Skip to main content

Get help for ARIS Risk and Compliance

Example scenario for Compliance Management

The organization has identified the new European General Data Protection Regulation (GDPR) as relevant to its activities. This regulation was identified in the Regulation inventory model of the organization. The various rules of the GDPR have been identified, such as the obligation to delete personal data when it is no longer needed. For the various departments, this requirement was translated into specific requirements, such as for the HR department Delete applicant data after 12 months and Delete data of former employees after 60 months. Now the organization must ensure that it complies with these regulatory requirements, and the Chief Compliance Officer must supervise whether these requirements are being met. To achieve this, various compliance assessment definitions are created for the specific regulatory requirements of each department, and the respective users receive their tasks by the due date. After performing these compliance assessment tasks, the Chief Compliance Officer has an accurate view with which regulations the organization is compliant and where it is not. In the latter case, the Chief Compliance Officer then initiates issues to ensure compliance as soon as possible. Details on the procedures in ARIS Risk and Compliance are provided below and in the following chapters.

Regulation manager

Create compliance assessment definitions for each relevant regulation or regulatory requirement and generate compliance assessments to specify the activities required.

Regulation owner/Hierarchy owner

  1. Perform compliance assessments.

  2. Depending on the result of your assessment, generate an issue based on the compliance assessment to, for example, adapt a process and initiate a confirmation process to inform employees, or initiate a policy roll-out to ensure the regulation is complied with from now on.

Regulation reviewer

  1. Review compliance assessments.

  2. Depending on the result of your assessment, generate an issue based on the compliance assessment to, for example, adapt a process and initiate a confirmation process to inform employees, or initiate a policy roll-out to ensure the regulation is complied with from now on.

Regulation manager/Risk manager

  1. Depending on the result of the assessment, generate an issue as described for the owner and reviewer.

  2. A regulation manager who has also the risk manager role can additionally create a risk for the non-compliant regulation with the assigned regulatory requirement.