Challenges
- Segregation-of-duties reviews are time consuming and inefficient
- Internal control testing is sample-based look-back rather than real-time monitoring
- Many controls relied on for internal control purposes are detective and manual rather than preventative and automated
- Changes to Oracle forms and fields require significant Oracle knowledge and input from expert users or IT
- Monitoring changes to critical application settings is difficult
- Capability to monitor change and identify transaction anomalies is limited
Results
- Replaced external audit SoD reports with an internal segregation-of-duties detection, prevention and monitoring process in Oracle E-Business Suite
- Enabled a change controls detection, prevention and monitoring process
- Detected and prevented suspicious transactions across multiple enterprise applications
- Integrated GRC data into a single global system for all audit and compliance management activity
- Streamlined and automated risk assessment, control testing and process certification through workflows
- Automated controls testing and tracked issues and actions through workflows
- Gave management visibility into consolidated GRC activity through dashboards and reports