19.1 About the Compliance Tab

The Compliance tab provides a convenient way to perform compliance-based actions.

The Compliance tab allows you to initiate attestation processes and check the status of these processes. You can use the Compliance tab to:

Compliance and Proxy mode

Proxy mode works only on the Requests & Approvals tab and is not supported on the Compliance tab. If you enter proxy mode on the Requests & Approvals tab, and then switch to the Compliance tab, proxy mode is turned off for both tabs.

19.1.1 About Compliance and Attestation

Compliance is the process of ensuring that an organization conforms to relevant business laws and regulations. One of the key elements of compliance is attestation. Attestation gives an organization a method for verifying that personnel are fully aware of organizational policies and are taking steps to comply with these policies. By requesting that employees or administrators regularly attest to the accuracy of data, management ensures that personnel information such as user profiles, role assignments, and approved separation of duties (SoD) exceptions are up-to-date and in compliance.

Attestation Requests and Processes

To allow individuals within an organization to verify the accuracy of corporate data, a user makes an attestation request. This request in turn initiates one or more workflow processes. The workflow processes give the attesters an opportunity to attest to the correctness of the data. A separate workflow process is initiated for each attester. An attester is assigned a workflow task in the My Tasks list on the Requests & Approvals tab. To complete the workflow process, the attester opens the task, reviews the data, and attests that it is correct or incorrect.

The Roles Based Provisioning Module supports four types of attestation:

  • User profile

  • SoD violations

  • Role assignment

  • User assignment

In the case of a user profile attestation process, each user must be the attester for his/her own profile; no other individual can be the attester. In the case of SoD violation, role assignment, and user assignment attestation, the attester may be any user, group, or role. The initiator for the attestation request specifies whether every member or only a single member must attest for a group or role. In the case of a user attestation process, every member must attest for a selected group or role.

To simplify the process of making attestation requests, the Roles Based Provisioning Module installs a set of default request definitions, one for each attestation type:

  • User Profile - Default

  • SoD Violation - Default

  • Role Assignment - Default

  • User Assignment - Default

You can use these request definitions as the basis for making your own requests. Once you’ve provided the details for a new request, you can save these details for future use.

Attestation Forms

Each workflow has an attestation form associated with it. The attester must review the form and fill it in to affirm the correctness of the data. The form is defined by the Compliance Module Administrator or Attestation Manager.

Each attestation form contains a required attestation question along with a set of optional survey questions. The attestation question is a yes or no question attesting to or denying the overall data. Survey questions can be set up to gather additional data or ask qualifying questions.

The user profile attestation form also include a set of user attributes with values that the attester must review. The attestation form for an SoD violation, role assignment, or user assignment process includes an attestation report.

Attestation Reports

The attestation report for an SoD violation, role assignment, or a user assignment process provides detailed information that the attester is expected to review. The report is generated at the time the attestation process is initiated to ensure that all users are reviewing the same information. The report may be generated in several languages, depending on the report languages settings specified for the attestation process.

Attestation Request Status

Once an attestation request has been initiated, it can be easily tracked throughout its lifecycle. The User Application provides a convenient way to look at the status of the request as a whole, as well as the detailed status for each individual workflow process associated with the request. The high-level status for a request gives the user a way to see whether the request is running, completed, initializing, or in error. The detailed status provides information about the number of workflow processes, and the status for each workflow. In addition, it shows the attestation results, which indicate how many answers to the attestation question were affirmative and how many were negative. The attestation results also show which attesters have not taken any action on their assigned workflow tasks.

Compliance Security

The Compliance tab uses a set of system roles to secure access to compliance functions. Each menu action in the Compliance tab is mapped to one or more system roles. If a user is not a member of one of the security roles defined for compliance, the Compliance tab is not available.

The system roles for compliance are automatically defined by the system at install time. These include the following:

  • Compliance Module Administrator

  • Attestation Manager

A Compliance Module Administrator is designated at installation time. After installation, the Role Module Administrator can assign additional users to the Compliance Module Administrator and Attestation Manager roles. To make additional role assignments, the Role Module Administrator uses the Roles > Role Assignments page in the User Application.

The system roles are described in detail below:

Table 19-1 System Roles

Role

Description

Compliance Module Administrator

A system role that allows members to perform all functions on the Compliance tab, including those that the Attestation Manager can perform.

NOTE:In release 3.6.1 of the Roles Based Provisioning Module, the capabilities of the Compliance Module Administrator are exactly the same as those given to the Attestation Manager. In a future release, the Compliance Module Administrator may be given additional capabilities, as new features are added to the Compliance tab.

Attestation Manager

A system role that allows members to perform all attestation functions. These functions are listed below:

  • Request user profile attestation processes.

  • Request SoD violation attestation processes.

  • Request role assignment attestation processes.

  • Request user assignment attestation processes.

  • View the status for all attestation requests that have been submitted.

NOTE:Any user can be defined as an attester for an attestation process. An attester does not need to belong to either the Attestation Manager or Compliance Module Administrator role.

The Compliance tab does not allow access by authenticated users that do not have membership in either of the system roles listed above.