From ICIHelp8.2
Jump to: navigation, search
(Created page with " = ICM Risk Management App = == Overview == The Icertis (ICM) platform introduces the Risk Management application to make it easier for professionals to carry out their task...")
 
 
(116 intermediate revisions by 3 users not shown)
Line 1: Line 1:
  
= ICM Risk Management App =
+
= ICI Risk Management App =
  
 
== Overview ==
 
== Overview ==
  
The Icertis (ICM) platform introduces the Risk Management application to make it easier for professionals to carry out their tasks related to Risk Management such as assessment, due diligence, remediation, monitoring and reassessment. Risk Management is the process of identifying the potential risk, assessing the magnitude of the risk based on business objectives and devising strategies to mitigate them and tracking the performance until they are completely mitigated.&nbsp;<br/> It enables secure communication with different parties involved in the process of Risk Management that is more effective than the traditional ways of communication such as email. Its user-friendly interface makes it possible for anyone in the enterprise, from the risk management personnel to the supply analytics team, to be able to use the platform with ease.&nbsp;<br/> ICM Risk Management consists of:&nbsp;
+
The Icertis Contract Intelligence (ICI) platform introduces the Risk Management Application to make it easier for professionals to carry out their tasks related to risk management such as assessment, due diligence, remediation, monitoring and reassessment. Risk management is the process of identifying potential risk, assessing the magnitude of risk based on the business objectives, devising strategies to eliminate them and tracking the performance until they are completely mitigated.
  
*Risk assessment (with survey)
+
The platform’s modern, scalable and integration-friendly cloud architecture can model even the most complex risk management scenarios. The App provides secure access such that only authorized users can access the App entities and data, using ICI’s access control functionalities. The user-friendly interface makes it possible for anyone in the enterprise having access to be able to use the platform with ease.&nbsp;
*Auto instantiation of risk area
+
*Configurable contract types risk assessment and risk area with its workflow based on risk management process
+
*Masterdata that captures risk library, risk taxonomy and risk score matrix to effectively govern the risk management process
+
  
screen 1
+
Icertis uses a standard framework of discovery, assessment, remediation, monitoring and optimization to manage enterprise risk.
 +
<div class="image-green-border">ICI Risk Management supports the following risk management business scenarios: &nbsp;</div>
 +
*'''Business Operations Risk:&nbsp;'''For example, the impact of pandemic on the business operations of an organization.&nbsp;
 +
*'''Contractual Risk:'''&nbsp;For example, managing risks that arise from non-standard agreement terms, clauses, and so on.&nbsp;
 +
*'''Counter-Party Risk:'''&nbsp;For example, managing risks relevant to suppliers and vendors.
  
ICM Risk Management application is based on the ICM platform that supports the following business scenarios:
+
== The Terminology ==
  
*Contractual Risk Management
+
Here are some terms that will help you better understand the risk management process:
*Counter Party Risk Management (for example managing risks relevant to suppliers or vendors)  
+
 
*Business Operations Level Risk Management  
+
*Risk Assessment:&nbsp;&nbsp;It deals with the process of identifying and evaluating the magnitude of potential risk areas.
 +
*Risk Area:&nbsp;It is the exposure that an organization has from internal or external factor(s) that impact the normal<br/> functioning of business and will lower its bottom line (or profits) or lead it to fail. For example, cyber security<br/> risk.
 +
**Risk Taxonomy:&nbsp;It is comprehensive set of risk categories and sub-categories used in an<br/> organization. It outlines as approach to categorize and aggregate all types of risks that could affect<br/> the organization's objectives.
 +
**Assessment:&nbsp;Risk owner determines or assesses whether identified risk area is valid or not.<br/> Likewise, risk owner can add a risk area manually.
 +
**Due Diligence:&nbsp;It is a complete review of the risk area. As part of incomplete or missing<br/> information, tasks may be created to gather information.
 +
**Remediation:&nbsp;It is a strategy created to mitigate risks. For example, Avoid strategy, Transfer<br/> Strategy, Reduce Strategy, etc. Based on the remediation strategy, mitigation tasks are initiated.
 +
***Control Effectiveness Rating: It represents the effectiveness of risk remediation actions<br/> taken to mitigate risk.&nbsp;   
 +
*Monitor and Optimize: Monitoring involves the process of tracking the progress of residual risk level and risk<br/> score of a risk area as against the remediation tasks made for mitigation. If the residual risk score and risk<br/> level does not change as compared to the inherent score, then optimization allows taking additional due<br/> diligence or remediation tasks to mitigate risk.
 +
*Risk Score Matrix:&nbsp;&nbsp;It is a matrix that uses a combination of likelihood and consequence rating to determine<br/> magnitude of risk.&nbsp;
 +
**Inherent Risk:&nbsp;It is a risk indicator. It is the starting score for each identified risk area and is<br/> expected to be controlled.
 +
**Residual Risk:&nbsp;It is a risk indicator. It is the score that depicts the risk remaining once mitigation<br/> actions have been planned and implemented.
 +
**Likelihood Rating: On a risk matrix, it represents the likelihood (level of probability) of risk<br/> occurrence.
 +
**Consequence Rating:&nbsp;On a risk matrix, it represents the magnitude (level of impact) of risk<br/> occurrence.
 +
**Risk Level:&nbsp;&nbsp;It is the qualitative score for every risk area transaction.
 +
**Risk Score:&nbsp;It is the quantitative score for every risk area transaction. 
 +
 
 +
== The Challenge ==
 +
 
 +
Business risk can emerge from any division of a company and must be managed proactively to avoid devastating<br/> impacts. Often, these risks originate in the contracts of an organization with an external party or because of the<br/> business and regulatory environment in which the entity operates.<br/> Yet, most organizations manage contractual, regulatory, financial reporting and environmental obligations<br/> manually. Automated extraction and monitoring of obligations are prevalent in very few companies across various<br/> industry verticals. Consequently, organizations do not have adequate visibility into the status of these obligations<br/> and end up being reactive in identifying and handling risks.
 +
 
 +
This raises the following challenges:&nbsp;
 +
 
 +
*Companies cannot proactively assess and manage their risks in business environment characterized by<br/> unpredictability, volatility and mounting counter-party solvency risks.
 +
*Traditional Governance, Risk and Compliance (GRC) and Risk Management tools are not able to roll-up<br/> enterprise-wide risk insights from across contracts which are the ultimate source of commercial truth, and<br/> hence are only good at reporting and analyzing risks in hindsight.&nbsp;
 +
*Lack of visibility and insight into obligations, typically spelled out in detail in service contracts, can lead to<br/> substantial risks for businesses if not surfaced at the appropriate time and monitored at an adequate level to<br/> provide required executive attention.
 +
 
 +
== The Solution ==
 +
 
 +
Built on the Icertis Contract Intelligence platform, the ICI Risk Management App brings a paradigm shift in<br/> the management of business risks. The App offers a process-oriented enterprise-wide solution to stay on top<br/> of all potential risks that a business faces – whether they emanate from the potential insolvency of a<br/> counter-party, payment default by a customer, supply disruption due to a pandemic or natural disaster,<br/> logistics blockades due to localized conflicts, or other market turbulence.
 +
 
 +
With the Risk Management App, companies can:&nbsp;
 +
 
 +
*Perform risk discovery, assessment, remediation, monitoring and optimization in any business context that is<br/> relevant to a specific organization. For example, supplier risk assessment at the time of onboarding a supplier,<br/> customer credit risk check while signing long-term contracts on non-cash terms, contractual performance risk<br/> while evaluating technical capabilities of a service provider, etc.&nbsp;
 +
*Prevent and reduce risk-injection as opposed to only managing risks.
 +
 
 +
== The Capabilities ==
 +
 
 +
The intelligent and easy-to-use ICI Risk Management App offers these powerful capabilities:
 +
 
 +
*Ability to embed risk assessment in various business processes:
 +
**For example, during negotiation, supplier/ customer onboarding, third party contract ingestion, etc. 
 +
*Flexible and configurable risk assessment frameworks:
 +
**To cater to various industry and business-specific risk management requirements. 
 +
*Questionnaire-based risk identification:
 +
**Questionnaire configuration capability to discover all vendor or business operation risks based on<br/> responses. 
 +
*Risk area and scoring model configurability:
 +
**A configurable risk area to gauge contract, counter-party and operations risk at various levels of<br/> business granularity.
 +
**An easy-to-configure platform that helps to set up a quantitative and qualitative risk score model to<br/> meet business needs. 
 +
*Alerts and notifications:&nbsp;
 +
**In-built notifications to inform risk owner about changes in risk area status. 
 +
*Auditing:&nbsp;
 +
**Audit trails of every action with user and time-stamp details. 
 +
 
 +
== The Benefits&nbsp; ==
 +
 
 +
*The ICI Risk Management App changes the risk management paradigm from identification and mitigation to<br/> preventing risk injection and remediation.
 +
*Effective risk monitoring reduces the impact of operational, financial and reputational risk, contributing<br/> significantly to the company’s bottom line.
 +
*Configurable system can conform to any risk model in the world and even develop industry and companyspecific risk models with no custom code required, thereby greatly reducing deployment costs.
  
 
== The Prerequisites ==
 
== The Prerequisites ==
Line 23: Line 81:
 
The user must have:&nbsp;
 
The user must have:&nbsp;
  
*Completed ICM Product Training  
+
*Completed ICI Product Training  
 
*Risk Management App must be enabled on customer environment   
 
*Risk Management App must be enabled on customer environment   
  
 
== Configuration setup overview ==
 
== Configuration setup overview ==
  
ICM offers the ability to determine the application type (Contracting, Sourcing, Obligation Management and Risk Management application) when creating a contract type. This is possible with the inclusion of two new choice type attributes, Business Application Type and Business Application Category at the contract type level. This feature helps effortlessly drive business applications on ICM platform.<br/> These attributes are enabled through technical configuration and &nbsp;applicable for agreements and associated document contract types. The access privileges for business applications (such as Risk Management) are managed through security groups.&nbsp;<br/> screen2
+
ICI offers the ability to determine the application type (Contracting, Sourcing, Obligation Management and Risk Management application) when creating a contract type. This is possible with the inclusion of two new choice type attributes, Business Application Type and Business Application Category at the contract type level. This feature helps effortlessly drive business applications on ICI platform.<br/> These attributes are enabled through technical configuration and &nbsp;applicable for agreements and associated document contract types. The access privileges for business applications (such as Risk Management) are managed through security groups.&nbsp;
  
The Risk Management Application provides some seeded entities that are necessary for the flow of the Risk Management. Some of the entities are:&nbsp;
+
=== Seeded Configuration and setup ===
 +
 
 +
The ICI Risk Management application provides &nbsp;some seeded &nbsp;entities, attributes, workflows, rules and notifications that are necessary for the flow of the risk management. Some of the entities are:
  
 
*Masterdata:&nbsp;  
 
*Masterdata:&nbsp;  
Line 37: Line 97:
 
**Risk Area Master  
 
**Risk Area Master  
 
**Likelihood Rating  
 
**Likelihood Rating  
**Likelihood & Consequence Rating
 
 
**Risk Score Matrix   
 
**Risk Score Matrix   
 
*Contract types:  
 
*Contract types:  
**Risk Assessment as agreement contract type with business application type as risk management and business application category as risk assessment defined at contract type level  
+
**Risk Assessment: as agreement contract type with Business Application Type as Risk Management and Business Application Category as Risk Assessment defined at contract type level.Risk Area as associated document contract type with business application type as risk management and business application category as risk area defined at contract type level.
**Risk Area as associated document contract type with business application type as risk management and business application category as risk area defined at contract type level   
+
**Risk Area: as associated document contract type with Business Application Type as Risk Management and Business Application Category as Risk Area defined at contract type level.    
 
