Configuring the Supplier Risk Engagement Project Template

Objectives

After completing this lesson, you will be able to:
  • Configure the default documents in the Supplier Risk Engagement Project Template.
  • Configure inherent risk ratings.
  • Configure project conditions in the Supplier Risk Engagement Project Template.
  • Configure the team in the Supplier Risk Engagement Project Template.
  • Configure phases and tasks in the Supplier Risk Engagement Project Template.

Supplier Risk Engagement Project Template Default Documents

Business details questionnaire

  • The business details questionnaire is the first step of creating an engagement request and captures engagement details such as the title, description, and applicable commodities, regions, and departments.
    • The engagement’s details drive the inclusion of specific questions in the second part of the request, the inherent risk screening questionnaire.
  • The Supplier Risk Engagement Template includes a default survey document with default content for the business details questionnaire.

Inherent risk screening questionnaire

  • The inherent risk screening questionnaire is the second step of creating an engagement request and includes specific questions based on the business details of the engagement.
    • The answers to its questions determine the risk controls that are required for the engagement.
  • The Supplier Risk Engagement Template includes an empty default survey document for the inherent screening questionnaire.

Business Details Questionnaire Default Configuration

The business details questionnaire includes the following default content and field mappings:

  • A question about the engagement title, mapped to project.Title
  • A question of type Commodity, mapped to matrix.Categories
  • A question of type Region, mapped to matrix.Regions
  • A question of type Department, mapped to matrix.Departments

The title question is recommended because its answer automatically becomes the name of the control-based engagement risk assessment project created from the engagement request.

  • If you do not include a mapped title question, all projects created from the Supplier Risk Engagement Project Template are automatically named﹤name of business details questionnaire survey document﹥by﹤name of requester﹥.

The commodity, region, and department questions and field mappings are required for the correct functioning of the control-based risk assessment project. The answers to those questions determine:

  • Which questions that trigger risk controls show in the inherent risk screening questionnaire
    • The mapping between project attributes and control trigger questions is defined in your site's engagement attribute mappings.
  • The membership of project groups on the project team, if you are using buyer category assignments (the user matrix)
  • Approvers for the request and the overall project, if you are using project-level conditions to create conditional approval flows

Business Details Questionnaire Optional Configuration

You can optionally add any or all of the following questions to the business details questionnaire:

  • A question about the engagement's materiality, with answer type Yes/No, mapped to project.materiality.
    • A yes answer to this question adds a TRUE flag to the Materiality project field.
  • A question about the engagement's criticality, with answer type Yes/No, mapped to project.criticality.
    • A yes answer to this question adds a TRUE flag to the Criticality project field.
  • A question about whether or not the engagement requires outsourcing, with answer type Yes/No, mapped to project.outsouring.
    • A yes answer to this question adds a TRUE flag to the Outsourcing project field.

You can use the materiality, criticality, and outsourcing project fields to:

  • Show or hide questions that trigger risk controls in the inherent risk screening questionnaire in addition to those added by the commodity, region, and department.
  • Create conditional approval and review flows for the request and the overall project.

Note

You can optionally add other questions to the business details questionnaire for informational purposes. All of the questions and answers in this questionnaire show on the engagement page after the requester has submitted the request. However, only the mapped questions described in this topic affect the overall behavior and workflow of the associated project.

How To Configure the Business Details Questionnaire

This video will explain how to set up the business details questionnaire in the Supplier Risk Engagement Template.

Supplier Field Mapping in the Inherent Risk Screening Questionnaire

The Supplier field mapping field is highlighted on the Edit Question page.

To set up the inherent risk screening questionnaire, you add questions designed to determine whether specific risk controls should be required. Each screening question must specify a unique identifier in the Supplier field mapping field using the format question.﹤question ID﹥.

  • The question.﹤question ID﹥ mapping format is only supported for questions in the inherent risk screening questionnaire.

The question ID you specify is used to:

  • Hide the question by default and show it only when the answers to the commodity, region, and department questions in the business details questionnaire map to the question ID in the engagement attribute mapping master data.
  • Trigger the controls mapped to the question ID in the engagement control mapping master data.

Inherent Risk Screening Questionnaire Configuration

You can add questions to the empty inherent risk screening questionnaire in two different ways:

Commodity, region, and department screening questions
  • Add all possible related questions to the survey document without applying any visibility conditions.
  • Engagement attribute mapping data in your site maps between specific commodities, regions, and departments and the IDs for these questions that you specify in the Supplier field mapping field.
  • There is no need to apply visibility conditions because questions with IDs that are mapped but that do not match the commodities, regions, and departments of the current engagement request are always hidden.
Criticality, materiality, and outsourcing screening questions
  • Create project conditions with a field match to criticality, materiality, and outsourcing project fields.
  • Add all possible related questions to the survey document and apply those conditions as visibility conditions.

