Purpose:

Make sure that the communication to stakeholders is effective and timely and the basis for reporting is established to increase performance, identify areas for improvement, and confirm that IT-related objectives and strategies are in line with the enterprise’s strategy.

Objective:

Ensure that enterprise IT performance and conformance measurement and reporting are transparent, with stakeholders approving the goals and metrics and the necessary remedial actions.

Description:

<?>

Inputs:

  • Actions to Improve Value Delivery
  • Risk Management Issues for the Board
  • Feedback on Allocation and Effectiveness of Resources and Capabilities
  • Refined Scope
  • Risk Analysis and Risk Profile Reports for Stakeholders
  • Assurance Review Report
  • Assurance Review Results

Outputs:

  • Evaluation of Enterprise Reporting Requirements
  • Reporting and Communication Principles
  • Rules for Validating and Approving Mandatory Reports
  • Escalation Guidelines
  • Assessment of Reporting Effectiveness

Controls:

<?>

Task Instructions:

Evaluate Stakeholder Reporting Requirements

    1. Examine and make a judgment on the current and future mandatory reporting requirements relating to the use of IT within the enterprise (regulation, legislation, common law, contractual), including extent and frequency.

    2. Examine and make a judgment on the current and future reporting requirements for other stakeholders relating to the use of IT within the enterprise, including extent and conditions.

    3. Maintain principles for communication with external and internal stakeholders, including communication formats and communication channels, and for stakeholder acceptance and sign-off of reporting.

Direct Stakeholder Communication and Reporting

    1. Direct the establishment of the communication strategy for external and internal stakeholders.
    2. Direct the implementation of mechanisms to ensure that information meets all criteria for mandatory IT reporting requirements for the enterprise.
    3. Establish mechanisms for validation and approval of mandatory reporting.
    4. Establish reporting escalation mechanisms.

Monitor Stakeholder Communication

    1. Periodically assess the effectiveness of the mechanisms for ensuring the accuracy and reliability of mandatory reporting.

    2. Periodically assess the effectiveness of the mechanisms for, and outcomes from, communication with external and internal stakeholders.

    3. Determine whether the requirements of different stakeholders are met.