Skip to main content

Get help for ARIS Risk and Compliance

Policy object

Use the Policy object to model policy templates. A policy that has the Transfer to ARIS Risk and Compliance attribute set to true is transferred to ARIS Risk and Compliance as a policy template.

Attributes included into the data transfer

ARIS attribute

ARCM attribute (deviating)

M*

Notes

Name

X

Description/

Definition

Roll-out type

X

Two options:

  • Confirmation required (the confirmation process is started after the policy is published)

  • Publish only (the process ends after the policy is published)

Policy confirmation text

Confirmation text

Policy confirmation duration in days

Confirmation duration

(X)

Indicates the time span in which the users in the policy addressee role can read and confirm the policy. The confirmation duration is relevant only for policies of the type Confirmation required.

Start date of publishing preparation period

Publishing preparation period

X

Start date of the period for preparing the policy for publication. The policy is generated at that time and can then be prepared by the policy owner.

End date of publishing preparation period

Publishing preparation period

X

End date of the period for preparing the policy for publication.

Start date of approval period

Approval period

X

Start date of the period for approving the policy. The approving period must occur the publishing preparation period. The approvals are generated at that time and can then be performed by the policy approver.

End date of approval period

Approval period

X

End date of the period for approving the policy. The approving period must occur within the publishing preparation period.

Earliest publishing date

Earliest date from which a policy can be published. If not specified, the publishing is possible directly after approval by the policy owner.

Latest publishing date

X

Latest date for publishing the policy.

Transfer to ARIS Risk and Compliance

Specifies whether a policy template is transferred to ARIS Risk and Compliance.

Title (1‑4)

Indicates the titles of linked documents.

Link (1‑4)

Indicates the links of linked documents.

ARIS document storage Title (1‑4)

Indicates the titles of linked documents in ARIS document storage.

ARIS document storage link (1‑4)

Indicates the links of linked documents in ARIS document storage.

*The M column specifies whether the attribute is a mandatory field.

Additional attributes (Review attribute group) for the Policy review object (from ARIS 9.5)

ARIS attribute

ARCM attribute (deviating)

M*

Notes

Review-relevant

Marks the policy as review-relevant.

Review activities

Activities

Describes the activities to be executed during the review.

Review frequency

Task frequency

(X)

Indicates the interval at which the policy review is to be carried out.

If the policy roll-out was marked as review-relevant, this field becomes mandatory.

Event-driven review allowed

Event-driven task allowed

Indicates whether manually created reviews are allowed for policies. Is automatically set to true during transfer from ARIS to ARIS Risk and Compliance if the Review frequency attribute is set to Event-driven.

Time limit for the execution of the review in days

Time limit for task processing

(X)

Indicates the number of days that the policy owner has to process the review. The review duration is specified by the end date at which the review must be completed. If the policy roll-out was marked as review-relevant, this field becomes mandatory. This attribute is not mandatory if the Review frequency attribute has the value Event-driven.

Start date of policy review

Start date

(X)

Indicates the date from which the first policy review is to be generated. If the policy roll-out was marked as review-relevant, this field becomes mandatory. This attribute is not mandatory if the Review frequency attribute has the value Event-driven.

End date of policy review

End date

Indicates the date up to which policy reviews are generated.

Length of control period

Indicates the period to which the policy review relates. If the policy was marked as review-relevant, it is recommended specifying this field, but it is not mandatory.

*The M column specifies whether the attribute is a mandatory field.