Kontrolldefinitionen/en: Unterschied zwischen den Versionen
Weitere Optionen
Faha (Diskussion | Beiträge) Die Seite wurde neu angelegt: „By clicking the button "Create copy of this control definition" the control definition can be copied. The copy contains all the data of the original, i.e. desc…“ |
Isan (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
||
(74 dazwischenliegende Versionen von 3 Benutzern werden nicht angezeigt) | |||
Zeile 1: | Zeile 1: | ||
A control definition determines, at what intervals a control is to be executed. Implementers, examiners, and the approval behavior for the control are also determined. Control definitions can have the state "active", "suspended", or "deactivated". Only an active control definition triggers controls at the set intervals, provided it has been configured as a recurring control. | |||
Controls traverse various phases when they are triggered, from the implementation of the control itself, through the exam of the control, to the finished or failed control. | |||
[[Datei:Kontrollen aktives Mms.png|left|thumb|900px|Select management system]] | Experts and professionals can see '''all''' control definitions created in the current management system under "Controls → Control definitions". | ||
[[Datei:Kontrollen aktives Mms.png|left|thumb|900px|Select management system, create and copy control definitions]] | |||
<br clear=all> | <br clear=all> | ||
__TOC__ | __TOC__ | ||
<span id="Kontrolldefinition_anlegen/bearbeiten/kopieren"></span> | |||
== <span id="create_check"></span> Create/edit/copy control definition== | |||
When creating a control definition, make sure that the correct management system has been selected, as control definitions are only created for the current management system. | |||
To create a new control definition, click the "Plus" button. | |||
To | To edit an existing control definition, double-click the desired control definition. | ||
To | To copy an already existing control definition, click on the "copy" button next to the "plus". This will copy the control definition 1:1, but no control executions and links will be copied! | ||
[[Datei:Kontrolle bearbeiten Maske.png|left|thumb|902px|Page for editing a control definition]] | |||
[[Datei:Kontrolle bearbeiten Maske.png|left|thumb| | |||
<br clear=all> | <br clear=all> | ||
<span id="Kopfdaten"></span> | |||
=== <span id="Header data"></span>Header data === | === <span id="Header data"></span>Header data === | ||
:<u> | :<u>OrgUnit:</u> Here, you enter the organizational unit in which the control is to be performed. | ||
:<u> | :<u>Code:</u> This is the code under which the control definition and control can be found. (e.g. OrgUnit + sequence number Per_K_001). | ||
:<u> | :<u>State:</u> | ||
:*Active: Control to be performed as soon as it | :*Active: Control to be performed as soon as it is triggered. | ||
:*Suspended: The control is not to be performed for a specific reason, but it can be reactivated. | :*Suspended: The control is not to be performed for a specific reason, but it can be reactivated. | ||
:* | :*Deactivated: The control definition is generally no longer active. This status is for control definitions that are not to be deleted for archiving purposes, because controls have already been performed. | ||
:<u>Description:</u> | :<u>Description:</u> Here, you should briefly describe what topic the control definition deals with. | ||
:<u>Control measure:</u> | :<u>Control measure:</u> In the control measure, describe the control and explain what to look for when performing it. This is a html field. The formatting is also applied in reports. | ||
:<u>Note:</u> | :<u>Note:</u> Here, you enter additional information to be considered when performing the control. | ||
:<u>Norm mapping:</u> | :<u>Norm mapping:</u> Here, you can map the control definition to a standard. Prefilling: | ||
*When creating a control definition from a template, the template's mapping is adopted. | |||
*When creating a control definition in the course of a review, the mapping of the review question/result is adopted, if set. | |||
*When creating a control definition within a risk (tab Measures & controls), the mapping of the risk is adopted, if set. | |||
*Note: Mappings from the review question/result or the risk are overwritten if a template is used for creation. | |||
:<u>Control types:</u> | :<u>Control types:</u> | ||
:*Organizational: organizational procedures are checked. | :*Organizational: organizational procedures are checked. | ||
:*Technical: | :*Technical: technical processes are checked. | ||
