Skip to main content

Get help for ARIS Risk and Compliance

Assess risks

As soon as risk assessments are generated, the risk owner roles responsible can view the risk assessments in My tasks. Use the lists to gain an overview of the objects assigned to the risk assessment via the risk, such as incidents, losses, controls, control test definitions. You can Hand over object hand over or Delegate object delegate objects to another role.

Prerequisite

You have the Risk owner role.

Procedure. Procedure
  1. Open Risk assessment.

    1. Click Home Home > My tasks. Your tasks are displayed. Initially, tasks with the Open status are displayed.

    2. Filter the list with the Risk assessment object type.

    3. Check the due date. To do so, sort the list in Sort ascending ascending or Sort descending descending order by clicking the column header.

    4. To gain a better overview, you can filter the list using various criteria. Click Show extended filter Show extended filter to display additional filter options and the filter attributes.

      Show extended filter
    5. Click the name of the risk assessment you want to edit. The form divided into Task, Assessment, and Information is displayed with information such as assessment activities, risk category, assigned risk.

  2. Assess the risk based on various impact types.

    1. Click Assessment.

    2. Select the assessment type. Depending on which assessment type you selected, either the attributes of the quantitative or the qualitative valuation criteria are displayed. If there are predefinitions for impact types, not all existing risk assessment attributes are displayed. If an assessment type is predefined, you cannot select the assessment type. Instead, the attributes of the predefined assessment type are displayed directly. If reduced values and/or minimum and maximum values (quantitative risk assessments) are excluded, the attributes are not displayed in the form. These predefinitions can be specified for the system or for specific environments (Risk management > Impact types).

    3. Edit the mandatory fields (Mandatory field, Recommended field) and the optional fields.

    4. Click Save Save.

  3. Edit the required fields.

    1. Click Task.

    2. Edit the mandatory fields (Mandatory field, Recommended field) and the optional fields.

    3. For example, select the basis of assessment, the data source, or assign documents with further information.

  4. Save your entries and select the status.

    1. Click Save Save. Your entries are saved. The status is automatically set to In progress. If you want to continue later, keep this status.

    2. Use the status buttons Assessed or Assessment not possible to select another status. In the latter case, enter a reason in the Remark field that then becomes mandatory. Save your entries again.

    3. If you changed the status, save your entries again (Save).

Your entries are saved. If you saved the status Completed or Assessment not possible, you can no longer edit the risk assessment. The risk assessment is displayed to the risk reviewer roles responsible in My tasks. The users responsible are notified automatically by e-mail.

If the risk assessments are not answered within the predefined risk assessment period, they are automatically closed when checked. The assessment status is set to Not assessed and the review status to Unspecified.

Next step: Review risk assessments