1 Control Environment Assessment_\n- Board & Governance Policy and Information Security Policy (current approved versions with effective dates)\n- Acceptable Use Policy acknowledgment records for employees and contractors\n- Minutes and decisions from the two most recent quarterly governance reviews\n- Signed quarterly attestations from the independent governance advisor, as executed to date under the prospective engagement\n- The linked consolidated controls for tone at the top and board-level oversight\n\nRole definitions for the executive sponsor, technology owner, and security and compliance lead, plus any outsourced security leadership or advisory scope\n- Information Security Policy sections assigning security roles, responsibilities, and authorities\n- Human Resources Security Policy with screening, onboarding agreement, and training records for the assessment window\n- Access documentation mapping role authority to cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform permissions\n\nBoard & Governance Policy and Human Resources Security Policy (accountability, performance, and sanctions provisions)\n- Control-owner assignments on the linked consolidated controls\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- Quarterly oversight reporting covering control metrics, overdue actions, and escalations\n\n_CC2 Communication and Information Assessment_\n- Information Security Objectives with the security metrics catalog and owners\n- The linked consolidated control for quality records and control information\n- A sample of recent control-run records with attached evidence across the operating processes\n- System-generated exports used by recurring controls: cloud identity and access management bindings, the workforce identity and collaboration platform membership, the continuous integration service results\n\nPolicy publication and acknowledgment records across the applicable governing policies\n- Security awareness communications and onboarding materials for the window\n- Customer-facing commitments: terms, support channels, and incident notification obligations\n- Subservice communication evidence: the cloud provider, the workforce identity and collaboration platform, and the source-control platform advisories and status feeds\n\n_CC3 Risk Assessment_\n- Information Security Objectives and business-context documentation\n- Risk Assessment Methodology and the current risk register with scores and owners\n- The most recent enterprise risk assessment run and its sign-off record\n- The linked consolidated controls for objective-setting and periodic risk assessment\n\nFraud-risk entries in the risk register, including management override and misappropriation scenarios\n- The linked consolidated controls for fraud risk and change-impact assessment\n- Segregation-of-duties documentation across cloud identity and access management, the source-control platform, and the billing surface\n- Change-assessment records for significant platform or organizational changes in the window\n\nRisk Management Policy and Risk Assessment Methodology (current approved versions with effective dates)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the risk-assessment series\n\n_CC4 Monitoring Activities Assessment_\n- The linked consolidated control for monitoring risk and control performance\n- Control-run completion data across the operating processes for the window\n- Internal audit program schedule and any completed engagement records\n- Quarterly governance review minutes covering control metrics\n\nThe linked consolidated control for deficiency tracking and remediation\n- The issue register for the window: source, severity, owner, age, and status\n- Escalation records for material deficiencies, including governance review minutes\n- Remediation action plans with due dates and closure evidence\n\n_CC5 Control Activities Assessment_\n- The linked consolidated control for the risk-based control baseline\n- The risk register with treatment mappings from risk to mitigating controls\n- The consolidated control set with its domain coverage (access, change, operations)\n- Segregation-of-duties expectations for control performers and approvers\n\nInformation Security Policy and the policy register with owners, versions, and review dates\n- The linked consolidated control for maintaining approved policies and procedures\n- Process records showing which procedures operationalize which policies\n- Acknowledgment and exception records for the window\n\n_CC6 Logical and Physical Access Controls Assessment_\n- The asset and system inventory identifying protected information assets\n- The linked consolidated controls for account lifecycle, least privilege, and asset inventory\n- Joiner, mover, and leaver records for the window with matching cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform changes\n- Role-to-permission mappings including privileged roles\n\nThe linked consolidated controls for physical access and media handling\n- The carve-out position for the cloud provider data-center physical security with current attestation coverage\n- Endpoint and media inventory: laptops and any removable media in circulation\n- Disposal and sanitization records for devices retired during the window\n\nThe linked consolidated controls for network boundary, encryption, and software restriction\n- Network and service architecture for the customer environments: ingress paths, TLS termination, service-to-service authentication\n- Encryption standards for data at rest and in transit, with key management ownership\n- Endpoint protection and allowed-software configuration for workforce devices\n\nAccess Control Policy, Password & Authentication Policy, and Physical Security Policy (current approved versions)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the access series\n\n_CC7 System Operations Assessment_\n- The linked consolidated controls for configuration baselines and continuous monitoring\n- Vulnerability management records: scans, dependency checks in the continuous integration service, and triage decisions\n- Configuration baselines for the customer environments and drift-detection evidence\n- Monitoring and alerting configuration with escalation routing\n\nThe linked consolidated controls for event evaluation and incident response\n- Incident response plan with declaration criteria, severity levels, and role assignments\n- Event triage records and any declared-incident records for the window\n- Notification obligations toward customers and dependencies on subservice providers\n\nThe linked consolidated control for incident recovery\n- Recovery procedures: infrastructure redeployment, backup restore, and credential rotation paths\n- Postmortem records or recovery exercise results for the window\n- Dependencies on subservice recovery commitments from the cloud provider\n\n_CC8 Change Management Assessment_\n- The linked consolidated control for change authorization and approval\n- the source-control platform configuration: protected branches, merge request approval rules, CI gate definitions\n- A sample of production changes from the window: application code, infrastructure, and database migrations\n- Emergency change records with retrospective approvals\n\nChange Management Policy and Software Development Lifecycle Policy (current approved versions with effective dates)\n- The design conclusion and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the change series\n\n_CC9 Risk Mitigation Assessment_\n- The linked consolidated control for business continuity and contingency planning policy\n- Disruption scenarios in the risk register with their selected mitigations\n- Continuity plan with roles, activation criteria, and recovery priorities\n- Key-person and succession arrangements for critical roles\n\nThe linked consolidated control for vendor due diligence\n- Vendor register with criticality tiers, owners, and review dates\n- Attestation evidence on file: SOC 2 or equivalent reports for the subservice organizations\n- Contracts and data processing terms for vendors touching customer data\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb the detailed assessment activities below; the assigned assessor evaluates the evidence and drafts each criterion conclusion for management review. Original criterion procedures retain their evidence and conclusion requirements within this package.*\n\n_CC1 Control Environment Assessment_\n1. Assessment scope for Assess Tone at the Top & Board Oversight: Assess CC1.1 and CC1.2: the entity demonstrates a commitment to integrity and ethical values, and the board function demonstrates independence from management and exercises oversight of the development and performance of internal control. Assess the ethical culture and governance oversight anchoring the scoped control environment.\n\n2. Read the Board & Governance Policy and confirm it defines standards of conduct, conflict-of-interest handling, and escalation paths that bind the executive sponsor as well as staff.\n\n3. Trace the two most recent quarterly governance reviews end to end: agenda, minutes, decisions, and follow-up actions recorded against the owning process in AssureSwarm.\n\n4. Verify the independent governance advisor's engagement establishes independence from day-to-day management, a defined oversight cadence, and a direct escalation path.\n\n5. Sample Acceptable Use Policy acknowledgments across the workforce and confirm any deviation was handled under the Human Resources Security Policy's sanctions provisions.\n\n6. Compare observed practice against each linked control's statement and record a design conclusion per criterion, noting gaps as candidate findings.\n\n7. Assessment scope for Evaluate Organizational Structure & Competence: Evaluate CC1.3 and CC1.4: management establishes structures, reporting lines, and authorities appropriate for the organization and its documented service architecture, and the organization attracts, develops, and retains competent people in alignment with its objectives.\n\n8. Confirm documented reporting lines match practice: who authorizes risk acceptances, production releases, and vendor commitments, and where each decision escalates.\n\n9. Verify segregation between engineering execution and independent review - including the firm-internal segregation attested through the advisory engagement - is reflected in the role definitions.\n\n10. Inspect screening evidence and signed confidentiality and acceptable-use agreements for personnel onboarded during the window.\n\n11. Review security awareness and role-based training completion and confirm that misses triggered documented follow-up.\n\n12. Test that authority in systems mirrors authority on paper by sampling cloud identity and access management bindings and the source-control platform access for one privileged role and one standard role.\n\n13. Record a design conclusion per criterion and log any mismatch as a candidate finding.\n\n14. Assessment scope for Conclude on Accountability & Control Environment: Assess CC1.5: individuals are held accountable for their internal control responsibilities. Then close the control-environment portion of the readiness assessment by consolidating the conclusions of the Assess Tone at the Top & Board Oversight and Evaluate Organizational Structure & Competence activities.\n\n15. Verify every in-scope control names an accountable owner and that ownership was reassigned promptly for any joiner, mover, or leaver event during the window.\n\n16. Inspect how missed control executions and policy violations were handled: escalation to the security and compliance lead and executive sponsor, sanctions applied under the Human Resources Security Policy, and corrective actions tracked to closure.\n\n17. Confirm performance expectations for roles holding privileged access or approval authority explicitly reference their control responsibilities.\n\n18. Consolidate the design conclusions for the full control-environment series into the readiness summary, classifying each criterion as designed or gap.\n\n19. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC2 Communication and Information Assessment_\n20. Assessment scope for Assess Quality of Control Information: Assess CC2.1: the entity obtains or generates and uses relevant, quality information to support the functioning of internal control. For the scoped service this means the information the control set runs on - control-run evidence in AssureSwarm, the cloud provider audit and application logs, the source-control platform pipeline results, and access exports - is relevant, complete, accurate, and timely enough to support control conclusions.\n\n21. Inventory the information each recurring control consumes and identify its source system, producer, and refresh cadence.\n\n22. For a sample of control runs in the assessment window, verify the evidence attached was system-generated where practical and current as of the run date.\n\n23. Trace two security metrics from the Information Security Objectives to their underlying data and confirm the figures are reproducible.\n\n24. Check that information the controls depend on is retained per requirements and remains retrievable for the audit period.\n\n25. Record a design conclusion for CC2.1 and log information-quality gaps as candidate findings.\n\n26. Assessment scope for Evaluate Internal & External Communication: Evaluate CC2.2 and CC2.3: the entity internally communicates information necessary for internal control to function, including objectives and responsibilities, and communicates with external parties on matters affecting internal control. In scope are onboarding and policy communication to the workforce, and the channels the organization maintains with customers, subservice organizations, and other external parties.\n\n27. Verify each policy names an owner and audience and that publication reached the affected workforce through the acknowledgment flow.\n\n28. Inspect how control responsibilities reach individuals: onboarding materials, role definitions, and recurring security awareness communications.\n\n29. Confirm externally facing channels exist for customers to report security, availability, and privacy concerns, and that inbound reports route to the incident process.\n\n30. Verify subservice advisories and status changes from the cloud provider, the workforce identity and collaboration platform, and the source-control platform are monitored and acted on.\n\n31. Record a design conclusion per criterion and log any communication gap as a candidate finding.\n\n_CC3 Risk Assessment_\n32. Assessment scope for Assess Objectives & Enterprise Risk Identification: Assess CC3.1 and CC3.2: the entity specifies objectives with sufficient clarity to enable identification and assessment of risks, and identifies and analyzes risks across the entity as a basis for determining how they are managed. For the scoped service the anchor artifacts are the Information Security Objectives and the periodic enterprise risk assessment feeding the risk register.\n\n33. Verify objectives are specific enough that a risk can be traced to the objective it threatens - sample three register entries and walk the trace.\n\n34. Confirm the enterprise risk assessment covered the platform, the subservice dependencies (the cloud provider, the workforce identity and collaboration platform, the source-control platform), and the workforce dimension.\n\n35. Check each identified risk carries an analysis: likelihood, impact, inherent and residual scores per the methodology, and a treatment decision.\n\n36. Verify risk owners exist for every open register entry and treatment actions carry target dates.\n\n37. Record a design conclusion per criterion and note gaps as candidate findings.\n\n38. Assessment scope for Evaluate Fraud Risk & Significant Change: Evaluate CC3.3 and CC3.4: the entity considers the potential for fraud in assessing risks, and identifies and assesses changes that could significantly impact the system of internal control. Assess management-override exposure and the available segregation of duties; change assessment must catch platform, subservice, and organizational shifts before they erode the control set.\n\n39. Verify the register carries explicit fraud scenarios - override of controls, unauthorized data access for gain, and misstatement - with analysis and treatments.\n\n40. Assess whether compensating measures for the small-team override risk are designed: independent review through the governance advisor, dual approvals, and immutable audit logging.\n\n41. Inspect how significant changes - new subservice providers, architecture shifts, tenancy model changes, key-person changes - enter risk assessment before adoption.\n\n42. Walk one significant change from the window through its documented risk assessment and approval.\n\n43. Record a design conclusion per criterion with gaps as candidate findings.\n\n44. Assessment scope for Conclude on Risk Assessment Design: Close the risk-assessment portion of the readiness assessment by consolidating the conclusions of the Assess Objectives & Enterprise Risk Identification and Evaluate Fraud Risk & Significant Change activities into a single series verdict against the governing risk policies.\n\n45. Confirm the Risk Management Policy and Risk Assessment Methodology are current, approved, and reflected in the practices the assessment observed.\n\n46. Reconcile every design conclusion recorded in this workflow against its criterion and confirm none is unsupported by attached evidence.\n\n47. Verify each open gap exists as an issue on the readiness audit with a named owner and a target date, and that no gap is silently absorbed into the verdict.\n\n48. Draft the risk-assessment section of the readiness summary, classifying each criterion as designed or gap.\n\n49. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC4 Monitoring Activities Assessment_\n50. Assessment scope for Assess Ongoing & Separate Evaluations: Assess CC4.1: the entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. For the scoped service the design rests on continuous control operation in AssureSwarm with recurring process runs, plus separate evaluations - the internal audit program, quarterly reviews with the governance advisor, and this readiness assessment itself.\n\n51. Verify recurring control runs have a defined cadence and an owner, and that completion is visible on the compliance dashboards.\n\n52. Confirm separate evaluations are scheduled with defined scope and independence - internal audit, the governance advisor's quarterly review, and external assessments.\n\n53. Inspect how monitoring results feed back: who reviews completion rates, missed runs, and stale evidence, and on what cadence.\n\n54. Walk one monitoring cycle end to end, from signal through review to a recorded action.\n\n55. Record a design conclusion for CC4.1 and note monitoring blind spots as candidate findings.\n\n56. Assessment scope for Evaluate Deficiency Communication & Remediation: Evaluate CC4.2: the entity evaluates and communicates internal control deficiencies in a timely manner to the parties responsible for corrective action, including senior management. For the scoped service deficiencies surface as issues in AssureSwarm; the design question is whether they reach the security and compliance lead and the executive sponsor fast enough and are tracked to closure rather than aging quietly.\n\n57. Verify each deficiency was recorded as an issue with severity, an accountable owner, and a remediation date at intake.\n\n58. Trace two deficiencies from detection through communication to the responsible owner and on to closure, confirming timelines match the severity.\n\n59. Confirm material deficiencies reached the executive sponsor and the governance advisor's quarterly review, with decisions minuted.\n\n60. Check that overdue remediation triggers escalation rather than silent date slippage.\n\n61. Record a design conclusion for CC4.2 and log any gap as a candidate finding.\n\n_CC5 Control Activities Assessment_\n62. Assessment scope for Assess Control Selection & Technology General Controls: Assess CC5.1 and CC5.2: the entity selects and develops control activities that mitigate risks to the achievement of objectives to acceptable levels, and selects and develops general control activities over technology. For the scoped service the design rests on a risk-based control baseline mapped to the register, with technology general controls spanning access, change, and operations across the cloud provider, the application hosting service, and the source-control platform.\n\n63. Sample three high residual risks and verify each maps to at least one designed control whose statement actually addresses the risk.\n\n64. Confirm the baseline covers the technology layers the platform depends on: the cloud provider infrastructure and IAM, the application hosting services, the managed database layer, and the source-control platform pipeline.\n\n65. Verify control activities mix types - preventive and detective, automated and manual - proportionate to the risk they mitigate.\n\n66. Check segregation of duties between performing a control and approving its result, with the small-team compensations documented.\n\n67. Record a design conclusion per criterion and log coverage gaps as candidate findings.\n\n68. Assessment scope for Evaluate Policy-to-Procedure Deployment: Evaluate CC5.3: the entity deploys control activities through policies that establish what is expected and procedures that put policies into action. The design question is whether the applicable governing policies anchored by the Information Security Policy translate into operable procedures - the recurring process runs and control activities in AssureSwarm - rather than sitting as shelfware.\n\n69. Verify every policy names an owner, carries an approval and a next review date, and completed its periodic review on schedule.\n\n70. Sample three policies and confirm each is deployed through at least one linked process or control that puts it into action.\n\n71. Confirm policy exceptions follow the documented path - time-boxed, risk-assessed, and approved by the authorized role.\n\n72. Check the accountability wiring: performers can reach the procedure that governs their control activity from the control record itself.\n\n73. Record a design conclusion for CC5.3 and note deployment gaps as candidate findings.\n\n_CC6 Logical and Physical Access Controls Assessment_\n74. Assessment scope for Assess Logical Access Architecture & Credential Lifecycle: Assess CC6.1, CC6.2, and CC6.3: logical access security software and architectures protect information assets; new users are registered and authorized before credentials issue and credentials are removed when access ends; and access is authorized, modified, or removed based on roles with least privilege and segregation of duties. Evaluate the documented customer-isolation architecture where the scoped service hosts multiple customers.\n\n75. Verify the inventory covers the systems holding customer and corporate data, so access architecture decisions rest on a complete asset picture.\n\n76. Confirm the documented customer-isolation model through scoped service identities and segregation of customer resources; verify that credentials cannot cross an unauthorized customer boundary.\n\n77. Trace each leaver in the window to credential removal across cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform within the required interval.\n\n78. Sample privileged and standard role grants and verify authorization preceded issuance and matches the role mapping.\n\n79. Record a design conclusion per criterion and log deviations as candidate findings.\n\n80. Assessment scope for Evaluate Physical Safeguards & Asset Disposal: Evaluate CC6.4 and CC6.5: physical access to facilities and protected information assets is restricted to authorized personnel, and physical protections are discontinued only after the ability to read or recover data has been diminished. Identify direct and inherited physical responsibilities from the documented operating model. Review provider attestations where relied upon, and assess controlled facilities, workforce endpoints, remote workspaces where applicable, and media disposal.\n\n81. Confirm the boundary: which physical responsibilities are inherited from the hosting provider and which remain with the organization, and that the inherited portion is covered by current attestations.\n\n82. Verify workforce physical practice is defined for remote work - screen locking, clear desk, secured devices - and communicated to everyone with production access.\n\n83. Check every retired device in the window has a sanitization or destruction record before leaving control.\n\n84. Verify media containing customer data never leaves the cloud boundary except through approved, encrypted paths.\n\n85. Record a design conclusion per criterion and log gaps as candidate findings.\n\n86. Assessment scope for Assess Boundary Defense, Transmission Protection & Malware Controls: Assess CC6.6, CC6.7, and CC6.8: logical access measures protect against threats from outside the system boundary; transmission, movement, and removal of information is restricted to authorized parties and protected in motion; and controls prevent or detect the introduction of unauthorized or malicious software. The perimeter under review is the application hosting service boundary of each scoped customer environment plus the workforce endpoint fleet.\n\n87. Verify each customer environment exposes only intended ingress: authenticated application hosting service endpoints behind TLS, no stray listeners or publicly readable storage.\n\n88. Confirm encryption in transit end to end and at rest on managed storage, with key management responsibilities documented.\n\n89. Check information movement paths - exports, support access, engineering diagnostics - are restricted to authorized users and logged.\n\n90. Verify endpoint protection and software allow-listing are deployed on workforce devices, with unauthorized-software detection feeding alerts.\n\n91. Record a design conclusion per criterion and log exposures as candidate findings.\n\n92. Assessment scope for Conclude on Access Control Design: Close the logical and physical access portion of the readiness assessment by consolidating the conclusions of the Assess Logical Access Architecture & Credential Lifecycle, Evaluate Physical Safeguards & Asset Disposal, and Assess Boundary Defense, Transmission Protection & Malware Controls activities into a single series verdict against the governing access policies.\n\n93. Confirm the three governing policies are current, approved, and consistent with the access practices the assessment observed.\n\n94. Reconcile the design conclusion for each of the eight criteria against its supporting evidence and flag any unsupported verdict.\n\n95. Verify every open access gap exists as an issue on the readiness audit with a named owner and a target date.\n\n96. Draft the access section of the readiness summary, classifying each criterion as designed or gap.\n\n97. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC7 System Operations Assessment_\n98. Assessment scope for Assess Vulnerability Detection & Anomaly Monitoring: Assess CC7.1 and CC7.2: detection and monitoring procedures identify configuration changes that introduce vulnerabilities and susceptibilities to newly discovered ones, and system components are monitored for anomalies indicative of malicious acts, natural disasters, or errors. The surface is the cloud provider estate and the application hosting services plus the source-control platform pipeline that changes them.\n\n99. Verify hardened baselines exist for the platform's building blocks and that deviations surface as findings rather than persisting silently.\n\n100. Confirm dependency and container scanning runs in the source-control platform pipeline with triage timelines tied to severity.\n\n101. Inspect alert coverage across the customer environments: authentication anomalies, availability signals, and error-rate spikes reach an accountable responder.\n\n102. Walk one vulnerability and one anomaly from detection to disposition.\n\n103. Record a design conclusion per criterion and log blind spots as candidate findings.\n\n104. Assessment scope for Evaluate Event Evaluation & Incident Response: Evaluate CC7.3 and CC7.4: the entity evaluates security events to determine whether they are security incidents, and responds to incidents through a defined program to understand, contain, remediate, and communicate. The design under review is the incident lifecycle from event triage through declared-incident execution, including customer notification duties and coordination with subservice providers.\n\n105. Verify declaration criteria distinguish events from incidents and that triage decisions in the window applied them consistently.\n\n106. Confirm the response program defines roles, containment playbooks, evidence preservation, and communication duties, including customer notification thresholds.\n\n107. Walk one event through triage and, if any incident was declared, through containment, remediation, and communication to closure; otherwise inspect the most recent response exercise.\n\n108. Check that post-incident review feeds corrective actions into the issue register.\n\n109. Record a design conclusion per criterion and log gaps as candidate findings.\n\n110. Assessment scope for Assess Incident Recovery Activities: Assess CC7.5: the entity identifies, develops, and implements activities to recover from identified security incidents. For the scoped service this means restoring affected customer services after a security incident - rebuilding from clean infrastructure definitions and restoring from protected backups - and folding lessons learned back into controls and playbooks.\n\n111. Verify documented recovery procedures exist for the plausible incident classes: compromised credentials, malicious change, data corruption, and service compromise.\n\n112. Confirm recovery is exercisable - a tenant environment can be redeployed from definitions and data restored from backups - with recent evidence of a test.\n\n113. Check recovery includes integrity verification before returning to service, so a compromise is not restored along with the data.\n\n114. Verify postmortems produced corrective actions with owners and dates, and that those actions closed.\n\n115. Record a design conclusion for CC7.5 and log gaps as candidate findings.\n\n_CC8 Change Management Assessment_\n116. Assessment scope for Assess Change Authorization, Testing & Deployment: Assess CC8.1: the entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures. Assess the approved production change path: independently reviewed change requests, automated test gates, protected branches, infrastructure definitions, and database migrations.\n\n117. Verify the pipeline enforces the lifecycle: no direct pushes to protected branches, independent review before merge, and green CI gates before deploy.\n\n118. Sample changes across the three classes - application code, infrastructure definitions, database migrations - and confirm each shows authorization, testing, approval, and deployment evidence.\n\n119. Check segregation between author and approver holds in practice, including the small-team case with documented compensations.\n\n120. Verify emergency changes follow the expedited path and receive retrospective review within the required interval.\n\n121. Record a design conclusion for CC8.1 and log deviations as candidate findings.\n\n122. Assessment scope for Conclude on Change Management Design: Close the change-management portion of the readiness assessment by consolidating the conclusion of the Assess Change Authorization, Testing & Deployment activity into a series verdict against the governing change policies.\n\n123. Confirm both governing policies are current, approved, and consistent with the observed pipeline practice, including the emergency path.\n\n124. Reconcile the CC8.1 design conclusion against its supporting evidence and flag anything unsupported.\n\n125. Verify every open change gap exists as an issue on the readiness audit with a named owner and a target date.\n\n126. Draft the change section of the readiness summary, classifying the criterion as designed or gap.\n\n127. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the assessment activity instead of closing it here.\n\n_CC9 Risk Mitigation Assessment_\n128. Assessment scope for Assess Business Disruption Risk Mitigation: Assess CC9.1: the entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions. For the scoped service, assess disruptions including hosting-region loss, key-person unavailability, subservice failure, and funding interruption; the design anchor is the business continuity and contingency planning framework.\n\n129. Verify the register carries the disruption scenarios that matter for the operating model and each carries a selected mitigation, not just an acceptance.\n\n130. Confirm the continuity plan assigns roles and activation criteria and covers the platform's dependency on the cloud provider regional services.\n\n131. Check key-person risk carries concrete mitigations: documented runbooks, credential escrow, and cross-training or advisory cover.\n\n132. Verify mitigation activities have owners and review dates, so they survive personnel and platform change.\n\n133. Record a design conclusion for CC9.1 and log gaps as candidate findings.\n\n134. Assessment scope for Evaluate Vendor & Business Partner Risk Management: Evaluate CC9.2: the entity assesses and manages risks associated with vendors and business partners. Use the approved vendor register to identify material cloud, identity, development-platform, and advisory dependencies; document the significance of each relationship.\n\n135. Verify every active vendor appears in the register with a criticality tier, an owner, and a next review date.\n\n136. Confirm due diligence preceded engagement for vendors touching customer data and was refreshed on schedule for the critical tier.\n\n137. Inspect the most recent attestation review for each subservice organization, including exceptions noted and complementary controls adopted in response.\n\n138. Check exit thinking exists for the concentrated dependencies: what happens if a critical vendor degrades, and who decides.\n\n139. Record a design conclusion for CC9.2 and log gaps as candidate findings.\n\n140. Keep a separate conclusion for each criterion, with the assessor identity, evidence references, applicable controls, design or implementation gaps and rationale. Preserve adverse and conflicting evidence. The executive sponsor and security and compliance lead each review this exact package version and acknowledge findings, action ownership and commitments through separate native approvals; an unresolved objection prevents completion and requires correction. Their approval does not replace the independent readiness review at soc2-readiness-closure.\n\n**Record in AssureSwarm**\nUse the markdown step result for the signed assessor conclusions, criterion-to-evidence references and limitations; use attached step documents for the workpapers listed below. After checking the tenant schema, create or update each gap as an Issue (issue_type: finding, source: internal_audit, severity, issue_owner) and link it to the existing Audit and affected Control records. Record each corrective action on a linked Remediation item using plan, action_owner and target_date. If those fields or the Remediation type are unavailable, retain the action plan, owner and target date in the step workpaper and disclose the missing destination; do not invent Issue fields. Describe criterion identifiers in the workpaper and Issue; no Criterion item is required. Bind both native management approvals to the same reviewed package version. Substantive changes require renewed approvals before downstream reliance.\n\n_CC1 Control Environment Assessment_\nAttach the governance minutes, the advisor attestations, and the acknowledgment export to this step. Raise each design gap as an issue linked to the readiness audit, referencing the affected control by title, and note the design conclusion in the step record.\n\nAttach the role definitions, sampled screening and training evidence, and the permission exports to this step. Link each gap to the affected control, raise it as an issue on the readiness audit, and capture the rationale for each conclusion in the step record.\n\nRecord the consolidated conclusion on this step and attach the control-environment section of the readiness summary. Confirm every gap exists as an issue linked to the readiness audit with a named owner and a target date before requesting approval.\n\n_CC2 Communication and Information Assessment_\nAttach the information inventory, sampled control-run evidence, and metric traces to this step. Raise each information-quality gap as an issue linked to the readiness audit, referencing the affected control by title.\n\nAttach acknowledgment exports, sample communications, and the external-channel inventory to this step. Raise gaps as issues linked to the readiness audit and record the conclusion for each criterion in the step record.