SAP: Speeding GRC Control Testing by 90% with SAP Solutions for GRC

Similar documents
MDG100 Master Data Governance

HA100 SAP HANA Introduction

HA240 SAP HANA 2.0 SPS02

HA240 Authorization, Security and Scenarios

HA100 SAP HANA Introduction

HA215 SAP HANA Monitoring and Performance Analysis

HA215 SAP HANA Monitoring and Performance Analysis

S4H01. Introduction to SAP S/4HANA COURSE OUTLINE. Course Version: 04 Course Duration: 2 Day(s)

HA100 SAP HANA Introduction

HA150 SQL Basics for SAP HANA

SLT100. Real Time Replication with SAP LT Replication Server COURSE OUTLINE. Course Version: 13 Course Duration: 3 Day(s)

HA301. SAP HANA 2.0 SPS03 - Advanced Modeling COURSE OUTLINE. Course Version: 15 Course Duration:

Device Operation Process Diagrams. SAP Mobile Secure rapid-deployment solution September 2014

ADM505. Oracle Database Administration COURSE OUTLINE. Course Version: 15 Course Duration: 3 Day(s)

BC414. Programming Database Updates COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)

CLD100. Cloud for SAP COURSE OUTLINE. Course Version: 16 Course Duration: 2 Day(s)

HA150. SAP HANA 2.0 SPS02 - SQL and SQLScript for SAP HANA COURSE OUTLINE. Course Version: 14 Course Duration: 3 Day(s)

C4C30. SAP Cloud Applications Studio COURSE OUTLINE. Course Version: 21 Course Duration: 4 Day(s)

Device Application Onboarding Process Diagrams. SAP Mobile Secure: SAP Afaria 7 SP5 September 2014

HA355. SAP HANA Smart Data Integration COURSE OUTLINE. Course Version: 12 Course Duration: 3 Day(s)

SAP Hybris Billing, Pricing Simulation Extended Functions Release 2.0, SP03

HA300 SAP HANA Modeling

BC404. ABAP Programming in Eclipse COURSE OUTLINE. Course Version: 16 Course Duration: 3 Day(s)

BC403 Advanced ABAP Debugging

HA100 SAP HANA Introduction

BW305H. Query Design and Analysis with SAP Business Warehouse Powered by SAP HANA COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

UX402 SAP SAPUI5 Development

Complementary Demo Guide

ADM506. Database Administration Oracle II COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)

FAQs Data Cleansing SAP Hybris Cloud for Customer PUBLIC

BOD410 SAP Lumira 2.0 Designer

HA150. SAP HANA 2.0 SPS03 - SQL and SQLScript for SAP HANA COURSE OUTLINE. Course Version: 15 Course Duration:

DS10. Data Services - Platform and Transforms COURSE OUTLINE. Course Version: 15 Course Duration: 3 Day(s)

SAP EarlyWatch Alert. SAP HANA Deployment Best Practices Active Global Support, SAP AG 2015

SAP 3D Visual Enterprise 9.0: Localization of Authoring Content

BW405. BW/4HANA Query Design and Analysis COURSE OUTLINE. Course Version: 14 Course Duration: 5 Day(s)

HA300 SAP HANA Modeling

CA611 Testing with ecatt

S4H410. SAP S/4HANA Embedded Analytics and Modeling with Core Data Services (CDS) Views COURSE OUTLINE. Course Version: 05 Course Duration: 2 Day(s)

HA 450. Application Development for SAP HANA COURSE OUTLINE. Course Version: 12 Course Duration:

SAP SMS 365 SAP Messaging Proxy 365 Product Description August 2016 Version 1.0

BOCRC. SAP Crystal Reports Compact Course COURSE OUTLINE. Course Version: 15 Course Duration: 3 Day(s)

BC405 Programming ABAP Reports

ADM110. Installing and Patching SAP S/4HANA and SAP Business Suite Systems COURSE OUTLINE. Course Version: 17 Course Duration: 4 Day(s)