*Rules:  
 
*Rules:  
 
**Instantiate the risk areas after completing the risk assessment  
 
**Instantiate the risk areas after completing the risk assessment  
 
**Copy attribute values from risk assessment to the risk area  
 
**Copy attribute values from risk assessment to the risk area  
**Add risk area owner to the team
+
**Add Team members to the risk area    
**Add Approver
+
**Add Team members  
+
**Select the Template    
+
 
*Notifications for events:  
 
*Notifications for events:  
 
**Risk area is created  
 
**Risk area is created  
Line 56: Line 112:
 
**Risk area is deactivated   
 
**Risk area is deactivated   
  
Please refer to the Risk Management Configuration guide for details.<br/> &nbsp;
+
Refer&nbsp;the Risk Management Configuration guide for details.<br/> &nbsp;
  
== Setting up masterdata values ==
+
== Prerequisite set-up&nbsp; ==
  
Risk Management Application provides some seeded masterdata that are necessary for the flow of the Risk Management. Users can create masterdata instances with desired values.<br/> To create masterdata instance:
+
The ICI Risk Management application provides some seeded masterdata that are necessary for the flow of the risk management. Users can create masterdata instances with desired values.<br/> To create masterdata instance:
  
#'''Click '''''Configuration ''> ''Masterdata ''> ''Create Masterdata ''on the ''Home ''page. The ''Create Masterdata ''page opens.  
+
1.&nbsp;'''Click '''"Configure"&nbsp;> "Masterdata"&nbsp;from the "Home"&nbsp;page menu. The Masterdata page opens.
 +
<div class="image-green-border">[[File:RMApp1-11.PNG|720px|RMApp1-11.PNG]]</div>
 +
2. '''Click&nbsp;'''"Create" button. The "Create Masterdata" page opens.
 +
<div class="image-green-border">[[File:RMApp1-12.PNG|720px|RMApp1-12.PNG]]</div>
 +
3.'''Select '''the "Masterdata" Contract Type. For example, "Risk Area Master".
 +
<div class="image-green-border">[[File:RMApp1-13.PNG|720px|RMApp1-13.PNG]]</div>
 +
3.&nbsp;'''Click '''"Next". The "Attributes"&nbsp;page opens.
  
Screen 3
+
4.&nbsp;'''Enter '''or '''select '''the details in all relevant fields. For example,&nbsp;enter "Risk Area Name" as "Anti-Bribery Corruption".
<ol start="2">
+
<li>'''Select '''the ''Masterdata Contract Type''. For example, ''Risk Area Master''.</li>
+
</ol>
+
  
Screen 4
+
5.&nbsp;'''Click '''"Create". The masterdata instance is created.
<ol start="3">
+
<div class="image-green-border">[[File:RMApp1-14.PNG|600px|RMApp1-14.PNG]]</div>  
<li>'''Click '''''Next''. The ''Attributes ''page opens.</li>
+
Similarly, setup masterdata for "Risk Taxonomy", "Risk Remediation",&nbsp; "Likelihood Rating"&nbsp;and&nbsp; "Risk Score Matrix" Masters.
<li>'''Enter '''or '''select '''the details in the fields.</li>
+
<li>'''Click '''''Save''. The masterdata instance is created.</li>
+
</ol>
+
  
screen 5
+
== Working with Risk Assessment ==
  
Similarly, setup masterdata for ''Risk Taxonomy, Risk Remediation action, Risk Area, Likelihood Rating, Likelihood & Consequence Rating and Risk Score Matrix Masters''.
+
The ICI Risk Management application enables users to manage risks by creating risk assessment. Risk Assessment deals with the process of identifying and evaluating the magnitude of potential risk areas. For example, buyers can use the ICI Risk Management application &nbsp;that allows configuring a questionnaire to perform supplier risk assessment. The risk areas can be identified based on the responses received for the questionnaire as the outcome of the risk assessment process.<br/> Risk assessment workflow performed by risk assessment owners typically involves the following:
  
== Working with Risk Assessment ==
+
*Initiating Risk Assessment: The risk assessment owners can initiate the risk assessment workflow to identify the risks. For example, the risk assessment can be a questionnaire where the users respond to the questions by submitting it. This initiates the risk assessment in "Draft" state.
 +
*Approving Risk Assessment: Based on the complexity of risk assessment, ICI administrators can configure the rules to add approvers to the assessment team. If there are approvers added to the team, the risk assessment is sent to the approvers for approval. The risk assessment is approved automatically if no approvers are added to the team.
 +
*Completing Risk Assessment: The status of the risk assessment changes to "Assessment Complete" when the risk assessment is approved. The risk area can be identified and auto-instantiated based on the configured rules.
  
The Icertis Risk Management app enables users to manage risks by creating risk assessment. Risk Assessment deals with the process of identifying and evaluating the magnitude of potential risk areas. For example, buyers can use the ICM Risk Management application that allows configuring a questionnaire to perform supplier risk assessment. The risk areas can be identified based on the responses received for the questionnaire as the outcome of the risk assessment process.<br/> Risk assessment workflow performed by risk assessment owners typically involves the following:
+
Here is the Risk Assessment workflow at a glance:
 +
<div class="image-green-border">[[File:7.12-RiskManagementWorkflow.png|720px|7.12-RiskManagementWorkflow.png]]</div>  
 +
&nbsp;
  
*Initiating Risk Assessment: The risk assessment owners can instantiate the risk assessment workflow to identify the risks. For example, the risk assessment can be a questionnaire where the users respond to the questions by submitting the risk assessment. This initiates the risk assessment in Draft state.
+
&nbsp;
*Risk Assessment approval: Based on the complexity of risk assessment, ICM administrators can configure the rules to add approvers to the assessment team. If there are approvers added to the assessment team, the risk assessment is sent to the approvers for approval. The risk assessment is approved automatically if no approvers are added to the assessment team.
+
*Risk Assessment Complete: The status of the risk assessment changes to Assessment Complete when the risk assessment is approved. The risk area can be identified and auto instantiated based on the configured rules.
+
  
<br/> Here is the Risk Assessment workflow at a glance:
+
&nbsp;
  
image 6
 
  
 
== Creating a Risk Assessment ==
 
== Creating a Risk Assessment ==
  
#'''Click '''the ''Risk Management'' tile on the ''Home ''page. The drop-down opens with options:  
+
1.'''Click '''the "Risk Management" tile on the "Home"&nbsp;page. The dropdown opens with&nbsp; the following option:
 
<ul style="margin-left: 40px;">
 
<ul style="margin-left: 40px;">
<li>''Risk Assessment''</li>
+
<li>Risk Assessments</li>
<li>''Create Risk Assessment''</li>
+
 
</ul>
 
</ul>
 +
<div class="image-green-border">[[File:RMApp1.PNG|720px|RMApp1.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">'''Click&nbsp;'''"Create" on the Risk Assessment index page to open the "Create Risk Assessment" page.&nbsp;</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:8.1-RiskAssessmentIndexPage.PNG|720px|8.1-RiskAssessmentIndexPage.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">&nbsp; &nbsp; a. Alternatively, '''click''' the Create workbench plus icon, the "Create" workbench drawer opens with several create action options.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-RiskWorkflow13.PNG|720px|RMApp-RiskWorkflow13.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">&nbsp; &nbsp; b. '''Click''' "Create Assessment".</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-RiskWorkflow15.PNG|720px|RMApp-RiskWorkflow15.PNG]]</div>
 +
2.&nbsp;'''Click '''"Create Risk Assessment". The "Attributes" page for "Create Risk Assessment" opens. The "Attributes" page includes questions to capture the responses based on which the risk areas can be generated. These questions are non-seeded attributes and users can configure &nbsp;them to the Risk Assessment contract type as per their business needs.
  
screen 7
+
Attributes page has seeded sections as:
 
+
#'''Click '''''Create Risk Assessment''. The ''Attributes ''page for ''Create Risk Assessment ''opens. The ''Attributes ''page includes questions to capture the responses based on which the risk areas can be generated. These questions are non-seeded attributes and users can add them to the ''Risk Assessment'' contract type as per their business needs.
+
 
+
The sections on the attributes page can be:
+
 
<ul style="margin-left: 40px;">
 
<ul style="margin-left: 40px;">
<li>''Identification''</li>
+
<li>Identification</li>
<li>''Risk Assessment Timeline''</li>
+
<li>Risk Assessment Timeline</li>
<li>''Supplier Perspective''</li>
+
<li>''Risk Assessment and Treatment''</li>
+
<li>''Security Policy''</li>
+
<li>''Organization Security''</li>
+
<li>''Asset and Information''</li>
+
<li>''Human Resource Security''</li>
+
<li>''Physical and Environmental''</li>
+
<li>''Ops Management''</li>
+
<li>''Access Control''</li>
+
<li>''Application Security''</li>
+
<li>''Incident Management''</li>
+
<li>''Business Resilience''</li>
+
<li>''Compliance''</li>
+
 
</ul>
 
</ul>
<ol start="3">
+
 
<li>'''Enter '''the details in fields in the ''Identification ''section:</li>
+
3.&nbsp;'''Enter '''the details in fields in the "Identification"&nbsp;section:
</ol>
+
 
<ul style="margin-left: 40px;">
 
<ul style="margin-left: 40px;">
<li>''Risk Assessment Name'': Enter the risk assessment name. To make it easier for the users of your organization to find the risk assessment, the name should include some basic information about the risk assessment. For example, purpose of the risk assessment. For example, enter a name as Risk_Assessment_May2020.</li>
+
<li>Risk Assessment Name</li>
<li>''Risk Assessment Description:'' Enter the description of the risk assessment you are creating. This should include information that will help in finding the risk assessment based on the information you entered. For example, this is created to assess the probable risks due to the COVID-19 pandemic.&nbsp;</li>
+
<li>Risk Assessment Description&nbsp;</li>
<li>''Risk Assessment Entity: ''Select the entity for which you are creating the risk assessment. This includes entities which might be at risk. For example, select Business Operations.</li>
+
<li>Risk Assessment Entity: The context for which the risk assessment is being created. For example, "Business Operations", "Contractual" or "Counter Party".</li>
 
</ul>
 
</ul>
 
+
<div class="image-green-border">&nbsp;[[File:RMApp1-15.PNG|600px|RMApp1-15.PNG]]</div>  
&nbsp;screen 8
+
4.&nbsp;'''Enter '''the details in fields in the "Risk Assessment Timeline" section.
<ol start="4">
+
<li>'''Enter '''the details in fields in the ''Risk Assessment Timeline section''.</li>
+
</ol>
+
 
<ul style="margin-left: 40px;">
 
<ul style="margin-left: 40px;">
<li>''Assessment Start Date: ''Select the start date of the assessment. This is the date from which you want to assess the probable risks to business due to specific reasons. For example May 31, 2020.</li>
+
<li>Assessment Start Date: The date that you start the risk assessment of entity. For example, January 15, 2022.</li>
<li>''Assessment End Date: ''Select the end date of the assessment. This is the date till which the probable risks to business will be assessed. For example, June 1, 2020.</li>
+
<li>Assessment Due Date: The date by which risk assessment of entity should be completed. The assessment due date should be greater than the start date, otherwise a&nbsp;validation error message is displayed.</li>
 
</ul>
 
</ul>
 +
<div class="image-green-border">[[File:RMApp1-17.PNG|720px|RMApp1-17.PNG]]</div>
 +
5.&nbsp;'''Enter '''the details in fields in all the sections on the Attributes page.
  
screen 9
+
6.&nbsp;'''Click '''"Next". The "Verify"&nbsp;page opens.
<ol start="5">
+
<li>'''Enter '''the details in fields in all the sections on the ''Attributes ''page.</li>
+
<li>'''Click '''''Next''. The ''Verify ''page opens.</li>
+
</ol>
+
  
Note: The template to create the risk assessment is seeded and selected through the configured ''Template Selection'' rule.
+
7.&nbsp;'''Verify '''the details and '''click'''&nbsp;"Create".
<ol start="7">
+
<div class="image-green-border">[[File:8.0 RM 1.PNG|720px|8.0 RM 1.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">The risk assessment is created in "Draft" state.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp1-18.PNG|720px|RMApp1-18.PNG]]</div>  
<li>'''Click '''''Create''. The risk assessment is created in ''Draft ''state.&nbsp;</li>
+
Once created, users can "Edit", "Delete", "Cancel"&nbsp;or "Submit"&nbsp;the "Risk Assessment".
</ol>
+
  
&nbsp;screen 10
+
On deleting the risk assessment, users will be redirected to the Risk Assessment “Index” page.&nbsp;<br/> &nbsp;&nbsp;<br/> Some actions that are used less frequently such as “Delete”, option is now moved under the three dots icon on the Risk Assessment “Details” page.
 +
 
 +
The “Copy Record” action is not supported for Risk Assessment.
 +
<div class="note-box">'''Note''': Users can configure the less frequently used actions such as “Copy Record”, “Delete” &nbsp;as per the requirement. &nbsp;</div>
 +
&nbsp;
  
Once created, users can ''Edit, Delete, Cancel ''or ''Submit ''the ''Risk Assessment''.&nbsp;
 
  
 
=== Searching and viewing the Risk Assessment ===
 
=== Searching and viewing the Risk Assessment ===
  
#'''Click '''the ''Risk Management ''> ''Risk Assessment ''on the ''Home ''page.  
+
1.&nbsp;'''Click '''the "Risk Management"&nbsp;> "Risk Assessments" tile options&nbsp;on the "Home"&nbsp;page.
 
