Configuring system settings
Who is this article for?
Administrators needing to configure system settings for roles and planning.
Launch System Settings and Edit System Settings permissions are required.
The system offers many settings that may be configured by administrators, normally set during the initial configuration of the system.
Roles
An optional default role can be set for a user when not assigned to a specific Client, Entity, or Audit.
Unassigned Client (multi-client mode only):
- Universe Manager – manages audit universe within a Client
- Universe Departmental User – works within a universe department
- Universe User – auditor role
- Universe Business User – business user access
- Universe Viewer – view-only access
Unassigned Entity:
- Entity Manager – manages risk register for an Entity
- Entity Business Manager – business manages risk register
- Entity User – owns risk register items
- Entity Business User – business owner of risk items
- Entity Viewer – view-only access
Unassigned Audit:
- Senior Audit Manager – manages all Audit features
- Audit Manager – manages and performs Audit
- Auditor – performs Audit
- Junior Auditor – limited Audit performance
- Business Auditor – participates in external Audits
- Audit Viewer – view-only access
An optional unassigned default role can be set per user at Client Universe, Entity, and Audit levels, overriding system defaults.
Planning risk aggregation
In the Planning Risk Assessments screen (Universe > Planning Period > Planning Risk Assessments), each Entity-Process has a Planning Risk Assessment for every Planning Risk.
Each assessment must have a 'Rating' before it can be marked "Completed".
Aggregate scores for each Entity/Process cell can be calculated by:
- Average – mean of all related Planning Risk Assessment scores
- Sum – total of all related scores
- Max – highest score among all related assessments
Ratings have configurable values in Planning Risks Assessment Ratings.
Examples of calculation:
- If aggregation is Average, the score is the average of child Entity-Process scores.
- If aggregation is Sum, the score is the total of child Entity-Process scores.
- If aggregation is Max, the score is the highest child Entity-Process score.
The Entity-Process Score is only calculated once all Planning Risk Assessments have a rating.
Scheduling settings
The Audit Scheduling screen helps create Candidate Audits within a Planning Period by suggesting audit dates based on scheduling factors. It calculates a suggested next Audit date for each Entity-Process cell.
- Reference Date – Used if there is no Current or Last Audit Date. Calculated as Reference Date + Audit Frequency = Suggested Audit Date.
- Last Audit State – Audit State used to identify the Last Audit for each cell.
- Last Audit Milestone – Milestone used to identify the Last Audit for each cell.
-
Last Audit Date – Date shown on the Audit Scheduling matrix:
- Actual Date – latest Audit End Actual Date
- Planned Date – latest Audit End Planned Date
- Current Audit Milestone (default: Start)
- Current Audit Date (default: Planned)
These settings determine the date shown in the hover text on the HierarchyMatrix during a Planning Period.
The rule: for a Current Audit (not yet Complete), use the specified date. If none exists, use the specified date from the Last Audit (Complete).
They also decide which audit is Last or Current for an Entity/Process in Data Grids. When multiple audits are Open, the one with the most recent Planned Start Date (or chosen setting) is used.
Audit coverage
Note
The value in the system settings should be ignored but may be used with custom development.
The Audit Coverage screen displays a dynamic matrix to track all Audits across the Universe for one or multiple periods. The cells can be filtered by:
- Count – number of audits in each cell
- Coverage – percentage of Entity/Process cells audited
- Progress – milestone with a progress value
Auto-populate settings
When an Audit is set to Open, the system can auto-populate it with Work Plans, Objectives, and Questionnaires.
Work Plans
- None – no auto-population
- Library (default) – auto-populate from the Library
- Include Results – option to include Results
- Include Attachments – option to include Attachments
Objectives
- None (default) – no auto-population
- Entity – auto-populate from entity-level
- Library – auto-populate from the Library
- Include Assessments – option to include Assessments
- Include Attachments – option to include Attachments
Questionnaires
- None – no auto-population
- Library (default) – auto-populate from the Library
- Include Tailoring Answers
- Include Detail Answers
Get Work Plan settings
The following system settings control the behaviour of the Get From dialog for importing Work Plans into an Audit:
- Include Results Force – choose to include Comments when importing Work Plans from an existing Audit
- Include Results Value – choose to include the Comments value when importing Work Plans for an existing Audit
- Include Attachments Force – choose to include Attachments when importing Work Plans from an existing Audit
- Include Attachments Value – choose to include the Attachments value when importing Work Plans for an existing Audit
- Include Notes Force – choose to include Notes when importing Work Plans from an existing Audit
- Include Notes Value – choose to include the Notes value when importing Work Plans for an existing Audit
Get Objective settings
The following system settings control the behaviour of the Get From dialog when importing Objectives into an Audit:
- Include Assessments Force – automatically include Assessments when importing Objectives from an existing Audit
- Include Assessments Value – include the Assessments value when importing Objectives
- Include Results Force – automatically include Results when importing Objectives
- Include Results Value – include the Results value when importing Objectives
- Include Attachments Force – automatically include Attachments when importing Objectives
- Include Attachments Value – include the Attachments value when importing Objectives
- Include Notes Force – automatically include Notes when importing Objectives
- Include Notes Value – include the Notes value when importing Objectives
Refresh Objective settings
These settings are used in conjunction with the refresh from library (Entity ORCTS).
Get Questionnaire settings
The following system settings control the behaviour of the Get From dialog for questionnaires via the Audit Work spine item:
- Including Tailoring Answers Force – choose if Tailoring Answers are automatically included when using Get From on Questionnaires from an existing Audit
- Including Tailoring Answers Value – choose whether to include Tailoring Answer values during Get From
- Including Detail Answers Force – choose if Detail Answers are automatically included when using Get From
- Include Detail Answers Value – choose whether to include Detail Answer values during Get From
- Include Attachments Force – choose if Attachments are automatically included during Get From
- Include Attachments Value – choose whether to include Attachment values during Get From
- Include Notes Force – choose if Notes are automatically included during Get From
- Include Notes Value – choose whether to include Notes values during Get From
Get Finding settings
This System Setting lets users copy Findings and their child Actions from one Audit to another, automatically closing items in the source Audit under certain conditions. Users need read/write access to both source and target Audits.
The following settings control the behaviour of the Get From dialog for importing Findings:
- Update Prior Force – choose if updates to the source Finding happen automatically
- Update Prior Value – decide whether to include the Finding Value in the target Audit
- Include Actions Force – automatically include Actions when importing Findings
- Include Actions Value – choose to include Action values in the target Audit
-
Include Action Updates Value:
- None – no auto-population of Action Updates
- Open – only Open Action Updates are imported
- All – all Action Updates are imported regardless of status
- Include Attachments Force – auto-include Attachments
- Include Attachments Value – choose to include Attachment values
- Include Notes Force – auto-include Notes
- Include Notes Value – choose to include Note values
- Finding Sign Off State – set the Sign Off State of Findings in the target Audit
- Action Sign Off State – set the Sign Off State of Actions in the target Audit
Update Prior Entity settings
When using the Follow Up Audit functionality the Action Resolution in the prior audit can be automatically set to one of the following values:
- Not Actioned
- Actioned
- Reviewed
- Cleared
- Not Relevant
To configure the Update Prior Entity setting:
- Set Update Prior Entity system setting value to Cleared.
- Create Prior audit with Findings and Actions.
- Create Post audit and select the above audit as a Prior Audit.
- Perform the Get From Audit.
- Select on items you wish to get from the prior audit.
- Ensure that the Update Prior Audit is ticked.
- Items now appear in the post-audit.
- Transferred items from the Prior Audit have changed to an Approved state, based on the Get Finding system setting value.
- Action Resolution in the prior audit is automatically set based on the Update Prior Entity system setting value.
Definition Sign Off settings
The default sign-off process is:
- Open > Complete > Approved
This can be extended to:
- Open > Prepared > Confirmed > Complete > Approved
The extra 'Prepared' and 'Confirmed' stages relate to the object's Definition, while 'Complete' and 'Approved' relate to its Execution.
Definition Sign-Off can be applied to:
- Incident
- Key Issue
- Audit
- Problem
- Finding
- Action
- Audit Report
- Work Plan
- Step
- Objective
- Risk
- Control
- Test
Each Definition Sign-Off object has three system settings:
- Off (default) – Only Execution sign-offs apply.
- On – Enables independent Definition sign-off; execution can start before Confirmation.
- Force – Execution is disabled until Definition is Confirmed.
Execution Sign Off settings
Determines when the Execution fields become read only.
Each Sign Off has two setting values: Approval (Default) and Completion.
