Showing posts with label rmc. Show all posts
Showing posts with label rmc. Show all posts

Overview of Surveys in Risk Management Cloud

What is a Survey in Risk Management Cloud?

A Survey is a set of questions that may be associated with assessments or distributed independently of assessments.

You may link a survey to an assessment activity in an assessment plan. Survey questions concern the type of object (process, risk or control) and the activity specified in the plan. Answers to the questions help assessment participants form judgments about objects in assessments developed from the plan. Assessment participants are selected automatically on the basis of their job roles.

As you prepare a survey, you may start with any of the following components:
  1. Choice Sets. A choice is a possible answer to a question, and a choice set is an assortment of answers a person may select from. You can associate a given choice set with any number of questions.
  2. Questions. These may or may not require choice sets. Or you can select choices are you create questions and save them into choice sets.
  3. Template. As you create a template, you can select existing questions for it, or create questions. Moreover, you can use an existing template to distribute a new survey or create a new template for a survey.
Survey question formats

Survey questions may take the following formats. For any format other than open text, you can associate a question with a choice set.




Issue Management and Lifecycle in Risk Management Cloud

Manage the Issue Resolution Process

The resolution of an issue includes these steps:
  1. A User creates an Issue
  2. A User with proper privileges validates the issue, either determining that it requires investigation, closing it or putting it on hold
  3. If the issue is valid, a user with proper permissions determines whether a remediation plan is required for the issue to be resolved. If not, this user closes the issue.
  4. If so the user creates or selects a remediation plan. Other users respond to the worklists to complete remediation tasks. The remediation plan is marked as complete and the issue is closed.
The Issue object records defects or deficiencies detected for risks, controls or assessments. Typically, you discover issues when you assess risks or controls. Typically, one user identifies an issue, another verifies it and another resolves it.

Raising an Issue

A user may raise an issue from several places:
  • From an issue-management work area
  • from the issues tab in the management page for an individual risk or control, create an issue specific to that object or review its details
  • within an assessment of a risk or control
Resolving an Issue

Once an issue exists, the process of resolving it may include:

  1. Validating the issue
  2. Take appropriate actions to resolve the issue
  3. Closing an Issue
Validating the issue

When an issue is created, a user may receive a worklist notification to validate if. This user may:
  • Determine that it requires investigation.
  • Determine that it does not require investigation, and close it
  • Put it on Hold
To Receive a validation worklist, a user must be assigned a duty role called Issue Validator Composite. In effect, this user determines whether the issue is genuine, and so should be a user other than the one who creates the issue. However, the validation workflow is optional. If no user is assigned the Issue Validator Composite duty role, no validation worklist is issued.

Users with the Issue Validator Composite, or Issue Manager Composite duty role may oversee the validation and resolution of issues, and close them.

Closing an Issue

you can close an issue:
  1. when it is resolved; when points of concern have been addressed
  2. At any other time. You may, for example, determine during the validation step that the issue is invalid or cannot be resolved.
For more full-detailed Tutorials and Tips, check out #TheOracleProdigy at https://lifeofanoracleprodigy.blogspot.com/
Follow The Oracle Prodigy on Facebook (https://www.facebook.com/theOracleProdigy/) and Twitter (https://twitter.com/D_OracleProdigy)

Overview of Assessments in Oracle Risk Management Cloud

What is an assessment?

An assessment is the review of a risk or a control to ensure that it is defined correctly or that its definition remains appropriate over time.

An assessment may
  • focus on objects themselves, or on activities involving object, such as certification or audit
  • be batch or ad-hoc
  • concern a single risk or control, or encompass many.
  • Involve the participation of business stakeholders, internal and external auditors, or other users.
  • Incorporate test plans for controls
To determine what an assessment is meant to uncover, you assign one or more activity types to it. assessment activity types include:


The Assessment Page
  • An Introduction page presents an overview of the item being assessed. It includes guidance text, which is a broad statement of the assessment's purpose.
  • A "Review Prior Results" page displays records for any prior actions taken for this assessment.
  • An "Enter Test Results" page enables you to complete a test plan. It appears only if you are assessing a control for which a test plan has been created.
  • Use the response field to select an answer to an activity question. This determines whether the object passes or fails the assessment. You can also create a summary statement, create an issue, or attach a file to the assessment.
Batch Assessments follows the flow:


A batch assessment depends on several components
  1. A template designates a primary object of assessment, Risk and Control. The template also designates one or more activities to be completed in assessments.
  2. From the template, you develop a plan. It may contain filters that select instances of the primary object specified by the template. 
  3. From a plan, you initiate an assessment, selecting object instances made available by the plan.
A batch assessment offers an array of options:
  1. It not only involves multiple object instances, but also may designate multiple activities to be completed
  2. Its generation involves the use of supporting tools: templates and plans. You use these to select assessment activities to define a set of objects for assessments.
  3. You Initiate it and manage the components that support it within the Assessment work area
Initiating a Batch Assessment
  1. Provide the general information
  2. Review the selection criteria
  3. select risks or controls to be assessed
  4. review participants
The final page in the initiate assessment series identifies the assessors for each risk or control selected for assessment. These people are selected according to role assignments, and you cannot modify that selection in this page.

The purpose of this review is to identify risks or controls that have no assessors, so that you can return to the components page and remove them from the assessment

Adhoc Assessments

An adhoc assessment is simpler:
  1. It not only focuses on a single object, but also designates a single activity to be completed
  2. You initiate it from within the page to manage the risk or control you want to assess
Completing an Assessment

An assessment may include any number of risk or controls. You assess each of these individually. You May:
  • Select a Worklist notification for a risk or control included in the assessment
  • Select the "Complete Assessment" option in the tasks panel tab of any page in the Assessments work area. In a search page, search of an Assessment, select one of its risks or controls, and select "Complete Assessment".
  • Navigate to the Assessments tab of the Management page for the risk or control being assessed. Select the row for an Assessment and the "Complete Assessment" action.
For more full-detailed Tutorials and Tips, check out #TheOracleProdigy at https://lifeofanoracleprodigy.blogspot.com/
Follow The Oracle Prodigy on Facebook (https://www.facebook.com/theOracleProdigy/) and Twitter (https://twitter.com/D_OracleProdigy)

Recent Posts

SQL Fundamentals

Introduction to SQL and Syntax What is SQL? SQL stands for Structured Query Language. is a standard programming language for accessing datab...

Top Posts