BW305. SAP Business Warehouse Query Design and Analysis COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

S4D430 Building Views in Core Data Services ABAP (CDS ABAP)

ADM110. Installing and Patching SAP S/4HANA and SAP Business Suite Systems COURSE OUTLINE. Course Version: 18 Course Duration: 4 Day(s)

BIT660 Data Archiving

Software and Delivery Requirements

SAP Analytics Cloud model maintenance Restoring invalid model data caused by hierarchy conflicts

Device Configuration Process Diagrams. SAP Mobile Secure: SAP Afaria 7 SP5 September 2014

Week 2 Unit 3: Creating a JDBC Application. January, 2015

BC470. Form Printing with SAP Smart Forms COURSE OUTLINE. Course Version: 18 Course Duration:

BW310H. Data Warehousing with SAP Business Warehouse powered by SAP HANA COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

FAQs Data Sources SAP Hybris Cloud for Customer PUBLIC

UX400. OpenUI5 Development Foundations COURSE OUTLINE. Course Version: 02 Course Duration: 5 Day(s)

Let s Exploit DITA: How to automate an App Catalog

BW462 SAP BW/4HANA COURSE OUTLINE. Course Version: 16 Course Duration: 5 Day(s)

BC401. ABAP Objects COURSE OUTLINE. Course Version: 18 Course Duration:

Week 2 Unit 1: Introduction and First Steps with EJB. January, 2015

opensap TEXT ANALYTICS WITH SAP HANA PLATFORM WEEK 1

TADM51. SAP NetWeaver AS - DB Operation (Oracle) COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

D75AW. Delta ABAP Workbench SAP NetWeaver 7.0 to SAP NetWeaver 7.51 COURSE OUTLINE. Course Version: 18 Course Duration:

BW362. SAP BW Powered by SAP HANA COURSE OUTLINE. Course Version: 11 Course Duration: 5 Day(s)

COURSE LISTING. Courses Listed. Training for Database & Technology with Modeling in SAP HANA. Einsteiger. Fortgeschrittene.

SAP HANA SPS 09 - What s New? SAP River

FAQs OData Services SAP Hybris Cloud for Customer PUBLIC

System x Server for SAP Business One, version for SAP HANA

UX300 SAP Screen Personas 3.0 Development

DBW4H. Data Warehousing with SAP BW/4HANA - Delta from SAP BW powered by SAP HANA COURSE OUTLINE. Course Version: 13 Course Duration: 2 Day(s)

SAP Business One Integration Framework

ADM535. DB2 LUW Administration for SAP COURSE OUTLINE. Course Version: Course Duration: 3 Day(s)

BOID10. SAP BusinessObjects Information Design Tool COURSE OUTLINE. Course Version: 17 Course Duration: 5 Day(s)

FAQs Data Workbench SAP Hybris Cloud for Customer PUBLIC

BW350H. SAP BW Powered by SAP HANA - Data Acquisition COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

SAP HANA SPS 08 - What s New? SAP HANA Web-based Development Workbench. (Delta from SPS 07 to SPS 08) SAP HANA Product Management May, 2014

HA400 ABAP Programming for SAP HANA

How-to Guide for Exercise Access the Demo Appliance Landscape (Week 1, Unit 6, Part 1)

SAP HANA Operation Expert Summit PLAN - Hardware Landscapes. Addi Brosig, SAP HANA Product Management May 2014

Alert Consumption for Business Process Monitoring on MAI with SAP Solution Manager 7.1 SP12 Setup and features of notifications and incidents

SAP Single Sign-On 2.0 Overview Presentation

SAP Branch Agreement Origination V3.703: Software and Delivery Requirements

SAP Mobile Secure Rapiddeployment. Software Requirements

FAQs Facebook Integration with SAP Hybris Cloud for Customer SAP Hybris Cloud for Customer PUBLIC

COURSE LISTING. Courses Listed. Training for Cloud with SAP Hybris in Sales Cloud (C4C) 25 August 2018 (01:04 BST) Fortgeschrittene.