- Time Sheet
- Incident
- Key Issue
- Audit
- Problem
- Finding
- Action
- Audit Report
- Work Plan
- Step
- Audit Process
- Objective
- Risk
- Control
- Test
- Audit Questionnaire
- Audit Questionnaire section
- Point
- Entity Process Period
Local Matrices settings
A True/False flag controls the use of Local Matrices.
- If Local Matrices are off, existing systems and report templates remain unaffected.
- Local Matrices support multiple risk impacts and standard Costing customisation.
- Matrices, risk exposure, and control coverage function with Local Matrices.
For existing customers enabling Local Matrices:
- Home Screen widgets (Universe and Audit) report local scores; if Local Matrices is enabled, these must be edited to use group scores.
- Local Matrices cannot be applied retrospectively to audits, especially Approved and Closed ones, which remain read-only. Draft audits are the exception as they are not yet populated.
- Enabling Local Matrices on an entity with an Open audit removes current assessments, though assessment history remains in both Entity and Audit.
- Library items can only be assessed using the Group matrix.
- Custom Reporting Templates may be affected; enabling Local Matrices might require updates as scores could come from different matrices (local vs group), causing apparent inconsistencies.
Linked Controls settings
A True/False flag controls linked controls.
- If Linked Controls are off, existing systems or report templates remain unaffected.
- Linked Controls support multiple risk impacts and standard Costing customisation.
- Rarely, linked controls may not link during subsequent Get or Update operations between entities or audits (e.g., the third risk linked to the same control may not link).
For existing customers enabling local matrices or linked controls:
- Linked controls cannot be applied retrospectively to approved or closed audits; only draft audits can be updated.
- Libraries can be copied and converted for linked controls (recommended for a fresh start) or edited to preserve existing links. Use Refresh From Library in each entity to apply changes.
- There is no automated way to convert existing linked control documentation; historic data cannot be converted.
- Turning on Linked Controls may affect templates, requiring new specifications and development. Child items won't report parent risk scores as before; reporting must be redefined to show the maximum score of all parent risks.
Risk Impacts settings
A True/False flag enables Multiple Risk Impacts, defaulting to False. When True, the Impact value becomes read-only and is calculated automatically.
The number of Risk Impacts can be set between 2 and 9, with a True/False flag to make impacts mandatory.
In Multi-Client setups, the number of additional risk impacts is shared system-wide.
Certification settings
Require Audit Processes Certification before Completion
If enabled, Audit Processes cannot be marked Complete without certification.
Require Control Certification before Completion
If enabled, Controls cannot be marked Complete without certification. This applies only to Controls with a Control Importance set to an Importance flagged as Certified.
Sign Off settings
You may change the mandatory Sign Off rule for the update Audit Milestones on (Completion or Approval).
When an audit is complete you may set the Sign Off for the Audit Processes to be Manual or Automatic.
You may change the mandatory Sign Off rules for Risk and Control assessments (Never, Approved, Completed).
Sampling settings
The aggregation of Sample Test Results has a default of Average. This can be configured to Sum if required.
Update Work Plan settings
- Include Results Force – select whether Results (Execution) are updated back to the library when doing an Update to Library of Work Plans/Steps from an existing Audit
- Include Results Value – select whether to include the Results value (Execution) when doing an Update to Library of Work Plans/Steps from an existing Audit
Both the Force and Value System Setting values work in parallel together
For example, if you want to force Work Plans/Steps to be included set Force = True and True = False. However, if you want them to be excluded set Force = True and Value = False
Update Objective settings
- Include Results Force – select whether Results (Execution) are automatically included when doing an Update to Library of ORCTs from an existing Audit
- Include Results Value – select whether to include the Results value when doing an Update to Library of ORCTs from an existing Audit
- Include Assessments Force – select whether to include the assessment values for Risks and Controls when doing an Update to Library from an existing Audit
- Include Assessment Value – select whether to include the assessment values when doing an Update to Library from an existing Audit
Both the Force and Value System Setting values work in parallel together. For example, if you want to force Assessments to be included set Force = True and Value = True. However, if you want them to be excluded set Force = True and Value = False
Post-Audit settings
The Post-Audit settings allow the user to conduct a further subset of audit level work to be to be performed up until when the Audit is Closed. This may also be applied explicitly to individual objects listed below using the Post Audit attribute within the objects properties.
- Work Plan - implicitly applied to child Steps
- Questionnaires
- Objectives - implicitly applied to child Risks, Controls and Tests
The effect is that a subset of work can continue to be performed against objects until they have themselves been approved or the parent Audit is signed off as Closed.