Dual control
Dual control ensures that important decisions are not made by a single person and that critical tasks are not edited and reviewed by a single person. Dual control is also known as segregation of duties or four eyes principle. Affected objects are opened in read mode with a message informing about the privilege conflict. Dual control in ARIS Risk and Compliance is based on two approaches:
Role-based dual control
Checks the assignment of users to their roles. A user must not be assigned simultaneously to the owner role that edits an object and to the reviewer role that approves an object, because the same user could then enter and approve the information. Therefore, editor and reviewer roles must be strictly separated. The role-based dual control of ARIS Risk and Compliance can be customized. It can be deactivated for small teams or organizations. For detailed information, contact the support team.
A user who enters information to a risk assessment must be assigned to a risk owner role. The user who reviews and approves this information must be assigned to the risk reviewer role. A user must not be assigned simultaneously to the risk owner role and the risk reviewer role.
The check is activated by default for the following:
Objects | Editor role | Reviewer role |
|---|---|---|
Risk assessments | Risk owner | Risk reviewer |
Control tests | Control tester | Control test reviewer |
Sign-off definitions | Sign-off owner | Sign-off reviewer |
Surveys | Interviewee | Survey reviewer |
The check can be activated for the following:
Objects | Editor role | Reviewer role |
|---|---|---|
Audits | Audit owner | Audit reviewer |
Incidents | Incident owner | Incident reviewer |
Losses | Loss owner | Loss reviewer |
User-based dual control
Checks the user name of a user. A user must not edit an object and then approve these changes. This principle cannot therefore be circumvented by deleting the role assignment to the risk owner role after editing and then assigning the role to the risk reviewer role to review the task. The user-based dual control of ARIS Risk and Compliance can be customized. If the role-based dual control is deactivated (see above), the user-based dual control ensures that the same user cannot first enter and then approve changes.
In small teams or companies with only a few employees, a strict role-based dual control can be impossible. Therefore, users of the same team can be assigned both to the risk owner role and to the risk reviewer role. The user-based dual control and the associated user name prevent the same user from first editing the information for a risk assessment as the risk owner and then approving it as the risk reviewer.
The check is activated by default for the following:
Objects | Editor role | Reviewer role |
|---|---|---|
Risk assessments | Risk owner | Risk reviewer |
Control tests | Control tester | Control test reviewer |
Sign-off definitions | Sign-off owner | Sign-off reviewer |
Surveys | Interviewee | Survey reviewer |
Audits | Audit owner | Audit reviewer |
Losses | Loss owner | Loss reviewer |
The check can be activated for the following:
Objects | Editor role | Reviewer role |
|---|---|---|
Incidents | Incident owner | Incident reviewer |