SOP - Stage 5: Monitoring and Improvement Flashcards
Why might CM require update?
To align to updates to business operations and process objective.
What are the two purposes of Stage 5: Monitoring and Improvement?
- Assess ongoing effectiveness
- Optimise CM where possible
What are the 3 key activities in Stage 5: Monitoring and Improvement?
- Complete self-assessment
- Complete independent CM testing
- Change or decommission CM
How is CM self-assessed?
Via a Continuous Monitoring Self-Assessment (CMSA)
Why is CM self-assessed?
To determine whether the CM design meets its objective and is operating as designed.
What are 4 triggers for Continuous Monitoring Self-Assessment (CMSA)?
- Annual PH process certification
- A material event
- Findings (moderate and above)
- Indicator (red) linked to the CM/Process
What should be done if Continuous Monitoring Self-Assessment (CMSA) result is Not Effective?
Create Finding and Treatment Plan
Who undertakes periodic independent testing of CM and why?
CCoE do independent testing as an ongoing governance mechanism to ensure the integrity of the CM.
Where is the Continuous Monitoring Self-Assessment (CMSA) uploaded?
SharePoint
Where are independent CM testing results (and applicable Findings) uploaded?
GRACE - Second Line Review tab
If CM design or operation is determined to be Not Effective, what two things must Process Owners do?
- Inform owners who have controls, risks, and obligations that are linked to the CM.
- Respond to the findings in GRACE with a TP