System records represent applications, databases, or other technological systems and processes that handle data for a specific business purpose — for example, CRM software. They are a core component of TrustArc Data Inventory, capturing what data is processed, who has access, and what controls are in place.
This article explains how to create and configure a system record, including completing the Details, Subjects & Recipients, Data & Controls, Risk & Assessments, and Contacts tabs, as well as using the top navigation features available throughout the record.
To set up a system record, follow these steps:
From the left side of the page, hover over the Data Mapping & Risk Manager icon, and then select Data Inventory.
Click to open the System Records tab.
From the top-right corner of the page, click Add New, and then select System Record.
Complete the Details tab. At minimum, you must enter the system name and owner of the system.
You can use the AI Autofill Search feature to complete the Details tab. For more information, see Completing the Details Tab Using the AI Autofill Search Feature.
The Owned By field represents the company that owns the system — for example, TrustArc owns Nymity Inc. If the owning entity or its parent already has data subjects, you can add them to the system or skip and add them manually later.
After you enter the website URL of the company or organization that owns the system, the logo for that organization is automatically generated in the Upload Logo field.
Click the Subjects & Recipients tab, and then complete the following:
Click the Data & Controls tab, and then complete the following:
Click the Risk & Assessments tab, review the Data Processing Risk, Data Transfer Risk, and AI Risk scores for this system record, and complete the recommended assessments.
Charts at the bottom of this tab show how many assessments are in Open, In Progress, Pending Approval, Failed, and Approved states.
To review the inherent risk score of the system record, go to the Data Processing Risk subtab. Under the Step 1: Review Inherent Risk Score column, click Review Score.
The Review Inherent Risk Score modal appears. Complete the following and then click Save Changes.
After evaluating inherent risk, start an impact assessment to evaluate control effectiveness and calculate residual risk.
To start an assessment:
Under the Step 2: Complete Risk Assessment column, click Start Assessment.
A Start Assessment modal appears.
Select an assessment template, and then click Start Assessment.
Assessment template selection should be based on your company's risk tolerance or policies. Based on the country laws triggered, where applicable:
Risk factors are determined by the data elements, processing purposes, individual types, number of individual records, or data subject volume selected in the record. Multiple selections under a single risk factor count as one, except in the case of processing purposes.
If an assessment has already been created for the system record, the Change Assessment and View Assessment buttons become available.
The system redirects you to the Assessment Manager setup page. From the Edit Assessment page, update the following sections as needed:
For more information, see the Creating an Assessment section of the Assessment Manager User Guide.
To download the report, click Download Risk Report under the Step 3: Review Residual Risk Score & Download Report column. The report downloads as a .pdf file.
To review the data transfer risk score, go to the Data Transfer Risk subtab. Under the Step 1: Review Data Transfer Risk Score column, click Review Score.
The View Countries modal appears. View the data transfer risk score for each country, and then click Done.
The Data Transfer Residual Risk Score is calculated after a System Data Transfer Risk Assessment is completed. This assessment gives you insight into your Data Transfer Risk at both the record and organization levels.
To start a data transfer risk assessment:
Under the Step 2: Complete Risk Assessment column, click Start Assessment.
A Start Assessment modal appears.
Select an assessment template, and then click Start Assessment.
The system redirects you to the Assessment Manager setup page. From the Edit Assessment page, update the following sections as needed:
For more information, see the Creating an Assessment section of the Assessment Manager User Guide.
To download the report, click Download Risk Report under the Step 3: Review Data Transfer Residual Risk Score & Download Report column. The report downloads as a .pdf file.
To review the AI Risk score, go to the AI Risk subtab. Under the Step 1: Review AI Risk Score column, click Review Score.
The Review AI Risk Score modal appears. Complete the following and then click Save Changes.
The AI Risk Score is calculated after a System AI Risk Assessment is completed. This assessment gives you clear insight into your AI Risk at both the record and organization levels.
To start the AI risk assessment:
Under the Step 2: Complete AI Risk Assessment column, click Start Assessment.
A Start Assessment modal appears.
Select an assessment template, and then click Start Assessment.
The system redirects you to the Assessment Manager setup page. From the Edit Assessment page, update the following sections as needed:
For more information, see the Creating an Assessment section of the Assessment Manager User Guide.
To download the report, click Download Risk Report under the Step 3: Review Residual AI Risk Score & Download Report column. The report downloads as a .pdf file.
Click the Contacts tab, and then add the record's external and internal contacts.
Click the Edit or Delete icon to edit or delete an existing contact. Use the Search field to locate a contact not shown on the first page. By default, only 10 records are displayed.