Triggering an asset review request

You may want, or need, to periodically review your approved data privacy-related assets. As shown in the following table, there are three means by which to trigger a review.

Note When a review request is triggered, a Review Request asset is created; however, there is no obligation on the part of the Business Steward or Owner to carry out a change to the asset. It is simply a request to review the asset.

Trigger types Description Trigger mechanism
Manual

A trigger that is manually actioned by a user if, for example, the user wants to request a review of a Business Process asset considered to be incomplete or inaccurate.

Any user can manually request a review of an approved asset.

Any user clicks Submit review request:

  • On an asset page of an approved asset.
  • In an asset view.
    From an asset view, you can trigger a review request for multiple assets, of different asset types, at the same time.
  • In a traceability view.

Time-based

A trigger that is automatically actioned at a specified frequency. This is useful for assessment assets for which you might be required to review periodically to comply with a regulation.

A Time-based Review Rule asset that dictates, for example, that all PIA assets should be reviewed every 12 months.

 

Event-based

A trigger that is automatically actioned by the fact of changes made to specified characteristics of a related asset.

An Event-based Review Rule asset that dictates, for example, that Business Process assets should be reviewed if changes have been made to related Technology assets.

Update an asset directly

In addition to the three scenarios described in the preceding section, the Update asset directly workflow enables Business Stewards to start the asset change management process, without creating Review Request assets, assigning tasks to themselves to approve, or triggering the Review Request Handler workflow.