Grc ebook final

12
CONFIDENCE powers success. SAP solutions for Governance, Risk, and Compliance

description

GRC eBook

Transcript of Grc ebook final

© 2

013

SAP

AG o

r an

SAP

affilia

te c

ompa

ny. A

ll rig

hts

rese

rved

.

CONFIDENCEpowers success.

SAP solutions for Governance, Risk, and Compliance

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

2

Table of Contents

3) Build trust to achieve business results Introduction

4-5) Clarity comes from insight SAP Risk Management

6-7) Control who accesses your data SAP Access Control

8-9) Accountabilitythrougheffectivepolicyandcontrolmanagement SAP Process Control

10) Protect against fraud SAP Fraud Management

11) SAPsolutionsforGovernance,Risk,andCompliance A portfolio of solutions

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

3

Whatever your business; confidence is key.

Confidence comes from knowing your organization is anticipating and effectively responding to ever-changing risks and compliance requirements. By managing risks effectively and making business processes more transparent and efficient, you’ll assure stakeholders that investments in people, processes, and technology are protected and well managed.

With SAP solutions for governance, risk, and compliance (GRC), you can move forward with confidence. You’ll gain greater clarity into how risks impact business value, protect against unanticipated losses, and discover how risk and controls management drive performance and accountability in your organization.

It’s time to act with greater insight into risk and compliance; it’s time to drive business value.

Find out more >

68%of organizations admit they were caught

off guard by an operational surprise in the

last five years (Source: Beasley, Branson,

and Hancock, July 2012)

66%of executives consider enterprise risk

management somewhat or extremely

important (Source: SAP insider Research)

90%of companies that have integrated

governance, risk, and compliance have

had results that met or exceeded their

expectations (Source: OCEG 2012

Maturity Survey)

50%of companies are using outdated risk

management solutions (Source: SAP

insider Research)

Build trust to achieve business results

SAP SOLUTIONS FOR GOVERNANCE, RISK, AND COMPLIANCE

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

4

Learn MoreRisk Management: The Value Proposition

Watch the video >

It’s one thing to know the risks your organization faces; it’s another to understand their causes and related impacts.

The SAP Risk Management solution will help you formalize the way you plan, identify, analyze, monitor, and respond to risks that drive business value.

By automating risk indicators and controls and reducing redundancy, you can cut the cost of managing risks.

You’ll have the confidence that comes from understanding what drives your business risk and the effectiveness of your risk responses.

The SAP Risk Management Solution will enable you to:

1 Preserve and grow the value of your business through better collaboration and effective communication

2 Manage risk with increased reliability

3 Respond more effectively by drawing on clear insight into relationships between drivers, risk indicators, events, and effects

4 Maximize gains from business opportunities

5 Reduce the impact of losses through early mitigation

Clarity comes from insight

AberdeenReport–Effective GRC Management Strategies for Mitigating Risks and Sustaining Growth in the Tough Economy

Find out more >

SAP RISK MANAGEMENT

SAP Risk Management solution in detail

Find out more >

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

5

South African diversified mining company Exxaro Resources was seeking integrated enterprise and operational risk management to ensure a uniform and effective risk culture in the organization. This desired change in culture included a shift in focus from a “check the box” and compliance-related exercise to real risk mitigation, which would allow the organization to achieve its strategic objectives.

By using SAP Risk Management, Exxaro was able to establish this desired risk culture, highlighting relevant and new topics from the operational level all the way up to the board level. Items previously

Know Your Risks, Respond Better – Nearly two thirds of companies say they’re facing more and more complex risks than five years ago

View the Infographic >

Learn how SAP Risk Management, combined with SAP Process Control, can help you monitor any aspect of your organization to mitigate risk

Watch product demo >

Taking Risk Management to the Next Level at Exxaro Resources

Read the Exxaro Resources Integrated Report for 2012 story >

Watch the interview with Saret van Loggerenberg, Director of Risk and Compliance for Exxaro Resources

Watch the video >

Learn More

Case study Exxaro Resources

SAP RISK MANAGEMENT

overlooked are now discussed, with a focus on what responses are needed to mitigate significant risks. Exxaro now audits differently, with a more refined risk-based approach linking key controls and compliance initiatives as part of the overall response.

Exxaro Resources was seeking integrated enterprise and operational risk management to ensure a uniform and effective risk culture.

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

6

Giving the right access to the right users – in a timely manner – is essential to running your business smoothly.

Granting too much access, however, can be risky and result in compliance violations and fraud.

With the SAP Access Control application, you can automate key processes to detect, remediate, and ultimately prevent access violations.

By automating access governance activities and embedding compliance into daily processes, you can efficiently control access to your systems, manage risk on an exception basis, and focus more on value-adding initiatives.

SAP Access Control will help you:

1 Reduce access risk – as well as levels of internal fraud and loss of revenue due to employee error

2 Cut costs of enterprise-wide access management

3 Enable efficient, cost-effective audits and on-going compliance activities

Control who accesses your data

SAP ACCESS CONTROL

SAP Solution in DetailSAP Solutions for Governance, Risk, and Compliance

SAP Access Control

Minimize Access Risk and Prevent Fraud – With SAP® Access Control

© 2

013

SAP

AG o

r an

SAP

affilia

te c

ompa

ny. A

ll rig

hts

rese

rved

.

Learn MoreSAP Access Control solution in detail

Find out more >

Efficiently control access to your systems, manage risk on an exception basis, and focus more on value-adding initiatives.

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

7

Learn MoreReduce Fraud and Increase Efficiency with Automated Access Controls. Giving employees the right access to the right information is essential to help ensure smooth operations and prevent fraud.

View the infographic >

Who has access to your information? Find out more about the important part this solution can play in your business.

