Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Compliance Case form

Use the Create Compliance Case form in the GRC: Compliance Case Management application to report a compliance case.

See the following table for a description of the field values.

FieldDescription
NumberNumber of the case. This field is automatically set to a case number.
NameName of the case. For example, Verdict of a lawsuit leaked.
TypeType of the case. This field is automatically set to Compliance case.
Sub-typeSub-type of the case. For example, Fraud and Embezzlement.
StateWorkflow state of the case. This field is automatically set to New.
PriorityPriority of the case:- 1 - Critical - 2- High - 3 - Moderate - 4 - Low - 5 - Planning
RequesterPerson who reported the case.
Requested on behalf ofName of the person you created the case for.
Primary entityEntity that is affected by the case. This field is automatically set to the entity that is identified in the Impacted areas related list.
Entity ownerUser who is the owner of the entity. This field is automatically set based on the entity that is selected in the Impacted areas related list.
DescriptionBrief description of the case.
Assignment
Assignment groupGroup that is assigned to the case.Note: The assignment group is preconfigured to the case type during the configuration setup.
Watch listUser who must be informed about the case.
Case analystAnalyst who can analyze and work on the case. The case analyst is a part of the assignment group.
Accountable executiveExecutive who is accountable for the case.
Primary origin
LocationLocation where the case occurred. For example, Japan.
Sub-locationSub-location of the case occurrence. For example, the sub location is Tokyo.
Impacted business unitBusiness unit that is affected by the reported cases or events. For example, Finance.
Impacted departmentDepartment that is affected by the case. For example, Customer support.
SourceSource from which the case is reported: - Manual: When the case is created from the compliance workspace, the field displays the source as Manual. - Employee Center: When the case is reported from the Employee Center, the field displays the source as Employee Center.
Source recordSource record of the source object from where the case is created. For example, if the case is reported from risk events, then this field displays the name of the risk event from which the case is reported.
Additional sourceMode of how the case is reported when the case is created manually. This field is available only when Manual is selected from the Source field and the record is saved. The choices are as follows:- Email: When you create the case from the information that you received in an email. - Phone: When you create the case from the information that you received in a phone call.
Schedule
Date of occurrenceDate when the case occurred. For example, the case may have occurred on 18-02-2024.
Date of discoveryDate when the case was discovered. For example, the case may have occurred on 18-02-2024, but was discovered on 12-03-2024.
Case creation dateDate when the case was created. This field is automatically set to the current date and time.
Case closure SLAExpected date of the case closure. This date is automatically calculated based on the case creation date.
Investigation planned startPlanned start date to investigate the case.
Investigation planned endPlanned end date to investigate the case.
Investigation actual startActual start date of the case investigation.
Investigation actual endActual end date of the case investigation.
Remediation planned startPlanned start date to remediate the case.
Remediation planned endPlanned end date of the case remediation.
Remediation actual startActual start date of the case remediation.
Remediation actual endActual end date of the case remediation.
Breach analysis
Breach statusStatus to indicate if a breach has occurred or not:- To be determined: When the breach isn’t determined yet. - Breach detected: When the breach is confirmed. - Future potential: When the breach hasn’t occurred but may occur in the future. - Not a breach: When no breach is detected.
Reporting statusStatus of the case being reported to the regulators. This field is automatically set based on the reporting status of the regulations that are associated with the case. If a case has many regulations and even if one regulation is identified as reportable, then the reporting status of the case is set to reportable. The default value of this field is To be determined.
Breach startDate that the breach started. This field only appears when Breach detected or Future potential is selected from Breach status.
Breach endDate that the breach ended. This field only appears when Breach detected or Future potential is selected from Breach status.
Breach significance identifiedDate when the user identifies that the breach is significant. This field only appears when Breach detected or Future potential is selected from Breach status.
Root cause analysis
Primary causePrimary cause of the case reported. This field is automatically set to the primary cause that is selected in the Cause and consequences related list.
ConsequencesConsequences from the primary cause of the case reported. For example, damage to physical assets.
Overall observationsObservations made regarding the case.
Remediation takenOption to indicate if the remediation measures have been taken to address the case:- Yes - No
Overall preventive measuresPreventive measures taken to re-mediate the case.
Activity
Work notes \(Private\)Notes or information about the case.
Additional comments \(Customer visible\)Additional information about the case that you want to share with the customers.
SaveSave the details of the compliance case.

Parent Topic:Create a compliance case in the Compliance Workspace