GRC Journal - (Page 77) Governance, risk & Compliance GovernmenTAL AGenCieS PerFormAnCe meASUreS & BenChmArkS reGULATionS & inDUSTry mAnDATeS riSk & ConTroL LiBrArieS inFLUenCe CoUnCiLS BoD & CommiTTee minUTeS GrC rePoSiTory CorPorATe PoLiCieS & ProCeDUreS BeST PrACTiCeS ADviSory ServiCeS (AUDiTorS, ATTorneyS) Figure 2 ConTroL FrAmeWorkS (CoBiT, jSox, ) inTernAL PoLiCieS can ensure that corporate policies and controls function as intended. SAP delivers a comprehensive set of GRC solutions for aligning corporate policies with strategic direction, implementing these policies through embedding controls in business processes, and tracking and reporting on control effectiveness and organizational performance toward goals. With SAP solutions for GRC, an organization can benefit from consistently, effectively and efficiently applying corporate governance. As a result of embedding controls, the organization ensures that all operational activities and transactions are in line with its strategic goals, and that employees and managers are working toward common objectives. GRC Repository SAP solutions for GRC centrally document and store records in the GRC Repository to streamline and manage all types of GRC content, including company strategy, policies and procedures, control frameworks and business process flows. The GRC Repository helps to drive corporate governance because it provides managers with a single location for documentation related to all GRC initiatives and correlates myriad compliance requirements with key controls. This centralized perspective eliminates fragmentation and allows managers to quickly find information that will help them improve efficiencies related to corporate compliance and governance. The GRC Repository also reduces work by enabling managers to implement fewer controls to address multiple compliance requirements – whether compliance with internal company policies or with external control frameworks such as Committee of Sponsoring Organizations (COSO) and Control Objectives for Information and Related Technologies (COBIT). SAP GRC Process Control SAP GRC Process Control includes a library of pre-delivered control monitors that continuously monitor business process controls to identify inefficiencies and non-compliance with company policy across critical business processes. These automated controls help reduce the cost of ongoing monitoring of the control environment without compromising assurance. The controls also allow an organization to rapidly apply hundreds of tests across different departments while reducing the amount of setup and ongoing maintenance required. SAP GRC Process Control can then pinpoint any control violations through a global heat map, making it easy for management to prioritize corrective action. Because SAP GRC Process Control leverages the GRC Repository, the solution helps a company link strategic plans to daily operations, as well as develop scorecards that can track financial and operational performance data. SAP GRC Process Control is powered by the SAP NetWeaver® platform, enabling it to integrate directly with SAP and non-SAP enterprise applications. This integration eliminates false positives that can waste time and resources and enables drilldown on supporting data for faster remediation. www.BTQuarterly.com Business Trends Quarterly 39 http://www.BTQuarterly.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.