Enforcing a review workflow is optional, and recommended as your organisation matures. The demand workflow is configured in Settings, under the Risk Demand tab.
1. Review process
Choose how demands are reviewed in your workspace:
- Direct: no review step. Anyone with Risk Management access can see and manage every demand.
- Analyst review: an Analyst triages each demand (accept, request information, reject) and hands the result back to the requester. Requesters only see the assessment once it is sent to them.
- Assurance review: adds a second reviewer. After the analyst, an Assurance reviewer signs off before the demand can be completed.
Note: Users whose role grants Full access with Edit on Risk Management always see and manage all demands, regardless of the review process selected here.
2. Role assignment
Under Role assignment, pick which workspace role acts as the Analyst role and which acts as the Assurance role. Who actually holds these responsibilities is then managed by assigning members to those roles in Settings, Users. Analyst and Assurance are workflow assignments, not separate workspace roles.
3. Validation modes
Two independent choices control how many approvals are needed:
- Risk response validation: with Single validation, any analyst can approve the requester's risk response and complete the demand. With Multiple validation, every member holding the Analyst role must approve before the demand can be completed.
- Assurance validation: the same choice at the assurance gate; with Multiple validation, every member holding the Assurance role must approve at that step.
The mode in force when a validation round starts applies for that whole round; changing the setting never rewrites a round already in progress. A workspace owner or Account Manager approval can override a pending multiple round.
4. Notifications and default SLAs
- Demand notifications: members holding the Analyst role are always alerted when a demand is submitted for review (drafts stay silent until then). Add extra recipients here; they are also notified when a requester updates a demand that was sent back for more information.
- Default SLA by priority: set a default turnaround (in days, weeks or months) per priority level. New demands of that priority pre-fill their due date accordingly.
Tip: The workspace's approval workflows, including the risk ones, are also visible in Settings, Workflows, grouped under Risk management.