workflow

Regulatory Exam & External Audit Management

Manage a live regulator examination or external audit end to end — from notification intake through request fulfillment, QC’d evidence release, fieldwork support, preliminary-findings response, and commitment closure. Runs on an Audit engagement item created per exam (audit_type = regulatory_exam, or external_attestation for an external audit); the workflow instance attaches to that Audit anchor, and preliminary findings and their corrective-action commitments become linked Issue items. No upstream workflow feeds this — it is triggered by the exam or audit notification itself. In scope: coordinating examiner requests, controlled evidence release, and management responses for a single exam or audit engagement. Out of scope: remediating the underlying control gaps — the findings and committed corrective actions hand off to Finding Remediation & Action-Plan Monitoring — and standing up new obligations surfaced by the exam, which hand off to Regulatory Horizon Scanning & Triage and Regulatory Obligation Implementation.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
grc
department
compliance-legal
lineOfDefense
monitor

Details

teams
  • compliance-legal
domains
  • grc
  • reg
standards
  • nydfs-500
  • dora
  • soc1
  • soc2
sourceTemplateId
workflow-library:grc-regulatory-exam-management
releaseId
sha256:5f11b74c03db584b9dd5fb49c63673a927c3baf590e860cb36f54d90be0c2b69
canonicalUrl
https://evidenceflows.com/workflows/all/?w=grc-regulatory-exam-management
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-GOV-23
    • UC-AUDIT-17
    • UC-AUDIT-23
    • UC-AUDIT-24
    • UC-ACCESS-14
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings
          • code
            reliance-basis-incomplete
            title
            Reliance basis is incomplete
            message
            Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
            missing
            • independence
            • competence
            • evidence
            • recency
            • reliance rationale
            nodeIds

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:5f11b74c03db584b9dd5fb49c63673a927c3baf590e860cb36f54d90be0c2b69

            Connections