This is a proposed sequence for a first controlled workflow, not a claim that every enterprise can complete the work with existing staffing. Select a process with a clear success oracle, a named resource owner, and bounded consequences. Schedule depends on access, integrations, procurement, reviewer capacity, and the maturity of existing controls.
| Phase | Work | Accountable first-line role | Exit evidence |
|---|---|---|---|
| Days 1-30: authority and inventory | Choose workflow; register manifest and mandate; inventory effect routes; implement identities, least privilege, limits, and exact-scope approval. | Business process owner, with platform/resource owners | E01/E02/E04 artifacts; successful denial, revocation, budget, and bypass tests. |
| Days 31-60: evaluation and evidence | Build external outcome oracles; add paired normal/harmful cases; evaluate timing, monitor thresholds, delayed influence, interactions, and recovery. | Platform lead and workflow owner | Locked test set; configuration-linked results; evidence reconciliation; residual-failure register. |
| Days 61-90: bounded operation and challenge | Run shadow then bounded canary; verify reviewer staffing; compare customer stages where relevant; exercise incident response; obtain independent release challenge. | Business process owner | Production evidence, completed drill, stage outcomes, challenge record, and bounded operating authorization. |
15.1 Responsibilities across the three lines
| Decision or activity | First line | Second line | Third line |
|---|---|---|---|
| Mandate and autonomy | Business proposes and owns use; platform implements. | Risk approves the framework and challenges proposed scope. | Tests governance and exception discipline. |
| Evaluation design | Supplies business scenarios and system access. | Validation challenges construct validity and owns independent conclusions. | Re-performs selected methods and tests. |
| Runtime enforcement | Platform and resource owners operate controls. | Security/risk defines control standards and reviews residual risk. | Tests operating effectiveness and bypass coverage. |
| Customer outcomes | Business owns service and remediation. | Compliance/fairness reviews lawful scope, analysis, and rights. | Audits end-to-end decision and remedy evidence. |
| Incident handling | Operations contains, reconciles, and restores. | Legal/compliance determines reporting duties; risk challenges restart. | Assesses control failure and corrective-action closure. |
| Release and promotion | Business accepts responsibility within approved policy. | Independent validation/risk challenges evidence and exceptions. | Reviews authorization and the evidence chain. |
Assign one accountable role per deliverable in the local RACI. Internal audit should retain independence from designing or approving the controls it will later audit. Legal review should establish applicable duties and exemptions without substituting for technical enforcement tests.
15.2 What the governing body needs
The operating pack should contain the permitted business mandate; maximum autonomy by action class; system configuration and material dependencies; evidence for the critical control claims; unresolved misses and coverage gaps; customer impacts; exception owners and expiry; incident/recovery results; and the basis for the next operating decision.
Keep detection performance separate from prevention. Identify any claim that relies on an untested vendor assertion, unavailable reasoning trace, missing effect oracle, or unresolved legal applicability. A governed exception should be explicit, time-limited, attributable, and accompanied by a containment plan. It should not silently become evidence that the control works.
15.3 A reusable incident drill
| Drill step | Required action | Proof of completion |
|---|---|---|
| Detect and classify | Identify the observable effect, implicated configuration, severity, and affected workflow. | Incident record and preserved source events. |
| Stop new authority | Pause commits and revoke relevant credentials or grants. | Post-revocation attempts fail on every covered route. |
| Contain descendants | Stop child agents, jobs, queues, and continuing network paths. | Delegation-tree reconciliation and effective halt times. |
| Establish effects | Query independently for completed, partial, and pending actions. | Resource receipts and reconciled state. |
| Preserve and protect evidence | Apply custody/access rules and prevent agent edits to authoritative records. | Integrity record and evidence-access log. |
| Assess duties and customer remedy | Determine applicable reporting clocks and remediation. | Legal/compliance determination with jurisdiction and trigger. |
| Repair and restart | Correct configuration or data; replay retained failures and restoration cases. | Fresh gate decision and bounded restart authorization. |