cancel
Showing results for 
Search instead for 
Did you mean: 

GRC PC 10 Automatic Controls as event and not as issue

Former Member
0 Kudos

Dear all,

We are now implementing GRC 10 PC and AC on an international SOx Compliance Company.

Nowadays we are trying to configure monitoring controls to report events every day that are NOT issues, (for example we would like to report every day the JETs with Document Type SA; or new hires reported by HR). We did this configuring that as an automatic control and control worked but, the tool reported it as an "Issue" it means that it was reported as Control Deficiency, then we void the control if necessary.

What we would like to know is if there is any way that PC could inform that monitoring control as an "event" and NOT as an "issue" in order just to let the user know and decide whether an issue or not.

Hope you can help us.

Thanks in advance

Frank

Accepted Solutions (1)

Accepted Solutions (1)

former_member205878
Contributor
0 Kudos

Hi Frank,

Automated controls always result or report issue when the exceptions are captured.

If your  requirement is to monitor events then Process Control has provided a facility - Event Based Monitoring by which specific events can be monitored and required action can take place.

You can find Event Based Monitoring details under -

SAP Market Place -> Release & Upgrade Info ->  Installation & Upgrade Guides ->  Governance, Risk, and Compliance -> Process Control -> Release 10.0 -> PC10-Event Driven Subscenarios for Continuous Monitoring

Regards,

Silky Sharma

Former Member
0 Kudos

Silky,

Thanks for your response. We appreciate that.

We were taking a look at the guide you provide us, but in that case also the events will be

reported as issues too. What we need to figure out if there is a way that PC 10 could help us informing events but not as issue.

For example, we defined as a Business Rule that any new user (New entry on USR02 table) will be informed. In that case with any new user, the control owner receives a Control Deficiency mail, then he must log into the system and "Void" the control after checking that everything is ok. It isn't a control deficiency, but Control Owner wants to be informed about new users in production system.

Having this scenario, Is there any way that an automatic control could be configured as a notification but not an issue? or anytime the result is captured as issue?

On the other hand, if we VOID those daily control, will them appear in the final sign-off?

Regards,

Frank

Former Member
0 Kudos

Hello everyone,

Sorry for the insistance but is there any other expert that could provide any other idea with this scenario?

Thanks in advance.

rajeshwari_akkamgari
Active Participant
0 Kudos

Hi Francisco,

What kind of analysis and deficinecy level are you using. You can set the deficiency level to'Review Required' (with analysis type-Changes), and try. Review required is generally used where user just want to review the control and do not want to report any issues out of the testing.

regards,

Rajeshwari

Answers (1)

Answers (1)

saksham
Advisor
Advisor
0 Kudos

Hi Francisco,

1.Review Required is displayed in the following cases:Analysis Type: Changes (Review Required is displayed)

It is not displayed for the following field values:Analysis Type: Number Of Changes.
Analysis Type: Monitor.

2.The parameter "review required" is used in those scenarios ,wherein,the changes/exceptions recorded cannot be exactly categorized for deficiency but they still need to be reviewed by the reviewer/responsible person.

3. "Review Required" works the same way as the parameters "High/Medium/Low" do.

Kind Regards,

Saksham