How to create a What If simulation in SAP Analytics Cloud

SAP 3D Visual Enterprise 9.0: Identifiers in VDS Files

COURSE LISTING. Courses Listed. Training for Database & Technology with Administration in Database Migration. 3 September 2018 (21:31 BST)

Two-Factor Authentication over Mobile: Simplifying Security and Authentication

COURSE LISTING. Courses Listed. Training for Cloud with SAP Ariba in Integration. 20 August 2018 (03:01 BST) Grundlagen.

SAP Cloud Platform Configuration SAP Subscription Billing

opensap: Big Data with SAP HANA Vora Course Week 03 - Exercises

Using SAP SuccessFactors Integration Center for generating exports on Interview Central. SAP SuccessFactors Recruiting Management

Week 1 Unit 1: Introduction to Data Science

User Interface Layouts

SAP HANA tailored data center integration Frequently Asked Questions

COURSE LISTING. Courses Listed. Training for Database & Technology with Modeling in SAP HANA. Last updated on: 30 Nov 2018.

Analyze Big Data Faster and Store It Cheaper

Customer Helpdesk User Manual

COURSE LISTING. Courses Listed. Training for Cloud with SAP Ariba in Buy Side. 27 July 2018 (05:54 BST) Grundlagen. Fortgeschrittene.

Transcription:

2015 SAP SE or an SAP affiliate company. All rights reserved. SAP: Speeding GRC Control Testing by 90% with SAP Solutions for GRC By implementing its solutions for governance, risk, and compliance (GRC), SAP SE has achieved a holistic regulation, business process, risk, and control overview based on a single, accurate, real-time data source. It is the world s largest GRC implementation that SAP is aware of. The project accelerated many key GRC processes and is greatly assisting decision makers.

Company SAP SE Headquarters Walldorf, Germany Industry High tech Products and Services Enterprise software and services Employees 68,800 Revenue 16.8 billion Web Site www.sap.com Implementation Partner SAP Consulting BUSINESS TRANSFORMATION The company s top objectives Standardize, automate, and accelerate all GRC processes Create a single, highly transparent source of GRC information Display thought leadership in enterprise GRC management The resolution Implemented the SAP Process Control and SAP Risk Management applications company-wide Integrated them with the SAP Fraud Management analytic application, the SAP Access Control application, and the SAP Customer Relationship Management (SAP CRM) application Took a phased approach The key benefits Better-informed business decisions and mobile risk reporting Holistic regulation, process, risk, and control overviews based on a single data source Automatic control monitoring of system configuration and data Read more TOP BENEFITS ACHIEVED SAP solutions for GRC serve as a single source of the truth, enabling decision makers at SAP to efficiently and holistically manage risk delivering real value to the business. Miriam Kraus, Senior VP of Governance, Risk, and Compliance, SAP SE 90% Faster control testing on average 3 FTEs Redeployed to higher-value activities 30% Gain in report generation efficiency See more metrics 2 / 6

Modernizing and automating the GRC environment SAP SE is one of the world s largest software companies and a leader in providing enterprise software and services. Among the company s many products is a set of solutions for GRC. These solutions are designed to help enterprises protect their revenues streams, shareholder values, and brand reputations while reducing the cost of GRC compliance initiatives. Until recently SAP addressed its own GRC challenges using several of its applications that are now retired, including one for administration of risk data and another for internal control management. SAP wanted to improve its GRC environment by replacing these applications with current software. The company also wanted better integration with a unified control and master data repository, more automation in control testing and result consolidation, and less duplication of effort and data maintenance costs. We wanted to achieve the benefits of integration and automation throughout our worldwide GRC landscape, as well as accurate risk data produced in real time at a lower cost, says Miriam Kraus, senior VP of governance, risk, and compliance for SAP. To address our immediate issues while building a sustainable architecture for the future, we decided to replace our former GRC system with modern, fully supported software. Our new GRC solution needed to deliver effectiveness, efficiency, and agility to the business in managing the relationships among governance, risk, and compliance based on a single source of information. By removing the system disconnect we had in the past, we knew we stood to significantly reduce the effort entailed in control testing. Miriam Kraus, Senior VP of Governance, Risk, and Compliance, SAP SE 3 / 6