+
<div class="image-green-border">The Risk Assessment index&nbsp;page opens displaying all the risk assessments.&nbsp;Users can refine the search result by applying filters, options and keywords.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:8.1-RiskAssessmentIndexPage.PNG|720px|8.1-RiskAssessmentIndexPage.PNG]]</div>
screen 11
+
2.&nbsp;'''Click '''the View Record eye&nbsp;icon next to the Risk Assessment record you want to open. For example, "Risk Assessment for Acme Corporation". The Risk Assessment Details page opens.
 
+
<div class="image-green-border">[[File:RMApp1-20.PNG|720px|RMApp1-20.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">The left navigation pane can be expanded or collapsed, as needed. The collapsed view gives a wider view of the Risk Assessment Details page.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-RiskWorkflow26.PNG|560px|RMApp-RiskWorkflow26.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">Clicking the hamburger menu icon&nbsp;[[File:Hamburger-menu-1.jpg|15px|Hamburger-menu-1.jpg]] expands the left pane.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-RiskWorkflow27.PNG|560px|RMApp-RiskWorkflow27.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">'''Advanced Search'''</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">The Advanced Search now displays the business app entity Risk Assessment and Risk Area in the Advanced Search window.&nbsp;</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:8.1-RMApp-AdvancedSearch.PNG|720px|8.1-RMApp-AdvancedSearch.PNG]]</div> <div class="image-green-border">&nbsp;</div>
The saved search result page opens with all ''Risk Assessment ''records.
+
 
+
screen 12
+
<ol start="2">
+
<li>'''Click '''the ''View Record ''icon next to the ''Risk Assessment ''record you want to open. For example, ''Risk_Assessment_May2020''. The ''Risk Assessment Details ''page opens.</li>
+
</ol>
+
 
+
screen 13
+
  
 
=== Editing the Risk Assessment ===
 
=== Editing the Risk Assessment ===
<ol start="3">
 
<li>'''Click '''Edit on the Risk Assessment Details page. The Edit Agreement page opens.</li>
 
</ol>
 
  
screen 14
+
1.&nbsp;'''Click '''"Edit" on the Risk Assessment Details page. The Edit Risk Assessment page opens.
<ol start="4">
+
<div class="image-green-border">[[File:RMApp-Edit.PNG|720px|RMApp-Edit.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">2.&nbsp;'''Make '''the required changes and '''click'''&nbsp;"Next". The "Verify"&nbsp;page opens.&nbsp;</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-Edit2.PNG|600px|RMApp-Edit2.PNG]]</div>
<li>'''Make '''the required changes and click Next. The Verify page opens.</li>
+
3.&nbsp;'''Verify '''the details and '''click'''&nbsp;"Update". The risk assessment is updated and remains in "Draft" state.
<li>'''Verify '''the details and click Update. The risk assessment is updated and remains in Draft state.</li>
+
<div class="image-green-border">[[File:RMApp-Edit3.PNG|480px|RMApp-Edit3.PNG]]</div>  
</ol>
+
&nbsp;
  
 
=== Canceling the Risk Assessment ===
 
=== Canceling the Risk Assessment ===
<ol start="6">
 
<li>'''Click '''Cancel on the Risk Assessment Details page.</li>
 
</ol>
 
 
screen 15
 
  
 +
1.'''Click '''"Cancel" on the Risk Assessment Details page.
 +
<div class="image-green-border">[[File:RMApp-Cancel.PNG|840px|RMApp-Cancel.PNG]]</div>
 
The confirmation window opens.
 
The confirmation window opens.
 +
<div class="image-green-border">[[File:RMApp-Cancel2.PNG|360px|RMApp-Cancel2.PNG]]</div>
 +
2.&nbsp;'''Click '''"Yes". The "Add Note" drawer&nbsp;opens.
 +
<div class="image-green-border">[[File:RMApp-Cancel3.PNG|540px|RMApp-Cancel3.PNG]]</div>
 +
3.&nbsp;'''Add '''note text and '''select''' the "Reason Code".
  
screen 16
+
4.&nbsp;'''Click '''"Add". The Risk Assessment status changes to "Cancelled".
<ol start="7">
+
<div class="image-green-border">[[File:RMApp-Cancel4.PNG|720px|RMApp-Cancel4.PNG]]</div>  
<li>'''Click '''Yes. The Add Note window opens.</li>
+
&nbsp;
</ol>
+
  
screen 17
+
&nbsp;
<ol start="8">
+
<li>'''Add '''note text and select the Reason Code.</li>
+
<li>'''Click '''Add. The Risk Assessment status changes to Cancelled.</li>
+
</ol>
+
 
+
screen 18
+
  
 
=== Deleting the Risk Assessment ===
 
=== Deleting the Risk Assessment ===
<ol start="10">
 
<li>'''Click '''Delete on the Risk Assessment Details page. The risk assessment will be deleted.</li>
 
</ol>
 
  
screen 19
+
1.&nbsp;'''Click '''"Delete" on the Risk Assessment Details page.&nbsp;
 +
<div class="image-green-border">[[File:RMApp-Delete1.PNG|720px|RMApp-Delete1.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">The "Add Note"&nbsp;window opens.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">2.&nbsp;'''Add''' note text and '''select''' the "Reason Code".</div>
 +
3.&nbsp;'''Click'''&nbsp;"Add". The risk assessment will be deleted and risk assessment index page opens.
 +
 
 +
&nbsp;
  
 
=== Submitting the Risk Assessment ===
 
=== Submitting the Risk Assessment ===
<ol start="11">
 
<li>'''Click '''Submit on the Risk Assessment Details page. The risk assessment is sent for approval and its status changes to Waiting for Approval.&nbsp;</li>
 
</ol>
 
  
screen 20
+
'''&nbsp;Click '''"Submit" on the Risk Assessment Details page.
 +
<div class="image-green-border">[[File:RMApp-Submit.PNG|720px|RMApp-Submit.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">The risk assessment is sent for approval and its status changes to "Waiting for Approval".</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-Submit2.PNG|720px|RMApp-Submit2.PNG]]</div>
 +
Approvers can Approve or Reject the Risk Assessment from the risk assessment Details page.
  
Approvers can Approve or Reject the Risk Assessment from the risk assessment Details page.&nbsp;
+
&nbsp;
  
'''To reject:'''
+
&nbsp;
<ol start="12">
+
<li>'''Click '''Reject. The Add note window opens.</li>
+
</ol>
+
  
screen 21
+
=== Rejecting the risk assessment ===
<ol start="13">
+
<li>'''Add '''note text and select the Reason Code.</li>
+
<li>'''Click '''Add. The Risk Assessment goes back to Draft state.</li>
+
</ol>
+
  
'''To approve:'''
+
'''To reject:'''
<ol start="15">
+
<li>'''Click '''Approve. The Add Note window opens.&nbsp;</li>
+
<li>'''Add '''note text and select the Reason Code.</li>
+
<li>'''Click '''Add. The Risk Assessment state changes to Assessment Complete.</li>
+
</ol>
+
  
If there are no Approvers added to the Risk Assessment Team, the record will be approved directly and move to the Assessment Complete state.<br/> &nbsp;
+
1.&nbsp;'''Click '''"Reject".&nbsp;
 +
<div class="image-green-border">[[File:RMApp-Reject1.PNG|700px|RMApp-Reject1.PNG]]</div>
 +
2.&nbsp;'''Add '''note text and select the Reason Code.
 +
<div class="image-green-border">[[File:RMApp-Reject2.PNG|600px|RMApp-Reject2.PNG]]</div>  
 +
3.&nbsp;'''Click '''"Add". The Risk Assessment is rejected and&nbsp;goes back to "Draft" state.
  
screen 22
+
&nbsp;
  
Note: The Assessment Complete state is the final state for Risk Assessment, and users cannot take further actions.
+
&nbsp;
  
=== Auditing Risk Assessment ===
+
=== Approving the risk assessment ===
  
Changes made to the Risk Assessment record during various ICM risk management workflows are captured and can be viewed under History tab. For example, changes in Risk_Assessment_May2020 throughout its lifecycle are captured.
+
'''To approve:'''
  
screen 23
+
1.&nbsp;'''Click '''"Approve". The "Add Note" window opens.&nbsp;
 +
<div class="image-green-border">[[File:1080px-8.0 RM 3.PNG|720px|1080px-8.0 RM 3.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">2.&nbsp;'''Add&nbsp;'''note text.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">3.&nbsp;'''Click '''"Add". The Risk Assessment state changes to "Assessment Complete".</div>
 +
If there are no Approvers added to the Risk Assessment Team, the record will be approved directly and move to the "Assessment Complete" state.
 +
<div class="image-green-border">[[File:RMApp-Complete.PNG|720px|RMApp-Complete.PNG]]</div>
 +
&nbsp;
 +
<div class="note-box">'''Note''': The "Assessment Complete" state is the final state for Risk Assessment, and users cannot take further actions.</div>
 +
&nbsp;
  
 
&nbsp;
 
&nbsp;
 +
 +
=== Auditing Risk Assessment ===
 +
 +
Changes made to the Risk Assessment record during various ICI risk management workflows are captured and can be viewed under "History" tab. For example, changes in "Risk Assessment for Acme Corporation&nbsp;throughout its lifecycle are captured.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow12.PNG|720px|RMApp-RiskWorkflow12.PNG]]</div>
 +
'''Click'''&nbsp;"Show Changes" to view the details of the particular event of the risk assessment instance.
 +
<div class="image-green-border">[[File:RMApp-History2.PNG|800px|RMApp-History2.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">Clicking the status of the Risk Assessment or Risk Area opens the “History” window.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:8.1-RMApp-History.png|500px|8.1-RMApp-History.png]]</div> <div class="image-green-border">&nbsp;</div>
  
 
== Working with Risk Area ==
 
== Working with Risk Area ==
Line 260: Line 285:
  
 
The risk area can be generated automatically by seeded rules based on the risk assessment responses. Users can also add the risk area manually to the risk assessment.
 
The risk area can be generated automatically by seeded rules based on the risk assessment responses. Users can also add the risk area manually to the risk assessment.
 +
 +
&nbsp;
  
 
=== <br/> Creating Risk Area automatically using rules ===
 
=== <br/> Creating Risk Area automatically using rules ===
  
=== Creating Risk Area manually ===
+
The ICI Risk Management application provides set of rules to generate Risk Areas automatically based on the responses gathered from the risk assessment. Refer the "ICI Risk Management Configuration Guide" for details on rules used in the ICI Risk Management application.
 +
 
 +
The workflow for generating risk areas automatically includes process as follows:
 +
 
 +
1.&nbsp;A recommended rule "Identify Risk Areas" can be configured by the app implementation team&nbsp;on the event "Risk Assessment Created" to identify&nbsp;applicable risk areas, based on the specific attribute values from the Risk Assessment record.
 +
 
 +
For the attribute "Risk Assessment Description", if the response is "Sup" (representing supplier), then the Applicable Risk Area is identified and set as "Sanctions".
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow32.png|360px|RMApp-RiskWorkflow32.png]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">2.&nbsp;Once the "Risk Areas" are identified, the seeded rule "Auto instantiate applicable risk area" generates those identified risk areas.</div> <div class="image-green-border">3.&nbsp;Another seeded rule "Copy Attribute Values" then copies values specified in the rule from Risk Assessment record to the Risk Areas.</div> <div class="image-green-border">For example, when the "Risk_Assessment_Jan2022" is approved, the risk area is automatically created as "Sanctions".</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-RiskWorkflow33.PNG|720px|RMApp-RiskWorkflow33.PNG]]</div>
 +
&nbsp;
 +
 
 +
&nbsp;
 +
 
 +
=== Creating Risk Area manually&nbsp; ===
  
 
To create a risk area for risk assessment:&nbsp;
 
To create a risk area for risk assessment:&nbsp;
  
#'''Click '''Risk Management > Risk Assessment on the Home page. The search results page with all risk assessment records opens.
+
1.&nbsp;'''Click '''"Risk Management" > "Risk Assessments" from&nbsp;the "Home" page. The search results page with all risk assessment records opens.
#'''Click '''the View Record icon next to the Risk Assessment for which you want to create Risk Area. The Risk Assessment Details page opens.
+
#'''Click '''Create Association action icon (plus sign) next to Risk Area under the Associations. The Create Association for Risk Area page opens.  
+
  
screen 1
+
2.&nbsp;'''Click '''the View Record icon next to the Risk Assessment for which you want to create Risk Area. The Risk Assessment Details page opens.
  
