The following flowchart outlines the Drova GRC Compliance Management process.
Individuals appropriately trained and experienced in Compliance should identify and record all requirements for Compliance within your organisation. This can include compliance with:
Regulatory controls,
Government Acts,
Industry standards, and
Codes of Practice.
If your organisation is moving from another Compliance Management System to Drova GRC, a lot of this work has probably already been done and it’s just a matter of getting the information into Drova GRC.
For each identified Compliance Process:
determine the appropriate schedule for performing the Process Controls, and
identify the most suitable people to perform the Process Controls.
On the appropriate date (determined by the Schedule and Reminder settings for each Process Control), Drova GRC generates Process Controls and emails the person recorded in the Process Control Record as responsible for Actioning the Task (the ‘Actioned By’ Position).
The generated Process Controls are displayed in each ‘Actioned By’ Position’s ‘My Summary’ page 'Current Task' tab.
Once the actions in the Process Control have been performed and any documentary evidence prepared, the ‘Actioned By’ Position reports completion of the Process Control in Drova GRC. Where required, documentary evidence can be attached to the Process Control Record during completion, forming a permanent record of the actions taken and results obtained.
If a Process Control is not completed on time, or won’t be completed at all for some reason, then Drova GRC provides a way to ensure that this is managed.
You can set a Position to be the ‘Escalate To’ Position for each Process Control. If the Process Control is not completed by the due date, Drova GRC sends a notification email:
Every day beyond the due date, to the the ‘Actioned By’ Position, till the task is done.
Once to the ‘Escalate To’ Position, so they can act on this information as required.
This ensures that your Compliance Tasks are not missed, thus helping to avoid possible Compliance breaches.
Drova GRC retains data recorded for each Compliance Process and Process Control. The ability to include attachments, links to other Records and resources makes Drova GRC a valuable tool for building an accurate and detailed history of your organisation’s Compliance performance.
The more Compliance data Drova GRC collects, the more information you have to improve organisational compliance, performance and reputation within your industry