Organisation model
The organisation model (/hierarchy) is the backbone of your 3rdRisk environment and is applied throughout the platform to structure your data. This article will introduce and explain the concept and then describe the implementation on 3rdRisk.com.
What is the organisation model?
The organisation model is a visual representation of your organisation's setup/hierarchy. Within the platform, we use it to provide the organisational context to your compliance requirements, third parties, contracts, risks and issues in an easy, structured way. It is the backbone of your 3rdRisk environment and is applied throughout the platform to structure your data.
Within the platform, you have the option to completely tailor your organisation model, whereby size, geographical location or industry do not matter. From small startups and Fortune 500 companies to NGOs and governments, organisations of all sizes can create simple or complex organisation models within the 3rdRisk platform. You can create a traditional organisational hierarchy setup using an organisation organogram, but you can even include your organisation's value chains, key services and processes as elements in the organisation model.
We recommend first starting with a straightforward and/or flat organisation model without unnecessary complexity to first understand the platform and your requirements. You may continuously enrich or change the model at a later stage.
Create the organisation model
To start laying out your organisation model, start adding elements to your organisation model:
- Navigate to: Left side menu: Configuration, then Organisation model.
- The organisation model opens. Here, you see all your active organisation elements. Use the Show inactive slider to view both active and inactive elements.
- Click on Add organisation element to add an element to your organisation.
- Fill in the following Element properties on the General tab:
Element | Description |
|---|---|
Type * | Type of the organisational element. Learn more below: Organisation element types |
Name * | Unique identifier of the element, e.g. store name, facility number or process name. |
Status * | Slider to deactivate an organisation element. Elements cannot be fully deleted for data integrity and auditing purposes. Deactivating an organisation element will disable it from active use and remove it from view outside of the editing mode. |
Location within the organisation * | The parent organisation element of this new element. Determines the position of the element within the visual organisation model. |
Responsible colleague * | The responsible colleague for this organisation element, e.g. factory director, department lead, shop manager. |
Description | Field to provide additional internal context, e.g. types of products fabricated at the location, and a specific explanation of the key service. |
- Use the Assessments tab to record who assesses the element and when it is next reviewed. See Assessments.
- Click on Save for the element.
Organisation element types
To accommodate all types and sizes of organisations, you have the option to use a wide variety of organisation elements:
Element | Description |
|---|---|
Brand | Organisations use an identifying name to distinguish their product or service from others. |
Entity | A partnership, organisation, or business has a legal and separately identifiable existence. |
Country | A geographic territory. |
City | A large town. |
Department | A separate division of an organisation. Typical departments are Marketing, Finance, Operations Management, Human resources, IT etc. |
Team | A Group of people organised to work together. |
Factory | Commercial or industrial property such as a building, plant, or structure. |
Office | A place of business used for administrative or professional work. |
Warehouse | Building for storing goods. |
Point of sale | The place where customers make payments for products or services at a specific store. |
Value chain | All the business activities it takes to create a product or service from start to finish (e.g., design, production, distribution, etc.). |
Process | A set of recurrent or periodic activities that interact to produce a result. |
Key service | Most important service that delivers value to customers. |
Asset | The crown jewels/critical assets of your organisation. |
Branch | A branch of a financial entity, recorded for the DORA Register of Information. |
Function | A business function recorded for DORA, with its criticality, recovery objectives and function identifier. |
Edit the organisation model
To edit your existing organisation model structure:
- Navigate to: Left side menu: Configuration - Organisation model
- Edit your organisation model by clicking on an element to edit its properties.
- Use the Status slider in the element properties to deactivate the element.
- Elements cannot be fully deleted for data integrity and auditing purposes. Deactivating an organisation element will disable it from active use and remove it from view outside of the editing mode.
- The principal element in your organisation model is always your primary entity and cannot be changed manually. This is the entity set during the registration. For changes to the principal element, please contact 3rdRiskSupport@diligent.com
- Click on Save for the element.
Assessments
Every organisation element has a second tab, Assessments, next to General. It records which risk assessments apply to the element, who is responsible for them, and when the assessment is next due for review. All of its fields are optional.
Permissions needed: Organisation model — read to view an element, update to change one. Grant it per role via Configuration → Roles.
Field | Description |
|---|---|
Risk assessment template(s) | The risk assessments that apply to this element. You can select more than one. |
Template order | Appears once you have selected two or more templates. Drag the templates into the order you want them shown. |
Assessor | The colleague who carries out the assessment. |
Reviewer | The colleague who reviews it. Required before the element can send any review notification. |
Assessment date | When the assessment was last carried out. |
Next review date | When it is due to be reviewed again. Cannot be earlier than the assessment date. |
Notify reviewer | Tells the reviewer a review is waiting. See Plan and track reviews. |
Assign risk assessment templates
- Open an organisation element and click on the Assessments tab.
- Click on the Risk assessment template(s) field. The templates are grouped: Business Impact Analysis (BIA) holds the three ready-made BIA domains, and Other assessment templates holds the risk domains your own organisation has created.
