Triggering an asset review request
You may want, or need, to periodically review your approved data privacy-related assets. As shown in the following table, there are three means by which to trigger a review.
Note When a review request is triggered, a Review Request asset is created; however, there is no obligation on the part of the Business Steward or Owner to carry out a change to the asset. It is simply a request to review the asset.
| Trigger types | Description | Trigger mechanism |
|---|---|---|
| Manual |
A trigger that is manually actioned by a user if, for example, the user wants to request a review of a Business Process asset considered to be incomplete or inaccurate. Any user can manually request a review of an approved asset. |
Any user clicks Submit review request:
|
| Time-based |
A trigger that is automatically actioned at a specified frequency. This is useful for assessment assets for which you might be required to review periodically to comply with a regulation. |
A Time-based Review Rule asset that dictates, for example, that all PIA assets should be reviewed every 12 months.
|
| Event-based |
A trigger that is automatically actioned by the fact of changes made to specified characteristics of a related asset. |
An Event-based Review Rule asset that dictates, for example, that Business Process assets should be reviewed if changes have been made to related Technology assets. |
Update an asset directly
In addition to the three scenarios described in the preceding section, the Update asset directly workflow enables Business Stewards to start the asset change management process, without creating Review Request assets, assigning tasks to themselves to approve, or triggering the Review Request Handler workflow.