workflow

Enterprise Risk Treatment Operations Cycle

Enterprise Risk Treatment Operations Cycle as a decision-aware workflow: it runs the documented risk methodology each cycle - identification and analysis of risks and opportunities, evaluation and prioritization against risk criteria, treatment selection and tracking for risks exceeding tolerance with residual re-evaluation, and risk-register and portfolio reporting to management and the board - triggering dynamic reassessment when internal or external change shifts the risk profile. This cycle has no anchor item of its own: the enterprise risk register it maintains IS the Risk item population, and the workflow instance is the cycle record and durable audit trail. In scope: entity-level and process-level risk across the enterprise, explicitly including cybersecurity, privacy, and financial-reporting risk alongside operational and strategic risk and opportunity. Out of scope: detailed control design and testing, which downstream control workflows own - a mitigate or share/transfer plan that creates or strengthens a control hands that work off to those workflows, which anchor on the affected Control items. This cycle has no upstream workflow feeding it; its starting inputs are the documented methodology, the consistent likelihood/impact scoring scales, the board-approved risk criteria and appetite/tolerance statements, and the risk-acceptance delegation matrix - all carried as Policy items - plus the existing control, insurance and transfer information (Control items and step documents) and the prior cycle's Risk register. Named deliverables: the maintained enterprise risk register (the Risk items), the prioritized risk heat-map dashboard, and the management and board portfolio report package.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
grc
department
operations
lineOfDefense
operate

Details

teams
  • operations
  • risk-management
domains
  • grc
standards
  • iso-31000
  • coso-erm
  • nist-csf-2
  • nist-800-53
sourceTemplateId
workflow-library:grc-enterprise-risk-assessment-treatment-cycle
releaseId
sha256:79071c080ea903483397902e6789786a717a9ec9a2eb7bc8c1b87c00d8065f55
canonicalUrl
https://evidenceflows.com/workflows/all/?w=grc-enterprise-risk-assessment-treatment-cycle
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-RISK-06
    • UC-RISK-07
    • UC-RISK-08
    • UC-RISK-09
    • UC-RISK-10
    • UC-RISK-11
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:79071c080ea903483397902e6789786a717a9ec9a2eb7bc8c1b87c00d8065f55

            Connections