workflow

Enterprise Risk Register Lifecycle

Enterprise Risk Register Lifecycle as a decision-aware workflow. This is a standalone recurring instance (quarterly or annual) that runs against the existing Risk item population — the enterprise risk register itself — enriching those Risk items in place rather than recreating a register: per-risk results are written onto the individual Risk items, and cycle-level deliverables attach to the workflow instance's steps. In scope: maintaining the register across the confirmed entities, business units, and risk-taxonomy categories for this cycle — intake and deduplication of new risks, Three-Lines ownership, control and assurance mapping, KRIs, periodic review and escalation, and retirement. Out of scope: any entity, unit, or category not named in this cycle's confirmed scope. It consumes the candidate-risk handoff package from the upstream Risk Register Intake workflow and hands its maintained register, residual positions, and escalations to two downstream workflows — Enterprise Risk Assessment & Portfolio Oversight Cycle (the maintained register, the concentration and correlation flags, and the residual positions) and Risk Appetite Definition & Board Reporting (the above-appetite entries, the escalations, and the acceptances) — rather than duplicating repeated work.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
grc
department
risk-management
lineOfDefense
monitor

Details

teams
  • risk-management
domains
  • grc
standards
  • coso-erm
  • iso-31000
sourceTemplateId
workflow-library:grc-enterprise-risk-register-lifecycle
releaseId
sha256:6aae208521d7e2f231f94e91d93be13625d59548764d010770807e11cac9496d
canonicalUrl
https://evidenceflows.com/workflows/all/?w=grc-enterprise-risk-register-lifecycle
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-RISK-10
    • UC-RISK-09
    • UC-RISK-13
    • UC-RISK-05
    • UC-GOV-38
    roleIntegrity
    activityCount
    1
    ermPhases
    • cross_cutting
    lineRoles
    • second
    serviceModes
    • administrative
    warnings

      Source

      No record-specific source URL is provided.

      Download workflow template · Release: sha256:6aae208521d7e2f231f94e91d93be13625d59548764d010770807e11cac9496d

      Connections