SOP - Stage 5: Monitoring and Improvement Flashcards

1
Q

Why might CM require update?

A

To align to updates to business operations and process objective.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the two purposes of Stage 5: Monitoring and Improvement?

A
  1. Assess ongoing effectiveness
  2. Optimise CM where possible
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 3 key activities in Stage 5: Monitoring and Improvement?

A
  1. Complete self-assessment
  2. Complete independent CM testing
  3. Change or decommission CM
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How is CM self-assessed?

A

Via a Continuous Monitoring Self-Assessment (CMSA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why is CM self-assessed?

A

To determine whether the CM design meets its objective and is operating as designed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are 4 triggers for Continuous Monitoring Self-Assessment (CMSA)?

A
  1. Annual PH process certification
  2. A material event
  3. Findings (moderate and above)
  4. Indicator (red) linked to the CM/Process
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What should be done if Continuous Monitoring Self-Assessment (CMSA) result is Not Effective?

A

Create Finding and Treatment Plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Who undertakes periodic independent testing of CM and why?

A

CCoE do independent testing as an ongoing governance mechanism to ensure the integrity of the CM.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Where is the Continuous Monitoring Self-Assessment (CMSA) uploaded?

A

SharePoint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where are independent CM testing results (and applicable Findings) uploaded?

A

GRACE - Second Line Review tab

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

If CM design or operation is determined to be Not Effective, what two things must Process Owners do?

A
  1. Inform owners who have controls, risks, and obligations that are linked to the CM.
  2. Respond to the findings in GRACE with a TP
How well did you know this?
1
Not at all
2
3
4
5
Perfectly