Process hierarchy
The following process models can be used for setting up the process hierarchy:
Value-added chain diagram
EPC
EPC (material flow)
EPC (column display)
EPC (row display)
EPC (table display)
EPC (horizontal table display)
Function tree
BPMN process diagram (BPMN 2.0)
Enterprise BPMN process diagram
In ARIS Risk and Compliance, only a tree structure for hierarchies is allowed. Therefore, each hierarchy element can only have one superior hierarchy element. Below, you find modeling examples of the process landscape with the various notations (Value-added chain, EPC and BPMN).
Object-specific control auditors and control test auditors can be modeled using this hierarchy type. These roles have read access to the control executions and control tests assigned to the hierarchy. The relation between the object-specific auditor role and the hierarchy is represented by the decides on connection.
Process modeling with Value-added chain diagram
Process overviews are often modeled using the Value-added chain diagram model (VACD) and the Function object. In ARIS Risk and Compliance, VACD functions are converted to process hierarchy elements.

The hierarchy between the objects is represented by the is process-oriented superior or is process-oriented subordinate connection. The following model types can be assigned to a Function object type in a VACD:
Objective | Assigned model type |
|---|---|
Subprocess [Value-added chain] | Value-added chain diagram |
Show more assigned objects | Function allocation diagram |
Process modeling with Event-driven process chain
You can describe company processes using an Event-driven process chain model (EPC) and the Function object. It is based on the logical and chronological sequence of the activities to be carried out. In addition, a sequence of functions and resulting events is used. In ARIS Risk and Compliance, EPC functions are converted to process hierarchy elements.

These lean processes can be supplemented by additional objects (organizational units, positions, roles, application systems, and so on) containing extended information.

Modeling process details with Function allocation diagram
To keep the process diagram lean, either create subprocesses or assign additional objects to functions using model assignments, for example, using the Function allocation diagram model. The following model types can be assigned to a Function object in an EPC:
Objective | Assigned model type |
|---|---|
Subprocess | Event-driven process chain |
Show more assigned objects | Function allocation diagram |

Attributes included into the data transfer
ARIS attribute | M* | Notes |
|---|---|---|
Name | X | |
Description/Definition | ||
Sign-off-relevant | Used for Sign-off Management. |
*The M column specifies whether the attribute is a mandatory field.
Process modeling with business process model and notation (BPMN)
You can describe business processes using BPMN. It is based on the logical and chronological sequence of tasks to be executed. In ARIS Risk and Compliance, BPMN tasks are converted into process hierarchy elements.

You cannot assign Call activity objects to GRC objects such as risks, controls, or survey schedulers. Call activities represent elements (a single task or process) modeled elsewhere and are used only to call those elements. To avoid duplicates, Call activity objects are ignored.