Skip to main content

Get help for ARIS

ARIS Risk and Compliance components

The following ARIS Risk and Compliance components are available. For detailed information, refer to Use components and functions in ARIS Risk and Compliance help.

  • Issue Management is the basis for identifying issues or tasks for objects in ARIS Risk and Compliance or ARIS. Issues can be created for one or more process functions, regulations, organizational units, IT systems, risks, controls, or other objects.

  • Using Survey Management, you can create questionnaires and generate surveys. Surveys can be used in association with an ARIS element, with GRC context, for example, as preparation for a risk self-assessment, or without specific context.

  • Using Regulatory Management, you can ensure and prove the correct and complete fulfillment of requirements from current laws, regulations, standards, or norms. Using Regulatory Change Management, you can ensure not to miss any new version of a regulation. It provides a structured workflow for the scheduled review of regulations by their owners responsible. Users are requested to check the regulations for current changes or enhancements and to initiate appropriate measures and adjustments if necessary. Using Compliance Management, you ensure that your organization regularly checks compliance with the identified legal requirements. Users are requested to check their inventories, such as processes, systems or policies, for compliance with the related current legal requirements and to perform the appropriate measures and adjustments if required.

  • Policy Management offers the roll-out and review of policies as the basis for corporate governance. The policy roll-out workflow, consists of approval, publishing and review. For policy roll-outs, users are prompted according to their role to approve a policy roll-out or confirm that they received the published policy. Policies are used to mitigate risk.

  • Risk Management identifies and describes all risks. Risk assessments with qualitative or quantitative risk impacts are generated regularly or on demand. Incidents and losses are recorded by Loss and Incident Management. Risks and risk portfolios, for example per process, organizational unit, regulation, can be assessed from various perspectives.

  • Control Management serves as an internal control system to identify, assign, and describe all manual or automated controls. With integrated Test Management organizations can create, plan, execute, and monitor control tests for design and effectiveness. For specific requirements, Deficiency Management allows the identification and escalation of formal deficiencies.

  • Sign-off Management allows you to organize the review and final approval of your internal controls with a structured bottom-up approach. For any hierarchy structure, the responsible users can be asked for final approval.

  • Audit Management defines and executes integrated audit plans for any type of audit objective. Audits and their audit steps are automatically generated according to the plan. When due, users responsible are notified automatically about required tasks and workflows. All audit steps are related to the respective company assets.