Automated Control Self-Certification
I would like to know how to automatically send a report link in a certification? The report would be one run by each control owner showing the controls assigned to them so they can verify the control is still in operation and control description remains correct.
I am thinking a process certification could work for this is there is a way to include a link to where they will run the RCM type report for controls assigned to them.
Is it possible?
-
Hi Kari,
What a great question! This is possible to accomplish, but I don't think there's necessarily one right way to do it.
Certifications could be a useful tool here. It would be possible to add a link and instructions into a letter for your control owners to review. Then, they could certify that they completed the review you're asking of them. In this case, the best practice would be to use a link to a user centric report that would allow the users to navigate to controls they are listed as the control owner of.
On the other hand, our team thinks that this process could be an even better use case for Assessments!
To sort through these options, I've reached out to your CSM who will help discuss the pros & cons and get you started in the right direction with this process improvement! You should hear from them in the next week :)
0Please sign in to leave a comment.
Comments
1 comment