cancel
Showing results for 
Search instead for 
Did you mean: 

GRC rules needs to be incorporated within rule set

Former Member
0 Kudos

Hi Experts,

A number of transactions were not included that have SOD conflicts with other transactions. In addition, some additional SOD rules for transactions, that have other conflicts configured in the system, have conflicts with additional transactions. In order for the GRC RAR module to be used for SOD testing as part of organization's annual Sarbanes Oxley (SOX) control testing; these rules need to be incorporated into the overall GRC RAR rule set.

Kindly provide any suugetion to find out the solution as I am new in this field.

Accepted Solutions (0)

Answers (2)

Answers (2)

former_member184114
Active Contributor
0 Kudos

Hi,

If you have access to RAR, then you can check accessing the tab Rule Architect. Here all the elements are mentioned and start making use of them for modify the rule set for your needs.

Please let me know if further help is needed.

Regards,

Faisal

Former Member
0 Kudos

Hi,

Would I be correctly understanding that you have already implemented the SAP delivered ruleset into your GRC system but you wish to modify it to cater for risk definitions specific to your organisation?

If so, this is absoloutly normal. The usual approach is to implement the SAP standard rule set, and then modify that rule set as per your control needs. Involvement of the Internal Audit/Goverenance team would be beneficial in defining the risk rules, as they would have valuable input/considerations from the annual audit reviews to feed into the rule set etc.

Also consider adding custom transactions into the risk definitions, for which you should consider getting support from the busines users who use the programs etc.

I think there are some articles out there, which may be useful for you to understand the basic Risk Analysis and Remediation appraoch. Try the BPX part of the website.

All the best.