Contents1 About Enterprise Governance, Risk and ComplianceManagerWhat Is Governance, Risk and Compliance? . 1-1Enterprise Governance, Risk and Compliance Manager Explained 1-1Business Objects Explained . 1-1What are User-Defined Attributes? . 1-2Example: Using UDAs. 1-2Perspectives Explained . 1-2Risks Explained . 1-3Controls Explained . 1-3Issues Explained . 1-3Assessments Explained . 1-4Surveys Explained . 1-4Application Modules Explained . 1-4What Is the Financial Governance Module? . 1-5Reporting Explained . 1-52 Basic Application Operation and Common TasksSecurity Overview. 2-1Roles Explained. 2-1Basic User Interface . 2-2Home Page Explained . 2-2Common Regions on Overview Pages . 2-3Contentsiii

Common Elements in Overview, Dashboard,and Component Pages . 2-3Object States . 2-4Common Tasks . 2-5Preferences Explained . 2-5Attachments Explained . 2-6Revisions Explained . 2-6Managing Objects Explained . 2-6Copying Objects Explained . 2-6Reviewing Objects Explained . 2-8Approving Objects Explained . 2-8Creating Issues: Critical Choices . 2-8EGRCM Reporting Described . 2-83 Perspective ManagementPerspective Management Explained . 3-1Delivered Perspectives Explained. 3-1When Should I Create an Issue for a Perspective? . 3-2Creating Perspectives: Critical Choices . 3-3Perspective Assessments Explained . 3-3Perspective Certification Process Explained . 3-34 Risk ManagementRisk Management Explained . 4-1Risk Life Cycle Explained. 4-1Proposing a Risk Explained . 4-2What Is the Difference Between Creating andProposing a Risk? . 4-2Do I Always Have to Propose a Risk Before ICan Create One? . 4-2Are Risks Automatically Created from Proposed Risks? . 4-3Creating a New Risk: Critical Choices. 4-3Editing Related Controls: Critical Choices . 4-3Creating a New Event: Critical Choices . 4-4Creating New Consequences: Critical Choices . 4-4ivOracle Enterprise Governance, Risk and Compliance Manager User Guide

Risk Analysis Explained . 4-4Risk Analysis Process . 4-5Create an Analysis: Critical Choices . 4-5Risk Evaluation Explained . 4-6Creating an Evaluation: Critical Choices . 4-6Risk Assessments Explained. 4-6Risk Treatments Explained . 4-7Creating a New Treatment Plan: Critical Choices . 4-7Creating a New Treatment: Critical Choices . 4-7Risk Administration . 4-8Creating an Analysis Model: Critical Choices . 4-8Creating a Likelihood or Impact Model: Critical Choices . 4-8Creating a Risk Context Model: Critical Decisions . 4-9Risk Significance Models Explained. 4-95 Control ManagementManaging Controls Explained . 5-1Creating New Controls: Critical Choices . 5-1Creating Control Test Plans and Instructions . 5-2Test Plans Explained . 5-2Creating Test Plans: Critical Choices . 5-2Creating Manual Test Instructions Explained . 5-3Creating Automatic Test Instructions Explained . 5-3Editing Control Definitions Explained . 5-3Control Assessments Explained . 5-36 Managing Base ObjectsBase Objects Explained . 6-1Managing Base Objects Explained . 6-1Creating New Base Objects: Critical Choices . 6-1When Would I Create an Issue for an Object? . 6-2Base Object Assessments Explained . 6-2Action Items . 6-2Creating Action Items: Critical Choices . 6-2Contentsv

What Is the Difference Between an Action Itemand an Issue? . 6-3What Is the Difference Between a Target CompletionDate and a Due Date? . 6-37 Issue ManagementIssue Management Explained . 7-1Issues Explained . 7-1Issue Life Cycle Explained . 7-1Creating Issues: Critical Choices . 7-2Editing an Issue: Critical Choices . 7-2Creating Remediation Plans: Critical Choices . 7-3What Is the Difference Between a Target CompletionDate and a Due Date? . 7-3Creating a Remediation Task: Critical Choices . 7-38 Managing AssessmentsAssessments Explained . 8-1Assessment Activities Described . 8-2Methods of Initiating Assessments Described . 8-3Ad Hoc Assessments Explained . 8-3Assessment Management Explained . 8-4Managing Assessments . 8-4Creating Assessment Templates: Critical Choices. 8-4Assessment Plans Explained . 8-5Creating Assessment Plans: Critical Choices . 8-5What Is the Difference Between an AssessmentTemplate and an Assessment Plan? . 8-5Initiating Assessments Explained . 8-5Initiating an Assessment: Critical Choices . 8-5Completing Assessments Explained . 8-6Reviewing and Approving Assessments Explained. 8-7What Do the Assessment Result Options Mean? . 8-79 Managing SurveysManaging Surveys Explained. 9-1viOracle Enterprise Governance, Risk and Compliance Manager User Guide

Managing Survey Questions. 9-1Creating Questions: Critical Choices. 9-1Managing Survey Choice Sets . 9-2Managing Survey Templates . 9-3Creating a Survey Template: Critical Choices . 9-3What Happens When I Delete a Survey Template? . 9-3Creating and Editing Surveys Explained . 9-3Completing Surveys Explained . 9-410 ReportingReports Explained . 10-1Delivered Reports . 10-211 Administration TasksManaging Application Configurations . 11-1Properties Tab . 11-1Worklist Tab . 11-2Security Tab . 11-2Analytics Tab . 11-3User Integration Tab . 11-3Notification Tab . 11-4Managing Installation Options . 11-5Managing Lookup Tables . 11-5Managing Content Types . 11-6Managing the URL Repository. 11-7Managing Assessment Results Explained . 11-712 Managing SecuritySecurity Overview. 12-1Managing Duty Roles . 12-1Managing Data Roles . 12-1Managing Job Roles . 12-3Managing Users . 12-3Creating New Users . 12-3Importing Users from LDAP . 12-4Contentsvii

13 Managing ModulesModule Management . 13-1Templates Explained . 13-1Example: Creating a New Module . 13-2Configuring Module Objects . 13-4Managing User-Defined Attributes . 13-4Managing Module Perspectives . 13-5Managing Data Migration . 13-6GlossaryviiiOracle Enterprise Governance, Risk and Compliance Manager User Guide

1About Enterprise Governance, Risk andCompliance ManagerWhat Is Governance, Risk and Compliance?Worldwide, legislators, regulators and investors are placing increasing mandates onbusinesses to improve transparency and controls over financial and compliancereporting. Laws such as the U.S. Sarbanes Oxley Act, Canadian Bill 198, OMBCircular 123A, and Japanese SOX (JSOX) are forcing organizations to adoptrigorous approaches to documenting and testing internal proces

