Skip to main content

Get help for ARIS Risk and Compliance

Example scenario for Regulatory Change Management

The organization has identified the new European General Data Protection Regulation (GDPR) as relevant to its activities. This regulation was identified in the Regulation inventory model of the organization. The organization must ensure that it keeps track of changes to regulations that are relevant to the organization. Therefore, persons responsible, for example the Legal officers for IT regulations, must be reminded to regularly review the regulation regarding changes. (To achieve this, the frequency and time of execution for the reminder are specified in ARIS in the Regulation object.) At the time specified, the responsible users receive a task to review the regulations and document the results. If the review shows that there are changes in the regulation, the required tasks for the persons responsible are specified. Existing requirements must then be modified, new requirements included, or the risks resulting from the regulation reassessed. Regulatory change management allows the Chief Compliance Officer to provide a monitoring process to ensure that no amendment or change to a relevant regulation is missed. Details on the procedures in ARIS Risk and Compliance are provided below and in the following chapters.

Regulation manager/Regulation owner (Hierarchy manager/Hierarchy owner)

Generate regulatory change reviews.

Regulation owner (Hierarchy owner)

Review regulatory change reviews.