Challenges
- Segregation-of-duties issues identified
- Manual process of checking transactions
- Lack of reports and visibility
- Mitigate risk through embedded real-time enforcement and prevention
- Build better, more compliant roles
Results
- Designed access controls to identify the risk of users holding both Create Supplier and Approve Invoices entitlements
- Created a continuous monitoring access control from the access design model, assigning incidents to investigators
- Enabled the team to investigate access incidents and remediate them, with greater visibility into the control process across the organisation
- Designed a transaction control to identify suspicious transactions in the procure-to-pay cycle and automated the process across the organisation