Challenges
- Auditors required a full review of all ERP Cloud roles to ensure SoD risks were mitigated before production roll-out
- IT Security needed assurance that roles given to users did not violate the company's security policy or access controls
- Business users needed assurance that process controls such as 3-way match, approval hierarchy and cross-validation rules were configured accurately in ERP Cloud
- Finance management needed to prevent financial misstatement risk in GL, AP, FA and AR modules
Results
- Within three days, delivered role and user violation reports with over 100 SoD policies tested
- Reviewed over 300 configurations across the GL, AP, FA, AR, INV, PO and TNE modules
- Gave internal audit and control owners access to a Cloud ERP risk repository of over 500 access, transactional and configuration risks to map against their risk and control matrices
- Created more than 100 unique Oracle ERP roles
- Identified more than 30 SDLC control defects
- Reduced implementation cost by 30%