The present invention relates to compliance with regulations and policies, and in particular to facilitating the compliance process using mobile devices.
Unless otherwise indicated herein, the approaches described in this section are not prior art to the claims in this application and are not admitted to be prior art by inclusion in this section.
In addition to the challenges posed due to a rapidly changing business environment and increasing competitive pressure, businesses around the world also face stronger regulative pressures. Regulations run the full gamut from employee protections, workplace safety, product quality, environmental protection, financial reporting, and so on. The number of regulations from various governing bodies, such as the government and within industries, continues to rise at a steady pace. Businesses have to invest a huge amount of resources/time to ensure they are in compliance with applicable regulations.
Large business enterprises often have a compliance management department to oversee the compliance process. Not only is the initial establishment of compliance important, but assuring that compliance is being maintained over time is equally important. Accordingly, controls are often defined to monitor compliance to the regulations. Periodic (e.g., annually, bi-annually, etc.) surveys are often used to assess these controls. However, it is often the case that the very people who need access to the central regulation compliance system do not have convenient access to the system, or are often in the places where such access is not always available. Consequently, responses to surveys and other questionnaires relating to the compliance process may not be available, thus making the compliance process incomplete and difficult to perform.
These and other issues are addressed by embodiments of the present invention, individually and collectively.
In embodiments, a mobile device may be configured to perform compliance processing including receiving a survey from a compliance management organization. A survey processing session is then conducted, including displaying a survey question from the survey on a display of the mobile device. An input graphic is displayed, along with first and second graphics. A response input from the user is sent to the compliance management organization. If the first graphic is selected, then auxiliary data (e.g., help information) related to the survey question may be displayed. If the second graphic is selected, then communication with an individual at the compliance management organization may be established.
In embodiments, the user may type in their response to a survey question, or the user may speak their response. The response may be sent to the compliance management organization as text or as a voice file. In some embodiments, a spoken response may be transcribed to text prior to sending to the compliance management organization.
In some embodiments, communication between the user and an individual at the compliance management organization may be with email or by texting. In other embodiments, the communication may be by phone or other interactive communication channel. Contact information for establishing communication with an individual at the compliance management organization may be included with the survey data sent from the compliance management organization. The auxiliary information may be included with the survey data sent from the compliance management organization.
Most employees and business users in an enterprise have access to mobile devices, whether a smart phone, a computer tablet, and so on. The use of mobile device to access compliance surveys and complete them can greatly expand the scope of survey recipients to many business users who may not always have access to a central regulation compliance system. Embodiments in accordance with the principles of the present invention can improve the quality of the survey response process and the effectiveness of the survey. It can also reduce the time needed to complete the survey.
The following detailed description and accompanying drawings provide a better understanding of the nature and advantages of the present invention.
In the following description, for purposes of explanation, numerous examples and specific details are set forth in order to provide a thorough understanding of the present invention. It will be evident, however, to one skilled in the art that the present invention as defined by the claims may include some or all of the features in these examples alone or in combination with other features described below, and may further include modifications and equivalents of the features and concepts described herein.
Referring to
The compliance management organization 102 may manage aspects of the compliance process. The compliance management organization 102 may be affiliated with the business enterprise in any of a number of ways. In a large business enterprise, for example, the compliance management organization 102 may be an entire department within the enterprise. In a smaller enterprise, compliance management may be handled by an existing department. For example, the human resources department may double up it duties to include compliance management. Very small businesses may outsource their compliance management responsibilities, and so on.
Tasks of the compliance management organization 102 may include identifying applicable regulations and policies, identifying, and enacting processes for complying with the regulations and policies. Controls are usually defined to assess compliance with the regulations and policies. The task of control assessment typically includes monitoring the state of compliance and assessing whether there are potential or actual deviations from compliance that need to be addressed. The loop in the compliance management process is closed by taking subsequent action to address those deviations and thus maintain the enterprise's compliance with applicable regulations and policies.
The compliance management organization 102 may include some software component (e.g., a governance, risk, compliance (GRC) application) 102a to facilitate the compliance management process. A communication server 102b allows the compliance management organization 102 to communicate with the users 104 in order to manage compliance across the enterprise. Typically, surveys 110 comprising one or more survey questions are distributed to the users 104 for completion by the users.
Referring to a flow chart shown in
The surveys 110 may be sent to users 104 at their desktop or laptop computers 106a, step 206. A survey 110 may be sent via email, for example, where a communication client 112 in the desktop or laptop computer 106a is an email client. In embodiments, the survey 110 may be attached in an email as an Adobe® interactive form 114 that can be filled out by the user. The survey 110 may be a text document or a formatted text document (e.g., Microsoft® Word® document) that can be opened and edited by the user 104. The survey 110 may be embedded in the email as an XML attachment, and so on.
In accordance with principles of the present invention, the users' mobile devices 106b, 106c may receive notification of a survey, in a step 208. In embodiments, the communication server 102b may be an email server, and communication clients 116 in the mobile devices 106b, 106c may be email clients, where the notification is notification of the receipt of an email from the compliance management organization 102. The survey 110 may be an attachment in an email sent from the compliance management organization 102 to the mobile device 106b. The attachment may be in any data format that is suitable for the receiving mobile device 106b, and may vary depending on the particular capabilities of the mobile device. For example, the attachment may be an XML file embedded in the email which can be opened in the survey application 108.
