Edit control tests
As soon as control tests are generated and the start date of the testing period is reached, the control tester roles responsible can view the control tests in My tasks or in My GRC tasks in ARIS. By default, control tests are opened in My GRC tasks in ARIS. For detailed information, refer to Edit or review control tests in the online help of ARIS. How to edit control tests in ARIS Risk and Compliance is described below. You can
hand over or
delegate objects to another role.
Prerequisite
You have the Control tester role.
Open the list of control tests.
Click
Home > My tasks. Your tasks are displayed. Initially, tasks with the Open status are displayed.Filter the list with the Control test object type.
Check the due date. To do so, sort the list in
ascending or
descending order by clicking the column header.
Edit the optional fields.
Click the name of the control test you want to edit. The Control test form is displayed with information such as test type, testing activities, test size, as well as assigned risks, controls, and control test definitions.
Edit the optional fields.
Assign documents with further information, if necessary.
You can assign change or improvement recommendations that can serve as additional information in an audit, for example. The recommendation can be sent automatically after you have completed the task if you enter an e-mail address and the e-mail functionality is configured. Alternatively, you can send the e-mail manually (
).
Save your entries, select the status, and initiate further measures, if required.
Click
Save. Your entries are saved. The status is automatically set to In progress. If you want to continue later, keep this status.If you want to complete the control test, select the status Test passed, Test failed, or Test not possible depending on the result.
If you selected the status Test failed:
Describe the test in detail so that someone who is not familiar with the process can reproduce the results when repeating the test. If only one test type (Test of control design or Test of control effectiveness) is specified for the control test, the failure type is automatically given: Design test failed or Effectiveness test failed. If both test types are specified for the control test, the control tester must specify which of the two failed or if both failed.
Specify the measure, this means whether a deficiency, an issue or no further measure is to be initiated.
If you selected the status Test not possible enter a reason.
If you changed the status, save your entries again (
).
Your entries are saved. If you saved the status Test passed, Test failed, or Test not possible, you can no longer edit the control test.
By default, control tests with status Test failed, Test passed, and Test not possible require a review. Administrators can configure in the Risk and Compliance configuration of ARIS Administration (
Configuration > Risk and Compliance > SYSTEM CONFIGURATION > Workflow management > Configuration > Task reviews > Control test) whether and how many reviews are required. If reviews are required, review tasks are generated for the reviewers responsible in My GRC tasks in ARIS. The users responsible are notified automatically by e-mail.
If you initiated a deficiency or an issue as a measure for the control test, the corresponding object is generated automatically. The deficiency is then edited by the deficiency manager (L1) in the next step. If you are logged in as a deficiency manager (L1), you can edit the deficiency immediately. The control tester is assigned to the issue as an issue creator. The issue is displayed in your list of issues and can be edited immediately.
If control tests are not tested within the specified testing period, they are automatically closed during checking and are given the status Not tested.
Next steps: