GRACE Personas Flashcards

1
Q

What are the 6 core personas in GRACE?

A
  1. Owner
  2. Manager
  3. GRC Facilitator
  4. Review & Challenge
  5. General User
  6. Librarian
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are 4 additional GRACE roles?

A
  1. Independent Control Testers
  2. BES Submitter/Lead/Delegate
  3. MOI Manager
  4. Regulatory Management Contributor & Viewer
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an Independent Control Tester responsible for?

A

Key role in control assurance: schedule TCTs, perform targeted Control tests, and similar.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In GRACE, what does BES stand for?

A

Business Environment Summary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does a BES Submitter/Lead/Delegate do?

A

Create, read, and update Business Environment Summaries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In GRACE, what does MOI stand for?

A

Matters of Interest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or false: MOI manager is a specialist Risk role with elevated access in the Finding/Treatment Plan module?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Who is accountable for a record?

A

Record Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Can a Record Owner nominate an “Owner’s Delegate” to assist with managing records?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True or False: Owner’s Delegates are unable to provide approvals as part of managing records?

A

This is false – A delegate can provide approvals, assuming this is part of their delegated responsibilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Who would generally be a Record Owner?

A

This role is generally held by a GM or HO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are Record Owner key responsibilities?

A
  • Accountable for assigned records and associated approvals.
  • Responsible for linkages to their records.
  • Approve assessments.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who would normally be a Record Manager?

A

Typically, a 2IC of an Owner. They are nominated by the Owner for GRC Facilitator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What must a Record Manager do?

A
  • Day-to-day responsibilities for managing record details in the system.
  • Support the Owner to help monitor and review records through to closure/retirement/withdrawal.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Who will a Record Manager work closely with to ensure effective management of records?

A

DCO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Who is responsible for performing assessments for Control Records

A

Record Manager

17
Q

Can a Record Manager create, manage, and initiate closure/retirement/withdrawal for their assigned records?

A

Yes

18
Q

What records can a Record Manager manage?

A
  • Risk
  • Controls
  • Events
  • Findings & Treatment Plan
  • Indicators
19
Q

Do all NAB employees have access to GRACE in their NAB single sign on profile?

A

Yes

20
Q

What can create, modify, manage, retire, close, withdraw records in GRACE?

A
  • Owner
  • Manager
  • GRC Facilitator
  • General User
21
Q

Who can be considered a General User of GRACE?

A

Anyone from NAB

22
Q

What key attributes/responsibilities does a General User have?

A
  • Responsible for identifying risk.
  • Is the eyes and ears of the Organisation.
23
Q

What is a GRC Facilitator?

A
  • An SME with enhanced system access.
  • Typically, a specialist from Enterprise Controls/Divisional Controls, however, could also be from the Business.
24
Q

What do GRC Facilitators do?

A
  • Triage, edit, and provide guidance on a broad range of records.
  • Help coordinate risk management activities and insights.
  • Provide guidance/expertise to help Business manage their records.
  • Complete activities on behalf of Owner or Manager.
25
Q

Who provides review & challenge in GRACE?

A
  • 2nd Line Risk Specialist
  • Typically, a Senior Manager or Senior Risk Partner
26
Q

Is a 2nd Line Risk Specialist part of the workflow in GRACE?

A

No

27
Q

What does a 2nd Line Risk Specialist do in GRACE?

A
  • Review and challenge of a record.
  • Independently monitor and manage risks (not part of formal record workflow).
  • Create and read records (as a General User).
28
Q

What is a GRACE Librarian?

A

Risk Specialist responsible for creating, modifying, and managing library records.

29
Q

Is a GRACE Librarian part of the normal workflow of a record?

A

Only for Obligations; otherwise, no.

30
Q

What does a GRACE Librarian do regarding Obligations?

A
  • Create Master Obligations
  • Assign Obligation Owner & Manager
  • Creating Obligation instances from relevant Master Obligation and assigning this to the appropriate node in the hierarchy.
  • Closing/retiring Master Obligations and Obligation Instances.