The Create Association Risk Area page has sections:
+
3.&nbsp;'''Click '''Create Association action icon (plus sign) next to Risk Area under the Associations. The "Create Association" for Risk Area page opens.
 +
<div class="image-green-border">[[File:RMApp-Association1-1.PNG|720px|RMApp-Association1-1.PNG]]</div>
 +
The "Create Association Risk Area" page has these sections:
  
 
*Reference Risk Assessment  
 
*Reference Risk Assessment  
Line 280: Line 319:
 
*Risk Remediation Plan&nbsp;  
 
*Risk Remediation Plan&nbsp;  
 
*Residual Risk Rating&nbsp;  
 
*Residual Risk Rating&nbsp;  
<ol start="4">
+
 
<li>'''Select '''or enter the details in the attributes in all the sections. The attributes can be mandatory, lookup type, cascading, conditional, multi-select and so on.</li>
+
4.&nbsp;'''Select '''or '''enter''' the details in the attributes in all the sections. The attributes can be mandatory, lookup type, cascading, conditional, multi-select and so on.
</ol>
+
  
 
'''Reference Risk Assessment'''
 
'''Reference Risk Assessment'''
Line 290: Line 328:
 
*Risk Assessment Name: This field is populated automatically based on the information entered when creating the risk assessment.&nbsp;  
 
*Risk Assessment Name: This field is populated automatically based on the information entered when creating the risk assessment.&nbsp;  
 
*Risk Assessment Description: This field is populated automatically based on the information entered when creating the risk assessment.&nbsp;  
 
*Risk Assessment Description: This field is populated automatically based on the information entered when creating the risk assessment.&nbsp;  
 
+
<div class="image-green-border">[[File:RMApp-Association2.PNG|600px|RMApp-Association2.PNG]]</div>
screen 2
+
 
+
 
'''Risk Area Details&nbsp;'''
 
'''Risk Area Details&nbsp;'''
  
Line 298: Line 334:
  
 
*Risk Area Instance ID: This is generated automatically after the risk area is created.  
 
*Risk Area Instance ID: This is generated automatically after the risk area is created.  
*Risk Area Name: Select the risk area name from the drop-down list. This populates the information for the following attributes.&nbsp;  
+
*Risk Area Name: '''Select''' the risk area name from the dropdown list. This populates the information for the following attributes from the masterdata.&nbsp;  
 
**Risk Area Master ID&nbsp;  
 
**Risk Area Master ID&nbsp;  
 
**Short Description  
 
**Short Description  
 
**Category  
 
**Category  
**Sub Category   
+
**Sub Category  
*Origin: Enter the description that contains information about the probable source of risk area.&nbsp;  
+
**"Risk Area Owner"    
*Effect: Enter the description about the probable effects of the risks foreseen based on the risk assessment created.  
+
*Origin: '''Enter''' the description that contains information about the probable source of risk area.&nbsp;  
*Risk Area Owner: Select the user from the risk assessment team as the risk area owner who can validate whether the created risk is valid and the probable level of risk.&nbsp;
+
*Effect: '''Enter''' the description about the probable effects of the risks foreseen based on the risk assessment created.  
*Additional Risk Area Owners: You can add additional risk area owners to whom the risk assessment task can be delegated as required.
+
*Additional Risk Area Owners: If risk area owner is not available in master, then user can add additional risk area owners.&nbsp;
 
+
screen 3
+
 
+
Note: The values in the risk area details section can be auto-populated from Risk Area Master. The Risk Owner can be added to the risk area through configured rules.
+
  
 +
Risk Area owners are Subject Matter Experts who can look into risk area end to end for validity of risk, planning risk remediation, monitoring the progress and performance of risk remediation actions
 +
<div class="image-green-border">[[File:RMApp-Association3.PNG|600px|RMApp-Association3.PNG]]</div>
 +
&nbsp;
 +
<div class="note-box">'''Note''': The certain values in the risk area details section can be auto-populated from Risk Area Master . The Risk Owner and Additional Risk Area Owners can be added to the risk area team through configured rules.</div>
 
'''Inherent Risk Rating&nbsp;'''
 
'''Inherent Risk Rating&nbsp;'''
  
 
Inherent risk rating is the risk rating applicable to the risk when it was determined for the first time.<br/> This section contains the attributes:
 
Inherent risk rating is the risk rating applicable to the risk when it was determined for the first time.<br/> This section contains the attributes:
  
*Inherent Risk Trigger Date: Select the date and time on which the inherent risk record is created.  
+
*Inherent Risk Trigger Date: The date and time on which the inherent risk record is created.  
*Inherent Likelihood Rating: This comprises of the level of impact of the probable risk. Select the appropriate level from this list.&nbsp;
+
*Inherent Likelihood Rating: The probability of occurrence of risk.  
*Inherent Consequence Rating: This comprises of the effects of the foreseen risks happening in reality.&nbsp;  
+
*Inherent Consequence Rating: The impact or consequence of risk occurrence.&nbsp;  
*Inherent Risk Level: This comprises of the risk posed by the errors made by factors other than a failure of internal control. Select the level of inherent risks based on the risk assessment created.  
+
*Inherent Risk Level:Qualitative scoring based on likelihood of risk occurrence and consequence if risk occurred.&nbsp;
*Inherent Risk score: This comprises the amount of impact a foreseen risk might have on the business operations and so on.  
+
*Inherent Risk score:Quantitative scoring based on likelihood of risk occurrence and consequence if risk occurred.&nbsp;
 +
<div class="note-box">Note: The Inherent risk level and score is determined from the values in inherent likelihood rating and consequences rating and can be entered manually or by configuring rules.</div>
 +
*Comments: This includes any additional information that you might want to provide regarding the risk assessment created.
 +
<div class="image-green-border">[[File:RMApp-Association4.PNG|600px|RMApp-Association4.PNG]]</div>
 +
'''Risk Remediation Plan&nbsp;'''
  
Note: The Inherent risk level and score is determined from the values in inherent likelihood rating and consequences rating and can be entered manually or by configuring rules.
+
This section includes the informaton related to the remediation strategies and actions that can be taken to mitigate the risk areas.<br/> This section contains the attributes:&nbsp;
  
*Comments: This includes any additional information that you might want to provide regarding the risk assessment created.  
+
*Remediation Action: '''Enter''' the remediation action that is planned to be taken to minimize the probable risks.&nbsp;
 +
*Control Effectiveness: '''Select''' the level from the dropdown list that defines the level of effectiveness of measures that will be applied to minimize the risks.
 +
*Remediation Action Details: '''Enter''' the remediation action details that describe the remediation actions that will be taken to minimize the risk.&nbsp;
 +
<div class="image-green-border">&nbsp;[[File:RMApp-Association5.PNG|600px|RMApp-Association5.PNG]]</div>
 +
'''Residual Risk Rating'''<br/> This section includes the information related to the residual risk left after the remediation actions are taken.<br/> This section contains the attributes:
  
screen 4
+
*Residual Risk Update Date: The date on which the residual risk record is updated.
 +
*Residual Likelihood Rating: This indicates the likelihood of occurrence of the remaining risk.&nbsp;
 +
*Residual Consequence Rating: This indicates impact of occurrence of the remaining risks happening after the mitigations actions are implemented.
 +
*Residual Risk Level: Qualitative scoring based on likelihood and consequence if residual risk occurred.&nbsp;&nbsp;
 +
*Residual Risk Score: Quantitative scoring based on likelihood and consequence if residual risk occurred.&nbsp;
 +
*Comments for Residual Risk:&nbsp;This includes any additional information that you might want to provide regarding the risk area.
 +
<div class="image-green-border">[[File:RMApp-Association6.PNG|600px|RMApp-Association6.PNG]]</div>
 +
5.&nbsp;'''Click '''"Create". The Risk Area is created in Assessment state.&nbsp;
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow14.PNG|720px|RMApp-RiskWorkflow14.PNG]]</div>
 +
&nbsp;
  
'''Risk Remediation Plan&nbsp;'''
+
&nbsp;
  
This section includes the informaton related to the remediation stategies and actions that can be taken to mitigate the risk areas.<br/> This section contains the attributes:&nbsp;
+
&nbsp;
  
*Remediation Action: Enter the remediation action that is planned to be taken to minimize the probable risks.&nbsp;
+
&nbsp;
*Control Effectiveness: Select the level from the drop-down list that defines the level of effectiveness of measures that will be applied to minimize the risks.
+
*Remediation Action Details: Enter the remediation action details that describe the remediation actions that will be taken to minimize the risk.&nbsp;  
+
  
&nbsp;screen 5
+
&nbsp;
  
'''Residual Risk Rating'''<br/> This section includes the information related to the residual risk left after the remediation actions are taken.<br/> This section contains the attributes:
+
&nbsp;
  
*Residual Risk Update Date: This date is populated automatically based on the remaining risk after the mitigation actions are implemented.&nbsp;
+
=== Searching Risk Area records ===
*Residual Likelihood Rating: This indicates the score that depicts the likelihood of the remaining risk.&nbsp;
+
*Residual Consequence Rating: This indicates the level of consequences of the remaining risks happening after the mitigations actions are implemented.
+
*Residual Risk Level: This indicates the level of remaining risk after the mitigation actions are implemented.&nbsp;
+
*Residual Risk Score: It is the score that depicts the remaining risk after the mitigation actions are implemented.&nbsp;
+
  
screen 6
+
Risk Area records can be searched from:
  
*File Path: Select and upload any document that provides more information about the risk assessment.&nbsp;
+
*Advanced Search page
*Business Status: Select the business status of the risk area that you are creating. For example, Assessment.&nbsp;
+
*Global Search
  
screen 7
+
To&nbsp;search risk area from Advanced Search page:
<ol start="5">
+
<li>'''Click '''Create. The Risk Area is created in Assessment state.&nbsp;</li>
+
</ol>
+
  
screen 8
+
1.&nbsp;'''Click'''&nbsp;the "Advanced" link on the header toolbar. The "Advanced Search" page opens.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow16.PNG|600px|RMApp-RiskWorkflow16.PNG]]</div>
 +
<br/> 2. '''Select '''"Risk Area" in the "Entity"&nbsp;dropdown&nbsp;field.
 +
<div class="image-green-border">[[File:RMApp-RASearch1.PNG|360px|RMApp-RASearch1.PNG]]</div>
 +
3. '''Click''' the search icon. All available Risk Area records are displayed.
 +
<div class="image-green-border">[[File:RMApp-RASearch2.PNG|720px|RMApp-RASearch2.PNG]]</div>
 +
&nbsp;
  
=== Searching Risk Area records ===
+
The left navigation pane can be expanded or collapsed, as needed. The collapsed view gives a wider view of the Risk Area Details page.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow28.PNG|600px|RMApp-RiskWorkflow28.PNG]]</div> <div class="image-green-border">Clicking the hamburger menu icon&nbsp;[[File:Hamburger-menu-1.jpg|15px|Hamburger-menu-1.jpg]] expands the left pane.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-RiskWorkflow29.PNG|600px|RMApp-RiskWorkflow29.PNG]]</div>
 +
&nbsp;
  
Risk Area records can be searched from:
+
=== Risk Area using Global Search ===
  
*Associations index page
+
To search risk area using Global Search:
*Risk Assessments search result page
+
  
