What comes to mind when you hear “digital evidence”?

Who cares?

I mean, who actually has to care about digital evidence? Consider the audiences or different roles of people who need to produce or rely on digital evidence: management and business unit leaders; auditors; information management, technology, compliance, and security professionals; and the officers of your organization. We are producing unstructured data, much of it valuable, at a breakneck pace. Do you know who your producers of quality digital evidence are?

When I hear digital evidence, I think of the artifacts that may be considered digital evidence such as raw data, reports, signed documents, test results, specifications, and performance receipts. Documentation of activities that provide assurance, including procedures, work instructions, training sessions and materials, and attestations are also critical. Have you identified which practices and assurances are closest to your significant accounts, risks, and controls?

How do we wrap our arms around digital evidence?

There are systems and practices that provide the bookends for ensuring relevant and reliable results contributing to digital evidence such as systematic management and monitoring of workflow, milestones, deadlines, analyses, and remediations. Digital evidence also relies on the trail of bread crumbs that show who touched what and when including the audit trail of changes, versions, handoffs, and approvals. Without a central portal or system in place, it is plain to see, we cannot reliably manage digital evidence.

Are you taking advantage of all that policyIQ has to offer in these areas?

Alerts, dashboard notifications, and email generated systematically by RGP’s policyIQ helps employees know when work is required of them. The taxonomy of the digital content is configurable and can be subject to the information governance preferences of your organization with appropriate read, write, and approve rights established during initial configuration. policyIQ can provide an enforceable framework to manage contributions, the complete capture, monitoring, and reporting on critical documentation and evidence.

If your opportunity has more to do with the quality of your existing evidence or the need for corroborating evidence, RGP’s subject matter experts can help to assess your need and to fill any gaps identified. Right now—whether related to technology, process, quality, or completeness—make a note of some of those gaps or pain points that just crossed your mind. And then reach out to us: Information@policyIQ.com; 412-263-3330.

How to Transition from Manual to Automated Workflows

Tis the season for fresh starts!

Let us help you manage the development, hand-offs, review and approval of your GRC content more efficiently! Have you designated the parties responsible for updating your Process Narratives and Control documentation? Do you have a process defined for who captures testing details and who performs the final review of audits?

Have you mapped out hand-offs in your processes?

The workflow features in policyIQ support multiple levels of authoring, reviewing, and final approval by individuals or groups, such as one of two line staff or any of 3 auditors. These features allow you to institute your expectation for updates and hand-offs so that those actually responsible for performing various duties are prompted by the system to properly wrap up their work and to establish a defensible audit trail with appropriate documentation and evidence.

Is your team utilizing the Check-in/Check Out capability to collaborate with fellow contributors? Have you added external auditors and other stakeholders as Viewers on your documentation? Rest assured that Viewers will have Read-only access only after your content has completed your designated approval process.

Ensure greater communication, security, performance, and cost savings with automated workflows

We are standing by ready to talk through your options on how to transition from manual maintenance to automated workflows. It’s 2019! Time for a fresh start and more efficient and effective processes. Talk to you soon!