Defining a Risk Control
Controls for risks serve to monitor them. They ensure that changes relating to the risk are identified.
Controls for risks serve to monitor them. They ensure that changes relating to the risk are identified. Control assessments serve to verify the effectiveness of the controls.
Concept of Risk Controls
As a Process Owner, you can define controls for risks and assess them regularly. A control is a precaution that serves for monitoring purposes. It does not contain any specific actions, for example to reduce the risk, but instead ensures that changes relating to the risk are identified. The control assessments serve to verify the effectiveness of the controls.
Adding a Control
Prerequisites
You must be the Process Owner of the process.
A risk has been added to a process or a process element.
The risk is not published.
To save a control, you must at least define the title and the assessment cycle (default: Annually).
Context
Controls for risks should be defined and assessed regularly in particular when processes or process elements with a high risk or a high level of opportunity require regular attention.
The assessment cycle of the controls specifies how often the data collected for the controls is assessed in order to verify their effectiveness.
Implementation provisions for the control support the significance of the control assessments.
Several different controls can be set up for each risk.
How to Proceed
-
Select the process or process element whose risk is to be controlled.
The risks recorded for it so far are listed.
-
Click the risk that is to be controlled.
The details are expanded.
-
To add a control for the risk, click Add Control.
The dialog of the same name appears.
-
Enter the Title and a Description of the control.
-
Select the Control Frequency, the Control Type and the Control Mechanism.
-
Click Responsible Person and select the person who is responsible for the control.
-
Select the Assessment Cycle for the control.
-
As the Evidence Storage Location, enter a reference or link to the implementation provisions and the evidence for the controls.
-
Click Record Control.
The control is displayed in the Controls list.
The risk is marked with the control icon.
Assessing a Control
Prerequisites
You must be the Process Owner of the process.
A control has been added to a risk and this risk is published.
Context
The assessments of the controls serve to verify the effectiveness of the controls.
A control is assessed on the Overview tab of a process in the respective risk analysis.
How to Proceed
-
In the detail view of the risk, in the Controls section, click the control you want to assess.
The details of the control are expanded.
-
Click Assess Now for the first assessment or Reassess.
The Assess Risk Control dialog appears.
-
To assess the control, select the applicable entries for the assessment criteria Implementation, Control Design, Effectiveness and Appropriateness.
The Overall Assessment is determined automatically from these entries.
-
To define a different overall assessment, select it.
-
If necessary, enter the specific Weaknesses of the control activity.
-
Click Record Assessment.
The assessment is displayed in the Assessments list.
The overall assessment is displayed with a color highlight.
The control assessment can be edited using the edit icon.