To search risk area from association index page:
+
Enter the relevant search criteria in the Enter search here…search bar on the ICI UI. For example, "Risk Area". All available Risk Area records are displayed in a dropdown.
 +
<div class="image-green-border">[[File:RMApp-RASearch3.PNG|480px|RMApp-RASearch3.PNG]]</div>
 +
&nbsp;
  
#'''Click '''Associations Management > Associations on the Home page. The Associations index page opens.
+
&nbsp;
#'''Filter '''the records for Risk Area entity using Categories facet search. All available Risk Area records are displayed.
+
  
&nbsp;screen 9
 
  
To search risk area from Risk Assessments search result page:
+
=== Working of existing ICI actions for Risk Area ===
  
#'''Click '''Risk Management > Risk Assessment on the Home page. The search page with all risk assessment records opens.
+
Risk area owner can take existing ICI actions for associations on risk area.
#'''Select '''Risk Area in the Please select Entities to search field.
+
#'''Click '''search icon. All available Risk Area records are displayed.  
+
  
screen 10
+
*Preview Document: Opens the preview of the risk area if available, in the Document Viewer drawer.
 +
*View Smart Links: Opens the smart links if available, in a Smart Links window.&nbsp;
 +
*Edit: Opens the Edit Associated Document - Risk Area page to modify the details of the risk area instance.
 +
*View Details: Opens the Risk Area Details page.
 +
<div class="image-green-border">[[File:900px-8.1-RiskAreaAssociationList.png|720px]]</div> <div class="image-green-border">&nbsp;</div>
  
 
=== Taking actions on the Risk Area ===
 
=== Taking actions on the Risk Area ===
  
The Risk owner can be added to the risk area through configured rules. Risk owner then can take certain actions from the risk area Details page when the risk area is in Assessment state. &nbsp;<br/> The actions can be:
+
The Risk owner can be added to the risk area through configured rules. Risk owner can&nbsp;then take certain actions from the risk area Details page. &nbsp;<br/> The actions can be:
  
 
*Initiate Due Diligence - action taken to capture more information related to the risk and validate the identified risk area.&nbsp;  
 
*Initiate Due Diligence - action taken to capture more information related to the risk and validate the identified risk area.&nbsp;  
*Remediate - action taken to mitigate the valid risk  
+
*Remediate - action taken to mitigate the valid risk area.
*Deactivate - action taken for risks identified as invalid. Users can not take further &nbsp;actions once the risk area is deactivated.  
+
*Deactivate - action taken for risk area&nbsp;identified as invalid. Users cannot take further &nbsp;actions once the risk area is deactivated.  
 
*Monitor - action taken to track the performance based on remediation actions until risks are completely mitigated  
 
*Monitor - action taken to track the performance based on remediation actions until risks are completely mitigated  
  
Users can repeat the workflow Due Diligence – Remediate – Monitor until the risk is completely mitigated.<br/> Users can also automate the workflows to initiate due diligence, remediate and monitor risk areas by configuring rules.<br/> &nbsp;
+
Users can repeat the workflow Due Diligence – Remediate – Monitor until the risk is completely mitigated.<br/> Users can also automate the workflows to initiate due diligence, remediate and monitor risk areas by configuring rules.
  
==== Editing Risk Area ====
+
&nbsp;
  
#'''Click '''Risk Management > Risk Assessments on the Home page. The list of all available risk assessments opens.
+
&nbsp;
#'''Click '''View Record icon next to the Risk Assessment you want to opens. The Risk Assessment Details page opens.
+
#'''Click '''Risk Area tab in the left navigation. The risk area grid opens.
+
#'''Click '''View Record icon next to the risk area you want to open. The risk area Details page opens.
+
#'''Click '''Edit. The Edit Associated Document for Risk Area page opens.
+
  
screen 11
+
&nbsp;
<ol start="6">
+
<li>'''Make '''the required changes and click Update. The Risk Area is updated and the Risk Area Details page opens again.</li>
+
</ol>
+
  
==== Initiating Due Diligence ====
+
&nbsp;
  
'''Click '''Initiate Due Diligence. The Risk Area Details page opens again.&nbsp;
+
==== Editing Risk Area from Three Dots Menu ====
  
screen 12
+
1.&nbsp;'''Click '''"Risk Management" > "Risk Assessments" from&nbsp;the Home page. The list of all available risk assessments opens.
  
The status of the risk area changes to Due Diligence.
+
2.&nbsp;'''Click '''View Record icon next to the Risk Assessment you want to opens. The Risk Assessment Details page opens.
  
screen 13
+
3.&nbsp;'''Click '''"Risk Area" tab in the left navigation. The risk area grid opens.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow21.PNG|720px|RMApp-RiskWorkflow21.PNG]]</div>
 +
4.&nbsp; '''Click''' the three dots menu of a Risk Area record.
 +
<div class="image-green-border">5.&nbsp;'''Click '''"Edit". The "Edit Risk Area" for Risk Area page opens.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-RiskWorkflow25.PNG|720px|RMApp-RiskWorkflow25.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">6.&nbsp;Make the required changes and '''click '''"Update". The Risk Area will be updated and the Risk Area Details page opens again.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:RMApp-RiskWorkflow24.PNG|600px|RMApp-RiskWorkflow24.PNG]]</div> <div class="image-green-border"><br/> &nbsp;</div>
 +
==== Editing Risk Area from&nbsp;Risk Area Details page ====
 +
<div class="image-green-border">&nbsp;</div> <div class="image-green-border">Users can edit the Risk Area from the Risk Area Details page as well:</div> <div class="image-green-border">
 +
1.&nbsp;'''Click '''View Record icon next to the risk area you want to open. The risk area Details page opens.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow22.PNG|720px|RMApp-RiskWorkflow22.PNG]]</div>
 +
2.&nbsp;'''Click '''"Edit". The "Edit Associated Document" for Risk Area page opens. Then, follow the aforementioned step # 6 under "Editing Risk Area from Three Dots Menu" to edit and save the editing.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow23.PNG|720px|RMApp-RiskWorkflow23.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">&nbsp;</div> </div> <div class="image-green-border">&nbsp;</div>
 +
==== Initiating Due Diligence ====
  
 +
'''Click '''"Initiate Due Diligence". The Risk Area Details page opens again.
 +
<div class="image-green-border">[[File:RMApp-RAActions4-4.PNG|720px|RMApp-RAActions4-4.PNG]]</div>
 +
The status of the risk area changes to "Due Diligence".
 +
<div class="image-green-border">[[File:RMApp-RAActions5.PNG|720px|RMApp-RAActions5.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">&nbsp;</div>
 
==== Remediating the risk area ====
 
==== Remediating the risk area ====
  
'''Click '''Remediate on the risk area Details page. The Risk Area Details page opens again.&nbsp;
+
With the status of the risk area in&nbsp;"Due Diligence", '''click '''"Remediate" on the risk area Details page.
 
+
screen 14
+
 
+
The status of the risk area changes to Remediation.
+
 
+
screen 15
+
  
 +
The Risk Area Details page opens again&nbsp;and the status of the risk area changes to "Remediation".
 +
<div class="image-green-border">[[File:RMApp-RAActions6.PNG|720px|RMApp-RAActions6.PNG]]</div> <div class="image-green-border" style="text-align: justify;">&nbsp;</div> <div class="image-green-border" style="text-align: justify;">&nbsp;</div>
 
==== Monitoring the risk area ====
 
==== Monitoring the risk area ====
  
Users can monitor the risk areas based on the remediation actions taken to check whether the risks are reduced.&nbsp;<br/> To monitor a risk area:&nbsp;<br/> Click Monitor on the risk area Details page. The Risk Area Details page opens.&nbsp;
+
Users can monitor the risk areas based on the remediation actions taken to check whether the risks are reduced.&nbsp;
  
screen 16
+
To monitor a risk area:&nbsp;
  
The status of the risk area changes to Monitoring.
+
'''Click'''&nbsp;"Monitor" on the risk area Details page. The risk area Details page opens again and the status of the risk area changes to "Monitoring".&nbsp;
 
+
<div class="image-green-border">[[File:RMApp-RAActions7.PNG|600px|RMApp-RAActions7.PNG]]</div>
screen 17
+
The status of the risk area changes to "Monitoring".
 
+
<div class="image-green-border">[[File:RMApp-RAActions8.PNG|600px|RMApp-RAActions8.PNG]]</div> <div class="image-green-border">&nbsp;</div>
==== Reassessing the risk area ====
+
==== Iterating workflow&nbsp;for risk area ====
  
 
Users can repeat the actions taken on the risk areas until the risks are completely mitigated.
 
Users can repeat the actions taken on the risk areas until the risks are completely mitigated.
  
#'''Click '''Initiate Due Diligence or Remediate on the risk area Details page for the risk area in the Monitoring state. For example, select Initiate Due Diligence. The Association Initiate Due Diligence note window opens to add a note.
+
1.&nbsp;'''Click '''"Initiate Due Diligence" or "Remediate" on the risk area Details page for the risk area in the Monitoring state. For example, select Initiate Due Diligence. The Association "Initiate Due Diligence" note window opens to add a note.
#'''Add '''a note text and select a Reason code.  
+
  
screen 18
+
2.&nbsp;'''Add '''a note text and select a Reason code.
<ol start="3">
+
<div class="image-green-border">[[File:RMApp-RAActions9.PNG|600px|RMApp-RAActions9.PNG]]</div>  
<li>'''Click '''Add. The status of the risk area changes back to Due Diligence.</li>
+
3.&nbsp;'''Click '''"Add". The status of the risk area changes back to Due Diligence.
</ol>
+
  
screen 19
+
&nbsp;
  
 
==== Deactivating the risk area ====
 
==== Deactivating the risk area ====
Line 452: Line 506:
 
Risk owners can deactivate the invalid risk area. Once deactivated, no further actions are allowed on the risk area.
 
Risk owners can deactivate the invalid risk area. Once deactivated, no further actions are allowed on the risk area.
  
#'''Click '''Deactivate on the risk area Details page. The Association Deactivate note window opens to add a note.  
+
1.&nbsp;'''Click '''"Deactivate" on the risk area Details page. The "Add Note - Deactivate" drawer opens to add a note.
 +
<div class="image-green-border">[[File:RMApp-RAActions10.PNG|720px|RMApp-RAActions10.PNG]]</div>
 +
2.&nbsp;'''Add '''a note text and select a Reason code.
 +
<div class="image-green-border">[[File:RMApp-RAActions12.PNG|600px|RMApp-RAActions12.PNG]]</div>
 +
3.&nbsp;'''Click '''"Add". The status of the risk area changes to "Deactivated".
 +
<div class="image-green-border">[[File:RMApp-RAActions13.PNG|600px|RMApp-RAActions13.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">&nbsp;</div>
 +
==== Auditing Risk Area ====
  
screen 20
+
Changes made to the Risk Area record during various ICI risk management workflows are captured and can be viewed under History tab. For example, changes in "ICMRiskArea_100"&nbsp;throughout its lifecycle are captured.
<ol start="2">
+
<div class="image-green-border">[[File:RMApp-RiskWorkflow30.PNG|720px|RMApp-RiskWorkflow30.PNG]]</div>  
<li>'''Add '''a note text and select a Reason code.</li>
+
'''Click'''&nbsp;"Show Changes" to view the details of the particular event of the risk area instance.
<li>'''Click '''Add. The status of the risk area changes to Deactivated.</li>
+
<div class="image-green-border">[[File:RMApp-RiskWorkflow31.PNG|720px|RMApp-RiskWorkflow31.PNG]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">Clicking the status of the&nbsp;Risk Area on the "Details" page opens the “History” window.</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">[[File:8.1-RMApp-History1.png|720px|8.1-RMApp-History1.png]]</div> <div class="image-green-border">&nbsp;</div> <div class="image-green-border">&nbsp;</div>
</ol>
+
&nbsp;
  
screen 21
+
==== Moving Risk Area workflow automatically ====
  
==== Auditing Risk Area ====
+
Users can manage the Risk Assessment and Risk Area action workflows using the script attribute Target ICM Status. Users can set the value in Target ICM Status to specific status and move records to that particular state during the risk management workflow.&nbsp;For example, risk area record can be moved from the Draft &nbsp;state to either Due Diligence, Remediation or Monitoring state using attribute Target ICM status .
  
