An organization has a list of companies with which they no longer wish to do business. The list is not stored in their ERP Could but is stored in a file.
Which transaction model will identify payments made to these companies?
Your client is configuring their Test pod (which has no data) and has created their initial import template with controls, test plans, perspectives, and perspective-control mappings. They have used custom list of values for Control Frequency.
Which three tasks must be completed before performing the data import? (Choose three.)
You have completed the data import process with no errors. You created process, risks, controls, and one perspective. Controls were related to perspectives. You have provided the customer with the Control Manager security role. When the customer logs in to Financials Risk Compliance (FRC), the customer cannot see any controls.
Which step was missed during the import process?
You are helping your client identify and define their controls. You have determined that your client requires two perspectives: Business Units and Regulatory Standards.
The controls are going to be secured by the business unit, and you want to ensure that when the client defines new controls, it is mandatory to assign a Business Units perspective to the control. You are going to set the “Required†field to “yes†for the Control-Business Units association.
Where do you do this in the product?
Your customer needs to conduct monthly Operational Effectiveness assessments for controls across two organizations (North America and EMEA). Your customer requires that assessment results for North America be accessible only to users in North America and likewise for EMEA. Additionally, the Chief Risk Officer reviews the assessment results by Business Process every week.
How should you design perspectives to achieve this?
Which three steps can be performed by using the Configure Module Objects pages? (Choose three.)
You want to identify Controls with the most Incidents, with the condition that the identified Controls should have 80% of all Incidents. To do this, you have imported a custom object that contains the number of incidents associated with each control, and have added that object to a transaction model.
Which pattern filter must you now apply?
Which two should you determine to ensure that your client can successfully maintain and administer Perspectives post go-live? (Choose two.)
A Control Manager has changed the status of an issue to “In Remediation†and has submitted it.
What will be the state of the Issue if there is no issue validator, reviewer, or approver configured?
You are remediating access incidents in Advanced Access Controls (AAC), and have just completed the remediation of a segregation of duties conflict for users in Fusion Security by removing the conflicting access from the users.
What status do you set for the incident in AAC?
Your client has configured separate roles for control assessor and control assessment reviewer. The control assessor has submitted his or her assessment. The control assessor realizes later that he or she has forgotten to attach a critical test evidence document to the assessment and needs to attach it now.
How can this be accomplished?
During implementation, you created a Financial Reporting Compliance superuser and assigned this user the following roles:
The superuser logs in to Financial Reporting Compliance but is not able to create new Data Security Policies.
What is wrong?
Which two steps are required to set up two levels of approval for new controls, which are added after the initial import? (Choose two.)
You have imported risks in Financial Reporting Compliance using data migration. Your client is asking if you can add controls for these risks.
Which two statements are true? (Choose two.)
Which two would need to happen in order for Advanced Access Controls (AAC) to automatically assign a status of “Closed†to an access incident? (Choose two.)
You have two segregation of duties requirements:
1) a user can access either the supplier creation pages or the invoice pages, but not both.
2) a user can access either the invoice creation pages or the payment creation pages, but not both.
How must these requirements be met in Advanced Access Controls?
Which three objects can be related to issues when creating an issue on the Manage Issues page? (Choose three.)
You have built a transaction model to identify possible duplicate charges between invoicing and expense credit cards. The model logic already includes two standard filters that identify amounts and suppliers that are the same or similar, as shown:
Which additional date filter will further refine the set of duplicate charges found?