In my last post, I broke down the 4-Layer Architecture for ARIS Scripting & Data Traversal explaining how custom report scripts navigate from the Database Layer down through Hierarchy, Metamodel (ObjOcc vs. ObjDef), and Data Traversal.
A question that came up after sharing that framework was: How does this traversal logic actually work in a highly regulated enterprise environment?
To show how this works in practice, let’s look at a concrete example from pharmaceutical logistics. Under strict EU GxP and GDP guidelines, every process handling or transporting medicinal products must be validated. Static PDFs or unmanaged spreadsheets don't cut it .ARIS serves as our single source of truth.
Below is how we apply that 4-layer traversal logic to check mandatory compliance attributes automatically and keep our database audit-ready.
The QA(Quality Assurance) Audit Governance Model
In our previous scripting layer model, the decision node checked whether an attribute was maintained. In pharma logistics, we make that decision concrete by inspecting specific GxP attributes and control linkages:
1. Metamodel Layer: Risk & Control Alignment At the Metamodel Layer, every operational step—represented as a Function object (OT_FUNC) is directly linked to its corresponding Risk (OT_RISK) and Control (OT_CTRL) objects. This anchors operational workflows directly to compliance safeguards.
2. Mandatory Attributes & Segregation of Duties (SoD) During the script's attribute evaluation phase, we inspect specific metadata required by Quality Assurance:
-
AT_GXP_RELEVANT = True: Identifies functions impacting product quality or safety. - Segregation of Duties (SoD): Enforces role separation and authorization constraints.
3. Scripting Traversal Layer: Automated Repository Scanning Following the traversal path outlined in the 4-layer architecture (ArisData.getSelectedModels() → model.ObjOccList() → objOcc.ObjDef()), our custom ARIS JavaScript report script scans the repository.
-
Compliant (Pass): If all required controls are linked and attributes are maintained, the process is flagged as Audit Compliant (Inspect Ready).
- Non-Compliant (Fail): If any required attribute or control is missing, the script flags an Audit Gap (Requires Fix), letting QA teams fix compliance issues long before an auditor sees them.