Compliance case workflow
Summarize
Summary of Compliance Case Workflow
The Compliance Case Workflow in the Compliance Case Management application facilitates the reporting and management of compliance issues requiring attention from the compliance team. This structured process enhances accountability and ensures thorough investigation and resolution of compliance cases.
Show less
Key Features
- Reporting: Compliance violations can be reported by business users or the compliance team through the Employee Center or Compliance Workspace applications.
- Triage: The compliance team assesses reported cases for validity and assigns a case analyst for further investigation.
- Investigation: Case analysts collaborate with various teams to gather evidence, create tasks, and evaluate the compliance case. This includes identifying impacted and related areas, compliance regulations, and analyzing causes and consequences.
- Resolution: After analysis, the case analyst initiates remediation actions and tracks regulatory violations for proper reporting.
- Post Case Review: A thorough review is conducted to analyze causes and manage related issues before the case is officially closed.
Key Outcomes
Implementing this workflow enables organizations to effectively manage compliance cases, ensuring thorough investigation and action. It leads to improved compliance management, reduced risks, and better collaboration among teams, ultimately supporting regulatory obligations and organizational integrity.
The workflow in the Compliance Case Management application is a process that enables you to report and manage cases that need the compliance team's attention.
- Report a compliance case
- Triage the compliance case
- Investigate and evaluate the compliance case
- Resolve the compliance case
- Post case review and closure
Report a compliance case
A business user or a compliance team can report a compliance violation in the Employee Center application. Compliance case team can report cases in the Compliance Workspace application. For more information, see Reporting a compliance case in GRC: Compliance Case Management.
Triage the compliance case
After a compliance case is reported, the compliance team triages the case from a validity standpoint. The team then assigns a case analyst to work on the case.
Investigate and evaluate the compliance case
The compliance case analyst collaborates with multiple teams to investigate, gather evidence, and capture the details and responses about the case. Then, the case analyst creates the case tasks to initiate an investigation and assessment of a reported case and assigns them to a case task owner.
- Add the areas that are impacted by a compliance case. For example, the impacted areas or records that could be impacted are the entities, controls, locations, or users that are affected by the compliance case. For more information, see Add an impacted area to a compliance case.
- Add the areas that are related to the compliance case. For example, the related areas include the policies, citations, control objectives, or risk events. For more information, see Add a related area to a compliance case.
- Add the compliance regulations that might be impacted by the compliance case. For more information, see Add compliance regulations to a compliance case.
- Add the causes and consequences of this compliance case such as the root cause for the reported compliance case or event and its consequences to the organization. For more information, see Add a cause and consequence to a compliance case.
Resolve the compliance case
After all the analysis for the reported case is completed, the case analyst initiates the remediation actions and preventive measures to resolve the case. The case analyst also tracks the reportable regulatory violations to ensure their lodgement to the regulators.
Post case review and closure
The case analyst analyzes the causes and consequences of the case. Then, the case analyst​ conduct​s a root-cause analysis to remove the cause of the case. The case analyst can review the case to identify and manage the issues that are related to the impacted areas. For more information, see Add an issue for a compliance case. Finally, the compliance analyst works closely with the various teams to review and close the compliance case.