Skip to content

Case study Public sector

Ministry of Health improves SOD to mitigate risk in EBS with GRC controls

A Ministry of Health in Oceania, the principal advisor on health and disability, was checking transactions by hand with segregation-of-duties issues identified and little reporting or visibility.

IndustryPublic sector
RegionOceania
SizeOver 1,000 employees; principal advisor on health and disability
Primary ERPOracle E-Business Suite

Challenges

  • Segregation-of-duties issues identified
  • Manual process of checking transactions
  • Lack of reports and visibility
  • Mitigate risk through embedded real-time enforcement and prevention
  • Build better, more compliant roles

Results

  • Designed access controls to identify the risk of users holding both Create Supplier and Approve Invoices entitlements
  • Created a continuous monitoring access control from the access design model, assigning incidents to investigators
  • Enabled the team to investigate access incidents and remediate them, with greater visibility into the control process across the organisation
  • Designed a transaction control to identify suspicious transactions in the procure-to-pay cycle and automated the process across the organisation

See it on your ERP

A 30-minute walkthrough against the systems you actually run.

See how this model applies to the systems sitting inside your own estate.

What this story shows

  • Create Supplier and Approve Invoices cannot sit with one person unnoticed
  • Access incidents route to investigators rather than waiting for review
  • Procure-to-pay transactions are screened by a designed control