\n\n_CC3 Risk Assessment_\nAttach the risk register export and the assessment sign-off to this step. Raise each gap as an issue linked to the readiness audit and record the design conclusions in the step record.\n\nAttach the fraud-risk extract, override compensations, and the sampled change assessment to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the risk-assessment section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC4 Monitoring Activities Assessment_\nAttach the cadence inventory, completion metrics, and review minutes to this step. Raise blind spots as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the issue register export and the traced deficiency records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC5 Control Activities Assessment_\nAttach the risk-to-control mapping sample and the domain coverage summary to this step. Raise coverage gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the policy register export and the sampled policy-to-procedure traces to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC6 Logical and Physical Access Controls Assessment_\nAttach the inventory extract, lifecycle samples, and permission exports to this step. Raise deviations as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the carve-out summary, endpoint inventory, and disposal records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the architecture summary, encryption standard, and endpoint configuration evidence to this step. Raise exposures as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the access section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC7 System Operations Assessment_\nAttach scan samples, baseline evidence, and alert-routing configuration to this step. Raise blind spots as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach triage samples, the response plan, and walkthrough records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach recovery procedures, exercise evidence, and postmortem records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC8 Change Management Assessment_\nAttach the pipeline configuration export and the sampled change records to this step. Raise deviations as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the change section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC9 Risk Mitigation Assessment_\nAttach the disruption-scenario extract and continuity plan to this step. Raise gaps as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the vendor register export and attestation review notes to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n**Exit criteria**\n_CC1 Control Environment Assessment_\nCC1.1 and CC1.2 each carry a documented design conclusion supported by attached evidence, and every candidate finding has a named owner and a target date. CC1.3 and CC1.4 each carry a supported design conclusion across structures, reporting lines, and competence practices, and any divergence between documented authority and system permissions is logged as an issue with an owner and a target date. All five control-environment criteria (CC1.1–CC1.5) carry a supported design conclusion, both approvers have signed off on this step, and no control-environment gap remains without an owner, a target date, and a linked issue.\n\n_CC2 Communication and Information Assessment_\nCC2.1 carries a documented design conclusion supported by attached evidence, and every information-quality gap has a named owner and a target date. CC2.2 and CC2.3 each carry a documented design conclusion, every communication gap is logged with a named owner and a target date, and the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC3 Risk Assessment_\nCC3.1 and CC3.2 each carry a documented design conclusion supported by attached evidence, and identified gaps have named owners and target dates. CC3.3 and CC3.4 each carry a documented design conclusion, and every gap is logged with a named owner and a target date. All four criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no risk-assessment gap remains without an owner, a target date, and a linked issue.\n\n_CC4 Monitoring Activities Assessment_\nCC4.1 carries a documented design conclusion supported by attached evidence, and every monitoring blind spot has a named owner and a target date. CC4.2 carries a documented design conclusion, both traced deficiencies show timely communication and closure, and remaining gaps carry named owners and target dates.\n\n_CC5 Control Activities Assessment_\nCC5.1 and CC5.2 each carry a documented design conclusion, and every coverage gap is logged with a named owner and a target date. CC5.3 carries a documented design conclusion, sampled policies trace to operating procedures, and every deployment gap has a named owner and a target date.\n\n_CC6 Logical and Physical Access Controls Assessment_\nCC6.1, CC6.2, and CC6.3 each carry a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC6.4 and CC6.5 each carry a documented design conclusion, the inherited-versus-retained boundary is explicit, and every gap has a named owner and a target date. CC6.6, CC6.7, and CC6.8 each carry a documented design conclusion supported by attached evidence, and every exposure has a named owner and a target date. All eight criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no access gap remains without an owner, a target date, and a linked issue.\n\n_CC7 System Operations Assessment_\nCC7.1 and CC7.2 each carry a documented design conclusion supported by attached evidence, and every blind spot has a named owner and a target date. CC7.3 and CC7.4 each carry a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC7.5 carries a documented design conclusion supported by attached evidence, and every recovery gap has a named owner and a target date.\n\n_CC8 Change Management Assessment_\nCC8.1 carries a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC8.1 carries a supported design conclusion, both approvers have signed off on this step, and no change gap remains without an owner, a target date, and a linked issue.\n\n_CC9 Risk Mitigation Assessment_\nCC9.1 carries a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC9.2 carries a documented design conclusion supported by attached evidence, and every vendor gap has a named owner and a target date.\n\nThe executive sponsor and security and compliance lead are two distinct assigned approvers. Both have approved this version, every criterion has a signed assessor conclusion and evidence or a visible gap, and all gaps have owners and dates. The independent readiness conclusion remains pending until soc2-readiness-closure.","type":"TASK","requiredApprovals":2,"linkedItems":[{"itemTitle":"Incident Response Investigation","itemType":"audit","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1},{"email":"ann.veal@bluth.example","reviewLevel":2}]},{"stepNumber":3,"name":"Approve SOC 2 readiness record","description":null,"summary":null,"instructions":"**Objective**\nApprove SOC 2 readiness record. The independent readiness reviewer challenges evidence sufficiency and approves the examination-planning disposition.\n\n**Inputs**\nConsume the reviewed assessment package from soc2-common-criteria-assessment, with its two management approvals, signed assessor conclusions, criterion evidence and owned gap register. Also consume the reviewed companion assessment for each selected optional category; exclusions must trace to the approved scope.\n1. Review mapped controls, walkthroughs, sample evidence across the intended period, system-description draft, incidents, exceptions, vendor reports, gap inventory, remediation plans, and readiness milestones.\n2. Review all stage evidence, final mapping, system-description version, gap and remediation tracker, readiness result, subservice and user responsibilities, changes, limitations, and stakeholder comments.\n\n**Procedure**\n1. Inspect evidence quality and continuity, identify missing operating history, validate design and implementation observations, assess gap impact by criterion, sequence remediation and evidence generation, and avoid presenting readiness work as examination testing.\n2. Trace the disposition to criterion-level evidence, verify gaps and dependencies remain visible, reconcile document versions and scope, challenge unsupported timing, and return inconsistencies or hidden limitations for correction.\n3. Independently challenge all 33 common-criteria conclusions (CC1.1–CC1.5, CC2.1–CC2.3, CC3.1–CC3.4, CC4.1–CC4.2, CC5.1–CC5.3, CC6.1–CC6.8, CC7.1–CC7.5, CC8.1, CC9.1–CC9.2). For each, record the independent reviewer conclusion, evidence sufficiency, control mapping and remaining gap; reconcile the four optional categories to the approved engagement scope and applicable reviewed companion outputs.\n4. Verify both named management roles approved the exact package versions and that the reviewer is independent of preparation and operation of the assessed controls. Return unsupported or disputed conclusions to the owning assessment package; substantive corrections require its renewed dual approvals and this independent review. Management acceptance cannot cure insufficient evidence or override the independent conclusion.\n5. Hand the approved disposition, conditions and action tracker to management for remediation and examination planning. Keep SOC 2 Type II interim testing, PBC evidence preparation and management assertion with their separate owners and workflows. The service auditor retains responsibility for any SOC opinion.\n\n**Record in AssureSwarm**\n1. Step result: Document the readiness result by criterion, evidence reviewed, design or implementation gaps, operating-history needs, remediation owner and due date, dependencies, conditions, and proposed examination timing.\n2. Step document: Attach the SOC 2 readiness summary and final evidence index; capture the authorized reviewer, final boundary and mapping references, readiness result, conditions, gaps, remediation owners and dates, system-description status, intended next step, limitations, and reassessment triggers. The native approval records the independent reviewer’s decision against this version.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the evidence-based readiness disposition, conditions and gaps are fully owned, and no claim of SOC 2 certification or auditor opinion is made. The authorized reviewer accepts a management readiness record for planning purposes; closure is not certification and does not predict or replace a service auditor’s opinion.\nEvery common criterion and selected optional category has an independent conclusion with evidence or an explicit limitation. The independent readiness reviewer has recorded native approval; the two management approvals remain separate and traceable.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Incident Response Investigation","itemType":"audit","kind":"related"},{"itemTitle":"Security Incident Triage","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","name":"SOC 2 Trust Services Readiness — SOC 2 Security and Availability Readiness — prior cycle","templateName":"SOC 2 Trust Services Readiness","templateSourceId":"coworkcanvas:template:soc2-readiness","description":"SOC 2 Trust Services Readiness for SOC 2 Security and Availability Readiness (prior cycle).","status":"COMPLETED","displayOrder":353,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Map criteria, risks, and controls","description":null,"summary":null,"instructions":"**Objective**\nMap criteria, risks, and controls. The engagement lead applies expertise to system boundaries, category applicability and complementary responsibilities.\n\n**Inputs**\n1. Review contracts and commitments, architecture and data flows, inventories, policies, risk assessments, vendor relationships, prior reports, incidents, change plans, and selected Trust Services Criteria.\n2. Use the approved boundary, criteria, risk register, control inventory, policies and procedures, architecture, vendor controls, customer responsibilities, prior findings, and available evidence.\n\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\nBefore execution, resolve the declared roles to named tenant users and verify native assignments and counts on every instantiated step. Assign two distinct people, the executive sponsor and security and compliance lead, to the assessment package. Assign a separate independent readiness reviewer who did not prepare or operate the assessed controls. Library role declarations do not assign users or enforce role membership; changing approvers may replace the required count, so recheck the two-person assignments after any change.\n\n**Procedure**\n1. Interview accountable owners, reconcile the system description to deployed services, identify carve-out or inclusive subservice treatment, define customers and commitments, select categories, and document boundary exclusions and dependencies.\n2. Assess criterion applicability, identify control coverage and gaps, test mapping specificity, document complementary user and subservice controls, trace system-description assertions to support, and challenge duplicate controls that do not address the criterion.\n3. Security common criteria CC1–CC9 remain in scope. For Availability, Confidentiality, Processing Integrity and Privacy, record category selection from service commitments and engagement scope, with the reason for each exclusion. Identify the reviewed companion assessment and its period, boundary, evidence, findings and approval version for each selected category. A missing or incompatible output is an explicit readiness gap, never an assumed pass.\n4. Prepare one evidence index across criteria: identify each artifact once with source, version, period, control references and the criteria it supports.\n\n**Record in AssureSwarm**\n1. Step result: Capture the review period, intended report type and period, services, trust categories, system components, locations, subservice organizations, commitments, boundaries, exclusions, changes, and limitations. Use the Audit.scope and Audit.period_start / Audit.period_end fields only after checking the tenant schema.\n2. Step document: Attach the criterion-to-control mapping and evidence index; document applicability rationale, risks, controls, evidence sources, owners, frequencies, subservice and user controls, system-description references, gaps, and conflicting evidence. Record the document reference in the step result.\n\n**Exit criteria**\nEngagement lead provides expertise: The readiness boundary and selected criteria are unambiguous, subservice treatment is explicit, and material components or commitments are not omitted without documented rationale. Every selected criterion has supported coverage or a visible gap, mappings are specific enough for evidence assessment, and owners agree on responsibility boundaries.\nThe engagement lead checks that the assessment package uses the same reviewed boundary and evidence index; optional categories remain scoped companion assessments, with no executor questionnaire.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"},{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Review common criteria design","description":null,"summary":null,"instructions":"**Objective**\nAssess CC1–CC9 design and obtain the two management contributions to the criterion-level evidence and action package. The executive sponsor approves governance and technical commitments and action ownership; the security and compliance lead applies expertise to the control design and approves the criterion findings and owned actions.\n\n**Inputs**\nConsume the reviewed system boundary, criteria-to-control mapping and resource-reference index from soc2-criteria-mapping. Use its named systems of record, current policy versions, review period and control references to resolve the evidence below. Record unavailable resources as gaps.\n\n_CC1 Control Environment Assessment_\n- Board & Governance Policy and Information Security Policy (current approved versions with effective dates)\n- Acceptable Use Policy acknowledgment records for employees and contractors\n- Minutes and decisions from the two most recent quarterly governance reviews\n- Signed quarterly attestations from the independent governance advisor, as executed to date under the prospective engagement\n- The linked consolidated controls for tone at the top and board-level oversight\n\nRole definitions for the executive sponsor, technology owner, and security and compliance lead, plus any outsourced security leadership or advisory scope\n- Information Security Policy sections assigning security roles, responsibilities, and authorities\n- Human Resources Security Policy with screening, onboarding agreement, and training records for the assessment window\n- Access documentation mapping role authority to cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform permissions\n\nBoard & Governance Policy and Human Resources Security Policy (accountability, performance, and sanctions provisions)\n- Control-owner assignments on the linked consolidated controls\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- Quarterly oversight reporting covering control metrics, overdue actions, and escalations\n\n_CC2 Communication and Information Assessment_\n- Information Security Objectives with the security metrics catalog and owners\n- The linked consolidated control for quality records and control information\n- A sample of recent control-run records with attached evidence across the operating processes\n- System-generated exports used by recurring controls: cloud identity and access management bindings, the workforce identity and collaboration platform membership, the continuous integration service results\n\nPolicy publication and acknowledgment records across the applicable governing policies\n- Security awareness communications and onboarding materials for the window\n- Customer-facing commitments: terms, support channels, and incident notification obligations\n- Subservice communication evidence: the cloud provider, the workforce identity and collaboration platform, and the source-control platform advisories and status feeds\n\n_CC3 Risk Assessment_\n- Information Security Objectives and business-context documentation\n- Risk Assessment Methodology and the current risk register with scores and owners\n- The most recent enterprise risk assessment run and its sign-off record\n- The linked consolidated controls for objective-setting and periodic risk assessment\n\nFraud-risk entries in the risk register, including management override and misappropriation scenarios\n- The linked consolidated controls for fraud risk and change-impact assessment\n- Segregation-of-duties documentation across cloud identity and access management, the source-control platform, and the billing surface\n- Change-assessment records for significant platform or organizational changes in the window\n\nRisk Management Policy and Risk Assessment Methodology (current approved versions with effective dates)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the risk-assessment series\n\n_CC4 Monitoring Activities Assessment_\n- The linked consolidated control for monitoring risk and control performance\n- Control-run completion data across the operating processes for the window\n- Internal audit program schedule and any completed engagement records\n- Quarterly governance review minutes covering control metrics\n\nThe linked consolidated control for deficiency tracking and remediation\n- The issue register for the window: source, severity, owner, age, and status\n- Escalation records for material deficiencies, including governance review minutes\n- Remediation action plans with due dates and closure evidence\n\n_CC5 Control Activities Assessment_\n- The linked consolidated control for the risk-based control baseline\n- The risk register with treatment mappings from risk to mitigating controls\n- The consolidated control set with its domain coverage (access, change, operations)\n- Segregation-of-duties expectations for control performers and approvers\n\nInformation Security Policy and the policy register with owners, versions, and review dates\n- The linked consolidated control for maintaining approved policies and procedures\n- Process records showing which procedures operationalize which policies\n- Acknowledgment and exception records for the window\n\n_CC6 Logical and Physical Access Controls Assessment_\n- The asset and system inventory identifying protected information assets\n- The linked consolidated controls for account lifecycle, least privilege, and asset inventory\n- Joiner, mover, and leaver records for the window with matching cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform changes\n- Role-to-permission mappings including privileged roles\n\nThe linked consolidated controls for physical access and media handling\n- The carve-out position for the cloud provider data-center physical security with current attestation coverage\n- Endpoint and media inventory: laptops and any removable media in circulation\n- Disposal and sanitization records for devices retired during the window\n\nThe linked consolidated controls for network boundary, encryption, and software restriction\n- Network and service architecture for the customer environments: ingress paths, TLS termination, service-to-service authentication\n- Encryption standards for data at rest and in transit, with key management ownership\n- Endpoint protection and allowed-software configuration for workforce devices\n\nAccess Control Policy, Password & Authentication Policy, and Physical Security Policy (current approved versions)\n- Design conclusions and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the access series\n\n_CC7 System Operations Assessment_\n- The linked consolidated controls for configuration baselines and continuous monitoring\n- Vulnerability management records: scans, dependency checks in the continuous integration service, and triage decisions\n- Configuration baselines for the customer environments and drift-detection evidence\n- Monitoring and alerting configuration with escalation routing\n\nThe linked consolidated controls for event evaluation and incident response\n- Incident response plan with declaration criteria, severity levels, and role assignments\n- Event triage records and any declared-incident records for the window\n- Notification obligations toward customers and dependencies on subservice providers\n\nThe linked consolidated control for incident recovery\n- Recovery procedures: infrastructure redeployment, backup restore, and credential rotation paths\n- Postmortem records or recovery exercise results for the window\n- Dependencies on subservice recovery commitments from the cloud provider\n\n_CC8 Change Management Assessment_\n- The linked consolidated control for change authorization and approval\n- the source-control platform configuration: protected branches, merge request approval rules, CI gate definitions\n- A sample of production changes from the window: application code, infrastructure, and database migrations\n- Emergency change records with retrospective approvals\n\nChange Management Policy and Software Development Lifecycle Policy (current approved versions with effective dates)\n- The design conclusion and open issues recorded in the preceding procedure items, with owners and target dates\n- The readiness summary template for the change series\n\n_CC9 Risk Mitigation Assessment_\n- The linked consolidated control for business continuity and contingency planning policy\n- Disruption scenarios in the risk register with their selected mitigations\n- Continuity plan with roles, activation criteria, and recovery priorities\n- Key-person and succession arrangements for critical roles\n\nThe linked consolidated control for vendor due diligence\n- Vendor register with criticality tiers, owners, and review dates\n- Attestation evidence on file: SOC 2 or equivalent reports for the subservice organizations\n- Contracts and data processing terms for vendors touching customer data\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb the detailed assessment activities below; the assigned assessor evaluates the evidence and drafts each criterion conclusion for management review. Original criterion procedures retain their evidence and conclusion requirements within this package.*\n\n_CC1 Control Environment Assessment_\n1. Assessment scope for Assess Tone at the Top & Board Oversight: Assess CC1.1 and CC1.2: the entity demonstrates a commitment to integrity and ethical values, and the board function demonstrates independence from management and exercises oversight of the development and performance of internal control. Assess the ethical culture and governance oversight anchoring the scoped control environment.\n\n2. Read the Board & Governance Policy and confirm it defines standards of conduct, conflict-of-interest handling, and escalation paths that bind the executive sponsor as well as staff.\n\n3. Trace the two most recent quarterly governance reviews end to end: agenda, minutes, decisions, and follow-up actions recorded against the owning process in AssureSwarm.\n\n4. Verify the independent governance advisor's engagement establishes independence from day-to-day management, a defined oversight cadence, and a direct escalation path.\n\n5. Sample Acceptable Use Policy acknowledgments across the workforce and confirm any deviation was handled under the Human Resources Security Policy's sanctions provisions.\n\n6. Compare observed practice against each linked control's statement and record a design conclusion per criterion, noting gaps as candidate findings.\n\n7. Assessment scope for Evaluate Organizational Structure & Competence: Evaluate CC1.3 and CC1.4: management establishes structures, reporting lines, and authorities appropriate for the organization and its documented service architecture, and the organization attracts, develops, and retains competent people in alignment with its objectives.\n\n8. Confirm documented reporting lines match practice: who authorizes risk acceptances, production releases, and vendor commitments, and where each decision escalates.\n\n9. Verify segregation between engineering execution and independent review - including the firm-internal segregation attested through the advisory engagement - is reflected in the role definitions.\n\n10. Inspect screening evidence and signed confidentiality and acceptable-use agreements for personnel onboarded during the window.\n\n11. Review security awareness and role-based training completion and confirm that misses triggered documented follow-up.\n\n12. Test that authority in systems mirrors authority on paper by sampling cloud identity and access management bindings and the source-control platform access for one privileged role and one standard role.\n\n13. Record a design conclusion per criterion and log any mismatch as a candidate finding.\n\n14. Assessment scope for Conclude on Accountability & Control Environment: Assess CC1.5: individuals are held accountable for their internal control responsibilities. Then close the control-environment portion of the readiness assessment by consolidating the conclusions of the Assess Tone at the Top & Board Oversight and Evaluate Organizational Structure & Competence activities.\n\n15. Verify every in-scope control names an accountable owner and that ownership was reassigned promptly for any joiner, mover, or leaver event during the window.\n\n16. Inspect how missed control executions and policy violations were handled: escalation to the security and compliance lead and executive sponsor, sanctions applied under the Human Resources Security Policy, and corrective actions tracked to closure.\n\n17. Confirm performance expectations for roles holding privileged access or approval authority explicitly reference their control responsibilities.\n\n18. Consolidate the design conclusions for the full control-environment series into the readiness summary, classifying each criterion as designed or gap.\n\n19. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC2 Communication and Information Assessment_\n20. Assessment scope for Assess Quality of Control Information: Assess CC2.1: the entity obtains or generates and uses relevant, quality information to support the functioning of internal control. For the scoped service this means the information the control set runs on - control-run evidence in AssureSwarm, the cloud provider audit and application logs, the source-control platform pipeline results, and access exports - is relevant, complete, accurate, and timely enough to support control conclusions.\n\n21. Inventory the information each recurring control consumes and identify its source system, producer, and refresh cadence.\n\n22. For a sample of control runs in the assessment window, verify the evidence attached was system-generated where practical and current as of the run date.\n\n23. Trace two security metrics from the Information Security Objectives to their underlying data and confirm the figures are reproducible.\n\n24. Check that information the controls depend on is retained per requirements and remains retrievable for the audit period.\n\n25. Record a design conclusion for CC2.1 and log information-quality gaps as candidate findings.\n\n26. Assessment scope for Evaluate Internal & External Communication: Evaluate CC2.2 and CC2.3: the entity internally communicates information necessary for internal control to function, including objectives and responsibilities, and communicates with external parties on matters affecting internal control. In scope are onboarding and policy communication to the workforce, and the channels the organization maintains with customers, subservice organizations, and other external parties.\n\n27. Verify each policy names an owner and audience and that publication reached the affected workforce through the acknowledgment flow.\n\n28. Inspect how control responsibilities reach individuals: onboarding materials, role definitions, and recurring security awareness communications.\n\n29. Confirm externally facing channels exist for customers to report security, availability, and privacy concerns, and that inbound reports route to the incident process.\n\n30. Verify subservice advisories and status changes from the cloud provider, the workforce identity and collaboration platform, and the source-control platform are monitored and acted on.\n\n31. Record a design conclusion per criterion and log any communication gap as a candidate finding.\n\n_CC3 Risk Assessment_\n32. Assessment scope for Assess Objectives & Enterprise Risk Identification: Assess CC3.1 and CC3.2: the entity specifies objectives with sufficient clarity to enable identification and assessment of risks, and identifies and analyzes risks across the entity as a basis for determining how they are managed. For the scoped service the anchor artifacts are the Information Security Objectives and the periodic enterprise risk assessment feeding the risk register.\n\n33. Verify objectives are specific enough that a risk can be traced to the objective it threatens - sample three register entries and walk the trace.\n\n34. Confirm the enterprise risk assessment covered the platform, the subservice dependencies (the cloud provider, the workforce identity and collaboration platform, the source-control platform), and the workforce dimension.\n\n35. Check each identified risk carries an analysis: likelihood, impact, inherent and residual scores per the methodology, and a treatment decision.\n\n36. Verify risk owners exist for every open register entry and treatment actions carry target dates.\n\n37. Record a design conclusion per criterion and note gaps as candidate findings.\n\n38. Assessment scope for Evaluate Fraud Risk & Significant Change: Evaluate CC3.3 and CC3.4: the entity considers the potential for fraud in assessing risks, and identifies and assesses changes that could significantly impact the system of internal control. Assess management-override exposure and the available segregation of duties; change assessment must catch platform, subservice, and organizational shifts before they erode the control set.\n\n39. Verify the register carries explicit fraud scenarios - override of controls, unauthorized data access for gain, and misstatement - with analysis and treatments.\n\n40. Assess whether compensating measures for the small-team override risk are designed: independent review through the governance advisor, dual approvals, and immutable audit logging.\n\n41. Inspect how significant changes - new subservice providers, architecture shifts, tenancy model changes, key-person changes - enter risk assessment before adoption.\n\n42. Walk one significant change from the window through its documented risk assessment and approval.\n\n43. Record a design conclusion per criterion with gaps as candidate findings.\n\n44. Assessment scope for Conclude on Risk Assessment Design: Close the risk-assessment portion of the readiness assessment by consolidating the conclusions of the Assess Objectives & Enterprise Risk Identification and Evaluate Fraud Risk & Significant Change activities into a single series verdict against the governing risk policies.\n\n45. Confirm the Risk Management Policy and Risk Assessment Methodology are current, approved, and reflected in the practices the assessment observed.\n\n46. Reconcile every design conclusion recorded in this workflow against its criterion and confirm none is unsupported by attached evidence.\n\n47. Verify each open gap exists as an issue on the readiness audit with a named owner and a target date, and that no gap is silently absorbed into the verdict.\n\n48. Draft the risk-assessment section of the readiness summary, classifying each criterion as designed or gap.\n\n49. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC4 Monitoring Activities Assessment_\n50. Assessment scope for Assess Ongoing & Separate Evaluations: Assess CC4.1: the entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. For the scoped service the design rests on continuous control operation in AssureSwarm with recurring process runs, plus separate evaluations - the internal audit program, quarterly reviews with the governance advisor, and this readiness assessment itself.\n\n51. Verify recurring control runs have a defined cadence and an owner, and that completion is visible on the compliance dashboards.\n\n52. Confirm separate evaluations are scheduled with defined scope and independence - internal audit, the governance advisor's quarterly review, and external assessments.\n\n53. Inspect how monitoring results feed back: who reviews completion rates, missed runs, and stale evidence, and on what cadence.\n\n54. Walk one monitoring cycle end to end, from signal through review to a recorded action.\n\n55. Record a design conclusion for CC4.1 and note monitoring blind spots as candidate findings.\n\n56. Assessment scope for Evaluate Deficiency Communication & Remediation: Evaluate CC4.2: the entity evaluates and communicates internal control deficiencies in a timely manner to the parties responsible for corrective action, including senior management. For the scoped service deficiencies surface as issues in AssureSwarm; the design question is whether they reach the security and compliance lead and the executive sponsor fast enough and are tracked to closure rather than aging quietly.\n\n57. Verify each deficiency was recorded as an issue with severity, an accountable owner, and a remediation date at intake.\n\n58. Trace two deficiencies from detection through communication to the responsible owner and on to closure, confirming timelines match the severity.\n\n59. Confirm material deficiencies reached the executive sponsor and the governance advisor's quarterly review, with decisions minuted.\n\n60. Check that overdue remediation triggers escalation rather than silent date slippage.\n\n61. Record a design conclusion for CC4.2 and log any gap as a candidate finding.\n\n_CC5 Control Activities Assessment_\n62. Assessment scope for Assess Control Selection & Technology General Controls: Assess CC5.1 and CC5.2: the entity selects and develops control activities that mitigate risks to the achievement of objectives to acceptable levels, and selects and develops general control activities over technology. For the scoped service the design rests on a risk-based control baseline mapped to the register, with technology general controls spanning access, change, and operations across the cloud provider, the application hosting service, and the source-control platform.\n\n63. Sample three high residual risks and verify each maps to at least one designed control whose statement actually addresses the risk.\n\n64. Confirm the baseline covers the technology layers the platform depends on: the cloud provider infrastructure and IAM, the application hosting services, the managed database layer, and the source-control platform pipeline.\n\n65. Verify control activities mix types - preventive and detective, automated and manual - proportionate to the risk they mitigate.\n\n66. Check segregation of duties between performing a control and approving its result, with the small-team compensations documented.\n\n67. Record a design conclusion per criterion and log coverage gaps as candidate findings.