Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create New Issue form in Regulatory Change Management

Use the Create New Issue form in Compliance Workspace to create an issue or add an existing issue to a regulatory task in Regulatory Change Management (RCM).

Create New Issue form

For a description of the field values, see the following table.

FieldDescription
Issue
NumberNumber of the issue. This field is auto-filled.
NameName of the issue. For example, `Non-compliant control`.
Issue sourceSource from where the issue was created, such as risk event or risk assessment. This field is auto-filled.
Issue typeType of the issue. The options are as follows:- Control design effectiveness failure: The control was poorly designed and cannot effectively prevent or detect the intended risk. - Control operative effectiveness failure: The control was well-designed but failed during execution or wasn't followed correctly. - Control doesn’t meet requirement: The control is in place but doesn't satisfy regulatory, policy, or business requirements. - Control doesn’t exist: There is no control present to address a known risk or requirement. - Non-compliance to a regulation: A law or regulation was not followed, potentially exposing the organization to penalties. - Non-compliance to a policy: An internal policy was not adhered to, which could lead to risks or inefficiencies. - Improvement or suggestion to an existing policy: A recommendation to enhance an existing policy for better clarity, coverage, or effectiveness. - Recommendation for a new policy: A proposal to create a policy to address a gap that currently isn’t covered. - Process optimization or improvement: Opportunities identified to improve efficiency, accuracy, or effectiveness of a business process. - Observation: A general note or finding that may not be an issue now but could warrant attention. - Data breach: Unauthorized access, disclosure, or loss of sensitive or personal data. - Fraud: Intentional deception for personal or organizational gain, such as misappropriation of assets. - Misstatement: Errors or omissions in financial or operational reporting that misrepresent facts. - Training: Gaps or needs identified in knowledge or skills that require attention. - Documentation: Issues related to missing, outdated, or inaccurate documentation. - Risk issue: A broad risk-related concern that may not fall under other specific categories. - Other: Any issue that doesn't fit into the above types but is still worth tracking and resolving.
ClassificationClassification of the issue. The options are as follows:- Audit - Compliance - Risk - Vendor risk
LocationLocation where the issue occurred. For example, United States.
StateLifecycle stage of the issue. The options are as follows:- New - Analyze - Respond - Review - Closed Complete - Closed Incomplete
SubstateSubstate of the issue. This field is auto-filled.
PriorityUrgency of the issue. The options are as follows:- 1-Critical - 2-High - 3-Moderate - 4-Low - 5-Planning
Issue ratingSeverity or risk level of the issue. The options are as follows:- 1-Very High - 2-High - 3-Moderate - 4-Low - 5-Very Low
DescriptionDetailed explanation of the issue. For example, `The "Manage change requests" control does not meet compliance requirements.`
Assignment
Assignment groupGroup to whom the issue is assigned. For example, GRC Business Users.
Assigned toUser to whom the issue is assigned.
Issue manager groupManager group responsible for overseeing the issue. Available options are:- Compliance Managers - IT Risk Managers - Risk Managers
Issue managerManager responsible for overseeing the issue.
WatchlistUsers who must receive notifications about updates to the issue.
Schedule
Due dateDate when the issue is due.
Confirmed dateConfirmation date for the issue. This field is auto-filled.
Planned start datePlanned start date for the issue.
Planned end datePlanned end date for the issue.
DurationDuration for the issue in days, hours, minutes, and seconds.
CreatedDate on which the issue is created. This field is auto-filled.
ClosedDate on which the issue is closed.
Actual start dateActual start date for the issue.
Actual end dateActual end date for the issue.
Actual durationActual duration for the issue in days, hours, minutes, and seconds.
Issue grouping
Parent issueParent issue that is associated with the issue.
Issue group ruleGroup rule for the issue. This field is auto-filled.
Action plan
RecommendationRecommendation for the issue. For example, `Ensure that changes to the entity's controls follow an approved change process.`
Action planAction plan for the issue. For example, `Leverage the approved change management procedures in the RCM.`
Activity
Work notesInternal notes about the issue. These are private and visible only to users with access to the issue record.
Additional commentsAdditional information about the issue that you want to share with your customers. These are visible to external stakeholders and customers.
Settings
Functional domainFunctional domain that the issue belongs to. For example, IT risk and compliance.