Camms.Risk Controls Management - November 2024

Camms.Risk-Controls-release-note-FD-banner.jpg

Camms is pleased to bring you the Quarterly Product Update Release Note for the Camms.Risk Controls Capability.

This quarter we've got exciting enhancements to improve your user experience within the system, which will be available in your Test environment on 12th October 2024 and will be available in your Live environment on 2nd November 2024.

1. Enhancing the Control Permissions of the Control Review process to maintain field-wise editability & introduce new email snippets for controls

1. Enhancing the Control Permissions of the Control Review process to maintain field-wise editability & introduce new email snippets for controls

This enhancement allows users to have field-specific editability for Control review frequency, Next review date, and Last review date related to the Control review process.

Additionally, new control email snippets, such as Review frequency and Next review date, will be added to the list of control email snippets.

 

How do you configure this?

  • Specific permissions such as Edit Next Review Date, Last Review Date and Review Frequency must be present after activating the setting ‘Control Review’ within the Role Management > Controls Product Tree. If the setting is deactivated from Control settings, the new set of permissions will be disappeared from the Role management.

image-20241010-060102.png
Figure 1.1: Controls permissions within Control Product Tree
  • Specific permissions such as Edit Next Review Date, Last Review Date and Review Frequency must be present after activating the setting ‘Control Review’ within the Role Management > Risk Product Tree. If the setting is deactivated from Control settings, the new set of permissions will be disappeared from the Role management.

  • Specific permissions such as Edit Next Review Date, Last Review Date and Review Frequency must be present after activating the setting ‘Control Review’ within the Risk Settings > Standard Roles > Control node. If the setting is deactivated from Control settings, the new set of permissions will be disappeared from the Standard roles as well.

  • Further these permissions will be extended to Compliance > Controls Object User Role and for the ‘Control Creator’ static role.

Before the Q4 Quarterly Release, previously if the Control > Edit permission is ticked for the user roles, then by default, along with the Q4 release, these new permissions will also be ticked for those user roles with the activation of the Control review setting. If you have activated the Control review setting newly, post Q4 Quarterly Release, please request Camms Support if all of those new edit permissions need to be ticked automatically.

 

  • A new snippet named ‘Review Frequency’ is introduced within controls notifications area when during the design of the templates.

How does it work?

  • Permissions will be restricted for the specific user in union of the roles he/she has in place, hence for example when ‘Control Review’ is activated editability of the i.e. Next Review Date can be restricted for the user to be editable.

  • Further, the control review frequency value can be utilized for your control email notification templates.

2. Enhancing the control email functionality to consider only active controls when triggering emails to users.

2. Enhancing the control email functionality to consider only active controls when triggering emails to users.

This enhancement eliminates all the inactive controls when it comes to triggering control emails to users. Only active controls will be considered to send out control emails.

 

How does it work? 

 From this enhancement, if user makes a control as inactive, then there won’t be any email notification triggered with regards to that inactive control.

The Control Name List snippet will exclude any ‘Inactive’ controls.

The following control related email triggers will exclude emails for ‘Inactive’ controls:

  • Control Creation

  • Control Assignment

  • Control Owner Rating Change

  • Control Authorizer Rating Change

  • Control Solution Creation

  • Control Solution Next Update

  • Control Solution End Date

  • Control Solution Completed Date

  • Control Next Review Date

This will reduce the inconvenience for the user to receive unnecessary emails regarding inactive controls that do not require attention to look into, meanwhile allowing user to focus on the active controls only, thus enhancing the user experience.

 

 

Â