Perform an Applicability Assessment
Last Modified on 05/19/2022 10:53 am EDT
Once an assessment has been scoped, Compliance Team members must review its requirements. All requirements assigned to you and your team will be available in Compliance Management > Determine Applicability > Applicability Assessment.
To perform an applicability assessment:
- Log into a user account from the Compliance Team user group.
- Click the dropdown bar in the nav bar > Compliance Management to display the Determine Applicability activity.
The Compliance Management activity.
- Click a requirement in the Applicability Assessment section to display it.
The Applicability Assessment section from the Determine Applicability page.
- Review the requirement to determine if it's relevant to your line of business.
- The Requirement Name, Description, Subtopic, and Source of Requirement fields may already be completed, depending on the content in your compliance framework.The Determine Applicability form.
- Click the links within the Requirement Details section to review the specific areas your organization must comply with.
Review Requirement Details.
- Select either Applicable or Not Applicable in the Applicability Assessment field.
If you selected
| Then |
Applicable | - In the Requirement Owner and Requirement Delegate (if applicable) fields, start typing to display a list of available options, then select the relevant user and/or user group.
- Optional: Click View Requirement Profile to view this assessment's Requirement Profile report, which summarizes all information about the requirement as well as its attached controls and issues.
- Click Send for Risk Assessment. The Requirement Owner will get an email that a requirement has been assigned to them.
An applicable requirement. |
Not Applicable
| - Enter your reason for marking this requirement Not Applicable in the Rationale for Not Applicable field.
- Click Requirement Not Applicable. The Requirement will move to the Not Applicable workflow state and can be viewed in the Reports application. Note: Only the Compliance Team can reassess a requirement when it’s deemed inapplicable.
Marking a requirement as Not Applicable.
|