Changes made to the Risk Area record during various ICM risk management workflows are captured and can be viewed under History tab. The History tab for Risk Area has All, Draft, Approval and Post-Approval tabs. For example, changes in ICMRiskArea_372 throughout its lifecycle are captured.
+
Risk assessment and risk area records can be uploaded in ICI directly in specific status by setting the state value in the Target ICM Status attribute using ICI’s Legacy Upload functionality. The business status would then be set accordingly.
  
screen 22
+
For example, when users want to upload large number of historical risk assessment records using Legacy Upload, they can directly upload in the Approved state by setting it in the Target ICM Status attribute and the business state would be set as Assessment Complete.
  
==== Automation of Risk Area workflow ====
+
Refer the ICI Risk Management Configuration Guide for details on Managing Risk Workflows using attribute Target ICM Status.
  
The Risk Area action workflows can also be managed automatically by configuring rules. Users can set the value in the script type attribute Target ICM to move the Risk Area workflow automatically from Assessment state to Due Diligence, Remediation or Monitoring state.
+
&nbsp;
  
 
== Creating and managing tasks for Risk workflow ==
 
== Creating and managing tasks for Risk workflow ==
  
Users can create remediation tasks for managing risks using commitments, obligations or any third party system. ICM Risk management app currently supports managing Risk Assessments using ICM Commitment functionaity.<br/> To create a task using commitment:
+
Users &nbsp;can create remediation tasks for managing risks using commitments, obligations or any third party system. ICI Risk Management app currently supports managing Risk Assessment and Risk Area using ICI Commitment functionality.
  
#'''Click '''the Risk Management > Risk Assessment on the Home page. The saved search result page opens with all Risk Assessment records.
+
To create a task using commitment:
#'''Click '''the View Record icon next to the Risk Assessment record you want to open. For example, Risk_Assessment_May2020. The Risk Assessment Details page opens.
+
#'''Click '''the Commitments tab in the left navigation. The existing commitments are displayed if any.
+
#'''Click '''Select Action (3 dots) icon next to the Commitment text. The actions available for the selected commitment will be displayed in the drop-down.
+
#'''Edit '''or '''delete '''the existing Commitment using the Edit Commitment or Delete Commitment options.
+
#'''Click '''Add Commitment action icon. The Add Commitment window opens.&nbsp;
+
  
screen 1
+
1.&nbsp;'''Click '''"Risk Management" > "Risk Assessment" from the "Home" page. The saved search result page opens with all Risk Assessment records.
<ol start="7">
+
<li>'''Enter '''the details for the commitment.</li>
+
</ol>
+
  
screen 2
+
2.&nbsp;'''Click '''the View Record icon next to the "Risk Assessment" record you want to open. For example, "Risk_Assessment_Jan2022". The Risk Assessment Details page opens.
<ol start="8">
+
<li>'''Click '''Add Commitment. The commitment is created and added to the risk assessment.</li>
+
</ol>
+
 
+
screen 3
+
  
 +
3.&nbsp;'''Click '''the "Commitments" tab in the left navigation. The existing commitments are displayed if any.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow1.PNG|800px|RMApp-RiskWorkflow1.PNG]]</div>
 +
4.&nbsp;'''Click'''&nbsp;"Add Commitment" action icon. The "Add Commitment" drawer opens.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow2.PNG|600px|RMApp-RiskWorkflow2.PNG]]</div>
 +
5.&nbsp;Enter&nbsp;the details for the commitment and '''c''''''lick '''"Save". The commitment is created and added to risk assessment.&nbsp;
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow3.PNG|720px|RMApp-RiskWorkflow3.PNG]]</div>
 
To view and take action on the commitment tasks:
 
To view and take action on the commitment tasks:
<ol start="9">
 
<li>'''Click '''the icon Take action on commitment. The Add Action window opens.</li>
 
<li>'''Add '''the action details.</li>
 
<li>'''Click '''Save. The Commitment status is updated according to the action taken.</li>
 
</ol>
 
  
screen 4
+
1.&nbsp;'''Click '''the&nbsp;three dots menu and click "Take action on commitment". The "Take&nbsp;Action on Commitment" drawer opens.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow5-5.PNG|720px|RMApp-RiskWorkflow5-5.PNG]]</div>
 +
2.&nbsp;'''Add '''the action details.
 +
 
 +
3.&nbsp;'''Click '''"Save". The Commitment status is updated according to the action taken.
 +
<div class="image-green-border">[[File:RMApp-RiskWorkflow6.PNG|500px|RMApp-RiskWorkflow6.PNG]]<br/> &nbsp;</div> <div class="note-box">'''Note:&nbsp;'''The action can also be delegated to a desired user by clicking on the "Delegate" button.</div>
 +
Refer to the "Compliance Management" page for more details on working with commitments.
 +
 
 +
&nbsp;
  
 
== Accessing the Risk Area actions Notifications&nbsp; ==
 
== Accessing the Risk Area actions Notifications&nbsp; ==
  
The ICM Risk Management app sends the notifications when certain actions are taken on the Risk Area. These notifications are seeded.<br/> The notifications are sent when events occurs:
+
The ICI Risk Management app sends&nbsp;notifications when certain actions are taken on the Risk Area. These&nbsp;seeded notifications are sent when an events occurs:
  
 
*Risk area is created  
 
*Risk area is created  
Line 514: Line 570:
 
*Risk area is deactivated  
 
*Risk area is deactivated  
  
The recipients can access the notifications from Notification Dashboard:
+
The recipients can access the notifications from "Notification Dashboard":
 
+
#'''Click '''Notifications tab on the Home page. The Notifications Dashboard opens.
+
#'''Click '''Risk Management Notifications. The list of notification events opens.
+
#'''Expand '''the notification event. The notifications belonging to the selected event are displayed.&nbsp;
+
#'''Select '''the Notification you want to view. The selected Notification opens in the right pane.
+
 
+
screen 5
+
  
 +
#'''Click '''the'''&nbsp;'''Notifications bell icon on&nbsp;the top right. The "Notifications Dashboard" opens.
 +
<div class="image-green-border">[[File:RMApp-RiskNotifications1.PNG|600px|RMApp-RiskNotifications1.PNG]]</div> <ol start="2">
 +
<li>'''Click '''"Risk Management Notifications". The list of notification events opens.</li>
 +
<li>'''Expand '''the notification event. The notifications belonging to the selected event are displayed.&nbsp;</li>
 +
<li>'''Select '''the Notification you want to view. The selected Notification opens in the right pane.</li>
 +
</ol>
 +
<div class="image-green-border">[[File:RMApp-Notifications.png|720px|RMApp-Notifications.png]]</div>
 
&nbsp;
 
&nbsp;
  
Line 528: Line 584:
  
 
&nbsp;
 
&nbsp;
 +
 +
'''Related Topics''':''&nbsp;[[Agreement_Management|Agreement Management]]&nbsp;|&nbsp;''

Latest revision as of 17:21, 22 August 2022

ICI Risk Management App

Overview

The Icertis Contract Intelligence (ICI) platform introduces the Risk Management Application to make it easier for professionals to carry out their tasks related to risk management such as assessment, due diligence, remediation, monitoring and reassessment. Risk management is the process of identifying potential risk, assessing the magnitude of risk based on the business objectives, devising strategies to eliminate them and tracking the performance until they are completely mitigated.

The platform’s modern, scalable and integration-friendly cloud architecture can model even the most complex risk management scenarios. The App provides secure access such that only authorized users can access the App entities and data, using ICI’s access control functionalities. The user-friendly interface makes it possible for anyone in the enterprise having access to be able to use the platform with ease. 

Icertis uses a standard framework of discovery, assessment, remediation, monitoring and optimization to manage enterprise risk.

ICI Risk Management supports the following risk management business scenarios:  
  • Business Operations Risk: For example, the impact of pandemic on the business operations of an organization. 
  • Contractual Risk: For example, managing risks that arise from non-standard agreement terms, clauses, and so on. 
  • Counter-Party Risk: For example, managing risks relevant to suppliers and vendors.

The Terminology

Here are some terms that will help you better understand the risk management process:

  • Risk Assessment:  It deals with the process of identifying and evaluating the magnitude of potential risk areas.
  • Risk Area: It is the exposure that an organization has from internal or external factor(s) that impact the normal
    functioning of business and will lower its bottom line (or profits) or lead it to fail. For example, cyber security
    risk.
    • Risk Taxonomy: It is comprehensive set of risk categories and sub-categories used in an
      organization. It outlines as approach to categorize and aggregate all types of risks that could affect
      the organization's objectives.
    • Assessment: Risk owner determines or assesses whether identified risk area is valid or not.
      Likewise, risk owner can add a risk area manually.
    • Due Diligence: It is a complete review of the risk area. As part of incomplete or missing
      information, tasks may be created to gather information.
    • Remediation: It is a strategy created to mitigate risks. For example, Avoid strategy, Transfer
      Strategy, Reduce Strategy, etc. Based on the remediation strategy, mitigation tasks are initiated.
      • Control Effectiveness Rating: It represents the effectiveness of risk remediation actions
        taken to mitigate risk. 
  • Monitor and Optimize: Monitoring involves the process of tracking the progress of residual risk level and risk
    score of a risk area as against the remediation tasks made for mitigation. If the residual risk score and risk
    level does not change as compared to the inherent score, then optimization allows taking additional due
    diligence or remediation tasks to mitigate risk.
  • Risk Score Matrix:  It is a matrix that uses a combination of likelihood and consequence rating to determine
    magnitude of risk. 
    • Inherent Risk: It is a risk indicator. It is the starting score for each identified risk area and is
      expected to be controlled.
    • Residual Risk: It is a risk indicator. It is the score that depicts the risk remaining once mitigation
      actions have been planned and implemented.
    • Likelihood Rating: On a risk matrix, it represents the likelihood (level of probability) of risk
      occurrence.
    • Consequence Rating: On a risk matrix, it represents the magnitude (level of impact) of risk
      occurrence.
    • Risk Level:  It is the qualitative score for every risk area transaction.
    • Risk Score: It is the quantitative score for every risk area transaction.

The Challenge

Business risk can emerge from any division of a company and must be managed proactively to avoid devastating
impacts. Often, these risks originate in the contracts of an organization with an external party or because of the
business and regulatory environment in which the entity operates.
Yet, most organizations manage contractual, regulatory, financial reporting and environmental obligations
manually. Automated extraction and monitoring of obligations are prevalent in very few companies across various
industry verticals. Consequently, organizations do not have adequate visibility into the status of these obligations
and end up being reactive in identifying and handling risks.

This raises the following challenges: 

  • Companies cannot proactively assess and manage their risks in business environment characterized by
    unpredictability, volatility and mounting counter-party solvency risks.
  • Traditional Governance, Risk and Compliance (GRC) and Risk Management tools are not able to roll-up
    enterprise-wide risk insights from across contracts which are the ultimate source of commercial truth, and
    hence are only good at reporting and analyzing risks in hindsight. 
  • Lack of visibility and insight into obligations, typically spelled out in detail in service contracts, can lead to
    substantial risks for businesses if not surfaced at the appropriate time and monitored at an adequate level to
    provide required executive attention.

The Solution

Built on the Icertis Contract Intelligence platform, the ICI Risk Management App brings a paradigm shift in
the management of business risks. The App offers a process-oriented enterprise-wide solution to stay on top
of all potential risks that a business faces – whether they emanate from the potential insolvency of a
counter-party, payment default by a customer, supply disruption due to a pandemic or natural disaster,
logistics blockades due to localized conflicts, or other market turbulence.

With the Risk Management App, companies can: 

  • Perform risk discovery, assessment, remediation, monitoring and optimization in any business context that is
    relevant to a specific organization. For example, supplier risk assessment at the time of onboarding a supplier,
    customer credit risk check while signing long-term contracts on non-cash terms, contractual performance risk
    while evaluating technical capabilities of a service provider, etc. 
  • Prevent and reduce risk-injection as opposed to only managing risks.

The Capabilities

The intelligent and easy-to-use ICI Risk Management App offers these powerful capabilities:

  • Ability to embed risk assessment in various business processes:
    • For example, during negotiation, supplier/ customer onboarding, third party contract ingestion, etc.
  • Flexible and configurable risk assessment frameworks:
    • To cater to various industry and business-specific risk management requirements.
  • Questionnaire-based risk identification:
    • Questionnaire configuration capability to discover all vendor or business operation risks based on
      responses.
  • Risk area and scoring model configurability:
    • A configurable risk area to gauge contract, counter-party and operations risk at various levels of
      business granularity.
    • An easy-to-configure platform that helps to set up a quantitative and qualitative risk score model to
      meet business needs.
  • Alerts and notifications: 
    • In-built notifications to inform risk owner about changes in risk area status.
  • Auditing: 
    • Audit trails of every action with user and time-stamp details.

