Exploring the entities
Entities are one of the most fundamental and crucial elements for using Governance, Risk, and Compliance. Entities can be people, processes, departments, applications or objects that are examined for risks.
To effectively maintain the risk universe of your organization, we recommend that you define entity types, entity classes, and entity tiers. A risk universe refers to a list of risks that your organization either faces or might face in the future. The list contains a description of each risk's criticality and frequency. Entities are used within all offerings of GRC such as GRC: Policy and Compliance Management, Audit Management, and GRC: Regulatory Change Management.
- Entities in GRC
An entity is a person, process, department, application, or other object whose compliance exposure is tracked in GRC. Each entity has an owner, so non-compliant items and their owners can be identified individually. - Entity types in GRC
Entity types enable you to find and create entities that match a set of filter conditions. Entity types also enable you to create risks and controls for each entity without spending much time. - Entity classes in GRC
Entity classes are used to tag your entities and to provide a complete view of the risk status in your organization. - Entity tiers in GRC
By creating entity tiers, you can prioritize the entity classes.
Parent Topic:Governance, Risk, and Compliance