Workflow Template
Compliance Attestation Workflow
Manages a compliance attestation campaign end-to-end: the compliance owner defines the campaign, population and declaration questions; each respondent certifies the declaration (reporting exceptions with comments/evidence); clean attestations are auto-completed while exceptions route to a reviewer who decides on remediation and assigns it; the owner is notified of outstanding respondents and campaign completion.
Organisations subject to regulatory, contractual, or internal control obligations must periodically obtain formal attestations from staff, managers, or third parties confirming compliance with policies and declarations. This workflow manages the full attestation lifecycle for compliance owners, respondents, reviewers, and remediation owners, from campaign definition and population selection through to declaration capture, exception review, and resolution. It provides a structured, auditable record of who attested, what exceptions were reported, and how each was remediated, supporting compliance, risk, and internal audit teams across the enterprise.
Business Outcomes
- Helps reduce time spent chasing outstanding attestations through automated respondent tracking
- Supports faster identification and routing of exceptions to the appropriate reviewer
- Improves visibility into remediation status across a compliance attestation campaign
- Strengthens the audit trail for regulatory and internal control reporting
- Streamlines campaign completion reporting for compliance owners
Workflow Steps
Steps
- 1Create Attestation Campaign Recordcreate record
Registers the campaign defined by the compliance owner.
- 2Create Attestation Response Recordcreate record
Creates the individual respondent's attestation response record.
- 3Set Status: Awaiting Responseupdate record
Marks the response as awaiting the respondent's certification.
- 4Request Respondent Declarationrequest external input
Sends the respondent a link to certify the declaration or report an exception.
- 5Persist Declaration Responseupdate record
Writes the respondent's certification and exception flag to the record.
- 6Route: Clean vs Exception
Classifies the response as clean or exception-reported and routes accordingly.
exception_reported: "true"→Set Status: Exception ReportedDefault→Mark Attestation Clean - Complete - 7Mark Attestation Clean - Completeupdate record
No exception reported; the attestation is recorded as complete.
- 8Assign Exception to Reviewerassign user
Routes the exception-reported attestation to a compliance reviewer.
- 9Set Status: Under Reviewupdate record
Marks the exception-reported attestation as under reviewer assessment.
- 10Reviewer Assesses Exceptioncreate task
Reviewer examines the exception comment/evidence and decides whether remediation is required.
- 11Persist Review Outcomeupdate record
Writes the reviewer's remediation decision and notes to the record.
- 12Route: Remediation Required?
Branches based on whether the reviewer determined remediation is required.
remediation_required: "Yes"→Assign Remediation Ownerremediation_required: "No"→Mark Exception Resolved - CompleteDefault→Mark Exception Resolved - Complete - 13Assign Remediation Ownerassign user
Assigns the exception to a remediation owner to action the required steps.
- 14Set Status: Remediation Assignedupdate record
Marks the attestation as having remediation assigned.
- 15Complete Remediationcreate task
Remediation owner documents and completes the required remediation actions.
- 16Persist Remediation Actionsupdate record
Writes remediation actions taken to the record and marks it complete.
- 17Mark Exception Resolved - Completeupdate record
No remediation required; the exception attestation is recorded as complete.
- 18Set Status: Exception Reportedupdate record
Marks the attestation as having an exception reported, prior to reviewer assignment.
Fields
- Campaign Name*
- Compliance Owner Email*
- Declaration / Attestation Statement*
- Declaration Questions*
- Campaign Close Date*
- Respondent Name*
- +11 more fields
Forms
Define Attestation Campaign
8 fields
Data Views
All Attestation Responses
respondent_name, respondent_email, respondent_department, attestation_status +1 more
Dashboard Widgets
Similar Workflows
Similar Categories
FAQs
How is this attestation campaign audited?
Every step of the workflow, including campaign creation, respondent declarations, exception routing, reviewer decisions, and remediation actions, is persisted as a discrete record within assess.one. This creates a timestamped, sequential history that compliance and internal audit teams can reference to demonstrate the integrity of the attestation process. Status changes such as 'Under Review' or 'Remediation Assigned' are logged automatically as part of the workflow's step progression.
Who has access to attestation responses and exception details?
Access is configured directly within assess.one according to role, so respondents typically see only their own declaration, reviewers see exceptions assigned to them, and the compliance owner retains oversight of the full campaign population. Permissions and visibility rules can be adjusted per step to reflect organisational reporting lines or segregation-of-duties requirements. This role-based structure helps limit sensitive compliance data to those who need it for their part of the process.
How does this integrate with existing notification tools?
Notifications, such as reminders to outstanding respondents or alerts to the compliance owner on campaign completion, are configured inside assess.one and can be connected to email or Slack without requiring separate development work. Reviewers and remediation owners can similarly be notified when a task is assigned to them. These integrations are set up directly in the platform's step configuration.
Can the declaration questions and exception criteria be customised?
Yes, the compliance owner defines the declaration questions, respondent population, and the criteria distinguishing a clean attestation from an exception when configuring the campaign in assess.one. These fields, along with reviewer assignment logic and remediation steps, can be edited directly in the platform to reflect changes in policy, scope, or regulatory requirements. No external configuration or coding is needed to adjust the campaign structure.
Who needs to be given access before launching a campaign?
Typically the compliance owner, the full respondent population, one or more reviewers, and any designated remediation owners should have access before the campaign goes live. The compliance owner is generally responsible for confirming the respondent list and reviewer assignments during setup. Additional participants, such as secondary reviewers, can be added to the workflow configuration at any time.
What happens when a respondent reports an exception?
When a respondent declares an exception with supporting comments or evidence, the workflow automatically routes the case to a reviewer and updates the status to 'Under Review', bypassing the automatic completion applied to clean attestations. The reviewer then assesses the exception and records an outcome, which determines whether remediation is required. This structured routing helps compliance teams focus review effort only on cases that need attention.
How are remediation actions tracked and closed out?
If a reviewer determines remediation is required, the workflow assigns a remediation owner and sets the status to 'Remediation Assigned', keeping the exception open until action is confirmed. Once remediation actions are completed and persisted, the exception is marked resolved and the record is closed within the workflow. This provides a clear, traceable path from exception identification through to resolution.
How long does it take to launch a new attestation campaign?
The attestation campaign template is ready to use, so the compliance owner can configure the population, declaration questions, and reviewer logic, then publish it live within minutes. There is no lengthy implementation project; once published, respondents can begin submitting declarations immediately. Adjustments to the workflow can be made at any point without interrupting an active campaign.
How is the compliance owner kept informed of campaign progress?
The workflow notifies the compliance owner of outstanding respondents while the campaign is active, helping surface who has yet to complete their attestation. On completion of the campaign, or once all outstanding exceptions are resolved, the owner receives notification that the process has concluded. These notifications are configured within assess.one and can be tailored to the owner's preferred channel.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