- Select every template that applies. Each one you add appears as a chip in the field.
- Click on Save.
Learn what the BIA templates contain: Business Impact Analysis (BIA)
Select two or more templates and a Template order block appears underneath. Drag the templates with the handle on the left to set the order they are shown in.
Templates that are assigned for you
New elements of the following types start with all three BIA domains — C - Confidentiality, I - Integrity and A - Availability — already assigned, so they appear on the Risk Profile tab straight away:
- Process
- Key service
- Asset
- Factory
Any other element type starts with no templates assigned, and you can add them by hand. You can also remove the three domains from an element that received them automatically.
Note: this applies to elements created from now on. Elements that already existed are left exactly as they were, so add the templates to those yourself if you want them scored.
An element with nothing filled in
An element that has never been assessed shows an empty Assessments tab. Nothing is required, and the Notify reviewer toggle stays unavailable until a reviewer is selected.
Risk Profile
The organisation model page has two tabs:
- Organisation model — the tree view described above.
- Risk Profile — a table of every element that has at least one BIA domain assigned, with its scores, its owners and its review planning side by side.
Navigate to: Left menu: Configuration, then Organisation model, then the Risk Profile tab.
Note: an element only appears here once at least one of the three BIA domains is assigned to it. Elements with no BIA domain are not listed, which is why the table is usually much shorter than the tree.
Table
Column | Description |
|---|---|
Name | The element name. Click it to open the element. |
Type | The organisation element type, for example Process or Asset. |
Linked controls | How many active controls are linked to this element. |
Linked third parties | How many active third parties are linked to this element. |
C | The Confidentiality score, as a coloured dot. |
I | The Integrity score, as a coloured dot. |
A | The Availability score, as a coloured dot. |
Assessor | The colleague who carries out the assessment. |
Reviewer | The colleague who reviews it. |
Next review date | How long is left before the review is due, as a coloured bar. |
Actions | The ••• menu, for editing the element. |
Domain score indicators
Each of the C, I and A columns shows one dot, coloured by that domain's average score:
Average score | Indicator |
|---|---|
Not yet scored | Grey |
1.0 – 2.0 | Green |
2.1 – 3.0 | Orange |
3.1 – 4.0 | Red |
4.1 – 5.0 | Dark red |
Note: a dot stays grey until every question in that domain has been answered. A partly answered domain produces no partial score.
Next review date
The Next review date column shows how much time is left, so an overdue review is visible without opening anything:
Time left | Indicator |
|---|---|
More than 30 days | Green bar |
8 – 30 days | Orange bar |
1 – 7 days | Red bar |
Passed | Dark red bar, with the number of days overdue |
No date set | Empty |
Search, filter, and export
- Search: search the table by element name.
- Filters: filter by Element types, and use Show inactive to include deactivated elements.
- Export: download the table, including the columns shown.
- Number of rows per page: change how many elements are listed at once.
Interacting with the table
- Sort: sort on Name, Type or Next review date by clicking the column heading.
- Details: click an element name to open it, or use Edit in the ••• menu.
Plan and track reviews
An assessment is only worth having if somebody looks at it again. Set a Reviewer and a Next review date on the Assessments tab and the platform chases the review for you.
Ask for a review now
- Open the element and click on the Assessments tab.
- Select a Reviewer. The Notify reviewer toggle becomes available.
- Switch Notify reviewer on.
- Click on Save. The reviewer is told straight away that a review is waiting, with a link to the element.
Note: the notification is sent on Save, not when you flick the toggle. Saving an element whose toggle was already on does not send it again.
Automatic reminders
When an element has both a reviewer and a next review date, the reviewer is reminded three times: 30 days before the date, 7 days before, and on the date itself.
- Move the next review date and the reminders simply reschedule around the new date. The reviewer is not told that the date changed.
- Remove the date, or the reviewer, and no further reminders are sent.
- Set a date in the past and no reminders are sent for the days that have already gone by.
Every reminder arrives as an in-app notification and an email. It is also sent to Microsoft Teams or Slack when the reviewer has connected that account.
Known module limitations
- The organisation model creation is currently available on desktops only.
- You cannot add custom organisation element types. Feel welcome to provide suggestions for new elements at 3rdRiskSupport@diligent.com.
- The platform saves the order of the different organisation elements/nodes on the same level within the tree by the creation order.
- The Risk Profile tab lists elements with at least one BIA domain assigned. Elements assessed only with your own risk domains are not shown there.
- The C, I and A columns are fixed to the three BIA domains. Other assessment templates assigned to an element do not get their own column.
- Review reminders go to the reviewer only. The assessor is not reminded.
- There is no review workflow or approval status. The reviewer is notified, and recording the outcome is done by updating the assessment date.
Related articles
What the three BIA templates contain, and how to change their domains, questions and scores: Business Impact Analysis (BIA)
How to create and configure your own risk domains: Risk management