Watch the video >

When Brazil-based cosmetics and personal care products company Natura was faced with a high level of information security risk, it decided to strengthen its governance model for data and access control.

By upgrading to the SAP Access Control solution, the company achieved a remarkable 87% reduction in its level of information security risk. The solution also enabled more complete and compliant reporting, with the time taken to prepare reports for auditing falling by some 60%. And by allowing inactive profiles to be excluded, Natura’s access

control became leaner – with a resulting 30% drop in transaction volume per profile.

Add the lower maintenance costs involved as a result of 50% fewer support calls, and it’s clear to see how SAP has helped Natura to run more productively as well as securely.

Natura BTS Find out more >

Case study Natura

SAP ACCESS CONTROL

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

8

SAP Process Control helps executives focus resources on high-impact processes, regulations, and risks – driving effective controls and ongoing compliance.

Continuous control monitoring and automated testing enable businesses to identify control deficiencies and control-related issues quickly, leading to faster resolution.

Once you’re confident these controls are effective and accountability is assured, you can increase focus on optimizing business performance.

The SAP Process Control solution can help your business to:

1 Increase consistency and confidence in control information across the enterprise through centralization and standardization

2 Improve efficiency and reliability of key business processes

3 Gain continuous insight into the status of compliance and controls for more timely decision making and intervention.

4 Increase accountability through stronger user involvement and collaboration

5 Reduce regulatory compliance and audit costs through automated control testing, workflows, and standardized processes

6 Establish a culture of compliance through clear communication and acceptance of corporate policies

Learn MoreSAP Process Control Solution in Detail

Find out more >

Accountabilitythrougheffectivepolicyandcontrolmanagement

SAP PROCESS CONTROL

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

9

Sharp Electronics is a manufacturing and service company producing state-of-the-art solar system electronics. Formerly, the company had a decentralized control framework comprising ten business units across North and South America – each with its own processes for identifying risks and controls to mitigate them.

Having introduced SAP’s Process Control solution, all the company’s controls are now centralized. This has enabled Sharp to streamline its operations by reducing their number from 350 to 230. By automating these to tie

in with business objectives, control owners can focus on resolving issues rather than merely identifying them – and the business as a whole can focus on delivering innovation rather than just managing processes.

Watch the video >

Case study Sharp Electronics

SAP PROCESS CONTROL

Learn MoreExperience SAP Process Control in Action. See how SAP Process Control can help you align compliance and control activities to key risks, regulations, and business processes.

Watch the product demo >

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

10

Detect fraud earlier with more effective protection.

The SAP Fraud Management solution safeguards against loss from fraud. It offers greater accuracy, reduces false positives, and lowers investigation costs.

In addition, the solution’s advanced analytics help you uncover changing trends and fraud patterns for better on-going prevention.

The SAP Fraud Management solution enables your business to:

1 Uncover suspicious transactions and relationships in large amounts of data to detect fraud earlier

2 Reduce false positives and increase investigation with powerful simulation features

3 Quickly adapt to evolving fraud patterns and enhance prevention with predictive analytics

4 Reduce the risk of fraud with advanced analytic capabilities and greater visibility.

Learn More Discover SAP Fraud Management powered by the SAP HANA platform. An application for detecting, investigating, and deterring fraud.

Watch the video >

SAP Fraud Management Solution Brief

Find out more >

Protect against fraud

SAP FRAUD MANAGEMENT

Uncover changing trends and fraud patterns for better on-going prevention.

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

11

By automating your access governance activities and embedding compliance into daily processes, SAP Access Control efficiently controls access to your systems, manages risks on an exception basis, and focuses more on value-adding initiatives.

With SAP Process Control, you can focus resources on high-impact processes, regulations, and risks. Gain confidence and ensure accountability with continuous insight into the effectiveness of policies and controls.

By streamlining risk response decisions and reducing unnecessary duplication, SAP Risk Management will help you optimize resources, see value-adding opportunities, and protect existing business value.

Learn More Solution in Detail Manage Enterprise Risk and Compliance

Find out more >

Brewing Up Process Change – Grupo Modelo Manages Risk with SAP’s Latest Solutions for GRC.

Find out more >

Improving Internal Controls and Reducing Access Risk Southern California Edison and American Water share their success @ Sapphire 2013.

Southern California Edison >

American Water >

SAP solutions for Governance, Risk,andCompliance

SAP SOLUTIONS FOR GOVERNANCE, RISK, AND COMPLIANCE

The SAP Fraud Management solution offers earlier detection and more effective protection against loss from fraud – with greater accuracy that reduces false positives and lowers investigation costs.

Managing risks and compliance across each of these areas with a common technological platform allows you to:

• Employ a unified approach

• Improve workflow and collaboration

• Reduce redundant controls and responses

• Use native integration

• Provide users with an intuitive and familiar experience.

More information If you’d like to know more about SAP’s solutions for governance, risk, and compliance – and see how the portfolio can bring confidence into your business – please call your SAP representative or visit SAP.COM/GRC

Focus resources on high-impact processes, regulations, and risks.

SAP solutions for Governance, Risk, and Compliance

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

12

Contact Us

Thank you for your interest in SAP. Let us know how we can help improve your business practices and processes with SAP solutions and services.

Visit www.sap.com

© 2013 SAP AG or an SAP affiliate company. All rights reserved.

No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice.

Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. National product specifications may vary.

These materials are provided by SAP AG and its affiliated companies (“SAP Group”) for informational purposes only, without representation or warranty of any kind, and SAP Group shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP Group products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty.

SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and other countries.

Please see http://www.sap.com/corporate-en/legal/copyright/index.epx#trademark for additional trademark information and notices.