The BenchMark platform is built on a scalable database with a secure web interface. Avior sets up a private instance for each customer. When data separation is required, additional instances of the application (including the database, web interface and administrative users) can be used. For example, the database for internal business units may need to be kept separate from the database of vendors. The platform has an API which facilitates the import of data from other sources. For example, the list of vendors can be imported this way. There are screens in the web interface to manually add or edit this data.
BenchMark supports a wide range of applications. The relevant questionnaires, workflow templates and tools, reports and dashboard needed for the application are bundled in Knowledge Modules. These allow our customers to leverage best practices to implement new compliance programs quickly and cost-effectively. By understanding compliance and program status, our customers can maintain a risk register to track status. The dashboards and reports provide the deep analysis of everything from program and project status to balanced scorecards.
A framework is an organized set of controls used to measure compliance against multiple regulations, standards, and best practices in Governance, Risk and Compliance (GRC). Avior's patent-pending approach provides a new automated way to developing and maintaining dynamic compliance mappings, delivered as part of a subscription. The BenchMark Dynamic Complaince Matrix groups the various data elements into Discrete Compliance Objectives (DCO's). These are logical groupings of related compliance requirements, controls, and assessment questions. For example, all requirements from all supported regulations dealing with business continuity are associated with the Business Continuity DCO. DCO's make it easier for compliance managers to find all controls and assessment questions related to their specific compliance mandates, and to select an efficient set of controls and assessment questions. The relationship between questions, controls, and authoritative sources is easily visualized, depicted and analyzed for review.
The system allows customers to add their internal policies and treat them as any other compliance mandate. We enable our customers to add and cross-map their policies as another authoritative source, focus on the regulations or sources that apply to them and fully automate the ongoing management of the framework.
Our unique approach to building and maintaining the framework also allows customers to report on compliance against one, some or all compliance mandates. In addition, this can be done for individual entities (such as department or vendor), groups based on criteria (such as geography or line of business) or the entire population. This allows you to generate a report that answers a key question (for example, do all my business units comply with PCI?) and know that the results are based on an auditable database and workflow. This consolidation reduces "survey fatigue" by optimizing the coorelation of controls to the questions.
BenchMark uses projects to manage the workflow. This allows the customer to define different questionnaires for different responding organizations which aids in ongoing compliance management and tracking. A project may have multiple users/affiliates and multiple questionnaires. This allows the customer to focus a questionnaire on the relevant areas or to define questionnaires as part of a remediation project.
BenchMark supports a Task List for each user. This could be used to show all outstanding tasks associated with a responding organization or all tasks assigned to a given customer administrator.
Benchmark supports complete reviewer functionality to any questionnaire. The review function can be used to validate responses, examine supporting documentation or interpret results. The reviewer can work online and add remarks, adjust the score based on findings or create remediation tasks.
BenchMark uses the concept of tasks to allow customers to manage any outstanding problems such as a late questionnaire or incomplete documentation. This allows the customer to focus on resolving problems rather than doing data entry. The remediation workflow includes automatically generating tasks based on failure to perform actions (such as a missed deadline for a questionnaire), creation of tasks based on a review or audit and assignment of tasks to users. This facilitates a dialog between the requesting and responding organizations.
Questionnaire Development and Associated Workflow
Standard Questionnaires are part of the BenchMark Knowledge Module (all of the content needed for a specific application). The platform provides the ability to build or edit questionnaires as needed through the Assessment Designer application. Conditional (Jump/Skip) Logic allows the questionnaire designer to permit the responder to skip a section if it does not apply. Unlike other survey platforms, our sophisticated scoring rubric enables this flexibility without affecting the scoring of the questionnaire. Scoring is used to evaluate status, identify trends and compare different entities.
Questionnaires allow (or may require) the responder to submit multiple attachments while maintaining an audit trail. This facilitates compliance management for more complex environments. BenchMark has integrated e-mail features to facilitate distribution and tracking. E-mail management features and templates can be customized to create a user-friendly and compliant look and feel. Email notifications are customizable with 15 e-mail templates available standard in the system to assist in creating the correct instructions and constructive interaction with your responding organizations. BenchMark tracks the status of completion of the questionnaire, monitors due dates automatically and maintains a complete audit trail. The workflow automatically provides for overdue reminders, escalations and completion status.
Reporting and Analysis
Standard reports and dashboards are part of the Knowledge Module.
Upon completion of the questionnaire, a risk tolerance scorecard report can be generated at the question, section, subsection, or questionnaire level from the risk weights assigned. Dashboard reports, including heat maps are used generated to visually display the data. All report and dashboards reflect real-time status.
To learn more about how Benchmark meets the needs of specific markets, please follow one of these links:
- BenchMark for Healthcare Plans
- BenchMark for Healthcare Providers
- BenchMark for Life Sciences
- BenchMark for Financial Services