Title: Centralizing Compliance Documentation
1Centralizing Compliance Documentation
4th Annual Conference for Effective Compliance
Systems In Higher Education Presented by David
Galloway Deena King Brigham Young University
Office of Compliance and Audit March 30, 2006
2Agenda
- BYU Who We Are
- BYU Compliance Environment
- Dimensions of Centralized Documentation
- Demonstration of Documentum Enterprise Content
Management Software - Questions/Answers/Other Solutions
3Brigham Young University
- Private, Church-sponsored
- Founded 1875
- Three independent campuses
- Provo, Utah (30,000)
- Rexburg, Idaho (14,000)
- Laie, Hawaii (2,000)
4Brigham Young University
- 75 students speak language in addition to
English - Students come from all 50 states and more than
120 countries - 1 Stone-cold Sober University in the nation
(Princeton Review)
5Brigham Young University
- 1,600 faculty
- 2,500 administrative staff
- 13,000 part-time student employees
- 25 million in externally funded research grants
6BYU Compliance Environment
- High reliance on student employees
- Limited Resources to Address Compliance Issues
- No medical school
- Level III Biohazard laboratory
- Very Risk-Averse Culture
- Formal compliance function organized July 2005
7BYU Compliance Organization
8(No Transcript)
9Scope Areas/Programs
10BYU Institutional Compliance Universe
International
Environmental Health Safety
Human Resources
Information Security
Student Services
Athletics/NCAA
Intellectual Property
Student Financial Aid
Tax
ADA/Access
Financial Controls
Land Use Planning
Investment Charter
Research Administration
Donor Gift Restrictions
Campus Security
Controlled Substances
11Compliance Universe
Information Security
Compliance Category
FERPA
PCI/CISP
Compliance Class/Program
Gramm-Leach Bliley
HIPPA
12Deliverable Compliance Program
13Program Documentation
Evaluation File
Resources
Overview
Implementation Plan
Audit Plan
Policy Statement
Audit Schedule
Compliance Handbook
Audit Program
Compliance Guide
Purpose/ Scope
Audit Reports
Compliance Training
Procedures
Responsibilities
Audit Follow-up
Self-Audit Checklists
Training Requirements
Summary Evaluation
Monitoring Requirements
Website
Monitoring Reports
Compliance Database
14(No Transcript)
15Enterprise Content Management
Website
- Central Database
- Accessible
- Controlled Access (General and Content Specific)
- Work-flow Capability
- Accommodate Multiple Users
- Populate Website(s) from Approved and Controlled
Content
Compliance Database
16Enterprise Content Management Software
Website
Central Database -Documentation from any
source/format -Centrally managed and
secured -Service to University units
Compliance Database
17Enterprise Content Management Software
Website
Accessible -General University
Community -Facilitate Ownership -Populate
multiple websites
Compliance Database
18Enterprise Content Management Software
Website
Controlled Access (General and Content
Specific) -Users/writers/approvers/executives all
can have access to content appropriate to their
needs
Compliance Database
19Enterprise Content Management Software
Website
Work-flow Capability -Check-in, check-out,
approval routing -E-mail notification -Facilitate
Collaboration -Edit/approval/publish
Compliance Database
20Enterprise Content Management Software
Accommodate Multiple Users -University
community (policy, procedures, general
information) -Department websites -Executive
review -Compliance/Risk Management/Legal
Website
Compliance Database
21Enterprise Content Management Software
Website
Populate Website(s) from Approved and
Controlled Content -Compliance/Risk
Management/Legal -Departments (Chemistry Labs,
Physical Facilities)
Compliance Database
22Enterprise Content Management Software
Website
Other -Version control -Historic
archive -Integration with other University
content (University Policy Manual)
Compliance Database
23Overview
Policy Statement
Statutes/ Requirements
Purpose/ Scope
Compliance Database
Procedures
Responsibilities
Training Requirements
Monitoring Requirements
Website
Monitoring Reports
24(No Transcript)
25(No Transcript)
26(No Transcript)
27(No Transcript)
28(No Transcript)
29Demonstration of Documentum
30Upload a Document
31Log In Screen
32Meta-data
33Meta-data
34Inbox
35Edit A Document
36Web Cabinets
37File Structure Very Similar to Windows Explorer
38Compliance Web Cabinet
39Lockout-Tagout Folder and Contents
40View versus Check-Out
41A document must be checked out before it can be
edited.
42A checked out document is locked.
43Click on the document title and MSWord is
automatically opened.
44An edited document must be checked back in.
45The document now has a new version number.
46Workflow
47Clicking the arrow next to the document name will
automatically start a workflow.
48The change set indicates the document is in the
workflow.
An e-mail is automatically generated and sent to
the next person in workflow notified that a
document is ready for their review.
49Inbox of Next Person in Workflow
50Once editor/approver Accepts a task they can
edit and Submit or edit and Reject. If
submitted, it is either sent to next person or
published.
51Source Gartner (October 2005)
52Centralizing Compliance Documentation
4th Annual Conference for Effective Compliance
Systems In Higher Education Presented by David
Galloway Deena King Brigham Young University
Office of Compliance and Audit March 30, 2006