\n\n68. Assessment scope for Evaluate Policy-to-Procedure Deployment: Evaluate CC5.3: the entity deploys control activities through policies that establish what is expected and procedures that put policies into action. The design question is whether the applicable governing policies anchored by the Information Security Policy translate into operable procedures - the recurring process runs and control activities in AssureSwarm - rather than sitting as shelfware.\n\n69. Verify every policy names an owner, carries an approval and a next review date, and completed its periodic review on schedule.\n\n70. Sample three policies and confirm each is deployed through at least one linked process or control that puts it into action.\n\n71. Confirm policy exceptions follow the documented path - time-boxed, risk-assessed, and approved by the authorized role.\n\n72. Check the accountability wiring: performers can reach the procedure that governs their control activity from the control record itself.\n\n73. Record a design conclusion for CC5.3 and note deployment gaps as candidate findings.\n\n_CC6 Logical and Physical Access Controls Assessment_\n74. Assessment scope for Assess Logical Access Architecture & Credential Lifecycle: Assess CC6.1, CC6.2, and CC6.3: logical access security software and architectures protect information assets; new users are registered and authorized before credentials issue and credentials are removed when access ends; and access is authorized, modified, or removed based on roles with least privilege and segregation of duties. Evaluate the documented customer-isolation architecture where the scoped service hosts multiple customers.\n\n75. Verify the inventory covers the systems holding customer and corporate data, so access architecture decisions rest on a complete asset picture.\n\n76. Confirm the documented customer-isolation model through scoped service identities and segregation of customer resources; verify that credentials cannot cross an unauthorized customer boundary.\n\n77. Trace each leaver in the window to credential removal across cloud identity and access management, the workforce identity and collaboration platform, and the source-control platform within the required interval.\n\n78. Sample privileged and standard role grants and verify authorization preceded issuance and matches the role mapping.\n\n79. Record a design conclusion per criterion and log deviations as candidate findings.\n\n80. Assessment scope for Evaluate Physical Safeguards & Asset Disposal: Evaluate CC6.4 and CC6.5: physical access to facilities and protected information assets is restricted to authorized personnel, and physical protections are discontinued only after the ability to read or recover data has been diminished. Identify direct and inherited physical responsibilities from the documented operating model. Review provider attestations where relied upon, and assess controlled facilities, workforce endpoints, remote workspaces where applicable, and media disposal.\n\n81. Confirm the boundary: which physical responsibilities are inherited from the hosting provider and which remain with the organization, and that the inherited portion is covered by current attestations.\n\n82. Verify workforce physical practice is defined for remote work - screen locking, clear desk, secured devices - and communicated to everyone with production access.\n\n83. Check every retired device in the window has a sanitization or destruction record before leaving control.\n\n84. Verify media containing customer data never leaves the cloud boundary except through approved, encrypted paths.\n\n85. Record a design conclusion per criterion and log gaps as candidate findings.\n\n86. Assessment scope for Assess Boundary Defense, Transmission Protection & Malware Controls: Assess CC6.6, CC6.7, and CC6.8: logical access measures protect against threats from outside the system boundary; transmission, movement, and removal of information is restricted to authorized parties and protected in motion; and controls prevent or detect the introduction of unauthorized or malicious software. The perimeter under review is the application hosting service boundary of each scoped customer environment plus the workforce endpoint fleet.\n\n87. Verify each customer environment exposes only intended ingress: authenticated application hosting service endpoints behind TLS, no stray listeners or publicly readable storage.\n\n88. Confirm encryption in transit end to end and at rest on managed storage, with key management responsibilities documented.\n\n89. Check information movement paths - exports, support access, engineering diagnostics - are restricted to authorized users and logged.\n\n90. Verify endpoint protection and software allow-listing are deployed on workforce devices, with unauthorized-software detection feeding alerts.\n\n91. Record a design conclusion per criterion and log exposures as candidate findings.\n\n92. Assessment scope for Conclude on Access Control Design: Close the logical and physical access portion of the readiness assessment by consolidating the conclusions of the Assess Logical Access Architecture & Credential Lifecycle, Evaluate Physical Safeguards & Asset Disposal, and Assess Boundary Defense, Transmission Protection & Malware Controls activities into a single series verdict against the governing access policies.\n\n93. Confirm the three governing policies are current, approved, and consistent with the access practices the assessment observed.\n\n94. Reconcile the design conclusion for each of the eight criteria against its supporting evidence and flag any unsupported verdict.\n\n95. Verify every open access gap exists as an issue on the readiness audit with a named owner and a target date.\n\n96. Draft the access section of the readiness summary, classifying each criterion as designed or gap.\n\n97. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n_CC7 System Operations Assessment_\n98. Assessment scope for Assess Vulnerability Detection & Anomaly Monitoring: Assess CC7.1 and CC7.2: detection and monitoring procedures identify configuration changes that introduce vulnerabilities and susceptibilities to newly discovered ones, and system components are monitored for anomalies indicative of malicious acts, natural disasters, or errors. The surface is the cloud provider estate and the application hosting services plus the source-control platform pipeline that changes them.\n\n99. Verify hardened baselines exist for the platform's building blocks and that deviations surface as findings rather than persisting silently.\n\n100. Confirm dependency and container scanning runs in the source-control platform pipeline with triage timelines tied to severity.\n\n101. Inspect alert coverage across the customer environments: authentication anomalies, availability signals, and error-rate spikes reach an accountable responder.\n\n102. Walk one vulnerability and one anomaly from detection to disposition.\n\n103. Record a design conclusion per criterion and log blind spots as candidate findings.\n\n104. Assessment scope for Evaluate Event Evaluation & Incident Response: Evaluate CC7.3 and CC7.4: the entity evaluates security events to determine whether they are security incidents, and responds to incidents through a defined program to understand, contain, remediate, and communicate. The design under review is the incident lifecycle from event triage through declared-incident execution, including customer notification duties and coordination with subservice providers.\n\n105. Verify declaration criteria distinguish events from incidents and that triage decisions in the window applied them consistently.\n\n106. Confirm the response program defines roles, containment playbooks, evidence preservation, and communication duties, including customer notification thresholds.\n\n107. Walk one event through triage and, if any incident was declared, through containment, remediation, and communication to closure; otherwise inspect the most recent response exercise.\n\n108. Check that post-incident review feeds corrective actions into the issue register.\n\n109. Record a design conclusion per criterion and log gaps as candidate findings.\n\n110. Assessment scope for Assess Incident Recovery Activities: Assess CC7.5: the entity identifies, develops, and implements activities to recover from identified security incidents. For the scoped service this means restoring affected customer services after a security incident - rebuilding from clean infrastructure definitions and restoring from protected backups - and folding lessons learned back into controls and playbooks.\n\n111. Verify documented recovery procedures exist for the plausible incident classes: compromised credentials, malicious change, data corruption, and service compromise.\n\n112. Confirm recovery is exercisable - a tenant environment can be redeployed from definitions and data restored from backups - with recent evidence of a test.\n\n113. Check recovery includes integrity verification before returning to service, so a compromise is not restored along with the data.\n\n114. Verify postmortems produced corrective actions with owners and dates, and that those actions closed.\n\n115. Record a design conclusion for CC7.5 and log gaps as candidate findings.\n\n_CC8 Change Management Assessment_\n116. Assessment scope for Assess Change Authorization, Testing & Deployment: Assess CC8.1: the entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures. Assess the approved production change path: independently reviewed change requests, automated test gates, protected branches, infrastructure definitions, and database migrations.\n\n117. Verify the pipeline enforces the lifecycle: no direct pushes to protected branches, independent review before merge, and green CI gates before deploy.\n\n118. Sample changes across the three classes - application code, infrastructure definitions, database migrations - and confirm each shows authorization, testing, approval, and deployment evidence.\n\n119. Check segregation between author and approver holds in practice, including the small-team case with documented compensations.\n\n120. Verify emergency changes follow the expedited path and receive retrospective review within the required interval.\n\n121. Record a design conclusion for CC8.1 and log deviations as candidate findings.\n\n122. Assessment scope for Conclude on Change Management Design: Close the change-management portion of the readiness assessment by consolidating the conclusion of the Assess Change Authorization, Testing & Deployment activity into a series verdict against the governing change policies.\n\n123. Confirm both governing policies are current, approved, and consistent with the observed pipeline practice, including the emergency path.\n\n124. Reconcile the CC8.1 design conclusion against its supporting evidence and flag anything unsupported.\n\n125. Verify every open change gap exists as an issue on the readiness audit with a named owner and a target date.\n\n126. Draft the change section of the readiness summary, classifying the criterion as designed or gap.\n\n127. Present the consolidated conclusion for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the assessment activity instead of closing it here.\n\n_CC9 Risk Mitigation Assessment_\n128. Assessment scope for Assess Business Disruption Risk Mitigation: Assess CC9.1: the entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions. For the scoped service, assess disruptions including hosting-region loss, key-person unavailability, subservice failure, and funding interruption; the design anchor is the business continuity and contingency planning framework.\n\n129. Verify the register carries the disruption scenarios that matter for the operating model and each carries a selected mitigation, not just an acceptance.\n\n130. Confirm the continuity plan assigns roles and activation criteria and covers the platform's dependency on the cloud provider regional services.\n\n131. Check key-person risk carries concrete mitigations: documented runbooks, credential escrow, and cross-training or advisory cover.\n\n132. Verify mitigation activities have owners and review dates, so they survive personnel and platform change.\n\n133. Record a design conclusion for CC9.1 and log gaps as candidate findings.\n\n134. Assessment scope for Evaluate Vendor & Business Partner Risk Management: Evaluate CC9.2: the entity assesses and manages risks associated with vendors and business partners. Use the approved vendor register to identify material cloud, identity, development-platform, and advisory dependencies; document the significance of each relationship.\n\n135. Verify every active vendor appears in the register with a criticality tier, an owner, and a next review date.\n\n136. Confirm due diligence preceded engagement for vendors touching customer data and was refreshed on schedule for the critical tier.\n\n137. Inspect the most recent attestation review for each subservice organization, including exceptions noted and complementary controls adopted in response.\n\n138. Check exit thinking exists for the concentrated dependencies: what happens if a critical vendor degrades, and who decides.\n\n139. Record a design conclusion for CC9.2 and log gaps as candidate findings.\n\n140. Keep a separate conclusion for each criterion, with the assessor identity, evidence references, applicable controls, design or implementation gaps and rationale. Preserve adverse and conflicting evidence. The executive sponsor and security and compliance lead each review this exact package version and acknowledge findings, action ownership and commitments through separate native approvals; an unresolved objection prevents completion and requires correction. Their approval does not replace the independent readiness review at soc2-readiness-closure.\n\n**Record in AssureSwarm**\nUse the markdown step result for the signed assessor conclusions, criterion-to-evidence references and limitations; use attached step documents for the workpapers listed below. After checking the tenant schema, create or update each gap as an Issue (issue_type: finding, source: internal_audit, severity, issue_owner) and link it to the existing Audit and affected Control records. Record each corrective action on a linked Remediation item using plan, action_owner and target_date. If those fields or the Remediation type are unavailable, retain the action plan, owner and target date in the step workpaper and disclose the missing destination; do not invent Issue fields. Describe criterion identifiers in the workpaper and Issue; no Criterion item is required. Bind both native management approvals to the same reviewed package version. Substantive changes require renewed approvals before downstream reliance.\n\n_CC1 Control Environment Assessment_\nAttach the governance minutes, the advisor attestations, and the acknowledgment export to this step. Raise each design gap as an issue linked to the readiness audit, referencing the affected control by title, and note the design conclusion in the step record.\n\nAttach the role definitions, sampled screening and training evidence, and the permission exports to this step. Link each gap to the affected control, raise it as an issue on the readiness audit, and capture the rationale for each conclusion in the step record.\n\nRecord the consolidated conclusion on this step and attach the control-environment section of the readiness summary. Confirm every gap exists as an issue linked to the readiness audit with a named owner and a target date before requesting approval.\n\n_CC2 Communication and Information Assessment_\nAttach the information inventory, sampled control-run evidence, and metric traces to this step. Raise each information-quality gap as an issue linked to the readiness audit, referencing the affected control by title.\n\nAttach acknowledgment exports, sample communications, and the external-channel inventory to this step. Raise gaps as issues linked to the readiness audit and record the conclusion for each criterion in the step record.\n\n_CC3 Risk Assessment_\nAttach the risk register export and the assessment sign-off to this step. Raise each gap as an issue linked to the readiness audit and record the design conclusions in the step record.\n\nAttach the fraud-risk extract, override compensations, and the sampled change assessment to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the risk-assessment section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC4 Monitoring Activities Assessment_\nAttach the cadence inventory, completion metrics, and review minutes to this step. Raise blind spots as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the issue register export and the traced deficiency records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC5 Control Activities Assessment_\nAttach the risk-to-control mapping sample and the domain coverage summary to this step. Raise coverage gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the policy register export and the sampled policy-to-procedure traces to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC6 Logical and Physical Access Controls Assessment_\nAttach the inventory extract, lifecycle samples, and permission exports to this step. Raise deviations as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the carve-out summary, endpoint inventory, and disposal records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the architecture summary, encryption standard, and endpoint configuration evidence to this step. Raise exposures as issues linked to the readiness audit and record the three conclusions in the step record.\n\nAttach the access section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC7 System Operations Assessment_\nAttach scan samples, baseline evidence, and alert-routing configuration to this step. Raise blind spots as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach triage samples, the response plan, and walkthrough records to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach recovery procedures, exercise evidence, and postmortem records to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC8 Change Management Assessment_\nAttach the pipeline configuration export and the sampled change records to this step. Raise deviations as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the change section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n_CC9 Risk Mitigation Assessment_\nAttach the disruption-scenario extract and continuity plan to this step. Raise gaps as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the vendor register export and attestation review notes to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n**Exit criteria**\n_CC1 Control Environment Assessment_\nCC1.1 and CC1.2 each carry a documented design conclusion supported by attached evidence, and every candidate finding has a named owner and a target date. CC1.3 and CC1.4 each carry a supported design conclusion across structures, reporting lines, and competence practices, and any divergence between documented authority and system permissions is logged as an issue with an owner and a target date. All five control-environment criteria (CC1.1–CC1.5) carry a supported design conclusion, both approvers have signed off on this step, and no control-environment gap remains without an owner, a target date, and a linked issue.\n\n_CC2 Communication and Information Assessment_\nCC2.1 carries a documented design conclusion supported by attached evidence, and every information-quality gap has a named owner and a target date. CC2.2 and CC2.3 each carry a documented design conclusion, every communication gap is logged with a named owner and a target date, and the independent readiness reviewer signs off on this series at soc2-readiness-closure.\n\n_CC3 Risk Assessment_\nCC3.1 and CC3.2 each carry a documented design conclusion supported by attached evidence, and identified gaps have named owners and target dates. CC3.3 and CC3.4 each carry a documented design conclusion, and every gap is logged with a named owner and a target date. All four criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no risk-assessment gap remains without an owner, a target date, and a linked issue.\n\n_CC4 Monitoring Activities Assessment_\nCC4.1 carries a documented design conclusion supported by attached evidence, and every monitoring blind spot has a named owner and a target date. CC4.2 carries a documented design conclusion, both traced deficiencies show timely communication and closure, and remaining gaps carry named owners and target dates.\n\n_CC5 Control Activities Assessment_\nCC5.1 and CC5.2 each carry a documented design conclusion, and every coverage gap is logged with a named owner and a target date. CC5.3 carries a documented design conclusion, sampled policies trace to operating procedures, and every deployment gap has a named owner and a target date.\n\n_CC6 Logical and Physical Access Controls Assessment_\nCC6.1, CC6.2, and CC6.3 each carry a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC6.4 and CC6.5 each carry a documented design conclusion, the inherited-versus-retained boundary is explicit, and every gap has a named owner and a target date. CC6.6, CC6.7, and CC6.8 each carry a documented design conclusion supported by attached evidence, and every exposure has a named owner and a target date. All eight criteria in the series carry supported design conclusions, both approvers have signed off on this step, and no access gap remains without an owner, a target date, and a linked issue.\n\n_CC7 System Operations Assessment_\nCC7.1 and CC7.2 each carry a documented design conclusion supported by attached evidence, and every blind spot has a named owner and a target date. CC7.3 and CC7.4 each carry a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC7.5 carries a documented design conclusion supported by attached evidence, and every recovery gap has a named owner and a target date.\n\n_CC8 Change Management Assessment_\nCC8.1 carries a documented design conclusion supported by attached evidence, and every deviation has a named owner and a target date. CC8.1 carries a supported design conclusion, both approvers have signed off on this step, and no change gap remains without an owner, a target date, and a linked issue.\n\n_CC9 Risk Mitigation Assessment_\nCC9.1 carries a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. CC9.2 carries a documented design conclusion supported by attached evidence, and every vendor gap has a named owner and a target date.\n\nThe executive sponsor and security and compliance lead are two distinct assigned approvers. Both have approved this version, every criterion has a signed assessor conclusion and evidence or a visible gap, and all gaps have owners and dates. The independent readiness conclusion remains pending until soc2-readiness-closure.","type":"TASK","requiredApprovals":2,"linkedItems":[{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"},{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1},{"email":"george.michael@bluth.example","reviewLevel":2}]},{"stepNumber":3,"name":"Approve SOC 2 readiness record","description":null,"summary":null,"instructions":"**Objective**\nApprove SOC 2 readiness record. The independent readiness reviewer challenges evidence sufficiency and approves the examination-planning disposition.\n\n**Inputs**\nConsume the reviewed assessment package from soc2-common-criteria-assessment, with its two management approvals, signed assessor conclusions, criterion evidence and owned gap register. Also consume the reviewed companion assessment for each selected optional category; exclusions must trace to the approved scope.\n1. Review mapped controls, walkthroughs, sample evidence across the intended period, system-description draft, incidents, exceptions, vendor reports, gap inventory, remediation plans, and readiness milestones.\n2. Review all stage evidence, final mapping, system-description version, gap and remediation tracker, readiness result, subservice and user responsibilities, changes, limitations, and stakeholder comments.\n\n**Procedure**\n1. Inspect evidence quality and continuity, identify missing operating history, validate design and implementation observations, assess gap impact by criterion, sequence remediation and evidence generation, and avoid presenting readiness work as examination testing.\n2. Trace the disposition to criterion-level evidence, verify gaps and dependencies remain visible, reconcile document versions and scope, challenge unsupported timing, and return inconsistencies or hidden limitations for correction.\n3. Independently challenge all 33 common-criteria conclusions (CC1.1–CC1.5, CC2.1–CC2.3, CC3.1–CC3.4, CC4.1–CC4.2, CC5.1–CC5.3, CC6.1–CC6.8, CC7.1–CC7.5, CC8.1, CC9.1–CC9.2). For each, record the independent reviewer conclusion, evidence sufficiency, control mapping and remaining gap; reconcile the four optional categories to the approved engagement scope and applicable reviewed companion outputs.\n4. Verify both named management roles approved the exact package versions and that the reviewer is independent of preparation and operation of the assessed controls. Return unsupported or disputed conclusions to the owning assessment package; substantive corrections require its renewed dual approvals and this independent review. Management acceptance cannot cure insufficient evidence or override the independent conclusion.\n5. Hand the approved disposition, conditions and action tracker to management for remediation and examination planning. Keep SOC 2 Type II interim testing, PBC evidence preparation and management assertion with their separate owners and workflows. The service auditor retains responsibility for any SOC opinion.\n\n**Record in AssureSwarm**\n1. Step result: Document the readiness result by criterion, evidence reviewed, design or implementation gaps, operating-history needs, remediation owner and due date, dependencies, conditions, and proposed examination timing.\n2. Step document: Attach the SOC 2 readiness summary and final evidence index; capture the authorized reviewer, final boundary and mapping references, readiness result, conditions, gaps, remediation owners and dates, system-description status, intended next step, limitations, and reassessment triggers. The native approval records the independent reviewer’s decision against this version.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the evidence-based readiness disposition, conditions and gaps are fully owned, and no claim of SOC 2 certification or auditor opinion is made. The authorized reviewer accepts a management readiness record for planning purposes; closure is not certification and does not predict or replace a service auditor’s opinion.\nEvery common criterion and selected optional category has an independent conclusion with evidence or an explicit limitation. The independent readiness reviewer has recorded native approval; the two management approvals remain separate and traceable.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"},{"itemTitle":"Backup Restoration Test","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","name":"SOX Annual Planning & Risk Assessment — FY2026 SOX Annual Program — next cycle","templateName":"SOX Annual Planning & Risk Assessment","templateSourceId":"coworkcanvas:template:sox-annual-planning","description":"SOX Annual Planning & Risk Assessment for FY2026 SOX Annual Program (next cycle).","status":"DRAFT","displayOrder":361,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess ICFR scope and risks","description":null,"summary":null,"instructions":"**Objective**\nAssess ICFR scope and risks. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review financial plans and statements, approved materiality, legal entities, locations, acquisitions and divestitures, systems, service organizations, prior scope, deficiencies, auditor strategy, and regulatory deadlines.\n2. Use reconciled financial data, FSLI significance assessments, quantitative coverage, qualitative factors, transaction classes, risk assessments, entity-level controls, IT landscape, prior errors, and deficiencies.\n\n**Procedure**\n1. Reconcile entity and reporting data, validate planning thresholds and ownership, identify significant changes, set the annual calendar and decision rights, and define how scope or risk changes will be approved.\n2. Calculate coverage, evaluate qualitative significance and aggregation, identify relevant assertions and reasonable misstatement risks, map processes and systems, consider fraud and management override, and explain all inclusions and exclusions.\n\n**Record in AssureSwarm**\n1. Capture fiscal year, reporting perimeter, materiality reference and thresholds, governance roles, methodology, milestones, changes, dependencies, assumptions, data limitations, and responsible owners.\n2. Document calculations, scoped entities, locations, FSLIs, disclosures, assertions, processes, systems, fraud risks, qualitative judgments, exclusions, coverage gaps, and reassessment triggers. Also record scope analysis reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The planning basis agrees to authoritative reporting information, roles and thresholds are approved inputs, and known changes or limitations are visible for scoping analysis. The proposed scope is reproducible and risk-based, material relationships and exclusions are explicit, and unresolved data or mapping gaps are assigned before program design.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve annual SOX plan","description":null,"summary":null,"instructions":"**Objective**\nApprove annual SOX plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use proposed scope, risk-control matrices, control frequency and ownership, prior testing, deficiencies, internal audit and external auditor plans, service-auditor reports, resources, specialists, and reporting dates.\n2. Review materiality, scope calculations, risk assessments, program design, staffing, calendar, external auditor feedback, governance comments, limitations, and open data or mapping actions.\n\n**Procedure**\n1. Set testing timing and extent, allocate controls and locations, define roll-forward and year-end work, coordinate reliance and PBC needs, assign reviewers, plan deficiency escalation, and test feasibility against deadlines and capacity.\n2. Challenge risk-to-coverage alignment, confirm key changes and exclusions are addressed, reconcile populations and milestones, verify ownership and escalation, and return unsupported scope or reliance assumptions for correction.\n\n**Record in AssureSwarm**\n1. Capture the control universe, coverage plan, timing, reliance assumptions, owners, resources, milestones, quality reviews, committee calendar, auditor coordination, decision, and required revisions. Also record program decision.\n2. Document the authorized reviewer, final scope and coverage references, methodology, program calendar, resources, reliance, limitations, open actions, owners, due dates, and reassessment triggers. Also record annual SOX plan summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts a feasible program responsive to scoped risks, reliance and exclusions are supportable, and unresolved capacity or coverage gaps have explicit escalation. The authorized reviewer accepts the annual management plan and authorize its documented work; planning closure is not a management assertion, audit opinion, or operating-effectiveness conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","name":"SOX Annual Planning & Risk Assessment — Identity and Access Management Audit — current cycle","templateName":"SOX Annual Planning & Risk Assessment","templateSourceId":"coworkcanvas:template:sox-annual-planning","description":"SOX Annual Planning & Risk Assessment for Identity and Access Management Audit (current cycle).","status":"ACTIVE","displayOrder":362,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess ICFR scope and risks","description":null,"summary":null,"instructions":"**Objective**\nAssess ICFR scope and risks. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review financial plans and statements, approved materiality, legal entities, locations, acquisitions and divestitures, systems, service organizations, prior scope, deficiencies, auditor strategy, and regulatory deadlines.\n2. Use reconciled financial data, FSLI significance assessments, quantitative coverage, qualitative factors, transaction classes, risk assessments, entity-level controls, IT landscape, prior errors, and deficiencies.\n\n**Procedure**\n1. Reconcile entity and reporting data, validate planning thresholds and ownership, identify significant changes, set the annual calendar and decision rights, and define how scope or risk changes will be approved.\n2. Calculate coverage, evaluate qualitative significance and aggregation, identify relevant assertions and reasonable misstatement risks, map processes and systems, consider fraud and management override, and explain all inclusions and exclusions.\n\n**Record in AssureSwarm**\n1. Capture fiscal year, reporting perimeter, materiality reference and thresholds, governance roles, methodology, milestones, changes, dependencies, assumptions, data limitations, and responsible owners.\n2. Document calculations, scoped entities, locations, FSLIs, disclosures, assertions, processes, systems, fraud risks, qualitative judgments, exclusions, coverage gaps, and reassessment triggers. Also record scope analysis reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The planning basis agrees to authoritative reporting information, roles and thresholds are approved inputs, and known changes or limitations are visible for scoping analysis. The proposed scope is reproducible and risk-based, material relationships and exclusions are explicit, and unresolved data or mapping gaps are assigned before program design.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve annual SOX plan","description":null,"summary":null,"instructions":"**Objective**\nApprove annual SOX plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use proposed scope, risk-control matrices, control frequency and ownership, prior testing, deficiencies, internal audit and external auditor plans, service-auditor reports, resources, specialists, and reporting dates.\n2. Review materiality, scope calculations, risk assessments, program design, staffing, calendar, external auditor feedback, governance comments, limitations, and open data or mapping actions.\n\n**Procedure**\n1. Set testing timing and extent, allocate controls and locations, define roll-forward and year-end work, coordinate reliance and PBC needs, assign reviewers, plan deficiency escalation, and test feasibility against deadlines and capacity.\n2. Challenge risk-to-coverage alignment, confirm key changes and exclusions are addressed, reconcile populations and milestones, verify ownership and escalation, and return unsupported scope or reliance assumptions for correction.\n\n**Record in AssureSwarm**\n1. Capture the control universe, coverage plan, timing, reliance assumptions, owners, resources, milestones, quality reviews, committee calendar, auditor coordination, decision, and required revisions. Also record program decision.\n2. Document the authorized reviewer, final scope and coverage references, methodology, program calendar, resources, reliance, limitations, open actions, owners, due dates, and reassessment triggers. Also record annual SOX plan summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts a feasible program responsive to scoped risks, reliance and exclusions are supportable, and unresolved capacity or coverage gaps have explicit escalation. The authorized reviewer accepts the annual management plan and authorize its documented work; planning closure is not a management assertion, audit opinion, or operating-effectiveness conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Procure to Pay Audit","itemType":"audit","name":"SOX Annual Planning & Risk Assessment — Procure to Pay Audit — prior cycle","templateName":"SOX Annual Planning & Risk Assessment","templateSourceId":"coworkcanvas:template:sox-annual-planning","description":"SOX Annual Planning & Risk Assessment for Procure to Pay Audit (prior cycle).","status":"COMPLETED","displayOrder":363,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess ICFR scope and risks","description":null,"summary":null,"instructions":"**Objective**\nAssess ICFR scope and risks. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review financial plans and statements, approved materiality, legal entities, locations, acquisitions and divestitures, systems, service organizations, prior scope, deficiencies, auditor strategy, and regulatory deadlines.\n2. Use reconciled financial data, FSLI significance assessments, quantitative coverage, qualitative factors, transaction classes, risk assessments, entity-level controls, IT landscape, prior errors, and deficiencies.\n\n**Procedure**\n1. Reconcile entity and reporting data, validate planning thresholds and ownership, identify significant changes, set the annual calendar and decision rights, and define how scope or risk changes will be approved.