Skip to main content

Get help for ARIS

Perform or review compliance assessments

As soon as compliance assessments are generated and the assessment period is reached, the regulation owner or hierarchy owner responsible can view the compliance assessments in My GRC tasks My GRC tasks in ARIS or in My tasks My tasks in ARIS Risk and Compliance. The users responsible are notified automatically by e-mail. If compliance assessments are not edited within the predefined assessment period, they are automatically closed during checking with the Not completed status. when checked and can no longer be edited. They can no longer be edited.

You can Hand over task Hand over or Delegate task Delegate tasks to another role (Change responsibility/Open user search Change responsibility ).

By default, compliance assessments with status Compliant, Not compliant, or Not possible require a review. Administrators can configure in the Risk and Compliance configuration of ARIS Administration whether and how many reviews are required. If result reviews are required, review tasks are generated for the regulation reviewers responsible in My My GRC tasks GRC tasks. The users responsible The users responsible are notified automatically by e-mail.

Prerequisite

  • Perform compliance assessments: You have the Regulation owner or Hierarchy owner Risk and Compliance role.

  • Review compliance assessments: You have the Regulation reviewer Risk and Compliance role.

Procedure. Procedure
  1. Click Open 'My GRC tasks' Open 'My GRC tasks' in the header of ARIS to open the list of your GRC tasks. Only if GRC tasks are available for you, the icon with the number of tasks is displayed in the ARIS header. Alternatively, click Application launcher Application launcher > Quick access > My GRC tasks My GRC tasks. Your tasks are displayed.

  2. Use the Filter Filter to obtain a better overview. Filter your tasks, for example by due date or type.

  3. Click the relevant compliance assessment. The Compliance assessment form is displayed with information such as related regulation, regulatory requirement, and activities, as well as assigned risks, hierarchy elements, and compliance assessment definition.

  4. Depending on your role, perform the following steps:

Regulation owner/Hierarchy owner

  1. Based on this information, assess whether the related regulations have been complied with.

  2. Edit the optional fields.

  3. Under Result documents you can add a link or upload documents as additional information. To upload a document, you can select or drag and drop it from your local storage, or paste it from the clipboard.

  4. Click Save Save. Your entries are saved. The status is automatically set to In progress. If you want to continue later, keep this status.

  5. If you want to complete the assessment, select the status Compliant, Not compliant, or Not possible, depending on your results. Provide a reason for the status Not compliant or Not possible.

  6. Depending on the result of your assessment, generate an issue based on the compliance assessment to, for example, adapt a process and initiate a confirmation process to inform employees, or initiate a policy roll-out to ensure the regulation is complied with from now on.

  7. Save your entries (Save).

Your entries are saved. If reviews are required for compliance assessments, the regulation reviewers responsible are notified automatically by e-mail. If If more than one role is required to perform a result check, the roles perform the result review in the order in which they are modeled at the associated object. In other words, the role that is closest to the related object performs the result review first.

Regulation reviewer

  1. Check the owner's remarks and attachments.

  2. If you want to complete the review click Review Review, then select the status Accepted, or if you do not agree, select the status Rejected.

  3. Enter an explanation for your decision.

  4. Click Save.

If you selected the Accepted status and more than one reviewer role is required to perform the result review, the next role responsible is notified automatically by e-mail and so on, until all required roles have completed the result reviews.

If you selected the Rejected status, the review process is interrupted and the task is displayed again to the owner role in My GRC tasks My GRC tasks with In progress status. The other reviewers are no longer required to perform the result reviews.

The users responsible are notified automatically by e-mail.