PO8  Ensure Compliance with External Requirements
Control over the IT process of ...
compliance with external requirements
    with the business goal
    to meet legal, regulatory and contractual obligations
     
      is enabled by
      • identifying and analysing external requirements for their IT impact, and taking appropriate measures to comply with them

        and takes consideration

        • Critical Success Factors that leverage
        • specific IT Resources and is measured by
        • Key Performance Indicators

Record of Assessment
Assignment ID: * Enter Name:*
Reference Code: * Enter Location:* Tel. Num: *
Enter Full e-mail Address: *
  Control Objective:

Define and manage service levels. 

CRITICAL SUCCESS FACTORS
Selected Status
Description
*
Policies and procedures relating to compliance with external requirements have been documented and communicated
*
A monitoring function reviews compliance
*
An inventory of corrective actions needed to meet external requirements is maintained
*
Follow-up processes to resolve external compliance issues are defined
*
Information is available to determine the cost of compliance with external requirements
*
Effective internal audits covering compliance are performed
*
*
*
*
*
*
*
*
*
*
KEY GOAL INDICATORS
*
Number of external legal, regulatory or contractual issues arising
*
Average age of external legal, regulatory or contractual open issues
*
Cost of non-compliance, such as settlements or fines
*
*
*
*
*
*
*
*
*
*
*
*
KEY PERFORMANCE INDICATORS
*
Frequency of compliance reviews
*
Number of exceptions identified in compliance reviews
*
Average time lag between identification of external compliance issues and resolution
*
*
*
*
*
*
*
*
*
*
*
*
*
*
  Conclusions:
* Non-existent 
There is little awareness of external requirements that affect IT, with no process regarding compliance with regulatory, legal and contractual requirements.
* Optimised 
There is a well-organised, efficient and enforced process for complying with external requirements, based on a single central function that provides guidance and co-ordination to the whole organisation. There is extensive knowledge of the applicable external requirements, including their future trends and anticipated changes, and the need for new solutions. The organisation takes part in external discussions with regulatory and industry groups to understand and influence external requirements affecting them. Best practices have been developed ensuring efficient compliance with external requirements, resulting in very few cases of compliance exceptions. A central, organisation-wide tracking system exists, enabling management to document the workflow and to measure and improve the quality and effectiveness of the compliance monitoring process. An external requirements self-assessment process is implemented and has been refined to a level of best practice. The organisation's management style and culture relating to compliance are sufficiently strong and processes are developed well enough for training to be limited to new personnel and whenever there is a significant change.
* Managed and Measurable 
There is full understanding of issues and exposures from external requirements and the need to ensure compliance at all levels. There is a formal training scheme that ensures that all staff are aware of their compliance obligations. Responsibilities are clear and process ownership is understood. The process includes a review of the environment to identify external requirements and on-going changes. There is a mechanism in place to monitor non-compliance with external requirements, enforce internal practices and implement corrective action. Non-compliance issues are analysed for root-causes in a standard manner, with the objective to identify sustainable solutions. Standardised internal best practices are utilised for specific needs such as standing regulations and recurring service contracts.
* Defined Process 
Policies, procedures and processes have been developed, documented and communicated to ensure compliance with regulations and with contractual and legal obligations. These are not always followed and some may be out-of-date or impractical to implement. There is little monitoring performed and there are compliance requirements that have not been addressed. Training is provided in external legal and regulatory requirements affecting the organisation and the defined compliance processes. Standard pro-forma contracts and legal processes exist to minimise the risks associated with contractual liability.
* Repeatable but Intuitive 
There is an understanding for the need to comply with external requirements and the need is communicated. Where compliance has become a recurring requirement, as in financial regulations or privacy legislation, individual compliance procedures have been developed and are followed on a year-to-year basis. There is, however, no overall scheme in place ensuring that all compliance requirements are met. It is likely, therefore, that exceptions will occur and that new compliance needs will only be dealt with on a reactive basis. There is high reliance on the knowledge and responsibility of individuals and errors are likely. There is informal training regarding external requirements and compliance issues.  
* Initial / Adhoc 
There is awareness of regulation, contract and legal compliance impacting the organisation. Informal processes are followed to maintain compliance, but only as the need arises in new projects or in response to audits or reviews.
Settings will expire on: 

(Do NOT edit.) Field set by Form.
Save and E-mail this form. (Saves only "*" fields & sends E-mail to address above):


Maintenance Functions

Note: If using Netscape on a Macintosh you may have to submit twice, the first will fail, or you can push the "Save Changes and/or Set New Expiration" then Submit.