Platform: Risk Assessment Platform
Applies to: End User Roles (e.g. Standard, Approver)
Reports
There are two types of assessment-related reports available to users:
Assessment Unit Report
The final stage in the process is to review the overall risk ratings, add comments or actions for the board/senior management, generate the report, and publish to save a view-only audit of the assessment unit.
This report page shows the Overall Inherent Risk Rating, Overall Control Effectiveness, and Overall Residual Risk Rating for the assessment unit.
Scrolling down reveals graphs for Inherent Risk Rating by Group, Controls Effectiveness by Category, and Residual Risk by Risk Factor.
Users with override permissions are able to override the Residual Risk Rating for the Assessment Unit. This will prompt the user to enter comments on the override. The override and comments will appear in the audit and generated reports.
Hovering over a section of the bar charts will display the rating label, count, and percentage. Clicking on a section of the bar chart will drill down to the risks/controls that belong to the respective rating.
Add comments under Inherent Risk Rating by Group, Control Effectiveness by Group, and Residual Risk by Risk Factor. These fields are mandatory only when the assessment unit is ready to be published.
Users may also add any Actions related to the assessment unit that should be brought to the attention of the board/senior management in the Executive Summary.
Print the Assessment Unit Report
A Word version of the Assessment Unit report can be produced at any time from the Action menu (). The report can be configured to display selected sections using the Configure Assessment Unit Report function in the Action menu.
After the Assessment Unit report is generated, it can be customised as required for presentation to senior management and/or the board of directors. The final version of the Word report can then be attached to the Assessment Unit using the Attach Final Report function in the Action menu.
Complete the Assessment Unit
Once the Assessment Unit is deemed complete it should be Published (press the Publish button) so that the Assessment Unit data cannot be edited.
Note: Overall Risk Comments (for Inherent Risk Rating by Group, Control Effectiveness by Group, and Residual Risk by Risk Factor) are required before the assessment unit can be published.
Assessment Report
The Assessment Report aggregates the risk across all assessment units in the Assessment. This report can be generated as a Word doc at any time during the assessment process and is based on all assessment unit data entered to that point.
The Assessment Report page shows the Overall Ratings for all assessment units in the assessment, or the assessment units defined in the selected Custom Weighting Group (if any).
Users may also add comments and actions related to the assessment that should be brought to the attention of the board/senior management in the Executive Summary.
Weightings and Custom Weighting Groups
The Assessment Units should be assigned weightings by clicking the Weight column header (this can also be done from the Assessment Unit History page). This opens the weightings window where assessment units can be included/excluded and weightings applied.
Functions on this page:
- Use the handle (
) to the left of assessment units to change their position in the list.
- Use the checkbox to include or exclude an assessment unit from the report.
- Enter values in the Weight column to specify the weighting for each assessment unit; or
- Press the Distribute Equally button to equally distribute weightings between the selected assessment units.
- Press the Save button to update the default weightings; or
- Use the Save As button to create a custom weighting group. Multiple custom weighting groups can be created and saved.
Note: Custom Weighting Groups can be edited and deleted from the Custom Weighting Group Details function in the Action menu ().
Print the Assessment Report
A Word version of the Assessment Unit report can be produced at any time from the Action menu (). The report can be run for a specific custom weighting group by selecting it from the Run Assessment Report dropdown options in the Action menu.
The report can be configured to display selected sections using the Configure Assessment Unit Report function in the Action menu.
After the Assessment Report is generated as a Word document, it can be customised as required for presentation to senior management and/or the board of directors. The final version of the Word report can then be attached to the Assessment using the Attach Final Report function in the Action menu.
Complete the Assessment
Once all Assessment Units are published, the Assessment process is ready to enter the final stage. Enter overall comments under the sections for Inherent Risk Rating by Assessment Unit, Control Effectiveness by Assessment Unit, and Residual Risk by Assessment Unit. These are required before the assessment can be published.
Once the Assessment is deemed complete it should be Published (press the Publish button) so that the Assessment data cannot be edited.
Comments
0 comments
Please sign in to leave a comment.