Skip to main content

Get help for ARIS

Perform or review control executions

As soon as control executions are generated and the execution period was reached, the control executor roles responsible can view the control executions in My GRC tasks My GRC tasks in ARIS or in My tasks My tasks in ARIS Risk and Compliance. The users responsible are notified automatically by e-mail.

By default, control executions with status Not possible and Completed require a review. Administrators can configure in the Risk and Compliance configuration of ARIS Administration whether and how many reviews are required. If reviews are required, review tasks are generated for the control execution reviewers responsible in My GRC tasks My GRC tasks. The users responsible are notified automatically by e-mail.

Prerequisite

  • Control executions: You have the Control executor role.

  • Review control executions: You have the Control execution reviewer role.

Procedure. Procedure
  1. Click Open 'My GRC tasks' Open 'My GRC tasks' in the header of ARIS to open the list of your GRC tasks. Only if GRC tasks are available for you, the icon with the number of tasks is displayed in the ARIS header. Alternatively, click Application launcher Application launcher > Quick access > My GRC tasks My GRC tasks. Your tasks are displayed.

  2. If necessary, use the Filter filter to restrict the list based on specific search criteria.

  3. Click the relevant control execution task. The Control execution form with information, such as activities and further documents, is displayed.

  4. Depending on your role, perform the following steps:

Control executor

  1. Edit the optional fields.

  2. Under Result documents you can add a link or upload documents as additional information. To upload a document, you can select or drag and drop it from your local storage, or paste it from the clipboard.

  3. Click Save Save. The status is automatically set to In progress. If you want to continue later, keep this status.

  4. If you want to complete control execution editing, select the status Completed or Not possible, depending on the result.

  5. If you selected the status Not possible, the Remark field becomes a mandatory field.

  6. Enter an explanation of why processing is not possible.

  7. Save your entries (Save).

If you saved the status Completed or Not possible, you can no longer edit the control test.

If reviews are required for control executions, the control execution reviewers responsible are notified automatically by e-mail. If more than one role is required to perform a result check, the roles perform the result review in the order in which they are modeled at the associated object. In other words, the role that is closest to the related object performs the result review first.

Control execution reviewer

  1. Check the control executor's findings.

  2. If you want to complete the review click Review Review, then select the status Accepted, or if you do not agree, select the status Rejected.

  3. Enter an explanation for your decision.

  4. Click Save.

If you selected the Accepted status and more than one reviewer role is required to perform the result review, the next role responsible is notified automatically by e-mail and so on, until all required roles have completed the result reviews.

If you selected the Rejected status, the review process is interrupted and the task is displayed again to the owner role in My GRC tasks My GRC tasks with In progress status. The other reviewers are no longer required to perform the result reviews.

The users responsible are notified automatically by e-mail.