Skip to main content

Get help for ARIS Risk and Compliance

Business controls diagram

Use the Business controls diagram model to allocate the roles responsible and to specify the objects relevant for the assessment of risks. This allows you to document effects on company assets, for example, which risk affects which organizational unit. Alternatively, use the KPI allocation diagram.

Business controls diagram structure for Risk Management

Inheritance of attributes and connections between risk objects

The is assigned to connection can be used to inherit object assignments between risks. Objects assigned to the risk object with outgoing connection are passed on to the risk object with ingoing connection. Only the following object types are passed on: Function, Organizational unit, Application system type, Regulation, Risk category, and Roles. An object type is only passed on if the receiving risk has no direct connection to the same object type. A role is only passed on if the receiving object has no direct connection to the same role. Example: The risk reviewer role is passed on but the risk owner role is not passed on, because the receiving risk already has an assignment to the risk owner role.

KPI allocation diagram - inheritance of risk objects

Relationships of the risk object

The following connections are relevant between the objects in the KPI allocation diagram:

Object

Connection

Object

Notes

Risk

is technically responsible for

Role

This connection creates the relationship to the risk owner, risk manager, and risk reviewer. The allocations of risk owner and risk reviewer are mandatory if the Risk Management-relevant attribute is set to true. All other allocations are optional.

Risk

affects

Organizational unit/

Application system type/

Regulation

This connection creates the relationship to the hierarchy.

Risk

affects

Technical term

This connection creates the relationship to the standards hierarchy. It becomes a mandatory relationship if Financial reporting has also been selected for the Risk type risk attribute.

Risk

is assigned to

Risk

This connection is used to inherit object assignments from one risk to several risks, for example, if all risks have the same regulation or risk reviewer.