I have a team that is looking to note a risk at the process level instead of at each task step within the process. I want to keep the master object attributes if possible when doing this - so that the risk ID which is pulled from another system is maintained and can be referenced in reporting as needed.
Has anyone done this that they could share a best approach?
Alexander Cherednichenko on
There are several ways to approach this, and the best option depends on how your ARIS environment was implemented and which components/licenses you have available—for example, whether you have an API license.
From your description, it's still not completely clear what the exact task or limitation is. In general, there are many ways to integrate process and risk information and keep risk data synchronized with an external system.
If you have the ARIS API, you can implement the integration externally in almost any way—for example, with a custom application, integration script, middleware, or even an AI-based service. The external system can identify the existing risk object by its Risk ID and update the required attributes while keeping the same ARIS object definition.
If API access is not available, a very common approach is file-based integration. For example, the ERP/GRC system exports a file in an agreed format to a shared folder on a schedule, and an ARIS report/script reads this file, finds the corresponding risk objects by their external Risk ID, and updates the required attributes.
So I would first clarify what you want to achieve: whether the issue is reusing the same Risk definition at the process level instead of the task level, or keeping Risk attributes synchronized with the external system.