Getting started
ARIS Risk and Compliance is a process-based solution for corporate integrated management of risks, internal controls, compliance, and audits. ARIS Risk and Compliance supports companies in complying with legal requirements and standards using a professional environment and role concept, the usage of Governance, Risk and Compliance workflows, and a flexible method that can be adapted to different requirements. The various technical functions in Risk and Compliance Management are integrated into operational process and performance management. All processes in ARIS Risk and Compliance are transparent, that is, all actions and changes are logged, can be viewed at any time, and can be assigned to a user.
ARIS Risk and Compliance components and functions become available through the license key in ARIS Administration. The help texts for handling all components can be viewed regardless of whether you have a license key.
Administration
As an administrator, you find the relevant information, for example, how to configure ARIS Risk and Compliance, manage data, users, roles, and user groups, in Administrate ARIS Risk and Compliance. In addition, you can refer to the Installation and upgrade help.
Components and functions
The company’s process functions, organization, regulations and standards, IT systems and related assets as well as risk categories and control tester organization are managed in
Hierarchies. Hierarchy elements can be transferred from ARIS Architect or ARIS (Transfer Risk and Compliance data).Issue Management is the basis for identifying issues or tasks for objects in ARIS Risk and Compliance or ARIS. Issues can be created for one or more process functions, regulations, organizational units, IT systems, risks, controls, or other objects.
Using Survey Management, you can create questionnaires and generate surveys. Surveys can be used in association with an ARIS element, with GRC context, for example, as preparation for a risk self-assessment, or without specific context.
Using Regulatory Management, you can ensure and prove the correct and complete fulfillment of requirements from current laws, regulations, standards, or norms. Using Regulatory Change Management, you can ensure not to miss any new version of a regulation. It provides a structured workflow for the scheduled review of regulations by their owners responsible. Users are requested to check the regulations for current changes or enhancements and to initiate appropriate measures and adjustments if necessary. Using Compliance Management, you ensure that your organization regularly checks compliance with the identified legal requirements. Users are requested to check their inventories, such as processes, systems or policies, for compliance with the related current legal requirements and to perform the appropriate measures and adjustments if required.
Policy Management offers the roll-out and review of policies as the basis for corporate governance. The policy roll-out workflow, consists of approval, publishing and review. For policy roll-outs, users are prompted according to their role to approve a policy roll-out or confirm that they received the published policy. Policies are used to mitigate risk.
Risk Management identifies and describes all risks. Risk assessments with qualitative or quantitative risk impacts are generated regularly or on demand. Incidents and losses are recorded by Loss and Incident Management. Risks and risk portfolios, for example per process, organizational unit, regulation, can be assessed from various perspectives.
Control Management serves as an internal control system to identify, assign, and describe all manual or automated controls. With integrated Test Management organizations can create, plan, execute, and monitor control tests for design and effectiveness. For specific requirements, Deficiency Management allows the identification and escalation of formal deficiencies.
Sign-off Management allows you to organize the review and final approval of your internal controls with a structured bottom-up approach. For any hierarchy structure, the responsible users can be asked for final approval.
Audit Management defines and executes integrated audit plans for any type of audit objective. Audits and their audit steps are automatically generated according to the plan. When due, users responsible are notified automatically about required tasks and workflows. All audit steps are related to the respective company assets.
Data protection management add-in enhances the standard configuration of ARIS Risk and Compliance and is designed for the ARIS Accelerators for GDPR package. This package helps organizations comply with the European General Data Protection Regulation (GDPR).