PACE 2.0 Flashcards
What are the 7 PACE steps?
- Understand core business activities
- Develop process objective
- Document process model and identify controls
- Analyse controls and review linkages
- Raise findings and treatment plans
- Overlay controls, obligations, and risks
- PACE certification and model approval
What does PACE focus on?
The link between processes and controls
In PACE 2.0, what risks and obligations will you have?
Only those related to processes you execute
What will process objective capture?
- Business objectives
- Obligation compliance
- Risk mitigation
- Continuous monitoring (where relevant)
What are PACE Coaches two key responsibilities to ensure?
- PACE methodology is followed
- Colleagues are appropriately trained and skilled to execute PACE
Will PACE actively manage obligations or risk exposure?
No
How will obligations be managed?
Through the Compliance Plan
How will risks be managed?
Through risk profiling
What will be the source of truth for controls supporting obligation or risk management?
GRACE
Will the PACE Coach validate analysis of processes?
No
Will PACE Coach QA models?
No
When will relevant risks and obligations be agreed on?
At the start of PACE in a workshop
Who is responsible for identifying risks and obligations relevant to in-scope processes?
‘Managers’ for Process, Risk, and Obligations
After understand core process activities, what happens if it is determined that these aren’t included in the risk profile?
Risk Manager requests a Risk Profile refresh
Who is responsible for ensuring process changes are reflected in Process Hub?
Process Model Owner
Who is responsible for the execution of business activities (L4 processes)?
Process Owners/Managers
What does individual control analysis check for?
Confirming if control objective supports process objective.
What happens if an individual control objective does not match process objective?
A Finding is raised to have the control updated.
When controls are analysed collectively, when it is decided that a gap has been identified?
If controls do not cover all aspects of the process objective (business performance requirements, obligation execution, risk exposure). Unless a risk has been ‘risk accepted’ with no controls.
Who documents the process model steps?
- Process Model Owner
- PACE Process SME
Who identifies/analyses controls?
- Process Model Owner
- PACE Controls SME
How do we ensure the correct anticipated risks and obligations are automatically overlayed onto the process model once published?
The control-risk and control-obligation linkages are reviewed in GRACE. If they’re not aligned to what was agreed in the process objective workshop, the PMO or PACE Controls SME must create a Finding to address this
How is the model finalised (seven tasks)?
- PMO or PACE Controls SME overlays controls on the model.
- Process Owner/Manager confirms model and controls are correct.
- PMO validates the linkages align to agreed objective.
- Findings/TPs raised in GRACE if required.
- PACE Process SME submits the model.
- PACE Coach certifies the model.
- Process Owner/Manager provides final approval.