Objects of Policy Management
The following objects are Policy Management-relevant.
Policy template
Policy templates are the basis for generating policy roll-outs. They describe the policy and provide relevant documents and workflow details, such as roll-out type, approval period, and publishing preparation period. They can be imported from ARIS or created manually in ARIS Risk and Compliance.
Policy roll-out
Policy roll-outs contain all requirements that must be fulfilled for the policy to be formally valid, for example, the internal approval of a policy and the confirmation by the addressees. Policy roll-outs are generated from policy templates. The policy owner roles responsible can view policy roll-outs in My tasks. The policy manager can view the policy roll-outs in Explorer > Policy Management.
Policy roll-out approval
Policy roll-out approvals are generated automatically when the To be approved status is selected for a policy roll-out. If the start date of the approval period was reached, the approvals are made available for editing. Policy approvers check the correctness of the policy roll-outs. However, the status of policy roll-out approval has no direct influence on the status of the policy roll-out. Only the policy owner can decide whether a policy roll-out is approved for publishing or not. Open policy roll-out approvals are automatically closed if the policy owner set the status Approved or Not approved for the policy roll-out.
Policy roll-out confirmation
Policy roll-out confirmations are generated automatically when the Published status is selected for a policy roll-out of the Confirmation required type. The members of the policy addressee group check the content of the policy roll-out and select whether they accept the policy roll-out or not.
For Publish only policy roll-outs, the members of the policy addressee group are notified automatically by e-mail. The policy must be available, for example, on the intranet or in ARIS. There is no control as to whether the user read the policy or not.
Policy review scheduler
Policy review schedulers are the basis for generating policy reviews. Policy review schedulers are created automatically when policy templates are created. Policy review schedulers are available under Information > Object assignments of policy roll-outs and policy templates. If policy reviews are to be generated, the status must be changed to Review-relevant and the corresponding mandatory fields (
,
) must be edited.
Policy review
Policy reviews control whether the current policy roll-out is still appropriate or needs content editing. They are generated based on policy review schedulers.
Policy exception
Describes exceptional cases related to the policy roll-out. This can be exceptions based on time or minimal changes, for which it is not necessary to pass the approval process for the policy roll-out again.