\n2. Calculate coverage, evaluate qualitative significance and aggregation, identify relevant assertions and reasonable misstatement risks, map processes and systems, consider fraud and management override, and explain all inclusions and exclusions.\n\n**Record in AssureSwarm**\n1. Capture fiscal year, reporting perimeter, materiality reference and thresholds, governance roles, methodology, milestones, changes, dependencies, assumptions, data limitations, and responsible owners.\n2. Document calculations, scoped entities, locations, FSLIs, disclosures, assertions, processes, systems, fraud risks, qualitative judgments, exclusions, coverage gaps, and reassessment triggers. Also record scope analysis reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The planning basis agrees to authoritative reporting information, roles and thresholds are approved inputs, and known changes or limitations are visible for scoping analysis. The proposed scope is reproducible and risk-based, material relationships and exclusions are explicit, and unresolved data or mapping gaps are assigned before program design.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve annual SOX plan","description":null,"summary":null,"instructions":"**Objective**\nApprove annual SOX plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use proposed scope, risk-control matrices, control frequency and ownership, prior testing, deficiencies, internal audit and external auditor plans, service-auditor reports, resources, specialists, and reporting dates.\n2. Review materiality, scope calculations, risk assessments, program design, staffing, calendar, external auditor feedback, governance comments, limitations, and open data or mapping actions.\n\n**Procedure**\n1. Set testing timing and extent, allocate controls and locations, define roll-forward and year-end work, coordinate reliance and PBC needs, assign reviewers, plan deficiency escalation, and test feasibility against deadlines and capacity.\n2. Challenge risk-to-coverage alignment, confirm key changes and exclusions are addressed, reconcile populations and milestones, verify ownership and escalation, and return unsupported scope or reliance assumptions for correction.\n\n**Record in AssureSwarm**\n1. Capture the control universe, coverage plan, timing, reliance assumptions, owners, resources, milestones, quality reviews, committee calendar, auditor coordination, decision, and required revisions. Also record program decision.\n2. Document the authorized reviewer, final scope and coverage references, methodology, program calendar, resources, reliance, limitations, open actions, owners, due dates, and reassessment triggers. Also record annual SOX plan summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts a feasible program responsive to scoped risks, reliance and exclusions are supportable, and unresolved capacity or coverage gaps have explicit escalation. The authorized reviewer accepts the annual management plan and authorize its documented work; planning closure is not a management assertion, audit opinion, or operating-effectiveness conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Journal Entry Approval","itemType":"control","name":"SOX Control Testing — Journal Entry Approval — next cycle","templateName":"SOX Control Testing","templateSourceId":"coworkcanvas:template:sox-control-testing","description":"SOX Control Testing for Journal Entry Approval (next cycle).","status":"DRAFT","displayOrder":371,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"SAMPLE","description":null,"summary":null,"instructions":"**Objective**\nSAMPLE. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, SOX applicability, walkthrough and design work, risk and FSLI mappings, control frequency and the approved test plan, with prior approved workpapers, previous exceptions and remediation, change assessments and program reliance guidance.\n2. Review the approved control design, risk and assertion mapping, walkthrough, policy or procedure, reviewer precision, thresholds, system dependencies, the approved history and reliance decision, and prior attribute definitions.\n3. Use the native population extract, report parameters, control frequency, expected occurrence count, the approved attribute plan and its population applicability, sampling guidance, prior-period considerations, and approved targeted strata.\n\n**Procedure**\n1. Verify the control was in scope for the period, reconcile its description to program documentation, identify design or ownership changes and define reliance boundaries. Then confirm prior work relates to the same control and attributes, compare performers, systems, frequency and evidence, identify recurring conditions, and document whether history informs expectations or qualifies for approved reliance.\n2. Translate each essential control feature into an observable pass/fail criterion, define not-applicable handling, specify expected evidence and timing, and distinguish design, performance, and review attributes.\n3. Validate completeness and accuracy, reconcile counts and date coverage, preserve the original population, execute the approved random, systematic, targeted, or full-population selection, and document replacements.\n\n**Record in AssureSwarm**\n1. Document the fiscal period, scope, control version, assertions, preparer and reviewer roles, known changes and limitations; attach or link the prior workpaper and record its period, conclusion, exceptions, remediation status, the reliance decision and the procedure it affects. Also record testing scope summary; history and reliance assessment.\n2. List each numbered attribute, its expected value or evidence, population applicability, source, failure condition, and approved treatment for missing or conflicting support. Also record attribute plan.\n3. Record the period and test kind in the native sample result, attach the frozen population and sample listing, and record extraction logic, reconciliation, sample size, selection method, seed or interval, and substitutions. Also record test of design; test of operating effectiveness.\nStep.result is markdown. Include exactly one versioned JSON block with the actual period and kind (tod or toe):\n```json\n{\"soxSample\":{\"schemaVersion\":1,\"period\":\"2026-Q2\",\"kind\":\"toe\"}}\n```\nReplace the example period for this run. Keep fiscal year in Workflow.customFields.sox.fiscalYear.\n\nRecord `period` (Testing period) in Step.result fenced json soxSample.period.\n\nRecord `kind` (Test kind; values: tod, toe) in Step.result fenced json soxSample.kind.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The test objective and period are unambiguous under an approved scope, history is considered without replacing current-period evidence, recurring matters are carried forward visibly, any reliance is approved, bounded and supported, and its effect on attribute scope and sample extent is stated. Attributes cover the relevant control features without ambiguity, can be applied consistently by another tester, and changes after testing starts require documented approval and rework assessment. The population is suitable, every selected item traces to it, the method can be reproduced, and the sample covers the period and risk characteristics required by the plan.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Journal Entry Approval","itemType":"control","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"TEST","description":null,"summary":null,"instructions":"**Objective**\nApprove SOX testing record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved sample and attributes, original source documents, system records, report outputs, approvals, reviewer annotations, population support, and authorized owner responses.\n2. Use the frozen sample, approved attribute plan, indexed evidence, relevant history, control and risk context, exception criteria, owner responses, and required result schema.\n3. Review the scope, population and sample, attributes, evidence index, history assessment, workpaper, results artifact, proposed conclusion, exceptions, limitations, and linked follow-up records.\n\n**Procedure**\n1. Obtain evidence for each sample and attribute, verify dates and identifiers, retain native or authoritative formats where practical, name files consistently, and flag missing, altered, late, or owner-created-after-selection support.\n2. Test every item and attribute, retain per-cell results and support, distinguish control exceptions from documentation issues, investigate contradictory evidence, reconcile counts, and route confirmed exceptions for evaluation.\n3. Trace selected results to evidence, recalculate counts, challenge contrary evidence and scope limitations, verify published-result compatibility, and return incomplete or inconsistent work with specific review notes.\n\n**Record in AssureSwarm**\n1. Attach evidence to this CAPS stage, maintain a sample-to-file index, record source and receipt date, identify confidentiality restrictions, and cross-reference evidence that legitimately supports multiple attributes. Also record evidence index and gaps.\n2. Upload the annotated workpaper and required results artifact, record the conclusion, exception count and workpaper reference in the markdown step result, and link exception or remediation records without hiding limitations. Also record operating Effectively; exceptions Noted; not Operating Effectively; exceptions count.\n3. Document reviewer comments and resolutions, the approved or returned status, the authorized reviewer, date, remaining limitations, exception handoffs, and the exact workpaper and results references reviewed. Also record final review summary.\nRetain conclusion, exceptions_count and workpaper_reference in the markdown step result. Publish the supported SOX results JSON document and annotated workpaper on TEST using the existing publication schema. Native approval and validated result documents drive publication; narrative alone is not publication.\n\nRecord `conclusion` (Testing conclusion; values: operating_effectively, exceptions_noted, not_operating_effectively) in Step.result markdown.\n\nRecord `exceptions_count` (Exceptions) in Step.result markdown.\n\nRecord `workpaper_reference` (Workpaper reference) in Step.result markdown.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: Each selected item has indexed support or a documented evidence gap, identifiers agree to the sample, source and timing are clear, and testing can begin without relying on undocumented explanations. Results reconcile to the sample and attributes, the proposed conclusion follows the evidence, every exception is traceable, and reviewer approval evaluates the work rather than inferring effectiveness from completion. The authorized reviewer can support the explicit conclusion from the complete record, review notes are resolved or retained, follow-up is assigned, and closure does not create an audit opinion by itself.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Journal Entry Approval","itemType":"control","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Privileged Access Approval","itemType":"control","name":"SOX Control Testing — Privileged Access Approval — current cycle","templateName":"SOX Control Testing","templateSourceId":"coworkcanvas:template:sox-control-testing","description":"SOX Control Testing for Privileged Access Approval (current cycle).","status":"ACTIVE","displayOrder":372,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"SAMPLE","description":null,"summary":null,"instructions":"**Objective**\nSAMPLE. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, SOX applicability, walkthrough and design work, risk and FSLI mappings, control frequency and the approved test plan, with prior approved workpapers, previous exceptions and remediation, change assessments and program reliance guidance.\n2. Review the approved control design, risk and assertion mapping, walkthrough, policy or procedure, reviewer precision, thresholds, system dependencies, the approved history and reliance decision, and prior attribute definitions.\n3. Use the native population extract, report parameters, control frequency, expected occurrence count, the approved attribute plan and its population applicability, sampling guidance, prior-period considerations, and approved targeted strata.\n\n**Procedure**\n1. Verify the control was in scope for the period, reconcile its description to program documentation, identify design or ownership changes and define reliance boundaries. Then confirm prior work relates to the same control and attributes, compare performers, systems, frequency and evidence, identify recurring conditions, and document whether history informs expectations or qualifies for approved reliance.\n2. Translate each essential control feature into an observable pass/fail criterion, define not-applicable handling, specify expected evidence and timing, and distinguish design, performance, and review attributes.\n3. Validate completeness and accuracy, reconcile counts and date coverage, preserve the original population, execute the approved random, systematic, targeted, or full-population selection, and document replacements.\n\n**Record in AssureSwarm**\n1. Document the fiscal period, scope, control version, assertions, preparer and reviewer roles, known changes and limitations; attach or link the prior workpaper and record its period, conclusion, exceptions, remediation status, the reliance decision and the procedure it affects. Also record testing scope summary; history and reliance assessment.\n2. List each numbered attribute, its expected value or evidence, population applicability, source, failure condition, and approved treatment for missing or conflicting support. Also record attribute plan.\n3. Record the period and test kind in the native sample result, attach the frozen population and sample listing, and record extraction logic, reconciliation, sample size, selection method, seed or interval, and substitutions. Also record test of design; test of operating effectiveness.\nStep.result is markdown. Include exactly one versioned JSON block with the actual period and kind (tod or toe):\n```json\n{\"soxSample\":{\"schemaVersion\":1,\"period\":\"2026-Q2\",\"kind\":\"toe\"}}\n```\nReplace the example period for this run. Keep fiscal year in Workflow.customFields.sox.fiscalYear.\n\nRecord `period` (Testing period) in Step.result fenced json soxSample.period.\n\nRecord `kind` (Test kind; values: tod, toe) in Step.result fenced json soxSample.kind.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The test objective and period are unambiguous under an approved scope, history is considered without replacing current-period evidence, recurring matters are carried forward visibly, any reliance is approved, bounded and supported, and its effect on attribute scope and sample extent is stated. Attributes cover the relevant control features without ambiguity, can be applied consistently by another tester, and changes after testing starts require documented approval and rework assessment. The population is suitable, every selected item traces to it, the method can be reproduced, and the sample covers the period and risk characteristics required by the plan.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Privileged Access Approval","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"TEST","description":null,"summary":null,"instructions":"**Objective**\nApprove SOX testing record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved sample and attributes, original source documents, system records, report outputs, approvals, reviewer annotations, population support, and authorized owner responses.\n2. Use the frozen sample, approved attribute plan, indexed evidence, relevant history, control and risk context, exception criteria, owner responses, and required result schema.\n3. Review the scope, population and sample, attributes, evidence index, history assessment, workpaper, results artifact, proposed conclusion, exceptions, limitations, and linked follow-up records.\n\n**Procedure**\n1. Obtain evidence for each sample and attribute, verify dates and identifiers, retain native or authoritative formats where practical, name files consistently, and flag missing, altered, late, or owner-created-after-selection support.\n2. Test every item and attribute, retain per-cell results and support, distinguish control exceptions from documentation issues, investigate contradictory evidence, reconcile counts, and route confirmed exceptions for evaluation.\n3. Trace selected results to evidence, recalculate counts, challenge contrary evidence and scope limitations, verify published-result compatibility, and return incomplete or inconsistent work with specific review notes.\n\n**Record in AssureSwarm**\n1. Attach evidence to this CAPS stage, maintain a sample-to-file index, record source and receipt date, identify confidentiality restrictions, and cross-reference evidence that legitimately supports multiple attributes. Also record evidence index and gaps.\n2. Upload the annotated workpaper and required results artifact, record the conclusion, exception count and workpaper reference in the markdown step result, and link exception or remediation records without hiding limitations. Also record operating Effectively; exceptions Noted; not Operating Effectively; exceptions count.\n3. Document reviewer comments and resolutions, the approved or returned status, the authorized reviewer, date, remaining limitations, exception handoffs, and the exact workpaper and results references reviewed. Also record final review summary.\nRetain conclusion, exceptions_count and workpaper_reference in the markdown step result. Publish the supported SOX results JSON document and annotated workpaper on TEST using the existing publication schema. Native approval and validated result documents drive publication; narrative alone is not publication.\n\nRecord `conclusion` (Testing conclusion; values: operating_effectively, exceptions_noted, not_operating_effectively) in Step.result markdown.\n\nRecord `exceptions_count` (Exceptions) in Step.result markdown.\n\nRecord `workpaper_reference` (Workpaper reference) in Step.result markdown.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: Each selected item has indexed support or a documented evidence gap, identifiers agree to the sample, source and timing are clear, and testing can begin without relying on undocumented explanations. Results reconcile to the sample and attributes, the proposed conclusion follows the evidence, every exception is traceable, and reviewer approval evaluates the work rather than inferring effectiveness from completion. The authorized reviewer can support the explicit conclusion from the complete record, review notes are resolved or retained, follow-up is assigned, and closure does not create an audit opinion by itself.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Privileged Access Approval","itemType":"control","kind":"related"},{"itemTitle":"Cybersecurity Program Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Production Change Approval","itemType":"control","name":"SOX Control Testing — Production Change Approval — prior cycle","templateName":"SOX Control Testing","templateSourceId":"coworkcanvas:template:sox-control-testing","description":"SOX Control Testing for Production Change Approval (prior cycle).","status":"COMPLETED","displayOrder":373,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"SAMPLE","description":null,"summary":null,"instructions":"**Objective**\nSAMPLE. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Control item, SOX applicability, walkthrough and design work, risk and FSLI mappings, control frequency and the approved test plan, with prior approved workpapers, previous exceptions and remediation, change assessments and program reliance guidance.\n2. Review the approved control design, risk and assertion mapping, walkthrough, policy or procedure, reviewer precision, thresholds, system dependencies, the approved history and reliance decision, and prior attribute definitions.\n3. Use the native population extract, report parameters, control frequency, expected occurrence count, the approved attribute plan and its population applicability, sampling guidance, prior-period considerations, and approved targeted strata.\n\n**Procedure**\n1. Verify the control was in scope for the period, reconcile its description to program documentation, identify design or ownership changes and define reliance boundaries. Then confirm prior work relates to the same control and attributes, compare performers, systems, frequency and evidence, identify recurring conditions, and document whether history informs expectations or qualifies for approved reliance.\n2. Translate each essential control feature into an observable pass/fail criterion, define not-applicable handling, specify expected evidence and timing, and distinguish design, performance, and review attributes.\n3. Validate completeness and accuracy, reconcile counts and date coverage, preserve the original population, execute the approved random, systematic, targeted, or full-population selection, and document replacements.\n\n**Record in AssureSwarm**\n1. Document the fiscal period, scope, control version, assertions, preparer and reviewer roles, known changes and limitations; attach or link the prior workpaper and record its period, conclusion, exceptions, remediation status, the reliance decision and the procedure it affects. Also record testing scope summary; history and reliance assessment.\n2. List each numbered attribute, its expected value or evidence, population applicability, source, failure condition, and approved treatment for missing or conflicting support. Also record attribute plan.\n3. Record the period and test kind in the native sample result, attach the frozen population and sample listing, and record extraction logic, reconciliation, sample size, selection method, seed or interval, and substitutions. Also record test of design; test of operating effectiveness.\nStep.result is markdown. Include exactly one versioned JSON block with the actual period and kind (tod or toe):\n```json\n{\"soxSample\":{\"schemaVersion\":1,\"period\":\"2026-Q2\",\"kind\":\"toe\"}}\n```\nReplace the example period for this run. Keep fiscal year in Workflow.customFields.sox.fiscalYear.\n\nRecord `period` (Testing period) in Step.result fenced json soxSample.period.\n\nRecord `kind` (Test kind; values: tod, toe) in Step.result fenced json soxSample.kind.\n\n**Exit criteria**\nTest supervisor independent of the operator provides approval: The test objective and period are unambiguous under an approved scope, history is considered without replacing current-period evidence, recurring matters are carried forward visibly, any reliance is approved, bounded and supported, and its effect on attribute scope and sample extent is stated. Attributes cover the relevant control features without ambiguity, can be applied consistently by another tester, and changes after testing starts require documented approval and rework assessment. The population is suitable, every selected item traces to it, the method can be reproduced, and the sample covers the period and risk characteristics required by the plan.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Production Change Approval","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"TEST","description":null,"summary":null,"instructions":"**Objective**\nApprove SOX testing record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved sample and attributes, original source documents, system records, report outputs, approvals, reviewer annotations, population support, and authorized owner responses.\n2. Use the frozen sample, approved attribute plan, indexed evidence, relevant history, control and risk context, exception criteria, owner responses, and required result schema.\n3. Review the scope, population and sample, attributes, evidence index, history assessment, workpaper, results artifact, proposed conclusion, exceptions, limitations, and linked follow-up records.\n\n**Procedure**\n1. Obtain evidence for each sample and attribute, verify dates and identifiers, retain native or authoritative formats where practical, name files consistently, and flag missing, altered, late, or owner-created-after-selection support.\n2. Test every item and attribute, retain per-cell results and support, distinguish control exceptions from documentation issues, investigate contradictory evidence, reconcile counts, and route confirmed exceptions for evaluation.\n3. Trace selected results to evidence, recalculate counts, challenge contrary evidence and scope limitations, verify published-result compatibility, and return incomplete or inconsistent work with specific review notes.\n\n**Record in AssureSwarm**\n1. Attach evidence to this CAPS stage, maintain a sample-to-file index, record source and receipt date, identify confidentiality restrictions, and cross-reference evidence that legitimately supports multiple attributes. Also record evidence index and gaps.\n2. Upload the annotated workpaper and required results artifact, record the conclusion, exception count and workpaper reference in the markdown step result, and link exception or remediation records without hiding limitations. Also record operating Effectively; exceptions Noted; not Operating Effectively; exceptions count.\n3. Document reviewer comments and resolutions, the approved or returned status, the authorized reviewer, date, remaining limitations, exception handoffs, and the exact workpaper and results references reviewed. Also record final review summary.\nRetain conclusion, exceptions_count and workpaper_reference in the markdown step result. Publish the supported SOX results JSON document and annotated workpaper on TEST using the existing publication schema. Native approval and validated result documents drive publication; narrative alone is not publication.\n\nRecord `conclusion` (Testing conclusion; values: operating_effectively, exceptions_noted, not_operating_effectively) in Step.result markdown.\n\nRecord `exceptions_count` (Exceptions) in Step.result markdown.\n\nRecord `workpaper_reference` (Workpaper reference) in Step.result markdown.\n\n**Exit criteria**\nIndependent audit reviewer provides approval: Each selected item has indexed support or a documented evidence gap, identifiers agree to the sample, source and timing are clear, and testing can begin without relying on undocumented explanations. Results reconcile to the sample and attributes, the proposed conclusion follows the evidence, every exception is traceable, and reviewer approval evaluates the work rather than inferring effectiveness from completion. The authorized reviewer can support the explicit conclusion from the complete record, review notes are resolved or retained, follow-up is assigned, and closure does not create an audit opinion by itself.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Production Change Approval","itemType":"control","kind":"related"},{"itemTitle":"SOC 2 Security and Availability Readiness","itemType":"audit","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","name":"Deficiency Evaluation & Committee — FY2026 SOX Annual Program — next cycle","templateName":"Deficiency Evaluation & Committee","templateSourceId":"coworkcanvas:template:sox-deficiency-eval","description":"Deficiency Evaluation & Committee for FY2026 SOX Annual Program (next cycle).","status":"DRAFT","displayOrder":381,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess severity and aggregation","description":null,"summary":null,"instructions":"**Objective**\nAssess severity and aggregation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review failed test or monitoring work, control description, exceptions and population, risk and assertion mappings, process walkthrough, owner response, prior issues, compensating activities, and supporting evidence.\n2. Use validated facts, materiality, affected accounts and assertions, transaction volume, exposure period, compensating controls, possible misstatement scenarios, related deficiencies, prior errors, and auditor observations.\n\n**Procedure**\n1. Reperform the fact pattern, separate evidence gaps from control failures, quantify known exceptions and affected periods, confirm whether the issue is isolated or systemic, identify root cause, and search for related deficiencies.\n2. Develop reasonably possible misstatement scenarios, evaluate magnitude and likelihood, assess precision and evidence for compensating controls, consider aggregation by cause and assertion, compare indicators, and document contrary factors.\n\n**Record in AssureSwarm**\n1. Capture the deficiency reference, validated condition, criteria, cause, affected controls and assertions, population and exceptions, period, locations, systems, owner response, limitations, and immediate actions. Also record validated fact summary.\n2. Document proposed severity, scenario calculations, likelihood and magnitude rationale, compensating-control analysis, aggregation set, indicators considered, differences of view, and additional evidence needed.\n\n**Exit criteria**\nSOX technical evaluator provides expertise: The factual record is supported and complete enough for severity analysis, disputed facts remain explicit, and related or recurring matters are identified for aggregation. The proposed severity is reproducible from evidence and applicable criteria, aggregation has been explicitly addressed, and unresolved judgments are ready for management challenge.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve deficiency evaluation","description":null,"summary":null,"instructions":"**Objective**\nApprove deficiency evaluation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the fact record, severity analysis, aggregation inventory, management response, remediation plan, disclosure considerations, external auditor view where available, and draft governance materials.\n2. Review all stage evidence, final calculations and criteria, committee disposition, management response, auditor communication, remediation plan, disclosures, related deficiencies, and outstanding limitations.\n\n**Procedure**\n1. Present evidence and judgments, record questions and dissent, challenge optimistic assumptions and unsupported compensating controls, confirm communication requirements and timing, and route material changes back through evaluation.\n2. Verify the final severity follows supported facts, aggregation and dissent are addressed, required communications occurred, linked issue and remediation records agree, and return any unsupported or inconsistent disposition.\n\n**Record in AssureSwarm**\n1. Capture attendees, date, materials, questions, management and committee views, disposition, revised severity or conditions, disclosure and auditor communications, remediation commitments, owners, and due dates.\n2. Document the authorized reviewer, final severity and rationale, aggregation set, committee date and decision, communications, disclosure impact, remediation owner and due date, reassessment triggers, and links. Also record final evaluation summary.\n\n**Exit criteria**\nManagement and audit committee provides approval: An approver confirms required governance review is evidenced, the accepted or revised evaluation is clear, and dissent or unresolved reporting implications remain visible. The authorized reviewer accepts the documented management evaluation and governance record; workflow completion alone does not constitute management assertion or an auditor conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","name":"Deficiency Evaluation & Committee — Identity and Access Management Audit — current cycle","templateName":"Deficiency Evaluation & Committee","templateSourceId":"coworkcanvas:template:sox-deficiency-eval","description":"Deficiency Evaluation & Committee for Identity and Access Management Audit (current cycle).","status":"ACTIVE","displayOrder":382,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess severity and aggregation","description":null,"summary":null,"instructions":"**Objective**\nAssess severity and aggregation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review failed test or monitoring work, control description, exceptions and population, risk and assertion mappings, process walkthrough, owner response, prior issues, compensating activities, and supporting evidence.\n2. Use validated facts, materiality, affected accounts and assertions, transaction volume, exposure period, compensating controls, possible misstatement scenarios, related deficiencies, prior errors, and auditor observations.\n\n**Procedure**\n1. Reperform the fact pattern, separate evidence gaps from control failures, quantify known exceptions and affected periods, confirm whether the issue is isolated or systemic, identify root cause, and search for related deficiencies.\n2. Develop reasonably possible misstatement scenarios, evaluate magnitude and likelihood, assess precision and evidence for compensating controls, consider aggregation by cause and assertion, compare indicators, and document contrary factors.\n\n**Record in AssureSwarm**\n1. Capture the deficiency reference, validated condition, criteria, cause, affected controls and assertions, population and exceptions, period, locations, systems, owner response, limitations, and immediate actions. Also record validated fact summary.\n2. Document proposed severity, scenario calculations, likelihood and magnitude rationale, compensating-control analysis, aggregation set, indicators considered, differences of view, and additional evidence needed.\n\n**Exit criteria**\nSOX technical evaluator provides expertise: The factual record is supported and complete enough for severity analysis, disputed facts remain explicit, and related or recurring matters are identified for aggregation. The proposed severity is reproducible from evidence and applicable criteria, aggregation has been explicitly addressed, and unresolved judgments are ready for management challenge.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve deficiency evaluation","description":null,"summary":null,"instructions":"**Objective**\nApprove deficiency evaluation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the fact record, severity analysis, aggregation inventory, management response, remediation plan, disclosure considerations, external auditor view where available, and draft governance materials.\n2. Review all stage evidence, final calculations and criteria, committee disposition, management response, auditor communication, remediation plan, disclosures, related deficiencies, and outstanding limitations.\n\n**Procedure**\n1. Present evidence and judgments, record questions and dissent, challenge optimistic assumptions and unsupported compensating controls, confirm communication requirements and timing, and route material changes back through evaluation.\n2. Verify the final severity follows supported facts, aggregation and dissent are addressed, required communications occurred, linked issue and remediation records agree, and return any unsupported or inconsistent disposition.\n\n**Record in AssureSwarm**\n1. Capture attendees, date, materials, questions, management and committee views, disposition, revised severity or conditions, disclosure and auditor communications, remediation commitments, owners, and due dates.\n2. Document the authorized reviewer, final severity and rationale, aggregation set, committee date and decision, communications, disclosure impact, remediation owner and due date, reassessment triggers, and links. Also record final evaluation summary.\n\n**Exit criteria**\nManagement and audit committee provides approval: An approver confirms required governance review is evidenced, the accepted or revised evaluation is clear, and dissent or unresolved reporting implications remain visible. The authorized reviewer accepts the documented management evaluation and governance record; workflow completion alone does not constitute management assertion or an auditor conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Procure to Pay Audit","itemType":"audit","name":"Deficiency Evaluation & Committee — Procure to Pay Audit — prior cycle","templateName":"Deficiency Evaluation & Committee","templateSourceId":"coworkcanvas:template:sox-deficiency-eval","description":"Deficiency Evaluation & Committee for Procure to Pay Audit (prior cycle).","status":"COMPLETED","displayOrder":383,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess severity and aggregation","description":null,"summary":null,"instructions":"**Objective**\nAssess severity and aggregation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review failed test or monitoring work, control description, exceptions and population, risk and assertion mappings, process walkthrough, owner response, prior issues, compensating activities, and supporting evidence.\n2. Use validated facts, materiality, affected accounts and assertions, transaction volume, exposure period, compensating controls, possible misstatement scenarios, related deficiencies, prior errors, and auditor observations.\n\n**Procedure**\n1. Reperform the fact pattern, separate evidence gaps from control failures, quantify known exceptions and affected periods, confirm whether the issue is isolated or systemic, identify root cause, and search for related deficiencies.