Control Indicators
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-13-2022 08:53 AM
Afternoon
We have mapped a number of Controls to Risk within the GRC platform, could you advise if it possible to create an indicator that would highlight to the risk owner when a control becomes non compliant. This would allow the risk owner to then re-assess the risk as the likelihood may increase as a result of the mapped control being non-compliant, just to confirm that this would be a Control Indicator and not a Risk indicator?
- Labels:
-
Risk Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-13-2022 09:09 AM
Hey rebecca, in my experience a control indicator might not work (I could be wrong).
An easy way I can think of is to create a 'Notification' which is triggered - when a Control Status changes from Compliant to Non-Compliant, the Risk Owner of the related risk(s) (the table to identify the related risks is - sn_risk_m2m_risk_control) would get an email.
I hope this works.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-13-2022 11:06 PM
When Controls mapped against a Risk become non-compliant either the Calculated Risk (Classic Risk Assessment) or Automated Factors within RAMs would impact the Risk Score. Monitoring the Risk Score is a natural part of the Risk Owners job. Should the Risk Score fall outside Risk Tolerance, the Risk Owner MAY need to reperform the Risk Assessment and define new Response Tasks (maybe the Risk Response is no longer "Accept" but "Mitigate" and may require defining new and/or better Controls)
Whenever a single Control fails once, the Risk Assessment in itself is still fine, only the Control Environment changes when Controls fail or pass. Reperforming an entire Risk Assessment the second a Control Fails would also mean that the same Risk Assessment needs to be retaken as soon as the Control becomes Compliant again. Remember that Controls Compliance can change every day (or technically even minutes) if you use Indicators to monitor data on the SN platform.
Finally, Risk Owners are also rarely the ones in charge of Compliance but rather 1st/2nd/3rd lines of defense test Controls. A task to solve an issue arising from a failed Control will therefore often fall on someone elses lap than the Risk Manager/Owner.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-14-2022 01:28 AM
The best out-of-the-box way is to create an issue automatically for non-compliance of a control. The issue to be assigned to control owner and this way a notification is delivered to him/her. The issue is fixed in two ways:
1. If the next indicator passes.
2. Manually by the control owner.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-14-2022 03:58 AM
Issues are getting created OOTB - open issues actually make the Control Non-Compliant, so nothing to create to get there. However Rebecca's use case related to Risk Owner and not Control Owner.