Control Indicators

rebecca18
Kilo Contributor

Afternoon

We have mapped a number of Controls to Risk within the GRC platform, could you advise if it possible to create an indicator that would highlight to the risk owner when a control becomes non compliant.  This would allow the risk owner to then re-assess the risk as the likelihood may increase as a result of the mapped control being non-compliant, just to confirm that this would be a Control Indicator and not a Risk indicator?

4 REPLIES 4

Ronak Gandhi
Giga Expert

Hey rebecca, in my experience a control indicator might not work (I could be wrong).

An easy way I can think of is to create a 'Notification' which is triggered - when a Control Status changes from Compliant to Non-Compliant, the Risk Owner of the related risk(s) (the table to identify the related risks is - sn_risk_m2m_risk_control) would get an email.

I hope this works. 

Sebastien Fix
Giga Guru
Giga Guru

When Controls mapped against a Risk become non-compliant either the Calculated Risk (Classic Risk Assessment) or Automated Factors within RAMs would impact the Risk Score. Monitoring the Risk Score is a natural part of the Risk Owners job. Should the Risk Score fall outside Risk Tolerance, the Risk Owner MAY need to reperform the Risk Assessment and define new Response Tasks (maybe the Risk Response is no longer "Accept" but "Mitigate" and may require defining new and/or better Controls)

Whenever a single Control fails once, the Risk Assessment in itself is still fine, only the Control Environment changes when Controls fail or pass. Reperforming an entire Risk Assessment the second a Control Fails would also mean that the same Risk Assessment needs to be retaken as soon as the Control becomes Compliant again. Remember that Controls Compliance can change every day (or technically even minutes) if you use Indicators to monitor data on the SN platform.

Finally, Risk Owners are also rarely the ones in charge of Compliance but rather 1st/2nd/3rd lines of defense test Controls. A task to solve an issue arising from a failed Control will therefore often fall on someone elses lap than the Risk Manager/Owner.

 

Asparuh
Tera Contributor

  The best out-of-the-box way is to create an issue automatically for non-compliance of a control. The issue to be assigned to control owner and this way a notification is delivered to him/her. The issue is fixed in two ways:

1. If the next indicator passes.

2. Manually by the control owner.

Issues are getting created OOTB - open issues actually make the Control Non-Compliant, so nothing to create to get there. However Rebecca's use case related to Risk Owner and not Control Owner.