Mapping Controls for Risk Management
The objective of this SOP is to map relevant risks, rules, or business processes related to a control to understand how this control can help achieve the business's goals effectively.
Key Steps:
- Enter Relevant Business Processes:
- Go to the configuration tab and enter the relevant business processes.
- Create a New Risk for the Control:
- Within the control section, create a new risk associated with the control.
- Add Applications Used in the Control:
- Specify the applications that are used in this control. Multiple applications can be added.
- Include External Service Providers:
- Add any external service providers involved in the control process.
- Provide Accountability Statements:
- Lastly, include accountability statements for clear ownership and responsibility.
Cautionary Notes:
- Ensure that the business processes entered are accurate and up-to-date.
- Double-check the applications, external service providers, and accountability statements for completeness and accuracy.
Tips for Efficiency:
- Utilise the sorting feature to organise risks effectively.
- Regularly review and update the mapping of controls to ensure alignment with business goals.
Watch a video demonstration: