Using Assessments to manage risks and controls

The Diligent One Platform Assessments app empowers you with tools to manage your most common risks and controls, while reducing overhead.

Under My Activities, you'll find several navigation tools to provide a prioritized overview of your risk assessments and control tests, and the ability to rapidly complete the tasks in-line on the page. The Risk and Control Matrix (R&C Matrix) provides a flat list of all the risks and controls you have permission to view in order to provide supporting context.

Assessments presents the risk and control information assigned to you in the Projects app in a simplified view that’s also easy to access. You can use Assessments to manage the risks and controls you have access to, while completing your assessments and testing activities.

All risk and control information is synced between Projects and Assessments and is displayed in both apps, in real time.

Before you start using Assessments

Before you can complete an assessment, someone on your team needs to define your risks and controls in the Projects app. Then, they need to assign your tasks, which will appear in the Assessments app.

How Assessments works

Assessments has two primary sections.

The first section in the left menu, My Activities, contains several options to view the different types of activities assigned to you across multiple projects. The All option under My Activities displays all activities to which you have been assigned. The other options in My Activities display specific types of activity assignments. On all pages, activities are organized in a card view, and cards are displayed in order of the last time they were updated, with the most recent first.

On each card, you can be assigned one of the following activities:

  • Walkthrough the assessment of whether or not a control is designed effectively. Control walkthrough cards are assigned to you in Assessments if you are a Control Owner or a reviewer of the walkthrough. This card is where you document the results of a control walkthrough.
  • Questionnairecontent for a single questionnaire. This card is where you complete the questionnaire.
  • Test plan a description or series of steps that detail how the control is tested, though this is not an assessment. Test Plan cards are assigned to you in Assessmentsif you are a Control Owner or reviewer of the test plan.
  • Testing the testing of whether or not a control is operating effectively. Control testing cards are assigned to you in Assessments if you are a Control Owner, assigned to one of the control testing rounds, or test reviewer. This card is where you complete a test of a control.
  • Assess a risk the assessment of risk factors that have an impact on the achievement of objectives. This card is where you score a risk by choosing the relevant scoring factors. This card appears in My Activities in Assessments if you are assigned the Owner role for a risk.
  • Action monitor and manage action items related to issues that have been identified. Action cards appear in Assessments for actions that you have added, that have been assigned to you, or on which you have been CCed.
  • Request request or deliver documentation for audit-related queries. Request cards appear for requests that you have added, that have been assigned to you, or on which you have been CCed.

The second section on the left menu, Risk and Control Matrix, allows you to sort and filter risks and controls you have access to and that were assigned to you in Projects.

Caution

If you disable sign-off configuration settings in Project's project type settings, the control items (Walkthrough, Test plan, Testing) will not appear in the Assessments app.

  • Walkthrough tab > Sign-off configuration > Walkthrough Results
  • Test Plan tab > Sign-off configuration > Test Plan detail
  • Testing > Sign-off configuration > Testing Round detail

Do not disable this sign-off level if you will use the Assessments app.

See Customizing terms, fields, and notifications.

What the widgets mean for completing your activities in Assessments

    Assessments Widget Associated messages

    Checkmark for sign-off

    Each level of sign-off that has occurred, along with the name of the person who completed the sign-off

    Exclamation point for issue to address

    • Design Failure

    • Exception(s) Noted

    • No reviewer assigned

    Waiting for sign off

    The next pending sign-off level and assignee

    Created on

    Where the item was created such as Issue Test documents or Control Test

    Comment(s)

    Comments are available to view

    Refresh bar

    Click this button to refresh the cards listed on the My activities screen. Any card updates will appear, and cards will reorder based on the time of last updating.

Using Filters in Assessments

You can use Filters to locate cards. Some filters are based on what you have selected under My Activities, such as Actions, Controls, and so on.

Filter Description

Ongoing and Complete Status

Toggle this filter to select the status of the cards you want to see.

Ongoing - All cards that have an task for you to do, including test a control, review a tested control, sign any status of a control, assess a risk, or complete an action.

Completed - All cards that have no tasks for you to do. These cards show a "Complete" status on the information widget.

Sort by

Choose an option for the display order of cards:

Newest - Cards display from newest to oldest, based on the time the card was last edited.

Oldest - Cards display from oldest to newest, based on the time the card was last edited.

Project

This filter lists all the projects you have access to in Assessments.

The default status is All, enabling you to see risks and controls for all your projects.

You can search projects using the Search field inside the filter.

You can search for more than one project using multiple project search fields inside the filter. When the filter is active, only risks and controls from the selected projects will appear in the list of cards.

After selecting the desired projects, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.

Action Status (from Actions)

This filter lists all the action status you have access to in Assessments, such as Open, Remediated, or other values set by your organization.

The default status is All.

After selecting the desired action status, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.

Action Priority (from Actions)

This filter lists all the action priorities you have access to in Assessments, such as High, Low, or other values set by your organization.

The default status is All.

After selecting the desired action priorities, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.

Next Sign-off (from Controls)

This filter lists all the sign off statuses for the selected Project filter that you have access to in Assessments, such as Preparer, Reviewer, or other values set by your organization.

The default status is All.

After selecting the desired sign off statuses, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.

Control Activity Type (from Controls)

This filter lists all the control activity types you have access to in Assessments, such as test plan, walkthrough, or other values set by your organization.

The default status is All.

After selecting the desired control activity types, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.

Testing Rounds (from Controls)

This filter lists all the request testing rounds you have access to in Assessments, such as Initial, Final, or other values set by your organization.

After selecting the testing rounds, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.

Control (from Controls)

This filter lists all the controls you have access to in Assessments.

The default status is All.

After selecting the desired controls, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.

Request Status

(from Requests)

This filter lists all the request status terms you have access to in Assessments, such as In Progress, Open or other values set by your organization.

The default status is All.

After selecting the desired request status terms, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.

Risk Term (from Risk)

This filter lists all the risk terms you have access to in Assessments, such as All, Risk, or other values set by your organization.

All and Risk are selected as the default.

After selecting the desired risk term, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.

Completed Questionnaires (from Questionnaires)

This filter lists all the questionnaires you have completed.

The default status is All.

After selecting the desired questionnaire, click Apply.

Click Cancel to return to your previously applied state.

Click Clear to return to the default state and select all projects.