{"description":"Runs on the existing control item that owns compliance content monitoring, started once a week by its owner or a scheduled agent. Read the public EvidenceFlows catalog history (https://evidenceflows.com/data/v1/history.json) since the last processed revision, keep the requirement, risk and control changes that apply to adopted frameworks, and approve how each is routed. Deliver new Compliance Requirement items, which start Requirement Applicability & Control Mapping, and review workflows on the existing Requirement, Risk or Control items a change affects; the step result records the newest processed revision for the next run.","edges":[{"id":"e-triage-catalog-changes-approve-change-routing","source":"triage-catalog-changes","target":"approve-change-routing"}],"isPublic":true,"itemTypeSlug":"control","metadata":{"capabilities":["regulatory-change-monitoring"],"controlVerbs":{"UC-GOV-03":"operates","UC-RISK-11":"operates"},"controls":["UC-RISK-11","UC-GOV-03"],"department":"compliance-legal","domains":["reg"],"kind":"compliance-content-change-scan","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:compliance-content-change-scan"}],"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=reg-compliance-content-change-scan","contentDigest":"sha256:fe3ea2bd379a72965ab4fee277165e4d411cd4d9c42d6a6ea97929e06294dc95","prerequisites":{"anchorItemType":{"slug":"control"},"evidenceDestinations":[{"description":"Native step results with the classified change list and newest processed revision, the downloaded change sets as step documents, new Compliance Requirement items and the attached review workflows.","id":"scan-evidence"}],"fields":[{"itemTypeSlug":"control","key":"frequency"},{"itemTypeSlug":"requirement","key":"reference"},{"itemTypeSlug":"requirement","key":"framework"},{"itemTypeSlug":"requirement","key":"framework_version"},{"itemTypeSlug":"requirement","key":"applicability"}],"handoffs":[{"direction":"output","name":"New requirements to map","sourceTemplateId":"workflow-library:reg-requirement-applicability-mapping"},{"direction":"output","name":"Changed requirements to assess","sourceTemplateId":"workflow-library:reg-requirement-change-impact"}],"roles":[{"contribution":"expertise","description":"Compliance analyst. Judges which catalog changes apply to the organization and how each one is classified.","id":"compliance-analyst","nodeIds":["triage-catalog-changes"]},{"contribution":"approval","description":"Compliance owner. Approves the new requirements and the review workflows each change starts.","id":"compliance-owner","nodeIds":["approve-change-routing"]}],"status":"declared"},"provenance":[{"source":"workflow-library","sourceTemplateId":"coworkcanvas:template:compliance-content-change-scan"}],"releaseId":"sha256:fe3ea2bd379a72965ab4fee277165e4d411cd4d9c42d6a6ea97929e06294dc95","schemaVersion":1,"sourceTemplateId":"workflow-library:reg-compliance-content-change-scan"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"reg-compliance-content-change-scan","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53","soc2","coso-ic"],"teams":["compliance-legal","risk-management"]},"name":"Compliance Content Change Scan","nodes":[{"data":{"controls":["UC-RISK-11"],"description":"The agent reads every EvidenceFlows release since the last scan and classifies each requirement, risk and control change; the compliance analyst judges which changes apply.","instructions":"**Objective**\nFind every requirement, risk and control that changed in the EvidenceFlows catalog since the last scan, and decide which changes apply to the organization.\n\n**Inputs**\n- The control item this workflow runs on, and the newest processed catalog revision recorded in the step result of this control's last completed scan. On the first run there is none; scan only the current release.\n- The release history at https://evidenceflows.com/data/v1/history.json. Each release lists its revision, the previous revision, its publication date, counts and a change set (`changesUrl`) of added, changed and removed records.\n- The Compliance Requirement register (`Requirement.reference`, `Requirement.framework`, `Requirement.framework_version`, `Requirement.applicability`), and the Risk and Control registers.\n- The frameworks the organization has adopted: the distinct `Requirement.framework` values on applicable requirements.\n\n**Procedure**\n1. Read the release history and collect every release published after the last processed revision, oldest first. If the last processed revision is not in the history, stop and record that the scan cannot establish its starting point.\n2. Read each release's change set. Keep added, changed and removed records of type `standard` or `control` (framework requirements), `risk` and `unified` (unified controls). Ignore `workflow` records.\n3. Drop records for frameworks the organization has not adopted, and count what was dropped for each reason.\n4. Match each remaining record to the registers: framework requirements by framework and reference, risks and unified controls by title and their catalog mappings.\n5. Classify each record as a new requirement (no matching Requirement item), a changed requirement, a changed risk or control, a removed record, or not applicable, with the reason.\n6. Note the newest revision read, so the next run starts after it.\n\n**Record in AssureSwarm**\n- Step result: the revision range scanned, each kept change with its catalog record id, record URL, classification and proposed action, the dropped counts by reason, and the newest processed revision.\n- Step document: the change sets read, as downloaded (JSON).\n\n**Exit criteria**\nCompliance analyst provides expertise: each kept change is classified correctly against the registers, no change to an adopted framework was dropped, and the newest processed revision is recorded for the next run.","kind":"task","label":"Triage the catalog changes","requiredApprovals":1},"id":"triage-catalog-changes"},{"data":{"controls":["UC-GOV-03"],"description":"The compliance owner approves the new requirements and the review workflows the triage proposes; the agent prepares each create and attachment.","instructions":"**Objective**\nTurn each applicable change into a new Compliance Requirement or a review of the record it affects, with the compliance owner's approval.\n\n**Inputs**\n- The classified change list and newest processed revision from Triage the catalog changes.\n- The matching Requirement, Risk and Control items, and their owners.\n- The `Requirement.framework` options available in this workspace.\n\n**Procedure**\n1. For each new requirement, prepare a Compliance Requirement item: title, `Requirement.reference`, `Requirement.framework`, `Requirement.framework_version`, `Requirement.description` with the catalog record URL, and `Requirement.applicability` set to `pending_review`. Creating it starts Requirement Applicability & Control Mapping on the new item.\n2. For each changed requirement, attach Regulatory Change Intake & Impact Assessment to the existing Requirement item, citing the release and the change.\n3. For each changed risk, attach Risk Assessment & Treatment Review to the matching Risk item. For each changed unified control, attach Control Design Assessment to the matching Control item.\n4. For each removed record, do not delete anything. Name the affected item and its owner as an open action for the owner's next review.\n5. When a framework is not among the `Requirement.framework` options, record the requirement as an open action for a workspace administrator instead of creating it with the wrong framework.\n6. Submit the creates and attachments for approval together, so the routing is approved as one decision.\n\n**Record in AssureSwarm**\n- Item create: the new Compliance Requirement items with the fields in Procedure step 1.\n- Workflow instance: Regulatory Change Intake & Impact Assessment, Risk Assessment & Treatment Review or Control Design Assessment attached to each affected item.\n- Step result: the routing table (each change, the action taken and the item or workflow it created) and the open actions for removed records and missing frameworks.\n\n**Exit criteria**\nCompliance owner provides approval: every kept change has exactly one action or a recorded reason for none, new requirements carry their catalog source, and each review workflow cites the change that triggered it.","kind":"task","label":"Approve how each change is routed","performedBy":{"primitives":["coach-item-create","coach-workflow-attach"]},"requiredApprovals":1},"id":"approve-change-routing"}],"sourceTemplateId":"workflow-library:reg-compliance-content-change-scan"}
