12.2.4 Adding Compliance Risks

<< Click to Display Table of Contents >>

Navigation:  12.COMPLIANCE MONITORING MODULE > 12.2 Regulations Register >

12.2.4 Adding Compliance Risks

 

Similar to ‘Mandated Controls’, ‘Compliance Risks’ can be added to the hierarchy from the “Add New” button shown below:

 

Version 6_img566

The screen is composed of the following fields (Mandatory fields are highlighted in grey):

Version 6_img567

 

 

Risk Subject - This field is used to record a brief description of the compliance risk; this field appears in all of CAREwebprinted output and therefore the description needs to be meaningful in its own right.

 

Description – used to record a complete description of the compliance risk set out in the short description. Treat this as a word processing field, give as full a description of the compliance risk as you can.

 

Asset (or whatever you have personalized it in the Parameters section (see above) - This is mandatory and is where the user details the particular attribute under threat if the compliance risk occurs.  The available attributes have already been set up in the “Asset Types” screen (see above).  By opening the drop-down list, the available asset types are displayed and the appropriate asset can be selected.

 

Impact and Probability - The drop-down boxes allow the user to detail the impact and the probability of the compliance risk.  Quantification follows the parameters set up at the Installation stage (refer to the parameters section), in this example they are:

High

Medium

Low

 

 

Different Language- To add the subject and description of the compliance risk in a corresponding language (Arabic, English or another language predefined in the system), click on “edit” and then Version 6_img558  button will appear in the toolbar. Click on it and the following screen will appear:

 

Version 6_img569

 

After filling in the fields with information and clicking “save” the page should look like this.

Version 6_img570

 

Link to Regulation Hierarchy - You can link the risk to other related regulations through this screen by selecting the relevant regulation/ article under the “Link to Regulation Hierarchy” feature. Clicking on the button Version 6_img571:

 

Version 6_img572

 

Here you can expand the hierarchy and select articles that you wish to link the compliance risk to.

Click on “Save” to add the risk to the selected articles. The related regulations section below will be automatically updated to reflect the changes.

 

 

Related Regulations

 

Going back to the compliance risk screen, the related regulations tab will be updated

This tab shows the list of regulatory articles which are linked with this compliance risk.

 

Version 6_img573

 

Related Controls

The related controls tab shows Mandated and Operational Controls linked to the compliance risk.  Details of defining controls and the controls-related screens.

 

Version 6_img574

 

The related controls tab contains two features “Add New Control” or “Link to Control”

 

Related Controls Tab - Add New Control

Selecting the add new control feature will present the following screen:

 

Version 6_img575

 

From this screen, you can define a new operational control that helps in mitigating the compliance risk. The details of the fields required for defining a new control. In brief, for each new control you will have to specify the following:

 

-Control Subject; this field is intended to record a brief description of the control

-Control Description; This field is intended to provide a fuller description of the control set out in the short description.

-Control type; this is where you can specify the control type from the drop-down list presented below:

Version 6_img576

 

Once you define all the required fields, click on the “Version 6_img577” and the system will automatically save the new control and link it with the compliance risk.

 

 

Related Control Tab – Link to Control

 

The Link to Control feature provides you with a list of all controls available in your CAREweb database and allows you to link these controls to compliance risks. Clicking on “Link to Control” will provide you with the below pop-up screen:

 

Version 6_img578

 

This screen contains a list of all controls available in your database. In addition, for each control the screen outlines the following:

-Control Subject

-Control type

-Whether the control is a mandated control or an operational control

 

The search option presented on top of the screen allows you to search the list of controls based on selected keywords.

 

To link a risk with a control through this screen, place click on the tick box next to the control and then click on the “Version 6_img579”.