SAP GRC


What is SAP GRC?

Governance, risk, and compliance (GRC) is a vital set of functions for enterprises to maintain secure and audit-friendly environments while being more confident in their actions. For SAP customers, SAP GRC can mean a set of GRC products provided by SAP itself or the GRC activities and technologies related to SAP systems.

What is SAP GRC?

Governance, risk, and compliance (GRC) is a vital set of functions for enterprises to maintain secure and audit-friendly environments while being more confident in their actions. For SAP customers, SAP GRC can mean a set of GRC products provided by SAP itself or the GRC activities and technologies related to SAP systems.

GRC is growing in importance with rapidly changing regulations that create new compliance challenges. Security and financial risks are also on the rise as companies adopt more cloud technologies, enact bring-your-own-device policies, and enable remote workers in greater numbers.

SAP GRC tools are available to help with areas of risk management, process control, financial compliance, threat detection, identity management, privacy governance, and more. SAP partners and other vendors that provide GRC solutions and consulting services include Appsian Security, Fastpath, and Soterion.

Key Considerations for SAPinsiders:

  • Take inventory of your GRC processes and automate wherever possible. In our most recent GRC State of the Market research, successful GRC organizations are focused on automation to streamline processes. To do this, processes being automated need to be repeatable and effective. Before investing in GRC automation technology, it’s best to get processes in line. Many companies are automating the process of keeping track of who makes changes to the SAP systems.
  • Digital transformation offers the opportunity to rethink GRC processes. If your company is implementing new software such as SAP S/4HANA, it’s smart to use that project as a catalyst to examine key GRC processes and find out how they can be improved. For example, HP set up a new GRC system during its SAP S/4HANA migration, including rethinking its user access processes and segregation of duties (SoD) ruleset. In the past HP relied on a homegrown tool for access control but implemented SAP Access Control and SAP Process Control as a component of its SAP S/4HANA migration.
  • Determine the present and future state of remote work at your company, and how that impacts risk and security. Many companies have gone more remote in the past two years. For GRC groups, this provides more challenges for user access and opens companies up to more cyber threats. Map out your remote working landscape and determine what processes and tools you have in place to reduce risk.

457 results

  1. Improve Business Reporting on Your RAR Data Using Data Mart Functionality

    Reading time: 11 mins

    Reporting can be challenging when technical information is not presented in a user-friendly way, causing business users to ignore it or misread it. Overcome these challenges in the risk analysis and remediation (RAR) component of SAP BusinessObjects Access Control by using the data mart feature included in Support Packages 9 and 10. Discover the customizing...…

  2. Live from SAPinsider: Stanley, Black & Decker’s GRC Journey

    Rebecca Hodge of Stanley, Black & Decker joins Steve Biskie of High Water Advisors at the SAPinsider GRC 2016 event to discuss her company’s GRC journey with SAP Access Control. This is an edited transcript of the discussion:  Steve Biskie, High Water Advisors: Hi, I’m Steve Biskie, Managing Director of High Water Advisors, here with...…

  3. Supply Chain GRC: Gain Control of Your Supply Chain Processes

    June 14, 2023

    Most companies want to grow their business as fast as possible, but they need stay in control of their supply chain process and avoid unnecessary risks. By implementing a Governance, Risk and Compliance (GRC) system, organizations can monitor processes and ensure they are defined, managed, planned, and executed correctly. Recent SAPinsider benchmark research points to…

  4. SAP Security: Dealing with cross-division access in Saint-Gobain

    Reading time: 1 mins

    Saint-Gobain South Africa faced unique access control issues due to having multiple companies within a shared SAP ecosystem. With a mix of role methodologies and outsourced providers, they consistently failed access control audits. Through implementing a GRC solution and a role redesign, they established a solid foundation for access control and mitigated risks. Continual efforts…

  5. Reduce Costs in Compliance Management with a Top-Down, Risk-Based Scoping Approach

    Reading time: 15 mins

    With the requirement of identifying and assessing the design and operating effectiveness of internal controls many companies have ended up producing too much documentation and performing more testing, resulting in increased costs of compliance. Regulatory agencies such as the US Securities and Exchange Commission and the Public Company Accounting Oversight Board (PCAOB) encourage companies to...…

  6. 5 Pillars for Addressing Cybersecurity and Data Protection: SAP Highlights Key Areas for Organizations to Focus on to Build Digital Trust with Employees and Customers

    Reading time: 11 mins

    by Bruce Romney, Senior Director of Product Marketing, GRC and Security Solutions, SAP and Erin Hughes, SAP S/4HANA Finance and Governance, Risk, and Compliance (GRC) Center of Excellence, SAP North America and Thomas Frénéhard, Global Finance and Risk Center of Excellence, SAP What are today’s business leaders most focused on and what are their top...…

  7. chain with red link image

    Increasing Threats Highlight the Need for Robust Enterprise Risk Management

    Reading time: 2 mins

    In the face of challenging micro and macro events, companies need to be able to anticipate and better manage risks that impact their core business objectives. Additionally, legacy business models and IT landscapes don’t contain all of the capabilities necessary to manage risk across the entire enterprise. For example, intelligent technologies like robotic process automation…

  8. GRC State of the Market 2022

    Governance, Risk, and Compliance: State of the Market 2022

    Reading time: 1 mins

    GRC teams are stretched, and their scope of responsibility continues to grow. In traditional areas of GRC, changing business models and regulations are creating new challenges. However, security threats have risen to the top as a driver for GRC strategy. GRC professionals are now tasked with playing a role in security risk assessment and threat…

  9. GRC Strategies

    GRC State of the Market 2023 – Benchmark Research Report

    Reading time: 1 mins

    Governance, Risk, and Compliance teams and organizations face a wide range of challenges and obstacles in 2023. These include a constantly shifting landscape of regulations, emerging technologies, and an ever-growing list of cybersecurity threats. Contending with these challenges is a top priority for organizations of all sizes.

  10. Soterion Corporate Video

    Soterion’s plug-and-play agile GRC offering provides immediate integration into SAP allowing you to keep up with the market while effectively managing risk. The team at Soterion understand that the world is changing more rapidly than ever before. We know that organisations are having to become more agile to stay competitive, while dealing with escalating risk,…