:*Preventive: the control is used to prevent a risk/damage (e.g. checking a fire extinguisher). | :*Preventive: the control is used to prevent a risk/damage (e.g. checking a fire extinguisher). | ||
:*Corrective: The control is used to check a known problem and assess whether said problem has been reduced. | :*Corrective: The control is used to check a known problem and assess whether said problem has been reduced. | ||
:*Detective: The control is used to uncover a problem, which can then be reduced or solved. | |||
::Technical and organizational, as well as preventive, corrective, and detective are mutually exclusive, so only one of the respective options can be chosen at any time. | |||
:<u>Priority:</u> | :<u>Priority:</u> | ||
:*There is no official definition of a key control. However, a distinction can save time in documenting and testing controls that are not key.<br />The following characteristics can help guide decisions:<br /><ul><li>It is required to provide reasonable assurance that material misstatements are prevented or detected on a timely basis. </li><li>It is the only control that covers the risk of material misstatement.</li><li>If it fails, it is highly unlikely that another control could detect the absence of the control.</li><li>It is a control that covers more than one risk or supports an entire process execution.</li></ul | :*There is no official definition of a key control. However, a distinction can save time in documenting and testing controls that are not key.<br />The following characteristics can help guide decisions:<br /><ul><li>It is required to provide reasonable assurance that material misstatements are prevented or detected on a timely basis. </li><li>It is the only control that covers the risk of material misstatement.</li><li>If it fails, it is highly unlikely that another control could detect the absence of the control.</li><li>It is a control that covers more than one risk or supports an entire process execution.</li></ul>. | ||
::<b>Note:</b> If no threshold has been defined for a key control, any failure of the control escalates to the management system owner! | ::<b>Note:</b> If no threshold has been defined for a key control, any failure of the control escalates to the management system owner! | ||
:<u>Threshold:</u> | :<u>Threshold:</u> | ||
:*Alarmed if the threshold was exceeded:<br /><ul><li>Management System Responsible(s)</li><li>as well as persons and team leaders entered in the input field "Functional escalation to"</li></ul | :*Alarmed if the threshold was exceeded:<br /><ul><li>Management System Responsible(s)</li><li>as well as persons and team leaders entered in the input field "Functional escalation to"</li></ul>Depending on the selected period is the review period of quick value violations: <ul><li>Year: Since the beginning of the year,</li><li>Quarter: Since the last start of the quarter,</li><li>Month: Since the beginning of the month,</li><li>Week: Since the beginning of the week,</li><li>Day: Since the beginning of the day,</li><li>Hour: Since the beginning of the hour. </li></ul><b>Note:</b> If an already violated threshold is violated again within the period, each new violation will escalate. | ||
=== <span id="Prüfungsdaten"></span> | <span id="Prüfungsdaten"></span> | ||
=== <span id="Prüfungsdaten"></span>Exam data=== | |||
:<u> | :<u>Implementer:</u> Here, you enter the persons who are responsible for the implementation of the control. | ||
:<u> | :<u>Approval behavior:</u> | ||
:* Here you define when it is decided whether a | :* Here, you define when it is decided whether a control counts as performed when multiple examiners exist. | ||
::* All must accept | ::* All must accept | ||
::* First | ::* First response applies | ||
::* | ::* Majority must accept | ||
::* All must | ::* All must agree in order of precedence | ||
:<u>Examiner:</u> Here, you enter the persons who check the implementation of the control. | |||
:<u> | :<u>Next control:</u> Here you set the date of when the next control has to be carried out. Furthermore, you can decide whether the control is recurring and, if so, at what interval the control should be performed. You can choose a simple repetition for the interval, e.g., every 6 months, or a weekday-bound repetition, e.g., the last Friday of every quarter. | ||
:<u> | :<u>Deadline:</u> If the control is to have a deadline, you must specify it and define which people will be informed when the deadline is exceeded. | ||
:<u> | :<u>E-mail notifications once pending:</u> If this is enabled, as soon as a control is performed, the implementer is notified. This may be undesirable if a control is to be performed daily, for example. | ||