The Benefits 

  • The ICI Risk Management App changes the risk management paradigm from identification and mitigation to
    preventing risk injection and remediation.
  • Effective risk monitoring reduces the impact of operational, financial and reputational risk, contributing
    significantly to the company’s bottom line.
  • Configurable system can conform to any risk model in the world and even develop industry and companyspecific risk models with no custom code required, thereby greatly reducing deployment costs.

The Prerequisites

The user must have: 

  • Completed ICI Product Training
  • Risk Management App must be enabled on customer environment 

Configuration setup overview

ICI offers the ability to determine the application type (Contracting, Sourcing, Obligation Management and Risk Management application) when creating a contract type. This is possible with the inclusion of two new choice type attributes, Business Application Type and Business Application Category at the contract type level. This feature helps effortlessly drive business applications on ICI platform.
These attributes are enabled through technical configuration and  applicable for agreements and associated document contract types. The access privileges for business applications (such as Risk Management) are managed through security groups. 

Seeded Configuration and setup

The ICI Risk Management application provides  some seeded  entities, attributes, workflows, rules and notifications that are necessary for the flow of the risk management. Some of the entities are:

  • Masterdata: 
    • Risk Taxonomy
    • Risk Remediation
    • Risk Area Master
    • Likelihood Rating
    • Risk Score Matrix
  • Contract types:
    • Risk Assessment: as agreement contract type with Business Application Type as Risk Management and Business Application Category as Risk Assessment defined at contract type level.Risk Area as associated document contract type with business application type as risk management and business application category as risk area defined at contract type level.
    • Risk Area: as associated document contract type with Business Application Type as Risk Management and Business Application Category as Risk Area defined at contract type level.
  • Rules:
    • Instantiate the risk areas after completing the risk assessment
    • Copy attribute values from risk assessment to the risk area
    • Add Team members to the risk area
  • Notifications for events:
    • Risk area is created
    • Risk area due diligence is initiated
    • Risk area remediation is initiated
    • Risk area monitoring is initiated
    • Risk area is deactivated

Refer the Risk Management Configuration guide for details.
 

Prerequisite set-up 

The ICI Risk Management application provides some seeded masterdata that are necessary for the flow of the risk management. Users can create masterdata instances with desired values.
To create masterdata instance:

1. Click "Configure" > "Masterdata" from the "Home" page menu. The Masterdata page opens.

RMApp1-11.PNG

2. Click "Create" button. The "Create Masterdata" page opens.

RMApp1-12.PNG

3.Select the "Masterdata" Contract Type. For example, "Risk Area Master".

RMApp1-13.PNG

3. Click "Next". The "Attributes" page opens.

4. Enter or select the details in all relevant fields. For example, enter "Risk Area Name" as "Anti-Bribery Corruption".

5. Click "Create". The masterdata instance is created.

RMApp1-14.PNG

Similarly, setup masterdata for "Risk Taxonomy", "Risk Remediation",  "Likelihood Rating" and  "Risk Score Matrix" Masters.

Working with Risk Assessment

The ICI Risk Management application enables users to manage risks by creating risk assessment. Risk Assessment deals with the process of identifying and evaluating the magnitude of potential risk areas. For example, buyers can use the ICI Risk Management application  that allows configuring a questionnaire to perform supplier risk assessment. The risk areas can be identified based on the responses received for the questionnaire as the outcome of the risk assessment process.
Risk assessment workflow performed by risk assessment owners typically involves the following:

  • Initiating Risk Assessment: The risk assessment owners can initiate the risk assessment workflow to identify the risks. For example, the risk assessment can be a questionnaire where the users respond to the questions by submitting it. This initiates the risk assessment in "Draft" state.
  • Approving Risk Assessment: Based on the complexity of risk assessment, ICI administrators can configure the rules to add approvers to the assessment team. If there are approvers added to the team, the risk assessment is sent to the approvers for approval. The risk assessment is approved automatically if no approvers are added to the team.
  • Completing Risk Assessment: The status of the risk assessment changes to "Assessment Complete" when the risk assessment is approved. The risk area can be identified and auto-instantiated based on the configured rules.

Here is the Risk Assessment workflow at a glance:

7.12-RiskManagementWorkflow.png

 

 

 


Creating a Risk Assessment

1.Click the "Risk Management" tile on the "Home" page. The dropdown opens with  the following option:

  • Risk Assessments
RMApp1.PNG
 
Click "Create" on the Risk Assessment index page to open the "Create Risk Assessment" page. 
 
8.1-RiskAssessmentIndexPage.PNG
 
    a. Alternatively, click the Create workbench plus icon, the "Create" workbench drawer opens with several create action options.
 
RMApp-RiskWorkflow13.PNG
 
    b. Click "Create Assessment".
 
RMApp-RiskWorkflow15.PNG

2. Click "Create Risk Assessment". The "Attributes" page for "Create Risk Assessment" opens. The "Attributes" page includes questions to capture the responses based on which the risk areas can be generated. These questions are non-seeded attributes and users can configure  them to the Risk Assessment contract type as per their business needs.

Attributes page has seeded sections as:

  • Identification
  • Risk Assessment Timeline

3. Enter the details in fields in the "Identification" section:

  • Risk Assessment Name
  • Risk Assessment Description 
  • Risk Assessment Entity: The context for which the risk assessment is being created. For example, "Business Operations", "Contractual" or "Counter Party".
 RMApp1-15.PNG

4. Enter the details in fields in the "Risk Assessment Timeline" section.

  • Assessment Start Date: The date that you start the risk assessment of entity. For example, January 15, 2022.
  • Assessment Due Date: The date by which risk assessment of entity should be completed. The assessment due date should be greater than the start date, otherwise a validation error message is displayed.
RMApp1-17.PNG

5. Enter the details in fields in all the sections on the Attributes page.

6. Click "Next". The "Verify" page opens.

7. Verify the details and click "Create".

8.0 RM 1.PNG
 
The risk assessment is created in "Draft" state.
 
RMApp1-18.PNG

Once created, users can "Edit", "Delete", "Cancel" or "Submit" the "Risk Assessment".

On deleting the risk assessment, users will be redirected to the Risk Assessment “Index” page. 
  
Some actions that are used less frequently such as “Delete”, option is now moved under the three dots icon on the Risk Assessment “Details” page.

The “Copy Record” action is not supported for Risk Assessment.

Note: Users can configure the less frequently used actions such as “Copy Record”, “Delete”  as per the requirement.  

 


Searching and viewing the Risk Assessment

1. Click the "Risk Management" > "Risk Assessments" tile options on the "Home" page.

The Risk Assessment index page opens displaying all the risk assessments. Users can refine the search result by applying filters, options and keywords.
 
8.1-RiskAssessmentIndexPage.PNG

2. Click the View Record eye icon next to the Risk Assessment record you want to open. For example, "Risk Assessment for Acme Corporation". The Risk Assessment Details page opens.

RMApp1-20.PNG
 
The left navigation pane can be expanded or collapsed, as needed. The collapsed view gives a wider view of the Risk Assessment Details page.
 
RMApp-RiskWorkflow26.PNG
 
Clicking the hamburger menu icon Hamburger-menu-1.jpg expands the left pane.
 
RMApp-RiskWorkflow27.PNG
 
 
Advanced Search
 
The Advanced Search now displays the business app entity Risk Assessment and Risk Area in the Advanced Search window. 
 
8.1-RMApp-AdvancedSearch.PNG
 

Editing the Risk Assessment

1. Click "Edit" on the Risk Assessment Details page. The Edit Risk Assessment page opens.

RMApp-Edit.PNG
 
2. Make the required changes and click "Next". The "Verify" page opens. 
 
RMApp-Edit2.PNG

3. Verify the details and click "Update". The risk assessment is updated and remains in "Draft" state.

RMApp-Edit3.PNG

 

Canceling the Risk Assessment

1.Click "Cancel" on the Risk Assessment Details page.

RMApp-Cancel.PNG

The confirmation window opens.

RMApp-Cancel2.PNG

2. Click "Yes". The "Add Note" drawer opens.

RMApp-Cancel3.PNG

3. Add note text and select the "Reason Code".

4. Click "Add". The Risk Assessment status changes to "Cancelled".

RMApp-Cancel4.PNG

 

 

Deleting the Risk Assessment

1. Click "Delete" on the Risk Assessment Details page. 

RMApp-Delete1.PNG
 
The "Add Note" window opens.
 
2. Add note text and select the "Reason Code".

3. Click "Add". The risk assessment will be deleted and risk assessment index page opens.

 

Submitting the Risk Assessment

 Click "Submit" on the Risk Assessment Details page.

RMApp-Submit.PNG
 
The risk assessment is sent for approval and its status changes to "Waiting for Approval".
 
RMApp-Submit2.PNG

Approvers can Approve or Reject the Risk Assessment from the risk assessment Details page.

 

 

Rejecting the risk assessment

To reject:

1. Click "Reject". 

RMApp-Reject1.PNG

2. Add note text and select the Reason Code.

RMApp-Reject2.PNG

3. Click "Add". The Risk Assessment is rejected and goes back to "Draft" state.

 

 

Approving the risk assessment

To approve:

1. Click "Approve". The "Add Note" window opens. 

1080px-8.0 RM 3.PNG
 
2. Add note text.
 
3. Click "Add". The Risk Assessment state changes to "Assessment Complete".

If there are no Approvers added to the Risk Assessment Team, the record will be approved directly and move to the "Assessment Complete" state.

RMApp-Complete.PNG

 

Note: The "Assessment Complete" state is the final state for Risk Assessment, and users cannot take further actions.

 

 

Auditing Risk Assessment

Changes made to the Risk Assessment record during various ICI risk management workflows are captured and can be viewed under "History" tab. For example, changes in "Risk Assessment for Acme Corporation throughout its lifecycle are captured.

RMApp-RiskWorkflow12.PNG

Click "Show Changes" to view the details of the particular event of the risk assessment instance.

RMApp-History2.PNG
 
Clicking the status of the Risk Assessment or Risk Area opens the “History” window.
 
8.1-RMApp-History.png
 

Working with Risk Area

Managing Risk Area includes: 

  • Ensuring the validity of the identified risk area
  • Devising strategies to mitigate risks
  • Tracking the performance until risks are completely mitigated

The risk area can be generated automatically by seeded rules based on the risk assessment responses. Users can also add the risk area manually to the risk assessment.

 


Creating Risk Area automatically using rules

The ICI Risk Management application provides set of rules to generate Risk Areas automatically based on the responses gathered from the risk assessment. Refer the "ICI Risk Management Configuration Guide" for details on rules used in the ICI Risk Management application.

The workflow for generating risk areas automatically includes process as follows:

1. A recommended rule "Identify Risk Areas" can be configured by the app implementation team on the event "Risk Assessment Created" to identify applicable risk areas, based on the specific attribute values from the Risk Assessment record.

For the attribute "Risk Assessment Description", if the response is "Sup" (representing supplier), then the Applicable Risk Area is identified and set as "Sanctions".

RMApp-RiskWorkflow32.png
 
2. Once the "Risk Areas" are identified, the seeded rule "Auto instantiate applicable risk area" generates those identified risk areas.
3. Another seeded rule "Copy Attribute Values" then copies values specified in the rule from Risk Assessment record to the Risk Areas.
For example, when the "Risk_Assessment_Jan2022" is approved, the risk area is automatically created as "Sanctions".
 
RMApp-RiskWorkflow33.PNG

 

 

Creating Risk Area manually 

To create a risk area for risk assessment: 

1. Click "Risk Management" > "Risk Assessments" from the "Home" page. The search results page with all risk assessment records opens.

2. Click the View Record icon next to the Risk Assessment for which you want to create Risk Area. The Risk Assessment Details page opens.

3. Click Create Association action icon (plus sign) next to Risk Area under the Associations. The "Create Association" for Risk Area page opens.

