Tip of the Month: Version 11 Embedding Risk Management with RCSAs
March 13, 2024
-
- Step 1 – Risk Champion creates and distributes the RCSA
-
- Step 2 – Owners complete their RCSAs online
-
- Step 3: Risk Champion monitors and collates the RCSA results
-
- Step 4: Risk Champion updates the live BarnOwl registers with the RCSA voting results
- Step 5: Up to date risk management reporting
Step 1 – Risk Champion creates and distributes the RCSA
Step 1.1 – Create and configure a vote
The risk champion (Rich license) creates RCSA template/s and applies these to the required business units.
FIG1.1a: capture a new Voting Template
FIG1.1b: e.g. Control Self-Assessment (CSA) | FIG1.1c: Select a filter on controls which is applied when the vote is sent out |
FIG1.1d: Select additional filters and conditions which force the voter to capture comments and/ or action plans depen ding on how they rate the control |
FIG1.1e: Select users or a Voting template of pre-configured users who are required to vote. Votes are also filtered by Unit permissions. Multiple users can vote on a control and the votes can be moderated by a ‘Reviewer’ |
FIG1.1f: Configure recurrence if required, whereby a vote will automatically be sent out by the system based on its recurrence settings (monthly, quarterly, twice per annum, annually etc.). |
FIG1.1g: set the date by when the Voters must vote by as well as by when the Reviewer must review by. The system sends out automatic email reminders to the relevant Voters and Reviewer. |
Step 1.2 – Apply the vote to the relevant Units in your organisational structure:
FIG1.2a: Apply the vote to the relevant Business Units in your organisational structure
FIG1.2b: Apply and activate the vote check boxes. | FIG1.2c: Select the relevant unit/s where this voting template will be applied to. The system will activate the vote for Voters who have voting rights on their specific units. |
FIG1.2d: Vote is applied / copied to the relevant units
Step 2 – Owners complete their RCSAs online
Step 2.1 – Risk & Control Owner/s complete their RCSA online (free license)
The system automatically sends an email to the relevant risk and control owners with a web link to their RCSA/s including an end (due) date by which their vote must be completed. The system will send out email reminders automatically as the end date (due date) approaches. The risk / control owner can also login to the BarnOwl portal at any time to view and complete his / her active RCSA/s. In the following example, the control owner rates the control effectiveness for each of his / her controls:
FIG2.1a: My Voting page (logged in as the voter ‘Manager, Risk’)
Fig2.1b: Voter rates his / her controls
Fig2.1c: Voter can capture the following per control: a) Action Plans in moderation mode b) Upload evidence c) Capture comments
In the example below, the Voter captures an action plan. New action plans are automatically saved in moderation mode which means that they won’t go ‘live’ until they have been moderated (authorised) by the reviewer and the vote has been closed and updated to BarnOwl.
Fig2.1d: A voter can also ‘assign a proxy’ if someone else needs to vote on his / her behalf
Step 2.2 – Reviewer (optional) reviews the completed CSA online (free license)
Once the risk and control owners have completed their vote/s, the reviewer views the voting results and can override the vote where required including a reason for the override.
Fig2.2a: By clicking on the ‘scale’ icon, the Reviewer can see all the other votes and use the ‘Use Average’ button if required to average all voting
The Reviewer can also rate each controls which takes precedence over all other votes. (i.e. becomes the final control rating)
FIG2.2b: The Reviewer can choose to ‘select’ or ‘deselect’ any action plans created or linked by the Voter/s
The Reviewer can also add an action plan/s to the control/s.
The ‘selected’ action plans only become live once the vote is closed and updated to BarnOwl.
The action plan icon shows the number of action plans selected (authorised) out of the total number of action plans:
Fig2.2c: The Reviewer (or Voter) can generate a Vote report and / or export the voting register to PDF
Fig2.2d: Reviewer can close the vote and update to BarnOwl
Step 3 – Risk Champion monitors and collates the RCSA results
Step 3.1 – Monitor the RCSA submission status
Fig3.1a: Vote tracking showing status of votes
Step 3.2 – View the RCSA results including comparing the Reviewer’s control ratings with the Control Owners’ ratings:
Fig3.2a: Vote tracking results
Fig3.2b: Vote tracking dashboard
Fig3.2c: Vote tracking dashboard drill through into a specific vote
Step 4 – Risk Champion updates the live BarnOwl registers with the RCSA voting results
Step 4.1 – Update the risk and control registers with the RCSA voting results
Fig4.1a: Update voting results into BarnOwl
Step 4.2 – View the updated risk and control registers in BarnOwl
Fig4.2a: View the updated results in BarnOwl
Step 5 – Up to date risk management reporting
The BarnOwl business intelligence module provides interactive, drill-down dashboards transforming risk, compliance and audit data into valuable business insight and foresight.
Fig5.1a: Risk dashboard showing risk rating trends
Fig5.1b: Control dashboard showing control effectiveness trends
Useful links
Link to info latest info sharing session
https://www.barnowl.co.za/tip-of-the-month/tip-of-the-month-barnowl-combined-assurance/
https://www.barnowl.co.za/tip-of-the-month/tip-of-the-month-barnowl-online-help-manuals/
About BarnOwl:
BarnOwl is a fully integrated governance, risk management, compliance and audit software solution used by over 150 blue-chip organisations. BarnOwl is a locally developed software solution and is the preferred risk management solution for the South African public sector supporting the National Treasury risk framework.
Please see www.barnowl.co.za for more information.