Oracle Risk Management Cloud 2023 Implementation Professional Questions and Answers
Which controls can user A manage for the following Control Manager role Configuration? See details of perspective trees and control-perspective association below.
You are building a transaction model to identify invoices with USD amounts that are greater than the supplier’s average invoice amount. The order of the filters is important.
1. Add an “Average” Function filter grouping by “Supplier ID” where “Invoice Amount” is greater than 0.
2. Add a standard filter where “Invoice Currency” equals “USD.”
3. Add a standard filter where the delivered “Average Value” attribute is less than “Invoice Amount.”
What is the correct order of the filters for this transaction model?
Which three tasks should be completed before starting the Financial Reporting Compliance implementation? (Choose three.)
Your client has three operating units.
What are two ways in which you can exclude an operating unit where there are not enough personnel to allow segregation of duties? (Choose two.)
The internal auditor advised the Control Owner of North America to perform assessment for two P2P controls.
Which three steps can the Control Owner perform to kick-off assessments for only those two controls? (Choose three.)
Your customer has a requirement to define an IT Compliance Manager job role with privileges to manage risks and controls, and the issues related to the risks and controls.
What are the duty roles that must be included in this job role to achieve this requirement?
Your client is configuring their Test pod (which has no data) and has created their initial import template with controls, test plans, perspectives, and perspective-control mappings. They have used custom list of values for Control Frequency.
Which three tasks must be completed before performing the data import? (Choose three.)
During implementation, you created a Financial Reporting Compliance superuser and assigned this user the following roles:
- Enterprise Risk and Control Manager
- IT Security Manager
- Employee
The superuser logs in to Financial Reporting Compliance but is not able to create new Data Security Policies.
What is wrong?
During an assessment, an issue was created. Your job as the Issue Manager is to review the issues and validate them. If it is determined that they are not valid issues, you need to close them. You have found an issue that is not valid and with Status: Open and State: Reported.
Identify the correct step to close this issue.
You want to identify Controls with the most Incidents, with the condition that the identified Controls should have 80% of all Incidents. To do this, you have imported a custom object that contains the number of incidents associated with each control, and have added that object to a transaction model.
Which pattern filter must you now apply?
You are implementing Advanced Financial Controls and you want to identify suspect transactions where the payment amount is less than $20 USD. However, you only want the results returned to be temporary.
What will you build in order to accomplish your objective?
You are working with the customer to gather Risk-Control data for the data import process. The customer has information in multiple formats. Which format should be used for importing the data?
Your customer needs to conduct monthly Operational Effectiveness assessments for controls across two organizations (North America and EMEA). Your customer requires that assessment results for North America be accessible only to users in North America and likewise for EMEA. Additionally, the Chief Risk Officer reviews the assessment results by Business Process every week.
How should you design perspectives to achieve this?
You have created security roles for the Procure-to-Pay (P2P) Control Manager for the EMEA region in your client’s organization. But, there are two problems with his or her security configuration.
Problem 1: This person should not receive notifications to complete control assessments, but currently he or she does.
Problem 2: Also, although he or she has access to controls associated with EMEA, he or she is unable to access controls created for individual regions within EMEA.
You have given him or her the following job role:
- EMEA P2P Control Manager Job Role
Which two actions need to be taken to correct the problems? (Choose two.)
Identify the four statuses and states in which you can edit an issue’s description, assuming you have the necessary privileges to edit the issue. (Choose four.)
You have created a risk definition R100 and have created a new control C100 for this risk. No user has been assigned the Risk or Control reviewer and approver roles. What will be the state of R100 and C100 after submitting?
Which two filters must be combined to identify different suppliers who use the same taxpayer ID? (Choose two.)
The GRC Business owner responsible for reviewing and investigating access incidents related to the “Order to Cash” perspective does not see any worklists for the generated results. You have validated that:
1. Other business owners are able to view their assigned worklists without any problem
2. Incidents have been generated for the controls related to Order to Cash
3. The business owner’s assigned roles contain the correct functional privileges and data access to the correct perspective values
What is the reason the business owner cannot see any worklists for the generated incidents?
Which two activities can be performed using Financial Reporting Compliance? (Choose two.)
How do you populate the Control Method field with a new custom value, such as a third-party application’?
You are designing data for data import. The customer decided that they want to secure controls based on their company organization.
Which three worksheets of the import template are required to accomplish this requirement? (Choose three.)
Select three fields that are required to create an impromptu assessment. (Choose three.)