cancel
Showing results for 
Search instead for 
Did you mean: 

How to send reminder notification to Mitigating Monitor to run compliance reports at agreed frequency

Former Member
0 Kudos

Hi

I know there are no standard workflows or alerts for this particular item.  Maybe that is the answer but I was interested in understanding how other companies have dealt with this.   We are implementing GRC10 for both ARA and SPM at this stage.

Scenario

It seems logical that we would want to send reminders to the monitors for our mitigating controls.  That way they have received the reminder and cannot say they forgot.  I understand that the standard alert is sent to Mitigating Controller and is based on report not being run by the Mitigating Monitor within the agreed frequency.  The issue with this is that it may not always be possible to identify one SAP report/transaction which will satify the mitigation control.  Plus - just because the report has been run doesn't mean it has been analysed and signed off in accordance with agreed controls.

So - how do we setup notification to be sent to Monitor X every 30 days with a customised message based on the control e.g. you must run mitigating control SAP report ZZZZ to mitigate risk S001 for user JBLOGGS.  Please ensure the appropriate documentation is filed for audit control purposes.

Any help or insight would be much appreciated.

Gráinne

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Awaiting update and general release of note 1728869 which resolves issue.  This was confirmed by another GRC client on the GRC forum.

Answers (1)

Answers (1)

simon_persin4
Contributor
0 Kudos

You can do this using the ARA Alerts functionality. An alert is generated based upon the frequency set in the Mitigating control Report tab. If the user has not executed the transaction within the frequency stated, then an alert is generated. If you run the alert generation background job with the "Notifications enabled" flag then your monitors will recieve a prompt to run the report.

If you want to be a bit more keen, you can implement Process Controls and define the conditions there to automate and monitor the mitigating controls in operation in your business. If you're only looking at ARA and SPM currently, that might be a bit of a leap in your roadmap.


Simon

Former Member
0 Kudos

Thanks Simon, we will let you know how we get on with this.  It seems there may be some known bugs in GRC 10 in relation to use of alerts.