Stephanie Morgan
posted this on October 13, 2011 02:46 pm
A recommendation in the RisKey world is the same as a recommendation in the audit and compliance world. Some refer to it as a finding, exception, or control gap. Regardless of what its called, it is something that needs "fixin" as we say in Texas. Basicaly, it's a requirement or suggestion that something needs to change in order to bring risk to an acceptable level.
When you make a "recommendation" within RiskKey the system flags it as an item that requires follow up. From there you can formulate a response, designate a plan of action, create a deadline and assign responsibility.