\n2. Develop reasonably possible misstatement scenarios, evaluate magnitude and likelihood, assess precision and evidence for compensating controls, consider aggregation by cause and assertion, compare indicators, and document contrary factors.\n\n**Record in AssureSwarm**\n1. Capture the deficiency reference, validated condition, criteria, cause, affected controls and assertions, population and exceptions, period, locations, systems, owner response, limitations, and immediate actions. Also record validated fact summary.\n2. Document proposed severity, scenario calculations, likelihood and magnitude rationale, compensating-control analysis, aggregation set, indicators considered, differences of view, and additional evidence needed.\n\n**Exit criteria**\nSOX technical evaluator provides expertise: The factual record is supported and complete enough for severity analysis, disputed facts remain explicit, and related or recurring matters are identified for aggregation. The proposed severity is reproducible from evidence and applicable criteria, aggregation has been explicitly addressed, and unresolved judgments are ready for management challenge.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve deficiency evaluation","description":null,"summary":null,"instructions":"**Objective**\nApprove deficiency evaluation. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the fact record, severity analysis, aggregation inventory, management response, remediation plan, disclosure considerations, external auditor view where available, and draft governance materials.\n2. Review all stage evidence, final calculations and criteria, committee disposition, management response, auditor communication, remediation plan, disclosures, related deficiencies, and outstanding limitations.\n\n**Procedure**\n1. Present evidence and judgments, record questions and dissent, challenge optimistic assumptions and unsupported compensating controls, confirm communication requirements and timing, and route material changes back through evaluation.\n2. Verify the final severity follows supported facts, aggregation and dissent are addressed, required communications occurred, linked issue and remediation records agree, and return any unsupported or inconsistent disposition.\n\n**Record in AssureSwarm**\n1. Capture attendees, date, materials, questions, management and committee views, disposition, revised severity or conditions, disclosure and auditor communications, remediation commitments, owners, and due dates.\n2. Document the authorized reviewer, final severity and rationale, aggregation set, committee date and decision, communications, disclosure impact, remediation owner and due date, reassessment triggers, and links. Also record final evaluation summary.\n\n**Exit criteria**\nManagement and audit committee provides approval: An approver confirms required governance review is evidenced, the accepted or revised evaluation is clear, and dissent or unresolved reporting implications remain visible. The authorized reviewer accepts the documented management evaluation and governance record; workflow completion alone does not constitute management assertion or an auditor conclusion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","name":"Management Assessment & Assertion — FY2026 SOX Annual Program — next cycle","templateName":"Management Assessment & Assertion","templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","description":"Management Assessment & Assertion for FY2026 SOX Annual Program (next cycle).","status":"DRAFT","displayOrder":391,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Synthesize ICFR results","description":null,"summary":null,"instructions":"**Objective**\nSynthesize ICFR results. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review approved SOX scope and plans, risk-control matrices, walkthroughs, testing trackers and workpapers, entity and IT coverage, service-auditor reports, sub-certifications, changes, and deficiency inventory.\n2. Use reviewed testing results, exceptions, deficiency evaluations, remediation and retests, entity-level and IT results, service-auditor reports, certifications, close controls, subsequent events, and disclosure drafts.\n\n**Procedure**\n1. Reconcile scoped controls to completed testing, identify missing reviews and evidence, validate entity and period coverage, confirm changes are reflected, inventory open deficiencies, and establish the assessment calendar and decision owners.\n2. Aggregate results by process and assertion, verify unresolved exceptions are captured, evaluate scope and evidence limitations, reconcile deficiency severity, consider subsequent changes, and draft conclusions tied to specific supporting records.\n\n**Record in AssureSwarm**\n1. Capture assessment period, scope reference, control and testing reconciliation, certifications, service-provider coverage, changes, deficiencies, missing work, reporting criteria, owners, and due dates. Also record approved scope reference.\n2. Link the results memorandum, summarize coverage and outcomes, list exceptions and deficiencies, limitations, remediation status, contradictory evidence, disclosure considerations, and remaining management judgments. Also record results memorandum reference.\n\n**Exit criteria**\nSOX assessment reviewer provides expertise: The assessment population reconciles to approved scope, incomplete evidence and review are visible, and management has a supportable basis for result synthesis. The synthesis is traceable to reviewed evidence, does not hide gaps or dissent, and all judgments requiring certification or disclosure review are explicit.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve management assessment record","description":null,"summary":null,"instructions":"**Objective**\nApprove management assessment record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the population reconciliation, results memorandum, final deficiency evaluations, certifications, disclosure drafts, remediation status, external auditor communications, legal input, and proposed assertion wording.\n2. Review all stage records, final results memorandum, signed certifications, approved assertion and disclosures, deficiency and remediation status, committee materials, auditor communications, and unresolved limitations.\n\n**Procedure**\n1. Challenge evidence sufficiency and scope, verify assertion language matches the evaluated criteria and period, reconcile material weakness determinations and disclosures, record dissent and conditions, and prohibit approval while material support remains incomplete.\n2. Trace material statements to evidence, verify approved versions and dates, confirm required governance and disclosures, reconcile linked records, and return the package if results, deficiencies, or assertion language conflict.\n\n**Record in AssureSwarm**\n1. Capture the decision, approvers, assertion and disclosure versions reviewed, evidence and criteria considered, conditions, dissent, unresolved items, communications, owners, and due dates. Also record assertion package decision.\n2. Document the authorized reviewer, final assessment and assertion references, period, criteria, scope, deficiencies, disclosure outcome, certifications, committee and auditor communications, limitations, and archive index. Also record management assessment summary.\n\n**Exit criteria**\nAuthorized management signatory provides approval: An approver accepts the package for final governance or records precise revisions and blockers; the workflow does not itself issue management’s formal assertion. The authorized reviewer accepts the support and governance record; only the separately approved management assertion carries its stated meaning, not workflow completion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","name":"Management Assessment & Assertion — Identity and Access Management Audit — current cycle","templateName":"Management Assessment & Assertion","templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","description":"Management Assessment & Assertion for Identity and Access Management Audit (current cycle).","status":"ACTIVE","displayOrder":392,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Synthesize ICFR results","description":null,"summary":null,"instructions":"**Objective**\nSynthesize ICFR results. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review approved SOX scope and plans, risk-control matrices, walkthroughs, testing trackers and workpapers, entity and IT coverage, service-auditor reports, sub-certifications, changes, and deficiency inventory.\n2. Use reviewed testing results, exceptions, deficiency evaluations, remediation and retests, entity-level and IT results, service-auditor reports, certifications, close controls, subsequent events, and disclosure drafts.\n\n**Procedure**\n1. Reconcile scoped controls to completed testing, identify missing reviews and evidence, validate entity and period coverage, confirm changes are reflected, inventory open deficiencies, and establish the assessment calendar and decision owners.\n2. Aggregate results by process and assertion, verify unresolved exceptions are captured, evaluate scope and evidence limitations, reconcile deficiency severity, consider subsequent changes, and draft conclusions tied to specific supporting records.\n\n**Record in AssureSwarm**\n1. Capture assessment period, scope reference, control and testing reconciliation, certifications, service-provider coverage, changes, deficiencies, missing work, reporting criteria, owners, and due dates. Also record approved scope reference.\n2. Link the results memorandum, summarize coverage and outcomes, list exceptions and deficiencies, limitations, remediation status, contradictory evidence, disclosure considerations, and remaining management judgments. Also record results memorandum reference.\n\n**Exit criteria**\nSOX assessment reviewer provides expertise: The assessment population reconciles to approved scope, incomplete evidence and review are visible, and management has a supportable basis for result synthesis. The synthesis is traceable to reviewed evidence, does not hide gaps or dissent, and all judgments requiring certification or disclosure review are explicit.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve management assessment record","description":null,"summary":null,"instructions":"**Objective**\nApprove management assessment record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the population reconciliation, results memorandum, final deficiency evaluations, certifications, disclosure drafts, remediation status, external auditor communications, legal input, and proposed assertion wording.\n2. Review all stage records, final results memorandum, signed certifications, approved assertion and disclosures, deficiency and remediation status, committee materials, auditor communications, and unresolved limitations.\n\n**Procedure**\n1. Challenge evidence sufficiency and scope, verify assertion language matches the evaluated criteria and period, reconcile material weakness determinations and disclosures, record dissent and conditions, and prohibit approval while material support remains incomplete.\n2. Trace material statements to evidence, verify approved versions and dates, confirm required governance and disclosures, reconcile linked records, and return the package if results, deficiencies, or assertion language conflict.\n\n**Record in AssureSwarm**\n1. Capture the decision, approvers, assertion and disclosure versions reviewed, evidence and criteria considered, conditions, dissent, unresolved items, communications, owners, and due dates. Also record assertion package decision.\n2. Document the authorized reviewer, final assessment and assertion references, period, criteria, scope, deficiencies, disclosure outcome, certifications, committee and auditor communications, limitations, and archive index. Also record management assessment summary.\n\n**Exit criteria**\nAuthorized management signatory provides approval: An approver accepts the package for final governance or records precise revisions and blockers; the workflow does not itself issue management’s formal assertion. The authorized reviewer accepts the support and governance record; only the separately approved management assertion carries its stated meaning, not workflow completion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Procure to Pay Audit","itemType":"audit","name":"Management Assessment & Assertion — Procure to Pay Audit — prior cycle","templateName":"Management Assessment & Assertion","templateSourceId":"coworkcanvas:template:sox-mgmt-assessment","description":"Management Assessment & Assertion for Procure to Pay Audit (prior cycle).","status":"COMPLETED","displayOrder":393,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Synthesize ICFR results","description":null,"summary":null,"instructions":"**Objective**\nSynthesize ICFR results. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review approved SOX scope and plans, risk-control matrices, walkthroughs, testing trackers and workpapers, entity and IT coverage, service-auditor reports, sub-certifications, changes, and deficiency inventory.\n2. Use reviewed testing results, exceptions, deficiency evaluations, remediation and retests, entity-level and IT results, service-auditor reports, certifications, close controls, subsequent events, and disclosure drafts.\n\n**Procedure**\n1. Reconcile scoped controls to completed testing, identify missing reviews and evidence, validate entity and period coverage, confirm changes are reflected, inventory open deficiencies, and establish the assessment calendar and decision owners.\n2. Aggregate results by process and assertion, verify unresolved exceptions are captured, evaluate scope and evidence limitations, reconcile deficiency severity, consider subsequent changes, and draft conclusions tied to specific supporting records.\n\n**Record in AssureSwarm**\n1. Capture assessment period, scope reference, control and testing reconciliation, certifications, service-provider coverage, changes, deficiencies, missing work, reporting criteria, owners, and due dates. Also record approved scope reference.\n2. Link the results memorandum, summarize coverage and outcomes, list exceptions and deficiencies, limitations, remediation status, contradictory evidence, disclosure considerations, and remaining management judgments. Also record results memorandum reference.\n\n**Exit criteria**\nSOX assessment reviewer provides expertise: The assessment population reconciles to approved scope, incomplete evidence and review are visible, and management has a supportable basis for result synthesis. The synthesis is traceable to reviewed evidence, does not hide gaps or dissent, and all judgments requiring certification or disclosure review are explicit.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve management assessment record","description":null,"summary":null,"instructions":"**Objective**\nApprove management assessment record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the population reconciliation, results memorandum, final deficiency evaluations, certifications, disclosure drafts, remediation status, external auditor communications, legal input, and proposed assertion wording.\n2. Review all stage records, final results memorandum, signed certifications, approved assertion and disclosures, deficiency and remediation status, committee materials, auditor communications, and unresolved limitations.\n\n**Procedure**\n1. Challenge evidence sufficiency and scope, verify assertion language matches the evaluated criteria and period, reconcile material weakness determinations and disclosures, record dissent and conditions, and prohibit approval while material support remains incomplete.\n2. Trace material statements to evidence, verify approved versions and dates, confirm required governance and disclosures, reconcile linked records, and return the package if results, deficiencies, or assertion language conflict.\n\n**Record in AssureSwarm**\n1. Capture the decision, approvers, assertion and disclosure versions reviewed, evidence and criteria considered, conditions, dissent, unresolved items, communications, owners, and due dates. Also record assertion package decision.\n2. Document the authorized reviewer, final assessment and assertion references, period, criteria, scope, deficiencies, disclosure outcome, certifications, committee and auditor communications, limitations, and archive index. Also record management assessment summary.\n\n**Exit criteria**\nAuthorized management signatory provides approval: An approver accepts the package for final governance or records precise revisions and blockers; the workflow does not itself issue management’s formal assertion. The authorized reviewer accepts the support and governance record; only the separately approved management assertion carries its stated meaning, not workflow completion.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","name":"External Audit Support & PBC — FY2026 SOX Annual Program — next cycle","templateName":"External Audit Support & PBC","templateSourceId":"coworkcanvas:template:sox-pbc","description":"External Audit Support & PBC for FY2026 SOX Annual Program (next cycle).","status":"DRAFT","displayOrder":401,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve PBC request closure","description":null,"summary":null,"instructions":"**Objective**\nApprove PBC request closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the auditor request list and correspondence, prior submissions, SOX scope, control and process records, data owners, retention requirements, confidentiality rules, and reporting calendar.\n2. Use the validated request, authoritative reports and documents, source-system extracts, report parameters, reconciliations, prior submissions, retention rules, and approved secure workspace.\n3. Review the request and clarification history, prepared package, reconciliation, source parameters, redactions, limitations, related submissions, legal or security restrictions, and delivery protocol.\n4. Review the released response, delivery evidence, auditor acknowledgment, follow-up questions, supplemental packages, dispute or restriction decisions, request tracker, and related SOX records.\n\n**Procedure**\n1. Clarify ambiguous wording and dates with the auditor, identify the authoritative source and preparer, detect duplicate or superseded requests, assess sensitive data, agree delivery format, and set preparation and review milestones.\n2. Generate or collect support with reproducible parameters, reconcile totals and populations, validate dates and identifiers, explain transformations, remove out-of-scope sensitive data, preserve source versions, and identify limitations.\n3. Reperform key reconciliations, inspect samples of source agreement, confirm no privileged or out-of-scope data is included, verify explanations are factual, approve the exact version, and transmit through the authorized channel.\n4. Confirm the tracker reflects the exact response and status, link all clarifications and supplements, ensure superseded versions cannot be mistaken for final, assign open questions, and preserve the secure audit trail.\n\n**Record in AssureSwarm**\n1. Capture request reference, exact scope, period, requested format, purpose, auditor contact, preparer, reviewer, source system, confidentiality, dependencies, due date, and clarification history. Also record requested population and period.\n2. Link the response package, source and query parameters, reconciliation, preparer and date, transformations, redactions, exceptions, limitations, version, and cross-references to related controls or workpapers. Also record prepared response reference.\n3. Capture the release decision, reviewer, approved version and hash or identifier, reconciliation checks, restrictions, delivery channel, recipient, timestamp, portal confirmation, and any required revision.\n4. Document the authorized reviewer, closure status, final package and delivery reference, auditor receipt, clarifications, supplemental versions, open items, owners, due dates, restrictions, and archive location. Also record request closure status.\n\n**Exit criteria**\nPBC release authority provides approval: The request is unambiguous and owned, sensitive handling is defined, duplicates are resolved, and the preparer can produce the requested support from an authoritative source. The response matches the request and authoritative records, reconciliation and handling are evidenced, and differences or limitations are explicit for quality review. An approver authorizes the exact package and secure delivery is evidenced, or the request remains held with specific revision or escalation requirements. The authorized reviewer accepts a complete request trail and accurate status; closure evidences request handling and does not imply auditor acceptance of management’s broader controls.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","name":"External Audit Support & PBC — Identity and Access Management Audit — current cycle","templateName":"External Audit Support & PBC","templateSourceId":"coworkcanvas:template:sox-pbc","description":"External Audit Support & PBC for Identity and Access Management Audit (current cycle).","status":"ACTIVE","displayOrder":402,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve PBC request closure","description":null,"summary":null,"instructions":"**Objective**\nApprove PBC request closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the auditor request list and correspondence, prior submissions, SOX scope, control and process records, data owners, retention requirements, confidentiality rules, and reporting calendar.\n2. Use the validated request, authoritative reports and documents, source-system extracts, report parameters, reconciliations, prior submissions, retention rules, and approved secure workspace.\n3. Review the request and clarification history, prepared package, reconciliation, source parameters, redactions, limitations, related submissions, legal or security restrictions, and delivery protocol.\n4. Review the released response, delivery evidence, auditor acknowledgment, follow-up questions, supplemental packages, dispute or restriction decisions, request tracker, and related SOX records.\n\n**Procedure**\n1. Clarify ambiguous wording and dates with the auditor, identify the authoritative source and preparer, detect duplicate or superseded requests, assess sensitive data, agree delivery format, and set preparation and review milestones.\n2. Generate or collect support with reproducible parameters, reconcile totals and populations, validate dates and identifiers, explain transformations, remove out-of-scope sensitive data, preserve source versions, and identify limitations.\n3. Reperform key reconciliations, inspect samples of source agreement, confirm no privileged or out-of-scope data is included, verify explanations are factual, approve the exact version, and transmit through the authorized channel.\n4. Confirm the tracker reflects the exact response and status, link all clarifications and supplements, ensure superseded versions cannot be mistaken for final, assign open questions, and preserve the secure audit trail.\n\n**Record in AssureSwarm**\n1. Capture request reference, exact scope, period, requested format, purpose, auditor contact, preparer, reviewer, source system, confidentiality, dependencies, due date, and clarification history. Also record requested population and period.\n2. Link the response package, source and query parameters, reconciliation, preparer and date, transformations, redactions, exceptions, limitations, version, and cross-references to related controls or workpapers. Also record prepared response reference.\n3. Capture the release decision, reviewer, approved version and hash or identifier, reconciliation checks, restrictions, delivery channel, recipient, timestamp, portal confirmation, and any required revision.\n4. Document the authorized reviewer, closure status, final package and delivery reference, auditor receipt, clarifications, supplemental versions, open items, owners, due dates, restrictions, and archive location. Also record request closure status.\n\n**Exit criteria**\nPBC release authority provides approval: The request is unambiguous and owned, sensitive handling is defined, duplicates are resolved, and the preparer can produce the requested support from an authoritative source. The response matches the request and authoritative records, reconciliation and handling are evidenced, and differences or limitations are explicit for quality review. An approver authorizes the exact package and secure delivery is evidenced, or the request remains held with specific revision or escalation requirements. The authorized reviewer accepts a complete request trail and accurate status; closure evidences request handling and does not imply auditor acceptance of management’s broader controls.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Procure to Pay Audit","itemType":"audit","name":"External Audit Support & PBC — Procure to Pay Audit — prior cycle","templateName":"External Audit Support & PBC","templateSourceId":"coworkcanvas:template:sox-pbc","description":"External Audit Support & PBC for Procure to Pay Audit (prior cycle).","status":"COMPLETED","displayOrder":403,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve PBC request closure","description":null,"summary":null,"instructions":"**Objective**\nApprove PBC request closure. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the auditor request list and correspondence, prior submissions, SOX scope, control and process records, data owners, retention requirements, confidentiality rules, and reporting calendar.\n2. Use the validated request, authoritative reports and documents, source-system extracts, report parameters, reconciliations, prior submissions, retention rules, and approved secure workspace.\n3. Review the request and clarification history, prepared package, reconciliation, source parameters, redactions, limitations, related submissions, legal or security restrictions, and delivery protocol.\n4. Review the released response, delivery evidence, auditor acknowledgment, follow-up questions, supplemental packages, dispute or restriction decisions, request tracker, and related SOX records.\n\n**Procedure**\n1. Clarify ambiguous wording and dates with the auditor, identify the authoritative source and preparer, detect duplicate or superseded requests, assess sensitive data, agree delivery format, and set preparation and review milestones.\n2. Generate or collect support with reproducible parameters, reconcile totals and populations, validate dates and identifiers, explain transformations, remove out-of-scope sensitive data, preserve source versions, and identify limitations.\n3. Reperform key reconciliations, inspect samples of source agreement, confirm no privileged or out-of-scope data is included, verify explanations are factual, approve the exact version, and transmit through the authorized channel.\n4. Confirm the tracker reflects the exact response and status, link all clarifications and supplements, ensure superseded versions cannot be mistaken for final, assign open questions, and preserve the secure audit trail.\n\n**Record in AssureSwarm**\n1. Capture request reference, exact scope, period, requested format, purpose, auditor contact, preparer, reviewer, source system, confidentiality, dependencies, due date, and clarification history. Also record requested population and period.\n2. Link the response package, source and query parameters, reconciliation, preparer and date, transformations, redactions, exceptions, limitations, version, and cross-references to related controls or workpapers. Also record prepared response reference.\n3. Capture the release decision, reviewer, approved version and hash or identifier, reconciliation checks, restrictions, delivery channel, recipient, timestamp, portal confirmation, and any required revision.\n4. Document the authorized reviewer, closure status, final package and delivery reference, auditor receipt, clarifications, supplemental versions, open items, owners, due dates, restrictions, and archive location. Also record request closure status.\n\n**Exit criteria**\nPBC release authority provides approval: The request is unambiguous and owned, sensitive handling is defined, duplicates are resolved, and the preparer can produce the requested support from an authoritative source. The response matches the request and authoritative records, reconciliation and handling are evidenced, and differences or limitations are explicit for quality review. An approver authorizes the exact package and secure delivery is evidenced, or the request remains held with specific revision or escalation requirements. The authorized reviewer accepts a complete request trail and accurate status; closure evidences request handling and does not imply auditor acceptance of management’s broader controls.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Financial Close and Consolidation","itemType":"process","name":"Process Walkthrough & Design Assessment — Financial Close and Consolidation — next cycle","templateName":"Process Walkthrough & Design Assessment","templateSourceId":"coworkcanvas:template:sox-walkthrough","description":"Process Walkthrough & Design Assessment for Financial Close and Consolidation (next cycle).","status":"DRAFT","displayOrder":411,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Trace transactions and close activities","description":null,"summary":null,"instructions":"**Objective**\nTrace transactions and close activities. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review SOX scoping, significant accounts and disclosures, relevant assertions, prior narratives, risk-control matrix, entity and IT dependencies, deficiencies, changes, and auditor requests.\n2. Use selected source documents, system records, journal entries, reconciliations, reports, approvals, interfaces, spreadsheets, narrative, flowchart, and knowledgeable personnel.\n\n**Procedure**\n1. Reconcile the Process item to current SOX scope, identify material transaction streams and close activities, select representative transactions, confirm process and control owners, and surface changes since prior testing.\n2. Follow identifiers and amounts across each handoff, inspect evidence of approvals and review, observe information-produced-by-entity dependencies, inquire about exceptions and overrides, and compare practice to documentation.\n\n**Record in AssureSwarm**\n1. Capture fiscal period, cycles, assertions, locations, applications, key reports, service organizations, selected transactions, stakeholders, changes, exclusions, and known limitations. Also record in-scope cycles and locations.\n2. Link the transaction trails and evidence, identify performers and reviewers, record system and manual steps, report logic, deviations, changes, missing evidence, and follow-up by assertion. Also record transaction trace reference.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides expertise: The walkthrough boundary aligns to approved ICFR scope, selected transactions cover material paths, and dependencies or exclusions requiring governance attention are assigned. Each selected item is traceable to the financial records, observed practice is reconciled to the narrative, and unexplained deviations or missing support have owners and due dates.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Financial Close and Consolidation","itemType":"process","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve SOX walkthrough record","description":null,"summary":null,"instructions":"**Objective**\nApprove SOX walkthrough record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the traced transactions, current risk-control matrix, control descriptions, owners, frequencies, evidence, precision criteria, information dependencies, prior findings, and process changes.\n2. Review scope, trace evidence, updated process documents, control evaluations, change analysis, gaps, proposed matrix updates, management responses, and linked deficiency work.\n\n**Procedure**\n1. Assess who performs and reviews each control, what triggers it, population completeness, threshold and follow-up precision, segregation of duties, evidence retention, and whether implementation is demonstrated for the walkthrough item.\n2. Confirm material transaction streams and assertions were addressed, trace conclusions to evidence, ensure gaps remain visible, reconcile document versions and mappings, and return unsupported conclusions for correction.\n\n**Record in AssureSwarm**\n1. Document the design result by control, rationale, walkthrough evidence, assertion coverage, gaps, compensating activities, proposed mapping changes, and linked deficiency or action references. Also record design assessment result.\n2. Capture the authorized reviewer, final narrative and matrix references, walkthrough summary, design observations, changes, linked deficiencies or actions, owners, due dates, and planned testing handoff.\n\n**Exit criteria**\nIndependent design reviewer provides approval: An approver accepts the documented design and implementation observations, all gaps are routed for evaluation, and no operating-effectiveness conclusion is inferred from the walkthrough. The authorized reviewer accepts a complete ICFR walkthrough record, linked records can be updated consistently, and closure does not claim an audit opinion or operating effectiveness.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Financial Close and Consolidation","itemType":"process","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Record to Report","itemType":"process","name":"Process Walkthrough & Design Assessment — Record to Report — current cycle","templateName":"Process Walkthrough & Design Assessment","templateSourceId":"coworkcanvas:template:sox-walkthrough","description":"Process Walkthrough & Design Assessment for Record to Report (current cycle).","status":"ACTIVE","displayOrder":412,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Trace transactions and close activities","description":null,"summary":null,"instructions":"**Objective**\nTrace transactions and close activities. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review SOX scoping, significant accounts and disclosures, relevant assertions, prior narratives, risk-control matrix, entity and IT dependencies, deficiencies, changes, and auditor requests.\n2. Use selected source documents, system records, journal entries, reconciliations, reports, approvals, interfaces, spreadsheets, narrative, flowchart, and knowledgeable personnel.\n\n**Procedure**\n1. Reconcile the Process item to current SOX scope, identify material transaction streams and close activities, select representative transactions, confirm process and control owners, and surface changes since prior testing.\n2. Follow identifiers and amounts across each handoff, inspect evidence of approvals and review, observe information-produced-by-entity dependencies, inquire about exceptions and overrides, and compare practice to documentation.\n\n**Record in AssureSwarm**\n1. Capture fiscal period, cycles, assertions, locations, applications, key reports, service organizations, selected transactions, stakeholders, changes, exclusions, and known limitations. Also record in-scope cycles and locations.\n2. Link the transaction trails and evidence, identify performers and reviewers, record system and manual steps, report logic, deviations, changes, missing evidence, and follow-up by assertion. Also record transaction trace reference.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides expertise: The walkthrough boundary aligns to approved ICFR scope, selected transactions cover material paths, and dependencies or exclusions requiring governance attention are assigned. Each selected item is traceable to the financial records, observed practice is reconciled to the narrative, and unexplained deviations or missing support have owners and due dates.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Record to Report","itemType":"process","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve SOX walkthrough record","description":null,"summary":null,"instructions":"**Objective**\nApprove SOX walkthrough record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the traced transactions, current risk-control matrix, control descriptions, owners, frequencies, evidence, precision criteria, information dependencies, prior findings, and process changes.\n2. Review scope, trace evidence, updated process documents, control evaluations, change analysis, gaps, proposed matrix updates, management responses, and linked deficiency work.\n\n**Procedure**\n1. Assess who performs and reviews each control, what triggers it, population completeness, threshold and follow-up precision, segregation of duties, evidence retention, and whether implementation is demonstrated for the walkthrough item.