Perform or review control tests
As soon as control tests are generated and the start date of the testing period is reached, the control tester roles responsible can view the control tests in My GRC tasks in ARIS or in
My tasks in ARIS Risk and Compliance. The users responsible are notified automatically by e-mail. If control tests are not tested within the specified testing period, they are automatically closed during checking with the Not tested status. They can no longer be edited.
The status is automatically set to In progress. If you want to continue later, keep this status.
Prerequisite
Control tests: You have the Control tester role.
Review control tests: You have the Control test reviewer role.
Click
Open 'My GRC tasks' in the header of ARIS to open the list of your GRC tasks. Only if GRC tasks are available for you, the icon with the number of tasks is displayed in the ARIS header. Alternatively, click Application launcher > Quick access >
My GRC tasks. Your tasks are displayed.
If necessary, use the
filter to restrict the list based on specific search criteria.
Click the relevant control test task. The Control test form is displayed with information, such as test type, testing activities, test size, as well as assigned risks, controls, and control test definitions.
Depending on your role, perform the following steps:
Control tester
Edit the optional fields.
Under Result documents you can add a link or upload documents as additional information. To upload a document, you can select or drag and drop it from your local storage, or paste it from the clipboard.
Click
Save. The status is automatically set to In progress. If you want to continue later, keep this status.
If you want to complete the control test, select the status Test passed, Test failed, or Test not possible, depending on the result.
If you selected the status Test failed:
Describe the test in detail so that someone who is not familiar with the process can reproduce the results when repeating the test. If only one test type (Test of control design or Test of control effectiveness) is specified for the control test, the failure type is specified automatically: Design test failed or Effectiveness test failed. If both test types are specified for the control test, specify which of the two failed or if both failed.
Specify the measure, that is, whether a deficiency, an issue or no further measure is to be initiated.
If you selected the status Test not possible enter a reason and specify the measure, if necessary.
Save your entries (
).
If you saved the status Test passed, Test failed, or Test not possible, you can no longer edit the control test.
If you initiated a deficiency or an issue as a measure for the control test, the corresponding object is generated automatically as soon as the result review was performed by the control test reviewer roles. If no result review is required, the corresponding object is generated immediately.
If reviews are required for control tests, the control test reviewers responsible are notified automatically by e-mail. If more than one role is required to perform a result check, the roles perform the result review in the order in which they are modeled at the associated object. In other words, the role that is closest to the related object performs the result review first.
Control test reviewer
Check the control tester's answers.
If you want to complete the review click
Review, then select the status Accepted, or if you do not agree, select the status Rejected.
Enter an explanation for your decision.
Click Save.
If you selected the Accepted status and more than one reviewer role is required to perform the result review, the next role responsible is notified automatically by e-mail and so on, until all required roles have completed the result reviews.
If you selected the Rejected status, the review process is interrupted and the task is displayed again to the owner role in My GRC tasks with In progress status. The other reviewers are no longer required to perform the result reviews.
The users responsible are notified automatically by e-mail.