New risk value in Advanced Risk

Arnaud Bretz1
Tera Contributor

Hi everyone,

 

I am implementing advanced risk for a customer. The customer wants to ass Inherent Risk / Control Assessment / Residual Risk (pretty classic) but on top of that they want to have another calculated risk value which considers only controls which are compliant (Control status is obtained during control attestation).
 
I don't seem to have such this option when building the risk assessment methodology. Have you encountered a similar requirement? 

Thank you;
Arnaud
1 ACCEPTED SOLUTION

Hi Arnaud

 

For which record you want to check control compliant(control effectiveness)  risk or entity.

If it is risk configure factor as below:

KumudRanjan_1-1692377679085.png

 

If it is entity configure factor accordingly.

Also on Control assessment record select Calculate based on as Control environment assessment and add your factor in related list.

 

Thanks

Kumud

 

View solution in original post

3 REPLIES 3

Kumud Ranjan
Mega Guru

Hi Arnaud,

 

Under control assessment on RAM you can create one automated query factor where you can return all the compliant control map to a particular risk.

Create another automated query factor where you will return all the control  mapped to a risk.

Using the count of passed control and total control from factors you can apply formula and calculate risk score on control assessment using script.

 

And count of the compliant control and passed control  can be seen under control assessment section on risk assessment form.

 

If you want more details on how to configure automated query factor to get passed and total control let me know.

 

Mark answer helpful if it helped you to resolve your query.

 

Thanks,

Kumud

 

Hi @Kumud Ranjan,

Thanks for your reply. I tried to configure an automated factor but I did not succeed. 

Under "Control Assessment" assessment type of my RAM, I selected my automated factor in the field "factor for overall effectiveness". (See picture 1).

ArnaudBretz1_1-1692285812667.png

 


In picture 2, you can see the parameters my automated factor called "Complaint Control". 

ArnaudBretz1_2-1692285832332.png

 

 

Hi Arnaud

 

For which record you want to check control compliant(control effectiveness)  risk or entity.

If it is risk configure factor as below:

KumudRanjan_1-1692377679085.png

 

If it is entity configure factor accordingly.

Also on Control assessment record select Calculate based on as Control environment assessment and add your factor in related list.

 

Thanks

Kumud