\n2. Confirm material transaction streams and assertions were addressed, trace conclusions to evidence, ensure gaps remain visible, reconcile document versions and mappings, and return unsupported conclusions for correction.\n\n**Record in AssureSwarm**\n1. Document the design result by control, rationale, walkthrough evidence, assertion coverage, gaps, compensating activities, proposed mapping changes, and linked deficiency or action references. Also record design assessment result.\n2. Capture the authorized reviewer, final narrative and matrix references, walkthrough summary, design observations, changes, linked deficiencies or actions, owners, due dates, and planned testing handoff.\n\n**Exit criteria**\nIndependent design reviewer provides approval: An approver accepts the documented design and implementation observations, all gaps are routed for evaluation, and no operating-effectiveness conclusion is inferred from the walkthrough. The authorized reviewer accepts a complete ICFR walkthrough record, linked records can be updated consistently, and closure does not claim an audit opinion or operating effectiveness.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Record to Report","itemType":"process","kind":"related"},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Revenue Recognition","itemType":"process","name":"Process Walkthrough & Design Assessment — Revenue Recognition — prior cycle","templateName":"Process Walkthrough & Design Assessment","templateSourceId":"coworkcanvas:template:sox-walkthrough","description":"Process Walkthrough & Design Assessment for Revenue Recognition (prior cycle).","status":"COMPLETED","displayOrder":413,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Trace transactions and close activities","description":null,"summary":null,"instructions":"**Objective**\nTrace transactions and close activities. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review SOX scoping, significant accounts and disclosures, relevant assertions, prior narratives, risk-control matrix, entity and IT dependencies, deficiencies, changes, and auditor requests.\n2. Use selected source documents, system records, journal entries, reconciliations, reports, approvals, interfaces, spreadsheets, narrative, flowchart, and knowledgeable personnel.\n\n**Procedure**\n1. Reconcile the Process item to current SOX scope, identify material transaction streams and close activities, select representative transactions, confirm process and control owners, and surface changes since prior testing.\n2. Follow identifiers and amounts across each handoff, inspect evidence of approvals and review, observe information-produced-by-entity dependencies, inquire about exceptions and overrides, and compare practice to documentation.\n\n**Record in AssureSwarm**\n1. Capture fiscal period, cycles, assertions, locations, applications, key reports, service organizations, selected transactions, stakeholders, changes, exclusions, and known limitations. Also record in-scope cycles and locations.\n2. Link the transaction trails and evidence, identify performers and reviewers, record system and manual steps, report logic, deviations, changes, missing evidence, and follow-up by assertion. Also record transaction trace reference.\n\n**Exit criteria**\nProcess owner and walkthrough specialist provides expertise: The walkthrough boundary aligns to approved ICFR scope, selected transactions cover material paths, and dependencies or exclusions requiring governance attention are assigned. Each selected item is traceable to the financial records, observed practice is reconciled to the narrative, and unexplained deviations or missing support have owners and due dates.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Revenue Recognition","itemType":"process","kind":"related"},{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve SOX walkthrough record","description":null,"summary":null,"instructions":"**Objective**\nApprove SOX walkthrough record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the traced transactions, current risk-control matrix, control descriptions, owners, frequencies, evidence, precision criteria, information dependencies, prior findings, and process changes.\n2. Review scope, trace evidence, updated process documents, control evaluations, change analysis, gaps, proposed matrix updates, management responses, and linked deficiency work.\n\n**Procedure**\n1. Assess who performs and reviews each control, what triggers it, population completeness, threshold and follow-up precision, segregation of duties, evidence retention, and whether implementation is demonstrated for the walkthrough item.\n2. Confirm material transaction streams and assertions were addressed, trace conclusions to evidence, ensure gaps remain visible, reconcile document versions and mappings, and return unsupported conclusions for correction.\n\n**Record in AssureSwarm**\n1. Document the design result by control, rationale, walkthrough evidence, assertion coverage, gaps, compensating activities, proposed mapping changes, and linked deficiency or action references. Also record design assessment result.\n2. Capture the authorized reviewer, final narrative and matrix references, walkthrough summary, design observations, changes, linked deficiencies or actions, owners, due dates, and planned testing handoff.\n\n**Exit criteria**\nIndependent design reviewer provides approval: An approver accepts the documented design and implementation observations, all gaps are routed for evaluation, and no operating-effectiveness conclusion is inferred from the walkthrough. The authorized reviewer accepts a complete ICFR walkthrough record, linked records can be updated consistently, and closure does not claim an audit opinion or operating effectiveness.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Revenue Recognition","itemType":"process","kind":"related"},{"itemTitle":"Revenue Recognition Audit","itemType":"audit","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","name":"Year-End Planning & Roll-Forward — FY2026 SOX Annual Program — next cycle","templateName":"Year-End Planning & Roll-Forward","templateSourceId":"coworkcanvas:template:sox-ye-planning","description":"Year-End Planning & Roll-Forward for FY2026 SOX Annual Program (next cycle).","status":"DRAFT","displayOrder":421,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Design roll-forward and year-end work","description":null,"summary":null,"instructions":"**Objective**\nDesign roll-forward and year-end work. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review annual scope and plan, interim testing tracker, reviewed workpapers, exceptions, deficiencies, remediation, changes, new entities or systems, auditor requests, control calendars, and close timetable.\n2. Use reconciled interim status, control frequencies, last test dates, remaining populations, risk and assertion mapping, changes, exceptions, deficiencies, remediation evidence, close activities, and methodology.\n\n**Procedure**\n1. Reconcile planned controls to completed and reviewed work, identify remaining periods and populations, confirm unresolved exceptions and remediation status, assess changes since interim, and validate owner availability and due dates.\n2. Determine where inquiry and change confirmation are sufficient versus additional selection or reperformance, plan year-end-only controls, define population reconciliation, schedule remediation retests, and avoid unsupported reliance on elapsed interim work.\n\n**Record in AssureSwarm**\n1. Capture the year-end period, interim status reference, completed and remaining coverage, changes, exceptions, deficiencies, remediation status, missing evidence, owners, and critical dates.\n2. Document the procedure and basis by control, remaining period, population, selection method, change checks, year-end evidence, remediation dependencies, preparer, reviewer, and due date. Also record roll-forward basis.\n\n**Exit criteria**\nEngagement lead provides expertise: The interim record reconciles to the approved plan, remaining work is accurately identified, and material changes or gaps are visible for risk reassessment. Every in-scope control has a risk-responsive year-end disposition, rationale is specific to evidence and change, and unaddressed coverage gaps have owners.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve year-end plan","description":null,"summary":null,"instructions":"**Objective**\nApprove year-end plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the control-specific strategy, PBC tracker, population owners, financial close calendar, staffing and specialists, external auditor coordination, open deficiencies, remediation dates, and committee schedule.\n2. Review all stage records, interim tracker, control strategies, readiness decision, approved conditions, PBC and review calendars, deficiency status, auditor coordination, and unresolved limitations.\n\n**Procedure**\n1. Challenge feasibility and sequencing, confirm access and accountable owners, prioritize high-risk and year-end-only controls, set escalation thresholds, resolve conflicts with close activities, and document conditions that could prevent timely completion.\n2. Trace remaining work to in-scope controls and risks, verify strategies reflect frequency and change, confirm conditions are assigned, reconcile dates and ownership, and return unsupported shortcuts or missing coverage for correction.\n\n**Record in AssureSwarm**\n1. Capture the readiness decision, conditions, critical path, evidence owners, staffing, review schedule, auditor dependencies, deficiency and remediation milestones, escalations, and due dates.\n2. Document the authorized reviewer, final year-end plan reference, remaining coverage, critical dates, resources, conditions, deficiencies, remediation and auditor dependencies, owners, and escalation route. Also record year-end plan summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts a feasible year-end execution path or records specific blockers, conditions, owners, and escalation before work is represented as ready. The authorized reviewer authorize the documented year-end work, while plan closure does not establish management assessment, an audit opinion, or operating effectiveness.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"FY2026 SOX Annual Program","itemType":"audit","kind":"related"},{"itemTitle":"Account Reconciliation Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Identity and Access Management Audit","itemType":"audit","name":"Year-End Planning & Roll-Forward — Identity and Access Management Audit — current cycle","templateName":"Year-End Planning & Roll-Forward","templateSourceId":"coworkcanvas:template:sox-ye-planning","description":"Year-End Planning & Roll-Forward for Identity and Access Management Audit (current cycle).","status":"ACTIVE","displayOrder":422,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Design roll-forward and year-end work","description":null,"summary":null,"instructions":"**Objective**\nDesign roll-forward and year-end work. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review annual scope and plan, interim testing tracker, reviewed workpapers, exceptions, deficiencies, remediation, changes, new entities or systems, auditor requests, control calendars, and close timetable.\n2. Use reconciled interim status, control frequencies, last test dates, remaining populations, risk and assertion mapping, changes, exceptions, deficiencies, remediation evidence, close activities, and methodology.\n\n**Procedure**\n1. Reconcile planned controls to completed and reviewed work, identify remaining periods and populations, confirm unresolved exceptions and remediation status, assess changes since interim, and validate owner availability and due dates.\n2. Determine where inquiry and change confirmation are sufficient versus additional selection or reperformance, plan year-end-only controls, define population reconciliation, schedule remediation retests, and avoid unsupported reliance on elapsed interim work.\n\n**Record in AssureSwarm**\n1. Capture the year-end period, interim status reference, completed and remaining coverage, changes, exceptions, deficiencies, remediation status, missing evidence, owners, and critical dates.\n2. Document the procedure and basis by control, remaining period, population, selection method, change checks, year-end evidence, remediation dependencies, preparer, reviewer, and due date. Also record roll-forward basis.\n\n**Exit criteria**\nEngagement lead provides expertise: The interim record reconciles to the approved plan, remaining work is accurately identified, and material changes or gaps are visible for risk reassessment. Every in-scope control has a risk-responsive year-end disposition, rationale is specific to evidence and change, and unaddressed coverage gaps have owners.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve year-end plan","description":null,"summary":null,"instructions":"**Objective**\nApprove year-end plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the control-specific strategy, PBC tracker, population owners, financial close calendar, staffing and specialists, external auditor coordination, open deficiencies, remediation dates, and committee schedule.\n2. Review all stage records, interim tracker, control strategies, readiness decision, approved conditions, PBC and review calendars, deficiency status, auditor coordination, and unresolved limitations.\n\n**Procedure**\n1. Challenge feasibility and sequencing, confirm access and accountable owners, prioritize high-risk and year-end-only controls, set escalation thresholds, resolve conflicts with close activities, and document conditions that could prevent timely completion.\n2. Trace remaining work to in-scope controls and risks, verify strategies reflect frequency and change, confirm conditions are assigned, reconcile dates and ownership, and return unsupported shortcuts or missing coverage for correction.\n\n**Record in AssureSwarm**\n1. Capture the readiness decision, conditions, critical path, evidence owners, staffing, review schedule, auditor dependencies, deficiency and remediation milestones, escalations, and due dates.\n2. Document the authorized reviewer, final year-end plan reference, remaining coverage, critical dates, resources, conditions, deficiencies, remediation and auditor dependencies, owners, and escalation route. Also record year-end plan summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts a feasible year-end execution path or records specific blockers, conditions, owners, and escalation before work is represented as ready. The authorized reviewer authorize the documented year-end work, while plan closure does not establish management assessment, an audit opinion, or operating effectiveness.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Identity and Access Management Audit","itemType":"audit","kind":"related"},{"itemTitle":"Emergency Access Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Procure to Pay Audit","itemType":"audit","name":"Year-End Planning & Roll-Forward — Procure to Pay Audit — prior cycle","templateName":"Year-End Planning & Roll-Forward","templateSourceId":"coworkcanvas:template:sox-ye-planning","description":"Year-End Planning & Roll-Forward for Procure to Pay Audit (prior cycle).","status":"COMPLETED","displayOrder":423,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Design roll-forward and year-end work","description":null,"summary":null,"instructions":"**Objective**\nDesign roll-forward and year-end work. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review annual scope and plan, interim testing tracker, reviewed workpapers, exceptions, deficiencies, remediation, changes, new entities or systems, auditor requests, control calendars, and close timetable.\n2. Use reconciled interim status, control frequencies, last test dates, remaining populations, risk and assertion mapping, changes, exceptions, deficiencies, remediation evidence, close activities, and methodology.\n\n**Procedure**\n1. Reconcile planned controls to completed and reviewed work, identify remaining periods and populations, confirm unresolved exceptions and remediation status, assess changes since interim, and validate owner availability and due dates.\n2. Determine where inquiry and change confirmation are sufficient versus additional selection or reperformance, plan year-end-only controls, define population reconciliation, schedule remediation retests, and avoid unsupported reliance on elapsed interim work.\n\n**Record in AssureSwarm**\n1. Capture the year-end period, interim status reference, completed and remaining coverage, changes, exceptions, deficiencies, remediation status, missing evidence, owners, and critical dates.\n2. Document the procedure and basis by control, remaining period, population, selection method, change checks, year-end evidence, remediation dependencies, preparer, reviewer, and due date. Also record roll-forward basis.\n\n**Exit criteria**\nEngagement lead provides expertise: The interim record reconciles to the approved plan, remaining work is accurately identified, and material changes or gaps are visible for risk reassessment. Every in-scope control has a risk-responsive year-end disposition, rationale is specific to evidence and change, and unaddressed coverage gaps have owners.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve year-end plan","description":null,"summary":null,"instructions":"**Objective**\nApprove year-end plan. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the control-specific strategy, PBC tracker, population owners, financial close calendar, staffing and specialists, external auditor coordination, open deficiencies, remediation dates, and committee schedule.\n2. Review all stage records, interim tracker, control strategies, readiness decision, approved conditions, PBC and review calendars, deficiency status, auditor coordination, and unresolved limitations.\n\n**Procedure**\n1. Challenge feasibility and sequencing, confirm access and accountable owners, prioritize high-risk and year-end-only controls, set escalation thresholds, resolve conflicts with close activities, and document conditions that could prevent timely completion.\n2. Trace remaining work to in-scope controls and risks, verify strategies reflect frequency and change, confirm conditions are assigned, reconcile dates and ownership, and return unsupported shortcuts or missing coverage for correction.\n\n**Record in AssureSwarm**\n1. Capture the readiness decision, conditions, critical path, evidence owners, staffing, review schedule, auditor dependencies, deficiency and remediation milestones, escalations, and due dates.\n2. Document the authorized reviewer, final year-end plan reference, remaining coverage, critical dates, resources, conditions, deficiencies, remediation and auditor dependencies, owners, and escalation route. Also record year-end plan summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts a feasible year-end execution path or records specific blockers, conditions, owners, and escalation before work is represented as ready. The authorized reviewer authorize the documented year-end work, while plan closure does not establish management assessment, an audit opinion, or operating effectiveness.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Procure to Pay Audit","itemType":"audit","kind":"related"},{"itemTitle":"Change Migration Reconciliation","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"GOB Security Monitoring","itemType":"system","name":"SOC Report, Subservice & CUEC Review — GOB Security Monitoring — next cycle","templateName":"SOC Report, Subservice & CUEC Review","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","description":"SOC Report, Subservice & CUEC Review for GOB Security Monitoring (next cycle).","status":"DRAFT","displayOrder":431,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Evaluate opinion, controls, and exceptions","description":null,"summary":null,"instructions":"**Objective**\nEvaluate opinion, controls, and exceptions. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, current SOC report and bridge letter, contract and service description, architecture and data flows, relevant processes and controls, user population, prior review, and reporting period.\n2. Use the scoped report, independent auditor opinion, system description, control matrix, test procedures and results, exceptions, management responses, subsequent-event disclosure, bridge letter, and customer risk-control mapping.\n\n**Procedure**\n1. Verify report authenticity and period, compare covered services and locations to actual use, identify scope exclusions and boundary differences, determine bridge-period needs, map business dependencies, and flag stale or missing reports.\n2. Read the opinion and basis, map relevant controls to dependencies, analyze exception populations and impact, evaluate testing periods and methods, assess subsequent changes, challenge unsupported remediation claims, and identify reliance limitations.\n\n**Record in AssureSwarm**\n1. Capture report type, auditor, opinion date and period, criteria, services, locations, actual-use alignment, boundary differences, bridge coverage, excluded components, reliance purpose, and information gaps. Also record scope alignment.\n2. Document the opinion result, relevant controls and criteria, exceptions and affected populations, management responses, period limitations, subsequent events, mapping references, reliance implications, and follow-up requests. Also record report evaluation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The report is identified and aligned to actual service use, scope and period gaps are explicit, and the evidence package is sufficient for detailed evaluation. The opinion and testing results are evaluated against actual reliance needs, material exceptions and limitations remain visible, and subservice and CUEC analysis can proceed.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"GOB Security Monitoring","itemType":"system","kind":"related"},{"itemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve SOC review record","description":null,"summary":null,"instructions":"**Objective**\nApprove SOC review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the report evaluation, subservice disclosures, carve-out or inclusive method, complementary subservice controls, CUEC list, customer policies and controls, test results, contracts, architecture, and open exceptions.\n2. Review all stage records, report and bridge evidence, mappings, exception analysis, subservice and CUEC conclusions, customer control support, linked issues, and monitoring commitments.\n\n**Procedure**\n1. Map each relevant CUEC to an owned control and evidence, assess operating support, trace subservice dependencies, evaluate uncovered responsibilities, determine compensating measures, define reliance limits, and create linked issues for material gaps.\n2. Trace each reliance conclusion to report and customer evidence, verify gaps and exceptions are routed, reconcile owners and dates, confirm report-period limitations remain visible, and return unsupported analysis for correction.\n\n**Record in AssureSwarm**\n1. Record CUEC status and mappings, control owners and evidence, subservice method and dependencies, gaps, compensating controls, reliance response, linked issues, monitoring requirements, owners, and due dates.\n2. Capture the authorized reviewer, review summary, report period and opinion, reliance response, material exceptions, CUEC and subservice status, linked issues, monitoring dates, owners, and evidence references.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts the documented responsibility and reliance response, all relevant CUECs and subservices are addressed, and unsupported coverage remains an explicit gap. The authorized reviewer accepts the SOC review as a traceable analysis record, related system and control records can be updated consistently, and closure does not establish assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"GOB Security Monitoring","itemType":"system","kind":"related"},{"itemTitle":"Anti-malware / endpoint protection deployed on personnel endpoints","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Lucille Identity Cloud","itemType":"system","name":"SOC Report, Subservice & CUEC Review — Lucille Identity Cloud — current cycle","templateName":"SOC Report, Subservice & CUEC Review","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","description":"SOC Report, Subservice & CUEC Review for Lucille Identity Cloud (current cycle).","status":"ACTIVE","displayOrder":432,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Evaluate opinion, controls, and exceptions","description":null,"summary":null,"instructions":"**Objective**\nEvaluate opinion, controls, and exceptions. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, current SOC report and bridge letter, contract and service description, architecture and data flows, relevant processes and controls, user population, prior review, and reporting period.\n2. Use the scoped report, independent auditor opinion, system description, control matrix, test procedures and results, exceptions, management responses, subsequent-event disclosure, bridge letter, and customer risk-control mapping.\n\n**Procedure**\n1. Verify report authenticity and period, compare covered services and locations to actual use, identify scope exclusions and boundary differences, determine bridge-period needs, map business dependencies, and flag stale or missing reports.\n2. Read the opinion and basis, map relevant controls to dependencies, analyze exception populations and impact, evaluate testing periods and methods, assess subsequent changes, challenge unsupported remediation claims, and identify reliance limitations.\n\n**Record in AssureSwarm**\n1. Capture report type, auditor, opinion date and period, criteria, services, locations, actual-use alignment, boundary differences, bridge coverage, excluded components, reliance purpose, and information gaps. Also record scope alignment.\n2. Document the opinion result, relevant controls and criteria, exceptions and affected populations, management responses, period limitations, subsequent events, mapping references, reliance implications, and follow-up requests. Also record report evaluation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The report is identified and aligned to actual service use, scope and period gaps are explicit, and the evidence package is sufficient for detailed evaluation. The opinion and testing results are evaluated against actual reliance needs, material exceptions and limitations remain visible, and subservice and CUEC analysis can proceed.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"},{"itemTitle":"Authenticate all users with multi-factor authentication","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve SOC review record","description":null,"summary":null,"instructions":"**Objective**\nApprove SOC review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the report evaluation, subservice disclosures, carve-out or inclusive method, complementary subservice controls, CUEC list, customer policies and controls, test results, contracts, architecture, and open exceptions.\n2. Review all stage records, report and bridge evidence, mappings, exception analysis, subservice and CUEC conclusions, customer control support, linked issues, and monitoring commitments.\n\n**Procedure**\n1. Map each relevant CUEC to an owned control and evidence, assess operating support, trace subservice dependencies, evaluate uncovered responsibilities, determine compensating measures, define reliance limits, and create linked issues for material gaps.\n2. Trace each reliance conclusion to report and customer evidence, verify gaps and exceptions are routed, reconcile owners and dates, confirm report-period limitations remain visible, and return unsupported analysis for correction.\n\n**Record in AssureSwarm**\n1. Record CUEC status and mappings, control owners and evidence, subservice method and dependencies, gaps, compensating controls, reliance response, linked issues, monitoring requirements, owners, and due dates.\n2. Capture the authorized reviewer, review summary, report period and opinion, reliance response, material exceptions, CUEC and subservice status, linked issues, monitoring dates, owners, and evidence references.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts the documented responsibility and reliance response, all relevant CUECs and subservices are addressed, and unsupported coverage remains an explicit gap. The authorized reviewer accepts the SOC review as a traceable analysis record, related system and control records can be updated consistently, and closure does not establish assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lucille Identity Cloud","itemType":"system","kind":"related"},{"itemTitle":"Authenticate all users with multi-factor authentication","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Never Nude HR Platform","itemType":"system","name":"SOC Report, Subservice & CUEC Review — Never Nude HR Platform — prior cycle","templateName":"SOC Report, Subservice & CUEC Review","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","description":"SOC Report, Subservice & CUEC Review for Never Nude HR Platform (prior cycle).","status":"COMPLETED","displayOrder":433,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Evaluate opinion, controls, and exceptions","description":null,"summary":null,"instructions":"**Objective**\nEvaluate opinion, controls, and exceptions. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, current SOC report and bridge letter, contract and service description, architecture and data flows, relevant processes and controls, user population, prior review, and reporting period.\n2. Use the scoped report, independent auditor opinion, system description, control matrix, test procedures and results, exceptions, management responses, subsequent-event disclosure, bridge letter, and customer risk-control mapping.\n\n**Procedure**\n1. Verify report authenticity and period, compare covered services and locations to actual use, identify scope exclusions and boundary differences, determine bridge-period needs, map business dependencies, and flag stale or missing reports.\n2. Read the opinion and basis, map relevant controls to dependencies, analyze exception populations and impact, evaluate testing periods and methods, assess subsequent changes, challenge unsupported remediation claims, and identify reliance limitations.\n\n**Record in AssureSwarm**\n1. Capture report type, auditor, opinion date and period, criteria, services, locations, actual-use alignment, boundary differences, bridge coverage, excluded components, reliance purpose, and information gaps. Also record scope alignment.\n2. Document the opinion result, relevant controls and criteria, exceptions and affected populations, management responses, period limitations, subsequent events, mapping references, reliance implications, and follow-up requests. Also record report evaluation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The report is identified and aligned to actual service use, scope and period gaps are explicit, and the evidence package is sufficient for detailed evaluation. The opinion and testing results are evaluated against actual reliance needs, material exceptions and limitations remain visible, and subservice and CUEC analysis can proceed.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Never Nude HR Platform","itemType":"system","kind":"related"},{"itemTitle":"Annual performance and conduct evaluation per personnel","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve SOC review record","description":null,"summary":null,"instructions":"**Objective**\nApprove SOC review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the report evaluation, subservice disclosures, carve-out or inclusive method, complementary subservice controls, CUEC list, customer policies and controls, test results, contracts, architecture, and open exceptions.\n2. Review all stage records, report and bridge evidence, mappings, exception analysis, subservice and CUEC conclusions, customer control support, linked issues, and monitoring commitments.\n\n**Procedure**\n1. Map each relevant CUEC to an owned control and evidence, assess operating support, trace subservice dependencies, evaluate uncovered responsibilities, determine compensating measures, define reliance limits, and create linked issues for material gaps.\n2. Trace each reliance conclusion to report and customer evidence, verify gaps and exceptions are routed, reconcile owners and dates, confirm report-period limitations remain visible, and return unsupported analysis for correction.\n\n**Record in AssureSwarm**\n1. Record CUEC status and mappings, control owners and evidence, subservice method and dependencies, gaps, compensating controls, reliance response, linked issues, monitoring requirements, owners, and due dates.\n2. Capture the authorized reviewer, review summary, report period and opinion, reliance response, material exceptions, CUEC and subservice status, linked issues, monitoring dates, owners, and evidence references.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts the documented responsibility and reliance response, all relevant CUECs and subservices are addressed, and unsupported coverage remains an explicit gap. The authorized reviewer accepts the SOC review as a traceable analysis record, related system and control records can be updated consistently, and closure does not establish assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Never Nude HR Platform","itemType":"system","kind":"related"},{"itemTitle":"Annual performance and conduct evaluation per personnel","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Banana ERP","itemType":"system","name":"System & Third-Party Risk Review — Banana ERP — next cycle","templateName":"System & Third-Party Risk Review","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","description":"System & Third-Party Risk Review for Banana ERP (next cycle).","status":"DRAFT","displayOrder":441,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess system and third-party risk","description":null,"summary":null,"instructions":"**Objective**\nAssess system and third-party risk. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, architecture and data-flow records, inventory, contracts, service descriptions, business impact analysis, prior assessments, incidents, changes, user populations, and provider documentation.\n2. Use the confirmed scope, risk criteria, due-diligence responses, security and privacy evidence, service performance, incidents, vulnerabilities, continuity tests, contract terms, change history, monitoring, and prior findings.\n\n**Procedure**\n1. Reconcile inventory and ownership, map data types and trust boundaries, identify critical business processes and integrations, distinguish provider and customer responsibilities, identify material fourth parties, and document scope changes.\n2. Evaluate threats and business impacts, inspect control and performance evidence, assess concentration and exit risk, compare contract commitments to practice, analyze incidents and changes, and challenge ratings based only on questionnaires or attestations.\n\nMap data flows, access boundaries and system/provider dependencies explicitly and inspect associated security/control coverage.\n\n**Record in AssureSwarm**\n1. Capture the review period, system and service scope, owners, provider, environments, data classification, users, integrations, critical processes, subservices, locations, changes, exclusions, and information gaps.\n2. Document risk ratings and direction, criteria, evidence, control strengths and gaps, provider and customer responsibilities, concentration and resilience concerns, incidents, uncertainties, and prior-period comparison. Also record risk assessment.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The review boundary and responsibility model are unambiguous, critical dependencies are represented, and missing information that could affect risk is assigned. The assessment is reproducible, material gaps and uncertainty remain visible, and rating changes or reliance on provider evidence are supported before response selection.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve system risk review record","description":null,"summary":null,"instructions":"**Objective**\nApprove system risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, open findings, service roadmap, remediation commitments, contract rights, business continuity and exit plans, stakeholder needs, appetite criteria, and proposed monitoring indicators.\n2. Review every stage result, source evidence, ratings, provider and customer responsibilities, response approval, linked issues, monitoring commitments, contract actions, and information gaps.\n\n**Procedure**\n1. Compare continued use, remediation, restriction, replacement, and exception paths; define commitments and evidence; confirm decision authority; set performance and risk triggers; plan escalation and exit readiness; and create linked actions.