Note

You can optionally add other questions to the inherent risk screening questionnaire for informational purposes. All of the questions and answers in this questionnaire show on the engagement page after the requester has submitted the request.

How To Configure the Inherent Risk Screening Questionnaire

This video will explain how to set up the inherent risk screening questionnaire in the Supplier Risk Engagement Template.

Inherent Risk Ratings Configuration

The Inherent risk field is highlighted on the Supplier management software deployment page.

Answers to the inherent risk screening questionnaire can generate a numerical inherent risk score, which you can show as a rating on the engagement page and use to create project-level conditions for conditional approval flows and other conditional content.

Inherent risk ratings based on the score of the inherent risk screening questionnaire involves the following components:

  • Scoring the inherent risk screening questionnaire
  • Defining risk ratings

Inherent Risk Screening Questionnaire Scoring

Set up the scoring so that riskier answers result in a higher score and less risky answers result in a lower score.

You can use either point-based or percentage-based scoring to calculate request and assessment questionnaire scores.

  • Point-based scoring is a more straightforward and easy-to-configure method, awarding each answer several points and adding all awarded points together to calculate the total score; however, approvers and other stakeholders must know how a given point total translates into risk levels.
  • Percentage-based scoring is more complicated to configure because it awards each answer several points, then uses the question's importance and its section's weight to calculate the total score; however, it is easier for approvers and other stakeholders to interpret percentage scores intuitively.

You can choose a scoring method for each individual survey document in the supplier engagement risk assessment project template, allowing you to select the method that best meets the requirements for individual questionnaires.

Inherent Risk Screening Questionnaire Pre-Grading

The pre-grade you assign to a specific answer to a question determines the amount that the answer contributes to the total score of the questionnaire relative to other answers to the same question.

When you pre-grade a question, you assign a grade to each possible answer to the question. You can only pre-grade questions that have defined or quantifiable answers.

  • In percentage-based scoring, pre-grades are always percentage values between 0 and 100, with 0 being the lowest and 100 being the highest . They specify the percentage of the question's available scoring points each answer earns. That question-level scoring point calculation rolls up into the calculation of both section-level and overall questionnaire scores based on the question's importance and its section's weight.
  • In point-based scoring, pre-grades are always pointed values, that add up to section-level and overall questionnaire scores. Point-based scoring is available in the engagement request inherent risk screening questionnaire in control-bases engagement risk assessment projects in sites that include SAP Ariba Supplier Risk. It is not available in sourcing events or modular supplier management questionnaires.

You can only pre-grade questions with defined or quantifiable answers, including multiple-choice and Yes/No questions.

  • You cannot pre-grade a question of type Text (single line limited) with no defined acceptable answers because a respondent can answer with any possible text, and there is no way to quantify and grade such an answer. However, if you set the Acceptable Values option to List of Choices for the question so that the respondent must choose from a set of predefined answers, you can pre-grade each answer.

Risk Ratings Definition

A self-service configuration parameter defines the risk ratings (such as "High" and "Low") and the ranges of numerical scores for each rating in your site.

  • If you use point-based scoring, the parameter is

    Application.SR.Engagement.RiskPointBasedScoreRanges

    .
  • If you use percentage-based scoring, the parameter is

    Application.SR.Engagement.RiskScoreRanges

    .

The parameter defines ranges from 0 through 100 (for percentage-based scoring) or 0 or greater up to a maximum of 1000 (for point-based scoring) with no gaps between ranges.

  • The format is "rating name:low value:high value." For example, Low:0:60,Medium:60:90,High:90:1000.

Inherent Risk Ratings and Commodity Risk Classifications

Control-based engagement risk assessment projects can also have an inherent risk rating based on the commodities the requester selects in the business details questionnaire.

Suppose you have defined commodity risk classifications in your site. In that case, the commodity-based rating shows in the Inherent Risk (Commodity) field in the Engagement Summary, and its corresponding numerical value is stored in the Inherent Risk Score (Commodity) project field.

Although you can set up both types of inherent risk ratings for your control-based engagement risk assessment projects, it is possible for the same project to show different and even conflicting ratings in the Inherent Risk and Inherent Risk (Commodity) fields.

  • SAP Ariba recommends that you choose only one method of rating the inherent risk for engagements in order to provide clearer guidance to engagement approvers and other stakeholders.

How To Configure Inherent Risk Ratings

This video will explain how to set up inherent risk ratings based on scoring in the inherent risk screening questionnaire.

Project-Level Conditions

Control-based engagement risk assessment projects include specialized project-level fields with corresponding project field mappings. These fields allow you to create:

  • Conditional approval flows based on mapped questions in the business details questionnaire
  • Visibility conditions on criticality, materiality, and outsourcing screening questions in the inherent risk screening questionnaire

Apply Project Conditions to Inherent Risk Screening Questions

In this simulation you will create a project condition and apply the condition to an inherent risk screening question in the Supplier Risk Engagement Project Template.

The Supplier Risk Engagement Project Template Team

You can add members to project template teams in the following two ways:

  • Manually add individual users or user groups to project groups
  • Dynamically add individuals or user groups to project groups based on buyer category assignments

Buyer Category Assignments

The Buyer Category Assignments are displayed.

You can dynamically add users to project groups in the Supplier Risk Engagement Project Template by using buyer category assignments. Buyer category assignments are created by a combination of the following two components:

  • User matrix data, which assigns either individual users or system groups to project groups for specific commodities, regions, and departments
  • Template project groups, when the Use commodity and region assignments setting is enabled

By default, assignments are based on a combination of commodity and region. If the department dimension feature is enabled in your site, buyer category assignments are based on a combination of commodity, region, and department.

An advantage of buyer category assignments is that when a user is assigned to a combination of commodity, region, and department, they are also assigned to all of the values below it in the hierarchy. Therefore, you do not have to explicitly assign users to every commodity, region, and department in your site.

User Matrix Data

The User Matrix data is displayed.

You define buyer category assignments in the UserMatrix.csv file.

  • SM Ops Administrators import the file in SM Administration.

You can assign individual users or global user groups to project groups.

  • If you assign users, when a user leaves the company or changes roles, you must edit and re-import the User Matrix.
  • If you assign user groups, when you subsequently edit who is part of the user group, you do not have to edit the User Matrix.

You can assign a user to multiple commodities, regions, or departments in separate rows.

Assignments can be deactivated.

Using Buyer Category Assignments

The Use commodity and region assignments option is highlighted on the Project Group Details page.

You must configure project groups in the Supplier Risk Engagement Project Template to use buyer category assignments. To do so, complete the following steps:

  1. Open the template for editing.
  2. On the Team tab, choose ActionsTeam MembersEdit.
  3. Edit an existing project group or add a new project group.
  4. For Use commodity and region assignments, choose Yes.

Edit the Supplier Risk Engagement Project Template Team

In this simulation you will edit the team in the Supplier Risk Engagement Project Template.

Supplier Risk Engagement Project Template Phases and Tasks

The control-based engagement risk assessment workflow is defined by a specific pattern of phases and tasks on the Tasks tab of the project template.

The default Supplier Risk Engagement Template project template does not include any tasks or phases.

  • You must add them when setting up the template.

Supplier Risk Engagement Project Template Phases

Control-based engagement risk assessment projects use the following phases with tasks that define the project workflow:

  • Request Approval (required)
  • Trigger Evidence and Control Process (required)
  • Evidence Collection (required)
  • Risk Control Effectiveness Review (required)
  • Project Approval (required)
  • Post Project Approval (optional)
  • Change Request Initial Approval (required for the change request workflow)
  • Change Request Final Approval (required for the change request workflow)
  • Project Archiving (required for the advanced archiving workflow)

Workflow order for phases in control-based engagement risk assessment projects is defined by the Choose where the tasks in this phase should be applied setting. Do not use predecessors for these phases.

Supplier Risk Engagement Project Template Tasks

In most cases, predecessors define workflow order for tasks in control-based engagement risk assessment projects. Workflow order is never related to the display order of the tasks on the Tasks tab in the project template.

Approval tasks in control-based engagement risk assessment projects support the ability for requesters or a member of the Supplier Risk Engagement Governance Analyst to add ad hoc approvers after the request is submitted rather than using an approval flow defined in the template task.

  • To enable this ability, add the approval task but keep its approval flow empty.

Request Approval

You must add an Approval task in this phase and associate it with the business details questionnaire or the inherent risk screening questionnaire.

  • SAP Ariba recommends that you associate the task with the inherent risk screening questionnaire so the approval task details page will show the answers from both questionnaire documents to approvers.

