New SoD Management Solution with Improved Governance Processes

Client sector: Telecommunications

Client Profile

Large stock listed telecommunications services provider with presence in nearly twenty countries with +20 000 employees worldwide. SAP solutions are used widely in main administrational processes and some of the key business processes.  Organization has high emphasis on building sustainable control processes for key areas.

Challenge

Segregation of duties (SoD) matrix and related reporting was outdated and processes missing. Especially in SAP systems there was a need to mitigate the segregation of duty risks and get control of the access rights. Objective was to implement a stronger engagement for segregation of duty risks from process perspective and the governance around this with defined responsibilities. 

Solution

After evaluation a decision was made to develop a new SoD management model based on the SAP GRC Access Control solution. Project set to work and created a new SoD rule-set together with process owners of each process area, implemented a global way of working and governance to avoid and reduce SoD risks and implemented SAP GRC Access Control v 10 solution to support these processes. At the last phases of the project new SoD reporting practice was launched and the strategy for further reduction of SoD level was created. Already during the project several “low hanging fruits” were collected resulting improvements in processes and immediate SoD reduction.

GRC Nordic Role

GRC Nordic worked in partnership with the client and the project was completed in 6 months including the summer vacation period. Project method was based on GRC Nordic Rapid Deployment model for SAP GRC including usage of several best practices and implementation accelerators. Consultants had full responsibility of facilitating risk and control workshops with business process owners and ensuring the smooth implementation of the SAP solution in partnership with IT. Special emphasis was given to ensure governance processes and change management of the new solution. Project was finished on time, scope and budget.

More success stories