SlideShare a Scribd company logo
Looking to
Automate
Your Access
Controls?
Case Study: Global Cosmetics Company
Learn how other companies are eliminating
SoD conflicts and soaring through their
internal audits
Chemical Security
Cosmetics
How PeroxyChem nearly
eliminated SoD conflicts
with Access Analyzer
How a fortune 500 global
security company reduced
SoD Auditing by 700+ hours
How a global cosmetics
company met increased
audit requirements
during an SAP GRC
install.
“Access Analyzer produced very targeted and
accurate SAP access and utilization data we
needed to provide our external auditors. They
were very happy with the tool and kept asking
us for more data, eventually using it
themselves when we got too busy.”
- SENIOR DIRECTOR OF INTERNAL AUDIT
GLOBAL COSMETICS COMPANY
Case Study 3: Global Cosmetics Company
The client is a global cosmetics and
beauty care products company. Its well-
known brand is synonymous with beauty
and its products are distributed in more
than 100 countries.
The Company
The
ProblemThe company was faced with an
upcoming year-end audit which
included a review of the company’s
SAP® access controls and
utilization data. They had a list of
requests from their external
auditors and they did not have an
automated tool to efficiently
capture and present this
information. The company was also
starting to implement SAP’s
Governance, Risk and Compliance
(GRC) platform, however the project
would not be complete in time to
help with the 2015 year-end audit
process.
THE
SOLUTION
Upon reviewing the reporting capabilities of Access Analyzer, the team
decided to move forward with the Reporting Plan subscription, which
includes a suite of executive-level Segregation of duties (SoD) and
Sensitive Access analysis reporting capabilities. The initial installation of
Access Analyzer took less than 30 minutes, which allowed the Senior
Director of Internal Audit to begin running the needed reports almost
immediately.
THE RESULTS
The company was able to complete
their year-end audit tasks by providing
accurate data from Access Analyzer to
the external auditors while the Director
of Global IT Compliance and her team
were able to continue to focus on the
implementation of SAP GRC across
the company.
W W W . E R P M A E S T R O . C O M
01 02
03
RESULTS
The Senior Director of Internal Audit
primarily relied on the User Conflict
Matrix and BPO Conflict reports
utilization reporting to demonstrate
utilization of access and segregation of
duties (SoD) controls over the course of
the year, which was then shared with
their external auditors. Using Access
Analyzer, he was also able to document
any mitigating controls.
Besides the reporting capabilities which work well in place of or alongside SAP GRC,
the flexibility of ERP Maestro’s cloud-based subscription model was another plus for
the Director of Global IT Compliance and her team. With no long-term commitment,
they could easily decide to stop or continue the service after the GRC
implementation.
WANT TO
LEARN MORE?
http://www.erpmaestro.com/resources/case-studies

More Related Content

Similar to Case Study: How a global cosmetics company met increased audit requirements during an SAP GRC install.

Reciprocity_GRC Software Buyers Guide v5
Reciprocity_GRC Software Buyers Guide v5Reciprocity_GRC Software Buyers Guide v5
Reciprocity_GRC Software Buyers Guide v5
justinklooster
 
Brochure Auditing Erp System V2
Brochure   Auditing Erp System V2Brochure   Auditing Erp System V2
Brochure Auditing Erp System V2
agc infotech
 
Crawford - Akritiv Case Study Article
Crawford - Akritiv Case Study ArticleCrawford - Akritiv Case Study Article
Crawford - Akritiv Case Study Article
Bruce Rosenblum
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controls
Oracle
 

Similar to Case Study: How a global cosmetics company met increased audit requirements during an SAP GRC install. (20)

Transform Data into Action
Transform Data into ActionTransform Data into Action
Transform Data into Action
 
SAP GRC
SAP GRC SAP GRC
SAP GRC
 
Reciprocity_GRC Software Buyers Guide v5
Reciprocity_GRC Software Buyers Guide v5Reciprocity_GRC Software Buyers Guide v5
Reciprocity_GRC Software Buyers Guide v5
 
Brochure Auditing Erp System V2
Brochure   Auditing Erp System V2Brochure   Auditing Erp System V2
Brochure Auditing Erp System V2
 
Lima Consulting Group at SIP Connect 2015 - Deploying the LCG Maturity Model
Lima Consulting Group at SIP Connect 2015 - Deploying the LCG Maturity ModelLima Consulting Group at SIP Connect 2015 - Deploying the LCG Maturity Model
Lima Consulting Group at SIP Connect 2015 - Deploying the LCG Maturity Model
 
Introducing Smartsheet Gov: The Trusted Work Execution Platform for Government
Introducing Smartsheet Gov: The Trusted Work Execution Platform for GovernmentIntroducing Smartsheet Gov: The Trusted Work Execution Platform for Government
Introducing Smartsheet Gov: The Trusted Work Execution Platform for Government
 
Review the five signs that you need a new Segregation of Duties compliance st...
Review the five signs that you need a new Segregation of Duties compliance st...Review the five signs that you need a new Segregation of Duties compliance st...
Review the five signs that you need a new Segregation of Duties compliance st...
 
CoDel Assistant
CoDel AssistantCoDel Assistant
CoDel Assistant
 
Faster and more reliable reporting for a Fortune 500 consumer goods company.
Faster and more reliable reporting for a Fortune 500 consumer goods company.Faster and more reliable reporting for a Fortune 500 consumer goods company.
Faster and more reliable reporting for a Fortune 500 consumer goods company.
 