\n2. Trace material ratings and decisions to evidence, verify commitments and dates, reconcile inventory and linked records, confirm contrary evidence remains visible, and return unsupported or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Record the decision, rationale, authorized approver, remediation commitments, monitoring indicators and cadence, contract actions, restrictions, contingency or exit steps, linked issues, owners, and due dates. Also record response decision; monitoring plan.\n2. Capture the authorized reviewer, review summary, accepted ratings and response, review effective date, monitoring cadence, provider commitments, linked issues, limitations, owners, and due dates. Also record system risk review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that the response follows from risk and criticality, decision authority is confirmed, and monitoring and action commitments are measurable. The authorized reviewer accepts the review as a traceable record of work and decisions, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Banana ERP","itemType":"system","kind":"related"},{"itemTitle":"AI agents restricted to suggestion-only pattern - no direct production writes","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Tidewell File Exchange","itemType":"system","name":"System & Third-Party Risk Review — Tidewell File Exchange — current cycle","templateName":"System & Third-Party Risk Review","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","description":"System & Third-Party Risk Review for Tidewell File Exchange (current cycle).","status":"ACTIVE","displayOrder":442,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess system and third-party risk","description":null,"summary":null,"instructions":"**Objective**\nAssess system and third-party risk. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, architecture and data-flow records, inventory, contracts, service descriptions, business impact analysis, prior assessments, incidents, changes, user populations, and provider documentation.\n2. Use the confirmed scope, risk criteria, due-diligence responses, security and privacy evidence, service performance, incidents, vulnerabilities, continuity tests, contract terms, change history, monitoring, and prior findings.\n\n**Procedure**\n1. Reconcile inventory and ownership, map data types and trust boundaries, identify critical business processes and integrations, distinguish provider and customer responsibilities, identify material fourth parties, and document scope changes.\n2. Evaluate threats and business impacts, inspect control and performance evidence, assess concentration and exit risk, compare contract commitments to practice, analyze incidents and changes, and challenge ratings based only on questionnaires or attestations.\n\nMap data flows, access boundaries and system/provider dependencies explicitly and inspect associated security/control coverage.\n\n**Record in AssureSwarm**\n1. Capture the review period, system and service scope, owners, provider, environments, data classification, users, integrations, critical processes, subservices, locations, changes, exclusions, and information gaps.\n2. Document risk ratings and direction, criteria, evidence, control strengths and gaps, provider and customer responsibilities, concentration and resilience concerns, incidents, uncertainties, and prior-period comparison. Also record risk assessment.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The review boundary and responsibility model are unambiguous, critical dependencies are represented, and missing information that could affect risk is assigned. The assessment is reproducible, material gaps and uncertainty remain visible, and rating changes or reliance on provider evidence are supported before response selection.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Tidewell File Exchange","itemType":"system","kind":"related"},{"itemTitle":"Govern security of external and cloud service use","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve system risk review record","description":null,"summary":null,"instructions":"**Objective**\nApprove system risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, open findings, service roadmap, remediation commitments, contract rights, business continuity and exit plans, stakeholder needs, appetite criteria, and proposed monitoring indicators.\n2. Review every stage result, source evidence, ratings, provider and customer responsibilities, response approval, linked issues, monitoring commitments, contract actions, and information gaps.\n\n**Procedure**\n1. Compare continued use, remediation, restriction, replacement, and exception paths; define commitments and evidence; confirm decision authority; set performance and risk triggers; plan escalation and exit readiness; and create linked actions.\n2. Trace material ratings and decisions to evidence, verify commitments and dates, reconcile inventory and linked records, confirm contrary evidence remains visible, and return unsupported or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Record the decision, rationale, authorized approver, remediation commitments, monitoring indicators and cadence, contract actions, restrictions, contingency or exit steps, linked issues, owners, and due dates. Also record response decision; monitoring plan.\n2. Capture the authorized reviewer, review summary, accepted ratings and response, review effective date, monitoring cadence, provider commitments, linked issues, limitations, owners, and due dates. Also record system risk review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that the response follows from risk and criticality, decision authority is confirmed, and monitoring and action commitments are measurable. The authorized reviewer accepts the review as a traceable record of work and decisions, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Tidewell File Exchange","itemType":"system","kind":"related"},{"itemTitle":"Govern security of external and cloud service use","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Cornballer Revenue Engine","itemType":"system","name":"System & Third-Party Risk Review — Cornballer Revenue Engine — prior cycle","templateName":"System & Third-Party Risk Review","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","description":"System & Third-Party Risk Review for Cornballer Revenue Engine (prior cycle).","status":"COMPLETED","displayOrder":443,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Assess system and third-party risk","description":null,"summary":null,"instructions":"**Objective**\nAssess system and third-party risk. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, architecture and data-flow records, inventory, contracts, service descriptions, business impact analysis, prior assessments, incidents, changes, user populations, and provider documentation.\n2. Use the confirmed scope, risk criteria, due-diligence responses, security and privacy evidence, service performance, incidents, vulnerabilities, continuity tests, contract terms, change history, monitoring, and prior findings.\n\n**Procedure**\n1. Reconcile inventory and ownership, map data types and trust boundaries, identify critical business processes and integrations, distinguish provider and customer responsibilities, identify material fourth parties, and document scope changes.\n2. Evaluate threats and business impacts, inspect control and performance evidence, assess concentration and exit risk, compare contract commitments to practice, analyze incidents and changes, and challenge ratings based only on questionnaires or attestations.\n\nMap data flows, access boundaries and system/provider dependencies explicitly and inspect associated security/control coverage.\n\n**Record in AssureSwarm**\n1. Capture the review period, system and service scope, owners, provider, environments, data classification, users, integrations, critical processes, subservices, locations, changes, exclusions, and information gaps.\n2. Document risk ratings and direction, criteria, evidence, control strengths and gaps, provider and customer responsibilities, concentration and resilience concerns, incidents, uncertainties, and prior-period comparison. Also record risk assessment.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The review boundary and responsibility model are unambiguous, critical dependencies are represented, and missing information that could affect risk is assigned. The assessment is reproducible, material gaps and uncertainty remain visible, and rating changes or reliance on provider evidence are supported before response selection.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve system risk review record","description":null,"summary":null,"instructions":"**Objective**\nApprove system risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, open findings, service roadmap, remediation commitments, contract rights, business continuity and exit plans, stakeholder needs, appetite criteria, and proposed monitoring indicators.\n2. Review every stage result, source evidence, ratings, provider and customer responsibilities, response approval, linked issues, monitoring commitments, contract actions, and information gaps.\n\n**Procedure**\n1. Compare continued use, remediation, restriction, replacement, and exception paths; define commitments and evidence; confirm decision authority; set performance and risk triggers; plan escalation and exit readiness; and create linked actions.\n2. Trace material ratings and decisions to evidence, verify commitments and dates, reconcile inventory and linked records, confirm contrary evidence remains visible, and return unsupported or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Record the decision, rationale, authorized approver, remediation commitments, monitoring indicators and cadence, contract actions, restrictions, contingency or exit steps, linked issues, owners, and due dates. Also record response decision; monitoring plan.\n2. Capture the authorized reviewer, review summary, accepted ratings and response, review effective date, monitoring cadence, provider commitments, linked issues, limitations, owners, and due dates. Also record system risk review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that the response follows from risk and criticality, decision authority is confirmed, and monitoring and action commitments are measurable. The authorized reviewer accepts the review as a traceable record of work and decisions, related records can be updated consistently, and closure is not represented as assurance.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Cornballer Revenue Engine","itemType":"system","kind":"related"},{"itemTitle":"Revenue Contract Review","itemType":"control","kind":"related"}],"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Lindsay Fünke","itemType":"personnel","name":"Transfer & Access Modification — Lindsay Fünke — current cycle","templateName":"Transfer & Access Modification","templateSourceId":"coworkcanvas:template:transfer-access-modification","description":"Transfer & Access Modification for Lindsay Fünke (current cycle).","status":"ACTIVE","displayOrder":452,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve additions and removals","description":null,"summary":null,"instructions":"**Objective**\nApprove additions and removals. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR transfer record, prior and new position descriptions, current entitlement extracts from each in-scope system, and the role profiles for both positions.\n2. Use the prior entitlement inventory, the new role profile, the entitlement catalogue, the conflict matrix, system owner approval routes, and policy on retaining prior access during transition.\n\n**Procedure**\n1. Extract current entitlements from source systems rather than from memory or prior tickets, compare against the prior role profile, identify accumulated entitlements outside any profile, and confirm the effective date against the HR record.\n2. Default to REMOVING prior-role entitlements and justify each retention explicitly, route additions and removals to their authorized approvers, test the resulting combined set against the conflict matrix, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the transfer effective date, prior and new position, the complete prior entitlement inventory per system with extract dates, entitlements held outside profile, and extraction gaps.\n2. Document additions and removals with approver and date, retentions with justification and expiry, conflicts and their disposition, privileged entitlements flagged separately, and declined requests. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The prior entitlement inventory is extracted from source systems and dated, accumulated access is visible, and extraction gaps are declared rather than assumed empty. An approver accepts that removals were considered by default rather than by exception, retentions carry justification and an expiry, and conflicts are dispositioned before provisioning.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lindsay Fünke","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve modification record","description":null,"summary":null,"instructions":"**Objective**\nApprove modification record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved delta, system administration consoles, post-change entitlement extracts, evidence of each addition and removal, and the timing expectations for transfer changes in policy.\n2. Review all stage records, the prior and post-change extracts, approvals for additions and removals, retention justifications and expiries, conflict dispositions, deviations, and outstanding items.\n\n**Procedure**\n1. Apply removals as well as additions, RE-EXTRACT entitlements after the change, reconcile the post-change state against the approved target line by line, and record residual prior-role access as a deviation rather than an oversight.\n2. Trace the post-change state to approved decisions, verify every retention carries an expiry, confirm removals actually took effect in the extract, and return unreconciled residual access with precise comments.\n\n**Record in AssureSwarm**\n1. Document applied changes per system with evidence references and dates, the post-change entitlement extract, reconciliation result, deviations with cause, and outstanding items with owners. Also record modification outcome.\n2. Capture the authorized reviewer, the modification summary, HR-backed Personnel updates specified below, retentions and their expiries, deviations accepted, outstanding items with owners, and linked issues raised.\n\nUpdate Personnel.position_title, Personnel.department and Personnel.role_effective_date only from the authoritative approved HR transfer record. Update Personnel.manager_name and Personnel.manager_personnel_key when the source establishes a changed reporting line. A transfer must not reset Personnel.engagement_start_date or Personnel.engagement_end_date; change Personnel.engagement_status only when a separate authoritative HR status event supports it. Put access execution dates, before/after entitlement inventories, approved additions/removals, retention expiries and exceptions in the markdown step result; attach approval and re-extraction evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: The post-change state reconciles to the approved target, residual prior-role access is named as a deviation, and outstanding removals carry owners and dates. The authorized reviewer accepts the modification record as evidence an access control operated for this transfer, and closure implies no assurance over entitlements in systems outside the stated scope.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Lindsay Fünke","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Maeby Fünke","itemType":"personnel","name":"Transfer & Access Modification — Maeby Fünke — prior cycle","templateName":"Transfer & Access Modification","templateSourceId":"coworkcanvas:template:transfer-access-modification","description":"Transfer & Access Modification for Maeby Fünke (prior cycle).","status":"COMPLETED","displayOrder":453,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve additions and removals","description":null,"summary":null,"instructions":"**Objective**\nApprove additions and removals. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR transfer record, prior and new position descriptions, current entitlement extracts from each in-scope system, and the role profiles for both positions.\n2. Use the prior entitlement inventory, the new role profile, the entitlement catalogue, the conflict matrix, system owner approval routes, and policy on retaining prior access during transition.\n\n**Procedure**\n1. Extract current entitlements from source systems rather than from memory or prior tickets, compare against the prior role profile, identify accumulated entitlements outside any profile, and confirm the effective date against the HR record.\n2. Default to REMOVING prior-role entitlements and justify each retention explicitly, route additions and removals to their authorized approvers, test the resulting combined set against the conflict matrix, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the transfer effective date, prior and new position, the complete prior entitlement inventory per system with extract dates, entitlements held outside profile, and extraction gaps.\n2. Document additions and removals with approver and date, retentions with justification and expiry, conflicts and their disposition, privileged entitlements flagged separately, and declined requests. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The prior entitlement inventory is extracted from source systems and dated, accumulated access is visible, and extraction gaps are declared rather than assumed empty. An approver accepts that removals were considered by default rather than by exception, retentions carry justification and an expiry, and conflicts are dispositioned before provisioning.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Maeby Fünke","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve modification record","description":null,"summary":null,"instructions":"**Objective**\nApprove modification record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved delta, system administration consoles, post-change entitlement extracts, evidence of each addition and removal, and the timing expectations for transfer changes in policy.\n2. Review all stage records, the prior and post-change extracts, approvals for additions and removals, retention justifications and expiries, conflict dispositions, deviations, and outstanding items.\n\n**Procedure**\n1. Apply removals as well as additions, RE-EXTRACT entitlements after the change, reconcile the post-change state against the approved target line by line, and record residual prior-role access as a deviation rather than an oversight.\n2. Trace the post-change state to approved decisions, verify every retention carries an expiry, confirm removals actually took effect in the extract, and return unreconciled residual access with precise comments.\n\n**Record in AssureSwarm**\n1. Document applied changes per system with evidence references and dates, the post-change entitlement extract, reconciliation result, deviations with cause, and outstanding items with owners. Also record modification outcome.\n2. Capture the authorized reviewer, the modification summary, HR-backed Personnel updates specified below, retentions and their expiries, deviations accepted, outstanding items with owners, and linked issues raised.\n\nUpdate Personnel.position_title, Personnel.department and Personnel.role_effective_date only from the authoritative approved HR transfer record. Update Personnel.manager_name and Personnel.manager_personnel_key when the source establishes a changed reporting line. A transfer must not reset Personnel.engagement_start_date or Personnel.engagement_end_date; change Personnel.engagement_status only when a separate authoritative HR status event supports it. Put access execution dates, before/after entitlement inventories, approved additions/removals, retention expiries and exceptions in the markdown step result; attach approval and re-extraction evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: The post-change state reconciles to the approved target, residual prior-role access is named as a deviation, and outstanding removals carry owners and dates. The authorized reviewer accepts the modification record as evidence an access control operated for this transfer, and closure implies no assurance over entitlements in systems outside the stated scope.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Maeby Fünke","itemType":"personnel","kind":"related"},{"itemTitle":"Banana ERP","itemType":"system","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemTitle":"Tony Wonder","itemType":"personnel","name":"Transfer & Access Modification — Tony Wonder — next cycle","templateName":"Transfer & Access Modification","templateSourceId":"coworkcanvas:template:transfer-access-modification","description":"Transfer & Access Modification for Tony Wonder (next cycle).","status":"DRAFT","displayOrder":451,"workflowType":"standard","isPublic":true,"steps":[{"stepNumber":1,"name":"Approve additions and removals","description":null,"summary":null,"instructions":"**Objective**\nApprove additions and removals. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR transfer record, prior and new position descriptions, current entitlement extracts from each in-scope system, and the role profiles for both positions.\n2. Use the prior entitlement inventory, the new role profile, the entitlement catalogue, the conflict matrix, system owner approval routes, and policy on retaining prior access during transition.\n\n**Procedure**\n1. Extract current entitlements from source systems rather than from memory or prior tickets, compare against the prior role profile, identify accumulated entitlements outside any profile, and confirm the effective date against the HR record.\n2. Default to REMOVING prior-role entitlements and justify each retention explicitly, route additions and removals to their authorized approvers, test the resulting combined set against the conflict matrix, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the transfer effective date, prior and new position, the complete prior entitlement inventory per system with extract dates, entitlements held outside profile, and extraction gaps.\n2. Document additions and removals with approver and date, retentions with justification and expiry, conflicts and their disposition, privileged entitlements flagged separately, and declined requests. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The prior entitlement inventory is extracted from source systems and dated, accumulated access is visible, and extraction gaps are declared rather than assumed empty. An approver accepts that removals were considered by default rather than by exception, retentions carry justification and an expiry, and conflicts are dispositioned before provisioning.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Tony Wonder","itemType":"personnel","kind":"related"},{"itemTitle":"GOB Security Monitoring","itemType":"system","kind":"related"}],"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}]},{"stepNumber":2,"name":"Approve modification record","description":null,"summary":null,"instructions":"**Objective**\nApprove modification record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved delta, system administration consoles, post-change entitlement extracts, evidence of each addition and removal, and the timing expectations for transfer changes in policy.\n2. Review all stage records, the prior and post-change extracts, approvals for additions and removals, retention justifications and expiries, conflict dispositions, deviations, and outstanding items.\n\n**Procedure**\n1. Apply removals as well as additions, RE-EXTRACT entitlements after the change, reconcile the post-change state against the approved target line by line, and record residual prior-role access as a deviation rather than an oversight.\n2. Trace the post-change state to approved decisions, verify every retention carries an expiry, confirm removals actually took effect in the extract, and return unreconciled residual access with precise comments.\n\n**Record in AssureSwarm**\n1. Document applied changes per system with evidence references and dates, the post-change entitlement extract, reconciliation result, deviations with cause, and outstanding items with owners. Also record modification outcome.\n2. Capture the authorized reviewer, the modification summary, HR-backed Personnel updates specified below, retentions and their expiries, deviations accepted, outstanding items with owners, and linked issues raised.\n\nUpdate Personnel.position_title, Personnel.department and Personnel.role_effective_date only from the authoritative approved HR transfer record. Update Personnel.manager_name and Personnel.manager_personnel_key when the source establishes a changed reporting line. A transfer must not reset Personnel.engagement_start_date or Personnel.engagement_end_date; change Personnel.engagement_status only when a separate authoritative HR status event supports it. Put access execution dates, before/after entitlement inventories, approved additions/removals, retention expiries and exceptions in the markdown step result; attach approval and re-extraction evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: The post-change state reconciles to the approved target, residual prior-role access is named as a deviation, and outstanding removals carry owners and dates. The authorized reviewer accepts the modification record as evidence an access control operated for this transfer, and closure implies no assurance over entitlements in systems outside the stated scope.","type":"TASK","requiredApprovals":1,"linkedItems":[{"itemTitle":"Tony Wonder","itemType":"personnel","kind":"related"},{"itemTitle":"GOB Security Monitoring","itemType":"system","kind":"related"}],"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}]}]},{"itemType":"issue","itemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","name":"Policy Exception & Risk Acceptance — AI Governance & Acceptable AI Use Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Policy exception — AI Governance & Acceptable AI Use Policy","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","kind":"related"},{"itemType":"policy","itemTitle":"AI Governance & Acceptable AI Use Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","kind":"related"},{"itemType":"policy","itemTitle":"AI Governance & Acceptable AI Use Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","kind":"related"},{"itemType":"policy","itemTitle":"AI Governance & Acceptable AI Use Policy","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","kind":"related"},{"itemType":"policy","itemTitle":"AI Governance & Acceptable AI Use Policy","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","kind":"related"},{"itemType":"policy","itemTitle":"AI Governance & Acceptable AI Use Policy","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — AI Governance & Acceptable AI Use Policy","kind":"related"},{"itemType":"policy","itemTitle":"AI Governance & Acceptable AI Use Policy","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Policy exception — Access Control Standard","name":"Policy Exception & Risk Acceptance — Access Control Standard","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Policy exception — Access Control Standard","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Access Control Standard","kind":"related"},{"itemType":"policy","itemTitle":"Access Control Standard","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Access Control Standard","kind":"related"},{"itemType":"policy","itemTitle":"Access Control Standard","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"michael.bluth@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Access Control Standard","kind":"related"},{"itemType":"policy","itemTitle":"Access Control Standard","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Access Control Standard","kind":"related"},{"itemType":"policy","itemTitle":"Access Control Standard","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Access Control Standard","kind":"related"},{"itemType":"policy","itemTitle":"Access Control Standard","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Access Control Standard","kind":"related"},{"itemType":"policy","itemTitle":"Access Control Standard","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Policy exception — Board & Governance Policy","name":"Policy Exception & Risk Acceptance — Board & Governance Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Policy exception — Board & Governance Policy","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Board & Governance Policy","kind":"related"},{"itemType":"policy","itemTitle":"Board & Governance Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"michael.bluth@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Board & Governance Policy","kind":"related"},{"itemType":"policy","itemTitle":"Board & Governance Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Board & Governance Policy","kind":"related"},{"itemType":"policy","itemTitle":"Board & Governance Policy","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Board & Governance Policy","kind":"related"},{"itemType":"policy","itemTitle":"Board & Governance Policy","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Board & Governance Policy","kind":"related"},{"itemType":"policy","itemTitle":"Board & Governance Policy","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Board & Governance Policy","kind":"related"},{"itemType":"policy","itemTitle":"Board & Governance Policy","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Policy exception — Cloud Services Security Policy","name":"Policy Exception & Risk Acceptance — Cloud Services Security Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Policy exception — Cloud Services Security Policy","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Cloud Services Security Policy","kind":"related"},{"itemType":"policy","itemTitle":"Cloud Services Security Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Cloud Services Security Policy","kind":"related"},{"itemType":"policy","itemTitle":"Cloud Services Security Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"george.michael@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Cloud Services Security Policy","kind":"related"},{"itemType":"policy","itemTitle":"Cloud Services Security Policy","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Cloud Services Security Policy","kind":"related"},{"itemType":"policy","itemTitle":"Cloud Services Security Policy","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Cloud Services Security Policy","kind":"related"},{"itemType":"policy","itemTitle":"Cloud Services Security Policy","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Cloud Services Security Policy","kind":"related"},{"itemType":"policy","itemTitle":"Cloud Services Security Policy","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Policy exception — Data Classification & Handling Policy","name":"Policy Exception & Risk Acceptance — Data Classification & Handling Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Policy exception — Data Classification & Handling Policy","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Data Classification & Handling Policy","kind":"related"},{"itemType":"policy","itemTitle":"Data Classification & Handling Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Data Classification & Handling Policy","kind":"related"},{"itemType":"policy","itemTitle":"Data Classification & Handling Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Data Classification & Handling Policy","kind":"related"},{"itemType":"policy","itemTitle":"Data Classification & Handling Policy","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Data Classification & Handling Policy","kind":"related"},{"itemType":"policy","itemTitle":"Data Classification & Handling Policy","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Data Classification & Handling Policy","kind":"related"},{"itemType":"policy","itemTitle":"Data Classification & Handling Policy","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Data Classification & Handling Policy","kind":"related"},{"itemType":"policy","itemTitle":"Data Classification & Handling Policy","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Policy exception — Financial Close Procedure","name":"Policy Exception & Risk Acceptance — Financial Close Procedure","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Policy exception — Financial Close Procedure","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Financial Close Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Financial Close Procedure","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Financial Close Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Financial Close Procedure","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"michael.bluth@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Financial Close Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Financial Close Procedure","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Financial Close Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Financial Close Procedure","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Financial Close Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Financial Close Procedure","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Financial Close Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Financial Close Procedure","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Policy exception — Incident Response Policy","name":"Policy Exception & Risk Acceptance — Incident Response Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Policy exception — Incident Response Policy","status":"DRAFT","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Incident Response Policy","kind":"related"},{"itemType":"policy","itemTitle":"Incident Response Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"michael.bluth@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Incident Response Policy","kind":"related"},{"itemType":"policy","itemTitle":"Incident Response Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Incident Response Policy","kind":"related"},{"itemType":"policy","itemTitle":"Incident Response Policy","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Incident Response Policy","kind":"related"},{"itemType":"policy","itemTitle":"Incident Response Policy","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Incident Response Policy","kind":"related"},{"itemType":"policy","itemTitle":"Incident Response Policy","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Incident Response Policy","kind":"related"},{"itemType":"policy","itemTitle":"Incident Response Policy","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","name":"Policy Exception & Risk Acceptance — Information Transfer & Leakage Prevention Policy","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Policy exception — Information Transfer & Leakage Prevention Policy","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","kind":"related"},{"itemType":"policy","itemTitle":"Information Transfer & Leakage Prevention Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","kind":"related"},{"itemType":"policy","itemTitle":"Information Transfer & Leakage Prevention Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"george.michael@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","kind":"related"},{"itemType":"policy","itemTitle":"Information Transfer & Leakage Prevention Policy","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","kind":"related"},{"itemType":"policy","itemTitle":"Information Transfer & Leakage Prevention Policy","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","kind":"related"},{"itemType":"policy","itemTitle":"Information Transfer & Leakage Prevention Policy","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Information Transfer & Leakage Prevention Policy","kind":"related"},{"itemType":"policy","itemTitle":"Information Transfer & Leakage Prevention Policy","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Policy exception — Management Review Procedure","name":"Policy Exception & Risk Acceptance — Management Review Procedure","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Policy exception — Management Review Procedure","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Management Review Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Management Review Procedure","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Management Review Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Management Review Procedure","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Management Review Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Management Review Procedure","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Management Review Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Management Review Procedure","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Management