RMApp-Association1-1.PNG

The "Create Association Risk Area" page has these sections:

  • Reference Risk Assessment
  • Risk Area Details 
  • Inherent Risk Rating 
  • Risk Remediation Plan 
  • Residual Risk Rating 

4. Select or enter the details in the attributes in all the sections. The attributes can be mandatory, lookup type, cascading, conditional, multi-select and so on.

Reference Risk Assessment

This section contains the attributes:

  • Risk Assessment Name: This field is populated automatically based on the information entered when creating the risk assessment. 
  • Risk Assessment Description: This field is populated automatically based on the information entered when creating the risk assessment. 
RMApp-Association2.PNG

Risk Area Details 

This section contains the attributes: 

  • Risk Area Instance ID: This is generated automatically after the risk area is created.
  • Risk Area Name: Select the risk area name from the dropdown list. This populates the information for the following attributes from the masterdata. 
    • Risk Area Master ID 
    • Short Description
    • Category
    • Sub Category
    • "Risk Area Owner"
  • Origin: Enter the description that contains information about the probable source of risk area. 
  • Effect: Enter the description about the probable effects of the risks foreseen based on the risk assessment created.
  • Additional Risk Area Owners: If risk area owner is not available in master, then user can add additional risk area owners. 

Risk Area owners are Subject Matter Experts who can look into risk area end to end for validity of risk, planning risk remediation, monitoring the progress and performance of risk remediation actions

RMApp-Association3.PNG

 

Note: The certain values in the risk area details section can be auto-populated from Risk Area Master . The Risk Owner and Additional Risk Area Owners can be added to the risk area team through configured rules.

Inherent Risk Rating 

Inherent risk rating is the risk rating applicable to the risk when it was determined for the first time.
This section contains the attributes:

  • Inherent Risk Trigger Date: The date and time on which the inherent risk record is created.
  • Inherent Likelihood Rating: The probability of occurrence of risk.
  • Inherent Consequence Rating: The impact or consequence of risk occurrence. 
  • Inherent Risk Level:Qualitative scoring based on likelihood of risk occurrence and consequence if risk occurred. 
  • Inherent Risk score:Quantitative scoring based on likelihood of risk occurrence and consequence if risk occurred. 
Note: The Inherent risk level and score is determined from the values in inherent likelihood rating and consequences rating and can be entered manually or by configuring rules.
  • Comments: This includes any additional information that you might want to provide regarding the risk assessment created.
RMApp-Association4.PNG

Risk Remediation Plan 

This section includes the informaton related to the remediation strategies and actions that can be taken to mitigate the risk areas.
This section contains the attributes: 

  • Remediation Action: Enter the remediation action that is planned to be taken to minimize the probable risks. 
  • Control Effectiveness: Select the level from the dropdown list that defines the level of effectiveness of measures that will be applied to minimize the risks.
  • Remediation Action Details: Enter the remediation action details that describe the remediation actions that will be taken to minimize the risk. 
 RMApp-Association5.PNG

Residual Risk Rating
This section includes the information related to the residual risk left after the remediation actions are taken.
This section contains the attributes:

  • Residual Risk Update Date: The date on which the residual risk record is updated.
  • Residual Likelihood Rating: This indicates the likelihood of occurrence of the remaining risk. 
  • Residual Consequence Rating: This indicates impact of occurrence of the remaining risks happening after the mitigations actions are implemented.
  • Residual Risk Level: Qualitative scoring based on likelihood and consequence if residual risk occurred.  
  • Residual Risk Score: Quantitative scoring based on likelihood and consequence if residual risk occurred. 
  • Comments for Residual Risk: This includes any additional information that you might want to provide regarding the risk area.
RMApp-Association6.PNG

5. Click "Create". The Risk Area is created in Assessment state. 

RMApp-RiskWorkflow14.PNG

 

 

 

 

 

 

Searching Risk Area records

Risk Area records can be searched from:

  • Advanced Search page
  • Global Search

To search risk area from Advanced Search page:

1. Click the "Advanced" link on the header toolbar. The "Advanced Search" page opens.

RMApp-RiskWorkflow16.PNG


2. Select "Risk Area" in the "Entity" dropdown field.

RMApp-RASearch1.PNG

3. Click the search icon. All available Risk Area records are displayed.

RMApp-RASearch2.PNG

 

The left navigation pane can be expanded or collapsed, as needed. The collapsed view gives a wider view of the Risk Area Details page.

RMApp-RiskWorkflow28.PNG
Clicking the hamburger menu icon Hamburger-menu-1.jpg expands the left pane.
 
RMApp-RiskWorkflow29.PNG

 

Risk Area using Global Search

To search risk area using Global Search:

Enter the relevant search criteria in the Enter search here…search bar on the ICI UI. For example, "Risk Area". All available Risk Area records are displayed in a dropdown.

RMApp-RASearch3.PNG

 

 


Working of existing ICI actions for Risk Area

Risk area owner can take existing ICI actions for associations on risk area.

  • Preview Document: Opens the preview of the risk area if available, in the Document Viewer drawer.
  • View Smart Links: Opens the smart links if available, in a Smart Links window. 
  • Edit: Opens the Edit Associated Document - Risk Area page to modify the details of the risk area instance.
  • View Details: Opens the Risk Area Details page.
900px-8.1-RiskAreaAssociationList.png
 

Taking actions on the Risk Area

The Risk owner can be added to the risk area through configured rules. Risk owner can then take certain actions from the risk area Details page.  
The actions can be:

  • Initiate Due Diligence - action taken to capture more information related to the risk and validate the identified risk area. 
  • Remediate - action taken to mitigate the valid risk area.
  • Deactivate - action taken for risk area identified as invalid. Users cannot take further  actions once the risk area is deactivated.
  • Monitor - action taken to track the performance based on remediation actions until risks are completely mitigated

Users can repeat the workflow Due Diligence – Remediate – Monitor until the risk is completely mitigated.
Users can also automate the workflows to initiate due diligence, remediate and monitor risk areas by configuring rules.

 

 

 

 

Editing Risk Area from Three Dots Menu

1. Click "Risk Management" > "Risk Assessments" from the Home page. The list of all available risk assessments opens.

2. Click View Record icon next to the Risk Assessment you want to opens. The Risk Assessment Details page opens.

3. Click "Risk Area" tab in the left navigation. The risk area grid opens.

RMApp-RiskWorkflow21.PNG

4.  Click the three dots menu of a Risk Area record.

5. Click "Edit". The "Edit Risk Area" for Risk Area page opens.
 
RMApp-RiskWorkflow25.PNG
 
6. Make the required changes and click "Update". The Risk Area will be updated and the Risk Area Details page opens again.
 
RMApp-RiskWorkflow24.PNG

 

Editing Risk Area from Risk Area Details page

 
Users can edit the Risk Area from the Risk Area Details page as well:

1. Click View Record icon next to the risk area you want to open. The risk area Details page opens.

RMApp-RiskWorkflow22.PNG

2. Click "Edit". The "Edit Associated Document" for Risk Area page opens. Then, follow the aforementioned step # 6 under "Editing Risk Area from Three Dots Menu" to edit and save the editing.

RMApp-RiskWorkflow23.PNG
 
 
 

Initiating Due Diligence

Click "Initiate Due Diligence". The Risk Area Details page opens again.

RMApp-RAActions4-4.PNG

The status of the risk area changes to "Due Diligence".

RMApp-RAActions5.PNG
 
 

Remediating the risk area

With the status of the risk area in "Due Diligence", click "Remediate" on the risk area Details page.

The Risk Area Details page opens again and the status of the risk area changes to "Remediation".

RMApp-RAActions6.PNG
 
 

Monitoring the risk area

Users can monitor the risk areas based on the remediation actions taken to check whether the risks are reduced. 

To monitor a risk area: 

Click "Monitor" on the risk area Details page. The risk area Details page opens again and the status of the risk area changes to "Monitoring". 

RMApp-RAActions7.PNG

The status of the risk area changes to "Monitoring".

RMApp-RAActions8.PNG
 

Iterating workflow for risk area

Users can repeat the actions taken on the risk areas until the risks are completely mitigated.

1. Click "Initiate Due Diligence" or "Remediate" on the risk area Details page for the risk area in the Monitoring state. For example, select Initiate Due Diligence. The Association "Initiate Due Diligence" note window opens to add a note.

2. Add a note text and select a Reason code.

RMApp-RAActions9.PNG

3. Click "Add". The status of the risk area changes back to Due Diligence.

 

Deactivating the risk area

Risk owners can deactivate the invalid risk area. Once deactivated, no further actions are allowed on the risk area.

1. Click "Deactivate" on the risk area Details page. The "Add Note - Deactivate" drawer opens to add a note.

RMApp-RAActions10.PNG

2. Add a note text and select a Reason code.

RMApp-RAActions12.PNG

3. Click "Add". The status of the risk area changes to "Deactivated".

RMApp-RAActions13.PNG
 
 

Auditing Risk Area

Changes made to the Risk Area record during various ICI risk management workflows are captured and can be viewed under History tab. For example, changes in "ICMRiskArea_100" throughout its lifecycle are captured.

RMApp-RiskWorkflow30.PNG

Click "Show Changes" to view the details of the particular event of the risk area instance.

RMApp-RiskWorkflow31.PNG
 
 
Clicking the status of the Risk Area on the "Details" page opens the “History” window.
 
8.1-RMApp-History1.png
 
 

 

Moving Risk Area workflow automatically

Users can manage the Risk Assessment and Risk Area action workflows using the script attribute Target ICM Status. Users can set the value in Target ICM Status to specific status and move records to that particular state during the risk management workflow. For example, risk area record can be moved from the Draft  state to either Due Diligence, Remediation or Monitoring state using attribute Target ICM status .

Risk assessment and risk area records can be uploaded in ICI directly in specific status by setting the state value in the Target ICM Status attribute using ICI’s Legacy Upload functionality. The business status would then be set accordingly.

For example, when users want to upload large number of historical risk assessment records using Legacy Upload, they can directly upload in the Approved state by setting it in the Target ICM Status attribute and the business state would be set as Assessment Complete.

Refer the ICI Risk Management Configuration Guide for details on Managing Risk Workflows using attribute Target ICM Status.

 

Creating and managing tasks for Risk workflow

Users  can create remediation tasks for managing risks using commitments, obligations or any third party system. ICI Risk Management app currently supports managing Risk Assessment and Risk Area using ICI Commitment functionality.

To create a task using commitment:

1. Click "Risk Management" > "Risk Assessment" from the "Home" page. The saved search result page opens with all Risk Assessment records.

2. Click the View Record icon next to the "Risk Assessment" record you want to open. For example, "Risk_Assessment_Jan2022". The Risk Assessment Details page opens.

3. Click the "Commitments" tab in the left navigation. The existing commitments are displayed if any.

RMApp-RiskWorkflow1.PNG

4. Click "Add Commitment" action icon. The "Add Commitment" drawer opens.

RMApp-RiskWorkflow2.PNG

5. Enter the details for the commitment and 'c'lick "Save". The commitment is created and added to risk assessment. 

RMApp-RiskWorkflow3.PNG

To view and take action on the commitment tasks:

1. Click the three dots menu and click "Take action on commitment". The "Take Action on Commitment" drawer opens.

RMApp-RiskWorkflow5-5.PNG

2. Add the action details.

3. Click "Save". The Commitment status is updated according to the action taken.

RMApp-RiskWorkflow6.PNG
 
Note: The action can also be delegated to a desired user by clicking on the "Delegate" button.

Refer to the "Compliance Management" page for more details on working with commitments.

 

Accessing the Risk Area actions Notifications 

The ICI Risk Management app sends notifications when certain actions are taken on the Risk Area. These seeded notifications are sent when an events occurs:

  • Risk area is created
  • Risk area due diligence is initiated
  • Risk area remediation is initiated
  • Risk area monitoring is initiated
  • Risk area is deactivated

The recipients can access the notifications from "Notification Dashboard":

  1. Click the Notifications bell icon on the top right. The "Notifications Dashboard" opens.
RMApp-RiskNotifications1.PNG
  1. Click "Risk Management Notifications". The list of notification events opens.
  2. Expand the notification event. The notifications belonging to the selected event are displayed. 
  3. Select the Notification you want to view. The selected Notification opens in the right pane.
RMApp-Notifications.png

 

 

 

Related Topics: Agreement Management |