THE GOOD, THE BAD, THE DATA - Artificial Intelligence and Robotic Process Aut...
THE GOOD, THE BAD, THE DATA - Artificial Intelligence and Robotic Process Aut...THE GOOD, THE BAD, THE DATA - Artificial Intelligence and Robotic Process Aut...
THE GOOD, THE BAD, THE DATA - Artificial Intelligence and Robotic Process Aut...
 
THE GOOD, THE BAD, THE DATA - Artificial Intelligence and Robotic Process Aut...
THE GOOD, THE BAD, THE DATA - Artificial Intelligence and Robotic Process Aut...THE GOOD, THE BAD, THE DATA - Artificial Intelligence and Robotic Process Aut...
THE GOOD, THE BAD, THE DATA - Artificial Intelligence and Robotic Process Aut...
 
Performance Testing: Eliminate System Outages and Save Millions
Performance Testing: Eliminate System Outages and Save MillionsPerformance Testing: Eliminate System Outages and Save Millions
Performance Testing: Eliminate System Outages and Save Millions
 
Crawford - Akritiv Case Study Article
Crawford - Akritiv Case Study ArticleCrawford - Akritiv Case Study Article
Crawford - Akritiv Case Study Article
 
Smartsheet: Transformation through Innovation: Work Execution and the Impact ...
Smartsheet: Transformation through Innovation: Work Execution and the Impact ...Smartsheet: Transformation through Innovation: Work Execution and the Impact ...
Smartsheet: Transformation through Innovation: Work Execution and the Impact ...
 
Adaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyAdaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_study
 
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
 
166427325 sap-a udit-management
166427325 sap-a udit-management166427325 sap-a udit-management
166427325 sap-a udit-management
 
Business Benefits of Robotic Process Automation
Business Benefits of Robotic Process AutomationBusiness Benefits of Robotic Process Automation
Business Benefits of Robotic Process Automation
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controls
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...
 

Recently uploaded

Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
Bhaskar Mitra
 

Recently uploaded (20)

Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone KomSalesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
 
UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1
 
Optimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through ObservabilityOptimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through Observability
 
Exploring UiPath Orchestrator API: updates and limits in 2024 🚀
Exploring UiPath Orchestrator API: updates and limits in 2024 🚀Exploring UiPath Orchestrator API: updates and limits in 2024 🚀
Exploring UiPath Orchestrator API: updates and limits in 2024 🚀
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
 
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptxWSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
 
Speed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in MinutesSpeed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in Minutes
 
Introduction to Open Source RAG and RAG Evaluation
Introduction to Open Source RAG and RAG EvaluationIntroduction to Open Source RAG and RAG Evaluation
Introduction to Open Source RAG and RAG Evaluation
 
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptxIOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
 
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya HalderCustom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
 
IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 

Case Study: How a global cosmetics company met increased audit requirements during an SAP GRC install.

  • 1. Looking to Automate Your Access Controls? Case Study: Global Cosmetics Company
  • 2. Learn how other companies are eliminating SoD conflicts and soaring through their internal audits Chemical Security Cosmetics How PeroxyChem nearly eliminated SoD conflicts with Access Analyzer How a fortune 500 global security company reduced SoD Auditing by 700+ hours How a global cosmetics company met increased audit requirements during an SAP GRC install.
  • 3. “Access Analyzer produced very targeted and accurate SAP access and utilization data we needed to provide our external auditors. They were very happy with the tool and kept asking us for more data, eventually using it themselves when we got too busy.” - SENIOR DIRECTOR OF INTERNAL AUDIT GLOBAL COSMETICS COMPANY Case Study 3: Global Cosmetics Company
  • 4. The client is a global cosmetics and beauty care products company. Its well- known brand is synonymous with beauty and its products are distributed in more than 100 countries. The Company
  • 5. The ProblemThe company was faced with an upcoming year-end audit which included a review of the company’s SAP® access controls and utilization data. They had a list of requests from their external auditors and they did not have an automated tool to efficiently capture and present this information. The company was also starting to implement SAP’s Governance, Risk and Compliance (GRC) platform, however the project would not be complete in time to help with the 2015 year-end audit process.
  • 6. THE SOLUTION Upon reviewing the reporting capabilities of Access Analyzer, the team decided to move forward with the Reporting Plan subscription, which includes a suite of executive-level Segregation of duties (SoD) and Sensitive Access analysis reporting capabilities. The initial installation of Access Analyzer took less than 30 minutes, which allowed the Senior Director of Internal Audit to begin running the needed reports almost immediately.
  • 8. The company was able to complete their year-end audit tasks by providing accurate data from Access Analyzer to the external auditors while the Director of Global IT Compliance and her team were able to continue to focus on the implementation of SAP GRC across the company. W W W . E R P M A E S T R O . C O M 01 02 03 RESULTS The Senior Director of Internal Audit primarily relied on the User Conflict Matrix and BPO Conflict reports utilization reporting to demonstrate utilization of access and segregation of duties (SoD) controls over the course of the year, which was then shared with their external auditors. Using Access Analyzer, he was also able to document any mitigating controls. Besides the reporting capabilities which work well in place of or alongside SAP GRC, the flexibility of ERP Maestro’s cloud-based subscription model was another plus for the Director of Global IT Compliance and her team. With no long-term commitment, they could easily decide to stop or continue the service after the GRC implementation.