Review Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Management Review Procedure","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Policy exception — Management Review Procedure","kind":"related"},{"itemType":"policy","itemTitle":"Management Review Procedure","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Change approval waived for a revenue system release","name":"Policy Exception & Risk Acceptance — Change approval waived for a revenue system release","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Change approval waived for a revenue system release","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Change approval waived for a revenue system release","kind":"related"},{"itemType":"policy","itemTitle":"Risk Management Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"michael.bluth@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Change approval waived for a revenue system release","kind":"related"},{"itemType":"policy","itemTitle":"Risk Management Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Change approval waived for a revenue system release","kind":"related"},{"itemType":"policy","itemTitle":"Risk Management Policy","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Change approval waived for a revenue system release","kind":"related"},{"itemType":"policy","itemTitle":"Risk Management Policy","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Change approval waived for a revenue system release","kind":"related"},{"itemType":"policy","itemTitle":"Risk Management Policy","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Change approval waived for a revenue system release","kind":"related"},{"itemType":"policy","itemTitle":"Risk Management Policy","kind":"related"}]}]},{"itemType":"issue","itemTitle":"Privacy Waiver Expiring","name":"Policy Exception & Risk Acceptance — Privacy Waiver Expiring","templateSourceId":"coworkcanvas:template:policy-exception-risk-acceptance","templateName":"Policy Exception & Risk Acceptance","description":"Policy Exception & Risk Acceptance for Privacy Waiver Expiring","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess and package","type":"TASK","diagramNodeId":"assess-and-package","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Privacy Waiver Expiring","kind":"related"},{"itemType":"policy","itemTitle":"Threat Intelligence Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"policy_clause","label":"Policy and specific clause you cannot meet","type":"text","required":true},{"key":"why_not_met","label":"Why the requirement cannot be met as written","type":"textarea","required":true},{"key":"alternative_considered","label":"Compliant alternative you considered, and why it was rejected","type":"textarea","required":true},{"key":"cost_and_timeline_of_compliance","label":"Cost and timeline of achieving full compliance","type":"textarea","required":true},{"key":"scope_in_and_out","label":"Assets, systems, or processes the exception covers - and what it explicitly does not cover","type":"textarea","required":true},{"key":"requested_end_date","label":"Date the exception should end","type":"date","required":true},{"key":"remediation_milestone","label":"Remediation milestone that end date is tied to","type":"textarea","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]},{"stepNumber":2,"name":"Route for approval","type":"TASK","diagramNodeId":"route-for-approval","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Privacy Waiver Expiring","kind":"related"},{"itemType":"policy","itemTitle":"Threat Intelligence Policy","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"approval_decision","label":"Route for approval","type":"select","required":true,"options":[{"value":"approved_time_bound","label":"Approved time-bound"},{"value":"rejected","label":"Rejected"},{"value":"escalated","label":"Escalated to risk committee"}]}]},"formAssignments":[{"email":"george.michael@bluth.example"}]},{"stepNumber":3,"name":"Committee review","type":"TASK","diagramNodeId":"committee-review","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Privacy Waiver Expiring","kind":"related"},{"itemType":"policy","itemTitle":"Threat Intelligence Policy","kind":"related"}]},{"stepNumber":4,"name":"Register and implement","type":"TASK","diagramNodeId":"register-and-implement","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Privacy Waiver Expiring","kind":"related"},{"itemType":"policy","itemTitle":"Threat Intelligence Policy","kind":"related"}]},{"stepNumber":5,"name":"Monitor to expiry","type":"TASK","diagramNodeId":"monitor-to-expiry","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Privacy Waiver Expiring","kind":"related"},{"itemType":"policy","itemTitle":"Threat Intelligence Policy","kind":"related"}]},{"stepNumber":6,"name":"Close and archive","type":"TASK","diagramNodeId":"close-and-archive","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"issue","itemTitle":"Privacy Waiver Expiring","kind":"related"},{"itemType":"policy","itemTitle":"Threat Intelligence Policy","kind":"related"}]}]},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","name":"Model Validation — Banana Stand Demand Forecast — overdue validation","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation","description":"Model Validation for Banana Stand Demand Forecast","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Independent validation review","type":"TASK","diagramNodeId":"independent-validation","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}]},{"stepNumber":2,"name":"Approve the validation outcome","type":"TASK","diagramNodeId":"approve-validation","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}]}]},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","name":"Model Validation — Frozen Banana Churn Classifier — overdue validation","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation","description":"Model Validation for Frozen Banana Churn Classifier","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Independent validation review","type":"TASK","diagramNodeId":"independent-validation","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}]},{"stepNumber":2,"name":"Approve the validation outcome","type":"TASK","diagramNodeId":"approve-validation","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}]}]},{"itemType":"model","itemTitle":"Sudden Valley Reserve Model","name":"Model Validation — Sudden Valley Reserve Model — annual validation","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation","description":"Model Validation for Sudden Valley Reserve Model","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Independent validation review","type":"TASK","diagramNodeId":"independent-validation","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Sudden Valley Reserve Model","kind":"related"}]},{"stepNumber":2,"name":"Approve the validation outcome","type":"TASK","diagramNodeId":"approve-validation","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Sudden Valley Reserve Model","kind":"related"}]}]},{"itemType":"model","itemTitle":"Construction Cost Estimator","name":"Model Validation — Construction Cost Estimator — annual validation","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation","description":"Model Validation for Construction Cost Estimator","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Independent validation review","type":"TASK","diagramNodeId":"independent-validation","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Construction Cost Estimator","kind":"related"}]},{"stepNumber":2,"name":"Approve the validation outcome","type":"TASK","diagramNodeId":"approve-validation","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Construction Cost Estimator","kind":"related"}]}]},{"itemType":"model","itemTitle":"Tenant Credit Risk Scorecard","name":"Model Validation — Tenant Credit Risk Scorecard — annual validation","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation","description":"Model Validation for Tenant Credit Risk Scorecard","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Independent validation review","type":"TASK","diagramNodeId":"independent-validation","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Tenant Credit Risk Scorecard","kind":"related"}]},{"stepNumber":2,"name":"Approve the validation outcome","type":"TASK","diagramNodeId":"approve-validation","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Tenant Credit Risk Scorecard","kind":"related"}]}]},{"itemType":"model","itemTitle":"Model Home Pricing Engine","name":"Model Validation — Model Home Pricing Engine — next validation","templateSourceId":"coworkcanvas:template:model-validation","templateName":"Model Validation","description":"Model Validation for Model Home Pricing Engine","status":"DRAFT","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Independent validation review","type":"TASK","diagramNodeId":"independent-validation","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}]},{"stepNumber":2,"name":"Approve the validation outcome","type":"TASK","diagramNodeId":"approve-validation","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}]}]},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","name":"Model Monitoring Breach Review — Banana Stand Demand Forecast — current breach","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review","description":"Model Monitoring Breach Review for Banana Stand Demand Forecast","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Diagnose the breach","type":"TASK","diagramNodeId":"diagnose-breach","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}]},{"stepNumber":2,"name":"Approve the response","type":"TASK","diagramNodeId":"decide-response","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}]}]},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","name":"Model Monitoring Breach Review — Frozen Banana Churn Classifier — current breach","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review","description":"Model Monitoring Breach Review for Frozen Banana Churn Classifier","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Diagnose the breach","type":"TASK","diagramNodeId":"diagnose-breach","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}]},{"stepNumber":2,"name":"Approve the response","type":"TASK","diagramNodeId":"decide-response","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}]}]},{"itemType":"model","itemTitle":"Model Home Pricing Engine","name":"Model Monitoring Breach Review — Model Home Pricing Engine — watch review","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review","description":"Model Monitoring Breach Review for Model Home Pricing Engine","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Diagnose the breach","type":"TASK","diagramNodeId":"diagnose-breach","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}]},{"stepNumber":2,"name":"Approve the response","type":"TASK","diagramNodeId":"decide-response","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}]}]},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","name":"Model Monitoring Breach Review — Claims Triage GenAI Assistant — resolved breach","templateSourceId":"coworkcanvas:template:model-monitoring-breach-review","templateName":"Model Monitoring Breach Review","description":"Model Monitoring Breach Review for Claims Triage GenAI Assistant","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Diagnose the breach","type":"TASK","diagramNodeId":"diagnose-breach","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","kind":"related"}]},{"stepNumber":2,"name":"Approve the response","type":"TASK","diagramNodeId":"decide-response","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","kind":"related"}]}]},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","name":"Model Performance Monitoring — Banana Stand Demand Forecast — cycle 1","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Banana Stand Demand Forecast","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.91,"monitoring_threshold":0.8},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]}]},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","name":"Model Performance Monitoring — Banana Stand Demand Forecast — cycle 2","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Banana Stand Demand Forecast","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.89,"monitoring_threshold":0.8},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]}]},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","name":"Model Performance Monitoring — Banana Stand Demand Forecast — cycle 3","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Banana Stand Demand Forecast","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.86,"monitoring_threshold":0.8},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]}]},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","name":"Model Performance Monitoring — Banana Stand Demand Forecast — cycle 4","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Banana Stand Demand Forecast","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.83,"monitoring_threshold":0.8},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]}]},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","name":"Model Performance Monitoring — Banana Stand Demand Forecast — cycle 5","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Banana Stand Demand Forecast","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.79,"monitoring_threshold":0.8},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]}]},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","name":"Model Performance Monitoring — Banana Stand Demand Forecast — cycle 6","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Banana Stand Demand Forecast","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.74,"monitoring_threshold":0.8},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]}]},{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","name":"Model Performance Monitoring — Banana Stand Demand Forecast — current cycle","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Banana Stand Demand Forecast","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Banana Stand Demand Forecast","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"george.michael@bluth.example"}]}]},{"itemType":"model","itemTitle":"Model Home Pricing Engine","name":"Model Performance Monitoring — Model Home Pricing Engine — cycle 1","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Model Home Pricing Engine","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.93,"monitoring_threshold":0.85},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Model Home Pricing Engine","name":"Model Performance Monitoring — Model Home Pricing Engine — cycle 2","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Model Home Pricing Engine","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.92,"monitoring_threshold":0.85},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Model Home Pricing Engine","name":"Model Performance Monitoring — Model Home Pricing Engine — cycle 3","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Model Home Pricing Engine","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.9,"monitoring_threshold":0.85},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Model Home Pricing Engine","name":"Model Performance Monitoring — Model Home Pricing Engine — cycle 4","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Model Home Pricing Engine","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.89,"monitoring_threshold":0.85},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Model Home Pricing Engine","name":"Model Performance Monitoring — Model Home Pricing Engine — cycle 5","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Model Home Pricing Engine","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.87,"monitoring_threshold":0.85},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Model Home Pricing Engine","name":"Model Performance Monitoring — Model Home Pricing Engine — cycle 6","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Model Home Pricing Engine","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.86,"monitoring_threshold":0.85},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Model Home Pricing Engine","name":"Model Performance Monitoring — Model Home Pricing Engine — current cycle","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Model Home Pricing Engine","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Model Home Pricing Engine","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","name":"Model Performance Monitoring — Frozen Banana Churn Classifier — cycle 1","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Frozen Banana Churn Classifier","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.84,"monitoring_threshold":0.75},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]}]},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","name":"Model Performance Monitoring — Frozen Banana Churn Classifier — cycle 2","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Frozen Banana Churn Classifier","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.82,"monitoring_threshold":0.75},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]}]},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","name":"Model Performance Monitoring — Frozen Banana Churn Classifier — cycle 3","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Frozen Banana Churn Classifier","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.8,"monitoring_threshold":0.75},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]}]},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","name":"Model Performance Monitoring — Frozen Banana Churn Classifier — cycle 4","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Frozen Banana Churn Classifier","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.77,"monitoring_threshold":0.75},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]}]},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","name":"Model Performance Monitoring — Frozen Banana Churn Classifier — cycle 5","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Frozen Banana Churn Classifier","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.73,"monitoring_threshold":0.75},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]}]},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","name":"Model Performance Monitoring — Frozen Banana Churn Classifier — cycle 6","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Frozen Banana Churn Classifier","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.7,"monitoring_threshold":0.75},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]}]},{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","name":"Model Performance Monitoring — Frozen Banana Churn Classifier — current cycle","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Frozen Banana Churn Classifier","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Frozen Banana Churn Classifier","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"ann.veal@bluth.example"}]}]},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","name":"Model Performance Monitoring — Claims Triage GenAI Assistant — cycle 1","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Claims Triage GenAI Assistant","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.95,"monitoring_threshold":0.9},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","name":"Model Performance Monitoring — Claims Triage GenAI Assistant — cycle 2","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Claims Triage GenAI Assistant","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.96,"monitoring_threshold":0.9},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","name":"Model Performance Monitoring — Claims Triage GenAI Assistant — cycle 3","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Claims Triage GenAI Assistant","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.94,"monitoring_threshold":0.9},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","name":"Model Performance Monitoring — Claims Triage GenAI Assistant — cycle 4","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Claims Triage GenAI Assistant","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.95,"monitoring_threshold":0.9},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","name":"Model Performance Monitoring — Claims Triage GenAI Assistant — cycle 5","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Claims Triage GenAI Assistant","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.93,"monitoring_threshold":0.9},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","name":"Model Performance Monitoring — Claims Triage GenAI Assistant — cycle 6","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Claims Triage GenAI Assistant","status":"COMPLETED","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","kind":"related"}],"formData":{"resultType":"form","values":{"monitoring_metric":0.94,"monitoring_threshold":0.9},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","name":"Model Performance Monitoring — Claims Triage GenAI Assistant — current cycle","templateSourceId":"coworkcanvas:template:model-performance-monitoring","templateName":"Model Performance Monitoring","description":"Model Performance Monitoring for Claims Triage GenAI Assistant","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Review the period's monitoring result","type":"TASK","diagramNodeId":"review-monitoring-result","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"model","itemTitle":"Claims Triage GenAI Assistant","kind":"related"}],"formData":{"resultType":"form","values":{},"submittedAt":null,"fields":[{"key":"monitoring_metric","label":"Metric value for the period (higher is better)","type":"number","required":true},{"key":"monitoring_threshold","label":"Threshold: the minimum acceptable value","type":"number","required":true}]},"formAssignments":[{"email":"maeby.fuenke@bluth.example"}]}]},{"itemType":"audit","itemTitle":"Cybersecurity Program Audit","name":"Audit Fieldwork, Findings & Reporting — Cybersecurity Program Audit — fieldwork","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","description":"Audit Fieldwork, Findings & Reporting for Cybersecurity Program Audit","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Execute and review fieldwork","type":"TASK","diagramNodeId":"execute-fieldwork","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"audit","itemTitle":"Cybersecurity Program Audit","kind":"related"},{"itemType":"control","itemTitle":"Data Retention Enforcement","kind":"related"},{"itemType":"control","itemTitle":"Privileged Access Approval","kind":"related"},{"itemType":"control","itemTitle":"Quarterly Access Recertification","kind":"related"},{"itemType":"control","itemTitle":"SOC Report and CUEC Review","kind":"related"},{"itemType":"control","itemTitle":"Security Incident Triage","kind":"related"},{"itemType":"control","itemTitle":"Vulnerability Remediation Review","kind":"related"}]},{"stepNumber":2,"name":"Evaluate and clear findings","type":"TASK","diagramNodeId":"findings-clearance","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"audit","itemTitle":"Cybersecurity Program Audit","kind":"related"},{"itemType":"control","itemTitle":"Data Retention Enforcement","kind":"related"},{"itemType":"control","itemTitle":"Privileged Access Approval","kind":"related"},{"itemType":"control","itemTitle":"Quarterly Access Recertification","kind":"related"},{"itemType":"control","itemTitle":"SOC Report and CUEC Review","kind":"related"},{"itemType":"control","itemTitle":"Security Incident Triage","kind":"related"},{"itemType":"control","itemTitle":"Vulnerability Remediation Review","kind":"related"}]},{"stepNumber":3,"name":"Approve report and engagement closure","type":"TASK","diagramNodeId":"reporting-closure","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"audit","itemTitle":"Cybersecurity Program Audit","kind":"related"},{"itemType":"control","itemTitle":"Data Retention Enforcement","kind":"related"},{"itemType":"control","itemTitle":"Privileged Access Approval","kind":"related"},{"itemType":"control","itemTitle":"Quarterly Access Recertification","kind":"related"},{"itemType":"control","itemTitle":"SOC Report and CUEC Review","kind":"related"},{"itemType":"control","itemTitle":"Security Incident Triage","kind":"related"},{"itemType":"control","itemTitle":"Vulnerability Remediation Review","kind":"related"}]}]},{"itemType":"audit","itemTitle":"Vendor Risk Review","name":"Audit Fieldwork, Findings & Reporting — Vendor Risk Review — fieldwork","templateSourceId":"coworkcanvas:template:audit-fieldwork-reporting","templateName":"Audit Fieldwork, Findings & Reporting","description":"Audit Fieldwork, Findings & Reporting for Vendor Risk Review","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Execute and review fieldwork","type":"TASK","diagramNodeId":"execute-fieldwork","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"audit","itemTitle":"Vendor Risk Review","kind":"related"},{"itemType":"control","itemTitle":"SOC Report and CUEC Review","kind":"related"},{"itemType":"control","itemTitle":"Vendor Due Diligence","kind":"related"}]},{"stepNumber":2,"name":"Evaluate and clear findings","type":"TASK","diagramNodeId":"findings-clearance","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"audit","itemTitle":"Vendor Risk Review","kind":"related"},{"itemType":"control","itemTitle":"SOC Report and CUEC Review","kind":"related"},{"itemType":"control","itemTitle":"Vendor Due Diligence","kind":"related"}]},{"stepNumber":3,"name":"Approve report and engagement closure","type":"TASK","diagramNodeId":"reporting-closure","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"audit","itemTitle":"Vendor Risk Review","kind":"related"},{"itemType":"control","itemTitle":"SOC Report and CUEC Review","kind":"related"},{"itemType":"control","itemTitle":"Vendor Due Diligence","kind":"related"}]}]},{"itemType":"system","itemTitle":"Sitwell Payroll Bureau","name":"System & Third-Party Risk Review — Sitwell Payroll Bureau — annual review","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","description":"System & Third-Party Risk Review for Sitwell Payroll Bureau","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess system and third-party risk","type":"TASK","diagramNodeId":"system-risk-assessment","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Sitwell Payroll Bureau","kind":"related"}]},{"stepNumber":2,"name":"Approve system risk review record","type":"TASK","diagramNodeId":"system-review-closure","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Sitwell Payroll Bureau","kind":"related"}]}]},{"itemType":"system","itemTitle":"Sitwell Payroll Bureau","name":"SOC Report, Subservice & CUEC Review — Sitwell Payroll Bureau — SOC 2 type II","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","description":"SOC Report, Subservice & CUEC Review for Sitwell Payroll Bureau","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Evaluate opinion, controls, and exceptions","type":"TASK","diagramNodeId":"soc-report-evaluation","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Sitwell Payroll Bureau","kind":"related"}]},{"stepNumber":2,"name":"Approve SOC review record","type":"TASK","diagramNodeId":"soc-review-closure","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Sitwell Payroll Bureau","kind":"related"}]}]},{"itemType":"system","itemTitle":"Magic Supply Wholesale","name":"System & Third-Party Risk Review — Magic Supply Wholesale — annual review","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","description":"System & Third-Party Risk Review for Magic Supply Wholesale","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess system and third-party risk","type":"TASK","diagramNodeId":"system-risk-assessment","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Magic Supply Wholesale","kind":"related"}]},{"stepNumber":2,"name":"Approve system risk review record","type":"TASK","diagramNodeId":"system-review-closure","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Magic Supply Wholesale","kind":"related"}]}]},{"itemType":"system","itemTitle":"Magic Supply Wholesale","name":"SOC Report, Subservice & CUEC Review — Magic Supply Wholesale — SOC 2 type II","templateSourceId":"coworkcanvas:template:system-soc-report-cuec-review","templateName":"SOC Report, Subservice & CUEC Review","description":"SOC Report, Subservice & CUEC Review for Magic Supply Wholesale","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Evaluate opinion, controls, and exceptions","type":"TASK","diagramNodeId":"soc-report-evaluation","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Magic Supply Wholesale","kind":"related"}]},{"stepNumber":2,"name":"Approve SOC review record","type":"TASK","diagramNodeId":"soc-review-closure","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Magic Supply Wholesale","kind":"related"}]}]},{"itemType":"system","itemTitle":"Seaside Cloud Hosting","name":"System & Third-Party Risk Review — Seaside Cloud Hosting — annual review","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","description":"System & Third-Party Risk Review for Seaside Cloud Hosting","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess system and third-party risk","type":"TASK","diagramNodeId":"system-risk-assessment","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Seaside Cloud Hosting","kind":"related"}]},{"stepNumber":2,"name":"Approve system risk review record","type":"TASK","diagramNodeId":"system-review-closure","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Seaside Cloud Hosting","kind":"related"}]}]},{"itemType":"system","itemTitle":"Bluth Legal Retainer Services","name":"System & Third-Party Risk Review — Bluth Legal Retainer Services — annual review","templateSourceId":"coworkcanvas:template:system-third-party-risk-review","templateName":"System & Third-Party Risk Review","description":"System & Third-Party Risk Review for Bluth Legal Retainer Services","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"Assess system and third-party risk","type":"TASK","diagramNodeId":"system-risk-assessment","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Bluth Legal Retainer Services","kind":"related"}]},{"stepNumber":2,"name":"Approve system risk review record","type":"TASK","diagramNodeId":"system-review-closure","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"system","itemTitle":"Bluth Legal Retainer Services","kind":"related"}]}]},{"itemType":"control","itemTitle":"Production Change Approval","name":"SOX Control Testing — Production Change Approval — FY2026 interim","templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","description":"SOX Control Testing for Production Change Approval","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"SAMPLE","type":"TASK","diagramNodeId":"sample","requiredApprovals":1,"approvers":[{"email":"ann.veal@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"control","itemTitle":"Production Change Approval","kind":"related"}]},{"stepNumber":2,"name":"TEST","type":"TASK","diagramNodeId":"test","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"control","itemTitle":"Production Change Approval","kind":"related"}]}]},{"itemType":"control","itemTitle":"Backup Restoration Test","name":"SOX Control Testing — Backup Restoration Test — FY2026 interim","templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","description":"SOX Control Testing for Backup Restoration Test","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"SAMPLE","type":"TASK","diagramNodeId":"sample","requiredApprovals":1,"approvers":[{"email":"george.michael@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"control","itemTitle":"Backup Restoration Test","kind":"related"}]},{"stepNumber":2,"name":"TEST","type":"TASK","diagramNodeId":"test","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"control","itemTitle":"Backup Restoration Test","kind":"related"}]}]},{"itemType":"control","itemTitle":"Journal Entry Approval","name":"SOX Control Testing — Journal Entry Approval — FY2026 interim","templateSourceId":"coworkcanvas:template:sox-control-testing","templateName":"SOX Control Testing","description":"SOX Control Testing for Journal Entry Approval","status":"ACTIVE","isPublic":true,"workflowType":"standard","steps":[{"stepNumber":1,"name":"SAMPLE","type":"TASK","diagramNodeId":"sample","requiredApprovals":1,"approvers":[{"email":"maeby.fuenke@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"control","itemTitle":"Journal Entry Approval","kind":"related"}]},{"stepNumber":2,"name":"TEST","type":"TASK","diagramNodeId":"test","requiredApprovals":1,"approvers":[{"email":"michael.bluth@bluth.example","reviewLevel":1}],"linkedItems":[{"itemType":"control","itemTitle":"Journal Entry Approval","kind":"related"}]}]}],"dashboards":[],"users":[{"email":"michael.bluth@bluth.example","name":"Michael Bluth","isAdmin":false,"pageAccess":[{"pageName":"dashboards","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"workflows","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"templates","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"time-keeping","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"my-items","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"audit","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"risk","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"control","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"issue","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"remediation","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"process","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"policy","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"system","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"fsli","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"requirement","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"personnel","hasAccess":true,"accessLevel":"edit_all"}]},{"email":"george.michael@bluth.example","name":"George Michael Bluth","isAdmin":false,"pageAccess":[{"pageName":"dashboards","hasAccess":true,"accessLevel":"view_all"},{"pageName":"workflows","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"templates","hasAccess":true,"accessLevel":"view_all"},{"pageName":"time-keeping","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"my-items","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"audit","hasAccess":true,"accessLevel":"view_all"},{"pageName":"risk","hasAccess":true,"accessLevel":"view_all"},{"pageName":"control","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"issue","hasAccess":true,"accessLevel":"view_all"},{"pageName":"remediation","hasAccess":true,"accessLevel":"view_all"},{"pageName":"process","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"policy","hasAccess":true,"accessLevel":"view_all"},{"pageName":"system","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"fsli","hasAccess":true,"accessLevel":"view_all"},{"pageName":"requirement","hasAccess":true,"accessLevel":"view_all"},{"pageName":"personnel","hasAccess":true,"accessLevel":"view_all"}]},{"email":"maeby.fuenke@bluth.example","name":"Maeby Fünke","isAdmin":false,"pageAccess":[{"pageName":"dashboards","hasAccess":true,"accessLevel":"view_all"},{"pageName":"workflows","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"templates","hasAccess":true,"accessLevel":"view_all"},{"pageName":"time-keeping","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"my-items","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"audit","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"risk","hasAccess":true,"accessLevel":"view_all"},{"pageName":"control","hasAccess":true,"accessLevel":"view_all"},{"pageName":"issue","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"remediation","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"process","hasAccess":true,"accessLevel":"view_all"},{"pageName":"policy","hasAccess":true,"accessLevel":"view_all"},{"pageName":"system","hasAccess":true,"accessLevel":"view_all"},{"pageName":"fsli","hasAccess":true,"accessLevel":"view_all"},{"pageName":"requirement","hasAccess":true,"accessLevel":"view_all"},{"pageName":"personnel","hasAccess":true,"accessLevel":"view_all"}]},{"email":"ann.veal@bluth.example","name":"Ann Veal","isAdmin":false,"pageAccess":[{"pageName":"dashboards","hasAccess":true,"accessLevel":"view_all"},{"pageName":"workflows","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"templates","hasAccess":true,"accessLevel":"view_all"},{"pageName":"time-keeping","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"my-items","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"audit","hasAccess":true,"accessLevel":"view_all"},{"pageName":"risk","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"control","hasAccess":true,"accessLevel":"view_all"},{"pageName":"issue","hasAccess":true,"accessLevel":"view_all"},{"pageName":"remediation","hasAccess":true,"accessLevel":"view_all"},{"pageName":"process","hasAccess":true,"accessLevel":"view_all"},{"pageName":"policy","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"system","hasAccess":true,"accessLevel":"view_all"},{"pageName":"fsli","hasAccess":true,"accessLevel":"view_all"},{"pageName":"requirement","hasAccess":true,"accessLevel":"edit_all"},{"pageName":"personnel","hasAccess":true,"accessLevel":"view_all"}]}]}}
