Go to Welcome Page

Operating Guide

Version 3.3

What’s New

System Manuals

User Operations

Managing Operations

Outputs and Records

Administration

User Operations

Basics

My Summary

Portal / Mobile Device

Useful

Glossary

Managing Operations

SMCR (Accountability UK)

Compliance

Risk

KRIs

Events

Registers

Contracts

Control Inventory

Document Library

Obligations

Triage PRO

Outputs and Records

Dashboards

Reports Charts Adhoc Stats

Record Management

Alerts

Administration

Configuration & Maintenance

Current Tasks

Security

Monitor

Audit Trail

TriLine GRC and Compliance

Page contents

Overview

Overview

About Compliance

A Compliance Process identifies the Tasks required to meet your organisation’s legal and business requirements for the control and disclosure of information.

For example, a Compliance Process to ensure your organisation’s compliance with industry regulations might include the following Tasks (called Process Controls) to be carried out periodically:

The TriLine GRC Compliance Management Process

The following flowchart outlines the TriLine GRC Compliance Management process.

The TriLine GRC Compliance Management Process
The TriLine GRC Compliance Management Process

Identify and enter Compliance Process and Controls

1

Individuals appropriately trained and experienced in Compliance should identify and record all requirements for Compliance within your organisation. This can include compliance with:

If your organisation is moving from another Compliance Management System to TriLine GRC, a lot of this work has probably already been done and it’s just a matter of getting the information into TriLine GRC.

Tip:
Consider a plan to transfer existing Compliance Records and Process Controls into TriLine GRC as they become due for action. This will avoid you having to try and get everything into TriLine GRC in one go.

Schedule and allocate Process Control Tasks to Positions

2

For each identified Compliance Process:

Tip:
Process Controls should include a requirement to submit documentation to support any assertion of Compliance. These records can then be quickly recalled within TriLine GRC for evidence at any time. You can set a Process Control so that it cannot be completed without documentary evidence being attached to the Record.

TriLine GRC generates Tasks and sends email Reminders

3

On the appropriate date (determined by the Schedule and Reminder settings for each Process Control), TriLine GRC generates Process Controls and emails the person recorded in the Process Control Record as responsible for Actioning the Task (the ‘Actioned By’ Position).

The generated Process Controls are displayed in each ‘Actioned By’ Position’s ‘My Tasks’ page.

Position records completion of Task in TriLine GRC

4

Once the actions in the Process Control have been performed and any documentary evidence prepared, the ‘Actioned By’ Position reports completion of the Process Control in TriLine GRC. Where required, documentary evidence can be attached to the Process Control Record during completion, forming a permanent record of the actions taken and results obtained.

Task not completed—Task is escalated to Position’s Manager

5

If a Process Control is not completed on time, or won’t be completed at all for some reason, then TriLine GRC provides a way to ensure that this is managed.

You can set a Position to be the ‘Escalate To’ Position for each Process Control. If the Process Control is not completed by the due date, TriLine GRC sends a notification email:

This ensures that your Compliance Tasks are not missed, thus helping to avoid possible Compliance breaches.

Note: The escalation process does not move tasks from the Actioned By Position to the Escalation Position. The responsibility to complete the task remains with the Actioned By Position. The escalation process allows the Escalation Position to know when tasks are not completed by the due date so that they may choose to act.

Compliance Reports outlining Task completion and non-completion

6

TriLine GRC retains data recorded for each Compliance Process and Process Control. The ability to include attachments, links to other Records and resources makes TriLine GRC a valuable tool for building an accurate and detailed history of your organisation’s Compliance performance.

The more Compliance data TriLine GRC collects, the more information you have to improve organisational compliance, performance and reputation within your industry.

Page Contents Glossary