Skip to main content

Get help for ARIS Risk and Compliance

Process hierarchy

The following process models can be used for setting up the process hierarchy:

  • Value-added chain diagram

  • EPC

  • EPC (material flow)

  • EPC (column display)

  • EPC (row display)

  • EPC (table display)

  • EPC (horizontal table display)

  • Function tree

  • BPMN process diagram (BPMN 2.0)

  • Enterprise BPMN process diagram

In ARIS Risk and Compliance, only a tree structure for hierarchies is allowed. Therefore, each hierarchy element can only have one superior hierarchy element. Below, you find modeling examples of the process landscape with the various notations (Value-added chain, EPC and BPMN).

Object-specific control auditors and control test auditors can be modeled using this hierarchy type. These roles have read access to the control executions and control tests assigned to the hierarchy. The relation between the object-specific auditor role and the hierarchy is represented by the decides on connection.

Process modeling with Value-added chain diagram

Process overviews are often modeled using the Value-added chain diagram model (VACD) and the Function object. In ARIS Risk and Compliance, VACD functions are converted to process hierarchy elements.

Value-added chain diagram

The hierarchy between the objects is represented by the is process-oriented superior or is process-oriented subordinate connection. The following model types can be assigned to a Function object type in a VACD:

Objective

Assigned model type

Subprocess [Value-added chain]

Value-added chain diagram

Show more assigned objects

Function allocation diagram

Process modeling with Event-driven process chain

You can describe company processes using an Event-driven process chain model (EPC) and the Function object. It is based on the logical and chronological sequence of the activities to be carried out. In addition, a sequence of functions and resulting events is used. In ARIS Risk and Compliance, EPC functions are converted to process hierarchy elements.

Event-driven process chain 1

These lean processes can be supplemented by additional objects (organizational units, positions, roles, application systems, and so on) containing extended information.

Event-driven process chain 2

Modeling process details with Function allocation diagram

To keep the process diagram lean, either create subprocesses or assign additional objects to functions using model assignments, for example, using the Function allocation diagram model. The following model types can be assigned to a Function object in an EPC:

Objective

Assigned model type

Subprocess

Event-driven process chain

Show more assigned objects

Function allocation diagram

Function allocation diagram

Attributes included into the data transfer

ARIS attribute

M*

Notes

Name

X

Description/Definition

Sign-off-relevant

Used for Sign-off Management.

*The M column specifies whether the attribute is a mandatory field.

Process modeling with business process model and notation (BPMN)

You can describe business processes using BPMN. It is based on the logical and chronological sequence of tasks to be executed. In ARIS Risk and Compliance, BPMN tasks are converted into process hierarchy elements.

Enterprise BPMN process diagram

You cannot assign Call activity objects to GRC objects such as risks, controls, or survey schedulers. Call activities represent elements (a single task or process) modeled elsewhere and are used only to call those elements. To avoid duplicates, Call activity objects are ignored.