:<u> | :<u>Reminders:</u> Here, you can configure multiple e-mail reminders for the implementer. | ||
:<u> | :<u>Attachments:</u> Here, you can upload files or attach links that are visible to the implementer with each control. For example, this can be an control performance template that the implementer can download and fill out for each control and then return as evidence. Please note that the implementer cannot change the files uploaded here. | ||
<span id="Kontrolldefinition_kopieren"></span> | |||
== <span id="copy_check"></span> Copy control definition == | |||
By clicking the button "Make a copy of this control definition" the control definition can be copied. The copy contains all the data of the original, i.e. description, implementers, mappings, attachments, etc. The only thing that will not be copied from the original are the controls already performed. | |||
==Create/edit review and approval workflow== | |||
[[Datei:DM_Kontrolle.png|right|thumb|400px|Erweiterter Button zum Erstellen]] Professionals and Experts of the Doc-management have the option of creating review and approval workflows in addition to regular control definitions. | |||
More on the approval of documents an links can be found [[Special:MyLanguage/Freigabeworkflow|here]]. | |||
== <span id="Performed"></span> | <span id="Durchgeführte_Kontrollen"></span> | ||
== <span id="Performed"></span>Executed controls == | |||
Switch to the " | Switch to the "Executed controls" tab to get an overview of the controls already performed. | ||
[[Datei:Durchgeführte Kontrollen.PNG|left|thumb|900px|Overview of the controls | [[Datei:Durchgeführte Kontrollen.PNG|left|thumb|900px|Overview of the executed controls]] | ||
<br clear=all> | <br clear=all> | ||
If you then click on a control, a dialog opens in which you can see the details of the control execution. | If you then click on a control, a dialog opens in which you can see the details of the control execution. | ||
< | A control can be in various states: | ||
*<u>Pending</u>: The performance of the control by the implementer has been triggered but not yet completed. | |||
*<u>Suspended</u>: The control does not currently need to be performed. | |||
*<u>Needs approval</u>: The control has been forwarded to the examiner(s) by the implementer. | |||
*<u>Finished</u>: The control was accepted during approval. | |||
*<u>Failed</u>: The control was not accepted during approval or the deadline was exceeded. | |||
*<u>Irrelevant</u>: Controls must not be deleted. If they are to not be considered in KPIs or reports, they can instead be marked as irrelevant. | |||
[[Datei:Detail durchgeführte Kontrolle.PNG|left|thumb|900px|Details of a performed control]] | [[Datei:Detail durchgeführte Kontrolle.PNG|left|thumb|900px|Details of a performed control]] | ||
<br clear=all> | <br clear=all> | ||
[[Datei:Irrelevant.png|right|thumb|350px]] | |||
The status of a control can be changed manually on this page by experts and professionals. This can be usefor, for example, if a deadline was exceeded and the implementer or examiner is to be given more time. This is achieved by setting the status from "Failed" back to "Pending" or "Needs approval". Every manual change of the status is also shown in the change log. | |||
<b>Caution</b> By changing the state to "Pending" or "Needs approval", the control is sent out to the implementer or the examiner(s) for a new execution/assessment.<br clear=all> | |||
[[Datei:Kontrolle Verknüpfung Breadcrump.png|left|thumb|800px|Control link menu]] | <span id="Verknüpfungen"></span> | ||
== <span id="Verknüpfungen"></span>links== | |||
[[Datei:Kontrolle Verknüpfung Breadcrump.png|left|thumb|800px|Control definition link menu]] | |||
<br clear=all> | <br clear=all> | ||
If a control is assigned to a risk or a processing activity, for example, this link is displayed in this tab. | If a control definition is assigned to a risk or a processing activity, for example, this link is displayed in this tab. | ||
<b>Important:</b> This tab is only visible if the control is associated with entities. | <b>Important:</b> This tab is only visible if the control definition is associated with entities. | ||
[[Datei:Kontrolle Verknüpfungen.png|left|thumb|800px|Control | [[Datei:Kontrolle Verknüpfungen.png|left|thumb|800px|Control definition links]] | ||
<br clear=all> | <br clear=all> | ||
Clicking on the blue link opens the respective entity. | Clicking on the blue link opens the respective entity. | ||
<b>Note:</b> If the entity is not displayed in blue, | <b>Note:</b> If the entity is not displayed in blue, you lack the authorization to view it or it is in another management system. | ||
==Tips, tricks & best practice== | |||
[[Datei:BESTPRACTICE.png|left|thumb|100px]] | |||
When creating a weekday-bound control frequency, make sure to select the correct day for the first control yourself. When setting the date, the monthly view makes it easy to identify the first/second/third/last weekday.<p><u>Example</u>: If a control is to happen every Thursday, the set interval would be "every first Thursday every 1 week(s)". As weekdays can't occur more than once with a weekly frequency, the field "first/second/third/last" is automatically disabled.<br clear=all> |
Aktuelle Version vom 16. Juni 2025, 07:13 Uhr
A control definition determines, at what intervals a control is to be executed. Implementers, examiners, and the approval behavior for the control are also determined. Control definitions can have the state "active", "suspended", or "deactivated". Only an active control definition triggers controls at the set intervals, provided it has been configured as a recurring control.
Controls traverse various phases when they are triggered, from the implementation of the control itself, through the exam of the control, to the finished or failed control.
Experts and professionals can see all control definitions created in the current management system under "Controls → Control definitions".

Create/edit/copy control definition
When creating a control definition, make sure that the correct management system has been selected, as control definitions are only created for the current management system.
To create a new control definition, click the "Plus" button.
To edit an existing control definition, double-click the desired control definition.
To copy an already existing control definition, click on the "copy" button next to the "plus". This will copy the control definition 1:1, but no control executions and links will be copied!

Header data
- OrgUnit: Here, you enter the organizational unit in which the control is to be performed.
- Code: This is the code under which the control definition and control can be found. (e.g. OrgUnit + sequence number Per_K_001).
- State:
- Active: Control to be performed as soon as it is triggered.
- Suspended: The control is not to be performed for a specific reason, but it can be reactivated.
- Deactivated: The control definition is generally no longer active. This status is for control definitions that are not to be deleted for archiving purposes, because controls have already been performed.
- Description: Here, you should briefly describe what topic the control definition deals with.
- Control measure: In the control measure, describe the control and explain what to look for when performing it. This is a html field. The formatting is also applied in reports.
- Note: Here, you enter additional information to be considered when performing the control.
- Norm mapping: Here, you can map the control definition to a standard. Prefilling:
- When creating a control definition from a template, the template's mapping is adopted.
- When creating a control definition in the course of a review, the mapping of the review question/result is adopted, if set.
- When creating a control definition within a risk (tab Measures & controls), the mapping of the risk is adopted, if set.
- Note: Mappings from the review question/result or the risk are overwritten if a template is used for creation.
- Control types:
- Organizational: organizational procedures are checked.
- Technical: technical processes are checked.
- Preventive: the control is used to prevent a risk/damage (e.g. checking a fire extinguisher).
- Corrective: The control is used to check a known problem and assess whether said problem has been reduced.
- Detective: The control is used to uncover a problem, which can then be reduced or solved.
- Technical and organizational, as well as preventive, corrective, and detective are mutually exclusive, so only one of the respective options can be chosen at any time.
- Priority:
- There is no official definition of a key control. However, a distinction can save time in documenting and testing controls that are not key.
The following characteristics can help guide decisions:- It is required to provide reasonable assurance that material misstatements are prevented or detected on a timely basis.
- It is the only control that covers the risk of material misstatement.
- If it fails, it is highly unlikely that another control could detect the absence of the control.
- It is a control that covers more than one risk or supports an entire process execution.
- Note: If no threshold has been defined for a key control, any failure of the control escalates to the management system owner!
- There is no official definition of a key control. However, a distinction can save time in documenting and testing controls that are not key.
- Threshold:
- Alarmed if the threshold was exceeded:
- Management System Responsible(s)
- as well as persons and team leaders entered in the input field "Functional escalation to"
- Year: Since the beginning of the year,
- Quarter: Since the last start of the quarter,
- Month: Since the beginning of the month,
- Week: Since the beginning of the week,
- Day: Since the beginning of the day,
- Hour: Since the beginning of the hour.
- Alarmed if the threshold was exceeded:
Exam data
- Implementer: Here, you enter the persons who are responsible for the implementation of the control.
- Approval behavior:
- Here, you define when it is decided whether a control counts as performed when multiple examiners exist.
- All must accept
- First response applies
- Majority must accept
- All must agree in order of precedence
- Examiner: Here, you enter the persons who check the implementation of the control.
- Next control: Here you set the date of when the next control has to be carried out. Furthermore, you can decide whether the control is recurring and, if so, at what interval the control should be performed. You can choose a simple repetition for the interval, e.g., every 6 months, or a weekday-bound repetition, e.g., the last Friday of every quarter.
- Deadline: If the control is to have a deadline, you must specify it and define which people will be informed when the deadline is exceeded.
- E-mail notifications once pending: If this is enabled, as soon as a control is performed, the implementer is notified. This may be undesirable if a control is to be performed daily, for example.
- Reminders: Here, you can configure multiple e-mail reminders for the implementer.
- Attachments: Here, you can upload files or attach links that are visible to the implementer with each control. For example, this can be an control performance template that the implementer can download and fill out for each control and then return as evidence. Please note that the implementer cannot change the files uploaded here.
Copy control definition
By clicking the button "Make a copy of this control definition" the control definition can be copied. The copy contains all the data of the original, i.e. description, implementers, mappings, attachments, etc. The only thing that will not be copied from the original are the controls already performed.
Create/edit review and approval workflow

Professionals and Experts of the Doc-management have the option of creating review and approval workflows in addition to regular control definitions.
More on the approval of documents an links can be found here.
Executed controls
Switch to the "Executed controls" tab to get an overview of the controls already performed.
If you then click on a control, a dialog opens in which you can see the details of the control execution.
A control can be in various states:
- Pending: The performance of the control by the implementer has been triggered but not yet completed.
- Suspended: The control does not currently need to be performed.
- Needs approval: The control has been forwarded to the examiner(s) by the implementer.
- Finished: The control was accepted during approval.
- Failed: The control was not accepted during approval or the deadline was exceeded.
- Irrelevant: Controls must not be deleted. If they are to not be considered in KPIs or reports, they can instead be marked as irrelevant.

The status of a control can be changed manually on this page by experts and professionals. This can be usefor, for example, if a deadline was exceeded and the implementer or examiner is to be given more time. This is achieved by setting the status from "Failed" back to "Pending" or "Needs approval". Every manual change of the status is also shown in the change log.
Caution By changing the state to "Pending" or "Needs approval", the control is sent out to the implementer or the examiner(s) for a new execution/assessment.
links

If a control definition is assigned to a risk or a processing activity, for example, this link is displayed in this tab.
Important: This tab is only visible if the control definition is associated with entities.

Clicking on the blue link opens the respective entity.
Note: If the entity is not displayed in blue, you lack the authorization to view it or it is in another management system.
Tips, tricks & best practice

When creating a weekday-bound control frequency, make sure to select the correct day for the first control yourself. When setting the date, the monthly view makes it easy to identify the first/second/third/last weekday.
Example: If a control is to happen every Thursday, the set interval would be "every first Thursday every 1 week(s)". As weekdays can't occur more than once with a weekly frequency, the field "first/second/third/last" is automatically disabled.