If you do not want to require approval for the request, create one approval task and set it to auto-approve.

(Optional) You can add any other To Do or Approval tasks you want to include in the Request Approval phase.

  • Can be standalone or associated with documents

The first task in this phase must have no predecessor.

  • Predecessors of tasks in this phase must be other tasks in the Request Approval phase.

Trigger Evidence and Control Process

This phase must have exactly one To Do task that is standalone (not associated with a document).

  • This configuration identifies it as the task that triggers sending assessment questionnaires to recipients.
  • To activate correctly, the send assessments To Do task must have the previous task in the project workflow as a predecessor.

(Optional) You can add any other To Do or Approval tasks you want to include in the Trigger Evidence and Control Process phase.

  • To Do tasks must be associated with documents
  • Approval tasks can be standalone or associated with documents

Specify the last task in the Request Approval phase as the predecessor to the first task in this phase.

Evidence Collection

Do not add any tasks to this phase. This phase must always remain empty.

Once the owner of the To Do task for sending assessments completes it and the Trigger Evidence and Control Process phase has ended, the control-based risk assessment project automatically generates a task of the specialized type External in the Evidence Collection phase for each assessment questionnaire that:

  • Was sent by completing the To Do task in the previous phase
  • Is pending expiration or expired and requires an update

Risk Control Effectiveness Review

Do not add any tasks to this phase. This phase must always remain empty.

Once the owner of the To Do task for sending assessments completes it and the Trigger Evidence and Control Process phase has ended, the control-based risk assessment project automatically generates a task of the specialized type External in the Risk Control Effectiveness Review phase for each open control that:

  • Has an automatically generated name that includes the control name (defined in your site's risk control definition master data) and the words Control Review
  • Specifies the control decision maker defined in the DecisionMaker field in your site's risk control definition master data as the task owner

Project Approval

You must add at least one Approval task on the Supplier Risk Engagement Project Template itself.

(Optional) You can add any other To Do or Approval tasks you want to include in the Project Approval phase.

  • Can be standalone, associated with documents, or associated with the Supplier Risk Engagement Project Template

The first Approval task in this phase starts automatically when all of the external tasks for risk control reviews in the previous Risk Control Effectiveness Review phase have completed.

  • Making the last task in the Evidence Collection phase the predecessor of the first task in this phase ensures the correct display of tasks in the process flow on the engagement page.

Post Project Approval

This phase must include at least one task.

  • Can be a standalone To Do task, or a pair of To Do and Approval tasks on a supplemental engagement questionnaire survey document

(Optional) You can add any other To Do or Approval tasks you want to include in the Post Project Approval phase.

  • Can be standalone or associated with documents

The first task in this phase starts automatically after final approval. Do not make the last task in the Project Approval phase a predecessor of the first task in this phase.

Change Request Initial Approval

You must add an Approval task that is associated with the inherent risk screening questionnaire document.

(Optional) You can add any other To Do or Approval tasks you want to include in the Change Request Initial Approval phase.

  • Can be standalone or associated with documents

The Change Request Initial Approval phase has no predecessors because it identifies the start of the change request process.

  • Predecessors of tasks in this phase must be other tasks in the Change Request Initial Approval phase.

Change Request Final Approval

You must add an Approval task on the Supplier Risk Engagement Project Template itself.

(Optional) You can add any other To Do or Approval tasks you want to include in the Change Request Final Approval phase.

  • Can be standalone or associated with documents

The first Approval task in this phase starts automatically when the risk control effectiveness review tasks are completed.

  • Predecessors of tasks in this phase must be other tasks in the Change Request Final Approval phase.

Project Archiving

This phase must include at least one task.

  • Can be a standalone To Do task, or a pair of To Do and Approval tasks on a supplemental engagement questionnaire survey document

(Optional) You can add any other To Do or Approval tasks you want to include in the Project Archiving phase.

  • Can be standalone or associated with documents

This phase starts automatically when a project owner or governance analyst requests the archiving of a completed project on the engagement page.

  • Do not make the last task in the previous phase a predecessor of the first task in this phase.

Predecessors of tasks within this phase must be other tasks in the Project Archiving phase.

Add Supplier Risk Engagement Project Template Phases and Tasks

In these simulations you will add the required phases and tasks in the Supplier Risk Engagement Project Template.

Add Supplier Risk Engagement Project Template Phases

Add Supplier Risk Engagement Project Template Tasks

Log in to track your progress & complete quizzes