Ensuring compliance with Sarbanes-Oxley (SOX) and other regulation is a heavy burden on any company's internal controlling mechanisms. Putting the right processes in place is just the first step: identifying, verifying and documenting violations is the hard part.
SUIM's CE helps to reduce and mitigate risks effectively. Compliance Enforcer not only checks and alerts for potential authorizations-related risks in real-time, it can also analyze information about actual risks that have occurred, using data recorded by SUIM's Application Tracer (AT) and Emergency Handler (EH).
Efficiency
Flexibility
Simplicity
CE includes several preventive or reactive workflows for risk managers. The risk responsibility is clearly defined and the authorization and user administrator are assisted. Alerts can be configured if risks occur within an emergency access.
The ergonomic customizing workstation for configuring Compliance Enforcer makes creating rules and risks simple and intuitive. Furthermore it is possible to import existing rule or risk sets (e.g. EBS Schreiber, DSAG etc.).
Rules and risks can be customized and combined using all kind of authorizations related entitites:
- SAP authorization objects, SAP roles, SAP profiles, system parameters (RZ10).
- AM/AMSO organizations, SUIM systems, AM/AMSO organization type - organization level.
- AM/AMSO roles, BI authorizations.
- Open API.
In CE you can customize violations checks (triggers) that start automatically and send alerts/workflow items in case of:
- Modification of roles in a client system.
- Modification of user’s rights in a client system.
A comprehensive risk landscape can be overwhelming and difficult to manage. For a better understanding of your rule sets and risks, CE allows you to easily categorize and prioritize your risks based on the following criteria:
- Risk impact: Define the impact of a risk on your business (e.g. marginal, high, critical)
- Risk level: Specify color-coded risk levels (e.g. low, medium, high)
- Risk likelihood: Assess the possibility of a potential risk occurring (e.g. rare, unlikely, certain)
- Type of risk: Determine the type or risk (e.g. operational risk, strategic risk, financial risk)-- Module: Categorize the risk by modules (e.g. Accounts Receivable, General Ledger)
Such a structured risk landscape facilitates you own risk management.