The GRC portal is a combination of visions containing important information so that the manager can track and monitor the risk management in the organization. In order to improve the management of the GRC visions and results, the Chart view widget is available. In this widget, the results of the risks, according to the desired grouping level and filter, will be displayed graphically according to the risk evaluation method.
During the life cycle of a risk analysis or control analysis, many records are made to compose any risk or control evaluation. All these operations are recorded to compose the change history and risk analysis or control analysis evolution. This information is available in the history link on the analysis screen.
When executing a test for a control, in addition to the information that the test passed or failed, it is important to present a result that guides the user to the next action. Customizing control test results helps in internal communication and flexibility of results after executing the tests.
In some status, the risk and control records are maintained as a library that guides all risk management and controls. In this way, it is attempted to restrict the access to these screens to keep the information always updated and without redundancy. The creation of the webservices of the risk and control records helps in this management, as it allows the customers to customize the management of the risk and control library as needed, using SE Workflow as a tool for this management.
When executing a test, before this result is part of the control analysis, the approval route can be set up so that those responsible evaluate the result and the execution of the test, verifying that the result is within the desired specifications and guidelines.
While performing a test in some cases you may wish to add an attachment as a sample to confirm the test result. From this version, it is possible to attach attachments to the test sample as evidence of its execution and its result.
In order to simplify the tracking of the tests performed for the controls, a view test control is available that presents the main test results and the main information about their execution.
Viewing actions and plans of risks and controls
One of the major activities in managing the risks and controls is to monitor the progress of the actions and the action plans generated in SE Suite. The actions and action plans view allow this monitoring in a simple way to focus on the risk and control management, with the option of generating analysis to customize visions and portals.