World s largest implementation of GRC solutions from SAP SAP has a policy of using its own applications to run its business whenever possible, but this was far from the only reason why it decided on SAP solutions for GRC as the basis for its GRC modernization effort. We wanted a single, comprehensive, and integrated set of GRC solutions, and no one can match our own software in those respects, explains Kraus. The standard functionality of SAP solutions for GRC is fully utilized to provide transparency and to streamline and enhance GRC processes very important values to us. Furthermore, we wanted to demonstrate the confidence we have in our GRC software and its ability to satisfy the needs of very large enterprises. SAP turned to its own organization not just for software but also for implementation services. No one knows SAP applications like SAP Consulting, Kraus explains succinctly. The implementation was the most ambitious ever undertaken for GRC software from SAP spanning 580 organizations in 100 countries that support over 68,800 users, including 130 senior managers who use mobile devices to make risk-based decisions. Over a period of two years, a team of 12 consultants from SAP implemented the solution, which includes SAP Process Control and SAP Risk Management integrated with SAP Fraud Management, SAP Access Control, and SAP CRM as well as a promise-todeliver project system. This system is supported by complex online and offline survey scenarios, continuous control monitoring, issue management, control testing and scheduling, Committee of Sponsoring Organizations of the Treadway Commission (COSO) questionnaires, and policy management for all 68,800 employees. 4 / 6

An award-winning implementation The implementation concluded within budget and on schedule in two years. Control testing and remediation is now performed through 65 automated controls associated with 100 business rules. The central repository contains 20 regulations and 1,350 risks allocated to 50 risk categories associated with 900 activities in 80 activity categories and more than 120 processes and 350 subprocesses with 2,800 controls. The project was so successful that SAP applied for a prestigious GRC 20/20 Value Award from GRC 20/20 Research LLC. In its award announcement, GRC 20/20 Research confirmed that the implementation has achieved measurable value across the elements of GRC efficiency, effectiveness, and agility. In this context, the announcement states, GRC 20/20 has recognized SAP with a 2014 GRC Value Award in the domain of GRC Architecture and Integration. SAP also won an award from the Open Compliance and Ethics Group in 2012 for the implementation. KEY BENEFITS 90% Faster control testing on average 30% Gain in report generation efficiency 20% Gain in data maintenance efficiency 3 FTEs Redeployed to higher-value activities 100% Accuracy of control testing and remediation 5 / 6

SAP On to SAP HANA The next step in the plan is to incorporate the SAP HANA platform as the foundation for the GRC solution, thereby enhancing controls and improving interaction with SAP Fraud Management. SAP expects that this and other GRC environment improvements will deliver many additional benefits. Testing effort will be cut by 50%, for example, and audit fees will come down 15%. In addition, with workflow-based exception handling within a single source of the truth, manual effort will be reduced by 30%. Already our solutions for GRC allow us to make risk-based decisions at any time and at all levels of the company, concludes Kraus. Compliance is strengthened through automated and continuous management of internal controls well beyond Sarbanes-Oxley 404 requirements. The addition of SAP HANA will only make the environment even better. 34217 (15/01) 6 / 6

No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. Please see http://www.sap.com/corporate-en/legal/copyright/index.epx#trademark for additional trademark information and notices. Some software products marketed by SAP SE and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP SE or its affiliated companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP SE or SAP affiliate company products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation, and SAP SE s or its affiliated companies strategy and possible future developments, products, and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forward-looking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions.