Using Get, Refresh and Update to Library functions
Who is this article for?
Administrators who needs to use Get, Refresh and Update to Library functions.
Administrator access to the Universe module is required.
The Entity-level Risk Register of Objectives, Risks, Controls and Tests (ORCTs) can be populated and maintained from the Library using Get, Refresh and Update functions to ensure consistent and up-to-date audit information.
1. Understanding the recommended ORCT lifecycle
The Entity-level Risk Register may be directly populated from the Library prior to the first Audit. Alternatively, the first Audit might be populated directly from the Library and the items added to the Entity when the Audit is Completed.
This is undertaken using the Get functionality.
The recommended ORCT lifecycle can be represented as follows:
The benefits of this workflow are:
- Entity-specific ORCTs which are recorded in the first Audit end up being included in the subsequent Audits
- The Entity-level always contains the latest assessments as recorded in the Audits
- The Entity-level only ever contains one copy of each ORCT which results in meaningful analysis and reporting
- The user is still free to choose to get a Library (into an Entity or an Audit) more than once with the intention of using it as a template but modifying it
2. Avoiding incorrect workflows
The following workflow is not recommended:
This approach is not recommended because:
- It is difficult to produce meaningful Entity-level reports
- It is difficult to use the Risk Exposure screen
- It is difficult to know which Entity-level items to use as the basis for any subsequent Audit
- Entity-specific items do not end up in subsequent Audits at all
Note: It may be recommended that each Audit is populated from the Library under some circumstances, for example for Compliance customers or when not using Entity level at all for any other reason.
3. Using Refresh from Library
The Refresh from Library improves the workflow so that Entity-level (and therefore each subsequent Audit) can contain both the Entity-specific items and the latest library items.
The list of items to refresh includes Objectives, Risks, Controls and Tests. As with the Get functionality, tick the parent item to include all children automatically OR expand the children and tick none, one, many or all of them individually.
Note: The items will only be shown in the list if they are already within the Entity and Linked to a Library item (else there is nothing to refresh).
4. Configuring refresh options
The refresh dialogue includes the following check boxes:
- Include Assessments - only available if the source and target locations use the same Matrix Configuration
- Include Results
- Include Attachments
- Include New Children
If Include Assessments is checked, it will add a new (Internal) Assessment to each Risk or Control which has an Assessment in the Library. This will replace the existing current Assessment (if any) but the previous ones will be retained in the Assessment History.
If Include Results is checked, the Execution fields will also be included in the refresh.
If Include Attachments is checked, it will add any new Attachments and update any which already exist. When updating, it will match on both Ref and Title. If an Attachment already exists against the Entity-level object which has the same Ref AND Title, it will deem this to be the same Attachment and will replace it with a fresh copy from the Library. If no such match is found, it will simply add a new Attachment.
If Include new Children is checked, then new child items (which are not present in the Entity) will be added by the refresh. The system also prompts to include new child items when refreshing the Entity ORCTs independently (as part of an Audit auto population or prior to a Get from Entity to Audit).
If any of these check boxes are NOT ticked, it will simply leave the fields as they are.
Note: The default values for these check boxes are controlled by System Settings - refresh objective.
5. Understanding refresh behaviour
For each item (directly ticked or implied), the refresh will:
- Update all of the properties which were set by the original Get
- Automatically Get any new child items which are not present in the Entity
- Re-get the Attachments (if ticked) as described above
- Re-get the Assessments and Results (if ticked) as described above
The set of elements to copy will include the Active State. Therefore, if an item has now been Closed in the Library, the process of refreshing it will result in it being Closed at Entity-level too.
Note: There is nothing to prevent the same Library item being got twice into an Entity and if they were to both be refreshed, they would both be updated as per the rules above.
6. Reviewing Entity-level ORCTs
Entity-level ORCTs can be marked as Reviewed.
The purpose is to ensure that there is a record that an item has been reviewed by a member of staff with the relevant permission. Items which have been changed (including where an Assessment has been made) since they were Last Reviewed are indicated as Changed.
Adding a review puts a marker on the Data Grid to show that this is the case.
You may review the item more than once and a record of each review is shown every time an item is Re-Reviewed, even by the same Person.
A review may be deleted using the option available in the ribbon or right mouse click Sign Off and then Delete Review.