Challenges
- Segregation-of-duties issues identified
- Manual process of checking transactions
- Lack of reports and visibility
Results
- Designed access controls to identify the risk of users holding both Create Supplier and Approve Invoices entitlements
- Created continuous monitoring access control from the access design model, assigning incidents to investigators
- Enabled the team to investigate access incidents and act to remediate them, with greater visibility into the control process across the organisation
- Designed a transaction control to identify suspicious transactions in the procure-to-pay cycle
- Automated the process across the organisation