on ‎2020 Jan 28 7:15 PM
Hello,
We are currently on GRC 10.1 SP15.
We have defined the risk type as Critical or non-critical. The request mitigation policy is set to have mitigation only for the critical risks.
From what I understand, GRAC_MSMP_DETOUR_SODVIOL function helps route the request in cases of a risk. Currently, both critical and non-critical risks are routed and the risk owner cannot close a request with critical risk without mitigation.
Is there any standard function available where in the request is routed only in case of critical risks and the non-critical risks does not invoke the routing.
Thank you,
Praman Mulay
Request clarification before answering.
Hi Praman,
Then it can be achieved using the Mitigation Policy,your BRF+ DTshould look like this
Risk Type : SOD+ Risk Level : Critical should route to Complinance Rule
Risk Type : SOD+ Risk Level : Non Critical should route to Non Complinance Rule(No Stage for auto approval)
Thanks
Ramesh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 15 | |
| 8 | |
| 7 | |
| 6 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.