The workflow template library
138 audit, SOX, controls, regulatory and GRC workflow templates — steps, owners, lines of defence and control mappings already worked out.
Every template is a working definition rather than a diagram: named steps, the role that performs each one, the line of defence it belongs to, and the unified controls it operates. Average length is 10.9 steps.
What’s in it
| Domain | Templates | Route |
|---|---|---|
| Controls | 62 | workflow-library.com/controls/ |
| GRC | 34 | workflow-library.com |
| Regulatory | 16 | workflow-library.com/regulatory/ |
| SOX | 15 | workflow-library.com/sox/ |
| Audit | 11 | workflow-library.com/audit/ |
Split by who actually runs them, the shape of the profession appears: 90 templates are first-line operating work, 32 are second-line monitoring, and 16 are third-line assurance.
Why the shape matters
Sixteen assurance templates against 122 that belong to the first and second lines is not a gap in the library — it is an accurate picture of the terrain. Assurance is a thin layer over a very large operating surface. It is the reason a third-line function cannot test its way to coverage by hand, and the reason the leverage in modern auditing is in reading the first line’s systems directly rather than in auditing faster.
Using them
They import into CoworkCanvas directly, and they are readable JSON if you want to take the step definitions into something else. Nothing here is a lead magnet with the useful parts removed — the templates are the whole thing, including the control mappings, which is the part that normally takes a team a quarter to work out.