Process Design Assessment
In addition to the detailed Assessment of Control Design and Efficiency, management can also assess the superordinate level, in other words the entire process. Such an assessment can review, for example, whether the controls occur in the right sequence in the process, or whether controls are missing or occur in duplicate.
The person who is to perform the assessment has authorization for the task Perform Process Design Assessment (PERF-PDASS).
The P-CO-R-C view (Process – Control Objective – Risk – Control) forms the basis for process design assessment. In this view, you can check whether sufficient controls are defined to achieve the control objectives and to minimize risks as far as possible. Furthermore, you can check the purpose of the controls to ensure that preventive as well as detective controls are implemented.
When the assessor has reviewed the process design, he or she enters the assessment result in the system (using the appropriate task in his/her task list) and issues a rating manually. For this rating, the same values are available as those for assessing control design and efficiency. A process cannot be issued a green rating if one of the controls of that process has a yellow or red rating.
If a yellow or red rating is issued, the assessor must report the related issue.
As with the assessment of control design and efficiency, you can make a setting for process design assessment so that it has to be validated.
Depending on the result of the assessment and on whether validation is required, different changes in status and thereby different process flows are possible. For more information, see Process Flow of Assessments and Manual Tests.