In embodiments, the compliance management organization 102 may employ a web service interface to handle interactions with a mobile device. The compliance management organization 102 may provide web services using Simple Object Access Protocol (SOAP), Web Services Description Language (WSDL), and the like. For example, the REpresentational State Transfer (REST) architecture is an increasingly common architecture for provisioning web services. Referring to
Continuing with
Returning to step 208, in accordance with principles of the present invention, the mobile device 106c may include a survey application 108 (
In a step 216, the user 104 may invoke the survey application 108 on their mobile device 106c. In some embodiments, the notification may include a link to the survey application 108 that invokes the application when the user 104 “taps” on the link. In other embodiments, the user 104 may directly access the survey application; e.g., by tapping on the application's icon displayed on the mobile device 106c. The process flow then proceeds as discussed above with step 210.
Referring to
In other embodiments, such as illustrated in
The text message 328 may also include a link 334 to invoke the survey application 108. In some embodiments, the link 334 may be omitted. The user may simply exit the email message 326 or text message 328, navigate to an icon in the mobile device 106c that represents the survey application 108, and invoke the survey application directly. Processing in the survey application 108 will now be discussed.
A flow chart shown in
In a step 402, the survey application 108 receives from the compliance management organization 102 data that comprise the survey questions. The survey application 108 communicates with the compliance management organization 102 to download the survey questions of the survey 110 into the mobile device 106c. The entire survey may be downloaded, or portions of the survey may be downloaded one portion at a time and processed. For example, if the survey is large, it may be desirable to download a portion of the survey, process it, and the repeat the process with the next portion. For example, referring to the particular embodiment in
In a step 404, a navigation screen may be displayed that allows the user to select from among the survey questions that comprise the survey 110. For example,
In a step 406, when the user selects a survey question (e.g., by tapping one of the icons 502a), then a survey processing session may be initiated to process the selected survey question. A session screen may be displayed to support the survey processing session. Referring again to
Various display elements may be displayed (step 410). In some embodiments, the survey application may support multiple input modes. Accordingly, the session screen 504 may include a text input icon 504a and voice input icon 504b. Mobile device users may not have convenient access to individuals in the compliance management organizations. Therefore, in accordance with principles of the present invention, the survey application 108 may provide extensive support for the mobile device user. The session screen 504 may include a HELP button 504c and a CALL button 504d. These aspects of the present invention will be discussed in more detail below. A DONE button 504e may be provided to signal the survey application 108 that the user has responded to the survey question. An EXIT button 504f may be provided to allow the user to leave the session screen 504 without saving their response.
In a step 412, the survey application 108 receives input from the user. If the user has indicated (decision step 414) that they are done with the session screen (e.g., by having selected the DONE button 504e or the EXIT button 5040, then processing proceeds to step 404. Otherwise, the user input is processed in a step 416, which will be discussed in more detail in connection with
Referring now to
Processing of the user's input in step 416 in accordance with aspects of the present invention will now be discussed in connection with a flow chart shown in
In a step 432, if it is determined that the user selected the VOICE button 504b, then in a step 452, a voice recorder screen may be displayed. Referring to
In a step 433, if it is determined that the user selected the HELP button 504c, then in a step 462, a help screen may be displayed along with auxiliary information.
In some embodiments, the help screen 606 provides context specific information. For example, the auxiliary information that is displayed may include information specific to the survey question being answered by the user. The auxiliary information may include any information relating to the survey question. For example, help information such as a definition of terms may be provided. Other help information such as an explanation of the survey question may be provided, and so on. The auxiliary information may identify sources of information about the subject matter of the survey, world wide web (WWW) links to web sites, and so on. In general, the auxiliary information may be any information that may assist the user in responding to the survey question. Referring back to
Returning to
Referring back to
Returning to
In a step 436, if it is determined that the user selected the EXIT button 504f, then the user's response may be saved in a memory of the mobile device 106c, but not sent to the compliance management organization 102. Saving the response, but sending it allows the user to review and revise their response before sending. Alternatively, the response may be deleted if the user taps the EXIT button 504f.
Referring to
In embodiments, the memory component 702 includes various software stored in a non-volatile (non-transitory) part of the memory component, including for example the survey application 108. The survey application 108, when executed by the processor 701 results in the mobile device being a special purpose computer configured to perform the steps in accordance with the principles of the present invention and embodiments disclosed herein.
The above description illustrates various embodiments of the present invention along with examples of how aspects of the present invention may be implemented. The above examples and embodiments should not be deemed to be the only embodiments, and are presented to illustrate the flexibility and advantages of the present invention as defined by the following claims. Based on the above disclosure and the following claims, other arrangements, embodiments, implementations and equivalents will be evident to those skilled in the art and may be employed without departing from the spirit and scope of the invention as defined by the claims.