Skip to main content

Get help for ARIS Risk and Compliance

Modeling conventions

The objective of Control Management is to identify, plan, and implement controls that reduce risks. Controls can be described by their type and effect. Controls can be executed manually or automatically by a system. For manual controls, control executions can be generated automatically at scheduled times or event-driven. Automated controls are executed in an external system. They can be documented in ARIS Risk and Compliance using the public API for control execution documentation. For detailed information, refer to Import control executions using public API.

The users responsible receive a task with information about the activities to be performed. The central objects of Control Management are controls and control execution definitions.